SA 200-299
Overall objectives, quality management, documentation, fraud, laws and regulations, communication.
SA 200-299
Overall objectives, quality management, documentation, fraud, laws and regulations, communication.
← Back to hubSection-wise decoding
1. Objective
The 200-series Standards set the general principles that govern the whole engagement before any fieldwork begins: what the auditor is trying to achieve, how the engagement is agreed, how quality is controlled, what must be documented, and how fraud, non-compliance and governance communication are handled.
2. Applicability
Every SA in this block applies to every audit engagement — unlike the size/threshold-dependent Companies Act provisions, the 200-series has no entity-size carve-out.
3. Core Rules
| SA | Subject |
|---|---|
| SA 200 | Overall objectives of the independent auditor and the conduct of an audit |
| SA 210 | Agreeing the terms of audit engagements |
| SA 220 | Quality control for an audit of financial statements |
| SA 230 | Audit documentation |
| SA 240 | The auditor's responsibilities relating to fraud |
| SA 250 | Consideration of laws and regulations |
| SA 260 | Communication with those charged with governance (TCWG) |
| SA 265 | Communicating deficiencies in internal control to TCWG and management |
4. Practical Example
Under SA 230, a working paper is not "complete" merely because a conclusion is stated — an experienced auditor with no prior connection to the engagement must be able to understand the nature, timing, extent of procedures performed, the results obtained, and significant matters arising, purely from the file itself.
5. Common Mistake
Treating SA 240 fraud responsibility as "finding fraud." SA 240 requires maintaining professional scepticism and designing procedures responsive to fraud risk — it does not make the auditor a guarantor against fraud that is concealed through collusion or forgery.
Documentation and communication map
| Requirement | Standard | Evidence |
|---|---|---|
| Engagement terms agreed before commencement | SA 210 | Signed engagement letter |
| File assembled to the "experienced auditor" test | SA 230 | Working papers, sign-offs, cross-references |
| Significant internal-control deficiencies communicated | SA 265 | Management letter / TCWG communication, timely and in writing for significant items |
| Non-compliance with laws/regulations evaluated | SA 250 | Documented assessment of identified or suspected non-compliance and its financial-statement effect |
Exceptions and red flags
- Risk: Assembling the final audit file after the report date without contemporaneous documentation — SA 230 sets a specific documentation-assembly deadline (ordinarily within 60 days of the report date under the applicable ICAI standard), and documentation added after that window is treated differently from evidence gathered during the audit.
- Risk: Communicating only "significant" deficiencies to TCWG under SA 265 while failing to also communicate other identified deficiencies to management in writing as required.
- Risk: Confusing SA 250's "laws and regulations" scope — the auditor's responsibility differs for laws with a direct effect on financial statement amounts versus other laws where non-compliance may only trigger disclosure or going-concern considerations.
Implementation checklist
- ✓ Issue and obtain a signed engagement letter (SA 210) before commencing fieldwork, and reissue on any change in terms.
- ✓ Build the working-paper file to be self-explanatory to a reviewer with no prior involvement (SA 230's core test).
- ✓ Maintain a professional-scepticism log for fraud-risk indicators identified during planning and fieldwork (SA 240).
- ✓ Route all significant control deficiencies to TCWG in writing, not verbally, within a reasonable time of identification (SA 265).
Q&A
| What is the difference between SA 260 and SA 265? | SA 260 covers general two-way communication with those charged with governance about audit scope, timing and significant findings; SA 265 is specifically about communicating identified deficiencies in internal control. |
|---|---|
| Does SA 240 require the auditor to design procedures assuming fraud exists? | It requires maintaining professional scepticism and considering the risk of management override of controls specifically, but it does not require assuming every engagement involves active fraud. |
| Can engagement terms be agreed verbally? | No — SA 210 requires the agreed terms to be recorded in a written engagement letter or other suitable form of written agreement. |
| Can this be used as professional advice? | No. Confirm the exact current text of each SA and any ICAI implementation guidance before applying it to a live engagement. |
Finin2min Summary
SA 200-299 in 2 minutes: These are the engagement-wide ground rules — objectives (SA 200), engagement letter (SA 210), quality control (SA 220), documentation that stands alone (SA 230), fraud scepticism (SA 240), laws/regulations (SA 250), and two governance-communication standards (SA 260 general, SA 265 control deficiencies specifically).
Source log
- ICAI — Standards on Auditing, complete text — SA complete text
- ICAI — Guidance Notes on Auditing Aspects — Guidance Notes
- ICAI — Checklist on Standards on Auditing — SA checklist