Skip to main contentSkip to content

SA 200-299

Overall objectives, quality management, documentation, fraud, laws and regulations, communication.

Audit Hub · A02

SA 200-299

Overall objectives, quality management, documentation, fraud, laws and regulations, communication.

← Back to hub

Section-wise decoding

1. Objective

The 200-series Standards set the general principles that govern the whole engagement before any fieldwork begins: what the auditor is trying to achieve, how the engagement is agreed, how quality is controlled, what must be documented, and how fraud, non-compliance and governance communication are handled.

2. Applicability

Every SA in this block applies to every audit engagement — unlike the size/threshold-dependent Companies Act provisions, the 200-series has no entity-size carve-out.

3. Core Rules

SASubject
SA 200Overall objectives of the independent auditor and the conduct of an audit
SA 210Agreeing the terms of audit engagements
SA 220Quality control for an audit of financial statements
SA 230Audit documentation
SA 240The auditor's responsibilities relating to fraud
SA 250Consideration of laws and regulations
SA 260Communication with those charged with governance (TCWG)
SA 265Communicating deficiencies in internal control to TCWG and management

4. Practical Example

Under SA 230, a working paper is not "complete" merely because a conclusion is stated — an experienced auditor with no prior connection to the engagement must be able to understand the nature, timing, extent of procedures performed, the results obtained, and significant matters arising, purely from the file itself.

5. Common Mistake

Treating SA 240 fraud responsibility as "finding fraud." SA 240 requires maintaining professional scepticism and designing procedures responsive to fraud risk — it does not make the auditor a guarantor against fraud that is concealed through collusion or forgery.

Documentation and communication map

RequirementStandardEvidence
Engagement terms agreed before commencementSA 210Signed engagement letter
File assembled to the "experienced auditor" testSA 230Working papers, sign-offs, cross-references
Significant internal-control deficiencies communicatedSA 265Management letter / TCWG communication, timely and in writing for significant items
Non-compliance with laws/regulations evaluatedSA 250Documented assessment of identified or suspected non-compliance and its financial-statement effect

Exceptions and red flags

Implementation checklist

Q&A

What is the difference between SA 260 and SA 265?SA 260 covers general two-way communication with those charged with governance about audit scope, timing and significant findings; SA 265 is specifically about communicating identified deficiencies in internal control.
Does SA 240 require the auditor to design procedures assuming fraud exists?It requires maintaining professional scepticism and considering the risk of management override of controls specifically, but it does not require assuming every engagement involves active fraud.
Can engagement terms be agreed verbally?No — SA 210 requires the agreed terms to be recorded in a written engagement letter or other suitable form of written agreement.
Can this be used as professional advice?No. Confirm the exact current text of each SA and any ICAI implementation guidance before applying it to a live engagement.

Finin2min Summary

SA 200-299 in 2 minutes: These are the engagement-wide ground rules — objectives (SA 200), engagement letter (SA 210), quality control (SA 220), documentation that stands alone (SA 230), fraud scepticism (SA 240), laws/regulations (SA 250), and two governance-communication standards (SA 260 general, SA 265 control deficiencies specifically).

Source log

Home Insights All Hubs

© 2026 Finin2min · Author: CA Nikhil Gupta · Reviewed by CA Nikhil Gupta · Last reviewed 29 August 2026.