Launch offer — 25% off with code LAUNCH-25 See plans →
Microlesson · 5-min read

SA 300: Overall Audit Strategy and Legal/Regulatory Framework

## SA 300: Planning an Audit of Financial Statements

### Core Requirement

The auditor shall establish an overall audit strategy that sets the scope, timing, and direction of the audit, and guides the development of the audit plan.

---

## Purpose of the Audit Strategy

The audit strategy:

  • Sets scope, timing, and direction
  • Guides development of the detailed audit plan
  • Helps determine key resources to be employed
  • Assists in directing and assigning engagement team members

---

## Audit Strategy vs Audit Plan

Audit StrategyAudit Plan
LevelHigh-level / strategicDetailed / tactical
CoversOverall scope, timing, directionSpecific procedures at the assertion level
Documented asKey decisions and significant mattersPlanned nature, timing, extent of each procedure

---

## Key Factors in Establishing Audit Strategy

FactorDescription
Characteristics of the engagementNature of entity, reporting framework, industry specifics
Significant mattersFactors requiring professional judgment that direct the team's efforts
Legal and regulatory frameworkUnderstanding applicable laws/regulations and the entity's compliance
Resource planningIdentifying nature and extent of resources required

---

## Legal and Regulatory Framework — Critical Point

SA 300 requires the auditor to consider, prior to risk assessment, the following:

> Obtaining a general understanding of the legal and regulatory framework applicable to the entity and how the entity is complying with that framework.

### Practical Implication

If a regulation imposes significant compliance obligations (with material financial consequences such as fines), the auditor must:

1. Incorporate compliance assessment into the overall audit strategy

2. Identify and assess the risk of non-compliance

3. Plan appropriate inquiry or procedures to understand how the entity is complying

Worked example

### Example 1

Q (PYP JAN 25 — 5 marks): CA P is the engagement partner for the audit of Heavy Industries Limited (listed company). A regulatory guideline requires the company to maintain a digital database of personnel who can access the company's books, to prevent insider trading. Non-compliance attracts hefty fines.

(i) Should CA P consider digital database maintenance in the audit strategy?

Yes. SA 300 requires the auditor to identify characteristics of the engagement that define scope and consider factors significant in directing team efforts. The regulatory requirement imposes significant compliance obligations with material financial consequences (hefty fines). CA P must incorporate the assessment of digital database maintenance into the overall audit strategy.

(ii) Is CA P's plan to inquire from the IT Head in line with SA 300?

Yes. SA 300 requires the auditor to obtain a general understanding of the legal and regulatory framework applicable to the entity and how the entity is complying with it. Inquiring from the IT Head about digital database maintenance is an appropriate procedure to assess compliance, and is fully aligned with SA 300's planning requirements.

⚠️ Common exam mistakes

  • Treating audit strategy and audit plan as the same — strategy is high-level direction; plan is detailed procedure-level
  • Not recognising that legal/regulatory compliance considerations arise during planning, before formal risk assessment
  • Answering only whether the entity must comply — the auditor's obligation is to understand the framework AND how the entity is complying with it
  • Missing that financial consequences of non-compliance (fines, penalties) elevate the matter to a scope-defining characteristic of the engagement
Bare-Act text Establishing the Overall Audit Strategy · SA 300 — Planning an Audit of Financial Statements (ICAI) · click to expand
The auditor shall establish an overall audit strategy that sets the scope, timing, and direction of the audit, and that guides the development of the audit plan.
Now that you've read this — what's next?
Move from understanding → mastery in 3 clicks. Each option below picks up from this lesson's topic.
Start 15-min diagnostic