In this guide · 8 sections
- SA 300 requires an overall audit strategy and an audit plan. The audit plan — the audit programme — sets out the nature, timing and extent of the risk assessment procedures, the further audit procedures at the assertion level, and other procedures the SAs require.
- For a small entity, SA 300's application material accepts a brief memorandum as the strategy (if it covers the matters in paragraph 7) and standard programmes or checklists as the plan — provided they are tailored to the engagement and the risks you assessed.
- Tailoring means three things: drop steps that do not apply (with the reason), add steps for this year's risks, and size the work using materiality.
- Some procedures are required whatever the risk: substantive procedures for each material class of transactions, balance and disclosure (SA 330), and journal entry testing and a review of estimates for management override (SA 240).
- Each step should show who did it and when, who reviewed it and the working paper reference — that is how the programme records what SA 230 requires: who performed the work, who reviewed it, and when.
Try SignReady: A work programme tailored from the TB — steps that cannot apply are marked with the reason.
Start freeMost small-firm audit files contain an audit programme. Far fewer contain one that was actually used: the same printed checklist goes into every file, every box is ticked, and nothing in it reflects the client. Peer reviewers look for exactly this. This guide explains what SA 300 and SA 330 expect from an audit programme, how to tailor a standard one quickly, and a sample structure by area.
What SA 300 requires
SA 300 (Planning an Audit of Financial Statements) separates two things:
| Overall audit strategy | Audit plan (audit programme) | |
|---|---|---|
| What it sets | The scope, timing and direction of the audit: the reporting framework, reporting deadlines, materiality, the areas of higher risk, the team and its time | The nature, timing and extent of the procedures the team will perform |
| What it contains | Key decisions on scope, timing and conduct — often summarised in a memo | (a) planned risk assessment procedures (SA 315); (b) planned further audit procedures at the assertion level (SA 330); (c) other procedures needed to comply with the SAs |
| When it changes | When circumstances change during the audit | Updated as the audit progresses and the results come in |
SA 300 also requires you to plan the direction and supervision of the team and the review of their work, and to document the strategy, the plan and any significant changes to them during the audit, with the reasons.
For smaller entities, SA 300's application material is practical: a brief memorandum — for example, one prepared at the end of the previous audit and updated after a discussion with the owner-manager — can serve as the documented strategy if it covers the matters in paragraph 7, and standard audit programmes or checklists can serve as the plan, provided they are tailored to the circumstances of the engagement, including your risk assessment. That condition is where most files fall short.
A practical structure
A usable programme has one row per procedure with these columns:
| Column | Why it is there |
|---|---|
| Ref | A code such as RC2 (receivables, step 2) that the working papers can point back to |
| Procedure | What to do, in a sentence specific enough that someone else could do it |
| Assertion / risk | Why the step is there — existence, completeness, valuation, cut-off — or the specific risk it answers |
| Status | Done, Not relevant (with the reason), or Pending |
| Done by / date | SA 230 requires a record of who performed the work and when |
| Reviewed by / date | SA 230 requires a record of who reviewed the work, when and the extent of review |
| W/P reference | Where the evidence sits in the file |
| Conclusion / remarks | The result, the exceptions found, and any query raised |
Group the rows by area, in the order of the financial statements: planning, cash and bank, revenue, purchases, expenses and payroll, fixed assets, receivables, payables, borrowings, inventory, statutory compliance, and completion.
SignReady's work programme reads the trial balance and the client details: steps that cannot apply are marked "Not relevant" with the reason, and the key areas are picked out by performance materiality. You confirm, add and sign off.
Tailoring a standard programme in three moves
1. Drop the steps that cannot apply — and say why
A service company with no stock does not need inventory steps; a firm with no borrowings does not need loan confirmations. Mark such steps "Not relevant" with a one-line reason from the trial balance or the client's facts ("No inventory ledgers in TB; services company"). Deleting them silently leaves a reviewer unable to tell whether the step was considered.
2. Add steps for this year's risks
Your risk assessment — the CY vs PY review, the discussion with the client, last year's issues — should produce specific steps. Examples:
- Revenue up 60% with debtors up 150%: extend cut-off testing and confirmations; review credit notes after the year end.
- A new term loan: check the sanction letter, security and covenants, current maturities and the end-use.
- Cash sales in a retail business: test daily cash summaries against deposits; review section 269ST receipts.
- A large related party purchase: check approvals (section 188 for a company), pricing and disclosure.
3. Size the work with materiality
Use performance materiality to decide which balances need detailed testing and which can be covered by analytical procedures, and to set sample sizes and the confirmation threshold. A ₹40,000 prepaid expense in an audit with ₹2 lakh performance materiality needs little; a ₹30 lakh debtor needs a confirmation or alternative evidence.
Procedures that are always required
Some procedures stay in every programme, whatever the risk assessment says:
- Substantive procedures for each material area. SA 330 requires substantive procedures for each material class of transactions, account balance and disclosure, irrespective of the assessed risk.
- Closing process. SA 330 requires agreeing or reconciling the financial statements with the underlying accounting records, and examining material journal entries and other adjustments made in preparing them.
- Management override. SA 240 requires testing the appropriateness of journal entries and other adjustments, reviewing accounting estimates for bias, and evaluating the business rationale of significant unusual transactions — in every audit.
- Significant risks. Where you identify a significant risk, SA 330 requires substantive procedures that respond specifically to it.
- Completion. Subsequent events (SA 560), going concern (SA 570), written representations (SA 580), evaluation of misstatements (SA 450), and a final analytical review near the end of the audit (SA 520).
A sample programme for a small company audit
| Area | Typical steps |
|---|---|
| Planning | Engagement letter acknowledged; understanding of the entity updated; materiality set; previous year report and open points reviewed; preliminary CY vs PY review and risk areas identified |
| Cash and bank | Cash certificate or count; bank reconciliations for every account with old items reviewed; bank confirmations or year-end statements, including dormant accounts; large cash transactions against sections 40A(3), 269SS, 269ST and 269T (Income-tax Act, 1961 — for FY 2025-26; the Income-tax Act, 2025 applies from tax year 2026-27) |
| Revenue | Policy reviewed; sales reconciled with GST returns; sample vouched to dispatch and receipts; cut-off; monthly trend |
| Purchases and expenses | Sample vouched to invoices and goods receipt; input tax credit reconciled with GSTR-2B; gross profit and major expense heads compared with last year; TDS and section 40(a)(ia); payroll and PF / ESI; related party payments |
| Fixed assets | Register agreed to the TB; additions vouched with put-to-use dates; disposals; depreciation recalculated; title deeds of immovable property |
| Receivables and payables | Ageing agreed to the TB; confirmations above the threshold; recoverability and provisions; credit balances in debtors and debit balances in creditors; MSME dues and section 43B(h) |
| Borrowings | Loan statements or confirmations; interest recalculated; loans from directors and relatives against section 73 and the deposit rules; current maturities and security disclosed |
| Inventory | Attendance at the physical count where inventory is material (SA 501), or alternative procedures where attendance is impracticable; valuation at lower of cost and NRV; slow-moving stock; stock statements to the bank reconciled |
| Statutory compliance | GST, TDS / TCS, income tax provision, company law filings and registers, labour laws; tax audit figures agreed with the final statements |
| Completion | Journal entry review; subsequent events; going concern; final analytical review; uncorrected misstatements; representation letter; CARO report (where applicable) and audit report drafted; partner review |
Reviewing and closing the programme
- No blank rows. Every step is done, not relevant with a reason, or carried as an open point with an owner.
- Every "done" points somewhere. A W/P reference that leads to the evidence, not just a tick.
- Exceptions lead to action. An exception in a step becomes a client query, an adjustment or a misstatement on the SA 450 schedule.
- Partner review is visible. The reviewer's initials and date on the programme, and review notes cleared, show the direction, supervision and review that SA 220 makes the engagement partner responsible for, and that SA 300 asks you to plan.
- Carry it forward. At the end, note what to change next year — this becomes next year's planning memo.
Try SignReady: Every step with status, remarks and done by, printed in the file pack.
Start freeFrequently asked questions
Is a standard audit programme acceptable for a small audit?
Yes, if it is tailored. SA 300's application material says standard audit programmes or checklists may be used for smaller entities provided they are tailored to the circumstances of the engagement, including the auditor's risk assessments.
What is the difference between the audit strategy and the audit programme?
The overall audit strategy sets the scope, timing and direction of the audit. The audit plan (the programme) sets out the detailed procedures — the nature, timing and extent of the risk assessment and further audit procedures — that implement the strategy.
Should I delete steps that do not apply to the client?
Better to mark them "Not relevant" with a short reason. That shows the step was considered and lets a reviewer agree or disagree; a deleted step leaves no trace.
Which procedures must be in every audit programme?
Substantive procedures for each material class of transactions, account balance and disclosure, and procedures on the financial statement closing process (SA 330); journal entry testing, a review of estimates and of unusual transactions for management override (SA 240); and the completion procedures — subsequent events, going concern, written representations and evaluation of misstatements.
Who should sign off each step?
SA 230 requires the documentation to record who performed the work and the date it was completed, and who reviewed it, the date and the extent of the review. The programme is the simplest place to record both for each step.
Sources
- ICAI — SA 300 Planning an Audit of Financial Statements
- ICAI — SA 330 The Auditor's Responses to Assessed Risks
- ICAI — SA 240 The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements
- ICAI — SA 230 Audit Documentation
- ICAI — SA 320 Materiality in Planning and Performing an Audit
- ICAI — SA 505 External Confirmations
In SignReady, the work programme sits with the materiality, CY vs PY review, lead schedules and review points for the same client — and prints in the finalisation file pack. First 3 finalisations free.
Version history: 4 Oct 2026 — first published. 5 Oct 2026 — checked against the primary texts by an independent reviewer; wording made more precise and source links added.



