Published by Shah Teelani & Associates | PCAOB-Registered Audit Firm | Reg. No. 7161


Audit evidence quality sits at the center of the most persistent deficiency pattern in PCAOB inspection history. Engagement teams filled files with documentation. Yet the audit opinions still lacked adequate support — because the evidence was insufficient, unreliable, or unresponsive to identified risks.

Audit teams documented extensive procedures, yet the audit opinions still lacked adequate support. The issue was rarely missing documentation. Instead, auditors relied heavily on information prepared or influenced by management. As a result, PCAOB AS 1105 is now one of the most cited standards in PCAOB inspection reports. AuditConfirm Blog

Furthermore, Part I.A of PCAOB inspection reports identifies deficiencies where the auditor did not obtain sufficient appropriate audit evidence to support its opinion on the company’s financial statements and internal control over financial reporting.

At Shah Teelani & Associates, we treat audit evidence quality as a non-negotiable standard on every engagement. This blog explains what PCAOB AS 1105 requires — and why quality always wins over quantity.


What AS 1105 Defines as Audit Evidence

Before engaging with the quality debate, every auditor must understand what audit evidence actually means under PCAOB standards.

Audit evidence is all the information, whether obtained from audit procedures or other sources, that the auditor uses in arriving at the conclusions on which the auditor’s opinion is based. Audit evidence consists of both information that supports and corroborates management’s assertions regarding the financial statements or internal control over financial reporting and information that contradicts such assertions.

Consequently, audit evidence is not limited to documents the auditor collects directly. Any source qualifies — provided the auditor has evaluated that source and its reliability. Moreover, evidence contradicting management’s position carries equal importance to evidence supporting it. An engagement file containing only corroborating evidence — with no consideration of contradictory information — fails the professional skepticism standard embedded in AS 1105.


The Two Dimensions: Sufficient and Appropriate

PCAOB AS 1105 frames the evidence standard around two distinct dimensions. Understanding both resolves the debate immediately.

Sufficient refers to the quantity of evidence obtained. Appropriateness refers to the quality and reliability of that evidence.

Sufficiency addresses how much evidence the auditor needs. Higher risk areas require more extensive evidence. Lower risk areas require less. Risk assessment conclusions therefore drive sufficiency determinations — not habit, templates, or prior-year file volume. An engagement that applies identical testing volume regardless of risk fails the sufficiency requirement in both directions.

Appropriateness addresses whether evidence is relevant and reliable. Relevant evidence relates to the specific assertion under test. Reliable evidence genuinely supports the conclusion drawn. Furthermore, appropriateness requires both — relevance without reliability, or reliability on the wrong assertion, fails AS 1105 regardless of volume.

Why Volume Without Quality Always Fails

Accumulating irrelevant or unreliable evidence creates an illusion of coverage. PCAOB inspectors evaluate whether evidence actually supports conclusions — not how much of it exists. Consequently, a thick file of management-prepared schedules and inquiry-only documentation fails AS 1105 regardless of apparent volume.


Relevance: Matching Evidence to the Right Assertion

Relevance connects evidence directly to the assertion the auditor tests. Different assertions require fundamentally different evidence. Testing existence asks whether a recorded asset actually exists. Testing completeness asks whether all transactions appear in the record. Valuation asks whether recorded amounts are appropriate.

Collecting existence evidence when completeness is the high-risk assertion produces documentation with zero relevance to the actual audit risk. Moreover, each procedure must therefore begin with a clear articulation of the specific assertion being addressed and the evidence type needed for that objective.


Reliability: The Spectrum That Inspectors Apply

Reliability is where the quality debate most visibly plays out in practice. Not all evidence carries equal weight, and PCAOB inspectors apply a consistent reliability spectrum in evaluating engagement files.

Evidence exists on a reliability spectrum. The higher the auditor’s control and independence, the more reliable the evidence. While PCAOB AS 1105 does not prescribe a formal hierarchy, in practice inspection findings consistently reflect this reliability spectrum based on source and auditor control.

Practically, the spectrum operates across four levels. Evidence the auditor generates independently — through recalculation, reperformance, or direct observation — carries the highest reliability. Evidence obtained directly from external third parties carries strong reliability because management did not influence it. Company-sourced internal documentation carries lower reliability. Management representations alone carry the lowest reliability of all.

Why Inquiry Alone Never Satisfies AS 1105

Inquiry of company personnel, by itself, does not provide sufficient audit evidence to reduce audit risk to an appropriately low level for a relevant assertion or to support a conclusion about the effectiveness of a control.

Asking management questions, receiving explanations, and documenting responses without independent corroboration is one of the most consistently cited failures in PCAOB inspections. Moreover, treating management’s variance explanation as a conclusion — rather than a starting point for further investigation — represents the same failure in a different form. Consequently, every significant conclusion requires evidence beyond what management communicated.


The New Electronic Evidence Standard: AS 1105.10A

Companies now provide auditors with enormous volumes of information in electronic form — data extracts, system-generated reports, cloud-based records, third-party confirmations via portal. Each type requires specific reliability evaluation under the amended AS 1105.

The PCAOB amended AS 1105, effective for audits of fiscal years beginning on or after December 15, 2025. Central to these amendments is AS 1105.10A, which introduces a principle-based, risk-scalable framework for evaluating the reliability of electronic information provided by the company. This is rapidly becoming a recurring area of focus by global audit regulators — particularly when the information supports significant risks, revenue, fraud procedures, or management estimates.

Paragraph .10A requires auditors to evaluate the reliability of company-provided external electronic information by obtaining an understanding of the source and of the company’s process for receiving, maintaining, and processing the information.

Applying AS 1105.10A in Practice

Receiving a data file from management is not the same as obtaining reliable evidence. Before relying on any company-provided electronic information, the auditor must answer four questions: Where did the data originate? How did the company receive, maintain, and process it? Did the company’s process create any opportunity for manipulation? Does the source itself carry sufficient independence and reliability?

Furthermore, the amendments are designed to decrease the likelihood that an auditor performing audit procedures using technology-assisted analysis will issue an auditor’s report without obtaining sufficient appropriate audit evidence that provides a reasonable basis for the opinion. Running analytics across entire transaction populations does not automatically produce sufficient appropriate evidence. Output quality depends entirely on input data reliability. Consequently, auditors must evaluate underlying data reliability before drawing any conclusion from technology-assisted analysis.


The Six Types of Audit Procedures and Their Evidence Strength

AS 1105 recognizes six types of audit procedures. Each produces evidence of different strength depending on the assertion it addresses.

Inspection involves examining documents such as invoices, contracts, bank statements, and ledger entries. AS 1105 recognizes documentary evidence — particularly from external or reliable sources — as more persuasive than purely internal evidence. Documents the auditor obtains directly from external sources carry stronger reliability than those management provides.

Observation involves watching a process or procedure being performed. Direct observation produces reliable evidence about what occurred at the moment of observation. However, it provides no assurance about consistency when the auditor is not present. Therefore, observation requires supplementation for assertions about sustained control operation over a full period.

Inquiry generates information but never standalone evidence for significant assertions. Combined with other procedures, it helps auditors understand context and evaluate management’s explanations. Alone, it fails AS 1105 for any relevant assertion.

Confirmation involves obtaining written responses directly from third parties. External confirmations are particularly important in responding to fraud risks or high-risk balances, as encouraged by AS 2301. Consequently, confirmation is one of the highest-reliability evidence types available for balance-level assertions.

Recalculation checks mathematical accuracy using procedures the auditor performs independently — producing high-reliability evidence for precision-based assertions.

Reperformance involves independently executing procedures originally performed by company personnel. Like recalculation, it produces independent evidence and carries strong reliability for control effectiveness testing.


Evidence Must Be Proportionate to Risk

The nature, timing, and extent of audit procedures must respond directly to assessed risks. High-risk areas require more extensive procedures and higher-reliability evidence. Lower-risk areas permit less extensive procedures — provided the overall evidence package remains sufficient.

AS 2301 links risk assessment to audit procedures. The nature, timing, and extent of procedures must be designed to obtain reliable evidence that responds directly to assessed risks. Weak evidence in high-risk areas is a common PCAOB inspection finding.

Moreover, when auditors use sampling, AS 2315 requires that the selected items provide a reasonable basis for conclusions. Even a properly designed sample fails AS 1105 if the underlying evidence within the sample lacks reliability.

Applying identical evidence approaches to high-risk and low-risk areas equally demonstrates template-driven auditing — not risk-responsive professional judgment. Consequently, the connection between risk assessment and evidence design must run through every procedure in the audit plan.


Common Evidence Failures PCAOB Inspectors Identify

Understanding where evidence quality breaks down helps engagement teams build consistently strong processes. Recurring failures include:

Each of these failures produces a large, densely populated audit file that still fails to support the audit opinion. Moreover, each represents a pattern PCAOB inspectors specifically look for when reviewing engagement workpapers.


What Sufficient Appropriate Evidence Looks Like

Bringing both dimensions together, sufficient appropriate audit evidence has three defining characteristics. First, it is relevant — it addresses the specific assertion being tested, not a related but different one. Second, it is reliable — obtained from a source the auditor evaluated and determined to be trustworthy. Third, it scales to risk — the volume and nature of evidence obtained reflects the risk level the auditor assessed during planning.

Additionally, the documentation surrounding the evidence must show the auditor’s analysis — not just what was collected. Evidence in a workpaper without commentary explaining what it means and why it supports the conclusion fails AS 1215, even where the underlying evidence is strong.


What Issuers and Finance Teams Should Know

Audit evidence quality affects issuers directly. Finance teams that provide well-organized, independently verifiable supporting information enable auditors to obtain higher-quality evidence more efficiently. Consequently, the organization and completeness of issuer-provided documentation shapes the quality of evidence auditors can build conclusions on.

Supporting schedules that clearly trace to source documents, third-party documentation made available directly to auditors, system-generated reports with source validation, and proactively disclosed accounting judgment bases all strengthen audit evidence quality. Furthermore, strong issuer preparation reduces the risk that auditors compensate for evidence gaps with lower-reliability substitutes that create inspection exposure.


The Bottom Line

Audit evidence quality defeats quantity every time. A small set of relevant, reliable, independently obtained evidence supports an audit opinion. A large set of management inquiry responses, unverified schedules, and undocumented analysis does not — regardless of volume.

In 2026, with AS 1105.10A requiring explicit reliability evaluation of electronic evidence and PCAOB inspection findings continuing to trace Part I.A deficiencies to insufficient appropriate evidence, every registered firm must treat evidence quality as the primary standard — and let quantity follow from it.

Shah Teelani & Associates (PCAOB Reg. No. 7161) designs every audit procedure to obtain sufficient appropriate evidence responsive to identified risks. We work with US-listed and OTC public companies that understand what a genuinely supportable audit opinion requires.

If your organization requires a PCAOB-registered auditor who takes evidence quality seriously, we welcome the conversation.


Shah Teelani & Associates PCAOB-Registered Audit Firm | Reg. No. 7161 Ahmedabad | Dubai | United States

Leave a Reply

Your email address will not be published. Required fields are marked *