Athena — kb/audit-process-overview.md

Dutch Financial Statement Audit — Process Overview

Language / Taal: This document is the English version. Lees in het Nederlands

This document describes the end-to-end process of a Dutch statutory financial statement audit (wettelijke controle / jaarrekeningcontrole) as governed by the NV COS (Nadere voorschriften controle- en overige standaarden). The NV COS are the Dutch-language adaptations of the international ISAs, mandatory for all registered Dutch accountants performing covered engagements. They are published as part of the HRA (Handboek Regelgeving Accountancy) by the NBA.


1. Legal and Professional Framework

Who may perform a statutory audit

A statutory audit in the Netherlands may only be performed by a registered accountant (RA, Registeraccountant) affiliated with an accountantsorganisatie holding a Wta-vergunning (license under the Wet toezicht accountantsorganisaties). Oversight lies with the AFM (Autoriteit Financiële Markten) for OOB (organisaties van openbaar belang) audits and the NBA for non-OOB audits. The regulatory basis is the Wet toezicht accountantsorganisaties (Wta) and its implementing decree, the Besluit toezicht accountantsorganisaties (Bta).

When a statutory audit is required

A Dutch legal entity must have its annual accounts audited when it meets two of three size criteria in two consecutive years (BW2 Art. 2:397): balance sheet total ≥ €6 million, net turnover ≥ €12 million, or average number of employees ≥ 50. Entities below these thresholds (small and micro entities) are generally exempt, though some — listed entities, banks, insurers, pension funds, and certain publicly-funded organizations — face a statutory audit obligation regardless of size.

The most common engagement types in Dutch SME practice, in descending order of assurance:

| Engagement type | Standard | Assurance level | |---|---|---| | Controle (audit) | NV COS 200-series + 500-series | Reasonable (redelijke zekerheid) | | Beoordeling (review) | NV COS 2400N | Limited (beperkte zekerheid) | | Samenstelling (compilation) | NV COS 4410 | None expressed |

This document focuses on the controle (statutory audit).


2. Phase 1 — Engagement Acceptance and Continuance

Before any audit work begins, the accountant must assess whether to accept the engagement. NV COS 210 governs the agreement of engagement terms; NV COS 220 governs quality control at the engagement level.

Acceptance considerations include:

  • Client integrity: assessing whether management and those charged with governance can be trusted. If significant integrity concerns exist, the accountant should decline.
  • Competence: whether the firm has the skills, time, and resources to perform the engagement properly.
  • Independence: compliance with the ViO (Verordening inzake de onafhankelijkheid van accountants bij assurance-opdrachten).
  • Predecessor auditor communication: if this is not the first year, the incoming auditor contacts the outgoing one to understand any matters they should be aware of.

The agreed engagement terms are recorded in an opdrachtbevestiging (engagement letter) signed by both parties. This document specifies the scope, the applicable financial reporting framework (typically BW2 Titel 9 for Dutch entities), fees, and responsibilities.


3. Phase 2 — Planning

Planning is not a discrete moment but a continuous process throughout the engagement. NV COS 300 requires the accountant to develop an overall audit strategy and a detailed audit plan before performing substantive procedures.

3.1 Understanding the entity — NV COS 315

Risk assessment under NV COS 315 (Risico's op een afwijking van materieel belang identificeren en inschatten) is the cornerstone of the modern risk-based audit. The accountant must obtain a thorough understanding of:

  • The entity and its environment (industry, regulatory framework, business model, strategy)
  • The applicable financial reporting framework and accounting policies
  • The entity's system of internal control: the control environment, the entity's risk assessment process, information systems and communication, control activities, and monitoring of controls
  • The IT environment, including general IT controls and IT applications that process financially significant transactions

This understanding drives the identification of risks of material misstatement (RMM) at both the financial statement level (pervasive risks) and the assertion level (specific risks for individual account balances or transaction classes). Significant risks — risks that require special audit consideration, almost always including fraud risks and the risk of management override of controls — must be identified explicitly (NV COS 315 §26).

In practice, the risk assessment for a Dutch SME audit involves:

  • Reading the prior year's audit file and controleverklaring
  • Reviewing the entity's internal and external reporting
  • Performing analytical procedures on preliminary financial data
  • Inquiring of management, internal audit (if any), and others in the organization
  • Inspecting key documents and observing operations

The result is a documented risico-inschatting (risk assessment) covering all material financial statement areas.

3.2 Materiality — NV COS 320

NV COS 320 requires the accountant to set a materialiteitsdrempel (materiality threshold) for the financial statements as a whole, and if necessary performance materiality for specific account balances or transaction classes that, even if below overall materiality, could influence user decisions.

In Dutch SME practice, overall materiality is typically set at 5–8% of profit before tax, 1–2% of total assets, or 0.5–1% of revenue, depending on which metric best represents what financial statement users focus on. The choice must be documented with reasoning.

Performance materiality — always set below overall materiality — determines the threshold below which individual misstatements found during testing need not be accumulated for the final evaluation.

3.3 Fraud risk assessment — NV COS 240 and NBA Handreiking 1153

The auditor's responsibilities regarding fraud are governed by NV COS 240 (De verantwoordelijkheid van de accountant voor fraude bij de controle van financiële overzichten). NV COS 240 requires the accountant to:

  1. Maintain professioneel-kritische instelling (professional skepticism) throughout — treating fraud as a real possibility, not merely a theoretical one.
  2. Identify and assess fraud risks by inquiring of management, those charged with governance, and other employees; performing analytical procedures; and considering fraud risk factors.
  3. Presume that there are always two inherent fraud risks present in every audit unless they can be specifically rebutted: (a) the risk of management override of internal controls (NV COS 240 §31), and (b) the risk of fraudulent financial reporting through revenue recognition (NV COS 240 §26).

NBA Handreiking 1153 (Frauderisicoanalyse, published March 2025) provides updated practical guidance on how to perform the fraud risk analysis. It structures the analysis around the classic fraud triangle: opportunity (gelegenheid), motive/pressure (motief/druk), and rationalization (rationalisering). The accountant must evaluate identified fraud risk factors against each vertex, then translate identified risk factors into specific, client-tailored fraud risks — not generic boilerplate statements.

The AFM (in its report "Scherper op frauderisico's!", June 2023, and its January 2025 follow-up) has found that Dutch auditors often assess fraud risks too generically. NBA Handreiking 1153 was issued in direct response. The practical implication is that a fraud risk assessment must name specific accounts, transactions, or behaviors that are at risk for this particular client — not simply state "there is a risk of management override."


4. Phase 3 — Risk Response

Once the risk assessment is complete, the accountant designs and performs procedures that respond to the identified risks. NV COS 330 (Inspelen door de accountant op ingeschatte risico's) governs this.

4.1 Overall responses to financial-statement-level risks

If there are pervasive risks — risks affecting many assertions or the financial statements as a whole — the accountant responds at the financial statement level. Examples include assigning more experienced staff, greater supervision, introducing unpredictability in the nature/timing/extent of procedures, or modifying the approach to rely less on management-provided information.

4.2 Assertion-level procedures

For each significant account balance or transaction class, the accountant designs procedures that respond to the specific RMM at the assertion level. There are two main categories:

Toetsen van de werking van beheersingsmaatregelen (tests of controls): if the accountant intends to rely on internal controls to reduce substantive testing, they must test that those controls operate effectively. Tests of controls are particularly relevant for high-volume, automated transaction processing environments (ERP systems). If controls testing results are unsatisfactory, the accountant extends substantive procedures.

Gegevensgerichte werkzaamheden (substantive procedures): these gather evidence directly about the correctness of account balances and transaction classes. Substantive procedures split into:

  • Cijferanalyses (analytical procedures) — governed by NV COS 520. These involve comparing recorded amounts to expected amounts derived from relationships among financial and non-financial data. At the risk-response stage, analytical procedures must produce an expectation that is precise enough to detect a material misstatement.
  • Detailcontroles (tests of detail) — examination of individual transactions, account balances, or supporting documents. These include vouching (tracing from records back to source documents), tracing (following source documents forward into records), recalculation, and external confirmations.

NV COS 330 §18 requires that for each assessed significant risk, the accountant performs substantive procedures specifically designed to respond to that risk — relying solely on analytical procedures for significant risks is not acceptable when the risk is assessed as high.

4.3 Sampling — NV COS 530

When it is not practical to examine 100% of a population, the accountant may use audit sampling under NV COS 530. A sample must be designed so that each item has an equal chance of selection, and the results are projected to the population. SRA has developed a sampling model for Dutch SME audits. For fraud-risk areas, larger samples or 100% population testing via data analytics tools is preferable.


5. Phase 4 — Evidence Gathering and Evaluation

5.1 What constitutes audit evidence — NV COS 500

NV COS 500 defines controle-informatie (audit evidence) as all information used by the accountant to arrive at the conclusions on which the audit opinion is based. Evidence must be both voldoende (sufficient — adequate quantity to support the conclusion) and geschikt (appropriate — relevant and reliable).

Reliability of evidence varies by source: external evidence (e.g., bank confirmations) is more reliable than internally generated evidence; original documents are more reliable than copies; evidence obtained by the accountant directly is more reliable than evidence provided by management.

NV COS 505 governs externe bevestigingen (external confirmations) — letters sent directly to third parties (banks, debtors, lawyers) requesting confirmation of information relevant to the audit. Bank confirmations confirming account balances and outstanding facilities as of the balance sheet date are a standard procedure in virtually every Dutch statutory audit.

5.2 Evaluating misstatements found

As the audit proceeds, the accountant accumulates all misstatements identified (other than clearly trivial ones, typically set at 5% of performance materiality). At the end of the audit, the accumulated misstatements are compared to the materiality threshold. If the total exceeds materiality, the accountant requests that management correct the financial statements, and if correction is not made, a modified opinion is required (NV COS 705).

NV COS 450 governs the evaluation of misstatements identified during the audit.


6. Phase 5 — Closing and Reporting

6.1 Completion procedures

Before issuing the opinion, the accountant performs several closing procedures:

  • Written representations from management (NV COS 580) — management provides written confirmation of the accuracy of representations made during the audit.
  • Events after the reporting period (NV COS 560) — procedures to identify events between the balance sheet date and the date of the auditor's report that may require adjustment or disclosure.
  • Going concern assessment (NV COS 570) — evaluating whether there are material uncertainties about the entity's ability to continue as a going concern.
  • Related party review (NV COS 550) — identifying transactions with related parties that require specific disclosure under BW2.

6.2 Forming the opinion — NV COS 700

The accountant forms an opinion on whether the financial statements give a true and fair view (getrouw beeld) in accordance with the applicable reporting framework. The opinion is one of four types:

| Opinion type | NV COS | When issued | |---|---|---| | Goedkeurend (unmodified) | NV COS 700 | Financial statements present fairly in all material respects | | Met beperking (qualified) | NV COS 705 | Material misstatement limited to specific area, or scope limitation | | Oordeelonthouding (disclaimer) | NV COS 705 | Scope limitation so pervasive the accountant cannot form an opinion | | Afkeurend (adverse) | NV COS 705 | Material misstatement so pervasive the financial statements do not present fairly |

The opinion is communicated in the controleverklaring (auditor's report), which includes the audit opinion, key audit matters (kernpunten van de controle) for listed entities (NV COS 701), and — required since AFM/NBA regulation — a section describing the controleaanpak frauderisico's (fraud risk audit approach). The fraud section of the controleverklaring is governed by NV COS 700 and further elaborated in NBA Handreiking 1150.

6.3 Fraud reporting in the controleverklaring — NBA Handreiking 1150

NBA Handreiking 1150 (Rapporteren in de sectie 'Controleaanpak frauderisico's', October 2022) provides a step-by-step guide for completing the fraud section. The section must:

  • Describe the specific fraud risks identified for this client (not generic text)
  • Explain the audit procedures performed in response
  • Note findings and outcomes, which is "highly desirable though not mandatory" per the handreiking

The handreiking defines several scenarios: standard reporting where the revenue recognition presumption applies; abbreviated reporting where that presumption is specifically rebutted; and reporting where fraud was actually identified or suspected during the audit.


7. Documentation and Quality Requirements

7.1 Audit documentation — NV COS 230

NV COS 230 requires the accountant to document everything necessary to allow an experienced auditor, with no prior connection to the engagement, to understand the nature, timing, and extent of procedures performed; the results and evidence obtained; and the conclusions reached. All significant judgments must be documented.

The complete set of documentation is the controledossier (audit file or working papers). The controledossier may be electronic. In Dutch practice, SRA's Intern Reviewsysteem (Risk-Rhino platform) is commonly used to manage and review controledossiers. Bta Article 19 requires accountantsorganisaties to conduct an internal quality review of sampled engagement dossiers.

7.2 Quality management — SKM1

Since 1 January 2027 all Dutch accounting firms must comply with SKM1 (Standaard Kwaliteitsmanagement 1), which replaces the previous NVKM quality management rules. SKM1 shifts the emphasis from quality control (kwaliteitsbewaking) to quality management (kwaliteitsmanagement): firm leadership must be visibly and documentably "in control" of audit quality across the entire firm. Every audit tool and procedure that produces or processes evidence is part of the firm's SKM1 quality system.


8. Data-Driven Audit

The NBA's Taskforce Datagedreven Controle (updated February 2026) explicitly positions data analytics as an approved, standards-compliant approach to expanding and improving audit evidence gathering. NBA Handreiking 1141 (Data-analyse bij de controle, 2019, updated with a practical case study September 2024) defines the spectrum:

  • "Doing things differently": using data tools to perform existing audit procedures more efficiently — for example, testing 100% of a journal entry population instead of a sample.
  • "Doing different things": redesigning audit procedures around data analytics — for example, replacing a detailed accounts-payable walkthrough with a comprehensive analytical model over all payment transactions.

In both cases, the data analysis must fit within the NV COS framework: the evidence produced is controle-informatie under NV COS 500, the analytical procedures follow NV COS 520, and the accountant retains full professional responsibility for the conclusions. Per AFM's published guidance (November 2025): "De accountant blijft eindverantwoordelijk" — the accountant remains finally and non-delegably responsible — regardless of the sophistication of the tools used.


Sources

  • NV COS 200, 210, 220, 230, 240, 300, 315, 320, 330, 450, 500, 505, 520, 530, 550, 560, 570, 580, 700, 701, 705 (HRA / NBA)
  • NBA Handreiking 1141 (Data-analyse bij de controle, 2019/2024)
  • NBA Handreiking 1150 (Rapporteren fraude in controleverklaring, October 2022)
  • NBA Handreiking 1153 (Frauderisicoanalyse, March 2025)
  • NBA Taskforce Datagedreven Controle (updated February 2026)
  • NBA Leidraad 2: AI Toegepast (June 2026)
  • Wet toezicht accountantsorganisaties (Wta); Besluit toezicht accountantsorganisaties (Bta)
  • BW2 Art. 2:393 (audit obligation size criteria) and Titel 9 (annual accounts)
  • SRA research (docs/sra-research.md); Dutch audit standards research (docs/research-dutch-audit-standards.md)

Reacties

Nog geen reacties