Language / Taal: This document is the English version. Lees in het Nederlands
This document describes the end-to-end process of a Dutch statutory financial statement audit (wettelijke controle / jaarrekeningcontrole) as governed by the NV COS (Nadere voorschriften controle- en overige standaarden). The NV COS are the Dutch-language adaptations of the international ISAs, mandatory for all registered Dutch accountants performing covered engagements. They are published as part of the HRA (Handboek Regelgeving Accountancy) by the NBA.
A statutory audit in the Netherlands may only be performed by a registered accountant (RA, Registeraccountant) affiliated with an accountantsorganisatie holding a Wta-vergunning (license under the Wet toezicht accountantsorganisaties). Oversight lies with the AFM (Autoriteit Financiële Markten) for OOB (organisaties van openbaar belang) audits and the NBA for non-OOB audits. The regulatory basis is the Wet toezicht accountantsorganisaties (Wta) and its implementing decree, the Besluit toezicht accountantsorganisaties (Bta).
A Dutch legal entity must have its annual accounts audited when it meets two of three size criteria in two consecutive years (BW2 Art. 2:397): balance sheet total ≥ €6 million, net turnover ≥ €12 million, or average number of employees ≥ 50. Entities below these thresholds (small and micro entities) are generally exempt, though some — listed entities, banks, insurers, pension funds, and certain publicly-funded organizations — face a statutory audit obligation regardless of size.
The most common engagement types in Dutch SME practice, in descending order of assurance:
| Engagement type | Standard | Assurance level | |---|---|---| | Controle (audit) | NV COS 200-series + 500-series | Reasonable (redelijke zekerheid) | | Beoordeling (review) | NV COS 2400N | Limited (beperkte zekerheid) | | Samenstelling (compilation) | NV COS 4410 | None expressed |
This document focuses on the controle (statutory audit).
Before any audit work begins, the accountant must assess whether to accept the engagement. NV COS 210 governs the agreement of engagement terms; NV COS 220 governs quality control at the engagement level.
Acceptance considerations include:
The agreed engagement terms are recorded in an opdrachtbevestiging (engagement letter) signed by both parties. This document specifies the scope, the applicable financial reporting framework (typically BW2 Titel 9 for Dutch entities), fees, and responsibilities.
Planning is not a discrete moment but a continuous process throughout the engagement. NV COS 300 requires the accountant to develop an overall audit strategy and a detailed audit plan before performing substantive procedures.
Risk assessment under NV COS 315 (Risico's op een afwijking van materieel belang identificeren en inschatten) is the cornerstone of the modern risk-based audit. The accountant must obtain a thorough understanding of:
This understanding drives the identification of risks of material misstatement (RMM) at both the financial statement level (pervasive risks) and the assertion level (specific risks for individual account balances or transaction classes). Significant risks — risks that require special audit consideration, almost always including fraud risks and the risk of management override of controls — must be identified explicitly (NV COS 315 §26).
In practice, the risk assessment for a Dutch SME audit involves:
The result is a documented risico-inschatting (risk assessment) covering all material financial statement areas.
NV COS 320 requires the accountant to set a materialiteitsdrempel (materiality threshold) for the financial statements as a whole, and if necessary performance materiality for specific account balances or transaction classes that, even if below overall materiality, could influence user decisions.
In Dutch SME practice, overall materiality is typically set at 5–8% of profit before tax, 1–2% of total assets, or 0.5–1% of revenue, depending on which metric best represents what financial statement users focus on. The choice must be documented with reasoning.
Performance materiality — always set below overall materiality — determines the threshold below which individual misstatements found during testing need not be accumulated for the final evaluation.
The auditor's responsibilities regarding fraud are governed by NV COS 240 (De verantwoordelijkheid van de accountant voor fraude bij de controle van financiële overzichten). NV COS 240 requires the accountant to:
NBA Handreiking 1153 (Frauderisicoanalyse, published March 2025) provides updated practical guidance on how to perform the fraud risk analysis. It structures the analysis around the classic fraud triangle: opportunity (gelegenheid), motive/pressure (motief/druk), and rationalization (rationalisering). The accountant must evaluate identified fraud risk factors against each vertex, then translate identified risk factors into specific, client-tailored fraud risks — not generic boilerplate statements.
The AFM (in its report "Scherper op frauderisico's!", June 2023, and its January 2025 follow-up) has found that Dutch auditors often assess fraud risks too generically. NBA Handreiking 1153 was issued in direct response. The practical implication is that a fraud risk assessment must name specific accounts, transactions, or behaviors that are at risk for this particular client — not simply state "there is a risk of management override."
Once the risk assessment is complete, the accountant designs and performs procedures that respond to the identified risks. NV COS 330 (Inspelen door de accountant op ingeschatte risico's) governs this.
If there are pervasive risks — risks affecting many assertions or the financial statements as a whole — the accountant responds at the financial statement level. Examples include assigning more experienced staff, greater supervision, introducing unpredictability in the nature/timing/extent of procedures, or modifying the approach to rely less on management-provided information.
For each significant account balance or transaction class, the accountant designs procedures that respond to the specific RMM at the assertion level. There are two main categories:
Toetsen van de werking van beheersingsmaatregelen (tests of controls): if the accountant intends to rely on internal controls to reduce substantive testing, they must test that those controls operate effectively. Tests of controls are particularly relevant for high-volume, automated transaction processing environments (ERP systems). If controls testing results are unsatisfactory, the accountant extends substantive procedures.
Gegevensgerichte werkzaamheden (substantive procedures): these gather evidence directly about the correctness of account balances and transaction classes. Substantive procedures split into:
NV COS 330 §18 requires that for each assessed significant risk, the accountant performs substantive procedures specifically designed to respond to that risk — relying solely on analytical procedures for significant risks is not acceptable when the risk is assessed as high.
When it is not practical to examine 100% of a population, the accountant may use audit sampling under NV COS 530. A sample must be designed so that each item has an equal chance of selection, and the results are projected to the population. SRA has developed a sampling model for Dutch SME audits. For fraud-risk areas, larger samples or 100% population testing via data analytics tools is preferable.
NV COS 500 defines controle-informatie (audit evidence) as all information used by the accountant to arrive at the conclusions on which the audit opinion is based. Evidence must be both voldoende (sufficient — adequate quantity to support the conclusion) and geschikt (appropriate — relevant and reliable).
Reliability of evidence varies by source: external evidence (e.g., bank confirmations) is more reliable than internally generated evidence; original documents are more reliable than copies; evidence obtained by the accountant directly is more reliable than evidence provided by management.
NV COS 505 governs externe bevestigingen (external confirmations) — letters sent directly to third parties (banks, debtors, lawyers) requesting confirmation of information relevant to the audit. Bank confirmations confirming account balances and outstanding facilities as of the balance sheet date are a standard procedure in virtually every Dutch statutory audit.
As the audit proceeds, the accountant accumulates all misstatements identified (other than clearly trivial ones, typically set at 5% of performance materiality). At the end of the audit, the accumulated misstatements are compared to the materiality threshold. If the total exceeds materiality, the accountant requests that management correct the financial statements, and if correction is not made, a modified opinion is required (NV COS 705).
NV COS 450 governs the evaluation of misstatements identified during the audit.
Before issuing the opinion, the accountant performs several closing procedures:
The accountant forms an opinion on whether the financial statements give a true and fair view (getrouw beeld) in accordance with the applicable reporting framework. The opinion is one of four types:
| Opinion type | NV COS | When issued | |---|---|---| | Goedkeurend (unmodified) | NV COS 700 | Financial statements present fairly in all material respects | | Met beperking (qualified) | NV COS 705 | Material misstatement limited to specific area, or scope limitation | | Oordeelonthouding (disclaimer) | NV COS 705 | Scope limitation so pervasive the accountant cannot form an opinion | | Afkeurend (adverse) | NV COS 705 | Material misstatement so pervasive the financial statements do not present fairly |
The opinion is communicated in the controleverklaring (auditor's report), which includes the audit opinion, key audit matters (kernpunten van de controle) for listed entities (NV COS 701), and — required since AFM/NBA regulation — a section describing the controleaanpak frauderisico's (fraud risk audit approach). The fraud section of the controleverklaring is governed by NV COS 700 and further elaborated in NBA Handreiking 1150.
NBA Handreiking 1150 (Rapporteren in de sectie 'Controleaanpak frauderisico's', October 2022) provides a step-by-step guide for completing the fraud section. The section must:
The handreiking defines several scenarios: standard reporting where the revenue recognition presumption applies; abbreviated reporting where that presumption is specifically rebutted; and reporting where fraud was actually identified or suspected during the audit.
NV COS 230 requires the accountant to document everything necessary to allow an experienced auditor, with no prior connection to the engagement, to understand the nature, timing, and extent of procedures performed; the results and evidence obtained; and the conclusions reached. All significant judgments must be documented.
The complete set of documentation is the controledossier (audit file or working papers). The controledossier may be electronic. In Dutch practice, SRA's Intern Reviewsysteem (Risk-Rhino platform) is commonly used to manage and review controledossiers. Bta Article 19 requires accountantsorganisaties to conduct an internal quality review of sampled engagement dossiers.
Since 1 January 2027 all Dutch accounting firms must comply with SKM1 (Standaard Kwaliteitsmanagement 1), which replaces the previous NVKM quality management rules. SKM1 shifts the emphasis from quality control (kwaliteitsbewaking) to quality management (kwaliteitsmanagement): firm leadership must be visibly and documentably "in control" of audit quality across the entire firm. Every audit tool and procedure that produces or processes evidence is part of the firm's SKM1 quality system.
The NBA's Taskforce Datagedreven Controle (updated February 2026) explicitly positions data analytics as an approved, standards-compliant approach to expanding and improving audit evidence gathering. NBA Handreiking 1141 (Data-analyse bij de controle, 2019, updated with a practical case study September 2024) defines the spectrum:
In both cases, the data analysis must fit within the NV COS framework: the evidence produced is controle-informatie under NV COS 500, the analytical procedures follow NV COS 520, and the accountant retains full professional responsibility for the conclusions. Per AFM's published guidance (November 2025): "De accountant blijft eindverantwoordelijk" — the accountant remains finally and non-delegably responsible — regardless of the sophistication of the tools used.
docs/sra-research.md); Dutch audit standards research (docs/research-dutch-audit-standards.md)
Reacties