On 5 August 2026, the IAASB issued proposed revisions to ISA 330, ISA 500 and ISA 520. The proposals are not yet effective standards and remain open for comment until 15 December 2026. The important point for auditors is that this is not simply a technology update. The proposals change how Risk Assessment, audit procedures and audit evidence are expected to connect. The overall direction moves from a more procedure-driven audit toward a more genuinely risk- and evidence-driven audit.
The biggest change is in ISA 330. Under the existing ISA 330, paragraph 18 requires substantive procedures for each material class of transactions, account balance and disclosure regardless of the assessed risk. The proposed ISA 330 removes this blanket requirement. In other words, “material” would no longer automatically mean that a standard substantive procedure must always be performed. Instead, the auditor would design further audit procedures based on the assessed risk and the persuasiveness of evidence needed to address that risk.
This does not mean material accounts can simply be ignored. The important change is the logic behind the work. Under the existing approach, auditors may sometimes conclude: “The balance is material, therefore substantive testing is required.” Under the proposed approach, the stronger question becomes: “What is the assessed risk, and what evidence is necessary to address it?” In suitable circumstances, the proposals recognise that tests of controls may address a risk without substantive procedures automatically having to be added for that same risk.
Proposed ISA 330 also introduces a stronger stand-back evaluation after further audit procedures have been performed. Completing every audit-program step would no longer be the real end point. The auditor would step back and assess whether the evidence obtained from the overall response to the assessed risks is actually sufficient and appropriate. The mindset changes from “Did we complete the procedures?” to “Did the procedures collectively produce enough persuasive evidence?”
For ISA 500, the fundamental requirement to obtain sufficient appropriate audit evidence remains, but the framework for judging evidence becomes much clearer. The proposed standard places substantially greater emphasis on the intended purpose of the audit procedure, the relevance and reliability of information and professional skepticism. It also updates the framework for a digital environment while deliberately remaining technology-neutral.
The practical difference is important. Under the proposed approach, the auditor should be able to explain not merely what procedure was performed, but what that procedure was intended to prove. Analysing 100% of journal entries for unusual posting times may address that particular risk, but it does not automatically prove occurrence, accuracy, authorisation and cut-off. Similarly, analysing an entire extracted population does not provide strong evidence if the extraction itself is incomplete. The emphasis moves from quantity of testing toward persuasiveness of evidence for the specific audit purpose.
This principle applies equally to AI. An AI tool may review thousands of contracts or identify unusual transactions, but the output does not become persuasive audit evidence merely because advanced technology produced it. The auditor still needs to understand the information used, consider its reliability, investigate inconsistent information and determine whether significant results can be traced back to reliable underlying evidence.
For ISA 520, the existing principles of substantive analytical procedures remain, but the proposed standard makes their role more powerful and more disciplined. A significant proposed clarification is that, depending on the circumstances, a substantive analytical procedure may be the sole substantive procedure, just as a test of details may sometimes be the sole substantive procedure, provided sufficient appropriate audit evidence can be obtained.
This greater flexibility comes with a higher quality threshold. The auditor needs a plausible and predictable relationship between the information being analysed, a sufficiently precise expectation and an appropriate threshold for investigating differences. Analytical procedures intended to provide substantive evidence therefore need to go beyond broad year-on-year comparisons followed by a conclusion such as “variance appears reasonable.” The analytical model must actually be capable of detecting a material misstatement.
The changes can therefore be summarised quite simply. ISA 330 changes from “material balance = substantive procedures” toward “assessed risk = appropriate persuasive response.” ISA 500 changes from a relatively concise evidence standard toward a fuller framework asking what the procedure is intended to prove and whether the information is sufficiently relevant and reliable. ISA 520 strengthens substantive analytics and makes clearer that well-designed analytical procedures may, in appropriate circumstances, stand on their own.
For auditors, the most important impact is therefore not necessarily “more work.” Some mechanical requirements may actually decrease. What increases is the need to exercise and document professional judgment. Audit files will increasingly need to demonstrate a clear chain of Risk → Assertion → Audit Response → Purpose of Procedure → Reliability of Information → Evidence → Conclusion.
That is the core direction of the proposals. The future question will be less “Have we completed the audit program?” and more “Why did we perform this procedure, what risk did it address, and is the resulting evidence persuasive enough to support our conclusion?” As of August 2026 these changes remain proposals, so auditors should continue applying the current standards until final revised ISAs are issued and become effective.
เมื่อวันที่ 5 สิงหาคม 2569 IAASB ได้เสนอแก้ไข ISA 330, ISA 500 และ ISA 520 ครั้งสำคัญ โดยทั้งสามฉบับยังเป็น ร่างเพื่อรับฟังความคิดเห็นและยังไม่มีผลบังคับใช้ เปิดรับความคิดเห็นถึงวันที่ 15 ธันวาคม 2569 สิ่งสำคัญที่ผู้สอบบัญชีควรเข้าใจคือ การแก้ครั้งนี้ไม่ได้เป็นเพียงการเพิ่มเรื่องเทคโนโลยี แต่เป็นการปรับแนวคิดให้การประเมินความเสี่ยง วิธีตรวจ และหลักฐานการสอบบัญชีเชื่อมโยงกันมากขึ้น จากเดิมที่งานบางส่วนอาจขับเคลื่อนด้วยโปรแกรมตรวจ กำลังเปลี่ยนไปสู่การขับเคลื่อนด้วย ความเสี่ยงและคุณภาพของหลักฐาน มากขึ้น
จุดเปลี่ยนที่สำคัญที่สุดอยู่ใน ISA 330 ปัจจุบันย่อหน้า 18 กำหนดให้ผู้สอบบัญชีต้องทำวิธีตรวจสอบเนื้อหาสาระสำหรับรายการ ยอดคงเหลือ และการเปิดเผยข้อมูลที่มีสาระสำคัญทุกเรื่อง โดยไม่ขึ้นอยู่กับระดับความเสี่ยงที่ประเมินไว้ แต่ร่างใหม่เสนอ ตัดข้อกำหนดแบบเหมารวมนี้ออก หมายความว่า ในอนาคตคำว่า “มีสาระสำคัญ” เพียงอย่างเดียวอาจไม่ใช่เหตุผลที่จะต้องใส่วิธีตรวจสอบเนื้อหาสาระแบบมาตรฐานเสมอไป แต่ต้องกลับไปดูว่าความเสี่ยงคืออะไร และต้องใช้หลักฐานแบบใดจึงจะตอบความเสี่ยงนั้นได้อย่างเพียงพอ
ไม่ได้หมายความว่าบัญชีที่มีสาระสำคัญสามารถไม่ตรวจ แต่ เหตุผลในการเลือกวิธีตรวจเปลี่ยนไป จากเดิมที่อาจคิดว่า “ยอดมีสาระสำคัญ จึงต้องตรวจเชิงเนื้อหาสาระ” ร่างใหม่ผลักให้คิดว่า “ความเสี่ยงอยู่ตรงไหน และต้องใช้หลักฐานอะไรจึงจะตอบความเสี่ยงนั้นได้” ในบางสถานการณ์ หากระบบควบคุมมีประสิทธิผลและให้หลักฐานที่มีน้ำหนักเพียงพอ การทดสอบการควบคุมอาจตอบความเสี่ยงบางเรื่องได้โดยไม่จำเป็นต้องเพิ่มการตรวจเชิงเนื้อหาสาระสำหรับความเสี่ยงเดียวกันโดยอัตโนมัติ
ร่าง ISA 330 ยังเพิ่มความชัดเจนเรื่อง การถอยออกมามองภาพรวมหลังทำวิธีตรวจเพิ่มเติมเสร็จแล้ว กล่าวคือ งานไม่ควรจบเพียงเพราะโปรแกรมตรวจถูกทำครบทุกข้อ แต่ต้องกลับมาประเมินว่า เมื่อรวมหลักฐานทั้งหมดที่ได้จากการตอบสนองต่อความเสี่ยงแล้ว มีความเหมาะสมอย่างเพียงพอจริงหรือไม่ แนวคิดจึงเปลี่ยนจาก “ทำวิธีตรวจครบหรือยัง?” ไปเป็น “หลักฐานทั้งหมดที่ได้ดีและมากพอหรือยัง?”
สำหรับ ISA 500 หลักใหญ่เรื่องการต้องมีหลักฐานการสอบบัญชีที่เหมาะสมอย่างเพียงพอยังเหมือนเดิม แต่ร่างใหม่ทำกรอบการตัดสินคุณภาพของหลักฐานให้ชัดขึ้น โดยเน้นมากขึ้นเรื่อง วัตถุประสงค์ของวิธีตรวจ ความเกี่ยวข้อง ความน่าเชื่อถือของข้อมูล และความสงสัยเยี่ยงผู้ประกอบวิชาชีพ รวมทั้งทำให้มาตรฐานรองรับข้อมูลดิจิทัลได้ดีขึ้นโดยไม่ผูกกับเทคโนโลยีชนิดใดชนิดหนึ่ง
ความแตกต่างในทางปฏิบัติคือ ผู้สอบบัญชีต้องตอบให้ได้มากขึ้นว่า “วิธีตรวจนี้ทำเพื่อพิสูจน์อะไร?” เช่น การใช้การวิเคราะห์ข้อมูลตรวจรายการบัญชีทั้งหมดเพื่อค้นหารายการที่บันทึกในเวลาผิดปกติ อาจตอบความเสี่ยงเรื่องรายการผิดปกติได้ดี แต่ไม่ได้พิสูจน์พร้อมกันว่ารายการทั้งหมดเกิดขึ้นจริง ถูกต้อง ได้รับอนุมัติ และบันทึกถูกงวด หรือแม้จะตรวจข้อมูลครบทุกแถว แต่หากข้อมูลที่ดึงออกมาจากระบบไม่ครบ การตรวจทั้งหมดในไฟล์นั้นก็ยังไม่ใช่การตรวจประชากรจริงทั้งหมด จุดเน้นจึงเปลี่ยนจาก “ตรวจไปมากเท่าไร” เป็น “หลักฐานที่ได้มีน้ำหนักเพียงพอกับเรื่องที่ต้องการพิสูจน์หรือไม่”
หลักเดียวกันใช้กับ AI หาก AI อ่านสัญญาหลายพันฉบับหรือค้นหารายการผิดปกติได้ ผลจาก AI ไม่ได้กลายเป็นหลักฐานที่น่าเชื่อถือโดยอัตโนมัติ ผู้สอบบัญชียังต้องเข้าใจข้อมูลต้นทาง ประเมินความน่าเชื่อถือ ตรวจข้อมูลที่ขัดแย้ง และสามารถย้อนกลับไปยังหลักฐานจริงสำหรับประเด็นสำคัญได้ ร่าง ISA 500 จึงรองรับ AI และการวิเคราะห์ข้อมูล แต่ ไม่ได้ลดมาตรฐานของหลักฐานเพียงเพราะใช้เทคโนโลยี
สำหรับ ISA 520 หลักเดิมของการใช้วิธีการวิเคราะห์เชิงเนื้อหาสาระยังคงอยู่ แต่ร่างใหม่ทำให้บทบาทของวิธีวิเคราะห์ชัดและมีน้ำหนักมากขึ้น จุดสำคัญคือ ในบางสถานการณ์ วิธีวิเคราะห์เชิงเนื้อหาสาระสามารถเป็นวิธีตรวจเชิงเนื้อหาสาระเพียงวิธีเดียวได้ เช่นเดียวกับการตรวจรายละเอียด หากสามารถให้หลักฐานที่เหมาะสมอย่างเพียงพอ
แต่เมื่อเปิดให้ใช้วิธีวิเคราะห์ได้มากขึ้น คุณภาพของการวิเคราะห์ก็ต้องสูงขึ้นด้วย ผู้สอบบัญชีต้องมีความสัมพันธ์ของข้อมูลที่สมเหตุสมผลและสามารถคาดการณ์ได้ ต้องสร้างจำนวนที่คาดหมายด้วยความแม่นยำที่เหมาะสม และต้องกำหนดเกณฑ์ว่าความแตกต่างระดับใดต้องตรวจสอบต่อ ดังนั้น การเปรียบเทียบยอดปีนี้กับปีก่อนแล้วสรุปเพียงว่า “ส่วนต่างดูสมเหตุสมผล” จะไม่ใช่วิธีวิเคราะห์เชิงเนื้อหาสาระที่แข็งแรง หากไม่สามารถแสดงได้ว่าความคาดหมายนั้นละเอียดพอที่จะตรวจพบข้อผิดพลาดที่มีสาระสำคัญ
หากสรุปความแตกต่างให้จำง่ายที่สุด คือ ISA 330 เดิมมีลักษณะ “รายการมีสาระสำคัญ → ต้องมีการตรวจเชิงเนื้อหาสาระ” มากกว่า แต่ร่างใหม่ขยับไปเป็น “มีความเสี่ยง → เลือกวิธีตอบสนองที่ให้หลักฐานเพียงพอ”; ISA 500 เดิมวางหลักเรื่องหลักฐานค่อนข้างกว้าง แต่ร่างใหม่ถามชัดขึ้นว่าวิธีตรวจทำเพื่อพิสูจน์อะไร และข้อมูลน่าเชื่อถือเพียงพอหรือไม่; ISA 520 เดิมใช้วิธีวิเคราะห์เป็นหลักฐานเชิงเนื้อหาสาระได้อยู่แล้ว แต่ร่างใหม่ทำให้ชัดว่าหากออกแบบได้ดีพอ วิธีวิเคราะห์อาจยืนเป็นวิธีตรวจหลักได้ด้วยตัวเอง
ดังนั้น การแก้ครั้งนี้ไม่ได้แปลว่าผู้สอบบัญชีต้องทำงานมากขึ้นทุกเรื่อง ตรงกันข้าม งานที่เป็นลักษณะทำตามขั้นตอนแบบกลไกบางส่วนอาจลดลง แต่สิ่งที่เพิ่มขึ้นชัดเจนคือ วิจารณญาณของผู้สอบบัญชีและการอธิบายเหตุผลในกระดาษทำการ ทีมต้องเชื่อมให้เห็นว่า ความเสี่ยง → ข้อกล่าวอ้าง → วิธีตอบสนอง → วัตถุประสงค์ของวิธีตรวจ → ความน่าเชื่อถือของข้อมูล → หลักฐาน → ข้อสรุป ต่อกันอย่างไร
หัวใจของการเปลี่ยนแปลงจึงไม่ใช่คำถามว่า “โปรแกรมตรวจทำครบแล้วหรือยัง?” แต่คือ “ทำไมเราจึงเลือกวิธีตรวจนี้ วิธีนี้ตอบความเสี่ยงอะไร และหลักฐานที่ได้มีน้ำหนักเพียงพอที่จะรองรับข้อสรุปจริงหรือไม่?” นี่คือความแตกต่างสำคัญที่สุดที่ผู้สอบบัญชีควรเข้าใจจากร่าง ISA 330, ISA 500 และ ISA 520 ชุดใหม่ ทั้งนี้ ณ เดือนสิงหาคม 2569 ทั้งหมดยังเป็นเพียงข้อเสนอ ผู้สอบบัญชียังคงต้องใช้มาตรฐานฉบับปัจจุบันจนกว่ามาตรฐานฉบับสุดท้ายจะประกาศและมีผลบังคับใช้