Industry News & Expert Tips

HKSRS 4400 (Revised): Building Clear Agreed-Upon Procedures Documentation

Practical audit procedures, evidence points, and documentation considerations for Hong Kong audit teams.

Practice Overview

HKSRS 4400agreed-upon proceduresengagement documentationfactual findingsassurance reportingworking papersreporting qualityHong Kong auditors

Last updated: 16 September 2026

An agreed-upon procedures engagement is not an audit or review: the practitioner performs procedures agreed with the engaging party and reports factual findings, without expressing an assurance conclusion. For Hong Kong practitioners, a well-structured file makes the agreed purpose, intended users, subject matter, procedure wording and reported findings readily traceable, reducing the risk that a report is misunderstood or that a reviewer cannot reconstruct what was actually done.

Documentation quality is established before fieldwork starts and protected through reporting and file completion. This article highlights common HKSRS 4400 (Revised) documentation and reporting pitfalls, then sets out practical procedures and evidence controls to help teams record the nature, timing and extent of work performed, support each finding with reliable evidence, and avoid missing statements or inaccurate references. It is general professional technical education, not engagement-specific audit, assurance or legal advice.

Key Audit Issues

Scope, purpose and users are not anchored in the file

A file can become difficult to defend when the intended purpose, intended users, subject matter and precisely agreed procedures are described inconsistently across correspondence, the engagement terms, working papers and report. Ambiguity may cause users to assume that work beyond the agreed procedures was performed or that assurance was provided.

Changes to agreed procedures are undocumented

Late changes to a population, date range, source report, sampling approach or procedure wording can change the meaning of the engagement. If the reason for the change, the parties’ agreement and the resulting effect on the work and report are not contemporaneously documented, the final file may not explain the engagement actually performed.

Procedure performance cannot be reperformed from the working papers

A checklist marked complete, without population details, item identifiers, source records, calculations, exceptions and the person and date of performance, does not demonstrate how a factual finding was reached. Copying management schedules without reconciling them to the agreed source or retaining a clear audit trail also weakens evidence.

Findings drift into conclusions, interpretation or recommendations

The report should communicate factual findings from the agreed procedures, not turn those findings into an audit opinion, review conclusion or implied assurance. Teams should take particular care with labels such as ‘compliant’, ‘adequate’ or ‘no issue noted’ unless those words are themselves the clearly agreed factual output of a specified procedure.

Report wording and standard references are treated as boilerplate

Reusing a prior report without a line-by-line tailoring review can leave obsolete references, missing engagement-specific statements, inconsistent subject-matter descriptions or an incorrect description of the practitioner’s responsibilities. High-level HKSRS 4400 (Revised) reporting concepts include a clear description of the agreed procedures and findings and an explicit statement that no assurance conclusion is expressed.

Tailored Audit Procedures

Confirm the agreed engagement terms before work begins

Obtain and retain the agreed terms that identify the purpose, intended users, subject matter, responsibilities, procedures and expected form of report. Read the terms against the request and key correspondence, and resolve wording that could be interpreted as requiring assurance or work outside the proposed procedures.

Build a procedure-to-evidence matrix

For every agreed procedure, prepare a working-paper step that states exactly what will be inspected, compared, recalculated, observed or otherwise performed; the relevant period or population; the source of information; and the factual finding to be reported. This reduces the risk that generic work is substituted for the procedure actually agreed.

Validate the population or source information used

Where a procedure uses a client-prepared listing, obtain a clear version of the listing and document its date, source, completeness checks or reconciliation steps that are included within the agreed procedures. Record population size, selection method and unique identifiers for selected items so another experienced practitioner can follow the work performed.

Perform and document each procedure as worded

Record the nature, timing and extent of work, link each test item to the supporting records, preserve recalculations and screenshots where relevant, and distinguish factual exceptions from explanations supplied by management. If evidence is unavailable or a procedure cannot be completed as agreed, document the circumstances promptly for appropriate consideration within the engagement terms and reporting process.

Control and document agreed changes

When circumstances require a change, pause to document the reason, revised wording, affected population or period, agreement by the appropriate parties and the consequential update to the work papers and draft report. Do not silently replace an agreed procedure with a different one merely because it is more convenient to perform.

Perform a report-to-file completion review

Trace every reported procedure and finding to the final signed terms and underlying working papers. Review the report for correct engagement-specific references, consistent dates and subject matter, appropriate description of the intended purpose and users, and clear wording that factual findings are reported without an assurance conclusion.

The procedures are illustrative. The engagement team should tailor the nature, timing, and extent of its work to the assessed risks, materiality, relevant reporting framework, and facts of the engagement.

Controls and Evidence to Consider

Approved terms and change-control record

Retain the final agreed engagement terms, relevant scope correspondence and a dated change log showing the reason for each change, the party agreeing it and updates made to procedures and reporting.

Indexed procedure work papers and source-evidence trail

Maintain a cross-referenced work-paper index that links each agreed procedure to the population, selected items, source documents, calculations, factual exceptions and preparer and reviewer sign-offs. Use stable identifiers and retain readable copies or secure links to the underlying evidence.

Tailored report cross-check and quality review

Use a completion checklist that traces the final report to the signed terms and confirms engagement-specific wording, procedures, factual findings, references and the absence of an assurance conclusion. Retain evidence of the preparer’s and reviewer’s completion of that check.

File integrity, retention and post-completion controls

Apply role-based access, version history, documented file-completion dates and an approval trail for any permitted post-completion change. These controls help preserve the integrity of the documentation and show what evidence was available when the report was issued.

Apply Technical Insight to Your Audit Workflow

EQC can discuss audit-quality priorities, documentation, inspection readiness, and Audit Program 4.1 (AP4.1) workflow support relevant to your practice.

Scroll to Top