Industry News & Expert Tips
HKSRS 4400 (Revised): Building Clear Agreed-Upon Procedures Documentation
Practical audit procedures, evidence points, and documentation considerations for Hong Kong audit teams.
Practice Overview
Last updated: 16 September 2026
An agreed-upon procedures engagement is not an audit or review: the practitioner performs procedures agreed with the engaging party and reports factual findings, without expressing an assurance conclusion. For Hong Kong practitioners, a well-structured file makes the agreed purpose, intended users, subject matter, procedure wording and reported findings readily traceable, reducing the risk that a report is misunderstood or that a reviewer cannot reconstruct what was actually done.
Documentation quality is established before fieldwork starts and protected through reporting and file completion. This article highlights common HKSRS 4400 (Revised) documentation and reporting pitfalls, then sets out practical procedures and evidence controls to help teams record the nature, timing and extent of work performed, support each finding with reliable evidence, and avoid missing statements or inaccurate references. It is general professional technical education, not engagement-specific audit, assurance or legal advice.
Key Audit Issues
Scope, purpose and users are not anchored in the file
A file can become difficult to defend when the intended purpose, intended users, subject matter and precisely agreed procedures are described inconsistently across correspondence, the engagement terms, working papers and report. Ambiguity may cause users to assume that work beyond the agreed procedures was performed or that assurance was provided.
Changes to agreed procedures are undocumented
Late changes to a population, date range, source report, sampling approach or procedure wording can change the meaning of the engagement. If the reason for the change, the parties’ agreement and the resulting effect on the work and report are not contemporaneously documented, the final file may not explain the engagement actually performed.
Procedure performance cannot be reperformed from the working papers
A checklist marked complete, without population details, item identifiers, source records, calculations, exceptions and the person and date of performance, does not demonstrate how a factual finding was reached. Copying management schedules without reconciling them to the agreed source or retaining a clear audit trail also weakens evidence.
Findings drift into conclusions, interpretation or recommendations
The report should communicate factual findings from the agreed procedures, not turn those findings into an audit opinion, review conclusion or implied assurance. Teams should take particular care with labels such as ‘compliant’, ‘adequate’ or ‘no issue noted’ unless those words are themselves the clearly agreed factual output of a specified procedure.
Report wording and standard references are treated as boilerplate
Reusing a prior report without a line-by-line tailoring review can leave obsolete references, missing engagement-specific statements, inconsistent subject-matter descriptions or an incorrect description of the practitioner’s responsibilities. High-level HKSRS 4400 (Revised) reporting concepts include a clear description of the agreed procedures and findings and an explicit statement that no assurance conclusion is expressed.
Tailored Audit Procedures
Confirm the agreed engagement terms before work begins
Obtain and retain the agreed terms that identify the purpose, intended users, subject matter, responsibilities, procedures and expected form of report. Read the terms against the request and key correspondence, and resolve wording that could be interpreted as requiring assurance or work outside the proposed procedures.
Build a procedure-to-evidence matrix
For every agreed procedure, prepare a working-paper step that states exactly what will be inspected, compared, recalculated, observed or otherwise performed; the relevant period or population; the source of information; and the factual finding to be reported. This reduces the risk that generic work is substituted for the procedure actually agreed.
Validate the population or source information used
Where a procedure uses a client-prepared listing, obtain a clear version of the listing and document its date, source, completeness checks or reconciliation steps that are included within the agreed procedures. Record population size, selection method and unique identifiers for selected items so another experienced practitioner can follow the work performed.
Perform and document each procedure as worded
Record the nature, timing and extent of work, link each test item to the supporting records, preserve recalculations and screenshots where relevant, and distinguish factual exceptions from explanations supplied by management. If evidence is unavailable or a procedure cannot be completed as agreed, document the circumstances promptly for appropriate consideration within the engagement terms and reporting process.
Control and document agreed changes
When circumstances require a change, pause to document the reason, revised wording, affected population or period, agreement by the appropriate parties and the consequential update to the work papers and draft report. Do not silently replace an agreed procedure with a different one merely because it is more convenient to perform.
Perform a report-to-file completion review
Trace every reported procedure and finding to the final signed terms and underlying working papers. Review the report for correct engagement-specific references, consistent dates and subject matter, appropriate description of the intended purpose and users, and clear wording that factual findings are reported without an assurance conclusion.
Controls and Evidence to Consider
Approved terms and change-control record
Retain the final agreed engagement terms, relevant scope correspondence and a dated change log showing the reason for each change, the party agreeing it and updates made to procedures and reporting.
Indexed procedure work papers and source-evidence trail
Maintain a cross-referenced work-paper index that links each agreed procedure to the population, selected items, source documents, calculations, factual exceptions and preparer and reviewer sign-offs. Use stable identifiers and retain readable copies or secure links to the underlying evidence.
Tailored report cross-check and quality review
Use a completion checklist that traces the final report to the signed terms and confirms engagement-specific wording, procedures, factual findings, references and the absence of an assurance conclusion. Retain evidence of the preparer’s and reviewer’s completion of that check.
File integrity, retention and post-completion controls
Apply role-based access, version history, documented file-completion dates and an approval trail for any permitted post-completion change. These controls help preserve the integrity of the documentation and show what evidence was available when the report was issued.
Related Reading
Apply Technical Insight to Your Audit Workflow
EQC can discuss audit-quality priorities, documentation, inspection readiness, and Audit Program 4.1 (AP4.1) workflow support relevant to your practice.