The confirmation goes out on a Tuesday and comes back three weeks later, signed by somebody with an unknown job title. The senior reviewer carries on regardless, and the partner signs off. Nobody asks whether the fax number belongs to the bank.
This is not a hypothetical risk. It illustrates the control failures that ISA 505 is designed to address. It also highlights why technology is becoming an increasingly important part of the external confirmation process.
What ISA 505 actually asks of auditors
ISA 505 External Confirmations establishes requirements and guidance for auditors on the use of external confirmations as audit evidence. This standard deals with the auditor’s responsibilities regarding the determination of when confirmations should be used, the design of confirmation requests, control over confirmation requests, direct acquisition of replies, and the reliability of the replies obtained.
The underlying principle is straightforward: the auditor needs appropriate control over the confirmation process so that the response provides reliable evidence from the intended external source. That includes considering risks that a confirmation request could be intercepted, altered, redirected, or answered by an unintended party.
In the US, the parallel requirements include PCAOB AS 2310 and AU-C Section 505 under AICPA auditing standards. These frameworks are similar in principle, which is particularly relevant for firms auditing US subsidiaries of multinational organizations or multinational groups with US reporting requirements. Firms working across multiple frameworks therefore need a confirmation process that can support the applicable requirements in each jurisdiction.
Why external confirmations in audit work carry so much evidentiary value
Audit evidence is evaluated based on factors such as its relevance, reliability, source, and the circumstances in which it is obtained. Evidence obtained directly by the auditor from an independent external source can provide strong audit evidence, particularly when the auditor has appropriately controlled the confirmation process.
This is why external confirmations in an audit can be more valuable than relying solely on information provided by the client. A confirmation gives the auditor an opportunity to obtain information directly from an appropriate external party.
Some examples of external confirmations in auditing include:
- Bank balances, loans, and other banking relationships confirmed directly with banks
- Accounts receivable confirmations sent to customers, including positive or negative confirmations where appropriate
- Requests to external legal counsel concerning litigation, claims, and contingencies
- Inventory held by third parties, including warehouses and consignees
- Confirmation of contractual terms or side agreements that may affect revenue recognition
- Other information held by independent external parties that is relevant to the audit
All of these external confirmation procedures address a fundamental audit question: Was the information obtained independently from an appropriate external source, and did the auditor maintain sufficient control over the process used to obtain it?
Where paper confirmations quietly fail
Paper-based confirmation processes can introduce practical and control challenges.
First, postal and fax transmissions can take time, making late confirmations more difficult to manage as the reporting deadline approaches. Second, paper-based processes can make it harder to verify that a response came from the intended institution and respondent. Third, client involvement in addressing, routing, or transmitting confirmation requests can introduce risks to the auditor’s control over the confirmation process.
These challenges are not new. Historical accounting fraud cases have demonstrated how weaknesses in confirmation procedures can undermine otherwise persuasive-looking evidence. The lesson is not that confirmations are unreliable. It is that the reliability of a confirmation depends partly on how the request is controlled, transmitted, received, and evaluated.
That distinction becomes particularly important when auditors receive a response that appears genuine but have limited evidence demonstrating who actually responded, how the response was transmitted, or whether the request could have been intercepted or redirected.
What electronic audit confirmations change
Electronic audit confirmations can address many of the practical weaknesses associated with traditional paper workflows. Rather than simply replacing paper with email, a well-designed digital confirmation process can help strengthen the communication channel and provide additional evidence about how the confirmation was handled.
Depending on the platform and workflow, technology can help verify the responding party, timestamp communications, control access to the confirmation process, restrict inappropriate client involvement, and preserve an audit trail that can be reviewed as part of the engagement documentation.
The key benefit is not simply speed. It is greater visibility and control over the confirmation workflow.
When the auditor controls the request and transmission process, technology can help implement the control objectives underlying ISA 505. However, using an electronic platform does not by itself establish compliance. The auditor still needs to evaluate whether the process provides sufficient evidence that the request reached the intended recipient and that the response came from an appropriate source.
This distinction matters in international audits. An auditor based in the US sending confirmation requests to banks, customers, or other organizations in different countries may face challenges related to postal efficiency, response timing, differing business practices, and varying fraud risks.
A secure digital workflow can help standardize the process across jurisdictions, while the auditor remains responsible for applying the requirements of the relevant auditing standards and exercising professional judgment.
What CPAs should look for before adopting a platform
Not all electronic confirmation solutions provide the same level of control or documentation. Before adopting an audit confirmation software platform, CPAs should consider whether the technology supports the procedures and controls required by their applicable auditing standards.
Three questions are particularly important:
1. Does the system provide reasonable assurance that the response came from the intended external party?
A platform should do more than authenticate the login credentials of the person initiating a request. The auditor should consider how the system establishes the identity of the responding party and whether the response can reasonably be attributed to the intended external source.
2. Does it create a detailed and exportable audit trail?
The system should capture relevant events such as requests, transmissions, responses, timestamps, status changes, and other workflow activity. An exportable audit trail can make it easier for engagement teams to document their procedures and respond to questions from reviewers, regulators, or inspection teams.
3. Does it help prevent client interference with the confirmation process?
The platform should help prevent the client from changing, intercepting, redirecting, or otherwise manipulating the request or response. The objective is to support an auditor-controlled confirmation process rather than simply digitize a workflow that still leaves critical steps under client control.
If the answer to any of these questions is unclear, the system may solve a convenience problem without fully addressing the underlying evidentiary and control risks.
ISA 505 does not really revolve around paper or electronic confirmation. Rather, it deals with the auditor’s proper control over the confirmation process and the obtaining of credible evidence from the appropriate external source.
How technology helps with ISA 505 external confirmations
ISA 505 does not prescribe a particular technology or communication method. Its requirements can be implemented through paper-based, email-based, or digital confirmation processes, provided the auditor maintains appropriate control and obtains sufficient reliable evidence.
This is where technology in external audit confirmations can add value.
A digital platform can help auditors implement and document important controls associated with external confirmation procedures, including:
- Identity verification: helping establish that a response came from the intended external party
- Controlled routing: helping ensure confirmation requests are sent through an appropriate communication channel
- Auditor control: reducing opportunities for inappropriate client involvement in sending, receiving, or modifying confirmations
- Timestamping: recording when requests and responses move through the workflow
- Audit trails: preserving evidence of key events for engagement documentation and review
- Workflow management: giving audit teams visibility into outstanding, returned, and follow-up confirmations
- Centralized documentation: keeping confirmation-related records together for easier review
The platform does not replace the auditor’s judgment. Instead, it can make the auditor’s procedures more controlled, repeatable, and easier to document.
CPAs therefore face a question that goes beyond whether a confirmation was sent. They also need to consider how the request was sent, who controlled the process, how the response was received, and what evidence exists to demonstrate the process’s reliability.
The benefits of electronic audit confirmations go beyond speed
Turnaround time is the benefit most CPAs notice first. It is not necessarily the most important one.
The real benefits of electronic audit confirmations often appear in the parts of an engagement that consume significant audit team and partner time.
Faster response cycles: Confirmations that previously took weeks via postal workflows may now be returned much sooner through digital channels, depending on the responding organization’s processes.
Fewer lost requests: Digital workflows can reduce the risk of confirmations being misplaced, sent to outdated addresses, or delayed in mailrooms.
More efficient follow-up: Verified delivery, workflow status, and identity checks can help reduce avoidable non-responses and simplify follow-up work.
Lower risk of manipulation: Auditor-controlled workflows can reduce opportunities for a client to redirect, intercept, or manipulate a confirmation request or response.
Stronger documentation: Digital systems can capture timestamps, status information, communication records, and other workflow data, making it easier to document how the confirmation procedure was performed and support subsequent review.
For firms managing dozens or hundreds of confirmations during the busy season, these improvements can compound. The result is less time spent chasing paperwork and more time available to evaluate evidence and address exceptions.
Why the PCAOB updated its confirmation standard
A significant development in the US audit environment came with the PCAOB’s updated confirmation standard, AS 2310.
The updated standard reflects increased attention to the risks surrounding confirmation procedures, including the auditor’s evaluation of the reliability of confirmation responses and the procedures required when confirmations are not returned.
AS 2310 applies to audits of fiscal years ending on or after June 15, 2025, and establishes requirements for confirmation procedures regardless of whether confirmations are conducted through paper, electronic communication, or other methods.
The important point for firms adopting electronic confirmation audit processes is that the technology itself is not the determining factor. The auditor must still evaluate the reliability of the confirmation evidence and perform the procedures required by the applicable standard.
This is particularly relevant when a confirmation is received electronically. A digital response may arrive quickly and look authentic, but the auditor still needs to consider whether it came from the appropriate source and whether the confirmation process was sufficiently controlled.
For firms working across ISA 505 and PCAOB requirements, the practical lesson is similar: maintain appropriate control over the confirmation process, evaluate the reliability of responses, and document the procedures performed and conclusions reached.
Technology can support each of those activities, but it does not eliminate the auditor’s responsibility.
What a strong digital confirmation workflow looks like
A useful way to evaluate electronic confirmation audit procedures is to examine the complete workflow rather than focusing solely on the final response.
A strong workflow should help the auditor answer five questions:
1. Who initiated the confirmation?
The system should provide a clear record of the person or audit team that initiated the request.
2. Where was the confirmation sent?
The process should provide evidence of the intended recipient and communication channel.
3. Who responded?
The auditor should have information that supports the identity and appropriateness of the responding party.
4. What happened between the request and the response?
Relevant workflow activity, timestamps, status changes, and communication events should be recorded where appropriate.
5. Can the auditor demonstrate what happened later?
The resulting documentation should be accessible for engagement review and, where applicable, inspection or regulatory inquiry.
This is where audit confirmation software can move beyond simple digitization. The objective is not merely to send confirmations electronically. It is to create a controlled and documented confirmation workflow that supports the auditor’s procedures.
Choosing technology in external audit confirmations
When evaluating technology for external audit confirmations, firms should consider more than turnaround time and user experience.
Key questions include:
- Does the platform support an auditor-controlled confirmation process?
- How does it verify the identity of responding organizations?
- What information is captured in the audit trail?
- Can confirmation requests and responses be traced through the workflow?
- Can the client interfere with or redirect the process?
- How are exceptions and non-responses managed?
- Can records be exported or incorporated into the engagement file?
- Does the workflow support the firm’s quality management and documentation requirements?
- Can the system support confirmations across different jurisdictions and respondent types?
- Does the technology complement, rather than replace, auditor judgment?
These questions help firms distinguish between a platform designed primarily for convenience and one designed to strengthen the controls surrounding external confirmation procedures.
Conclusion
ISA 505 is not a technology standard. It does not require auditors to use a particular platform, communication channel, or confirmation system.
What it does require is an appropriately designed confirmation process in which the auditor maintains control, obtains reliable responses, and evaluates the evidence received.
Technology can make those objectives easier to implement and document.
Electronic audit confirmations can help auditors manage requests, verify responding parties, control communication workflows, record timestamps, track outstanding confirmations, and preserve an audit trail. For firms managing large confirmation populations or auditing across multiple jurisdictions, these capabilities can deliver significant efficiency gains while strengthening process visibility.
But the distinction is important: technology supports compliance; it does not automatically create compliance. The auditor remains responsible for determining whether the confirmation procedures performed are appropriate and whether the evidence obtained is sufficient and reliable under the applicable auditing standards.
AuditConfirm is built around these workflow principles: verified communication channels, auditor-controlled confirmation requests and responses, and a documented audit trail. For firms conducting audits under ISA 505, PCAOB AS 2310, or other applicable standards, these capabilities can help make confirmation procedures more controlled, efficient, and easier to document.
The future of external confirmations is therefore not simply a matter of paper versus digital.
It is about building a confirmation process in which the auditor can demonstrate not only what response was received, but also how that response was obtained, from whom it came, and how the process was controlled.
FAQs
ISA 505 is the international auditing standard that sets out requirements and guidance for auditors on using external confirmations as audit evidence. It addresses matters including the design of confirmation requests, auditor control over the confirmation process, obtaining responses, and evaluating the reliability of those responses.
An external confirmation audit procedure is a process in which the auditor seeks information directly from an independent external party to obtain audit evidence. Examples can include confirming bank balances with banks or receivable balances with customers.
Common examples of external confirmations in auditing include bank balance confirmations, accounts receivable confirmations, requests to external legal counsel regarding litigation and claims, confirmations of inventory held by third parties, and confirmations of contractual terms or other audit-relevant information.
A response obtained directly from an appropriate external source can provide evidence that is independent of information produced by the audit client. Its reliability still depends on the nature of the confirmation, the source, the auditor’s control over the process, and the procedures used to evaluate the response.
Electronic audit confirmations are external confirmation procedures conducted through digital communication channels or platforms rather than traditional paper-based methods. Depending on the technology used, electronic confirmation systems can provide identity verification, workflow controls, timestamps, status tracking, and an audit trail.
The benefits of electronic audit confirmations can include faster response cycles, improved workflow visibility, reduced administrative effort, stronger documentation, better tracking of outstanding requests, and controls that can help reduce the risk of interception, redirection, or manipulation.
No. Using electronic confirmation software does not, by itself, establish compliance with ISA 505. The auditor remains responsible for determining whether the confirmation process meets the applicable requirements, whether the response is reliable, and whether sufficient appropriate audit evidence has been obtained.
Auditors should consider whether the software supports an auditor-controlled confirmation process, provides reasonable assurance about the identity of respondents, maintains a detailed audit trail, restricts inappropriate client involvement, supports follow-up procedures, and provides documentation that can be reviewed as part of the engagement file.

