ASA 600 Revised Group Audits in Australia: Component Auditors, Risk-Based Approach, and What Businesses Must Know in 2026
ASA 600 Revised transforms group audit requirements in Australia. Learn about component auditor obligations, risk-based planning, and choosing a group auditor.
For Australian businesses operating through group structures — parent companies with subsidiaries, trusts with multiple entities, or consolidated groups spanning multiple jurisdictions — the quality of the group audit is a critical governance matter. The revised Auditing Standard ASA 600, Audits of a Group Financial Report (Including the Work of Component Auditors), has fundamentally changed how group audits must be planned, executed, and documented in Australia. Understanding these changes is essential for boards, audit committees, and any business that relies on a consolidated financial report.
Understanding ASA 600 Revised and Group Audits
A group audit is an audit of a financial report that includes the financial information of more than one component — typically a parent entity and its subsidiaries, joint ventures, or associates. The complexity of group audits arises from the involvement of multiple entities, potentially across different jurisdictions, with different accounting systems, internal controls, and risk profiles.
The Australian Auditing and Assurance Standards Board (AUASB) issued the revised ASA 600 in May 2022, effective for reporting periods commencing on or after 15 December 2023. This means that for most Australian companies with a 30 June year-end, the revised standard has applied since the 2024-25 financial year and is now fully embedded in the 2025-26 audit cycle.
The revision aligns ASA 600 with the AUASB's updated suite of quality management standards — including ASQM 1 and ASA 220 — and with the risk-based approach mandated by ASA 315 (Revised 2019) and ASA 330. The result is a more rigorous, better-documented, and more transparent group audit process.
Key Changes Under ASA 600 Revised
The revised standard introduces several significant changes that affect how group audits are planned and performed:
Risk-Based Scoping of Components
Under the previous standard, auditors often used a mechanical approach to scoping components — for example, including all components above a certain size threshold. The revised ASA 600 requires a risk-based approach: the group engagement team must identify and assess the risks of material misstatement at the group level, and then determine which components require audit procedures based on those risks.
This means that a smaller component with unusual transactions or a high-risk operating environment may require more audit attention than a larger but lower-risk component. For businesses, this translates to a more targeted and potentially more efficient audit — but also one that may focus more intensely on specific entities within the group.
Enhanced Communication with Component Auditors
The revised standard places much greater emphasis on two-way communication between the group engagement team and component auditors. The group engagement partner must now actively direct, supervise, and review the work of component auditors — not simply rely on their reports.
Component auditors must be provided with clear instructions about the group audit strategy, the identified risks, and the specific procedures required. They must also communicate back to the group team about any significant matters arising from their work, including unexpected findings, changes in risk assessment, or difficulties encountered.
Professional Scepticism and Independence
The revised ASA 600 explicitly reinforces the requirement for professional scepticism throughout the group audit. The group engagement partner must maintain an independent and questioning mindset when evaluating the work of component auditors — particularly where those auditors are in different jurisdictions with different regulatory environments or professional standards.
Scalability for Smaller Groups
Recognising that group audits vary enormously in complexity, the revised standard is designed to be scalable. The requirements regarding component auditors only trigger when component auditors are actually engaged. For smaller, less complex groups where the group engagement team performs all the work directly, many of the component auditor-specific requirements do not apply.
What Businesses Must Know: Practical Implications
The revised ASA 600 has practical implications for businesses that go beyond the technical audit process:
- Increased documentation requirements — Expect your auditor to request more detailed documentation about group structure, intercompany transactions, and the controls operating at each component level
- More detailed audit planning discussions — The risk-based scoping process requires meaningful dialogue between the audit committee and the group engagement partner about where the significant risks lie within the group
- Potential changes to audit scope — Components that were previously subject to limited procedures may now receive more attention if they carry significant risks; conversely, low-risk components may receive less
- Connectivity between financial and sustainability reports — Where a business also prepares a sustainability report, the auditor must address the connectivity between the two reports, which may affect the scope of both engagements
- Longer audit timelines for complex groups — The enhanced communication and documentation requirements may extend the time required to complete group audits, particularly for groups with overseas components
Component Auditors: Roles, Responsibilities, and Selection
A component auditor is an auditor who performs work on the financial information of a component at the request of the group engagement team. In Australian group audits, component auditors may be from the same firm as the group auditor (a network firm) or from a completely different firm.
Under the revised ASA 600, the group engagement partner retains ultimate responsibility for the group audit opinion, regardless of how much work is performed by component auditors. This creates a clear accountability structure — but it also means that the group engagement partner must be satisfied that component auditors have the competence, capabilities, and independence required for the work assigned to them.
Evaluating Component Auditor Competence
When selecting or evaluating component auditors, the group engagement team must consider:
- Professional qualifications and registration — Component auditors must hold appropriate qualifications in their jurisdiction; in Australia, this means registration as a company auditor with ASIC where required
- Independence — Component auditors must be independent of the component entity and must not have relationships that could compromise their objectivity
- Understanding of applicable standards — Component auditors must understand and apply the auditing standards required by the group engagement team, which may differ from local standards
- Quality management systems — The group engagement team should consider whether the component auditor's firm has adequate quality management systems in place
Common Mistakes and Red Flags in Group Audits
Businesses and audit committees should be alert to the following warning signs that a group audit may not be meeting the revised ASA 600 requirements:
- Mechanical scoping without risk justification — If your auditor cannot explain why specific components were included or excluded from the audit scope based on risk, the scoping process may not be compliant
- Minimal communication with component auditors — A group audit where the engagement partner has had little direct contact with component auditors is a red flag for inadequate supervision
- Boilerplate audit instructions — Component auditors should receive tailored instructions reflecting the specific risks identified for their component, not generic templates
- Delayed identification of significant matters — Component auditors should be communicating significant findings to the group team in real time, not at the end of the engagement
- Inadequate documentation of professional scepticism — ASIC's audit quality reviews have consistently identified insufficient documentation of professional scepticism as a key deficiency in group audits
Australian Regulatory Context
Group audits in Australia operate within a comprehensive regulatory framework:
- AUASB — Issues and maintains Australian Auditing Standards, including ASA 600 Revised; provides implementation support including FAQs and fact sheets for practitioners
- ASIC — Registers company auditors and conducts audit quality reviews; ASIC's annual audit inspection program specifically examines compliance with group audit standards and has identified component auditor supervision as a recurring area of concern
- Corporations Act 2001 (Cth) — Mandates audit requirements for large proprietary companies, public companies, and registered schemes; ASA 600 Revised contains specific "Aus" paragraphs reflecting local Corporations Act requirements
- APES 110 — The Code of Ethics for Professional Accountants, administered by the Accounting Professional and Ethical Standards Board (APESB), governs independence and ethical obligations for both group and component auditors
- ASQM 1 — The Auditing Standard on Quality Management at the firm level, which underpins the quality management requirements that flow through to group audit engagements
ASIC's 2026-27 financial reporting and audit quality focus areas include group audit supervision and the adequacy of component auditor instructions — making this a live enforcement priority for the current audit cycle.
Questions to Ask When Choosing a Group Auditor
When selecting or reviewing your group auditor, consider asking the following questions to assess their capability and compliance with ASA 600 Revised:
- How do you determine which components require audit procedures, and can you walk us through your risk-based scoping methodology?
- Who are the component auditors for our overseas or interstate subsidiaries, and how do you evaluate their competence and independence?
- What instructions do you provide to component auditors, and how do you tailor those instructions to the specific risks at each component?
- How do you maintain two-way communication with component auditors throughout the engagement, and what triggers escalation to the group engagement partner?
- How does your firm's quality management system (under ASQM 1) apply to group audit engagements?
- Has your firm been subject to ASIC audit quality reviews, and what were the outcomes for group audit engagements?
- How do you address the connectivity between our financial report and sustainability report in the audit process?
How MyMoney® Can Help
Selecting the right auditor for a group structure is a critical governance decision. The revised ASA 600 has raised the bar for group audit quality, and not all audit firms have the resources, network, or expertise to meet these requirements for complex multi-entity groups.
MyMoney® connects Australian businesses with qualified, ASIC-registered auditors who have demonstrated expertise in group audits, component auditor supervision, and the full suite of AUASB standards. Whether you are a listed company, a large proprietary company, or a private group seeking assurance over your consolidated financial report, our marketplace helps you find the right professional.
Post a Brief to describe your group audit requirements and receive proposals from qualified auditors, or Browse Auditors on the MyMoney® Marketplace to find a specialist in group financial report audits.
This article provides general information only and does not constitute personal financial advice. Consider whether the information is appropriate for individual circumstances before acting on it. MyMoney® Marketplace is operated by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640).