Chapters
1. Intro to Assurance
2. Rules and regulations
3. Corporate governance
4. Ethics and acceptance
5. Internal controls
6. Specific controls
1- Intro to Assurance
Assurance engagements
Definition- an engagement in which a practitioner gains sufficient evidence on a subject matter
to compare against criteria in order to give a conclusion with the intention to improve the
confidence of the party using the information rather than the party responsible for it.
5 Elements- CPSEW- criteria, 3 parties, subject, evidence, written report
Limited vs reasonable assurance- A reasonable assurance involves collecting higher quality
evidence through thorough testing in order to provide a more confident conclusion that the
information conforms/doesn’t against criteria and the report is worded more positively. The
objectives of a limited and reasonable assurance are different, one sets out to achieve a
plausible conclusion while the other aims to sufficiently test the subject matter against criteria
External Audit
Purpose- this is an example of a reasonable assurance engagement which intends to enhance
confidence of shareholders in the FS. It is done by providing opinions on 2 aspects, whether or
not the FS are true and fair and are they prepared in all material aspects against a relevant
reporting framework (this framework is different in places but assumed to be the IFRS here).
Objective of auditor- to obtain reasonable assurance on whether or not the FS are free from
material misstatements, express an opinion on whether or not the FS are complying to the
framework, report on the FS while complying to ISAs.
Need- some countries have laws requiring the publishing of FS along with a required external
audit for quoted and large companies while other companies might want to get one for benefits.
Expectation gap- auditors do not test all transactions, only a sample. They do not investigate all
fraud in FS preparation, only assure there aren’t material misstatements (could be caused by
fraud). So, auditors do not provide absolute assurance.
Review engagement- a limited assurance engagement where tests of control are not performed
on FS, instead only enquiries on management and analytical procedures are used. This is less
disruptive than an audit but provides an indicator for how well FS are conforming to IFRS.
The need for an audit or FS in general is required due to the separation of control. The directors
are the agents and the stewards and have a fiduciary responsibility towards the shareholders-
the principal.
An audit increases usefulness of FS for all stakeholders involved.
An unmodified opinion is the most favorable kind of report which indicates that the FS are true
and fair in all material respects and prepared according to the framework.
2- Rules and Regulations
Legal requirements of auditors and audit
Need for regulation- to increase trust and credibility in auditors, standard setters and regulators
aim to harmonize the auditing process, adhere to an ethical code and focus on audit quality.
Examples of regulations are national corporate law, international audit standards and the code
of ethics.
Who needs an audit- Large quoted companies require an audit in most countries while smaller
owner managed companies are exempt since material misstatements in these don’t affect the
wider economy by much and they don’t benefit from audit services.
Who can audit- to be eligible you need to either be authorized by the state or be a member of a
recognized supervisory body like the ACCA (and allowed by that body). It is possible for both
individuals and firms to audit if they meet these criteria.
Who can’t audit- Law in countries can prohibit people with incentives tied to a firm from
auditing them and the code of ethics can do this too based on competence, incentive,
confidentiality etc.
Who appoints auditors- At the AGM, shareholders will vote for an auditor. However, if they fail
to do so, the directors can appoint an auditor with the approval of the shareholders. If neither
the shareholders nor the directors appoint an auditor, then the secretary of state can appoint
one for them.
Removal of auditor- An auditor can be removed by member votes in a meeting, but there are
safeguards to prevent instant removal. Notice periods are in place, allowing the auditor time to
address any concerns raised and the company to cope. After the meeting, a statement of
circumstances must be sent by the auditor to both the company and the regulatory bodies
(ACCA in our case).
Auditor rights- access to books and records, answers to questions relating to audit, notification
of AGMs or written resolutions along with participation in the meetings. Upon resignation they
can request a meeting and also have the company be responsible for the sharing of the
statement of circumstances.
Auditor duties- primary duty is to audit the FS and tell whether or not they give a true and fair
view, but other duties may be imposed by law. On resignation they may also be required to
cooperate with the new auditors
International regulation
IFAC- main international body of accountants ensuring the profession is regulated
internationally
IAASB- responsible for producing and promoting ISAs and quality management standards
ISAs- professional regulations that guide the planning, performance and reporting of audits for
FS (can also apply to other historical financial records). These will lay out principles and
requirements with explanations for auditors that must be followed unless specific exemptions
exist like national legal requirements.
National regulators- in the UK the FRC is responsible for overseeing the accounting profession
including RSBs like the ACCA. It’s auditing division doesn’t just take up ISAs but instead modifies
them for UK use, they also have their own ethics code, their own auditing standards and
monitor the audit reports in the UK.
Role of professional bodies- like the ACCA is to not only provide high quality education and
training for members and auditing companies but also to regulate them ethically (for instance
through quality reviews) to ensure they are complying with standards and quality is high. The
government also receives advice from bodies like these.
3- Corporate governance
The corporate governance code
Good corporate governance- CG is how a company is controlled and operated and the goal with
good governance is to ensure that the interests of shareholders, employees and other
stakeholders are being considered by management.
Relevance to auditors- good CG will mean better internal and external controls including
financial controls. This means lower chances of material misstatements and therefore less effort
required from auditors. Audit committees will also be crucial in ensuring good communication
and independence for the external auditors. Auditors also have responsibilities with regards to
CG.
UK code- is similar to the OECD’s CG principles and promotes best practice for large quoted
companies through a comply or explain approach (listing rules require explanations for
deviations from the code). There are 5 parts to the code:
1- Board leadership and company purpose
Principles- The board should lay out the purpose, values and strategy and have the directors
lead the culture by example. They should make sure every stakeholder has a voice- especially
the workforce with their policies being in line with values, they should promote long run
shareholder wealth maximization and ensure that the company always has resources.
Major provisions- the board should: explain future risks and what is being done in the annual
report, monitor and ensure compliance with culture throughout the business, meet with major
shareholders to understand views, understand views of stakeholders and discuss them in
meetings, should allow whistleblowing, act against conflict of interest, note down director
problems with the board that aren’t resolved along with hearing out NEDs upon retirement.
Board roles- The board is made up of EDs, NEDs and a chairman. They may hold their own board
meetings or general meetings where they meet with members (shareholders) who can cast vote
on decisions like auditor change.
o Chair- leads the BODs in meetings in terms of setting agendas and ensuring effective
communication including voices of every stakeholder like auditors being heard.
Monitors sub committees. Must be non-executive and independent
o CEO and EDs- ensure operations of the company
o NEDs- not involved in the day-to-day activities, rather bring independence and
expertise by being a part of sub committees and showing up in important meetings to
strategize with and supervise the ED.
2- Division of responsibilities
Principles- The chair should lead the board and is responsible for everyone’s equal participation.
The board should have enough resources and its composition should be equal
Main provisions- the chair should be independent upon assigning and not be the CEO.
NEDs need to make up half of the board, elect a senior designated NED, meet once yearly to
assess the chair’s performance, assess EDs performance against objectives and reappoint them.
Independence tests are to be run for NEDs and reported in the annual report.
3- Composition, success and evaluation
Principles- The board needs to have a formal succession plan and evaluation must be made
annually to determine whether or not the board is skilled, experienced, diverse and unbiased.
Main provisions- in order to achieve this a nomination committee is made. This is mostly NEDs
and will evaluate and re-appoint both EDs and NEDs at least once annually. NEDs and the chair
are to be appointed through open advertising or external consulting. Chair can’t be a part of the
NC
4- Audit, risk and internal control
Principles- the board should create policies to make internal and external auditors independent
and effective. They should present a fair and balanced view of the co position. They should
monitor internal controls and create procedures to manage risk.
Audit committee- Should be formed made up of only NEDs (at least 2 members) and one of
them has to be skilled in finances while the rest competent in their industry. Chairman can’t be a
part
Committee role- monitoring and giving advice in the preparation of: FS, financial controls and
risk management, internal audit (if none exists must explain why) and external audit. They
should report on these functions in the annual report.
Board role in risk- board should do an annual robust assessment of risk and opportunities,
explaining these in the annual report along with information on whether or not they are a going
concern.
Benefits of AC- improves public confidence in FS and the audit by providing a monitor (listing
requires an AC), expertise can benefit other directors and the external auditors get an
independent communication channel.
Internal audit- the AC has to monitor the internal audit, communicate with them and ensure
independence and communication lines with the chair. They are also to monitor how well
management is responding to internal audit recommendations.
Risk committee- to monitor and plan against risks a committee can be created with mostly NEDs
which will advise management. Risks can be reduced by paying their cost, insurance and
effective controls. Directors are responsible for risk management and controls; auditors will only
test internal controls for financial reporting that cause material misstatement and then report
these to those charged with governance (isa 265).
5- Remuneration
Principles- pay for the board should encourage goal congruence, no director should be able to
select their own pay.
Main provisions- the committee should only have NEDs and at least 3 members, the chair can
be a part of it but not a lead. They will create a policy and set remuneration for the whole board
and senior management, but NED fees will be determined by the board and cannot be
performance based. Contracts should be annual.
Committee Min members NED comp CEO Chair
nomination - mostly yes Not allowed
remuneration 3 all no Yes but cant lead
audit 2 but 1 exp in fin all no no
risk - mostly - -
4- Ethics and acceptance
Ethics are guidelines and professional ethics suggest behavior for a particular profession
Auditors should be neutral- both in intention and perception
IFAC’s IESBA produces ethical guidelines which are adopted by bodies across the world
Fundamental ethical principles- Integrity- honesty and straightforward, objective- no conflict of
interest, professional competence and due care- continuous development and no negligence,
professional behavior, confidentiality
confidentiality exceptions- if you are required by law or professional body to disclose such
information, if you need to disclose such information to protect your firm’s interests in a legal
setting and finally if the client is involved in illegal activities these MUST be reported
Ethical threats- compromise an auditor’s independency and objectivity and safeguards will
minimize the threat of these to an acceptable level. These safeguards are to be discussed with
audit committee.
1-Self-interest threat- like owning shares might result in the auditor not giving a modified
opinion since he wants the share price to stay high.
Examples: too high/low fees or ones that depend on something, previous unpaid fees, If
the new client fees > 15% of total revenue of a firm (only from plc not pvt) then this is
not allowed and should be discussed with audit committee if more than 2 years have
been charged consecutively. This cool off period also refers to partners
Safeguards: sell the shares, replace member. Fees should be fixed at market rates
through the AEL audit engagement letter. Should not have any credit.
2- Self review threat- if employee of client company and now is auditing it. (2 year cool off
period). Providing non audit services does the same.
Safeguards- discuss with audit committee, Chinese wall where there are 2 different
audit engagement partners, members are different and the partners have a
confidentiality agreement with an EQCR engagement quality control reviewer that does
a hot review (before report issuance) and a cold review. This EQCR must be an
independent partner that is unfamiliar with the company.
3- Familiarity threat- having a relative that can affect FS, taking gifts, continuous same client
audit, a firm member becomes a company employee
Safeguards- replace member, reject gifts or hospitality if they are material, max 7 years
of audit same co (2 year cool off period with partner change required but it can be
extended to 2 more years max if desperate with new 5 year cool off), don't take old
friend in team and change methods
4- Intimidation threat- Not paying unpaid fees, blackmailing individual members or previous
misconducts.
Safeguards- discuss with audit committee, stand ground, resigning from the audit team
is the last step
5- Advocacy threat- Supporting in share issuance, legal cases or marketing. The safeguard
against this is to not support the client in matters unless called up by courts
Advertising- the work of audit firms should be ethical- no degrading others, exaggerating,
specifying time, use ethical channels. ACCA allows its logo use if 50% partners are ACCA
members with 51% profit sharing
Conflicts of interest between auditor and client- if auditor is the shareholder/partner/any
stakeholder of a direct competitor of the client there is a conflict of interest. Info could be
misused. To prevent this, you replace the person or discuss with the audit committee
2 competing clients being audited- by the same firm. Again, there is a threat of misuse of
information. To safeguard this, you have to notify the clients and ask their consent, advise them
to get legal advice and get some yourself, use the Chinese wall
Tendering process- When searching for an auditor a tender is released which is signed and sent
back by firms. Then management and the audit committee will review these. this content is
evaluated and presented as auditor profiles to shareholders in the AGM. Upon selection, before
accepting the audit the auditor mustq consider factors and pre-conditions and then send an
AEL- audit engagement letter
contents- in each firms tender form- name of firm, partners, experience, locality, legal
jurisdiction, audit method, fees, quality standards and other services offered.
Factors before accepting- ensure IESBA compliance, check for conflicts of interest and
ethical threats, if present then set safeguards to reduce risk to acceptable level.
contact previous auditor through the client for a clearance letter detailing whether or
not you should accept the audit. If these guys say no or are not allowed to share info
then don't take the audit. If they never respond, remind them and mention you will take
the audit if they don't respond by a fixed date.
ensure legal restrictions to the firm, resources are enough and how much fees to ask,
screen client's BOD and activities
Pre-conditions (ISA 210)- Ensure client is using the right framework and you can audit this,
ensure client takes responsibility for financial statement preparation and their necessary
controls. client should acknowledge they will give unrestricted access to info required
Audit engagement letter- written contractual agreement between the auditor and the client. it
should have the scope of audit (FS), objective of audit (opinion), level of assurance (reasonable),
basis of fees, details of each side’s responsibilities, clause saying management will provide
written representation to auditor at the end.
Quality standards (ISA 220)- partners in a firm are responsible for the quality control, staff
should only be hired if they are knowledgeable and experienced, their training and supervision
is to be ensured by the firm, ethical threat safeguards must be in place, company should seek
independent legal/professional advice with issues in audit, quality control partners need to be
present and used
Hierarchy- Trainee- senior- supervisor (ensures quality standards)- manager (manages audit)-
audit partner (gives opinion)
5- Internal Controls
Internal controls- are tested by the auditor (TOC) since they have an effect on FS. Controls are a system
that is designed and operated by the management or those charged with governance.
ISA 315- deals with controls and as an auditor we first need to understand the control system of the
client before testing it. It has 5 components
5 components- control environment, entity’s risk assessment, info system of FR, control activities and
monitoring of controls- (AIMER)
1- control environment- the overall culture surrounding controls. Managements attitude,
commitment and seriousness about internal controls sets the tone for the rest of the company
and effects all elements of controls.
the elements of control environment include- the structure if the organization, attitude to risk,
HR policies, management styles, ethical value enforcement
2- risk assessment process- how management identifies, assesses and manages its risk to financial
reporting. Some may not deem risk significant and leave gaps
3- info system relevant to FR- could be IT or manual and refers to how they initiate, record,
process and report transactions and events regarding our assets, equities and liabilities. Auditors
should understand info systems like Tps, mis, eis, es
4- control activities- these are policies and procedures which ensure that the directives of
management are carried out without fraud, error and try to ensure these are corrected if they
exist. They can be IT or manual based.
Examples- duty segregation, confidential info restricted access, CCTV, approval from seniors
required, performance reviews, internal audit.
5- monitoring- involves checking how effective controls are in achieving their purpose and taking
actions to remedy ineffective internal controls (internal auditors help with this but management
is held responsible)
Controls are divided- into specific and common controls. The former applies to a specific department
and are more relevant to exam case studies and common controls apply to the whole company
specific controls- include the bank, inventory, purchase, nca, sales and payroll system. These
departments have their own control systems and all have an impact on FS.
Why have common controls? To reduce fraud and errors, to prevent misuse of assets and info, to
minimize misstatements in FS, to achieve objectives in time with solid info
Common control activities can be summarized with SPAMSOAP
-Segregation of duties. Physical controls like locks and passwords. Authorization of transactions and
events. Management control oversees every department via analytics like budgets, variances and
internal audit. Supervision of day-to-day activities. Organization chart which identifies authority and
responsibilities and should be in a manual. Arithmetic controls like the trial balances, control accounts
and reconciliations to ensure no mathematical errors. Personnel controls include training, performance
reviewing, disciplining and hiring.
other common controls- backups, recovery IT, proper dates, categorized documents, signatures
limitations to controls- are anything that delay your objective achievement or prevent it. Examples
include collusion from staff, management not following it, controls may have errors in their operations,
expensive, non-routine activities are not benefited, must be updated regularly
6- Specific controls
Cash and bank system
Reasons for controls: maintain complete and accurate records of cash and bank, ensure the bank
statement reconciles and prevent misuse of cash or theft
good petty cash system:
nature of expenses is to be defined and limited to required amount. Excess cash to be banked
Duties should be separated- payment, approval and accounting.
Supervision should be done with restricted access (fixtures).
Payments received should be documented with receipt copies stamped and kept. Expenses
reimbursed should have detailed vouchers kept that have things like name, department,
amount, number transposition etc.
Sequential pre-numbering is essential
Good bank system: Cheque book access restricted, large amounts should have multiple signatures,
passwords for online systems, bank statements are to be reviewed regularly and reconciliation
statements prepared (arithmetic control)
Question Tips:
when answering questions that ask for deficiencies and recommendations, we are to provide a
negative along with why it's bad then suggesting something along with why it's good.
Weaknesses can also just be deficiencies
another tip for answering questions is to assume if something isn't told that it doesn't exist and
state the obvious solutions
Inventory system
Inventory control- is relevant to auditors since this will reflect how accurately and reliably inventory is
being reflected in the FS. To maintain accurate records, reduce chances of theft/fraud, reduce waste and
holding/stockout costs
Warehouse- should be in good condition, appropriate temperature, surveillance, fire alarms
Inventory records- bin card is a document for recording material, it is labelled with location/quantity
and quality. Store ledger records movement of inventory with monetary values. Inventory master file
records all material information like cost, selling price, date of purchase, frequency of usage
Inventory levels- reorder levels are to be based on lead time and usage and EOQ must be ordered.
Minimum inventory levels are a buffer amount and are based on highest amount of usage in lowest lead
time.
Inventory counting- periodic/perpetual counting is to be maintained. A count can be done at downtimes
with a counter and a recounter independent of inventory maintenance should do the count without
knowing the recorded amount in advance and having been given full guidance. counting sheets are to be
sequentially numbered, areas counted flagged, units sold not included in the count, and counters should
sign.
Computerized controls
General controls- overall controls on the whole digital system of the company that also protect
indirectly FR information. Examples include login passwords, restricted access, training, anti-viruses etc.
Application IT controls- controls over the financial reporting information application process. These
include input, process and output controls which ensure that complete and accurate accounting
information is recorded.
Input controls- ensure data entered into the system is complete and accurate, examples include format,
range, sequence and existence checks along with digit verification and a direct comparison of entered
data with source documents- one for one checking.
Process controls- ensures that data input is processed by the software correctly, these include systems
that notify that processing is complete or warn when an error occurs or you have not processed
information completely.
Output controls- these ensure that only the relevant and authorized people are the ones that are able
to view the processed information and others are restricted from it
Purchase Controls
Division- there is the procurement department which will order goods, the store department which
receives the goods and the accounts department which pays the suppliers. Each will have their own
controls.
Ordering goods- Only BOD approved suppliers to be used, quotations are to be obtained, evaluate and
choose the best based on the purchase mix- includes quantity, quality, discounts, lead time. Send a
purchase order (PO) to the supplier and a copy to the store department (sequentially numbered to
ensure completeness)
Receiving goods- the store department should check against the PO for quality, send a GRN to the
ordering dept and create a record.
Paying suppliers- the PO, invoice and the GRN are to be verified by the accounts dept before they
authorize a crossed check in the supplier’s name
Reasons for control- to ensure that complete and accurate purchases and payables records are kept, to
prevent fraud/collusion, to ensure quality and quantity through double verification and achieve the best
purchase in efficiency.
Sales and dispatch system
Sales- when accepting an old customer’s orders, you need to look at their payment history and limits
and give credit in line with your policy. With new customers you need to check their references,
reputation and credit worthiness. After selling you need to obtain written documentation- PO. You
should also do reconciliation statements with customers and also suppliers
Dispatch- production should be within deadlines and when delivering the responsible manager should
be in place to ensure against the PO that the right goods are being sent. A goods delivery note should be
sent (this needs to be signed and sent back by the client) along with gate passes.
Why have controls- to ensure complete and accurate records of sales and receivables, that the correct
goods are being delivered at the right times and only credit worthy customers are given credit.
Performing TOC
CAIRO- these are procedures used by auditors to test things like controls, detail and analytical
procedures. TOC will only use the last 3
tests- design/existence of controls along with their operations/effectiveness
Exam focus- in the exam you may have to test for design of controls or you may be given controls and
be asked to test their effectiveness. In both cases you have to suggest a procedure CAIRO and then
secondly explain what the purpose of the procedure was.
CAATs- computerized assisted audit techniques are any software or applications used by the auditor to
do either substantive testing through “audit software” or tests of controls through “data testing”. Data
testing involves using dummy data to test controls and looking at past trails of data.
NCA/capital expenditure
Good controls- these are similar to purchasing controls and include having a NCA register, requiring
approval from BOD and high-level management for purchases, surveying markets before purchases and
having security and surveillance measures.
Reasons for- other than maintaining complete and accurate records you want to minimize extra
expenditures and ensure no misuse of NCAs is taking place.
Exam focus- when asked to find controls auditors can rely on you have to identify what seem like good
controls and explain why they are good. Then if asked to test for these controls you have to prepare
procedures and what their purpose is:
Payroll system
Attendance- every employee should have an id card and a computerized attendance system should be
in place with supervision of its usage, ID cards issued are to be compared to HR number of employees to
ensure that there is no fraud/error.
Data entry- attendance should be integrated with the payroll software, data on joiners and leavers is to
be updated regularly with authorization, timesheet calculation and pay are to be separated as duties,
second person should review all payments and tax deductions, payroll department should confirm with
other department heads, pay slips with gross wages and deductions is to be produced.
Staff payment- cash payments must be done with multiple people present and checking of id,
automated bank transfers for salaries are to be reviewed before by a responsible manager.
Clerks- only responsible for entering data and recording, they should not have access to standing data
(confidential info) and should not be able to update payroll software
Reasons for controls- to ensure complete and accurate records of staff wages, prevent ghost employees
fraud and errors
Significant deficiencies for controls- anything that can lead to fraud, material misstatements in the
financial statements, which can cause further deficiencies in controls, subjective estimates being made
by non-experts.
Directors are only to authorize not manage and review, refer to roles. Manager should review payroll.
This director manager cross can be used in many control systems where the manager makes a review
while the director authorizes it upon a second review.
Controls documentation
Auditors must maintain records of control systems a client has and should update this yearly, there are 4
methods
Narrative notes- written descriptions of control systems and stages after discussions from management.
These are thorough and easy to understand but may be a burden to read if extensive.
Flow chart- arrows and small diagrams which are easy to view quickly and understand but can be hard
to amend and lack descriptions
Questionnaires- pre determined questions can categorize whether or not controls exist and if so, how
effective they are. Anyone can ask these and these can be used on other clients, but specialized clients
can't be dealt with
Check list- preparing a list of controls and then ticking them off through sheer observations. Is easy and
standardized but misses out on communication.
Approach to controls- first understand the control system, then document them, then you perform
TOC, write a report to management regarding control deficiencies and recommendations
Management letter- and has a space for Management's response, a copy of Management's response is
to be kept by the auditor
6- Internal Audit
Creation- Internal audit is established by the BOD and acts as the company's agent. Their goal is to
review the other departments and in effect be a management control. Any employee can be in the IA
Requirements- IA must be independent, have no ethical threats or conflicts of interest
Objectives-
Review controls and FS, distinct from preparation- that is managements role.
Check for value added with decisions (like buying a new machine)- best value audit
Perform VFM for every department- economy, efficiency, effectiveness
review whether operations are running as intended- operational audit
compliance audit- are rules and regulations being followed
undertake investigations like fraud, IT audit, purchase audit, customer relation audit, business
risk suggestions.
IA role- is a form of an internal control, good corporate governance, independent internally, should
report to the BOD through the audit committee
Need for IA- history of frauds and breaches of controls, expansion or major change in the business
structure, unusual situations and crises
IA fraud- they are to identify the fraud, quantify it, explain how it was done and who did it. Reports are
given to the audit committee and then they report to the BOD.
ISA 610- refers to the EA using the work of the IA. As part of the TOC, the work of the IA department is
reviewed through discussions with IA staff, reviewing their work and their report.
Direct assistance- a responsibility to be provided by the IA to the EA by giving them necessary
information on their workings.
Before relying on IA- ISA 610 suggests factors are to be considered- independence, competence- both
qualifications and experience, reporting structure, professionality, if outsourced then check reputation
too. The better the strength of IA, the better controls are and so less substantive testing is required.
Advantages- improves the control environment, external parties deem the company to be more
credible, independence in reviews is brought in, BOD can get neutral advice, external auditors can rely
on their work and reduce audit procedures and fees
Disadvantages- no real requirement to be an accounting professional, there may be collusion with staff,
BOD may restrict the IA department to certain areas and not consider advice.
6- FS Assertions
Financial statement assertions- through the FS, management are making explicit/implicit statements
and claims about financial performance and these are then used by auditors as the basis of their audit,
they will try to substantiate these claims and figure out material misstatements.
Types of assertions- ACCA COVER P
C- Completeness- all FS are asserted to be complete in recorded figures and notes
A- Accurate- accuracy, valuation and allocation are linked. For instance, appropriate allocation
of 20 depreciation will result in an adjustment to the book value
C- cut off- assertion that the accruals concept has been followed and all the transactions have
been recorded in the right period
O- Occurrence- asserts all the transactions have already taken place
V- Valuation- refers to asset, liability and equity values and the assertion here is that they have
all been recorded at their appropriate year end values (NBV, NRV, FV, Par)
E- Existence
R- Rights and obligations- rights on assets and obligations on liabilities are asserted
P- Presentation- the layout and structure of FS is appropriate
Relevance to FS- all these assertions are not relevant to both FS, the left side are account balances and
refer to the SOFP while the right side are transactions referring to the SOCI.
ISA 500- audit evidence
Audit evidence- information gathered by auditors after applying appropriate audit procedures on FS.
Evidence should be sufficient and appropriate
Audit procedures- CAIRO
Sufficiency- evidence is sufficient if quantity is high and this level will depend on how experienced the
auditor is, how material the item being inspected is, how much risk of estimation the item has, what
sample size is being taken, how reliable the evidence is
Appropriateness- refer to picture (both reliability and relevance)
Management experts- there are certain professionals that may be employed or outsourced that are not
directly linked to FS by not being part of the financial team or having experience in audit and accounting,
but they have an impact on FS. For example, lawyers predicting lawsuits or engineers predicting life or
amortization.
ISA 500- just as with internal auditor’s work, expert’s work can be relied on but only after discussions
with them and evaluations. Similar requirements are in place: competence, professionality,
independence, reputation (if outsourced).
Isa 315 assertion definitions-