0% found this document useful (0 votes)
11 views133 pages

Module 1

The document is a study guide for an advanced assurance course, detailing various modules covering professional ethics, audit planning, risk assessment, and internal control testing among other topics. It outlines the learning outcomes for each module, emphasizing the importance of ethical considerations and auditor independence. Additionally, it provides guidelines on how to address ethical dilemmas and the potential threats to auditor independence.

Uploaded by

hassaan nabeel
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views133 pages

Module 1

The document is a study guide for an advanced assurance course, detailing various modules covering professional ethics, audit planning, risk assessment, and internal control testing among other topics. It outlines the learning outcomes for each module, emphasizing the importance of ethical considerations and auditor independence. Additionally, it provides guidelines on how to address ethical dilemmas and the potential threats to auditor independence.

Uploaded by

hassaan nabeel
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Skills

Advanced
Assurance

Study Guide
2024
Contents
Course overview................................................................................................................................... 2
Module 1 – Professional Ethics........................................................................................................... 4
Module 2 – Evaluating data integrity................................................................................................. 13
Module 3 – Audit acceptance and continuance decisions..............................................................20
Module 4 – Audit Planning................................................................................................................. 29
Module 5 – Specific risk areas and the impact on the audit approach..........................................42
Module 6 – Internal Control Testing.................................................................................................. 50
Module 7 – Substantive Analytical Procedures...............................................................................62
Module 8 – Substantive Procedures – Part 2...................................................................................66
Module 9 – Substantive Procedures – Part 3...................................................................................80
Module 10 – Completion and Reporting...........................................................................................87
Module 11 – Group Audits............................................................................................................... 100
Module 12 – Other assurance engagements and related services...............................................111

1
Course overview
Module Module title Content
1 Professional ethics Ethical threats (financial, business, employment and
personal relationships; long association, fees,
remuneration and evaluation policies, gifts &
hospitality and litigation; non- audit/additional
services)
2 Evaluating Data integrity
data integrity Evaluating the reliability of information
3 Audit acceptance Acceptance and continuance risks
and continuance Acceptance and continuance
decisions
procedures
Responding to acceptance risks
4 Audit planning Risk assessment
Planning analytical
review Materiality
Responses to assessed risk
Documentation and communication with those
charged with governance
5 Specific risk areas Laws and
and the impact on regulations Related
the audit approach
parties
Audit of accounting estimates
Using the work of others
6 Internal control Auditor’s testing of internal
testing controls The sales system
The purchase system
The non-current assets
system The payroll system
The inventory management system
Internal audit
7 Substantive Substantive analytical procedures
analytical Incorporating technology in substantive
procedures
testing
8 Substantive Designing a substantive testing audit work
procedures – part programme Specific accounts and considerations
2
Designing follow up substantive
procedures Comparative and opening
balances
Final considerations
9 Substantive Audit sampling
procedures – part Practical application
3
Outstanding matters
Recording, considering and communicating
misstatements

2
Module Module title Content
10 Completion Going concern
and reporting Subsequent events
Evaluation of evidence
Completion documents and quality
review Audit report
Communication with those charged with governance
11 Group audit Acceptance and continuance of group audit
engagements Group audit planning
Group audit: Test of controls, substantive testing,
completion and reporting
Communication between group auditor and
component auditors
12 Other Assurance engagements and related
assurance services Review of interim financial
engagements
information Assurance on prospective
and related
services financial information Other assurance
engagements
Assurance on sustainability information

3
Module 1 – Professional Ethics
Learning Outcomes
 Evaluate and respond appropriately to ethical issues arising in assurance engagements

Module Learning Outcomes


By completing this module, you will have worked towards the following module learning
outcomes:

 Identify ethical dilemmas arising in an assurance engagement


 Recommend a course of action to address ethical dilemmas in line with the
ICAS Code of Ethics

This will be achieved by working towards the following performance indicators:

 Evaluate assurance engagements to identify and explain potential ethical implications.


 Explain the implications of ethical threats to auditor independence and objectivity.
 Apply safeguards to ethical dilemmas.

Using permitted materials


For your AA assessment you are allowed the following permitted materials: the ICAS
Auditing and Reporting Handbook, which contains the Ethical Standard (2019) and
selected Auditing Standards, the ICAS Code of Ethics and IFRS Standards.

The Auditing and Reporting Handbook and the ICAS Code of Ethics will be available in
the assessment platform during your assessment.

You may take a hardcopy of IFRS Standards into the assessment, which you are allowed
to highlight, tab, sideline and underline.

You should ensure that you practice using these materials throughout the

AA course. Here is a reminder of some key points to look at in this module.

4
ICAS Code of Conduct
The five fundamental principles of ICAS Code of Conduct are:

 Integrity
 Objectivity
 Professional competence and due care
 Confidentiality
 Professional behavior

Threats to Independence
The FRC’s Ethical Standard (ES) identifies six threats to independence, which are:

 Self-interest threat
 Self-review threat
 Advocacy
 Familiarity
 Intimidation

Five Threats to Auditor Independence

The following are the five things that can potentially compromise the independence
of auditors:

1. Self-Interest Threat

A self-interest threat exists if the auditor holds a direct or indirect financial interest in
the company or depends on the client for a major fee that is outstanding.

Example

The audit team is preparing to conduct its 2020 audit for ABC Company. However,
the audit team has not received its audit fees from ABC Company for its 2019 audit.

Issue

The audit team might be tempted to issue a favorable report so that the company is
able to secure a loan to settle the fees outstanding for their 2019 audit.

2. Self-Review Threat

A self-review threat exists if the auditor is auditing his own work or work that is done
by others in the same firm.

Example

The auditor prepares the financial statements for ABC Company while also serving as
the auditor for ABC Company.

Issue

5
By having the auditor review his or her own work, the auditor cannot be expected to
form an unbiased opinion on the financial statements.

3. Advocacy Threat

An advocacy threat exists if the auditor is involved in promoting the client, to the
point where their objectivity is potentially compromised.

Example

The auditor is assisting in selling ABC Company while also serving as the auditor for
the company.

Issue

The auditor may issue a favorable report to increase the sale price of ABC Company.

4. Familiarity Threat

A familiarity threat exists if the auditor is too personally close to or familiar with
employees, officers, or directors of the client company.

Example

ABC Company has been audited by the same auditor for over 10 years and the
auditor regularly plays golf with the CEO and CFO of ABC Company.

Issue

The auditor may have become too familiar with the client and, thus, lack objectivity
in their work.

5. Intimidation Threat

An intimidation threat exists if the auditor is intimidated by management or its


directors to the point that they are deterred from acting objectively.

Example

ABC Company is unhappy with the conclusion of the audit report and threatens to
switch auditors next year. ABC Company is the biggest client of the auditor.

Issue

The auditor’s independence may be compromised, as ABC Company is their biggest


client and they, quite naturally, do not want to lose such a client. Therefore, the
auditor may issue a report that appeases ABC Company.

The ES also has the following requirements for audit firms:

6
 The firm should have policies in place for procedures regarding certain ethical matters
 All firms (with the exception of the smallest) should appoint an ethics partner
 Communicating significant facts and matters that impact on auditor integrity,
objectivity and independence to those charged with governance
(Means those entrusted with the supervision, control and direction
of an entity and would therefore include the audit committee and
non-executive directors. They only include management when it
performs such functions

Approach to ethical scenario questions:

3. What are you


1. What is the issue? 2. Why is this an
going to do?
issue?

Step 1: IDENTIFY the ethical issues

Step 2: Think of the relevant ethical guidance and of explain its IMPLICATIONS on
auditor’s objectivity and independence

Step 3: APPLY the guidance to the given scenario

7
TYPES OF THREATS AND ETHICAL ISSUES

Financial Interest
A financial interest in a client constitutes a substantial self-interest threat.

Ethical example Exceptions


Shareholding in a client No exception for direct holdings.
Debt instruments in a Exception where the interest is an
client Share options immaterial indirect investment where the
holder has no influence over investment
decisions.

Loans and guarantees


Giving a loan to a client, being a guarantor for a client’s loan or accepting a loan or
guarantee of a loan from a client would lead to self-interest and intimidation threats to
integrity or objectivity.

Ethical example Safeguard


Accepting a loan from a client Should not be accepted
Being a guarantor for a client’s Exception to this are:
loan  Client is a bank or a similar deposit
Accepting a guarantee of a loan from a taking institution
client  The loan is made in the ordinary
course of business on normal
business terms
 It is not material to the audit firm and
client

Business relationships
A close business relationship will involve a common commercial interest, which in
addition to a self- interest threat, could cause advocacy or intimidation threats to
independence.

Ethical example Safeguard


Joint venture with audit client Allowable where the transaction is:
Distribution / marketing  In the normal course of business,
arrangements on an arm’s length basis
 The transaction is clearly not
Auditor leases office space from client or
material to either party
vice versa

8
Employment relationships
The loan of personnel to an audit client might create a self-review, advocacy, familiarity or
management threat.

Ethical example Safeguard


Audit staff on loan to audit client Deemed the threat would be too
significant that no safeguards are
available.
FRC’s ES states that firms cannot enter
into agreements with audit entities or
their affiliates to provide partners or
employees to work for them for a
temporary period
The only exception available relates to staff
employed by a UK national audit agency.
To safeguard the threats, it must be
ensured that:
 It does not include
management
responsibilities
 It is for a period of 3 months or
less (6 months if the employee is
on a training contract)
 It does not include the
provision of a prohibited
service

Audit staff leaving to join an audit client


If a member of the audit team joins the audit client in a key management position,
familiarity, self- interest and intimidation threats may arise.

Significance of the threats depend on the role the individual was at in the audit team,
the seniority of the role that they have taken up at the client and the length of time that
has passed between the individual’s connection with the audit engagement and the new
role at the client.

Ethical threat Safeguard


Audit partner joining in senior management Not allowed within 1 year period (2 for a
position public interest client)
A member of the audit team joins the Modifying the audit plan
audit client in a key management position Ensuring the audit team has senior team
within two years of leaving the members who have sufficient experience
engagement team as compared with the individual who has
left
Involving an additional professional
accountant not involved with the
engagement to review the work done
Where any member of the engagement Notify the firm of any situation involving
team who was involved in an engagement their potential/ probable employment with
in the previous year (or two years in the any such entity
case of a partner) is going to be employed Be removed from the engagement team
by a client
Have a review performed of their work on
both their current and most recent
engagement
9
Former audit client staff joins the audit firm
When former audit client staff join the audit firm, the key threat is self-review as the
audit team member will report on work they prepared originally, or elements of the
financial statement they had responsibility for at the client, but there is also a risk of
self-interest and familiarity threats.

The significance of the threat depends on:

 Position the individual held within the entity


 Length of time since the individual left the entity
 Position the individual holds in the engagement team or audit firm

Ethical threat Safeguard


Former audit client staff joins the audit firm When former directors or employee of an
audit client who were in a position to
exert significant influence over the
preparation of the financial statements
joins the audit firm, they should not be
assigned to the audit team.

They should not be assigned to any


position in which they are able to influence
the conduct and outcome of the audit for 2
years following the date of leaving the
audit client.

Family and other personal relationships


 Immediate family: A spouse (or equivalent) or a dependent
 Close family: A parent, non-dependent child or sibling who is not an
immediate family member.

When an immediate or close family member has a financial, business or employment


relationship it may lead to familiarity, self-interest, and intimidation threats.

The safeguards will be dependent on the individual circumstances:

Ethical threat - examples Safeguard


Spouse is the finance director of your The firm should have procedures for staff
audit client – there is no acceptable to report any possible relationships that
safeguard to reduce to acceptable risk may compromise independence and the
therefore they should be removed from engagement partner must assess any
the audit. threats identified and apply appropriate
safeguards. The engagement partner may
do this in consultation with the ethics
Niece working in the marketing
partner.
department of your audit client – this
could be deemed as an acceptable risk as
they would have no influence on the audit. According to ICAS' code of ethics,
examples of actions that might be
safeguards to address such self-interest,
familiarity or intimidation threats include
structuring the partner’s or employee’s
responsibilities to reduce any potential
influence over the audit engagement and
having an appropriate reviewer review the
relevant audit work performed.

1
0
Long association with an audit engagement
Long association by senior members of the audit team with a particular audit client
might lead to familiarity, self-interest and self-review threats as there can be actual or
perceived lack of scepticism when performing the audit.

The ES’ requirements differ for public-interest and non-public interest clients:

Public interest clients

 Engagement partners should be rotated after 5 years (to safeguard the quality of
the audit this may be extended to 7 years)
 The engagement quality control reviewer should be rotated after 7 years (and
must not return for 5 years)
 Any other key partners (such as tax partner) should be rotated after 7 years
(and must not return for 2 years)
 The independence of any other audit staff should be seriously considered and
discussed with the ethics partner after seven years.

Non-public interest clients

 Rotation of the audit partner should be considered after 10 years in the role.

If this is not carried out, an alternative safeguard should be put in place, such as:

 Involving an additional partner who is not involved, or has not recently been
involved, on the audit engagement to review the work
 If the individual is not removed, the reasons behind the decision must be
documented and those charged with governance of the audit client should be
informed.

The Companies Act 2006 includes rules on mandatory audit firm rotation of auditors of
public interest entities. A maximum period of 10 years has been introduced which can be
extended to 20 years provided that an appropriate tender process takes place at least
every 10 years. Therefore, under the Companies Act 2006, an audit firm can only
undertake the audit of a specific PIE for a limited period.

Fees and remuneration


Conducting an audit on a contingent fee basis gives rise to a self-interest threat.

Where fees are overdue, a self-interest threat to independence may arise. The overdue
fee effectively constitutes a loan to a client.

Fee dependence covers situations where firms may be reluctant to act in a way which
could jeopardise their relationship with the client, for fear of losing a significant portion
of their fee income.

If the auditor is receiving substantial fees for non-audit services from an audit client or
is perceived to be dependent on a particular client, there may be a perceived self-
interest and intimidation threats to independence.

If audit team members have their performance appraised or their pay linked to their
ability to cross sell the firm’s services to audit clients, the self-interest threat that may
arise is so significant that no ` ` `

11
Ethical threat Safeguard
Providing audit or non-audit services on a Threat is so significant that there is no
contingent fee basis. safeguard possible.
Overdue audit fees The engagement partner and ethics
partner should consider whether the audit
firm can continue or whether it is
necessary to resign unless fees are clearly
trivial.
If the firm does not resign, the
engagement partner should apply
appropriate safeguards (such as a review
by a partner with relevant expertise who
is not involved in the engagement) and
notify the ethics partner of the facts
concerning the overdue fees.
Dependence on non-audit services The total fees for non-audit services in
relation to a public interest audit client are
capped at 70% of the average of the fees
paid over the last three years for the audit
of the entity.
Dependence on one client If total recurring fees (audit and non-
audit) are expected to regularly exceed
10% (public interest and other listed
clients) or 15% (non- listed clients) of the
annual fee income of the audit firm, then
the auditor should resign or not stand for
re-appointment.
Total fees approaching these limits should
be disclosed to the ethics partner and
those charged with governance at the
client.
Potential safeguards include reducing the
amount of non-audit work and applying
independent internal quality reviews.
Remuneration for selling non-audit services Auditors should not be remunerated,
appraised or given bonuses based on the
selling of non- audit services to audit
clients. The focus for evaluation and
remuneration should be audit quality.

Gifts and hospitality


Gifts or hospitality given by or received by the auditor could be perceived as a self-interest and
familiarity threats to independence.

Ethical threat Safeguard


Accepting gifts or hospitality (including Firms should have policies in place
immediate family or persons able to regarding the extent to which gifts and
influence the audit) hospitality may be accepted from audited
entities.
Gifts and hospitality can only be accepted
where the value is clearly trivial.

1
2
Threatened and actual litigation
When a client threatens to sue or sues the firm for work that has been done previously, self-
interest, intimidation and advocacy threats to auditor’s integrity, objectivity and independence
arise.

Ethical threat Safeguard


Threatened and actual litigation If litigation is in progress or is probable,
the firm should either not continue with or
not accept the audit engagement.
Not required to resign if an objective,
reasonable and informed third party would
not regard it as being in the interests of the
shareholders (or equivalent) or otherwise
contrary to the public interest.

Non-audit services for audit clients


When a firm provides non-audit services to their audit clients, self-review, management,
self- interest and advocacy threats commonly arise.

Non-audit services explicitly prohibited for PIE clients that are audit clients are given in
the document FRC ES - Appendix B. This is included within the ICAS Auditing and
Reporting Handbook, which is permitted material for your assessment.

Ethical threat Safeguard


Provision of non-audit services Have a separate team from the audit
team perform the non-audit service
Complete an independent engagement
quality review on the audit engagement
Firms cannot take decisions on behalf of
the client’s management. The firm needs
to evaluate if there is informed
management at the client. If there is, it
may be possible that safeguards can be
implemented to minimise management
threat.

Some non-audit services are strictly prohibited:

 Internal audit
 Accounting services – not permitted on listed clients
 IT services – the design, provision or implementation of a significant part of the
accounting system is not permitted
 Corporate finance services - services that involve dealing, underwriting or
promoting an audit client’s shares are not permitted
 Recruitment and remuneration services
 Tax services – those which involve the firm undertaking a management
role are not permitted.
 Valuation services – not permitted on listed clients
 Legal services/litigation support services

13
Assessment approach
It is important to understand that in AA, marks are given for appropriate application
of the knowledge rather than just stating knowledge.

The assessment approach to be taken is:

Step 1: IDENTIFY the ethical issues

Step 2: Think of the relevant ethical guidance and of explain its IMPLICATIONS on
auditor’s objectivity and independence

Step 3: APPLY the guidance to the given scenario

Conclusion
On completing this module, you can now attempt AAPQ 15 and 23.

1
4
Module 2 – Evaluating data integrity
Introduction
Welcome to the study guide for Module 2 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.

Syllabus Learning Outcomes


 Apply professional judgement and professional scepticism in conducting an
assurance engagement

Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:

 Design procedures to evaluate the integrity and completeness of data and


evaluate the results of audit data analytical procedures when collecting audit
evidence

This will be achieved by working towards the following performance indicators:

 Evaluate an organisation's risks in relation to data integrity, analysing the


impact on management's ability to make effective strategic decisions, and
recommend procedures to maintain data integrity
 Design procedures to evaluate the reliability of information produced by the entity
 Evaluate the reliability of information produced by the entity for the purpose of audit
evidence

You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.

Here is a reminder of some key points to look at in this module.

15
Data integrity

Data integrity and decision making


Data integrity – the accuracy, completeness and reliability of data over its

life cycle. The components of data integrity are:

Accurate Data correctly reflects real-world information


Complete Data should contain all critical information
Consistent Data across an organisation should be consistent with itself
Reliable Decision-makers should be able to rely on the data they are provided
with
Secure Data should be secure and protected
Timely Data should be up-to-date and therefore relevant
Traceable The source of data should be understood
Valid Data should exhibit the required characteristics
Uniqueness Duplicate items should not occur within a data set

Types of data integrity


Physical integrity

Considers maintaining the integrity of the data as it is stored and retrieved and the
procedures to manage when the physical integrity of data may be compromised.

Logical integrity

Focus on the rationality of the data itself. There are four types of logical integrity:

Entity integrity In a database, data is captured in a table. Entity integrity refers


to ‘columns’ within this table as being the primary key(s). The
primary key(s) should be unique and not null
Referential integrity This looks at the processes in place to ensure data is stored and
used uniformly. Referential integrity ensures that data between
two connected data sets is accurately referenced.
Domain integrity This looks to ensure that data within a specific ‘column’ of a
table is accurate for that column. This, for example, might
include a range of acceptable values or limit the format of data.
User-defined integrity This covers any rules not classified into the three categories
above which
are defined by a user of the data. They will be specific to an
entity’s needs.

1
6
The difference between data integrity, security and quality

Data integrity Data integrity is the threat that data is modified or corrupted within its
life cycle as a result of failures, such as those around storage,
processing, software or human intervention.
Data security Data security deals with protecting data against unauthorised access
or disclosure, which is important to ensure data integrity.
Data security focuses on keeping data inaccessible to those who
should not have access.
Data quality Data quality focuses more on whether the data meets any defined
standards and the needs of the organisation, and therefore can be used
for its intended purpose.

How data integrity can be compromised

Human error If an authorised individual accidentally amends data by not


following the correct process or making an error, then data
integrity will be at risk.
Transfer errors Data may need to be moved from one location to another.
Should the data be corrupted during this process, data integrity
will be put at risk.
Bugs and viruses Corruption in software may result in data being altered or
deleted.
Compromised Server crashes or other such problems may mean data is not
hardware or software processed or stored in a consistent way and therefore present a
data integrity risk.
Data processing error If data processes are not properly designed and developed,
then data could be adversely amended or altered.

17
Maintaining data integrity
There’s no single universal solution for maintaining data integrity. There are numerous
tactics that can help to build an environment that supports data integrity. These include:

Culture and control  Culture around reducing risks


environment  Strong control environment
 Training of staff
 Mandating internal audit to monitor and assess data
integrity
Follow the systems  Guards against potential risks involved in system
development life cycle development
(SDLC)
Implement a formal,  Quality controls
controlled data  Physical controls
management process
 Logical security controls
Implement audit trails  Secure and system generated audit trails
 Details of amendments made, time stamps of edits to
data and who amended data
 Reviewed
Limit access to systems  Appropriate access rights
 Physical access controls
 Logical access controls
Maintain backup and  Regular and effective backup and recovery procedures
recovery procedures  Data can be restored in the instance of an
unexpected event causing loss or amendment of
data
Purchase reputable  High standard and designed to maintain data integrity
software  Robust due diligence required
Perform regular internal  Systems audits; operational audits; post-implementation
audit reviews reviews; investigations; inspection and quality control
and culture audits
 Promote interaction between internal and external
auditors to share lessons

Evaluating the reliability of information

Audit Evidence
Auditors must gain sufficient appropriate evidence on which to base their

opinion. For evidence to be appropriate, it must be:

 Relevant
 Reliable

1
8
Relevance
Evidence will be relevant if it provides evidence over one or more financial statement
assertions as listed below:

Account balances and related disclosures at Existence; Rights and Obligations;


the period end: Completeness; Accuracy, Valuation
and Allocation; Classification;
Presentation
Classes of transactions and events Occurrence; Completeness; Accuracy; Cut-off;
throughout the period and related Classification; Presentation
disclosures:

Reliability of client information


 Before using information generated by the entity the auditor must evaluate to
confirm that it is sufficiently reliable, accurate and complete, and sufficiently
precise and detailed for their purpose
 More assurance is often obtained from independent information generated from
outside the entity

Professional scepticism
The auditor should always exercise professional scepticism, and this requires a challenging
and questioning mind. Auditors exercise professional scepticism as follows:

 Not just accept information produced by the entity


 Use their knowledge of the entity to identify new specific audit risks and tailor audit
procedures
 Use their knowledge of the entity to analyse figures and the results of testing, and
to challenge management's assumptions and explanations
 Determine whether any evidence is contradictory
 Only make judgements based on the evidence gathered and only conclude on an
account when there has been sufficient enquiry and challenge, testing of
assertions and the quality of evidence has been critically appraised and judged
to be persuasive
 Document audit judgements

Data for use in audit data analytics


 The auditor must consider the accuracy and completeness of information and
whether it is sufficiently precise and detailed for the auditor’s purpose
 This will include detailed procedures over the data, but may also involve
reliance on client systems through testing of IT general controls
 Data produced from client systems may require cleansing and the auditor will
put in place checks and controls over the data cleaning process

19
Some examples of relevant ADA procedures:

1. Agreeing opening balances to prior year signed financial statements


2. Agree closing balances to financial statements being audited
3. Cast and cross-cast data
4. Agreeing that the total movement in a dataset equals to the total movement in that
account per the F/S
5. Testing IT General Controls or other controls around the production of data
6. Considering the continuity of sequentially numbered documents
7. Considering the characteristics exhibited by data, such as dates or time stamps
8. Performing sample checks of data lines to corroborated evidence
9. Review data for unusual characteristics such as duplicates, missing fields or
information in inappropriate format
10. Agreeing batch totals to the client’s IT system

Assessment approach
When you are asked to analyse risks to data integrity and evaluate their impact on management’s
ability to design and implement an effective strategy:

 You should begin with identifying risks to data integrity when you are reading the
scenario.
 You should then analyse the risk by thinking of its implications.
 When asked to evaluate the impact of the risks on the organisation’s strategy, think
about the impact of unreliable data on the company’s ability to make proper
decisions.
When you are asked to analyse information given in the scenario to highlight any concerns over
the accuracy, validity and completeness of the underlying data:
You need to begin by identifying the issue from the scenario and then analyse it.
It is important to read the information provided carefully. Look for unusual trends or
information that appears to contradict other information and explain them.
When you are asked to describe any further audit evidence (or procedures) that are required to
conclude on whether reliance can be placed on the underlying data by the audit team:
When explaining evidence (or procedures), ensure that you identify the source document
and then go on to explain what you are confirming from the source document.

Conclusion
On completing this module, you can now attempt AAPQ 4 and 20.

2
0
Study guide checklist

Have you completed reading module 2?

Have you completed the skills checkers and skills builders?

Can you confidently complete the module learning outcomes listed on this module?

Can you confidently answer the guiding questions?

Have you completed the assessment practice questions?

Have you used the discussion board to ask questions on areas you are unsure
about?

21
Module 3 – Audit acceptance and continuance
decisions
Introduction
Welcome to the study guide for Module 3 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.

Syllabus Learning Outcomes


 Apply professional judgement and professional scepticism in conducting an
assurance engagement

Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:

 Evaluate the results of acceptance and planning procedures, including the use
of audit data analytics to assess and determine the risk of material
misstatement and impact on audit approach

This will be achieved by working towards the following performance indicators:

 Explain an auditor's professional requirements in relation to acceptance and


continuance of an audit engagement
 Evaluate the acceptance and continuance risks presented by an audit engagement
 Design appropriate safeguards to respond to acceptance threats

You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.

Here is a reminder of some key points to look at in this module.

2
2
Key terms from ASR

Recap of the audit process


The audit process is split into seven elements.

The risk assessment, engagement and client management elements must run throughout
the whole of the audit process and are referred to as ongoing elements.

The other five elements (acceptance, planning, systems and control analysis, substantive
testing, and completion) represent the stages of the audit process.

Audit process

Risk assessment

Acceptanc Plannin Systems Substantiv


Completio
e g and control e n

Engagement and client management

Element Detail
Acceptance  Before the engagement begins
 Professional and ethical requirements
Planning  Need to gain an in-depth understanding of the client, its
environment, the financial reporting framework and the system
of internal control
 From this, the auditor will identify areas in the financial
statements that have a higher chance of fraud or error
 Preliminary materiality level will be set, which will be reviewed
throughout the audit
 Planning usually happens before the year end.
Systems and  Understand what processes and controls a client has in place
controls  Test how effectively these operate in terms of preventing or
analysis detecting an error/fraud (or ‘misstatement’) in the accounts.
 Frequently occurs during an ‘interim audit’ before the entity’s year
end.
Substantive  Occurs after the year end
testing  Involves testing the figures in the financial statements
to identify misstatements
Completion  Performed to allow the audit to be concluded
& reporting  The final audit report can be issued, stating whether, in the
auditor’s opinion, the financial statements are ‘true and
fair’.
Risk  Auditors follow a ‘risk-based approach’ in external audits.
assessment  More work done by the auditor where there is more risk of
misstatement
 Ongoing element
Engagemen  Audit must be properly managed
t and client  Appropriate staff
manageme  Adequate review
nt  Managing clients' expectations
 Communication within the audit team and between the client
and the audit team is a key requirement
 Ongoing element
23
Auditors do not need to wait for the accounting year end to start the audit process. For
larger clients, an interim audit may be carried out.

Benefits of conducting interim activities before year end


 Spread resources throughout the year
 Provide clients with a status report on internal control recommendations before year end
 Issues can be identified before year end
 Reduces risk of not achieving deadlines
 A better understanding of the business, processes and controls can be obtained

Winning an audit engagement


Procedures undertaken prior to winning the client can involve the following:

 Understanding the client and the services to be provided


 Preparing budgets and considering resources
 Drafting a proposal document for audit services to provide to management and directors
 Submitting the proposal and giving a presentation to the potential client

A proposal will generally be submitted summarising key information regarding why the
audit firm should be chosen by the prospective client. This will include:

An estimate of the audit fee The audit team profile An initial assessment of
including experience the key risk areas
An explanation of the tools Client deliverables, A follow up presentation
and technologies to be used meetings and engagement
timeline

Client acceptance and continuance considerations


As learnt in ASR, the key matters to be considered and the procedures that an audit firm
should carry out before accepting a new client or engagement include the following:

 Risk analysis
 Firm’s ability to audit the client
 Ethical considerations
 Communication with the outgoing auditor

2
4
Acceptance/continuance risks
The audit firm must assess risks of accepting/continuing the client engagement.

Commercial risks include:


Financial risks  Financial loss due to unpaid fees
 Financial loss due to a low fee that
does not meet the costs of the audit.
 Financial loss due to litigation related
to the client.
 Financial loss due to damaged
reputation and related loss of
clients.
 The requirement to forego fees for
non-audit services, in order to accept
an audit
appointment.
Reputational risks  Association with an unscrupulous client
 Association with a client that fails
 Legal claims brought
against the professionalism
of the auditor
Professional risks include:
Ethical risks  Audit firm does not comply with
professional standards
 Engagement partner not being
independent
Legal risks  Audit firm does not comply with
laws and regulations
 Suspicions of money laundering
at the potential client

ISQM (UK) 1
The firm’s system of quality management

The audit firm must establish processes to ensure that relevant ethical requirements,
including those related to independence, are fulfilled. These procedures should ensure
that the firm and its staff:

 Understand the relevant ethical requirements.


 Fulfil the relevant requirements in relation to these.

Acceptance and continuance

The firm must establish a process to ensure that judgements about whether to accept or
continue a client relationship or engagement are appropriate based on:

 Information obtained about the nature and circumstances of the engagement.


 The integrity and ethical values of the client.
 The firm’s ability to perform the engagement in accordance with professional
standards and applicable legal and regulatory requirements.

The audit firm should not let financial or other operational priorities lead to inappropriate
decisions about accepting or continuing an engagement.

25
ISA (UK) 220
Preliminary engagement activities

At the beginning of an audit engagement, the auditor must undertake the following activities:

 Perform procedures regarding the acceptance and continuance of client


relationships and specific audit engagements.
 Evaluate the firm’s ability to comply with ethical requirements, professional
standards and applicable legal and regulatory requirements.

Ethical requirements

The engagement partner is required to:

 Have an understanding of the relevant ethical requirements for the


engagement, including those related to independence.
 Take responsibility for making sure the entire engagement team is aware of
the relevant ethical requirements for the engagement

Acceptance and continuance

The engagement partner shall:

 Determine whether the firm’s policies or procedures for acceptance and


continuance have been followed and that appropriate conclusions have been
reached.
 Take into account information obtained during acceptance/continuance in
planning and performing the audit engagement.

ISA (UK) 210


The auditor should accept or continue an audit engagement only when the basis upon which it is
to be performed has been agreed, through:

 Establishing whether the preconditions for an audit are present.


 Confirming whether there is a common understanding between the auditor and
the client’s management (including those charged with governance) of the terms
of the audit engagement.

To establish that the preconditions for an audit are present, the auditor shall:

 Determine that the financial reporting framework is acceptable.


 Obtain agreement from management that it acknowledges and understands its
responsibility for:
 The preparation of financial statements.
 Internal controls that enable financial statements to be free from material
misstatement.
 Providing the auditor with access to relevant information and staff

If management imposes a limitation on the scope of the auditor’s work that the auditor
believes will result in the auditor disclaiming the opinion on the financial statements, the
financial reporting framework is not applicable or management does not agree to
acknowledge and understand their responsibilities as laid out above, the auditor must
not accept the engagement unless required by law or regulation to do so.

2
6
Tutor tip
The auditor obtains such information as is deemed necessary in order to reach a decision
regarding the acceptance of the engagement. This information is then assessed
according to how it impacts the audit firm in terms of commercial and professional risk.

An assessment question should be approached in the same way. If you are given
information about a client in the scenario, you need to identify facts from the scenario to
consider how they impact the audit firm’s risks. Then, as a part of the analysis, you should
explain the importance of the facts in relation to the acceptance decision.

Example

FACTS from question ANALYSIS in terms of risk


 A partner in the firm has a  This partner should not be on the
shareholding in the client audit as they are not independent,
and this would breach the ethical
standard requirements

Acceptance and continuance procedures


There are seven main acceptance procedures.

You may wish to use the anagram below to help remember these:

Basis for performance


Auditor previous
ID Procedures
Legal and financial
stability Management's
integrity Ability to audit
Nature and users

1. Identify the users and nature of the engagement - includes understanding the
prospective client, the impact on legal responsibilities and the nature of the
financial statements.

Understanding the prospective client may include consideration of:

 The size, complexity and nature of the entity.


 Timetable for reporting.
 Whether there have been changes in the entity or in the industry since the
previous audit (for continuance decisions).

The auditor’s legal responsibilities on an engagement may vary depending on the


intended users of the financial statements and the nature of the engagement.

The auditor should consider the nature of the financial statements, including whether the
general- purpose financial statements will meet the needs of the users or whether any
special-purpose reports will be required.

27
2. Assess the prospective client's legal and financial stability – an auditor will want to take
steps to protect themselves from the risk of legal claims or unpaid audit fees.

Clients that pose a high risk of litigation or financial loss may be rejected, such as:

 Entities whose principal operations or products are the subjects of either


material lawsuits or investigations by regulatory authorities, the outcome of
which could adversely affect the viability of the business
 Entities that are known to be experiencing financial instability

3. Assess integrity of TCWG, management and the principal owners - an auditor should
seek reasonable assurance that the entity’s management can be trusted.

Matters to consider when assessing the integrity of a client include:

 Nature and complexity of entity and its operations


 Interpretation of accounting standards and quality of internal control environment
 Concerns with keeping the fee low
 Indications of a client-imposed limitation in the scope of work.
 Possible money laundering activities
 The reasons behind the firm’s appointment and non-reappointment of the previous firm.

To assess the integrity of management the auditor should perform a number of procedures:

 New engagement - contact the previous auditor


 Continuing engagement – consider past experience with the entity’s management
 Make enquiries of third parties
 Background checks
 Review press

4. Communicate with the previous auditor - a prospective auditor is required to


contact the existing or previous auditor as part of the acceptance decision
process

5. Evaluate the audit firm's ability to audit the entity - this may include assessing:

 Competency and resources


 Limitations imposed by the client
 Independence

6. Perform client identification procedures – this is a statutory requirement and a risk


assessment procedure. Auditors must obtain evidence that establishes the full name
and permanent address of the entity and its principal directors, partners and
shareholders.

7. Agree the basis for performance of the audit - the auditor must establish the
preconditions for an audit and that there is a common understanding between the
auditor and management about the terms of the engagement.

Tutor tip
In a scenario question, you will be required to consider how the facts provided impact the
risks to the firm. As discussed in the previous lesson, the facts must be analysed, not
simply identified, in order to gain marks.
Use the seven procedures as a checklist to identify all of the issues relevant to the
question. This should increase your chances of identifying enough points for the marks
available. It is a reminder of the things you should consider and does not represent the
headings that you need to use.
The ethical standard headings may be used as a further prompt to ensure all
2
8
independence risks are considered.

29
Continuance procedures
 A continuance decision focuses primarily on any changes since the prior year audit
 An evaluation of risks and consideration of independence will still be required
 For a public company a decision will need to be made before the AGM. During the
completion stage of the prior year audit is common
 A private company does not require an AGM to re-appoint the auditor. The
statutory auditor is automatically re-appointed each year

Safeguards are required where risks are identified, or else the engagement should be declined.

Responding to acceptance risks


Where significant risks are identified, the auditor must:

 Take steps to eliminate each risk or reduce it to an acceptable level to enable


acceptance or continuance of the engagement OR
 Decline the engagement where it is impossible to reduce the risks to an acceptable level.

Examples of steps to eliminate risk or reduce it to an acceptable level include the following:

 Recruiting audit staff or using seconded staff from other offices to ensure
audit staff have sufficient time to complete the engagement within the
required timeframe.
 Rotation of the engagement partner or other members of the engagement team.
 Using an auditor’s expert where the audit firm lacks competence to audit a specified
area.
 Using separate engagement teams where independence issues arise.
 Engagement quality control review (independent partner review).

Tutor tip
A question may ask you to identify the specific risks arising from the scenario and a
response to those risks that would enable the firm to take on the client. You must ensure
that you can identify and explain how these acceptance risks impact the audit firm and
be able to propose safeguards, where appropriate, to mitigate each risk or reduce it to
an acceptable level.

You must also be able to identify when an auditor is unable to propose sufficient
safeguards or is prohibited outright from undertaking the engagement. When proposing
safeguards, you should ensure that they are relevant to the firm outlined in the scenario.
For example, partner rotation is an inappropriate safeguard for a one-partner firm.

Engagement letters
ISA (UK) 210 includes the requirements regarding the engagement

letter. The following items must be included in the engagement

letter:

 Objective and scope of the audit


 Responsibilities of the auditor
 Responsibilities of management
 Identification of the applicable financial reporting framework
 The form and content of any reports to be issued by the auditor
 A statement that there may be circumstances in which a report may differ from
its expected form and content

3
0
The following items may be included in the engagement letter:

 That the auditor will expect management to sign management representations


as part of the audit
 More detail on the scope (for example, reference to applicable legislation,
regulations, ISAs (UK)) and planning of the audit
 Any caveats or disclaimers that are included to limit the potential liability of
the auditor in relation to the engagement.

For continuing engagements, where significant changes have taken place since the prior
year audit, a new engagement letter may be required.

Study guide checklist

Have you completed reading module 3?

Have you completed the skills checkers and skills builders?

Can you confidently complete the module learning outcomes listed on this module?

Can you confidently answer the guiding questions?

Have you completed the assessment practice questions?

Have you used the discussion board to ask questions on areas you are unsure about?

31
Module 4 – Audit Planning
Introduction
Welcome to the study guide for Module 4 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.

Syllabus Learning Outcomes


 Apply professional judgement and professional scepticism in conducting an
assurance engagement

Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:

 Evaluate the results of acceptance and planning procedures, including the use
of audit data analytics to assess and determine the risk of material
misstatement and impact on audit approach.

This will be achieved by working towards the following performance indicators:

 Evaluate the information collected about an entity to identify the significant


risks of material misstatement in the financial statements
 Evaluate the results of planning analytical review findings, including calculating
an expectation for key figures in the financial statements
 Recommend appropriate materiality figures and consider the application of
materiality to the audit process
 Plan an approach to gathering sufficient appropriate audit evidence in response
to identified risks of material misstatement
 Produce planning documentation including the audit strategy memorandum
 Plan the methods, timing and content of communication with those charged with
governance during the audit

You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.

Here is a reminder of some key points to look at in this module.

3
2
Audit Planning
 Good planning ensures audit focused on risky areas and carried out in an
efficient/ effective manner
 Planning is a continuous process

Audit strategy:  Audit strategy memorandum (ASM) captures the main general
areas of planning: materiality, risk, audit approach, use of experts
and internal audit, timing, team, budgets and deadlines.
 The overall audit strategy should be updated as necessary during
the course of the engagement.
Audit plan:  The plan contains the detail needed to implement the strategy
 The audit plan is more detailed than the overall audit strategy in
that it includes the nature, timing and extent of audit procedures
to be performed by engagement team members.

Audit risk
Audit risk is the risk that the auditor gives an inappropriate opinion on the financial
statements when the financial statements are materially misstated.

The risk must be reduced to an acceptably low

level. The components that make up the audit

risk formula are:

Audit Risk = Inherent Risk x Control Risk x Detection Risk

The combination of Inherent Risk and Control Risk is called Risk of Material Misstatement (ROMM).

Risk assessment procedures


Risk assessment procedures will collect information that the auditor will use to identify
and analyse potential risks of misstatement in the financial statements.

Enquiry Inspection
Of management and others within the May include inspection of internal
client documents and reports prepared by
management and TCWG
Analytical Procedures Observation
Help identify inconsistencies or unusual May support or contradict inquiries. May
transactions or trends occur at client’s premises.

Additionally, the auditor is required to consider information from other sources and engagement
team discussion.

33
Understanding the entity
Auditor must gain an understanding of:

 The entity and its environment


 Organisational structure, ownership and governance and business model
(including the use of IT)
 Industry, regulatory and other external factors
 The measures used, internally and externally, to assess the
entity’s financial performance.
 Applicable financial reporting framework and the entity’s accounting policies
 Inherent risk factors
 System of internal controls

Identify and assess ROMM


Risk of material misstatements in the financial statements may arise due to fraud or error.

In order to assess ROMM, it is important to understand its impact at the overall financial
statements level as well as the assertion level.

ISA (UK) 315 requires that risks of material misstatement are identified and assessed in
terms of their impact at:

 The financial statement level (financial statements as a whole)


 The assertion level for individual balances, transactions and disclosures (risks
consist of inherent and control risk)

Risks of material misstatement at the financial statement level arise from:

Fraud A higher risk of fraud could result in a ROMM over a number of


accounts due to a higher risk of manipulation generally. This is
particularly where there are risk factors in relation to management
override and the manipulation of profit to meet bank covenants,
combined with weaknesses in the control environment, rather than a
particular process.
Going concern Going concern is a fundamental concept of the financial statements.
Therefore, if there is a risk that the going concern assumption is not
appropriate or that uncertainties are not disclosed properly, then this
has an impact on the financial statements as a whole.
A weak control The impact of a weak control environment is likely to impact all account
environment balances and transactions as the detailed controls within individual
systems over all accounts are less likely to be operating effectively.

Risk of material misstatement at the assertion level – the assertions are as follows:

Account balances Classes of transactions


Existence Occurrence
Rights and obligations Completeness
Completeness Accuracy
Accuracy, valuation and allocation Cut-off
Classification Classification
Presentation Presentation

3
4
Control risk
Control risk is the risk that an organisation’s internal control systems do not adequately
prevent or detect and correct a misstatement either because they are poorly designed
or do not operate effectively.

Control risk is assessed predominantly at the systems and controls stage of the audit.

Inherent risk
Inherent risk can arise from:

Business risk Only an audit risk if they could result in a material misstatement in
the financial statements
 Strategic and operational (market, organisational, financial)
 Reliable financial reporting
 Compliance (social and environmental/legal and regulatory)
Inherent risk factors  Complexity – Arises either from the nature of the information
or in the way that the information is prepared.
 Subjectivity – Arises from inherent limitations in the ability to
prepare information objectively, due to limitations in the
availability of knowledge or information, such that
management is required to make a judgement.
 Change – May include changes to the entity’s business
operations, accounting standards, regulatory environment
or industry which have an impact on the financial
statements.
 Uncertainty – Arises when the required information cannot
be prepared based on only sufficiently precise and
comprehensive data that is verifiable through direct
observation.
 Susceptibility to misstatement due to management bias or other
fraud risk factors – This arises from conditions that create
susceptibility to intentional or unintentional failure by
management to maintain neutrality in preparing the
information. If intentional, this may
amount to fraudulent financial reporting.

Tutor tip
Students often identify the audit risk arising from business risks, such as the loss of a key
customer or too much inventory on hand. However, they often miss the inherent specific
risks relating to correct accounting.

This will identify a range of risks. You should always explain the risks in relation to the
possible impact of material misstatement in the financial statements.

For example, if the client has obsolete goods in stock, the business risk is that they
would need to sell it at lower margins (or scrap it), resulting in financial loss for the
business.

The risk of material misstatement needs to be linked to how this obsolete inventory has
been recorded in the year-end financial statements. If it has not been recorded at the
lower of cost and net realisable value, inventory and profit would be overstated. This
overstatement is the potential impact on the financial statements.

35
Fraud Risk
There are two different types of fraud:

Fraudulent financial reporting More commonly involves management override of controls


Misappropriation of assets More commonly perpetrated by employees

The responsibility for the prevention and detection of fraud rests with management and
those charged with governance.

The auditor's responsibilities are:

Audit objectives  Obtain reasonable assurance about whether the financial


statements as a whole are free from material
misstatement due to fraud
 To respond appropriately to fraud or suspected fraud
identified during the audit.
Professional scepticism  The auditor must maintain an attitude of professional
scepticism at all times when conducting their work.
Discussion among the  Discussion among the engagement team
engagement team including the engagement partner is required

Risk assessment procedures

 Obtaining an understanding of the fraud risk factors relevant to the entity


 Making enquiries of management, those charged with governance and others within the
entity
 Consideration of whether any unusual or unexpected relationships have been
identified in performing analytical procedures
 Consideration of other information obtained by the auditor

Tutor tip
Fraud risk factors or evidence that indicates a fraud has been committed will be included
in facts within a scenario. The factors listed within the appendices to ISA (UK) 240 are
common indicators you will be presented with. Being familiar with these indicators will
make it easier to identify from a scenario whether a fraud risk exists.

The fraud risk factor categories may be used as prompts in a risk question to identify all
of the factors that may result in a fraud risk. Often, it is easier to identify incentives to
commit fraud, but harder to identify the opportunities and rationalisations, such as a
weak control environment and disregard for controls. Events such as improved
profitability where available cash is declining are also indications that fraud may have
occurred. Therefore, using the categories can help you identify a larger range of fraud
risk factors.

The indicators that you identify should be explained in terms of them providing an
incentive, opportunity, rationalisation or evidence of a fraud occurring.

3
6
Going concern
General purpose financial statements are prepared on a going concern basis under which
assets and liabilities are recorded on the basis that the entity will be able to continue
trading for the foreseeable future and realise its assets and discharge its liabilities in the
normal course of business.

Audit objectives:

 Obtain evidence regarding and conclude on whether there are any material uncertainties
 Obtain evidence regarding and conclude on the appropriateness of the GC assumption
 Report on GC

In performing risk assessment procedures the auditor must consider:

 The entity and its environment


 The applicable financial reporting framework
 The entity’s system of internal control
 The entity’s risk assessment process
 The entity’s information system and related business processes relating to going concern

It is the responsibility of the directors to prepare the financial statements and to assess
whether or not the entity is a going concern and to prepare the financial statements
accordingly.

Tutor tip
You may be given a scenario in an assessment question and asked to identify the audit
risks. The facts that you may identify are the matters in the activity above, which should
be explained in terms of how they could impact the going concern. This is a risk to the
organisation and also an AR at the financial statement level.

For financial statement-level risks, you may find that several facts combine to create an
audit risk. For example, say a company has net liabilities and negative cashflows and
needs to repay a large loan in two months. In this instance, you should group the facts
together under the risk of the going concern assumption being inappropriate. Grouping
the points is important as multiple marks are not awarded for identifying separate going
concern points in the exam.

Significant risks
 Includes risks with the highest inherent risk and those designated by ISAs (UK)
 Fraud is required to be classified as a significant risk
 Allows the auditor to focus more attention on those risks that carry a higher inherent risk

Assessment approach
For questions on analysing audit risks, the recommended assessment approach is:

1. Read through the scenario and highlight the relevant facts that can result in audit
risk (increase the chances of fraud or error in the financial statements)
2. Think of the impact of each fact on the financial statements
3. Write the answer. Ensure your answer cover the fact and the financial statements
impact. Use headings to improve the layout of your answer.

37
Planning analytical review
Analytical procedures are a mandatory risk assessment procedure at the planning stage.

Common analytical procedures at planning: comparison; ratio analysis; reasonableness tests.

Performing the planning analytical review


 Auditor may use evidence such as client’s management accounts or draft accounts
 The auditor may calculate movements or common ratios to allow appropriate
analysis of the information
 Calculation can be carried out manually or through the application of audit
data analytics (ADAs)

Steps to perform:

1. Set an expectation
2. Compare the actual results to the expectation
3. Evaluate the results
4. Seek justification for the movement with a plausible explanation
5. Unexplained variances may create a potential audit risk

Tutor tip
In the AA assessment, if you are asked to perform planning analytical procedures, there
could be a variety of information sources provided within the scenario including
documents, notes or minutes from a meeting with the client. You should read through
this information carefully annotating anything that you think should be reflected in the
financial information. For example, if the scenario states that a new contract has been
entered into in the current year, you would expect revenue to increase against the prior
year as a result of that information.

Where you have identified scenario information that you expect to be reflected in the
financial information, you should focus on these areas first. For example, if you are told
that customer credit terms have been reduced, you could either calculate trade
receivables days, if not provided, or consider any analysis provided to confirm that this
is reflected.

You can then focus on any other movements or unusual/unexpected changes identified
from the results of the calculations.

In the AA assessment, you will likely be provided with information in relation to the client as
well as a summary of the results of the initial analytical review exercise. There may also
be a requirement to calculate your own expectation of a figure to complete the initial
analysis.

You should undertake an analysis of the rationale, where possible, of movements identified
during the analysis and identify and evaluate any potential audit risks. A common
mistake is to immediately assume there is an audit risk and fail to analyse the movement
using the information in the scenario. This analysis is the key element of an analytical
review and aids the auditor in informing their judgement over audit risk.

However, as noted it is important to consider if there are still any indicators of an audit risk, even if
the movement has been explained, and ensure this is included within your analysis.

1. Read the scenario, highlight key information and if required, create an expectation
using the information available.
2. Analyse the movements, attempting where possible, to explain the changes
using the information in the scenario.
3. Using the results of your analysis in Step 2, identify and evaluate potential audit
3
8
risks that would require further investigation by the audit team.

39
Audit materiality
 To express an opinion on whether the financial statements are true and fair, and
therefore free from material misstatement, the auditor must decide what qualifies
as ‘material’.
 Materiality is referred to throughout the audit and provides a basis for:
 Determining the nature, timing and extent of risk assessment procedures
 Identifying and assessing the risks of material misstatement
 Determining the nature, timing and extent of further audit procedures

Overall materiality
Materiality for the financial statements as a whole is often referred to as overall materiality.

Tutor tip
In your assessment, it is important to fully explain the decisions made when assessing
materiality. As materiality calculations are not prescribed and are subject to professional
judgement, the rationale behind calculations must be documented on the audit file.
Therefore, in an assessment, you should explain the reasons behind selecting the
benchmark, data and final materiality figure so that the marker can understand your
justification and award appropriate credit.

Setting overall materiality:

1. Select an appropriate benchmark - selecting an appropriate benchmark depends on


several factors, including:

a. The elements of the financial statements


b. Whether there are items on which the attention of the users of that
entity’s financial statements tend to be focused
c. The nature of the entity and the industry and environment that it operates in
d. The ownership structure and financing of the entity
e. The relative volatility of the benchmark
Benchmark Examples of entity measures are appropriate for
Profit before tax Profit-oriented entity in a standard industry, consistently
(from continuing operations) showing profit. Normally required for public interest
entities and listed entities.
Operating expenses Public sector entity providing services based on awarded budget
Revenue May be used for profit-oriented entities where there are
fluctuations in profit before tax and revenue is more
stable. Also may be relevant for not-for-profit entity that
has minimal profits or is loss- making
Total assets Property management company with value derived from asset
valuations/ entities funded primarily by debt
Net assets Investment trust company

4
0
2. Select the appropriate range to apply to the benchmark - the appropriate percentage is
based on the auditor's professional judgement. Examples of percentages applied to
different benchmarks include:

Benchmark Percentage
Profit before tax from continuing 5–10
operations
Operating expenses 0.5–2
Revenue 0.5–2
Total assets 0.5–2
Net assets 0.5–5

3. Select the data to be used to calculate materiality - the relevant data is dependent on
what is available to the auditor at the planning stage and what data the auditor
believes is the most representative of the expected actual financial statement
figures.

Data should be adjusted to show normalised figures. However, this should only be for
exceptional one-off items and not for items that recur each year, such as
amortisation of intangibles or due to a general change in trend.

4. Calculate materiality based on steps 1 – 3 - once the benchmark, data and percentage
range have been selected, the auditor can calculate the range from within which the
final materiality level can be calculated.

5. Select the final materiality figure from within the range - The final percentage selected
will depend on the risk within the entity. Where there is more risk, a lower level of
materiality should be selected. Considerations include:

a. Whether the entity is listed or a public interest entity


b. If it is a first-year audit
c. Any going concern issues
d. Any significant audit risks
e. Any material misstatements in the past
f. High fraud risk

Performance materiality
 Used to assess ROMM, design further audit procedures and determine sample sizes
 Lower than overall materiality to reduce the likelihood that total
immaterial undetected/uncorrected misstatements is material
 Calculation involves professional judgement, often 50 - 75% of overall materiality

Materiality should be revised throughout the audit.

41
Response to assessed ROMM
Once the auditor has assessed the risks of material misstatement, they are required to
respond to the risks that they have found.

This will impact the audit approach – how they are going to obtain evidence about these

risks. Response is dependent on whether ROMM at the assertion or FS level

Response to ROMM at the FS level

Fraud  Assigning experienced staff


 Considering appropriateness of accounting policies
 Incorporating an element of unpredictability in testing
 Increase level of professional scepticism
Control  Increase level of professional scepticism
weaknesses  Assigning experienced staff or experts
 Increasing supervision
 Incorporating additional unpredictability in testing procedures
 Performing more testing at year end
 Modifying procedures to provide more persuasive evidence
 Increasing level of substantive testing
Going concern  Ask management to make an assessment of significance of
events and impact on GC
 Evaluating management’s method
 Evaluating relevance and reliability of underlying data and
assumptions
 Evaluating plans for future actions
 Consider any facts or information since assessment
 Obtain written representations

Response to ROMM at the assertion level

 Responses at the assertion level require further audit procedures whose


nature, timing and extent are responsive to the ROMM at the assertion level.
 Appendix 2 ISA (UK) 240 provides details of specific tests that may be performed
in relation to fraud risks at the assertion level

Significant risks
The determination of significant risks allows for the auditor to focus more attention on
these risks and perform certain required responses. These include:
 Controls that address significant risks that should be evaluated
 Controls that address significant risks that should be tested in the current period
(when the auditor intends to rely on the operating effectiveness of such controls)
and substantive procedures need to be planned and performed that are
specifically responsive to the identified significant risk
 The auditor is required to obtain more persuasive audit evidence for these high-risk area
 Significant risks must be communicated to those charged with governance
 Timely review of audit documentation by the engagement partner at the
appropriate stages during the audit allows significant matters, including
significant risks, to be resolved on a timely basis to the engagement partner’s
satisfaction on or before the date of the auditor’s report

4
2
Tutor tip
Designing the audit approach for assertion level risks is less prescribed than financial
statement level risks as the approach must be tailored to the specific risk identified.

For some areas, such as related parties, fraud or laws and regulations, the ISAs provide
guidance on the audit approach where a ROMM exists.

Alternatively, for other assertion-level risks you should aim to include in your approach two
elements:

1. Management’s procedures and controls that the auditor would understand and test
2. A high-level substantive procedure that the auditor would undertake in relation to the risk
identified

You are planning the audit approach which will involve considering procedures at the
systems and controls, substantive testing and completion stage of the audit and,
therefore, your answer should cover the various stages of the audit.

If you are asked in the assessment to evaluate audit risks and design the corresponding
audit approach, you should keep this relatively high-level. Both substantive procedures
and controls will be considered in more detail later in the course.

Documentation: Planning
The objective of the auditor is to record of basis for auditor's report and evidence the audit
is planned and performed in accordance with ISAs (UK) and other regulations

Specific documentation requirements in other ISAs (UK)

 ISA (UK) 240: Decision from fraud risk discussion, fraud risks, controls, responses
to fraud risks, results of procedures, how inconsistencies addressed,
communication to management and revenue recognition justification
 ISA (UK) 300: Overall strategy, audit plan and any changes
 ISA (UK) 315: Team discussions, UTE, evaluation of controls, risks
 ISA (UK) 320: Overall, particular and performance materiality and any changes
 ISA (UK) 330: Responses to risks, results of additional procedures

Audit strategy memorandum


This is a summary of key planning information and commonly contains BSSMART:

 Background client information


 Systems and controls information
 Staffing and key client contacts
 Materiality
 Analytical procedure results
 Risk assessment findings and procedures planned in response
 Timetable

Communication with those charged with governance


Objectives of the auditor:

A. Communicate responsibilities, planned scope and timing


B. Obtain relevant information for the audit
C. Provide timely significant observations
D. Promote effective two-way communication

43
Matters to be communicated
Minimum to communicate at planning stage:

 Auditor’s responsibilities – engagement letter


 Planned scope and timing:
- How the auditor has addressed ROMM
- Internal controls approach
- Concept of the application of materiality
- Use of

experts The

communication process

 Inform TCWG of the form, timing and expected general content of communications
 Communication should be in writing if oral communication deemed insufficient
 Communications will reflect size and nature of the entity and the way TCWG operate

Assessment approach
It is important to understand that in AA, you will be required to apply your knowledge to the
information given in the scenario.

Active reading of the case and critical evaluation of each piece of information given in the
question is the main technique that needs to be applied while practising these
questions.

The key techniques to remember are:

For audit risk questions:

1. Read through the scenario, highlight the relevant facts that can result in audit risk
(ie increase the chances of fraud or error in the financial statements)
2. Think of the impact of each fact on the financial statements

Write the answer. Ensure your answer covers the facts and the financial statements impact.
Use headings to improve the layout of your answer.

For questions on responses to audit risk:

For each audit risk identified, you need to think of a suitable risk response.

Your risk response should depend on whether it is a financial statement-level risk or


assertion-level risk.

For responses at the assertion level you should consider if a specific ISA (UK) can provide
guidance or alternatively include in your approach two elements:

1. Management’s procedures and controls that the auditor would understand and test
2. A high-level substantive test that the auditor would undertake concerning the risk identified

For planning analytical review questions:

1. Read the scenario, highlight key information and if required, create an


expectation using the information available.
2. Analyse the movements, attempting where possible, to explain the changes using
the information in the scenario.
3. Using the results of your analysis in Step 2, identify and evaluate potential audit
risks that would require further investigation by the audit team.
4
4
For calculating overall materiality:

Remember to follow the five steps. They are:

Step 1: Select an appropriate


benchmark Step 2: Select the
appropriate range Step 3: Select
the data to be used
Step 4: Calculate the materiality range
Step 5: Select the final materiality figure from within the range

Conclusion
On completing this module, you can now attempt AAPQ 17.

Study guide checklist

Have you completed reading module 4?

Have you completed the skills checkers and skills builders?

Can you confidently complete the module learning outcomes listed on this module?

Can you confidently answer the guiding questions?

Have you completed the assessment practice questions?

Have you used the discussion board to ask questions on areas you are unsure about?

45
Module 5 – Specific risk areas and the
impact on the audit approach
Introduction
Welcome to the study guide for Module 5 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.

Syllabus Learning Outcomes


 Apply professional judgement and professional scepticism in conducting an
assurance engagement

Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:

 Evaluate the results of acceptance and planning procedures, including the use
of audit data analytics to assess and determine the risk of material
misstatement and impact on audit approach

This will be achieved by working towards the following performance indicators:

 Evaluate information on understanding the entity to identify risks of material


misstatements in relation to the auditing standards on laws and regulations,
related parties, service organisations, using the work of an expert and using the
work of internal audit
 Plan the approach to obtain sufficient appropriate audit evidence in relation to the
auditing standards on laws and regulations, related parties, service organisations,
using the work of an expert and using the work of internal audit

You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.

Here is a reminder of some key points to look at in this module.

4
6
1. Laws and regulations
Non-compliance may materially affect the financial statements through:

 Uncertainty over the going concern


 Fines or litigation that require adjustment or disclosure
 A breach of a required financial reporting

disclosure Compliance is the responsibility of

management, not auditors Two categories of laws and

regulations:

Direct effect Laws and regulations that have a direct effect on the
determination of material amounts and disclosures in the
financial statements.
The auditor's responsibility is to obtain sufficient appropriate
audit evidence regarding compliance with the provisions of
these laws and regulations.
Do not have a direct effect Other laws and regulations that do not have a direct effect
on the financial statements but compliance with which may
be fundamental to operations of the business or non-
compliance may result in material penalties or the entity
failing to continue in the foreseeable future.
The auditor’s responsibility is limited to undertaking specified
audit procedures to help identify non-compliance with those
laws and
regulations that may have a material effect on the financial
statements.

Audit procedures required:

Auditor's consideration of  Auditors must gain understanding of the legal and


compliance regulatory framework and how entity complies
 Enquire with management/ inspect correspondence with
relevant authorities
 Obtain written representations
 Remain alert
Audit procedures where  Understand situation
non-compliance is  If suspicions of money laundering, needs to be reported
identified to audit firm’s money laundering reporting officer
 Evaluate the possible effect of non-compliance on the
financial statements
 Discuss with management (unless prohibited by law)
 Evaluate the implications of non-compliance in relation
to other aspects of the audit

A number of entities will have very specific laws and regulations that the auditor needs
to be aware of as part of their understanding of the entity e.g. public sector bodies such
as local authorities.

47
2. Related parties
 ISA (UK) 550
 A related party is an individual or entity that is related to the entity that is
preparing its financial statements. A related party relationship in the
following situations:
 An individual (or close family) who controls or jointly controls an entity
 An individual (or close family) who has significant influence over an entity
 An individual (or close family) who is a key management personnel of an entity.
 All entities within the same group, or associates and joint ventures related to the
group.
 An entity and its pension plan.
 Two entities that are connected through an individual with control or significant
influence.
 An entity provides key management personnel services to another.
 Increased risk of material misstatement in FS if:
 There can be extensive and complex relationships and structures in place.
 Information systems may not effectively identify or summarise transactions
Related party transactions
 objectives
Auditor's Understand may not beparty
related conducted under normal market
relationships
terms and conditions (i.e. without exchange
 Recognise fraud risk factors of consideration).
 Conclude on fair presentation of FS
 Obtain evidence of correct identification and disclosure
of related parties
Audit procedures  The engagement team discussion considering the ROMM
due to related party relationships.
 Enquiring of management about related party relationships
 Understanding the controls over identifying,
accounting for, disclosing and authorising related
party transactions.
 Remaining alert for evidence of related parties throughout
the audit when inspecting records and documents.
 Inspecting bank and legal confirmations and board
minutes for evidence of related parties.
 Inspect income tax returns, shareholder registers,
records of the entity's investments, life insurance
policies, etc.
 Understanding related party transactions outside the
entity's normal course of business.
Risk assessment  Auditors to assess if identified related parties pose
significant risk The following would automatically be
significant risks:
 Significant related party transactions outside the
entity's normal course of business
 Fraud risk factors identified when understanding related
party relationships, including a related party with a
dominant influence.
Responses to risk of  If assessed risk is low:
material misstatement  Test whether these controls were operating effectively
 Perform substantive analytical review of the
transactions and balances
Other requirements:

 Written representations - obtain written representations that management has


disclosed to the auditor and accounted for and disclosed all related party
relationships and transactions in the financial statements.
 Communicate - with those charged with governance any significant matters in
relation to related parties.
 Document - the names of identified related parties and the nature of
related party relationships.

3. Estimates
 ISA (UK) 540
 A monetary amount for which the measurement, in accordance with the
requirements of the applicable financial reporting framework is subject to
estimation uncertainty
 Examples include provisions related to inventories and receivables, impairment
of intangible assets and valuation of financial instruments

Audit procedures There are various ways the auditor may obtain evidence, including:
 An evaluation of the process for preparing the accounting
estimate, including the selection of the method,
experience of the preparer, assumptions and data used.
 Audit of the calculation of management's point estimate.
 Review of the disclosures about the accounting estimate,
including disclosures about how the accounting estimate was
developed and the
nature, extent, and sources of estimation uncertainty.
Risk assessment Auditors must obtain an understanding of matters related to accounting
estimates, including:
 The entity’s environment and applicable financial reporting
framework (connected to inherent risk)
 The system of internal control (connected to control risk), which
includes:
 The client’s own risk assessment process
 Management experts and the use of specialised skills
 The entity’s information system
 How management reviews the outcome of past
estimates The likelihood and magnitude of potential
misstatement is impacted by:
 Estimation uncertainty - accounting estimates are an
approximation, and their measurement is uncertain. Higher
degree of estimation uncertainty will result in higher risk
 Subjectivity, including management bias – management uses
judgement when developing assumptions, interpreting data and
selecting measurement. The higher the level of subjectivity, the
greater the risk of material misstatement
 Complexity - determination of certain accounting estimates
can be complex if they require the use of methods or
models that require
specialised skills or knowledge in relation to their valuation.
Responses to risk of  Obtaining evidence from events occurring up the date of the
material auditor’s report - e.g. reviewing a post-year end event such as
misstatement settlement of a legal case
 Testing how management made the accounting estimate - includes
assessing if the method and assumptions are appropriate, the
data is relevant and reliable and if there are any indications of
management bias
 Developing the auditor’s point estimate or auditor’s range of
estimates – the auditor may form their own estimate to assess the
45
reasonableness of managements estimate

46
4. Service organisations
 ISA (UK) 402
 A service organisation is a third-party organisation that provides services to
user entities that are part of the financial reporting process e.g. payroll
processing
 A user entity is an entity that uses a service organisation whose financial
statements are being audited e.g. the audit client
 Auditor to understand how an entity uses a service organisation:
 Nature and significance of services
 Nature and materiality of accounts processed
 Interaction with/delegation to service organisation
 Contractual terms/service level agreements
 Auditor to evaluate design of controls audit client implements over service
organisation, including if necessary
 Report from service organisation's auditor
 Contact the service organisation
 Visit and perform test of controls
 Using another auditor

Auditor’s objectives  To obtain an understanding of the nature and significance of


the services provided by the service organisation and the effect
on the risk of material misstatement
 To design and perform audit procedures to respond to
those risks of material misstatement.
Risk assessment Determine whether sufficient, appropriate evidence is available from
records held at the user entity
Perform further audit procedures to obtain sufficient appropriate
audit evidence or use another auditor to perform those procedures at
the service organisation
Responses to risk  Tests of controls/ substantive testing at client
of material To obtain evidence that controls at service organisation operated
misstatement effectively:
 Report from service organisation's auditor
 Visit and perform test of controls
 Using another auditor to test controls – Type 1 or Type 2 report

Relying on the work of a service auditor

In order to rely on a service auditor’s report, the auditor must:

 be satisfied of service auditors competence/independence


 be satisfied of adequacy of standards used
 be satisfied that sufficient appropriate evidence over the design and operating
effectiveness
of service organisation’s control activities can be obtained

The auditor will not refer to the work of a service auditor in the audit report unless it is relevant
to the understanding of a modified audit opinion.

5. Using the work of an expert


 ISAs (UK) 500 and 620
 Employ someone with expert knowledge in an area other than audit and
accounting. May include valuation of certain assets, actuarial valuations or
impact of climate related risks
 Employed/contracted by:
 Client (management's expert) (ISA (UK) 500)
 Auditor (auditor's expert) (ISA (UK) 620)
47
Management’s expert

Specific audit procedures:

Evaluate the Consider:


competence,  Experience of the expert
capabilities and  Discussions with others familiar with the expert’s work
objectivity of that  Professional certification or membership of a professional
expert body or professional qualifications
 The use of technical standards by the expert
 The relevance of the expert’s field and familiarity with
applicable accounting standards
 Any threats to objectivity, such as personal and business
relationships, and corresponding safeguards
Understand the workConsider:
of the expert  Whether the expert's field has areas of speciality that are
relevant to the audit
 Whether standards or legal requirements apply
 What assumptions and methods are used by the management
expert and whether these are generally accepted for financial
reporting purposes
 The nature of the data or information the expert uses
Evaluate whether thatConsider:
expert's work is  The relevance and reasonableness of assumptions and methods
appropriate as used
audit evidence  Source data used and whether it is relevant, complete and
accurate
 The relevance and reasonableness of the expert's
findings and conclusions and their consistency with
other audit evidence

Considerations when using a management's expert

Nature/complexity of the matter Risk of material misstatement

Other available evidence Expert employed by entity being audited


Nature, scope and objectives of the Management ability to exert control/influence
management expert’s work over expert’s work
Expert bound by standards/requirements Controls within entity
Auditor’s knowledge/experience of area ofAudit team experience of area
expertise

Auditor’s expert

In determining the need for an auditor's expert consider:

 Have management used an expert


 Nature, significance, complexity of matter
 Risk of material misstatement
 Expected nature of

procedures Specific auditor's

procedures:

 Evaluate competence, capabilities and objectivity


 Understand field of expertise

48
 Agree work to be performed
 Evaluate adequacy of auditor's experts work
 Do not refer to expert in auditor's report

49
Tutor tip
You may receive information in the scenario about asset valuations, stock items that require
estimation, stage of completion for construction contracts, legal cases etc. These are
likely to be areas that are complex, judgemental or involve estimation and therefore
there is an audit risk that the amounts are misstated. The complexities arising from the
audit of accounting estimates were discussed in previous lessons. An appropriate audit
response may be to use an expert, in which case you will refer to ISA (UK) 500 Audit
Evidence or ISA (UK) 620 Using the Work of an Auditor’s Expert.

6. Using the work of internal audit (IA)


 ISA (UK) 610
 Direct assistance is prohibited in the UK. This is the use of the internal auditor
function to perform audit procedures under the direction, supervision and
review of the external auditor.

Auditor's objectives  Determine whether IA work performed can be used and if


so in what area and to what extent
 Determine whether the IA work is adequate for
purposes of the external audit
Audit planning The IA function should be assessed considering:
 Objectivity
 Technical competence
 Systematic and disciplined
approach Restrict use of IA where:
 High areas of judgement
 High risk of material misstatement for particular accounts
 Concerns over IA effectiveness
Timing and liaison  The extent of the use of internal audit must be agreed in
advance with management, the directors or the audit
committee, as appropriate.
 The testing and sampling methods to be carried out and
the documentation to be produced should all be agreed in
advance, as
should the timing of procedures and deadlines.
Procedures to determine  Making enquiries of internal audit staff
the adequacy of work  Observing procedures performed by the internal audit
of the internal audit function
function  Reviewing the internal audit function’s work
programme, working papers and reports
 Reperforming tests already performed by internal audit

Considerations for objectivity, competence and a systematic and disciplined approach include:

 The status of the internal audit function


 Whether internal auditors are free of conflicting responsibilities
 Constraints or restrictions on internal auditors
 Membership of internal auditors of relevant professional bodies
 Whether the internal audit function is adequately and appropriately resourced
based on the size of the entity and the nature of its operations
 Appropriate knowledge/training/qualifications
 Use of documented internal audit procedures or guidance
 Existence of quality control procedures on internal auditors’ work

50
Assessment approach
A scenario may indicate that particular laws and regulations are critical to the organisation.
These may include health and safety, terms of a licence, financial services and
environmental regulation. Where it is clear that a company is highly regulated and if
auditors become aware of any actual or suspected non-compliance, you should refer to
implications on audit work.

As with other audit risks, the relevant fact should be explained in terms of its impact on the
financial statements, e.g. going concern or unrecognised liabilities/judgemental
provisions and, if required, appropriate procedures should be designed in response to
the risk of material misstatement.

Within an audit risk and approach question, the scenario provided may include, for example,
the use of an accounting estimate, the use of an outsourced service provider, complex
related party relationships or management’s use of an expert. You should recognise
from the scenario that there is a specific auditing standard in relation to each of these
matters and refer to the requirements of the standard in preparing your answer.

You may also be asked to evaluate the strengths and weaknesses of an audit client’s
internal audit function and conclude on whether external auditors can rely on the work
of internal audit.

For questions related to relying on the work of others (experts and internal auditors in
particular), you’ll often be asked to conclude on whether reliance can be placed on their
work. It’s important to give that conclusion as it is awarded separate marks in the AA
assessment.

Conclusion
On completing this module, you can now attempt AAPQ 3.

Study guide checklist

Have you completed reading module 5?

Have you completed the skills checkers and skills builders?

Can you confidently complete the module learning outcomes listed on this module?

Can you confidently answer the guiding questions?

Have you completed the assessment practice questions?

Have you used the discussion board to ask questions on areas you are unsure about?

51
Module 6 – Internal Control Testing
Introduction
Welcome to the study guide for Module 6 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.

Syllabus Learning Outcomes


 Apply professional judgement and professional scepticism in conducting an
assurance engagement

Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:

 Evaluate business processes and the components of internal

control This will be achieved by working towards the following

performance indicators:

 Evaluate an entity's control environment and information systems


 Recommend actions, including relevant IT general and application controls,
that an entity should implement to rectify deficiencies in its control
environment and information systems
 Evaluate an internal audit function recommending improvements where applicable
 Document and evaluate the client's overall control and IT environment and
consider the impact on the audit approach
 Evaluate the design of key internal controls
 Design audit procedures, including the use of computer assisted audit
techniques and audit data analytics, to test the operating effectiveness of key
internal controls
 Plan an approach to the audit following the results of controls testing

You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.

Here is a reminder of some key points to look at in this module.

52
Systems and control analysis
The auditor's approach to evaluating and testing internal controls and the subsequent
impact on substantive testing:

Understanding and documenting internal controls


Components of internal control

1. Control environment
2. The entity’s risk assessment process
3. The entity’s process to monitor the system of internal control
4. The information system and communication and
5. Control activities.

Direct controls are controls that are precise enough to address risks of material
misstatement at the assertion level. The auditor is required to identify specific controls
in the control activities component, evaluate the design and determine whether the
controls have been implemented.

Indirect controls are controls that support direct controls. Having a strong control
environment is an indirect control. Understanding the indirect controls (i.e. the control
environment, the entity’s risk assessment process and its process for monitoring the
system of internal control) is important as it provides an overall foundation for the
operation of the other components of the system of internal control.

Categories of control activities

1. Authorisation and approvals


2. Reconciliations
3. Verification
4. Segregation of duties
5. Physical or logical controls

IT general controls (ITGCs) - apply to the whole computerised system.

Information processing controls (IPCs) - are specific to a given application and their
objectives are to ensure the completeness, existence and accuracy of the accounting
records and the validity of entries made in those records.

Understanding internal control

 The auditor must gain an understanding of control activities, even if not testing controls
 Includes understanding direct and indirect controls, the use of IT in internal
controls and identifying key controls

Key controls – relevant to preventing and detecting material misstatements in the


financial statements.

For each key control activity, the auditor:

 Evaluates the control, assessing whether it is designed effectively to


address the risk of material misstatement
 Obtains evidence to determine whether the control has been implemented
(that the control exists and that the entity is using it)

53
Documenting internal controls

The auditor can use:

 Narrative notes
 Flowcharts
 Checklists

Assess the design and operating effectiveness of controls


Evaluating the design of controls

 Consider if the procedure will be effective in achieving the stated objectives,


that is, whether the control is designed well
 The design indicates how good the control could be if consistently applied

Testing operation of controls

 The auditor must test whether the controls on which they plan to reply on
operated throughout the year
 Test operation throughout period – only effective if operates consistently
 Control testing techniques
 Enquire PLUS inspect/observe/reperform
 It is essential to test the control in operation throughout the whole period
under review, focusing on specifically higher-risk time periods to ensure
consistency in the control's application

CAATs and ADA

 CAATs and ADA are computer programs and data used to perform audit procedures
 Normally applied where large volume of information of highly automated
processes/controls
 Controls testing – test data and audit data analytics

Tutor tip
You may be asked to review the results of controls and system analysis carried out by ADAs
and evaluate their impact on audit risk and audit approach. You may be asked for
examples of CAATs or ADAs when identifying tests of control.

To identify relevant CAATs or ADAs, you may find it easier to firstly think about how you
would test this manually and then think about how you could use the techniques
described in this lesson to do the same test.

It’s important to remember that the objective of a sound internal control system over
financial reporting is to process the data (used to prepare the financial statements)
completely and accurately. You should therefore think about the risks (what could go
wrong) at each step of the process, from initiation of the transaction through to recording
in the individual ledgers and the general ledger. Once you identify the risk, you can think
of a control. Once you know the control, you can then think about how to test it either
manually or by CAATs/ADAs.

You will only get marks for control tests that are relevant and reliable. Therefore, enquiry on
its own will not be sufficient. You need to ensure that you use your judgement in
selecting either one test or a combination of tests that are sufficiently reliable.

To ensure that you are properly writing a test, and not documenting the control, try starting
the test procedures with the terminology of the techniques, for example, enquire,
observe, inspect and reperform. This will ensure you are writing what the auditor should
do to test the operating effectiveness of the control. A common mistake during exams is
54
to confuse the control with the test.

55
When writing the test, aim to include:

1. The technique (e.g. inspect)


2. The control you are looking at (eg sample of timesheets)
3. What you are looking for (eg department manager's signature to ensure hours
are reviewed and authorised)

The full procedure must be documented with appropriate detail to warrant marks being
awarded.

Evaluation of the results of controls testing


 If controls are operating effectively, auditors can reply on controls
 If not operating as expected, may seek to test compensating controls or increase
substantive testing
 A management letter should be sent to those charged with governance with
details of the control failure, weakness or absence
 Any significant deficiencies in a client's accounting and internal control systems,
and other matters including errors identified during the audit, must be reported
to management and those charged with governance promptly and in writing.

Timing of control activities testing


 Test controls throughout period under review (often at interim)
 Can rely on control tests from prior year audit in certain situations
 Where there is a significant risk of material misstatement, or where the auditor
places a high level of reliance on the control, the control should be re-tested
each year.

Steps for designing accounting information system


Step 1: Break the business process down into
phases Step 2: Consider the objectives for that
phase
Step 3: Decide on the relevant documentation for that phase
Step 4: Consider the risks that will prevent achievement of the
objectives Step 5: Design controls to address these risks

Sales system

Phase of sales cycle Possible controls


Customer places  Inventory availability should be checked for all orders before
order accepting so that customers can be made aware of any
potential delays.
 Orders should be approved before processing. Approval
limits should be in place based on value or bespoke
variations to orders.
 All new customers should be subject to a credit check before
being accepted and credit limits should be set. Master file
controls should be implemented on customer details file.
 Pro-forma sales order forms should be completed by
trained individuals in the sales team. Regular
exception reporting on sequencing of documentation
should be done.
 Prices should be automatically included on order forms based
on price listing. Master file controls should be in place around
the price listing.

56
Phase of sales cycle Possible controls
Order fulfilled and  Goods should only be despatched by trained staff. A regular
despatched exception report of goods despatched against sales orders
fulfilled should be reviewed by the warehouse manager.
 Customer should sign for delivery upon receipt, or other
evidence should be obtained, that items are delivered
(e.g., photo).
 Goods should be agreed to the sales order details before
despatch (or picking lists automatically generated based on
sales order details).
 Goods should be inspected by an independent member of
staff before despatch, agreeing details to the sales order with
quality checks in place.
 All processed sales orders should be matched to goods
despatch notes (GDNs) when fulfilled. Regular exception
reporting on unfulfilled orders should be carried out and
followed up.
 Completed orders should be presented to customers for
approval (for example, confirmation email).
Customer invoiced  Once an invoice is raised, the corresponding GDN is
for goods and marked as ‘invoiced’ in the system. A regular review of
customer pays for unmarked (un-invoiced) GDNs should be performed.
goods  ‘Three-way-match’ control. Invoices should be agreed to
sales orders and GDNs before posting and processing.
 Sequentially pre-numbered, pro-forma invoices should be
completed by trained individuals. Regular sequence checks
should be performed.
 GDNs should be marked in the system as invoiced.
Invoices should not be raised unless they are matched to
an order and a GDN. The system should not allow a second
invoice to be raised for a single GDN.
 Bank reconciliations should be performed monthly by
trained staff, with reconciling items followed up and
investigated.
 Access to online bank accounts should be restricted
through passwords and all cash should be kept in a
locked safe.
 Regular reviews should be performed of outstanding unpaid
invoices, with the credit control team responsible for
following up with the customer.
 Monthly customer statements should be sent to all
customers, with outstanding balances at the month end.
Customers should be asked to inform the client if they
disagree with the balance.
 Monthly reconciliation should be performed between the
debtors ledger and general ledger. Reconciling items
should be investigated and followed up.
 Invoices should include a unique reference that must be
referenced alongside payment. Payments should be matched
to the invoice using
the reference when received.
Overall  Management review of budgets versus actual as part of the
monthly management accounts review.
 Relevant segregation of duties at each stage of the sales
cycle. For example, recording of sales, maintaining customer
accounts and preparing statements should be performed by
different individuals. Despatching goods, recording sales,
recording cash received and following up outstanding
balances (credit control) should be performed
by different individuals.

57
Tutor tip
If asked to assess an organisation’s sales system (either as an external or internal
auditor), the omission of one of the controls discussed previously from that system does
not necessarily indicate there is a weakness. There may be other
mitigating/compensating controls in place, or the uncontrolled risk may be minimal and
therefore the cost of the control would outweigh the benefit.

58
Therefore, you should focus on the specific issues identified in the scenario such as: a
poorly designed control; a control that is not operating effectively; or where the impact
of a missing control has been specifically raised.

A common way of testing students' knowledge of internal control in the assessment


involves evaluation of an existing information system. You may be presented with a
scenario where a specific information system is described and you are expected to
appraise it by:

a) Identifying facts from the scenario which result in weaknesses in the system; these
may arise due to:
i. Poorly designed controls
ii. Controls that are not operating
iii. (Gaps where there are no controls to manage risk

b) Evaluating why each of these facts is a weakness, that is, what is the implication to the
business?

c) Advising on the relevant control activities that could be implemented to


mitigate/reduce the risk – providing a recommendation. Remember, such
recommendations are communicated to the management through the management
letter.

Purchases system
Additional controls may be required if an organisation makes upfront payments for raw
material purchases:

Phase of purchases Possible controls


cycle
Place order  Perform a credit check on the supplier to reduce the risk that
payment is made and no goods are received due to the
supplier organisation failing.
 Have an approved supplier list to ensure risk of delays or
receiving poor quality material is minimised. Quality issues
which could have a knock-on impact on the quality of the
product sent to the entity’s
customers.
Invoice received  Invoice is only recognised if supported by an authorised
purchase order and supplier confirmation. (No longer
matching to goods received note (GRN) as goods have
not yet been received.)
 Authorisation of invoices with no GRN by manager prior to
processing.
Payment of goods  The controls would be the same as for the main credit
purchases cycle, except where the payment is being
reviewed to ensure that it is genuine as the invoice would
not have been agreed to a GRN. Therefore, increased
authorisation levels should be introduced for
upfront payments.
Receive goods  Match of paid invoices to GRNs once goods are received. A
regular exception report is produced to highlight
unmatched orders. This would help identify prepaid assets
as well.

59
Non-current assets system

Objective Possible controls


All non-current  Maintain a FAR recording all assets acquired.
assets acquired are  When orders are raised, these are coded by the user
identified as an department as an expense or an asset. The coding is
asset reviewed by the user department manager and the
accounts department.
 Policies regarding asset capitalisation are
documented and communicated to staff.
 Require all orders above a defined threshold to be sent to
the officer responsible for maintaining the FAR, on a timely
basis. This will allow assessment of whether these
purchases relate to assets.
 Capital expenditure recorded in the financial ledger is
reviewed on a regular basis to ensure expenses are not
capitalised inappropriately.
Non-current assets  Asset details recorded on the FAR are comprehensive and
are accurately uniquely described to allow identification.
recorded in the FAR  Asset counts are conducted over a pre-determined
and the general period and compared to the asset descriptions on the
ledger FAR.
 The classification of non-current assets is regularly
reviewed by the finance manager for unusual items.
 The value of the non-current assets recorded on the FAR is
regularly reconciled to the nominal ledger on a timely basis.
 Non-current assets are capitalised in line with formal policies.
 A policy is documented and communicated concerning the
useful lives that should be used for non-current assets.
 An expert revalues and assesses the remaining useful lives
of land and buildings in accordance with the requirements
of the accounting standards.
 Staff associated with asset management have been
adequately trained.
 A reasonableness test is applied to the depreciation
charges on a regular/monthly basis to ensure that the
charges are in line with the depreciation policy.
 Additions reports are reviewed by the finance manager on a
monthly
basis to ensure the amounts recorded are accurate, assets
have been classified correctly and the correct depreciation
rates have been used.
All non-current  Procedures are documented, requiring user departments to
asset disposals and complete asset disposal forms which are authorised and sent
transfers are to the non-current asset clerk.
identified and the  Disposal of obsolete or surplus assets is authorised by
FAR amended only a few named officers.
 Fully depreciated assets are reviewed regularly to confirm
they are still in use.
 Perform a review of transactions within ‘other income’ and
similar accounts, to identify possible mispostings of
proceeds of disposals.
Senior officers  Senior departmental officers responsible for the proper
are responsible management of non-current assets regularly receive and
for monitoring review details of departmental depreciation charges and
the non-current assets.
effectiveness,  Regular review of assets for indicators of impairment
cost efficiency with timely amendment to accounting records where
and operational impairment is detected.
use of assets  Gains or losses made on disposal of non-current assets are
monitored as an indication that assets' useful lives may be
60
inaccurate.
 Procedures and policies are established regarding the use
of assets within the company to ensure their use is
efficient.

61
Payroll system

Objective Possible controls


Phase 1: Engagement/ termination of employees and maintenance of master data (HR)
Only genuine  All new employees must complete a new employee form
employees of the (including personal details) and have that form approved by
organisation are the department manager and HR manager. This form is the
included and, basis of input to the master file. Segregation of duties
therefore, paid. between hiring, processing and payments of wages and
salaries is a key control for reducing the risk of fake
employees.
 Review of departmental headcount reports compared to
master file records.
Joiners/ leavers  Confirmation from the HR manager to the department
must be added/ manager on receipt of the new employee form and upload
removed from the to the master file, with regular follow up by the department
system in a timely manager for any unprocessed new employees.
manner.  Proforma for joiners/leavers signed by the department
manager and sent to the HR manager, with relevant
start/leaving dates.
 Edit reports (i.e. the list of changes and edits) automatically
generated monthly and reviewed and followed up by the HR
manager against
joiner/leaver confirmations.
The security of  Master file controls should be in place over the HR master
payroll data is file. For example, one-to-one checking of payroll master
adequately files to individual employee personal files can be done on
maintained. a regular basis.
 Similarly, all changes to an employee's personal details which
are
usually contained on a master file must be done in writing
and approved by both the employee and the line manager.
Phase 2: Work done and time recorded (production department)
Only genuine work  Any hours or overtime worked should be recorded through a
done (including timesheet system (can be automated through employees
overtime) is clocking in/ out electronically). Hours/ overtime should then
recorded. be approved by the department manager.
 Actual vs budget comparisons of hours by department
manager.
Work done is  Employee hours recorded are reviewed on a daily basis by
recorded accurately. the department supervisor who undertakes a
reasonableness check of hours worked, e.g. comparison of
actual to budget.
 Automating the system of clocking in/ out where possible
to avoid errors in recording or intentional manipulation.
Phase 3: Calculation of payroll liability (payroll department)
The payroll run is  Data is sourced from payroll master files on pay rates,
calculated deductions etc. and approved hours worked. Payroll is
correctly with calculated by trained staff and is subject to review by the
respect to both payroll manager.
employee  System-generated exception reports are reviewed by payroll
payments and staff and investigated for reasonableness. These are a key
tax liabilities. control if set up correctly as they can identify instances such
as where an employee’s salary has increased by more than a
pre-decided percentage, or if two employees have the same
bank account, for example (indicating a
possible fictitious employee).
Payroll expense and  Payroll reconciliation between the payroll listing and
liabilities are nominal ledger, performed monthly, with reconciling items
followed up. The reconciliation should be reviewed.
62
recorded correctly.  Review and authorisation of payroll journals before
posting. Access control for posting of journals should be
limited to senior authorised officials only.

63
Objective Possible controls
Phase 4: Payment of payroll liability (payroll department /accounts department)
Payroll payment is  BACS transfer document is downloaded from the payroll
accurate and system and reconciled to the payroll listing by the payroll
authorised. staff. Documents are signed to provide evidence of review.
 The director signs a copy of the BACS transfer form as
evidence of their approval, after agreement to supporting
documentation.
 The BACS confirmation is reviewed and reconciled to
the BACS transfer file on receipt.
No duplicate  Payroll listing marked as ‘paid’ once payment is made. The
payments are made. system will not allow payments to be processed twice.

Payment to HMRC  Payroll calendar completed, including all relevant deadlines


and employees is available to all payroll staff.
on time.

Outsourcing payroll

Many organisations outsource their payroll to a service provider that calculates payroll
based on information provided by the company.

While this third party is completing some of the process on behalf of the organisation,
the organisation should have controls in place to ensure:

1. Information passed to the service provider is accurate, valid and complete


2. Processed information received from the service organisation is correct and appropriate

Inventory system

64
Inventory counts

 Considered a key control over the completeness and existence of inventory records
 Where inventory is material, auditor must obtain evidence over existence and condition
 ISA (UK) 501 – Evidence over stock gained by:
 Attending stock counts
 Testing if final stock records reflect count

Perpetual inventory counting

For some organisations, there may be factors, such as resource availability, which impact
the feasibility of performing a full year-end count. In such instances, a business may
perform perpetual inventory counting, where samples of inventory are counted on a
regular basis, with system figures being amended to reflect the physical count figures in
real time.

Attendance at inventory counts

 Auditor needs to plan the timing of visits, locations to be visited and


extent of test counts/procedures. Includes consideration of:
 Risk of material misstatement (ROMM) of inventory
 Nature of internal control related to inventory
 Whether adequate procedures are expected to be established and proper instructions
issued for physical inventory counting
 Whether the entity maintains a perpetual inventory system
 The locations at which inventory is held
 Materiality of inventory at different locations
 Whether an expert is needed to help with measurement of the inventory
 The results of any internal audit findings
 Consider if there is any consignment stock held by the client
 During attendance at inventory count, the auditor must:
 Evaluate management’s procedures for recording and controlling the results
of physical inventory counting
 Observe performance
 Inspect stock
 Perform test counts

After attending the inventory count

After the inventory count, auditors will follow up the counts attended to compare
quantities counted by them with the inventory records, obtaining and verifying
explanations for any differences, and checking that the client has reconciled count
records with the accounting records.

Perpetual inventory counting

 Where client performs perpetual counts, auditor should attend one or more counts
 Review procedures/controls used during the year
 Perform tests of control
 If counts produce differences, auditor should consider asking client to perform a
full year end count

65
Tutor tip
You will need to know the standard procedures for attending an inventory count. For a given
scenario, you will be expected to apply relevant procedures and tests of control. For
example, if it is a perpetual inventory count, you will need to consider the normal tests
performed for attendance at an inventory count, as well as the other tests over
controlling the perpetual counts and assessing effectiveness.
You may be given specific problems at the count and would be expected to tailor general
procedures to these specific circumstances.

Controls over inventory counts are basic audit procedures that are common across many
audits and, therefore, should be known in detail.

Internal audit
Evaluating the internal audit function

1. The internal audit process – preparation of the plan; the internal audit report; follow up actions
2. The role of the audit committee – includes monitoring and reviewing the
effectiveness of the company’s internal audit function
3. Resource and competence – expect internal audit manager to be qualified,
experienced and a member of the Institute of Internal Auditors
4. Independence – reporting to the audit committee; audit plan approval; internal
audit manager appointment; remuneration; no operational involvement; position
and status
5. Quality assurance – adherence to standards; external review

Tutor tip
An assessment question may require you to recommend specific types of internal audit
reviews that the internal audit department could carry out. When asked for specific
reviews, it is important to utilise the information in the scenario, as well as any other
requirements attempted, to ensure you recommend reviews that are relevant.

For example, if you have been required to evaluate a specific process within the question,
eg payroll, and provide recommendations, the internal audit department could carry out
a follow up of the implementation of these recommendations by management.

Assessment approach
For questions on controls where the auditor may test operating effectiveness

To identify controls which are relevant to the auditor, you should think about whether the
control is useful in preventing or detecting material misstatements, and whether the
control is designed effectively.

When designing a test of control, remember to include the following:

1. A technique (e.g. inspect)


2. The control you are looking at (e.g. sample of timesheets)
3. What you are looking for (e.g. the department manager’s signature to
provide evidence that hours are reviewed and authorised)

66
For questions on control weaknesses

You may be asked to identify a control weakness, explain the implication of this and
suggest a recommendation to improve the control.

Step 1: Start by identifying facts from the scenario which indicate a control weakness.
Highlight the facts as you read through the case.

Step 2: Once identified, you need to explain ‘why’ it is a weakness (i.e. what implication
could that weakness have for the business and the financial reporting process).

Step 3: Recommend a control that can reduce the risks.

Conclusion
On completing this module, you can now attempt AAPQ 6, 14 and 19.

Study guide checklist

Have you completed reading module 6?

Have you completed the skills checkers and skills builders?

Can you confidently complete the module learning outcomes listed on this module?

Can you confidently answer the guiding questions?

Have you completed the assessment practice questions?

Have you used the discussion board to ask questions on areas you are unsure about?

67
Module 7 – Substantive Analytical Procedures
Introduction
Welcome to the study guide for Module 7 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.

Syllabus Learning Outcomes


 Apply professional judgement and professional scepticism in conducting an
assurance engagement

Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:

 Design substantive procedures including substantive analytical procedures and


tests of detail, incorporating the use of data analytics, and conclude based on
evidence received.

This will be achieved by working towards the following performance indicators:

 Design substantive analytical procedures, including audit data analytics.


 Evaluate the findings from substantive analytical procedures, including audit
data analytics, and determine the items to be followed up.

You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.

Here is a reminder of some key points to look at in this module.

68
Evidence gathering techniques
1. Analytical procedures: This is an evaluation of financial information by a comparison
of financial and non-financial data and the investigation of significant differences and
relationships which are inconsistent with other information. The level of assurance
that can be gained from performing analytical procedures varies as it depends on the
effectiveness of underlying controls and the integrity and completeness of data.
2. Enquiry: This means seeking information from those within or outside the entity.
The level of assurance is low as this can be subjective and is therefore normally
insufficient on its own.
3. Inspection: This is the examination of records, documents and tangible assets.
The level of assurance depends on the effectiveness of controls in place to
generate the information being inspected.
4. Recalculation: This involves verifying the arithmetical accuracy of documents or
records. The level of assurance is generally high as these procedures are normally
performed under the control of the auditor.
5. Confirmation: This involves obtaining representations directly from a third party. In
terms of level of assurance, generally, evidence from an independent knowledgeable
third party is more reliable than that from a source closely connected to the audited
entity.

Types of substantive analytical procedure


 Comparison
 Ratio analysis
 Reasonableness test (proof in total)
 Trend analysis
 Large and unusual items

review Stages for analytical

procedures

 Forming an expectation
 Comparing the expectation to the actual results
 Investigating and corroborating any significant variance
 Concluding whether sufficient appropriate evidence has been obtained

You will be expected to APPLY the above steps to a given scenario in the AA assessment.

Factors to consider when designing and performing substantive


analytical procedures:
1. The suitability of particular analytical procedures for given assertations –
substantive analytical procedures are generally more applicable to large volumes of
transactions that tend to be predictable over time.

2. The reliability of underlying data - consider:


 The source of data
 The comparability of data
 The nature and relevance of data
 The operating effectiveness of the controls over the preparation of internally produced
data.
 Prior year knowledge and understanding

3. Developing an expectation – must be sufficiently precise to identify a material


misstatement. Consider:
 The accuracy with which the expected results of substantive analytical
procedures can be predicted.
69
 The degree to which information can be disaggregated.
 The availability of reliable information, both financial and non-financial

70
4. Information that auditors may use to form an expectation includes:
 Management accounts
 Prior year information adjusted for current year trends
 Known interaction between financial data
 Known interaction between financial and non-financial data
 Discussions with management

5. Determining the amount of difference from the expectation that can be accepted
without further investigation
 Threshold or tolerable error is set using auditor judgement
 The auditor's determination of the amount of difference from the
expectation that can be accepted without further investigation is influenced
by materiality

The auditor will then follow up any significant differences between the expectation and the
actual balance.

Assessment approach
The recommended answering technique is as follows:

Step 1: Read the scenario carefully and form an expectation.


Step 2: Compare the expectation to the actual results given in the
scenario. Step 3: Conclude on which balances require further
investigation.
Step 4: Conclude on whether sufficient appropriate evidence was obtained. You should note
that, although not required in this question, if the conclusion is that sufficient
appropriate evidence has not been obtained, further procedures will need to be
performed.

Use of CAATs and ADA in substantive testing


Examples of using ADA at the substantive testing phase include:
 Detailed recalculations of depreciation on fixed assets by item, either using
approximations (such as assuming sales and purchases are mid-month) or using
the entire data set and exact dates.
 Analysis of capital expenditure versus repairs and maintenance expenditure.
 Inventory ageing to evaluate how many days inventory is in stock by item. This
would help in valuing inventory.
 Receivables ageing and evaluation of overdue debt over time (customer-wise).
 Analysis of revenue trends split by product or region.
 Analysis of gross margins and sales, highlighting items with reducing or negative
margins.

CAATs and ADA can be used for collecting and analysing audit evidence as part of
substantive testing.

The tests performed are commonly summarised as:

1. Sample selection
 Selection of manual journals for testing from criteria established by the auditor.
 Sample selection – statistical sampling, where there are large volumes of data,
or key item sample selection, where items are selected based on meeting
particular criteria such as size or customer code.
2. Summarisation
 Supporting substantive analytical procedures
 Analytical review and analysis/disaggregation of data
 Analysing contracts for key areas of consideration or terms.
 Manipulating data to assess the impact on different assumptions (derivatives

71
valuation or impairment modelling).

72
3. Computation/recalculation
 Recalculation of fixed asset depreciation using records of assets held,
additions and disposals.
 Recalculating the VAT portion of revenue to ensure it has been removed correctly.
 Casting schedules.
4. Re-performance
 Reperform debtors ageing to confirm accuracy of the ageing report as this
will be used to calculate the bad debt provision and to select a sample of
overdue debtors for testing.
 Ensure that payments were made only to real employees by checking their
employee card details against information in their personnel files.
 Comparing entity data to externally obtained data, for example, bank account balances.
 Comparing valuations of investments in other entities/financial instruments
etc to external third-party sources.

Tutor tip
These tests can be used as a prompt to be more creative when designing different types of
tests, and to consider whether too many of the same type have been used. You should
always try to use specific analytical procedures as well as other tests.

Practical application of CAATs and ADA


The auditor will perform procedures over the data to be used, including checks over its
completeness, accuracy and validity.

These will be performed over data input into the auditor’s software as well as the outputs
produced by the ADA.

Conclusion
On completing this module, you can now attempt AAPQ 1 and 22.

Study guide checklist

Have you completed reading module 7?

Have you completed the skills checkers and skills builders?

Can you confidently complete the module learning outcomes listed on this module?

Can you confidently answer the guiding questions?

Have you completed the assessment practice questions?

Have you used the discussion board to ask questions on areas you are unsure about?

73
Module 8 – Substantive Procedures – Part 2
Introduction
Welcome to the study guide for Module 8 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.

Syllabus Learning Outcomes


 Apply professional judgement and professional scepticism in conducting an
assurance engagement

Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:

 Design substantive procedures including substantive analytical procedures and


tests of detail, incorporating the use of data analytics, and conclude based on
evidence received

This will be achieved by working towards the following performance indicators:

 Design and evaluate substantive testing audit work programmes


 Design tests of detail, including computer assisted audit techniques (CAATs)
and audit data analytics (ADAs)
 Design tailored substantive procedures in response to findings arising during the audit
process

You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.

Here is a reminder of some key points to look at in this module.

74
Tests of detail
A test of detail involves testing specific items within a population. Should be written using the
format:

Verb Population Evidence Activity

Verb – refers to the testing technique to be used in the substantive procedure. The
techniques that may be applied to tests of details are:

 Enquiry
 Inspection
 Recalculation
 Confirmation

Source evidence – must be reliable and relevant. Can include documents, physical items,
calculations or discussions with management or other third parties.

Activity – describes what the auditor is going to use the evidence for and look for to
confirm the items selected for testing.

Substantive testing techniques

 Substantive analytical procedures (module 7),


 Enquiry
 Inspection
 Recalculation
 Confirmation

Can use Computer Assisted Audit Techniques (CAATs) and Audit Data Analytics (ADAs)

Designing a substantive testing programme


Use the six-step approach:

1. Risk of material misstatement (ROMM)


 Should refer to audit risk assessment performed in planning
 Consider key assertions
 For accounts with low ROMM, the auditor may only perform substantive analytical
procedures
 For accounts with higher ROMM< the auditor will carry out tests of details

2. Approach
 Can test movements which have given risk to the balance
 Can test closing balances directly

3. Accounting policies – need to understand:


 The requirements of the accounting standards in relation to a particular account
 The accounting policies applied by the audited entity in calculating the figure
 The entity and its operations (understanding gained during audit planning) to
assess whether the policies are appropriate and to identify all aspects of the
accounting standards to consider.

4. Assertions
 Must cover all relevant assertions

75
Account balances and related disclosures Classes of transactions and related disclosures
Existence (E) Occurrence (O)
Rights and obligations (R&O) Completeness (C)
Completeness (C) Accuracy (A)
Accuracy, valuation and allocation (AVA) Cut-off (CO)
Classification (Cl) Classification (Cl)
Presentation (P) Presentation (P)

 Some assertions are higher risk than others for particular accounts:

Account type Key assertions Reason higher risk


Assets Existence Accuracy,The key risk in relation to assets is overstatement, to
Valuation show a larger net asset position on the balance
sheet. Therefore, there is a higher risk that
and Allocation
management will include assets that do not exist or
(AVA)
include assets at an amount above fair value.
Liabilities Completeness The key risk in relation to liabilities is understatement,
to show a larger net asset position on the balance
sheet. Therefore, there is a higher risk that
management will not include all liabilities (i.e.
liabilities will be incomplete).
Transactions Cut-off The key risk in relation to transactions is overstatement
Occurrence of revenue (and other credit transactions) and
understatement of expenses (and other debit
(credit transactions)
transactions, to show a larger profit). Therefore, there
Completeness is a higher risk that transactions will not be recorded
(debit in the correct period, will be falsely included (credit
transactions) transactions), or incorrectly omitted (debit
transactions).

5. Common procedures
 Commonly undertaken for that account balance

6. Standard tests
 The auditor should perform some standard procedures to confirm that the
schedule/sub-ledger is appropriate as a basis for gathering audit evidence

Standard test Work required


Opening balances Agree to prior year audited financial statements.
 Note for profit and loss accounts the opening balance
should be 0.
 Where it is the first year an auditor is performing the audit,
additional procedures will be performed on opening
balances to confirm these
are correct. These will be covered later in the module.
Cast schedules Cast (add) supporting schedules to test their accuracy.
Closing balance: TB to FSConfirm that the closing balance of the supporting schedules
agrees with the trial balance and final financial statements.

76
Specific accounts and considerations
Plant, property and equipment

1. ROMM
 A key focus for PPE is often valuation due to complexity and judgement
 Higher ROMM assertions - AVA

2. Approach – test the movements


 Additions
 Disposals
 Depreciation
 Revaluations
 Impairments
 Also consider leased assets and ‘Own Work Capitalised’

3. Accounting policies
 The cost includes its purchase price, import duties, non-refundable VAT, and
costs directly attributable to bringing the asset to the final location and
condition and is net of discounts or refunds.
 Annually, the value is measured at cost less accumulated depreciation and
accumulated impairment losses.
 Where revaluations take place, these should be made with sufficient regularity
and include all items within the same class of assets.
 Where there are indicators of impairment, an impairment review should be carried out

4. Assertions – R&O, E, C, Cl, AVA, P

5. Common procedures

Areas for testing Assertions Explanation


Physical verification E, C Physically verify a sample of assets on the PPE
(sheet-to-floor and register to confirm they exist and agree a
floor- to-sheet) sample of assets inspected to the PPE register to
agree the PPE register is complete.
Repairs and C, Cl Inspect a breakdown of the repairs and
maintenance review maintenance charges incurred in the period to
identify any items expensed in error. Trace to
purchase invoice to confirm the nature of the
expense.
Depreciation AVA Calculate an expectation of the depreciation
reasonableness expense of each category of PPE based on the
test depreciation policy. Compare to actual
depreciation expense and investigate major
differences.
ADAs may be used for complex depreciation
calculations.

6. Standard tests
 Agree brought forward balances to last year's audited accounts
 Cast and cross-cast the PPE movement summary and underlying asset listings using
CAATs
 Verify PPE is disclosed in accordance with IAS 16 Property, Plant and
Equipment via a disclosure checklist
 Verify that accounting policies are reasonable, and consistent year on year
and outline all accounting standards
 Agree on the PPE register or PPE movement schedule to the trial balance
and financial statements

77
Tutor tip
In the assessment, you will not necessarily be required to prepare an audit work programme
but may just be asked to prepare a list of tests or procedures. In this case, you would not
be required to list the assertion for each test.

However, it is fundamental that you understand the assertions relevant to each test and so
it is good practice to include this in your studies.

Trade and other receivables

Trade receivables, Other receivables, prepayments and accrued income, employee loans

1. ROMM
 A profit making entity will want to present a strong balance sheet and may overstate
assets
 Higher ROMM assertions - E, AVA

2. Approach – test the closing balance


 Due to high volume of movements

3. Accounting policies – trade receivables should only be recorded as an asset if it is


believed that the balance will be recoverable. Accounting impacted by:
 Invoice raised on dispatch of goods
 Cash received
 Provisions/write-down
 Discounts
 Credit notes
 Foreign currency translation

4. Assertions – R&O, E, C, Cl, AVA, P

5. Common procedures
 Performing a trade receivables circularisation
 Subsequent cash testing
 Testing the allowance for doubtful debts

Testing allowance for doubtful debts

Procedures
 Review of aged trade receivables report
 Reasonableness of policy relating to the allowance for doubtful debt
 Post-year-end credit notes
 Subsequent cash testing

Other receivables

An audited entity’s financial statements will normally include other receivables such as
prepayments and accrued income and employee loans.

These will normally be tested through:

 Substantive analytical procedures


 Agreeing to supporting documentation (eg invoices and funding documentation)
 Reviewing subsequent events

78
Inventory

1. ROMM
 A profit making entity will want to present a strong balance sheet and may overstate
assets
 Higher ROMM assertions - E, AVA

2. Approach – test the closing balance


 Must gain assurance over the quantity and value

3. Accounting policies – inventory must be measured at the lower of cost and net
realisable value (NRV). Consider:
 quantity of inventory held
 components of inventory
 whether inventory valuation complies with IAS 2
 NRV

4. Assertions – R&O, E, C, Cl, AVA, P

5. Common procedures
 Follow-up tests performed at the inventory count
 Cut-off testing
 Cost vs. NRV testing
 Testing the inventory provision

Cost vs NRV – auditor must test both cost and NRV. Be alert to situations such as:

 Product line was replaced by another model


 Poor quality/ damaged/faulty inventory
 Changes in legislation that render a product unusable or increase production costs
 Obsolescence (ie technical innovation)
 Management decision to reduce pricing to remain competitive
 Adverse exchange rate movements
 Poor inventories management
 Reduction in sales volumes, requiring sales prices to be discounted

Testing the inventory provision

 Inventory provision is often prepared using an aged inventory listing


 Auditor can identify items at risk of obsolescence and use this as a basis to
assess whether the provision is reasonable
 Size and method to calculate the provision should be compared to previous
periods for reasonableness

Tutor tip
As well as designing procedures yourself in an assessment, you could be asked to evaluate
procedures that have already been prepared by another member of the team. You
should consider whether the procedures detailed:

 are reliable
 address all the relevant risks and assertions, or whether items are missing
 can be followed by another member of the team, or whether more detail
is required (remember verb, population, evidence, activity)
 include all evidence available

79
Investments

1. ROMM
 Main risks are around valuation and presentation (long-term)
 Higher ROMM assertions - AVA, P

2. Approach – test the movements, but also assess valuation of closing balance
 Additions
 Disposals
 Valuations
 Impairments

3. Accounting policies
 Need to be recorded at fair value (may be estimates for unlisted investments)

4. Assertions – R&O, E, C, Cl, AVA, P

5. Common procedures – no specific common

procedures Some example substantive tests of details

for investments are:

Procedure Assertion(s) tested


For a sample of investment additions taken from the investment listing, AVA, E, Cl, R&O
agree these to board minutes, third-party confirmations and other
supporting documentation to confirm that the amount recognised is
correct (AVA), that the transaction actually happened (E), that they
are owned by the company (R&O) and that they have been
classified correctly within the listing as either listed or unlisted
investments. (Cl)
Select a sample of share certificates (or other investment records)
held by the entity and vouch to the investment listing to verify that
these have been included
Review board minutes for evidence of disposals or additions of E, C
investments and agree that they have been removed from or added
to the investment listing as appropriate.
For a sample of disposals taken from the investment listing, agree cash
C, AVA
receipts to the bank statement and the number of shares sold to
sale documentation to verify that the number of shares recorded as
disposed of is accurate and that the disposal took place.
Select a sample of investments from the investment listing and enquire P, CL
of management about the purpose of these investments and their
intent to hold the investment for more than 12 months. Confirm this
by inspecting board minutes for evidence of intent regarding these
investments.
Inspect management’s investment impairment indicator assessment AVA
and consider if this is in line with the auditor’s understanding. Where
impairment indicators/triggers are noted, obtain managements
impairment calculation, review the underlying assumptions for
reasonability and re-perform the calculation for accuracy.
Verify share prices of listed investments held at year-end per theAVA
investment listing, to a reputable third-party source to confirm
that the value is accurate in the financial statements.
For a sample of unlisted investments taken from the investment listing,
AVA
consider the reasonableness of the valuation per share by reviewing
the accounts of the investee company to assess whether the
carrying value should be written down.
80
Bank and cash

1. ROMM
 Will depend on nature of audited entity
 Consider susceptibility to theft, volume of bank accounts, incorrect netting of overdrafts
 Higher ROMM assertions - E, C, P

2. Approach – test the closing balance


 Obtain third-party evidence from audited entity’s bank

3. Accounting policies
 Any right of set-off

4. Assertions – R&O, E, C, Cl, AVA, P

5. Common procedures
 Testing the year-end bank reconciliation
 Testing the bank confirmation letter
 Physical verification of material cash balances
 Verifying foreign currency rates used for FX accounts to independent
sources, and recalculating the translation

Current and non-current liabilities

Trade payables, GRNI accrual, accruals and deferred income, Vat and social security,
provisions for liabilities, loans payable

Current (due < 12 months) vs non-current due > 12 months

Tutor tip
How the auditor approaches substantive testing of trade payables often overlaps with
other liabilities recorded in the financial statements. When studying this section focus on
understanding the principles as these will apply to other liabilities also.

1. ROMM
 Due to impact of liabilities on the balance sheet, completeness, classification and
presentation are high-risk
 Higher ROMM assertions - C, Cl, P

2. Approach – test the closing balance


 Due to high volume of movements

3. Accounting policies – considerations include:


 A liability should be raised when inventory is received
 Once an invoice is received, a trade payable is recognised and (if relevant) the
GRNI accrual removed
 Cash payments reduce the trade payables balance
 The valuation of the liability should be based on an estimate of the expected
cash outflow. Therefore, the value of creditors should be adjusted for any
discounts the client is entitled to as this will impact the cash outflow
 Credit notes received will reduce the trade payables/GRNI balance
 Foreign currency balances should be restated at the year-end exchange rate

4. Assertions – R&O, E, C, Cl, AVA, P

81
5. Common procedures
 Search for unrecorded liabilities
 Creditors circularisation
 Supplier statement reconciliations

Equity and reserves

 Auditor often tests the movements within the disclosure note within the financial
statements.
 For private companies normally low risk, however for public companies
movements in share capital and reserves can be large making it a more
complex audit area

Intangible assets

Examples include development expenditure, patents, computer software, licenses, franchises

1. ROMM
 Accounting treatment and valuation is complex
 Higher ROMM assertions - AVA

2. Approach – test the movements


 Additions
 Disposals
 Amortisation
 Revaluations
 Impairments

3. Accounting policies
 Research – costs not permitted to be capitalised.
 Development – costs only recognised if can demonstrate six criteria:
 Technical feasibility
 Intention to complete
 Ability to use or sell
 Commercial feasibility
 Adequate resources
 Ability to reliably measure

4. Assertions – R&O, E, C, Cl, AVA, P

5. Common procedures
 Vouching the costs capitalised during the period to invoices to determine
whether they relate to development expenditure and vouch the amount
capitalised
 Inspecting expenses listings for any significant invoices paid but not capitalised
 Inspecting the research expense account for items that may be related to
development costs and should be capitalised as an asset and vice versa
 Recalculating the amortisation charge for the period
 Inspecting sales made post-year-end to determine whether the valuation of the
intangible has suffered an impairment
 Compare actual costs to budgeted costs to determine if there is any indication
that costs have been over or under-capitalised

82
Estimates

ROMM for estimates is normally high due to:

 Estimation uncertainty
 Subjectivity
 Complexity

Example procedures over estimates include:


 assessing whether the method selected is appropriate in line with the
relevant financial reporting framework
 whether assumptions made are appropriate
 whether data used is appropriate, relevant and reliable and has been properly maintained
 whether data has been appropriately understood or interpreted by management,
including the presence of appropriate skills and knowledge to prepare the
estimate
 whether there are any indications of management bias
 an expert may be used

Responses available to the

auditor:

 obtaining evidence from events occurring up to the date of the auditor’s report
 testing how management made the accounting estimate
 developing the auditor’s point estimate or auditor’s range of estimates

Provisions and Contingencies

Provision – liability of uncertain timing or amount

 Only recognised when following three criteria satisfied:


 Entity has present obligation as result of past event
 Probably outflow of economic resources is required
 Reliable estimate can be made

Procedures to perform to test provisions include:

 Enquiries of management and others within the entity


 Inspection of board meeting minutes
 Inspection of correspondence with solicitors
 Examination of legal expense accounts
 Direct communication with the entity’s legal counsel where there is a ROMM
(these are often called solicitors' confirmations)

Contingent asset – possible asset that arises from past events and whose existence will be
confirmed only by the occurrence or non-occurrence of one or more uncertain future
events not wholly within the control of the entity

Contingent liability:

 is a possible obligation that arises from past events and whose existence will be
confirmed only by the occurrence or non-occurrence of one or more uncertain
future events not wholly within control of the entity; or
 is a present obligation that arises from past events but it is not recognised
because it is not probable that an outflow of resources embodying economic
benefits will be required to settle the obligation or the amount of the obligation
cannot be measured with sufficient reliability.

83
Derivatives

Financial instrument – a contract that gives rise to both a financial asset of one entity and a
financial liability or equity instrument of another entity.

Type of financial instrument – examples include options, futures, forward contracts, interest
rate swaps and currency swaps

The value of a derivative depends on, or is derived from, an underlying rate or price such as
interest rates, exchange rates or commodity prices.

1. ROMM
 Accounting involves complexity, use of management judgement and
requires specific presentation in the financial statement notes
 Higher ROMM assertions - AVA, Cl, P

2. Approach – test the closing balances


 Measured at fair value through profit or loss (FVTPL)

3. Accounting policies
 The nature of the derivative and the risks the entity is exposed to
 Classification/ presentation requirements under accounting standards
 Accounting standard requirements over valuation (FVTPL)

4. Assertions – R&O, E, C, Cl, AVA, P

5. Common procedures
 external confirmations
 review of reconciliations and operational data such as reconciliation differences
 review journal entries
 review contracts
 testing of assumptions and fair value adjustments
 post year end events
 validity of valuation models
 confirmation of external prices to third-party sources

Statement of Profit or loss

Areas to be tested include:

 Turnover/revenue
 Cost of sales/expenses
 Depreciation
 Payroll

Revenue recognition

 Normally identified as a risk by the auditor and occurrence and cut off of revenue
can be a key audit risk area, especially if there is any risk of fraud.

Response to fraud risk in revenue recognition:

 Confirming directly with customers the details of relevant contracts


 Being physically present at period end to observe goods being shipped
 Using automated tools to perform disaggregated substantive analytical procedures

84
Revenue from contracts with customers

 When auditing revenue from contracts with customers, the auditor should test
whether the five criteria in IFRS 15 have been met:
 Identify the contract(s) with a customer
 Identify the performance obligations in the contract
 Determine the transaction price
 Allocate the transaction price to the performance obligation(s) in the contract
 Recognise revenue when (or as) the entity satisfies a performance obligation

Designing follow up procedures


Follow up on substantive analytical procedures

Tailored tests of detail may be required to corroborate any explanations for variances
between actual and expectation identified by the auditor following substantive analytical
procedures. Further follow up tests may also be required of a plausible explanation has
not been identified

Tutor tip
In the assessment, you may be asked to:

 Respond to identified audit risks, outstanding matters, or other events


identified during the audit
 Evaluate audit risks and design an approach to your identified risks
 Design follow-up procedures for material variances discovered as a result of
substantive analytical procedures

In all instances, you can use the skills learnt in this module to help you answer the
requirement. You must design relevant and tailored procedures to address the area you
have been presented with.

You can use the considerations covered in this lesson regarding risk, accounting policies,
and common procedures to help you design the procedures required.

Comparatives and opening balances


Continuing engagements

The auditor must obtain sufficient appropriate evidence that the comparative information
agrees to the prior year financial statements and has been presented in line with
relevant accounting standards

First year engagements

The auditor may need to perform audit tests where the prior year financial statements were
not audited or were audited by another auditor

Final considerations
Substantive testing procedures for the financial statement close process include:

 Agreeing the audited entity’s financial statements to its underlying accounting


records e.g. the trial balance and nominal ledger
 Examining material journal entries and other adjustments made during the course
of preparing the financial statements.

The auditor will use a disclosure checklist to gain assurance over the presentation disclosure.
85
Assessment approach
The key techniques to remember are:

For designing tests of detail

 Document the procedure considering verb (e.g enquiry, inspection,


recalculation, confirmation), population, evidence and activity.

It is important that you understand what assertion you are addressing with any test you
design. Some questions may only ask for testing of certain assertions or certain aspects
of the balance. No matter how well worded a test is, if it doesn’t address the assertion
required in the question it will gain no marks.

For designing substantive audit work programmes

When designing a substantive audit work testing programme use the following
considerations to help you design a variety of substantive procedures:

 Risk of material misstatement (ROMM)


 Approach
 Accounting policies
 Assertions
 Common procedures
 Standard Tests

Consider whether the tests you have provided are reliable and address all relevant risks
and assertions. You should also consider whether the procedures include all evidence
available.

As well as designing procedures yourself in an assessment, you could be asked to


evaluate procedures that have already been prepared by another member of the team.
You should consider whether the procedures detailed:

 are reliable;
 address all the relevant risks and assertions, or whether items are missing;
 can be followed by another member of the team, or whether more detail
is required (remember verb, population, evidence, activity);
 include all evidence available.

When designing follow up procedures

Consider the following:

1. Could the substantive analytical calculation be improved?


2. What further evidence could be required?

Remember that any substantive procedures must be tailored and relevant to the given scenario.

Note that 1 mark will be awarded for a basic procedure (enquire/observe) or a common
procedure or standard test which is not tailored to the scenario, whereas a well
designed test tailored to the scenario with analysis/evaluation/recommendation and a
procedure other than enquiry/observation may gain 2 marks.

Conclusion
On completing this module, you can now attempt AAPQ 5.

86
Study guide checklist

Have you completed reading module 8?

Have you completed the skills checkers and skills builders?

Can you confidently complete the module learning outcomes listed on this module?

Can you confidently answer the guiding questions?

Have you completed the assessment practice questions?

Have you used the discussion board to ask questions on areas you are unsure
about?

87
Module 9 – Substantive Procedures – Part 3
Introduction
Welcome to the study guide for Module 9 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.

Syllabus Learning Outcomes


 Apply professional judgement and professional scepticism in conducting an
assurance engagement

Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:

 Design substantive procedures including substantive analytical procedures and


tests of detail, incorporating the use of data analytics, and conclude based on
evidence received

This will be achieved by working towards the following performance indicators:

 Explain the sample selection techniques available to an auditor and select


appropriate items to test as part of a sample
 Apply substantive procedures
 Evaluate the findings from substantive procedures
 Evaluate outstanding matters from the audit and design procedures to gather
evidence to conclude on the matters
 Assess whether items require adjustment in the financial statements and
prepare a summary of audit misstatements

You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.

Here is a reminder of some key points to look at in this module.

88
Audit evidence
Auditors must obtain ‘sufficient appropriate evidence’ on which to base their opinion.

Sufficiency – a measure of the quantity of evidence.

Appropriateness – a measure of the quality of evidence. Must be relevant and

reliable Sources of evidence:

 Auditor generated
 Audited entity generated
 Third party/externally generated

Audit sampling
Sampling methods include:

 Random selection
 Monetary unit sampling
 Haphazard selection

Based on the characteristics of the population, the auditor may determine that
stratification or value- weighted selection is appropriate. A population for testing may be
split into different sub-populations that share a particular characteristic; this can often
help to reduce sample sizes without increasing sampling risk.

Steps auditor will take when using audit sampling

1. Determine the level of tolerable misstatement - addresses the risk that the sum of
individually immaterial or undetected misstatements result in the financial statements
is materially misstated. It is a monetary amount and application of performance
materiality and may be the same or lower than performance materiality.
2. Determine the sample size and select items for testing e.g. statistical/non-statistical
sampling - can be determined by applying a statistically-based formula or through
professional judgement.
3. Perform the audit procedure - should be applied to all items in the sample. If the
procedure is not relevant to a particular item, a replacement item should be
selected. If a procedure cannot be performed and there is no suitable alternative
procedure to perform, then the item should be treated as a misstatement.
4. Identify the nature and causes of misstatement - investigate the nature and cause of
any misstatements identified and their effect on the assertion and other areas of
the audit. This may involve extending audit testing further over a particular type of
transaction in the population.
5. Extrapolate and project the misstatement to the population - for tests of detail,
misstatements found in a sample should be projected to the entire population unless
assessed as an anomaly or isolated/one off incident.
6. Evaluate the results – consider whether the use of sampling provides a reasonable
conclusion about the population being tested. If misstatements were detected, then
the extrapolated error, if applicable, should be calculated and compared to the level
of tolerable misstatement to determine if it would be material.
7. Conclude and determine further actions - If the total projected misstatement (plus
anomalies) does not exceed tolerable misstatement, then the sample provides a
reasonable basis for conclusion.

If there is not a reasonable basis for conclusion, the auditor may request
management to investigate and quantify the total misstatement or change the
nature of testing to provide a reasonable basis for conclusion.

89
Tutor tip
You may:

 Be asked to prepare training notes for junior staff on substantive testing;


 Be provided with a scenario and asked to comment on appropriate sampling
techniques to improve audit efficiency; or
 Be provided with various differences arising from audit procedures and asked to
consider what that would mean for the specified assertion.

You need to have a good understanding of these techniques to be able to apply them to
different scenarios.

Assessment approach
In the assessment, you may be provided with information regarding the section being
audited including audit work papers, sub-ledgers, invoices and other relevant
documentation. You will only be expected to perform substantive procedures based on
the information provided and not all audit procedures that could be performed in relation
to an account.

You will not be provided with a substantive testing programme and need to assess which
procedures are possible based on the information provided. The following approach will
help you to undertake an assessment question in this area.

Approach to exam question

• Peform a high-level review of the question including the requirement and appendices
• It is important to understand what you are being asked and what information
Step 1 you have been given before attempting the question.

• Identify if you are required to design substantive procedures as well as perform them
• Some questions may expect you to firstly design the substantive procedures
Step 2 before performing them. Your knowledge from Module 8 of this course will help you with
this.
• Perform the substantive procedures and identify any issues requiring further
investigation
Step 3 • Remember you will only be able to perform substantive procedures in relation to
the information that you have been provided with.

• Document your findings including any conclusions or follow up procedures required


• This may involve designing further procedures to address any issues identified.
Step 4

Roll forward procedures


The auditor may perform substantive procedures at an interim date and then perform
additional roll forward procedures e.g. substantive procedures and tests of control to
extend testing up to the year end.

May be performed across a wide range of balances and classes of transactions,


including debtors and/or creditors circularisations, supplier statement reconciliations
and stock counts.

90
To help determine whether to perform substantive procedures prior to the year end consider:

 The control environment and other relevant controls


 The availability of information at a later date that is necessary for the auditor’s
procedures
 The purpose of the substantive procedure
 The risk of material misstatement
 The nature of the figure being tested and related assertions
 The ability of the auditor to perform substantive procedures (or substantive
procedures and control tests) to cover the remaining period

Trade Receivables circularisation

 Sample of an entity’s customers are requested to confirm their outstanding


balance directly to the auditor
 Can also be performed for trade payables
 If auditor does not receive a response they will need to perform alternative
verification procedures. These may include
 Checking outstanding invoices to supporting documentation
 Verifying receipt of payment for outstanding invoices to bank statements
 The auditor must evaluate the results and follow up on any issues. Any
differences require to be aggregated and if applicable extrapolated to the
population as a whole
 The audited entity’s management may refuse to allow the auditor to send
confirmation requests. If so the auditor must understand the reasons and
whether any alternative procedures can be performed.

Stock count follow up procedures

 The auditor my use the results from tests of controls over stock (inventory) ie
stock count as part of their substantive procedures
 Procedures may include:

Assertion Substantive testing procedure


Completeness Agree test counts performed at the year-end stock take and copies of the
audited entity’s stock count sheets to the detailed inventory listing and
investigate all differences.
Obtain a complete set of the audited entity’s final inventory sheets and
agree the total per the final stock count sheets to the detailed listing from
the system and investigate all differences.
Existence Agree a sample of quantities of inventory per the detailed inventory listing
to the
test counts performed at the stock count per the count sheets.
Accuracy, Agree items identified as spoiled, slow moving or obsolete during the
valuation stock take to the final detailed inventory listing and ensure these have
and been identified.
allocation Enquire with management how the valuation of these items has been
of stock considered and ensure included in the inventory provision, where
necessary.
Where not provided for, vouch to sales prices after the year end and post
year-end quantities sold to corroborate explanations that no provision
should be made

Substantive procedures over payroll

 Payroll is usually one of the most significant accounts in the statement of profit or loss
 Often risk over fraud and auditor will carry out tests of detail in response to this risk

91
Outstanding matters
Following the final audit visit it is often the case that the auditor will have outstanding
matters that the audit team will need to follow up and conclude on before the audit report
can be issued

Examples include:

 Evidence not yet provided by the audited entity


 Missing evidence
 Evidence received after the conclusion of the final audit visit
 Ongoing matters that may affect the financial

statements The auditor should approach any

outstanding matters as follows

 Analyse the outstanding matter and how it impacts the audit


 Design further procedures to gather sufficient appropriate evidence to resolve the
outstanding matters

Tutor tip
In an assessment, you will often be asked to evaluate a number of outstanding matters from
the audit and advise what additional evidence is required. Therefore, you must first
discuss the matter and why it is relevant to the audit before listing further procedures to
gather the additional evidence required. You may be provided with information such as
materiality to help you determine whether the matter is material and would impact the
financial statements.

Recording, considering and communicating misstatements


Recording misstatements

The auditor documents any misstatements, except those clearly trivial, identified during the
audit in a document called a Summary of Audit Misstatements

92
An example of a summary of misstatements is as follows:

Wolfpack Ltd
Year end: 30 September 20X2
Summary of audit misstatements
Financial Statements Account Dr Cr
Material Adjusted
£ £
1 P&L – administrative expenses 100,000
Fixed assets – accumulated depreciation 100,000 N N
being adjustment to apply depreciation policy consistently
2 P&L – sales 625,333
Trade debtors 625,333 Y Y
being October 20X2 sales incorrectly included in current year
3 P&L – administrative expenses 214,000
Trade and other creditors 214,000 Y Y
being correction for unrecorded liabilities
Summary and Conclusion
Adjusted differences in P&L 839,333
Dr
Unadjusted differences
Unadjusted differences in P&L 100,000
Dr are judged to be
Adjusted differences in net assets 839,333 immaterial.
Cr
Unadjusted differences in net 100,000
assets Cr

The auditor must determine whether as a consequence of the detected misstatement,


there needs to be a revision to the audit procedures performed.

The auditor will consider whether:

 The misstatement is an isolated incident


 There is evidence of a breakdown of internal control
 Inappropriate assumptions or methods have been applied elsewhere

Considering and communicating misstatements

 The auditor requests that an entity’s management correct all


misstatements before the financial statements are issued
 The auditor should also communicate with those charged with governance
uncorrected misstatements and the effect that they individually or in
aggregate may have on the audit opinion
 The auditor will re-evaluate the risk of material misstatement taking into
account any adjustments made
 Items may be material by size or by nature. Examples may include:
 Circumstances that affect the company's compliance with regulatory
requirements and/or debt covenants
 Circumstances that distort the company's financial ratios
 Accounting policies that do not lead to material misstatement but may set
precedents that cumulatively could become material in future
 Conditions that increase management compensation (such as profit-
related pay) by achieving certain targets
 Related party transactions, e.g. transactions with directors

93
Assessment approach:
For audit sampling questions (where results from testing are provided):

1. Identify nature and causes of misstatement.


2. Extrapolate and project the misstatement to the population (were appropriate).
3. Evaluate the results.
4. Conclude or determine further actions/procedures.

For performing substantive procedures questions:

 Perform a high-level review of the question including the requirement and appendices.
 Identify if you are required to design substantive procedures as well as perform them.
 Perform the substantive procedures and identify any issues requiring further
investigation.
 Document your findings including any conclusions or follow up procedures required.

Remember, you will not be provided with a substantive testing programme and need to assess
which procedures are possible and appropriate based on the information provided.

For outstanding matters questions:

1. Discuss the matter and why it is relevant to the audit before listing further procedures
to gather the additional evidence required.
2. Look out for information in the scenario such as materiality to help you determine
whether the matter is material and would impact the financial statements.

For audit misstatements questions:

 Is the misstatement material Yes/No or could it be material by nature?


 If multiple misstatements in the same balance/transaction/disclosure, are
they material in aggregate?

Conclusion
On completing this module, you can now attempt AAPQ 7, 9, 10, 13 and 18.

Study guide checklist

Have you completed reading module 9?

Have you completed the skills checkers and skills builders?

Can you confidently complete the module learning outcomes listed on this module?

Can you confidently answer the guiding questions?

Have you completed the assessment practice questions?

Have you used the discussion board to ask questions on areas you are unsure about?

94
Module 10 – Completion and Reporting
Introduction
Welcome to the study guide for Module 10 of the Advanced Assurance course. This
study guide will help you prepare for the assessment.

Syllabus Learning Outcomes


 Apply professional judgement and professional scepticism in conducting an
assurance engagement

Module Learning Outcomes


By completing this module, you will have worked towards the following module learning
outcomes:

 Evaluate the results of substantive procedures and the impact of audit


misstatements and other findings from the audit process on the audit report
and other reporting responsibilities.

This will be achieved by working towards the following performance indicators:

 Evaluate and advise on management's going concern assessment


 Evaluate subsequent events and design procedures to obtain sufficient,
appropriate audit evidence in relation to outstanding subsequent events
 Evaluate the sufficiency and appropriateness of audit evidence at the completion
stage of the audit, including the evaluation of misstatements arising from the
audit
 Explain the purpose of, and prepare, completion documentation
 Explain the purpose of Engagement Quality Control Review
 Evaluate audit findings and, based on the evidence collected, recommend an
appropriate audit report, including the audit opinion and any relevant
additional reporting areas
 Explain the communication required with those charged with governance
during and at the end of the audit

You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.

Here is a reminder of some key points to look at in this module.

95
Going Concern Principle
Under the going concern assumption, an entity is ordinarily viewed as continuing in business for
the foreseeable future.

The period of assessment should be a minimum of 12 months from the date of approval of
the financial statements

Directors assess the company’s going concern status and prepare financial statements

accordingly. The directors’ assessment of going concern may focus on:

 The preparation and review of forecasts and budgets, including a cash flow forecast
 A review of lending facilities
 A review of any pending legal cases
 A review of contracts with major customers and suppliers
 A review of competitor performance or entry to local market

Auditor's responsibilities

Aspects of auditor’s responsibilities:

a) Timing and period of assessment - The auditor should use the same period of time for
the going concern assessment as that used by the directors. If this is less than 12
months from the approval of the financial statements, the auditor must ask the
directors to extend this period.

b) Indicators of going concern risks - examples in ISA (UK) 570 paragraph A3.

Include: Financial

 Net liability or net current liability position.


 Fixed-term borrowings approaching maturity without realistic prospects of
renewal or repayment; or excessive reliance on short-term borrowings to
finance long-term assets.
 Indications of withdrawal of financial support by creditors.
 Negative operating cash flows indicated by historical or prospective financial statements.
 Adverse key financial ratios.
 Substantial operating losses or significant deterioration in the value of assets used
to generate cash flows.
 Arrears or discontinuance of dividends.
 Inability to pay creditors on due dates.
 Inability to comply with the terms of loan agreements.
 Change from credit to cash-on-delivery transactions with suppliers.
 Inability to obtain financing for essential new product development or
other essential investments

Operating

 Management intentions to liquidate the entity or to cease operations.


 Loss of key management without replacement.
 Loss of a major market, key customer(s), franchise, license, or principal supplier(s).
 Labor difficulties.
 Shortages of important supplies.
 Emergence of a highly successful competitor.

96
Other

 Non-compliance with capital or other statutory or regulatory requirements, such


as solvency or liquidity requirements for financial institutions.
 Pending legal or regulatory proceedings against the entity that may, if
successful, result in claims that the entity is unlikely to be able to satisfy.
 Changes in law or regulation or government policy expected to adversely affect the
entity.
 Uninsured or underinsured catastrophes when they occur.
 Substantial decrease in share price.

You should look out for these factors when evaluating indicators of going concern problems
in the assessment.

c) Procedures to evaluate management’s assessment of going concern

The auditor is required to evaluate management’s assessment of going concern. In


doing this the auditor must perform procedures to obtain sufficient appropriate
evidence about whether:

 events or conditions exist that may cast significant doubt over going concern
 material uncertainties related to going concern exists
 management’s use of the going concern assumption is appropriate

Procedures include:

 Evaluating management’s method (including appropriateness of the method and


calculations used, and whether any changes from the method used in prior
periods are appropriate)
 Evaluating the relevance and reliability of data used by management
 Evaluating the appropriateness and consistency of assumptions made
 Evaluating management’s plans for future actions relating to the assessment
 Considering any additional facts or information available since management
made their initial assessment
 Requesting written representations regarding any future actions and the
feasibility of such plans

ISA (UK) 570 provides some examples of considerations for the auditor when designing
such procedures:

Procedures Example considerations


Evaluating management’s  Appropriateness with applicable financial reporting
method framework
 Consistency with methods used in previous periods
Evaluating the relevance  Source of data
and reliability of data  Consistency of data with previous periods
used by management  Accuracy and completeness of data
Evaluating the  Management’s rationale for the selection of
appropriateness and assumptions
consistency of  Changes from prior periods and rationale
assumptions made  Effect of alternative assumptions (sensitivity analysis)
 Consistency of assumptions with those used in other
areas of business e.g. around estimates
Evaluating  Reviewing management’s documentation of plans
management’s plans for  Enquiry of management over reasons for courses of
future actions relating to action
the assessment  Management’s history of carrying out stated intentions
 Review of subsequent events
 Evaluating the feasibility of planned actions and any
97
implications e.g. legal, regulatory, and contractual
restrictions
 Availability of third-party support e.g. funding if
required

98
Other procedures can include:

 Analysing and discussing cash flow, profit and other relevant forecasts
 Discussing the entity’s latest interim financial statements (the auditor may
also consider management accounts)
 Reviewing the terms of debentures and loan agreements
 Reading minutes of meetings of shareholders, those charged with governance
and relevant committees
 Making inquiries of lawyers regarding ongoing litigation or claims against the company
 Confirming the existence and adequacy of borrowing facilities
 Inspecting regulatory reports

Tutor tip
The assessment may require you to undertake specific procedures relating to the
directors’ going concern assessment. For example:

 Advise the directors on how to undertake a going concern assessment


 Describe how the auditor should evaluate a going concern assessment
 Identify factors within a scenario that would cause the auditor to question the
going concern status of an entity and propose additional audit procedures to be
performed in response to these factors
 Evaluate the assumptions used by the client as part of their going concern
assessment and identify further evidence required to assess the going concern
assumption
 Evaluate the impact of conclusions concerning the going concern assumption
on the audit report and audit opinion

You will need to tailor the procedures learnt to the scenario given to ensure your answer is
relevant.

Subsequent events
Subsequent events are events that occur after the balance sheet date. They can be
either adjusting or non-adjusting events.

Adjusting events Non-adjusting events


These provide evidence of conditions that These provide evidence of conditions that
existed at the period end. arose
They require adjustments to the amounts after the period end.
included in the financial statements. They do not result in adjustments to the
amounts included in the financial
statements; they will be disclosed in the
notes to the accounts if they are judged
to be sufficiently material.

99
Auditor’s responsibilities:

a) Events occurring up to the date of the audit report - auditors should perform
additional substantive procedures designed to obtain sufficient appropriate audit
evidence to ensure that they have identified all events. These may include:

 Obtaining an understanding of any procedures management has


established to identify subsequent events
 Asking management and those charged with governance about any potential events
 Consider use of written representations
 Reviewing board and committee meeting minutes and enquiring about
other matters discussed but not yet minuted.
 Reviewing interim financial information
 Communicating with the entity’s legal representatives to consider any litigation or other
claims

If subsequent events are identified, these should be substantively tested in the same
way as any other area throughout the audit.

b) After the date of the audit report – auditors have no obligation to perform audit
procedures, however if a fact becomes known they should discuss with
management and determine whether an amendment to the financial statements is
required and enquire how management intends to address the matter. If the
financial statements are amended, the auditor must audit these adjustments.

Tutor tip
The assessment may ask you to evaluate potential subsequent events within a scenario
and design further audit procedures in order to allow you to reach a conclusion on the
required accounting treatment.

Identifying the relevant subsequent events period is key to answering questions:

 After the audit fieldwork, but prior to the signing of the audit report; or
 After the date of the audit report.

Once the period has been identified the relevant paragraphs in ISA (UK) 560 can be used
as a guide to identify what audit procedures should be undertaken at that point.
However, you should ensure, if requested, that you have first evaluated whether the
event is adjusting or non-adjusting, analysing your conclusion. You should also consider
whether an adjusting event actually requires adjustment in the financial statements
depending on any provided materiality. Note that this should not just consider the
amount, but whether any items are material by nature.

The audit procedures will need to be tailored to the circumstances within the scenario in
order to maintain the relevance of your answer to the question.

Evaluation of evidence at completion


Final analytical procedures – must be performed at completion. If results are not
consistent with auditors understanding, additional procedures may be required.

Evaluation of evidence and misstatements - the auditor needs to evaluate the outcome of
the procedures performed and determine whether the auditor's assessment of the risks
of material misstatement remains appropriate and that sufficient and appropriate audit
evidence has been obtained.

The auditor must evaluate the potential effect of any identified and uncorrected
misstatements on the audit and, if applicable, on the financial statements.

10
0
All misstatements (which are not clearly trivial) are communicated to the management
for correction. If material misstatements are left uncorrected, this may impact the audit
opinion.

Written representations - statements from management and those charged with


governance of an entity that confirm certain matters or support other audit evidence.

Types of matters included in representation letter:

Matter Representations to be included


Management A description of management's responsibilities in relation to
responsibilities the financial statements.
Representations that:
 Management has fulfilled its responsibilities for
the preparation of the financial statements
 Management has provided the auditor with all the
information and access required (and any deficiencies in
internal control have been communicated to the
auditor)
 All transactions are reflected in the financial statements
Required representations  Fraud – acknowledgement of responsibility, risk
from other auditing assessment and confirmation that
standards identified/alleged/suspected fraud has been
disclosed to the auditor
 Laws and regulations – confirmation that all known
instances/suspected instances of breaches of
laws/regulations have been disclosed to the auditor
 Evaluation of misstatements – confirmation that the
effects of uncorrected misstatements are immaterial (a
list will be attached to the letter)
 Accounting estimates – confirmation that
significant assumptions used in making
accounting estimates are reasonable
 Related parties – confirmation of appropriate
disclosure and complete identification of related
party relationships and transactions
 Subsequent events – all events occurring subsequent to
the date of the financial statements and for which the
applicable financial reporting framework requires
adjustment or disclosure have been adjusted or
disclosed
 Going concern – confirmation of plans to address
going concern issues and their feasibility
Representations to Representations (where necessary):
support other evidence  About the financial statements, for example, whether
obtained during the audit the selection and application of accounting policies are
of the financial appropriate
statements  To support information provided to the auditor, for
example, that all deficiencies in internal control have
been communicated to the auditor
 About specific assertions, for example where it is a
matter of management's judgements or intentions
such as the assumptions used in an impairment
calculation

Failure to provide representations on management's responsibilities for the financial


statements as a whole is pervasive.

10
1
Tutor tip
In past assessments, there have been questions requesting students to identify matters
within a scenario that require representations to be sought from management.
Consequently, you must be able to identify these matters and be able to describe the
nature of the related representations within a written representation letter and consider
whether there will be any impact on the audit report.

Internal completion documents


 Points forward schedule - a list of points that need to be brought to the
attention of next year's audit team and will be used when planning next
year's audit
 Audit highlights memorandum/summary review memorandum - concludes on the
performance of the audit and summarises the key matters of importance. It is
usually prepared by the audit manager or senior for the engagement partner
 Accounts disclosure checklist – used to check that all matters have been
presented and disclosed in accordance with the Companies Act 2006 (CA 2006)
and the applicable accounting standards.

Quality management – General points to consider


 Whether the work has been performed in accordance with the firm’s policies and
procedures and other professional standards and legal and regulatory
requirements
 Whether significant matters have been raised for further consideration
 Whether appropriate consultations have taken place, and resulting conclusions
documented and implemented
 Whether there is a need to revise the work performed
 Whether the work performed supports the conclusions reached and is
appropriately documented
 Whether the evidence obtained is sufficient and appropriate
 Whether the objectives of the audit procedures have been

achieved Engagement partner

 Takes responsibility for the direction, supervision and review of the audit engagement.
 Determines that the engagement is sufficiently and appropriately resourced,
with sufficient competence, capabilities and time
 Is ultimately responsible for determining that the audit evidence on file is
sufficient and appropriate to support the conclusions reached and the audit
report to be issued.

Engagement quality reviewer (EQR) - not a member of the engagement team and must be
a suitably qualified partner or other person in the firm not otherwise involved in the
engagement.

It is mandatory for an EQR to be appointed on listed

entities. The reviewer must:

 have the competence and capabilities, including sufficient time, and the
appropriate authority to perform the EQR
 comply with relevant ethical requirements
 comply with provisions of law and regulation, if any, that are relevant to the
eligibility of the engagement quality reviewer
 be eligible for appointment as a statutory auditor if the audit of the financial
statements relates to a Public Interest Entity

10
2
Engagement quality review should include:

 Reading and understanding information communicated by the engagement team


 Discussions, with the engagement partner and team, of significant matters and
judgements
 Review of the financial statements and the proposed audit report
 Review of selected audit documentation relating to any significant judgements
made by the engagement team
 A consideration of the engagement partner’s assessment of the firm’s
independence from the client
 An assessment of whether appropriate consultations have taken place on difficult matters
 An evaluation of the engagement partner’s determination that the
engagement partner’s involvement has been sufficient and appropriate
throughout the engagement.

For public interest entities the following must be specifically considered:

 The independence of the firm from the entity


 The significant risks relevant to the audit and response to those risks
 Reasoning in relation to materiality and significant risks
 Any request for advice from experts and implementation of that advice
 Nature and scope of corrected and uncorrected misstatements identified
 Items discussed with the audit committee, management or supervisory bodies
 Items discussed with the FRC or other third parties
 Whether the documentation on the audit file supports the audit report and
report to the audit committee

The auditor’s report


Auditor’s objective – to form an opinion on the financial statements. The audit report is used
to communicate their opinion.

Elements (as introduced in ASR):

1. Title
2. Addressee
3. Auditor’s opinion
4. Basis for opinion
5. Conclusions relating to going concern
6. Other information
7. Other reporting responsibilities
8. Matters on which auditors are required to report by exception
9. Responsibilities of management for the financial statements
10. Auditor’s responsibilities for the audit of the financial statements
11. Name & signature of the auditor
12. Address of the auditor
13. Date of the auditor’s report

10
3
Additional elements for listed companies
 Key audit matters – relevant for listed entities, public interest entities and entities
that report on the Code.

The auditor will consider:


 Areas of higher assessed risk of material misstatement
 Significant auditor judgments relating to areas in the financial statements
that involved significant management judgement or estimates
 The effect on the audit of significant events or transactions that occurred during the
period

For each key matter identified by the auditor, the auditor shall include in the audit report:
 a description of why the matter was considered to be one of the most
significant in the audit
 how the matter was addressed in the audit, including significant judgements
made by the engagement team with respect to the matter
 a reference to any related disclosures in the financial statements, if any

 Summary of audit approach – including:


 explanations of the application of materiality
 an overview of the scope of the audit

 Reporting on other legal and regulatory requirements – auditors responsibilities


extended to:
 Directors’ remuneration reports – the auditor is required to audit the
numerical part of the directors’ remuneration report, stating in the audit
report whether, in the auditor’s opinion, it has been prepared in accordance
with the CA 2006. The non-numerical information (the remuneration policies)
must be reviewed for consistency with the auditor’s understanding of the
client’s policies.
 Corporate governance statements - the auditor is required to conclude
on certain elements for consistency with the financial statements

Modified audit reports


Elements in audit report which may require modification:

a) The audit opinion

In forming the opinion, the auditor concludes on whether:

 Sufficient appropriate audit evidence has been obtained to conclude that


the financial statements as a whole are free from material misstatement
 Uncorrected misstatements are material, individually or in aggregate
 The financial statements give a true and fair view
 The financial statements have been prepared in accordance with accounting
standards and required legislation (e.g. CA 2006)

Auditor's judgement about the pervasiveness of the


effects or possible effects on the financial
statements
Nature of matter giving rise to modification
Material but not pervasive Material and pervasive
1 Financial statements are materially Qualified opinion Adverse opinion
misstated
2 Inability to obtain sufficient Qualified opinion Disclaimer of opinion
appropriate audit evidence

10
4
Limitations imposed by management

An auditor may have an inability to obtain sufficient appropriate evidence due to a


limitation imposed by management. If management refuses to remove the limitation the
auditor should both:

 Communicate to those charged with governance


 Perform alternative procedures

If the auditor is unable to undertake alternative procedures:

 Qualify the opinion if material, but not pervasive


 If pervasive withdraw from the audit or if not possible to withdraw, disclaim the opinion

b) Emphasis of matter paragraph

The auditor's report may also be modified without a modification to the audit opinion, by
the inclusion of an 'emphasis of matter' paragraph.

Purpose - to draw users' attention to a matter that is of such importance that it is fundamental
to users' understanding of the financial statements.

Examples:

 Uncertainty relating to the outcome of exceptional litigation or regulatory action


 Early application of a new accounting standard that has a material effect on
the financial statements
 A significant subsequent event that occurs between the date of the financial
statements and the date of the auditor's report
 A major catastrophe that has had, or continues to have, a significant effect on
the entity's financial position

c) Other matters paragraph

Purpose - refers to a matter other than those presented or disclosed in the financial
statements that, in the auditor’s judgement, is relevant to users’ understanding of the
audit, the auditor’s responsibilities or the auditor’s report.

Examples:

 Planning and scoping matters


 An outline of circumstances why the auditor is unable to withdraw from the
engagement, despite management imposing a limitation on their work; and
 An elaboration of auditor's responsibilities.

d) Impact of going concern issues on the audit report

The auditor will include a statement within a 'Conclusions relating to going concern'
section in the audit report regarding the going concern basis applied by the directors and
the assessment they have made.

The auditor will conclude on:

a) Whether the going concern assumption is appropriate;


b) Whether there are any material uncertainties requiring to be reported by the directors.

10
5
Conclusion from audit evidence Impact on audit report
Going concern basis is appropriate Unmodified opinion and report. Statement
confirming no matters to report
Inability to obtain sufficient, appropriate auditDisclaimer of opinion
evidence
Going concern basis is appropriate, but material
Unmodified opinion, details of uncertainty
uncertainty exists – disclosure appropriate within
going concern section of audit report
Going concern basis is appropriate, but material
Qualified/ Adverse opinion
uncertainty exists – disclosure inadequate
Going concern is inappropriate Adverse opinion

Tutor tip
A scenario may include you in the role of the external audit manager. The fieldwork has
been completed but some issues have arisen, and you have been asked to write notes
to be presented to the directors on the possible modifications to the audit opinion or
audit report that may be made. The solution would expect an outline of:

 The type of amendment to the audit opinion and/ or audit report (amended
opinion or additional paragraphs) and analysis to support that conclusion
(circumstances, material/ pervasive/ uncertainty, etc)
 Examples of the wording that will be issued
 Explanation of any other sections of the audit report requiring disclosure or amendment

In assessment questions, there is unlikely to be a single answer concerning the nature of the
opinion that should be given. It is far more likely that you will be required to discuss the
outcomes and various opinions depending on the information within the scenario and the
actions that the relevant parties could take.

Communication with those charged with governance


Examples of matters that must be communicated to those charged with governance on a
timely basis include the following.

Matter Representations to be included


Significant findings from audit
For example:
(all entities)  Difficulties due to the untimely provision of
information by the client
 Circumstances resulting in a modification to the audit
opinion
Auditor independence In the case of listed entities, the auditor must communicate the
(listed entities) following with TCWG.
a) A statement that the engagement team has
complied with relevant ethical requirements
regarding independence.
and
b) All relationships and other matters between the firm
and the client that can affect independence as well as
the related safeguards that have been applied to
eliminate identified threats to independence or reduce
them to an acceptable level.

10
6
Matter Representations to be included
Fraud  Reporting to management and those charged with
governance on any actual or suspected fraud
identified
 Reporting to an appropriate authority where the
auditor identified or suspects a fraud
Laws and regulations  Reporting instances of non-compliance to those
charged with governance or the audit committee
 Consideration of reporting to an appropriate authority
UK Corporate Governances Communications to the audit committee, including:
Code reporting entities  Information relevant in the context of fulfilling their
responsibilities to present a fair, balanced, and
understandable financial report and to assess the
effectiveness of the company's risk management and
internal control systems
Public interest entities Communications to the audit committee, including:
 Identification of key audit partner(s) involved in the audit
 Description of scope and timing of the audit
Management letter A description of the deficiencies and an explanation of
their potential effects

Assessment approach
AA assessment questions set at the completion and reporting stage of audit often test various
topics in combination.

It is important to ensure that you read the requirement carefully to understand the
examiner’s expectations.

For questions on going concern, if you are asked to evaluate indicators from the
scenario which may lead to going concern problems for the client, ensure that you
explain ‘why’ the indicator may cause liquidity or other related problems in the next
twelve months. Procedures to evaluate the management’s going concern assessment
need to be tailored to the scenario to ensure that your answer is relevant. If asked to
evaluate the impact on the audit report, this needs to be carefully assessed. For
example, if you agree with the management’s assessment, the opinion will not be
modified in this regard but the relevant section of the audit report will be modified.

For questions on subsequent events, you may be asked to evaluate whether an event is
adjusting or non-adjusting. Ensure that you explain ‘why’ as you are unlikely to be
awarded full marks if you simply write that it’s one or the other. You may also be
required to design further audit procedures to allow you to reach a conclusion on the
required accounting treatment. The audit procedures will need to be tailored to the
circumstances within the scenario in order to maintain the relevance of your answer to
the question.

The impact on audit reports is often tested in combination with evaluation of matters
identified at the completion stage of audit. These matters may include results of going
concern or subsequent events reviews or those of evaluating evidence related to
misstatements or inability to gather sufficient appropriate evidence. For all questions,
sound knowledge of the contents of unmodified and modified audit reports is the basic
prerequisite.

Conclusion
On completing this module, you can now attempt AAPQ 8, 16, 21, 24 and 25.
10
7
Study guide checklist

Have you completed reading module 10?

Have you completed the skills checkers and skills builders?

Can you confidently complete the module learning outcomes listed on this module?

Can you confidently answer the guiding questions?

Have you completed the assessment practice questions?

Have you used the discussion board to ask questions on areas you are unsure
about?

10
8
Module 11 – Group Audits
Introduction
Welcome to the study guide for Module 11 of the Advanced Assurance course. This
study guide will help you navigate the course material and prepare for the assessment.

Syllabus Learning Outcomes


 Apply professional judgement and professional scepticism in conducting an
assurance engagement

Module Learning Outcomes


By completing this module, you will have worked towards the following module learning
outcomes:

 Evaluate business processes and the components of internal control


 Evaluate the results of acceptance and planning procedures, including the use
of audit data analytics to assess and determine the risk of material
misstatement and impact on audit approach
 Design substantive procedures including substantive analytical procedures and
tests of detail, incorporating the use of data analytics, and conclude based on
evidence received
 Evaluate the results of substantive procedures and the impact of audit
misstatements and other findings from the audit process on the audit report
and other reporting responsibilities

This will be achieved by working towards the following performance

indicators: In relation to a group audit:

 Explain an auditor's professional requirements in relation to acceptance and


continuance of an audit engagement.
 Evaluate the information collected about an entity to identify the significant
risks of material misstatement in the financial statements
 Evaluate the results of planning analytical review findings, including calculating
an expectation for key figures in the financial statements
 Plan an approach to gathering sufficient appropriate audit evidence in response
to identified risks of material misstatement
 Evaluate a group’s control environment and control systems and recommend
control procedures that they should implement over their operations and
preparation of consolidated financial statements
 Recommend appropriate materiality figures and consider the application of
materiality to the audit process.
 Design tailored substantive procedures in response to findings arising during the audit
process
 Evaluate audit findings and, based on the evidence collected, recommend an
appropriate audit report, including the audit opinion and any relevant
additional reporting areas

You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.

Here is a reminder of some key points to look at in this module.

10
9
Group Audits
Group audits are audits of financial statements that include the financial information of
more than one entity or business unit.

Key terms:

Group financial statements Financial statements that include the financial information
of more than one component
Component An entity or business activity for which financial
information is separately prepared, and which is included
in the group financial statements.
Group auditor Responsible for providing the audit opinion on the group
financial statements. Includes the group engagement
partner and members of the engagement team other than
component auditors
Component auditor May be engaged by the group auditor to audit a specific
component.
Group engagement letter Confirms terms of the engagement
Letter of support May be issued by parent company to help the directors of
the subsidiary to meet their responsibilities with respect
to going concern, if there is an issue at a subsidiary.

The group auditor is responsible for:

 Establishing the overall group audit strategy and group audit plan
 Directing and supervising component auditors and reviewing their work
 Evaluating the conclusions drawn from the audit evidence obtained as the
basis for forming an opinion on the group financial statements
 Determining, through review of audit documentation and discussion with the
engagement team, that sufficient appropriate audit evidence has been obtained to
support the conclusions reached and for the auditor’s report on the group financial
statements to be issued.

The group engagement partner is solely responsible for expressing an opinion on the
group financial statements. As a result, the auditor's report on the group financial
statements must not refer to a component auditor (unless required by law or
regulation).

Key considerations which should be adhered to when conducting a group audit:

11
0
Group acceptance and continuance
The group auditor needs to determine whether they can obtain audit evidence in relation
to the consolidation process and the financial information of the components. To be able
to do this, the group audit team needs to understand the group, its components and their
environments. They need to gather an understanding of matters such as:

 Activities that are significant to the group (e.g. industry and regulatory,
economic and political environments)
 The use of service organizations
 The use of shared service centres
 The use of component auditors
 Risk associated with potential complex accounting treatments on consolidation
 Whether the group auditor will have unrestricted access to those charged with
governance (TCWG) of the group, group management, TCWG of the
component, component management and component information.
 For recurring engagements: significant changes in structure, activities, composition of
TCWG

Group engagement letter – to confirm the terms of the engagement, the group auditor
issues a group engagement letter.

The group auditor must obtain the agreement of group management that it
acknowledges and understands its responsibility to provide the engagement team with:

 Access to all information of which group management is aware that is


relevant to the preparation of the group financial statements, such as
records, documentation and other matters
 Additional information that the engagement team may request from group
management or component management for the purpose of the group audit
 Unrestricted access to persons within the group from whom the engagement
team determines it necessary to obtain audit evidence

Group audit planning


The group auditor establishes the overall group audit strategy and group audit plan.

a) Selecting components at which audit work will be performed

This is based on auditor judgement. There may be factors which increase ROMM:

 Newly formed or acquired components


 Components in which significant changes have taken place
 Components which have significant transactions with related parties
 Components where abnormal fluctuations have been identified by analytical procedures

b) The resources needed to perform the group audit engagement

Resources and extent to which component auditors are to be involved is a matter of


professional judgement and may include:

 Knowledge and experience of engagement team


 Initial expectations about potential ROMM
 The group’s system of internal control
 Previous experience with the component auditor

11
1
The group engagement partner is responsible for:

 Confirming whether component auditors understand and will comply with the
relevant ethical requirements
 Determining that component auditors have the appropriate competence and
capabilities, including sufficient time, to perform the assigned audit procedures
at the component

Understanding the group

The auditor must obtain a sound understanding of the structure and operations of the group
as part of the overall understanding of the organisation to enable any problems or issues
to be identified and considered right from the start of the audit.

Examples of matters that the group auditor must obtain an understanding of include the following:

 The group and its environment, the financial reporting framework and the
consistency of accounting policies and practices across the group.
 Organisational structure
 Regulatory factors impacting the group
 Measures used to assess the entities’ or business units’ financial performance
 The group’s system of internal controls
 Commonality of controls
 Whether and, if so, how the group centralises activities relevant to financial
reporting
 Consolidation process

Understanding key controls over the preparation of group financial statements.

Planning for the group audit may be impacted by whether the group structure is centralised
or decentralised. Consider:

 Management and governance by directors


 Operating processes and controls (such as treasury, finance and payroll)

Specific accounting issues related to the consolidation process

Different accounting policies If different, will require adjustments on consolidation


Non-conterminous accounting Can be consolidated at a different date if within 3 months
periods of parent company’s year end
Foreign subsidiaries Will require translation into group currency on
consolidation. There may also be cultural or language
differences which impact communication.
Fair values and goodwill On acquisition of subsidiary
Group taxation Tax can be complicated (eg group or consortium relief,
group VAT election)
Acquisitions made during the Must only include the results of the new subsidiary from
accounting period the date of acquisition
Related parties May be harder to identify in a group due to increased
complexity of organisational structure
Subsidiaries not wholly ownedMust be consolidated where control exists, and therefore a
group may include subsidiaries where less than 100%
of the subsidiary is owned by the group
Disclosure Higher level of disclosure required than for individual
financial statements

11
2
Tutor tip
In the assessment, you are likely to be given information about the components in the
group, the industries they are in and the related trading conditions as well as the group
structure and controls over group financial reporting.

Therefore, you can expect audit risks to arise in three areas:

1. Risks within each component similar to an individual entity


2. Risks arising from the group structure or changes in the group structure
3. Deficiencies of controls that impact on the consolidation process

You will need to consider the significance of risks within each individual component to
assess whether they would be considered a significant ROMM at the group engagement
level.

Group materiality
The group engagement team determines materiality for the group financial statements
as a whole and for the components

Overall materiality: Materiality is determined for the group financial statements as a


whole using the same approach as for an individual company outlined in Module 4.

Component materiality: For those components where component auditors will perform a
review or audit for group purposes, component materiality is determined by the group
engagement team at a level lower than overall group materiality. This is to reduce, to an
appropriately low level, the probability that the aggregate of uncorrected and
undetected misstatements in each component exceeds overall materiality for the group.

Clearly trivial threshold: Only misstatements above this level will be reported to the
group engagement team by component auditors.

Responding to the assessed risks of material misstatement


The group auditor is responsible for the nature, timing and extent of further audit
procedures to be performed, including determining the components at which to perform
further audit procedures and the nature, timing and extent of the work to be performed
at those components.

The group auditor may:

 Perform further audit procedures centrally


 Perform further audit procedures at the component level
 Perform further audit procedures on a large number of components
whose financial information is individually immaterial but material in
aggregate to the group financial statements

The group auditor may determine the following scope of work to be appropriate at a
component level (with the involvement of component auditors, if applicable):

 Design and perform further audit procedures on the entire financial


information of the component
 Design and perform further audit procedures on one or more classes of
transactions, account balances or disclosures
 Perform specific further audit procedures

11
3
Consolidation process controls
Group instructions

Issued by entity’s group accounting team to manage the quality of information


provided by the components and to enable the team to produce the consolidated
accounts within the reporting deadline. These may include:

 Standard reporting package


 Timetable
 Accounting policies
 Agreement of intra-group balances
 Stocktaking instructions
 Identification of related party transactions
 Exchange rates to be used
 Taxation information

Some suggested controls over the consolidation process are as follows:

Control Reason for control


Collection of data
An up-to-date consolidation manual should be made available Ensure that staff undertaking
to all relevant staff to inform them of the required the consolidation process
procedures and provide guidance to ensure that company are suitably trained.
policy is adhered to.
The entity’s group accounting team should identify all Data is collected from correct
companies that should be included within the consolidation set of subsidiaries to
using the group structure and completing a checklist to ensure completeness of
confirm all information received. A formal process should the financial information.
be implemented to report any changes to the group
structure (e.g., a disposal) through a change form to the
group team.
Issue each company requiring consolidation with a Data received is accurate
consolidation submission proforma to complete. These and complete.
proformas should be sequentially numbered/allocated with
company identifier to ensure that a submission is collected
from each relevant subsidiary and followed up if required.
Group instructions are provided to each group company to Data received is accurate
indicate what information should be provided. and complete and
received on a timely
basis, including relevant
disclosures.
Information from subsidiaries should be accepted only in Data received is accurate
agreed formats and after review and approval by the and complete, received
subsidiary finance director. on a timely basis and is
in a format appropriate
for the consolidation to
be performed.
Request subsidiaries confirm their compliance with group Individual returns comply with
accounting policies and agree accounting policies used group accounting policies.
within the subsidiaries to group policy on receipt of
consolidation return.
Investigate any differences.
Implement and communicate a formal process for subsidiariesLate adjustments are
to notify the group team of any late adjustments (including reflected in the
audit adjustments) that may arise after the submission of group financial
information. statements

11
4
Control Reason for control
Amalgamation of data
All returns are reviewed for completeness Only complete
(manual/automated) and omissions followed up. consolidation returns are
amalgamated, none are
excluded completely.
Subsidiary information should be agreed to source once All data is calculated
input, with any exceptions followed up. The consolidation accurately.
package should include master file controls including
restrictions on editing information. Include control total
checks, balancing checks, and the reporting of unusual
transactions within the consolidation package.
Consolidation adjustments
Checklist of consolidation adjustments followed and All consolidation
completed; checklist reviewed by an appropriate official. In adjustments required are
an automated system this checklist can be loaded onto the made, with no duplication.
system and the software programmed to flag
duplication/missing entries.
Agreement by an appropriate official of adjustments All consolidation
actually made to those proposed and included on adjustments are made
checklist. accurately.
Complete a journal posting form for all entries which is
subject to review.
Sign off by a responsible official of adjustments
documentation when agreed adjustments are made.
Staff making consolidation adjustments are adequately All consolidation
trained in the consolidation procedures and a responsible adjustments are calculated
official reviews the work done. in accordance with the
relevant accounting
standard/ company law.
Reporting
Review checklists for completeness and authorisation by Ensure consolidated
responsible official. accounts are complete.
Review of consolidated accounts by appropriate responsible Ensure consolidated
officials. Implement access controls to the consolidation accounts are accurate.
software, to ensure that only responsible officials can
request and access consolidation information. Agree
consolidated accounts to consolidation schedule and
supporting documentation.
Complete a disclosure checklist. Required disclosures have
been included.

Tutor tip
This knowledge can be applied to questions in the assessment which you may be asked
to describe tests of controls or evaluate control weaknesses in the group’s consolidation
process.

For example, a scenario could provide process notes detailing a client’s consolidation
process and require you to evaluate any weaknesses identified and recommend
appropriate control activities to improve the process. Understanding the types of
controls in place and the reason for these controls will allow you to identify where
weaknesses exist.

11
5
Audit work to be performed in relation to the consolidation process
 Evaluating whether all components have been included
 Evaluating the appropriateness, completeness and accuracy of consolidation adjustments
 Evaluating whether management’s judgements made in the consolidation process
give rise to indicators of possible management bias
 Responding to assessed ROMM due to fraud arising from the consolidation process.
 Checking that figures taken into the consolidation have been accurately
extracted from the financial statements of the components by reconciling the
data.
 Checking the arithmetical accuracy of all consolidation schedules and
recalculating all consolidation adjustments
 Reviewing the disclosures necessary in the group financial statements, such as
related party transactions
 Investigating the treatment of any components which have a different financial year end
from that of the rest of the group.
 Gathering evidence appropriate to the specific consolidation adjustments made
necessary by financial reporting standards, including, for example: calculation of
goodwill and cancellation of inter-company balances and transactions

When component auditors are involved in the design or performance of further audit
procedures for group audit, the group auditor must:

 Communicate with them about matters relevant to the design of responses to


the assessed ROMM
 Evaluate the appropriateness of these procedures on areas of higher assessed
ROMM or significant risks
 Ensure their work is directed, supervised and reviewed

Tutor tip
You may be required to produce a list of substantive tests over the consolidation for a
group engagement in the assessment.

Therefore, you will have to identify the relevant specific substantive procedures that
would be appropriate for this type of engagement. To do this, you should consider the
relevant accounting policies, risks and assertions.

You should approach the audit of the consolidation using the same methodology as for
any other balance: consider the ROMM, accounting policies and assertions to ensure you
have coverage of all areas requiring procedures.

11
6
Evaluating the component auditor’s communications and the adequacy of their work

To allow the group auditor to assess the adequacy of the component auditor’s work,
certain matters need to be communicated to the group auditor by the component
auditor. These include:

 Identification of the financial information on which the component auditor has


been requested to perform audit procedures.
 Whether the component auditor has performed the work requested by the group auditor.
 Whether the component auditor has complied with the relevant ethical
requirements, including those related to independence, that apply to the group
audit engagement.
 Information about instances of non-compliance with laws or regulations.
 Corrected and uncorrected misstatements of the component financial information
identified by the component auditor and that are above the threshold
communicated by the group auditor.
 Indicators of possible management bias.
 Description of any deficiencies in the system of internal control identified in
connection with the audit procedures performed.
 Fraud or suspected fraud involving component management, employees who
have significant roles in the group’s system of internal control at the component
or others where the fraud resulted in a material misstatement of the component
financial information.
 Any events or conditions identified by the component auditor that may cast
significant doubt on the group’s ability to continue as a going concern.

Completion
Evaluating the sufficiency and appropriateness of audit evidence obtained

Additional time must be built into the audit process to enable the group auditor to:

 Review the work of the component auditors and the group team
 Review any reporting documentation from the component auditors
 Consider any modifications of component audit reports on the group audit report
 Discuss all salient issues with the component auditors

Communications with TCWG


Should include:

a) An overview of the work to be performed at the components of the group, and the
involvement of component auditors
b) Any concerns about the quality of that component auditor’s work
c) Any limitations on the scope of the group audit,
d) Fraud or suspected fraud
e) Identified deficiencies in the group’s system of internal control
f) Additional matters for public interest entities

The group auditor has sole responsibility for the opinion on the consolidated group
financial statements.

11
7
Assessment approach
Audit Risks

You are likely to be given information about the components in the group, the industries
they are in and the related trading conditions as well as the group structure and controls
over group financial reporting.

Therefore, you can expect audit risks to arise in three areas:

1. Risks within each component similar to an individual entity


2. Risks arising from the group structure or changes in the group structure
3. Deficiencies of controls that impact on the consolidation process

You will need to consider the significance of risks within each individual component to
assess whether they would be considered a significant ROMM at the group engagement
level.

Internal control

You may be asked to describe tests of controls or evaluate control weaknesses in the
group’s consolidation process. For example, a scenario could provide process notes
detailing a client’s consolidation process and require you to evaluate any weaknesses
identified and recommend appropriate control activities to improve the process.
Understanding the types of controls in place and the reason for these controls will allow
you to identify where weaknesses exist.

Substantive procedures

You may be required to produce a list of substantive tests over the consolidation for a
group engagement in the assessment. You will have to identify the relevant specific
substantive procedures that would be appropriate for this type of engagement.

To do this, you should consider the relevant accounting policies, risks and assertions.
You should approach the audit of the consolidation using the same methodology as for
any other balance; consider the ROMM, accounting policies and assertions to ensure you
have coverage of all areas requiring procedures.

Evaluate group audit instructions

You may be asked to evaluate instructions given by the group auditor to the component
auditors for a particular group.

You will need to apply the knowledge gained from this module to evaluate these
instructions which may relate to the planning, controls testing, substantive testing or the
review stage of audit.

Conclusion
On completing this module, you can now attempt AAPQ 12.

11
8
Study guide checklist

Have you completed reading module 11?

Have you completed the skills checkers and skills builders?

Can you confidently complete the module learning outcomes listed on this module?

Can you confidently answer the guiding questions?

Have you completed the assessment practice questions?

Have you used the discussion board to ask questions on areas you are unsure
about?

11
9
Module 12 – Other assurance engagements
and related services
Introduction
Welcome to the study guide for Module 12 of the Advanced Assurance course. This
study guide will help you navigate the course material and prepare for the assessment.

Syllabus Learning Outcomes


 Apply practical skills and technical knowledge in providing assurance services

Module Learning Outcomes


By completing this module, you will have worked towards the following module learning
outcomes:

 Plan non-statutory assurance and sustainability reporting engagements,


including assurance engagements over financial and non-financial information

This will be achieved by working towards the following performance indicators:

 Explain the nature of other assurance services, related services and other
services provided by professional accountants and recommend suitable types of
engagements
 Design and evaluate the distinct considerations and requirements when
undertaking engagements other than a financial statement audit

You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.

Here is a reminder of some key points to look at in this module.

12
0
Assurance engagement
An engagement in which a practitioner aims to obtain sufficient appropriate evidence in
order to express a conclusion designed to enhance the degree of confidence of the
intended users other than the responsible party.

Elements

Appropriate Sufficient Written


Three-party
underlying Suitable and assuranc
relationship
subject criteria appropriate e report
matter audit

Tutor tip
In the AA assessment, you may be asked to assess if an engagement, that is not a
statutory audit, is an assurance engagement. The five elements (i.e. a three-party
relationship, an appropriate subject matter, suitable criteria, sufficient, appropriate
evidence and a written assurance report) are a good checklist to remember to consider
the different aspects that should be considered.

Level of assurance given may be reasonable or limited.

Key stages
1. Acceptance and continuance - consider commercial and professional factors.
Potential outcomes of preliminary risk assessment are:
a) Accept a duty of care and include an agreement by the third party in the engagement
letter
b) Ensure the third party confirms there is no duty of care
c) Include a disclaimer of liability to any third party in the report
d) Reject the engagement

An engagement can only be accepted or continued if it exhibits the following characteristics:

 The engagement partner has no reason to believe that ethical requirements


will not be satisfied
 The engagement partner is satisfied the engagement team have the appropriate
competence
and capabilities
 The basis upon which the engagement is to be performed has been agreed through:
 Establishing preconditions for an assurance engagement are present
 Confirming each party understands the responsibilities of the practitioner

The practitioner can only accept the assurance engagement if the following
preconditions have been met:

 The roles and responsibilities of the parties are suitable in the circumstances
 The underlying subject matter is appropriate
 The criteria are suitable to the engagement circumstances
 The criteria to be applied will be available to the intended users
 The practitioner expects to be able to obtain the evidence needed to support their
conclusion
 The conclusion is to be contained in a written report
 The practitioner is satisfied that there is a rational purpose for the engagement
and expects to be able to obtain a meaningful level of assurance

Engagement letter – clarifies responsibilities, the scope of the engagement and the
form of report that will be provided or work that will be performed.
12
1
Quality management -- quality management procedures (e.g. recording work,
supervision, review) should be followed as required by ISQM (UK) 1.

2. Planning - should set the scope, timing and direction of the engagement.

Items to consider:

 The characteristics of the engagement that define its scope


 The expected timing and the nature of the communications required
 The results of engagement acceptance activities
 The engagement process
 The practitioner’s understanding of the appropriate party and its environment
 Identification of intended users and their information needs, and consideration of
materiality
and the components of engagement risk
 The extent to which the risk of fraud is relevant to the engagement
 The nature, timing and extent of resources necessary to perform the
engagement, such as personnel and expertise requirements
 The impact of the internal audit function on the engagement

Materiality should be set considering what factors could reasonably influence the
decisions of the intended users

3. Evidence collection - will include obtaining a detailed understanding of the


underlying subject matter.

Considers:

 Risk considerations, and relevant responses (including tests of controls and


substantive procedures)
 The relevance and reliability of the evidence gathered
 The use of a practitioner’s expert or internal audit
 Written representations from management
 Subsequent events

4. Completion and reporting – assurance engagement report will include an opinion


similar to the opinion given in an auditor’s report:

Practitioner's judgment about the pervasiveness of


Nature of matter giving rise to the the effects or possible effects on the subject matter
modification information
Material but not Material and pervasive
pervasive
Subject matter information is Qualified
Adverse opinion
materially misstated opinion
(‘except for’)
Qualified
Limitation of scope Disclaimer of opinion
opinion
(‘except for’)

The minimum content of an assurance engagement report is as follows:

 Title clearly indicating the report is an independent assurance report


 Addressee
 An identification and description of the level of assurance obtained by the
practitioner and the underlying subject matter
 Identification of the criteria; where these are designed for another purpose, this
must also be stated
12
2
 If appropriate, description of any significant, inherent limitation with
measurement or evaluation of the subject matter
 A statement to identify the responsible party and describe their responsibilities
 A statement that the engagement was performed in accordance with ISAEs
 A statement that the practitioner’s firm applies ISQM (UK) 1 and ISQM (UK)
2 or other equivalent professional standards
 A statement confirming the practitioner's adherence to appropriate
professional and ethical standards
 An informative summary of the work performed as a basis for the conclusion
 The conclusion
 The practitioner's signature
 The date of the assurance report
 The location where the practitioner practices

Tutor tip
In the AA assessment, you may be provided with a scenario outlining the type of assurance
(or engagement) required. Examples of how you may be tested on this topic include:

 Comparing the level of assurance with an audit and outlining the key
differences in the form and content of reports issued
 Assessing whether an engagement is an assurance engagement
 Determining the form of report and evidence to be collected, and
 Outlining the stages of the assurance engagement and the considerations for
the auditor at each stage

Using the content in the lesson can help as a prompt to ensure you are covering a range of
issues, if required in the question.

Related services
Engagements where the practitioner performs services without providing assurance:

 Agreed-upon procedures – procedures to be performed are specified in the


engagement letter. The practitioner performs these procedures and reports
factual findings and results to the user.

It is the user's responsibility to interpret these findings to draw their own conclusions
and opinion. The practitioner reports on the agreed-upon procedures and
findings objectively in terms that are clear, not misleading and not subject to
varying interpretations.

They do not express any type of opinion or conclusion on the results.

 Compilation engagements – involves compiling financial information, such as


preparation of financial statements. No type of opinion or conclusion is
expressed.

A compilation engagement would commonly include the preparation of financial


statements but may also include the collection, classification and summarisation
of other financial information.

12
3
Types of assurance engagement
Review of interim financial information

 All listed companies must make public a half-yearly report. Companies can
choose to have this reviewed.
 Limited assurance engagement - opinion expressed in ‘negative’ form
 Less work, less costly for client

The key stages of a review of interim financial information are:

 Planning - the external auditor would have obtained an understanding of the


entity and its environment, including its internal control. In planning a review of
interim financial information, the auditor updates this understanding
 Evidence - primarily obtained by enquiry and analytical procedures
 Completion – the auditor will evaluate results of procedures performed,
including any uncorrected misstatements, and will form a conclusion
 Reporting – report should clearly state that the review is not an audit and the
auditor is not expressing an audit opinion

Assurance on prospective financial information (PFI)

 PFI is any financial information that is based on assumptions about events that
will happen in the future.
 It can be in the form of a forecast or projection or a combination of both
 More common to be limited assurance engagement (opinion in negative
form) due to subjectivity of PFI
 Auditor’s risk is higher if period covered is longer
 Procedures will include
 The likelihood of material misstatement
 The knowledge obtained during any previous engagements
 Management’s competence regarding the preparation of
prospective financial information
 The adequacy and reliability of the underlying data
 The extent to which the prospective financial information is
affected by the management’s judgement and reasonableness
of assumptions
 Correct application of assumptions in preparation of prospective financial
information
 Disclosure of assumptions (i.e. whether best estimates or hypothetical)
 Consistency of accounting principles and practices used in
historical financial information in preparation of prospective
financial information
 Obtaining written representations

Forensic audits

 Relates to the application of auditing skills to situations that have legal


consequences, such as the investigation of fraud or suspected fraud
 The auditor may be engaged to assess risks, test controls and identify
weaknesses in those controls.

12
4
Internal controls

Examples of circumstances where a client may request a professional accountant to


undertake an engagement concerning the testing of internal controls include the
following:

 Internal control assessment - to assist management in fulfilling their


responsibilities to ensure effective controls are in place and operating.
 Internal audit - professional accountants may be involved in undertaking
engagements reviewing the effectiveness and operation of internal controls over
financial systems as this is their area of expertise. The report produced may be
similar to a management letter highlighting weaknesses found and offering
recommendations.
 Service organisations - the client may use a service organisation (or be the service
organisation) whose functions are integral to the entity’s operations. The entity
using the service organisation may want assurance that the controls in place are
appropriate to ensure its operations or assets are properly accounted for and
managed (Type 1 and Type 2 reports).

Due diligence engagements

 Commonly performed where one company is planning to take over another


 Examples of procedures include:
 the legal investigation of contracts and obligations
 investigation of tax affairs or potential exposure
 an assessment of business operations
 a review of financial information

Public sector engagements

 Includes work related to grants


 Such work may be part of the scope of the public sector audit or may be
a separate engagement
 An example is Housing Benefit (HB) - consider administration and claims

Charity engagements

 OSCR requires charity’s accounts to be externally scrutinised


 Many charities can elect to submit an ‘independent examination’ of their
accounts, which is intentionally less onerous than a full audit
 An independent examination looks at a charity's accounting records and annual
accounts and considers whether the accounts are a fair reflection of the
underlying records.
 It provides a degree of comfort to the reader that the figures in the accounts and
the Trustees' Annual Report present an accurate picture of the financial activity of
the charity for the accounting period.

Sustainability reporting and assurance


The assurance engagement may:

 Provide assurance that sustainability information published is accurate


not materially misstated and, thus, increase the credibility of such
information
 Challenge views published in the annual report as part of disclosure; and/ or
 Complement internal processes such as internal audit or stakeholder engagement.

12
5
Organisations may report on sustainability and associated areas through several channels.
For example:

 An environment, social and governance report included in the annual report or


separately;
 A sustainability report included as part of the annual report or published separately;
 Through integrated reporting; or
 Listed entities reporting on green house gas emissions in their annual directors’ report.

Impact of sustainability risks and sustainability reporting on external audit

Where sustainability risks are financially material for a company, its auditors must consider
whether those risks are properly reflected in the financial statements in order to report
whether they provide a true and fair view of the financial position and performance of
the company.

Additionally, if sustainability reports are included in the annual report with audited financial
statements, the auditors will have responsibility to review these reports for consistency
with the financial statements.

Guidance on sustainability assurance

Sustainability assurance is a new and evolving area of assurance

engagements. Existing IAASB Standards and guidance that deal with

sustainability broadly include:

1. ISAE 3000 (Revised) Assurance Engagements Other than Audits or Reviews of


Historical Financial Information
2. ISAE 3410 Assurance Engagements on Greenhouse Gas Statements
3. The package of non-authoritative guidance on applying ISAE 3000 (Revised) to
sustainability and other extended external reporting assurance engagements

The auditor would seek evidence to verify the content of the report, including information such as:

Health and safety  Objectives regarding. health and safety


performance  Performance against objectives

Environmental  The organisation’s approach to the environment and sustainability


performance  An organisation’s assessment of climate risks
and  Aims and targets with reference to the organisation’s KPI’s
sustainability  How environmental factors are considered in investment appraisal
Business  Management systems and procedures in place to handle BC/DR,
continuity (BC) including responsibility structure.
and disaster  The regime established to test these plans, and possible
recovery (DR) references to third party audit/testing arrangements
 Considerations of the possible impact of extreme weather events
caused by climate change
People/human  Objectives e.g., recruitment strategy, staff retention, workforce
resources diversity, personal development and training, salary,
remuneration and incentivisation policy, company ethos,
employee communication methods used
Community  Objectives and approach to charitable giving and the policy on
relations encouraging staff involvement in local charities, community
projects and voluntary organisations

To meet the global need for consistent sustainability assurance standards, the IAASB has
developed proposed International Standard on Sustainability Assurance 5000 (ISSA
12
6
5000) General Requirements for Sustainability Assurance Engagements.

12
7
Conclusion
On completing this module, you can now attempt AAPQ 2 and 11.

Study guide checklist

Have you completed reading module 12?

Have you completed the skills checkers and skills builders?

Can you confidently complete the module learning outcomes listed on this module?

Can you confidently answer the guiding questions?

Have you completed the assessment practice questions?

Have you used the discussion board to ask questions on areas you are unsure
about?

12
8

You might also like