Module 1
Module 1
Advanced
Assurance
Study Guide
2024
Contents
Course overview................................................................................................................................... 2
Module 1 – Professional Ethics........................................................................................................... 4
Module 2 – Evaluating data integrity................................................................................................. 13
Module 3 – Audit acceptance and continuance decisions..............................................................20
Module 4 – Audit Planning................................................................................................................. 29
Module 5 – Specific risk areas and the impact on the audit approach..........................................42
Module 6 – Internal Control Testing.................................................................................................. 50
Module 7 – Substantive Analytical Procedures...............................................................................62
Module 8 – Substantive Procedures – Part 2...................................................................................66
Module 9 – Substantive Procedures – Part 3...................................................................................80
Module 10 – Completion and Reporting...........................................................................................87
Module 11 – Group Audits............................................................................................................... 100
Module 12 – Other assurance engagements and related services...............................................111
1
Course overview
Module Module title Content
1 Professional ethics Ethical threats (financial, business, employment and
personal relationships; long association, fees,
remuneration and evaluation policies, gifts &
hospitality and litigation; non- audit/additional
services)
2 Evaluating Data integrity
data integrity Evaluating the reliability of information
3 Audit acceptance Acceptance and continuance risks
and continuance Acceptance and continuance
decisions
procedures
Responding to acceptance risks
4 Audit planning Risk assessment
Planning analytical
review Materiality
Responses to assessed risk
Documentation and communication with those
charged with governance
5 Specific risk areas Laws and
and the impact on regulations Related
the audit approach
parties
Audit of accounting estimates
Using the work of others
6 Internal control Auditor’s testing of internal
testing controls The sales system
The purchase system
The non-current assets
system The payroll system
The inventory management system
Internal audit
7 Substantive Substantive analytical procedures
analytical Incorporating technology in substantive
procedures
testing
8 Substantive Designing a substantive testing audit work
procedures – part programme Specific accounts and considerations
2
Designing follow up substantive
procedures Comparative and opening
balances
Final considerations
9 Substantive Audit sampling
procedures – part Practical application
3
Outstanding matters
Recording, considering and communicating
misstatements
2
Module Module title Content
10 Completion Going concern
and reporting Subsequent events
Evaluation of evidence
Completion documents and quality
review Audit report
Communication with those charged with governance
11 Group audit Acceptance and continuance of group audit
engagements Group audit planning
Group audit: Test of controls, substantive testing,
completion and reporting
Communication between group auditor and
component auditors
12 Other Assurance engagements and related
assurance services Review of interim financial
engagements
information Assurance on prospective
and related
services financial information Other assurance
engagements
Assurance on sustainability information
3
Module 1 – Professional Ethics
Learning Outcomes
Evaluate and respond appropriately to ethical issues arising in assurance engagements
The Auditing and Reporting Handbook and the ICAS Code of Ethics will be available in
the assessment platform during your assessment.
You may take a hardcopy of IFRS Standards into the assessment, which you are allowed
to highlight, tab, sideline and underline.
You should ensure that you practice using these materials throughout the
4
ICAS Code of Conduct
The five fundamental principles of ICAS Code of Conduct are:
Integrity
Objectivity
Professional competence and due care
Confidentiality
Professional behavior
Threats to Independence
The FRC’s Ethical Standard (ES) identifies six threats to independence, which are:
Self-interest threat
Self-review threat
Advocacy
Familiarity
Intimidation
The following are the five things that can potentially compromise the independence
of auditors:
1. Self-Interest Threat
A self-interest threat exists if the auditor holds a direct or indirect financial interest in
the company or depends on the client for a major fee that is outstanding.
Example
The audit team is preparing to conduct its 2020 audit for ABC Company. However,
the audit team has not received its audit fees from ABC Company for its 2019 audit.
Issue
The audit team might be tempted to issue a favorable report so that the company is
able to secure a loan to settle the fees outstanding for their 2019 audit.
2. Self-Review Threat
A self-review threat exists if the auditor is auditing his own work or work that is done
by others in the same firm.
Example
The auditor prepares the financial statements for ABC Company while also serving as
the auditor for ABC Company.
Issue
5
By having the auditor review his or her own work, the auditor cannot be expected to
form an unbiased opinion on the financial statements.
3. Advocacy Threat
An advocacy threat exists if the auditor is involved in promoting the client, to the
point where their objectivity is potentially compromised.
Example
The auditor is assisting in selling ABC Company while also serving as the auditor for
the company.
Issue
The auditor may issue a favorable report to increase the sale price of ABC Company.
4. Familiarity Threat
A familiarity threat exists if the auditor is too personally close to or familiar with
employees, officers, or directors of the client company.
Example
ABC Company has been audited by the same auditor for over 10 years and the
auditor regularly plays golf with the CEO and CFO of ABC Company.
Issue
The auditor may have become too familiar with the client and, thus, lack objectivity
in their work.
5. Intimidation Threat
Example
ABC Company is unhappy with the conclusion of the audit report and threatens to
switch auditors next year. ABC Company is the biggest client of the auditor.
Issue
6
The firm should have policies in place for procedures regarding certain ethical matters
All firms (with the exception of the smallest) should appoint an ethics partner
Communicating significant facts and matters that impact on auditor integrity,
objectivity and independence to those charged with governance
(Means those entrusted with the supervision, control and direction
of an entity and would therefore include the audit committee and
non-executive directors. They only include management when it
performs such functions
Step 2: Think of the relevant ethical guidance and of explain its IMPLICATIONS on
auditor’s objectivity and independence
7
TYPES OF THREATS AND ETHICAL ISSUES
Financial Interest
A financial interest in a client constitutes a substantial self-interest threat.
Business relationships
A close business relationship will involve a common commercial interest, which in
addition to a self- interest threat, could cause advocacy or intimidation threats to
independence.
8
Employment relationships
The loan of personnel to an audit client might create a self-review, advocacy, familiarity or
management threat.
Significance of the threats depend on the role the individual was at in the audit team,
the seniority of the role that they have taken up at the client and the length of time that
has passed between the individual’s connection with the audit engagement and the new
role at the client.
1
0
Long association with an audit engagement
Long association by senior members of the audit team with a particular audit client
might lead to familiarity, self-interest and self-review threats as there can be actual or
perceived lack of scepticism when performing the audit.
The ES’ requirements differ for public-interest and non-public interest clients:
Engagement partners should be rotated after 5 years (to safeguard the quality of
the audit this may be extended to 7 years)
The engagement quality control reviewer should be rotated after 7 years (and
must not return for 5 years)
Any other key partners (such as tax partner) should be rotated after 7 years
(and must not return for 2 years)
The independence of any other audit staff should be seriously considered and
discussed with the ethics partner after seven years.
Rotation of the audit partner should be considered after 10 years in the role.
If this is not carried out, an alternative safeguard should be put in place, such as:
Involving an additional partner who is not involved, or has not recently been
involved, on the audit engagement to review the work
If the individual is not removed, the reasons behind the decision must be
documented and those charged with governance of the audit client should be
informed.
The Companies Act 2006 includes rules on mandatory audit firm rotation of auditors of
public interest entities. A maximum period of 10 years has been introduced which can be
extended to 20 years provided that an appropriate tender process takes place at least
every 10 years. Therefore, under the Companies Act 2006, an audit firm can only
undertake the audit of a specific PIE for a limited period.
Where fees are overdue, a self-interest threat to independence may arise. The overdue
fee effectively constitutes a loan to a client.
Fee dependence covers situations where firms may be reluctant to act in a way which
could jeopardise their relationship with the client, for fear of losing a significant portion
of their fee income.
If the auditor is receiving substantial fees for non-audit services from an audit client or
is perceived to be dependent on a particular client, there may be a perceived self-
interest and intimidation threats to independence.
If audit team members have their performance appraised or their pay linked to their
ability to cross sell the firm’s services to audit clients, the self-interest threat that may
arise is so significant that no ` ` `
11
Ethical threat Safeguard
Providing audit or non-audit services on a Threat is so significant that there is no
contingent fee basis. safeguard possible.
Overdue audit fees The engagement partner and ethics
partner should consider whether the audit
firm can continue or whether it is
necessary to resign unless fees are clearly
trivial.
If the firm does not resign, the
engagement partner should apply
appropriate safeguards (such as a review
by a partner with relevant expertise who
is not involved in the engagement) and
notify the ethics partner of the facts
concerning the overdue fees.
Dependence on non-audit services The total fees for non-audit services in
relation to a public interest audit client are
capped at 70% of the average of the fees
paid over the last three years for the audit
of the entity.
Dependence on one client If total recurring fees (audit and non-
audit) are expected to regularly exceed
10% (public interest and other listed
clients) or 15% (non- listed clients) of the
annual fee income of the audit firm, then
the auditor should resign or not stand for
re-appointment.
Total fees approaching these limits should
be disclosed to the ethics partner and
those charged with governance at the
client.
Potential safeguards include reducing the
amount of non-audit work and applying
independent internal quality reviews.
Remuneration for selling non-audit services Auditors should not be remunerated,
appraised or given bonuses based on the
selling of non- audit services to audit
clients. The focus for evaluation and
remuneration should be audit quality.
1
2
Threatened and actual litigation
When a client threatens to sue or sues the firm for work that has been done previously, self-
interest, intimidation and advocacy threats to auditor’s integrity, objectivity and independence
arise.
Non-audit services explicitly prohibited for PIE clients that are audit clients are given in
the document FRC ES - Appendix B. This is included within the ICAS Auditing and
Reporting Handbook, which is permitted material for your assessment.
Internal audit
Accounting services – not permitted on listed clients
IT services – the design, provision or implementation of a significant part of the
accounting system is not permitted
Corporate finance services - services that involve dealing, underwriting or
promoting an audit client’s shares are not permitted
Recruitment and remuneration services
Tax services – those which involve the firm undertaking a management
role are not permitted.
Valuation services – not permitted on listed clients
Legal services/litigation support services
13
Assessment approach
It is important to understand that in AA, marks are given for appropriate application
of the knowledge rather than just stating knowledge.
Step 2: Think of the relevant ethical guidance and of explain its IMPLICATIONS on
auditor’s objectivity and independence
Conclusion
On completing this module, you can now attempt AAPQ 15 and 23.
1
4
Module 2 – Evaluating data integrity
Introduction
Welcome to the study guide for Module 2 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.
Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:
You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.
15
Data integrity
Considers maintaining the integrity of the data as it is stored and retrieved and the
procedures to manage when the physical integrity of data may be compromised.
Logical integrity
Focus on the rationality of the data itself. There are four types of logical integrity:
1
6
The difference between data integrity, security and quality
Data integrity Data integrity is the threat that data is modified or corrupted within its
life cycle as a result of failures, such as those around storage,
processing, software or human intervention.
Data security Data security deals with protecting data against unauthorised access
or disclosure, which is important to ensure data integrity.
Data security focuses on keeping data inaccessible to those who
should not have access.
Data quality Data quality focuses more on whether the data meets any defined
standards and the needs of the organisation, and therefore can be used
for its intended purpose.
17
Maintaining data integrity
There’s no single universal solution for maintaining data integrity. There are numerous
tactics that can help to build an environment that supports data integrity. These include:
Audit Evidence
Auditors must gain sufficient appropriate evidence on which to base their
Relevant
Reliable
1
8
Relevance
Evidence will be relevant if it provides evidence over one or more financial statement
assertions as listed below:
Professional scepticism
The auditor should always exercise professional scepticism, and this requires a challenging
and questioning mind. Auditors exercise professional scepticism as follows:
19
Some examples of relevant ADA procedures:
Assessment approach
When you are asked to analyse risks to data integrity and evaluate their impact on management’s
ability to design and implement an effective strategy:
You should begin with identifying risks to data integrity when you are reading the
scenario.
You should then analyse the risk by thinking of its implications.
When asked to evaluate the impact of the risks on the organisation’s strategy, think
about the impact of unreliable data on the company’s ability to make proper
decisions.
When you are asked to analyse information given in the scenario to highlight any concerns over
the accuracy, validity and completeness of the underlying data:
You need to begin by identifying the issue from the scenario and then analyse it.
It is important to read the information provided carefully. Look for unusual trends or
information that appears to contradict other information and explain them.
When you are asked to describe any further audit evidence (or procedures) that are required to
conclude on whether reliance can be placed on the underlying data by the audit team:
When explaining evidence (or procedures), ensure that you identify the source document
and then go on to explain what you are confirming from the source document.
Conclusion
On completing this module, you can now attempt AAPQ 4 and 20.
2
0
Study guide checklist
Can you confidently complete the module learning outcomes listed on this module?
Have you used the discussion board to ask questions on areas you are unsure
about?
21
Module 3 – Audit acceptance and continuance
decisions
Introduction
Welcome to the study guide for Module 3 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.
Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:
Evaluate the results of acceptance and planning procedures, including the use
of audit data analytics to assess and determine the risk of material
misstatement and impact on audit approach
You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.
2
2
Key terms from ASR
The risk assessment, engagement and client management elements must run throughout
the whole of the audit process and are referred to as ongoing elements.
The other five elements (acceptance, planning, systems and control analysis, substantive
testing, and completion) represent the stages of the audit process.
Audit process
Risk assessment
Element Detail
Acceptance Before the engagement begins
Professional and ethical requirements
Planning Need to gain an in-depth understanding of the client, its
environment, the financial reporting framework and the system
of internal control
From this, the auditor will identify areas in the financial
statements that have a higher chance of fraud or error
Preliminary materiality level will be set, which will be reviewed
throughout the audit
Planning usually happens before the year end.
Systems and Understand what processes and controls a client has in place
controls Test how effectively these operate in terms of preventing or
analysis detecting an error/fraud (or ‘misstatement’) in the accounts.
Frequently occurs during an ‘interim audit’ before the entity’s year
end.
Substantive Occurs after the year end
testing Involves testing the figures in the financial statements
to identify misstatements
Completion Performed to allow the audit to be concluded
& reporting The final audit report can be issued, stating whether, in the
auditor’s opinion, the financial statements are ‘true and
fair’.
Risk Auditors follow a ‘risk-based approach’ in external audits.
assessment More work done by the auditor where there is more risk of
misstatement
Ongoing element
Engagemen Audit must be properly managed
t and client Appropriate staff
manageme Adequate review
nt Managing clients' expectations
Communication within the audit team and between the client
and the audit team is a key requirement
Ongoing element
23
Auditors do not need to wait for the accounting year end to start the audit process. For
larger clients, an interim audit may be carried out.
A proposal will generally be submitted summarising key information regarding why the
audit firm should be chosen by the prospective client. This will include:
An estimate of the audit fee The audit team profile An initial assessment of
including experience the key risk areas
An explanation of the tools Client deliverables, A follow up presentation
and technologies to be used meetings and engagement
timeline
Risk analysis
Firm’s ability to audit the client
Ethical considerations
Communication with the outgoing auditor
2
4
Acceptance/continuance risks
The audit firm must assess risks of accepting/continuing the client engagement.
ISQM (UK) 1
The firm’s system of quality management
The audit firm must establish processes to ensure that relevant ethical requirements,
including those related to independence, are fulfilled. These procedures should ensure
that the firm and its staff:
The firm must establish a process to ensure that judgements about whether to accept or
continue a client relationship or engagement are appropriate based on:
The audit firm should not let financial or other operational priorities lead to inappropriate
decisions about accepting or continuing an engagement.
25
ISA (UK) 220
Preliminary engagement activities
At the beginning of an audit engagement, the auditor must undertake the following activities:
Ethical requirements
To establish that the preconditions for an audit are present, the auditor shall:
If management imposes a limitation on the scope of the auditor’s work that the auditor
believes will result in the auditor disclaiming the opinion on the financial statements, the
financial reporting framework is not applicable or management does not agree to
acknowledge and understand their responsibilities as laid out above, the auditor must
not accept the engagement unless required by law or regulation to do so.
2
6
Tutor tip
The auditor obtains such information as is deemed necessary in order to reach a decision
regarding the acceptance of the engagement. This information is then assessed
according to how it impacts the audit firm in terms of commercial and professional risk.
An assessment question should be approached in the same way. If you are given
information about a client in the scenario, you need to identify facts from the scenario to
consider how they impact the audit firm’s risks. Then, as a part of the analysis, you should
explain the importance of the facts in relation to the acceptance decision.
Example
You may wish to use the anagram below to help remember these:
1. Identify the users and nature of the engagement - includes understanding the
prospective client, the impact on legal responsibilities and the nature of the
financial statements.
The auditor should consider the nature of the financial statements, including whether the
general- purpose financial statements will meet the needs of the users or whether any
special-purpose reports will be required.
27
2. Assess the prospective client's legal and financial stability – an auditor will want to take
steps to protect themselves from the risk of legal claims or unpaid audit fees.
Clients that pose a high risk of litigation or financial loss may be rejected, such as:
3. Assess integrity of TCWG, management and the principal owners - an auditor should
seek reasonable assurance that the entity’s management can be trusted.
To assess the integrity of management the auditor should perform a number of procedures:
5. Evaluate the audit firm's ability to audit the entity - this may include assessing:
7. Agree the basis for performance of the audit - the auditor must establish the
preconditions for an audit and that there is a common understanding between the
auditor and management about the terms of the engagement.
Tutor tip
In a scenario question, you will be required to consider how the facts provided impact the
risks to the firm. As discussed in the previous lesson, the facts must be analysed, not
simply identified, in order to gain marks.
Use the seven procedures as a checklist to identify all of the issues relevant to the
question. This should increase your chances of identifying enough points for the marks
available. It is a reminder of the things you should consider and does not represent the
headings that you need to use.
The ethical standard headings may be used as a further prompt to ensure all
2
8
independence risks are considered.
29
Continuance procedures
A continuance decision focuses primarily on any changes since the prior year audit
An evaluation of risks and consideration of independence will still be required
For a public company a decision will need to be made before the AGM. During the
completion stage of the prior year audit is common
A private company does not require an AGM to re-appoint the auditor. The
statutory auditor is automatically re-appointed each year
Safeguards are required where risks are identified, or else the engagement should be declined.
Examples of steps to eliminate risk or reduce it to an acceptable level include the following:
Recruiting audit staff or using seconded staff from other offices to ensure
audit staff have sufficient time to complete the engagement within the
required timeframe.
Rotation of the engagement partner or other members of the engagement team.
Using an auditor’s expert where the audit firm lacks competence to audit a specified
area.
Using separate engagement teams where independence issues arise.
Engagement quality control review (independent partner review).
Tutor tip
A question may ask you to identify the specific risks arising from the scenario and a
response to those risks that would enable the firm to take on the client. You must ensure
that you can identify and explain how these acceptance risks impact the audit firm and
be able to propose safeguards, where appropriate, to mitigate each risk or reduce it to
an acceptable level.
You must also be able to identify when an auditor is unable to propose sufficient
safeguards or is prohibited outright from undertaking the engagement. When proposing
safeguards, you should ensure that they are relevant to the firm outlined in the scenario.
For example, partner rotation is an inappropriate safeguard for a one-partner firm.
Engagement letters
ISA (UK) 210 includes the requirements regarding the engagement
letter:
3
0
The following items may be included in the engagement letter:
For continuing engagements, where significant changes have taken place since the prior
year audit, a new engagement letter may be required.
Can you confidently complete the module learning outcomes listed on this module?
Have you used the discussion board to ask questions on areas you are unsure about?
31
Module 4 – Audit Planning
Introduction
Welcome to the study guide for Module 4 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.
Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:
Evaluate the results of acceptance and planning procedures, including the use
of audit data analytics to assess and determine the risk of material
misstatement and impact on audit approach.
You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.
3
2
Audit Planning
Good planning ensures audit focused on risky areas and carried out in an
efficient/ effective manner
Planning is a continuous process
Audit strategy: Audit strategy memorandum (ASM) captures the main general
areas of planning: materiality, risk, audit approach, use of experts
and internal audit, timing, team, budgets and deadlines.
The overall audit strategy should be updated as necessary during
the course of the engagement.
Audit plan: The plan contains the detail needed to implement the strategy
The audit plan is more detailed than the overall audit strategy in
that it includes the nature, timing and extent of audit procedures
to be performed by engagement team members.
Audit risk
Audit risk is the risk that the auditor gives an inappropriate opinion on the financial
statements when the financial statements are materially misstated.
The combination of Inherent Risk and Control Risk is called Risk of Material Misstatement (ROMM).
Enquiry Inspection
Of management and others within the May include inspection of internal
client documents and reports prepared by
management and TCWG
Analytical Procedures Observation
Help identify inconsistencies or unusual May support or contradict inquiries. May
transactions or trends occur at client’s premises.
Additionally, the auditor is required to consider information from other sources and engagement
team discussion.
33
Understanding the entity
Auditor must gain an understanding of:
In order to assess ROMM, it is important to understand its impact at the overall financial
statements level as well as the assertion level.
ISA (UK) 315 requires that risks of material misstatement are identified and assessed in
terms of their impact at:
Risk of material misstatement at the assertion level – the assertions are as follows:
3
4
Control risk
Control risk is the risk that an organisation’s internal control systems do not adequately
prevent or detect and correct a misstatement either because they are poorly designed
or do not operate effectively.
Control risk is assessed predominantly at the systems and controls stage of the audit.
Inherent risk
Inherent risk can arise from:
Business risk Only an audit risk if they could result in a material misstatement in
the financial statements
Strategic and operational (market, organisational, financial)
Reliable financial reporting
Compliance (social and environmental/legal and regulatory)
Inherent risk factors Complexity – Arises either from the nature of the information
or in the way that the information is prepared.
Subjectivity – Arises from inherent limitations in the ability to
prepare information objectively, due to limitations in the
availability of knowledge or information, such that
management is required to make a judgement.
Change – May include changes to the entity’s business
operations, accounting standards, regulatory environment
or industry which have an impact on the financial
statements.
Uncertainty – Arises when the required information cannot
be prepared based on only sufficiently precise and
comprehensive data that is verifiable through direct
observation.
Susceptibility to misstatement due to management bias or other
fraud risk factors – This arises from conditions that create
susceptibility to intentional or unintentional failure by
management to maintain neutrality in preparing the
information. If intentional, this may
amount to fraudulent financial reporting.
Tutor tip
Students often identify the audit risk arising from business risks, such as the loss of a key
customer or too much inventory on hand. However, they often miss the inherent specific
risks relating to correct accounting.
This will identify a range of risks. You should always explain the risks in relation to the
possible impact of material misstatement in the financial statements.
For example, if the client has obsolete goods in stock, the business risk is that they
would need to sell it at lower margins (or scrap it), resulting in financial loss for the
business.
The risk of material misstatement needs to be linked to how this obsolete inventory has
been recorded in the year-end financial statements. If it has not been recorded at the
lower of cost and net realisable value, inventory and profit would be overstated. This
overstatement is the potential impact on the financial statements.
35
Fraud Risk
There are two different types of fraud:
The responsibility for the prevention and detection of fraud rests with management and
those charged with governance.
Tutor tip
Fraud risk factors or evidence that indicates a fraud has been committed will be included
in facts within a scenario. The factors listed within the appendices to ISA (UK) 240 are
common indicators you will be presented with. Being familiar with these indicators will
make it easier to identify from a scenario whether a fraud risk exists.
The fraud risk factor categories may be used as prompts in a risk question to identify all
of the factors that may result in a fraud risk. Often, it is easier to identify incentives to
commit fraud, but harder to identify the opportunities and rationalisations, such as a
weak control environment and disregard for controls. Events such as improved
profitability where available cash is declining are also indications that fraud may have
occurred. Therefore, using the categories can help you identify a larger range of fraud
risk factors.
The indicators that you identify should be explained in terms of them providing an
incentive, opportunity, rationalisation or evidence of a fraud occurring.
3
6
Going concern
General purpose financial statements are prepared on a going concern basis under which
assets and liabilities are recorded on the basis that the entity will be able to continue
trading for the foreseeable future and realise its assets and discharge its liabilities in the
normal course of business.
Audit objectives:
Obtain evidence regarding and conclude on whether there are any material uncertainties
Obtain evidence regarding and conclude on the appropriateness of the GC assumption
Report on GC
It is the responsibility of the directors to prepare the financial statements and to assess
whether or not the entity is a going concern and to prepare the financial statements
accordingly.
Tutor tip
You may be given a scenario in an assessment question and asked to identify the audit
risks. The facts that you may identify are the matters in the activity above, which should
be explained in terms of how they could impact the going concern. This is a risk to the
organisation and also an AR at the financial statement level.
For financial statement-level risks, you may find that several facts combine to create an
audit risk. For example, say a company has net liabilities and negative cashflows and
needs to repay a large loan in two months. In this instance, you should group the facts
together under the risk of the going concern assumption being inappropriate. Grouping
the points is important as multiple marks are not awarded for identifying separate going
concern points in the exam.
Significant risks
Includes risks with the highest inherent risk and those designated by ISAs (UK)
Fraud is required to be classified as a significant risk
Allows the auditor to focus more attention on those risks that carry a higher inherent risk
Assessment approach
For questions on analysing audit risks, the recommended assessment approach is:
1. Read through the scenario and highlight the relevant facts that can result in audit
risk (increase the chances of fraud or error in the financial statements)
2. Think of the impact of each fact on the financial statements
3. Write the answer. Ensure your answer cover the fact and the financial statements
impact. Use headings to improve the layout of your answer.
37
Planning analytical review
Analytical procedures are a mandatory risk assessment procedure at the planning stage.
Steps to perform:
1. Set an expectation
2. Compare the actual results to the expectation
3. Evaluate the results
4. Seek justification for the movement with a plausible explanation
5. Unexplained variances may create a potential audit risk
Tutor tip
In the AA assessment, if you are asked to perform planning analytical procedures, there
could be a variety of information sources provided within the scenario including
documents, notes or minutes from a meeting with the client. You should read through
this information carefully annotating anything that you think should be reflected in the
financial information. For example, if the scenario states that a new contract has been
entered into in the current year, you would expect revenue to increase against the prior
year as a result of that information.
Where you have identified scenario information that you expect to be reflected in the
financial information, you should focus on these areas first. For example, if you are told
that customer credit terms have been reduced, you could either calculate trade
receivables days, if not provided, or consider any analysis provided to confirm that this
is reflected.
You can then focus on any other movements or unusual/unexpected changes identified
from the results of the calculations.
In the AA assessment, you will likely be provided with information in relation to the client as
well as a summary of the results of the initial analytical review exercise. There may also
be a requirement to calculate your own expectation of a figure to complete the initial
analysis.
You should undertake an analysis of the rationale, where possible, of movements identified
during the analysis and identify and evaluate any potential audit risks. A common
mistake is to immediately assume there is an audit risk and fail to analyse the movement
using the information in the scenario. This analysis is the key element of an analytical
review and aids the auditor in informing their judgement over audit risk.
However, as noted it is important to consider if there are still any indicators of an audit risk, even if
the movement has been explained, and ensure this is included within your analysis.
1. Read the scenario, highlight key information and if required, create an expectation
using the information available.
2. Analyse the movements, attempting where possible, to explain the changes
using the information in the scenario.
3. Using the results of your analysis in Step 2, identify and evaluate potential audit
3
8
risks that would require further investigation by the audit team.
39
Audit materiality
To express an opinion on whether the financial statements are true and fair, and
therefore free from material misstatement, the auditor must decide what qualifies
as ‘material’.
Materiality is referred to throughout the audit and provides a basis for:
Determining the nature, timing and extent of risk assessment procedures
Identifying and assessing the risks of material misstatement
Determining the nature, timing and extent of further audit procedures
Overall materiality
Materiality for the financial statements as a whole is often referred to as overall materiality.
Tutor tip
In your assessment, it is important to fully explain the decisions made when assessing
materiality. As materiality calculations are not prescribed and are subject to professional
judgement, the rationale behind calculations must be documented on the audit file.
Therefore, in an assessment, you should explain the reasons behind selecting the
benchmark, data and final materiality figure so that the marker can understand your
justification and award appropriate credit.
4
0
2. Select the appropriate range to apply to the benchmark - the appropriate percentage is
based on the auditor's professional judgement. Examples of percentages applied to
different benchmarks include:
Benchmark Percentage
Profit before tax from continuing 5–10
operations
Operating expenses 0.5–2
Revenue 0.5–2
Total assets 0.5–2
Net assets 0.5–5
3. Select the data to be used to calculate materiality - the relevant data is dependent on
what is available to the auditor at the planning stage and what data the auditor
believes is the most representative of the expected actual financial statement
figures.
Data should be adjusted to show normalised figures. However, this should only be for
exceptional one-off items and not for items that recur each year, such as
amortisation of intangibles or due to a general change in trend.
4. Calculate materiality based on steps 1 – 3 - once the benchmark, data and percentage
range have been selected, the auditor can calculate the range from within which the
final materiality level can be calculated.
5. Select the final materiality figure from within the range - The final percentage selected
will depend on the risk within the entity. Where there is more risk, a lower level of
materiality should be selected. Considerations include:
Performance materiality
Used to assess ROMM, design further audit procedures and determine sample sizes
Lower than overall materiality to reduce the likelihood that total
immaterial undetected/uncorrected misstatements is material
Calculation involves professional judgement, often 50 - 75% of overall materiality
41
Response to assessed ROMM
Once the auditor has assessed the risks of material misstatement, they are required to
respond to the risks that they have found.
This will impact the audit approach – how they are going to obtain evidence about these
Significant risks
The determination of significant risks allows for the auditor to focus more attention on
these risks and perform certain required responses. These include:
Controls that address significant risks that should be evaluated
Controls that address significant risks that should be tested in the current period
(when the auditor intends to rely on the operating effectiveness of such controls)
and substantive procedures need to be planned and performed that are
specifically responsive to the identified significant risk
The auditor is required to obtain more persuasive audit evidence for these high-risk area
Significant risks must be communicated to those charged with governance
Timely review of audit documentation by the engagement partner at the
appropriate stages during the audit allows significant matters, including
significant risks, to be resolved on a timely basis to the engagement partner’s
satisfaction on or before the date of the auditor’s report
4
2
Tutor tip
Designing the audit approach for assertion level risks is less prescribed than financial
statement level risks as the approach must be tailored to the specific risk identified.
For some areas, such as related parties, fraud or laws and regulations, the ISAs provide
guidance on the audit approach where a ROMM exists.
Alternatively, for other assertion-level risks you should aim to include in your approach two
elements:
1. Management’s procedures and controls that the auditor would understand and test
2. A high-level substantive procedure that the auditor would undertake in relation to the risk
identified
You are planning the audit approach which will involve considering procedures at the
systems and controls, substantive testing and completion stage of the audit and,
therefore, your answer should cover the various stages of the audit.
If you are asked in the assessment to evaluate audit risks and design the corresponding
audit approach, you should keep this relatively high-level. Both substantive procedures
and controls will be considered in more detail later in the course.
Documentation: Planning
The objective of the auditor is to record of basis for auditor's report and evidence the audit
is planned and performed in accordance with ISAs (UK) and other regulations
ISA (UK) 240: Decision from fraud risk discussion, fraud risks, controls, responses
to fraud risks, results of procedures, how inconsistencies addressed,
communication to management and revenue recognition justification
ISA (UK) 300: Overall strategy, audit plan and any changes
ISA (UK) 315: Team discussions, UTE, evaluation of controls, risks
ISA (UK) 320: Overall, particular and performance materiality and any changes
ISA (UK) 330: Responses to risks, results of additional procedures
43
Matters to be communicated
Minimum to communicate at planning stage:
experts The
communication process
Inform TCWG of the form, timing and expected general content of communications
Communication should be in writing if oral communication deemed insufficient
Communications will reflect size and nature of the entity and the way TCWG operate
Assessment approach
It is important to understand that in AA, you will be required to apply your knowledge to the
information given in the scenario.
Active reading of the case and critical evaluation of each piece of information given in the
question is the main technique that needs to be applied while practising these
questions.
1. Read through the scenario, highlight the relevant facts that can result in audit risk
(ie increase the chances of fraud or error in the financial statements)
2. Think of the impact of each fact on the financial statements
Write the answer. Ensure your answer covers the facts and the financial statements impact.
Use headings to improve the layout of your answer.
For each audit risk identified, you need to think of a suitable risk response.
For responses at the assertion level you should consider if a specific ISA (UK) can provide
guidance or alternatively include in your approach two elements:
1. Management’s procedures and controls that the auditor would understand and test
2. A high-level substantive test that the auditor would undertake concerning the risk identified
Conclusion
On completing this module, you can now attempt AAPQ 17.
Can you confidently complete the module learning outcomes listed on this module?
Have you used the discussion board to ask questions on areas you are unsure about?
45
Module 5 – Specific risk areas and the
impact on the audit approach
Introduction
Welcome to the study guide for Module 5 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.
Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:
Evaluate the results of acceptance and planning procedures, including the use
of audit data analytics to assess and determine the risk of material
misstatement and impact on audit approach
You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.
4
6
1. Laws and regulations
Non-compliance may materially affect the financial statements through:
regulations:
Direct effect Laws and regulations that have a direct effect on the
determination of material amounts and disclosures in the
financial statements.
The auditor's responsibility is to obtain sufficient appropriate
audit evidence regarding compliance with the provisions of
these laws and regulations.
Do not have a direct effect Other laws and regulations that do not have a direct effect
on the financial statements but compliance with which may
be fundamental to operations of the business or non-
compliance may result in material penalties or the entity
failing to continue in the foreseeable future.
The auditor’s responsibility is limited to undertaking specified
audit procedures to help identify non-compliance with those
laws and
regulations that may have a material effect on the financial
statements.
A number of entities will have very specific laws and regulations that the auditor needs
to be aware of as part of their understanding of the entity e.g. public sector bodies such
as local authorities.
47
2. Related parties
ISA (UK) 550
A related party is an individual or entity that is related to the entity that is
preparing its financial statements. A related party relationship in the
following situations:
An individual (or close family) who controls or jointly controls an entity
An individual (or close family) who has significant influence over an entity
An individual (or close family) who is a key management personnel of an entity.
All entities within the same group, or associates and joint ventures related to the
group.
An entity and its pension plan.
Two entities that are connected through an individual with control or significant
influence.
An entity provides key management personnel services to another.
Increased risk of material misstatement in FS if:
There can be extensive and complex relationships and structures in place.
Information systems may not effectively identify or summarise transactions
Related party transactions
objectives
Auditor's Understand may not beparty
related conducted under normal market
relationships
terms and conditions (i.e. without exchange
Recognise fraud risk factors of consideration).
Conclude on fair presentation of FS
Obtain evidence of correct identification and disclosure
of related parties
Audit procedures The engagement team discussion considering the ROMM
due to related party relationships.
Enquiring of management about related party relationships
Understanding the controls over identifying,
accounting for, disclosing and authorising related
party transactions.
Remaining alert for evidence of related parties throughout
the audit when inspecting records and documents.
Inspecting bank and legal confirmations and board
minutes for evidence of related parties.
Inspect income tax returns, shareholder registers,
records of the entity's investments, life insurance
policies, etc.
Understanding related party transactions outside the
entity's normal course of business.
Risk assessment Auditors to assess if identified related parties pose
significant risk The following would automatically be
significant risks:
Significant related party transactions outside the
entity's normal course of business
Fraud risk factors identified when understanding related
party relationships, including a related party with a
dominant influence.
Responses to risk of If assessed risk is low:
material misstatement Test whether these controls were operating effectively
Perform substantive analytical review of the
transactions and balances
Other requirements:
3. Estimates
ISA (UK) 540
A monetary amount for which the measurement, in accordance with the
requirements of the applicable financial reporting framework is subject to
estimation uncertainty
Examples include provisions related to inventories and receivables, impairment
of intangible assets and valuation of financial instruments
Audit procedures There are various ways the auditor may obtain evidence, including:
An evaluation of the process for preparing the accounting
estimate, including the selection of the method,
experience of the preparer, assumptions and data used.
Audit of the calculation of management's point estimate.
Review of the disclosures about the accounting estimate,
including disclosures about how the accounting estimate was
developed and the
nature, extent, and sources of estimation uncertainty.
Risk assessment Auditors must obtain an understanding of matters related to accounting
estimates, including:
The entity’s environment and applicable financial reporting
framework (connected to inherent risk)
The system of internal control (connected to control risk), which
includes:
The client’s own risk assessment process
Management experts and the use of specialised skills
The entity’s information system
How management reviews the outcome of past
estimates The likelihood and magnitude of potential
misstatement is impacted by:
Estimation uncertainty - accounting estimates are an
approximation, and their measurement is uncertain. Higher
degree of estimation uncertainty will result in higher risk
Subjectivity, including management bias – management uses
judgement when developing assumptions, interpreting data and
selecting measurement. The higher the level of subjectivity, the
greater the risk of material misstatement
Complexity - determination of certain accounting estimates
can be complex if they require the use of methods or
models that require
specialised skills or knowledge in relation to their valuation.
Responses to risk of Obtaining evidence from events occurring up the date of the
material auditor’s report - e.g. reviewing a post-year end event such as
misstatement settlement of a legal case
Testing how management made the accounting estimate - includes
assessing if the method and assumptions are appropriate, the
data is relevant and reliable and if there are any indications of
management bias
Developing the auditor’s point estimate or auditor’s range of
estimates – the auditor may form their own estimate to assess the
45
reasonableness of managements estimate
46
4. Service organisations
ISA (UK) 402
A service organisation is a third-party organisation that provides services to
user entities that are part of the financial reporting process e.g. payroll
processing
A user entity is an entity that uses a service organisation whose financial
statements are being audited e.g. the audit client
Auditor to understand how an entity uses a service organisation:
Nature and significance of services
Nature and materiality of accounts processed
Interaction with/delegation to service organisation
Contractual terms/service level agreements
Auditor to evaluate design of controls audit client implements over service
organisation, including if necessary
Report from service organisation's auditor
Contact the service organisation
Visit and perform test of controls
Using another auditor
The auditor will not refer to the work of a service auditor in the audit report unless it is relevant
to the understanding of a modified audit opinion.
Auditor’s expert
procedures:
48
Agree work to be performed
Evaluate adequacy of auditor's experts work
Do not refer to expert in auditor's report
49
Tutor tip
You may receive information in the scenario about asset valuations, stock items that require
estimation, stage of completion for construction contracts, legal cases etc. These are
likely to be areas that are complex, judgemental or involve estimation and therefore
there is an audit risk that the amounts are misstated. The complexities arising from the
audit of accounting estimates were discussed in previous lessons. An appropriate audit
response may be to use an expert, in which case you will refer to ISA (UK) 500 Audit
Evidence or ISA (UK) 620 Using the Work of an Auditor’s Expert.
Considerations for objectivity, competence and a systematic and disciplined approach include:
50
Assessment approach
A scenario may indicate that particular laws and regulations are critical to the organisation.
These may include health and safety, terms of a licence, financial services and
environmental regulation. Where it is clear that a company is highly regulated and if
auditors become aware of any actual or suspected non-compliance, you should refer to
implications on audit work.
As with other audit risks, the relevant fact should be explained in terms of its impact on the
financial statements, e.g. going concern or unrecognised liabilities/judgemental
provisions and, if required, appropriate procedures should be designed in response to
the risk of material misstatement.
Within an audit risk and approach question, the scenario provided may include, for example,
the use of an accounting estimate, the use of an outsourced service provider, complex
related party relationships or management’s use of an expert. You should recognise
from the scenario that there is a specific auditing standard in relation to each of these
matters and refer to the requirements of the standard in preparing your answer.
You may also be asked to evaluate the strengths and weaknesses of an audit client’s
internal audit function and conclude on whether external auditors can rely on the work
of internal audit.
For questions related to relying on the work of others (experts and internal auditors in
particular), you’ll often be asked to conclude on whether reliance can be placed on their
work. It’s important to give that conclusion as it is awarded separate marks in the AA
assessment.
Conclusion
On completing this module, you can now attempt AAPQ 3.
Can you confidently complete the module learning outcomes listed on this module?
Have you used the discussion board to ask questions on areas you are unsure about?
51
Module 6 – Internal Control Testing
Introduction
Welcome to the study guide for Module 6 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.
Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:
performance indicators:
You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.
52
Systems and control analysis
The auditor's approach to evaluating and testing internal controls and the subsequent
impact on substantive testing:
1. Control environment
2. The entity’s risk assessment process
3. The entity’s process to monitor the system of internal control
4. The information system and communication and
5. Control activities.
Direct controls are controls that are precise enough to address risks of material
misstatement at the assertion level. The auditor is required to identify specific controls
in the control activities component, evaluate the design and determine whether the
controls have been implemented.
Indirect controls are controls that support direct controls. Having a strong control
environment is an indirect control. Understanding the indirect controls (i.e. the control
environment, the entity’s risk assessment process and its process for monitoring the
system of internal control) is important as it provides an overall foundation for the
operation of the other components of the system of internal control.
Information processing controls (IPCs) - are specific to a given application and their
objectives are to ensure the completeness, existence and accuracy of the accounting
records and the validity of entries made in those records.
The auditor must gain an understanding of control activities, even if not testing controls
Includes understanding direct and indirect controls, the use of IT in internal
controls and identifying key controls
53
Documenting internal controls
Narrative notes
Flowcharts
Checklists
The auditor must test whether the controls on which they plan to reply on
operated throughout the year
Test operation throughout period – only effective if operates consistently
Control testing techniques
Enquire PLUS inspect/observe/reperform
It is essential to test the control in operation throughout the whole period
under review, focusing on specifically higher-risk time periods to ensure
consistency in the control's application
CAATs and ADA are computer programs and data used to perform audit procedures
Normally applied where large volume of information of highly automated
processes/controls
Controls testing – test data and audit data analytics
Tutor tip
You may be asked to review the results of controls and system analysis carried out by ADAs
and evaluate their impact on audit risk and audit approach. You may be asked for
examples of CAATs or ADAs when identifying tests of control.
To identify relevant CAATs or ADAs, you may find it easier to firstly think about how you
would test this manually and then think about how you could use the techniques
described in this lesson to do the same test.
It’s important to remember that the objective of a sound internal control system over
financial reporting is to process the data (used to prepare the financial statements)
completely and accurately. You should therefore think about the risks (what could go
wrong) at each step of the process, from initiation of the transaction through to recording
in the individual ledgers and the general ledger. Once you identify the risk, you can think
of a control. Once you know the control, you can then think about how to test it either
manually or by CAATs/ADAs.
You will only get marks for control tests that are relevant and reliable. Therefore, enquiry on
its own will not be sufficient. You need to ensure that you use your judgement in
selecting either one test or a combination of tests that are sufficiently reliable.
To ensure that you are properly writing a test, and not documenting the control, try starting
the test procedures with the terminology of the techniques, for example, enquire,
observe, inspect and reperform. This will ensure you are writing what the auditor should
do to test the operating effectiveness of the control. A common mistake during exams is
54
to confuse the control with the test.
55
When writing the test, aim to include:
The full procedure must be documented with appropriate detail to warrant marks being
awarded.
Sales system
56
Phase of sales cycle Possible controls
Order fulfilled and Goods should only be despatched by trained staff. A regular
despatched exception report of goods despatched against sales orders
fulfilled should be reviewed by the warehouse manager.
Customer should sign for delivery upon receipt, or other
evidence should be obtained, that items are delivered
(e.g., photo).
Goods should be agreed to the sales order details before
despatch (or picking lists automatically generated based on
sales order details).
Goods should be inspected by an independent member of
staff before despatch, agreeing details to the sales order with
quality checks in place.
All processed sales orders should be matched to goods
despatch notes (GDNs) when fulfilled. Regular exception
reporting on unfulfilled orders should be carried out and
followed up.
Completed orders should be presented to customers for
approval (for example, confirmation email).
Customer invoiced Once an invoice is raised, the corresponding GDN is
for goods and marked as ‘invoiced’ in the system. A regular review of
customer pays for unmarked (un-invoiced) GDNs should be performed.
goods ‘Three-way-match’ control. Invoices should be agreed to
sales orders and GDNs before posting and processing.
Sequentially pre-numbered, pro-forma invoices should be
completed by trained individuals. Regular sequence checks
should be performed.
GDNs should be marked in the system as invoiced.
Invoices should not be raised unless they are matched to
an order and a GDN. The system should not allow a second
invoice to be raised for a single GDN.
Bank reconciliations should be performed monthly by
trained staff, with reconciling items followed up and
investigated.
Access to online bank accounts should be restricted
through passwords and all cash should be kept in a
locked safe.
Regular reviews should be performed of outstanding unpaid
invoices, with the credit control team responsible for
following up with the customer.
Monthly customer statements should be sent to all
customers, with outstanding balances at the month end.
Customers should be asked to inform the client if they
disagree with the balance.
Monthly reconciliation should be performed between the
debtors ledger and general ledger. Reconciling items
should be investigated and followed up.
Invoices should include a unique reference that must be
referenced alongside payment. Payments should be matched
to the invoice using
the reference when received.
Overall Management review of budgets versus actual as part of the
monthly management accounts review.
Relevant segregation of duties at each stage of the sales
cycle. For example, recording of sales, maintaining customer
accounts and preparing statements should be performed by
different individuals. Despatching goods, recording sales,
recording cash received and following up outstanding
balances (credit control) should be performed
by different individuals.
57
Tutor tip
If asked to assess an organisation’s sales system (either as an external or internal
auditor), the omission of one of the controls discussed previously from that system does
not necessarily indicate there is a weakness. There may be other
mitigating/compensating controls in place, or the uncontrolled risk may be minimal and
therefore the cost of the control would outweigh the benefit.
58
Therefore, you should focus on the specific issues identified in the scenario such as: a
poorly designed control; a control that is not operating effectively; or where the impact
of a missing control has been specifically raised.
a) Identifying facts from the scenario which result in weaknesses in the system; these
may arise due to:
i. Poorly designed controls
ii. Controls that are not operating
iii. (Gaps where there are no controls to manage risk
b) Evaluating why each of these facts is a weakness, that is, what is the implication to the
business?
Purchases system
Additional controls may be required if an organisation makes upfront payments for raw
material purchases:
59
Non-current assets system
61
Payroll system
63
Objective Possible controls
Phase 4: Payment of payroll liability (payroll department /accounts department)
Payroll payment is BACS transfer document is downloaded from the payroll
accurate and system and reconciled to the payroll listing by the payroll
authorised. staff. Documents are signed to provide evidence of review.
The director signs a copy of the BACS transfer form as
evidence of their approval, after agreement to supporting
documentation.
The BACS confirmation is reviewed and reconciled to
the BACS transfer file on receipt.
No duplicate Payroll listing marked as ‘paid’ once payment is made. The
payments are made. system will not allow payments to be processed twice.
Outsourcing payroll
Many organisations outsource their payroll to a service provider that calculates payroll
based on information provided by the company.
While this third party is completing some of the process on behalf of the organisation,
the organisation should have controls in place to ensure:
Inventory system
64
Inventory counts
Considered a key control over the completeness and existence of inventory records
Where inventory is material, auditor must obtain evidence over existence and condition
ISA (UK) 501 – Evidence over stock gained by:
Attending stock counts
Testing if final stock records reflect count
For some organisations, there may be factors, such as resource availability, which impact
the feasibility of performing a full year-end count. In such instances, a business may
perform perpetual inventory counting, where samples of inventory are counted on a
regular basis, with system figures being amended to reflect the physical count figures in
real time.
After the inventory count, auditors will follow up the counts attended to compare
quantities counted by them with the inventory records, obtaining and verifying
explanations for any differences, and checking that the client has reconciled count
records with the accounting records.
Where client performs perpetual counts, auditor should attend one or more counts
Review procedures/controls used during the year
Perform tests of control
If counts produce differences, auditor should consider asking client to perform a
full year end count
65
Tutor tip
You will need to know the standard procedures for attending an inventory count. For a given
scenario, you will be expected to apply relevant procedures and tests of control. For
example, if it is a perpetual inventory count, you will need to consider the normal tests
performed for attendance at an inventory count, as well as the other tests over
controlling the perpetual counts and assessing effectiveness.
You may be given specific problems at the count and would be expected to tailor general
procedures to these specific circumstances.
Controls over inventory counts are basic audit procedures that are common across many
audits and, therefore, should be known in detail.
Internal audit
Evaluating the internal audit function
1. The internal audit process – preparation of the plan; the internal audit report; follow up actions
2. The role of the audit committee – includes monitoring and reviewing the
effectiveness of the company’s internal audit function
3. Resource and competence – expect internal audit manager to be qualified,
experienced and a member of the Institute of Internal Auditors
4. Independence – reporting to the audit committee; audit plan approval; internal
audit manager appointment; remuneration; no operational involvement; position
and status
5. Quality assurance – adherence to standards; external review
Tutor tip
An assessment question may require you to recommend specific types of internal audit
reviews that the internal audit department could carry out. When asked for specific
reviews, it is important to utilise the information in the scenario, as well as any other
requirements attempted, to ensure you recommend reviews that are relevant.
For example, if you have been required to evaluate a specific process within the question,
eg payroll, and provide recommendations, the internal audit department could carry out
a follow up of the implementation of these recommendations by management.
Assessment approach
For questions on controls where the auditor may test operating effectiveness
To identify controls which are relevant to the auditor, you should think about whether the
control is useful in preventing or detecting material misstatements, and whether the
control is designed effectively.
66
For questions on control weaknesses
You may be asked to identify a control weakness, explain the implication of this and
suggest a recommendation to improve the control.
Step 1: Start by identifying facts from the scenario which indicate a control weakness.
Highlight the facts as you read through the case.
Step 2: Once identified, you need to explain ‘why’ it is a weakness (i.e. what implication
could that weakness have for the business and the financial reporting process).
Conclusion
On completing this module, you can now attempt AAPQ 6, 14 and 19.
Can you confidently complete the module learning outcomes listed on this module?
Have you used the discussion board to ask questions on areas you are unsure about?
67
Module 7 – Substantive Analytical Procedures
Introduction
Welcome to the study guide for Module 7 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.
Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:
You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.
68
Evidence gathering techniques
1. Analytical procedures: This is an evaluation of financial information by a comparison
of financial and non-financial data and the investigation of significant differences and
relationships which are inconsistent with other information. The level of assurance
that can be gained from performing analytical procedures varies as it depends on the
effectiveness of underlying controls and the integrity and completeness of data.
2. Enquiry: This means seeking information from those within or outside the entity.
The level of assurance is low as this can be subjective and is therefore normally
insufficient on its own.
3. Inspection: This is the examination of records, documents and tangible assets.
The level of assurance depends on the effectiveness of controls in place to
generate the information being inspected.
4. Recalculation: This involves verifying the arithmetical accuracy of documents or
records. The level of assurance is generally high as these procedures are normally
performed under the control of the auditor.
5. Confirmation: This involves obtaining representations directly from a third party. In
terms of level of assurance, generally, evidence from an independent knowledgeable
third party is more reliable than that from a source closely connected to the audited
entity.
procedures
Forming an expectation
Comparing the expectation to the actual results
Investigating and corroborating any significant variance
Concluding whether sufficient appropriate evidence has been obtained
You will be expected to APPLY the above steps to a given scenario in the AA assessment.
70
4. Information that auditors may use to form an expectation includes:
Management accounts
Prior year information adjusted for current year trends
Known interaction between financial data
Known interaction between financial and non-financial data
Discussions with management
5. Determining the amount of difference from the expectation that can be accepted
without further investigation
Threshold or tolerable error is set using auditor judgement
The auditor's determination of the amount of difference from the
expectation that can be accepted without further investigation is influenced
by materiality
The auditor will then follow up any significant differences between the expectation and the
actual balance.
Assessment approach
The recommended answering technique is as follows:
CAATs and ADA can be used for collecting and analysing audit evidence as part of
substantive testing.
1. Sample selection
Selection of manual journals for testing from criteria established by the auditor.
Sample selection – statistical sampling, where there are large volumes of data,
or key item sample selection, where items are selected based on meeting
particular criteria such as size or customer code.
2. Summarisation
Supporting substantive analytical procedures
Analytical review and analysis/disaggregation of data
Analysing contracts for key areas of consideration or terms.
Manipulating data to assess the impact on different assumptions (derivatives
71
valuation or impairment modelling).
72
3. Computation/recalculation
Recalculation of fixed asset depreciation using records of assets held,
additions and disposals.
Recalculating the VAT portion of revenue to ensure it has been removed correctly.
Casting schedules.
4. Re-performance
Reperform debtors ageing to confirm accuracy of the ageing report as this
will be used to calculate the bad debt provision and to select a sample of
overdue debtors for testing.
Ensure that payments were made only to real employees by checking their
employee card details against information in their personnel files.
Comparing entity data to externally obtained data, for example, bank account balances.
Comparing valuations of investments in other entities/financial instruments
etc to external third-party sources.
Tutor tip
These tests can be used as a prompt to be more creative when designing different types of
tests, and to consider whether too many of the same type have been used. You should
always try to use specific analytical procedures as well as other tests.
These will be performed over data input into the auditor’s software as well as the outputs
produced by the ADA.
Conclusion
On completing this module, you can now attempt AAPQ 1 and 22.
Can you confidently complete the module learning outcomes listed on this module?
Have you used the discussion board to ask questions on areas you are unsure about?
73
Module 8 – Substantive Procedures – Part 2
Introduction
Welcome to the study guide for Module 8 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.
Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:
You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.
74
Tests of detail
A test of detail involves testing specific items within a population. Should be written using the
format:
Verb – refers to the testing technique to be used in the substantive procedure. The
techniques that may be applied to tests of details are:
Enquiry
Inspection
Recalculation
Confirmation
Source evidence – must be reliable and relevant. Can include documents, physical items,
calculations or discussions with management or other third parties.
Activity – describes what the auditor is going to use the evidence for and look for to
confirm the items selected for testing.
Can use Computer Assisted Audit Techniques (CAATs) and Audit Data Analytics (ADAs)
2. Approach
Can test movements which have given risk to the balance
Can test closing balances directly
4. Assertions
Must cover all relevant assertions
75
Account balances and related disclosures Classes of transactions and related disclosures
Existence (E) Occurrence (O)
Rights and obligations (R&O) Completeness (C)
Completeness (C) Accuracy (A)
Accuracy, valuation and allocation (AVA) Cut-off (CO)
Classification (Cl) Classification (Cl)
Presentation (P) Presentation (P)
Some assertions are higher risk than others for particular accounts:
5. Common procedures
Commonly undertaken for that account balance
6. Standard tests
The auditor should perform some standard procedures to confirm that the
schedule/sub-ledger is appropriate as a basis for gathering audit evidence
76
Specific accounts and considerations
Plant, property and equipment
1. ROMM
A key focus for PPE is often valuation due to complexity and judgement
Higher ROMM assertions - AVA
3. Accounting policies
The cost includes its purchase price, import duties, non-refundable VAT, and
costs directly attributable to bringing the asset to the final location and
condition and is net of discounts or refunds.
Annually, the value is measured at cost less accumulated depreciation and
accumulated impairment losses.
Where revaluations take place, these should be made with sufficient regularity
and include all items within the same class of assets.
Where there are indicators of impairment, an impairment review should be carried out
5. Common procedures
6. Standard tests
Agree brought forward balances to last year's audited accounts
Cast and cross-cast the PPE movement summary and underlying asset listings using
CAATs
Verify PPE is disclosed in accordance with IAS 16 Property, Plant and
Equipment via a disclosure checklist
Verify that accounting policies are reasonable, and consistent year on year
and outline all accounting standards
Agree on the PPE register or PPE movement schedule to the trial balance
and financial statements
77
Tutor tip
In the assessment, you will not necessarily be required to prepare an audit work programme
but may just be asked to prepare a list of tests or procedures. In this case, you would not
be required to list the assertion for each test.
However, it is fundamental that you understand the assertions relevant to each test and so
it is good practice to include this in your studies.
Trade receivables, Other receivables, prepayments and accrued income, employee loans
1. ROMM
A profit making entity will want to present a strong balance sheet and may overstate
assets
Higher ROMM assertions - E, AVA
5. Common procedures
Performing a trade receivables circularisation
Subsequent cash testing
Testing the allowance for doubtful debts
Procedures
Review of aged trade receivables report
Reasonableness of policy relating to the allowance for doubtful debt
Post-year-end credit notes
Subsequent cash testing
Other receivables
An audited entity’s financial statements will normally include other receivables such as
prepayments and accrued income and employee loans.
78
Inventory
1. ROMM
A profit making entity will want to present a strong balance sheet and may overstate
assets
Higher ROMM assertions - E, AVA
3. Accounting policies – inventory must be measured at the lower of cost and net
realisable value (NRV). Consider:
quantity of inventory held
components of inventory
whether inventory valuation complies with IAS 2
NRV
5. Common procedures
Follow-up tests performed at the inventory count
Cut-off testing
Cost vs. NRV testing
Testing the inventory provision
Cost vs NRV – auditor must test both cost and NRV. Be alert to situations such as:
Tutor tip
As well as designing procedures yourself in an assessment, you could be asked to evaluate
procedures that have already been prepared by another member of the team. You
should consider whether the procedures detailed:
are reliable
address all the relevant risks and assertions, or whether items are missing
can be followed by another member of the team, or whether more detail
is required (remember verb, population, evidence, activity)
include all evidence available
79
Investments
1. ROMM
Main risks are around valuation and presentation (long-term)
Higher ROMM assertions - AVA, P
2. Approach – test the movements, but also assess valuation of closing balance
Additions
Disposals
Valuations
Impairments
3. Accounting policies
Need to be recorded at fair value (may be estimates for unlisted investments)
1. ROMM
Will depend on nature of audited entity
Consider susceptibility to theft, volume of bank accounts, incorrect netting of overdrafts
Higher ROMM assertions - E, C, P
3. Accounting policies
Any right of set-off
5. Common procedures
Testing the year-end bank reconciliation
Testing the bank confirmation letter
Physical verification of material cash balances
Verifying foreign currency rates used for FX accounts to independent
sources, and recalculating the translation
Trade payables, GRNI accrual, accruals and deferred income, Vat and social security,
provisions for liabilities, loans payable
Tutor tip
How the auditor approaches substantive testing of trade payables often overlaps with
other liabilities recorded in the financial statements. When studying this section focus on
understanding the principles as these will apply to other liabilities also.
1. ROMM
Due to impact of liabilities on the balance sheet, completeness, classification and
presentation are high-risk
Higher ROMM assertions - C, Cl, P
81
5. Common procedures
Search for unrecorded liabilities
Creditors circularisation
Supplier statement reconciliations
Auditor often tests the movements within the disclosure note within the financial
statements.
For private companies normally low risk, however for public companies
movements in share capital and reserves can be large making it a more
complex audit area
Intangible assets
1. ROMM
Accounting treatment and valuation is complex
Higher ROMM assertions - AVA
3. Accounting policies
Research – costs not permitted to be capitalised.
Development – costs only recognised if can demonstrate six criteria:
Technical feasibility
Intention to complete
Ability to use or sell
Commercial feasibility
Adequate resources
Ability to reliably measure
5. Common procedures
Vouching the costs capitalised during the period to invoices to determine
whether they relate to development expenditure and vouch the amount
capitalised
Inspecting expenses listings for any significant invoices paid but not capitalised
Inspecting the research expense account for items that may be related to
development costs and should be capitalised as an asset and vice versa
Recalculating the amortisation charge for the period
Inspecting sales made post-year-end to determine whether the valuation of the
intangible has suffered an impairment
Compare actual costs to budgeted costs to determine if there is any indication
that costs have been over or under-capitalised
82
Estimates
Estimation uncertainty
Subjectivity
Complexity
auditor:
obtaining evidence from events occurring up to the date of the auditor’s report
testing how management made the accounting estimate
developing the auditor’s point estimate or auditor’s range of estimates
Contingent asset – possible asset that arises from past events and whose existence will be
confirmed only by the occurrence or non-occurrence of one or more uncertain future
events not wholly within the control of the entity
Contingent liability:
is a possible obligation that arises from past events and whose existence will be
confirmed only by the occurrence or non-occurrence of one or more uncertain
future events not wholly within control of the entity; or
is a present obligation that arises from past events but it is not recognised
because it is not probable that an outflow of resources embodying economic
benefits will be required to settle the obligation or the amount of the obligation
cannot be measured with sufficient reliability.
83
Derivatives
Financial instrument – a contract that gives rise to both a financial asset of one entity and a
financial liability or equity instrument of another entity.
Type of financial instrument – examples include options, futures, forward contracts, interest
rate swaps and currency swaps
The value of a derivative depends on, or is derived from, an underlying rate or price such as
interest rates, exchange rates or commodity prices.
1. ROMM
Accounting involves complexity, use of management judgement and
requires specific presentation in the financial statement notes
Higher ROMM assertions - AVA, Cl, P
3. Accounting policies
The nature of the derivative and the risks the entity is exposed to
Classification/ presentation requirements under accounting standards
Accounting standard requirements over valuation (FVTPL)
5. Common procedures
external confirmations
review of reconciliations and operational data such as reconciliation differences
review journal entries
review contracts
testing of assumptions and fair value adjustments
post year end events
validity of valuation models
confirmation of external prices to third-party sources
Turnover/revenue
Cost of sales/expenses
Depreciation
Payroll
Revenue recognition
Normally identified as a risk by the auditor and occurrence and cut off of revenue
can be a key audit risk area, especially if there is any risk of fraud.
84
Revenue from contracts with customers
When auditing revenue from contracts with customers, the auditor should test
whether the five criteria in IFRS 15 have been met:
Identify the contract(s) with a customer
Identify the performance obligations in the contract
Determine the transaction price
Allocate the transaction price to the performance obligation(s) in the contract
Recognise revenue when (or as) the entity satisfies a performance obligation
Tailored tests of detail may be required to corroborate any explanations for variances
between actual and expectation identified by the auditor following substantive analytical
procedures. Further follow up tests may also be required of a plausible explanation has
not been identified
Tutor tip
In the assessment, you may be asked to:
In all instances, you can use the skills learnt in this module to help you answer the
requirement. You must design relevant and tailored procedures to address the area you
have been presented with.
You can use the considerations covered in this lesson regarding risk, accounting policies,
and common procedures to help you design the procedures required.
The auditor must obtain sufficient appropriate evidence that the comparative information
agrees to the prior year financial statements and has been presented in line with
relevant accounting standards
The auditor may need to perform audit tests where the prior year financial statements were
not audited or were audited by another auditor
Final considerations
Substantive testing procedures for the financial statement close process include:
The auditor will use a disclosure checklist to gain assurance over the presentation disclosure.
85
Assessment approach
The key techniques to remember are:
It is important that you understand what assertion you are addressing with any test you
design. Some questions may only ask for testing of certain assertions or certain aspects
of the balance. No matter how well worded a test is, if it doesn’t address the assertion
required in the question it will gain no marks.
When designing a substantive audit work testing programme use the following
considerations to help you design a variety of substantive procedures:
Consider whether the tests you have provided are reliable and address all relevant risks
and assertions. You should also consider whether the procedures include all evidence
available.
are reliable;
address all the relevant risks and assertions, or whether items are missing;
can be followed by another member of the team, or whether more detail
is required (remember verb, population, evidence, activity);
include all evidence available.
Remember that any substantive procedures must be tailored and relevant to the given scenario.
Note that 1 mark will be awarded for a basic procedure (enquire/observe) or a common
procedure or standard test which is not tailored to the scenario, whereas a well
designed test tailored to the scenario with analysis/evaluation/recommendation and a
procedure other than enquiry/observation may gain 2 marks.
Conclusion
On completing this module, you can now attempt AAPQ 5.
86
Study guide checklist
Can you confidently complete the module learning outcomes listed on this module?
Have you used the discussion board to ask questions on areas you are unsure
about?
87
Module 9 – Substantive Procedures – Part 3
Introduction
Welcome to the study guide for Module 9 of the Advanced Assurance course. This study
guide will help you navigate the course material and prepare for the assessment.
Module Outcomes
By completing this module, you will have worked towards the following module learning
outcome:
You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.
88
Audit evidence
Auditors must obtain ‘sufficient appropriate evidence’ on which to base their opinion.
Auditor generated
Audited entity generated
Third party/externally generated
Audit sampling
Sampling methods include:
Random selection
Monetary unit sampling
Haphazard selection
Based on the characteristics of the population, the auditor may determine that
stratification or value- weighted selection is appropriate. A population for testing may be
split into different sub-populations that share a particular characteristic; this can often
help to reduce sample sizes without increasing sampling risk.
1. Determine the level of tolerable misstatement - addresses the risk that the sum of
individually immaterial or undetected misstatements result in the financial statements
is materially misstated. It is a monetary amount and application of performance
materiality and may be the same or lower than performance materiality.
2. Determine the sample size and select items for testing e.g. statistical/non-statistical
sampling - can be determined by applying a statistically-based formula or through
professional judgement.
3. Perform the audit procedure - should be applied to all items in the sample. If the
procedure is not relevant to a particular item, a replacement item should be
selected. If a procedure cannot be performed and there is no suitable alternative
procedure to perform, then the item should be treated as a misstatement.
4. Identify the nature and causes of misstatement - investigate the nature and cause of
any misstatements identified and their effect on the assertion and other areas of
the audit. This may involve extending audit testing further over a particular type of
transaction in the population.
5. Extrapolate and project the misstatement to the population - for tests of detail,
misstatements found in a sample should be projected to the entire population unless
assessed as an anomaly or isolated/one off incident.
6. Evaluate the results – consider whether the use of sampling provides a reasonable
conclusion about the population being tested. If misstatements were detected, then
the extrapolated error, if applicable, should be calculated and compared to the level
of tolerable misstatement to determine if it would be material.
7. Conclude and determine further actions - If the total projected misstatement (plus
anomalies) does not exceed tolerable misstatement, then the sample provides a
reasonable basis for conclusion.
If there is not a reasonable basis for conclusion, the auditor may request
management to investigate and quantify the total misstatement or change the
nature of testing to provide a reasonable basis for conclusion.
89
Tutor tip
You may:
You need to have a good understanding of these techniques to be able to apply them to
different scenarios.
Assessment approach
In the assessment, you may be provided with information regarding the section being
audited including audit work papers, sub-ledgers, invoices and other relevant
documentation. You will only be expected to perform substantive procedures based on
the information provided and not all audit procedures that could be performed in relation
to an account.
You will not be provided with a substantive testing programme and need to assess which
procedures are possible based on the information provided. The following approach will
help you to undertake an assessment question in this area.
• Peform a high-level review of the question including the requirement and appendices
• It is important to understand what you are being asked and what information
Step 1 you have been given before attempting the question.
• Identify if you are required to design substantive procedures as well as perform them
• Some questions may expect you to firstly design the substantive procedures
Step 2 before performing them. Your knowledge from Module 8 of this course will help you with
this.
• Perform the substantive procedures and identify any issues requiring further
investigation
Step 3 • Remember you will only be able to perform substantive procedures in relation to
the information that you have been provided with.
90
To help determine whether to perform substantive procedures prior to the year end consider:
The auditor my use the results from tests of controls over stock (inventory) ie
stock count as part of their substantive procedures
Procedures may include:
Payroll is usually one of the most significant accounts in the statement of profit or loss
Often risk over fraud and auditor will carry out tests of detail in response to this risk
91
Outstanding matters
Following the final audit visit it is often the case that the auditor will have outstanding
matters that the audit team will need to follow up and conclude on before the audit report
can be issued
Examples include:
Tutor tip
In an assessment, you will often be asked to evaluate a number of outstanding matters from
the audit and advise what additional evidence is required. Therefore, you must first
discuss the matter and why it is relevant to the audit before listing further procedures to
gather the additional evidence required. You may be provided with information such as
materiality to help you determine whether the matter is material and would impact the
financial statements.
The auditor documents any misstatements, except those clearly trivial, identified during the
audit in a document called a Summary of Audit Misstatements
92
An example of a summary of misstatements is as follows:
Wolfpack Ltd
Year end: 30 September 20X2
Summary of audit misstatements
Financial Statements Account Dr Cr
Material Adjusted
£ £
1 P&L – administrative expenses 100,000
Fixed assets – accumulated depreciation 100,000 N N
being adjustment to apply depreciation policy consistently
2 P&L – sales 625,333
Trade debtors 625,333 Y Y
being October 20X2 sales incorrectly included in current year
3 P&L – administrative expenses 214,000
Trade and other creditors 214,000 Y Y
being correction for unrecorded liabilities
Summary and Conclusion
Adjusted differences in P&L 839,333
Dr
Unadjusted differences
Unadjusted differences in P&L 100,000
Dr are judged to be
Adjusted differences in net assets 839,333 immaterial.
Cr
Unadjusted differences in net 100,000
assets Cr
93
Assessment approach:
For audit sampling questions (where results from testing are provided):
Perform a high-level review of the question including the requirement and appendices.
Identify if you are required to design substantive procedures as well as perform them.
Perform the substantive procedures and identify any issues requiring further
investigation.
Document your findings including any conclusions or follow up procedures required.
Remember, you will not be provided with a substantive testing programme and need to assess
which procedures are possible and appropriate based on the information provided.
1. Discuss the matter and why it is relevant to the audit before listing further procedures
to gather the additional evidence required.
2. Look out for information in the scenario such as materiality to help you determine
whether the matter is material and would impact the financial statements.
Conclusion
On completing this module, you can now attempt AAPQ 7, 9, 10, 13 and 18.
Can you confidently complete the module learning outcomes listed on this module?
Have you used the discussion board to ask questions on areas you are unsure about?
94
Module 10 – Completion and Reporting
Introduction
Welcome to the study guide for Module 10 of the Advanced Assurance course. This
study guide will help you prepare for the assessment.
You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.
95
Going Concern Principle
Under the going concern assumption, an entity is ordinarily viewed as continuing in business for
the foreseeable future.
The period of assessment should be a minimum of 12 months from the date of approval of
the financial statements
Directors assess the company’s going concern status and prepare financial statements
The preparation and review of forecasts and budgets, including a cash flow forecast
A review of lending facilities
A review of any pending legal cases
A review of contracts with major customers and suppliers
A review of competitor performance or entry to local market
Auditor's responsibilities
a) Timing and period of assessment - The auditor should use the same period of time for
the going concern assessment as that used by the directors. If this is less than 12
months from the approval of the financial statements, the auditor must ask the
directors to extend this period.
b) Indicators of going concern risks - examples in ISA (UK) 570 paragraph A3.
Include: Financial
Operating
96
Other
You should look out for these factors when evaluating indicators of going concern problems
in the assessment.
events or conditions exist that may cast significant doubt over going concern
material uncertainties related to going concern exists
management’s use of the going concern assumption is appropriate
Procedures include:
ISA (UK) 570 provides some examples of considerations for the auditor when designing
such procedures:
98
Other procedures can include:
Analysing and discussing cash flow, profit and other relevant forecasts
Discussing the entity’s latest interim financial statements (the auditor may
also consider management accounts)
Reviewing the terms of debentures and loan agreements
Reading minutes of meetings of shareholders, those charged with governance
and relevant committees
Making inquiries of lawyers regarding ongoing litigation or claims against the company
Confirming the existence and adequacy of borrowing facilities
Inspecting regulatory reports
Tutor tip
The assessment may require you to undertake specific procedures relating to the
directors’ going concern assessment. For example:
You will need to tailor the procedures learnt to the scenario given to ensure your answer is
relevant.
Subsequent events
Subsequent events are events that occur after the balance sheet date. They can be
either adjusting or non-adjusting events.
99
Auditor’s responsibilities:
a) Events occurring up to the date of the audit report - auditors should perform
additional substantive procedures designed to obtain sufficient appropriate audit
evidence to ensure that they have identified all events. These may include:
If subsequent events are identified, these should be substantively tested in the same
way as any other area throughout the audit.
b) After the date of the audit report – auditors have no obligation to perform audit
procedures, however if a fact becomes known they should discuss with
management and determine whether an amendment to the financial statements is
required and enquire how management intends to address the matter. If the
financial statements are amended, the auditor must audit these adjustments.
Tutor tip
The assessment may ask you to evaluate potential subsequent events within a scenario
and design further audit procedures in order to allow you to reach a conclusion on the
required accounting treatment.
After the audit fieldwork, but prior to the signing of the audit report; or
After the date of the audit report.
Once the period has been identified the relevant paragraphs in ISA (UK) 560 can be used
as a guide to identify what audit procedures should be undertaken at that point.
However, you should ensure, if requested, that you have first evaluated whether the
event is adjusting or non-adjusting, analysing your conclusion. You should also consider
whether an adjusting event actually requires adjustment in the financial statements
depending on any provided materiality. Note that this should not just consider the
amount, but whether any items are material by nature.
The audit procedures will need to be tailored to the circumstances within the scenario in
order to maintain the relevance of your answer to the question.
Evaluation of evidence and misstatements - the auditor needs to evaluate the outcome of
the procedures performed and determine whether the auditor's assessment of the risks
of material misstatement remains appropriate and that sufficient and appropriate audit
evidence has been obtained.
The auditor must evaluate the potential effect of any identified and uncorrected
misstatements on the audit and, if applicable, on the financial statements.
10
0
All misstatements (which are not clearly trivial) are communicated to the management
for correction. If material misstatements are left uncorrected, this may impact the audit
opinion.
10
1
Tutor tip
In past assessments, there have been questions requesting students to identify matters
within a scenario that require representations to be sought from management.
Consequently, you must be able to identify these matters and be able to describe the
nature of the related representations within a written representation letter and consider
whether there will be any impact on the audit report.
Takes responsibility for the direction, supervision and review of the audit engagement.
Determines that the engagement is sufficiently and appropriately resourced,
with sufficient competence, capabilities and time
Is ultimately responsible for determining that the audit evidence on file is
sufficient and appropriate to support the conclusions reached and the audit
report to be issued.
Engagement quality reviewer (EQR) - not a member of the engagement team and must be
a suitably qualified partner or other person in the firm not otherwise involved in the
engagement.
have the competence and capabilities, including sufficient time, and the
appropriate authority to perform the EQR
comply with relevant ethical requirements
comply with provisions of law and regulation, if any, that are relevant to the
eligibility of the engagement quality reviewer
be eligible for appointment as a statutory auditor if the audit of the financial
statements relates to a Public Interest Entity
10
2
Engagement quality review should include:
1. Title
2. Addressee
3. Auditor’s opinion
4. Basis for opinion
5. Conclusions relating to going concern
6. Other information
7. Other reporting responsibilities
8. Matters on which auditors are required to report by exception
9. Responsibilities of management for the financial statements
10. Auditor’s responsibilities for the audit of the financial statements
11. Name & signature of the auditor
12. Address of the auditor
13. Date of the auditor’s report
10
3
Additional elements for listed companies
Key audit matters – relevant for listed entities, public interest entities and entities
that report on the Code.
For each key matter identified by the auditor, the auditor shall include in the audit report:
a description of why the matter was considered to be one of the most
significant in the audit
how the matter was addressed in the audit, including significant judgements
made by the engagement team with respect to the matter
a reference to any related disclosures in the financial statements, if any
10
4
Limitations imposed by management
The auditor's report may also be modified without a modification to the audit opinion, by
the inclusion of an 'emphasis of matter' paragraph.
Purpose - to draw users' attention to a matter that is of such importance that it is fundamental
to users' understanding of the financial statements.
Examples:
Purpose - refers to a matter other than those presented or disclosed in the financial
statements that, in the auditor’s judgement, is relevant to users’ understanding of the
audit, the auditor’s responsibilities or the auditor’s report.
Examples:
The auditor will include a statement within a 'Conclusions relating to going concern'
section in the audit report regarding the going concern basis applied by the directors and
the assessment they have made.
10
5
Conclusion from audit evidence Impact on audit report
Going concern basis is appropriate Unmodified opinion and report. Statement
confirming no matters to report
Inability to obtain sufficient, appropriate auditDisclaimer of opinion
evidence
Going concern basis is appropriate, but material
Unmodified opinion, details of uncertainty
uncertainty exists – disclosure appropriate within
going concern section of audit report
Going concern basis is appropriate, but material
Qualified/ Adverse opinion
uncertainty exists – disclosure inadequate
Going concern is inappropriate Adverse opinion
Tutor tip
A scenario may include you in the role of the external audit manager. The fieldwork has
been completed but some issues have arisen, and you have been asked to write notes
to be presented to the directors on the possible modifications to the audit opinion or
audit report that may be made. The solution would expect an outline of:
The type of amendment to the audit opinion and/ or audit report (amended
opinion or additional paragraphs) and analysis to support that conclusion
(circumstances, material/ pervasive/ uncertainty, etc)
Examples of the wording that will be issued
Explanation of any other sections of the audit report requiring disclosure or amendment
In assessment questions, there is unlikely to be a single answer concerning the nature of the
opinion that should be given. It is far more likely that you will be required to discuss the
outcomes and various opinions depending on the information within the scenario and the
actions that the relevant parties could take.
10
6
Matter Representations to be included
Fraud Reporting to management and those charged with
governance on any actual or suspected fraud
identified
Reporting to an appropriate authority where the
auditor identified or suspects a fraud
Laws and regulations Reporting instances of non-compliance to those
charged with governance or the audit committee
Consideration of reporting to an appropriate authority
UK Corporate Governances Communications to the audit committee, including:
Code reporting entities Information relevant in the context of fulfilling their
responsibilities to present a fair, balanced, and
understandable financial report and to assess the
effectiveness of the company's risk management and
internal control systems
Public interest entities Communications to the audit committee, including:
Identification of key audit partner(s) involved in the audit
Description of scope and timing of the audit
Management letter A description of the deficiencies and an explanation of
their potential effects
Assessment approach
AA assessment questions set at the completion and reporting stage of audit often test various
topics in combination.
It is important to ensure that you read the requirement carefully to understand the
examiner’s expectations.
For questions on going concern, if you are asked to evaluate indicators from the
scenario which may lead to going concern problems for the client, ensure that you
explain ‘why’ the indicator may cause liquidity or other related problems in the next
twelve months. Procedures to evaluate the management’s going concern assessment
need to be tailored to the scenario to ensure that your answer is relevant. If asked to
evaluate the impact on the audit report, this needs to be carefully assessed. For
example, if you agree with the management’s assessment, the opinion will not be
modified in this regard but the relevant section of the audit report will be modified.
For questions on subsequent events, you may be asked to evaluate whether an event is
adjusting or non-adjusting. Ensure that you explain ‘why’ as you are unlikely to be
awarded full marks if you simply write that it’s one or the other. You may also be
required to design further audit procedures to allow you to reach a conclusion on the
required accounting treatment. The audit procedures will need to be tailored to the
circumstances within the scenario in order to maintain the relevance of your answer to
the question.
The impact on audit reports is often tested in combination with evaluation of matters
identified at the completion stage of audit. These matters may include results of going
concern or subsequent events reviews or those of evaluating evidence related to
misstatements or inability to gather sufficient appropriate evidence. For all questions,
sound knowledge of the contents of unmodified and modified audit reports is the basic
prerequisite.
Conclusion
On completing this module, you can now attempt AAPQ 8, 16, 21, 24 and 25.
10
7
Study guide checklist
Can you confidently complete the module learning outcomes listed on this module?
Have you used the discussion board to ask questions on areas you are unsure
about?
10
8
Module 11 – Group Audits
Introduction
Welcome to the study guide for Module 11 of the Advanced Assurance course. This
study guide will help you navigate the course material and prepare for the assessment.
You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.
10
9
Group Audits
Group audits are audits of financial statements that include the financial information of
more than one entity or business unit.
Key terms:
Group financial statements Financial statements that include the financial information
of more than one component
Component An entity or business activity for which financial
information is separately prepared, and which is included
in the group financial statements.
Group auditor Responsible for providing the audit opinion on the group
financial statements. Includes the group engagement
partner and members of the engagement team other than
component auditors
Component auditor May be engaged by the group auditor to audit a specific
component.
Group engagement letter Confirms terms of the engagement
Letter of support May be issued by parent company to help the directors of
the subsidiary to meet their responsibilities with respect
to going concern, if there is an issue at a subsidiary.
Establishing the overall group audit strategy and group audit plan
Directing and supervising component auditors and reviewing their work
Evaluating the conclusions drawn from the audit evidence obtained as the
basis for forming an opinion on the group financial statements
Determining, through review of audit documentation and discussion with the
engagement team, that sufficient appropriate audit evidence has been obtained to
support the conclusions reached and for the auditor’s report on the group financial
statements to be issued.
The group engagement partner is solely responsible for expressing an opinion on the
group financial statements. As a result, the auditor's report on the group financial
statements must not refer to a component auditor (unless required by law or
regulation).
11
0
Group acceptance and continuance
The group auditor needs to determine whether they can obtain audit evidence in relation
to the consolidation process and the financial information of the components. To be able
to do this, the group audit team needs to understand the group, its components and their
environments. They need to gather an understanding of matters such as:
Activities that are significant to the group (e.g. industry and regulatory,
economic and political environments)
The use of service organizations
The use of shared service centres
The use of component auditors
Risk associated with potential complex accounting treatments on consolidation
Whether the group auditor will have unrestricted access to those charged with
governance (TCWG) of the group, group management, TCWG of the
component, component management and component information.
For recurring engagements: significant changes in structure, activities, composition of
TCWG
Group engagement letter – to confirm the terms of the engagement, the group auditor
issues a group engagement letter.
The group auditor must obtain the agreement of group management that it
acknowledges and understands its responsibility to provide the engagement team with:
This is based on auditor judgement. There may be factors which increase ROMM:
11
1
The group engagement partner is responsible for:
Confirming whether component auditors understand and will comply with the
relevant ethical requirements
Determining that component auditors have the appropriate competence and
capabilities, including sufficient time, to perform the assigned audit procedures
at the component
The auditor must obtain a sound understanding of the structure and operations of the group
as part of the overall understanding of the organisation to enable any problems or issues
to be identified and considered right from the start of the audit.
Examples of matters that the group auditor must obtain an understanding of include the following:
The group and its environment, the financial reporting framework and the
consistency of accounting policies and practices across the group.
Organisational structure
Regulatory factors impacting the group
Measures used to assess the entities’ or business units’ financial performance
The group’s system of internal controls
Commonality of controls
Whether and, if so, how the group centralises activities relevant to financial
reporting
Consolidation process
Planning for the group audit may be impacted by whether the group structure is centralised
or decentralised. Consider:
11
2
Tutor tip
In the assessment, you are likely to be given information about the components in the
group, the industries they are in and the related trading conditions as well as the group
structure and controls over group financial reporting.
You will need to consider the significance of risks within each individual component to
assess whether they would be considered a significant ROMM at the group engagement
level.
Group materiality
The group engagement team determines materiality for the group financial statements
as a whole and for the components
Component materiality: For those components where component auditors will perform a
review or audit for group purposes, component materiality is determined by the group
engagement team at a level lower than overall group materiality. This is to reduce, to an
appropriately low level, the probability that the aggregate of uncorrected and
undetected misstatements in each component exceeds overall materiality for the group.
Clearly trivial threshold: Only misstatements above this level will be reported to the
group engagement team by component auditors.
The group auditor may determine the following scope of work to be appropriate at a
component level (with the involvement of component auditors, if applicable):
11
3
Consolidation process controls
Group instructions
11
4
Control Reason for control
Amalgamation of data
All returns are reviewed for completeness Only complete
(manual/automated) and omissions followed up. consolidation returns are
amalgamated, none are
excluded completely.
Subsidiary information should be agreed to source once All data is calculated
input, with any exceptions followed up. The consolidation accurately.
package should include master file controls including
restrictions on editing information. Include control total
checks, balancing checks, and the reporting of unusual
transactions within the consolidation package.
Consolidation adjustments
Checklist of consolidation adjustments followed and All consolidation
completed; checklist reviewed by an appropriate official. In adjustments required are
an automated system this checklist can be loaded onto the made, with no duplication.
system and the software programmed to flag
duplication/missing entries.
Agreement by an appropriate official of adjustments All consolidation
actually made to those proposed and included on adjustments are made
checklist. accurately.
Complete a journal posting form for all entries which is
subject to review.
Sign off by a responsible official of adjustments
documentation when agreed adjustments are made.
Staff making consolidation adjustments are adequately All consolidation
trained in the consolidation procedures and a responsible adjustments are calculated
official reviews the work done. in accordance with the
relevant accounting
standard/ company law.
Reporting
Review checklists for completeness and authorisation by Ensure consolidated
responsible official. accounts are complete.
Review of consolidated accounts by appropriate responsible Ensure consolidated
officials. Implement access controls to the consolidation accounts are accurate.
software, to ensure that only responsible officials can
request and access consolidation information. Agree
consolidated accounts to consolidation schedule and
supporting documentation.
Complete a disclosure checklist. Required disclosures have
been included.
Tutor tip
This knowledge can be applied to questions in the assessment which you may be asked
to describe tests of controls or evaluate control weaknesses in the group’s consolidation
process.
For example, a scenario could provide process notes detailing a client’s consolidation
process and require you to evaluate any weaknesses identified and recommend
appropriate control activities to improve the process. Understanding the types of
controls in place and the reason for these controls will allow you to identify where
weaknesses exist.
11
5
Audit work to be performed in relation to the consolidation process
Evaluating whether all components have been included
Evaluating the appropriateness, completeness and accuracy of consolidation adjustments
Evaluating whether management’s judgements made in the consolidation process
give rise to indicators of possible management bias
Responding to assessed ROMM due to fraud arising from the consolidation process.
Checking that figures taken into the consolidation have been accurately
extracted from the financial statements of the components by reconciling the
data.
Checking the arithmetical accuracy of all consolidation schedules and
recalculating all consolidation adjustments
Reviewing the disclosures necessary in the group financial statements, such as
related party transactions
Investigating the treatment of any components which have a different financial year end
from that of the rest of the group.
Gathering evidence appropriate to the specific consolidation adjustments made
necessary by financial reporting standards, including, for example: calculation of
goodwill and cancellation of inter-company balances and transactions
When component auditors are involved in the design or performance of further audit
procedures for group audit, the group auditor must:
Tutor tip
You may be required to produce a list of substantive tests over the consolidation for a
group engagement in the assessment.
Therefore, you will have to identify the relevant specific substantive procedures that
would be appropriate for this type of engagement. To do this, you should consider the
relevant accounting policies, risks and assertions.
You should approach the audit of the consolidation using the same methodology as for
any other balance: consider the ROMM, accounting policies and assertions to ensure you
have coverage of all areas requiring procedures.
11
6
Evaluating the component auditor’s communications and the adequacy of their work
To allow the group auditor to assess the adequacy of the component auditor’s work,
certain matters need to be communicated to the group auditor by the component
auditor. These include:
Completion
Evaluating the sufficiency and appropriateness of audit evidence obtained
Additional time must be built into the audit process to enable the group auditor to:
Review the work of the component auditors and the group team
Review any reporting documentation from the component auditors
Consider any modifications of component audit reports on the group audit report
Discuss all salient issues with the component auditors
a) An overview of the work to be performed at the components of the group, and the
involvement of component auditors
b) Any concerns about the quality of that component auditor’s work
c) Any limitations on the scope of the group audit,
d) Fraud or suspected fraud
e) Identified deficiencies in the group’s system of internal control
f) Additional matters for public interest entities
The group auditor has sole responsibility for the opinion on the consolidated group
financial statements.
11
7
Assessment approach
Audit Risks
You are likely to be given information about the components in the group, the industries
they are in and the related trading conditions as well as the group structure and controls
over group financial reporting.
You will need to consider the significance of risks within each individual component to
assess whether they would be considered a significant ROMM at the group engagement
level.
Internal control
You may be asked to describe tests of controls or evaluate control weaknesses in the
group’s consolidation process. For example, a scenario could provide process notes
detailing a client’s consolidation process and require you to evaluate any weaknesses
identified and recommend appropriate control activities to improve the process.
Understanding the types of controls in place and the reason for these controls will allow
you to identify where weaknesses exist.
Substantive procedures
You may be required to produce a list of substantive tests over the consolidation for a
group engagement in the assessment. You will have to identify the relevant specific
substantive procedures that would be appropriate for this type of engagement.
To do this, you should consider the relevant accounting policies, risks and assertions.
You should approach the audit of the consolidation using the same methodology as for
any other balance; consider the ROMM, accounting policies and assertions to ensure you
have coverage of all areas requiring procedures.
You may be asked to evaluate instructions given by the group auditor to the component
auditors for a particular group.
You will need to apply the knowledge gained from this module to evaluate these
instructions which may relate to the planning, controls testing, substantive testing or the
review stage of audit.
Conclusion
On completing this module, you can now attempt AAPQ 12.
11
8
Study guide checklist
Can you confidently complete the module learning outcomes listed on this module?
Have you used the discussion board to ask questions on areas you are unsure
about?
11
9
Module 12 – Other assurance engagements
and related services
Introduction
Welcome to the study guide for Module 12 of the Advanced Assurance course. This
study guide will help you navigate the course material and prepare for the assessment.
Explain the nature of other assurance services, related services and other
services provided by professional accountants and recommend suitable types of
engagements
Design and evaluate the distinct considerations and requirements when
undertaking engagements other than a financial statement audit
You will be ‘assessment ready’ for questions in this module when you can confidently
complete each of the module learning outcomes above.
12
0
Assurance engagement
An engagement in which a practitioner aims to obtain sufficient appropriate evidence in
order to express a conclusion designed to enhance the degree of confidence of the
intended users other than the responsible party.
Elements
Tutor tip
In the AA assessment, you may be asked to assess if an engagement, that is not a
statutory audit, is an assurance engagement. The five elements (i.e. a three-party
relationship, an appropriate subject matter, suitable criteria, sufficient, appropriate
evidence and a written assurance report) are a good checklist to remember to consider
the different aspects that should be considered.
Key stages
1. Acceptance and continuance - consider commercial and professional factors.
Potential outcomes of preliminary risk assessment are:
a) Accept a duty of care and include an agreement by the third party in the engagement
letter
b) Ensure the third party confirms there is no duty of care
c) Include a disclaimer of liability to any third party in the report
d) Reject the engagement
The practitioner can only accept the assurance engagement if the following
preconditions have been met:
The roles and responsibilities of the parties are suitable in the circumstances
The underlying subject matter is appropriate
The criteria are suitable to the engagement circumstances
The criteria to be applied will be available to the intended users
The practitioner expects to be able to obtain the evidence needed to support their
conclusion
The conclusion is to be contained in a written report
The practitioner is satisfied that there is a rational purpose for the engagement
and expects to be able to obtain a meaningful level of assurance
Engagement letter – clarifies responsibilities, the scope of the engagement and the
form of report that will be provided or work that will be performed.
12
1
Quality management -- quality management procedures (e.g. recording work,
supervision, review) should be followed as required by ISQM (UK) 1.
2. Planning - should set the scope, timing and direction of the engagement.
Items to consider:
Materiality should be set considering what factors could reasonably influence the
decisions of the intended users
Considers:
Tutor tip
In the AA assessment, you may be provided with a scenario outlining the type of assurance
(or engagement) required. Examples of how you may be tested on this topic include:
Comparing the level of assurance with an audit and outlining the key
differences in the form and content of reports issued
Assessing whether an engagement is an assurance engagement
Determining the form of report and evidence to be collected, and
Outlining the stages of the assurance engagement and the considerations for
the auditor at each stage
Using the content in the lesson can help as a prompt to ensure you are covering a range of
issues, if required in the question.
Related services
Engagements where the practitioner performs services without providing assurance:
It is the user's responsibility to interpret these findings to draw their own conclusions
and opinion. The practitioner reports on the agreed-upon procedures and
findings objectively in terms that are clear, not misleading and not subject to
varying interpretations.
12
3
Types of assurance engagement
Review of interim financial information
All listed companies must make public a half-yearly report. Companies can
choose to have this reviewed.
Limited assurance engagement - opinion expressed in ‘negative’ form
Less work, less costly for client
PFI is any financial information that is based on assumptions about events that
will happen in the future.
It can be in the form of a forecast or projection or a combination of both
More common to be limited assurance engagement (opinion in negative
form) due to subjectivity of PFI
Auditor’s risk is higher if period covered is longer
Procedures will include
The likelihood of material misstatement
The knowledge obtained during any previous engagements
Management’s competence regarding the preparation of
prospective financial information
The adequacy and reliability of the underlying data
The extent to which the prospective financial information is
affected by the management’s judgement and reasonableness
of assumptions
Correct application of assumptions in preparation of prospective financial
information
Disclosure of assumptions (i.e. whether best estimates or hypothetical)
Consistency of accounting principles and practices used in
historical financial information in preparation of prospective
financial information
Obtaining written representations
Forensic audits
12
4
Internal controls
Charity engagements
12
5
Organisations may report on sustainability and associated areas through several channels.
For example:
Where sustainability risks are financially material for a company, its auditors must consider
whether those risks are properly reflected in the financial statements in order to report
whether they provide a true and fair view of the financial position and performance of
the company.
Additionally, if sustainability reports are included in the annual report with audited financial
statements, the auditors will have responsibility to review these reports for consistency
with the financial statements.
The auditor would seek evidence to verify the content of the report, including information such as:
To meet the global need for consistent sustainability assurance standards, the IAASB has
developed proposed International Standard on Sustainability Assurance 5000 (ISSA
12
6
5000) General Requirements for Sustainability Assurance Engagements.
12
7
Conclusion
On completing this module, you can now attempt AAPQ 2 and 11.
Can you confidently complete the module learning outcomes listed on this module?
Have you used the discussion board to ask questions on areas you are unsure
about?
12
8