ACCA Applied Skills · Audit and Assurance
Objective and general principles: formula sheet
Key formulas
- Objective of an audit
- Opinion on whether the financial statements give a true and fair view (or present fairly), in all material respects, in accordance with the applicable framework
- Learn this wording. It is the core of most written answers.
- Level of assurance in an audit
- Audit = reasonable assurance (high, not absolute)
- Never write that an audit gives a guarantee or absolute assurance.
- Assurance spectrum
- Audit (reasonable, positive opinion) > Review (limited, negative form) > Related services (none)
- Use to classify any engagement in a scenario.
- Elements of an assurance engagement
- Three-party relationship + subject matter + suitable criteria + sufficient appropriate evidence + written report
- Three parties: practitioner, responsible party and intended users.
- Responsibility split
- Directors: prepare statements, keep internal control. Auditor: form and express an opinion
- Audit does not remove management's responsibility.
- Five elements of an assurance engagement
- Three parties + subject matter + suitable criteria + sufficient appropriate evidence + written report
- List all five. Then tie each to the scenario given in the question.
- Reasonable assurance
- High (not absolute) assurance → positive opinion
- Used for a statutory audit. Assurance risk is reduced to an acceptably low level.
- Limited assurance
- Moderate assurance → negative form of conclusion
- Used for reviews. Work is mainly enquiry and analytical procedures. Assurance risk is higher than for reasonable assurance.
- Positive vs negative wording
- Positive: 'in our opinion, the information is true and fair' | Negative: 'nothing has come to our attention that causes us to believe it is materially misstated'
- Learn both wordings. Negative wording is not a weaker opinion on the same work. It reflects less work.
- Evidence and risk relationship
- More evidence → lower assurance risk → higher assurance
- Use it to explain why the two levels differ.
- Five fundamental principles
- Integrity + Objectivity + Professional competence and due care + Confidentiality + Professional behaviour
- Learn them as a set. Name the exact principle at risk in every answer.
- Five types of threat
- Self-interest, Self-review, Advocacy, Familiarity, Intimidation
- Memory aid: SSAFI. Match the situation to one type and say why.
- Framework for any ethics issue
- Identify threat → Evaluate significance → Apply safeguards → If not reduced to acceptable level, decline or withdraw
- This is the structure of a good written answer.
- Acceptable level test
- Would a reasonable and informed third party conclude compliance with the principles is not compromised?
- The test is objective. It is not what you personally feel.
- Professional scepticism (ISA 200)
- Questioning mind + alertness to possible misstatement + critical assessment of evidence
- It is an attitude. Maintain it throughout the audit, including when the client is long-standing and trusted.
- Professional judgement (ISA 200)
- Training + knowledge + experience, applied within auditing, accounting and ethical standards → informed decisions
- It is needed for materiality, risk assessment, evidence sufficiency, estimates and the opinion.
- Auditor's duty
- Plan and perform the audit with professional scepticism, recognising that material misstatement may exist
- This applies even if the auditor has past experience of management's honesty and integrity.
- Documentation of judgement
- Significant judgements and their basis → recorded in working papers
- An experienced auditor with no prior connection should be able to understand them.
- Audit risk model
- Audit risk = Risk of material misstatement × Detection risk
- A conceptual model, not a calculation you must perform in AA. Know what each part means.
- Risk of material misstatement
- Risk of material misstatement = Inherent risk × Control risk
- Both exist before and independently of the audit. The auditor assesses them but cannot change them.
- Inverse relationship
- Higher assessed risk of material misstatement → lower acceptable detection risk
- Lower detection risk means more, or more reliable, substantive procedures.
- Overall objectives (ISA 200)
- (1) Obtain reasonable assurance of no material misstatement; (2) report in line with findings
- Reasonable assurance is high but not absolute.
- Agency relationship
- Principals (shareholders) → appoint → Agents (directors)
- Conflict of interest and information asymmetry create agency costs. Governance and audit reduce them.
- Core audit committee functions
- Financial reporting integrity + internal control and risk + internal audit oversight + external auditor relationship
- Use these four headings to structure any answer on the committee's role.
- External vs internal audit: key contrasts
- Purpose | Reports to | Independence | Scope | Appointment
- External: opinion for shareholders, independent of the entity, set by law or standards. Internal: assists management, part of the entity, scope set by the entity.
- Auditor and TCWG
- Auditor reports significant findings and deficiencies to TCWG; directors keep responsibility for the financial statements and control
- Do not say the auditor is responsible for preparing the financial statements or internal controls.
Quick revision
- The audit objective is an opinion on whether the financial statements are prepared, in all material respects, in line with the applicable framework.
- Management and those charged with governance prepare the financial statements. The auditor only gives an opinion on them.
- Reasonable assurance is high but not absolute, because of inherent limits such as testing, judgement and persuasive rather than conclusive evidence.
- Limited assurance gives a lower level of assurance and is usually expressed as a negative conclusion.
- The fundamental principles are integrity, objectivity, professional competence and due care, confidentiality and professional behaviour.
- The threat types are self-interest, self-review, advocacy, familiarity and intimidation.
- Safeguards reduce a threat to an acceptable level. If none can, decline or withdraw from the engagement.
- Professional scepticism means a questioning mind and a critical assessment of evidence.
- Professional judgement means applying relevant training, knowledge and experience in the circumstances.
- Audit risk is the risk of giving an inappropriate opinion when the statements are materially misstated. It combines the risks of material misstatement and detection risk.
- Detection risk is the only component the auditor controls directly, through the nature, timing and extent of procedures.
- Governance sets who directs and controls the entity. Auditor independence supports confidence in the financial reporting process.
Common mistakes
- Saying an audit guarantees the statements are correct or free from fraud. Fix: Write reasonable assurance. Explain that testing, judgement and inherent limits mean absolute assurance is impossible.
- Stating that the auditor is responsible for preparing the financial statements. Fix: Directors prepare the statements. The auditor expresses an opinion on them.
- Saying a statutory audit gives absolute or 100% assurance. Fix: Always write reasonable (high but not absolute) assurance and give a reason, such as sampling, judgement and inherent limitations.
- Naming only four or fewer elements, or listing the practitioner alone as the 'party'. Fix: Memorise the five as: parties, subject matter, criteria, evidence, report. Name all three parties inside the first element.
- Listing the five principles with no link to the scenario. Fix: Always tie each threat to a specific fact from the scenario and say which principle is at risk.
- Confusing self-interest and self-review. Fix: Ask whether the auditor would be checking its own work (self-review) or is influenced by a financial or personal gain (self-interest).
- Saying professional scepticism means assuming management is dishonest. Fix: State that the auditor neither assumes honesty nor dishonesty. The auditor keeps a questioning mind and evaluates evidence critically.
- Treating scepticism and judgement as the same thing. Fix: Scepticism is an attitude of questioning. Judgement is applying knowledge and experience to make decisions. Define each separately, then link them.
- Saying the auditor gives absolute assurance or guarantees the statements are correct. Fix: Always write reasonable assurance: high but not absolute, because of inherent limitations.
- Saying the auditor can reduce inherent and control risk. Fix: The auditor only assesses inherent and control risk. Only detection risk is changed, by altering the nature, timing and extent of procedures.
Exam tips
- Learn the objective in one sentence and reuse it. Include the words opinion, true and fair, material and framework.
- In OT questions, treat words like guarantee, certify, absolute and prevent as warning signs.
- In scenario questions, always ask whether a conclusion is given and in what form to find the level of assurance.
- Keep written answers aligned to the verb: explain means give reasons, state means be brief.
- Mention the responsibility split briefly. It often earns an extra mark.
- In an objective question on wording, find the phrase 'nothing has come to our attention'. It signals limited assurance and a negative form of conclusion.
- Never use 'guarantee', 'certify' or 'absolute' when describing assurance. Examiners treat these as wrong.
- If a question asks for the elements of an assurance engagement, use the five as headings and add one scenario fact to each.