Skip to content

ACCA Strategic Professional · Advanced Audit and Assurance (International)

Other current issues: formula sheet

Full chapter guide

Key formulas

Benefits and risks balance
Benefit (what the tool does) + Risk (what can go wrong) + Response (what the auditor does)
Use this three-part structure for any discussion requirement. It is a framework, not a formula from the standards.
Reliability of data used in analytics
Completeness + Accuracy + Relevance of source data
Under ISA 500 the auditor must consider the relevance and reliability of information used as evidence. Test the data before relying on analytics output.
Exceptions must be followed up
Tool output → exception → investigation → conclusion
A flagged item is not evidence of misstatement until investigated, and an unflagged item is not proof of no misstatement.
Sufficient appropriate evidence
Evidence quantity (sufficiency) + Evidence quality (appropriateness)
Testing 100% of a population does not automatically make the evidence appropriate if the underlying data is unreliable.
ISQM 1 risk-based cycle
Quality objectives → Quality risks → Responses → Monitoring and remediation
Use this chain to structure any ISQM 1 answer. Each risk must be linked to a response.
ISQM 1 components
Governance and leadership; relevant ethical requirements; acceptance and continuance; engagement performance; resources; information and communication; the firm's risk assessment process; monitoring and remediation process
Use as a checklist when asked to evaluate or improve a firm's system. Resources cover technological, intellectual and human resources. Specified responses, such as engagement quality reviews, sit within the system.
Annual evaluation
Firm evaluates the system as at a specified date, at least annually, and concludes in one of three ways: (1) reasonable assurance that objectives are achieved; (2) reasonable assurance except for matters identified; (3) no reasonable assurance
The evaluation and conclusion are made by the individual(s) the firm has assigned ultimate responsibility and accountability for the system.
EQR trigger (ISQM 1)
EQR required for listed entity audits, for engagements where law or regulation requires one, and where the firm judges an EQR is a response to an assessed quality risk
ISQM 2 covers reviewer eligibility, performance and documentation. The reviewer must be objective and not part of the engagement team.
ISQC 1 vs ISQM 1
ISQC 1: prescribed policies. ISQM 1: risk-based, tailored, proactive, with continual monitoring
A very common comparison question.
Financial audit vs ESG assurance
Financial audit: opinion on financial statements (ISAs) | ESG assurance: conclusion on sustainability information (ISAE 3000, ISAE 3410 or ISSA 5000)
Different subject matter, different criteria, different report. Say which one the question is about.
Assurance levels
Reasonable assurance = positive opinion, high level | Limited assurance = negative-form conclusion, moderate level
Limited assurance still needs enough work to give a meaningful level, but less than reasonable assurance.
Elements of an assurance engagement
Three parties + subject matter + suitable criteria + sufficient appropriate evidence + written report
Use as a checklist for acceptance. Criteria must be relevant, complete, reliable, neutral and understandable.
Climate risk in financial statements
Climate risk → assumptions and estimates → possible misstatement in impairment, useful lives, provisions, fair value, going concern, disclosures
This is the link from climate risk to the financial audit.
Other information
ISA 720 (Revised): read, consider inconsistency with financial statements and audit knowledge, respond, report
Applies when a sustainability report sits in the annual report. It does not give assurance on that report.
Expectation gap
Expectation gap = Knowledge gap + Performance gap + Standards gap
Use this to structure any discussion of why users are disappointed by audits.
Assurance level
Audit = reasonable assurance (high, but not absolute)
Never say an audit guarantees that no fraud exists.
Responsibility split for fraud
Prevention and detection = management and TCWG; reasonable assurance on material misstatement = auditor
State both sides. Auditors are not responsible for preventing fraud.
Going concern responsibility split
Management assesses and discloses; auditor evaluates and concludes
Auditor concludes on appropriateness of the going concern basis and whether a material uncertainty exists.
Reform argument structure
Current duty → public expectation → proposed change → benefit → cost
A reliable shape for any written discussion.
Independence threat categories
Self-interest | Self-review | Advocacy | Familiarity | Intimidation
Link each reform to the threat it targets. This is the core of most answers.
Rotation – what it targets
Long association → familiarity threat
Applies to the engagement partner and, in some regimes, the firm. Exact time limits and cooling-off periods depend on the local rules or the Code. Use the figures given in the question and do not guess.
NAS at a PIE – general principle
If NAS creates a self-review threat at a PIE → do not provide it
The IESBA Code takes a stricter line for PIEs than for other entities. Safeguards are less available at a PIE.
Communication with governance
Auditor tells TCWG about NAS and fees → TCWG assess independence
For PIEs, the Code expects communication with those charged with governance and, for some matters, their concurrence.
Answer structure
Threat → Reform → Benefit → Drawback → Recommendation
Use this chain for any discuss or evaluate requirement.
Audit risk model
Audit risk = risk of material misstatement × detection risk
Risk of material misstatement is inherent risk combined with control risk. A new trend usually raises inherent or control risk, so detection risk must be lowered by more or better work.
Evidence standard
Evidence must be sufficient (quantity) and appropriate (relevance and reliability)
Applies equally to remote work. Evidence seen remotely, or from systems that may be compromised, may be less reliable.
Answer structure for current issues
Issue → risk → effect on audit → response → ethics or reporting point
A reliable pattern for any emerging issues requirement.

Quick revision

  • Technology can improve coverage and efficiency, but the auditor still needs professional judgement and scepticism.
  • Data analytics can test whole populations, but you must assess data completeness and reliability first.
  • Automated tools bring new risks, such as over-reliance, poor data and skills gaps in the audit team.
  • ISQM 1 requires a firm to design, implement and operate a system of quality management using a risk-based approach.
  • Under ISQM 1, the firm identifies quality risks, responds to them and monitors and remediates deficiencies.
  • Leadership responsibility and accountability for quality sit with the firm's leaders.
  • Sustainability assurance can be limited or reasonable, and the level changes the work and the conclusion.
  • Climate and ESG reporting raises risks around data quality, estimates and the competence of the assurance team.
  • The auditor's responsibility for fraud is to obtain reasonable assurance, with management and those charged with governance responsible for prevention and detection.
  • Going concern work needs evaluation of management's assessment and a check of material uncertainty disclosures.
  • Reform debates focus on audit quality, independence, competition and the expectation gap.
  • Cyber risk affects the client's financial reporting risks and the auditor's own data security and confidentiality.

Common mistakes

  • Saying technology removes the need for sampling or judgement entirely. Fix: State that analytics change how evidence is gathered, but the auditor still evaluates results and applies scepticism.
  • Listing generic advantages and risks not linked to the scenario. Fix: Pick points that match the client's system, industry and data, and name the scenario detail in each point.
  • Saying ISQM 1 is just ISQC 1 renamed. Fix: State that ISQM 1 is risk-based, with quality objectives, risks and responses, plus an annual evaluation and a stronger focus on monitoring and governance.
  • Listing ISQM 1 components without applying them. Fix: Tie each component to a fact in the scenario and give a specific recommendation.
  • Treating ESG assurance as a normal financial audit. Fix: State that the subject matter is sustainability information, the standard is ISAE 3000, ISAE 3410 or ISSA 5000, and the output is an assurance conclusion.
  • Confusing limited and reasonable assurance, for example saying limited assurance means no evidence is needed. Fix: Explain that limited assurance needs enough procedures for a meaningful moderate level, mainly enquiry and analytical procedures, while reasonable assurance needs more testing and risk assessment.
  • Saying the auditor is responsible for preventing and detecting fraud. Fix: Say management and TCWG are primarily responsible. The auditor obtains reasonable assurance on material misstatement.
  • Claiming an audit guarantees the company will continue as a going concern. Fix: Explain that the opinion is about the financial statements and that the auditor cannot predict future events.
  • Listing reforms without linking them to the scenario. Fix: Quote a fact from the case, such as years in post or fees earned, in every point.
  • Giving only the benefits of rotation. Fix: Add the costs: loss of client knowledge, higher audit cost, learning-curve risk and possible weaker quality in the first year.

Exam tips

  • Always tie your points to the scenario. Generic lists of advantages and risks earn few marks.
  • In discussion questions, give both benefits and risks, then say how the auditor responds. This three-part answer covers professional skills marks too.
  • Mention data reliability whenever you mention analytics or AI. It is one of the most commonly rewarded points.
  • Link technology to ISA concepts such as risk assessment, evidence under ISA 500 and analytical procedures, rather than treating it as a separate topic.
  • If asked to advise a partner or client, use a clear structure with a short conclusion and a recommendation, and write in a professional tone.
  • Always structure answers around the risk-based chain: objective, risk, response, monitoring.
  • Use scenario facts to find root causes. Marks go for application, not definitions.
  • Keep ISQM 1 firm-level and ISQM 2 and ISA 220 engagement-level in your answers.