ACCA Strategic Professional · Advanced Audit and Assurance (International)
Other current issues: formula sheet
Key formulas
- Benefits and risks balance
- Benefit (what the tool does) + Risk (what can go wrong) + Response (what the auditor does)
- Use this three-part structure for any discussion requirement. It is a framework, not a formula from the standards.
- Reliability of data used in analytics
- Completeness + Accuracy + Relevance of source data
- Under ISA 500 the auditor must consider the relevance and reliability of information used as evidence. Test the data before relying on analytics output.
- Exceptions must be followed up
- Tool output → exception → investigation → conclusion
- A flagged item is not evidence of misstatement until investigated, and an unflagged item is not proof of no misstatement.
- Sufficient appropriate evidence
- Evidence quantity (sufficiency) + Evidence quality (appropriateness)
- Testing 100% of a population does not automatically make the evidence appropriate if the underlying data is unreliable.
- ISQM 1 risk-based cycle
- Quality objectives → Quality risks → Responses → Monitoring and remediation
- Use this chain to structure any ISQM 1 answer. Each risk must be linked to a response.
- ISQM 1 components
- Governance and leadership; relevant ethical requirements; acceptance and continuance; engagement performance; resources; information and communication; the firm's risk assessment process; monitoring and remediation process
- Use as a checklist when asked to evaluate or improve a firm's system. Resources cover technological, intellectual and human resources. Specified responses, such as engagement quality reviews, sit within the system.
- Annual evaluation
- Firm evaluates the system as at a specified date, at least annually, and concludes in one of three ways: (1) reasonable assurance that objectives are achieved; (2) reasonable assurance except for matters identified; (3) no reasonable assurance
- The evaluation and conclusion are made by the individual(s) the firm has assigned ultimate responsibility and accountability for the system.
- EQR trigger (ISQM 1)
- EQR required for listed entity audits, for engagements where law or regulation requires one, and where the firm judges an EQR is a response to an assessed quality risk
- ISQM 2 covers reviewer eligibility, performance and documentation. The reviewer must be objective and not part of the engagement team.
- ISQC 1 vs ISQM 1
- ISQC 1: prescribed policies. ISQM 1: risk-based, tailored, proactive, with continual monitoring
- A very common comparison question.
- Financial audit vs ESG assurance
- Financial audit: opinion on financial statements (ISAs) | ESG assurance: conclusion on sustainability information (ISAE 3000, ISAE 3410 or ISSA 5000)
- Different subject matter, different criteria, different report. Say which one the question is about.
- Assurance levels
- Reasonable assurance = positive opinion, high level | Limited assurance = negative-form conclusion, moderate level
- Limited assurance still needs enough work to give a meaningful level, but less than reasonable assurance.
- Elements of an assurance engagement
- Three parties + subject matter + suitable criteria + sufficient appropriate evidence + written report
- Use as a checklist for acceptance. Criteria must be relevant, complete, reliable, neutral and understandable.
- Climate risk in financial statements
- Climate risk → assumptions and estimates → possible misstatement in impairment, useful lives, provisions, fair value, going concern, disclosures
- This is the link from climate risk to the financial audit.
- Other information
- ISA 720 (Revised): read, consider inconsistency with financial statements and audit knowledge, respond, report
- Applies when a sustainability report sits in the annual report. It does not give assurance on that report.
- Expectation gap
- Expectation gap = Knowledge gap + Performance gap + Standards gap
- Use this to structure any discussion of why users are disappointed by audits.
- Assurance level
- Audit = reasonable assurance (high, but not absolute)
- Never say an audit guarantees that no fraud exists.
- Responsibility split for fraud
- Prevention and detection = management and TCWG; reasonable assurance on material misstatement = auditor
- State both sides. Auditors are not responsible for preventing fraud.
- Going concern responsibility split
- Management assesses and discloses; auditor evaluates and concludes
- Auditor concludes on appropriateness of the going concern basis and whether a material uncertainty exists.
- Reform argument structure
- Current duty → public expectation → proposed change → benefit → cost
- A reliable shape for any written discussion.
- Independence threat categories
- Self-interest | Self-review | Advocacy | Familiarity | Intimidation
- Link each reform to the threat it targets. This is the core of most answers.
- Rotation – what it targets
- Long association → familiarity threat
- Applies to the engagement partner and, in some regimes, the firm. Exact time limits and cooling-off periods depend on the local rules or the Code. Use the figures given in the question and do not guess.
- NAS at a PIE – general principle
- If NAS creates a self-review threat at a PIE → do not provide it
- The IESBA Code takes a stricter line for PIEs than for other entities. Safeguards are less available at a PIE.
- Communication with governance
- Auditor tells TCWG about NAS and fees → TCWG assess independence
- For PIEs, the Code expects communication with those charged with governance and, for some matters, their concurrence.
- Answer structure
- Threat → Reform → Benefit → Drawback → Recommendation
- Use this chain for any discuss or evaluate requirement.
- Audit risk model
- Audit risk = risk of material misstatement × detection risk
- Risk of material misstatement is inherent risk combined with control risk. A new trend usually raises inherent or control risk, so detection risk must be lowered by more or better work.
- Evidence standard
- Evidence must be sufficient (quantity) and appropriate (relevance and reliability)
- Applies equally to remote work. Evidence seen remotely, or from systems that may be compromised, may be less reliable.
- Answer structure for current issues
- Issue → risk → effect on audit → response → ethics or reporting point
- A reliable pattern for any emerging issues requirement.
Quick revision
- Technology can improve coverage and efficiency, but the auditor still needs professional judgement and scepticism.
- Data analytics can test whole populations, but you must assess data completeness and reliability first.
- Automated tools bring new risks, such as over-reliance, poor data and skills gaps in the audit team.
- ISQM 1 requires a firm to design, implement and operate a system of quality management using a risk-based approach.
- Under ISQM 1, the firm identifies quality risks, responds to them and monitors and remediates deficiencies.
- Leadership responsibility and accountability for quality sit with the firm's leaders.
- Sustainability assurance can be limited or reasonable, and the level changes the work and the conclusion.
- Climate and ESG reporting raises risks around data quality, estimates and the competence of the assurance team.
- The auditor's responsibility for fraud is to obtain reasonable assurance, with management and those charged with governance responsible for prevention and detection.
- Going concern work needs evaluation of management's assessment and a check of material uncertainty disclosures.
- Reform debates focus on audit quality, independence, competition and the expectation gap.
- Cyber risk affects the client's financial reporting risks and the auditor's own data security and confidentiality.
Common mistakes
- Saying technology removes the need for sampling or judgement entirely. Fix: State that analytics change how evidence is gathered, but the auditor still evaluates results and applies scepticism.
- Listing generic advantages and risks not linked to the scenario. Fix: Pick points that match the client's system, industry and data, and name the scenario detail in each point.
- Saying ISQM 1 is just ISQC 1 renamed. Fix: State that ISQM 1 is risk-based, with quality objectives, risks and responses, plus an annual evaluation and a stronger focus on monitoring and governance.
- Listing ISQM 1 components without applying them. Fix: Tie each component to a fact in the scenario and give a specific recommendation.
- Treating ESG assurance as a normal financial audit. Fix: State that the subject matter is sustainability information, the standard is ISAE 3000, ISAE 3410 or ISSA 5000, and the output is an assurance conclusion.
- Confusing limited and reasonable assurance, for example saying limited assurance means no evidence is needed. Fix: Explain that limited assurance needs enough procedures for a meaningful moderate level, mainly enquiry and analytical procedures, while reasonable assurance needs more testing and risk assessment.
- Saying the auditor is responsible for preventing and detecting fraud. Fix: Say management and TCWG are primarily responsible. The auditor obtains reasonable assurance on material misstatement.
- Claiming an audit guarantees the company will continue as a going concern. Fix: Explain that the opinion is about the financial statements and that the auditor cannot predict future events.
- Listing reforms without linking them to the scenario. Fix: Quote a fact from the case, such as years in post or fees earned, in every point.
- Giving only the benefits of rotation. Fix: Add the costs: loss of client knowledge, higher audit cost, learning-curve risk and possible weaker quality in the first year.
Exam tips
- Always tie your points to the scenario. Generic lists of advantages and risks earn few marks.
- In discussion questions, give both benefits and risks, then say how the auditor responds. This three-part answer covers professional skills marks too.
- Mention data reliability whenever you mention analytics or AI. It is one of the most commonly rewarded points.
- Link technology to ISA concepts such as risk assessment, evidence under ISA 500 and analytical procedures, rather than treating it as a separate topic.
- If asked to advise a partner or client, use a clear structure with a short conclusion and a recommendation, and write in a professional tone.
- Always structure answers around the risk-based chain: objective, risk, response, monitoring.
- Use scenario facts to find root causes. Marks go for application, not definitions.
- Keep ISQM 1 firm-level and ISQM 2 and ISA 220 engagement-level in your answers.