CA Final · Advanced Auditing, Assurance and Professional Ethics
General Auditing Principles and Auditors Responsibilities: formula sheet
Key formulas
- Overall objective 1
- Obtain reasonable assurance that the financial statements as a whole are free from material misstatement (fraud or error) → enables an opinion on whether they are prepared, in all material respects, per the applicable framework
- The assurance relates to the statements as a whole, not to every item or balance.
- Overall objective 2
- Report on the financial statements and communicate as required by the SAs, in line with the auditor's findings
- Reporting covers the auditor's report and any required communication, for example with those charged with governance.
- Reasonable assurance
- Reasonable assurance = high level of assurance, not absolute; reached when sufficient appropriate audit evidence reduces audit risk to an acceptably low level
- Always say 'high but not absolute'. Never say 'guarantee'.
- Inherent limitations
- Nature of financial reporting + nature of audit procedures + timeliness and cost balance
- Use these three heads to structure answers.
- Audit risk link
- Audit risk is a function of the risks of material misstatement and detection risk (often shown as RMM × DR)
- This is a conceptual model, not a formula given in SA 200. Audit risk is the risk of giving a wrong opinion when the statements are materially misstated. The auditor lowers it by keeping detection risk low through sufficient appropriate audit evidence.
- Ethical requirements (SA 200)
- Auditor must comply with relevant ethical requirements, including independence, relating to financial statement audit engagements
- In India, source is the ICAI Code of Ethics read with the Chartered Accountants Act and its Regulations.
- Professional skepticism (SA 200)
- Professional skepticism = questioning mind + alertness to possible misstatement (error or fraud) + critical assessment of audit evidence
- Must be maintained throughout planning and performance of the audit.
- Fundamental principles
- Integrity, Objectivity, Professional competence and due care, Confidentiality, Professional behaviour
- Independence safeguards objectivity; it has independence of mind and independence in appearance.
- Threats to independence
- Self-interest, Self-review, Advocacy, Familiarity, Intimidation
- Respond with safeguards; if the threat cannot be reduced to an acceptable level, decline or withdraw.
- Skepticism vs judgment
- Skepticism = attitude toward evidence; Judgment = applying training, knowledge and experience to reach decisions
- Both are needed, and skepticism underpins sound judgment.
- Definition of professional judgment
- Professional judgment = training + knowledge + experience, applied within auditing, accounting and ethical standards, to make informed decisions on appropriate action
- Use these elements in your opening line. Add 'in the circumstances of the audit engagement'.
- Areas needing judgment
- Materiality and audit risk | nature, timing, extent of procedures | sufficiency and appropriateness of evidence | management's judgments | conclusions such as reasonableness of estimates
- Five areas. Write them as bullet points and give a one-line example for each.
- Limit on judgment
- Judgment ≠ justification for decisions not supported by facts, circumstances or sufficient appropriate audit evidence
- Always state this limit. It is a frequent exam point.
- Documentation test
- Documentation must enable an experienced auditor, with no previous connection to the audit, to understand significant matters and the judgments made
- Comes from SA 230. Document the reasoning for significant judgments, not only the conclusion.
- Audit risk model (conceptual)
- AR = RMM × DR
- A conceptual relationship, not a calculation the standard requires. SA 200 does not state a multiplicative formula. Use it to explain direction of effect.
- Components of RMM
- RMM = combined assessment of inherent risk and control risk (not an arithmetic sum). For illustration only, RMM = IR × CR.
- SA 200 allows separate or combined assessment. Under SA 315 (Revised 2019), assess inherent and control risk separately for assertions. Do not describe it as a literal arithmetic sum.
- Numerical illustration
- DR = AR ÷ RMM, where RMM = IR × CR for illustration only
- Only an illustration of the multiplicative model. Example: RMM = 0.5 × 0.5 = 0.25, so DR = 5% ÷ 0.25 = 20%.
- Audit evidence
- Sufficiency (quantity) + Appropriateness (relevance + reliability)
- Both are needed. Quantity cannot compensate for poor quality.
- Inverse relationship
- Higher RMM ⇒ lower acceptable detection risk ⇒ more extensive, or more effective, procedures
- Detection risk is managed through nature, timing and extent of procedures.
- Compliance rule
- Relevant SA + relevant requirement → must comply
- Do not claim an audit under SAs if any relevant requirement was not met, other than a justified departure with alternative procedures.
- Relevance test for an SA
- SA in effect AND circumstances addressed by the SA exist
- If the circumstances do not exist, the SA is not relevant to that audit.
- Relevance of a requirement
- A requirement is not relevant if it is conditional and the condition does not exist
- Example: a requirement that applies only when a specific circumstance arises.
- Use of objectives
- Objective achieved? If not, perform further procedures
- If the objective still cannot be achieved, the auditor evaluates the effect on the opinion or report, and may need to withdraw where permitted.
- Departure rule
- Exceptional circumstances → alternative procedures + documentation of reasons
- The alternative procedures must achieve the aim of the requirement departed from.
- Understanding the SA
- Requirements + application and other explanatory material = full text
- Read the whole text. Application material guides the requirements but does not create new ones.
- Fraud vs error test
- Intentional act = Fraud; Unintentional act = Error
- Intent is the only distinguishing factor. The auditor does not conclude on legal intent, only on whether a misstatement exists.
- Two types of fraud relevant to the auditor
- Fraudulent financial reporting + Misappropriation of assets
- Fraudulent reporting is usually by management; misappropriation is more often by employees but can involve management.
- Fraud triangle
- Incentive/Pressure + Opportunity + Attitude/Rationalisation
- Fraud risk factors are grouped under these three headings.
- Auditor's responsibility
- Reasonable assurance that financial statements as a whole are free from material misstatement (fraud or error)
- Reasonable assurance is high but not absolute. Auditor is not responsible for preventing fraud.
- Presumed risks
- Risk in revenue recognition + Risk of management override of controls
- Presume a risk of fraud in revenue recognition (rebuttable, with reasons documented). Management override risk is always treated as a significant risk and cannot be rebutted. Procedures include testing journal entries, reviewing estimates for bias and evaluating the business rationale of significant unusual transactions.
- Engagement team discussion
- Discuss susceptibility of the entity to material misstatement due to fraud
- Required among key engagement team members, with the engagement partner deciding which matters to communicate to members not present.
- Fraud risk factors
- Incentive or pressure + Opportunity + Attitude or rationalisation
- Use these three heads to classify every factor in a case. Fraud is more likely when all three are present.
- Presumed risk: revenue
- Revenue recognition: presume fraud risk unless rebutted and documented
- The presumption can be rebutted for a type of revenue or an assertion, with reasons documented. Fraud risks identified are treated as significant risks.
- Mandatory procedures for management override
- Journal entries + Accounting estimates (bias) + Significant unusual transactions
- Test appropriateness of journal entries and other adjustments, review estimates for bias, and evaluate the business rationale of significant transactions outside the normal course.
- Layers of response
- Overall responses + Assertion-level procedures + Override procedures
- Add unpredictability in the nature, timing or extent of procedures.
- Fraud vs error
- Intentional act = fraud; unintentional = error
- The auditor does not make legal determinations of whether fraud occurred.
Quick revision
- SA 200 aims at reasonable assurance, which is high but not absolute.
- The auditor also reports on the financial statements and communicates as required by the SAs, in line with findings.
- Professional skepticism means a questioning mind and critical assessment of evidence.
- Professional judgment must be exercised and documented where it matters, and it does not excuse a lack of evidence.
- Audit evidence has two qualities: sufficiency (quantity) and appropriateness (relevance and reliability).
- Higher assessed risk calls for more evidence, and higher quality evidence may reduce the quantity required. But a greater quantity of evidence cannot compensate for its poor quality.
- Audit risk is the risk of giving an inappropriate opinion when the statements are materially misstated.
- Audit risk has risks of material misstatement and detection risk as its parts. The auditor assesses the risks of material misstatement and, in response, sets an acceptable level of detection risk through the nature, timing and extent of further audit procedures.
- Inherent limitations of an audit exist, so an audit cannot give absolute assurance.
- Management and those charged with governance are primarily responsible for preventing and detecting fraud.
- The auditor is responsible for reasonable assurance on material misstatement, whether due to fraud or error.
- Fraud involves intent, while error is unintentional, and the distinction drives responses.
- The auditor presumes there are fraud risks in revenue recognition, but this presumption can be rebutted with documented reasons. The risk of management override of controls is always present and cannot be rebutted. The auditor treats assessed fraud risks, including management override, as significant risks.
Common mistakes
- Writing that the auditor gives absolute assurance or certifies the accounts as correct. Fix: Use the phrase 'reasonable assurance: high but not absolute' and mention inherent limitations.
- Listing only the first objective and forgetting the reporting objective. Fix: Write both objectives, and say the second is to report and communicate as the SAs require, in line with findings.
- Treating professional skepticism as assuming management is dishonest. Fix: Define it as a questioning mind and critical assessment of evidence. You can accept records as genuine unless there is reason to doubt them.
- Using skepticism and professional judgment as the same thing. Fix: Skepticism is an attitude toward evidence; judgment is applying training, knowledge and experience to decisions. Give one example of each.
- Treating professional judgment as the same as professional skepticism. Fix: Skepticism is an attitude of questioning and alertness. Judgment is the informed decision-making. Write them separately.
- Saying judgment lets the auditor override evidence or a standard. Fix: State that judgment operates within the standards and cannot justify decisions unsupported by facts and sufficient appropriate evidence.
- Saying the auditor can reduce inherent and control risk by doing more work. Fix: Inherent and control risks belong to the entity. You only assess them. You influence audit risk through detection risk.
- Defining detection risk as a failure of the entity's controls. Fix: Control risk is the entity's controls missing it. Detection risk is your procedures missing it.
- Saying the auditor may skip an SA that seems unimportant. Fix: State that all relevant SAs and all relevant requirements must be complied with. Only a requirement that is not relevant may be left out.
- Confusing an SA that is not relevant with a requirement that is not relevant. Fix: First decide if the whole SA applies, for example SA 600 when the entity is standalone with no components. Then decide, within a relevant SA, if a conditional requirement is triggered.
Exam tips
- Always open a theory answer with the exact two objectives, then expand. Examiners look for both.
- In case scenarios, name the limitation head that matches the facts (collusion, estimates, time and cost) and conclude on liability.
- Use the words 'reasonable assurance', 'sufficient appropriate audit evidence', 'material misstatement' and 'as a whole'. These earn marks.
- For MCQs, eliminate options that promise certainty. They are usually wrong.
- Connect to related SAs in one line, for example SA 700 for reporting and SA 705 where assurance cannot be obtained.
- For case MCQs on independence, first name the threat type. The correct option usually matches the threat and the proper response.
- In written answers, use the provision-facts-conclusion pattern and quote key words such as questioning mind, critical assessment and independence of mind and in appearance.
- If asked for the difference between skepticism and judgment, write a short two-column style comparison in bullets: nature, purpose and example.