CA Intermediate · Auditing and Ethics
Nature, Objective and Scope of Audit: formula sheet
Key formulas
- Definition of auditing
- Auditing = independent examination of financial information + evidence + opinion
- Use these three ideas in any definition answer: independence, evidence, opinion.
- Audit versus accounting
- Accounting = records and summarises; Auditing = examines and reports
- Accounting comes first. Audit follows and depends on the accounting records.
- Audit versus investigation
- Audit = general, periodic, opinion on financial statements; Investigation = specific, purpose-driven, in-depth
- Investigation can go beyond the books and is not limited to a fixed period.
- Level of assurance
- Audit gives reasonable assurance, not absolute assurance
- Limits come from testing, judgment, and inherent limits of controls and evidence.
- Overall objective (SA 200)
- Reasonable assurance that financial statements are free from material misstatement (fraud or error) → opinion on whether they are prepared, in all material respects, per the applicable framework
- Write both parts: obtaining assurance and reporting.
- Assurance level
- Audit assurance = reasonable assurance ≠ absolute assurance
- Reasonable assurance is a high level, not a guarantee.
- Fraud versus error
- Fraud = intentional act; Error = unintentional mistake
- The distinguishing factor is whether the underlying action is intentional or unintentional. Prevention and detection of both is primarily management's and TCWG's responsibility.
- Sources of inherent limitations
- Nature of financial reporting + nature of audit procedures + need for the audit to be conducted within a reasonable period of time and at a reasonable cost (SA 200 paras A46-A57)
- Use these three sources as a structure for long answers. Give a reason or example under each.
- Why fraud is harder to detect than error
- Fraud may involve collusion, forgery, deliberate omissions or management override, so it is harder to detect than error
- Concealment is the reason. This is separate from detection risk, which is a component of audit risk.
- Overall objectives (two parts)
- Objective 1 = reasonable assurance on material misstatement-free statements and opinion on framework compliance or true and fair view; Objective 2 = report and communicate as per SAs
- Write both parts. Many students remember only the first.
- Audit evidence
- Audit evidence = Sufficiency (quantity) + Appropriateness (relevance + reliability)
- Higher assessed risk needs more evidence. Poorer quality evidence needs more quantity, but more quantity does not cure poor quality.
- Audit risk
- Audit risk is a function of the risks of material misstatement (RMM) and detection risk
- The auditor works to reduce audit risk to an acceptably low level. RMM comprises inherent risk and control risk. SA 200 does not prescribe a formula, and RMM may be assessed in quantitative or non-quantitative terms. Any multiplication of these risks is only illustrative.
- Assurance level
- Reasonable assurance = high level, not absolute assurance
- Cite inherent limitations: nature of financial reporting, nature of audit procedures, and the need to audit within a reasonable period and at reasonable cost.
- Audit risk model
- Audit Risk = Risk of Material Misstatement × Detection Risk
- Risk of material misstatement is the combination of inherent risk and control risk.
- Risk of material misstatement
- RMM = Inherent Risk × Control Risk
- A conceptual illustration for numerical questions. SA 315 (Revised) requires separate assessment of inherent and control risk but does not prescribe numerical percentages. The auditor assesses RMM but does not control it.
- Acceptable detection risk
- Detection Risk = Audit Risk ÷ (Inherent Risk × Control Risk)
- Rearranged from the model. If RMM rises, detection risk must fall.
- Relationship rule
- Higher assessed RMM → lower acceptable detection risk → more substantive work
- Inverse relationship. Detection risk is the only component the auditor can change directly.
- Materiality rule
- Performance materiality < Overall materiality
- Performance materiality is set lower to cover aggregation of uncorrected and undetected misstatements.
- Materiality and audit risk
- Lower materiality → more audit evidence needed
- Materiality is judged by size and nature, and is not a fixed percentage prescribed for all cases.
- Classification test
- Type of audit = who requires it + what is examined + who receives the report
- Use this to place any audit in a one-line definition.
- Level of assurance
- Audit opinion = reasonable assurance, not absolute assurance
- Write this whenever you describe the auditor's role or the limits of audit.
- Statutory vs internal audit anchor
- Statutory: law, for members, independent. Internal: management, for management, as scoped by management
- Anchor the usual difference question: who appoints, objective, scope, report user, independence.
- Financial statement vs compliance audit
- Financial statement audit: opinion on true and fair view or fair presentation. Compliance audit: conclusion on adherence to specified requirements
- The first is about the numbers. The second is about rules followed.
- Preconditions for an audit (SA 210)
- Acceptable financial reporting framework + management's agreement to its responsibilities = audit can be accepted
- If either is missing, do not accept the engagement as an audit unless law or regulation requires it.
- Management's responsibilities agreed
- Prepare statements under the framework + maintain internal control + give access and information
- These three must be acknowledged by management in the engagement terms.
- Audit engagement letter
- Written agreement of objective, scope, responsibilities, framework and expected form of report
- The agreed terms should be recorded in writing. A letter is the usual form.
- Audit process flow
- Acceptance → Planning → Risk assessment → Further procedures → Evidence → Completion → Reporting
- Documentation under SA 230 runs through all stages.
- Compliance with SAs
- Comply with all SAs relevant to the audit; if a requirement is not followed, document the reason and the alternative procedures
- Explanatory material in an SA supports the requirements; it does not add to them.
Quick revision
- An audit is an independent examination of financial information, ending in an opinion.
- The auditor's opinion is on whether the financial statements are prepared, in all material respects, in line with the applicable framework.
- An audit gives reasonable assurance, which is high but not absolute.
- Inherent limitations include the use of judgment, the nature of financial reporting, limits of internal control, and the fact that much evidence is persuasive rather than conclusive.
- SA 200 sets the overall objectives of the independent auditor and the conduct of an audit in line with SAs.
- Professional skepticism means a questioning mind and a critical assessment of evidence.
- Audit risk is the risk of giving an inappropriate opinion when the statements are materially misstated.
- Risk of material misstatement has two parts: inherent risk and control risk. Detection risk is the auditor's own.
- Misstatements are material if they could reasonably influence the decisions of users.
- Materiality is a matter of professional judgment and is set for the statements as a whole and also at lower levels where needed.
- Higher assessed risk of material misstatement calls for lower detection risk, which means more audit work.
- Audit work starts with engagement acceptance and ends with the audit report.
Common mistakes
- Saying the auditor prepares the financial statements. Fix: Remember that management prepares them and the auditor only examines them and reports an opinion.
- Claiming an audit gives a guarantee that there are no errors or fraud. Fix: Write that audit gives reasonable assurance, not absolute assurance.
- Stating fraud detection as the main objective of audit. Fix: Write that the overall objective is reasonable assurance and the opinion on the financial statements. Fraud and error detection is only a subsidiary objective in textbooks, though the auditor must still plan for material misstatement from fraud.
- Saying the auditor prevents fraud or that prevention is an audit objective. Fix: State that prevention and detection of fraud is primarily the responsibility of management and TCWG. The auditor obtains reasonable assurance and reports.
- Saying the auditor gives absolute assurance that statements are correct. Fix: Write reasonable assurance, a high but not absolute level, and mention inherent limitations.
- Treating sufficient and appropriate as the same thing. Fix: Sufficiency measures quantity. Appropriateness measures quality through relevance and reliability.
- Saying the auditor gives absolute assurance or guarantees accuracy. Fix: Always write reasonable assurance: high but not absolute, because of inherent limitations such as sampling, judgment and control limitations.
- Treating detection risk as an entity risk. Fix: Remember that inherent and control risk belong to the entity. Detection risk belongs to the auditor's procedures.
- Saying the auditor prepares the financial statements. Fix: Write that management prepares the statements and the auditor expresses an opinion on them.
- Claiming an audit gives a guarantee that there is no fraud or error. Fix: Use the phrase reasonable assurance and mention inherent limitations such as sampling and judgment.
Exam tips
- Always include independence, evidence and opinion in a definition answer.
- For difference questions, use a two-column layout with four or five bases.
- In MCQs, reject options that say absolute assurance or that the auditor prepares accounts.
- Link your conclusion to true and fair view to show depth.
- Keep each point to one line so you cover more points in the time given.
- Open every answer with the exact phrase reasonable assurance. It is the keyword examiners look for.
- In scenario questions on missed fraud, the verdict depends on whether the SAs were followed. Say so clearly.
- Memorise limitations under three sources, nature of financial reporting, nature of audit procedures, and reasonable time and cost, so you can write a structured answer even if you forget individual points.