Advanced Audit and Assurance (International) · Other current issues
Cyber Risk, Remote Auditing and Emerging Audit Trends
Updated 11 October 2026 · Fact-checked
Emerging issues questions ask how cyber risk, remote working, new business models and similar trends change audit risk, audit procedures and ethics. You identify the issue in the scenario, link it to ISA risk assessment and evidence, then give practical, specific responses with professional scepticism.
Understand Emerging Issues: Cyber Risk, Remote Auditing and Other Trends
Emerging issues are developments that change the risks an entity faces or the way an auditor works. In AAA you are not asked to recite a technology manual. You are asked to apply audit thinking to a new situation.
Cyber risk is the risk of loss from attacks on, or failures of, information systems. Examples are ransomware, data theft, unauthorised access and system outages. For the auditor it matters in two ways. First, it can affect the financial statements: lost revenue, fines, remediation costs, impairment, provisions, contingent liabilities, and going concern doubt. Second, it can affect the reliability of the systems that produce the financial information, so it affects controls and the risk of material misstatement.
The auditor is not required to give assurance on cybersecurity as part of a financial statement audit. But under ISA 315 (Revised 2019) you must understand the entity's IT environment and how IT risks affect the financial reporting process. Under ISA 250 you consider laws such as data protection rules, and non-compliance may have a financial effect. Also consider the firm's own cyber risk. The firm holds confidential client data, so a breach raises confidentiality, ethical and liability issues.
Remote auditing means performing audit work without being physically at the client. Examples are video calls, secure file sharing, remote access to client systems, and virtual inventory observation. Benefits include lower travel cost, flexibility, and wider access to staff and specialists. Challenges include weaker evidence reliability, harder supervision and review, less insight into culture and control environment, data security, and difficulty in spotting fraud indicators. The ISA requirements do not change. You must still obtain sufficient appropriate evidence, supervise, review and keep professional scepticism.
Other trends include new business models (cryptoassets, platform and subscription revenue, gig-based workforces), use of data analytics and AI by clients and auditors, sustainability reporting and assurance, and fraud risks from new technology. The approach is the same for each: what is the new risk, which assertion or area is affected, and how should the audit respond?
Key rules to remember
- Audit risk model
- Audit risk = risk of material misstatement × detection risk
- Risk of material misstatement is inherent risk combined with control risk. A new trend usually raises inherent or control risk, so detection risk must be lowered by more or better work.
- Evidence standard
- Evidence must be sufficient (quantity) and appropriate (relevance and reliability)
- Applies equally to remote work. Evidence seen remotely, or from systems that may be compromised, may be less reliable.
- Answer structure for current issues
- Issue → risk → effect on audit → response → ethics or reporting point
- A reliable pattern for any emerging issues requirement.
How to solve Emerging Issues: Cyber Risk, Remote Auditing and Other Trends questions
Use this method for any question on cyber risk, remote auditing or another trend.
- 1Read the requirement and note the verb: discuss, evaluate, explain, recommend. Note the number of marks to set the number of points.
- 2Identify the emerging issue in the scenario and the specific facts: industry, systems, dates, incidents, staff.
- 3State the risk to the entity and to the financial statements, naming the affected area such as revenue, provisions, going concern or disclosure.
- 4Link to the ISA: risk assessment (ISA 315), response (ISA 330), evidence (ISA 500), laws (ISA 250), going concern (ISA 570), as relevant.
- 5Give specific audit procedures or changes to the approach, tied to the facts, not generic lists.
- 6Add ethical, quality or firm-level points: confidentiality, competence, supervision, data security, communication with those charged with governance.
- 7Conclude with a clear recommendation or judgement, using professional scepticism and commercial awareness.
Quickest way: Risk, response, reporting in three lines
When to use it: When time is short and the requirement carries few marks.
- Write one line on the risk and the financial statement area it hits.
- Write two or three specific procedures or approach changes linked to scenario facts.
- Write one line on the effect on the report, communication or ethics, such as disclosure, going concern or confidentiality.
Common mistakes in Emerging Issues: Cyber Risk, Remote Auditing and Other Trends
Writing a general essay on technology with no link to the audit.
Students know the topic as news, not as an audit issue.
Fix: Every point must connect to risk of material misstatement, evidence, reporting or ethics.
Saying the auditor must give assurance on the client's cybersecurity.
Confusing a financial statement audit with a separate assurance engagement.
Fix: State that the audit focuses on financial statement effects and relevant controls. Cyber assurance would be a separate engagement.
Treating remote auditing as lowering the standard of evidence.
Students assume convenience changes requirements.
Fix: Say the ISAs apply unchanged. Explain how you will keep evidence reliable, for example by live video, controlling the documents received and testing the source.
Listing generic procedures not tied to the scenario.
Memorised lists feel safe.
Fix: Use the client's facts: the incident date, the system affected, the affected balances. Markers reward application.
Ignoring the firm's own risks.
Students only think about the client.
Fix: Add points on the firm's data security, confidentiality, staff competence and supervision when working remotely.
Forgetting the reporting consequence.
Focus stays on procedures.
Fix: Ask whether there is a misstatement, missing disclosure, going concern doubt, a key audit matter or a need to inform those charged with governance.
Worked examples
Example 1
Your audit client, an online retailer, suffered a ransomware attack three weeks before its year end. Systems were down for four days and customer data was accessed. Explain the audit implications and the procedures you would perform. (10 marks)
Show the solution
- Risk: the attack may affect revenue completeness and cut-off because systems were down, and may create provisions for fines, compensation and remediation costs.
- Controls: it suggests weaknesses in IT general controls and access. Under ISA 315 reassess risk of material misstatement and consider whether you can rely on system-generated data.
- Laws: customer data loss may breach data protection law. Under ISA 250 consider the possible financial effect and whether non-compliance has occurred.
- Procedures: inspect incident reports and management's investigation. Review legal correspondence and regulator communications. Test sales records for the downtime period against bank receipts and despatch records. Test completeness of provisions and contingent liability disclosure.
- Going concern: assess the effect of lost customers, fines and cash flow. Review forecasts critically.
- Reporting: consider modification if misstatement or inadequate disclosure. Communicate significant control weaknesses to those charged with governance. Consider whether it is a key audit matter.
Answer: The attack raises risks over revenue completeness, provisions, contingent liabilities, going concern and data protection compliance. Reassess risk, test sales and cut-off for the outage, examine legal and regulatory evidence, challenge forecasts, and report any misstatement or disclosure gap, communicating control weaknesses to those charged with governance.
Example 2
Your firm plans to audit a new client's overseas subsidiary remotely because of travel costs. Evaluate the risks and how you would manage them. (8 marks)
Show the solution
- Benefits: lower cost, quicker scheduling, access to specialists. These do not reduce evidence requirements.
- Risk 1, evidence reliability: documents sent by email could be altered. Use secure portals, obtain information directly from systems, and corroborate with external sources.
- Risk 2, inventory and physical assets: you cannot attend a count. Consider live video observation, but it is limited, so use a local auditor or alternative procedures and assess whether evidence is sufficient.
- Risk 3, supervision and review: the team is dispersed. Use frequent video check-ins, shared working papers and timely review by the manager, as ISA 220 and ISQM 1 require.
- Risk 4, fraud and scepticism: less observation of behaviour and culture. Hold interviews by video, and watch for delays and reluctance in providing information.
- Risk 5, confidentiality and security: use encrypted tools and approved devices.
- Conclusion: remote work is acceptable only if sufficient appropriate evidence is obtainable. Otherwise visit in person for key areas.
Answer: Remote working saves cost but increases risks over evidence reliability, inventory observation, supervision, fraud detection and data security. Manage them with secure systems, direct system access, corroboration, video observation backed by local support, regular review, and an on-site visit for areas where remote evidence is inadequate.
Exam tips
- Treat emerging issues as application questions. Use the scenario facts in every paragraph.
- Link each trend to an ISA or ethics point. This shows technical knowledge and earns professional skills marks.
- Include both client risk and firm risk when the scenario involves remote work or data.
- Keep points short and distinct. One idea per sentence, matched to the mark allocation.
- End with a judgement or recommendation, for example whether evidence is sufficient or whether a visit is needed.
Practice questions from Other current issues
- Calder & Moss, an audit firm, uses data analytics software to test 100% of a client's sales ledger entries for unusual posting patterns, rat…
- Vantage Assurance is planning an engagement on Orrin plc's sustainability report, which uses the ISSB's IFRS S2 Climate-related Disclosures …
- Following corporate failures, regulators propose reforms to increase audit quality and reduce concentration in the audit market. Which refor…
- During the audit of Corvus Bank, a firm's cloud service provider suffers an outage and a data breach exposing client files from several audi…
- Halvorsen Audit proposes to provide Meridiane plc, a PIE audit client, with a non-audit service that the Code treats as a permissible one. U…
Emerging Issues: Cyber Risk, Remote Auditing and Other Trends in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Emerging Issues: Cyber Risk, Remote Auditing and Other Trends: frequently asked questions
Is the auditor responsible for the client's cybersecurity?
No. Management and those charged with governance are responsible. The auditor considers how cyber risk affects the financial statements and relevant controls, and reports findings. Separate assurance on cybersecurity would be a different engagement.
Do the ISAs change for remote audits?
No. The requirements on evidence, supervision, review and scepticism apply as normal. What changes is how you meet them, and you must show that remote methods give sufficient appropriate evidence.
How should I answer a current issues question in AAA?
Identify the issue, explain the risk, link it to an ISA, give specific responses based on the scenario, and finish with an ethical or reporting point. Keep your answer matched to the marks available.
Can cyber incidents affect the audit opinion?
Yes, indirectly. If the incident causes a misstatement, inadequate disclosure, or going concern doubt, the auditor may need a modified opinion, a material uncertainty paragraph or a key audit matter.