Integrated Business Solutions (Multidisciplinary Case Study with Strategic Management) · Advanced Auditing, Assurance and Professional Ethics
Assurance, Review and Other Engagements for CA Final
Updated 5 October 2026 · Fact-checked
An assurance engagement is one where a practitioner gives a conclusion that raises the confidence of intended users about a subject matter measured against criteria. It can give reasonable assurance (audit) or limited assurance (review). Solve questions by identifying the engagement type, the five elements, the level of assurance and the form of conclusion.
Understand Assurance, Review and Other Engagements
Start with the idea of assurance. A practitioner examines a subject matter, such as financial statements, controls or sustainability data. The practitioner compares it with suitable criteria and gives a conclusion. That conclusion increases the confidence of the intended users.
A standard assurance engagement has five elements: a three-party relationship (practitioner, responsible party, intended users), an appropriate subject matter, suitable criteria, sufficient appropriate evidence, and a written assurance report. If any element is missing, it is not an assurance engagement. ICAI's Standard on Assurance Engagements (SAE) 3000 deals with assurance engagements other than audits or reviews of historical financial information.
Assurance comes in two levels. Reasonable assurance is high but not absolute. The conclusion is positive, such as 'in our opinion the statements give a true and fair view'. An audit is the main example. Limited assurance is meaningful but lower. The conclusion is negative, such as 'nothing has come to our attention that causes us to believe...'. A review is the main example. Review relies mainly on inquiry and analytical procedures. Audit needs risk assessment, tests of controls and substantive procedures.
Review standards. Two Standards on Review Engagements (SREs) cover reviews of historical financial information:
- SRE 2410 deals with the review of interim financial information performed by the independent auditor of the entity.
- SRE 2400 (Revised) deals with review engagements performed by a practitioner who is not the auditor of the entity.
Both give limited assurance, expressed in negative form.
An engagement can also be assertion-based (attest) or a direct reporting engagement. In an assertion-based engagement, the responsible party measures or evaluates the subject matter against the criteria and makes an assertion about it. The practitioner gathers evidence on that assertion and concludes on it. In a direct reporting engagement, the practitioner measures or evaluates the subject matter against the criteria and reports the result.
Some engagements are not assurance at all. Agreed-upon procedures report factual findings and give no conclusion. Compilation engagements give no assurance either. Users draw their own conclusions from them.
Internal audit is a management function, but the statutory auditor may use it. SA 610 (Using the Work of Internal Auditors) says the external auditor stays solely responsible for the opinion. The auditor must evaluate the internal audit function's objectivity, competence and systematic, disciplined approach. The auditor then decides whether and how far to use the work. IT, data analytics and CAATs let the auditor test whole populations, find exceptions and automate recalculation. In an automated environment the auditor must also understand IT general controls and application controls.
Key rules to remember
- Five elements of assurance
- Three parties + Subject matter + Criteria + Evidence + Assurance report
- Missing any element means the engagement is not assurance. Use this as a checklist in case scenarios. Treat evidence and the written report as separate elements.
- Levels of assurance
- Reasonable assurance → positive conclusion; Limited assurance → negative conclusion
- Audit gives reasonable assurance. Review gives limited assurance. The risk of wrong conclusion is lower in audit.
- SA 610 evaluation factors
- Objectivity + Competence + Systematic and disciplined approach (with quality control)
- All three are evaluated before using internal audit work. Then decide the planned nature and extent of use.
- Responsibility under SA 610
- Opinion responsibility = Statutory auditor alone
- Using internal audit work never reduces this responsibility. SA 610 does not require a reference to it in the report, and the report must not imply that responsibility is reduced.
- Areas of limited use of internal audit
- Higher judgement or risk → less use of internal audit work
- Significant risks, high-judgement areas and areas needing direct evidence call for little or no use.
- Direct assistance from internal auditors
- Not permitted if law or regulation prohibits it, or if there are significant threats to objectivity or insufficient competence; otherwise only after evaluation and with safeguards
- Direct assistance means internal auditors performing audit procedures under the auditor's direction, supervision and review.
How to solve Assurance, Review and Other Engagements questions
Use this sequence for any case or theory question on assurance, review, internal audit or IT audit.
- 1Identify the engagement from the facts: audit, review, assurance on non-financial information, agreed-upon procedures or compilation.
- 2Test it against the five elements. Note any missing element, such as no suitable criteria or no third party.
- 3State the level of assurance and the matching form of conclusion (positive or negative).
- 4For internal audit, apply SA 610: evaluate objectivity, competence and systematic approach, then decide nature and extent of use.
- 5For IT or CAAT facts, name the control type (general or application) and the tool used, and say what evidence it gives.
- 6Apply the rule to the facts and give a clear conclusion. Say who bears responsibility and what must be documented.
- 7Write in provision, facts, conclusion form. Keep each part to one or two lines.
Quickest way: Element-Level-Responsibility scan
When to use it: Use it for MCQs and short case questions when time is under three minutes.
- Ask first: is there a conclusion? If not, it is not assurance (agreed-upon procedures or compilation).
- Check the level: positive wording means reasonable, negative wording means limited.
- For internal audit, ask who owns the opinion. The answer is always the statutory auditor.
- For CAATs, pick the answer that gives wider coverage or exception detection, not the one that replaces judgement.
- Eliminate options that claim absolute assurance or reduced auditor responsibility.
Common mistakes in Assurance, Review and Other Engagements
Saying the auditor can reduce responsibility by relying on internal audit
Students link reliance with sharing the work.
Fix: Write that the auditor alone is responsible for the opinion. Reliance only changes the nature, timing and extent of procedures.
Writing a positive conclusion in a review report
Review and audit report formats are confused.
Fix: A review gives limited assurance and a negative-form conclusion. Do not say 'true and fair view'.
Treating agreed-upon procedures as assurance
The word 'procedures' sounds like audit work.
Fix: Agreed-upon procedures give factual findings and no conclusion. Users draw their own conclusions, so there is no assurance.
Skipping the evaluation step in SA 610
Students jump straight to using the work.
Fix: Always state the three evaluation factors first. Then say whether the work can be used and how far.
Calling CAATs a substitute for auditor judgement
Technology is assumed to give conclusions automatically.
Fix: CAATs and analytics produce evidence and exceptions. The auditor still interprets, follows up and concludes.
Testing only application controls in an automated environment
General controls seem technical and are overlooked.
Fix: Weak IT general controls can make application controls unreliable. Cover access, change management and operations first.
Worked examples
Example 1
Case: Meera & Co. audits Zenith Ltd. Zenith's internal audit team reports to the audit committee. It has qualified staff and a documented methodology with review. Meera plans to use internal audit's work on observation of inventory counts. She also plans to rely on its work on the high-risk, high-judgement valuation of that inventory, and wants to say in her report that she relied on internal audit. Advise.
Show the solution
- Provision: under SA 610 the auditor first evaluates objectivity, competence and a systematic, disciplined approach. Only then does the auditor decide on use of the work.
- Facts: reporting to the audit committee supports objectivity. Qualified staff supports competence. Documented methodology and review support a systematic approach.
- Inventory observation is a different area from inventory valuation. Observation of counts involves less judgement, so Meera may use internal audit's observation work after this evaluation, and she should test some of that work herself.
- Valuation is high risk and needs significant judgement. The more judgement or risk involved, the less the work of internal audit should be used. Meera must perform her own procedures on valuation and not rely on internal audit's work there.
- Reference in the report: the auditor alone is responsible for the opinion. SA 610 does not require a reference to internal audit work in the report, and any wording must not imply reduced responsibility. A reference is unnecessary and risks that implication.
- Conclusion: after evaluation, Meera may use internal audit's inventory observation work. For the valuation she should perform her own procedures. She need not refer to reliance in the report, and must not word it in a way that suggests shared responsibility.
Answer: Evaluate the function first. It appears suitable, so Meera may use its inventory observation work, with her own testing of it. The high-judgement valuation is a different area and needs her own procedures. SA 610 does not require a reference to internal audit in the report, and the report must not imply reduced responsibility.
Example 2
Case: A bank asks CA Rohan to examine its report on greenhouse gas emissions against a published reporting framework. The agreed terms are for a limited assurance conclusion, worded as nothing indicating that the report is misstated. Rohan will use inquiry, analytical procedures and sample checks of records. Classify the engagement and state the key points.
Show the solution
- Identify: the subject matter is non-financial (emissions information). The criteria are a published reporting framework. The parties are the bank, Rohan and the users of the report. This fits SAE 3000 rather than an audit of financial statements.
- Elements: three parties, appropriate subject matter and suitable criteria are present. Evidence will be gathered by the inquiry, analytical procedures and sample checks described. A written assurance report will be issued with the agreed conclusion. All five elements are met.
- Type: the bank prepared the emissions report, so the responsible party has made the assertion and Rohan concludes on it. This is an assertion-based engagement.
- Level: the level of assurance is set by the engagement terms and by the sufficiency of evidence Rohan obtains. Here the terms call for limited assurance, and the evidence from inquiry, analytics and limited checking is the kind that supports it. The negative-form conclusion ('nothing has come to our attention') follows from this level. The wording or the choice of procedures does not by itself fix the level.
- Report: Rohan should state the assurance level clearly and describe the criteria and the work done. He must not use positive wording such as 'fairly stated' for limited assurance.
- Conclusion: this is a limited assurance engagement under the assurance framework.
Answer: It is an assertion-based, limited assurance engagement under SAE 3000 on non-financial information. The level comes from the engagement terms and the evidence obtained, and the negative-form conclusion reflects it. The report should describe the criteria and the procedures performed.
Exam tips
- In case MCQs, look for the missing element or the wording of the conclusion. These decide the engagement type.
- For SA 610 written answers, always list the three evaluation factors and state that the auditor alone is responsible for the opinion.
- When asked to differentiate audit and review, compare level of assurance, procedures, form of conclusion and risk of misstatement in a short table-like list.
- For CAAT questions, name the tool or technique, the control or population tested and the evidence obtained. Add the limitation of dependence on IT general controls.
- In Paper 6, link this topic to other papers. For example, tie internal audit reliance to the audit risk and ethics facts in the case.
Practice questions from Advanced Auditing, Assurance and Professional Ethics
- Case: Kaveri Agro Foods Ltd's FY 2024-25 profit before tax is Rs 12 crore. The management has not provided for a customer claim of Rs 2.5 cr…
- Case: Sagar Pharma Ltd, a listed company, plans to appoint CA Nair's firm as statutory auditor. The firm has been providing internal audit o…
- Case: CA Rohit, the statutory auditor of Deccan Pharma Ltd, discovers that the company's CFO has been inflating revenue through bill-and-hol…
- Case: Kaveri Textiles Ltd, a listed company, has an internal auditor who also prepares its monthly bank reconciliations and supervises the a…
- Case: Deccan Steels Ltd reported revenue of Rs 400 crore and profit before tax of Rs 20 crore. Its auditor sets overall materiality at 5% of…
Assurance, Review and Other Engagements in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Assurance, Review and Other Engagements: frequently asked questions
What is the difference between audit and review engagement?
An audit gives reasonable assurance through risk assessment, tests of controls and substantive procedures. A review gives limited assurance, mainly through inquiry and analytical procedures. The audit conclusion is positive and the review conclusion is negative in form.
Does the auditor have to refer to internal audit work in the audit report?
No. SA 610 does not require a reference to the use of internal audit work. The auditor alone is responsible for the opinion, so the report must not imply that this responsibility is reduced.
What does SAE 3000 cover?
SAE 3000 deals with assurance engagements other than audits or reviews of historical financial information. It sets out the elements of assurance, requirements for acceptance, evidence and reporting. Examples include assurance on controls or non-financial reports.
Why are IT general controls important when using CAATs?
CAATs and automated controls depend on the reliability of the underlying systems. If access, program change or operations controls are weak, the data and application controls may not be reliable. The auditor should therefore assess general controls before relying on automated processing.