CS · Advanced Level
Assurance and Reporting in Context
Applying audit and assurance knowledge to Case Study scenarios. Identifying AUDIT RISKS from scenarios: ROMM (risks of material misstatement) at financial statement level (pervasive) and assertion level (specific to balances/transactions); inherent risk factors (complexity, judgement, estimates, change, susceptibility to fraud); fraud risk factors (incentives/pressures, opportunities, attitudes/rationalisations); significant risks requiring special audit consideration. Recommending AUDIT PROCEDURES tailored to identified risks: substantive vs tests of controls; nature, timing, extent; specific procedures for each material area (revenue, payables, inventory, fixed assets, provisions, going concern, related parties); use of analytical procedures; using experts (ISA 620). EVALUATING GOING CONCERN (ISA 570 Revised): indicators of going concern issues (financial, operational, other); management's assessment; audit procedures; audit reporting implications. FORMING AUDIT OPINIONS (ISA 700/705/706): unmodified vs modified opinions; qualified, adverse, disclaimer; emphasis of matter and other matter paragraphs; key audit matters (KAM under ISA 701). ETHICAL CONSIDERATIONS in practice: independence threats from non-audit services; multiple engagements; familiarity from long association; advocacy in tax disputes; intimidation from management; specific ICAEW Code applications; safeguards. Other assurance services in scenarios: review engagements (ISRE 2400/2410); agreed-upon procedures (ISRS 4400 Revised); compilation engagements (ISRS 4410 Revised); prospective financial information (ISAE 3400); sustainability assurance (ISAE 3000; ISSA 5000 emerging). Communication with TCWG (ISA 260) and management (ISA 265) — significant deficiencies in internal control. Group audits (ISA 600 Revised) — component auditor work; component materiality. Subsequent events (ISA 560), written representations (ISA 580), other information (ISA 720).
Learning Objectives
- •Identify audit risks from Case Study scenarios at financial statement and assertion levels
- •Recognise fraud risk factors (incentives, opportunities, rationalisations)
- •Recommend appropriate audit procedures tailored to identified risks
- •Evaluate going concern using ISA 570 framework
- •Determine appropriate audit opinions and report modifications (ISA 700/705/706)
- •Apply ethical considerations using ICAEW Code in audit context
- •Discuss other assurance services relevant to scenarios
- •Apply group audit considerations (ISA 600 Revised)
Identifying Audit Risks from Scenarios
Audit risk = risk that the auditor expresses an inappropriate opinion when financial statements are materially misstated. AR = ROMM × DR (where ROMM = inherent × control risk; DR = detection risk).
Risks of Material Misstatement (ROMM):
1. Financial statement level risks (pervasive):
- Going concern uncertainty
- Management override of controls
- Complex group structures
- New IT systems/changes
- Industry-wide issues
- Regulatory changes
- Significant judgement areas (impairment, fair values)
- First-time engagement
2. Assertion level risks (specific):
Risks specific to balances, transaction classes, disclosures. Per ISA 315 (Revised 2019), assertions:
- For TRANSACTIONS: occurrence, completeness, accuracy, cut-off, classification, presentation
- For BALANCES: existence, rights and obligations, completeness, accuracy/valuation/allocation, classification, presentation
Inherent risk factors (ISA 315 Revised):
- COMPLEXITY: complex transactions, calculations, regulations
- SUBJECTIVITY: estimates, judgements, fair values
- CHANGE: new systems, new business, regulatory change, market disruption
- UNCERTAINTY: forecasts, environment, outcomes
- SUSCEPTIBILITY TO FRAUD/MANAGEMENT BIAS: incentives, opportunities
Significant risks (ISA 315 Revised):
- Risks requiring SPECIAL AUDIT CONSIDERATION
- Higher in inherent risk spectrum
- Examples: revenue recognition (always significant if not rebutted); related party transactions; non-routine transactions; significant accounting estimates
- Per ISA 240: revenue recognition is always a significant fraud risk unless rebutted
- Per ISA 240: management override is always a significant risk
FRAUD RISK FACTORS (ISA 240 — fraud triangle):
1. INCENTIVES/PRESSURES:
- Financial pressures (debt covenants; loss of capital; bonus targets)
- Management compensation tied heavily to results
- Personal financial obligations of management
- Industry pressures (declining margins; competitive threats)
- Pressure to meet analyst expectations
- Loan covenants at risk
- Initial public offering or going concern threats
2. OPPORTUNITIES:
- Weak internal controls
- Complex/unusual transactions
- Estimates/judgements
- Single-person dominance
- Inadequate oversight by TCWG
- Difficulty in testing transactions
- Inadequate IT general controls
- Related party transactions
3. ATTITUDES/RATIONALISATIONS:
- Aggressive accounting policies
- Disregard for ethics or controls
- History of regulatory issues
- Strained relationships with auditors
- "Everyone does it" attitude
Identifying audit risks from Case Study scenarios:
Scan the scenario for risk indicators. Common scenario triggers:
| Scenario indicator | Likely audit risk |
|---|---|
| Aggressive growth targets | Revenue recognition; cut-off; existence |
| Management bonus tied to results | Earnings management; management override |
| New IT system implementation | Data integrity; controls effectiveness |
| Acquisition during year | Goodwill; consolidation; related parties |
| Going concern indicators | Going concern; impairment; provisions |
| Loss-making contract | Onerous contracts (IAS 37); revenue |
| Related party transactions | Disclosure; arm's length pricing |
| Litigation/regulatory issues | Provisions; contingent liabilities |
| Foreign operations | Translation; transfer pricing; FX |
| Complex financial instruments | Valuation; classification; hedging |
| Restructuring announced | Provisions (IAS 37); impairment |
| Inventory build-up | NRV; obsolescence; existence |
| Receivables aging extending | Recoverability; revenue cut-off |
| Capitalisation increasing | Recognition criteria; useful lives |
| Pension scheme deficit | Actuarial assumptions; disclosure |
| Tax structure change | Deferred tax; uncertain tax positions |
| Going public / IPO planned | Earnings management; window dressing |
| Whistleblower allegations | Fraud; controls; disclosure |
Structuring audit risk identification in Case Study answers:
For each identified risk:
- STATE THE RISK with reference to specific scenario fact
- EXPLAIN THE ASSERTION at risk (if assertion-level)
- EXPLAIN WHY this is a risk (judgement, complexity, fraud incentive, etc.)
- NOTE MATERIALITY if relevant
- LINK to procedure (covered in next section)
Example structure:
"Revenue recognition risk: ManufactureCo's sales targets have increased 30% YoY (Exhibit 2) creating PRESSURE on management. The internal email (Exhibit 3) suggests ACCELERATED revenue recognition. There is risk of OCCURRENCE and CUT-OFF assertions failing — revenue may have been recognised before performance obligations satisfied (IFRS 15). Given materiality of revenue (£500m) and management override risk per ISA 240, this is a SIGNIFICANT RISK requiring special audit consideration."
Specific application better than generic risk listing.
Don't miss:
- Always include MANAGEMENT OVERRIDE (ISA 240 — significant risk presumed)
- Always consider REVENUE RECOGNITION (ISA 240 — significant fraud risk unless rebutted)
- Always consider GOING CONCERN if any indicators
- Always consider RELATED PARTIES if mentioned
- Always consider GROUP RISKS if subsidiaries
Pervasive scenario factors increasing overall risk:
- First-year audit (no prior knowledge)
- Complex group structures
- Multiple jurisdictions
- Significant changes in business
- High-risk industry (tech, financial services, pharma)
- Significant management changes
- Regulatory scrutiny / investigations
- Stretched audit team or budget
Recommending Audit Procedures
Audit procedures are the work performed to obtain audit evidence. Must be RESPONSIVE to identified risks (ISA 330).
Types of audit procedures (ISA 500):
- Inspection — examining records, documents, assets
- Observation — watching procedures performed
- Inquiry — questioning management/others
- Confirmation — independent verification (e.g., bank, customer, supplier confirmations)
- Recalculation — checking arithmetic
- Reperformance — independently performing procedures
- Analytical procedures — comparing, ratio analysis, trend analysis
Substantive procedures vs Tests of controls:
| Substantive procedures | Tests of controls | |
|---|---|---|
| Purpose | Detect material misstatements | Test control operating effectiveness |
| Required | For all material balances/transactions | Only if relying on controls |
| Types | Tests of detail; substantive analytical procedures | Inquiry + observation + inspection + reperformance |
| Sample size driver | Materiality; risk; reliance on other evidence | Risk assessment; control population |
Audit response framework (NTE — Nature, Timing, Extent):
- NATURE: WHAT procedure (inspection, confirmation, recalculation, etc.)
- TIMING: WHEN performed (year-end vs interim; close to year-end if higher risk)
- EXTENT: HOW MUCH (sample size; coverage)
Higher risk → more extensive, less predictable procedures, closer to year-end.
Specific procedures by material area:
1. REVENUE:
- Test revenue recognition policy against IFRS 15
- Cut-off testing (sales recorded in correct period)
- Sample sales transactions: trace to delivery, customer order, invoice
- Analytical: gross margin trends, comparison to budget
- Confirm balances with major customers
- Test journal entries to revenue (especially manual)
- Review credit notes after year-end (sales returns)
- Consider revenue recognition timing for complex contracts
2. RECEIVABLES:
- External confirmations (positive or negative)
- Aged trial balance review
- Subsequent receipts after year-end
- Bad debt provision adequacy
- Disputes review
- IFRS 9 expected credit loss model application
3. INVENTORY:
- Inventory count attendance (physical observation)
- Cut-off testing
- NRV testing (slow-moving, obsolete, damaged)
- Cost vs NRV (IAS 2)
- Subsequent sales prices (NRV evidence)
- Cost flow assumptions (FIFO, weighted average)
- Production cost analysis
4. PAYABLES:
- Search for unrecorded liabilities (especially completeness)
- Subsequent payments review
- Supplier confirmations (less common than for receivables)
- Cut-off testing
- Reconcile to supplier statements
- Accrued liabilities review
5. PROPERTY, PLANT, EQUIPMENT:
- Existence: physical verification of additions
- Authorisation of capex
- Depreciation policy and calculation
- Impairment indicators (IAS 36)
- Disposals: ensure removed from register
- Capitalisation criteria (capex vs revenue)
- Revaluation if applicable
6. PROVISIONS / CONTINGENCIES (IAS 37):
- Discuss with management; legal counsel correspondence
- Recognition criteria: present obligation, probable outflow, reliable estimate
- Calculation review (assumptions; discount rates)
- Disclosure adequacy
- Subsequent events review
7. GOING CONCERN:
- Cash flow forecasts review
- Covenant compliance
- Subsequent events
- Reasonableness of assumptions
- Sensitivity analysis
- Letters of support (parent guarantees)
- Bank facility availability
- Management plans
8. RELATED PARTIES:
- Identify related parties (ISA 550)
- Review board minutes for transactions
- Inquire of management about transactions
- Substantively test transactions
- Test arm's length pricing
- Disclosure adequacy (IAS 24)
9. ESTIMATES (ISA 540 Revised):
- Understand methodology
- Test assumptions for reasonableness
- Test data inputs
- Develop independent point estimate / range
- Compare to management estimate
- Consider management bias indicators
- Greater scepticism for high-risk estimates
10. JOURNAL ENTRIES (ISA 240 — management override):
- Identify and test journal entries
- Focus on: manual entries; entries close to period-end; non-standard entries; entries by senior management; entries to revenue or unusual accounts
- Use of computer-assisted audit techniques (CAATs)
USE OF EXPERTS (ISA 620):
- For specialised areas: valuations, actuarial, environmental, IT, legal
- Common in Case Study: pension valuations; impairment; complex financial instruments
- Procedures:
- Evaluate expert's competence and objectivity
- Understand expert's work
- Evaluate appropriateness of expert's work as audit evidence
- Apply professional scepticism to expert's conclusions
ANALYTICAL PROCEDURES (ISA 520):
- Substantive analytical procedures (ratios, trends)
- Final analytical procedures (overall reasonableness)
- Most powerful when:
- Predictable relationships
- Reliable data
- Low inherent risk area
- Significant volume
- Less reliance for high-risk areas
Structuring procedure recommendations in Case Study answers:
For each identified risk, recommend SPECIFIC procedures:
- State the procedure precisely
- State the assertion tested
- State why (links to risk identified)
- Note timing/extent if relevant
Example:
"To address revenue cut-off risk: select a sample of sales transactions recorded in the last 7 days of the year and the first 7 days after year-end. Trace each to delivery documentation. Confirm goods delivered before year-end for sales recorded pre-year-end (occurrence/cut-off). For post-year-end sales, ensure not recorded in current year. Sample size 30-50 transactions given materiality and significant risk classification."
Going Concern Evaluation (ISA 570 Revised)
Going concern assumes the entity will continue in operational existence for the foreseeable future (at least 12 months from approval of financial statements per IAS 1).
ISA 570 (Revised):
- Issued post-Carillion to strengthen going concern audit work
- Effective for periods beginning on/after 15 December 2019
- Enhanced scepticism requirements
- Stand-back review
- More extensive reporting
INDICATORS of going concern issues:
1. FINANCIAL indicators:
- Net liability or net current liability position
- Borrowing facilities at maturity without realistic refinancing prospects
- Adverse key financial ratios
- Substantial operating losses or significant deterioration
- Inability to pay creditors on due dates
- Inability to comply with terms of loan agreements
- Change from credit to cash-on-delivery transactions with suppliers
- Inability to obtain financing for essential investment or development
- Substantial sale of operating assets
2. OPERATING indicators:
- Management intentions to liquidate or cease operations
- Loss of key management without replacement
- Loss of major market, key customer(s), franchise, license, or principal supplier(s)
- Labour difficulties
- Shortages of important supplies
- Emergence of highly successful competitor
3. OTHER indicators:
- Non-compliance with capital or other statutory requirements
- Pending legal or regulatory proceedings against the entity that may, if successful, result in claims that the entity is unlikely to be able to satisfy
- Changes in law or regulation or government policy expected to adversely affect the entity
- Uninsured or underinsured catastrophes when they occur
Audit work on going concern:
1. Risk assessment:
- Consider going concern at PLANNING stage
- Identify events/conditions that may cast doubt
- Discuss with management
2. Evaluate management's assessment:
- Did management make assessment? (required by IAS 1)
- Period of assessment (minimum 12 months from approval)
- If management hasn't made assessment, ASK them to
- Evaluate methodology and assumptions
3. Audit procedures on management's assessment:
- Cash flow forecast review
- Reconcile to budgets and historical performance
- Test assumptions (revenue, costs, capex)
- Stress test forecasts (sensitivity analysis)
- Consider downside scenarios
- Covenant compliance projections
- Available financing facilities
- Subsequent events
- Other audit evidence (e.g., post year-end results)
4. Considering management plans:
- Are plans reasonable and feasible?
- Have actions been initiated?
- Likelihood of success
- Past track record on similar plans
5. Evaluate disclosures:
- Material uncertainty disclosure (IAS 1)
- Description of conditions and events
- Management's evaluation
- Plans
Audit conclusions on going concern:
Outcome 1: No material uncertainty exists
- Going concern basis appropriate; no material uncertainty
- Standard unmodified opinion
- If indicators existed but mitigated by appropriate plans: include in KAM if PIE
Outcome 2: Material uncertainty exists, ADEQUATELY DISCLOSED
- Going concern basis still appropriate
- Material uncertainty disclosed
- Audit report includes "Material Uncertainty Related to Going Concern" section
- Refers to financial statement disclosure
- Opinion still UNMODIFIED on this point (assuming everything else clean)
Outcome 3: Material uncertainty exists, INADEQUATE DISCLOSURE
- QUALIFIED OPINION (or adverse if pervasive)
- Specifically on disclosure inadequacy
Outcome 4: Going concern basis INAPPROPRIATE but used
- Financial statements should be prepared on alternative basis (typically break-up basis)
- If still prepared on going concern: ADVERSE OPINION
Outcome 5: Going concern basis INAPPROPRIATE and alternative used (e.g., break-up basis):
- Unmodified opinion possible
- Emphasis of matter paragraph likely to draw attention to basis
UK Corporate Governance Code requirements:
- Premium-listed companies: GOING CONCERN STATEMENT (12-month period from approval)
- VIABILITY STATEMENT (longer period — typically 3-5 years)
- Both reported on by auditors
Carillion lessons:
- 2018 collapse exposed weaknesses in going concern audit
- Aggressive accounting masked deteriorating position
- Strengthened ISA 570 Revised followed
- Increased scepticism required
- Documentation requirements enhanced
- Separate auditor commentary on going concern in some reports
Going concern in Case Study:
If scenario presents going concern indicators:
- IDENTIFY all indicators systematically (financial, operating, other)
- Note INTERCONNECTIONS between indicators
- Apply professional SCEPTICISM to management forecasts
- Consider both INDICATORS and MITIGANTS
- Reach REASONED CONCLUSION (uncertainty exists vs. doesn't)
- Recommend appropriate audit RESPONSE
- Identify REPORTING IMPLICATIONS
- Don't shy away — going concern issues require explicit treatment
Example structure:
"Going concern indicators in the scenario include:
1. Net current liability position of £15m at year-end (financial)
2. Loan covenant breach risk (financial) — interest cover declined to 1.8x vs covenant 2.0x
3. Loss of major customer representing 25% of revenue (operating)
4. Pending HMRC investigation potentially £30m (other)
These indicators COLLECTIVELY raise material uncertainty about going concern. Management forecasts assume covenant waiver and customer replacement — these assumptions require careful audit scrutiny.
Audit procedures should include: stress testing forecasts; obtaining bank confirmation on covenant treatment; reviewing post year-end actual performance vs budget; considering subsequent events; evaluating management plans for customer replacement.
Audit reporting: if material uncertainty exists and is adequately disclosed, include 'Material Uncertainty Related to Going Concern' section in audit report referring to financial statement disclosure. Opinion remains unmodified on this point but report draws attention. If disclosure inadequate, qualified opinion required."
Forming Audit Opinions (ISA 700/705/706/701)
The auditor's opinion is the formal output of the audit. ISAs 700/705/706 govern reporting; ISA 701 covers Key Audit Matters.
ISA 700 (Revised) — Forming an opinion:
- Conclude whether financial statements give true and fair view (or present fairly)
- Based on:
- Sufficient appropriate audit evidence obtained
- Uncorrected misstatements
- Going concern assessment
- Overall presentation and disclosure
UNMODIFIED OPINION:
- Standard "clean" opinion
- "In our opinion, the financial statements give a true and fair view..."
- Required when financial statements are properly prepared and free from material misstatement
MODIFIED OPINIONS (ISA 705 Revised):
Modifications arise from:
- FINANCIAL STATEMENTS ARE MATERIALLY MISSTATED, OR
- UNABLE TO OBTAIN SUFFICIENT APPROPRIATE AUDIT EVIDENCE (limitation of scope)
The MATERIALITY and PERVASIVENESS determine type of modification:
| Material but NOT pervasive | Material AND pervasive | |
|---|---|---|
| Financial statements materially misstated | QUALIFIED OPINION ("except for") | ADVERSE OPINION |
| Unable to obtain sufficient appropriate audit evidence | QUALIFIED OPINION ("except for") | DISCLAIMER OF OPINION |
"Pervasive" means:
- Not confined to specific elements/accounts
- If confined: represent or could represent substantial proportion of financial statements
- For disclosures: fundamental to users' understanding of financial statements
1. QUALIFIED OPINION:
- "Except for" the matter described
- Financial statements present fairly except for specific issue
- Material but limited in impact
- Used for both misstatement and scope limitation
Example wording:
"In our opinion, except for the effects of the matter described in the Basis for Qualified Opinion section of our report, the financial statements give a true and fair view..."
2. ADVERSE OPINION:
- Financial statements DO NOT give true and fair view
- Material AND pervasive misstatement
- Most severe negative opinion
- Rare in practice
Example wording:
"In our opinion, because of the significance of the matter discussed in the Basis for Adverse Opinion section, the financial statements do not give a true and fair view..."
3. DISCLAIMER OF OPINION:
- Cannot form an opinion
- Material AND pervasive scope limitation
- "We do not express an opinion"
- Even rarer than adverse
Example wording:
"We do not express an opinion on the accompanying financial statements because of the significance of the matter described in the Basis for Disclaimer of Opinion section."
EMPHASIS OF MATTER (ISA 706 Revised):
- Draws attention to matter PROPERLY presented or disclosed
- Not a modification of opinion
- Examples:
- Going concern with adequate disclosure
- Subsequent event after report date
- Effects of major catastrophe
- Early adoption of new standard
- Heading: "Emphasis of Matter"
- Reference to disclosure
- Statement that opinion not modified
OTHER MATTER (ISA 706 Revised):
- Matter relevant to UNDERSTANDING the audit, the auditor's responsibilities, or the auditor's report
- Not a modification of opinion
- Example: comparative financial statements audited by different auditor
Material Uncertainty Related to Going Concern (separate section per ISA 570 Revised):
- Distinct from emphasis of matter (specific section)
- When material uncertainty exists and is adequately disclosed
- Does not modify opinion
- Refers to disclosure
KEY AUDIT MATTERS (ISA 701):
- Required for LISTED ENTITIES (and others where required)
- Most significant matters in audit of current period
- From matters communicated with TCWG
- Description of why each matter was significant
- Description of how matter was addressed in audit
- NOT a modification of opinion
- Provides users with insight into significant areas of judgement
Common KAMs:
- Revenue recognition (especially complex contracts)
- Goodwill and intangibles impairment
- Provisions and contingencies
- Pension obligations
- Going concern (when material uncertainty)
- Acquisitions (PPA, valuation)
- IT systems and controls
- Tax matters (uncertain positions)
Audit report structure (ISA 700 Revised — common standard format):
- Opinion (paragraph)
- Basis for opinion
- Material Uncertainty Related to Going Concern (if applicable)
- Key Audit Matters (for listed)
- Other Information (ISA 720)
- Responsibilities of management
- Auditor's responsibilities
- Report on other legal/regulatory requirements
- Other reporting responsibilities
- Engagement partner name (UK PIE)
- Auditor's signature, address, date
Determining the appropriate opinion in Case Study scenarios:
Decision framework:
- Is there a material misstatement OR scope limitation?
- If YES: Is it MATERIAL?
- If MATERIAL: Is it PERVASIVE?
- Apply matrix:
- Material misstatement, not pervasive → QUALIFIED ("except for")
- Material misstatement, pervasive → ADVERSE
- Scope limitation, not pervasive → QUALIFIED ("except for")
- Scope limitation, pervasive → DISCLAIMER
- Consider also: emphasis of matter, KAM, going concern reporting
Common Case Study scenarios requiring opinion judgement:
- Refusal to recognise impairment → likely qualified or adverse depending on materiality
- Going concern with disclosure → unmodified with material uncertainty section
- Going concern without disclosure → qualified or adverse
- Cannot attend inventory count + cannot use alternative procedures → qualified scope limitation
- Cannot obtain confirmation from major customer + significant balance → likely qualified
- Disagreement on revenue recognition policy → qualified or adverse
- Inadequate disclosure of contingent liabilities → qualified
- Group audit without sufficient component evidence → potentially disclaimer
Exam approach — opinion analysis:
- Identify the issue (misstatement vs scope limitation)
- Assess materiality (quantitative and qualitative)
- Assess pervasiveness
- Determine type of modification
- Recommend appropriate report wording approach
- Consider any additional reporting (KAM; emphasis of matter; etc.)
- Consider implications (e.g., loss of public listing; covenant impact)
Ethical Considerations in Audit Practice
Audit ethics centre on INDEPENDENCE — being independent in mind and appearance. ICAEW Code applies; APB Ethical Standard for UK auditors.
Five fundamental principles (ICAEW Code):
- Integrity
- Objectivity
- Professional Competence and Due Care
- Confidentiality
- Professional Behaviour
Five threat categories:
1. SELF-INTEREST:
- Direct or indirect financial interest in client
- Significant fees from client (e.g., > 15% of total firm fees)
- Loans from client
- Close business relationships
- Family member working at client
- Audit and non-audit fees combined
2. SELF-REVIEW:
- Auditing own firm's work (e.g., bookkeeping for audit client)
- Reviewing own previous work
- Financial statements prepared by audit firm
- System implementation by audit firm
3. ADVOCACY:
- Promoting client's position
- Acting as advocate in tax dispute or litigation
- Promoting client's shares
- Significant role in client's public statements
4. FAMILIARITY:
- Long association with audit client
- Close personal relationship with client management
- Audit partner rotation requirements
- Cooling-off periods
- Senior staff joining audit client
5. INTIMIDATION:
- Threats from client management
- Threats of litigation
- Threats to remove from engagement
- Pressure on audit fees
- Aggressive client behaviour
SAFEGUARDS:
1. Created by profession/regulation:
- Education and training requirements
- Continuing professional development
- Quality control standards (ISQM 1, ISQM 2)
- Ethical standards (ICAEW Code, APB Ethical Standard)
- Regulatory inspection
2. Created by employer (firm-level):
- Independence policies
- Quality management systems (ISQM 1)
- Engagement quality reviews
- Tracking of relationships and fees
- Firm-wide training
3. Created in engagement:
- Engagement quality reviewer (EQR)
- Specialist consultation
- Different staff for different services
- Disclosure of relationships
- Withdrawal from engagement if needed
SPECIFIC AUDIT INDEPENDENCE RULES (UK):
1. Fee dependency:
- If fees from client > 15% of total firm fees: SIGNIFICANT THREAT
- For PIEs: > 15% triggers specific actions (additional procedures, reviewer)
- If > 15% for two consecutive years: must consider whether to continue
- UK Audit Reform: tighter restrictions for PIEs
2. Non-audit services:
- For PIEs: 70% cap on non-audit services as % of audit fee (averaged 3 years)
- Certain non-audit services PROHIBITED for PIEs:
- Bookkeeping
- Internal audit (relating to financial reporting)
- HR services for senior management
- Legal services
- Promoter or investment banking services
- Recruitment for senior management
- Tax services in certain circumstances
- FRC has tightened progressively
3. Audit partner rotation:
- For PIEs in UK: 5 years on; 5 years off (key audit partners)
- Engagement partner rotation
- Quality reviewer rotation
4. Audit firm rotation (UK PIEs):
- Mandatory audit firm rotation for PIEs every 10 years (with possibility of 10-year extension if tendered)
- Maximum 20 years total
5. Provision of services to audit client:
- Detailed restrictions in APB Ethical Standard
- FRC Audit Reform proposals further restrict
Common ethical scenarios in Case Study:
Scenario 1: Audit client offers attractive consultancy work
- Threats: self-interest (revenue); self-review (if related to audit area)
- Considerations: nature of work; PIE restrictions; APB ES
- Safeguards: separate teams; engagement quality review; disclosure
- Or: decline if prohibited
Scenario 2: Senior auditor offered position with client
- Threats: self-interest; intimidation (during job discussions)
- Considerations: cooling-off period required
- Safeguards: remove auditor from engagement; review work performed
Scenario 3: Client pressure on accounting treatment
- Threats: intimidation; self-interest (if fees at stake)
- Application: challenge management; consult firm technical; document
- Outcome: if material misstatement, modify opinion
Scenario 4: Audit firm provides bookkeeping for non-PIE client
- Threats: self-review
- Considerations: not prohibited for non-PIE; safeguards needed
- Safeguards: separate teams; engagement quality review; client management responsibility
Scenario 5: Long association with audit client (10+ years)
- Threats: familiarity
- Considerations: partner rotation rules (PIE 5 years); firm rotation (PIE 10/20 years)
- Safeguards: rotation; engagement quality review; staff changes
Scenario 6: NOCLAR situation (Section 360 ICAEW Code)
- Auditor identifies non-compliance with laws/regulations
- Steps: discuss with management/TCWG; encourage rectification
- If response inadequate: consider professional duties
- Disclosure to authority (e.g., money laundering)
- Consider withdrawal from engagement
- Document throughout
Scenario 7: Whistleblower allegations from within audit team
- UK PIDA 1998 protections
- Internal escalation: engagement quality reviewer; firm ethics partner
- External: appropriate authority depending on issue
- FRC for audit-specific issues
- Document properly
Conceptual framework approach for ethical analysis in Case Study:
- Identify ETHICAL ISSUES in scenario
- Identify THREATS to fundamental principles (5 categories)
- Evaluate SIGNIFICANCE of threats (qualitative + quantitative factors)
- Apply SAFEGUARDS to reduce to acceptable level
- Profession/regulation safeguards
- Firm-level safeguards
- Engagement-level safeguards
- If significance not reduced: decline or withdraw from engagement
- Document reasoning and conclusions
Communication with TCWG (ISA 260):
- Audit responsibilities; planned scope/timing; significant findings
- Auditor independence (PIEs)
- Material weaknesses in internal control
- Difficulties encountered
- Disagreements with management
- Significant matters discussed with management
Communication of internal control deficiencies (ISA 265):
- Significant deficiencies — written communication to TCWG
- Other deficiencies — communicate to management
- Distinguishes Significant deficiencies from Material weaknesses
- UK Material Controls Declaration (UK CGC 2024 effective 2026) creates new context
Other Assurance and Related Services
Beyond statutory audit, chartered accountants provide various assurance and related services. Case Study scenarios may include these.
Assurance engagement framework (IAASB):
Five elements of assurance engagement:
- Three-party relationship (practitioner, responsible party, intended user)
- Subject matter (e.g., financial statements; sustainability info; controls)
- Suitable criteria (e.g., IFRS; ISSB standards)
- Sufficient appropriate evidence
- Written assurance report
Levels of assurance:
- REASONABLE ASSURANCE: high but not absolute — "in our opinion" — used for audits and similar
- LIMITED ASSURANCE: less than reasonable — "nothing has come to our attention" — used for reviews
Reasonable assurance involves:
- Risk assessment
- Substantive procedures and tests of controls (where appropriate)
- Sufficient appropriate evidence
- Higher procedures than limited assurance
Limited assurance involves:
- Less work than reasonable assurance
- Primarily inquiry and analytical procedures
- Limited substantive testing
- Negative form of conclusion
1. REVIEW ENGAGEMENTS:
ISRE 2400 (Revised) — Engagements to review historical financial statements:
- Limited assurance
- For non-public entities (often)
- Inquiry and analytical procedures primarily
- Less than audit but more than compilation
- Conclusion: "nothing has come to our attention..."
ISRE 2410 — Review of interim financial information performed by auditor:
- For interim financial statements (e.g., half-year)
- Required for some listed entities
- Performed by entity's independent auditor
- Limited assurance
- UK premium-listed half-year results often reviewed
2. AGREED-UPON PROCEDURES:
ISRS 4400 (Revised) — Agreed-upon procedures engagements:
- NOT an assurance engagement
- Practitioner performs SPECIFIC procedures agreed with client
- Reports findings only — no conclusion or opinion
- Recipients draw own conclusions
- Common uses: due diligence; specific bank requirements; regulatory submissions
3. COMPILATION ENGAGEMENTS:
ISRS 4410 (Revised) — Compilation engagements:
- Practitioner ASSISTS in preparing financial information
- NO assurance provided
- Practitioner uses accounting expertise to compile
- Common for small entities not requiring audit
- Compilation report describes engagement, no conclusion
4. PROSPECTIVE FINANCIAL INFORMATION:
ISAE 3400 — Examination of prospective financial information:
- Forecasts or projections (different from historical)
- Common in: prospectus reporting; loan applications; planning
- Examines: assumptions; preparation; presentation
- Limited assurance on whether assumptions reasonable + preparation appropriate
- NO assurance that future will match forecast
5. SUSTAINABILITY / ESG ASSURANCE:
Increasingly important — covered in CR sustainability topics. Case Study likely to include sustainability assurance considerations.
Standards:
- ISAE 3000 (Revised) — Assurance engagements other than audits/reviews of historical financial info (general standard for sustainability)
- ISSA 5000 (proposed) — General requirements for sustainability assurance
- ISAE 3410 — Greenhouse gas statements specifically
- EU CSRD requires limited then reasonable assurance progressively
Considerations:
- Subject matter often qualitative (less precise than financial)
- Multiple frameworks (ISSB, ESRS, GRI, TCFD)
- Materiality concept different (especially CSRD double materiality)
- Specialist skills required (climate, biodiversity, supply chain, social)
- Big Four firms scaling sustainability assurance practices
- Independence considerations as for audit
6. DUE DILIGENCE:
- Pre-acquisition investigation
- Often AGREED-UPON PROCEDURES (ISRS 4400) format
- Areas: financial; commercial; legal; tax; operational; IT; HR; environmental
- Vendor DD vs buyer DD
- NOT typically assurance engagement
- Specialist work (transactions services / corporate finance)
7. INTERNAL AUDIT:
- Independent assurance and consulting
- Reports to AUDIT COMMITTEE (third line model)
- Risk-based annual plan
- IIA International Standards
- NOT a substitute for external audit
- External auditor may use internal audit work (ISA 610)
8. FORENSIC AND INVESTIGATIVE:
- Fraud investigations
- Litigation support
- Regulatory investigations
- Anti-money laundering reviews
- Asset tracing
- Specialist skill area
9. CONTROLS REPORTING:
- SOC reports (SSAE 18 / ISAE 3402) for service organisations
- Type 1 (design); Type 2 (operating effectiveness)
- UK Material Controls Declaration (effective 2026) — emerging area
10. REGULATORY REPORTING:
- FCA reporting for financial services firms
- Solvency II reporting (insurance)
- Capital regulatory reports (banks)
- Specific industry reporting
Other assurance services in Case Study scenarios:
Common scenarios:
- Loan covenant compliance reporting
- Royalty audits
- Government grant compliance
- Service charge accounts (property)
- Charity reporting
- Pension scheme audit/review
- Solicitor account audits
Approach to other assurance services in Case Study:
- Identify specific service requested
- Match to applicable standard (ISRE, ISRS, ISAE)
- Determine level of assurance (reasonable, limited, none)
- Identify key procedures
- Consider independence and ethical issues
- Consider acceptance of engagement (resources, competence)
- Identify reporting format and conclusion
Group audits (ISA 600 Revised — effective from 2024):
- Updated for greater group engagement partner involvement
- Identify components (subsidiaries, branches, joint operations)
- Significant components vs non-significant
- Component materiality (lower than group)
- Group engagement partner responsibilities
- Communication with component auditors
- Direction and supervision of component auditor work
- Documentation requirements
- Common in Case Study scenarios with international subsidiaries
Examiner Focus
Common Pitfall
Study Tip
Examiner Focus
Watch Out
Study Tip
Study Tip
Written Practice
Assurance and Reporting in Context: Applied Requirement
Prepare a short advisory section that combines analysis, conclusion, and next actions.
A client has asked for a concise integrated advisory note for a finance director on assurance and reporting in context. Use the key rules, calculations, risks, and professional judgement from this topic to structure your answer.
Answer Prompts
- •Identify the issue and explain why it matters in the scenario.
- •Apply the relevant technical rule, calculation, or framework.
- •State the commercial, ethical, tax, reporting, or assurance implication.
- •Conclude with a clear recommendation or exam-ready judgement.
Marking Focus
- Application to facts rather than textbook recall
- Clear structure and answer-first communication
- Balanced judgement where there is uncertainty
- Commercially sensible conclusion
Key Definitions
Audit risk model
AR = ROMM × DR. ROMM (Risk of Material Misstatement) = Inherent Risk × Control Risk. DR (Detection Risk) — auditor controls. Lower acceptable AR for higher risk audits. Audit response targets ROMM to keep DR at acceptable level.
Significant risks (ISA 315 Revised)
Risks requiring SPECIAL AUDIT CONSIDERATION; higher in inherent risk spectrum. Examples: revenue recognition (always significant fraud risk unless rebutted per ISA 240); related party transactions; non-routine transactions; significant accounting estimates. Management override is always a significant risk.
Fraud triangle (ISA 240)
Three conditions for fraud: INCENTIVES/PRESSURES (financial pressures, bonus targets, covenants); OPPORTUNITIES (weak controls, complex transactions, single-person dominance); ATTITUDES/RATIONALISATIONS (aggressive accounting, disregard for controls, "everyone does it"). Identify all three when assessing fraud risk.
NTE framework (ISA 330)
Audit response framework: NATURE (what procedure — inspection, confirmation, etc.); TIMING (when — year-end vs interim); EXTENT (how much — sample size, coverage). Higher risk = more extensive, less predictable procedures, closer to year-end.
ISA 570 (Revised) Going Concern
Strengthened post-Carillion. Three categories of indicators: FINANCIAL (net liabilities, covenants, ratios); OPERATING (key people loss, market loss, supplies); OTHER (statutory non-compliance, litigation). Five outcomes: no material uncertainty / material uncertainty disclosed / material uncertainty inadequately disclosed / inappropriate basis used / inappropriate basis with alternative used.
Audit opinion modifications (ISA 705)
Two grounds: (1) FINANCIAL STATEMENTS MATERIALLY MISSTATED; (2) UNABLE TO OBTAIN SUFFICIENT APPROPRIATE AUDIT EVIDENCE. Three modification types based on materiality + pervasiveness: QUALIFIED ("except for" — material not pervasive); ADVERSE (material misstatement, pervasive); DISCLAIMER (scope limitation, pervasive).
Pervasive (ISA 705)
Effects: (a) not confined to specific elements/accounts; OR (b) if confined, represent or could represent substantial proportion of financial statements; OR (c) for disclosures, fundamental to users' understanding. Determines whether modification escalates to adverse/disclaimer rather than qualified.
Emphasis of Matter (ISA 706)
Draws attention to matter PROPERLY presented or disclosed. NOT a modification of opinion. Examples: going concern with adequate disclosure (now separate "Material Uncertainty" section); subsequent event after report date; effects of major catastrophe; early adoption of new standard.
Key Audit Matters (ISA 701)
Required for LISTED ENTITIES. Most significant matters in audit of current period from those communicated with TCWG. Description of why each was significant + how addressed in audit. NOT modification of opinion. Provides users insight into significant judgement areas. Common KAMs: revenue recognition, goodwill impairment, provisions, going concern.
ICAEW threats categories
Five threat categories: SELF-INTEREST (financial interest, fees); SELF-REVIEW (auditing own work); ADVOCACY (promoting client position); FAMILIARITY (long association, close relationships); INTIMIDATION (client threats, pressure). Apply conceptual framework: identify → evaluate → safeguard → if not reduced, decline/withdraw.
Audit firm rotation (UK PIEs)
Mandatory rotation every 10 years (or 20 with tender). Audit partner rotation: 5 years on, 5 years off for key audit partners (PIEs). Engagement quality reviewer rotation. Designed to address familiarity threat and competition.
Non-audit services restrictions (UK PIEs)
70% cap on non-audit fees as % of audit fee (3-year rolling average). Certain services PROHIBITED: bookkeeping; HR/recruitment for senior management; legal services; promoter/investment banking; tax services in certain circumstances. FRC progressively tightening.
NOCLAR (Section 360 ICAEW Code)
Non-Compliance with Laws and Regulations. Auditor identifying non-compliance: discuss with management/TCWG; encourage rectification; if response inadequate consider professional duties; potentially disclose to authority; consider withdrawal. Document throughout. Specific provisions for money laundering (separate POCA framework).
ISRE 2400 vs ISRE 2410
ISRE 2400: review engagements on historical financial statements (typically non-public entities) — limited assurance, "nothing has come to our attention". ISRE 2410: review of INTERIM financial information by entity's independent auditor (e.g., listed entity half-year) — limited assurance.
ISRS 4400 (Revised)
Agreed-upon procedures engagements. NOT assurance — practitioner performs specific procedures agreed with client; reports findings only; recipients draw own conclusions. Common for due diligence, regulatory submissions, bank requirements. No conclusion/opinion provided.
ISA 600 (Revised) Group Audits
Effective from 2024. Strengthened group engagement partner responsibilities. Identify significant components (those of individual financial significance to group OR raising significant risks). Component materiality lower than group. Direction/supervision of component auditors. Documentation. Common in Case Study with international subsidiaries.
Key Formulas
Worked Examples
Related Topics
Key Takeaways
- ✓Audit risk model: AR = ROMM × DR. ROMM at financial statement level (pervasive) and assertion level (specific). Inherent risk factors per ISA 315 Revised: complexity, subjectivity, change, uncertainty, susceptibility to fraud. Significant risks require special audit consideration.
- ✓Per ISA 240, always significant: revenue recognition (unless rebutted) and management override (always). Fraud triangle: incentives/pressures + opportunities + attitudes/rationalisations. Identify all three when assessing fraud risk.
- ✓Audit response framework (ISA 330): Nature (what procedure), Timing (when), Extent (how much). Higher risk = more reliable evidence, year-end timing, larger samples. Substantive procedures essential for material balances; tests of controls only if reliance planned.
- ✓Specific procedures by area: revenue (cut-off, journals, confirmations, IFRS 15); receivables (confirmations, ECL); inventory (count attendance, NRV); PPE (existence, depreciation, impairment); provisions (IAS 37 criteria); going concern (forecasts, covenants, plans); related parties (identification, arm's length); estimates (ISA 540 Revised — methodology, assumptions, data); journals (ISA 240 management override).
- ✓Going concern (ISA 570 Revised): indicators in three categories (financial, operating, other). Five outcomes from no uncertainty to inappropriate basis. "Material Uncertainty Related to Going Concern" is separate audit report section per ISA 570 Revised — distinct from emphasis of matter.
- ✓Audit opinion modifications (ISA 705): based on materiality + pervasiveness. Material not pervasive → qualified ("except for"). Material AND pervasive misstatement → adverse. Pervasive scope limitation → disclaimer. Most modifications in practice are qualified; adverse and disclaimer rare.
- ✓Key Audit Matters (ISA 701): listed entities. Most significant matters from communication with TCWG. Description of why significant + how addressed. Common KAMs: revenue recognition, goodwill impairment, provisions, pension, going concern, acquisitions. NOT modification of opinion.
- ✓Audit ethics: 5 threat categories (self-interest, self-review, advocacy, familiarity, intimidation). Apply conceptual framework: identify → evaluate → safeguard → if not reduced, decline/withdraw. UK PIE rules strict: 70% non-audit services cap; certain services prohibited; partner rotation 5+5; firm rotation 10 (or 20 with tender).
- ✓NOCLAR (Section 360 ICAEW Code): tiered approach for non-compliance with laws/regulations. Discuss with management/TCWG; encourage rectification; if response inadequate consider disclosure/withdrawal; document throughout. Separate frameworks for money laundering (POCA/MLR) and whistleblowing (PIDA).
- ✓Other assurance services: review engagements (ISRE 2400/2410 — limited assurance); agreed-upon procedures (ISRS 4400 — no assurance); compilation (ISRS 4410 — no assurance); prospective FI (ISAE 3400); sustainability (ISAE 3000 / ISSA 5000 emerging). Group audits (ISA 600 Revised — effective 2024) — significant components, component materiality, group engagement partner direction.
Practice Questions
Question 1 of 8
Per ISA 240, which two risks are PRESUMED to be significant fraud risks?
Question 2 of 8
The NTE framework (ISA 330) for audit response means:
Question 3 of 8
Under ISA 570 Revised, if material uncertainty exists about going concern AND is adequately disclosed in financial statements, the audit opinion is:
Question 4 of 8
Audit opinion when material misstatement exists but is NOT pervasive:
Question 5 of 8
For UK PIE audits, non-audit services are restricted with:
Question 6 of 8
Key Audit Matters (ISA 701) are required for:
Question 7 of 8
In the fraud triangle (ISA 240), the three conditions for fraud are:
Question 8 of 8
When auditor identifies non-compliance with laws and regulations (NOCLAR), Section 360 ICAEW Code requires:
Source and Version
Syllabus: ICAEW ACA Advanced Level 2026 · Reviewed: 2026-05-04