AS · Certificate Level

The Concept and Need for Assurance

The definition and purpose of assurance, levels of assurance (reasonable and limited), elements of an assurance engagement (the three-party relationship, subject matter, suitable criteria, sufficient appropriate evidence, written assurance report), who needs assurance and why, the agency problem, and the public interest role of the auditor.

22 min read

Learning Objectives

  • Define assurance and explain why it is needed
  • Explain the agency problem and how assurance helps resolve it
  • Distinguish between reasonable assurance and limited assurance engagements
  • Identify and explain the five elements of an assurance engagement
  • Describe the three-party relationship in an assurance engagement
  • Explain who needs assurance and the different types of assurance service
  • Describe the auditor's role in serving the public interest

What is Assurance?

Assurance is an independent professional service that enhances the credibility and reliability of information. The IAASB (International Auditing and Assurance Standards Board) International Framework for Assurance Engagements defines an assurance engagement as:

An engagement in which a practitioner aims to obtain sufficient appropriate evidence in order to express a conclusion designed to enhance the degree of confidence of the intended users (other than the responsible party) about the subject matter information.

In simpler terms: an independent expert examines information prepared by one party and provides an opinion or conclusion to another party about whether that information is reliable. The most common form of assurance is the external audit of financial statements.

Why is assurance needed?

The fundamental reason is the separation of ownership and management in modern business — particularly in companies where shareholders (owners) are different from the directors (managers) who run the business day to day. This creates the agency problem.

The Agency Problem and the Need for Assurance

The agency relationship arises when one party (the principal — e.g., shareholders) delegates authority to another party (the agent — e.g., directors/management) to act on their behalf.

The agency problem: The interests of the agent may not always align with the interests of the principal. Directors may:

  • Maximise their own remuneration, perks, or job security rather than shareholder wealth
  • Take excessive risks, or conversely be too risk-averse
  • Present the company's financial results in an overly favourable light to protect their positions
  • Withhold or distort information that would be useful to shareholders

There is also an information asymmetry — management has detailed, day-to-day knowledge of the business, while shareholders and other external users typically rely on the financial statements management prepares. Shareholders cannot independently verify whether the financial statements are a faithful representation.

Assurance helps bridge this gap. An independent auditor examines the financial statements and provides an opinion on whether they present a true and fair view. This:

  • Increases users' confidence in the financial information
  • Reduces the information risk — the risk that the information on which users base their decisions is incorrect or misleading
  • Helps hold management accountable to shareholders and other stakeholders
  • Improves the functioning of capital markets — investors are more willing to invest when they can trust financial information
  • May help the entity obtain finance on better terms (lenders have more confidence in audited statements)

Other factors creating the need for assurance:

  • Complexity: Financial reporting is increasingly complex (IFRS standards, fair values, estimates). Users need confidence that the rules have been applied correctly.
  • Remoteness: Users are often geographically or organisationally remote from the entity and cannot directly observe its operations.
  • Volume: The sheer volume of transactions makes it impractical for users to check the information themselves.
  • Consequences of error: Decisions based on incorrect financial information (investing, lending) can result in significant financial loss.

Levels of Assurance

The International Framework identifies two levels of assurance:

1. Reasonable assurance (high, but not absolute)

  • The practitioner reduces engagement risk to an acceptably low level
  • The conclusion is expressed in the positive form: "In our opinion, the financial statements give a true and fair view…" or "In our opinion, the financial statements are presented fairly, in all material respects, in accordance with IFRSs."
  • More extensive evidence-gathering procedures are required
  • Example: An external audit of financial statements (ISA-based audit)
  • Reasonable assurance is the highest level of assurance available — absolute assurance is never achievable because of inherent limitations (sampling, judgement, estimates, possibility of collusion in fraud)

2. Limited assurance (moderate)

  • The practitioner reduces engagement risk to a level that is acceptable in the circumstances but higher than for reasonable assurance
  • The conclusion is expressed in the negative form: "Based on our review, nothing has come to our attention that causes us to believe that the financial statements are not presented fairly…"
  • Less extensive procedures — typically inquiry and analytical procedures rather than detailed substantive testing
  • Example: A review engagement (ISRE 2400, ISRE 2410) — e.g., a review of interim financial statements

No assurance

  • Some engagements provide no assurance at all — the practitioner does not express any conclusion about the information
  • Examples: Agreed-upon procedures (ISRS 4400) — the practitioner performs specific procedures agreed with the client and reports factual findings only; the users draw their own conclusions. Compilation engagements (ISRS 4410) — the practitioner assists in preparing financial information but does not express any assurance on it.
LevelAssurance providedOpinion/conclusion formEvidence requiredExample
ReasonableHigh (not absolute)Positive: "In our opinion…"Extensive (substantive + tests of controls)Statutory audit
LimitedModerateNegative: "Nothing has come to our attention…"Less extensive (inquiry + analytical)Review engagement
NoneNo assuranceNo conclusion expressedProcedures as agreed / compilation onlyAgreed-upon procedures, compilation

The Five Elements of an Assurance Engagement

The International Framework identifies five elements that must be present in all assurance engagements:

Element 1: A Three-Party Relationship

Every assurance engagement involves three separate parties:

  1. The practitioner (the assurance provider) — typically an external auditor or assurance firm. Must be independent of the responsible party and the intended users. Possesses appropriate competence and objectivity.
  2. The responsible party — the party responsible for preparing the subject matter information (e.g., the directors who prepare the financial statements). They are accountable for the information.
  3. The intended users — the person(s) for whom the practitioner prepares the assurance report. For a statutory audit, this is primarily the shareholders, but may also include lenders, regulators, and other stakeholders.

In a statutory audit: the practitioner is the auditor, the responsible party is the directors (who prepare the financial statements), and the intended users are primarily the shareholders (to whom the auditor's report is addressed).

It is essential that the practitioner is independent of the responsible party — otherwise the assurance has no credibility.

Element 2: Appropriate Subject Matter

The subject matter is the underlying data, systems, or topic being evaluated. The subject matter information is the output of measuring or evaluating the subject matter against the criteria.

  • In a financial statement audit: the subject matter is the entity's financial position, performance, and cash flows. The subject matter information is the financial statements themselves.
  • In a sustainability assurance engagement: the subject matter might be the entity's carbon emissions. The subject matter information is the sustainability report.

The subject matter must be identifiable and capable of consistent evaluation or measurement against the identified criteria.

Element 3: Suitable Criteria

The criteria are the benchmarks or standards used to evaluate or measure the subject matter. For criteria to be "suitable," they must be:

  • Relevant — they assist decision-making by intended users
  • Complete — they do not omit relevant factors that could influence conclusions
  • Reliable — they allow reasonably consistent measurement or evaluation
  • Neutral — they are free from bias
  • Understandable — clear to the intended users

In a financial statement audit, the criteria are the applicable financial reporting framework — typically IFRS or UK GAAP (FRS 102). The auditor assesses whether the financial statements have been prepared in accordance with these criteria.

Criteria can be established (e.g., IFRS, law) or developed specifically for the engagement.

Element 4: Sufficient Appropriate Evidence

The practitioner must obtain sufficient appropriate evidence on which to base the conclusion.

  • Sufficiency is the quantity of evidence — enough evidence must be gathered to support the conclusion. The amount needed depends on the assessed risk of material misstatement — higher risk requires more evidence.
  • Appropriateness is the quality of evidence, comprising:
    • Relevance: Does the evidence relate to the assertion being tested?
    • Reliability: Is the source and nature of the evidence trustworthy? External evidence is generally more reliable than internal; documentary evidence more reliable than oral; original documents more reliable than copies.

Evidence is gathered through procedures such as inspection, observation, inquiry, confirmation, recalculation, reperformance, and analytical procedures. The nature and extent of procedures differ between reasonable and limited assurance engagements.

Element 5: A Written Assurance Report

The engagement must culminate in a written report containing the practitioner's conclusion, addressed to the intended users.

  • For a reasonable assurance engagement (e.g., audit): the report contains an opinion expressed in positive form
  • For a limited assurance engagement (e.g., review): the report contains a conclusion expressed in negative form

The report enhances the credibility of the subject matter information by providing an independent practitioner's view. It should clearly identify: the subject matter, the criteria used, the responsible party, the practitioner's responsibility, and the conclusion.

The form and content of the statutory auditor's report is governed by ISA 700 (forming an opinion) and related standards (ISA 701, 705, 706).

Who Needs Assurance and Why

A wide range of stakeholders benefit from assurance services:

StakeholderWhy they need assurance
Shareholders (existing and potential)To make informed investment decisions (buy, hold, sell). They rely on audited financial statements to assess the entity's performance, financial position, and stewardship of their capital.
Lenders and creditorsTo assess creditworthiness and decide whether to extend credit or lend. Audited accounts provide confidence in the entity's ability to repay.
EmployeesTo assess job security, the entity's ability to pay wages and pensions, and the basis for profit-sharing or bonus schemes.
SuppliersTo assess whether the entity can pay for goods and services supplied on credit.
CustomersTo assess the entity's long-term viability, particularly for long-term contracts, warranties, or dependent relationships.
Government and regulatorsFor tax collection (HMRC), regulatory compliance, and national economic statistics.
The publicTo assess the entity's contribution to the local economy, employment, environmental impact, and social responsibility.

Types of assurance engagement beyond the statutory audit:

  • Review engagements — limited assurance on financial statements (e.g., interim reviews under ISRE 2410)
  • Sustainability / ESG assurance — assurance on environmental, social, and governance reports
  • Internal audit — assurance on internal controls, risk management, and governance (provided by an internal function or outsourced firm)
  • Due diligence — investigative work to support a transaction (e.g., acquisition, financing)
  • Prospective financial information — assurance on forecasts or projections
  • Compliance engagements — assurance that the entity has complied with specific regulations or contractual terms

The Public Interest Role of the Auditor

The statutory audit serves a public interest function. Although the auditor is appointed by, and reports to, the shareholders, the wider public benefits from the audit because:

  • Capital market confidence: Investors, both institutional and individual, rely on audited financial information to allocate capital efficiently. Without audit, the cost of capital would rise due to increased information risk.
  • Accountability and trust: The audit reinforces the accountability of directors to shareholders and, more broadly, to society. Audited information underpins trust in the business environment.
  • Deterrent effect: The knowledge that financial statements will be independently audited deters management from deliberate misstatement or fraud.
  • Economic stability: By identifying material misstatements and going concern issues early, auditors help prevent sudden corporate failures that could destabilise the wider economy.

The auditor's public interest responsibility is reflected in the professional and ethical obligations imposed by the ICAEW Code of Ethics, the FRC's Ethical Standard, and ISAs — all of which emphasise independence, objectivity, professional competence, and integrity.

Limitations of assurance:

Even a reasonable assurance engagement cannot provide absolute assurance. Inherent limitations include:

  • Sampling: Auditors test a sample of transactions, not every single one. There is always a risk that material misstatements in untested items go undetected.
  • Judgement and estimates: Financial statements involve significant judgements and estimates (e.g., provisions, fair values, useful lives). Reasonable people can disagree on these.
  • Fraud: Well-concealed fraud, especially involving collusion among management or with third parties, may not be detected even by a properly conducted audit.
  • Persuasive, not conclusive: Audit evidence is persuasive rather than conclusive. The auditor forms an opinion based on the balance of evidence, not certainty.
  • Timeliness: The audit is performed after the year end on historical information — it does not predict the future.

Examiner Focus

The five elements of an assurance engagement are a core exam topic. You must be able to identify all five in any scenario — particularly the three-party relationship. Know who the practitioner, responsible party, and intended users are for a statutory audit.

Common Pitfall

Students often confuse reasonable and limited assurance. Remember: reasonable = positive form ("In our opinion…"), limited = negative form ("Nothing has come to our attention…"). The key difference is the EXTENT of evidence gathered and the FORM of the conclusion, not the subject matter.

Study Tip

Absolute assurance is NEVER achievable. Even a properly conducted audit provides only reasonable (high, not absolute) assurance. Inherent limitations include sampling, judgement, estimates, and the possibility of undetected fraud involving collusion.

Watch Out

Agreed-upon procedures (ISRS 4400) provide NO assurance. The practitioner reports factual findings only — they do not express any conclusion or opinion. Don't confuse this with limited assurance.

Examiner Focus

The agency problem is frequently tested. Be able to explain WHY assurance is needed: separation of ownership and management, information asymmetry, complexity, remoteness, volume of transactions, consequences of errors. Link these to how assurance addresses them.

Common Pitfall

The auditor reports to the SHAREHOLDERS (not the directors). The directors are the responsible party — they prepare the financial statements. The auditor's independence from the directors is fundamental to the credibility of the assurance.

Key Definitions

Assurance

An independent professional service where a practitioner obtains sufficient appropriate evidence to express a conclusion designed to enhance the confidence of intended users about the subject matter information.

Reasonable assurance

A high (but not absolute) level of assurance. The practitioner's conclusion is expressed in the positive form ("In our opinion…"). Example: statutory audit of financial statements.

Limited assurance

A moderate level of assurance. The practitioner's conclusion is expressed in the negative form ("Nothing has come to our attention…"). Example: review engagement on interim financial statements.

Agency problem

The conflict of interest arising when agents (directors/management) may not act in the best interests of the principals (shareholders/owners) who appointed them, often due to differing incentives and information asymmetry.

Information asymmetry

A situation where one party (management) has significantly more or better information than another party (shareholders), creating an imbalance that may disadvantage the less-informed party.

Practitioner

The person or firm carrying out the assurance engagement. Must be independent and possess appropriate competence. In a statutory audit, this is the auditor.

Responsible party

The party responsible for preparing the subject matter information. In a statutory audit, this is the directors, who are responsible for preparing the financial statements.

Intended users

The person(s) for whom the assurance report is prepared. In a statutory audit, primarily the shareholders.

Subject matter

The underlying data, transactions, systems, or condition being examined (e.g., the entity's financial position and performance). The subject matter information is the presentation of the subject matter (e.g., the financial statements).

Suitable criteria

The benchmarks used to evaluate or measure the subject matter (e.g., IFRS for a financial statement audit). Must be relevant, complete, reliable, neutral, and understandable.

Sufficient appropriate evidence

Evidence that is adequate in quantity (sufficiency) and quality (appropriateness — relevance and reliability) to support the practitioner's conclusion.

Agreed-upon procedures

An engagement (ISRS 4400) where the practitioner performs specific procedures agreed with the engaging party and reports factual findings. No assurance conclusion is expressed.

Statutory audit

An audit required by law (Companies Act 2006 in the UK). Provides reasonable assurance that the financial statements give a true and fair view in accordance with the applicable framework.

Key Formulas

Worked Examples

Key Takeaways

  • Assurance is an independent professional service that enhances the credibility and reliability of information for intended users.
  • The agency problem (separation of ownership and management) and information asymmetry are the fundamental reasons assurance is needed.
  • Reasonable assurance (high, not absolute) uses extensive procedures and a positive opinion: "In our opinion…" Example: statutory audit.
  • Limited assurance (moderate) uses less extensive procedures and a negative conclusion: "Nothing has come to our attention…" Example: review engagement.
  • Agreed-upon procedures and compilation engagements provide no assurance.
  • Five elements of an assurance engagement: (1) three-party relationship, (2) appropriate subject matter, (3) suitable criteria, (4) sufficient appropriate evidence, (5) written assurance report.
  • In a statutory audit: practitioner = auditor, responsible party = directors, intended users = shareholders, criteria = IFRS/UK GAAP + CA 2006.
  • Absolute assurance is never achievable due to inherent limitations: sampling, judgement, estimates, fraud risk, persuasive (not conclusive) evidence.
  • The auditor serves the public interest by underpinning capital market confidence, accountability, and economic stability.

Practice Questions

Question 1 of 8

In a statutory audit of financial statements, the "responsible party" is:

Question 2 of 8

Reasonable assurance provided by a statutory audit means:

Question 3 of 8

A review engagement under ISRE 2410 provides:

Question 4 of 8

Which of the following is NOT one of the five elements of an assurance engagement?

Question 5 of 8

The agency problem arises because:

Question 6 of 8

In a statutory audit, the suitable criteria against which the financial statements are evaluated are:

Question 7 of 8

An agreed-upon procedures engagement (ISRS 4400) results in:

Question 8 of 8

Which of the following is an inherent limitation of a statutory audit that prevents absolute assurance from being achieved?

Source and Version

Syllabus: ICAEW ACA Certificate Level 2026 · Reviewed: 2026-05-04

ICAEW ACA syllabusLocal syllabus coverage review