AUI3701: Internal Audit Planning and Business Cycles Exam Pack — UNISA BCom Internal Auditing Study Guide

This exam pack is a comprehensive study guide for UNISA AUI3701: Internal Audit Planning and Business Cycles, tailored for BCom Internal Auditing students preparing for semester tests, assignments, and exams. It focuses on high‑value exam topics, integrates common question styles used at UNISA, and references related modules at South African universities (such as CUT and UJ) to align with what students commonly search for online (e.g. AUI3701 exam pack, AUI3701 past questions, BCom Internal Auditing UNISA notes). The emphasis is on practical understanding of internal audit planning, business cycles, and risk‑based audit methodologies in a South African context.

1. Positioning AUI3701 within UNISA’s BCom Internal Auditing Curriculum

1.1 Where AUI3701 Fits in the Qualification Structure

AUI3701: Internal Audit Planning and Business Cycles is typically offered as a third‑level (NQF Level 7) module in the BCom in Internal Auditing at the University of South Africa (UNISA). It builds directly on earlier internal auditing and risk management modules, such as:

  • AUI2601 – Internal Auditing: Concepts and Principles
  • AUI2602 – Internal Auditing: Techniques and Procedures
  • FRK201 – Financial Accounting (or equivalent)
  • MAC2601 – Management Accounting
  • RMI2601 – Risk Management

Students commonly search online for combinations such as “AUI3701 exam notes pdf”, “UNISA AUI3701 past exam questions”, and “UNISA BCom Internal Auditing study pack”. This guide is structured to reflect the flow and emphasis of typical UNISA assessments.

At other South African universities and universities of technology, similar content is covered in:

  • Central University of Technology (CUT):
    • INA30AS – Internal Auditing IIIA
    • INA30BS – Internal Auditing IIIB
  • University of Johannesburg (UJ):
    • IAD3A01 – Internal Auditing 3A
  • Tshwane University of Technology (TUT):
    • INA301T – Internal Auditing III

While the module codes differ, the core body of knowledge overlaps strongly: risk‑based internal audit planning, understanding business cycles, and designing internal audit engagements that respond to risk.

1.2 Core Outcomes of AUI3701

By the end of AUI3701, you are expected to demonstrate the ability to:

  1. Explain and apply the risk‑based internal audit approach in planning and executing audits.
  2. Understand and document key business cycles (e.g. revenue, procurement, payroll, production, inventory, financing).
  3. Identify risks and related controls within each major business cycle.
  4. Develop internal audit plans:
    • Strategic/rolling multi‑year audit plans.
    • Annual internal audit plans.
    • Detailed engagement‑level audit planning documents.
  5. Link internal audit work to governance and risk management frameworks, including King IV in the South African context.
  6. Prepare exam‑style responses that combine theory, application, and practical examples drawn from realistic case studies.

In UNISA exam questions, students are often required to:

  • Interpret a short case study and identify risks and controls.
  • Draft elements of an internal audit plan or an audit program.
  • Evaluate adequacy and effectiveness of internal controls for a specific business cycle.
  • Discuss how internal audit supports governance, risk management, and internal control.

1.3 Relationship to Other UNISA Modules and Common Search Keywords

AUI3701 does not exist in isolation. Typical search clusters from UNISA students include:

  • “AUI3701 and AUI3702 combined notes”
  • “AUI3701 exam pack with MNG3701” (Management modules often run in parallel)
  • “UNISA BCom Internal Auditing past papers AUI2601 AUI2602 AUI3701”

Within the UNISA: BCom Internal Auditing stream, AUI3701 acts as a bridge between foundational internal auditing theory and more advanced application in modules like:

  • AUI3702 – Internal Auditing: Advanced Governance and Reporting
  • AUI4801 – Internal Auditing Honours (for those who continue)

At CUT and other institutions, equivalent search queries might look like:

  • INA30AS exam notes CUT
  • INA30BS internal audit planning study guide

The technical content, however, remains widely applicable across institutions, making this guide useful even if you are enrolled under different module codes.

1.4 Exam and Assessment Focus Areas

UNISA typically tests AUI3701 through a mix of:

  • Multiple‑choice questions (MCQs) on principles, definitions, and standards.
  • Short‑answer questions checking understanding of concepts like risk, control, and audit objectives.
  • Long case‑based questions (20–40 marks) requiring:
    • Identification and ranking of risks.
    • Development of audit objectives and procedures.
    • Linking business cycle activities to controls and assertions.

High‑frequency exam focus areas include:

  • The risk‑based internal audit approach and its phases.
  • The role of internal audit in the governance, risk, and control environment.
  • Detailed understanding of revenue and procurement cycles.
  • Planning an audit engagement: objective, scope, resources, timing, work program.
  • Evaluating control adequacy and effectiveness.

Understanding these focus areas helps you prioritise your study time and prepare model answers.

2. Foundations of Risk‑Based Internal Audit Planning (AUI3701 Core)

2.1 Internal Auditing, Governance, and King IV

Internal auditing in South Africa operates within a governance framework heavily influenced by:

  • King IV Report on Corporate Governance for South Africa, 2016
  • The Companies Act, 2008
  • Professional guidance from the Institute of Internal Auditors (IIA), such as:
    • International Professional Practices Framework (IPPF)
    • International Standards for the Professional Practice of Internal Auditing (Standards)

In AUI3701, internal auditing is defined consistent with the IIA:

Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organisation’s operations. It helps an organisation accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of governance, risk management, and internal control processes.

King IV emphasises three lines of assurance:

  1. Management (first line) – owns and manages risk and controls.
  2. Risk and Compliance Functions (second line) – support and monitor risk and regulatory compliance.
  3. Internal Audit (third line) – provides independent assurance on the effectiveness of governance, risk management, and internal control.

Internal audit planning in AUI3701 is therefore not random; it is strategic and risk‑based, aligning with the organisation’s:

  • Strategy and objectives.
  • Risk profile and risk appetite.
  • Governance expectations from the board and audit committee.

2.2 Risk‑Based Internal Audit Approach: Overview

The risk‑based internal audit (RBIA) approach is central to AUI3701. RBIA aligns the internal audit plan and engagements to the organisation’s key risks, rather than auditing every process on a cyclical basis without regard to risk.

A simplified RBIA cycle includes:

  1. Understand the organisation and its environment:

    • Business model, strategies, objectives.
    • Industry forces, regulatory environment, macroeconomic risks.
  2. Identify and assess risks at:

    • Strategic level (e.g. failing to achieve growth targets).
    • Operational level (e.g. process failures in procurement, payroll).
    • Financial reporting level (e.g. misstatements, fraud).
  3. Evaluate the risk management and control environment:

    • Existence and design of controls.
    • Effectiveness of risk management processes.
  4. Develop the internal audit universe:

    • List of auditable units (e.g. business cycles, branches, departments, IT systems, projects).
  5. Risk‑rank the auditable units:

    • Impact and likelihood scores.
    • Inherent vs residual risk considerations.
  6. Prepare the multi‑year/strategic internal audit plan:

    • Often 3‑year rolling plan.
    • Shows planned audits, frequency, and coverage.
  7. Prepare the annual internal audit plan:

    • Detailed for the upcoming year.
    • Includes available resources, hours, timelines.
  8. Plan and execute individual audit engagements:

    • Engagement‑level risk assessment.
    • Audit objectives, scope, work program.
    • Fieldwork, testing, reporting, and follow‑up.

2.3 The Internal Audit Universe and Risk Assessment

In AUI3701, you must understand how the internal audit universe is developed and used.

Internal Audit Universe:
A structured list of everything that internal audit could potentially audit. Typical components:

  • Business units / divisions (e.g. Retail Banking, Manufacturing Plant).
  • Business processes / cycles (e.g. Revenue, Procurement, Payroll, Inventory).
  • IT systems (e.g. ERP systems, custom applications).
  • Projects / initiatives (e.g. system implementations, mergers).
  • Compliance areas (e.g. tax compliance, regulatory reporting).

Risk Assessment Process:

  1. Define risk factors used to score items in the audit universe:

    • Financial impact (e.g. rand value at risk).
    • Operational impact (e.g. customer service, production).
    • Reputational impact.
    • Compliance/regulatory impact.
    • Complexity and change.
    • Control environment maturity.
  2. Assign weights to each risk factor, for example:

Risk Factor Weight (%)
Financial impact 25%
Operational impact 20%
Compliance impact 20%
Reputational impact 15%
Complexity and change 10%
Control environment 10%
Total 100%
  1. Score each auditable unit (e.g. from 1–5 for each factor).

  2. Calculate a composite risk score for each unit:

    • Multiply each factor score by its weight.
    • Sum the results to get a total risk score.
  3. Rank auditable units from highest to lowest risk.

  4. Select units for audit coverage based on:

    • Available internal audit resources.
    • Required assurance levels by the audit committee.
    • Regulatory or statutory requirements.

In exams (UNISA, CUT, UJ), you might be asked to:

  • Explain the purpose of an internal audit universe.
  • Discuss how risk factors are selected and weighted.
  • Interpret a table of risk scores and make recommendations for audit coverage.

2.4 Strategic vs Annual Internal Audit Plan

Strategic (Multi‑Year) Internal Audit Plan:

  • Typically covers 3 years on a rolling basis.
  • Shows how the internal audit function intends to provide coverage of the full audit universe over time, focusing more frequently on high‑risk areas.
  • Helps the audit committee understand planned assurance over the medium term.
  • Is flexible – updated annually based on changing risks.

Annual Internal Audit Plan:

  • Refines the strategic plan into a detailed plan for the next 12 months.
  • Includes:
    • Specific engagements to be performed.
    • Estimated audit hours per engagement.
    • Timing (quarter or month).
    • Responsible audit team members.
  • Is approved by the audit committee after discussion.

In a typical AUI3701 exam question, you may receive a scenario describing an organisation’s risk profile and be asked to:

  • Draft key elements of a one‑year internal audit plan.
  • Justify why certain business cycles or units are selected for audit.
  • Explain how changes in the risk environment (e.g. new IT system, new regulations) would affect the plan.

2.5 Internal Audit Engagement Planning

Once the annual plan is set, engagement‑level planning begins for each internal audit assignment. Key steps:

  1. Gather background information:

    • Process descriptions, organisation charts.
    • Policies, procedures, and previous audit reports.
    • Risk registers and management self‑assessments.
  2. Understand the process and relevant business cycle:

    • Use walkthroughs and process flowcharts.
    • Identify key activities, decision points, and control points.
  3. Identify and assess process‑level risks:

    • Map risks to specific activities in the cycle.
    • Consider both fraud and error risks.
  4. Identify and evaluate existing controls:

    • Preventive vs detective controls.
    • Manual vs automated controls.
    • Key vs non‑key controls.
  5. Set the audit objective and scope:

    • Objective: what the audit aims to achieve (e.g. assess adequacy and effectiveness of controls over revenue recognition for the year ended 31 December 20X5).
    • Scope: boundaries of the audit (time period, business units, locations, systems).
  6. Develop the audit program:

    • Detailed list of procedures to perform, including:
      • Tests of design.
      • Tests of operating effectiveness.
      • Substantive procedures where necessary.
  7. Plan resources and timing:

    • Allocate team members and hours.
    • Agree timelines with management.

Exams often require you to draft audit objectives, identify risks and controls, and propose audit procedures for a given business cycle (e.g. procurement or payroll).

3. Business Cycles: Understanding, Documenting, and Auditing

A key feature of AUI3701 (and related modules like INA30AS at CUT and IAD3A01 at UJ) is the study of major business cycles, which are central to both financial reporting and operational performance. Internal auditors must understand how these cycles function, what can go wrong, and how to plan effective audits.

3.1 Overview of Major Business Cycles

Typical business cycles covered in AUI3701 include:

  1. Revenue and Receivables Cycle
  2. Procurement and Payables Cycle
  3. Inventory and Production Cycle
  4. Payroll and Human Resources Cycle
  5. Financing and Treasury Cycle
  6. Fixed Assets (Property, Plant, and Equipment) Cycle

Each cycle involves:

  • Key activities (e.g. placing orders, shipping goods, paying employees).
  • Documents (e.g. invoices, purchase orders, GRNs, timesheets).
  • Accounting records (e.g. journals, ledgers).
  • Risks (e.g. fraud, error, misstatement).
  • Controls (e.g. approvals, reconciliations, access controls).

AUI3701 often expects you to:

  • Draw or interpret flowcharts.
  • Prepare risk and control matrices.
  • Link cycle activities to financial statement assertions (e.g. completeness, existence, accuracy).

3.2 Revenue and Receivables Cycle

The revenue cycle encompasses all activities from receiving a customer order to collection of cash. It includes:

  1. Order receipt and approval.
  2. Credit approval.
  3. Order fulfilment (picking and dispatch).
  4. Invoicing.
  5. Recording sales and receivables.
  6. Collections and cash application.
  7. Returns, allowances, and write‑offs.

Key risks in the revenue cycle:

  • Fictitious sales recorded to inflate revenue.
  • Unrecorded sales (completeness risk).
  • Incorrect pricing or discounts.
  • Misappropriation of cash receipts.
  • Improper cut‑off (recording revenue in the wrong period).
  • Inadequate credit control leading to bad debts.

Common controls:

  • Credit checks and approvals for new customers or large orders.
  • Sequentially pre‑numbered sales orders, delivery notes, and invoices.
  • Matching of sales orders, delivery notes, and invoices.
  • Segregation of duties: order processing, dispatch, invoicing, and cash collection.
  • Daily banking of cash receipts; bank reconciliations.
  • Monthly customer statements and follow‑up of disputes.

Typical AUI3701 exam requirement:

  • You might receive a short case describing a wholesaler, such as “Alpha Distribution (Pty) Ltd,” with specific weaknesses like:
    • No credit checks.
    • Invoices prepared by delivery drivers.
    • Cash receipts kept in a safe and banked only once a week.
  • You may be asked to:
    • Identify risks arising from the weaknesses.
    • Suggest appropriate controls.
    • Draft audit procedures to test revenue and receivables.

Example audit procedures for the revenue cycle:

  • Test of controls:

    • Inspect a sample of sales transactions to confirm:
      • Existence of approved sales orders.
      • Evidence of credit approval.
      • Matching of delivery notes to invoices.
    • Observe the process of receiving cash and depositing it to verify segregation of duties and timely banking.
  • Substantive procedures:

    • Perform cut‑off tests around year‑end: inspect a sample of sales and dispatch documents before and after year‑end to ensure correct period recognition.
    • Circularise a sample of trade receivables (external confirmation).
    • Reconcile the receivables sub‑ledger to the general ledger.

Understanding the revenue cycle is critical because revenue is often a significant figure in financial statements and a common area for fraud.

3.3 Procurement and Payables Cycle

The procurement (purchases) and payables cycle encompasses activities from requisitioning goods or services to payment of suppliers:

  1. Purchase requisition (request for goods/services).
  2. Supplier selection and purchase order (PO) creation.
  3. Receiving goods/services (goods received note – GRN).
  4. Invoice receipt and verification.
  5. Recording payables.
  6. Payment processing.
  7. Supplier reconciliations and dispute resolution.

Key risks:

  • Unauthorized purchases or kickback schemes.
  • Purchases from fictitious suppliers.
  • Duplicate or inflated invoices.
  • Goods not received but paid for.
  • Incorrect prices or quantities.
  • Late payments leading to penalties or damaged supplier relationships.
  • Fraudulent changes to supplier master data (e.g. bank details).

Common controls:

  • Use of approved supplier lists.
  • Segregation of duties: requisitioning, ordering, receiving, invoice processing, and payment.
  • Formal purchase orders approved by authorised personnel.
  • Three‑way match: PO, GRN, and supplier invoice.
  • System controls to prevent duplicate invoice numbers.
  • Payments initiated and approved by different individuals.
  • Monthly creditors reconciliations.

Typical exam requirement:

  • In an AUI3701 or INA30AS question, you may be given a narrative description of a procurement process with weaknesses like:
    • No approved supplier list.
    • Same clerk creates purchase orders, receives goods, and processes invoices.
    • Suppliers allowed to change banking details by phone without verification.

You may be asked to:

  • Identify risks related to completeness, accuracy, and validity of purchases.
  • Suggest controls to mitigate each risk.
  • Propose an internal audit program for the procurement cycle.

Example audit procedures for procurement:

  • Test of controls:

    • Review a sample of purchases to ensure existence of approved POs.
    • Verify that GRNs are matched to invoices before payment.
    • Inspect authorisation signatures on payments against authority limits.
  • Substantive procedures:

    • Perform analytical procedures on purchases (e.g. compare monthly purchases to prior periods, budgets).
    • Test for duplicate payments by searching for invoices with same amount, date, and supplier.
    • Confirm balances with key suppliers and investigate reconciling items.

3.4 Payroll and Human Resources Cycle

The payroll cycle covers activities from hiring employees to paying salaries and related statutory deductions:

  1. Recruitment and hiring.
  2. Employee master file maintenance.
  3. Time and attendance recording (or performance measures for salaried staff).
  4. Payroll calculations (gross pay, deductions, net pay).
  5. Payment and distribution (EFT, payslips).
  6. Statutory reporting and payments (PAYE, UIF, SDL).
  7. Termination and exit processes.

Key risks:

  • Ghost employees (non‑existent employees on payroll).
  • Unauthorised salary increases.
  • Incorrect deduction calculations (e.g. PAYE, UIF).
  • Overtime abuse or false timesheets.
  • Late or incorrect statutory payments.
  • Fraudulent changes to banking details.

Common controls:

  • HR‑approved appointments and terminations with supporting documentation.
  • Access controls over the payroll system.
  • Segregation of duties: HR (authorisation) vs Payroll (processing) vs Finance (payment).
  • Regular review and authorisation of payroll reports by senior management.
  • Reconciliation of total payroll expenses to general ledger.
  • Independent review of changes to employee master file.

Example exam scenario:

  • A public entity, “Beta Municipality,” experiences increasing payroll costs with no corresponding increase in staff. The internal audit function is asked to investigate. You may be required to:
    • Identify potential fraud scenarios (e.g. ghost employees, overtime fraud).
    • Recommend controls and audit procedures.

Audit procedures for payroll:

  • Compare employee master file to HR records to detect ghost employees.
  • Recalculate payroll for a sample of employees.
  • Review changes to banking details and salary levels for proper authorisation.
  • Perform analytical procedures (e.g. payroll cost as a percentage of revenue, headcount analysis).

3.5 Inventory, Production, and Other Cycles

Depending on the organisation, the inventory and production cycle and fixed asset cycle are also crucial:

  • Inventory risks:
    • Misappropriation of stock.
    • Obsolescence and slow‑moving items.
    • Incorrect costing and valuation.
  • Production risks:
    • Inefficient production leading to higher costs.
    • Quality control failures.
    • Waste and scrap not properly recorded.

Controls may include:

  • Physical safeguards (locks, CCTV, restricted access).
  • Perpetual inventory systems and cycle counts.
  • Standard costing and variance analysis.
  • Quality control checks at various stages.

Audit procedures may involve:

  • Attending physical stock counts.
  • Testing valuation and cut‑off.
  • Reviewing production reports and investigating variances.

Understanding each major business cycle allows internal auditors to map risks and controls systematically and plan audits that are focused and effective.

4. Detailed Risk Identification, Control Evaluation, and Audit Planning

AUI3701 places strong emphasis on the mechanics of risk identification and control evaluation, and how these feed directly into an audit engagement plan. This is where theory becomes operational.

4.1 Risk Identification Techniques

Internal auditors use various techniques to identify risks at the entity and process level:

  • Interviews and workshops with management and process owners.
  • Review of risk registers and risk management reports.
  • Analysis of strategic and business plans.
  • Review of past incidents, audit reports, and loss events.
  • Examination of industry and regulatory developments.

In exam questions, risk identification is often tested by:

  • Providing a narrative description of a process and expecting you to extract and articulate specific risks.
  • Giving a list of weaknesses and asking you to state the risk for each weakness.

Example:

  • Weakness: “Salespeople can approve their own credit limits for customers.”
  • Risk: “Customers may be granted credit beyond their ability to pay, leading to increased bad debts and cash flow problems.”

4.2 Linking Risks to Objectives and Assertions

Risk does not exist in a vacuum; it threatens specific objectives:

  • Strategic objectives (e.g. market share growth).
  • Operational objectives (e.g. efficiency, quality).
  • Financial reporting objectives (e.g. accurate, complete, and timely financial statements).
  • Compliance objectives (e.g. adherence to tax laws).

Internal auditors typically link risks to financial statement assertions, especially for business cycles with direct financial impact:

  • Existence/occurrence.
  • Completeness.
  • Accuracy/valuation.
  • Rights and obligations.
  • Cut‑off.
  • Presentation and disclosure.

Example (revenue cycle):

  • Risk: “Fictitious sales recorded to boost reported revenue.”
    • Assertion affected: Occurrence (sales recorded may not have occurred).
  • Risk: “Goods dispatched but not invoiced.”
    • Assertion affected: Completeness (not all sales are recorded).

In exam responses, showing the explicit link between risk and assertion can earn extra marks and demonstrate solid understanding.

4.3 Evaluating the Design and Implementation of Controls

Once risks are identified, internal auditors evaluate controls designed to mitigate those risks.

Two key concepts:

  • Adequacy (design effectiveness):
    • Are the controls, if they operate as designed, capable of mitigating the identified risks to an acceptable level?
  • Operating effectiveness:
    • Are the controls actually operating as intended, consistently over time?

Example:

  • Risk: “Unauthorised changes to supplier bank details leading to payments to fraudsters.”
  • Control design:
    • Only the vendor master data team can change bank details.
    • All changes require written confirmation from the supplier and approval from the finance manager.
  • Adequacy:
    • If this process is followed, the control is adequate.
  • Operating effectiveness:
    • Internal audit tests a sample of changes and finds that approvals are often missing. The control is not operating effectively.

In AUI3701, you may be asked to:

  • Evaluate whether specific controls are adequate for a given risk.
  • Suggest additional controls where gaps exist.

4.4 Control Activities: Classification and Examples

When describing controls, be precise. Controls can be classified as:

  • Preventive vs Detective vs Corrective.
  • Manual vs Automated vs IT‑dependent manual.
  • General vs Application controls (for IT).

Examples in the procurement cycle:

  • Preventive:
    • System blocks purchase orders above a certain amount without senior approval.
  • Detective:
    • Monthly supplier statement reconciliations.
  • Corrective:
    • Investigation and correction of discrepancies found in reconciliations.

In payroll:

  • Preventive:
    • Only HR can authorise the creation of new employees.
  • Detective:
    • Monthly exception reports highlighting large salary changes.

AUI3701 exam questions often allocate marks for:

  • Identifying control activities correctly.
  • Classifying them appropriately (e.g. preventive/detective).
  • Explaining how they mitigate the risk.

4.5 Developing an Engagement‑Level Internal Audit Plan

For each audit engagement, internal auditors prepare a planning memorandum or engagement plan. Core components typically tested in AUI3701 include:

  1. Background:
    • Short description of the process or unit to be audited.
  2. Audit objective:
    • Clear, concise statement (e.g. “To evaluate the adequacy and operating effectiveness of controls over the procurement and payables cycle for the period 1 January 20X5 to 31 December 20X5.”)
  3. Scope:
    • Coverage (locations, time period, systems).
    • Exclusions (if any).
  4. Risk assessment summary:
    • Key risks identified.
    • Links to organisation’s risk register.
  5. Audit approach and methodology:
    • Use of walkthroughs, tests of controls, substantive procedures, data analytics.
  6. Resources and timing:
    • Team members, hours, start and end dates.
  7. Reporting and communication:
    • Expected deliverables.
    • Channels for communicating findings.

Exam example:

  • You may be given a scenario: “The internal audit activity has been requested to perform an audit of the payroll cycle at Gamma Manufacturing (Pty) Ltd. Draft the audit objective, scope, and key risks to be included in the planning memorandum (15 marks).”

Model answer elements:

  • Objective: mention effectiveness and efficiency of controls, compliance with laws, accuracy and completeness of payroll.
  • Scope: include all relevant branches, period under review, systems (e.g. SAP, SAGE).
  • Key risks: ghost employees, unauthorised salary changes, incorrect deductions, non‑compliance with tax laws, etc.

4.6 Audit Work Programs

An audit work program is a step‑by‑step list of procedures. In AUI3701, you should be able to:

  • Draft a work program for a specific cycle (e.g. revenue).
  • Link each procedure to a risk and control.

Example extract of a simple revenue cycle work program:

Step Procedure Purpose / Risk Addressed
1 Obtain and review documented policies and procedures for credit sales. Understand framework; identify gaps in design of controls.
2 Perform a walkthrough of the revenue process from order to cash receipt. Confirm understanding of process; identify key control points.
3 Select a sample of 30 sales invoices and trace to delivery notes and POs. Test validity of sales and proper authorisation of transactions.
4 Check that prices on invoices agree with approved price lists. Ensure accuracy of billing and prevention of under/over‑charging.
5 Review aged receivables for overdue balances and follow‑up procedures. Assess adequacy of credit management and collection procedures.

In exams, not every work program requires a detailed table, but structured listing of procedures with brief reasons is essential.

5. Exam Strategy, Common Question Types, and Integrated Application

A strong understanding of content must be matched with exam technique. Many UNISA BCom Internal Auditing students search for “AUI3701 exam tips” and “AUI3701 past exam solutions” precisely because internal audit questions require both knowledge and application.

5.1 Typical AUI3701 Question Types

  1. Definition and Theory Questions (MCQ and Short Answer):

    • Define internal auditing, risk ‑based audit, internal audit universe.
    • Differentiate between inherent and residual risk.
    • List the phases of the internal audit process.
  2. Scenario‑Based Risk and Control Questions (Short to Medium Answer):

    • Given a narrative of a business cycle, identify:
      • Weaknesses.
      • Risks arising from weaknesses.
      • Recommended controls.
  3. Engagement Planning Questions (Medium to Long Answer):

    • Draft audit objectives, scope, and approach.
    • Prepare or evaluate parts of a planning memorandum.
  4. Audit Program Design Questions (Medium Answer):

    • Prepare an audit program for a specific process (e.g. payroll master file changes).
  5. Integrated Case Study Questions (Long Answer; 30–40 marks):

    • Cover multiple learning outcomes:
      • Risk assessment.
      • Control evaluation.
      • Internal audit planning.
      • Reporting and communication.

Questions at CUT (INA30AS, INA30BS), UJ (IAD3A01), and TUT (INA301T) follow similar patterns, although mark allocations and depth may vary.

5.2 Mark Allocation and Time Management

At UNISA, a typical 2‑hour exam may contain 100 marks. Time management is critical:

  • Allocate approximately 1.2 minutes per mark (120 minutes ÷ 100 marks).
  • For a 20‑mark question, plan to spend around 24 minutes.
  • Break your answer up logically:
    • If a 20‑mark question has four sub‑questions of 5 marks each, allocate roughly 6 minutes per sub‑question.

When answering scenario questions:

  1. Read the scenario carefully once to gain overall understanding.
  2. Underline key facts that indicate:
    • Weaknesses.
    • Risk events.
    • Controls or lack thereof.
  3. Allocate marks logically:
    • If required to “list FIVE risks” for 10 marks, aim for 5 well‑explained risks (2 marks each) rather than 10 superficial ones.

5.3 Structuring High‑Scoring Answers

For scenario questions, structure and clarity are essential:

  1. Use headings and sub‑headings:

    • “Weaknesses”
    • “Risks”
    • “Recommended Controls”
    • “Audit Procedures”
  2. Link points clearly:

    • For each weakness, explicitly show the related risk and control.

    • Example:

      • Weakness: Sales clerks can approve customer credit limits without independent review.
      • Risk: Customers may receive credit beyond their capacity, resulting in high levels of bad debts and potential financial losses.
      • Recommended control: Implement a credit committee or independent credit control department to review and approve all new credit customers and significant limit increases based on creditworthiness assessments.
  3. Use bullet points for clarity:

    • Particularly for listing controls or procedures.
  4. Write in complete sentences:

    • Avoid single‑word answers unless explicitly requested (e.g. in MCQs).

5.4 Example Integrated Case Study Approach (AUI3701 Style)

Consider an example case that integrates business cycles, risk‑based planning, and control evaluation:

Scenario (summarised):
Sigma Retail (Pty) Ltd is a mid‑sized retailer operating 10 stores in Gauteng. The internal audit function is preparing the annual audit plan. Recent issues include:

  • Increase in inventory shrinkage at several stores.
  • Customer complaints about incorrect pricing at tills.
  • Late payments to suppliers resulting in penalties.
  • Rapid expansion of online sales, with limited documented procedures.

You are required to:

  1. Identify and explain key risks facing Sigma Retail. (10 marks)
  2. Recommend business cycles or auditable units that should be prioritised in the annual internal audit plan. Justify your choices. (8 marks)
  3. For the inventory cycle, list five key internal controls that should be in place. (10 marks)
  4. Draft the audit objective and scope for an internal audit of the inventory cycle at Sigma Retail. (7 marks)
  5. List four audit procedures you would perform to test the effectiveness of inventory controls at store level. (5 marks)

Suggested answer structure:

  1. Key risks:

    • Inventory shrinkage leading to financial losses and stockouts.
    • Incorrect pricing resulting in revenue loss and customer dissatisfaction.
    • Late supplier payments leading to penalties and damaged relationships.
    • Weak controls over online sales leading to fraud or errors (e.g. unrecorded sales, incorrect shipments).
    • Reputational damage due to customer complaints.
  2. Auditable units / cycles to prioritise:

    • Inventory and store operations (direct link to shrinkage).
    • Revenue cycle (point‑of‑sale and online sales) (pricing and fraud risks).
    • Procurement and payables (late payments and supplier relations).
    • Justification: high financial impact, high likelihood, and significant customer/reputational implications.
  3. Key inventory controls:

    • Restricted access to stockrooms and back‑office areas.
    • Regular cycle counts and reconciliation to stock records.
    • Segregation of duties between ordering, receiving, and recording inventory.
    • Approval procedures for write‑offs and adjustments.
    • Use of barcodes and point‑of‑sale systems integrated with inventory records.
  4. Audit objective and scope:

    • Objective: “To evaluate the adequacy and operating effectiveness of key controls over the inventory management process at Sigma Retail (Pty) Ltd’s 10 Gauteng stores for the period 1 January 20X5 to 31 December 20X5, with specific focus on inventory recording, safeguarding, shrinkage, and write‑off processes.”
    • Scope: All 10 stores, warehouse, and related systems (e.g. POS and inventory modules), including stock receiving, storing, movement, stock counts, and adjustments.
  5. Audit procedures:

    • Observe stock count procedures at selected stores and test a sample of counts for accuracy.
    • Review inventory adjustment reports and verify approvals.
    • Reconcile perpetual inventory records to general ledger balances.
    • Perform analytical review: compare shrinkage percentages across stores and investigate outliers.

This kind of integrated practice is excellent preparation for both UNISA AUI3701 and related modules such as CUT INA30AS and UJ IAD3A01.

5.5 Cross‑Module Integration and Career Relevance

While AUI3701 is an academic module, its content is directly relevant to:

  • Trainee Internal Auditors in public and private sectors.
  • SAICA and SAIPA trainee accountants who engage in internal control reviews.
  • Risk and compliance officers who interact with internal audit.

Related modules frequently searched together include:

  • “AUI3701 and AUI3702 combined notes UNISA”
  • “INA30AS study notes CUT internal auditing”
  • “IAD3A01 UJ past exam questions”

Mastery of AUI3701 content supports further study and professional designations such as:

  • Certified Internal Auditor (CIA).
  • Certified Government Auditing Professional (CGAP).
  • Certified Information Systems Auditor (CISA) (for the IT aspects).

5.6 Study Plan and Resources

An effective study plan for AUI3701 should:

  1. Map the syllabus to topics in this exam pack:

    • Risk‑based internal audit planning.
    • Business cycles and controls.
    • Audit engagements and work programs.
  2. Use multiple resources:

    • Official UNISA study guide and tutorial letters.
    • Prescribed or recommended textbooks.
    • Past exam papers (UNISA’s website).
    • Supplementary notes or exam packs for related modules (e.g. AUI2601, INA30AS).
  3. Practice under timed conditions:

    • Attempt at least two full past exam papers under 2‑hour exam conditions.
    • Review model answers critically.
  4. Form small study groups (online or face‑to‑face):

    • Discuss case studies and compare approaches.
  5. Develop personal “cheat sheets” (for revision):

    • Summaries of each business cycle.
    • Lists of common risks and controls.
    • Templates for audit objectives, scope, and work programs.

5.7 Final Consolidation Points for AUI3701

To conclude the exam‑oriented perspective of this AUI3701: Internal Audit Planning and Business Cycles Exam Pack, keep these consolidation points in mind:

  • Always link risk, control, and audit procedure in your answers.
  • Use business cycle terminology accurately (e.g. GRN, PO, delivery note, master file).
  • Emphasise the risk‑based nature of internal audit planning and the connection to governance (King IV).
  • Demonstrate understanding of both design and operating effectiveness of controls.
  • Structure answers clearly with headings, bullet points, and logical flow.

With consistent study, targeted practice on past questions, and a solid grasp of how internal audit planning connects to business cycles, students in UNISA’s BCom Internal Auditing (AUI3701) – as well as similar modules at CUT (INA30AS, INA30BS), UJ (IAD3A01), and other South African institutions – will be well positioned to perform strongly in assessments and to apply these skills in professional internal auditing roles.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare