ACC4000H: Governance, Audit & Control Study Notes (UCT BCom Financial Accounting)

These exam notes are tailored for ACC4000H: Governance, Audit & Control at the University of Cape Town (UCT) within the BCom Financial Accounting stream. They also reflect terminology and emphasis common in South African institutions such as UNISA (e.g. AUE3703 Governance in Audit) and Central University of Technology (CUT, e.g. AUA40AS Auditing & Assurance), so they are useful as cross‑reference study notes for governance, audit and control–type courses.

1. Corporate Governance Foundations (UCT ACC4000H / UNISA AUE3703 Cross‑Reference)

Corporate governance is a core pillar of ACC4000H and appears heavily in essay and application questions. For South African students, governance is inseparable from King IV, the Companies Act 71 of 2008, the JSE Listings Requirements, and the broader public sector governance environment (e.g. PFMA, MFMA). This section builds conceptual understanding and highlights examinable angles.

1.1 Defining Corporate Governance

Corporate governance refers to the system by which companies are directed and controlled in order to:

  • Set and achieve strategic objectives;
  • Safeguard stakeholders’ interests;
  • Ensure responsible and ethical decision‑making; and
  • Promote long‑term sustainability.

Common definitions used in UCT ACC4000H and UNISA AUE3703:

  • Cadbury Report (UK, 1992): Governance is the system by which companies are directed and controlled.
  • King IV (SA, 2016): Governance is the exercise of ethical and effective leadership to achieve four governance outcomes: ethical culture, good performance, effective control, and legitimacy.

In exam scenarios, always link your definition to purpose (why governance matters) and outcomes, not just structures.

1.2 Agency Theory and Stakeholder Theory

ACC4000H expects you to ground governance in key theoretical perspectives.

1.2.1 Agency Theory

Agency theory explains the conflict between:

  • Principals: Shareholders (and sometimes other providers of capital); and
  • Agents: Managers/directors who control day‑to‑day decisions.

Key assumptions:

  • Agents are self‑interested and risk‑averse.
  • Principals seek maximum return at acceptable risk.
  • Information asymmetry exists (managers know more than owners).

Governance mechanisms (e.g. independent non‑executive directors, performance‑linked remuneration, audit committees, external audit) are devices to mitigate agency costs:

  • Monitoring costs (e.g. audit fees, board oversight);
  • Bonding costs (e.g. covenants in debt agreements); and
  • Residual losses (value lost when interests are not fully aligned).

Examiners may ask you to:

  • Explain how a particular governance mechanism reduces agency costs.
  • Analyse a case where weak governance aggravated agency problems (e.g. management overriding controls, related‑party transactions).

1.2.2 Stakeholder Theory

Stakeholder theory holds that a company has responsibilities to multiple stakeholders, not just shareholders:

  • Employees;
  • Customers;
  • Suppliers;
  • Creditors;
  • Communities;
  • Regulators; and
  • The environment.

In South Africa, King IV explicitly adopts a stakeholder‑inclusive approach. Directors should consider the legitimate and reasonable needs, interests and expectations of material stakeholders when making decisions.

Exam application:

  • Discuss how a board should balance shareholder pressure for short‑term dividends against long‑term sustainability issues (e.g. environmental impacts, labour relations).
  • Evaluate whether a company’s decision (e.g. closing a plant, changing supplier) is consistent with a stakeholder‑inclusive philosophy.

1.3 South African Governance Landscape

South African governance is highly codified and exam questions often reference specific frameworks.

1.3.1 King IV Report on Corporate Governance

King IV (2016) is principle‑based and applies to all entities, not only JSE‑listed companies. It uses an apply and explain approach.

Key exam‑relevant features:

  • 16 Principles applicable to all organisations, addressing:
    • Ethical leadership;
    • Governance of strategy, risk, technology and information, compliance, remuneration, assurance;
    • Stakeholder relationships.
  • Four outcomes:
    • Ethical culture;
    • Good performance;
    • Effective control;
    • Legitimacy.

Common King IV exam tasks:

  • Identify relevant King IV principles in a scenario (e.g. weak IT governance, board dominance by executives, lack of risk oversight).
  • Explain how implementing specific King IV practices would improve governance and support the four outcomes.

1.3.2 Companies Act 71 of 2008 (South Africa)

The Companies Act is a statutory baseline, particularly for UCT ACC4000H and UNISA governance modules.

Important governance‑related aspects:

  • Directors’ duties (fiduciary duty, duty of care, skill and diligence).
  • Business judgment rule (protects directors if decisions were informed, in good faith, no conflict, and in best interests of company).
  • Audit committees (mandatory for certain categories of companies, especially listed and public interest score thresholds).
  • Company secretary (for public and some state‑owned companies).
  • Accounting and auditing provisions:
    • Requirement for annual financial statements (AFS);
    • Independent review versus audit thresholds.

Exam angles:

  • Analyse whether a director has breached fiduciary duties in a given set of facts (e.g. undisclosed conflict, insider trading).
  • Explain the statutory role of the audit committee under the Companies Act versus its broader King IV responsibilities.

1.3.3 JSE Listings Requirements

For listed companies, the JSE Listings Requirements incorporate King IV and impose:

  • Minimum number of independent non‑executive directors;
  • Mandatory audit committee and remuneration committee, with specific composition rules;
  • Disclosure requirements relating to governance, director dealings, related‑party transactions.

Exams may ask to:

  • Compare governance requirements for a JSE‑listed company versus a private company.
  • Advise a company considering listing on steps to upgrade its governance structures.

1.4 Roles and Responsibilities of Governance Participants

Understanding who does what is heavily tested.

1.4.1 Shareholders

Shareholders:

  • Appoint and remove directors at the AGM;
  • Approve certain major transactions (e.g. disposal of most of company’s assets);
  • Approve auditors, in many cases on recommendation of the audit committee;
  • Approve remuneration policies (for listed entities, via non‑binding votes).

Exam application: Discuss the limits of shareholder power versus board autonomy; evaluate the role of institutional investors in promoting governance.

1.4.2 Board of Directors

The board is ultimately responsible for governance. Core responsibilities:

  • Set strategic direction and approve the company’s strategy.
  • Appoint and oversee the CEO.
  • Ensure a sound system of risk management and internal control.
  • Approve key policies (e.g. risk appetite, ethics, remuneration).
  • Oversee IT governance, compliance, and sustainability reporting.
  • Ensure integrated reporting and disclosure.

Composition considerations:

  • Mix of executive, non‑executive, and independent non‑executive directors;
  • Chairperson ideally an independent non‑executive;
  • Separation of chair and CEO roles;
  • Diversity (skills, gender, race, experience).

Exam case studies often present a problematic board structure (e.g. chair = CEO, no independent directors, family‑dominated board) and expect you to:

  • Identify weaknesses;
  • Relate them to King IV principles; and
  • Recommend improvements.

1.4.3 Board Committees

Key standing committees:

  • Audit Committee
  • Risk Committee (or combined Audit & Risk)
  • Remuneration Committee
  • Social and Ethics Committee

Common SA practice and exam emphasis:

  • Audit Committee:
    • Composed mostly or entirely of independent non‑executive directors.
    • Oversees financial reporting, internal controls relating to financial reporting, internal audit function, and external audit.
    • Recommends appointment and removal of external auditors to shareholders.
  • Risk Committee:
    • Oversees enterprise risk management, risk appetite, and risk reporting.
    • Often overlaps with audit; at some entities they are merged.
  • Remuneration Committee:
    • Designs and oversees executive remuneration policies.
    • Ensures alignment with long‑term strategy and stakeholder expectations.
  • Social and Ethics Committee (Companies Act requirement)
    • Monitors activities relating to social and economic development, good corporate citizenship, environment, health and safety, consumer relationships, labour and employment.

Exam tasks:

  • Given a scenario, advise whether a company needs a Social and Ethics Committee.
  • Evaluate the effectiveness of an audit committee given its composition and activities.
  • Recommend how to improve remuneration governance when excessive bonuses are being paid despite poor results.

1.5 Ethical Leadership and Corporate Culture

Governance is not only structures; ethics and culture are central in ACC4000H, UNISA AUE3703 and CUT AUA40AS.

Key points:

  • Tone at the top: Directors and senior management must model ethical behaviour.
  • Code of ethics/conduct: Formal articulation of expected behaviours, conflict‑of‑interest rules, gifts policy, whistle‑blowing.
  • Ethics management: Ethics training, ethics hotline, disciplinary mechanisms, ethics risk assessments.

Exam angle: Given an ethical dilemma (e.g. pressure to manipulate revenue recognition, bribes to secure a contract), you may have to:

  • Identify stakeholders and ethical issues;
  • Analyse options using ethical theories (e.g. utilitarianism, deontology);
  • Recommend a course of action consistent with professional codes (e.g. SAICA Code) and King IV.

2. Boards, Committees and Director Responsibilities (UCT ACC4000H Focus)

Building on governance foundations, ACC4000H often examines the practical design and evaluation of boards and committees. This section dives deeper into board structures, director responsibilities, and common exam scenarios.

2.1 Board Composition and Structure

Examiners want you to evaluate board composition against best practice.

2.1.1 Executive vs Non‑Executive vs Independent Directors

  • Executive Directors:
    • Employed by the company in a management role (e.g. CEO, CFO).
    • Involved in day‑to‑day running.
  • Non‑Executive Directors (NEDs):
    • Not part of management; oversight role.
    • Provide independent judgment, but may have some relationships with the company (e.g. major customer or supplier).
  • Independent Non‑Executive Directors (INEDs):
    • Free of relationships and circumstances that could materially interfere with their judgment.
    • Independence assessed using criteria such as:
      • Not a recent employee;
      • No significant shareholding or business relationship;
      • No close family ties with executives;
      • No cross‑directorships that create mutual back‑scratching.

Exam tasks:

  • Assess whether an individual is truly independent given their history (e.g. ex‑CEO stepping into chair role; major supplier on the board).
  • Discuss why a high proportion of INEDs is particularly important for listed companies.

2.1.2 Board Size and Diversity

No fixed optimal size, but typical South African listed boards might have between 7 and 15 members.

Considerations:

  • Skills and Experience: Finance, industry knowledge, legal, IT, HR, risk.
  • Demographic Diversity: Gender, race, age; aligned with transformation objectives and broad stakeholder perspectives.
  • Tenure: Long tenure may impair independence; rotation helps bring fresh perspectives.

Exam scenario: A board of five, all family members, all with operational roles, no formal committees. Required: critique this structure and advise how to redesign it to align with King IV and JSE expectations.

2.2 Board Processes and Meetings

Strong governance also depends on how the board operates.

2.2.1 Board Charter

A board charter is a document which sets out:

  • Board’s role and responsibilities;
  • Matters reserved for the board vs those delegated to management;
  • Chair and CEO roles;
  • Committees and their mandates;
  • Meeting frequency, quorum, decision‑making processes.

Exam tasks: Draft key elements of a board charter or identify deficiencies in a given charter extract.

2.2.2 Meetings, Agendas, and Information

Effective meetings require:

  • Adequate frequency (e.g. at least quarterly, often more for JSE entities).
  • Properly structured agendas aligned with strategy, risk, performance monitoring.
  • Timely, accurate, and complete information provided to directors in advance.
  • Accurate minute‑taking, documenting decisions, rationale, and dissent where relevant.

Examiners may test:

  • How inadequate information flow can undermine the business judgment rule protection.
  • How to improve board meeting effectiveness (e.g. pre‑reading packs, clear decision points, performance dashboards).

2.3 Chairperson and CEO Roles

Separation of power at the top is heavily emphasised.

2.3.1 Chairperson

The chair:

  • Leads the board;
  • Sets the agenda with the CEO and company secretary;
  • Ensures directors participate fully;
  • Facilitates evaluation of the board and individual directors;
  • Acts as the main link between board and CEO.

Best practice:

  • Chair should be an independent non‑executive;
  • If the chair is not independent (e.g. founder), a lead independent director should be appointed.

2.3.2 CEO

The CEO:

  • Leads the executive team;
  • Implements the board‑approved strategy;
  • Manages operations and resources;
  • Reports performance, risks and opportunities to the board.

Exam application: In a case where the CEO is also the chair, discuss risks (e.g. concentration of power, inability of board to challenge management) and recommend mitigations (e.g. appointment of strong INEDs, lead independent director, separation of roles over time).

2.4 Audit Committee: Composition, Roles and Exam Angles

In ACC4000H and UNISA AUE3703, the audit committee frequently appears in exam questions.

2.4.1 Composition and Requirements

For certain public and state‑owned companies, the Companies Act requires:

  • At least three members;
  • All non‑executive directors, majority independent;
  • Elected by shareholders at the AGM;
  • Financial literacy and expertise.

King IV further recommends:

  • Only independent non‑executive directors on the committee;
  • Chair should not be the board chair.

2.4.2 Responsibilities

Core responsibilities:

  1. Financial Reporting

    • Review AFS, interim reports, integrated reports;
    • Consider significant accounting estimates and judgments;
    • Assess going concern and solvency/liquidity statements.
  2. Internal Control and Risk (where combined)

    • Evaluate adequacy and effectiveness of financial reporting controls;
    • Consider management’s responses to internal and external audit findings.
  3. Internal Audit

    • Approve internal audit charter, plan and budget;
    • Recommend appointment and dismissal of head of internal audit;
    • Ensure internal audit’s independence and objectivity.
  4. External Audit

    • Recommend appointment, reappointment or removal of external auditor;
    • Approve audit fees and terms;
    • Assess auditor independence, including non‑audit services;
    • Review audit strategy and significant findings.
  5. Combined Assurance

    • Oversee integration and coordination of assurance providers (internal audit, external audit, management, risk, compliance).

Exam questions may ask:

  • To list and explain the responsibilities of the audit committee.
  • To evaluate a scenario where the CFO sits on the audit committee (not appropriate).
  • To advise on how to strengthen audit committee oversight after a control failure.

2.5 Risk, Remuneration, and Social & Ethics Committees

Although the audit committee often gets the spotlight, other committees are equally examinable.

2.5.1 Risk Committee

Responsibilities:

  • Oversee implementation of Enterprise Risk Management (ERM);
  • Recommend risk appetite and risk tolerance levels;
  • Evaluate significant risks and mitigation strategies;
  • Monitor emerging risks (e.g. cyber, climate, regulatory).

Composition:

  • Mix of non‑executive and executive directors, plus relevant experts;
  • Chair typically an independent non‑executive director.

Exam angle: Explain how a risk committee should respond to a major cyber breach or operational failure.

2.5.2 Remuneration Committee

Responsibilities:

  • Design and recommend executive remuneration policies;
  • Balance fixed vs variable pay, short‑term vs long‑term incentives;
  • Align incentives with long‑term sustainable performance and risk appetite;
  • Oversee succession planning for key executives.

Exam tasks:

  • Evaluate a remuneration scheme that rewards revenue growth without considering risk or long‑term value.
  • Suggest how to introduce clawback provisions for bonuses linked to misstated results.

2.5.3 Social and Ethics Committee

Statutory requirement for certain companies (Companies Act Regulations).

Monitors:

  • Social and economic development (B‑BBEE, UN Global Compact principles);
  • Good corporate citizenship;
  • Environment, health and public safety;
  • Consumer relationships;
  • Labour and employment (including ethical labour practices).

Exam application: Using a case where a mining company faces community protests over environmental damage, outline the role of the Social and Ethics Committee.

2.6 Director Duties, Liabilities and Business Judgment Rule

Understanding director liability is crucial.

2.6.1 Fiduciary Duties

Directors must:

  • Act in good faith and in the best interests of the company;
  • Avoid conflicts of interest and disclose any existing conflicts;
  • Not use their position or information for personal advantage or to harm the company.

Breach examples:

  • Undisclosed related‑party transactions on favourable terms;
  • Diverting corporate opportunities to themselves.

2.6.2 Duty of Care, Skill and Diligence

Standard: What may reasonably be expected of a person—

  • Carrying out the same functions as those carried out by the director; and
  • Having the general knowledge, skill and experience of that director.

Exam case: A director with a strong finance background fails to notice an obvious misclassification in the AFS. Discuss whether they breached the duty of care and skill.

2.6.3 Business Judgment Rule

Provides a defence if:

  • Director acted in good faith and for a proper purpose;
  • Director did not have a material personal financial interest;
  • Director was informed to the extent they reasonably believed appropriate;
  • Director had a rational basis for believing the decision was in the best interests of the company.

Exam application: Assess whether a director can rely on the business judgment rule after approving a risky acquisition based on limited information.

3. Internal Control Systems and Risk Management (UCT ACC4000H / CUT AUA40AS Alignment)

Internal control and risk management underpin both governance and audit. ACC4000H expects you to apply control frameworks, design control systems, and link them to risk management.

3.1 Internal Control: Definition and Objectives

According to the COSO framework (widely referenced in UCT, UNISA and CUT materials), internal control is:

A process, effected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to:

  • effectiveness and efficiency of operations;
  • reliability of financial reporting; and
  • compliance with applicable laws and regulations.

Key exam points:

  • Emphasise reasonable, not absolute, assurance.
  • Mention that internal control is embedded in operations, not a separate activity.
  • Stress that everyone (board, management, staff) plays a role.

3.2 COSO Components of Internal Control

COSO identifies five integrated components. Examiners frequently ask you to identify weaknesses in each.

3.2.1 Control Environment

The control environment is the foundation; it sets the tone at the top.

Elements:

  • Integrity and ethical values;
  • Commitment to competence;
  • Board and audit committee oversight;
  • Organisational structure and reporting lines;
  • Assignment of authority and responsibility;
  • Human resource policies and practices.

Exam example: A company with no code of conduct, high staff turnover, and weak disciplinary process. You must explain how this weak control environment undermines other control components.

3.2.2 Risk Assessment

Risk assessment involves:

  1. Identifying relevant risks to achieving objectives;
  2. Estimating their significance and likelihood;
  3. Determining how to manage those risks.

Key considerations:

  • Changes in operating environment;
  • New personnel;
  • New systems;
  • Rapid growth;
  • New technology or products;
  • Corporate restructuring;
  • Foreign operations.

Exam question: Describe the risk assessment process when a company implements a new ERP system; identify specific risks (e.g. data migration errors, access control weaknesses).

3.2.3 Control Activities

Control activities are policies and procedures that help ensure management directives are carried out.

Types:

  • Preventive vs Detective vs Corrective controls;
  • Manual, automated, or IT‑dependent manual controls.

Common categories:

  • Authorisation and approval (e.g. credit limits, purchase order approval);
  • Segregation of duties (custody, recording, authorisation);
  • Physical controls (locks, safes, access cards);
  • Reconciliations (bank reconciliations, stock counts);
  • Supervisory controls (review and sign‑off);
  • IT controls (access controls, change management, backup and recovery).

Examiners often give you a process (e.g. sales, purchasing, payroll) and ask:

  • Identify control weaknesses;
  • Recommend control improvements;
  • Classify controls by type.

3.2.4 Information and Communication

Effective control requires:

  • Adequate information systems to capture, process and report relevant, reliable, and timely information;
  • Clear communication of roles, responsibilities and expectations;
  • Communication channels for reporting problems (e.g. whistle‑blowing hotlines).

Example: If warehouse staff never receive updated standard cost information, variance analysis will be unreliable and stock valuation may be misstated.

3.2.5 Monitoring Activities

Monitoring ensures that controls continue to operate effectively over time.

Types:

  • Ongoing monitoring (e.g. management review of performance reports, key indicators);
  • Separate evaluations (e.g. internal audit reviews, self‑assessment questionnaires).

Exam tasks:

  • Distinguish monitoring from control activities;
  • Suggest monitoring mechanisms for a medium‑sized retailer with limited internal audit capacity (e.g. surprise stock counts, independent review of reconciliations).

3.3 Limitations of Internal Control

Internal control can only provide reasonable assurance due to inherent limitations:

  • Human error (carelessness, misunderstanding);
  • Collusion between employees (overcoming segregation of duties);
  • Management override of controls;
  • Cost‑benefit trade‑off (controls must be economical);
  • External events beyond control (e.g. natural disasters, sudden regulatory changes).

Exam scenario: A fraud is committed despite apparently strong controls through collusion between the accounts payable clerk and a supplier. You must explain how this reflects inherent limitations and suggest additional safeguards (e.g. supplier vetting, rotation of duties).

3.4 Enterprise Risk Management (ERM) and Risk Governance

Risk management is heavily integrated into ACC4000H and King IV.

3.4.1 ERM Concepts

ERM is a structured, enterprise‑wide approach to identifying, assessing, responding to, and monitoring risks in pursuit of objectives.

Key elements:

  1. Risk Appetite and Tolerance

    • Appetite: The amount and type of risk the organisation is willing to pursue or retain.
    • Tolerance: Acceptable variation around objectives.
  2. Risk Identification

    • Brainstorming, workshops, SWOT analysis, process mapping, incident data, industry benchmarking.
  3. Risk Assessment

    • Qualitative (high/medium/low) or quantitative (probabilities, expected values);
    • Impact vs likelihood matrices.
  4. Risk Response Strategies

    • Avoid (discontinue activity);
    • Reduce/mitigate (controls, process changes);
    • Transfer (insurance, hedging, outsourcing);
    • Accept (within appetite, monitored).
  5. Risk Monitoring and Reporting

    • Key risk indicators (KRIs);
    • Risk registers;
    • Regular reporting to management, risk committee, and board.

Examiners may ask you to construct a simple risk register with mitigation actions and responsible parties.

3.4.2 King IV and Risk Governance

King IV emphasises that:

  • The board is responsible for governing risk, setting risk appetite, and ensuring risk‑based decision‑making.
  • Risk should be integrated with strategy and performance (not siloed).
  • Risk governance includes emerging risks and opportunities, not only downside risks.

Exam application: Evaluate the adequacy of risk governance in a scenario where the board receives only annual, high‑level “risk heatmaps” without clear links to strategy or performance measures.

3.5 IT Governance and Cyber Risk

ACC4000H increasingly tests understanding of IT governance, especially in the context of fintech, ERP systems, and remote work.

Key IT governance concepts:

  • Alignment of IT strategy with business strategy;
  • Value delivery from IT investments;
  • Risk management of IT (security, availability, data integrity);
  • IT resource management (people, infrastructure, applications);
  • Performance measurement (e.g. service levels, uptime, project success rates).

Common IT risks and controls:

  • Access Security:

    • Risks: Unauthorised access, data theft, fraud.
    • Controls: Strong passwords, multi‑factor authentication, role‑based access, periodic access reviews.
  • Change Management:

    • Risks: System errors due to untested changes, unauthorised modifications.
    • Controls: Formal change requests, approvals, testing, segregation between development and production.
  • Backup and Recovery:

    • Risks: Data loss, downtime after failures.
    • Controls: Regular backups, off‑site storage, disaster recovery plans, tested recovery procedures.
  • Cybersecurity:

    • Risks: Malware, ransomware, phishing.
    • Controls: Firewalls, antivirus, user awareness training, incident response plans.

Exam scenarios might include:

  • Assessing weaknesses in a company that uses a cloud‑based accounting system with shared passwords and no logs.
  • Designing an IT control environment for a newly implemented online sales platform.

4. Internal Audit, External Audit and the Combined Assurance Model (UCT ACC4000H / UNISA AUE4861)

Audit and assurance form the bridge between governance intent and credible stakeholder assurance. ACC4000H expects you to differentiate internal vs external audit, understand combined assurance, and recognise the expanding scope of assurance (e.g. ESG, integrated reporting).

4.1 Internal Audit: Purpose, Role and Independence

4.1.1 Definition and Objectives

The Institute of Internal Auditors (IIA) defines internal auditing as:

An independent, objective assurance and consulting activity designed to add value and improve an organisation's operations. It helps an organisation accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.

Objectives:

  • Provide assurance to management and the board on:

    • Adequacy and effectiveness of internal controls;
    • Risk management processes;
    • Governance processes.
  • Provide consulting (without compromising independence), e.g. advice on control design in new projects.

Exam angles:

  • Explain how internal audit contributes to governance and control.
  • Distinguish internal audit’s assurance role from management’s responsibility for controls.

4.1.2 Independence and Objectivity

For internal audit to be effective:

  • Organisational Independence:

    • Reports functionally to the audit committee (or board);
    • Administratively to CEO or similar (for resources);
    • Unrestricted access to records and personnel.
  • Individual Objectivity:

    • No auditing of activities for which the auditor was responsible in the last year;
    • No designing and then auditing the same controls (threat to objectivity).

Exam scenario: The head of internal audit is also responsible for risk management implementation. Discuss threats to independence and propose mitigations (e.g. clear role definitions, external quality assessment).

4.1.3 Internal Audit Charter and Planning

Internal Audit Charter defines:

  • Purpose, authority, and responsibility;
  • Access rights;
  • Reporting lines;
  • Scope of activities.

Risk‑based internal audit planning involves:

  1. Understanding the organisation’s risk universe;
  2. Prioritising high‑risk areas;
  3. Developing an annual plan focused on areas of greatest risk and materiality.

Exam tasks may include crafting key elements of an internal audit charter or outlining a risk‑based planning process for a new internal audit function.

4.2 External Audit: Purpose, Scope and Key Concepts

Although ACC4000H is not a full auditing technical paper like UCT’s ACC4002W Auditing and Assurance, you still need solid fundamentals.

4.2.1 Purpose of External Audit

External audit provides reasonable assurance that the financial statements:

  • Are free from material misstatement (due to error or fraud); and
  • Are prepared, in all material respects, in accordance with an applicable financial reporting framework (e.g. IFRS).

This enhances the credibility of financial reporting for users (shareholders, lenders, regulators).

4.2.2 External Auditor Independence

Independence is both in mind and in appearance.

Threats:

  • Self‑interest (fee dependence, financial interest);
  • Self‑review (providing non‑audit services that are later audited);
  • Familiarity (long association with client);
  • Advocacy (promoting client’s position);
  • Intimidation (pressure from client).

Safeguards:

  • Rotation of engagement partners;
  • Limits on non‑audit services;
  • Audit committee oversight of auditor appointments and fees;
  • Independence policies and declarations.

Exam questions may test:

  • Identification of independence threats in a scenario (e.g. auditor owning shares, providing payroll services).
  • Recommending safeguards to restore independence.

4.3 Combined Assurance in South Africa

King IV advocates a combined assurance model to optimise assurance coverage and reduce duplication.

4.3.1 Levels of Assurance Providers

Typically:

  1. Management and Internal Line Functions

    • First line: Operational management, risk owners.
    • Second line: Risk management, compliance, quality.
  2. Internal Assurance Providers

    • Internal audit;
    • Specialist functions (e.g. health & safety, IT security).
  3. External Assurance Providers

    • External audit;
    • Regulators;
    • External specialists (e.g. environmental auditors).

The audit committee usually coordinates combined assurance, ensuring:

  • Key risks are covered by appropriate levels of assurance;
  • Overlaps (e.g. internal and external auditors both testing the same control unnecessarily) are minimised;
  • Assurance gaps are identified and addressed.

Exam tasks:

  • Map a given organisation’s assurance providers into a combined assurance framework;
  • Identify gaps (e.g. no assurance over IT security) and overlaps (e.g. two functions reviewing the same process) and recommend changes.

4.4 Audit Committees and Relationships with Auditors

Reinforcing Section 2, focus on relationships:

  • Audit committee appoints and oversees internal audit;
  • Recommends external auditor to shareholders;
  • Reviews independence and quality of auditors;
  • Receives and evaluates audit reports and management letters;
  • Ensures management responds appropriately to findings.

Exam scenario: The audit committee meets once a year and never discusses internal audit findings in detail. You must evaluate and recommend how to enhance oversight.

4.5 Non‑Financial and Integrated Reporting Assurance

South Africa is a global leader in integrated reporting and sustainability disclosure. ACC4000H may test conceptual aspects of assurance over non‑financial information.

Key points:

  • Integrated reports blend financial and non‑financial information (strategic, governance, social & environmental).
  • Assurance can be:
    • Reasonable assurance (higher level; similar to audit);
    • Limited assurance (lower level; more moderate procedures).

Examples:

  • Assurance over greenhouse gas emissions;
  • Assurance over B‑BBEE scorecards;
  • Assurance over selected key performance indicators in integrated reports.

Exam tasks:

  • Explain why users might demand external assurance over sustainability metrics.
  • Discuss challenges: lack of standardised measurement frameworks, subjectivity, data quality issues.

5. Governance, Audit and Control Exam Application: Case Analysis, Typical Questions and Study Tips

The final section consolidates how ACC4000H content is examined, relating also to patterns seen in UNISA’s AUE3703 and CUT’s AUA40AS. It focuses on exam technique, question types, and integrative application.

5.1 Typical ACC4000H Question Types

Expect a mix of:

  1. Discursive Theory Questions

    • Definitions (governance, internal control, combined assurance);
    • Explanations of King IV principles;
    • Discussion of agency vs stakeholder theory.
  2. Scenario‑Based Application Questions

    • Case study describing a company with governance problems;
    • Required to evaluate, identify weaknesses, and recommend improvements.
  3. Control and Process Analysis

    • Detailed description of a process (e.g. purchases, payroll, inventory);
    • Required to identify control weaknesses, associated risks, and design controls.
  4. Short‑Form Questions

    • List duties of directors;
    • Identify limitations of internal control;
    • Outline responsibilities of the audit committee.

5.2 Frameworks to Use in Application Answers

In application questions, structure answers around recognised frameworks:

  • King IV Principles and Practices
    • When asked to critique governance structures or culture.
  • COSO Internal Control Components
    • When analyzing internal control environment and risk assessment.
  • COSO ERM or Risk Management Steps
    • When evaluating risk governance or risk responses.
  • Combined Assurance Levels
    • When mapping assurance providers.

Using these frameworks shows integrated understanding and earns high marks.

5.3 Example Scenario and Model Approach

Consider a typical ACC4000H style question:

XYZ Ltd is a rapidly growing technology firm listed on the JSE. The CEO, who is also the founder, serves as board chair. The board consists of five members: the CEO, CFO, COO, the CEO’s sister (a non‑executive director who owns 20% of shares), and a long‑time family friend (non‑executive) who is also a major supplier. There is no audit committee or internal audit department. Recent events include a data breach, unexplained variances in inventory records, and an anonymous whistle‑blower complaint alleging manipulation of revenue figures to meet bonus targets.

Required:
(a) Identify and explain governance weaknesses at XYZ Ltd, with reference to King IV.
(b) Discuss risks arising from the current internal control environment.
(c) Recommend improvements in governance, audit and control that XYZ Ltd should implement.

5.3.1 Part (a): Governance Weaknesses

Use King IV and board structure principles:

  • Concentration of power: CEO is also chair → violates recommended separation; risk of unchecked executive dominance.
  • Board independence issues:
    • Only two non‑executives, both with conflicts (sister = major shareholder; friend = major supplier).
    • No independent non‑executive directors; violates best practice for JSE‑listed companies and King IV board composition guidelines.
  • No audit committee:
    • Contravenes Companies Act and JSE requirements for listed companies.
    • Weak oversight of financial reporting, internal control, and external audit.
  • No internal audit function:
    • No systematic, independent evaluation of risk management, control and governance.
  • Possible weak IT governance:
    • Data breach suggests inadequate board oversight of IT risks and security.

5.3.2 Part (b): Risks from Internal Control Environment

Apply COSO components:

  • Control Environment:

    • Dominant founder‑CEO; potential override of controls.
    • Family and friend board composition; culture of informality and loyalty over objectivity.
  • Risk Assessment:

    • Rapid growth without formal systems; likely weak risk identification and mitigation.
  • Control Activities:

    • Inventory variances suggest poor stock controls, weak reconciliations.
    • Allegations of revenue manipulation imply inadequate segregation of duties, lack of review, or performance targets that incentivise fraud.
  • Information and Communication:

    • Whistle‑blower complaint indicates issues may not be openly reported or addressed internally.
  • Monitoring:

    • Absence of internal audit; minimal monitoring of control effectiveness.

Risks include:

  • Financial statement misstatements (fraudulent revenue recognition, misstated inventory).
  • Regulatory non‑compliance (JSE, Companies Act).
  • Reputational damage due to data breach and governance failures.
  • Potential legal liability for directors and the company.

5.3.3 Part (c): Recommendations

Structure recommendations by governance level:

  • Board Structure:

    • Separate CEO and chair roles; appoint an independent non‑executive chair.
    • Expand board to include several independent non‑executive directors with relevant skills (IT, finance, risk).
  • Committees:

    • Establish an audit committee composed exclusively of independent non‑executive directors;
    • Set up a risk committee (or combined audit & risk committee) and a remuneration committee;
    • Consider a Social and Ethics Committee (likely required given listing and size).
  • Internal Audit and Controls:

    • Establish a risk‑based internal audit function reporting to the audit committee;
    • Strengthen IT security, access controls, and incident response procedures;
    • Review and enhance inventory controls (stock counts, reconciliations, system controls);
    • Redesign revenue recognition processes with adequate segregation of duties and approval steps.
  • Ethics and Whistle‑Blowing:

    • Implement a code of ethics and whistle‑blowing hotline;
    • Ensure protection of whistle‑blowers and transparent investigation of allegations.
  • Remuneration Governance:

    • Link bonuses to sustainable performance, not just short‑term revenue targets;
    • Introduce clawback clauses for bonuses paid on misstated results.

This structured, framework‑driven approach is what earns high marks.

5.4 Integrating Governance, Audit and Control in Public Sector and NPO Contexts

ACC4000H may occasionally frame questions around public sector entities or non‑profit organisations, drawing on PFMA, MFMA, and King IV’s sector supplements.

Key differences:

  • Public Sector:

    • Oversight by Parliament, provincial legislatures or municipal councils;
    • External audit by the Auditor‑General South Africa (AGSA);
    • Strict compliance focus (PFMA/MFMA, Treasury Regulations);
    • Emphasis on service delivery and public accountability.
  • Non‑Profit Organisations (NPOs):

    • Boards may be voluntary; resources limited;
    • Governance still critical due to donor expectations and reputational risk;
    • Internal control systems must be tailored to size and capacity but still cover basic segregation of duties, authorisations, reconciliations.

Exam tasks:

  • Compare governance structures of a state‑owned company with a private listed company.
  • Evaluate control environments in a small NGO and suggest cost‑effective improvements (e.g. independent bank reconciliations by a volunteer, two signatures on payments).

5.5 Study Strategies for ACC4000H (and Similar Modules like UNISA AUE3703, CUT AUA40AS)

  1. Master Core Frameworks

    • King IV principles and outcomes;
    • COSO internal control components;
    • ERM steps and risk response strategies;
    • Roles of key governance players (board, audit committee, internal audit, external audit).
  2. Practice Scenario Questions

    • Use past ACC4000H tutorial questions and UCT past papers;
    • Look at UNISA AUE3703 and CUT AUA40AS past exam questions for additional practice on governance and control scenarios;
    • Time yourself to build exam speed.
  3. Develop a Structured Answer Technique

    • Start with brief identification of the issue;
    • Explain why it is a problem using relevant theory/framework;
    • Provide practical recommendations linked to that framework.
  4. Use South African Context Examples

    • Refer to King IV rather than only international codes;
    • Know the basic governance implications of the Companies Act, JSE Listings Requirements, PFMA/MFMA where appropriate.
  5. Link Topics Together

    • Show how weak governance can lead to poor controls and higher risk of audit qualifications;
    • Show how combined assurance supports the board in discharging its responsibilities.
  6. Memorise Key Lists Intelligently

    • Duties of directors (fiduciary, care/skill);
    • Responsibilities of audit committee;
    • Components of COSO;
    • Limitations of internal control.

Instead of rote learning, connect each item to a practical example so you can recall and apply it under exam pressure.

These ACC4000H Governance, Audit & Control study notes, framed for UCT BCom Financial Accounting but cross‑aligned with modules such as UNISA AUE3703 Governance in Audit and CUT AUA40AS Auditing & Assurance, provide a comprehensive conceptual base, practical frameworks, and exam‑oriented structures. Mastery of these concepts and their application to realistic scenarios is critical for excelling in governance, audit and control assessments across South African universities.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare