These notes are tailored for Walter Sisulu University (WSU) BCom (Accounting) students registered for AUD221 / Auditing 2B, but they are also highly relevant for South African students in equivalent modules such as UNISA AUE2602 / AUE2601, CUT AUD20B0 / AUI20BT, and similar second-year auditing papers. The focus is on the core examinable areas: the audit process, planning and risk assessment, internal control and tests of control, substantive procedures for major transaction cycles, and completion and reporting. Emphasis is placed on SAICA/IRBA-based principles, ISA-compliant terminology, and common exam-style applications typical of South African universities.
1. The External Audit Environment and Overall Audit Process
Second-year auditing at WSU and other South African universities builds on introductory concepts from first-year modules (such as WSU’s AUD111 / Auditing 1A or UNISA’s AUE1501) and deepens understanding of the external audit function, especially within the South African regulatory and professional framework.
1.1 Purpose and Objectives of an External Audit
The primary purpose of an external audit is to enhance the degree of confidence of intended users in the financial statements. This is achieved by expressing an independent opinion on whether the financial statements are prepared, in all material respects, in accordance with an applicable financial reporting framework (in South Africa, typically IFRS or IFRS for SMEs).
Key objectives:
- Obtain reasonable assurance that the financial statements as a whole are free from material misstatement, whether due to fraud or error (ISA 200).
- Report on the financial statements and communicate in accordance with the auditor’s findings.
- Support the credibility of financial information used by:
- Equity investors and prospective investors.
- Lenders, including banks and other credit providers.
- Regulatory bodies (e.g. CIPC, SARS).
- Other stakeholders (employees, trade unions, suppliers, customers).
Reasonable assurance is a high, but not absolute, level of assurance. It recognises that the audit is subject to inherent limitations, such as use of sampling, judgement, and limitations of internal control.
1.2 Reasonable Assurance and Inherent Limitations
Understanding inherent limitations is frequently examined in AUD221, often via short theory questions or scenario-based application.
Main sources of inherent limitations:
-
Nature of financial reporting
- Use of judgement and estimates (e.g. provisions, impairments, fair values).
- Complexity of accounting standards.
- Potential management bias in applying accounting policies.
-
Nature of audit procedures
- Reliance on sampling instead of 100% testing.
- Use of inquiry and analytical procedures, which may not reveal all misstatements.
- Possibility of collusion that can circumvent control activities (e.g. segregation of duties).
-
Timeliness and cost-benefit constraints
- Audits must be completed within deadlines and at reasonable cost, limiting the extent of testing.
- Management may restrict physical access at certain times (e.g. stock counts), making certain procedures difficult.
Exam tip (AUD221 and AUE2602 style): Be able to explain reasonable assurance and inherent limitations, and apply them to a brief scenario, e.g. a case where a fraud was not detected and users claim the auditor “guaranteed” correctness of statements.
1.3 The Regulatory and Professional Framework in South Africa
For WSU BCom Accounting students, familiarity with the South African environment is essential:
- IRBA (Independent Regulatory Board for Auditors) – Regulates Registered Auditors (RAs), issues audit pronouncements, and enforces ethical standards.
- SAICA (South African Institute of Chartered Accountants) – Professional body for CAs(SA), co-issues guidance and codes with IRBA.
- Companies Act 71 of 2008
- Prescribes which companies must be audited (e.g. public companies, some private companies based on Public Interest Score).
- Regulates auditor appointment, rotation, and independence.
- ISAs (International Standards on Auditing) – Adopted in South Africa; core standards for AUD221 include:
- ISA 200 – Overall objectives of the independent auditor.
- ISA 210 – Agreeing the terms of audit engagements.
- ISA 220 – Quality control for an audit.
- ISA 230 – Audit documentation.
- ISA 240 – Auditor’s responsibilities relating to fraud.
- ISA 315 (Revised) – Identifying and assessing risks of material misstatement.
- ISA 330 – Responses to assessed risks.
- ISA 500 series – Audit evidence, sampling, external confirmations, etc.
- ISA 700/705/706 – Auditor’s reports.
1.4 The Overall Audit Process: From Engagement to Report
AUD221 expects students to understand and describe a typical audit cycle. Although terminology may differ slightly across WSU, UNISA (e.g. AUE2602), and CUT modules, the core stages are consistent:
-
Pre-engagement activities
- Evaluate acceptance and continuance of client relationships (ISA 220).
- Consider integrity of management, risk profile of the entity, competence of the firm.
- Address independence threats and safeguards.
-
Engagement terms
- Agree terms with those charged with governance.
- Prepare and sign audit engagement letter (ISA 210) covering:
- Objective and scope of the audit.
- Responsibilities of auditor and management.
- Applicable financial reporting framework.
- Expected form and content of reports.
-
Planning
- Develop overall audit strategy (ISA 300).
- Draft a detailed audit plan with specific procedures.
- Understand entity and environment; assess risks.
-
Risk assessment and internal control evaluation
- Perform risk assessment procedures (inquiries, analytical procedures, observation and inspection).
- Understand and document internal control relevant to the audit.
- Assess control risk and overall risk of material misstatement (ROMM).
-
Design and performance of responses
- Tests of control (if relying on controls).
- Substantive procedures (substantive analytical procedures and tests of details).
- Focus on assertions (existence, completeness, accuracy, valuation, rights and obligations, presentation and disclosure).
-
Completion
- Evaluate the sufficiency and appropriateness of audit evidence.
- Review subsequent events and going concern.
- Accumulate and evaluate misstatements.
- Obtain written representations from management (ISA 580).
-
Reporting
- Form an audit opinion (ISA 700).
- Modify the opinion where necessary (ISA 705).
- Include Emphasis of Matter or Other Matter paragraphs if needed (ISA 706).
1.5 Roles and Responsibilities: Management, Those Charged with Governance, Auditor
Auditing exams frequently test understanding of who is responsible for what.
Management responsibilities:
- Preparation and fair presentation of financial statements in accordance with the applicable framework.
- Design, implementation, and maintenance of internal control relevant to the preparation of financial statements free from material misstatement.
- Preventing and detecting fraud and error.
- Providing the auditor with access to all information and persons within the entity.
Those charged with governance (TCWG):
- Oversee the strategic direction of the entity.
- Oversee financial reporting process and internal control (e.g. Board of Directors, Audit Committee).
- Approve the financial statements.
- Oversee the external audit process (appointment, fees, independence considerations).
Auditor responsibilities:
- Conduct the audit in accordance with ISAs and relevant ethical requirements.
- Plan and perform the audit to obtain reasonable assurance that financial statements are free from material misstatement.
- Maintain independence in mind and appearance.
- Exercise professional scepticism and professional judgement.
- Communicate with TCWG (e.g. significant findings, deficiencies in internal control).
Exam-style question pattern (WSU AUD221 / UNISA AUE2602):
- “Explain the respective responsibilities of management and the auditor regarding the prevention and detection of fraud.”
- “Discuss the responsibilities of those charged with governance in relation to the external audit.”
Being able to give clear, concise, ISA-based answers is critical.
2. Audit Planning, Materiality and Risk Assessment
WSU’s AUD221, similar to UNISA’s AUE2602: The Audit Process, places strong emphasis on planning, materiality, and risk assessment. This section unpacks these interrelated topics.
2.1 Audit Planning and the Overall Audit Strategy
ISA 300 requires proper planning to ensure that the audit is performed in an effective and efficient manner.
Key planning outputs:
-
Overall audit strategy
- High-level decisions on:
- Scope (which locations, components, periods).
- Timing (interim vs year-end testing).
- Direction (areas of focus and significant risk).
- Resources (staffing levels, expertise, use of specialists or internal audit work).
- High-level decisions on:
-
Detailed audit plan (programme)
- Nature, timing, and extent of further audit procedures (tests of control and substantive procedures).
- Specific procedures per account balance / transaction cycle.
- Allocation of tasks to individual team members (e.g. senior, junior, manager).
Planning procedures (often examinable as “procedures you will perform during planning”):
- Perform risk assessment procedures:
- Inquiries of management and others (e.g. internal audit).
- Analytical procedures (e.g. ratio analysis, trend analysis).
- Observation and inspection (e.g. factory visit, review of internal reports).
- Obtain an understanding of:
- The entity and its environment.
- The entity’s internal control.
- The entity’s accounting policies and financial reporting framework.
- Determine materiality levels.
- Assess risk of material misstatement at financial statement and assertion levels.
- Develop responses to assessed risks.
2.2 Materiality: Concept, Levels, and Revisions
Materiality is central to AUD221 and equivalent modules. Examiners often expect clear definitions, numerical application, and the ability to recalculate when circumstances change.
Definition (ISA 320):
Information is material if omitting, misstating, or obscuring it could reasonably be expected to influence the economic decisions of users taken on the basis of the financial statements.
Types and levels of materiality:
-
Overall materiality (planning materiality)
- Applied to the financial statements as a whole.
- Often based on a chosen benchmark, such as:
- Profit before tax (PBT).
- Revenue.
- Total assets or equity.
- Typical rules of thumb (not in ISAs, but used in practice and exam scenarios):
- 5–10% of PBT.
- 1–2% of revenue.
- 1–2% of total assets.
-
Performance materiality
- Amount set at less than overall materiality.
- Used to reduce to an appropriately low level the probability that:
- The aggregate of uncorrected and undetected misstatements exceeds overall materiality.
- Usually a percentage of overall materiality, e.g. 75–90%.
-
Specific materiality
- Lower materiality for particular classes of transactions, account balances or disclosures where misstatements of lesser amounts could influence users (e.g. related party transactions, directors’ remuneration).
-
Tolerable misstatement
- Practical application of performance materiality at account balance or class of transaction level in audit sampling.
Illustrative example:
Assume a WSU student is given the following scenario in an AUD221 exam:
- Profit before tax: R4 000 000.
- Revenue: R80 000 000.
- Total assets: R60 000 000.
The auditor selects PBT as the benchmark and applies 5%.
- Overall materiality = 5% × R4 000 000 = R200 000.
- Performance materiality = 75% of overall materiality = 0.75 × R200 000 = R150 000.
If misstatements accumulate above R150 000, the risk of exceeding overall materiality (R200 000) increases significantly.
Revising materiality:
- Materiality is set at planning but must be revised if:
- Actual results differ significantly from the initial estimates (e.g. final profit is far lower).
- New information comes to light, such as discovery of fraud or major errors.
- ISA 320 requires that both overall materiality and performance materiality be updated and the audit plan adjusted accordingly.
2.3 Audit Risk Model and Components of Risk
Most universities, including WSU, UNISA (AUE2602), and CUT (AUD20B0), examine the audit risk model in some form.
Audit risk model:
Audit Risk (AR) = Inherent Risk (IR) × Control Risk (CR) × Detection Risk (DR)
-
Inherent Risk (IR)
- Susceptibility of an assertion to a misstatement that could be material, assuming there are no related controls.
- Influenced by:
- Nature of the account/item (e.g. cash is inherently more risky than furniture).
- Complexity and judgement involved (e.g. derivatives, provisions).
- Industry conditions (e.g. rapidly changing technology).
-
Control Risk (CR)
- Risk that a misstatement that could occur in an assertion and that could be material will not be prevented, or detected and corrected, on a timely basis by the entity’s internal control.
- Lower if strong, effective controls exist and operate consistently.
- Higher if controls are weak, not designed properly, or not implemented.
-
Detection Risk (DR)
- Risk that the auditor’s procedures will not detect a misstatement that exists and could be material.
- Unlike inherent and control risk, detection risk is influenced by the auditor (through the nature, timing and extent of audit procedures).
Interactions in practice:
-
If IR and CR are high, ROMM is high; therefore, the auditor must set detection risk low by:
- Increasing the extent of testing.
- Performing more effective procedures (e.g. confirmations vs merely inspecting documents).
- Performing procedures at year-end rather than at interim.
-
If IR and CR are low, detection risk can be set higher; the auditor may:
- Use more analytical procedures.
- Reduce sample sizes.
- Perform some testing at interim.
Exam application:
Students might be given a scenario describing, for example, a small retail business in Mthatha with poor documentation. The question may require:
- Identification of factors increasing inherent risk (e.g. high cash turnover).
- Evaluation of control risk given described weak controls.
- Explanation of how the auditor should respond in terms of detection risk (e.g. more extensive substantive tests).
2.4 Risk Assessment Procedures and Understanding the Entity
ISA 315 (Revised) sets out procedures to identify and assess the risks of material misstatement through understanding the entity and its environment.
Risk assessment procedures:
-
Inquiries
- Discuss with management, internal audit, and other employees.
- Ask about:
- Business risks.
- Fraud risk factors.
- Changes in operations.
- Significant transactions near year-end.
-
Analytical procedures
- Compare current period numbers with:
- Prior periods.
- Budgets/forecasts.
- Industry benchmarks.
- Calculate key ratios (e.g. gross profit %, inventory days, debtor days) and investigate unexpected fluctuations.
- Compare current period numbers with:
-
Observation and inspection
- Observe processes (e.g. stock counting procedures).
- Inspect documents (e.g. internal reports, management minutes).
- Tour premises to understand operations.
Understanding the entity and its environment:
- Industry, regulatory, and other external factors:
- State of the South African economy.
- Changes in tax laws (SARS regulations).
- Industry competition and technological changes.
- Nature of the entity:
- Organisational structure and governance.
- Types of products/services (e.g. WSU cafeteria supplier vs large manufacturing entity).
- Major revenue sources and customers.
- Objectives and strategies and related business risks:
- Expansion into new markets.
- Cost-cutting strategies affecting internal control.
- Measurement and review of financial performance:
- Key performance indicators used by management.
- Bonuses based on profit, which may increase risk of earnings management.
- Internal control:
- Control environment, risk assessment process, information systems, control activities, monitoring.
2.5 Identifying and Assessing Risks of Material Misstatement
After performing risk assessment procedures and obtaining an understanding of the entity, the auditor must:
-
Identify risks of material misstatement at:
- Financial statement level (e.g. risk relating to going concern, management override).
- Assertion level (for classes of transactions, account balances and disclosures).
-
Determine which risks are significant risks, requiring special audit consideration (ISA 315). Indicators include:
- Risk of fraud.
- Significant non-routine transactions.
- Significant related party transactions.
- Significant judgements or estimation uncertainty.
Documenting risks:
In exams, you may be required to list and explain likely risks. For example, for a small manufacturing entity in East London that recently changed its inventory system, assessed risks could include:
- Risk of inventory overstatement due to faulty new system – affects existence and valuation assertions.
- Risk of cut-off errors around year-end due to confusion with the new system – affects completeness and accuracy of cost of sales.
- Risk of IT-related errors or unauthorised program changes.
Exam technique:
- State the risk clearly.
- Link it to:
- A specific financial statement assertion (e.g. existence, completeness, valuation).
- A relevant account balance or class of transactions.
- Where required, propose appropriate audit responses, which will be further explored in later sections.
3. Internal Control, Tests of Control and the Control Environment
AUD221 students must be able to explain, evaluate and test internal controls. This section builds the skills needed to understand control systems and design tests of control.
3.1 Components of Internal Control (Based on COSO)
The widely used framework for internal control (including in South African textbooks used at WSU, UNISA and CUT) describes five components:
-
Control Environment
- Sets the tone at the top (“tone of the organisation”).
- Includes:
- Integrity and ethical values.
- Board and audit committee participation.
- Management’s philosophy and operating style.
- Organisational structure and assignment of authority/responsibility.
- Human resource policies and practices (hiring, training, promotion).
-
Entity’s Risk Assessment Process
- How management identifies and responds to business risks.
- Includes formal risk registers, risk committees, and documented risk responses.
-
Information System and Communication
- Financial and non-financial information systems (e.g. accounting software like Sage or Pastel).
- Procedures for capturing and processing transactions.
- Communication channels (e.g. policies, memos).
-
Control Activities
- Specific policies and procedures to address risks.
- Common types:
- Authorisation (e.g. credit limit approvals).
- Performance reviews (e.g. budget vs actual analysis).
- Information processing controls (e.g. edit checks, automated calculations).
- Physical controls (e.g. locks, safes, segregation of duties).
- Segregation of duties (custody, recording, authorisation).
-
Monitoring of Controls
- Ongoing and periodic evaluation of control performance.
- Activities of internal audit, management review of control reports, follow-up on control deficiencies.
3.2 Understanding and Documenting Internal Control
In AUD221 and similar courses like UNISA AUE2602 and CUT AUD20B0, students are taught several methods for documenting the client’s internal control:
-
Narratives
- Written descriptions of the system.
- Simple but can be lengthy and difficult to interpret.
-
Flowcharts
- Visual diagrams showing flow of documents and data.
- Helpful for identifying weaknesses like missing authorisation or inadequate segregation of duties.
-
Internal control questionnaires (ICQs)
- Structured set of questions on controls.
- Typically phrased so that a “Yes” answer indicates a strong control.
- Follow-up questions gather detail on how controls operate.
-
Checklists
- Lists of key controls that should be present.
- Used particularly for compliance with regulatory requirements (e.g. Companies Act).
Exam application:
A common question type is “Describe the internal controls you would expect to find over the cash receipts cycle at XYZ (Pty) Ltd” or “Identify control weaknesses in the following narrative and recommend improvements.”
3.3 Control Environment and Its Audit Implications
The control environment influences the effectiveness of specific control activities. A strong control environment might feature:
- Ethical leadership with a clear code of conduct.
- An active, independent audit committee.
- A culture of compliance with policies and procedures.
- Strong HR policies, including background checks for employees dealing with cash.
Conversely, a weak control environment might be characterised by:
- Dominant CEO with minimal oversight.
- No internal audit function for a fairly large, complex entity.
- No segregation of duties because management “trusts” staff.
- High staff turnover and lack of formal training.
Audit implications:
-
Strong control environment:
- May support a lower assessed control risk.
- Auditor might rely more on controls (perform more tests of control).
-
Weak control environment:
- Control risk likely to be high.
- Auditor will rely less on controls and more on substantive procedures.
- Increased professional scepticism and perhaps need for more experienced staff on the engagement.
3.4 Designing and Performing Tests of Control
ISA 330 requires the auditor to design and perform tests of controls when:
- The auditor’s risk assessment includes an expectation that the controls are operating effectively, or
- Substantive procedures alone cannot provide sufficient appropriate audit evidence (e.g. for completeness of revenue in some settings).
Nature of tests of control:
- Inquiry (asking personnel about how they perform controls).
- Observation (watching control procedures being performed, e.g. stock counts).
- Inspection (examining documents and records for evidence that controls operated, e.g. evidence of review and authorisation).
- Re-performance (independently executing the control, e.g. re-performing bank reconciliations).
Designing tests of control – example for credit sales:
Important controls might include:
- Credit approval by a credit controller prior to dispatch.
- Matching of sales orders, delivery notes, and invoices.
- Sequentially pre-numbered documents with completeness checks.
- Independent review of monthly aged debtors list.
Tests of control could involve:
- Selecting a sample of sales transactions and inspecting:
- Evidence of prior credit approval.
- Matching of order, delivery note and invoice.
- Sequential continuity of invoice numbers.
- Observing month-end procedures for generating and reviewing debtors ageing.
Sampling in tests of control:
- Often use attribute sampling to test frequency of deviation.
- Example: To test whether credit limits are approved, select a sample of 60 transactions and inspect for approval signatures.
- Evaluate whether deviations are within tolerable rates; if deviation rate is too high, control may not be reliable.
3.5 Limitations of Internal Control and Control Deficiencies
Even a well-designed system of internal control has inherent limitations, such as:
- Human error due to fatigue, misunderstanding or neglect.
- Collusion between employees to circumvent controls.
- Management override of controls (e.g. CEO bypasses procurement procedures).
- Controls becoming outdated with changes in systems or business processes.
Control deficiencies:
- Control deficiency: Design or operation of a control does not allow timely prevention, or detection and correction of misstatements.
- Significant deficiency: Important enough to merit attention by those charged with governance.
- Material weakness (term more common in US GAAS, but conceptually similar): Reasonable possibility that material misstatement will not be prevented or detected.
Communication of deficiencies:
- Auditor must communicate significant deficiencies in internal control to management and TCWG (ISA 265).
- Written communication includes:
- Description of deficiency.
- Potential effects (risks).
- Suggestions for remedial action.
Exam perspective:
WSU AUD221 exams often require students to:
- Identify control weaknesses in a narrative (e.g. “The same person receives cash, records receipts, and does bank reconciliations.”).
- Explain the risk/implication (e.g. increased risk of misappropriation and concealment).
- Recommend an improvement (e.g. segregation of duties; independent review of bank reconciliations).
Being able to present answers in three-column format (weakness, implication, recommendation) is very useful.
4. Substantive Procedures for Major Transaction Cycles and Balances
Substantive procedures are designed to detect material misstatements at assertion level. AUD221 at WSU and similar modules like UNISA AUE2602 and CUT AUD20B0 place extensive emphasis on practical procedures for the main transaction cycles.
4.1 Substantive Procedures: Nature and Types
There are two main types of substantive procedures:
-
Tests of details
- Involve inspecting documents, confirming balances, recalculating amounts, re-performing computations, physically examining assets, and inquiring of third parties.
- Focus on individual transactions or balances.
-
Substantive analytical procedures
- Evaluation of financial information by studying relationships among data.
- Include ratio analysis, trend analysis, and reasonableness tests (e.g. comparing payroll costs to average number of employees and average salaries).
Substantive procedures are designed to address specific assertions:
- Existence/Occurrence.
- Completeness.
- Rights and Obligations.
- Accuracy.
- Valuation and Allocation.
- Cut-off.
- Presentation and Disclosure.
4.2 Revenue and Receivables Cycle
Revenue recognition and trade receivables are highly significant and high-risk areas.
4.2.1 Common Risks
- Overstatement of revenue to meet targets (existence/occurrence).
- Cut-off errors near year-end (existence and completeness).
- Bad debts not adequately provided for (valuation).
- Fictitious customers to conceal fraud (existence, rights and obligations).
4.2.2 Substantive Procedures – Revenue
-
Substantive analytical procedures
- Compare current year sales with prior years and budgets.
- Analyse gross profit margins by product line; investigate unusual changes.
- Compare monthly/weekly sales trends; identify spikes around year-end.
-
Tests of details of transactions
- Occurrence: Select a sample of recorded sales (from sales journal) and:
- Trace to matched shipping documents and customer orders.
- Inspect for authorised credit terms.
- Completeness: Select a sample of shipping documents around year-end and:
- Trace to sales invoices and to the sales journal.
- Investigate any goods dispatched without being invoiced.
- Cut-off: Test transactions in the few days before and after year-end:
- Ensure goods dispatched before year-end are recorded as sales in current year.
- Ensure goods dispatched after year-end are not recorded prematurely.
- Occurrence: Select a sample of recorded sales (from sales journal) and:
-
Presentation and disclosure
- Inspect financial statements for:
- Correct classification of revenue by segment (if applicable).
- Adequate disclosure of revenue recognition policies.
- Inspect financial statements for:
4.2.3 Substantive Procedures – Trade Receivables
-
External confirmations (ISA 505)
- Positive confirmations: Ask customers to confirm the balance, or state their own figure, whether they agree or disagree.
- Negative confirmations: Ask customers to respond only if they disagree (used where risk is lower and control is strong).
- Select a sample of trade receivable balances at year-end; send confirmations; follow up non-responses (e.g. by alternative procedures such as examining subsequent receipts).
-
Subsequent receipts testing
- Inspect cash receipts after year-end; trace to the year-end debtor balances.
- Provides evidence of existence and valuation.
-
Review of aged debtors list
- Evaluate the ageing of balances (e.g. current, 30 days, 60 days, 90+ days).
- Identify long-outstanding balances for further investigation.
-
Allowance for doubtful debts
- Evaluate management’s basis for the allowance:
- History of bad debts.
- Age analysis.
- Specific problematic customers.
- Recalculate allowance per the entity’s policy and compare to recorded allowance.
- If possible, inspect correspondence with major overdue debtors (e.g. letters of demand).
- Evaluate management’s basis for the allowance:
-
Rights and obligations
- Inquire whether receivables have been factored or pledged as security.
- Inspect bank loan agreements for covenants involving trade receivables.
4.3 Purchases, Payables and Inventory Cycle
The purchases and payables cycle, often integrated with inventory, is another frequently examined area.
4.3.1 Purchases and Payables
Key risks:
- Understatement of liabilities (completeness).
- Incorrect recognition of expenses vs capital (classification).
- Fictitious suppliers and payments to shell companies (existence, accuracy).
Substantive procedures – trade payables:
-
Completeness
- Perform search for unrecorded liabilities:
- Inspect post-year-end payments; trace to supporting documents; determine if related to pre-year-end goods/services.
- Inspect unmatched goods received notes (GRNs) around year-end; ensure liabilities recorded in correct period.
- Reconcile supplier statements to the trade payables ledger and investigate reconciling items.
- Perform search for unrecorded liabilities:
-
Existence and accuracy
- Select a sample of recorded payables and trace to supplier invoices, GRNs and purchase orders.
- Confirm selected balances with key suppliers (especially those with large or unusual balances).
-
Cut-off
- Test purchases and payables recorded in the last few days before and after year-end to ensure correct period recognition.
-
Analytical procedures
- Compare gross margin with previous periods to detect potential misclassification or understatement of purchases.
- Analyse ratios such as creditors days; investigate unexpected shifts.
4.3.2 Inventory
Inventory is a high-risk balance, particularly in manufacturing and retail entities common in South African contexts (e.g. small factories in East London, wholesalers in Mthatha).
Key risks:
- Overstatement due to inclusion of obsolete or damaged items (valuation).
- Incorrect cut-off of purchases and sales affecting inventory and cost of sales.
- Physical theft or shrinkage (existence).
Participation in physical inventory count (ISA 501):
- Auditor attend the client’s year-end stock count to:
- Evaluate the counting instructions and procedures.
- Observe the performance of management’s count procedures.
- Inspect inventory and perform test counts.
- Identify obsolete or slow-moving items.
Key procedures:
-
Before the count
- Review counting instructions for proper controls:
- Segregation of counting teams.
- Pre-numbered count sheets.
- Procedures for dealing with damaged items.
- Discuss with management any areas of special risk (e.g. high value stores).
- Review counting instructions for proper controls:
-
During the count
- Observe adherence to counting instructions.
- Perform test counts:
- From floor to count sheets (existence).
- From count sheets to floor (completeness).
- Note any damaged, obsolete or slow-moving inventory for valuation considerations.
- Confirm that goods held on consignment from third parties are excluded from counts.
-
After the count
- Obtain final inventory listings and reconcile them to test counts.
- Test mathematical accuracy of the inventory compilation.
Valuation tests:
- For a sample of items:
- Agree quantities to count sheets.
- Verify unit cost to purchase invoices (for bought-in goods) or cost sheets (for manufactured goods).
- Compare costs with net realisable value (NRV) – e.g. selling price less costs to complete and sell.
- Identify items where NRV < cost and check whether adequate write-downs are recorded.
Cut-off procedures:
- Test deliveries and dispatches around year-end:
- Ensure purchases recorded in correct period by matching GRNs and purchase invoices.
- Ensure sales recorded in correct period by matching dispatch notes and invoices.
4.4 Cash and Bank
Cash is inherently risky due to its liquidity and susceptibility to misappropriation.
Key risks:
- Misappropriation of cash received (existence).
- Unrecorded cash receipts (completeness).
- Unrecorded bank accounts or overdraft facilities.
Substantive procedures – bank:
-
Bank confirmations
- Send standard bank confirmation letters to each bank with which the client has accounts.
- Confirm:
- Balances of current and savings accounts.
- Loans, overdrafts, guarantees, and contingent liabilities.
-
Bank reconciliations
- Obtain year-end bank reconciliations prepared by the client.
- Check:
- Mathematical accuracy of the reconciliation.
- Balance per books agrees with general ledger.
- Balance per bank statement agrees with actual bank statement.
- Test reconciling items:
- Outstanding cheques – trace to cash book entries and subsequent bank statements to ensure they cleared.
- Deposits in transit – trace to subsequent bank statement deposits.
-
Cut-off tests
- Check last few days’ cash receipts and payments to ensure recorded in correct period.
-
Cash on hand
- Perform year-end cash count at all petty cash locations.
- Reconcile counted amount to petty cash imprest.
- Inspect petty cash vouchers for reasonableness.
4.5 Property, Plant and Equipment (PPE)
PPE is generally material in companies in South Africa, especially manufacturing and transport entities.
Key risks:
- Wrong capitalisation of repairs (classification and valuation).
- Omitted or unrecorded disposals (existence and completeness).
- Incorrect depreciation and residual values (valuation).
Substantive procedures – PPE:
-
Existence
- Physically inspect a sample of significant assets.
- Compare asset numbers on the floor to asset register listings.
-
Completeness
- From the floor, select assets and trace back to the asset register (to detect unrecorded items).
- Review repairs and maintenance expense accounts for items that should have been capitalised.
-
Additions
- Select a sample of additions during the year:
- Inspect supplier invoices or contracts.
- Confirm proper authorisation.
- Ensure correct classification (e.g. building vs equipment).
- Select a sample of additions during the year:
-
Disposals
- Review asset register for disposals.
- Inspect supporting documentation for sale proceeds.
- Recalculate gain or loss on disposal.
-
Depreciation
- Obtain schedule of depreciation.
- Recalculate depreciation for selected assets considering:
- Cost.
- Useful life.
- Residual value.
- Method (straight-line, reducing balance).
- Assess whether useful lives and residual values are reasonable and consistent with prior periods.
-
Impairment
- Inquire of management regarding indicators of impairment (e.g. idle assets, obsolescence).
- If necessary, review impairment calculations and evaluate for reasonableness.
5. Audit Completion, Evaluation of Misstatements and Reporting
Completion and reporting are crucial components of AUD221 at WSU and analogous modules at UNISA (AUE2602) and CUT (AUD20B0). This final section focuses on tasks usually performed towards the end of the audit and on the audit report itself.
5.1 Completing Fieldwork and Subsequent Events
Towards completion, the auditor must gather additional evidence regarding events occurring after the reporting date but before the date of the auditor’s report (ISA 560).
Subsequent events:
- Adjusting events: Provide additional evidence of conditions that existed at the date of the financial statements (e.g. bankruptcy of a customer that was already in financial difficulty at year-end).
- Non-adjusting events: Relate to conditions that arose after the reporting date (e.g. natural disaster destroying a factory after year-end).
Auditor’s procedures:
- Inquire of management and TCWG about subsequent events.
- Review minutes of board and shareholder meetings held after year-end.
- Review latest interim financial statements or management accounts.
- Inquire of the entity’s lawyers about significant legal developments.
Impact on the audit:
- For adjusting events – financial statements must be adjusted.
- For non-adjusting events – must be disclosed if material.
- If management refuses to adjust/disclose appropriately, the auditor may need to modify the audit opinion.
5.2 Going Concern Assessment
ISA 570 deals with the auditor’s responsibilities relating to going concern. This is particularly relevant in South Africa, where economic challenges and load-shedding can significantly impact businesses.
Management’s responsibility:
- Assess the entity’s ability to continue as a going concern for at least 12 months from the reporting date.
- Prepare financial statements on going concern basis unless management intends to liquidate or cease trading.
Auditor’s responsibilities:
- Evaluate management’s assessment.
- Consider whether there are events or conditions that cast significant doubt on the entity’s ability to continue as a going concern (e.g. recurring losses, negative cash flows, difficulty obtaining financing, legal actions).
Audit procedures:
- Analyse cash flow forecasts and budgets.
- Review loan agreements and compliance with covenants.
- Assess ability to obtain additional funding or refinance.
- Inquire of management regarding future plans (e.g. cost cutting, asset sales).
- Review subsequent events for evidence that supports or undermines going concern assumption.
Reporting implications:
- If there is a material uncertainty related to going concern, and adequate disclosure is provided, include a separate section in the audit report (“Material Uncertainty Related to Going Concern”) but issue an unmodified opinion.
- If disclosure is inadequate, issue a qualified or adverse opinion depending on the severity.
- If the going concern basis is inappropriate, express an adverse opinion.
5.3 Evaluation of Misstatements
Throughout the audit, auditors accumulate identified misstatements (except clearly trivial ones). Near completion, they must evaluate whether the financial statements are materially misstated.
Types of misstatements:
-
Factual misstatements
- There is no doubt; the amount is wrong (e.g. arithmetic error).
-
Judgemental misstatements
- Differences arising from management’s judgements about accounting estimates or selection of accounting policies (e.g. estimated useful lives).
-
Projected misstatements
- Arise from extrapolating misstatements found in a sample to the entire population.
Evaluation process:
- Compare the aggregate of uncorrected misstatements with materiality:
- If aggregate < overall materiality and not indicative of systematic issue, financial statements may still be fairly presented.
- But consider nature and circumstances of misstatements, not just amount.
- Re-assess whether the overall presentation of financial statements remains faithful.
Communication with management:
- Communicate all misstatements (other than trivial) to appropriate level of management.
- Request management to correct them.
- If management refuses to adjust certain misstatements, obtain their reasons and evaluate whether effect is material, individually or in aggregate.
Exam link:
AUD221 and UNISA AUE2602 examinations may present a list of misstatements and require students to:
- Distinguish between factual, projected and judgemental misstatements.
- Decide whether the misstatements are material, individually or in aggregate.
- Indicate the impact on the audit opinion if not adjusted.
5.4 Written Representations
ISA 580 deals with written representations obtained from management.
Purpose:
- Confirm oral representations given during the audit.
- Support other audit evidence, but not a substitute for other procedures.
Typical contents:
- Management’s responsibility for preparation and fair presentation of financial statements.
- Confirmation that all records and information have been made available.
- Confirmation that all known misstatements have been corrected or disclosed.
- Specific representations on matters such as:
- Related party transactions.
- Contingent liabilities.
- Litigation and claims.
- Subsequent events.
- Going concern.
Limitations:
- Written representations do not provide high-quality evidence on their own (they are lower in the hierarchy of reliability).
- If management refuses to provide written representations, this is a scope limitation and usually results in a qualified opinion or disclaimer of opinion depending on severity.
5.5 Auditor’s Report: Types of Opinions
The auditor’s report is the principal output of an external audit. AUD221 students must be able to:
- Describe the structure and content of the ISA 700-compliant report.
- Distinguish between unmodified and modified opinions.
- Identify when emphasis of matter and other matter paragraphs are used.
Unmodified (clean) opinion:
- Issued when the auditor concludes that the financial statements are prepared, in all material respects, in accordance with the applicable framework.
- Standard sections include:
- Opinion.
- Basis for opinion.
- Key Audit Matters (for listed entities).
- Responsibilities of management and TCWG.
- Auditor’s responsibilities.
- Other legal and regulatory requirements.
Modified opinions (ISA 705):
-
Qualified opinion
- Used when:
- Misstatements are material but not pervasive, or
- Inability to obtain sufficient appropriate evidence is material but not pervasive.
- Language: “except for the effects of the matter(s) described…”
- Used when:
-
Adverse opinion
- Used when misstatements are both material and pervasive.
- Financial statements do not present fairly.
- Language: “do not present fairly…”
-
Disclaimer of opinion
- Used when auditor cannot obtain sufficient appropriate audit evidence and the possible effects could be both material and pervasive.
- Or in extreme situations where independence is compromised.
- Language: “we do not express an opinion…”
Emphasis of Matter and Other Matter (ISA 706):
- Emphasis of Matter (EoM):
- Draws users’ attention to a matter appropriately presented or disclosed in the financial statements that is of such importance that it is fundamental to users’ understanding (e.g. major litigation disclosed, significant subsequent event).
- Opinion remains unmodified.
- Other Matter:
- Refers to matters not presented or disclosed in the financial statements, but relevant to users’ understanding of the audit, auditor’s responsibilities, or the auditor’s report (e.g. explanation of why a prior period was audited by another auditor).
Exam applications:
WSU AUD221 and UNISA AUE2602 exam questions might provide scenarios such as:
- Management refuses to adjust a material inventory overstatement.
- Auditor is prevented from attending stock count and cannot perform alternative procedures.
- Material uncertainty exists about going concern but properly disclosed.
Students must:
- Identify the appropriate type of opinion.
- Describe the modifications to the report (e.g. Basis for Qualified Opinion paragraph).
- Indicate whether an EoM paragraph is appropriate.
5.6 Ethics, Independence and Professional Scepticism at Completion
Although ethics are taught across several modules (including introductory courses like WSU’s Accounting Ethics components and UNISA’s AUE1601), AUD221 specifically expects integration of ethics with completion and reporting.
Key ethical requirements:
- Compliance with IRBA Code of Professional Conduct (aligned with IESBA Code).
- Principles:
- Integrity.
- Objectivity.
- Professional competence and due care.
- Confidentiality.
- Professional behaviour.
Independence:
- Both independence of mind and independence in appearance.
- Threats include:
- Self-interest (e.g. large fees, loans to/from audit client).
- Self-review (e.g. preparing financial statements then auditing them).
- Advocacy (e.g. representing client in tax dispute).
- Familiarity (e.g. long association, close relationships).
- Intimidation (e.g. pressure from client to issue clean opinion).
Final evaluation:
At completion, the engagement partner must:
- Review key working papers.
- Ensure that ethical and independence considerations have been addressed.
- Confirm that professional scepticism was maintained throughout:
- Not accepting management explanations without corroboration.
- Evaluating contradictions in evidence.
- Being alert to management bias or possible management override of controls.
These AUD221: Auditing 2B Study Notes align with the core expectations of Walter Sisulu University (WSU) BCom in Accounting, while also providing a strong foundation for students taking comparable modules such as UNISA AUE2602 / AUE2601 and CUT AUD20B0 / AUI20BT. Mastery of these concepts—supported by practice with past papers and case-based questions—will significantly improve exam performance and practical readiness for professional training in South Africa’s auditing environment.
