AUD301: Auditing III Study Notes (Rhodes University BCom Accounting)

These comprehensive AUD301 Auditing III study notes are tailored for Rhodes University (RU) BCom Accounting students, but they also align well with core material tested in UNISA Auditing modules (e.g. AUE3701, AUE3761) and CUT auditing courses. The focus is on higher‑level audit concepts, planning and risk, detailed procedures, reporting, and ethics/quality control, with South African context and references to International Standards on Auditing (ISAs) as adopted locally. Use these notes as an integrated study guide for tests, assignments, and final exams in Auditing III.

1. Advanced Auditing Concepts and the South African Environment

1.1 The Role of Auditing in Corporate Governance

Auditing III builds on basic assurance knowledge by deepening understanding of how auditing supports corporate governance, especially in South Africa’s regulatory environment.

Corporate governance framework in South Africa

  • Companies Act 71 of 2008

    • Establishes requirements for financial reporting, appointment of auditors, audit committees (for certain companies), and auditor rotation.
    • Public companies and some larger private companies are required to be audited.
  • King IV Report on Corporate Governance

    • Encourages principles-based governance: ethical culture, good performance, effective control, and legitimacy.
    • Emphasises the role of the governing body (board) in oversight and the importance of assurance.

Audit’s contribution to governance

  • Enhances credibility: An independent audit opinion on financial statements increases confidence of shareholders, creditors, and regulators.
  • Reduces information asymmetry: Management prepares financial statements; users rely on auditors to assess whether they are free from material misstatement.
  • Supports oversight: Audit findings and management letters provide the audit committee and board with insights into internal control weaknesses and financial reporting risks.
  • Deters fraud and error: The existence of an audit (and the possibility that issues will be detected) exerts a preventive control effect.

Exam focus for AUD301 / UNISA AUE3701 equivalents

Expect questions on:

  • Explaining how auditing supports elements of King IV.
  • The interaction between auditors, audit committees, and internal auditors.
  • The role of assurance in integrated reporting (e.g. ESG and sustainability information).

1.2 Types of Audits and Assurance Engagements

By third‑year (AUD301), students must clearly distinguish between different types of assurance and non‑assurance engagements, with reference to the IAASB framework.

1.2.1 Assurance engagement basics

An assurance engagement involves:

  1. A three-party relationship (practitioner, responsible party, intended users).
  2. A subject matter (e.g. financial statements).
  3. Suitable criteria (e.g. IFRS).
  4. Sufficient appropriate evidence.
  5. A written assurance report.

Reasonable vs limited assurance

  • Reasonable assurance (e.g. statutory audit under ISA 200–700)
    • High, but not absolute assurance.
    • Positive expression: “In our opinion, the financial statements present fairly…”.
  • Limited assurance (e.g. review engagements, key parts of integrated reports)
    • Moderate level of assurance.
    • Negative expression: “Nothing has come to our attention that causes us to believe…”.

1.2.2 Audit vs review vs agreed‑upon procedures

Engagement Type Level of Assurance Report wording Typical South African Use
Statutory Financial Audit Reasonable Positive opinion Public companies, certain private companies
Review Engagement Limited Negative conclusion Smaller companies, voluntary engagements
Agreed‑Upon Procedures (AUP) None (factual) Findings, no opinion Specific matters, e.g. verifying grant spending
Compilation Engagement None No assurance statement Assisting with FS preparation by small practitioners

In exams (at Rhodes or in UNISA AUE3701/AUE3761), you may be asked to:

  • Identify which engagement type is appropriate given a scenario and cost/benefit constraints.
  • Draft extracts of engagement letters with scope and assurance level clearly stated.

1.3 The South African Regulatory and Professional Framework

Key institutions

  • Independent Regulatory Board for Auditors (IRBA)

    • Regulates auditors, sets ethical requirements, issues auditing pronouncements in line with ISAs.
    • Oversees auditor registration, inspections, and disciplinary processes.
  • South African Institute of Chartered Accountants (SAICA)

    • Professional body; issues guidance and supports education, including for BCom Accounting students progressing towards the CA(SA) designation.
  • CIPC (Companies and Intellectual Property Commission)

    • Oversees company compliance with the Companies Act, including filing of annual returns and financial statements.

Applicable standards

  • International Standards on Auditing (ISAs): Adopted by IRBA.
  • International Code of Ethics for Professional Accountants (including International Independence Standards), adapted by IRBA.
  • International Financial Reporting Standards (IFRS): Criteria used for listed and many large entities.

Exam implications

  • Distinguish between statutory requirements (Companies Act, IRBA) and professional requirements (ISAs, ethics).
  • Explain the hierarchy of standards: e.g. ISA, SAAPS (South African Auditing Practice Statements), guidance notes.
  • Discuss mandatory audit firm rotation and partner rotation in the SA context.

1.4 Fundamental Audit Concepts Revisited at Advanced Level

By Auditing III, concepts introduced in earlier modules (e.g. RU’s Auditing I & II, UNISA AUE2601, CUT Auditing II) are examined in greater depth.

1.4.1 Assertions

Financial statement assertions drive audit procedures. At this level, be able to:

  • Link each assertion to specific classes of transactions, account balances, and disclosures.
  • Design procedures that respond to assertion-level risks.

Common assertions:

  • For classes of transactions: occurrence, completeness, accuracy, cut‑off, classification.
  • For account balances: existence, rights and obligations, completeness, valuation and allocation.
  • For presentation and disclosure: occurrence, rights & obligations, completeness, classification & understandability, accuracy & valuation.

1.4.2 Audit risk model

Audit risk (AR) = Inherent risk (IR) × Control risk (CR) × Detection risk (DR)

  • Inherent Risk: Susceptibility of an assertion to misstatement assuming no controls.
  • Control Risk: Risk that a misstatement will not be prevented or detected and corrected by internal control.
  • Detection Risk: Risk that audit procedures will fail to detect a misstatement.

In AUD301 exams, you will:

  • Assess IR and CR based on detailed client information.
  • Decide how much substantive testing is needed by setting acceptable DR.
  • Justify why higher IR leads to more evidence and lower DR.

1.4.3 Professional scepticism and judgement

  • Scepticism: Questioning mind, critically assessing evidence, being alert to contradictions or inconsistencies.
  • Judgement: Weighing evidence, choosing appropriate procedures, deciding on materiality and risk responses.

Strong exam answers often:

  • Comment explicitly on where scepticism should be heightened (e.g. management override, complex estimates, related parties).
  • Discuss competing possibilities and justify selected judgements (e.g. why to classify a risk as significant).

2. Audit Planning, Risk Assessment, and Materiality

2.1 Phases of an Audit: Where Planning Fits

Auditor activities typically follow these phases:

  1. Client acceptance and continuance
  2. Planning (overall strategy and detailed audit plan)
  3. Risk assessment (understanding entity, internal control, identifying risks)
  4. Response to risks (tests of controls and substantive procedures)
  5. Completion (final analytical procedures, review of subsequent events, going concern evaluation)
  6. Reporting

Auditing III (AUD301, UNISA AUE3701, CUT higher-level auditing modules) places heavy emphasis on the planning and risk assessment phases, because these drive audit efficiency and effectiveness.

2.2 Client Acceptance and Ethical Considerations

Before planning, auditors must decide whether to accept or continue with a client.

2.2.1 Pre‑engagement activities

  • Independence check: Confirm no financial, business, or family relationships creating threats to independence.
  • Competence and resources: Assess whether the firm has the expertise and capacity (e.g. sector knowledge, IT auditors).
  • Integrity of management: Gather information from previous auditors (with permission), background checks, discussions with bankers or lawyers.
  • Engagement letter: Document scope, responsibilities, reporting framework, fees, and timelines.

For exam purposes:

  • Given a scenario (e.g. a politically exposed person wants to list a company quickly), you must identify ethical threats and safeguards, and possibly recommend declining the engagement.

2.3 Understanding the Entity and Its Environment (ISA 315)

This is a major component of AUD301 assessment.

2.3.1 Information to obtain

  • Industry, regulatory, and economic factors
    • Market conditions, competition, technology changes, regulatory requirements (e.g. sector‑specific rules).
  • Nature of the entity
    • Business model, major revenue streams, key customers and suppliers, financing structure.
  • Accounting policies
    • IFRS policies, choices in estimates, changes from prior years.
  • Objectives, strategies, and business risks
    • Expansion plans, cost‑cutting, product launches, funding sources.
  • Measurement and performance review
    • Budgets, KPIs, internal management reports.

2.3.2 Internal control system

Understand and document:

  • Control environment: Tone at the top, assignment of authority, HR policies.
  • Entity’s risk assessment process: How management identifies and responds to business risks.
  • Information system: IT systems used, flow of transactions, automated controls.
  • Control activities: Authorisations, reconciliations, segregation of duties.
  • Monitoring controls: Internal audit, management reviews, oversight functions.

In an AUD301 exam, you may be asked to:

  • Produce a narrative description or flowchart of a system (e.g. credit sales).
  • Identify control weaknesses and suggest improvements.
  • Link weaknesses to specific assertion‑level risks.

2.4 Risk Assessment Procedures

Risk assessment procedures are used to obtain an understanding, not primarily to provide audit evidence on assertions.

2.4.1 Required procedures under ISA 315

  1. Inquiries of management and others
  2. Analytical procedures
  3. Observation and inspection

Example analytical procedures

  • Compare current year gross profit percentage to prior years and industry benchmarks.
  • Analyse days receivable outstanding; significant increases may indicate issues with existence, valuation, or cut‑off.
  • Examine trend in operating expenses; unusual fluctuations require explanation.

Examiners often require you to:

  • Design specific analytical procedures given a set of financial information.
  • Interpret results and identify areas for further investigation.

2.5 Identifying and Assessing Risks of Material Misstatement

2.5.1 At financial statement level vs assertion level

  • Financial statement level risks impact overall financial statements (e.g. poor control environment, going concern uncertainties).
  • Assertion level risks relate to specific classes of transactions, account balances, and disclosures.

2.5.2 Significant risks

Risks that require special audit consideration, often due to:

  • Fraud risk (e.g. revenue recognition, management override).
  • Complexity or subjectivity (e.g. fair value of financial instruments).
  • Significant non‑routine transactions (e.g. business acquisitions).

For each significant risk, you must:

  • Document why it is significant.
  • Plan specific responses, often more reliable tests and possibly a lower materiality level.

2.6 Materiality and Performance Materiality

Understanding and applying materiality is core to Auditing III and UNISA AUE3701 exam questions.

2.6.1 Definitions

  • Overall (financial statement) materiality: The maximum misstatement that could exist without affecting decisions of users.
  • Performance materiality: An amount set below overall materiality to reduce the risk that the total of uncorrected and undetected misstatements exceeds overall materiality.
  • Specific materiality: For particular classes of transactions, account balances, or disclosures where smaller misstatements could influence users (e.g. related party disclosures, directors’ emoluments).

2.6.2 Setting quantitative materiality

Common benchmarks used by SA audit firms:

  • 5–10% of profit before tax for profit‑orientated entities.
  • 0.5–1% of revenue for low margin/high turnover entities.
  • 1–2% of total assets for asset‑heavy or non‑profit entities.

Example

  • Profit before tax: R10 000 000
  • Auditor selects 5% as benchmark → Overall materiality = R500 000.
  • Performance materiality might be set at, say, 70% of overall materiality → R350 000, to allow for aggregation of misstatements.

In exams:

  • Show your calculations clearly.
  • Justify chosen benchmarks and percentages based on entity type and risk.
  • Consider qualitative factors: small misstatement may be material if it affects loan covenants, turns a profit into a loss, or involves fraud.

2.7 Documenting the Audit Strategy and Plan

2.7.1 Overall audit strategy

High‑level decisions on:

  • Scope and timing of the audit.
  • Involvement of component auditors (for groups).
  • Use of experts (valuers, actuaries, IT specialists).
  • Allocation of work among team members.

2.7.2 Detailed audit plan

Translates strategy into specific audit programmes for each significant area:

  • Identifies assertions to be tested.
  • Specifies nature, timing, and extent of procedures.
  • Considers whether to perform tests of controls (relying on controls) vs more substantive testing.

Typical exam tasks:

  • Draft parts of an audit plan (e.g. for revenue, inventory, PPE).
  • Explain why certain procedures are scheduled before year‑end vs after year‑end.
  • Adapt plans when new information emerges (e.g. discovery of fraud mid‑audit).

3. Audit Evidence, Procedures, and Use of Technology

3.1 Nature and Quality of Audit Evidence

3.1.1 Sufficiency and appropriateness

  • Sufficiency: Quantity of evidence.
  • Appropriateness: Quality of evidence (relevance and reliability).

Factors affecting sufficiency:

  • Materiality of the item.
  • Assessed risk of misstatement.
  • Quality of controls and reliability of evidence.

Factors affecting reliability:

  • Source (external vs internal).
  • Form (documentary vs oral).
  • Directness (auditor’s direct observation vs indirect).

Hierarchy of reliability

  • High: External evidence obtained directly (e.g. bank confirmations).
  • Medium: Internal evidence supported by effective controls (e.g. system‑generated reports).
  • Low: Verbal representations by management (but may still be necessary).

In AUD301/UNISA AUE3703 exams, you are expected to evaluate evidence quality and justify whether more evidence is needed.

3.2 Types of Audit Procedures

ISA 500 sets out major procedures used to obtain audit evidence:

  1. Inspection (records, documents, tangible assets)
  2. Observation
  3. Inquiry
  4. Confirmation
  5. Recalculation
  6. Reperformance
  7. Analytical procedures

3.2.1 Inspection

  • Examining documents and records (e.g. invoices, contracts) for evidence of occurrence, accuracy, and authorisation.
  • Inspecting tangible assets (e.g. inventory, PPE) to support existence.

Example procedure

  • Inspect a sample of sales invoices to ensure they are supported by signed delivery notes and recorded in the correct period (cut‑off).

3.2.2 Observation

  • Watching a process being performed by others (e.g. inventory count, wage payout).
  • Useful to evaluate controls in operation, but provides evidence only for the time of observation.

3.2.3 Inquiry

  • Seeking information from knowledgeable persons inside or outside the entity.
  • Often combined with other procedures since it alone is not sufficient.

3.2.4 Confirmation

  • Direct written responses from third parties (e.g. bank confirmations, debtor circularisations).
  • Very strong evidence, especially if auditor maintains control over the process.

3.2.5 Recalculation and Reperformance

  • Recalculation: Checking mathematical accuracy of records (e.g. depreciation, interest).
  • Reperformance: Independently executing procedures or controls (e.g. reperforming an aging analysis).

3.2.6 Analytical procedures

  • Evaluation of financial information through analysis of plausible relationships; investigation of fluctuations and inconsistencies.

In exams, be precise: match each assertion to specific procedures and state how many items or what coverage (e.g. 60% of total value).

3.3 Tests of Controls vs Substantive Procedures

3.3.1 Tests of controls

Performed when auditors plan to rely on internal controls to reduce substantive testing. Typical tests:

  • Inquiry and observation of control performance.
  • Inspection of documents for evidence of sign‑off/approval.
  • Reperformance of control activities.

For example:

  • To test the control that all credit notes above R10 000 must be authorised by the financial manager, the auditor:
    • Selects a sample of credit notes above R10 000.
    • Inspects for evidence of the financial manager’s signature.

3.3.2 Substantive procedures

Used to detect material misstatements at assertion level; include:

  • Substantive tests of details (e.g. vouching individual transactions, confirming balances).
  • Substantive analytical procedures (e.g. comparing actual to budget with investigation of significant variances).

Deciding mix of tests:

  • If controls are effective, more tests of controls + fewer substantive tests.
  • If controls are weak, minimal tests of controls and more extensive substantive procedures.

Examiners often ask you to design both tests of controls and substantive procedures for key cycles (revenue, purchases, payroll, inventory).

3.4 Audit Sampling (ISA 530)

In AUD301, sampling is examined quantitatively and qualitatively.

3.4.1 Types of sampling

  • Statistical sampling: Uses probability theory; allows quantification of sampling risk.
  • Non‑statistical sampling: Uses judgement; no statistical evaluation but still needs structured approach.

3.4.2 Sampling methods

  • Random selection: Each item has equal chance (e.g. random number tables, computer selection).
  • Systematic selection: Every nth item, with random start.
  • Haphazard selection: Without conscious bias, but not truly random (non‑statistical).
  • Stratified sampling: Population divided into strata (e.g. by value) and sampled separately.

3.4.3 Determining sample size

Affected by:

  • Tolerable misstatement (lower tolerable misstatement → larger sample).
  • Expected misstatement (higher expectation → larger sample).
  • Risk of over‑reliance/incorrect acceptance (lower risk → larger sample).
  • Population size (less impact, except for very small populations).

Typical exam question:

  • Provide factors affecting sample size and how each factor influences it.
  • Distinguish between sampling risk and non‑sampling risk (e.g. human error, misinterpretation of results).

3.5 Use of Computer-Assisted Audit Techniques (CAATs) and Data Analytics

With increasing IT complexity, Auditing III includes technology-based tools.

3.5.1 CAATs and data analytics

Common tools:

  • Generalized Audit Software (GAS) (e.g. IDEA, ACL) to:
    • Extract and analyse data.
    • Test all transactions instead of sample for specific controls or anomalies.
  • Spreadsheets and pivot tables for ad‑hoc analyses.
  • Automated scripts within ERPs to flag exceptions (e.g. SAP, Oracle).

Examples of CAAT‑based procedures:

  • Identify duplicate invoice numbers to detect potential fraud or error.
  • Test three‑way matches between purchase orders, goods received notes, and supplier invoices.
  • Recalculate interest charges across the loan portfolio.

In exam contexts (RU AUD301, UNISA AUE3703):

  • You may need to propose CAATs procedures to test specific assertions.
  • Explain advantages (e.g. efficiency, coverage) and limitations (e.g. reliance on IT controls, data completeness).

3.6 Working Papers and Documentation (ISA 230)

3.6.1 Purpose of documentation

  • Evidence of auditor’s basis for opinion.
  • Evidence that audit was planned and performed in accordance with ISAs and ethical requirements.
  • Facilitates review and supervision within firm.
  • Supports quality inspections by IRBA.

3.6.2 Content of working papers

  • Planning documentation (materiality, risk assessment).
  • Audit programmes and detailed procedures performed.
  • Evidence obtained and conclusions reached.
  • Significant judgements and discussions with management.

In exams:

  • Be able to explain characteristics of good working papers: clear, complete, logically organised, signed, dated, cross‑referenced.
  • Possibly draft a sample working paper extract based on a given procedure and results (e.g. debtors’ circularisation).

4. Selected Audit Areas: Complex Accounts and Specialised Topics

AUD301 and comparable South African modules (e.g. UNISA AUE3703, CUT Auditing III) often focus on higher-risk and more complex audit areas.

4.1 Revenue and Receivables

4.1.1 Risks and assertions

Revenue is inherently risky due to:

  • Pressure to meet targets and earnings expectations.
  • High volume of transactions.
  • Potential for fictitious revenue, cut‑off errors, or incorrect pricing.

Key assertions:

  • Occurrence: Recorded revenue actually occurred.
  • Completeness: All revenue that occurred is recorded.
  • Accuracy: Amounts and calculations are correct.
  • Cut‑off: Recorded in correct period.
  • Existence and valuation (for receivables).

4.1.2 Tests of controls

Examples for a manufacturing client:

  • Review credit approval procedures for new customers; test sample of new accounts for evidence of credit checks.
  • Observe and inspect separation of duties between order taking, dispatch, invoicing, and cash collection.
  • Reperform control: Ensure that invoices are sequentially numbered and numerical sequence is checked regularly.

4.1.3 Substantive procedures

  • Debtors’ confirmations:
    • Positive confirmations for large/old/overdue balances.
    • Negative confirmations for many small, low‑risk items.
  • Subsequent receipts testing:
    • Check cash received after year‑end against outstanding balances to support existence and valuation.
  • Cut‑off tests:
    • Select dispatch notes before and after year‑end; trace to invoices and ledgers; verify correct period recognition.
  • Analytical procedures:
    • Compare gross profit margins and days sales outstanding to prior years and industry norms.

Examiners may provide extracts of financial data (e.g. from a hypothetical RU case study such as “Grahamstown Traders (Pty) Ltd”) and ask you to:

  • Identify unusual patterns (e.g. spike in year‑end sales).
  • Propose investigative procedures.

4.2 Inventory and Cost of Sales

Inventory often represents a material and high‑risk balance.

4.2.1 Key risks

  • Overstatement of quantity (e.g. poor counts).
  • Obsolete or slow‑moving stock not written down.
  • Incorrect costing (e.g. overhead allocation errors).
  • Cut‑off errors in purchases and sales.

4.2.2 Inventory counts and observation

Auditors typically attend physical stock‑takes:

  • Evaluate count instructions and procedures (e.g. segregation of duties, tag control).
  • Observe counting and test counts:
    • Select items from warehouse floor → trace to count sheets (completeness).
    • Select items from count sheets → trace to warehouse (existence).
  • Note damaged or obsolete inventory and ensure proper identification.

Cut‑off testing

  • At year‑end, inspect last goods received notes (GRNs) and last dispatch notes:
    • Confirm that purchases and sales are recorded in correct period.

Common exam tasks:

  • Identify weaknesses in an inventory count plan.
  • Recommend improvements (e.g. freezing movement, independent supervisors).
  • Design test counts and cut‑off procedures.

4.3 Property, Plant and Equipment (PPE)

Auditing PPE involves both existence and valuation issues.

4.3.1 Key risks

  • Capitalising repairs and maintenance incorrectly (overstatement of assets).
  • Not capitalising appropriate items (understatement).
  • Incorrect depreciation methods and useful lives.
  • Inadequate recording of disposals and impairments.

4.3.2 Procedures

  • Tests of controls:

    • Inspect asset addition authorisations.
    • Verify that changes to asset registers require independent approval.
  • Substantive tests:

    • Additions:
      • Trace from asset register to supplier invoices, contracts, board minutes.
      • Verify classification as PPE vs expense.
    • Existence:
      • Physically inspect a sample of assets from register.
    • Disposals:
      • Trace disposals to sale agreements and removal from register.
    • Depreciation:
      • Recalculate for a sample; assess reasonableness of useful lives.

Exams may include:

  • A PPE note to the financial statements with errors embedded.
  • You must identify potential misstatements and design relevant procedures.

4.4 Provisions, Contingent Liabilities, and Estimates

Provisions and estimates require judgement, posing a high risk of management bias.

4.4.1 Relevant IFRS guidance

  • IAS 37: Provisions, contingent liabilities and contingent assets.
  • IAS 36: Impairment of assets.
  • IFRS 9: Expected credit loss models for financial assets.

4.4.2 Risks

  • Under‑provisioning (to inflate profits).
  • Over‑provisioning (creating “cookie jar” reserves).
  • Non‑disclosure of contingent liabilities.

4.4.3 Auditor procedures

  • Evaluate management’s process for identifying obligations and contingencies.
  • Review board minutes, legal correspondence, and representation letters.
  • For litigation:
    • Obtain lawyer’s letters (with client permission).
    • Discuss likely outcomes and potential financial impact.
  • For impairments:
    • Test assumptions in cash flow forecasts (e.g. growth rates, discount rates).
    • Evaluate consistency with budgets and external market information.

In AUD301 and UNISA AUE3703 exams, the focus is often on:

  • Demonstrating a solid understanding of recognition criteria for provisions.
  • Challenging optimistic or pessimistic assumptions with specific audit responses.

4.5 Group Audits and Component Auditors (ISA 600)

Group audits are standard in advanced auditing courses.

4.5.1 Definitions

  • Group: Parent and all its subsidiaries.
  • Component: An entity or business activity whose financial information is included in group financial statements.
  • Group engagement team: Team responsible for the group audit.
  • Component auditor: Auditor responsible for reporting on a component.

4.5.2 Responsibilities of group auditor

  • Obtain understanding of group, components, and their environments.
  • Assess materiality for group and components.
  • Evaluate competence and independence of component auditors.
  • Provide clear instructions to component auditors (scope, risks, thresholds).
  • Review component auditors’ work to determine extent of reliance.

Exams often ask you to:

  • Explain the division of responsibilities between group and component auditors.
  • Draft examples of instructions to component auditors.
  • Discuss how the group auditor deals with significant components vs non‑significant ones.

4.6 Other Specialised Topics

Depending on the year’s syllabus at Rhodes or overlapping UNISA/CUT content, you may also need to cover:

  • Audits of public sector entities (e.g. Auditor‑General South Africa context).
  • Audits of small and medium‑sized entities (SMEs) – use of ISAs in a proportionate way (ISQC/ISQM scalability).
  • Integrated reporting and sustainability assurance – limited vs reasonable assurance on non‑financial information.

For each, be ready to:

  • Identify unique risks and constraints (e.g. performance objectives in public sector instead of profit).
  • Tailor procedures appropriately.

5. Completion, Audit Reporting, Ethics, and Quality Control

5.1 Audit Completion Activities

Completion procedures ensure that evidence gathered supports the final opinion.

5.1.1 Subsequent events review (ISA 560)

Types of events:

  • Adjusting events: Provide further evidence of conditions that existed at reporting date (e.g. settlement of a court case confirming obligation).
  • Non‑adjusting events: Indicative of conditions arising after year‑end (e.g. major fire, new legislation).

Auditor procedures:

  • Review post year‑end management accounts.
  • Read minutes of directors’ meetings held after year‑end.
  • Inquire of management about any significant events.
  • Review subsequent press releases, analyst reports.

5.1.2 Going concern (ISA 570 (Revised))

Evaluate whether there is significant doubt about the entity’s ability to continue as a going concern for at least 12 months from reporting date.

Procedures:

  • Analyse cash flow forecasts and budgets.
  • Assess assumptions (e.g. revenue growth, cost reductions, refinancing).
  • Review post year‑end performance.
  • Inquire about plans (e.g. raising capital, cost‑cutting).
  • Obtain written representations from management.

If material uncertainties exist:

  • Ensure adequate disclosure in financial statements.
  • Modify audit report if necessary (e.g. include a Material Uncertainty Related to Going Concern section or a qualification if disclosure is inadequate).

Exams typically require:

  • Identification of going concern indicators.
  • Recommended auditor responses, including possible report modifications.

5.2 Evaluation of Misstatements and Communication with Management

5.2.1 Accumulating misstatements

  • All identified misstatements, except clearly trivial, must be accumulated.
  • Auditor must consider whether uncorrected misstatements are material individually or in aggregate.

5.2.2 Communicating misstatements

  • Present a summary of misstatements to management, request adjustments.
  • If management refuses, document reasons and evaluate impact on opinion.

5.2.3 Management representation letter (ISA 580)

  • Written confirmation from management about:
    • Responsibility for financial statements.
    • Completeness of information provided.
    • Specific matters such as contingencies, related parties, fraud.

In exam answers, emphasise that:

  • Representations are not a substitute for other audit evidence.
  • They complement evidence obtained and cover areas where evidence is difficult to obtain.

5.3 Auditor’s Report: Forms and Modifications (ISA 700–706)

Students must be able to draft and interpret standard and modified auditor’s reports.

5.3.1 Unmodified (clean) opinion

Issued when:

  • Financial statements are prepared, in all material respects, in accordance with applicable framework (e.g. IFRS, Companies Act requirements).
  • No material misstatement and no significant limitation in scope.

Basic elements:

  • Title (“Independent Auditor’s Report”).
  • Addressee (e.g. shareholders).
  • Opinion section.
  • Basis for opinion.
  • Key audit matters (for listed entities).
  • Responsibilities of management and auditor.
  • Other legal and regulatory requirements.

5.3.2 Modified opinions (ISA 705)

Types:

  1. Qualified opinion: FS are materially misstated or scope limitation exists, but misstatement is material but not pervasive.
  2. Adverse opinion: Misstatement is material and pervasive.
  3. Disclaimer of opinion: Scope limitation or uncertainty is so severe that auditor cannot obtain sufficient appropriate evidence; misstatements could be pervasive.

Decision framework

  • Is there misstatement or a limitation of scope?
  • Is the impact material? If not material: unmodified.
  • If material: assess pervasiveness to decide between qualified vs adverse/disclaimer.

5.3.3 Emphasis of Matter and Other Matter paragraphs (ISA 706)

  • Emphasis of Matter (EOM):

    • Draws attention to an appropriately disclosed matter of fundamental importance (e.g. major subsequent event, significant uncertainty).
    • Does not modify the opinion.
  • Other Matter:

    • Refers to matters not presented or disclosed in the FS but relevant to users’ understanding of audit, auditor’s responsibilities, or report (e.g. prior period FS audited by another auditor).

Exam questions often provide scenarios requiring:

  • Identification of type of modification (if any).
  • Drafting the correct opinion paragraph and relevant EOM/Other Matter paragraphs.

5.4 Professional Ethics in the South African Context

Ethics is heavily tested at third‑year level (AUD301, UNISA AUE3701/AUE3761, CUT Auditing III).

5.4.1 Fundamental principles

Derived from the IESBA Code as adopted by IRBA:

  1. Integrity
  2. Objectivity
  3. Professional competence and due care
  4. Confidentiality
  5. Professional behaviour

Students must identify threats to these principles and appropriate safeguards.

5.4.2 Types of threats

  • Self‑interest: Financial interest, undue dependence on fees, close business relationship.
  • Self‑review: Auditing own work or that of the firm.
  • Advocacy: Promoting client’s position (e.g. as legal representative).
  • Familiarity: Long association, close relationships.
  • Intimidation: Pressures, threats to replace auditor or withhold fees.

Examples relevant to SA universities’ exam questions

  • A partner in the audit firm holds shares in the client: self‑interest threat.
  • Firm provides bookkeeping and financial statement preparation, then audits: self‑review.
  • Long‑standing friendship with CFO: familiarity threat.
  • Client threatens to switch auditors if certain adjustments are required: intimidation threat.

5.4.3 Safeguards

  • Firm‑level: quality control policies, rotation of partners, training.
  • Engagement‑level: separate teams, reviews by independent partners, consulting with ethics partner.
  • In some cases, declining or resigning from engagement is the only adequate safeguard.

Exams typically test:

  • Identification of threats in realistic scenarios.
  • Proposal of practical safeguards, with reference to IRBA/IESBA guidance.

5.5 Quality Control and Firm‑Level Standards (ISQC 1 / ISQM 1)

Quality control is not just theoretical; it directly impacts the reliability of audit opinions.

5.5.1 Elements of quality control (legacy ISQC 1 structure)

  1. Leadership responsibilities for quality (tone at the top).
  2. Relevant ethical requirements.
  3. Acceptance and continuance of client relationships.
  4. Human resources (recruitment, training, evaluation).
  5. Engagement performance (supervision, review, consultation).
  6. Monitoring (internal inspections, external reviews).

Under the newer ISQM 1 framework (risk‑based approach to quality management), firms must:

  • Establish quality objectives.
  • Identify and assess quality risks.
  • Design and implement responses to manage those risks.
  • Perform ongoing monitoring and remediation.

Although exam syllabi may still refer to ISQC 1, many South African universities (including Rhodes, UNISA, CUT) incorporate ISQM 1 principles, so understand both.

5.5.2 Engagement quality review (EQR)

  • Conducted by an experienced, independent partner.
  • Required for listed entities and other high‑risk engagements.
  • Reviews significant judgements, conclusions, and the proposed auditor’s report.

Exams often ask:

  • Why EQR is necessary in particular high‑risk scenarios (e.g. first‑year audits, those with significant going concern issues).
  • What aspects an EQR partner would review (e.g. significant risk areas, uncorrected misstatements, proposed modifications).

5.6 Communicating with Those Charged with Governance (ISA 260)

Communication with the board or audit committee is essential for accountability and governance.

Matters to communicate

  • Auditor’s responsibilities and scope of the audit.
  • Significant findings:
    • Significant deficiencies in internal control.
    • Significant qualitative aspects of accounting practices.
    • Significant difficulties encountered during the audit.
    • Uncorrected misstatements.
  • Independence issues and safeguards applied.

Exams may include a scenario of a meeting with the audit committee and require you to:

  • List items to be communicated.
  • Explain why they are important for governance.

6. Exam Strategy for AUD301 (Rhodes University) and Related South African Courses

Although each university sets its own assessments, there is strong overlap across Rhodes University AUD301, UNISA AUE3701/AUE3703, and CUT Auditing III.

6.1 Common Themes and Overlapping Topics

Key areas consistently tested:

  • Audit planning and risk assessment (ISA 300, 315).
  • Materiality and audit risk model.
  • Detailed procedures for major cycles (revenue, inventory, PPE, provisions).
  • Sampling and evidence (ISA 500, 530).
  • Audit reporting and modifications (ISA 700–706).
  • Ethics and quality control (IESBA Code, ISQC 1/ISQM 1).
  • Specialised topics: going concern, subsequent events, group audits.

Students at Rhodes often consult online search terms similar to:

  • AUD301 Rhodes University past papers
  • AUE3701 UNISA exam pack
  • CUT Auditing III study guide PDF

These notes consolidate many of the overlapping concepts so you can study once for multiple modules if you later articulate or cross‑register.

6.2 Answering Technique and Application Focus

Lecturers and examiners emphasise application, not just theory.

6.2.1 Use scenario details

  • Quote or paraphrase relevant facts in your answer.
  • Link each risk or procedure explicitly to those facts:
    • “Because sales staff are paid commission based on revenue (scenario, paragraph 3), there is an increased risk of fictitious or prematurely recognised sales.”

6.2.2 Structure answers logically

For risk and procedure questions, a good structure is:

  1. Identify assertion at risk.
  2. Explain why (link to scenario).
  3. Propose specific procedure, including:
    • Action (what will you do).
    • Source (what evidence you use).
    • Purpose (which assertion it addresses).

For ethics questions:

  1. Identify threat(s).
  2. Explain how they breach or could breach a fundamental principle.
  3. Propose safeguards (or withdrawal).

6.3 Time Management and Mark Maximisation

  • Allocate time in proportion to marks; for example, in a 100‑mark exam with 3 hours, average 1.8 minutes per mark.
  • For a 20‑mark section on audit procedures, aim for 20–25 well‑explained points, not one‑line bullet lists.
  • Use headings and numbering to structure long answers; markers at Rhodes, UNISA, and CUT appreciate clarity.

6.4 Integrating Theory with South African Context

When possible, demonstrate awareness of the local environment:

  • Reference to IRBA and Companies Act where relevant.
  • Use Rand amounts and realistic South African examples (e.g. retailers, mining companies, public entities).
  • Recognise practical challenges (e.g. resource constraints in SMEs, transitioning to ISQM 1).

This context makes your answers stronger and more relevant, particularly in an RU BCom Accounting setting with South African focus.

These AUD301: Auditing III study notes (Rhodes University BCom Accounting) provide a comprehensive, exam‑oriented summary of advanced auditing concepts, with strong alignment to related modules at UNISA and CUT. For maximum benefit, combine these notes with past paper practice, your official course materials, IRBA/ISA reference reading, and class examples specific to your institution.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare