AUE2601 is a core auditing module offered by the University of South Africa (UNISA) for BCom Accounting and related qualifications, and its content overlaps closely with similar modules at other South African universities such as CUT (Central University of Technology), NWU, and UJ (for example, AUE2601 UNISA, AUDI201 CUT, and AUI204 NWU). This study guide provides integrated exam notes and explanations aligned with South African syllabi and standards, focusing on auditing theory, the audit process, audit evidence, internal control, and reporting. It is designed to support distance-learning students and exam preparation for mid-year and year-end assessments.
The notes concentrate on the most examinable themes: the nature and purpose of auditing, professional ethics and independence, planning and risk, internal controls and tests of controls, substantive procedures, and the auditor’s opinion and report. Keywords such as “AUE2601 UNISA exam notes”, “AUE2601 past exam questions”, and similar module equivalents at CUT and other universities are naturally integrated to reflect real search behaviour by South African students.
1. Introduction to Auditing Theory (UNISA AUE2601, CUT AUDI201)
Auditing theory underpins the practical procedures performed in real audits. In AUE2601, as well as comparable modules like AUDI201 at CUT and AUI204 at NWU, students are expected to understand what auditing is, why it is necessary in the South African context, and how it differs from other types of assurance and non‑assurance engagements.
1.1 Definition and Objective of an Audit
Definition (ISA 200 / South African context)
An audit of financial statements is an independent examination of the financial statements of an entity, whether profit-oriented or not, conducted with the objective of expressing an opinion on whether the financial statements are prepared, in all material respects, in accordance with the applicable financial reporting framework (e.g. IFRS or IFRS for SMEs).
Key elements of the definition:
- Independent: The auditor must be unbiased and free from undue influence.
- Examination: Involves procedures such as inspection, observation, inquiry, confirmation, recalculation, analytical procedures, and re-performance.
- Financial statements: Statement of financial position, profit or loss and other comprehensive income, changes in equity, cash flows, and notes.
- Material respects: Focus on information that could reasonably influence the decisions of users.
- Applicable framework: IFRS, IFRS for SMEs, or other standards required by law or regulation.
Overall objective of the auditor (ISA 200):
- To obtain reasonable assurance about whether the financial statements as a whole are free from material misstatement, whether due to fraud or error; and
- To express an opinion on the financial statements and report in accordance with the auditor’s findings.
This is a recurring theory question in AUE2601 and similar courses, and you should be able to reproduce it accurately in your own words.
1.2 Reasonable Assurance vs Absolute Assurance
Exams often test understanding of the level of confidence conveyed by an audit opinion.
-
Reasonable assurance:
- High, but not absolute, level of assurance.
- Achieved through a risk-based audit approach.
- Recognises inherent limitations of an audit (time, cost, sampling, internal control limitations, human judgment).
-
Why not absolute assurance?
- Financial statements include estimates and judgment (e.g. impairments, provisions).
- Use of sampling rather than exhaustive testing.
- Possible collusion among staff to override controls.
- Inherent limitations in internal control systems.
- Time and cost constraints; not feasible to test every transaction.
Exam-style explanation often requires:
- Definition of reasonable assurance.
- At least three reasons why absolute assurance is not possible.
- Link to audit risk (the risk that the auditor expresses an inappropriate opinion).
1.3 Audit, Review, and Compilation – Distinguishing Engagement Types
In AUE2601, you must be able to distinguish between different types of engagements frequently referenced in South African practice:
| Engagement Type | Level of Assurance | Nature of Work | Typical Report |
|---|---|---|---|
| Audit (ISA 200) | Reasonable (high) | Detailed testing, risk assessment, evidence | Positive opinion (“in all material respects…”) |
| Review (ISRE 2400) | Limited (moderate) | Primarily inquiry and analytical procedures | Negative assurance (“nothing has come to our attention…”) |
| Compilation (ISRS 4410) | No assurance | Assist management in preparing information | Compilation report; no assurance expressed |
| Agreed-upon procedures (ISRS 4400) | No assurance | Procedures agreed with client; reporting of factual findings only | Factual findings, no conclusion or opinion |
Example exam point:
“Discuss the differences between an audit of financial statements and a review engagement” requires you to mention:
- Different levels of assurance (reasonable vs limited).
- Different procedures (substantive and tests of controls vs mostly inquiries and analytics).
- Wording of the report (positive vs negative assurance).
- Use cases: audits typically required for companies above certain thresholds in South Africa; reviews for smaller entities.
1.4 Users of Audited Financial Statements and Their Needs
Common external users in South African modules like AUE2601 and AUDI201 CUT include:
- Shareholders / investors: Need assurance on profitability, solvency, and going concern to make buy/hold/sell decisions.
- Banks / lenders: Assess credit risk, ability to repay loans, compliance with covenants.
- SARS: Evaluate tax compliance and accuracy of taxable income.
- Suppliers / trade creditors: Evaluate whether the entity can pay accounts when due.
- Employees / unions: Interested in stability, job security, and wage negotiations.
- Regulators (e.g. JSE, FSCA): Monitor compliance with listing requirements and sector regulations.
Why an independent auditor is needed:
- Management prepares financial statements and has an incentive to present results favourably.
- Users are often geographically distant and have no access to underlying records.
- Users often lack accounting expertise or time to evaluate raw financial data.
- An audit reduces information asymmetry and improves the reliability of financial information.
1.5 Types of Audits and Related Services
Beyond statutory financial statement audits, AUE2601 students must recognise different audit classifications:
-
External audit:
- Performed by an independent audit firm (e.g. registered auditors with IRBA).
- Focus on financial statements.
- Required under the Companies Act for certain categories of companies in South Africa.
-
Internal audit:
- Part of the entity’s governance structure.
- Focus on internal controls, risk management, and governance processes.
- Reports to the audit committee or board.
- Internal auditors do not provide a statutory audit opinion on financial statements.
-
Compliance audit:
- Assess compliance with laws and regulations (e.g. environmental laws, B-BBEE codes).
- Common in public sector audits (e.g. Auditor-General of South Africa).
-
Performance audit / value-for-money audit:
- Evaluate economy, efficiency, and effectiveness of programmes or operations.
- Often performed in public sector or large NGOs.
-
Information systems / IT audit:
- Focus on general IT controls (e.g. access controls, change management) and application controls.
- Increasingly examinable given integration with Accounting Information Systems modules at UNISA.
1.6 Limitations of an Audit
A recurring theory question in AUE2601 is: “Explain the inherent limitations of an audit of financial statements.”
Key points:
-
Use of sampling:
- It is impractical to test 100% of transactions; auditors test samples.
- There is a sampling risk that the sample is not representative.
-
Nature of financial reporting:
- Many items require management judgment and estimates (e.g. provisions, fair value).
- Different reasonable judgments may lead to different yet acceptable results.
-
Nature of audit evidence:
- Most audit evidence is persuasive rather than conclusive.
- External evidence is more reliable, but still subject to error or fraud.
-
Limitations of internal control:
- Controls can be overridden by management.
- Collusion between employees can circumvent controls.
-
Time and cost constraints:
- Auditors perform the audit within a defined budget and timeframe.
- Cannot investigate every potential minor issue.
Understanding these limitations helps explain why the auditor provides reasonable, not absolute, assurance and shapes the wording of the audit report.
2. Professional Ethics, Independence and the South African Audit Environment
Ethics and independence are central themes in AUE2601 and similar modules at CUT and other universities (for example, AUDI301 CUT or AUE3703 UNISA build further on these themes). Many exam questions in South African universities are based on scenarios involving threats to independence, ethical dilemmas, and appropriate safeguards.
2.1 Professional Bodies and Regulatory Framework in South Africa
For exam purposes, distinguish between the main professional and regulatory bodies:
-
IRBA (Independent Regulatory Board for Auditors):
- Regulates registered auditors in South Africa.
- Issues auditing pronouncements and enforces the IRBA Code of Professional Conduct.
- Maintains the public register of auditors.
-
SAICA (South African Institute of Chartered Accountants):
- Professional body for CAs(SA).
- Sets standards for training, education, and professional conduct for members.
- Aligns its Code of Professional Conduct with the IESBA Code.
-
CIPC (Companies and Intellectual Property Commission):
- Oversees company registrations and some aspects of corporate governance.
-
Auditor-General of South Africa (AGSA):
- Responsible for auditing public sector entities, national and provincial departments, and municipalities.
AUE2601 focuses on the general ethical framework, but you should know the IRBA Code of Professional Conduct is based on the IESBA (International Ethics Standards Board for Accountants) Code.
2.2 Fundamental Principles of Professional Ethics
The IRBA / IESBA Code sets out five fundamental principles:
-
Integrity
- Be straightforward and honest in all professional and business relationships.
- Example: Not knowingly associating with false or misleading financial information.
-
Objectivity
- Do not allow bias, conflict of interest, or undue influence to override professional judgment.
- Example: Declining to audit a close family member’s company due to conflict of interest.
-
Professional competence and due care
- Maintain professional knowledge and skill at the required level.
- Act diligently and in accordance with applicable technical and professional standards.
- Example: Keeping up to date with new IFRS standards relevant to engagements.
-
Confidentiality
- Respect confidentiality of information acquired as a result of professional relationships.
- Do not disclose such information without proper authority unless there is a legal or professional right or duty to disclose.
- Example: Not revealing client financial details to competitors.
-
Professional behaviour
- Comply with relevant laws and regulations.
- Avoid any conduct that discredits the profession.
- Example: Not making exaggerated claims about services or qualifications.
Exam answers must often explicitly name and define these principles and then apply them to a scenario.
2.3 Threats to Compliance with the Fundamental Principles
Threats can compromise independence and ethical behaviour. The IRBA Code classifies threats into five categories:
-
Self-interest threat
- Financial or other interests improperly influence judgment or behaviour.
- Examples:
- Holding shares in an audit client.
- Significant outstanding fees from a client.
- Dependency on fees from a single client (e.g. >15% of firm revenue).
-
Self-review threat
- Auditing own work or work of your firm.
- Examples:
- Providing bookkeeping services and then auditing the same records.
- Designing internal controls and later auditing those controls.
-
Advocacy threat
- Promoting a client’s position to the point where objectivity is compromised.
- Examples:
- Representing a client in tax disputes with SARS.
- Promoting the sale of client’s shares.
-
Familiarity threat
- Close relationship with client leads to sympathetic or lenient treatment.
- Examples:
- Long association with same client (same partner for many years).
- Close friendship or family relationship with client management.
-
Intimidation threat
- Deterred from acting objectively due to actual or perceived pressures.
- Examples:
- Client threatens to replace the auditor over a disagreement.
- Client management exerts pressure regarding tight deadlines.
In an exam, if asked to “identify and explain threats to independence”, you need to:
- Name each relevant threat category.
- Apply it to the facts of the scenario.
- Mention possible safeguards.
2.4 Safeguards to Reduce Threats to an Acceptable Level
Safeguards are actions that eliminate threats or reduce them to an acceptable level.
Examples of safeguards in the work environment:
-
Firm-level:
- Implement quality control policies (ISQC 1 / ISQM 1).
- Rotation of engagement partners after a prescribed period.
- Internal review of contentious or high-risk engagements.
- Consulting with independent technical experts.
-
Engagement-level:
- Removing an individual from an engagement when a conflict of interest arises.
- Using separate engagement teams for conflicting services.
- Obtaining second partner reviews or hot reviews.
- Declining or terminating the engagement if threats cannot be reduced.
Examples of safeguards at the client level:
- Establishing an active and independent audit committee.
- Clear corporate governance structures.
- Policies for hiring and rotation of key management personnel.
Exam scenarios in UNISA AUE2601 frequently require:
- Identify the threat(s).
- Explain why it is a threat.
- Propose appropriate safeguards.
- Conclude whether the engagement can continue.
2.5 Independence: In Mind and In Appearance
Independence has two dimensions:
-
Independence in mind:
- The state of mind that permits the audit opinion to be expressed without being affected by influences that compromise professional judgment.
- Enables an honest and objective approach.
-
Independence in appearance:
- The avoidance of facts and circumstances that could cause a third party to perceive that independence has been compromised.
Example scenario (typical exam style):
A partner in a firm auditing “Mzansi Retail (Pty) Ltd” holds 5% of the client’s shares. Even if the partner believes they can remain unbiased (independence in mind), the shareholding threatens independence in appearance. The firm should either dispose of the shares or remove the partner from the engagement.
2.6 Confidentiality and Its Exceptions
While confidentiality is a fundamental principle, there are circumstances where auditors may have a right or duty to disclose information, for example:
-
When disclosure is required by law:
- Reporting irregularities under specific South African legislation (for example, the Auditing Profession Act).
- Providing information to a court under subpoena.
-
When permitted by client:
- With the client’s explicit permission, e.g. sharing information with another auditor or tax advisor.
-
When there is a public duty:
- To protect the public interest, e.g. serious health and safety breaches, fraud that materially affects stakeholders, subject to legal advice.
In AUE2601-type exams, a question may describe a scenario where a student must determine whether confidentiality allows or forbids disclosure. Answers should:
- State the general principle.
- Describe applicable exceptions.
- Apply them to the scenario.
- Conclude whether to disclose, and to whom.
2.7 Professional Skepticism and Professional Judgment
Professional skepticism (ISA 200) is an attitude that includes:
- A questioning mind.
- Being alert to conditions indicating possible misstatement due to error or fraud.
- Evaluating audit evidence critically, not accepting information at face value.
Professional judgment is the application of relevant knowledge and experience in making informed decisions about appropriate actions.
Practical application:
- Considering reliability of management explanations.
- Being alert to unusual journal entries at year-end.
- Investigating inconsistencies between different pieces of evidence.
Examiners expect students to reference these concepts when explaining why auditors:
- Do not accept documentation at face value.
- Obtain corroborative evidence.
- Challenge management estimates and assumptions.
3. Audit Planning, Risk Assessment and Materiality (UNISA AUE2601 Core)
Planning is a major component of AUE2601 and similar courses such as AUDI202 at CUT and AUE2602 at UNISA. Exam questions often require descriptions of the planning stages, risk assessment process, and determination of materiality.
3.1 Purpose and Benefits of Audit Planning
Audit planning, required by ISA 300 (Planning an Audit of Financial Statements), aims to:
- Ensure that appropriate attention is devoted to important areas of the audit.
- Identify and manage areas of higher risk of material misstatement.
- Organise and manage the audit engagement effectively and efficiently.
- Assign work properly to team members based on skill and experience.
- Coordinate work with clients and other auditors or experts.
Benefits:
- Avoids last-minute surprises.
- Reduces audit risk to an acceptably low level.
- Ensures compliance with deadlines (e.g. statutory reporting deadlines under Companies Act).
Typical exam task: “Explain the reasons why the auditor should plan the audit of financial statements.” Answers should cover efficiency, risk focus, staffing, co-ordination, and quality control.
3.2 Stages of Audit Planning
Planning is not a single step but an iterative process. Major stages include:
-
Preliminary engagement activities:
- Evaluate whether to accept or continue the engagement.
- Assess independence and ethical compliance.
- Establish an understanding of the terms of engagement.
- Issue or update the engagement letter.
-
Obtaining an understanding of the entity and its environment (ISA 315):
- Nature of the entity (operations, ownership, governance).
- Industry, regulatory, and other external factors.
- Objectives and strategies and related business risks.
- Measurement and review of financial performance.
-
Understanding internal control:
- Control environment (tone at the top, governance, HR policies).
- Risk assessment process.
- Information systems, including related business processes.
- Control activities (authorisation, reconciliations, physical controls).
- Monitoring of controls.
-
Determining materiality and performance materiality (ISA 320):
- Establish an overall materiality level for the financial statements.
- Set performance materiality for specific classes of transactions, account balances, or disclosures.
-
Assessing risks of material misstatement (ISA 315):
- Identify and assess inherent risks and control risks at financial statement and assertion levels.
-
Designing overall audit strategy and detailed audit plan:
- Decide on mix of tests of controls and substantive procedures.
- Determine nature, timing, and extent of audit procedures.
AUE2601 exams frequently require a structured description of planning activities with headings and short explanations.
3.3 Audit Risk Model
Audit Risk (AR) is the risk that the auditor expresses an inappropriate opinion when financial statements are materially misstated.
The classic model:
AR = Inherent Risk (IR) × Control Risk (CR) × Detection Risk (DR)
-
Inherent Risk (IR):
- Susceptibility of an assertion to material misstatement, assuming there are no related controls.
- Factors: complexity, estimation, volume of transactions, susceptibility to theft or fraud.
-
Control Risk (CR):
- Risk that a misstatement that could occur in an assertion and that could be material will not be prevented or detected and corrected timely by the entity’s internal control.
-
Detection Risk (DR):
- Risk that procedures performed by the auditor will not detect a misstatement that exists and that could be material.
Relationship:
- The auditor sets a desired low level of AR.
- As IR and CR increase, DR must decrease (i.e. the auditor performs more or more effective procedures).
- If IR and CR are assessed as lower, DR can be higher (fewer or less extensive procedures).
Exam answers should explain this inverse relationship and give practical examples:
- High inherent risk (e.g. derivatives trading) → low detection risk → extensive substantive testing.
- Strong controls with low control risk (e.g. automated bank reconciliations) → higher detection risk allowed → rely on tests of controls and perform less substantive testing.
3.4 Materiality and Performance Materiality
Materiality is a central planning concept tested heavily in AUE2601 and similar modules across South African universities.
Definition (ISA 320):
Information is material if its omission or misstatement could reasonably be expected to influence the economic decisions of users taken on the basis of the financial statements.
Types of materiality:
-
Overall materiality (financial statement level):
- Often calculated as a percentage of a benchmark such as:
- Profit before tax (e.g. 5%).
- Revenue (e.g. 1%).
- Total assets (e.g. 1–2%).
- Equity (e.g. 1–2%).
- Choice of benchmark depends on the nature of the entity.
- Often calculated as a percentage of a benchmark such as:
-
Performance materiality:
- An amount set at less than overall materiality to reduce to an appropriately low level the probability that the aggregate of uncorrected and undetected misstatements exceeds overall materiality.
- Usually set as a percentage of overall materiality, e.g. 50–75%.
-
Specific materiality:
- For particular classes of transactions, account balances, or disclosures where smaller misstatements could influence decisions (e.g. related-party transactions, directors’ remuneration).
Example calculation (as might appear in exam practice):
- Profit before tax: R2 000 000.
- Overall materiality: 5% of profit before tax = R100 000.
- Performance materiality: 70% of R100 000 = R70 000.
You must be able to:
- Choose appropriate benchmark and percentage (with justification).
- Calculate the amounts correctly.
- Explain how materiality influences the nature, timing, and extent of audit procedures.
3.5 Understanding the Entity and Its Environment
ISA 315 requires auditors to obtain sufficient understanding of the entity and its environment to identify and assess the risks of material misstatement.
Areas to understand:
-
Industry, regulatory, and other external factors:
- Economic conditions in South Africa.
- Specific industry risks (e.g. mining, retail, banking).
- Regulatory requirements (Companies Act, tax laws, B-BBEE codes).
-
Nature of the entity:
- Business operations and processes.
- Ownership and governance structures (e.g. family-owned, listed).
- Types of investments and financing structures.
- Related parties and group structures.
-
Objectives, strategies, and business risks:
- Strategic goals (expansion, new products).
- Risks that may lead to misstatements (e.g. aggressive revenue targets leading to revenue recognition issues).
-
Measurement and review of financial performance:
- Internal performance indicators (KPIs, budgets, variances).
- External indicators (market share, analyst forecasts).
Exams may present a scenario about a company and require you to identify business risks and related financial statement risks, then describe how this affects the audit strategy.
3.6 Risk Assessment Procedures
Risk assessment procedures include:
-
Inquiries of management and others:
- Discuss with management, internal auditors, and key staff.
- Understand processes, risks, and controls.
-
Analytical procedures:
- Trend analysis (current year vs prior year).
- Ratio analysis (gross margin, current ratio, debtor days).
- Comparison to budgets, industry averages.
-
Observation and inspection:
- Observe operations (e.g. inventory counts).
- Inspect documents (e.g. contracts, minutes, policies).
- Visit premises and major sites.
Risk assessment procedures do not provide sufficient appropriate evidence on their own, but help design further audit procedures.
3.7 Documentation: Audit Strategy and Audit Plan
The auditor documents:
-
Overall audit strategy:
- Scope, timing, and direction of the audit.
- Reporting objectives.
- Factors that determine the focus of audit resources.
-
Detailed audit plan (audit programme):
- Nature, timing, and extent of planned risk assessment and substantive procedures.
- Specific procedures for each assertion for significant account balances and classes of transactions.
In UNISA AUE2601 exams, you may be asked to:
- Distinguish between audit strategy and audit plan.
- Explain the importance of documenting planning decisions.
- Describe the components of an audit plan for a specific section (e.g. trade receivables).
4. Internal Control, Tests of Control and Substantive Procedures
Internal control and audit procedures form a large practical component of AUE2601, and similar modules like AUE2602 UNISA and AUDI202 CUT. Exams frequently focus on cycles such as revenue, purchases, inventory, cash, and payroll.
4.1 Components of Internal Control (COSO Framework)
The COSO framework, widely used in auditing, identifies five components of internal control:
-
Control environment:
- Set of standards, processes, and structures providing the basis for internal control.
- Includes integrity and ethical values, board oversight, organisational structure, assignment of authority and responsibility, HR policies.
-
Entity’s risk assessment process:
- How management identifies and analyses risks relevant to achieving objectives and financial reporting.
-
Information system and communication:
- Procedures and records for initiating, recording, processing, and reporting transactions.
- Includes IT systems and manual procedures.
-
Control activities:
- Policies and procedures to ensure management directives are carried out.
- Examples: authorisations, reconciliations, physical controls, segregation of duties.
-
Monitoring of controls:
- Ongoing or separate evaluations to ascertain whether controls are present and functioning.
- Internal audit activities, management reviews.
AUE2601 questions often ask you to list and explain these components and apply them to a specific cycle (e.g. sales and debtors).
4.2 Types of Control Activities
Control activities are the most examinable aspect of internal control. Common types include:
-
Authorisation controls:
- Approvals for transactions (e.g. credit limits for customers, purchase order approvals).
-
Segregation of duties:
- Separate responsibilities for:
- Authorisation of transactions.
- Custody of assets.
- Recording and reconciliation.
- Example: In the revenue cycle, separate credit approval, invoicing, and receipts.
- Separate responsibilities for:
-
Physical controls:
- Safeguarding assets (locks, safes, access controls).
- Physical inventory counts and security cameras.
-
Reconciliations and reviews:
- Bank reconciliations.
- Supplier statement reconciliations.
- Management review of budget vs actual results.
-
Supervisory controls:
- Supervisors review work of staff.
- Performance reviews and sign-offs.
Typical exam approach:
Present a short narrative of a company’s processes and ask students to:
- Identify existing controls.
- Evaluate their effectiveness.
- Recommend improvements.
4.3 The Revenue Cycle: Example of Internal Controls
Because AUE2601 exam papers often use the revenue and receipts cycle as an example, it is worth revising typical controls for each stage:
-
Order receiving and acceptance:
- Written customer orders or electronic orders recorded sequentially.
- Credit approval before dispatch (credit controller checks credit limits).
- Segregation between sales department and credit controller.
-
Dispatch of goods:
- Sequentially pre-numbered delivery notes (DN).
- Dispatch clerks match goods to customer orders and record dispatch.
- Sign-off by warehouse manager for goods dispatched.
-
Invoicing:
- Invoices generated from DN and price lists.
- Sequentially pre-numbered invoices.
- Periodic review of unmatched DNs, orders, and invoices.
-
Recording sales:
- Sales journal updated from approved invoices.
- Automated posting to general ledger and debtors subsidiary ledger.
- Independent review of sales journal totals.
-
Receipts and banking:
- Segregation between cashier, accounting, and reconciliation.
- Daily banking of all cash and cheques.
- Bank reconciliations prepared by someone independent of cash handling.
Exam answers may require designing tests of controls for the revenue cycle and related substantive procedures on trade receivables.
4.4 Tests of Controls vs Substantive Procedures
Tests of controls:
- Aim: To evaluate the operating effectiveness of controls in preventing, detecting, and correcting material misstatements.
- Types:
- Inquiry, observation, inspection of documents, re-performance.
- Example: Inspect a sample of sales invoices to check for evidence of authorisation and credit approval.
Substantive procedures:
- Aim: To detect material misstatements at the assertion level.
- Types:
- Tests of details (transactions and balances).
- Substantive analytical procedures.
- Examples:
- Confirm trade receivables directly with customers.
- Analytical procedures on gross margin percentages.
Relationship:
- If controls are effective, auditor may rely on them and perform fewer substantive tests.
- If controls are weak, auditor must increase substantive testing.
In AUE2601, you often need to:
- Differentiate definitions.
- Provide examples for a specific assertion (e.g. existence, completeness, accuracy).
- Select appropriate combination of tests given a scenario.
4.5 Assertions for Classes of Transactions and Account Balances
Assertions are management representations about recognition, measurement, presentation, and disclosure.
For classes of transactions (e.g. sales, purchases):
- Occurrence: Recorded transactions actually occurred.
- Completeness: All transactions that should have been recorded have been recorded.
- Accuracy: Amounts and data are recorded correctly.
- Cut-off: Transactions recorded in the correct accounting period.
- Classification: Transactions recorded in proper accounts.
- Presentation: Properly aggregated and clearly described.
For account balances (e.g. inventory, receivables):
- Existence: Assets/liabilities actually exist.
- Rights and obligations: Entity holds rights to assets and obligations for liabilities.
- Completeness: All assets/liabilities are recorded.
- Accuracy, valuation, and allocation: Balances are recorded at appropriate amounts and any resulting valuation or allocation adjustments are recorded.
- Presentation: Appropriately aggregated and disclosed.
Exam questions may ask: “State the assertions relevant to trade receivables and design one substantive procedure for each.”
Example for trade receivables:
- Existence: Select a sample of receivable balances and send confirmation letters to customers.
- Completeness: Trace a sample of dispatch notes to the sales ledger and debtors ledger.
- Valuation: Review the aged trial balance and evaluate adequacy of allowance for doubtful debts.
4.6 Designing Tests of Controls and Substantive Procedures – Example: Trade Receivables
Objective: To ensure that trade receivables are:
- Existent.
- Complete.
- Properly valued.
- Properly presented and disclosed.
Tests of controls:
-
Credit approval:
- Inspect a sample of invoices for evidence of prior credit approval.
- Ensure credit limits are not exceeded without authorisation.
-
Sequential numbering and matching:
- Check that sales invoices and DNs are pre-numbered and regularly accounted for.
- Inspect reconciliation between DNs, invoices, and entries in sales journal.
-
Monthly statements:
- Confirm that monthly statements are sent to customers.
- Inspect evidence of follow-up on customer queries.
-
Segregation of duties:
- Observe that the person who handles receipts is not responsible for updating the debtors ledger.
- Inspect organisational chart and job descriptions.
Substantive procedures:
-
Debtors’ circularisation (confirmation):
- Select a sample of debtor balances.
- Send positive confirmations (require reply regardless of whether they agree) or negative confirmations (reply only if they disagree).
- Investigate non-responses and discrepancies by alternative procedures (e.g. subsequent receipts, invoices).
-
Subsequent receipts testing:
- Inspect cash receipts after year-end to see if they relate to year-end balances.
- Evidence that balances existed and were collected.
-
Aged analysis review:
- Obtain aged trial balance of receivables.
- Review overdue accounts; discuss with management.
- Recalculate allowance for doubtful debts and compare with prior years.
-
Analytical procedures:
- Compare receivables days to prior year and industry averages.
- Investigate significant changes.
-
Cut-off tests:
- Inspect invoices and dispatch notes around year-end.
- Ensure sales are included in the correct accounting period.
Understanding how to design procedures around assertions is crucial for exam success in AUE2601 and similar modules at CUT and other universities.
4.7 Use of Computer-Assisted Audit Techniques (CAATs)
In South African syllabi (UNISA AUE2601 and AIS-related modules like FAC3701), knowledge of CAATs is increasingly important.
Common CAATs:
-
Generalised audit software (GAS):
- Perform tasks like extracting data, recalculating totals, sampling, and querying large datasets.
-
Test data:
- Input fictitious or dummy transactions into the client’s system to test control procedures.
-
Integrated test facility (ITF):
- Introduce fake entities within the client’s database to test processing controls continuously.
Benefits:
- Efficient handling of large volumes of data.
- Ability to test full populations rather than samples.
- Enhanced detection of unusual transactions or trends.
Limitations:
- Requires auditor IT skills or specialist support.
- Client may restrict access due to data protection concerns.
- Design and testing of CAATs can be time-consuming.
In exams, you may be required to:
- Explain CAATs.
- Discuss advantages and disadvantages.
- Provide examples of audit procedures using audit software (e.g. identify duplicate payments, unusual journal entries).
5. Audit Evidence, Completion and Reporting (UNISA AUE2601, CUT AUDI301)
The final key theme in AUE2601 and comparable South African modules is the gathering of sufficient appropriate audit evidence, evaluation at completion, and the expression of an audit opinion.
5.1 Characteristics of Audit Evidence
ISA 500 defines audit evidence as all the information used by the auditor in arriving at conclusions on which the audit opinion is based.
Key characteristics:
-
Sufficiency:
- The measure of the quantity of evidence.
- Influenced by risk of material misstatement and quality of evidence.
- Higher risk and lower quality require more evidence.
-
Appropriateness:
- A measure of evidence quality:
- Relevance: Relationship to the assertion being tested.
- Reliability: Depends on source and nature.
- A measure of evidence quality:
Reliability hierarchy (from more to less reliable):
- Evidence obtained directly by the auditor (e.g. observation, re-performance).
- External evidence obtained directly from third parties (e.g. confirmations from banks).
- External evidence held by the client (e.g. supplier invoices).
- Internal evidence generated by the client’s systems and processes.
- Oral representations from management (least reliable; not sufficient alone).
Exam questions often require comparing two or more types of evidence and discussing which is more reliable and why.
5.2 Procedures for Obtaining Audit Evidence
ISA 500 lists the main audit procedures:
-
Inspection:
- Examination of records, documents, or tangible assets.
- Example: Inspect invoices, contracts, minutes, and physical assets.
-
Observation:
- Watching processes or procedures being performed by others.
- Example: Observing inventory count.
-
External confirmation:
- Obtaining a direct written response from a third party (e.g. banks, customers, lawyers).
-
Recalculation:
- Checking mathematical accuracy of documents or records.
-
Re-performance:
- Independent execution by the auditor of procedures originally performed by client personnel.
-
Analytical procedures:
- Evaluations of financial information through analysis of plausible relationships among data.
-
Inquiry:
- Seeking information from knowledgeable persons within or outside the entity.
Example application:
- Inventory: inspection of physical inventory, observation of count, test counts, recalculation of costing.
- Bank balances: external confirmations from banks, inspection of bank statements and reconciliations.
5.3 Analytical Procedures: Planning and Completion
Analytical procedures are used:
-
At planning stage (required):
- To understand the entity and identify areas of potential risk.
- Example: Comparing current and prior year revenue growth, margins, expense ratios.
-
As substantive procedures (optional, but often used):
- Where they can provide sufficient appropriate evidence, especially for large homogeneous populations.
-
At completion stage (required):
- Overall analytical review of financial statements to assess whether they are consistent with the auditor’s understanding of the entity.
Types of analytical procedures:
- Trend analysis (time series).
- Ratio analysis (profitability, liquidity, solvency).
- Reasonableness tests (e.g. recomputing interest expense based on loan balances and interest rates).
In exams, you may be asked to:
- Define analytical procedures.
- Provide examples for a specific section (e.g. revenue, payroll).
- Explain their purpose at planning vs completion.
5.4 Written Representations
ISA 580 deals with written representations from management.
Definition: Written statements by management provided to the auditor to confirm certain matters or to support other audit evidence.
Examples:
- Management acknowledges responsibility for preparation of financial statements and internal control.
- Confirmation that all related party transactions have been disclosed.
- Confirmation of completeness of litigation and claims information.
Important exam points:
- Written representations are necessary but not sufficient audit evidence.
- They support other evidence but do not replace it.
- If management refuses to provide written representations, this constitutes a scope limitation and may lead to a qualified opinion or disclaimer.
5.5 Subsequent Events and Going Concern
Completion phase of the audit includes specific considerations under:
- Subsequent events (ISA 560):
- Events occurring between the date of the financial statements and the date of the auditor’s report.
- Types:
- Adjusting events: Provide evidence of conditions existing at the period-end (e.g. customer bankruptcy confirming impairment).
- Non-adjusting events: Indicative of conditions that arose after period-end (e.g. major fire after year-end).
Procedures include:
- Reviewing subsequent management accounts and budgets.
- Inquiring of management and those charged with governance.
- Reviewing minutes of meetings after year-end.
- Examining subsequent receipts from debtors, etc.
- Going concern (ISA 570):
- Management is responsible for assessing whether the entity can continue as a going concern for at least 12 months from reporting date.
- Auditor evaluates management’s assessment and whether there are material uncertainties.
Indicators of going concern problems:
- Negative operating cash flows.
- Net liabilities or working capital deficiency.
- Loan defaults and arrears.
- Loss of key customers or suppliers.
- Legal proceedings that may threaten survival.
If material uncertainty exists, auditor must ensure appropriate disclosure in the financial statements and consider its impact on the audit report.
5.6 Misstatements: Identifying and Evaluating
During the audit, auditors identify misstatements, which may be:
- Factual misstatements: No doubt (e.g. invoice total incorrectly added).
- Judgmental misstatements: Differences between auditor’s and management’s judgment (e.g. provision estimates).
- Projected misstatements: Extrapolated from sample results to the population.
The auditor:
- Accumulates misstatements other than clearly trivial.
- Communicates them to management.
- Requests management to correct identified misstatements.
At completion:
- Evaluates whether uncorrected misstatements (individually or in aggregate) are material.
- Considers both size and nature (qualitative factors).
If uncorrected misstatements are material:
- Auditor modifies the opinion (usually a qualified or adverse opinion).
5.7 Types of Audit Opinions
ISA 700 and ISA 705/706 govern audit reports.
1. Unmodified (unqualified) opinion:
- Used when auditor concludes that financial statements are prepared, in all material respects, in accordance with applicable financial reporting framework.
- Standard report structure:
- Opinion.
- Basis for opinion.
- Key audit matters (for listed entities, in South Africa).
- Responsibilities of management and auditor.
2. Modified opinions (ISA 705):
- Used when:
- Financial statements are materially misstated (disagreement), or
- Auditor cannot obtain sufficient appropriate evidence (limitation of scope).
Types:
-
Qualified opinion:
- Material but not pervasive misstatement or limitation.
- Wording: “…except for the effects of the matter described in the Basis for Qualified Opinion paragraph…”
-
Adverse opinion:
- Misstatements are both material and pervasive.
- Financial statements do not present fairly in accordance with the framework.
-
Disclaimer of opinion:
- Limitation of scope is both material and pervasive.
- Auditor cannot form an opinion.
- Wording: “We do not express an opinion on the financial statements.”
3. Emphasis of matter and other matter paragraphs (ISA 706):
-
Emphasis of matter:
- Draws attention to matters appropriately presented or disclosed, which are fundamental to understanding financial statements.
- Opinion is not modified.
- Example: Significant uncertainty regarding going concern appropriately disclosed.
-
Other matter:
- Refers to matters not presented or disclosed in financial statements but relevant to users’ understanding of the audit, auditor’s responsibilities, or report.
Exam questions frequently:
- Provide a scenario and ask what type of opinion is appropriate and why.
- Require drafting of a suitable opinion or explanation of wording changes.
5.8 Structure of the Independent Auditor’s Report (South African Example)
Typical headings in a South African auditor’s report:
-
Report on the Audit of the Financial Statements:
- Identify entity and financial statements audited.
-
Opinion:
- Clear expression of conclusion.
-
Basis for Opinion:
- Reference to ISAs and ethical requirements.
- Statement of independence and sufficiency of evidence.
-
Key Audit Matters (for listed companies) :
- Describe matters of most significance and how they were addressed.
-
Responsibilities of Directors for the Financial Statements:
- Management’s responsibility for preparation, going concern assessment, internal control.
-
Auditor’s Responsibilities for the Audit of the Financial Statements:
- High-level description of procedures and responsibilities.
-
Report on Other Legal and Regulatory Requirements:
- As required by Companies Act or other legislation.
Students of AUE2601 and similar modules must be familiar with this standard structure and able to identify which sections would be impacted when modifications are required.
5.9 Exam Strategy for AUE2601, CUT AUDI201 and Similar Modules
Because this guide targets UNISA and South African university students (AUE2601 UNISA, AUDI201 CUT, AUI204 NWU, etc.), a final focus on exam technique is essential:
-
Know the definitions verbatim or in accurate paraphrase:
- Audit, reasonable assurance, materiality, audit risk, professional skepticism, etc.
- These are often repeated in MCQs and short theory questions.
-
Practise scenario-based questions:
- Ethical dilemmas, independence threats, internal control evaluations.
- Always structure answers: identify issue, reference principle/standard, apply to facts, conclude.
-
Use assertion-based thinking:
- When asked for procedures, start by identifying relevant assertions (existence, completeness, accuracy, valuation, rights/obligations, cut-off, presentation).
- Design one or more procedures targeting each assertion.
-
Integrate South African context:
- Reference IRBA, SAICA, Companies Act, SARS, JSE where relevant.
- Recognise the role of AGSA in public sector examples.
-
Time management:
- Allocate time according to marks (e.g. 1.5 minutes per mark).
- Answer high-mark scenario questions after quickly capturing easy definition questions.
-
Show clear structure and headings:
- Use headings like “Threat identified”, “Fundamental principles affected”, “Safeguards”, “Conclusion”.
- This aligns with how markers award method and content marks in UNISA-style exams.
-
Cross-link with other modules:
- Accounting standards from FAC2601 / FAC3701 and AIS from INF2603 / AIS modules support audit reasoning.
- Understanding double-entry and financial statement presentation enhances substantive testing logic.
By mastering the theory and process elements summarised in this guide, and practising application through past papers and tutorial letters, students of AUE2601 UNISA, AUDI201 CUT, and similar South African auditing modules can approach exams with confidence in both conceptual understanding and practical exam technique.
