AUE4861: Advanced Auditing Study Guide (UNISA CTA)

This study guide provides structured, exam‑focused notes for AUE4861 Advanced Auditing, a key module in the UNISA Postgraduate Diploma in Applied Accounting Sciences (CTA). It is designed to support students preparing for UNISA AUE4861 exam papers, CTA auditing tests, and similar advanced auditing courses at South African universities such as CUT, UJ, and NWU. The focus is on high‑yield theory, practical application in the South African context, and techniques for answering integrated case‑study questions.

1. Overview of AUE4861 and the Advanced Auditing Environment

1.1 Position of AUE4861 in the UNISA CTA Programme

AUE4861 Advanced Auditing is a core module in the UNISA: Postgraduate Diploma in Applied Accounting Sciences (CTA). It builds on undergraduate auditing modules (e.g. AUE2602, AUE3702) and expects a solid grasp of basic auditing principles, ethics, and assurance. At CTA level, the emphasis shifts from learning definitions to application, integration, and professional judgment.

In the UNISA CTA structure, AUE4861 is closely linked with:

  • FAC4861 / FAC4862 (Financial Accounting) – financial reporting underpins key audit assertions.
  • TAX4861 (Taxation) – tax risks and deferred tax balances affect audit risk.
  • MAC4861 (Management Accounting) – understanding cost structures and performance measures supports business risk analysis.
  • AUE4862 (if applicable) or other assurance‑related modules – internal audit, forensic elements, or specialised assurance can be cross‑examined implicitly.

Many exam questions mirror the style used in professional bodies (e.g. SAICA APC‑style integrated questions), so AUE4861 is a stepping stone towards ITC and ultimately the APC.

1.2 Learning Outcomes and Exam Focus

By the end of AUE4861, students should be able to:

  • Evaluate audit risk and design audit strategies for complex entities.
  • Apply ISA‑based concepts (International Standards on Auditing) in South African contexts, especially for public interest entities.
  • Critically assess governance structures and ethics in relation to King IV and the IRBA Code of Professional Conduct.
  • Design and evaluate internal controls, including IT controls, in modern business environments.
  • Perform and evaluate substantive procedures for significant balances and transactions.
  • Formulate appropriate audit opinions and reporting for various scenarios (listed vs private, group audits, special purpose).
  • Deal with special topics: going concern, subsequent events, related parties, group audits, and the auditor’s role in non‑audit services.

The AUE4861 UNISA exam traditionally features:

  • One or two long integrated case studies (covering risk assessment, procedures, and reporting) carrying the bulk of marks.
  • Several shorter theory/application questions (e.g. on ethics, independence, or governance).
  • Required answers in professional style: concise, point‑form, referencing assertions, risks, and relevant ISAs.

1.3 South African Auditing Context (IRBA, SAICA, King IV)

Advanced auditing in South Africa is framed by:

  • IRBA (Independent Regulatory Board for Auditors)

    • Regulates Registered Auditors (RAs).
    • Issues the IRBA Code of Professional Conduct, based on the IESBA Code.
    • Oversees audit quality inspections, disciplinary processes, and auditor registration.
  • SAICA (South African Institute of Chartered Accountants)

    • Professional body for CAs(SA).
    • Influences education standards (e.g. CTA, ITC, APC).
    • Works closely with IRBA on technical guidance.
  • King IV Report on Corporate Governance for South Africa

    • Applies a principle‑ and outcomes‑based approach.
    • Strong focus on ethical leadership, transparency, and integrated reporting.
    • Affects how auditors consider governance, combined assurance, and stakeholder communication.

AUE4861 expects you to link theory to this regulatory context. For example:

  • When identifying independence threats in an exam case, explicitly mention the IRBA Code.
  • When evaluating governance, refer to King IV principles like ethical leadership, stakeholder inclusivity, and combined assurance.
  • In questions involving listed companies or public interest entities, recognise heightened public interest and IRBA oversight.

1.4 Exam Skills: How AUE4861 Differs from Undergraduate Auditing

At undergraduate level (e.g. UNISA AUE2602 study notes, CUT AUD305 exam notes), many questions are:

  • Short definition questions.
  • Direct “list the procedures” type questions.
  • Focused on isolated topics (e.g. one on internal control, another on sampling).

In AUE4861, expect:

  • Integrated scenario‑based questions:

    • You receive several pages of information about a company (e.g. MNG 0001 Ltd manufacturing, or CNS 445 (Pty) Ltd in IT services).
    • You must identify business risks, audit risks, control weaknesses, and then design procedures and reporting responses.
  • Professional judgment and prioritisation:

    • Not every risk is equally important.
    • Marks reward relevance, depth, and link to assertions, rather than merely length.
  • Application over rote memorisation:

    • Knowing ISA 315 or ISA 330 summaries is not enough; you must show how they apply to the scenario.

Exam technique tips for AUE4861:

  1. Read the required first. Know whether you are asked for:

    • Risks,
    • Controls,
    • Substantive procedures,
    • Report modifications, or
    • Ethical issues.
  2. Plan headings (especially for long questions):

    • “Business risks” vs “Audit risks”.
    • “Control weaknesses” vs “Recommendations”.
    • “Substantive procedures – Inventory” with separate assertion‑focused bullets.
  3. Answer in clear, exam‑style point form, not essays:

    • Each point should follow the “risk – implication – response” structure where applicable.
  4. Time management:

    • Allocate time per mark (e.g. 1.8 minutes per mark if 180‑minute paper with 100 marks).
    • Do not over‑answer low‑mark questions.

2. Professional Ethics, Independence and Governance

2.1 IRBA Code of Professional Conduct: Fundamental Principles

The IRBA Code (aligned with the IESBA Code) requires RAs to uphold five fundamental principles:

  1. Integrity

    • Being honest and straightforward.
    • No deliberate misrepresentation or misleading information.
    • In an exam scenario: if management asks the auditor to “tone down” a Key Audit Matter (KAM), integrity requires resisting such pressure.
  2. Objectivity

    • No bias, conflict of interest, or undue influence.
    • Must not allow personal relationships or financial interests to override professional judgment.
    • In case studies: think of long‑standing client relationships, gifts, or close family members in management roles.
  3. Professional Competence and Due Care

    • Maintain professional knowledge and skill at the required level.
    • Act diligently and in accordance with applicable standards.
    • For AUE4861, you must consider whether the firm has sufficient competence to perform complex engagements (e.g. auditing derivatives, complex IT systems).
  4. Confidentiality

    • Do not disclose client information without authority, except when legally required or justified.
    • In exam questions involving whistle‑blowing or reporting fraud, you must balance confidentiality with legal and ethical obligations.
  5. Professional Behaviour

    • Comply with laws and regulations; avoid discrediting the profession.
    • Includes misleading marketing, improper fee arrangements, or association with misleading information.

2.2 Threats to Independence and Safeguards

The Code identifies five categories of threats to independence (including independence of mind and independence in appearance):

  1. Self‑interest threat

    • Financial or other personal interests in the client.
    • Examples:
      • Direct shareholding by audit partner in client.
      • Fees from client representing a large percentage of firm revenue.
      • Loan from client to firm or partner.
  2. Self‑review threat

    • Auditing your own work or that of your firm.
    • Examples:
      • Preparing financial statements, then auditing them.
      • Providing significant IT implementation, then auditing those systems.
  3. Advocacy threat

    • Promoting a client’s position to the point of loss of objectivity.
    • Examples:
      • Representing the client in tax disputes.
      • Promoting client shares in a capital raising.
  4. Familiarity threat

    • Too sympathetic to client interests due to close relationships.
    • Examples:
      • Long association of engagement partner with client.
      • Close family member of partner as CFO of client.
  5. Intimidation threat

    • Actual or perceived pressure to act in a certain way.
    • Examples:
      • Client threatens to replace auditor.
      • Dominant CEO exerts undue influence.

Safeguards can be:

  • Firm‑level (general):

    • Quality control policies (ISA 220).
    • Rotation of engagement partners.
    • Independent quality reviews.
    • Training and disciplinary mechanisms.
  • Engagement‑specific:

    • Removing specific individuals causing threats.
    • Involving an additional partner for review.
    • Consulting external experts.
    • Declining or withdrawing from the engagement if threats cannot be reduced to an acceptable level.

Example (typical AUE4861 scenario):
The audit firm Thabo & Co audits MNG 0001 Ltd and also provides tax planning services. The tax service is routine, but now MNG 0001 wants Thabo & Co to prepare the financial statements and design a new ERP system.

  • Identify threats:

    • Preparing financial statements → self‑review threat.
    • ERP design and implementation → self‑review threat and possibly advocacy (if recommending product).
    • Large total fees from this client → self‑interest threat.
  • Possible safeguards:

    • Decline ERP implementation engagement.
    • Use separate teams for tax and audit, with clear Chinese walls.
    • Have an independent partner review the audit file.
    • If threats remain too high, consider resigning as auditor.

2.3 NOCLAR (Non‑Compliance with Laws and Regulations)

At advanced level, you must understand the auditor’s responsibilities related to NOCLAR:

  • Categories of laws and regulations:

    • Direct effect on financial statements: e.g. tax laws, Companies Act provisions on dividends.
    • Indirect effect: e.g. environmental laws, labour laws, health and safety.
  • Auditor’s responsibilities:

    • Maintain professional scepticism.
    • Obtain sufficient appropriate audit evidence regarding compliance with laws of direct effect.
    • Be alert to indications of non‑compliance for other laws.
    • Discuss with management and those charged with governance.
    • Consider impact on audit opinion.
    • Determine whether there is a duty to report to regulators under South African law.

Link to IRBA Code:
The Code sets out when and how professional accountants should respond to NOCLAR, including escalation within the entity, disclosure to authorities, and documentation.

In an exam scenario:

  • Identify indicators of NOCLAR (e.g. repeated environmental fines).
  • Explain audit implications:
    • Increased risk of material misstatement (provisions, contingencies).
    • Possible going concern issues.
    • Need to communicate with those charged with governance (TCWG).
  • Discuss whether the auditor should:
    • Report to IRBA or other regulators.
    • Modify the audit opinion.

2.4 Corporate Governance: King IV and the Auditor’s Perspective

King IV applies to all organisations (public, private, state‑owned, NPOs) and emphasises:

  • Ethical leadership – directors must act in the best interests of the organisation and stakeholders.
  • Governing structures – effective boards, committees (audit committee, social and ethics committee, risk committee).
  • Strategy, performance and reporting – integrated thinking, balanced scorecards, holistic reporting.
  • Governing functional areas – including risk management, technology and information, and compliance.
  • Stakeholder relationships – inclusive approach to stakeholders.
  • Combined assurance – coordinated assurance from management, internal audit, external audit, and other assurance providers.

The external auditor’s concerns include:

  • Whether governance structures are robust:

    • Independent, skilled audit committee.
    • Clear risk oversight.
    • Transparent reporting.
  • The audit committee’s role:

    • Recommending auditor appointment.
    • Overseeing auditor independence.
    • Reviewing financial statements and integrated reports.
    • Engaging with both internal and external auditors.
  • Combined assurance model:

    • Understanding reliance on internal audit.
    • Coordinating audit efforts to avoid duplication and gaps.
    • Evaluating management’s self‑assessment and other assurance providers (like IT assurance firms).

In exam questions:

  • When asked to evaluate governance, structure answers around:
    • Board composition and independence.
    • Committees (audit, risk, social & ethics) – membership, roles, and reporting lines.
    • Risk management and internal controls.
    • Combined assurance and communication.

Example (scenario):
CNS 445 (Pty) Ltd, a technology services company, recently listed on the JSE. Its board has:

  • CEO, CFO, and COO (executive directors).
  • Two non‑executive directors (but both are former executives).
  • No separate audit committee; the full board acts as audit committee.

Issues to identify:

  • Lack of majority independent non‑executive directors.
  • Audit committee not properly constituted with independent members.
  • Potential independence concerns for external auditor where governance oversight is weak.

Implications:

  • Higher control risk and audit risk.
  • Potential governance disclosure issues.
  • Need for more extensive communication with TCWG.

3. Risk Assessment, Planning and Internal Control (ISA 315 / ISA 330 Focus)

3.1 Understanding the Entity and Its Environment

ISA 315 requires auditors to obtain an understanding of:

  • The entity and its environment (industry, regulatory, other external factors).
  • The entity’s nature, objectives, strategies, and related business risks.
  • The entity’s financial performance and measurement.
  • Internal control, including IT environment.
  • The reporting framework (e.g. IFRS in South Africa).

In AUE4861 exams, typical planning tasks include:

  • Identifying business risks (e.g. aggressive expansion, dependence on one supplier).
  • Translating them into audit risks (risk of material misstatement).
  • Explaining the impact on the audit approach.

Business risk vs audit risk:

  • Business risk – potential events or conditions that could reduce an entity’s ability to meet its objectives (e.g. loss of a key customer, new competitor).
  • Audit risk – risk that the auditor expresses an inappropriate opinion when financial statements are materially misstated; composed of inherent risk, control risk, and detection risk.

Example:
A UNE listed client, MNG 0001 Ltd, has recently expanded into Zimbabwe with a new branch.

  • Business risks:

    • Currency risk due to foreign operations.
    • Political and regulatory uncertainty.
    • Management inexperienced in cross‑border operations.
  • Audit risks:

    • Incorrect foreign currency translation (IAS 21).
    • Unrecorded or misstated foreign tax liabilities.
    • Inadequate internal controls at remote branch.

3.2 Components of Internal Control (Control Environment to Monitoring)

Understanding internal control is critical for risk assessment and for designing further audit procedures. The five components (aligned with COSO) are:

  1. Control Environment

    • Tone at the top, integrity, ethical values.
    • Board and management philosophy.
    • Organisational structure, HR policies.
    • In AUE4861: identify weak control environments (e.g. dominant CEO, high staff turnover, lack of ethics policies).
  2. Entity’s Risk Assessment Process

    • How management identifies and analyses risks.
    • Formal risk registers, workshops, or informal approaches.
    • In exam scenarios, question whether such processes are adequate and documented.
  3. Information System and Communication

    • Systems for initiating, recording, processing, and reporting transactions.
    • IT systems (ERP, accounting software), interfaces, data integrity.
    • Communication channels (policies, procedures, training, whistle‑blowing).
  4. Control Activities

    • Policies and procedures that help ensure management directives are carried out.
    • Examples:
      • Authorisation of transactions.
      • Segregation of duties.
      • Reconciliations.
      • Physical controls.
      • IT general and application controls.
  5. Monitoring of Controls

    • Ongoing or separate evaluations to assess control performance.
    • Internal audit function, management reviews, exception reports.

For AUE4861, be capable of:

  • Identifying specific control weaknesses in a scenario.
  • Explaining implications for audit risk.
  • Recommending improvements that are practical and tailored to the entity’s size and complexity.

3.3 IT Controls in Advanced Auditing (including CAATs)

Modern audits often rely heavily on IT systems. ISA 315 and ISA 330 require understanding of:

  • IT General Controls (ITGCs):

    • Access controls (user IDs, passwords, role‑based access).
    • Program change controls (development, testing, approval).
    • Computer operations controls (backups, batch processing, scheduling).
    • Physical and environmental controls for data centres.
  • Application Controls:

    • Data input validation (e.g. field checks, range checks).
    • Processing controls (control totals, reasonableness checks).
    • Output controls (reconciliation, exception reports).

In an AUE4861 exam, expect:

  • Scenario where the client uses ERP systems (e.g. SAP, Oracle, locally developed).
  • You may be asked to:
    • Identify IT control weaknesses (e.g. shared user accounts, no password policies).
    • Evaluate their impact on financial reporting.
    • Suggest compensating controls and audit procedures.

CAATs (Computer‑Assisted Audit Techniques):

  • Examples:

    • Test data – inputting fictitious transactions to test system controls.
    • Audit software (e.g. ACL, IDEA) – extracting data to test for anomalies, duplicates, or compliance with rules.
    • Embedded audit modules – code within client systems that flags certain transactions.
  • Advantages:

    • Can test large data sets.
    • Improve efficiency and coverage.
    • Useful for fraud detection.
  • Disadvantages:

    • Requires technical expertise.
    • Risk of incorrect use or misinterpretation.

Exam‑style application:

  • If CNS 445 (Pty) Ltd processes millions of online transactions:
    • Suggest using CAATs to:
      • Identify duplicate invoices.
      • Test cutoff.
      • Analyse unusual journals.
    • Highlight the need to test ITGCs first; if ITGCs are weak, reliability of application controls and data is compromised.

3.4 ISA 315 and ISA 330: From Risk Assessment to Response

ISA 315 – Identifying and Assessing Risks of Material Misstatement:

Key requirements:

  1. Perform risk assessment procedures:

    • Inquiries of management and others.
    • Analytical procedures.
    • Observation and inspection.
    • Walkthroughs of major transaction cycles.
  2. Understand:

    • The entity and its environment.
    • Internal control relevant to the audit.
    • The applicable financial reporting framework.
  3. Identify risks of material misstatement at:

    • Financial statement level.
    • Assertion level for classes of transactions, account balances, and disclosures.
  4. Determine whether any risks are significant risks:

    • Risks that require special audit consideration.
    • Often include fraud risks, complex transactions, significant estimates.

ISA 330 – The Auditor’s Responses to Assessed Risks:

Key ideas:

  • Design and implement overall responses at the financial statement level (e.g. more experienced staff, increased supervision, more professional scepticism).

  • Design and implement further audit procedures:

    • Tests of controls – when relying on controls.
    • Substantive procedures – always required for material classes of transactions, account balances, and disclosures.
  • The higher the assessed risk, the more persuasive evidence required (e.g. larger sample sizes, more year‑end work, more external evidence).

In exam answers, always link:

  • Risk identifiedRelevant assertion(s)Audit response (procedure)

Example:

  • Risk: Revenue overstatement at MNG 0001 Ltd due to aggressive sales targets (financial statement level and assertion level – occurrence, cutoff).
  • Responses:
    • Increase professional scepticism, involve senior staff (overall level).
    • Perform detailed cutoff testing around year‑end.
    • Confirm major customer balances; inspect post year‑end credit notes.
    • Review sales contracts for unusual terms.

3.5 Internal Audit and Combined Assurance

ISA 610 deals with using the work of internal auditors. In South Africa, internal audit is often central to combined assurance, as encouraged by King IV.

Key points:

  • Assess objectivity of internal audit:

    • Position in organisational structure.
    • Independence from operations.
    • Direct reporting to audit committee.
  • Assess competence:

    • Qualifications, training, and experience of internal auditors.
  • Evaluate systematic and disciplined approach:

    • Use of documented methodologies.
    • Quality of working papers and review processes.

If internal audit is reliable, the external auditor may:

  • Use internal audit’s work to understand internal controls.
  • Use some of their testing (e.g. on control effectiveness) to reduce external testing.

However:

  • External auditor remains solely responsible for the opinion.
  • Cannot rely on internal audit for areas involving significant judgment or high risk (e.g. goodwill impairment).

Combined assurance in exam scenarios:

  • Identify assurance providers:

    • Management oversight.
    • Internal audit.
    • External audit.
    • Specialist IT auditors.
    • Regulators (e.g. health, safety).
  • Evaluate whether:

    • There is duplication (overlap without added value).
    • There are gaps (areas with no assurance).
    • The audit committee integrates and coordinates assurance activities.

4. Substantive Procedures, Sampling, and Complex Areas

4.1 Substantive Procedures: Balances and Transactions

Substantive procedures are designed to detect material misstatements at the assertion level. They include:

  • Tests of details (e.g. inspecting invoices, confirming balances).
  • Substantive analytical procedures (e.g. ratio analysis, trend analysis).

Key assertions for classes of transactions:

  • Occurrence
  • Completeness
  • Accuracy
  • Cutoff
  • Classification
  • Presentation

Key assertions for account balances:

  • Existence
  • Rights and obligations
  • Completeness
  • Valuation and allocation
  • Presentation

4.1.1 Revenue

High‑risk area due to potential fraud (ISA 240). For a UNISA AUE4861 exam, you must design detailed procedures tailored to the entity.

Example procedures (for revenue occurrence and cutoff):

  • Occurrence:

    • Vouch a sample of recorded sales to customer orders, delivery notes, and invoices.
    • Confirm a sample of trade receivables directly with customers.
  • Completeness:

    • Trace from dispatch documents to sales invoices and the sales ledger.
    • Review post year‑end sales to detect unrecorded revenue before year‑end.
  • Cutoff:

    • Test a sample of dispatches before and after year‑end to ensure revenue recognised in correct period.
    • For a SaaS company like CNS 445 (Pty) Ltd, ensure subscription revenue is spread over correct service period.
  • Valuation:

    • Review sales returns and allowances after year‑end.
    • Consider allowances and rebates.

4.1.2 Inventory

Inventory often has issues around existence, valuation, and obsolescence.

Key procedures:

  • Attend year‑end inventory counts:

    • Observe adherence to count instructions.
    • Perform test counts and reconcile to client’s records.
    • Inspect for slow‑moving or damaged items.
  • For valuation:

    • Test unit cost (compare purchase documents to recorded costs).
    • Review cost build‑up for manufactured goods (materials, labour, overhead).
    • Compare NRV (selling price less costs to sell) to cost for samples of items.
  • For completeness:

    • Trace from warehouse floor items to count sheets and inventory records.
  • For rights and obligations:

    • Inspect consignment agreements; ensure consigned goods are excluded/included as appropriate.

4.1.3 Trade Receivables

Procedures typically include:

  • External confirmations (positive or negative confirmations).
  • Subsequent receipts testing (review cash receipts after year‑end).
  • Age analysis review; consider allowances for credit losses (IFRS 9 expected credit loss model).
  • Review for related party balances.

Link to scenario:

  • If MNG 0001 Ltd expanded credit terms, there may be increased credit risk; auditor should increase sample sizes, perform more detailed ECL analysis, and challenge management assumptions.

4.1.4 Provisions and Contingent Liabilities

Significant judgmental area (e.g. legal disputes, warranties, restructuring).

Procedures:

  • Review board minutes for discussions of significant risks or litigations.
  • Obtain lawyers’ letters for details on legal cases.
  • Evaluate management’s assumptions and estimates.
  • Review subsequent events (e.g. court rulings, settlements).
  • Ensure appropriate provision vs disclosure classification (IAS 37).

Exam‑style answer:
Identify risk: Understatement of provisions for environmental cleanup at a mining entity.
Procedures: Inspect environmental reports, correspondence with regulators, obtain legal opinions, analyse historical cleanup costs, review subsequent actions taken by company.

4.2 Auditing Estimates and Fair Value Measurements

ISA 540 addresses auditing accounting estimates. In AUE4861, you must:

  • Understand the nature of estimates (e.g. impairment, fair value properties, depreciation, ECL).
  • Consider inherent risk factors:
    • Estimation uncertainty.
    • Complexity.
    • Subjectivity.
    • Susceptibility to bias or fraud.

Approach:

  1. Understand process and controls over estimates:

    • Who prepares them?
    • What data and methods are used?
    • How are assumptions validated?
  2. Evaluate methods, data, and assumptions:

    • Methods: are they in line with IFRS?
    • Data: internal vs external; reliability.
    • Assumptions: reasonable and consistent with other evidence? (e.g. macroeconomic assumptions).
  3. Perform substantive procedures:

    • Test the calculations for mathematical accuracy.
    • Recalculate using auditor’s independent assumptions (develop point estimates or ranges).
    • Perform retrospective review of prior period estimates vs actual outcomes.

Example:

  • Impairment of goodwill for CNS 445 (Pty) Ltd:
    • High judgment and subjectivity in cash flow forecasts and discount rates.
    • Auditor procedures:
      • Test management’s forecasts against historical performance.
      • Challenge growth rates and margins.
      • Compare discount rate to market‑based data.
      • Consider sensitivity analyses.

4.3 Audit Sampling and Use of CAATs

ISA 530 covers audit sampling. At advanced level, you must distinguish:

  • Statistical vs non‑statistical sampling.
  • Sampling risk vs non‑sampling risk.
  • Tests of controls vs substantive tests.

Key points:

  • Sampling risk – risk that sample is not representative, leading to wrong conclusions.
  • Non‑sampling risk – errors due to inappropriate audit procedures, misinterpretation of evidence, or failure to recognise misstatements.

Designing a sample:

  1. Define population, sampling unit, and sampling method.

  2. Determine sample size based on:

    • Risk of material misstatement.
    • Tolerable misstatement or tolerable deviation rate.
    • Expected misstatement.
  3. Select items:

    • Random selection.
    • Systematic selection.
    • Monetary unit sampling.
  4. Perform procedures and evaluate results:

    • Project misstatements to population.
    • Consider nature and cause of errors.
    • Decide whether to extend testing.

Example:
To test occurrence and accuracy of revenue transactions for MNG 0001 Ltd:

  • Population: all sales invoices for the year.
  • Sampling unit: individual invoices.
  • Method: random selection with stratification (e.g. larger values more likely in sample).
  • Sample size: larger if high risk of fraud or weak controls.

CAATs can support sampling by:

  • Extracting a random sample directly from the client’s database.
  • Identifying high‑risk items (e.g. near year‑end, unusual amounts).

4.4 Substantive Analytical Procedures

At advanced level, analytical procedures can be powerful, especially for high‑volume, predictable areas (e.g. utilities, payroll). They can be used:

  • At planning stage – to identify unusual trends and risks.
  • As substantive procedures – to obtain audit evidence.
  • At completion stage – overall review.

Effective analytical procedures require:

  1. Developing an expectation (e.g. based on budgets, prior period, industry data).
  2. Setting a tolerable difference.
  3. Comparing recorded amounts to expectations.
  4. Investigating significant differences.

Examples:

  • Gross profit margin analysis across product lines.
  • Days sales outstanding (DSO) trend analysis for receivables.
  • Ratio of warranty provisions to sales for MNG 0001 Ltd.

When writing exams, be specific:

  • “Calculate gross profit margin by major product category and compare to prior year and industry benchmarks; investigate decreases greater than 2 percentage points.”

4.5 Fraud Considerations (ISA 240)

ISA 240 emphasises the auditor’s responsibility related to fraud. In exams:

  • Differentiate between fraud and error.
  • Recognise management’s responsibility for prevention and detection of fraud.
  • Auditor’s responsibility is to obtain reasonable assurance that financial statements are free from material misstatement due to fraud or error.

Two types of fraud:

  1. Fraudulent financial reporting (e.g. manipulating revenue, expenses).
  2. Misappropriation of assets (e.g. theft of inventory, cash).

Key procedures:

  • Brainstorming sessions with the engagement team about possible fraud risks.

  • Inquiries of management and others about fraud.

  • Incorporating an element of unpredictability in audit procedures.

  • Performing journal entry testing:

    • Focus on unusual entries (manual, late at night, round numbers).
    • Test entries at period end or just after.
    • Examine adjustments directly posted to revenue or profit.
  • Evaluating management override of controls:

    • Review accounting estimates for bias.
    • Review significant unusual transactions.

Exam scenario application:

  • CNS 445 (Pty) Ltd’s CEO exerts pressure to meet listing forecasts. Red flags:
    • Aggressive revenue recognition policies.
    • Late manual journal entries increasing revenue.
    • Bonuses tied to revenue targets.

Required responses:

  • Increase professional scepticism.
  • Expand journal entry testing.
  • Confirm major contracts and revenue terms.
  • Involve senior staff and possibly forensic specialists.

5. Audit Completion, Reporting, and Special Topics

5.1 Going Concern (ISA 570)

Management must assess the entity’s ability to continue as a going concern for at least 12 months from reporting date. The auditor must:

  1. Evaluate management’s assessment.
  2. Consider whether there are events or conditions that may cast significant doubt (e.g. recurring losses, liquidity issues, expiry of loan facilities, pending lawsuits).
  3. Perform procedures:
    • Analyse cash flow forecasts.
    • Review loan agreements and covenants.
    • Read minutes of meetings.
    • Consider post year‑end events (e.g. new finance obtained, loss of major customer).

Three main outcomes:

  1. No material uncertainty:

    • Entity is a going concern; unmodified opinion, with no specific going concern paragraph.
  2. Material uncertainty exists but financial statements adequately disclose it:

    • Unmodified opinion.
    • Include a “Material Uncertainty Related to Going Concern” section highlighting the note and referring to the uncertainty.
  3. Material uncertainty exists and disclosures are inadequate:

    • Qualified or adverse opinion depending on materiality and pervasiveness.

Exam application:

  • MNG 0001 Ltd faces covenant breaches and a net current liability position. You must:
    • Identify the going concern risk.
    • Specify further procedures.
    • Conclude on the type of report needed based on management’s plans and disclosures.

5.2 Subsequent Events (ISA 560)

Subsequent events are those occurring between:

  • The reporting date and the date of the auditor’s report; and
  • After the auditor’s report but before the financial statements issue.

Two types:

  1. Adjusting events – provide evidence of conditions existing at reporting date (e.g. settlement of lawsuit relating to pre‑year‑end event).
  2. Non‑adjusting events – indicative of conditions arising after reporting date (e.g. major fire after year‑end, issue of new shares).

Auditor’s responsibilities:

  • Design and perform procedures to identify subsequent events:

    • Read latest subsequent management accounts.
    • Read minutes of board and shareholder meetings.
    • Inquire of management and lawyers.
    • Obtain written representations.
  • Evaluate impact on financial statements and report:

    • Ensure appropriate adjustments or disclosures.
    • If events discovered after report date:
      • If financial statements are revised, perform necessary procedures and issue new report.
      • If not revised and misstatement is material, consider legal implications and possibly inform users.

5.3 Auditor’s Report (ISA 700, 705, 706, 701)

5.3.1 Unmodified Opinion

Structure of a standard unmodified report:

  1. Opinion.
  2. Basis for opinion.
  3. Key Audit Matters (for listed entities, per ISA 701).
  4. Responsibilities of management and those charged with governance.
  5. Auditor’s responsibilities.
  6. Other reporting responsibilities (if any).
  7. Signature, date, auditor’s address.

An unmodified opinion is expressed when:

  • The auditor concludes financial statements are prepared, in all material respects, in accordance with the applicable financial reporting framework.

5.3.2 Modified Opinions (ISA 705)

Types:

  1. Qualified opinion – material but not pervasive misstatements or limitations.
  2. Adverse opinion – material and pervasive misstatements.
  3. Disclaimer of opinion – material and pervasive limitation of scope; cannot obtain sufficient appropriate evidence.

Reasons for modification:

  • Misstatements (e.g. incorrect revenue recognition, inappropriate going concern basis).
  • Inability to obtain sufficient appropriate audit evidence (e.g. unable to observe inventory count and alternative procedures not possible).

Exam technique:

  • Clearly identify:
    • Nature of issue (misstatement or limitation).
    • Materiality and pervasiveness.
    • Appropriate type of opinion.
    • Content of the Basis for Qualified/Adverse/Disclaimer paragraph.

Example:

  • CNS 445 (Pty) Ltd prohibits auditor from confirming major debtors representing 40% of receivables, and alternative procedures fail. This is:
    • Limitation of scope.
    • Material and pervasive.
    • Likely leads to disclaimer of opinion.

5.3.3 Emphasis of Matter and Other Matter Paragraphs (ISA 706)

  • Emphasis of Matter (EOM):

    • Draws user attention to matter presented or disclosed in financial statements that is fundamental to understanding them.
    • Does not modify the opinion.
    • Example: Significant subsequent event properly disclosed (e.g. major lawsuit settlement after year‑end).
  • Other Matter:

    • Refers to matters not presented or disclosed in financial statements but relevant to users’ understanding of the audit, auditor’s responsibilities, or report.
    • Example: Explaining that a prior period financial statement was audited by another auditor.

In exam answers, be explicit whether a situation requires a modified opinion or only an EOM paragraph.

5.3.4 Key Audit Matters (ISA 701)

For listed entities, auditor reports must describe KAMs:

  • Matters that, in the auditor’s professional judgment, were of most significance in the audit.
  • Selected from matters communicated with those charged with governance.

KAMs typically involve:

  • Areas of significant management judgment (e.g. goodwill impairment).
  • Significant risks per ISA 315.
  • Significant transactions or events during the period.

Exam application:

  • For CNS 445 (Pty) Ltd (listed):

    • Potential KAMs:
      • Revenue recognition for complex contracts.
      • Impairment of capitalised development costs.
      • Going concern uncertainties.
  • For each KAM, the report should:

    • Describe why it is a KAM.
    • How the auditor addressed it (e.g. procedures performed).
    • Reference relevant disclosures.

5.4 Group Audits (ISA 600)

In AUE4861, group audits are a common topic.

Key concepts:

  • Group engagement partner is responsible for direction, supervision, and performance of the group audit.
  • Need to understand group, components, and component auditors.
  • Assess whether sufficient appropriate audit evidence can be obtained on the financial information of components.

Steps:

  1. Understand the group structure:

    • Components (subsidiaries, associates, joint ventures).
    • Locations (e.g. MNG 0001 Ltd’s Zimbabwe branch).
  2. Perform group‑wide risk assessment:

    • Identify significant components (due to individual financial significance or specific risks).
    • Determine nature, timing, and extent of work on components.
  3. Involve component auditors:

    • Evaluate their competence and independence.
    • Provide clear instructions:
      • Identified significant risks.
      • Work to be performed.
      • Materiality for component.
      • Reporting form and timing.
  4. Evaluate component auditors’ work:

    • Review reports and, if necessary, selected working papers.
    • Discuss findings and issues.
    • Consider whether additional procedures are needed.
  5. Consolidation procedures:

    • Test consolidation process.
    • Elimination of intercompany transactions and balances.
    • Foreign currency translation.
    • Non‑controlling interests and equity method.

Reporting implications:

  • Reference to component auditors in group report usually not made, except in limited circumstances (e.g. law/regulation requires).
  • Group engagement partner must not refer to component auditor’s report as a basis for opinion if not permitted.

Exam answers must show:

  • Clear understanding of how to plan, communicate, and evaluate component work.
  • Awareness of risks in cross‑border audits (e.g. regulatory differences, language barriers).

5.5 Special Purpose Engagements and Other Assurance

AUE4861 may also touch on other assurance and related services:

  • Review engagements (ISRE 2400/2410):

    • Provide limited assurance (negative assurance).
    • Procedures mainly inquiry and analytical procedures.
    • Less work than an audit; lower level of assurance.
  • Agreed‑upon procedures engagements (ISRS 4400):

    • Auditor performs procedures agreed with the engaging party.
    • No assurance is provided; only factual findings reported.
  • Prospective financial information (ISAE 3400):

    • Examination of forecasts and projections.
    • Emphasis on reasonableness of assumptions.
  • Assurance on non‑financial information (e.g. sustainability or integrated reporting):

    • Increasingly important in South African context (aligned with King IV).
    • May be limited or reasonable assurance engagements.

Exam tasks might include:

  • Differentiating between audit, review, and agreed‑upon procedures.
  • Advising a client which type of engagement is appropriate.
  • Explaining implications for assurance level and report wording.

5.6 Exam Strategy: Integrating Knowledge in AUE4861

To succeed in UNISA AUE4861 Advanced Auditing, integrate the above content with strong exam skills:

  1. Keyword focus for South African students:

    • Search and use past AUE4861 UNISA exam papers, UNISA CTA AUE4861 study notes, and examiners’ feedback.
    • Students from other universities (e.g. CUT AUD402, UJ AUD400, NWU AUEP 672) can use similar techniques and theory.
  2. Case‑study technique:

    • Read the required first, then skim scenario for relevant facts.
    • Use structured headings: “Risk”, “Implication”, “Procedures”.
    • Apply professional language and reference appropriate ISAs when relevant, without quoting them verbatim.
  3. Manage time and depth:

    • Prioritise high‑mark, integrative questions.
    • For each required, aim for one clear, well‑explained point per mark.
    • Avoid over‑long essays; stick to concise, exam‑style bullet points that show application.
  4. Link modules:

    • Use knowledge from FAC4861, TAX4861, MAC4861 to better understand transactions, estimates, and risk.
    • For instance, understanding deferred tax or fair value accounting helps design better audit procedures.
  5. Practice under exam conditions:

    • Attempt full past papers within allotted time.
    • After each attempt, debrief:
      • Which topics repeatedly appear?
      • Did you link business risk to audit risk properly?
      • Were your procedures sufficiently specific, relevant, and assertion‑linked?

By mastering professional ethics and governance, risk assessment and internal control, substantive procedures and sampling, and audit completion and reporting, UNISA CTA students will be well‑positioned to pass AUE4861 Advanced Auditing and progress towards ITC and APC.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare