These comprehensive study notes are tailored for Nelson Mandela University (NMU): BCom Accounting Sciences (CA Stream) students registered for RGO301: Auditing 3.1, but they are also useful for students at other South African universities such as UNISA (e.g. AUE3701, AUE3781) and Central University of Technology (CUT) (e.g. AUA30AS) preparing for auditing examinations. The notes focus on key examinable areas in intermediate auditing, with emphasis on South African Auditing Standards, the Companies Act, and typical assessment approaches used by NMU and similar institutions. Concepts are illustrated with practical examples that resemble those found in past NMU RGO301 exam papers and UNISA AUE modules.
1. Overview of the Auditing Environment in South Africa
1.1 Purpose and Objective of an Audit
Auditing at the RGO301 / Auditing 3.1 level builds on introductory courses (such as NMU’s RGO101 or equivalent first‑year modules at UNISA and CUT). The fundamental purpose of an audit remains the same:
To enable the auditor to express an opinion on whether the financial statements are prepared, in all material respects, in accordance with an applicable financial reporting framework.
In South Africa this usually means expressing an opinion on financial statements prepared in accordance with IFRS or IFRS for SMEs, and in compliance with the Companies Act 71 of 2008 where applicable.
Key aspects of the audit objective:
- Reasonable assurance:
- The auditor provides a high, but not absolute, level of assurance.
- The auditor reduces audit risk to an acceptably low level but cannot eliminate it.
- Material misstatement:
- Focus is on errors or frauds that could reasonably influence users’ decisions.
- The concept of materiality is both quantitative (size) and qualitative (nature).
- Applicable financial reporting framework:
- IFRS / IFRS for SMEs.
- Legislation such as the Companies Act for companies, and other sector‑specific requirements for public entities or NPOs.
Exam tip (RGO301 / AUE3701 style): Questions often ask you to distinguish between reasonable assurance and absolute assurance, or to explain why an audit does not guarantee the future viability of an entity or the complete absence of fraud. Explicitly link your explanation to inherent limitations of an audit (discussed below).
1.2 The South African Regulatory Framework
RGO301 assumes familiarity with the local environment. The main players and standards are:
- IRBA (Independent Regulatory Board for Auditors)
- Regulates registered auditors in South Africa.
- Issues South African Auditing Practice Statements (SAAPS) and adopts International Standards on Auditing (ISA).
- Maintains the Code of Professional Conduct for Registered Auditors, aligned with the IESBA Code.
- SAICA (South African Institute of Chartered Accountants)
- Professional body for Chartered Accountants [CA(SA)].
- Sets the educational requirements and competencies tested in undergraduate courses such as NMU’s BCom Accounting Sciences (CA stream), UNISA CTA, and CUT BTech/BCom accounting programmes.
- Companies Act 71 of 2008
- Prescribes when a company must be audited or independently reviewed (public interest score thresholds).
- Governs appointment, rotation (for certain categories), removal and duties of auditors.
- King IV Report on Corporate Governance
- Not a standard but a governance framework with recommended practices.
- Influences audit committees, internal audit, and combined assurance approaches.
Why this matters for exams:
- RGO301 case studies often involve a South African company where you must:
- Identify whether an audit is required.
- Comment on auditor appointment and rotation.
- Discuss governance issues and the role of the audit committee.
- You must be able to cite or at least refer to the Companies Act and ISA principles accurately.
1.3 Types of Engagements and Levels of Assurance
Auditors may perform various assurance and related services engagements:
-
Audit Engagements – Reasonable Assurance
- Objective: Express a positive opinion (e.g. “give a true and fair view”).
- Example: Statutory audit of a public company required by the Companies Act.
- Guided by ISAs (e.g. ISA 200, 300, 315, 330).
-
Review Engagements – Limited Assurance
- Objective: Express a negative assurance conclusion (e.g. “nothing has come to our attention…”).
- Uses enquiry and analytical procedures primarily.
- In South Africa, reviews of non‑public companies may be performed using ISRE 2400 (Revised).
-
Other Assurance Engagements
- Example: assurance on sustainability or integrated reports (ISAE 3000).
- Agreed‑upon procedures engagements (ISRS 4400) where no opinion is expressed, only factual findings.
-
Non‑assurance / Related Services
- Compilation engagements (ISRS 4410) where no assurance is provided.
- Tax consulting, accounting services, etc., subject to independence considerations.
Exam patterns across NMU, UNISA, CUT:
- Short questions might ask you to compare audit vs review or list differences between assurance and non‑assurance engagements.
- Scenario questions may require you to recommend the appropriate engagement type for a specific client (e.g. small owner‑managed company vs listed entity).
1.4 Inherent Limitations of an Audit
Understanding inherent limitations is crucial for explaining why auditors cannot detect all frauds and errors:
-
Use of Sampling
- It is impractical to test every transaction.
- Auditors use judgement and statistical / non‑statistical sampling methods.
- Even well‑selected samples can miss exceptions.
-
Nature of Evidence
- Audit evidence is generally persuasive rather than conclusive.
- Some evidence is inherently less reliable (e.g. management representations).
- Complex estimates (e.g. impairments, provisions) involve judgement and uncertainty.
-
Inherent Limitations of Accounting and Control Systems
- Controls can be overridden by management.
- Collusion can circumvent segregation of duties.
- Human error and system breakdowns are always possible.
-
Time and Cost Constraints
- Engagements are planned to be efficient and cost‑effective.
- Auditors focus on material aspects and cannot investigate every minor issue.
-
Future Events and Going Concern
- Audits deal primarily with historical information.
- Going concern assessment is based on information available at the date of the auditor’s report and may later prove incorrect due to unforeseen circumstances.
How to use this in exam answers:
When a question asks why an audit failed to detect a major fraud, structure your answer:
- Start with inherent limitations in general.
- Apply specifically: collusion between employees, management override, complexity of financial instruments, etc.
- Conclude that despite these limitations, auditors still have to comply with ISAs and exercise professional scepticism; failure can also be due to audit deficiencies, not just limitations.
1.5 Stakeholders and the Expectation Gap
The audit expectation gap is a recurring examination theme at NMU and UNISA. It refers to the difference between:
- What users of financial statements believe auditors are responsible for, and
- What auditors are actually required to do in terms of standards and legislation.
Main user groups:
- Shareholders and potential investors.
- Lenders (banks, bondholders).
- Employees and unions.
- Revenue authorities.
- Regulators (e.g. FSCA).
- The general public for public interest entities.
Common misconceptions:
- Users often expect auditors to:
- Detect all frauds and all errors.
- Guarantee the future profitability or survival of the entity.
- Test 100% of transactions.
- In reality, auditors:
- Provide reasonable assurance regarding material misstatements.
- May not detect well‑concealed frauds, particularly those involving management override and collusion.
- Are not responsible for the entity’s business decisions or future performance.
Bridging the expectation gap:
- Enhanced reporting under ISA 700 (Revised) and ISA 701 on Key Audit Matters (KAMs).
- Public education, training for directors and audit committees.
- Clear engagement letters (ISA 210) setting out auditor and management responsibilities.
Example exam application:
A typical RGO301 question may provide a media extract criticising auditors after a corporate failure. You may have to:
- Define the audit expectation gap.
- Identify unrealistic expectations in the extract.
- Suggest how auditors and regulators could reduce the gap.
2. Professional Ethics and Independence
2.1 Fundamental Principles of Professional Ethics
The IRBA Code of Professional Conduct (aligned with the IESBA Code) sets out five fundamental principles that all registered auditors must observe:
-
Integrity
- Being straightforward and honest in all professional and business relationships.
- No intentional misstatements, misrepresentations, or association with misleading information.
-
Objectivity
- Avoid bias, conflict of interest, or undue influence of others.
- Do not allow personal relationships or financial interests to override professional judgement.
-
Professional Competence and Due Care
- Maintain knowledge and skill at a level required to ensure competent professional service.
- Act diligently and in accordance with applicable technical and professional standards.
-
Confidentiality
- Respect the confidentiality of information acquired as a result of professional and business relationships.
- Do not disclose such information without proper and specific authority, unless there is a legal or professional right or duty to disclose.
-
Professional Behaviour
- Comply with relevant laws and regulations.
- Avoid any conduct that discredits the profession (e.g. false advertising, disparaging other professionals).
Exam focus:
- NMU’s RGO301 and UNISA’s AUE modules frequently present ethical dilemmas involving two or more of these principles.
- Answers must clearly:
- Identify which principles are threatened.
- Explain how they are threatened.
- Suggest practical safeguards.
2.2 Threats to Independence and Objectivity
The IRBA Code identifies five broad categories of threats to independence:
-
Self‑interest Threat
- Financial or other interests that could inappropriately influence the auditor’s judgement.
- Examples:
- Direct financial interest in the audit client (e.g. owning shares).
- Undue dependence on total fees from one client (fee dependency).
- Contingent fee arrangements.
-
Self‑review Threat
- Occurs when an auditor reviews a judgement or data that they previously prepared or were involved in.
- Examples:
- Providing accounting services that feed into the financial statements then auditing those same statements.
- Designing and implementing financial reporting systems and then auditing the system’s output.
-
Advocacy Threat
- Occurs when an auditor promotes a client’s position or opinion to the point that objectivity may be compromised.
- Examples:
- Acting as an advocate in legal disputes for the client.
- Representing the client to tax authorities in a way that appears to support aggressive or dubious tax schemes.
-
Familiarity Threat
- Arises from a close relationship with a client or its personnel.
- Examples:
- Long association of senior personnel with the engagement.
- Close family or personal relationships with client management.
- Acceptance of gifts or hospitality.
-
Intimidation Threat
- When the auditor is deterred from acting objectively due to actual or perceived pressures.
- Examples:
- Threat of replacement over a disagreement on accounting treatment.
- Dominant personality in management who intimidates audit staff.
- Litigation or threat of litigation by the client.
Illustrative RGO301-style scenario:
- The engagement partner for Mandla Ltd has been the partner for 12 years and plays golf weekly with the financial director. The audit firm also prepared the company’s financial statements.
- Threats identified:
- Familiarity (long association, personal relationship).
- Self‑review (audit of financial statements prepared by the firm).
- Impacted principles:
- Objectivity, professional behaviour, possibly integrity.
- Threats identified:
2.3 Safeguards to Address Ethical Threats
When threats are identified, the auditor must determine whether they are at an acceptable level. If not, safeguards must be applied or the relationship / engagement must be terminated.
Firm-level safeguards (policies and procedures):
- Independence and conflict‑of‑interest checks before accepting engagements.
- Rotation policies for partners and senior staff.
- Prohibiting certain non‑assurance services to audit clients (especially public interest entities).
- Quality control systems (ISQC 1 / ISQM 1) including internal reviews and hot‑file reviews.
Engagement-level safeguards:
- Using different personnel for non‑assurance and assurance services.
- Independent review of key judgements by a partner not involved in the engagement.
- Consulting with a technical department or external experts.
- Disclosing to those charged with governance the nature of services and safeguards applied.
When safeguards are not sufficient:
- Decline or terminate the engagement.
- Remove or replace affected individuals from the team.
- Dispose of financial interests that give rise to self‑interest threats.
Exam application:
Question structures often follow this pattern:
- Identify the threat category (self‑interest, self‑review, etc.).
- Explain why it is a threat, referencing specific facts.
- Suggest realistic safeguards that the firm could implement.
- Conclude whether the firm may continue as auditor and under what conditions.
Providing generic safeguards without linking to the scenario will not earn full marks. Tailor your answer to the facts given.
2.4 Independence in Mind vs Independence in Appearance
Independence has two dimensions:
- Independence of mind:
- The auditor’s actual state of mind that permits the provision of an opinion without being affected by influences that compromise professional judgement.
- Independence in appearance:
- The avoidance of facts and circumstances that are so significant that a reasonable and informed third party would be likely to conclude that the firm’s or a member of the audit team’s integrity, objectivity or professional scepticism has been compromised.
Both must be present for an audit to be credible to the market.
Practical examples:
- An auditor may feel they are independent (independence of mind) even though they hold a small shareholding in the client. However, a reasonable investor might see this as compromising independence (appearance).
- A partner’s spouse working as the client’s CFO may seriously impair independence in appearance, and in many cases in mind as well.
Companies Act requirements:
- For public companies and some state‑owned entities, audit committees must nominate the auditor and must consider the auditor’s independence.
- Certain restrictions on the provision of non‑audit services to audit clients may also be imposed by regulations and King IV guidance.
Exam tip (NMU / UNISA pattern):
When asked to comment on independence, clearly use the terms “independence of mind” and “independence in appearance” in your explanation. Where a fact might not create an actual bias but could appear so, mention the potential impact on the public’s perception and users’ confidence in the audit report.
2.5 Confidentiality and Whistle‑Blowing
While confidentiality is a fundamental principle, there are situations where an auditor may have a legal or professional duty to disclose information:
- Required by law or regulation:
- Reporting to the South African Revenue Service (SARS) in terms of tax legislation.
- Reporting reportable irregularities to IRBA in terms of the Auditing Profession Act.
- Permitted by law and authorised by the client:
- Providing information to prospective investors when engaged to do so by the client.
- Public interest considerations:
- NOCLAR (Non‑Compliance with Laws and Regulations) guidance in the IRBA Code may require external reporting under certain circumstances.
Reportable Irregularities:
- Defined in the Auditing Profession Act as any unlawful act or omission committed by any person responsible for the management of an entity, which has caused or is likely to cause material financial loss or is fraudulent or amounts to a material breach of fiduciary duty.
- Auditors must:
- Report in writing to IRBA within a prescribed period (usually 3 days) after becoming aware.
- Inform management and request them to rectify.
- Submit a follow‑up report to IRBA after 30 days on whether the irregularity has been rectified.
Exam application:
- Often examined in scenario form: an auditor becomes aware of possible VAT fraud or misappropriation of funds by directors.
- You must:
- Identify that this is or may be a reportable irregularity.
- Outline the auditor’s reporting obligations.
- Discuss the balance between confidentiality and public interest.
2.6 Ethics for Internal Auditors vs External Auditors
Though RGO301 focuses on external auditing, internal audit’s ethical framework is often tested:
- Internal auditors follow the IIA Code of Ethics (Integrity, Objectivity, Confidentiality, Competency).
- Internal auditors are employees of the entity but should have organisational independence through direct reporting lines to the audit committee.
- Their independence is narrower in scope compared to external auditors but remains critical for objective assurance work.
Comparison points for exams:
- External auditors are independent from the entity, appointed by shareholders and regulated by IRBA.
- Internal auditors are part of the entity, but independence is achieved through governance structures.
- External auditors issue an opinion on financial statements; internal auditors focus on risk management, controls, and governance.
3. Audit Planning, Risk Assessment and Materiality
3.1 Stages of an Audit
Auditing 3.1 at NMU expects you to understand the full audit cycle, not just isolated procedures. The stages are:
-
Client Acceptance and Continuance
- Assess integrity of management.
- Evaluate whether the firm has competence, resources, and can comply with ethical requirements.
- Consider independence and potential conflicts of interest.
- Document acceptance / continuance decisions.
-
Engagement Letter (ISA 210)
- Written agreement outlining:
- Objective and scope of the audit.
- Responsibilities of management and auditor.
- Applicable financial reporting framework.
- Form and content of reports.
- Written agreement outlining:
-
Planning (ISA 300)
- Develop an overall audit strategy.
- Prepare a detailed audit plan.
- Risk assessment procedures to obtain understanding of the entity and its environment.
-
Risk Assessment (ISA 315)
- Identify and assess the risks of material misstatement at the financial statement and assertion levels.
- Understand internal control relevant to the audit.
-
Response to Risks (ISA 330)
- Design and implement further audit procedures:
- Tests of controls (if relying on controls).
- Substantive procedures: analytical procedures and tests of details.
- Design and implement further audit procedures:
-
Completion and Reporting
- Evaluate misstatements identified.
- Perform overall analytical review.
- Obtain written representations (ISA 580).
- Form an opinion and issue the auditor’s report (ISA 700 and related standards).
Exam usage:
- Many RGO301 questions require you to identify which stage of the audit a certain action belongs to, or how a planning deficiency explains detected misstatements.
- For longer case studies, structure your answers around these stages for clarity and logical flow.
3.2 Understanding the Entity and Its Environment
ISA 315 requires auditors to obtain an understanding of:
-
Industry, regulatory environment and external factors
- Economic conditions, competition, technology changes.
- Relevant regulatory framework (e.g. JSE listing requirements, sector‑specific laws).
-
Nature of the entity
- Operations, ownership, governance structure.
-Types of investments, financing structure, business model.
- Operations, ownership, governance structure.
-
Objectives, strategies, and business risks
- Plans for expansion, cost‑cutting, product diversification.
- Risks from changes in technology, foreign exchange exposure, etc.
-
Measurement and review of financial performance
- Key performance indicators (KPIs) used by management.
- Internal budgets, variance analysis, incentive structures.
-
Internal control
- Control environment, risk assessment process, information systems, control activities, and monitoring.
Illustrative example:
Suppose you are auditing AlgoTech (Pty) Ltd, an Eastern Cape manufacturing company:
- Industry risk:
- High competition, rapid technological obsolescence, cyclical demand.
- Entity risk:
- High gearing, reliance on a single major customer for 40% of revenue.
- Business risk:
- Customer concentration risk could lead to going concern issues if the major contract is lost.
- Audit implications:
- Focus on revenue recognition, impairment of receivables, valuation of inventory, and going concern assessment.
3.3 Audit Risk, Inherent Risk, Control Risk and Detection Risk
Audit risk is the risk that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated.
The model:
Audit Risk (AR) = Risk of Material Misstatement (RMM) × Detection Risk (DR)
Where: RMM = Inherent Risk (IR) × Control Risk (CR)
-
Inherent Risk (IR)
- Susceptibility of an assertion to misstatement, assuming no related controls.
- Higher where transactions are complex, involve significant judgement, or are subject to fraud risk.
- Examples:
- Complex financial instruments.
- Significant estimates (provisions, impairments).
- Cash‑intensive businesses.
-
Control Risk (CR)
- Risk that a misstatement will not be prevented or detected and corrected on a timely basis by the entity’s internal controls.
- Dependent on design and operating effectiveness of controls.
-
Detection Risk (DR)
- Risk that the auditor’s procedures will not detect a misstatement that exists and could be material.
- Controlled by the auditor through the nature, timing and extent of audit procedures.
Balancing the model:
-
If RMM is high, the auditor must reduce detection risk by:
- Increasing sample sizes.
- Performing more substantive tests.
- Shifting testing closer to year‑end.
- Using more experienced staff.
-
If RMM is low, the auditor may accept a higher detection risk and perform fewer or less rigorous procedures (while still meeting ISA requirements).
Typical exam requirements:
- Given a scenario, you may be asked to:
- Identify factors increasing inherent risk.
- Assess control risk based on internal control descriptions.
- Explain the impact on the nature, timing and extent of substantive procedures.
- Understanding the audit risk model is critical for answering these questions logically.
3.4 Materiality and Performance Materiality
Materiality is central to planning and evaluating the impact of misstatements:
- A misstatement is material if it could reasonably be expected to influence the economic decisions of users taken on the basis of the financial statements.
Steps:
-
Set overall (financial statement) materiality
- Often calculated as a percentage of a benchmark (profit before tax, revenue, total assets, equity).
- Example calculation:
- Profit before tax: R10 million.
- Auditor chooses 5% as a guideline.
- Overall materiality = R10 million × 5% = R500 000.
-
Set performance materiality
- Amount set at less than overall materiality to reduce to an appropriately low level the probability that aggregate uncorrected misstatements exceed overall materiality.
- Often between 50% and 75% of overall materiality, depending on risk.
- Example:
- Overall materiality: R500 000.
- Performance materiality: 70% of R500 000 = R350 000.
-
Set specific materiality for particular classes of transactions, account balances or disclosures
- Where misstatements of lesser amounts than overall materiality could influence users’ decisions (e.g. related‑party transactions, directors’ remuneration).
-
Reassess materiality during the audit
- If circumstances change significantly (e.g. a large, unexpected loss reduces profit).
Tolerable misstatement vs performance materiality:
- In practice, auditors may allocate performance materiality to specific account balances (called tolerable misstatement for each balance), guiding sample sizes.
Exam application:
You may receive a trial balance and be asked to:
- Calculate overall and performance materiality using a justified benchmark and percentage.
- Discuss the impact of materiality on:
- The planning of audit procedures.
- The evaluation of identified misstatements.
- Communication with management and those charged with governance.
Be explicit about which benchmark you choose and why it is appropriate (e.g. for a profit‑oriented entity, use profit before tax; for a low‑profit or loss‑making entity, consider revenue or total assets).
3.5 Documentation of Planning
ISA 230 requires sufficient appropriate documentation. For planning, this typically includes:
-
Overall audit strategy memorandum
- Scope, timing, direction of the audit.
- Resources planned (staffing, use of experts, component auditors).
-
Detailed audit plan / programme
- Specific audit procedures by assertion (existence, completeness, accuracy, valuation, rights and obligations, presentation and disclosure).
-
Risk assessment documentation
- Identified significant risks and related controls.
- Linkage between risks and audit responses.
-
Materiality documentation
- Basis for materiality and performance materiality.
- Any revisions.
-
Understanding of the entity
- Minutes of discussions with management.
- Analytical procedures at planning stage (e.g. ratio analysis).
Importance for quality and exams:
- Proper documentation supports the conclusions reached and enables review and quality control.
- In exam questions, showing a logical documented flow from risk assessment to audit procedures often earns higher marks.
4. Internal Control Systems and Tests of Controls
4.1 Components of Internal Control (COSO Framework)
Auditing 3.1 requires you to apply the COSO internal control framework, consisting of five interrelated components:
-
Control Environment
- Tone at the top.
- Integrity and ethical values of management.
- Organisational structure, assignment of authority and responsibility.
- Human resource policies and practices.
-
Entity’s Risk Assessment Process
- Management’s identification and analysis of relevant risks to achievement of objectives.
- How risks are assessed (likelihood and impact), prioritised and addressed.
-
Information System and Communication
- Procedures and records established to initiate, record, process and report transactions.
- IT systems, manual processes, and communication of roles and responsibilities.
-
Control Activities
- Policies and procedures that ensure management directives are carried out.
- Examples:
- Authorisations and approvals.
- Reconciliations.
- Segregation of duties.
- Physical controls over assets.
- Performance reviews.
-
Monitoring of Controls
- Ongoing and separate evaluations (e.g. internal audit).
- Management review of control performance.
Exam expectation:
- Given narrative descriptions of systems, you may have to:
- Classify controls under these components.
- Identify strengths and weaknesses.
- Recommend improvements.
4.2 Limitations of Internal Control
Despite careful design, internal control systems have limitations:
- Human error in processing transactions or operating controls.
- Collusion among employees, which can circumvent segregation of duties.
- Management override of controls, especially in closely held companies.
- Cost‑benefit trade‑off:
- Cost of control should not exceed expected benefit.
- Small entities may not implement sophisticated controls due to cost constraints.
These limitations reinforce the need for substantive procedures even where controls appear effective.
4.3 Documenting Internal Controls: Narratives, Flowcharts and ICQs
Auditors document understanding of internal controls in several ways:
-
Narratives
- Written description of the system.
- Clear, detailed explanation of transaction flows and controls.
-
Flowcharts
- Visual representation using standard symbols to show processing steps, documents and information flow.
- Useful to understand complex systems quickly.
-
Internal Control Questionnaires (ICQs)
- Structured questions about control procedures (typically closed‑ended, Yes/No).
- “Yes” answers usually indicate the presence of a control.
- “No” answers indicate potential control weaknesses.
Example ICQ excerpt for purchases cycle (suppliers and payments):
| Question | Yes/No | Comments |
|---|---|---|
| Are all purchase orders pre‑numbered and accounted for? | ||
| Is the person authorising purchase orders independent of those receiving goods? | ||
| Are supplier statements reconciled to creditors’ ledgers monthly? |
In exams, you may be asked to:
- Draft a part of an ICQ for a specific cycle.
- Convert a narrative into a flowchart (or vice versa).
- Identify weaknesses in internal control descriptions and suggest improvements.
4.4 Tests of Controls vs Substantive Procedures
Tests of controls (TOCs):
- Designed to evaluate the operating effectiveness of controls in preventing, or detecting and correcting, material misstatements.
- Typical procedures:
- Inspection of documents for evidence of authorisation.
- Observation of control performance (e.g. stock counts).
- Reperformance of control procedures.
- Enquiry of personnel (supported by other evidence).
Substantive procedures:
- Designed to detect material misstatements at the assertion level.
- Two main types:
- Substantive analytical procedures (e.g. ratio analysis, trend analysis).
- Tests of details (e.g. examining invoices, confirming balances).
Relationship between TOCs and substantive procedures:
- If the auditor plans to rely on controls to reduce substantive testing, TOCs must be performed.
- If controls are weak or not relevant, the auditor may adopt a substantive approach with minimal TOCs.
Exam scenario example (RGO301 / AUE3701 style):
- You are given a description of the sales system, including:
- Credit checks by credit controller.
- Pre‑numbered sales orders and invoices.
- Independent review of discounts by the finance manager.
- Requirements may include:
- Identify key controls and explain the purpose of each.
- Design specific tests of controls for each key control.
- Discuss the impact on substantive procedures if certain controls are found ineffective.
4.5 Evaluating the Purchases and Cash Payments Cycle
The purchases and cash payments cycle is a favourite topic for intermediate auditing exams. Key stages:
-
Requisition of goods / services
- Initiated by a purchase requisition, authorised by appropriate manager.
-
Ordering
- Purchase order (PO) prepared, pre‑numbered, and authorised.
- Vendor selection procedures (approved supplier list).
-
Receiving
- Goods received note (GRN) prepared upon delivery.
- Independent count and inspection of goods by stores department.
-
Recording
- Supplier invoice recorded only after matching PO, GRN and invoice (three‑way match).
- Entries posted to creditors’ ledger and general ledger.
-
Payment
- Payments authorised based on supporting documentation.
- Segregation between those who authorise payments, record them, and handle cash.
Key controls and example tests of controls:
| Stage | Key Control | Test of Control |
|---|---|---|
| Ordering | POs are pre‑numbered and authorised by procurement head | Inspect a sample of POs for sequence and authorisation signatures. |
| Receiving | GRNs prepared by receiving staff and matched to POs | Inspect GRNs to confirm evidence of matching and independent quantity checks. |
| Recording | Supplier invoices matched with PO and GRN before posting | Inspect a sample of invoices and check for evidence of matching and approval. |
| Payment | Two signatories required on all EFT payments | Inspect payment documentation for signatures; observe EFT authorisation process. |
Potential weaknesses to look for in cases:
- Lack of segregation: same person orders, receives, records and pays.
- No independent review of supplier reconciliations.
- Use of manual, non‑pre‑numbered documents.
- No review of changes to supplier master file (risk of fictitious suppliers).
Your exam answer should:
- Identify specific control weaknesses (not generic statements).
- Explain the risk posed (e.g. unauthorised purchases, payments to fictitious suppliers).
- Recommend practical improvements (e.g. dual authorisation for new suppliers, reconciliations).
4.6 Computerised vs Manual Systems
Modern audits must deal with IT‑dependent environments. RGO301 expects you to understand:
-
General IT controls (GITCs):
- Data centre and network operations controls.
- Program change controls.
- Access security controls.
- System development and maintenance controls.
-
Application controls:
- Input controls (validation checks).
- Processing controls (run‑to‑run totals).
- Output controls (reconciliations, distribution controls).
Impact on the audit:
- Strong GITCs and application controls may allow greater reliance on system‑generated reports.
- Weak IT controls might necessitate more substantive testing, including manual recalculation or independent data extraction.
Example exam angle:
A problem may describe that:
- User IDs and passwords are shared.
- Program changes are made by operational staff without testing.
- No logs are maintained of user access.
You must:
- Identify that access controls and program change controls are weak.
- Explain risks (unauthorised transactions, data manipulation).
- Recommend controls (unique user IDs, segregation between developers and operators, change logs, testing procedures).
5. Substantive Procedures, Audit Evidence and Reporting
5.1 Nature and Sources of Audit Evidence
Audit evidence is information used by the auditor in arriving at the conclusions on which the audit opinion is based. It includes information from:
- Accounting records:
- Source documents (invoices, contracts, bank statements).
- Journals, ledgers, trial balances.
- Other information:
- External confirmations.
- Minutes of meetings.
- Management representations.
- Observations, enquiries, analytical procedures.
Characteristics of sufficient appropriate audit evidence:
-
Sufficiency:
- Measure of quantity of evidence.
- Influenced by risk of material misstatement and quality of evidence.
-
Appropriateness:
- Measure of quality of evidence, i.e. relevance and reliability.
- Evidence is more reliable if:
- Obtained from independent external sources.
- Generated internally under effective controls.
- Obtained directly by the auditor (observation, recalculation).
- In documentary form rather than oral representations.
- Original documents rather than copies.
Exam application:
- Questions often ask you to evaluate the sufficiency and appropriateness of evidence described in a case.
- You should comment on:
- Whether the evidence directly addresses the assertion being tested.
- Whether it is internally vs externally generated.
- Whether further corroboration is needed.
5.2 Substantive Analytical Procedures
Substantive analytical procedures involve evaluating financial information through analysis of:
- Plausible relationships between financial and non‑financial data.
- Investigation of fluctuations or relationships inconsistent with other relevant information.
Examples:
- Ratio analysis (gross profit margin, current ratio, inventory turnover).
- Trend analysis over multiple years.
- Reasonableness tests (e.g. expected interest expense based on loan balances and rates).
When used:
- Often at planning stage to identify unusual areas.
- Can be used as substantive procedures where relationships are predictable and internal controls are reliable.
- Required at completion stage for an overall review.
Example:
If AlgoTech’s gross profit margin drops from 30% to 20% while sales volume has remained steady, an auditor might:
- Investigate price cuts, increased cost of sales, or inventory write‑downs.
- Perform further substantive tests on revenue recognition and inventory valuation.
Exam focus:
- Identify where analytical procedures would be more efficient and effective than tests of details.
- Provide specific examples of analytical procedures for certain balances (e.g. depreciation expense, payroll costs).
- Interpret analytical results and suggest further actions.
5.3 Tests of Detail – Examples by Assertion
Common financial statement assertions and typical substantive procedures include:
-
Existence
- Assets, liabilities, and equity interests exist at a given date.
- Procedures:
- Physical inspection (e.g. inventory counts, fixed assets).
- Debtors’ confirmations.
- Vouching recorded transactions to source documents.
-
Completeness
- All transactions and accounts that should be recorded have been recorded.
- Procedures:
- Tracing from source documents to accounting records (e.g. receiving reports to purchases journal).
- Cut‑off tests at year‑end.
- Search for unrecorded liabilities (review of subsequent payments, review of unmatched GRNs).
-
Accuracy, Valuation and Allocation
- Amounts and other data are recorded appropriately; assets, liabilities and equity are included at appropriate amounts.
- Procedures:
- Recalculation of depreciation, interest, amortisation.
- Testing aged receivables and reviewing subsequent receipts.
- Evaluating inventory costing methods and net realisable value.
-
Rights and Obligations
- Entity holds or controls the rights to assets and owes the obligations for liabilities.
- Procedures:
- Inspecting title deeds, contracts, lease agreements.
- Confirmations of loans and security arrangements.
-
Presentation and Disclosure
- Components of financial statements are properly classified, described and disclosed.
- Procedures:
- Reviewing financial statements against disclosure checklists.
- Assessing compliance with IFRS / IFRS for SMEs and Companies Act.
Exam application:
You may be asked to design substantive procedures for a particular balance in a case (e.g. trade receivables, inventory). Always:
- Identify which assertions you are addressing.
- Write clear, specific procedures (not vague statements like “inspect documents”).
- Tailor to the scenario (e.g. if there is a new product line or unusual transaction).
5.4 External Confirmations (ISA 505)
External confirmations are powerful and commonly examined:
- Examples:
- Bank confirmations of balances, loans, guarantees.
- Debtors’ circularisations.
- Confirmations of accounts payable.
- Legal letters from attorneys regarding litigation and claims.
Positive vs Negative confirmations:
- Positive: request a response whether or not the recipient agrees with the information.
- Negative: request a response only if the recipient disagrees.
Factors influencing design:
- Risk of material misstatement.
- Size and nature of individual balances.
- Reliability of the confirming party.
Control of the confirmation process:
- Auditor must maintain control:
- Selecting items and addresses.
- Sending requests directly.
- Receiving responses directly.
Exam hints:
- When asked about weaknesses in confirmation procedures, often the case shows:
- Client staff posting or collecting confirmations.
- Confirmations being returned to the client, not the auditor.
- Use of only negative confirmations in high‑risk circumstances.
- Your answer should explain how these weaken reliability of evidence and suggest improvements consistent with ISA 505.
5.5 Subsequent Events (ISA 560)
Subsequent events are events occurring between:
- The date of the financial statements (e.g. 31 December 2025), and
- The date of the auditor’s report (e.g. 20 March 2026),
and facts that become known to the auditor after the date of the auditor’s report.
Two types:
-
Adjusting events
- Provide additional evidence of conditions that existed at the balance sheet date.
- Require adjustment in financial statements.
- Examples:
- Insolvency of a customer with long‑standing financial difficulties (evidence of impairment at year‑end).
- Settlement of a court case confirming an obligation existing at balance sheet date.
-
Non‑adjusting events
- Indicative of conditions that arose after the balance sheet date.
- Do not require adjustment, but may require disclosure if material.
- Examples:
- Natural disaster after year‑end damaging assets (where such conditions did not exist at year‑end).
- Major business combination after year‑end.
Audit procedures:
- Review subsequent management accounts and cash flows.
- Enquire of management and those charged with governance about significant events.
- Review minutes of meetings after year‑end.
- Obtain legal letters from attorneys covering subsequent events.
Exam application:
- A question may describe several events and require you to classify them as adjusting, non‑adjusting, or not material, and specify:
- Required financial statement treatment.
- Auditor’s reporting responsibilities.
5.6 Going Concern (ISA 570)
The going concern assumption is that the entity will continue in operation for the foreseeable future (at least 12 months from reporting date) and will not liquidate or significantly curtail its operations.
Indicators of going concern problems:
- Financial:
- Recurring operating losses.
- Net liability position.
- Adverse key ratios.
- Negative operating cash flows.
- Operational:
- Loss of major customers.
- Labour difficulties or loss of key staff.
- Obsolescence of products.
- Other:
- Legal proceedings with potential significant claims.
- Non‑compliance with covenants and loan defaults.
Auditor’s responsibilities:
- Evaluate management’s assessment of going concern.
- Perform additional procedures if events or conditions cast significant doubt.
- Consider adequacy of disclosures.
Reporting implications:
-
Material uncertainty exists, but financial statements prepared on going concern basis are appropriate and disclosures are adequate:
- Issue unmodified opinion but include a separate “Material Uncertainty Related to Going Concern” section drawing attention to the note.
-
Going concern basis is inappropriate:
- Financial statements require a fundamental adjustment.
- If not made: adverse opinion.
-
Different reporting scenarios may result in modified opinions (qualified or disclaimer) if evidence is insufficient.
Exam approach:
- Identify indicators in the case.
- Evaluate management’s actions (e.g. financing plans, cost reductions).
- Conclude on whether a material uncertainty exists and what impact this has on the auditor’s report.
5.7 Audit Completion and Evaluation of Misstatements
At completion stage:
- Aggregate identified misstatements.
- Compare aggregate misstatements with materiality.
- Determine whether they are:
- Adjusted by management, or
- Unadjusted but clearly trivial, or
- Unadjusted but not trivial.
Types of misstatements:
- Factual (known errors).
- Judgmental (disagreements over estimates).
- Projected (from sampling projections).
Auditor must:
- Communicate uncorrected misstatements to management and those charged with governance.
- Request correction where appropriate.
- Consider the qualitative aspects, e.g. misstatements affecting key ratios, compliance with debt covenants, or directors’ remuneration.
Exam application:
- You may receive a list of misstatements and be asked to:
- Determine whether financial statements are materially misstated.
- Advise on whether the opinion should be qualified or unmodified if management refuses to adjust.
5.8 Types of Audit Opinions and Reports (ISA 700, 705, 706, 701)
1. Unmodified (Unqualified) Opinion
- Issued when financial statements are prepared, in all material respects, in accordance with the applicable financial reporting framework.
- Standard elements:
- Opinion section.
- Basis for opinion.
- Key Audit Matters (for listed entities).
- Responsibilities of management and auditor.
2. Modified Opinions (ISA 705)
-
Qualified opinion:
- Issued when:
- Misstatements are material but not pervasive, or
- Unable to obtain sufficient appropriate evidence, and possible effects are material but not pervasive.
- Wording includes “except for”.
- Issued when:
-
Adverse opinion:
- Misstatements are both material and pervasive.
- Financial statements do not present fairly.
-
Disclaimer of opinion:
- Unable to obtain sufficient appropriate audit evidence and the possible effects are material and pervasive.
- Auditor does not express an opinion.
3. Emphasis of Matter and Other Matter Paragraphs (ISA 706)
-
Emphasis of Matter:
- Refers to a matter appropriately presented or disclosed in the financial statements that, in the auditor’s judgement, is of such importance that it is fundamental to users’ understanding.
- Does not modify the opinion.
-
Other Matter:
- Refers to a matter other than those presented or disclosed in the financial statements that is relevant to users’ understanding of the audit, auditor’s responsibilities or report.
4. Key Audit Matters (ISA 701)
- Required for listed entities; may be voluntary for others.
- KAMs are matters that, in the auditor’s professional judgement, were of most significance in the audit.
- For each KAM, the auditor:
- Describes why it is a KAM.
- Explains how it was addressed in the audit.
Exam guidance:
- Provide clear explanations of:
- When each type of opinion is appropriate.
- How wording changes in the opinion and basis for opinion sections.
- Be ready to draft simple extracts of modified opinion paragraphs based on scenario facts, e.g.:
- Qualified opinion due to limitation of scope (inventory not observed).
- Adverse opinion due to improper revenue recognition.
These RGO301: Auditing 3.1 study notes are aligned with the core competencies expected of Nelson Mandela University (NMU) BCom Accounting Sciences (CA Stream) students and are also relevant for similar intermediate auditing modules at UNISA (e.g. AUE3701, AUE3781) and CUT (e.g. AUA30AS). Mastery of these topics, combined with practising past papers and case‑based questions, will significantly strengthen performance in auditing examinations across South African universities.
