Welcome to Audit and Assurance!
Hello there! Welcome to your first step in mastering Audit and Assurance (AA). If you have ever wondered how investors know they can trust the numbers a company publishes, or why big companies need "the auditors" to visit every year, you are in the right place.
Audit and Assurance is often seen as a "wordy" or "dry" subject, but at its heart, it is about trust. In this chapter, we will look at the basic building blocks of what an audit is, why we do it, and the different ways professional accountants can provide confidence to people who use financial information. Don't worry if it seems like a lot of terminology at first—we will break it down piece by piece!
1. What is an Assurance Engagement?
Before we talk about "Auditing," we need to understand the bigger umbrella it sits under: Assurance.
In simple terms, Assurance means giving confidence to someone. Imagine you are buying a second-hand car. The seller says it’s in perfect condition. Do you trust them? Maybe. But if a professional mechanic checks the car and gives you a written report saying it’s fine, you feel much more confident. That "confidence boost" provided by the mechanic is what we call assurance.
Official Definition: An engagement in which a practitioner aims to obtain sufficient appropriate evidence in order to express a conclusion designed to enhance the degree of confidence of the intended users about the subject matter.
The Five Elements of an Assurance Engagement
To have a formal assurance engagement, five specific things must be present. You can remember these using the mnemonic CREST:
1. C - Criteria: The "benchmark" used to evaluate the subject matter. For financial statements, the criteria are usually the Accounting Standards (IFRS). You can't judge if something is "right" unless you have a rulebook to compare it to!
2. R - Report: A written report containing the practitioner's conclusion. It must be in writing so it can be shared with the users.
3. E - Evidence: The practitioner must gather proof (documents, observations, calculations) to support their conclusion. This evidence must be sufficient (enough) and appropriate (relevant and reliable).
4. S - Subject Matter: This is what the practitioner is looking at. It could be the Financial Statements, a company’s greenhouse gas emissions, or even their internal computer systems.
5. T - Three Parties: Every assurance engagement involves three distinct groups:
The Practitioner (the auditor/accountant),
The Responsible Party (the company management who prepared the info), and
The Intended Users (e.g., the shareholders or the bank).
Quick Summary: For assurance to exist, you need a practitioner to look at subject matter using criteria, gather evidence, and issue a report to users.
2. Different Levels of Assurance
Not all "checks" are the same. Some are very deep and thorough, while others are more of a "high-level look." In the ACCA AA curriculum, we focus on two types:
Reasonable Assurance (High Level)
This is what we provide in a Statutory External Audit.
- Evidence: The practitioner gathers a lot of evidence to be very sure of their conclusion.
- The Opinion: It is expressed positively. For example: "In our opinion, the financial statements give a true and fair view."
- Confidence: It provides a high, but not absolute, level of assurance.
Limited Assurance (Moderate Level)
Think of this as a "Review" rather than a full audit. It is faster and cheaper.
- Evidence: The practitioner gathers less evidence (mostly by asking questions and looking at trends).
- The Opinion: It is expressed negatively. This doesn't mean it's bad! It just means the wording is: "Nothing has come to our attention that causes us to believe the financial statements are not prepared, in all material respects, in accordance with the framework."
- Confidence: It provides a lower level of assurance than an audit.
Did you know? We never give 100% "Absolute Assurance." It is impossible to check every single transaction a company made during the year!
3. External Audit: Definition and Objective
Now we get to the core of this subject: the External Audit. This is a specific type of assurance engagement where the Subject Matter is the annual financial statements.
The Objective of an Audit (ISA 200)
According to International Standard on Auditing (ISA) 200, the objective of an auditor is to obtain reasonable assurance about whether the financial statements as a whole are free from material misstatement (big mistakes), whether due to fraud or error.
This allows the auditor to express an opinion on whether the financial statements are prepared, in all material respects, in accordance with an applicable financial reporting framework (like IFRS).
True and Fair View
You will see the phrase "True and Fair" constantly in this course.
- True: The information is factually correct and based on real evidence.
- Fair: The information is presented impartially, without bias, and reflects the commercial substance of transactions.
Common Mistake to Avoid: Students often think the auditor's job is to "guarantee the company will not go bust" or "find every single cent of fraud." This is not true! The auditor's job is only to provide an opinion on the financial statements.
4. Why is an Audit Beneficial?
If audits are expensive and time-consuming, why do we do them?
1. Quality of Information: It makes the financial statements more reliable for investors and banks.
2. Accountability (Agency Theory): Shareholders own the company, but Directors run it. The audit acts as an independent check to make sure the Directors are reporting the truth to the Owners.
3. Deterrent: If management knows an auditor is coming, they are less likely to try to hide errors or commit fraud.
4. Subsidiary Benefits: During the audit, the auditor might find weaknesses in the company’s internal systems and give advice on how to improve them.
5. Inherent Limitations of an Audit
As we mentioned earlier, an audit does not provide absolute (100%) assurance. Why? Because of Inherent Limitations. Even the best auditor in the world cannot be 100% sure. Here is why:
1. Sampling: Auditors don't look at every single invoice. They pick a "sample." There is always a tiny risk that the one invoice they didn't pick contains a massive error.
2. Subjectivity/Judgment: Accounting involves estimates (like "how long will this machine last?"). Different people might have different opinions on these numbers.
3. Evidence is Persuasive, not Conclusive: Most audit evidence points toward a conclusion but doesn't prove it with 100% mathematical certainty.
4. Fraud: If the company's management is deliberately colluding to hide something (e.g., forging documents), it is very difficult for an auditor to find it.
5. Time and Cost: An audit needs to be finished within a few months of the year-end to be useful. We can't spend 10 years checking one year's accounts!
Key Takeaway: Because of these limitations, the auditor provides Reasonable Assurance, which is a high level of confidence, but not a guarantee.
Quick Review Box
Check your understanding:
- Can you list the CREST elements?
- What is the difference between Positive and Negative assurance wording?
- Why can't an auditor give Absolute assurance?
- What are the Three Parties in an audit?
Don't worry if this seems tricky at first! These concepts will appear again and again as we move through the syllabus. Once you understand that an audit is just a professional "double-check" to help people trust financial numbers, the rest will start to fall into place.