AAT L4 Audit and Assurance Principles 2 — Questions and Answers
Question 1: An auditor identifies that the directors have prepared the financial statements on a going concern basis. Which of the following would most likely cause the auditor to question this assumption?
- The company has declared a dividend in the current year
- The company has significant net current liabilities and a loan due for renewal within 6 months (Correct answer)
- A key customer accounts for 30% of total revenue
- The company has recently expanded into a new market
Correct answer: The company has significant net current liabilities and a loan due for renewal within 6 months
Significant net current liabilities combined with a near-term loan renewal requirement are classic indicators of going concern doubt, as the business may be unable to meet its obligations as they fall due.
Going concern is a fundamental accounting concept: financial statements are prepared on the assumption that the entity will continue in operation for the foreseeable future (at least 12 months from the balance sheet date under ISA 570). Indicators of going concern doubt include: net current liabilities (current liabilities exceed current assets), inability to repay or refinance borrowings, loss of key customers or suppliers, significant operating losses, and legal proceedings. Having net current liabilities means the company may not be able to pay short-term debts as they fall due, and a loan renewal within 6 months creates additional refinancing risk. When going concern doubt exists, the auditor must assess the adequacy of management's disclosures and consider the appropriateness of the going concern basis. Depending on the severity, the auditor may issue a material uncertainty paragraph, a qualified opinion, or an adverse opinion. Under ISA 570 (Revised), auditors have enhanced responsibilities to challenge management's assessment and are required to evaluate whether the period assessed by management is reasonable — typically at least 12 months from the date of approval of the financial statements.
Question 2: During an audit of trade receivables, the auditor sends confirmation letters directly to customers. What audit assertion does this procedure primarily address?
- Completeness
- Valuation
- Existence (Correct answer)
- Classification
Correct answer: Existence
Receivables confirmations verify that the debts recorded actually exist — that customers acknowledge owing the amounts stated. This directly tests the existence assertion.
Audit assertions are the implicit claims that management makes in the financial statements. For balance sheet items (account balances), the key assertions are: Existence (assets and liabilities exist), Rights and Obligations (the entity owns or controls the assets), Completeness (all assets and liabilities are recorded), Valuation and Allocation (amounts are appropriate), and Classification/Presentation. Sending confirmation letters to customers directly tests existence — the response from the customer confirms (or disputes) that the debt is real and the amount is agreed. It also provides some evidence about valuation if the customer disputes the amount. Crucially, it does NOT test completeness — it cannot identify receivables that should exist but are not recorded. To test completeness of receivables, the auditor would review after-date cash receipts, check that all goods dispatched near year-end have been invoiced, or trace from despatch records to the receivables ledger. Confirmations are strong audit evidence because they come from an independent third party. However, their reliability depends on the response rate and whether customers have the information needed to confirm accurately.
Question 3: Which of the following best describes the concept of 'audit risk'?
- The risk that the client's business will fail during the audit engagement
- The risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated (Correct answer)
- The risk that the auditor will not be paid for their work
- The risk that management will restrict the auditor's access to information
Correct answer: The risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated
Audit risk is the risk that the auditor gives an unmodified (clean) opinion on financial statements that are, in fact, materially misstated. It is the product of inherent risk, control risk, and detection risk.
Audit risk (AR) is formally defined as the risk that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated. The audit risk model expresses this as: AR = IR × CR × DR, where IR = Inherent Risk, CR = Control Risk, and DR = Detection Risk. Inherent Risk is the susceptibility of an assertion to misstatement, ignoring internal controls (e.g., complex estimates, high-value judgements). Control Risk is the risk that the client's internal controls fail to prevent or detect a material misstatement. Together, IR × CR = Risk of Material Misstatement (RMM). Detection Risk is the only element the auditor can control directly — it is the risk that audit procedures fail to detect a material misstatement that exists. To keep overall audit risk at an acceptably low level, when RMM is high, the auditor must reduce detection risk by performing more extensive, reliable, or targeted procedures. The acceptable level of audit risk is professionally judged (typically very low) because stakeholders rely on the auditor's opinion to make decisions. Increased audit risk leads to more work, not higher accepted risk.
Question 4: A company has strong internal controls over the purchases cycle. How should this affect the auditor's approach to testing?
- The auditor should perform more substantive testing to verify the controls are working
- The auditor can rely solely on management representations without further testing
- The auditor may be able to reduce substantive testing by performing and relying on tests of controls (Correct answer)
- The auditor must ignore internal controls and perform full substantive procedures
Correct answer: The auditor may be able to reduce substantive testing by performing and relying on tests of controls
When internal controls appear strong, the auditor can test those controls (tests of controls) and, if they prove effective, reduce the extent of substantive testing required, saving time and cost.
ISA 330 requires auditors to design and implement responses to assessed risks of material misstatement. When controls appear strong, the auditor has a choice of audit strategy. A controls-based approach involves: (1) assessing and documenting internal controls (walkthrough tests), (2) testing the operating effectiveness of controls throughout the period (tests of controls), and (3) if controls are confirmed effective, reducing the extent of substantive procedures (though some substantive procedures are always required for material items). A purely substantive approach abandons reliance on controls and gathers sufficient evidence through substantive procedures alone. This is used when controls appear weak, when it is not efficient to test controls, or for certain assertions where controls cannot provide sufficient evidence (e.g., completeness of revenue). The efficiency gain from the controls-based approach is that tests of controls are often less costly than extensive substantive testing. However, if controls testing reveals weaknesses, the auditor must increase substantive testing, which can make the overall audit more expensive than anticipated. This risk-reward judgement is central to audit planning.
Question 5: What is the primary purpose of an engagement letter in an external audit?
- To confirm the audit fee agreed between the auditor and client
- To define the terms of the audit engagement and the respective responsibilities of auditor and client (Correct answer)
- To notify shareholders that an audit has been commissioned
- To satisfy the requirements of the Companies Act 2006 for listed companies
Correct answer: To define the terms of the audit engagement and the respective responsibilities of auditor and client
The engagement letter sets out the terms of the audit, including objectives, scope, responsibilities of both parties, and the basis of fees, reducing the risk of misunderstanding.
ISA 210 requires auditors to agree the terms of the audit engagement with management or those charged with governance before starting audit work. The engagement letter is the primary mechanism for doing this. Key contents of an engagement letter include: the objective and scope of the audit, the responsibilities of management (preparing financial statements, maintaining internal controls, providing accurate information), the responsibilities of the auditor (expressing an opinion), identification of the applicable financial reporting framework, reference to the form of any reports, the basis for calculating fees, and arrangements for planning, including use of experts. The engagement letter protects both parties. From the auditor's perspective, it establishes the boundaries of their work and limits liability if management fails in their stated responsibilities. From the client's perspective, it provides clarity about what the audit will and will not cover. For continuing audit engagements, ISA 210 requires the auditor to assess whether the engagement letter needs to be updated. A new letter should be issued if there are significant changes in circumstances, such as a change in reporting framework, ownership structure, or major expansion of the business.
Question 6: Under ISA 240, which of the following conditions are present in most fraud cases (the 'fraud triangle')?
- Motive, means, and method
- Incentive/pressure, opportunity, and rationalisation (Correct answer)
- Concealment, conversion, and cover-up
- Management override, collusion, and falsification
Correct answer: Incentive/pressure, opportunity, and rationalisation
The fraud triangle identifies three conditions typically present when fraud occurs: an incentive or pressure to commit fraud, an opportunity to do so, and a rationalisation that justifies the behaviour.
ISA 240 'The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements' requires auditors to maintain professional scepticism and be alert to fraud risk. The fraud triangle provides a conceptual framework for understanding fraud conditions. Incentive/Pressure: the motivation to commit fraud, such as personal financial difficulties, performance targets tied to bonuses, or pressure to meet market expectations. Opportunity: the means by which fraud can be perpetrated, typically arising from weak internal controls, poor segregation of duties, or inadequate management oversight. Rationalisation: the fraudster's justification, such as 'I'll pay it back', 'I deserve it', or 'everyone does it'. For auditors, all three elements inform fraud risk assessment. A business with heavy bonus pressure (incentive), weak controls (opportunity), and a culture that tolerates minor dishonesty (rationalisation) has a high fraud risk environment. ISA 240 requires auditors to presume there is a risk of fraud in revenue recognition in every audit, and to consider whether management override of controls is a risk. Fraud is harder to detect than error because it involves intentional concealment, and collusion can override controls that would otherwise be effective.
An auditor identifies that the directors have prepared the financial statements on a going concern basis.
Which of the following would most likely cause the auditor to question this assumption?