Skip to contentSkip to search

ACCA AAA · Chapter 10

Audit planning

Your chapter at a glance. Open any section, or keep the whole map in view.

Strategy, understanding and risk assessment

Plan from risk understand, assess and respond

Purpose

  • Plan an effective audit under ISA 300
  • Focus on important areas and resolve problems promptly

People and resources

  • Select competent team members and allocate time
  • Coordinate experts, component and internal auditors
  • Direct, supervise and review the engagement team

Audit overview

  • Understanding supports assessment of RoMM
  • Assessed risks shape strategy and audit responses
  • Evaluate all results when forming the audit opinion

Overall audit strategy

  • Sets scope, timing and direction
  • Consider engagement characteristics and reporting objectives
  • Use prior knowledge, significant factors and resources

Audit plan

  • Nature, timing and extent of risk assessment procedures
  • Nature, timing and extent of further procedures

Keep current

  • Update strategy and plan as the audit progresses
  • Document both and any significant changes

Apply to the scenario

  • Match skills, locations, timing and supervision to risks

Obtain an understanding of

  • Entity and environment; reporting framework
  • System of internal control

Relevant matters

  • Ownership, governance, business model and IT
  • Industry, regulation, objectives and business risks
  • Performance measures and accounting policies

Use the understanding to

  • Identify and assess RoMM and choose materiality benchmark
  • Assess accounting policies and develop analytical expectations
  • Plan specialists, controls reliance and further procedures
  • Challenge evidence inconsistent with management explanations

Required procedures

  • Enquiries of management and others
  • Analytical procedures for unusual transactions and trends
  • Observation and inspection to corroborate enquiries

Existing information

  • Use acceptance and prior year information if relevant
  • Check prior year information remains reliable

Relevant controls

  • Evaluate design: could a control prevent or detect and correct?
  • Determine implementation: is it in use?
  • Enquiry alone is insufficient for these assessments

Operating effectiveness

  • Test separately if planning to reduce substantive work

Responses, materiality and less complex entities

Evidence-led plan revise as findings emerge

Controls strategy

  • Test controls expected to operate effectively
  • If confirmed, substantive extent may be reduced
  • If ineffective, revise strategy and obtain more evidence

Always required

  • Substantive procedures for each material class of transactions
  • Also for each material account balance and disclosure

Communication

  • Report significant control deficiencies to TCWG

When RoMM exists

  • Reasonable possibility of a misstatement occurring
  • Misstatement could be material if it occurs

Two levels

  • Financial statement level: pervasive risks
  • Assertion level: transactions, balances and disclosures

Assessment concepts

  • Inherent and control risk are components of RoMM
  • Inherent risk varies along a spectrum
  • Relevant assertion has an identified RoMM
  • Significant class, balance or disclosure has a relevant assertion
  • Significant risk lies near upper end of inherent risk spectrum

Response

  • Assess assertion risks to determine further procedures

Definition

  • Omission, misstatement or obscuring may influence users
  • Size and nature, individually or combined, matter

Starting benchmarks

  • Revenue: 0.5%–1%; total assets: 1%–2%
  • Profit before tax: 5%–10%
  • Select benchmark and threshold using judgement

Performance materiality

  • Below overall materiality to limit aggregate misstatement risk
  • Lower level may apply to particular items or disclosures

Qualitative matters

  • Consider entity, reporting framework and narrative disclosures
  • Apply the specified exam basis and show the calculation

ISA for LCE

  • Standalone, proportionate audit standard
  • Same reasonable assurance as full ISAs
  • Use requires adoption or permission by jurisdiction

Eligibility

  • Depends on nature and complexity, not size alone
  • Simple model, ownership, IT, transactions and estimates

Cannot use for

  • Listed or public-interest entities
  • Other engagements barred by standard or local authority

UK position

  • Not adopted in the UK; cannot use under ISAs (UK)

Want it on paper? Download the PDF, or print this page.