Group 4: Risk Assessment & Internal Control

30 original descriptive cases. Descriptive mix: 10 at 3 marks, 14 at 5 marks, 6 at 10 marks.

Original practice, not ICAI questions, official suggested answers or an official examiner scheme. Equivalent correct work is credited within the stated caps. Public practice availability is not full official question-bank completion.

Source tension: printed 3.12 says assessment helps reduce risk of material misstatement, while printed 3.8 says the auditor influences detection risk, not entity inherent/control risks. These cases use assessment as the basis for responses and reducing audit risk; they do not claim direct elimination of entity risks.

AUD-G04-D001 · 5 marks

Three risk components are not three names for one defect Aster Sensors has a highly judgemental warranty estimate. Management has not implemented the planned independent review of it. The audit team then uses an unsuitable procedure that may fail to detect a material estimate error. No misstatement is yet proved. The manager says more audit work changes the client's inherent risk to zero and guarantees a correct opinion. Required: Classify the three risk concerns, explain their relationship and correct the guarantee/direct-control claim. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Inherent risk is assertion susceptibility before considering controls.The subjective estimate can be susceptible to material misstatement; complexity/uncertainty is distinct from the review failure.
1Control risk is failure of entity controls to prevent or detect/correct misstatement.The unimplemented independent review is an entity control concern, not the audit procedure itself.
1Detection risk concerns auditor procedures failing to detect existing material misstatement.The unsuitable audit procedure may leave a material error undetected; this does not prove one exists.
1Audit risk is a function of material-misstatement risk and detection risk.Entity inherent/control risks inform the nature, timing and extent of the response; they are not merely relabelled auditor errors.
1Auditor responses influence detection risk, not directly eliminate entity risks.Change the audit response as appropriate to reduce audit risk to an acceptably low level; more work does not guarantee zero risk or a correct result.

Non-credit errors

  • No direct auditor reduction of inherent/control risk to zero.
  • Risk is not proof of actual misstatement or negligence.
Official ICAI concept source

AUD-G04-D002 · 3 marks

Higher assessed risk changes the audit response Birch Devices introduces a complex new estimate while its review control is weak. A senior proposes keeping exactly the prior procedure solely because last year's audit found no error. A junior instead proposes an automatic adverse opinion. No current evidence establishes a misstatement. Required: Explain the appropriate risk-response logic and the limits on a conclusion. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Assess current material-misstatement risk, not just the prior outcome.New complexity and weak review can make last year's unchanged response inappropriate.
1Higher assessed risk requires an appropriate response managing detection risk.Reconsider procedure nature, timing and extent and evidence needs; a favourable past outcome is not current protection.
1Risk assessment is not an automatic opinion conclusion.Obtain and evaluate current evidence before reporting; do not label risk as an established material misstatement.

Non-credit errors

  • No automatic adverse opinion.
  • Past absence of error is not unchanged current risk.
Official ICAI concept source

AUD-G04-D003 · 5 marks

An interview is not the whole risk assessment Cedar Retail's CFO says all systems are unchanged. Sales staff report new return rights, legal counsel knows of product claims and IT staff report a billing-interface change. The audit team has conducted no analytics or observation/inspection and proposes relying on the CFO interview for its opinion. Required: Design an applied risk-assessment information plan and explain its evidence boundary. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Inquire of management and others with relevant perspectives.Ask sales about return terms, counsel about claims and IT about interface change instead of treating the CFO as the only source.
1Use analytical procedures in risk assessment.Compare relevant sales/returns trends and financial/nonfinancial indicators to identify unusual patterns, then investigate.
1Use observation and inspection.Inspect changed agreements/interface records and observe relevant processing or controls to support inquiries; do not claim the work was already performed.
1Identify and assess fraud/error risks at financial-statement and assertion levels.Relate return rights, claims and billing changes to what could go wrong and whether effects may be pervasive or assertion-specific.
1Risk-assessment procedures alone do not provide sufficient appropriate opinion evidence.Use the understanding as the basis for planned further responses; the CFO interview cannot stand in for the full evidence needed.

Non-credit errors

  • No assertion that all reported changes already caused misstatements.
  • No claim interviews alone support the audit opinion.
Official ICAI concept source

AUD-G04-D004 · 3 marks

Business risk is broader than reporting risk Dahlia Textiles expands to a new market. Demand forecasts may be optimistic and staff lack local expertise. The auditor is asked to identify every commercial risk and guarantee expansion success. No audit evidence yet proves any account wrong. Required: Explain the financial-reporting relevance and scope limit of understanding business risks. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Objectives/strategies and related business risks help identify reporting risks.Expansion and weak expertise can have financial consequences requiring understanding, not blind reliance on management optimism.
1Relate risks to possible financial-statement effects and assertions.Consider how forecasts/operations could affect relevant balances, disclosures or estimates, with evidence rather than automatic misstatement claims.
1Business risk is wider than risk of material misstatement.The auditor is not responsible for identifying all business risks or guaranteeing commercial success.

Non-credit errors

  • No expansion-success guarantee.
  • Every commercial risk is not automatically a material misstatement.
Official ICAI concept source

AUD-G04-D005 · 10 marks

Build an initial risk map for a changed business Elm Appliances has four developments: A. A rushed acquisition adds an unfamiliar inventory system and management has not reconciled the interface to the ledger. B. Sales bonuses depend on a steep year-end revenue target. Sales staff mention side agreements allowing unusual returns; the CFO says standard contracts have not changed. C. A warranty estimate uses a wide range of possible outcomes. A proposed independent review has not yet been implemented. D. A significant one-off transaction with a related party is outside the normal course of business. Its accounting is complex and heavily directed by management. All are risk indicators, not proved fraud or misstatement. No control operating-effectiveness tests or further substantive conclusions have been completed. The partner wants a risk map, not a predetermined opinion. Required: (a) Map each development to what could go wrong, relevant risk factors and useful understanding work. (6 marks) (b) Distinguish potentially pervasive and assertion-specific risks and significant-risk assessment. (2 marks) (c) Explain response and evidence boundaries. (2 marks)
Show answer and marking
MarksCreditCase application / answer
1.5A: new operations/system and weak reconciliation need current understanding.Possible inventory/ledger completeness or accuracy issues; inquire of operations/IT, inspect interface/reconciliation records and trace relevant transactions. Identify actual control design/use rather than assume reliance.
1.5B: targets and nonstandard terms can affect reporting risk.Potential revenue cut-off/recognition or return-estimate issues; inquire of sales beyond CFO, inspect actual side terms and analyse sales/returns. Pressure is a fraud-risk indicator, not proof fraud occurred.
1.5C: subjectivity/measurement uncertainty plus a missing control.Potential warranty valuation issue; understand assumptions/data and whether review is capable and actually implemented. High inherent susceptibility and control concern are separate.
1.5D: significant unusual related-party transaction deserves special attention.The supplied significant related-party transaction outside ordinary business is treated as significant risk in the module; understand actual terms, accounting and relevant controls, not management-directed result alone.
1Risk levels must be assessed, not inferred from account headings alone.Consider whether acquisition/control weaknesses or management pressures affect many assertions pervasively; link individual inventory/revenue/warranty/transaction concerns to assertions and potential magnitude/likelihood.
1Significant-risk judgement considers fraud, developments, complexity, related parties, subjectivity and unusual transactions.Use the actual factors in B-D; a risk of fraud is significant, but target pressure alone is not a confirmed fraud finding. D supplies the significant nonroutine related-party fact.
1Risk assessment provides a basis for responses, not sufficient opinion evidence alone.Plan appropriate further work and reconsider detection risk/evidence needs; no opinion is determined by this initial map.
1Design/implementation and operating effectiveness are distinct.Inquiry alone does not establish control implementation; a manual point-in-time walkthrough does not establish full-period operation. Document actual understanding and update as evidence changes.

Non-credit errors

  • No automatic fraud or modified opinion.
  • No claimed procedure performed when only proposed.
  • No double credit for generic headings without four case links.
Official ICAI concept source

AUD-G04-D006 · 5 marks

A policy exists, but is the control in use? Fir Manufacturing's policy says a supervisor compares each supplier invoice with authorised purchase and receipt records before posting. Staff confirm the policy verbally. A walkthrough finds postings made before matching, and no review record for selected transactions. The control, if performed properly, could identify relevant quantity/price differences. The audit team calls the written policy effective for the full year. Required: Distinguish design, implementation and operation; identify understanding evidence and correct the reliance claim. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Design asks whether control can prevent or detect/correct material misstatement.The specified matching design could detect relevant differences; assess its actual scope and capability first.
1Implementation means the control exists and is being used.Posting before matching and absent review evidence challenge actual use, notwithstanding the written policy.
1Inquiry alone is insufficient for design/implementation evidence.Inspect actual matching documents/review records, observe application and trace transactions, corroborating staff statements.
1Understanding manual control at one time does not prove full-period operating effectiveness.A walkthrough cannot be treated automatically as the full-year effectiveness test; assess needed testing separately.
1Reassess risks and response based on actual evidence.Do not assume reliance from a policy or declare all invoices wrong; clarify exceptions and plan an appropriate response.

Non-credit errors

  • No written-policy equals operation inference.
  • No full-year effectiveness claim from one manual walkthrough.
Official ICAI concept source

AUD-G04-D007 · 3 marks

Two signatures can still be circumvented Grove Motors requires two approvals for payment. Two employees collude, while a manager can override the approval setting. The board claims dual approval eliminates every possible error or fraud. No particular loss is quantified. Required: Explain the limitation, assurance level and audit implication. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Internal control gives reasonable, not absolute, assurance.Two approvals do not guarantee every reporting objective or eliminate error/fraud risk.
1Collusion and inappropriate management override can circumvent controls.The two stated routes are distinct from absence of any designed control; a signature rule is not immunity.
1Understanding limitations informs assessed risk and further responses.Investigate actual operation/override and relevant evidence without inventing a loss amount or automatic opinion.

Non-credit errors

  • No zero-risk guarantee.
  • Control bypass indicators are not quantified loss evidence.
Official ICAI concept source

AUD-G04-D008 · 5 marks

Owner oversight is neither automatic strength nor automatic failure Hazel Repairs has four employees, making full segregation impractical. The owner reviews bank reconciliations and unusual supplier payments using supporting records. The same owner can override all payment limits and enter adjustments without independent challenge. A trainee says small size means no relevant controls, while the owner says personal supervision guarantees perfect records. Required: Evaluate the compensating oversight, override risk, evidence needs and proportionate audit understanding. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Small entities may have limited opportunities for segregation.Four staff can constrain separation; absence of large-company structure is not automatically absence of all useful control.
1Owner-manager oversight may compensate for some limitations.Evidence-backed review of reconciliations/unusual payments may matter; assess what actually happens rather than assume effectiveness.
1Owner-manager may also be better able to override a less structured system.Unchallenged limits and journal overrides require attention to fraud-related reporting risks; oversight and override can coexist.
1Understand relevant design and implementation with corroboration.Inspect review evidence, observe use and trace selected transactions beyond asking the owner; no full-year operation claim from one point.
1Controls remain reasonable assurance and the response is proportionate.Reject both no-controls and perfect-records extremes; identify possible misstatements and plan appropriate further procedures without predetermined opinion.

Non-credit errors

  • No universal small-entity exemption.
  • No owner-oversight guarantees.
Official ICAI concept source

AUD-G04-D009 · 5 marks

Relevant to the financial-statement audit is not the same as important to operations Iris Transport has a route-punctuality system, access controls over cash-disbursement data and a fuel-use efficiency dashboard. Route/fuel tools are stated to serve only operational objectives with no identified financial-reporting link. Disbursement access protects posting/payment data. No additional statute requires a broader controls report. The manager wants equal audit attention to every system because each is important commercially. Required: Assess control relevance, the benefits of understanding relevant controls and the scope exception. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Consider relevance to reliable financial reporting and assessed risks.The disbursement access controls have an identified reporting-data link; their commercial label does not decide relevance.
1Operational controls without relevant reporting link ordinarily need not be considered for this audit.Route/fuel tools on the supplied narrow facts are not automatically in scope merely because operationally important.
1Understanding relevant controls helps identify potential misstatement types and risk factors.Use payment-data access to consider what could go wrong and risks, not assume every operational failure affects accounts.
1Understanding helps design further procedure nature/timing/extent.Evaluate relevant control design/use and evidence needs rather than spend identical effort on every system.
1Law/regulation may broaden the controls review.No such requirement is supplied here; check it if applicable rather than assert financial-reporting scope is an absolute legal rule.

Non-credit errors

  • No all-controls always relevant claim.
  • No dismissal of an actual financial-reporting link or broader statutory duty.
Official ICAI concept source

AUD-G04-D010 · 10 marks

A control review with five different weaknesses Juniper Foods' review shows: 1. The code of conduct exists, but senior management rewards staff who bypass controls to meet targets; oversight is weak. 2. No one assesses reporting risks from a newly launched product and its unfamiliar warranty terms. 3. The billing system records dispatch data, but changed return terms are not communicated to finance; sales and ledger records no longer reconcile. 4. A designed review of unusual credit notes is not used, even though staff say it is policy. 5. Repeated reconciliation exceptions are reported, but no one follows up or checks whether controls remain effective. No loss or fraud is proved, and no operating-effectiveness conclusion is supplied. The trainee groups all five under missing passwords and says a new policy document solves them. Required: (a) Map the five weaknesses to internal-control components and explain the specific reporting concern. (5 marks) (b) Distinguish control understanding from operation testing and state corroborating work for two issues. (3 marks) (c) Explain assurance limitations and what the proposed policy does not prove. (2 marks)
Show answer and marking
MarksCreditCase application / answer
1Control environment includes management attitude and oversight.Rewards for bypassing controls and weak oversight undermine the foundation; this is not merely a password issue.
1Entity risk-assessment process identifies/addresses business risks relevant to reporting.New product/warranty risks were not considered; identify potential estimate/disclosure consequences without asserting actual misstatement.
1Information system and communication support recording and reporting.Uncommunicated returns and unreconciled sales/ledger data can distort reporting; understand transaction flow and communication.
1Control activities implement policies/procedures addressing risks.The unusual-credit-note review is not actually used; a capable written design does not establish implementation.
1Monitoring evaluates control performance over time and timely corrective action.Unfollowed exceptions and no effectiveness follow-up are monitoring weaknesses, not only initial control design.
1Evaluate relevant design before implementation, and corroborate inquiry.For credit notes, inspect actual review records and trace postings; identify whether the review is capable and being used.
1Trace actual reporting flow for the interface/communication problem.Inspect return terms, dispatch/sales/ledger links and reconciliation exceptions; do not claim proposed procedures already performed.
1Manual point-in-time implementation does not prove full-period operating effectiveness.Separately determine needed operation testing and risk response; automatic-system consistency still requires relevant assessed/tested supporting controls.
1Internal control offers reasonable assurance and has inherent limitations.Human error, misunderstanding, collusion and override can remain even after policies are improved.
1A new policy is neither proof of implementation nor a fraud/opinion conclusion.Management must actually implement/use/monitor controls; auditor evaluates evidence and response rather than certifying perfection or assigning automatic fault.

Non-credit errors

  • No five-password answer in place of component mapping.
  • No policy document equals operating effectiveness.
  • No invented fraud, loss or predetermined opinion.
Official ICAI concept source

AUD-G04-D011 · 5 marks

A familiar industry, an unfamiliar entity Kestrel Diagnostics has overseas subsidiaries, a newly acquired laboratory, owner-controlled suppliers and debt carrying financial covenants. A new regulatory requirement may affect its operations. The auditor says having audited another diagnostics company makes entity-specific understanding unnecessary. No breach or misstatement has been established. Required: Develop an entity-specific understanding plan addressing four distinct areas and explain why industry experience is not a substitute. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Understand industry, regulatory and external factors.Inspect the applicable new requirement and its actual business/reporting implications; do not invent its content or a breach.
1Understand operations and investments.Investigate the laboratory acquisition and overseas activities to identify expected transactions, balances and disclosures.
1Understand ownership, governance and structure.Identify subsidiary relationships and owner-controlled suppliers to consider related-party identification and accounting; common ownership is not proof of improper transactions.
1Understand financing.Read actual debt/covenant terms and relevant financing information to identify potential reporting effects, without assuming a breach.
1Entity-specific understanding is the audit frame of reference.Prior industry knowledge is useful but cannot replace gathering and updating facts about this entity for planning and risk assessment.

Non-credit errors

  • No presumed regulatory or covenant breach.
  • No automatic qualification or conclusion from a complex structure.
Official ICAI concept source

AUD-G04-D012 · 3 marks

A changed policy needs a reason, not a popularity vote Linden Components changes an accounting policy and says the change is valid because two competitors use it. The file contains no reason for the change or evaluation against the applicable reporting framework. The auditor has not established whether either policy is appropriate. Required: State the understanding and evaluation needed, and the limit on the conclusion. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Understand selection/application of policies and reasons for changes.Obtain the rationale and actual application rather than accept an unexplained change.
1Evaluate appropriateness for the business and consistency with the applicable framework and relevant industry policies.Competitor use is context, not a replacement for assessing whether this entity complies with its framework.
1A missing evaluation is not proof either policy is wrong.Investigate and evaluate evidence before concluding; do not automatically demand reversal or modify the opinion.

Non-credit errors

  • Competitors are not the applicable reporting framework.
  • No assumed invalid policy.
Official ICAI concept source

AUD-G04-D013 · 3 marks

Performance pressure is information, not a fraud verdict Maple Distribution rewards managers for quarterly margins and lender ratios. Internal reports show large budget variances while public credit reports show funding pressure. A trainee calls all good reported results fraudulent without inspecting the measures or underlying records. Required: Explain the relevance of performance measures, useful understanding work and the conclusion boundary. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Performance measures can create incentives/pressures affecting reporting risk.Margins and lender ratios may motivate management actions, including possible misstatement; pressure is not proof of fraud.
1Understand internal and external measures and how management reviews them.Inspect budgets, variance analyses, relevant ratios and credit reports, and inquire about the measures and underlying causes.
1Use the understanding to assess possible reporting effects with evidence.Investigate unusual relationships and what could go wrong; do not label all favourable results fraudulent or predetermine the opinion.

Non-credit errors

  • No fraud finding from targets alone.
Official ICAI concept source

AUD-G04-D014 · 5 marks

A risk register without a risk process Nectar Foods lists a new cold-storage technology and new product line in a register. The register has no estimate of significance, likelihood assessment or decision on responses. Management says listing names alone proves its risk-assessment process is complete. Required: Evaluate the process through its four stages, apply each to the facts and distinguish the entity process from the auditor's work. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Identify business risks relevant to financial-reporting objectives.Check whether technology/product changes have been linked to specific reporting concerns, such as data processing or relevant estimates, rather than names alone.
1Estimate risk significance.Understand potential financial-reporting effects and their magnitude; the register supplies no significance evaluation.
1Assess likelihood of occurrence.Investigate likelihood on relevant information rather than treat listing as the assessment.
1Decide actions to address risks.Understand management decisions and actual responsibilities/actions; no response decision is recorded.
1Judge appropriateness in the circumstances and use it in audit risk identification.An appropriate entity process assists the auditor, but management listing or scoring does not replace the auditor's independent identification and assessment.

Non-credit errors

  • No generic four headings without case application.
  • No assumption a register is a complete process.
Official ICAI concept source

AUD-G04-D015 · 10 marks

Trace a sale through a changed information system Orchid Machines moves to a new billing platform. Order records start in sales; dispatch files feed billing; rejected interfaces await manual correction; accepted batches reach the ledger. Finance prepares statements from that ledger. Customer return terms are held separately, while finance says it never receives changes. Manual journal entries can adjust revenue. Management shows one successful invoice and claims every reporting stage and control is understood. Required: (a) Design an understanding plan covering six areas of the information system, applying each to these facts. (6 marks) (b) Explain communication and the people/procedures/data dimensions beyond hardware. (2 marks) (c) State corroborating work and limits on what the successful invoice proves. (2 marks)
Show answer and marking
MarksCreditCase application / answer
1Identify significant classes of transactions.Understand sales, returns and relevant adjustments and whether they are significant to statements; one invoice does not describe all relevant classes.
1Understand initiation, recording, processing, correction, ledger transfer and reporting.Trace order to dispatch, rejected/accepted interface handling, corrections and ledger posting rather than inspect only the final invoice.
1Understand accounting records, supporting information and specific accounts.Inspect order/dispatch/interface and ledger records supporting the reporting flow and how they link.
1Understand capture of significant events and conditions.Investigate how changed return terms are captured for relevant reporting effects, not just invoice generation.
1Understand the financial-reporting process.Follow the ledger into statement preparation, including relevant reconciliations and reporting adjustments.
1Understand controls surrounding journal entries.Investigate initiation/authorisation/recording of manual revenue adjustments and the actual controls rather than assume the billing platform controls them.
1Understand communication of financial-reporting roles and responsibilities.Inspect or inquire about how sales changes reach finance and who must act; the stated communication gap needs follow-up.
1The system includes infrastructure, software, people, procedures and data.Understand staff handling of rejections and terms, their procedures and data quality in addition to the new software/hardware.
1Corroborate inquiries through records, observation and transaction tracing.Inspect rejected batches and corrections and trace selected transactions through actual stages; proposed work is not evidence already obtained.
1Understanding/implementation is not an automatic full-period operating conclusion.One successful invoice does not establish all pathways, completeness or year-long control effectiveness; evaluate needed further procedures and relevant supporting controls.

Non-credit errors

  • No credit for six synonyms for inspect invoice.
  • No universal effectiveness from one transaction.
  • No invented established revenue misstatement.
Official ICAI concept source

AUD-G04-D016 · 5 marks

External complaints can be monitoring information Pine Logistics' customers repeatedly complain of duplicate bills. Management files the messages without investigating. A supervisor reviews control performance monthly, but no corrective actions are tracked and procedures remain unchanged after the system changes. Management says only internal reports can count as monitoring information. Required: Explain monitoring, evaluate the facts and outline what the auditor should understand without assuming a proved loss. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Monitoring assesses control performance over time and timely corrective action.A monthly meeting alone is insufficient evidence that identified problems are followed up and corrected.
1Monitoring may be ongoing activities, separate evaluations or both.The supervisor review may be an ongoing activity; understand its actual scope and follow-up rather than require a single prescribed structure.
1External communications can provide relevant monitoring information.Repeated customer complaints can indicate billing problems needing investigation; management's internal-only view is wrong.
1Consider operation as intended and modification for changed conditions.Understand whether changed-system procedures remain suitable and whether identified failures lead to remedial action.
1Obtain understanding with corroboration and assess implications.Inspect complaints, review/follow-up records and inquire about outcomes; use evidence for risks/responses, not invent duplicate amounts or assume fraud.

Non-credit errors

  • Complaint is an indicator, not established amount or fraud.
  • No compulsory new monitoring department.
Official ICAI concept source

AUD-G04-D017 · 3 marks

A code of conduct is not the whole control environment Quartz Services has a signed ethics code. Its governance body rarely scrutinises estimates, and finance staff assigned complex estimates receive no relevant training. The manager treats the signed code as conclusive evidence of a satisfactory control environment. Required: Identify two other relevant elements and explain the limit of the code and environment. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Participation by those charged with governance matters.Understand actual involvement, information and scrutiny of estimates; a signed code does not establish governance challenge.
1Commitment to competence matters.Understand required skills and staff training for complex estimates; the supplied lack of relevant training raises a different concern.
1Evaluate elements collectively; the environment is not an absolute fraud deterrent.A code alone does not prove the foundation is satisfactory or prevent/detect/correct a specific misstatement; consider effects on other controls without a fraud finding.

Non-credit errors

  • No code equals perfection inference.
Official ICAI concept source

AUD-G04-D018 · 5 marks

Automated consistency depends on more than one screenshot Redwood Retail's application rejects invoices without a valid account code. A walkthrough shows one rejection. During the year, developers could change validation rules without approval or a reliable change log. The team says automation means the walkthrough always proves full-year effectiveness. Required: Evaluate the qualified automation principle, the change-control concern and the appropriate evidence boundary. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Distinguish implementation understanding from operation evidence.One rejection shows information about the control in that observed configuration, not automatically every date or transaction.
1Automation can operate consistently.Implementation procedures may serve as effectiveness evidence for an automated control because of IT consistency, but this is conditional, not universal.
1Relevant supporting controls include program-change controls.Unapproved and unlogged rule changes challenge whether the observed configuration operated consistently over the period.
1Assess and test relevant controls and investigate actual changes.Inspect available configuration/change evidence and assess relevant supporting controls; do not invent logs or presume no changes occurred.
1Determine further evidence and responses on assessed risks.Do not claim full-year effectiveness from the screenshot; plan additional/alternative procedures as needed, without assuming every invoice is wrong.

Non-credit errors

  • No automation always proves operation claim.
  • No manual walkthrough rule blindly applied without automation qualifier.
Official ICAI concept source

AUD-G04-D019 · 5 marks

Unusual transactions and judgemental estimates need different attention Sequoia Energy enters a significant one-off transaction needing management-directed accounting, manual data assembly and complex calculations. Separately, an estimate depends on subjective assumptions about uncertain future events. Neither issue is established as fraudulent and the counterparty is not stated to be related. Required: Explain three risk drivers of the transaction, a distinct estimate driver and the significant-risk judgement boundary. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Greater management intervention can increase non-routine transaction risk.Management directs the accounting treatment; understand the actual treatment and evidence rather than accept the desired result.
1Greater manual data intervention can increase risk.Manual assembly can create relevant processing concerns distinct from accounting complexity; investigate actual information flow.
1Complex calculations/principles can increase risk.The transaction's complexity calls for understanding relevant calculations and principles, not merely its infrequency.
1Subjectivity/future assumptions can increase judgemental-matter risk.The separate estimate requires understanding uncertain assumptions and the reporting implications; it is not identical to the manual-data issue.
1Evaluate significant-risk factors using judgement and actual facts.Significant unusual transactions/uncertainty merit attention, but these facts do not establish fraud or the mandatory significant nonroutine related-party category; do not invent that relationship.

Non-credit errors

  • No automatic fraud or related-party finding.
  • No repeated unusual three times for three marks.
Official ICAI concept source

AUD-G04-D020 · 10 marks

Update the understanding when the business changes Tamarind Packaging's planning file describes a domestic manufacturer with a stable policy and bank financing. Before fieldwork ends: A. A subsidiary is acquired and purchases begin from an entity controlled by a director. B. Management changes an accounting policy but supplies no reason or framework analysis. C. Financing is replaced with debt linked to performance ratios; managers now receive bonuses tied to those ratios. D. Technology changes the transaction flow, but the old process description is still used. The senior says understanding was completed at planning and only a new audit opinion template is needed. No breach, fraud or misstatement has been established. Required: (a) For each development, state what understanding to update and a useful source/action. (6 marks) (b) Explain two distinct uses of the updated understanding in audit judgement. (2 marks) (c) Correct the completed-at-planning claim and state the evidence/conclusion boundary. (2 marks)
Show answer and marking
MarksCreditCase application / answer
1.5A: update structure, ownership and transaction understanding.Inspect acquisition/ownership and actual supplier relationships and transactions; consider expected balances/disclosures and related-party identification without assuming misconduct.
1.5B: update selection/application of policy and reasons for change.Obtain management rationale and assess appropriateness for the business and consistency with the applicable framework/relevant industry policies; no automatic invalidity finding.
1.5C: update financing and performance-measure understanding.Inspect debt terms, relevant ratios and bonus arrangements; understand reporting pressures and possible effects, without assuming a covenant breach or fraud.
1.5D: update systems and relevant controls understanding.Trace changed transaction stages and inspect current records/configuration; the obsolete description cannot support assumptions about current processing.
1Use the updated frame of reference to assess risks and special-attention areas.Reconsider reporting risks and areas such as related-party transactions/policy judgements based on actual changed facts.
1Use it in evaluating evidence or analytical expectations.Revise relevant analytical expectations for the changed group/financing, or assess evidence/assumptions in light of current facts; give one distinct applied use within this cap.
1Understanding is continuous and dynamic throughout the audit.Gather, update and analyse information beyond planning; a new opinion template does not update the underlying understanding.
1Understanding guides judgement and responses, not a predetermined opinion.Evaluate evidence and appropriate further procedures; no automatic breach/fraud finding or opinion conclusion from these developments.

Non-credit errors

  • No four generic repeat-update answers without distinct facts.
  • No assumption related party transactions are improper.
  • No predetermined audit opinion.
Official ICAI concept source

AUD-G04-D021 · 3 marks

A narrative must describe the system actually operating Umber Crafts has no formal control manual. The auditor proposes a narrative record but copies an owner's ideal process without testing or observing what staff do. Staff roles have changed repeatedly. Required: Explain the method's suitability, the evidence needed and a practical limitation. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Narrative record describes the system found in operation.It can suit a small business without a formal control system; an ideal owner description is not the actual operating-system record.
1Actual testing and observation are needed to develop the record.Verify staff activities and relevant records before writing what is in operation; inquiry alone does not establish implementation.
1Narratives can be difficult to comprehend, expose gaps or update.Changing staff roles make revisions harder; keep the actual description current rather than assume the copied story remains accurate.

Non-credit errors

  • No narrative equals unverified management story.
Official ICAI concept source

AUD-G04-D022 · 3 marks

Initials on a checklist are not automatic proof Violet Traders uses a list instructing audit staff to check purchase-order numbering and authorisation. Staff initial each completed instruction and answer Yes/No/Not Applicable. The senior has not reviewed the completed list, and one No answer has no explanation. Required: Identify the method and explain completion and review limits. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1A checklist is instructions/questions audit staff follow or answer.The instructed checks, initials and Yes/No/Not Applicable responses fit the checklist method.
1Complete the specified work and record an accurate response.Initials should reflect work actually done; follow up the unexplained No rather than turn it into a Yes.
1The completed checklist is studied by responsible senior staff to evaluate controls.Review findings and support for implementation/efficiency; filled boxes alone are not a control-effectiveness conclusion.

Non-credit errors

  • No all initials equals all controls effective claim.
Official ICAI concept source

AUD-G04-D023 · 5 marks

Resolve conflicting questionnaire answers Willow Supplies' internal-control questionnaire asks whether supplier invoices are matched with purchase orders and receipt notes. The accounts head answers Yes; receiving staff say invoices often arrive before any receipt record exists. A question about a process the company does not use is answered Yes merely to avoid an empty field. The trainee wants to accept every response as tested evidence. Required: Explain the method's benefit, response conventions, inconsistency follow-up and the resulting evaluation boundary. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1A questionnaire is a comprehensive series of internal-control questions.Its structured coverage reduces the chance of omitting significant review areas; it is not simply a list of confirmed controls.
1Generally Yes indicates satisfactory, No suggests weakness with details.The accounts Yes should be supported and reconciled with receiving information; do not assume it proves matching actually occurs.
1Not Applicable is used for irrelevant questions.Record the genuinely unused process as Not Applicable with explanation, rather than a misleading Yes.
1Discuss inconsistencies with relevant employees and clarify the actual system.Inspect actual invoice/order/receipt records and trace cases beyond asking the accounts head again.
1Evaluate deficiencies and recommendations from supported findings.Prepare a clear deficiencies/recommendations record after investigation; questionnaire answers alone do not establish full-period operation or actual misstatement.

Non-credit errors

  • No unsupported Yes treated as a test result.
  • No irrelevant question labelled effective.
Official ICAI concept source

AUD-G04-D024 · 3 marks

A flow chart must show the real flow Xenia Manufacturing's lengthy process description hides the route for rejected invoices. The auditor plans a flow chart but draws only the approved route, omitting corrections and transfers between departments. Required: Explain the method, its benefit and the preparation needed. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1A flow chart graphically presents the internal-control system.Map transaction movement and links rather than provide another long prose description.
1It gives a concise overall view and can expose gaps or integration problems.Showing rejected invoices and correction routes helps reveal the omitted pathway; a neat approved-route chart may conceal it.
1Study actual business activities and channels before recording the flow.Understand purchasing, receiving, accounts and correction links with relevant evidence; a drawing is not proof controls operated effectively.

Non-credit errors

  • No omitted exception path accepted as complete chart.
Official ICAI concept source

AUD-G04-D025 · 5 marks

Control evaluation changes the audit programme Yarrow Works' payroll review finds weak recruitment/enrolment records and no reliable link between approved workers and the wages sheet. A trainee says this administrative weakness is irrelevant to financial reporting and proposes the same programme as a client with supported strong controls. No dummy worker or loss is yet proved. Required: Explain the reporting link, two distinct audit-programme implications, useful work and the conclusion limit. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1An administrative control may bear on the audit through reporting effects.Weak enrolment can permit dummy names in the wages sheet; its label does not make it irrelevant.
1Understanding actual controls informs procedure nature.Consider procedures addressing genuine workers/payments, potentially including observation of wage distribution where appropriate to the actual system.
1Weak areas may change timing/extent or require additional tests.Plan appropriate coverage and evidence for payroll risk, rather than copy another client's programme or assert a universal sample size.
1Investigate the actual system and corroborate information.Inspect authorised enrolment and wages records and trace relevant workers/payment links; do not assume a designed policy is used.
1The weakness indicates possible risk, not established fraud or loss.Evaluate evidence and responses before concluding; control evaluation informs work rather than automatically deciding the opinion.

Non-credit errors

  • No administrative always irrelevant claim.
  • No predetermined dummy worker finding.
Official ICAI concept source

AUD-G04-D026 · 5 marks

Controls need evidence of application, consistency and performer Zinnia Services' bank-reconciliation review is supported by signatures for selected months. A new reviewer took over midyear, and high-volume months have unsigned reviews. The auditor says one old signature establishes operation throughout the period. Required: Explain three operating-effectiveness dimensions, suitable follow-up and the effect on the preliminary assessment. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Consider how controls were applied.Inspect what reconciliation/review actually involved, not just whether a signature exists.
1Consider consistency during the period.Unsigned high-volume months need investigation and appropriate period coverage; an old signature is not year-long evidence.
1Consider by whom controls were applied.Investigate the reviewer change and actual responsibility/competence in the affected period.
1Make specific inquiries and ensure tests cover changes/fluctuations.Corroborate with records and suitable tests around handover and busy months; do not assume every unsigned review failed or occurred.
1Evaluate deviations against the preliminary control-risk assessment.If unsupported, revise the assessment and planned substantive nature/timing/extent as appropriate; consider other supporting control evidence, not an automatic opinion change.

Non-credit errors

  • No one signature establishes whole year claim.
  • No universal deviation equals fraud rule.
Official ICAI concept source

AUD-G04-D027 · 3 marks

Understanding evidence can sometimes serve a second purpose Acacia Stores' auditor performs procedures while understanding bank reconciliations. The work also supplies evidence about relevant control design and operation. A trainee says all understanding work is either always sufficient as control testing or can never be used for that purpose. Required: Explain the conditional use and the sufficiency limit. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Some understanding procedures may also supply control-testing evidence.Evidence about the reconciliation control can have a second use even if not originally labelled a test of controls.
1Judge whether it supports relevant design and operating-effectiveness conclusions.Evaluate the actual procedure, assertion, timing/coverage and evidence obtained rather than rely on its label.
1Use it only where sufficient to support the intended assessment.Neither every walkthrough nor every understanding procedure automatically supports reliance; obtain additional evidence where needed.

Non-credit errors

  • No always or never rule based only on procedure label.
Official ICAI concept source

AUD-G04-D028 · 10 marks

Match control tests to three different evidence problems Banyan Repairs has three controls: A. Purchase orders require approval before release and normally retain approval records. B. Cash custody and transaction recording are assigned to different staff, but there is no written trail of who actually does each task. The organisation chart names intended staff only. C. Monthly bank reconciliations and review records exist, but unexplained items may have been carried forward incorrectly. During the audit, the approver changes and transaction volume rises sharply in the final quarter. The team proposes asking the manager once and treating all controls as effective for the year. Required: (a) Design two linked control-testing actions for each of A, B and C. (6 marks) (b) Explain two features of testing application over the period in the changed circumstances. (2 marks) (c) Explain deviation evaluation and the consequence for planned substantive work. (2 marks)
Show answer and marking
MarksCreditCase application / answer
1A: inspect documents supporting transaction approval.Compare approval evidence and timing with order release for selected actual transactions; the policy is not the operation evidence.
1A: investigate application of the approval requirement.Inquire about and corroborate exceptions/approval authority, including the changed approver, rather than accept a generic manager assurance.
1B: inquire of people who actually perform functions.Ask relevant custody/recording staff about actual tasks; the chart shows intended allocation only.
1B: observe actual performance where no audit trail exists.Observe who performs custody and recording to corroborate inquiry; do not describe observation as already done.
1C: independently reperform the relevant reconciliation control.Check reconciliation of bank/record amounts and treatment of carried-forward items to evaluate correct performance.
1C: inspect preparation/review and resolution evidence.Inspect reconciliation and follow-up records to understand whether identified differences were reviewed and addressed; recomputation alone does not show every review.
1Consider how and by whom controls were applied.Investigate approver handover and actual application, not just names on the original chart.
1Consider consistency and cover relevant change/fluctuation periods.Ensure appropriate coverage of the handover and high-volume quarter; one observation or old record is not universal year-long effectiveness.
1Investigate deviations and evaluate support for the preliminary assessment.Clarify causes/timing and consider evidence from other tests rather than assume every exception is fraud or every control failed.
1Revise substantive nature/timing/extent if the assessment needs revision.Adapt planned further work to evidence-supported risk conclusions; no automatic audit opinion is determined by these indicators.

Non-credit errors

  • No manager interview alone as all control tests.
  • No six generic inspect-policy repetitions.
  • No statement proposed tests have already been performed.
Official ICAI concept source

AUD-G04-D029 · 5 marks

A control improvement announcement is not closure Cypress Tools' interim review identifies weak supplier-statement reconciliation and missing follow-up of differences. Management announces a revised procedure. At year end, the auditor has not checked whether it is used. A senior says the announcement closes the deficiency and the old risk assessment need not be reconsidered, even though substantive work identifies unexplained differences. Required: Explain follow-up, relevant evidence, reconciliation of the assessment with later evidence and possible response changes. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1A suggested improvement or announcement is distinct from an implemented control.The revised procedure alone does not show reconciliation/follow-up actually occurs.
1Follow up whether weaknesses have been removed.Inspect actual post-change reconciliations and follow-up evidence and inquire of responsible staff at the later stage.
1Consider whether control evidence supports actual design and operation.Assess the new process and appropriate period coverage rather than backdate effectiveness to the announcement.
1Reconsider the control-risk assessment in light of later substantive and other evidence.Unexplained differences challenge the old assumptions and require investigation, not dismissal because management promised a fix.
1Revise planned substantive nature/timing/extent if the assessment is unsupported.Consider other supporting control evidence and adapt work as needed; a deficiency or difference does not predetermine fraud or the report.

Non-credit errors

  • No announcement equals verified correction.
  • No unexplained difference automatically fraud.
Official ICAI concept source

AUD-G04-D030 · 10 marks

Build a focused four-area control questionnaire Dogwood Engineering has these process facts: A. Purchasing staff can issue orders and also record goods receipts; order authorisation is unclear. B. Supplier statements differ from ledger balances; duplicate invoices are not marked and no one follows up differences. C. Physical inventory counts identify shortages, but there is no evidence of investigation or authorised adjustment of stock and accounting records. D. Fixed-asset verification reports identify damaged assets and record differences, but capital spending authority and correction approval are unclear. The manager asks the auditor to write eight focused control questions, not a generic request to describe every system. No actual misstatement or loss is established. Required: (a) For each area, formulate two distinct questions and explain the specific control concern they address. (8 marks) (b) Explain response conventions and corroboration/follow-up before concluding on implementation or operation. (2 marks)
Show answer and marking
MarksCreditCase application / answer
1A: ask who authorises purchase orders and whether only authorised staff sign.The question targets unclear transaction authorisation and useful support such as signed orders/authority records.
1A: ask whether receiving/receipt-record staff are denied order-issuing or invoice-approval authority.This addresses the stated incompatible purchasing/receipt functions; it is different from the approval question.
1B: ask whether duplicate invoices are marked immediately to prevent duplicate payment.This targets the unmarked duplicate pathway, not all creditor errors generically.
1B: ask whether supplier statements are compared to ledgers and differences followed up.This targets reconciliation and investigation of the supplied differences; do not assert they prove omitted or duplicate amounts.
1C: ask whether shortage/excess reports are investigated.The question targets finding the cause of inventory count differences instead of merely recording a count.
1C: ask whether approved adjustments reach both stock and financial records.This targets authorisation and consistent correction after investigation; it is distinct from investigating causes.
1D: ask whether capital spending authority is restricted and expenditure checked against approved amounts.This addresses unclear spending authority/approved limits, not the physical verification itself.
1D: ask whether verification discrepancies/damage are investigated and records corrected with authority.This addresses follow-up and authorised corrections for actual verification findings without an invented valuation conclusion.
1Generally Yes denotes satisfactory, No suggests weakness with details and Not Applicable is for irrelevant items.Obtain answers from relevant staff with explanations; these targeted questions need actual facts, not eight automatic Yes replies.
1Clarify inconsistent responses and corroborate before evaluating deficiencies.Inspect actual orders/receipt, duplicate/reconciliation, inventory-adjustment and asset records as relevant; answers alone do not prove full-period operation or a loss.

Non-credit errors

  • No eight versions of do you have controls.
  • No questionnaire responses treated as sufficient operating evidence.
  • No invented loss or automatic opinion.
Official ICAI concept source