Free Questions › ACCA › Advanced Audit and Assurance
Free ACCA Advanced Audit and Assurance Practice Questions & Answers
296 exam-style Advanced Audit and Assurance questions. Pick your answer, hit Check answer, and see the worked solution — free to start, no signup.
100% free · No login to startQuestion 1
What is the primary objective of an external audit?
Select an option first.
Correct answer: B — To provide an independent opinion on whether financial statements present a true and fair view
Explanation: B is correct. The primary objective of an external audit is to enable the auditor to express an opinion on whether the financial statements give a true and fair view (or present fairly, in all material respects). A: auditors plan to detect material misstatement, not all fraud — detecting every fraud is not possible. C: no audit can guarantee accuracy — reasonable assurance is given. D: management prepares the statements; the auditor only reports on them.
Question 2
What is the difference between 'reasonable assurance' and 'absolute assurance' in auditing?
Select an option first.
Correct answer: B — Reasonable assurance is a high level of confidence that financial statements are free from material misstatement, but not absolute because of the inherent limitations of audit (sampling, estimates, management override)
Explanation: B is correct. Reasonable assurance: high but not absolute confidence that statements are free from material misstatement. Limitations that prevent absolute assurance include: use of sampling (not examining every transaction), subjective estimates, and the risk of management override of controls. A: no audit provides 100% certainty. C: a review gives limited assurance, lower than the reasonable assurance of an audit. D: they are not interchangeable.
Question 3
What is the 'expectation gap' in auditing?
Select an option first.
Correct answer: B — The difference between what the public believes auditors do and what auditors are actually responsible for — the public often incorrectly believes auditors prevent all fraud, guarantee accuracy, or certify financial health
Explanation: B is correct. The expectation gap arises because the public (and some users) expects auditors to: detect all fraud, guarantee financial statement accuracy, and assess viability. In reality, auditors: express an opinion based on reasonable assurance, are not responsible for preventing fraud, and may not detect immaterial errors. A describes a cost variance. C and D are specific audit outcomes.
Question 4
Which body issues the International Standards on Auditing (ISAs)?
Select an option first.
Correct answer: B — The International Auditing and Assurance Standards Board (IAASB)
Explanation: B is correct. The IAASB, a body of the International Federation of Accountants (IFAC), develops and issues ISAs. A: the FRC issues UK-specific versions (ISAs(UK)) and governs auditors in the UK, but does not issue the international ISAs. C: the IASB issues IFRS accounting standards, not auditing standards. D: the FCA regulates financial markets in the UK.
Question 5
What is 'audit risk' and what are its three components?
Select an option first.
Correct answer: B — The risk that the auditor expresses an inappropriate opinion — composed of: inherent risk (the susceptibility of an assertion to misstatement), control risk (the risk that controls will not prevent or detect misstatement), and detection risk (the risk that audit procedures will not detect existing misstatement)
Explanation: B is correct. Audit risk = Inherent risk × Control risk × Detection risk. Inherent risk: natural susceptibility of an assertion to error (e.g., complex estimates, volatile items). Control risk: likelihood that the client's internal controls fail. Detection risk: the only component the auditor can control — by increasing the extent of procedures, detection risk is reduced. A, C and D are business or engagement risks, not the audit risk model.
Get the full ACCA question bank — free
Drop your email and we'll send you fresh ACCA practice questions, fully worked solutions and exam-deadline reminders. No spam — unsubscribe in one click.
Want to save your score and take a full mock exam? Create a free account →
Question 6
What is 'inherent risk' in the context of the audit risk model?
Select an option first.
Correct answer: B — The susceptibility of a financial statement assertion to a material misstatement, assuming no related internal controls — driven by the nature of the item (complexity, subjectivity, volume, and related party involvement)
Explanation: B is correct. Inherent risk: natural risk before considering controls. High inherent risk examples: accounting estimates (subjective), related party transactions (complex), inventory at year-end (volume and valuation risk), revenue recognition (judgemental). A is control risk. C is a practice-level quality risk. D is a going concern assessment risk, not inherent risk per se.
Question 7
What is 'control risk' and how does it affect audit planning?
Select an option first.
Correct answer: B — The risk that a misstatement that could occur will not be prevented or detected and corrected on a timely basis by the client's internal control system — if control risk is assessed as high, the auditor performs more substantive procedures to compensate
Explanation: B is correct. Control risk: depends on the effectiveness of the client's internal controls. If controls are strong (low control risk), the auditor can rely on them and reduce substantive work. If controls are weak (high control risk), more extensive substantive procedures are required to achieve the desired low overall audit risk. A is sampling risk. C and D are business risks.
Question 8
What is 'detection risk' and why is it the only component of audit risk the auditor can directly control?
Select an option first.
Correct answer: B — The risk that the auditor's procedures do not detect a material misstatement that exists — the auditor controls this by varying the nature, timing, and extent of audit procedures. More procedures or more effective procedures reduce detection risk
Explanation: B is correct. Detection risk is within the auditor's control because the auditor decides: what procedures to perform (nature), when to perform them (timing), and how many (extent). Inherent and control risk exist in the client's business and systems — the auditor can assess them but not change them. A and D are not detection risk. C relates to quality control.
Question 9
What is 'materiality' in an audit and why is it important?
Select an option first.
Correct answer: B — A threshold below which misstatements are considered unlikely to influence the decisions of users — used by the auditor to determine the scope of testing and to evaluate audit findings. Information is material if its omission or misstatement could reasonably influence the economic decisions of users
Explanation: B is correct. Materiality: set by the auditor based on a percentage of a benchmark (e.g., 5% of profit before tax, 0.5–1% of revenue or total assets). Items below materiality: not individually reported, may receive less testing. Misstatements above materiality: reported to management, assessed for impact on the audit opinion. A and C misuse the term. D describes audit complexity.
Question 10
How is 'performance materiality' different from 'overall materiality'?
Select an option first.
Correct answer: B — Performance materiality is set below overall materiality — it is used to plan and perform procedures to reduce the risk that the aggregate of uncorrected and undetected misstatements exceeds overall materiality. It provides a buffer to account for the fact that many small errors can collectively become material
Explanation: B is correct. Performance materiality (set at typically 50–75% of overall materiality): the working-level threshold used for individual tests. The gap between performance and overall materiality allows for accumulation of multiple misstatements. A reverses the relationship. C is wrong. D: performance materiality applies across all areas, though it may be set differently for specific high-risk areas.
Question 11
What is 'specific materiality' (sometimes called a lower threshold) and when might it apply?
Select an option first.
Correct answer: B — A materiality threshold lower than the overall level, applied to specific transactions or disclosures where even a small misstatement could influence users' decisions — e.g., related party transactions, directors' remuneration, or items where the nature (not just the size) makes them sensitive
Explanation: B is correct. Specific (lower) materiality thresholds: certain items are sensitive regardless of size. Related party transactions: legal and governance significance. Directors' remuneration: users focus on exact amounts. Compliance items (covenants, regulatory thresholds): a small breach could have major consequences. A reverses the concept. C and D are wrong.
Question 12
What is a 'significant risk' in auditing and how should the auditor respond?
Select an option first.
Correct answer: B — A risk of material misstatement that requires special audit consideration — typically because of: high complexity or subjectivity, significant management judgement, unusual transactions, or high susceptibility to fraud (including revenue recognition). The auditor must perform substantive procedures specifically addressing that risk
Explanation: B is correct. Significant risks (ISA 315): require the auditor to perform substantive procedures regardless of the results of controls testing — the auditor cannot rely on controls alone for significant risks. Examples: revenue recognition (often presumed to be a significant risk), management override of controls, complex fair value measurements, one-off unusual transactions. A and C describe aspects of significant risk but are incomplete. D is too narrow.
Question 13
What are 'financial statement assertions' and why are they important in audit planning?
Select an option first.
Correct answer: B — The implicit or explicit claims made by management in the financial statements (existence, completeness, accuracy, valuation, classification, rights and obligations, cut-off, presentation and disclosure) — they guide the auditor in designing procedures to address specific risks
Explanation: B is correct. Assertions: management asserts (claims) that: items exist (existence), all items are included (completeness), items are correctly valued (valuation/accuracy), transactions occurred in the right period (cut-off), the entity has rights to assets/obligations for liabilities (rights and obligations), and items are properly presented (classification/presentation). Each assertion may have different risk levels, guiding test design. A, C and D are wrong.
Question 14
What is the 'going concern' basis of accounting and what is the auditor's responsibility?
Select an option first.
Correct answer: B — The going concern basis assumes a business will continue operating for at least 12 months from the reporting date without the need for liquidation — the auditor must evaluate whether management's assessment of going concern is appropriate and whether there are material uncertainties that require disclosure
Explanation: B is correct. Going concern (ISA 570): management must assess at least 12 months from the financial statement date. The auditor evaluates: management's process, supporting evidence, and whether the going concern basis is appropriate. If material uncertainty exists: verify disclosure in the financial statements. If going concern is inappropriate: adverse opinion. A: the auditor expresses an opinion on the assessment, not a guarantee. D: going concern issues can arise in profitable companies (e.g., cash flow problems, breached covenants).
Question 15
What are indicators of going concern problems that an auditor should look out for?
Select an option first.
Correct answer: B — Financial indicators (recurring losses, net current liabilities, inability to pay debts, loss of major customer), operating indicators (industrial disputes, dependence on a single customer or supplier, loss of key management), and external indicators (regulatory changes, legal proceedings, uninsured disasters)
Explanation: B is correct. Going concern indicators are diverse: Financial: net liability position, working capital deficiency, borrowing facilities expiring without renewal prospects, cash flow problems. Operational: loss of key staff, losing major contracts, or supply chain disruption. External: legal threats, regulatory changes, adverse market conditions. A and C are only one category. D is just one example of a financial indicator.
Question 16
What is the audit planning process and why is planning important?
Select an option first.
Correct answer: B — Audit planning involves establishing an overall audit strategy and developing an audit plan — it ensures the audit is performed effectively and efficiently, risks are identified early, appropriate resources are allocated, and the audit team understands the entity and its environment
Explanation: B is correct. Planning (ISA 300): the auditor develops an overall audit strategy (scope, timing, direction) and an audit plan (nature, timing, extent of procedures). Planning ensures proper focus on high-risk areas, coordination of the team, and efficient use of time. A: even small audits require planning. C: reading prior files is one input, not the entire plan. D: plans should be updated as circumstances change during the audit.
Question 17
What is 'analytical procedures' and how are they used during planning?
Select an option first.
Correct answer: B — Evaluations of financial information through analysis of plausible relationships among both financial and non-financial data — used during planning to identify unusual fluctuations, unexpected relationships, or areas of potential risk that require further attention
Explanation: B is correct. Analytical procedures at planning (ISA 520): compare current period figures to prior periods, budgets, industry averages, and related financial data (e.g., inventory turnover, gross margin). Unexpected changes or relationships highlight areas of risk. Also used at final review and as substantive procedures during the audit. A describes tests of detail. D is tests of detail (substantive procedures).
Question 18
What is 'understanding the entity and its environment' and why is it required?
Select an option first.
Correct answer: B — The process of gathering knowledge about the entity's industry, regulatory environment, nature of its business, internal controls, and financial reporting to identify and assess risks of material misstatement — without this understanding, the auditor cannot design appropriate procedures
Explanation: B is correct. ISA 315: the auditor must understand: the industry and regulatory environment, the entity's strategy and objectives, the financial reporting process, and its internal control system. This understanding underpins risk assessment. Without it, the auditor cannot identify what could go wrong or design targeted procedures. A is a background check (different). C and D are wrong.
Question 19
What is the purpose of an 'engagement letter' in an audit?
Select an option first.
Correct answer: B — To document the agreed terms of the audit engagement before work begins — it sets out the scope of the audit, management's and the auditor's responsibilities, basis of fee calculation, and any limitations on the engagement
Explanation: B is correct. Engagement letter (ISA 210): the contract between auditor and client. Key contents: objective and scope of the audit, responsibilities of management (preparing statements, maintaining internal controls) and the auditor (forming and expressing an opinion), applicable financial reporting framework, expected form of audit report, basis for fees, and access to records. A is the audit report function. C and D are wrong.
Question 20
What is the 'audit strategy' vs the 'audit plan'?
Select an option first.
Correct answer: B — The audit strategy sets the overall direction: scope, timing, and approach (e.g., extent of reliance on internal controls). The audit plan translates the strategy into a detailed programme of procedures: nature, timing, and extent of specific tests for each audit area
Explanation: B is correct. ISA 300: audit strategy = high-level decisions (risk-based focus, use of IT, reliance on internal audit, team composition). Audit plan = detailed procedures derived from the strategy (which assertions to test, which accounts, timing of visits, sample sizes). Both are auditor-prepared. Both should be updated as the audit progresses. A conflates them. C and D are wrong.
Question 21
What is 'professional scepticism' and why is it essential in auditing?
Select an option first.
Correct answer: B — A questioning mind and a critical assessment of evidence — the auditor should not simply accept what management says but should evaluate whether evidence is sufficient, appropriate, and consistent. It is especially important when assessing management estimates, related party transactions, and fraud risks
Explanation: B is correct. Professional scepticism (ISA 200): maintaining a questioning mind throughout the audit — recognising that circumstances may exist that cause the financial statements to be materially misstated. It does not mean assuming dishonesty, but not assuming honesty either. A: scepticism is applied to evidence, not people. C: scepticism means evaluation, not blanket disagreement. D: scepticism is required throughout the audit, not just when fraud is suspected.
Question 22
What is 'professional judgement' in auditing?
Select an option first.
Correct answer: B — The application of relevant training, knowledge, and experience in making informed decisions about the courses of action that are appropriate in the circumstances of an audit — essential when evaluating evidence, assessing materiality, and forming opinions on complex matters
Explanation: B is correct. Professional judgement (ISA 200): the auditor applies professional judgement in many areas — assessing risk, setting materiality, choosing the nature and extent of procedures, and evaluating evidence. It must be grounded in the standards and underpinned by professional scepticism. A is client-driven (wrong — independence required). C is too narrow. D is wrong.
Question 23
What are the main components of internal control that an auditor must understand?
Select an option first.
Correct answer: B — The control environment, risk assessment process, information system (including related business processes), control activities, and monitoring of controls — together these form the framework through which management achieves its control objectives
Explanation: B is correct. COSO framework / ISA 315: five components of internal control. Control environment: the tone at the top (governance, culture, values). Risk assessment: management's process for identifying risks. Information system: how transactions are processed and reported. Control activities: specific policies and procedures (authorisation, reconciliations, segregation). Monitoring: ongoing evaluation of whether controls work. A, C and D are only individual components.
Question 24
What is the 'control environment' and why is it the foundation of internal control?
Select an option first.
Correct answer: B — The attitudes, awareness, and actions of governance and management about the importance of internal control — it sets the tone that influences the control consciousness of the organisation. A strong control environment: ethical leadership, competent staff, clear accountability, and strong governance
Explanation: B is correct. Control environment: the foundation for all other controls. If management has an ethical culture, strong oversight, and clear accountability, other controls are more likely to function effectively. Conversely, a poor control environment (e.g., domineering management, over-ride culture) undermines even well-designed controls. A is IT infrastructure. C is control activities. D is the compliance function.
Question 25
What are 'control activities' and give examples relevant to financial reporting?
Select an option first.
Correct answer: B — Specific policies and procedures that help ensure management directives are carried out — examples include: authorisation of transactions, reconciliations, physical controls over assets, segregation of duties, system access controls, and exception reporting
Explanation: B is correct. Control activities (ISA 315): the policies and procedures that are put in place to address risks. Examples: every invoice >£10k requires two signatures (authorisation), monthly bank reconciliations (reconciliation), inventory counts (physical controls), no one person can both raise and approve a purchase order (segregation of duties). A is internal audit. D is monitoring.
Question 26
What is 'segregation of duties' and why is it a key internal control?
Select an option first.
Correct answer: B — Ensuring that no single person has complete control over all stages of a transaction — by separating the functions of authorisation, recording, and custody, collusion is required to commit and conceal fraud, making it less likely to occur
Explanation: B is correct. Segregation of duties: classic example — the person who orders goods should not also receive them and process the payment invoice. If one person controls all three functions, they could create fictitious purchases and divert payments. Segregation means any fraud would require at least two people colluding, which is less likely. A is audit team structure. C and D are organisational separations.
Question 27
What is 'management override of controls' and why is it a fraud risk?
Select an option first.
Correct answer: B — When management uses its authority to bypass established internal controls — considered a significant fraud risk because management has the ability and access to circumvent controls that would otherwise prevent or detect misstatement. The auditor must always address this risk regardless of control strength
Explanation: B is correct. Management override (ISA 240): a presumed risk in every audit. Management can: make inappropriate journal entries, adjust estimates, structure transactions to circumvent controls. Audit procedures to address this: examine journal entries (especially unusual ones near year-end), review accounting estimates for bias, evaluate unusual transactions. A is an accounting policy change. C and D are different control failures.
Question 28
What is 'IT general controls' (ITGCs) and why do they matter to the auditor?
Select an option first.
Correct answer: B — Controls that apply to the overall IT environment and infrastructure — including: access controls (who can log in and what they can do), program change management (controls over changes to software), computer operations controls, and IT security. Weak ITGCs mean that application controls cannot be relied upon
Explanation: B is correct. ITGCs underpin automated application controls. If ITGCs are weak (e.g., anyone can change system parameters, or changes to programs are not tested), the reliability of automated controls (e.g., system-generated exception reports) is compromised. A describes application controls. C is partly application controls. D is too narrow.
Question 29
What is the relationship between assessed risk and the amount of audit work?
Select an option first.
Correct answer: B — There is an inverse relationship between detection risk and the assessed level of risk — when inherent risk and control risk are high (meaning material misstatement is more likely), the auditor must lower detection risk by doing more, or more effective, audit work
Explanation: B is correct. Audit risk = Inherent risk × Control risk × Detection risk. The auditor aims for a low audit risk. If inherent and control risk are high, the auditor must lower detection risk to compensate — achieved by performing more extensive or more effective substantive procedures. A reverses the logic. C: more work does typically translate to higher fees, but the driver is detection risk reduction. D is wrong.
Question 30
What is the purpose of 'tests of controls' and how do they differ from 'substantive procedures'?
Select an option first.
Correct answer: B — Tests of controls assess whether specific controls are operating effectively — if they are, the auditor can reduce substantive work. Substantive procedures (tests of detail and analytical procedures) directly detect material misstatements in account balances and transactions, regardless of controls
Explanation: B is correct. Tests of controls: is the control working? (e.g., check whether all invoices above £10k have two signatures). Substantive procedures: is the balance correct? (e.g., agree debtors to invoices and proof of dispatch). The auditor may choose not to test controls and go straight to substantive procedures, or test controls to reduce the extent of substantive work. A is wrong (both can be performed simultaneously). C conflates them. D is too narrow.
More free ACCA topics
Management Accounting401
Strategic Business Reporting400
Advanced Taxation400
Corporate and Business Law398
Advanced Financial Management396
Financial Reporting395
Financial Management394
Performance Management391
Financial Accounting388
Advanced Performance Management388
Business and Technology300
Taxation299
Strategic Business Leader297
Audit and Assurance294
Ten questions in
- The ones you miss are saved as a drill you can repeat
- Your place is kept, on this device and any other
- A streak, if that is the thing that gets you back tomorrow
Every question on this page stays free and open either way.