Treat the ACCA Audit and Assurance (AA) syllabus as a single reasoning chain. For any scenario, practise moving from risk identification, to the assertion affected, to the type of test required, and finally to the audit conclusion or report modification. Build each study session around one complete chain rather than one topic in isolation, and check your own answers for those links.
Why the audit risk model should organise your whole revision
The audit risk model (audit risk = inherent risk x control risk x detection risk) explains why the syllabus is sequenced as it is: assessment drives response. Use it as the spine of your notes, not as one topic among several.
Start by separating the components carefully. Inherent risk is the susceptibility of an assertion to misstatement before any controls, driven by factors such as estimation uncertainty, complexity, or transactions outside normal course of business. Control risk is the risk that the entity's controls fail to prevent or detect that misstatement. Detection risk is the risk that your own procedures miss what exists, and it is the only component the auditor directly controls.
This distinction has a practical consequence in scenario answers. If the question describes a complex estimate or an unusual transaction, that is inherent risk evidence. If it describes manual controls performed by one person with no review, that is control risk evidence. Mixing these up weakens the response, because the auditor's reaction differs: high inherent and control risk pushes you toward more effective substantive procedures, closer to period end, with a wider focus.
Practise labelling: take any past scenario paragraph and tag each sentence as inherent risk, control risk, or background information that affects neither. Expected observation: business and industry commentary falls mostly into inherent risk; descriptions of who signs what and who reconciles what fall into control risk. If you cannot classify a sentence, ask what an auditor would do differently if it were true.
Assertions: the vocabulary that converts a risk into a procedure
Assertions are the categories into which every audit procedure must fit. Learn the transaction-related assertions (occurrence, completeness, accuracy, cutoff, classification) separately from the balance-related ones (existence, rights and obligations, completeness, valuation and allocation).
Completeness and existence are easy to conflate because both seem to ask whether the records are right, yet they pull in opposite directions. Existence asks whether recorded items are real, so the auditor selects items from the accounting records and traces them to supporting evidence, such as confirming a receivable with the customer. Completeness asks whether all real items are recorded, so the direction of testing reverses: start from the underlying physical or external evidence and trace forward into the records, such as from a goods despatch note to the sales invoice.
Direction of testing is the idea worth drilling until it is automatic, because it determines whether a procedure is relevant to the assertion at all. Writing 'check sales invoices to despatch notes' tests occurrence; writing 'check despatch notes to sales invoices' tests completeness. The same documents, opposite assertions. In scenario answers, state the assertion first, then the direction, then the procedure, and the justification writes itself.
Exercise: write the five transaction assertions and the balance assertions on two lists. For each assertion on the revenue and receivables cycle, draft one procedure with its testing direction. Self-check rubric: 1 point for correctly naming the assertion, 1 point for stating the direction of the test, 1 point for naming a document or external source that fits that direction. A score below about 10 out of 15 means relearn the assertion definitions before attempting full scenario questions.
Tests of controls versus substantive procedures: choosing the right tool
Tests of controls evaluate whether a control operated effectively; substantive procedures detect misstatements in amounts or disclosures themselves. The choice depends on your assessed risk and the evidence each test can produce. Use the table below to decide.
A single activity can serve as either type of test depending on its purpose, which is where confusion arises. Reperforming a bank reconciliation tells you whether the control worked if your objective is control evaluation; the same reperformance is a substantive test of the cash balance if your objective is verifying the amount. In answers, the purpose sentence is what earns the marks, so write it explicitly: 'to determine whether the reconciliation control operated throughout the period' versus 'to confirm the accuracy of the recorded cash balance at year end'.
Dual-purpose tests exist and are worth naming when relevant: a single sample examined for both control operation and monetary accuracy. However, remember the limitation that a test of controls alone can never, by itself, provide sufficient evidence about a balance, because controls address the process rather than the recorded figure. Even in a low control risk environment, some substantive procedures remain necessary, which is why the model matters: low assessed risk justifies less extensive substantive work, not none.
Practise rewriting: take five generic procedures such as 'observe stock count' or 'review receivables ageing' and write two versions of each, one framed as a test of controls and one as substantive. Expected observation: the control version focuses on who performed the task, whether it was authorised, and whether exceptions were followed up; the substantive version focuses on the recorded amount, its valuation, and its supporting evidence.
| Feature | Test of controls | Substantive procedure |
|---|---|---|
| Purpose | Assess whether a control prevented or detected errors | Detect misstatement in an amount or disclosure |
| Typical question it answers | Did the control operate as designed throughout the period? | Is the recorded figure accurate, complete, and fairly stated? |
| Evidence source | Documents showing control performance, observation, reperformance of the control | External confirmations, recalculation, inspection of supporting documents |
| Use in the risk model | Reduces assessed control risk, which permits reduced substantive testing | Directly addresses detection risk for the assertion |
| Limitation | Cannot by itself evidence the recorded balance | Costlier and less informative about the control environment |
Ethics questions: match the threat type to the safeguard, not to a memorised list
The AA syllabus covers the five fundamental principles (integrity, objectivity, professional competence and due care, confidentiality, professional behaviour) and the familiar threat categories: self-interest, self-review, advocacy, familiarity, and intimidation. Learn them as a classification skill.
The classification matters because each threat implies a different family of safeguards. A self-review threat arises when the firm audits work it previously prepared or judged, for example auditing financial statements the firm's own accounting department helped draft; the safeguards involve independent review by someone not involved in the original work or declining the engagement. A familiarity threat arises from long association with a client, where sympathy for their interests erodes professional scepticism; relevant safeguards include rotating senior personnel or introducing an independent quality review.
In scenario answers, a strong response names the threat, explains the mechanism in one sentence, and then links a safeguard that actually addresses that mechanism. Weak responses list generic safeguards that fit any situation. If the scenario involves a fee that is a large proportion of the firm's total income, that is self-interest; a contingent fee arrangement is also self-interest; a partner whose close relative holds a senior finance post at the client is familiarity. Learn these trigger patterns deliberately.
Add independence of those charged with governance to your checklist: when you identify a threat, note whether the firm can refer the matter to those charged with governance as a possible safeguard, and whether the threat is so significant that no safeguard reduces it to an acceptable level, in which case declining or withdrawing is the only option. That final branch, resignation versus safeguards, is a decision you should be able to argue in either direction with reasons.
Worked scenario one: the revenue risk chain from planning to procedure
Scenario: revenue grew sharply in the final month of the year while the sales ledger clerk left mid-period and month-end reconciliations stopped for six weeks. Trace the chain correctly and the whole answer follows.
A plausible mistake is jumping straight to a generic procedure, for example 'perform sales cut-off testing', without establishing what the risk actually is or which assertion it threatens. The unfilled clerk vacancy and stopped reconciliations are control risk evidence; the year-end revenue spike, without more information, raises inherent risk around cutoff and occurrence. An answer that lists procedures for valuation of receivables here is answering a different question, because nothing in the scenario points to recoverability.
The better decision follows the chain explicitly. State the risk: overstated revenue through early recognition before year end. Name the assertions: occurrence and cutoff for revenue; existence for receivables as the mirror effect. Design the response: for cutoff, examine sales invoices either side of the year end and match them to goods despatch documentation to check recognition falls in the correct period; for occurrence, confirm selected year-end balances with customers. Explain why: the external despatch documentation and customer responses provide evidence from outside the entity's records, which matters when the recording process itself was unmonitored for six weeks.
Why it matters: this chain is the difference between an answer that demonstrates audit reasoning and one that recites procedures. Practise the same trace on a payables or payroll scenario and check that each procedure you write can answer the question 'which risk and assertion does this address, and why is this source of evidence persuasive for it?' If it cannot, delete or rewrite it.
Worked scenario two: going concern and choosing the right report modification
The review and reporting area turns on a decision tree: is there a material uncertainty, does the disclosure adequately address it, and does the issue affect the true and fair view? Each branch leads to a different report outcome.
Scenario: a client's loan facility expires three months after year end and renewal talks are unresolved. A plausible mistake is concluding 'issue a qualified opinion' reflexively, because qualification is the most memorable modification. That conflates a misstatement problem with a disclosure problem. Going concern issues, when properly disclosed, typically call for an unmodified opinion with a material uncertainty related to going concern section drawing attention to the disclosure, precisely because the financial statements have handled the matter correctly.
The better decision walks the branches in order. First, does an event or condition cast significant doubt on going concern? Here, yes, the facility expiry with no confirmed replacement. Second, are the disclosures adequate, including the mitigating plans and the assessment period? If yes: unmodified opinion plus the material uncertainty section, plus a key audit matter where relevant. If disclosures are inadequate: unmodified opinion is unavailable, and the appropriate response is a qualification or adverse opinion depending on materiality and pervasiveness. Misstatements that are material but not pervasive support qualification; pervasive ones support an adverse opinion.
Rehearse this as a spoken decision, not a paragraph: doubt, disclosure, pervasiveness, opinion. Practise with three mini-scenarios of your own construction, one landing on each of qualified, adverse, and emphasis-of-matter-type outcomes, and write one sentence per branch justifying the position. The skill being trained is matching the severity and nature of the issue to the modification, which is the point of the whole reporting topic.
A four-week preparation sequence and readiness checks
Spend the first two weeks building the chain topic by topic, week three on full scenario questions written to a plan, and week four on timed mixed practice with a self-marking rubric drawn from the syllabus areas.
Week one: audit framework, regulation, and ethics, including the threat-and-safeguard classification drill. Week two: planning, risk, internal control, and evidence, with the assertion-direction exercise and the tests-of-controls versus substantive comparison above. Week three: attempt scenario questions by writing a two-minute plan first, listing risks, assertions, and response types before any prose. Week four: mixed timed sets covering review and reporting alongside earlier areas, then mark yourself against a rubric.
Use this self-check rubric when marking your own scenario answers. Award one mark per element: a risk explicitly identified from scenario facts; a named assertion linked to that risk; a procedure whose direction and source of evidence fit the assertion; a conclusion or report implication where the question asks for one. A sensible learning milestone is scoring roughly four out of five elements on the majority of your attempts by the end of week four; treat this as a progress indicator for your own study, not as a prediction of any exam outcome.
Readiness checks before you finish: you can explain the difference between existence and completeness testing using direction of testing; you can classify any ethics scenario into a named threat within a minute; you can walk the reporting decision tree aloud without notes; and you can justify why a test of controls alone cannot evidence a balance. For administrative matters such as exam booking and current exam format, rely on ACCA's official site rather than secondary summaries.
One comparison table to keep beside your notes throughout:
| Feature | Test of controls | Substantive procedure |
|---|---|---|
| Purpose | Assess whether a control prevented or detected errors | Detect misstatement in an amount or disclosure |
| Typical question it answers | Did the control operate as designed throughout the period? | Is the recorded figure accurate, complete, and fairly stated? |
| Evidence source | Documents showing control performance, observation, reperformance of the control | External confirmations, recalculation, inspection of supporting documents |
| Use in the risk model | Reduces assessed control risk, which permits reduced substantive testing | Directly addresses detection risk for the assertion |
| Limitation | Cannot by itself evidence the recorded balance | Costlier and less informative about the control environment |
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
