2.3 The Assurance Engagement Lifecycle (Acceptance to Reporting)
Key Takeaways
- The assurance engagement lifecycle comprises 5 phases: Client Acceptance/Continuance, Agreeing Terms (ISA 210), Planning & Risk Assessment (ISA 300/315), Execution & Evidence (ISA 330/500), and Evaluation & Reporting (ISA 700).
- Pre-engagement acceptance requires verifying practitioner independence, ethical eligibility, technical competence, and obtaining professional clearance under ICAB Bye-laws.
- An Engagement Letter under ISA 210 forms a legally binding contract detailing scope, practitioner responsibilities, management duties, and financial reporting framework.
- Risk assessment under ISA 315 and materiality determination under ISA 320 drive the design of audit responses (tests of controls and substantive procedures).
- The final stage involves evaluating misstatements, completing quality reviews, and expressing a formal audit opinion under ISA 700, ISA 705, or ISA 706.
The Assurance Engagement Lifecycle (Acceptance to Reporting)
Quick Reference: An assurance engagement is not a random collection of audit tests; it is a structured, sequential process governed by International Standards on Auditing (ISAs). The lifecycle spans five core phases: (1) Pre-Acceptance & Continuance, (2) Agreeing Engagement Terms, (3) Planning & Risk Assessment, (4) Fieldwork Execution, and (5) Evaluation & Reporting.
+-------------------------------------------------------------------------+
| 5 PHASES OF ASSURANCE ENGAGEMENT |
+-------------------------------------------------------------------------+
| Phase 1: Client Acceptance & Continuance (Ethics, Independence, KYC) |
| Phase 2: Agreeing Engagement Terms (ISA 210 Engagement Letter) |
| Phase 3: Planning & Risk Assessment (ISA 300 Strategy, ISA 315 Risk) |
| Phase 4: Fieldwork & Execution (ISA 330 Controls & Substantive) |
| Phase 5: Evaluation & Reporting (ISA 700 Audit Opinion) |
+-------------------------------------------------------------------------+
Phase 1: Client Acceptance and Continuance
Before accepting a new client engagement (or deciding to continue an existing annual engagement), a firm of Chartered Accountants must perform rigorous preliminary checks to manage professional risk.
1. Ethical Requirements and Independence
The firm must ensure compliance with the ICAB Code of Ethics (which mirrors the IESBA International Code of Ethics). The practitioner must verify that:
- None of the six threats in the ICAB syllabus — self-interest, self-review, management, advocacy, familiarity or intimidation — is present at other than an acceptable level.
- The engagement team possesses the required specialized technical competence and resources.
2. Management Integrity and KYC/AML Regulations
The firm must evaluate the integrity of management and beneficial owners. Under the Money Laundering Prevention Act 2012 and Anti-Terrorism Act 2009 of Bangladesh, accounting firms are designated reporting entities. Auditors must perform Know Your Customer (KYC) background checks on client directors and major shareholders.
3. Professional Clearance (Etiquette with Predecessor Auditor)
Under ICAB Professional Rules, when proposed as auditor to replace an existing statutory auditor, the prospective auditor must write a formal letter requesting professional clearance to the outgoing auditor asking:
"Are there any professional or ethical reasons why we should not accept appointment as auditor of ABC Ltd?"
The outgoing auditor is obligated to respond. This protects the incoming auditor from accepting clients where management is attempting to hide fraud or escape audit qualifications.
Phase 2: Agreeing the Terms of Engagement (ISA 210)
Once acceptance criteria are satisfied, the auditor must agree on the terms of the engagement with management or Those Charged With Governance (TCWG). This agreement must be documented in writing via an Engagement Letter under ISA 210.
Purpose of the Engagement Letter:
- Avoids misunderstandings regarding the scope and nature of the audit.
- Establishes a legally binding contract between the audit firm and the client.
Mandatory Contents of an ISA 210 Engagement Letter:
- The objective and scope of the financial statement audit.
- The responsibilities of the auditor.
- The responsibilities of management (for preparing financial statements, maintaining internal control, and granting unrestricted access to information).
- Identification of the applicable financial reporting framework (e.g., IFRS / BFRS and Companies Act 1994).
- Reference to the expected form and content of any reports to be issued.
- Fee arrangements and billing terms.
Phase 3: Planning & Risk Assessment (ISA 300 & ISA 315)
Planning is not a discrete phase but a continuous process throughout the audit. Under ISA 300 (Planning an Audit of Financial Statements), the auditor establishes the Overall Audit Strategy and develops an Audit Plan.
Key Planning Activities:
UNDERSTAND ENTITY & ENVIRONMENT (ISA 315)
|---> Identify Business & Financial Risks
|---> Assess Internal Control Design (COSO Framework)
|
ESTABLISH MATERIALITY THRESHOLDS (ISA 320)
|---> Overall Materiality (e.g., 1% of Revenue or 5% of Profit Before Tax)
|---> Performance Materiality (buffer to reduce aggregation risk)
|
DEVELOP AUDIT PLAN (ISA 330)
|---> Design Audit Procedures responsive to Assessed Risks of Material Misstatement
- Understanding the Entity (ISA 315 Revised): Gaining deep knowledge of the client’s industry, regulatory environment (e.g., Bangladesh Bank guidelines for financial institutions), ownership structure, operations, and internal control framework.
- Setting Materiality (ISA 320): Determining materiality levels for financial statements as a whole and performance materiality to guide audit testing scopes.
Phase 4: Fieldwork & Execution (ISA 330 & ISA 500)
During fieldwork, audit teams execute audit procedures to gather sufficient appropriate audit evidence (ISA 500).
Audit Evidence Gathering Techniques:
- Tests of Controls: Procedures designed to evaluate the operating effectiveness of controls in preventing, or detecting and correcting, material misstatements at the assertion level.
- Substantive Procedures: Audit procedures performed to detect material misstatements at the assertion level. Substantive procedures include:
- Substantive Analytical Procedures: Comparing client financial ratios and trends against industry expectations or prior periods.
- Tests of Details: Direct verification of individual transactions, ledger balances, physical inventory counts, and third-party bank confirmations (ISA 505).
Phase 5: Evaluation, Conclusion & Reporting (ISA 700 series)
In the final stage, the practitioner reviews the audit working papers and evidence to form an audit opinion.
Step-by-Step Reporting Workflow:
- Evaluate Uncorrected Misstatements (ISA 450): Accumulate misstatements identified during the audit and evaluate whether they are material, individually or in the aggregate.
- Obtain Written Representations (ISA 580): Require management to sign a representation letter confirming their responsibility for financial statements and full disclosure of information.
- Quality Control Review (ISQM 1 / ISA 220): Perform an engagement quality review for Public Interest Entities prior to report signing.
- Issue Audit Report (ISA 700 / 705 / 706): Format and sign the final statutory audit report.
| Audit Opinion Type | Condition |
|---|---|
| Unmodified Opinion | Financial statements give a true and fair view in all material respects. |
| Qualified Opinion | Misstatements are material but not pervasive, or auditor cannot obtain evidence (material but not pervasive). |
| Adverse Opinion | Misstatements are both material AND pervasive (financial statements are fundamentally misleading). |
| Disclaimer of Opinion | Auditor cannot obtain evidence and potential effects are both material AND pervasive. |
Reporting to the engaging party
The syllabus requires you to identify how the assurance provider reports to the engaging party, and the answer depends on which engagement you are in.
| Engagement | Report goes to | Form of the conclusion |
|---|---|---|
| Statutory audit under the Companies Act 1994 | The members (shareholders), under s. 213; the report is read at the AGM under s. 216 and is open to inspection by any member | Positive, reasonable-assurance opinion: the accounts give a true and fair view |
| Review of interim financial information (ISRE 2400) | The party that engaged the practitioner, named in the engagement letter | Negative, limited-assurance conclusion: "nothing has come to our attention…" |
| Other assurance engagement (ISAE 3000) | The engaging party, with intended users identified in the report | Positive or negative depending on whether the engagement is reasonable or limited assurance |
Three points are examined repeatedly:
- The addressee is set at engagement acceptance, not at reporting. The ISA 210 engagement letter must already state the expected form and content of the report and who receives it, which is why a change of addressee mid-engagement is a change of terms.
- The report is restricted where the criteria are not general purpose. Where suitable criteria are available only to specific users, the assurance report carries a restriction-on-use paragraph so it is not relied on by others.
- A written report is a defining element. An assurance engagement always ends in a written report to the engaging party; an oral debrief to the finance director is not an assurance report, however detailed it is.
Under ICAB professional etiquette rules, what action MUST a prospective auditor take before accepting an appointment to replace an existing statutory auditor?
According to ISA 210, which of the following items MUST be documented within an audit Engagement Letter?
When an auditor discovers that financial statements contain misstatements that are BOTH material AND pervasive, which audit opinion must be issued under ISA 705?