Skip to content
SmartStudy

Nature and Regulatory Framework of Auditing

Foundations

Nature and Regulatory Framework of Auditing

Syllabus tag: KASNEB CPA | Intermediate Level | CA24 Auditing and Assurance | Topic 1 Nature and Regulatory Framework of Auditing

Lesson objectives

By the end of this topic, you will be able to:

  • Define an audit and state its objective
  • Explain the five elements of an assurance engagement
  • Distinguish reasonable from limited assurance
  • Explain the expectation gap and its components
  • Identify the regulatory framework applying in Kenya

Why this matters

An audit is not a search for fraud, nor a guarantee that the accounts are correct. Much of what the public believes about auditing is wrong, and a candidate must be able to say precisely what an audit is and is not.

What an audit is

The objective of an audit is to enable the auditor to express an opinion on whether the financial statements are prepared, in all material respects, in accordance with an applicable financial reporting framework.

Four features are worth drawing out of that sentence:

  • It produces an opinion, not a certificate or a guarantee
  • It concerns material respects, not every figure
  • It is judged against a framework — IFRS in Kenya
  • It is an independent examination, which is what gives it value

Why audits exist

The agency problem. Shareholders own the company but managers run it, and managers prepare the very statements on which their stewardship is judged. An independent examination gives the owners assurance that the account they receive is reliable.

That is why independence matters more than technical skill. A brilliant audit by someone the shareholders cannot trust is worth nothing to them.

Elements of an assurance engagement

Five, and an examiner may ask for them:

  1. A three-party relationship — practitioner, responsible party, intended users
  2. Subject matter — what is being examined
  3. Suitable criteria — the benchmark, such as IFRS
  4. Sufficient appropriate evidence
  5. A written report

Note that the intended user is a third party, not the client who pays. The auditor is engaged by the company and reports to the shareholders — a structural tension that runs through the ethics topic.

Reasonable and limited assurance

Reasonable assuranceLimited assurance
EngagementStatutory auditReview engagement
Work performedExtensive: tests of control and substantive proceduresMainly enquiry and analytical procedures
ConclusionPositive: "the statements give a true and fair view"Negative: "nothing has come to our attention"
LevelHigh, but not absoluteModerate

Reasonable assurance is high but never absolute. Absolute assurance is impossible, for reasons inherent to the exercise:

  • Testing is on a sample, not the whole population
  • Accounting involves judgement and estimates that cannot be verified exactly
  • Fraud may be concealed through collusion or forgery
  • Evidence is often persuasive rather than conclusive
  • The audit must be completed in a reasonable time and at a reasonable cost

The negative form of the review conclusion is deliberate. It says less, because less work was done, and the wording is designed to prevent a reader treating it as an audit opinion.

The expectation gap

The difference between what the public believes an auditor does and what an auditor actually does. It has three components:

The knowledge gap. The public misunderstands the role — believing the auditor certifies the accounts are correct, guarantees solvency, or checks every transaction.

The performance gap. Some audits fall short of the standards required. This part is the profession's own fault and is addressed by monitoring and discipline.

The evolution gap. Public expectations move faster than standards do — over climate disclosure or fraud detection, for example.

The most persistent misunderstanding: detecting fraud is not the primary objective of an audit. The auditor plans to obtain reasonable assurance that the statements are free from material misstatement whether caused by fraud or error, but responsibility for preventing and detecting fraud rests with management and those charged with governance.

:::checkpoint A company collapses six months after receiving an unmodified audit opinion, and the press asks how the auditors missed it. Identify which component of the expectation gap this illustrates, and explain what an unmodified opinion does and does not say about solvency. :::

The regulatory framework in Kenya

SourceRole
Companies Act 2015Requires audit; sets appointment, rights and duties
ICPAKRegulates the profession; issues practising certificates
Accountants Act 2008Establishes ICPAK and the disciplinary machinery
IAASBIssues the International Standards on Auditing
IESBA CodeEthical requirements, adopted by ICPAK
Capital Markets AuthorityAdditional requirements for listed entities
Public Audit Act 2015Audit of public entities by the Auditor-General

Kenya has adopted ISAs in full, so an audit conducted here follows the same standards as one anywhere else applying them.

ISQM 1 requires firms to operate a system of quality management covering governance, ethics, client acceptance, engagement performance, resources and monitoring. Quality is a firm-level obligation, not merely an engagement-level one.

:::checkpoint Explain why the auditor is appointed by the shareholders rather than by the directors, given that the directors are the people the auditor deals with daily. :::

Next in Auditing and AssuranceProfessional Ethics and Independence