Nature and Regulatory Framework of Auditing
Foundations
Nature and Regulatory Framework of Auditing
Syllabus tag: KASNEB CPA | Intermediate Level | CA24 Auditing and Assurance | Topic 1 Nature and Regulatory Framework of Auditing
Lesson objectives
By the end of this topic, you will be able to:
- Define an audit and state its objective
- Explain the five elements of an assurance engagement
- Distinguish reasonable from limited assurance
- Explain the expectation gap and its components
- Identify the regulatory framework applying in Kenya
Why this matters
An audit is not a search for fraud, nor a guarantee that the accounts are correct. Much of what the public believes about auditing is wrong, and a candidate must be able to say precisely what an audit is and is not.
What an audit is
The objective of an audit is to enable the auditor to express an opinion on whether the financial statements are prepared, in all material respects, in accordance with an applicable financial reporting framework.
Four features are worth drawing out of that sentence:
- It produces an opinion, not a certificate or a guarantee
- It concerns material respects, not every figure
- It is judged against a framework — IFRS in Kenya
- It is an independent examination, which is what gives it value
Why audits exist
The agency problem. Shareholders own the company but managers run it, and managers prepare the very statements on which their stewardship is judged. An independent examination gives the owners assurance that the account they receive is reliable.
That is why independence matters more than technical skill. A brilliant audit by someone the shareholders cannot trust is worth nothing to them.
Elements of an assurance engagement
Five, and an examiner may ask for them:
- A three-party relationship — practitioner, responsible party, intended users
- Subject matter — what is being examined
- Suitable criteria — the benchmark, such as IFRS
- Sufficient appropriate evidence
- A written report
Note that the intended user is a third party, not the client who pays. The auditor is engaged by the company and reports to the shareholders — a structural tension that runs through the ethics topic.
Reasonable and limited assurance
| Reasonable assurance | Limited assurance | |
|---|---|---|
| Engagement | Statutory audit | Review engagement |
| Work performed | Extensive: tests of control and substantive procedures | Mainly enquiry and analytical procedures |
| Conclusion | Positive: "the statements give a true and fair view" | Negative: "nothing has come to our attention" |
| Level | High, but not absolute | Moderate |
Reasonable assurance is high but never absolute. Absolute assurance is impossible, for reasons inherent to the exercise:
- Testing is on a sample, not the whole population
- Accounting involves judgement and estimates that cannot be verified exactly
- Fraud may be concealed through collusion or forgery
- Evidence is often persuasive rather than conclusive
- The audit must be completed in a reasonable time and at a reasonable cost
The negative form of the review conclusion is deliberate. It says less, because less work was done, and the wording is designed to prevent a reader treating it as an audit opinion.
The expectation gap
The difference between what the public believes an auditor does and what an auditor actually does. It has three components:
The knowledge gap. The public misunderstands the role — believing the auditor certifies the accounts are correct, guarantees solvency, or checks every transaction.
The performance gap. Some audits fall short of the standards required. This part is the profession's own fault and is addressed by monitoring and discipline.
The evolution gap. Public expectations move faster than standards do — over climate disclosure or fraud detection, for example.
The most persistent misunderstanding: detecting fraud is not the primary objective of an audit. The auditor plans to obtain reasonable assurance that the statements are free from material misstatement whether caused by fraud or error, but responsibility for preventing and detecting fraud rests with management and those charged with governance.
:::checkpoint A company collapses six months after receiving an unmodified audit opinion, and the press asks how the auditors missed it. Identify which component of the expectation gap this illustrates, and explain what an unmodified opinion does and does not say about solvency. :::
The regulatory framework in Kenya
| Source | Role |
|---|---|
| Companies Act 2015 | Requires audit; sets appointment, rights and duties |
| ICPAK | Regulates the profession; issues practising certificates |
| Accountants Act 2008 | Establishes ICPAK and the disciplinary machinery |
| IAASB | Issues the International Standards on Auditing |
| IESBA Code | Ethical requirements, adopted by ICPAK |
| Capital Markets Authority | Additional requirements for listed entities |
| Public Audit Act 2015 | Audit of public entities by the Auditor-General |
Kenya has adopted ISAs in full, so an audit conducted here follows the same standards as one anywhere else applying them.
ISQM 1 requires firms to operate a system of quality management covering governance, ethics, client acceptance, engagement performance, resources and monitoring. Quality is a firm-level obligation, not merely an engagement-level one.
:::checkpoint Explain why the auditor is appointed by the shareholders rather than by the directors, given that the directors are the people the auditor deals with daily. :::