All Papers
Expertise
E3 — Audit, Risk and Control
E3 Audit, Risk and Control succeeds AA (F8) with an expanded scope that adds risk management and internal control frameworks. The traditional audit syllabus is retained but enhanced with risk assessment, enterprise risk management, and IT controls. This reflects the evolving role of the auditor.
FormatSession CBE · 3 hours · 100 marks
Pass Mark50%
Legacy PaperAA (F8) — Audit and Assurance
Sections5 sections (A, B, C, D, E)
Current-syllabus equivalentOur paper mapping links E3 to AA — Audit and Assurance. The current structure's last sitting is June 2027.
Transition Planner Exam Format
Section A: 15 × 2-mark OTs (30 marks) · Section B: 3 × 10-mark MTQs (30 marks) · Section C: 2 × 20-mark constructed response (40 marks) · 3 hours
Key Changes vs Legacy Paper
- Expanded scope: adds enterprise risk management (Section B3)
- New Section E: Technology in Audit (data analytics, AI, cybersecurity)
- COSO framework added for internal control evaluation
- IT controls (general and application) given greater emphasis
- Exam format moves to session CBE with constructed response
Syllabus Comparison — AA/F8 → E3
| Change | Area / Topic | Detail |
|---|---|---|
| EXAM FORMAT | Exam structure | AA: Sec A = 3 × 10-mark OT cases (30 marks) + Sec B = 1 × 30-mark + 2 × 20-mark long-form (70 marks) = 100 marks. E3: Sec A = 15 × 2-mark OTs (30 marks) + Sec B = 3 × 10-mark case OTs (30 marks) + Sec C = 2 × 20-mark CRQs (40 marks) = 100 marks. Long-form weighting drops from 70% to 40%. AA had a single 30-mark question; E3 does not. |
| ADDED | Sustainability — integrated throughout | Sustainability appears in: audit risk assessment and business risk assessment (B2b, B2c), audit strategy planning (B4c), going concern indicators (E2b), and inconsistencies with sustainability information in the annual report (E5e). AA had no sustainability content anywhere in the syllabus. |
| ADDED | Sustainability assurance engagements (A1b) | Five elements of assurance now applied to sustainability information engagements and prospective financial information, not just traditional financial statement audits. AA’s assurance framework was financial-statement-only. |
| ADDED | Design procedures for review of financial statements (A1d) | New design-level outcome for limited assurance review engagements. Not present in AA as a design-level task — AA A1 focused on explaining types of assurance rather than designing review procedures. |
| ADDED | Why users misunderstand the auditor’s role (A1f) | Assessing the expectation gap — why users misunderstand the purpose and limitations of audit. Not a standalone assessable outcome in AA. |
| ADDED | Customer due diligence at acceptance (B1a) | CDD procedures explicitly added to engagement acceptance alongside the standard preconditions for an audit. AA B1 covered preconditions and engagement processes but did not name CDD. |
| ADDED | Business risk assessment including sustainability (B2c) | Assessing business risks (distinct from audit risks) as a standalone outcome, explicitly including sustainability-related business risks. Not a discrete outcome in AA B3 which focused on audit risk components only. |
| ADDED | Factors impairing professional scepticism: biases (B2g) | Conscious and unconscious biases identified as specific impairment factors for professional scepticism. AA B2 covered scepticism in general terms; identifying what impairs it was not an assessed outcome. |
| ADDED | Data analytics interpretation in planning (B3d) | Interpret results from analytical procedures and data analytics to assess audit risks — applied at the planning stage. AA’s data analytics content was limited to D5 (automated tools) and not applied during planning. |
| ADDED | Whether auditor should have detected fraud (A4b) | New outcome requiring assessment of whether an auditor should have detected a particular fraud. Not explicit in AA B5, which covered auditor responsibilities at a general level without this accountability-focused assessment. |
| ADDED | Money laundering explicitly in laws and regulations (A4c) | Money laundering named as a specific compliance area within auditor responsibilities. AA B5c covered laws and regulations generally without naming money laundering. |
| ADDED | Design tests of controls at assessment stage (C2b) | E3 C2b requires design of tests of controls to assess effectiveness of direct controls — a design-level outcome. AA C3 described tests of controls for each cycle but framed it as understanding the controls, not designing the tests. |
| ADDED | Initial audit engagement procedures (D2c) | Design of audit procedures specific to a first-year (initial) engagement. Not a standalone design outcome in AA — opening balances and initial engagement considerations were implicit rather than a named assessable outcome. |
| ADDED | Impact of subsequent events on audit opinion (E1c) | Assessing how adjusting and non-adjusting subsequent events affect audit work and the audit opinion. AA E1 covered subsequent events procedures and responsibilities but not the direct impact on the audit opinion. |
| ADDED | Material uncertainty relating to going concern as named communication type (E5d) | MURGC explicitly listed as a required type of additional communication in the auditor’s report, alongside KAM, EOM and OM paragraphs. AA covered going concern reporting under E2 but did not name MURGC as a distinct auditor’s report element in the reporting section (E5). |
| ADDED | Sustainability inconsistencies in annual report (E5e) | Assessing how inconsistencies between sustainability information in the annual report and the auditor’s knowledge should be communicated. AA E5 did not address sustainability in the context of the auditor’s report or other information review. |
| RESTRUCTURED | Corporate governance: AA A3 → E3 C4 | Moved from the Audit Framework section into Internal Control (Section C), where it also absorbs the internal audit content from AA C5 and C6. AA had corporate governance as a framework topic and internal audit as a separate operational topic; E3 unifies them under governance. |
| RESTRUCTURED | Ethics: AA A4 → E3 A2 | Same core content (fundamental principles, conceptual framework, threats, safeguards, independence, confidentiality, breach steps) moved earlier in the section. All outcomes maintained at [2] level. |
| RESTRUCTURED | Fraud, laws and regulations: AA B5 → E3 A4 | Moved from Planning (Section B) to the Audit Ecosystem (Section A) as “Responsibilities of the auditor.” The reframing shifts the topic from a planning consideration to a fundamental auditor responsibility. Two new outcomes added: whether auditor should have detected fraud (A4b) and money laundering explicit (A4c). |
| RESTRUCTURED | Quality management: AA A2h–j → E3 A3 | The three quality management outcomes from AA A2 are elevated into their own subsection (E3 A3), signalling greater independent weight. Content retained: principles [1], assess procedures [2], assess deficiencies and recommend [2]. |
| RESTRUCTURED | Internal audit: AA C5 + C6 → E3 C4 | AA’s two separate internal audit subsections (C5: IA and governance; C6: scope, outsourcing, assignments) are merged into E3 C4 alongside corporate governance. Internal audit is now presented within a governance context rather than as a standalone operational subsection. |
| EXPANDED | Audit of specific items: 7 areas → 20 named items (D2a) | AA D4 grouped audit evidence into 7 broad balance/transaction areas. E3 D2a names 20 specific items to which design-level procedures [2] must be applied. Items added compared to AA’s coverage: borrowing costs, earnings per share, effects of foreign exchange, government grants, investment property, leases, non-current assets held for sale, presentation of financial statements, purchases and other expenses. |
| EXPANDED | Audit strategy explicitly includes fraud and sustainability risks (B4c) | E3 B4c requires assessment of how both fraud risks and sustainability risks affect the audit strategy. AA B6 covered audit strategy content without naming these risk types as explicit strategy inputs. |
| RAISED | Automated tools: explain/understand → design level (D4a) | AA D5a was “explain the use of automated tools” [1]. E3 D4a requires design of procedures using automated tools — a move from knowledge to application level. |
| REMOVED | Section F — Employability and Technology Skills | All four outcomes (computer technology, CBE response options, screen navigation, data presentation) removed as a standalone section. Technology skills are now embedded elsewhere, principally in D4 (automated tools and techniques). |
| REMOVED | Accountability, stewardship and agency concepts (AA A1c) | Standalone outcome explaining accountability, stewardship, and agency in the context of audit. Not present in E3 A1. |
| REMOVED | Statutory regulations: appointment, rights, removal, resignation (AA A2c, A2d) | Outcomes covering statutory appointment, removal, and resignation of auditors, and their formal rights and duties. Not present in E3. |
| REMOVED | Development and status of ISAs; relationship with national standards (AA A2f, A2g) | Outcomes explaining the development of ISAs and their relationship to national auditing standards. Not present in E3 — ISA knowledge is treated as background for all E3 work. |
| REMOVED | Objective and general principles as a standalone subsection (AA B2) | AA B2 (2 outcomes) was a discrete subsection covering the auditor’s overall objectives and professional scepticism. In E3, scepticism is integrated and deepened within B2 (Assessing risks), with an additional outcome on factors impairing scepticism. |
| REMOVED | Process by which auditor obtains an engagement (AA B1c) | The procedural outcome about how an auditor is formally engaged has been removed from E3 B1. |
| REDUCED | Audit sampling: 4 outcomes → 1 outcome (D1d) | AA D3 had four detailed sampling outcomes: defining sampling [1], statistical vs non-statistical [2], applying statistical sampling [2], and evaluating results [2]. E3 D1d reduces this to a single [1]-level outcome: explain the need for sampling and methods to select a sample. |
| REMOVED | Smaller entities standalone outcome (AA D2d) | AA D2d covered smaller entity control environments and the types of evidence available. No equivalent outcome in E3. |
| Retained | Core audit process flow | The fundamental structure (planning → risk assessment → internal control → evidence → completion → reporting) is fully retained across E3 Sections B–E, underpinned by the same ISA framework. |
| Retained | Five components of internal control | Control environment, entity’s risk assessment process, information system and communication, control activities, and monitoring retained in E3 C1. |
| Retained | Six transaction cycles | Sales, purchases, payroll, inventory, bank and cash, and non-current assets — all six cycles retained in C1 and C2. |
| Retained | Seven audit evidence procedures | Inspection, observation, external confirmation, recalculation, reperformance, analytical procedures, and inquiry retained in D1a. |
| Retained | NFP organisations (moved) | Apply audit techniques to not-for-profit organisations retained as D2d, moved from a standalone AA D7 subsection into audit procedures. |
| Retained | Subsequent events, going concern, written representations | Core completion topics retained in E3 E1–E4 with largely consistent outcome scope. Going concern adds sustainability indicators (E2b); subsequent events adds opinion impact (E1c). |
| Retained | Auditor’s report framework | Unmodified, qualified, adverse, and disclaimer opinions; KAM, EOM, and OM paragraphs — all retained in E5. Two new outcomes added (MURGC, sustainability inconsistencies). |
Syllabus Breakdown
A
Audit Framework and Regulation
A1
The nature and purpose of audit
- Understand the objective and scope of external audit
- Understand the regulatory framework for audit
- Understand professional ethics and independence
- Identify the responsibilities of auditors and management
B
Risk Assessment and Internal Control
B1
Risk assessment
- Understand the audit risk model: inherent, control, detection risk
- Assess risks of material misstatement
- Understand business risk and how it relates to audit risk
B2
Internal control
- Evaluate internal control systems
- Understand the components of internal control (COSO framework)
- Identify control activities and their purpose
- Assess IT general controls and application controls
B3
Enterprise risk management
- Understand enterprise risk management frameworks
- Identify types of business risk: strategic, operational, financial, compliance
- Assess the role of risk management in governance
C
Audit Evidence and Procedures
C1
Audit evidence
- Understand the concept of sufficient appropriate audit evidence
- Identify and apply audit procedures: inspection, observation, enquiry, confirmation, recalculation, reperformance, analytical procedures
- Apply substantive procedures to key financial statement areas
- Apply tests of controls
D
Audit Review and Reporting
D1
Review and reporting
- Evaluate audit findings and form conclusions
- Understand the audit report: unmodified and modified opinions
- Understand emphasis of matter and other matter paragraphs
- Identify going concern considerations
E
Technology in Audit
E1
Audit technology
- Understand the use of data analytics in audit
- Identify the role of AI and automation in audit procedures
- Understand the impact of IT on audit planning and execution
- Identify cybersecurity risks and their audit implications




