Skip to main content
ACCA
All Papers
Expertise

E3 — Audit, Risk and Control

E3 Audit, Risk and Control succeeds AA (F8) with an expanded scope that adds risk management and internal control frameworks. The traditional audit syllabus is retained but enhanced with risk assessment, enterprise risk management, and IT controls. This reflects the evolving role of the auditor.

FormatSession CBE · 3 hours · 100 marks
Pass Mark50%
Legacy PaperAA (F8) — Audit and Assurance
Sections5 sections (A, B, C, D, E)
Current-syllabus equivalentOur paper mapping links E3 to AA — Audit and Assurance. The current structure's last sitting is June 2027.
Transition Planner

Exam Format

Section A: 15 × 2-mark OTs (30 marks) · Section B: 3 × 10-mark MTQs (30 marks) · Section C: 2 × 20-mark constructed response (40 marks) · 3 hours

Key Changes vs Legacy Paper

  • Expanded scope: adds enterprise risk management (Section B3)
  • New Section E: Technology in Audit (data analytics, AI, cybersecurity)
  • COSO framework added for internal control evaluation
  • IT controls (general and application) given greater emphasis
  • Exam format moves to session CBE with constructed response

Syllabus Comparison — AA/F8 → E3

ChangeArea / TopicDetail
EXAM FORMATExam structureAA: Sec A = 3 × 10-mark OT cases (30 marks) + Sec B = 1 × 30-mark + 2 × 20-mark long-form (70 marks) = 100 marks. E3: Sec A = 15 × 2-mark OTs (30 marks) + Sec B = 3 × 10-mark case OTs (30 marks) + Sec C = 2 × 20-mark CRQs (40 marks) = 100 marks. Long-form weighting drops from 70% to 40%. AA had a single 30-mark question; E3 does not.
ADDEDSustainability — integrated throughoutSustainability appears in: audit risk assessment and business risk assessment (B2b, B2c), audit strategy planning (B4c), going concern indicators (E2b), and inconsistencies with sustainability information in the annual report (E5e). AA had no sustainability content anywhere in the syllabus.
ADDEDSustainability assurance engagements (A1b)Five elements of assurance now applied to sustainability information engagements and prospective financial information, not just traditional financial statement audits. AA’s assurance framework was financial-statement-only.
ADDEDDesign procedures for review of financial statements (A1d)New design-level outcome for limited assurance review engagements. Not present in AA as a design-level task — AA A1 focused on explaining types of assurance rather than designing review procedures.
ADDEDWhy users misunderstand the auditor’s role (A1f)Assessing the expectation gap — why users misunderstand the purpose and limitations of audit. Not a standalone assessable outcome in AA.
ADDEDCustomer due diligence at acceptance (B1a)CDD procedures explicitly added to engagement acceptance alongside the standard preconditions for an audit. AA B1 covered preconditions and engagement processes but did not name CDD.
ADDEDBusiness risk assessment including sustainability (B2c)Assessing business risks (distinct from audit risks) as a standalone outcome, explicitly including sustainability-related business risks. Not a discrete outcome in AA B3 which focused on audit risk components only.
ADDEDFactors impairing professional scepticism: biases (B2g)Conscious and unconscious biases identified as specific impairment factors for professional scepticism. AA B2 covered scepticism in general terms; identifying what impairs it was not an assessed outcome.
ADDEDData analytics interpretation in planning (B3d)Interpret results from analytical procedures and data analytics to assess audit risks — applied at the planning stage. AA’s data analytics content was limited to D5 (automated tools) and not applied during planning.
ADDEDWhether auditor should have detected fraud (A4b)New outcome requiring assessment of whether an auditor should have detected a particular fraud. Not explicit in AA B5, which covered auditor responsibilities at a general level without this accountability-focused assessment.
ADDEDMoney laundering explicitly in laws and regulations (A4c)Money laundering named as a specific compliance area within auditor responsibilities. AA B5c covered laws and regulations generally without naming money laundering.
ADDEDDesign tests of controls at assessment stage (C2b)E3 C2b requires design of tests of controls to assess effectiveness of direct controls — a design-level outcome. AA C3 described tests of controls for each cycle but framed it as understanding the controls, not designing the tests.
ADDEDInitial audit engagement procedures (D2c)Design of audit procedures specific to a first-year (initial) engagement. Not a standalone design outcome in AA — opening balances and initial engagement considerations were implicit rather than a named assessable outcome.
ADDEDImpact of subsequent events on audit opinion (E1c)Assessing how adjusting and non-adjusting subsequent events affect audit work and the audit opinion. AA E1 covered subsequent events procedures and responsibilities but not the direct impact on the audit opinion.
ADDEDMaterial uncertainty relating to going concern as named communication type (E5d)MURGC explicitly listed as a required type of additional communication in the auditor’s report, alongside KAM, EOM and OM paragraphs. AA covered going concern reporting under E2 but did not name MURGC as a distinct auditor’s report element in the reporting section (E5).
ADDEDSustainability inconsistencies in annual report (E5e)Assessing how inconsistencies between sustainability information in the annual report and the auditor’s knowledge should be communicated. AA E5 did not address sustainability in the context of the auditor’s report or other information review.
RESTRUCTUREDCorporate governance: AA A3 → E3 C4Moved from the Audit Framework section into Internal Control (Section C), where it also absorbs the internal audit content from AA C5 and C6. AA had corporate governance as a framework topic and internal audit as a separate operational topic; E3 unifies them under governance.
RESTRUCTUREDEthics: AA A4 → E3 A2Same core content (fundamental principles, conceptual framework, threats, safeguards, independence, confidentiality, breach steps) moved earlier in the section. All outcomes maintained at [2] level.
RESTRUCTUREDFraud, laws and regulations: AA B5 → E3 A4Moved from Planning (Section B) to the Audit Ecosystem (Section A) as “Responsibilities of the auditor.” The reframing shifts the topic from a planning consideration to a fundamental auditor responsibility. Two new outcomes added: whether auditor should have detected fraud (A4b) and money laundering explicit (A4c).
RESTRUCTUREDQuality management: AA A2h–j → E3 A3The three quality management outcomes from AA A2 are elevated into their own subsection (E3 A3), signalling greater independent weight. Content retained: principles [1], assess procedures [2], assess deficiencies and recommend [2].
RESTRUCTUREDInternal audit: AA C5 + C6 → E3 C4AA’s two separate internal audit subsections (C5: IA and governance; C6: scope, outsourcing, assignments) are merged into E3 C4 alongside corporate governance. Internal audit is now presented within a governance context rather than as a standalone operational subsection.
EXPANDEDAudit of specific items: 7 areas → 20 named items (D2a)AA D4 grouped audit evidence into 7 broad balance/transaction areas. E3 D2a names 20 specific items to which design-level procedures [2] must be applied. Items added compared to AA’s coverage: borrowing costs, earnings per share, effects of foreign exchange, government grants, investment property, leases, non-current assets held for sale, presentation of financial statements, purchases and other expenses.
EXPANDEDAudit strategy explicitly includes fraud and sustainability risks (B4c)E3 B4c requires assessment of how both fraud risks and sustainability risks affect the audit strategy. AA B6 covered audit strategy content without naming these risk types as explicit strategy inputs.
RAISEDAutomated tools: explain/understand → design level (D4a)AA D5a was “explain the use of automated tools” [1]. E3 D4a requires design of procedures using automated tools — a move from knowledge to application level.
REMOVEDSection F — Employability and Technology SkillsAll four outcomes (computer technology, CBE response options, screen navigation, data presentation) removed as a standalone section. Technology skills are now embedded elsewhere, principally in D4 (automated tools and techniques).
REMOVEDAccountability, stewardship and agency concepts (AA A1c)Standalone outcome explaining accountability, stewardship, and agency in the context of audit. Not present in E3 A1.
REMOVEDStatutory regulations: appointment, rights, removal, resignation (AA A2c, A2d)Outcomes covering statutory appointment, removal, and resignation of auditors, and their formal rights and duties. Not present in E3.
REMOVEDDevelopment and status of ISAs; relationship with national standards (AA A2f, A2g)Outcomes explaining the development of ISAs and their relationship to national auditing standards. Not present in E3 — ISA knowledge is treated as background for all E3 work.
REMOVEDObjective and general principles as a standalone subsection (AA B2)AA B2 (2 outcomes) was a discrete subsection covering the auditor’s overall objectives and professional scepticism. In E3, scepticism is integrated and deepened within B2 (Assessing risks), with an additional outcome on factors impairing scepticism.
REMOVEDProcess by which auditor obtains an engagement (AA B1c)The procedural outcome about how an auditor is formally engaged has been removed from E3 B1.
REDUCEDAudit sampling: 4 outcomes → 1 outcome (D1d)AA D3 had four detailed sampling outcomes: defining sampling [1], statistical vs non-statistical [2], applying statistical sampling [2], and evaluating results [2]. E3 D1d reduces this to a single [1]-level outcome: explain the need for sampling and methods to select a sample.
REMOVEDSmaller entities standalone outcome (AA D2d)AA D2d covered smaller entity control environments and the types of evidence available. No equivalent outcome in E3.
RetainedCore audit process flowThe fundamental structure (planning → risk assessment → internal control → evidence → completion → reporting) is fully retained across E3 Sections B–E, underpinned by the same ISA framework.
RetainedFive components of internal controlControl environment, entity’s risk assessment process, information system and communication, control activities, and monitoring retained in E3 C1.
RetainedSix transaction cyclesSales, purchases, payroll, inventory, bank and cash, and non-current assets — all six cycles retained in C1 and C2.
RetainedSeven audit evidence proceduresInspection, observation, external confirmation, recalculation, reperformance, analytical procedures, and inquiry retained in D1a.
RetainedNFP organisations (moved)Apply audit techniques to not-for-profit organisations retained as D2d, moved from a standalone AA D7 subsection into audit procedures.
RetainedSubsequent events, going concern, written representationsCore completion topics retained in E3 E1–E4 with largely consistent outcome scope. Going concern adds sustainability indicators (E2b); subsequent events adds opinion impact (E1c).
RetainedAuditor’s report frameworkUnmodified, qualified, adverse, and disclaimer opinions; KAM, EOM, and OM paragraphs — all retained in E5. Two new outcomes added (MURGC, sustainability inconsistencies).

Syllabus Breakdown

A

Audit Framework and Regulation

A1

The nature and purpose of audit

  • Understand the objective and scope of external audit
  • Understand the regulatory framework for audit
  • Understand professional ethics and independence
  • Identify the responsibilities of auditors and management
B

Risk Assessment and Internal Control

B1

Risk assessment

  • Understand the audit risk model: inherent, control, detection risk
  • Assess risks of material misstatement
  • Understand business risk and how it relates to audit risk
B2

Internal control

  • Evaluate internal control systems
  • Understand the components of internal control (COSO framework)
  • Identify control activities and their purpose
  • Assess IT general controls and application controls
B3

Enterprise risk management

  • Understand enterprise risk management frameworks
  • Identify types of business risk: strategic, operational, financial, compliance
  • Assess the role of risk management in governance
C

Audit Evidence and Procedures

C1

Audit evidence

  • Understand the concept of sufficient appropriate audit evidence
  • Identify and apply audit procedures: inspection, observation, enquiry, confirmation, recalculation, reperformance, analytical procedures
  • Apply substantive procedures to key financial statement areas
  • Apply tests of controls
D

Audit Review and Reporting

D1

Review and reporting

  • Evaluate audit findings and form conclusions
  • Understand the audit report: unmodified and modified opinions
  • Understand emphasis of matter and other matter paragraphs
  • Identify going concern considerations
E

Technology in Audit

E1

Audit technology

  • Understand the use of data analytics in audit
  • Identify the role of AI and automation in audit procedures
  • Understand the impact of IT on audit planning and execution
  • Identify cybersecurity risks and their audit implications