IRBA Issues Staff Audit Practice Alert 13 on Public Sector Risks

Posted 06 October 2026 Written by Acts Online

Brought to you by SA Accounting Academy: The Independent Regulatory Board for Auditors (IRBA) has issued Staff Audit Practice Alert 13, establishing technical guidance for registered auditors on assessing and responding to risk in public sector audit engagements.

Issued pursuant to the regulatory mandate in the Auditing Profession Act, No. 26 of 2005, the Alert provides detailed guidance on risk assessment, fraud indicators, governance considerations, and auditor responses. The guidance is grounded primarily in International Standard on Auditing (ISA) 315 (Revised 2019), Identifying and Assessing the Risks of Material Misstatement, alongside ISA 240 (Revised), The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements.

While the Alert focuses directly on public sector audit engagements, its principles also apply to statutory audits of private sector entities that maintain substantial commercial, regulatory, or contractual relationships with organs of state. The stated effective date is immediately from 10 September 2026.

The guidance directs audit teams to address specific engagement factors, including:

  • Risk assessment procedures: Identifying public sector-specific regulatory environments, statutory operating models, and mandate-driven operational risks under ISA 315 (Revised 2019).
  • Fraud risk evaluation: Detecting fraud risk factors, procurement irregularities, and management override risks within state reporting entities in terms of ISA 240 (Revised).
  • Governance and oversight structures: Factoring accounting authorities, legislative reporting requirements, and oversight bodies into the audit risk assessment.
  • Audit responses: Designing tailored substantive and controls testing responsive to identified public sector vulnerabilities.

Click here to download IRBA Staff Audit Practice Alert 13.

What this means for you, your business, or your clients

  • For yourself: Registered auditors must apply the alert’s risk identification and fraud assessment procedures directly when completing engagement work programmes for public entities or government contractors.
  • For your business: Audit firms must update engagement templates, quality management reviews, and audit training to comply with ISA 315 and ISA 240 requirements specific to the public sector context.
  • For your clients: Public sector institutions and private contractors dealing with government must anticipate expanded auditor testing around internal financial controls, supply chain management, and anti-fraud mechanisms.

Originally published at https://accountingacademy.co.za/news/read/irba-staff-audit-practice-alert-13-strengthening-public-sector-audits-identifying-and-responding-to-public-sector-specific-risks


The views expressed herein are those of the author and do not necessarily reflect those of Acts Online. Acts Online accepts no responsibility for the accuracy, completeness or fairness of the article, nor does the information contained herein constitute advice, legal or otherwise.