Only Read Permission
No Write Permission
No Create Permission
From the Users form view (Settings -> User) , set the user as Auditor by selecting the Auditor in the Accounting & Finance
Then remove the user from all the other groups
Change the access permissions as shown below
Log in as auditor
No Create Permission.
Only read permissions are given to the user