0% found this document useful (0 votes)
3 views18 pages

Auditing2 ExamStudyGuide

This advanced auditing study guide covers key topics including the International Federation of Accountants (IFAC), client screening, auditor responsibilities regarding fraud and error, reliance on others, and audit risk. It emphasizes the importance of ethical, commercial, and legal considerations before accepting an audit, as well as the auditor's role in detecting fraud and the risks associated with relying on experts and internal auditors. The guide also details the audit risk formula and its components: inherent risk, control risk, and detection risk.

Uploaded by

kousarkhoso131
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views18 pages

Auditing2 ExamStudyGuide

This advanced auditing study guide covers key topics including the International Federation of Accountants (IFAC), client screening, auditor responsibilities regarding fraud and error, reliance on others, and audit risk. It emphasizes the importance of ethical, commercial, and legal considerations before accepting an audit, as well as the auditor's role in detecting fraud and the risks associated with relying on experts and internal auditors. The guide also details the audit risk formula and its components: inherent risk, control risk, and detection risk.

Uploaded by

kousarkhoso131
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

📚 AUDITING 2

ADVANCED AUDITING — EXAM-READY STUDY GUIDE


Covers: IFAC • Client Screening • Fraud & Error • Reliance on Others • Audit Risk • Internal
Control • Corporate Governance • Internal Audit

———————————————————————————————

TOPIC 1: IFAC — International Federation of Accountants


Think of IFAC as the 'world headquarters' of accounting. It sets the rules (ISAs) that auditors
everywhere must follow.

1.1 What is IFAC?


• IFAC = International Federation of Accountants
• It is a global body of accounting professionals
• Formed in 1977, headquartered in New York
• Has 180 member bodies representing 2.5 million+ accountants across 135 jurisdictions
• Objective: Develop & improve the accounting profession by issuing high-quality auditing
standards

1.2 IAASB — The Standard-Setting Committee


• IFAC formed the IAASB (International Auditing and Assurance Standards Board)
• IAASB is delegated the task of developing ISAs (International Standards on Auditing)
• Process: IAASB prepares an 'Exposure Draft' → circulates to member bodies for comments →
final vote
• Approval rule: At least two-thirds majority of those attending the meeting must approve

📊 EXAMPLE
Example: IAASB wants to issue a new ISA on Risk Assessment. It first releases an
'Exposure Draft', collects comments from member bodies in 135 countries, then in a meeting,
at least 2/3 of members vote YES before it becomes a standard.
⚠️ EXAM TIP
• IFAC issues ISAs through IAASB — not directly. Remember this distinction.
• Two-thirds majority is a commonly tested threshold.
• IFAC founded: 1977, New York — simple fact but asked in MCQs.

🎯 QUICK REVISION
• IFAC = Global body of accountants | Founded 1977, New York | 180 members, 135
jurisdictions
• ISAs issued by IAASB (committee of IFAC)
• Exposure Draft → Comments → 2/3 majority approval → Standard

📝 PAST PAPER STYLE QUESTIONS


SHORT:
1. What is IFAC and what is its objective? (3 marks)
2. Who issues ISAs, and what is the approval threshold? (2 marks)
LONG:
3. Describe the role of IFAC and IAASB in the development of International Standards
on Auditing. (8 marks)

TOPIC 2: Client Screening — Matters to Consider Before


Accepting an Audit
Before an auditor says 'yes' to a new client, they must carefully screen the client. Think of it like a job
interview — but the auditor is interviewing the client!

2.1 The Three Categories of Considerations


There are three kinds of considerations before accepting an audit:
4. Ethical Considerations
5. Commercial Considerations
6. Legal Considerations

2.2 Ethical Considerations


• Independence — Can the auditor remain independent from this client?
• Availability of staff — Does the firm have enough qualified staff to serve this client?
• Integrity of the client — Is the client's management honest and trustworthy?
• Competence of the auditor — Does the auditor have the skills/expertise to serve this client?
• Professional etiquette letter — A letter sent to the PREVIOUS auditor asking if there are any
valid reasons NOT to accept the audit
🔍 PROFESSIONAL ETIQUETTE LETTER — EXPLAINED
When a new auditor is appointed, they MUST write to the outgoing (previous) auditor before
accepting the appointment. This protects both auditors and the public.
Purpose: To find out if there are any professional reasons (e.g. unpaid fees, disagreement
with management, suspected fraud) that should stop the new auditor from accepting.
Requirement: Client's PERMISSION is needed before the previous auditor can reply
honestly.

📊 EXAMPLE
Example: ABC & Co. are approached by XYZ Ltd. to become their new auditors. Before
accepting, ABC & Co. must write to XYZ's previous auditors (DEF & Co.) asking: 'Are there
any professional reasons why we should not accept this appointment?' If DEF & Co. reply
saying XYZ's management had serious integrity issues, ABC & Co. should decline.

2.3 Commercial Considerations


• Ensure adequacy of fees — Will the audit fee cover the cost of work done? Is it profitable?

2.4 Legal Considerations


• Ensure that the appointment of the auditor is valid (done legally as per the Companies Act)
• Obtain a copy of the appointment resolution (board resolution appointing new auditor)
• Obtain a copy of the notice sent to the retiring auditor (previous auditor must be formally
notified)

🔴 IMPORTANT
• Professional etiquette letter is NECESSARY — skipping it is unprofessional.
• Legal validity of appointment must be confirmed — an invalid appointment means no
legal standing.
• Appointment resolution = formal board decision to appoint auditor.

Consideration Key Point Example

Ethical Independence, competence, integrity, Auditor must not hold


etiquette letter shares in client company

Commercial Fee adequacy If the fee is too low to cover


audit costs, reconsider

Legal Valid appointment, resolutions, notice Board resolution must be


to previous auditor passed to appoint new
auditor
🎯 QUICK REVISION
• 3 considerations: Ethical | Commercial | Legal
• Ethical: Independence, staff availability, client integrity, auditor competence, etiquette
letter
• Commercial: Fee adequacy
• Legal: Valid appointment + board resolution + notice to retiring auditor
• Professional etiquette letter = letter to PREVIOUS auditor asking for any professional
objections

📝 PAST PAPER STYLE QUESTIONS


SHORT:
7. What is a professional etiquette letter? Why is it necessary? (3 marks)
8. List the legal considerations before accepting an audit. (3 marks)
LONG:
9. Describe all matters an auditor should consider before accepting a new audit
appointment. (10 marks)

TOPIC 3: Responsibilities of an Auditor as Regards Fraud


& Error
A very commonly misunderstood topic. The auditor is NOT a fraud detective — but they must be alert!

3.1 Why Discovery of Fraud After Audit Doesn't Mean Negligence


Finding fraud AFTER the audit is completed does NOT automatically mean the auditor was negligent.
Reasons:
• Audit is carried out on a sample basis — not every transaction is checked
• Audit evidence is persuasive (gives reasonable assurance), NOT conclusive (absolute
assurance)
• Inherent limitations of the internal control system exist (discussed below)

📊 EXAMPLE
Example: After ABC Ltd.'s audit was signed off, it was discovered that the cashier had been
embezzling small amounts daily for 2 years — a total of Rs. 5 million. The auditor is not
automatically negligent because: (1) Audit was done on a sample basis, (2) The amounts
were small per transaction and wouldn't be material individually, (3) Internal controls had
inherent limitations.

3.2 Auditor's Attitude During Audit


• The auditor must carry out audit with a CRITICAL ATTITUDE (professional scepticism)
• Do NOT assume client is honest
• Do NOT assume client is dishonest
• Maintain neutral, questioning mind

3.3 Steps When Fraud/Error is Suspected


If the auditor has a doubt that financial statements contain fraud or error:
10. Extend audit procedures to investigate the doubt
11. If confirmed — ensure it is properly reflected in the financial statements
12. Discuss the fraud/error with management
13. If management refuses to correct — consider impact on audit report OR consider resignation
14. Report to regulatory authorities about the fraud/error
15. BEFORE reporting externally — take legal advice
16. Obtain a Letter of Representation from the client about fraud & error

🔴 IMPORTANT
• It is NOT the duty of the auditor to DETECT fraud — the objective is to form an
opinion on financial statements.
• Primary responsibility for fraud prevention lies with MANAGEMENT, not the auditor.
• Letter of Representation = written statement from management confirming specific
matters.
• Take LEGAL ADVICE before reporting to regulatory authorities.

Reasonable Assurance Absolute Assurance

What audit provides What audit does NOT provide

Evidence is persuasive Evidence would be conclusive

Based on sample testing Would require 100% checking

Acknowledges inherent limitations Assumes perfect systems

🎯 QUICK REVISION
• Audit = sample basis → not negligent if fraud found after audit
• Auditor's attitude: CRITICAL (neither honest nor dishonest assumption)
• Steps: Extend procedures → Confirm → Reflect in FS → Discuss with mgmt → If
refused, report or resign
• Take LEGAL ADVICE before reporting to regulators
• Get LETTER OF REPRESENTATION from client
• Objective of auditor = opinion on FS, NOT fraud detection

📝 PAST PAPER STYLE QUESTIONS


SHORT:
17. Why does post-audit discovery of fraud not necessarily imply auditor negligence? (4
marks)
18. What steps should an auditor take upon discovering fraud during audit? (5 marks)
LONG:
19. Discuss the responsibilities of an external auditor with regard to fraud and error. (10
marks)

TOPIC 4: Reliance on Others — Experts, Internal Auditors


& Service Organisations
Auditors often cannot be experts in everything. They may rely on others — but must be careful when
doing so.

4.1 Reliance on Experts


An expert is someone with specialised knowledge used for audit evidence (e.g. valuers, actuaries,
engineers).
Steps when relying on experts:
• Obtain a review of the assumptions used by the expert
• Evaluate the reasonableness of those assumptions
• Ensure assumptions are consistent with the expert's conclusions
• Enquire and assess the sources of data obtained by the expert
• Verify subsequent events that may affect the expert's work

📊 EXAMPLE
Example: A property development company includes land valued at Rs. 500 million in its
balance sheet. The auditor relies on an independent valuer (expert). The auditor must:
Review the valuer's assumptions about location, market conditions; Check those
assumptions are reasonable; Ensure the final valuation figure is consistent with those
assumptions; Check if any post-year-end events (e.g. a new zoning law) affected the land's
value.

4.2 Reliance on Internal Auditors


Steps when relying on internal auditors:
• Ensure independence of the internal auditor (not reporting to management under review)
• Review the scope of internal auditor's work
• Ensure internal auditor is sufficiently experienced and qualified
• Ensure sufficient audit evidence has been obtained by them
• Ensure internal auditor carried out work with professional care
• Test and evaluate work performed by internal auditor
⚡ KEY RULE
Even if the external auditor relies on the internal auditor's work, the SOLE RESPONSIBILITY
for expressing an opinion on financial statements remains with the EXTERNAL AUDITOR.

4.3 Reliance on Service Organisations


A service organisation handles some of the entity's processes (e.g. payroll processing outsourced to
another firm).
Steps:
• Obtain a list of assignments outsourced to the vendor
• Examine the professional qualifications of the vendor
• Ascertain the degree of supervision exercised by the entity over the service organisation
• Review errors made by the service organisation
• Also review the procedures for rectification of errors made by the service organisation

Who Key Concern Key Action

Expert Are assumptions reasonable? Review, evaluate, verify subsequent


events

Internal Auditor Is work reliable and independent? Test, evaluate, ensure scope
covered

Service Is outsourced process controlled? List assignments, check


Organisation qualifications, review errors

⚠️ EXAM TIP
• External auditor CANNOT transfer responsibility to internal auditor — solo
responsibility stays.
• All three (Expert, Internal Auditor, Service Org) have distinct steps — learn each set
separately.
• Service organisation questions often appear in scenario-based questions.

🎯 QUICK REVISION
• Expert: Review assumptions, reasonableness, consistency, data sources,
subsequent events
• Internal Auditor: Independence, scope, qualifications, evidence, care, test work
• Service Organisation: List assignments, qualifications, supervision, errors,
rectification procedures
• SOLE RESPONSIBILITY = always with external auditor

📝 PAST PAPER STYLE QUESTIONS


SHORT:
20. What steps should an external auditor take when relying on an expert? (5 marks)
21. What matters should an auditor consider when relying on a service organisation? (4
marks)
LONG:
22. Discuss the procedures an external auditor should follow when relying on the work of:
(a) Internal auditors, (b) Experts, (c) Service organisations. (12 marks)

TOPIC 5: Audit Risk — IR, CR & DR


Audit risk is the heart of modern auditing. Understanding this triangle will help you answer almost any
risk-based question.

5.1 What is Audit Risk?


Audit risk is the risk of issuing an INAPPROPRIATE audit opinion UNKNOWINGLY.
Two directions of error:
• Financial statements were FREE from material misstatement — but auditor says they are NOT
(false alarm)
• Financial statements DO HAVE material misstatement — but auditor says they're fine (missed
error — more dangerous!)

📐 THE AUDIT RISK FORMULA


Audit Risk (AR) = Inherent Risk (IR) × Control Risk (CR) × Detection
Risk (DR)
DR = AR ÷ (IR × CR)

5.2 Inherent Risk (IR) — 'Built-in Risk'


Inherent risk is the susceptibility of financial statements (or account balances) to material misstatement
— BEFORE considering any internal controls.
It can be mitigated but CANNOT be eliminated.

A) At the Account Balance Level:


• Estimates involved: e.g. useful life of a non-current asset
• Judgements involved: e.g. under IAS 38, development costs can be capitalised only if
technical feasibility exists
• Complex transactions: e.g. oil-well inventory count, livestock valuation

B) At the Financial Statement Level (as a whole):


• Inexperienced management — more prone to errors
• Integrity of management — dishonest management increases risk
• Nature of the entity — some industries are naturally riskier

📊 EXAMPLE
Example IR at account level: A construction company uses estimates for 'percentage of
completion' on long-term contracts. This judgement-based figure carries high inherent risk.
Example IR at FS level: A startup with an inexperienced CFO has higher inherent risk across
all financial statements.

5.3 Control Risk (CR)


Control risk is the risk that the entity's internal control system will FAIL to prevent, detect, or correct a
material misstatement.
Also cannot be fully eliminated — due to inherent limitations of internal controls (see below).

5.4 Internal Controls


Internal controls are systems established by the entity to ensure:
• All transactions are authorised
• Completeness and accuracy of data
• All transactions are accounted for
• Safeguard of assets
• Prevention and detection of fraud and error
• Promotion of operating efficiency
• Preparation of reliable financial information
• Regular comparison of recorded assets with physical assets

Types of Internal Controls:


• Preventive: Stop errors/fraud before they occur (e.g. requiring dual authorisation)
• Detective: Identify errors/fraud after they happen (e.g. bank reconciliation)
• Corrective: Fix identified errors (e.g. adjustment entries)

Inherent Limitations of Internal Controls:


• Cost of establishing a control may exceed its benefits
• Human errors — people make mistakes
• Management override — management can bypass controls
• Obsolete and inadequate controls — controls may become outdated
• Controls not established for non-routine transactions

5.5 Detection Risk (DR)


Detection risk is the risk that the auditor's substantive procedures will FAIL to detect a material
misstatement — due to the test nature of audit.
📐 KEY RELATIONSHIP
Higher sample size → Lower Detection Risk
Higher IR × CR → Lower DR required → More substantive testing needed
DR is the ONLY component directly controlled by the auditor.

Risk Type Definition Can be Who controls it?


eliminated?

Inherent Risk Built-in susceptibility to No Nobody (it's natural)


(IR) misstatement

Control Risk Failure of internal controls No Management


(CR) (partially)

Detection Risk Auditor procedures fail to find Yes (theoretically) Auditor


(DR) errors

⚠️ EXAM TIP
• DR is the only risk the AUDITOR can control — increase testing to reduce it.
• If IR and CR are HIGH, the auditor must REDUCE DR by increasing sample size.
• Control risk cannot be zero — always due to inherent limitations.
• The formula AR = IR × CR × DR is almost certainly tested every exam.

🎯 QUICK REVISION
• AR = IR × CR × DR
• IR = Built-in risk (estimates, judgements, complex transactions, weak management)
• CR = Internal controls fail (can't be eliminated — inherent limitations exist)
• DR = Auditor's procedures fail (auditor controls this — more testing = lower DR)
• 5 inherent limitations of IC: Cost-benefit, human errors, mgmt override, obsolete
controls, non-routine transactions
• 3 types of controls: Preventive | Detective | Corrective

📝 PAST PAPER STYLE QUESTIONS


SHORT:
23. Define audit risk and state its components. (4 marks)
24. What are the inherent limitations of a system of internal control? (5 marks)
25. Differentiate between preventive, detective, and corrective controls. (3 marks)
LONG:
26. Explain in detail the components of audit risk. How does each component affect the
auditor's approach? (12 marks)
27. Discuss the objectives and types of internal controls. What are their inherent
limitations? (10 marks)
TOPIC 6: Corporate Governance
Corporate governance ensures directors are held accountable and the company's resources are used
properly — for the benefit of shareholders.

6.1 What is Corporate Governance?


• Corporate governance is a system where accountability of directors is established and the
entity's risk management processes are evaluated
• Directors are accountable for the better utilisation of the entity's resources
• Applicable to Limited Liability Companies — where shareholders provide funds, and directors
manage them

💡 THE CORE PROBLEM IT SOLVES


Shareholders (fund providers) and Directors (fund managers) are SEPARATE bodies. Their
goals may NOT always align. Corporate Governance ensures GOAL CONGRUENCE —
both parties work toward the same objective.

6.2 Board of Directors


Executive Directors Non-Executive Directors (NEDs)

Involved in day-to-day financial/operational Supervisory role — oversee executive


decisions directors

Remuneration is approved by Non-Executive Paid only a meeting attendance fee


Directors

Full-time salaried Can claim charges for attending meetings


(airfare, hotel)

6.3 Requirements of Corporate Governance


• Supervisory Board
• Audit Committee
• Other non-executive committees (e.g. Board HR Committee, Board Risk Management
Committee, Board IT Committee)

6.4 Supervisory Board


The two-tier board: Executive Directors + Non-Executive Directors overseeing them. The Supervisory
Board consists of Non-Executive Directors who oversee Executive Directors. They represent
employees, investors, and other stakeholders.
Functions of the Supervisory Board:
• Approval of long-term plans, annual budget, major decisions (e.g. mergers & acquisitions)
• Evaluate and establish the system of internal control
• Proper disclosure to shareholders
• Monitor conflict of interest between executive directors
• Monitor corporate governance policies including risk management
• Selection of key executives
• Fix remuneration of directors
• Supervise audit committee

6.5 Audit Committee


A committee PRIMARILY consisting of Non-Executive Directors that reviews the entity's affairs
independently.
Structure: At least 3 members from Supervisory Board + remaining are external hires. Specialised
personnel.

Functions of the Audit Committee:


• Assist supervisory board
• Supervise internal audit
• Liaise with external auditors
• Evaluate corporate governance policies including risk management compliance
• Evaluate the system of internal control

📌 ISA 260 — Those Charged with Governance


Supervisory Board + Audit Committee = 'Those Charged with Governance'
ISA 260 requires auditors to COMMUNICATE with those charged with governance on:
• General approach and scope of audit
• Going concern problems
• Significant changes in accounting policies
• Effect on financial statements of significant risks (e.g. contingencies)
• Terms of engagement
• Disagreements with management
• Audit adjustments
• Weaknesses in the system of internal control

6.6 Business Risk Management


Business risks are threats that the company's overall objectives will not be achieved (e.g. cash flow
targets missed, liquidity shortages).
Steps to Evaluate/Manage Risk:
28. Identify the most important risks (internal and external)
29. Assess and determine the IMPACT and LIKELIHOOD of these risks
30. Management takes action to minimise these risks

📊 EXAMPLE
Risk Matrix Example:
HIGH Likelihood + LOW Impact → 'Out of fashion' product (manageable)
HIGH Likelihood + HIGH Impact → 'Loss of key employee', 'Inflation' (serious — action
needed)
LOW Likelihood + HIGH Impact → 'Earthquake', 'War' (catastrophic but rare — contingency
plan)

🎯 QUICK REVISION
• Corporate Governance = accountability of directors + risk management evaluation
• Executive Directors = operational | NEDs = supervisory
• Supervisory Board = NEDs overseeing EDs | Functions: plans, IC, disclosure,
remuneration
• Audit Committee = primarily NEDs | Functions: supervise IA, liaise with EA, evaluate
IC
• Those Charged with Governance (ISA 260) = Supervisory Board + Audit Committee
• ISA 260 requires communication on: scope, going concern, policies, risks,
engagement, disagreements, adjustments, IC weaknesses

📝 PAST PAPER STYLE QUESTIONS


SHORT:
31. What is corporate governance and why is it important? (3 marks)
32. What is the difference between executive and non-executive directors? (4 marks)
33. List the communications required under ISA 260. (5 marks)
LONG:
34. Describe the structure and functions of (a) Supervisory Board and (b) Audit
Committee. (12 marks)
35. Explain the concept of corporate governance and discuss the role of the audit
committee within it. (10 marks)

TOPIC 7: Internal Audit


Internal audit works INSIDE the organisation. Think of them as the company's own quality control team.

7.1 Fundamentals of Internal Audit


Key activities of the internal auditor:
• Review internal controls
• Review financial and non-financial data
• Review the 3Es in utilisation of entity's resources (Economy, Efficiency, Effectiveness)
• Review compliance with laws and regulations
• Review authorisation of expenditures
• Review entity's risk management policies and compliance
• Review compliance with management policies regarding operations
• Report weaknesses (along with risks and recommendations) to the audit committee

💡 THE 4Ms AND 3Es


Internal auditor monitors 4Ms: Men, Money, Machinery, Materials — with 3Es: Economy,
Efficiency, Effectiveness = Value for Money

7.2 Internal vs. External Auditor — Key Differences


Aspect Internal Auditor External Auditor

Appointed by Management/Board Shareholders

Reports to Audit Committee/Board Shareholders

Objective Improve operations, review IC, risk Express opinion on financial


management statements

Independence Less independent (employed by Fully independent


entity)

Scope Broad (financial + non-financial + Focused (financial statements)


operational)

Responsibility Cannot take sole responsibility for Sole responsibility for audit opinion
opinion

7.3 Limitations of Internal Audit


36. Independence — employed by the organisation, so may face pressure
37. Internal vs. External Auditor — different roles and authority
38. Relatively a new profession — compared to external audit
39. Understanding of internal audit — management/board may not fully appreciate its value

7.4 Outsourcing the Internal Audit Function


Advantages:
• Lower cost
• Broad expertise available
• No fear of losing staff
• Increased independence of internal auditor
• New marketplace techniques available (e.g. free audit softwares)

Disadvantages:
• Conflict of interest if outsourced to the SAME firm as external auditors
• Lack of independence / pressure on independence
• Lack of knowledge of organisation's culture
• Standard of services may fall if previous team is disbanded
• Reliance of shareholders may be impaired if internal audit is outsourced to the same firm as
external auditors

⚠️ EXAM TIP
• Outsourcing to SAME firm as external auditors = BIG RED FLAG — always mention
conflict of interest and impaired independence.
• The 4 limitations of internal audit are commonly tested as a list question.

7.5 Role of Internal Auditor in Corporate Governance


• Corporate Governance objective: proper board constitution, proper remuneration, proper
accountability, independent audit, proper internal control and risk management
• Internal auditor assists management to achieve these objectives by suggesting ways and
means and monitoring progress

7.6 Role of Internal Auditor in Risk Management


• Identifies major risks (with management)
• Monitors and evaluates management's risk management policies
• Reports non-compliance of risk management policies to higher management and audit
committee
• Suggests ways and means to handle the impact and likelihood of risks

7.7 Role of Internal Auditor: Fraud & Error


• Assists audit committee in identifying business risks of fraud and errors
• Provides recommendations to PREVENT fraud and errors
• Reviews management actions in prevention and detection of fraud and errors
• Evaluates those actions for adequacy

7.8 Internal Audit Procedures (Step-by-Step)


40. Identify key risky areas (high impact + high likelihood)
41. Establish the REQUIRED controls for the entity
42. Test EXISTING controls of the entity
43. Draw conclusions and provide recommendations to strengthen controls and manage risk
7.9 Operational Audit
Areas covered in operational audit:
• Sales / Marketing
• Purchase / Procurement
• Human Resources (HR)
• Production / Logistics
• Treasury

Purchase / Procurement Audit Procedures:


• Obtain procurement manual
• Verify compliance of management policies regarding procurement
• Evaluate the policies themselves for efficiency and effectiveness
• Review a sample of procurement transactions to ensure authorisation
• Conduct a walk-through test to understand the purchasing process
• Ensure competitive bidding has been obtained for major/substantial purchases
• Check that orders were placed with approved suppliers
• Ensure supplier balances were reconciled per entity's terms
• Ensure supplier prices are regularly updated
• Review Exception Report and actions taken

Sales / Marketing Audit Procedures:


• Obtain a copy of the Marketing manual
• Check compliance of marketing policies
• Evaluate marketing policies for effectiveness
• Evaluate that major decisions have been approved
• Verify only approved agents have been used
• Ensure customer complaints have been properly handled
• Ensure marketing team has been adequately trained
• Review advertising expenses for cost-benefit analysis
• Review Exception Report and actions taken

Generic XYZ Operational Audit Template:


• Obtain a copy of the Operation's manual
• Check compliance of management policies as regards that operation
• Evaluate the policies themselves for effectiveness
• Conduct a walk-through test to understand policy and procedure
• Evaluate that major decisions of the operation are approved
• Verify only approved supplier/customer/agents are being used
• Ensure complaints from third parties are handled properly
• Ensure operations staff is trained
• Review Exception Report and actions taken
📌 KEY TERMS TO KNOW
• Exception Report: A report of non-compliance with management policies, prepared
by the respective department — includes what policy was not followed and why.
• Walk-Through Test: The auditor takes one transaction from start to finish to
understand the complete process. E.g. for purchases: Order received → Approved →
Goods received → Delivery challan → Gate pass → Payment.

🎯 QUICK REVISION
• Internal auditor: Reviews IC, FS, 3Es, compliance, risk management, authorisations
• 4Ms (Men, Money, Machinery, Materials) + 3Es (Economy, Efficiency, Effectiveness)
= Value for Money
• Outsourcing IA: Pros = cost, expertise, independence | Cons = conflict of interest,
lack of culture knowledge
• IA in Governance: Helps achieve proper accountability, IC, risk management
• IA in Risk: Identifies risks, monitors policies, reports non-compliance
• IA Procedure: Identify risky areas → Required controls → Test existing controls →
Recommend
• Operational Audit areas: Sales, Procurement, HR, Production, Treasury
• Exception Report = non-compliance report | Walk-Through = trace one full transaction

📝 PAST PAPER STYLE QUESTIONS


SHORT:
44. What are the fundamentals of internal audit? (5 marks)
45. State the advantages and disadvantages of outsourcing the internal audit function. (6
marks)
46. What is a walk-through test? (2 marks)
47. What is an Exception Report? (2 marks)
LONG:
48. Compare and contrast the roles of internal and external auditors. (10 marks)
49. You are the internal auditor of a manufacturing company. Describe the procedures
you would follow for a procurement operational audit. (10 marks)
50. Discuss the role of the internal auditor in: (a) Corporate Governance (b) Risk
Management (c) Fraud and Error. (12 marks)

⚡ MASTER QUICK REVISION — ALL TOPICS

Topic Core Concept Key Points to Remember

IFAC Global accounting body 1977, New York, 180 members, 135 jurisdictions;
IAASB issues ISAs; 2/3 majority
Client Before accepting audit 3 types: Ethical (independence, staff, integrity,
Screening etiquette letter), Commercial (fees), Legal
(appointment, resolution, notice)

Fraud & Error Auditor's responsibility Not detective; sample basis; persuasive evidence;
extend procedures; legal advice before reporting;
letter of representation

Reliance on Using 3rd-party work Expert: assumptions, reasonableness; Internal IA:


Others independence, scope, test; Service Org: list,
qualifications, supervision. Sole responsibility
always with external auditor.

Audit Risk AR = IR × CR × DR IR = built-in; CR = control failure; DR = auditor's


procedures fail. DR is auditor-controlled. Inherent
limitations of IC are key.

Corporate Accountability of EDs vs NEDs; Supervisory Board (7+ functions);


Governance directors Audit Committee (5 functions); ISA 260 (8
communications); Business risk = identify, assess,
act

Internal Audit Company's own 4Ms + 3Es; IA vs EA differences; Outsourcing


watchdog pros/cons; Fraud role; IA Procedure (4 steps);
Operational audit (Purchase + Sales templates)

GOOD LUCK IN YOUR EXAM! 🎓


You've got this. Stay calm, read questions carefully, and apply concepts to the scenario.

You might also like