0% found this document useful (0 votes)
4 views15 pages

Data Analytics The Key To Risk Based Auditing

The document discusses the importance of data analytics in risk-based internal auditing, emphasizing its role in assessing and responding to risks within organizations. It outlines the differences between traditional and risk-based auditing, detailing the procedures and analytical techniques auditors can use to identify and mitigate risks, including fraud assessments and materiality considerations. The use of data analytics solutions is highlighted as a critical tool for enhancing audit efficiency and effectiveness.

Uploaded by

Tawanda Ngowe
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views15 pages

Data Analytics The Key To Risk Based Auditing

The document discusses the importance of data analytics in risk-based internal auditing, emphasizing its role in assessing and responding to risks within organizations. It outlines the differences between traditional and risk-based auditing, detailing the procedures and analytical techniques auditors can use to identify and mitigate risks, including fraud assessments and materiality considerations. The use of data analytics solutions is highlighted as a critical tool for enhancing audit efficiency and effectiveness.

Uploaded by

Tawanda Ngowe
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Data Analytics: The

Key to Risk-Based
Auditing
[Link]
[Link] Data Analytics: The Key to Risk-Based Auditing

Introduction
To ensure organisations reach their objectives, Internal Auditors, risk-based internal auditing
it is imperative that internal audit reviews allows internal audit to conclude that:
the controls in place to reduce the risks their
companies face. In order to distinguish this 1. Management has identified, assessed,
process from ‘traditional’ internal auditing, the and responded to risks above and
term ‘risk-based internal auditing’ was coined. below the risk appetite.
2. Responses to risks are effective, but
Whilst traditional internal auditing is limited to not excessive, in managing inherent
considering the controls over financial, fraud and risks within the risk appetite;
possibly IT risks as well, risk-based internal auditing 3. Action is being taken to correct situations where
begins by first assessing an organisation’s objectives residual risks are not in line with the risk appetite;
and providing an opinion as to whether internal 4. Risk management processes, including the
controls are reducing the risks threatening them to effectiveness of responses and the completion of
acceptable levels. Based on the opinions formed, it is actions, are being monitored by management to
then determined if those objectives will be achieved. ensure they continue to operate effectively; and
5. Risks, responses, and actions are being properly
‘Traditional’ versus risk- classified and reported.
based audits
In this eBook, we will look at how auditors
Today, risk-based internal auditing is the can assess, respond to, and analyse the risks
standard expected for internal auditing. they encounter during a risk-based audit.
According to the Chartered Institute of

2
[Link] Data Analytics: The Key to Risk-Based Auditing

Assessing Risk
Current standards require auditors to gain a thorough For example, all transactions for the period
understanding of the organisation’s industry and can be summarised by account and by
environment, including its internal controls. The journal source. A quick review of the results
risk assessment procedures required include can tell the auditor such things as:
inquiries of management and others, observations
and inspections to support the responses to the • What types of entries exist
inquiries, and analytical procedures. Data analytics • Whether there are a high number of manual journal
can be used to analyse information for comparison entries and what accounts are most often affected
with industry data that might be publicly available. • Volume of activity in loan accounts
• Whether excessive credits that are not from
In cases where a client has multiple roduct lines, it an accounts receivable posting source
might be necessary to obtain sales and cost details are included in accounts receivable
by product line for better comparisons or to explain • Whether excessive debits that are not
variations from public domain benchmarks. from an accounts receivable posting
source are included in revenues
Inquiries of management about the accounting • Whether the ledger balances and how many
system, initiation and recording of the various kinds of transactions are included in each account
transactions, and areas where estimates are required,
are necessary procedures. Since the trial balance is
the normal source for financial statement preparation,
the auditor should obtain a year-to-date general ledger
detail report and perform forensic-level analysis to
gain an understanding of transaction flows. With
the correct data analytics solution and an electronic
version of the report, these types of procedures are
powerful and provide substantial information in helping
to understand the client’s financial environment.

3
[Link] Data Analytics: The Key to Risk-Based Auditing

With this detailed analysis, auditors can identify financial statements. Whilst no specific formula
significant recorded activities that might represent is provided in the most recent auditing standards,
risks, ask more specific questions, and gain an amounts must be set while planning the audit.
understanding of the environment. Comparing this
type of summarisation with a similar summary from They must be based on the auditor’s quantitative and
the prior year will help the auditor know more about qualitative judgment, and take into consideration
changes during the year and be able to narrow the the users of the financial statements. Appropriate
scope of items to consider for the current year. reasoning must be documented in the work papers.

It’s been said that an audit both begins and Because data analytics solutions generally have no
ends with materiality—the threshold amount limit in how much data can be imported for review,
an auditor begins with in deciding what scope stratifications or data population profiles can help
to set in performing the risk assessment and identify individually significant items and groups of
further audit procedures. Tolerable misstatement items that are also significant. They can also provide
is the amount an account balance can be off documentation to support the basis of the auditor’s
without causing a material misstatement in the judgment when planning the audit strategy.

4
[Link] Data Analytics: The Key to Risk-Based Auditing

Fraud Assessments -
SAS 99 or ISA 240
Throughout the planning process, the • Disaggregated analysis of expenses/
risk assessment includes considering expenditures and payroll
risks that fraud may have occurred. • Identify and test journal entries made at the end
of reporting periods and other unusual entries
The auditing standard for fraud risk assessment • Identify accounting estimates for
requires auditors to ask what can go wrong review; analyse underlying details
and how could management intentionally • Perform cut-off procedures at period end
cause a material misstatement in each • Compare inventory quantities for current
significant area of the financial statements. period with prior periods by class or category of
inventory, location or other criteria, or comparison
Fraud risk factors outlined in the standards of quantities counted with perpetual records
are related to the fraud “triangle” of pressures: • Use computer-assisted audit techniques
incentives, opportunities, and rationalisations. In (CAATs) to further test the compilation
addition to the inquiries required, the auditor must of the physical inventory counts
perform specific analyses to help identify potential • Perform a computerised match of the
fraud or respond to all identified risk factors. vendor list with a list of employees to identify
matches of addresses or phone numbers
The procedures listed below are taken from the • Perform a computerised search of payroll
applicable audit standards and their appendices. records to identify duplicate addresses,
Data analysis software is a critical tool for employee identification or taxing
effectively performing these procedures. authority numbers or bank accounts
• Analyse sales discounts and returns
• Analyse unusual or unexpected relationships for unusual patterns or trends
identified in earlier analytical procedures • Review the propriety of large and unusual
• Perform disaggregated analysis of revenue expenses (requires data extraction)
(by m o n t h or quarter, by product line, etc.)
5
[Link] Data Analytics: The Key to Risk-Based Auditing

The Center for Audit Quality, affiliated with the American Institute of CPAs (AICPA),
released a Practice Aid on Journal Entry Testing. The guide lists the following
16 queries that can be performed using data analysis software:

Find journal entries that do not match Find manual entries

Find gaps in journal entry number sequences Sample journal entries (random or high-value)

Find high value journal entries Findspecific journal entries (by month, day or Journal
Entry number)
Find possible duplicate account entries Find all entries containing specific account(s)

Find rounded-value journal entries Find all entries within a range of accounts
Show journal entry information by employee Find post-dated entries
Find all entries made by a specific employee Find entries with unusual (non-standard) descriptions
Show values for the ‘journal entry type’ code Find entries posted on weekends

With transaction lists numbering anywhere from the hundreds to the tens-of-millions of records, and
sometimes held on servers across the globe–depending on the client–auditors need a reliable data
analytics solution to quickly identify, test for, and explain erroneous data entries.

6
[Link] Data Analytics: The Key to Risk-Based Auditing

Responding to Risk Assessments:


Audit Approach
Audit Risk, or the risk of material misstatement Some forms of sampling, such as monetary unit
(RMM), is often viewed as a formula: sampling, make use of materiality by requiring the
use of tolerable and expected errors as parameters
RMM = Inherent Risk (IR) x Control Risk (CR) while planning the sampling application.

AR = RMM x Detection Risk (DR) With large populations, data extraction


is the only efficient way to make sure all
The Standards require that auditors link their audit individually significant items are identified.
procedures—the nature, timing, and extent of tests
they perform—to the RMM. If IR and CR are low Example:
(controls must be tested to achieve a low risk), the
risk assessment procedures performed to make Big Kachina, Inc. is a rapidly expanding
that determination might be sufficient to lower the multi-location retailer of business equipment.
auditor’s risk. If they are not, or if any fraud risk Total assets are £12,000,000, including
factors are identified, the auditor must respond £9,914,148 in accounts receivable.
with a plan to perform additional procedures,
and they should be customised to the client. The accounts receivable aging report
provided by the client showed more than
Materiality is an important concept for £252,000 past due by 120 days or more. An
financial statement and other audits because electronic version of the detailed report
the cost of examining 100% of a population was obtained and further analysis helped
would be prohibitive for clients. document a decision to examine more current
account receivable balances separately
from those past due by 120 or more days.

7
[Link] Data Analytics: The Key to Risk-Based Auditing

In less than 20 minutes, the auditor was Further tests, based on the determination of
able to perform the following steps: materiality, would include extraction of a sample
for confirmations for the less risky accounts,
1. Gain a better understanding of the monitoring and later matching of subsequent collections
system for accounts receivable for those older items. Without the power and
2. Total the file and agree the balance efficiency of a data analytics solution, the auditor
to the client’s monitoring report might have selected accounts from the entire
and general ledger balance population and exceeded his or her budget dealing
3. Check (re-perform calculations) the with the inevitable problems that would occur
aging report by using the due date field if several of them were seriously past due.
4. Isolate past due balances and summarise
them and the more current balances by store, Data analytics is best suited to testing assertions of
then compare and calculate the percentage accuracy and cut-off. Whilst it would be impossible to
of past due accounts to total by store “find” something that is not in a database while testing
5. Decide on an effective strategy to respond to for completion, the auditor can check date statistics
the high inherent and control risk assessments to determine that every month is represented in the
population. A test for cut-off of transactions would
involve looking at subsequent payments to determine
that they were recorded in the correct period.

8
[Link] Data Analytics: The Key to Risk-Based Auditing

Audit programme steps should reflect the auditor’s the process for obtaining the data, importing it
risk assessment, noting how the tests (further into the data analytics solution, and the output
audit procedures) will be used to lower the risk of that will become part of the work papers.
material misstatement, and these must be defined
by the relevant assertion for the account balance. Some firms have adopted a policy of using IT
In the previous example, the valuation assertion specialists to acquire, import, and analyse the data
is affected by a high risk of overstatement for net during an audit; however, this practice handicaps
accounts receivable (or understatement of the field auditors who must see the results of the test
allowance for bad debts), because of the high and decide what to do next. With a comprehensive
percentage of past due accounts. Since the work data analytics solution, simply drilling down on a
that would be done to audit the allowance account questionable summarised amount can provide the
includes subsequent collections, evidence is also evidence needed to clear or isolate the exception.
obtained for those accounts regarding existence.
The audit evidence about existence that would With Data Analytics and SmartAnalyzer,
come from the confirmations could be reduced auditors can easily test for common indicators
in this case by segregating the population. such as negative amounts, duplicates,
rounded amounts and unusual descriptions
Since less experienced staff will normally perform on accounts receivable, general ledger,
the tests of details (further audit procedures) or accounts payable, inventory and fixed assets
other substantive tests in response to RMM, it data. Since the tests are pre-developed,
is important that the audit programme clearly training time for staff can be minimised.
define not only the tests to be performed, but also

9
[Link] Data Analytics: The Key to Risk-Based Auditing

Analytics Procedures
Analytical procedures include everything from and corroborating the reasons for variances.
simple financial statement balance and ratio
comparisons to complex correlations, time Scanning the general ledger or subsidiary accounts
series, and trend analyses; however, they also looking for unusual items is highly effective with a
include visually scanning records to identify large data analytics solution, which provides the ability
and unusual items. In each case, the objective to summarise the details and then drill down to
is to set an expectation, then perform the test further investigate anything that raises concerns
or other procedure, and compare the results to or questions about errors that might exist.
the initial expectation. Audit evidence consists
of the documentation of that process, together On the next page are two examples that illustrate
with the auditor’s conclusion about the account the ability of data analytics to achieve audit
balance or set of transactions after explaining effectiveness and provide added value for clients:

10
[Link] Data Analytics: The Key to Risk-Based Auditing

Analytical Procedure If detection risk represents the chance that the


auditor will miss a material error, then using analytical
• Summarise by payee entire year of cash procedures to bring more details to the auditor’s
disbursements and compare with a attention will help lower tahat risk. Performed during
similar summary from prior year. the risk assessment, analytical procedures result
• Compare inventory unit costs between years. in a better understanding of the client—and the
work counts as audit evidence. When performed as
Impact on Audit further audit procedures in response to identified
risks, the same data can be disaggregated so that
• Note excessive payments and payments smaller amounts in groupings will allow the auditor
to new payees. Auditing by exception to more easily see relationships and isolate the
is effective for fraud detection. cause for anomalies that need to be explained.
• Lowers the cost to perform inventory
testing in second and third years of an audit. In certain cases, data analytics can also be
Increases can be compared with expectations used to help clients and auditors recover from
based on auditor’s knowledge of economic challenges that occur when sampling is used. If
trends and other factors for prices. the error rate in a sample used for substantive
testing is higher than expected, the auditor
Value for Client can perform an analysis of the cause for
misstatements identified, and use this information
• Efficiencies for cheque processing when deciding on how to project the errors.
can be recommended in cases where
excessive payments, whilst accurate, For example, if an unusually high number of errors in
are wasteful for the client. cash disbursements data are analysed by enterer,
• By analysing all inventory items, special the auditor could summarise the sample and the
reports can be provided to clients that will population by enterer to better determine the impact
help them see anomalies or errors in their the errors found have had on cash disbursements.
inventory data that might not be material, but
would still provide valuable action items.

11
[Link] Data Analytics: The Key to Risk-Based Auditing

Internal Control Testing


Internal controls over the major transaction classes Utilising the correct data analytics solution is key in
include manual and automated control activities facilitating tests of controls: it calculates sample sizes
that assure Management’s directives are carried based on the desired confidence level and precision,
out. In most companies today, IT significantly and computes achieved confidence to help the
affects control activities, especially in the areas of auditor document his or her conclusions.
authorisation and segregation of duties (through
passwords and other access controls), accuracy, Sampling modules are also available to extract
and completeness (through IT general controls the sample on a random, systematic or stratified
over program change control and processing random basis. Stratified random sampling is useful
controls in each significant application). if the auditor is designing a “dual-purpose test”
because the sample will randomly select items
Testing controls to determine reliability of details from each strata per the auditor’s judgment as
will be needed if the information system data is to to how many items to select from each group.
be used for these kinds of analytical procedures.

Strong workflow management


for accounting, advice and o

12
[Link] Data Analytics: The Key to Risk-Based Auditing

Conclusions
Auditing is an iterative process that requires Accounting firms that are most successful
the auditor’s judgment to constantly evaluate in implementing data analytics incorporate
the evidence and determine when procedures the procedures into their audit process. They
are sufficient to minimise audit risk. Data provide adequate training and support to staff,
analytics solutions provide better coverage and guard against over-relying on technical
and reduction of risk than can be achieved specialists. They overcome the challenge of
manually or with spreadsheets alone. It is an insufficient staff levels by arming their field
auditor’s tool for gaining an understanding of auditors with data analysis software, which
the client’s systems and reporting environment; frees their IT auditors to work on others areas.
identifying anomalies, errors and potential
fraud; and extracting all items of individual Properly implemented and integrated into the
significance within a transaction or master file. audit, data analytics can solve the dilemma
of the expectations gap concerning the
auditor’s responsibility to detect material
misstatements in the financial statements.

13
[Link] Data Analytics: The Key to Risk-Based Auditing

The Data Analysis Powerhouse


Spreadsheets are simply not equipped with many of the core capabilities that auditors require
to audit effectively. If you’re looking for a secure, extensive, and efficient way to audit, then
Caseware IDEA Data Analytics Software is the professional data analysis solution for you. With
more than 400,000 users in 90 countries, Caseware technologies are built upon the foundation
of best practices in assessing risk and controls, enabling audit and finance professionals to use
real data insights to create remarkable ROI and business improvement opportunities.

About Caseware
For more than three decades, auditors and accountants around the world have relied on Caseware’s
flexible tools and platforms to help them work smarter and more efficiently, and in turn help their
clients achieve success. Connect with us today to see how we can help your organisation.

14
Caseware UK Ltd

County Gate 2
Staceys Street
Maidstone
Kent
ME14 1ST
United Kingdom

T +44 (0) 1622 355 200


E info@[Link]

[Link]

You might also like