1.
Audit Risk
Some risk will always exist because of the inherent limitations of internal
control – and control risk is a function of the effectiveness of the design
and operation of internal control in achieving the entity’s objectives
relevant to the preparation of the financials. The inherent limitations in
internal control must be considered:
• Management’s requirement that the cost of the internal control doesn’t
exceed the expected benefits to be derived (cost / benefit)
. • Most internal controls are directed at routine transactions rather than
non-routine transactions.
• Potential for human error due to carelessness, distraction, mistakes of
judgement and misunderstanding instructions.
• Possibility of circumvention of internal controls through collusion of a
member of management or employees with parties either inside or
outside the company.
• Possibility that person responsible for the internal control will abuse
that responsibility (e.g. management overriding a control).
• Possibility that procedures may become inadequate due to changes in
conditions and compliance with control procedures may deteriorate.
7.3.1 Reasons why it is important for the auditor to consider materiality:
• To plan audit procedures so that possible errors can be detected
where those errors could be material (individually or in total) for the
financial information under audit,
• To determine the extent of the audit procedures – limited or no further
audit procedures will be carried out if the item is not considered to be
material after evaluation,
• To assess the audit difference at the end of the audit – auditor should
request that management adjust the financial information if material
errors have occurred in order to ensure fair presentation in the
financials,
• Contribute to audit efficiency and cost effectiveness,
• To help with the formulation of an opinion regarding the
reasonableness of the financial statements. Purpose of making a
preliminary assessment of materiality during the planning of an audit to:
• Enable auditor to plan audit evidence in such a way that he will
examine sufficient audit evidence to detect possible errors which could
(individually or in total) be material for the financial information under
audit.
• Enable the auditor to choose audit procedures which could collectively
reduce the audit risk to an acceptably low level
• Help the auditor in the case of accounting balances and transactions
classes to decide which items should be investigated and if sampling
and analytical procedures should be applied.
Nature of materiality Materiality is very subjective – largely decided by
professional judgment and so different auditors will have different
decisions when setting up a materiality level (level of acceptable
misstatement) at planning stage or deciding if a particular matter is
material to fair presentation at the evaluating stage.
Materiality is relative, not absolute – what is material will vary from user
to user and from client to client and what might be material to small
company won’t be material to large company. Need to establish bases
against which materially can be measured so some auditing firms set a
planning materiality level which can use percentages of account
headings as a starting point or rule of thumb.
Most important point is that most misstatements affect the income
statement and the balance sheet but can be material to one and not the
other. So better to use the net income before tax as a basis to measure
the materiality of the misstatement as it is “truer” figure and so materiality
will be more relevant to the company.
Note: ISA 320 doesn’t set any percentages to be used for setting
materiality levels so auditor needs to use his professional judgment.
Materiality is both quantitative and qualitative:
Quantitatively material amount is one that exceeds the amount which
the auditor has determined is material (so that is the amount of
misstatement what would influence the decisions of a user).
Qualitatively material amount is one which is regarded as material when
judged against a factor other than an amount – so if an important
disclosure is omitted from the financials and the omission would
influence a user. Both the quantitative and qualitative aspect of
materiality should be considered by the auditor as something might be
material in respect of one and not the other.
Planning materiality and final materiality Auditor should consider
materiality at: Planning stage when determining nature, timing and
extent of testing (planning materiality) At final stage in audit process
when evaluating the effects of misstatement (final materiality) (so used
first as guideline in planning the audit and then as a guideline in
evaluating unresolved matters at the end of the audit).
7.3.4 Planning materiality Dealt with differently by different audit firms –
can either use a Rand amount based on guideline percentages or can
work with set formulas, or can just use concept to focus audit in a
general way to get an idea of what is important.
7.3.5 Using planning materiality in a general way Basically the auditor
will identify account headings or classes of transactions that appear
important in relation to the other accounts. One’s that have the largest
amounts will use majority of audit resources (time and expertise) to
assess the risk of misstatement and then carrying out the audit
procedures on these account headings. This is basic audit strategy and
audit plan in general way.
7.3.6 Setting planning materiality
The auditor must quantify the amount of misstatement which can be in
the financial statements without it affecting fair presentation. (What
amount of misstatement is acceptable?).
Once the acceptable level is known, the auditor will be able to consider
the amount of misstatement that is acceptable within an account
heading or class of transaction. The planning materiality will influence
the fair presentation of the financials which will have a direct effect on
the extent of the testing and the nature and timing of audit testing. Also
remember that what might not be material against a large account like
stock or property, plant and equipment may be high against net profit
before tax.
An inverse relationship exists between materiality and audit risk. So
lower the materiality level the higher the audit risk, and more amount of
testing. Higher materiality level the less audit risk but less amount of
testing that has to be done.
7.3.8 Factors to be considered when planning materiality:
Importance of specific information to users – if there is a special
importance for one specific account that will give rise to a stricter
planning materiality level e.g. bank has provided loan to client provided
current ratio is maintained. This would then mean that the bank would be
specifically relying on the fair presentation of the current assets and
current liabilities and auditor would plan the audit to ensure that they are
fairly presented
Legal requirements – any specific legal requirement would be carefully
and thoroughly audited to ensure that misstatement (quantitative or
qualitative) is kept at an acceptable level e.g. figure that must be
specifically disclosed in terms of the JSE Securities Exchange
regulations
Preliminary Judgments about materiality based on draft or preliminary
figures – auditor will have to consider if planning materiality needs to be
adjusted in the client’s final figures differ from the draft.
7.3.9 Final materiality.
Planning materiality is done before audit and the risk of misstatement is
assessed and then the auditor forms the audit plan (nature, timing and
extent of testing that will be done). Auditor then carries out the selected
audit procedures which are normally samples of different accounts
(populations).
Errors will be found in the samples and as audit conclusions are drawn
from the populations where the sample came from the auditor, must
analyze and project the error in the sample over the population that has
been sampled either by:
• Using statistical basis – if has used statistical basis for selecting the
sample then must use the appropriate statistical method for projecting
the error in the sample over the population.
• Proportional method – to obtain an idea of the extent that the
population is misstated: Error value in sample x total value of population
Total value of sample
Whichever method of projection is used – if the projected misstatement
for the population is unacceptable then the auditor must decide if further
tests should be carried out by the audit team or if the client should be
asked to check the population in detail for further errors.
The auditor will then discuss all misstatements with management in an
attempt to have them rectified. When management doesn’t correct the
misstatements then auditor left with unresolved audit differences and this
is when using final materiality.
Management might refuse to correct misstatements because they may:
• Disagree that there is a misstatement – client thinks that their
estimation of stock obsolescence is fair but auditor thinks that it is
too low.
• Not regard the misstatement as material – i.e. it would not
influence a user.
• Have ulterior motives – e.g. directors want to achieve particular
ratios which are based on figures in the financial statements and if
the auditor’s adjustments are made then the ratios will not be
achieved.
• Regard it as “too much hassle” to make the changes – e.g.
adjustment would mean changing the income statement, balance
sheet, consolidation etc.
• Be unconcerned about receiving a qualified audit opinion - auditor
must decide if the unresolved audit differences are immaterial (so
will not influence the decision of the user) or if they are material (so
failure to correct them will result in financial statements which
contain more misstatement then is acceptable i.e. some of the
financials will not be fairly presented and the auditor will have to
give a qualified opinion.) Decision is not just deciding that final
materiality should be equal to planning materiality and anything
over that would be material – still have to consider various factors
at the evaluation stage.
7.3.12 Factors to be considered in evaluating unresolved audit
differences:
Factual misstatement is a misstatement that the auditor and client can
clearly identify and substantiate with supporting evidence (e.g. sales
invoice in the wrong period). Auditor can be more forceful in requesting
that the error is correct and if management refuses then the auditor is on
strong grounds when he decides to qualify the audit opinion.
Judgmental misstatement is misstatement that the auditor is unable to
specifically quantify and substantiate because there is a level of
subjectivity or uncertainty associated with the error (e.g. provision for
doubtful debts). Auditor has to be less forceful and more open to
discussion and negotiation when insisting that the correction is done and
qualifying the report because the error is of a subjective nature.
So the main difference is the way in which the attitude or stance of the
auditor differs when dealing with these two errors
• Misstatements should not be considered in isolation – must be
aggregated and trends or patterns of misstatement should be
carefully evaluated, e.g. if general trend of understating provisions
then are the directors trying to manipulate the financials?
• Statutory or other contractual obligations – auditor will not tolerate
quantitative or qualitative errors in accounts that must be
specifically disclosed e.g. directors emoluments
• Nature of the misstatement - error in principle is more important
than misallocation of an expense – i.e. auditor will be strict
regarding incorrectly applied financial reporting standards
• Misstatement due to dishonesty of director is regarded as serious,
not just ignored as it may not be quantitatively material in
subjective misstatements auditor can be a bit less strict because
these are essentially estimates e.g. allowance for obsolete stock
• Impact of the misstatement – auditor must assess the impact of
the misstatement with common figures or ratios, e.g. earnings per
share as that is a figure commonly used so auditor must ensure it
is presented as fairly as possible
• Absolute and relative size of the misstatement – auditor will
consider the size of the misstatement in its absolute form – e.g.
known error of R1 million is unacceptable just by virtue of its size.
Misstatement must also be considered relative to other accounts
(i.e. error may be material in debtors but not relative in current
assets).
• In making decision as how to decide if unresolved audit difference
is material auditor may be influenced by the difficulty or
inconvenience of rectifying the misstatement, however this is
professionally unacceptable (e.g. misstatement in depreciation
means correcting IS, BS, cash flow and notes so client will not be
happy).
7.5.2 At assertion level auditor should:
Consider the nature, timing and extent of testing necessary to reduce
the risk of material misstatement due to fraud being present to an
acceptably low level.
Decide on what tests to do (nature), when to do them (timing) and how
to do (extent) - tests and procedures which the auditor has available in
compiling the audit plan to address the risk of fraud are not different to
those which are used to respond to the risk of unintentional material
misstatement, but when addressing appropriate response to fraud
auditor needs to remember people doing the fraud will try to hide it
therefore making it more difficult for the auditor to find, the most reliable
and relevant evidence must be sought – severe consequences arising
out of fraud and auditor needs to be on firm ground before deciding if
there is or isn’t fraud.
Nature of testing is likely to become more inclusive (e.g. observation
supported by inspection and analytical review that provides more
corroborative evidence coupled with extensive testing.) Auditor may then
decide on substantive testing due to management override, auditor-
generated and changing the timing of tests – introducing surprise visits
e.g. arriving unannounced to count cash, stock or conduct a physical
verification of employees
7.7 Examples of fraudulent financial reporting
7.7.1 Incentives / pressures factors: Financial stability or profitability is
threatened by economic or industry of entity’s operating conditions:
• High degree of competition accompanied by declining margins
• High vulnerability to rapid changes (changes in technology,
product obsoleteness or interest rates)
• Operating losses threatening going concern
• New accounting, statutory or regulatory requirements (e.g.
deliberate omission or contravention of environmental
transgressions
• Excessive pressure exists for management to meet the
requirements or expectations of 3 rd parties due to:
• Profitability or trend level expectations of investment analysts,
institutional investors, significant creditors or other external parties
• Need to obtain additional debt or equity financing to stay
competitive (e.g. manipulating financial statements used to support
a loan application)
• Difficulty in meeting debt repayment or other debt requirements
(e.g. manipulating the financials to maintain prescribed financial
ratios specified in a loan agreement)
• Perceived or real adverse effects of reporting poor financial results
on significant pending transactions such as a merger or the
awarding of a contract (e.g. construction company reporting on
financial losses having recently tendered for a large contract to
construct an office block)
• Information which indicates that the personal financial situation of
management is threatened by the entity’s financial performance
arising from the following:
• Significant personal financial interest in the entity (e.g.
management holds significant number of shares)
• Significant portions of their compensation (e.g. bonuses or stock
options are contingent on receiving aggressive targets for stock
price)
• Personal guarantees of debts of the entity (e.g. by directors)
• Excessive pressure on management to meet financial targets
established by those charged with governance (including sales or
profitability incentive goals)
7.7.2 Opportunity factors Nature of the industry or the entity’s
operations
: Significant related-party transactions particularly where the related
party is not audited by the same firm
Strong financial presence or ability to dominate a certain industry
sector that allows the entity to dictate terms or conditions to suppliers
or customers that may result in non- arm’s length transactions
assets, liabilities, revenues or expenses based on significant
estimates that involve subjective judgments or uncertainties that are
difficult to corroborate which can be used to manipulate results
Significant, unusual or highly complex transactions which can be
used to manipulate results
Use of business structures or business methods for which there
appears to be no clear business justification (e.g. importing goods
indirectly through a neighboring country)
Opportunities (caused by lack of internal controls)
• Inadequate segregation of duties (e.g. store man can access
and change stock records)
• Lack of appropriate management supervision (e.g. no-one
controls goods taken in or from stores)
• Lack of procedures to screen applicants for positions where
employees have access to assets that are susceptible to
misappropriation
• Inadequate record keeping or no reconciliation of assets
(comparison of theoretical to actual)
• Lack of appropriate system of authorisation and approval of
transactions (e.g. acquisition of and payment for purchases)
• Poor physical safeguards over cash or inventory
• Lack of timely and appropriate documentation for transactions
(e.g. customer takes goods but paperwork only completed later)
• Lack of mandatory vacations for employees performing key
control functions
• Inadequate authorisation and review of senior management
expenses (e.g. travel claims)
• Inadequate management understanding of IT so IT employees
have access to all levels of data (e.g. can change debtor’s
balances in the master file)
7.8.2 Opportunities (caused by nature of entity’s assets)
• Large amounts of cash on hand
• Inventory characteristics – e.g. small size with high value and
demand (e.g. jewellery & iPods)
• Easily convertible assets (e.g. bearer bonds or diamonds)
• Fixed assets characteristics such as small size, marketability or
lacking in ownership identification (e.g. hand-held power tools)
8.1 Introduction to internal control
One of the main requirements in planning an audit is to study and
evaluate the existing internal controls so as to define the tests to be
applied to the entity being audited. From a business perspective, Control
is any action taken by management, the board and other parties to
manage risk and to increase the likelihood that an organization’s
objectives and goals will be achieved. Therefore one of the fundamental
concepts of internal control is to address the risk of something
undesirable, unintended or illegal from happening. Also rooted in the
concept of internal control is that it is the responsibility of everyone in the
business, those in charge of governance (e.g. board of directors),
management at all levels as well as ordinary employees.
According to the Committee of Sponsoring Organizations (COSO)
Internal Control is a process, affected by an entity’s board of directors,
management and other personnel, designed to provide reasonable
assurance regarding the achievement of objectives in the following
categories:
Compliance with applicable laws and regulations
Effectiveness and Efficiency of operations
Reliability of financial reporting
Internal control could also be referred to as the ‘built in’ cross-checks in
the organization that is supplemented with proper supervision. It is not
limited to financial matters and it involves setting objectives and
identifying the potential risks associated with achieving those objectives.
It also includes putting suitable records, documents, policies and
procedures in place to address the identified risks. It’s policies and
procedures work best in combination as there is no single control that
totally addresses each identified risk. Internal control forms the
backbone of any organization hence weaknesses and total absence of
internal control activities could result in the eventual collapse of an
organization. It consist of the plan of an organization and all of the
methods and measures adopted within the organization to safeguard its
assets, check the accuracy and reliability of its data (e.g. accounting
data and operational data), promote operational efficiency, and
encourage adherence to the prescribed managerial policies
8.2 Components of internal control Internal control consists of five main
components. These five components are integrated with management
processes and are derived from the way management runs the
organization. The five components are:
• The Control Environment
• Risk Assessment
• Control Activities
• Information System
• Monitoring
8.2.1 The Control Environment
• The control environment serves as the foundation upon which all
other internal control components are built. It provides the
atmosphere in which people conduct their activities and perform
their organizational control responsibilities. It also includes the
governance and management functions and the awareness,
actions and attitudes of those charged with the management
concerning an organization or entity’s internal control and its
importance.
8.2.2 Risk Assessment
• This component deals with how an organization assesses the risks
that face the business and how they should be addressed. It
involves the identification and analysis of risk. However, it should
be noted that the objectives of an organization is also a factor in
determining the kind of risks the organization is exposed to. Hence
if the objectives of an organization are not defined, the risks of not
achieving the objectives cannot be well identified, assessed and
responded to
8.2.3 Control Activities
These are the policies and procedures that help an organization
ensure that management directives are carried out. They help ensure
that necessary actions are taken in order to address the risks that
could affect the achievement of organizational objectives.
There are numerous control activities with different objectives and
which are applied at different organization levels and functions. They
can also be categorized as follows:
a) Type
Approval (authorization) – employees perform certain tasks
within certain parameters.
Segregation of duties – the most important objective of internal
control is the safe guarding of the company’s assets. The principle
is that the various actions or procedures that are carried out in
respect of a transaction should be divided amongst the
employees. Segregation of duties also facilitates the checking of
one employees work by another employee. The biggest enemy of
segregation of duties is collusion.
Isolation of responsibility – for any internal control system to
work effectively, the people involved in the system must be fully
aware of their responsibilities and must be accountable for their
performance.
Access/custody (security) – control activities will include
actions, policies and procedures which protect the company’s
assets. Access/custody controls are designed to: prevent damage
to the physical assets, prevent deterioration of certain non
physical book assets, and prevent unauthorised use, theft or loss
of physical assets.
Comparison and reconciliation – a reconciliation is a comparison
of two different sets of recorded information or of recorded
information and a physical asset.
Performance reviews – when carrying out a review, the
reviewer is looking for consistency and reasonableness in the
data being reviewed. Unexpected results or unusual conditions
will then be followed up.
b) Preventive, detective or corrective. Preventive controls are
controls which are put in place to prevent or minimize errors or
illegal events from occurring
. Detective controls are like a second line of defence and are
designed and implemented to identify the errors, thefts,
omissions, which got through the first line of defence.
Corrective controls are implemented to resolve errors and
problems which have been identified by detective controls.
c) General and application controls
the classification of controls into general and application controls
emerged originally from computerized environment. It is not a
term that is generally used in manual accounting system.
8.3 Advantages of internal control Internal control being one of the major
determinants of an organization’s success requires the attention of every
individual in an organization. A good internal control system will provide
organizations with a high degree of confidence that their operations are
efficiently managed. There are many benefits to be gained from
effectively designed and implemented internal control. The following are
some of the benefits:
Effective Operation: Internal control ensures effective operation by
ensuring that organization’s resources are utilized only for their intended
purposes thereby minimizing the risk of resource misuse. It also ensures
that data and records are readily accessed for the preparation of timely
reports.
Clear view of risk: It identifies the nature and impact of inherent risk and
also identifies if all data; records, information databases and other
material are complete and accurate, and also protected from loss or risk.
Compliance: It ensures the compliance of organizations, their
employers and employee with legislations and regulations.
Identifies and discourages irregularities: Internal control helps to
promptly identify and control irregularities and misappropriation.
Safeguard employees, assets and resources: Internal control ensures
that assets are not used for unauthorized purposes and that employees
are not being accused wrongly for any irregularities and
misappropriations. It also helps an organization achieve its goals of
profitability, and also enable organizations to save cost efficiently.
8.4 Disadvantages and limitations of internal control Internal control also
has the potential for disadvantages.
The internal control policies and procedures put in place in an
organization do not provide absolute assurance that the risks that
threatens the objectives of the business will be adequately responded to,
because some risks may not be identified in the first place or throughout
the operations of the business. Also, if internal controls are badly
planned or too rigidly designed to allow for adaptation, frustration may
set in and organizations may find it difficult to sustain. Some of the main
limitations and disadvantages of internal control are:
Cost/benefits: One of the main goals of any business is to make profit.
Management’s usual requirement that the cost of internal control does
not exceed the expected benefits to be derived is always a limitation.
Example: To safeguard the inventory of bags, a bag manufacturing
company could store the bags in a vault, have armed security guards,
and demand security clearance from everyone entering the property.
The bags will definitely be safeguarded but at an unnecessary cost.
However, this type of control system will be necessary for an
organization dealing in the buying and selling of gold, diamond etc.
Routine transactions: Controls are usually designed for routine
transactions rather than non-routine transactions. Hence, unusual or
non-routine transactions may bypass control mechanisms. Example:
Internal control system to record sales in an organization. This system
will have a customer order receipt, a picking slip and a delivery note, and
this three will result in an invoice. However, when an employee of the
organization sells an old item that has been categorized as a non-trading
item, it is unlikely that there will be a generated invoice. This means that
there is a risk that the sale will not be raised because this is a non-
routine transaction.
Human error: The internal control system is operated by people, so there
is potential for human error due to carelessness, distractions, improper
judgment and lack of knowledge or misunderstanding of instructions.
Example: A newly employed sales official calculates discounts on a sale
after VAT has been charged. This is because he/she is careless or does
not understand what he is supposed to do.
Employees’ abuse of authority: There is a possibility that an employee
responsible for exercising internal control abuse a delegation or
responsibility (that is, privilege given to the employee to make internal
control changes) to override the internal control system. Example: A bag
retailer organization may have a policy which states that a customer with
an overdue account may not make a purchase. A shop manager could
override this internal control policy without authority because the
customer is a family member or a friend.
Inadequate procedures: Overtime, internal control may become
inadequate or ineffective due to changes in conditions, procedures or
practices and this may lead to deterioration in compliance with
procedures. Example: An organization may experience an increase in
sales to an extent that the only way the sales man can keep up with
demand is by ignoring certain controls. Thus, controls have remained
static but opportunities and risk have changed, so procedures and
practices should be re-evaluated.