0% found this document useful (0 votes)
2 views82 pages

Fam Complete Notes

The Audit Manual of the Department of the Auditor-General of Pakistan outlines modern auditing standards and procedures for conducting audits in government entities, focusing on regularity and performance audits. It details the accounting responsibility structure of the Government of Pakistan and emphasizes the importance of accountability, integrity, and independence in auditing practices. The manual also establishes the role of the Auditor General in ensuring public accountability and provides guidelines for auditors to maintain ethical standards and manage conflicts of interest.

Uploaded by

studying0072
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views82 pages

Fam Complete Notes

The Audit Manual of the Department of the Auditor-General of Pakistan outlines modern auditing standards and procedures for conducting audits in government entities, focusing on regularity and performance audits. It details the accounting responsibility structure of the Government of Pakistan and emphasizes the importance of accountability, integrity, and independence in auditing practices. The manual also establishes the role of the Auditor General in ensuring public accountability and provides guidelines for auditors to maintain ethical standards and manage conflicts of interest.

Uploaded by

studying0072
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

1

1. ORGANISATION AND PURPOSE OF THE MANUAL


Purpose of the Audit Manual- 2016+2021
The purpose of this Audit Manual is to provide Department of the Auditor-General of Pakistan auditors with a
set of modern auditing standards, concepts, techniques, and quality assurance arrangements that are
consistent with international standards, for auditing entities in the Government of Pakistan. The Manual
covers the entire audit cycle from planning to follow up.

This Audit Manual lays out what is expected of the auditors of the DAGP. It provides the standards by
which the audits are to be conducted. It provides guidance with regard to the methods and approaches to
audit that can be applied by the auditors in carrying out their duties.

Types of audits dealt with


This Manual focuses on regularity audit, as defined by INTOSAI Auditing Standards, which have been
adopted by the DAGP.

Regulatory audit embraces: - 2021+2013


a) Attestation of financial accountability of accountable entities, involving examination of financial records and
expression of opinions on financial statements;
b) Attestation of financial accountability of the government administration as a whole;
c) Audit of financial systems and transactions, including an evaluation of compliance with applicable statutes and
regulations;
d) Audit of internal controls and internal audit functions;
e) Audit of the probity and propriety of administrative decisions taken within the audited entity; and,
f) Reporting of any other matters arising from or relating to the audit that DAGP considers should be disclosed.

Performance audit
Performance audit is concerned with the audit of economy, efficiency and effectiveness.
Performance audit embraces:
a) Audit of the economy of administrative activities in accordance with sound administrative principle
and practices, and management policies;
b) Audit of the efficiency of utilisation of human, financial and other resources, including examination of
information systems, performance measures and monitoring arrangements, and procedures followed by
audited entities for remedying identified deficiencies; and
c) Audit of the effectiveness of performance in relation to the achievement of the objectives of the
audited entity, and audit of the actual impact of activities compared with the intended impact.

Accounting Responsibility Structure of the Government of


Pakistan- 2021+2014
The following is a brief summary of the accounting structure of the Government of Pakistan.
2

a) Federal government. The Controller General of Accounts (CGA) has primary responsibility for the
completeness and accuracy of the Federation’s financial statements. Reporting to the CGA, the Accountant
General Pakistan Revenues (AGPR) is responsible for the centralised accounting and reporting of federal
transactions. Additionally the AGPR is responsible for the consolidation of summarised financial information
prepared by federal self-accounting entities.

b) The AGPR receives accounts and reports from the sub-offices of the AGPR, district accounts officers,
principal accounting officers of self accounting entities, federal treasuries and the State Bank of
Pakistan/National Bank of Pakistan. The AGPR, in turn, provides annual accounts to the CGA.

c) There are AGPR sub-offices in each of the provinces that act as the district accounts officers in respect of
federal government transactions.

d) Provincial governments. The CGA also has primary responsibility for the completeness and accuracy of the
financial statements of the provincial governments.

e) Reporting to the CGA, the accountant general of each province is responsible for the centralised accounting
and reporting functions within his/her respective province.

f) District governments. Each province is divided into districts. The district coordination officer of each district
is the principal accounting officer of that district. The district coordination officer is supported by executive
district officers who, in turn, supervise offices headed by drawing and disbursing officers.

g) Principal Accounting Officers (PAOs). Each ministry and department has a PAO. For the self accounting
entities, the PAOs have been delegated authority to maintain their own accounts. They provide monthly
accounting data to the AGPR and to the accountant generals.

h) District Accounts Officers (DAOs). The DAOs are responsible for the accounting functions of the districts.
They have authority to pre-audit bills, issue payments, and record government transactions at the district level.
They receive reports from the drawing and disbursing officers and bank scrolls from the State Bank of
Pakistan/National Bank of Pakistan. They report district and provincial transactions to the Accountant General
responsible for the province in which their districts are located. They also report federal transactions to the
AGPR.

i) Departmental treasuries. Departmental treasuries are established to record specific accounting transactions
such as income and sales taxes and customs duties.
j) Drawing and Disbursing Officers (DDOs). The DDOs are responsible for the accounting, cash and personnel
functions of specific entities. They submit bills for pre-audit to the district accounts officers, and report to the
district coordination officer of each district. They also report to the principal accounting officer of his/her
entity.

DAGP’s mandate includes the audit of the entire process described above.
3

Role of the Auditor General

Parliamentary Control and Public Accountability 2016+2017


Accountability of elected officials and the public servants that implement their policies is a cornerstone of
democratic government. In Pakistan, the government is formed of elected representatives of the people, and is
required by the Constitution to seek a fresh mandate every five years.

To ensure the administrative machinery of the government performs its functions in accordance with the
aspirations of the people, the National Assembly (lower house of the Parliament) and the four Provincial
Assemblies constitute Standing Committees on Public Accounts (PACs). The PACs are mandated to oversee
the implementation of government policies and programmes.

The Government departments and agencies are held accountable for any major departure from the approved
budget and for significant violations of rules and regulations. The Auditor-General of Pakistan reviews the
financial statements submitted by each Government department and agency and reports findings to the
President and Provincial Governors who submit them to the National and Provincial Assemblies respectively.
The legislatures assign these reports to the PACs for detailed scrutiny. Each PAC holds hearings at which
secretaries of the ministry, divisions and departments submit their responses to the Auditor-General’s
observations. Based on this testimony, each PAC then makes its recommendations to the National Assembly.
This process ensures that departments and agencies are accountable to government for implementation of
policies in accordance with regulations.

Legislative Basis 2021+2015


4

The authority under which the Auditor-General of Pakistan conducts audits is given by Article 169 of the
Constitution of the Islamic Republic of Pakistan. In addition, Articles 168 to 171 also relate to the work of
the Auditor-General.

Until 1 July 2001, most of DAGP’s audit work was performed under Articles 168 to 171 of the Constitution,
and the Pakistan (Audit and Accounts) Order, 1973.

Effective 1 July 2001, the Pakistan (Audit and Accounts) Order, 1973 was replaced by the following two
ordinances:
a) Auditor-General’s (Functions, Powers and Terms and Conditions of Service) Ordinance, 2001 (Auditor-
General Ordinance); and
b) Controller General of Accounts (Appointment, Functions and Powers) Ordinance, 2001 (Controller General
Ordinance).

Among other things, these ordinances elaborate on the functions, powers and responsibilities of the Auditor-
General of Pakistan in line with the provisions of Article 169 of the Constitution.

Section 7 of the Auditor-General’s (Functions, Powers and Terms and Conditions of Service) Ordinance, 2001
(Auditor-General Ordinance) states that “The Auditor-General shall, on the basis of such audit as he may
consider appropriate and necessary, certify the accounts” … “of the Federation, of each Province and of each
district”. A financial attestation audit leads to the certifications called for in Section 7 of the Auditor-
General Ordinance.

In addition, Section 8 of the Auditor-General Ordinance mandates an audit of expenditures of the Federation
and of each province and Section 12 of the Auditor-General Ordinance mandates an audit of the receipts of
the Federal Government and of each Province and each district.

Vision, Mission and Values 2016


DAGP has developed a set of guiding principles for the exercise of its mandate. These principles – the Vision,
Mission and Values - are as follows:

The Vision of DAGP is to add value to public resources.

The Mission of DAGP is to develop our auditing and accounting capabilities to establish ourselves as a
credible professional institution that promotes good governance and public accountability.

The Values held by DAGP are:2016+2013+2010

a) Accountability. DAGP holds itself accountable for the achievement of its vision, mission, and these stated
values.
b) Professionalism. DAGP conducts all of its activities in an open, transparent, disciplined and highly ethical
manner that is worthy of professional respect and trust.
c) Integrity. DAGP takes an objective, fair, honest and balanced approach to all of its activities.
d) Excellence. DAGP strives for excellence in all of its activities.
5

e) Reliability. DAGP produces high quality products that are timely, accurate, useful, clear and candid.
f) Cooperative and constructive spirit. DAGP works with parliamentarians and with its audit entities, staff,
suppliers, consultants and other parties with whom it deals in a professional, cooperative and constructive
manner.
g) Innovative spirit. DAGP constantly looks for ways to improve its audit practices, operations and other
activities.
h) Making a difference. DAGP constantly looks for ways to improve the operations of the entities that it audits.
i) Risk managers. DAGP managers and staff are encouraged to accept challenges, and to take and manage the
risks required for DAGP to achieve its vision, mission and stated values.
j) Open communications. DAGP maintains open and timely communications with parliamentarians and with its
audit entities, staff, suppliers, consultants and other parties with whom it deals.
k) A respectful workplace. DAGP provides a workplace in which a diverse workforce can strive for excellence
and professional competence, and where individuals can realise their full career potential.

Expectations 2021
Auditors work in teams. Audit teams perform their work in accordance with DAGP’s Auditing Standards,
which are described in detail in Chapter 4. The audit teams should fulfil a number of general expectations
in performing their duties:
a) At least one auditor within the audit team should be fully conversant (knowledge) with the rules and
regulations concerning the accounts to be audited.
b) The audit team should subject the audit entity to a complete and thorough check according to the audit
programme within the constraints of the time available. Any failure to complete the prescribed audit
programme must be reported clearly and fully to the Audit Manager.
c) Each auditor is expected to use professional judgment in carrying out all aspects of an audit programme.
d) Although it is not the responsibility of the auditor to detect fraud, every auditor is expected to take appropriate
action wherever a situation of fraud is suspected.

Integrity 2016+2013

e)Integrity is the core value of this Code of Ethics. Auditors have a duty to adhere to high standards of
behaviour (e.g. honesty and candidness) in the course of their work and in their relationships with the staff
of audited entities. In order to sustain public confidence, the conduct of auditors should be above suspicion and
reproach.
f) Integrity, including financial, moral, and intellectual integrity, can be measured in terms of what is right and just.
Integrity requires auditors to observe both the form and the spirit of auditing and ethical standards. Integrity
also requires auditors to observe the principles of independence and objectivity, maintain irreproachable
standards professional conduct, make decisions with the public interest in mind, and apply absolute honesty in
carrying out their work and in handling the resources of the DAGP.

Independence, Objectivity and Impartiality 2019

g) Independence from the audited entity and other outside interest groups is indispensable for auditors. This
implies that auditors should behave in a way that increases, or in no way diminishes, their independence.
h) Auditors should strive not only to be independent of audited entities and other interested groups, but also to be
objective in dealing with the issues and topics under review.
6

i) It is essential that auditors are independent and impartial, not only in fact but also in appearance.
j) In all matters relating to the audit work, the independence of auditors should not be impaired by personal or
external influence. Independence may be impaired, for example, by external pressure or influence on auditors;
prejudices held by auditors about individuals, audited entities, projects or programmes; recent previous
employment with the audited entity; or personal or financial dealings which might cause conflicts of loyalties
or of interests. Auditors have an obligation to refrain from becoming involved in all matters in which they have
a vested interest.
k) There is need for objectivity and impartiality in all work conducted by auditors, particularly in their reports,
which should be accurate and objective. Conclusions in opinions and reports should, therefore, be based
exclusively on evidence obtained and assembled in accordance with the auditing standards of the DAGP.
l) Auditors should make use of information brought forward by the audited entity and other parties. This
information is to be taken into account in the opinions expressed by the auditors in an impartial way. The
auditor should also gather information about the views of the audited entity and other parties. However, the
auditor’s own conclusions should not be affected by such views.

Auditors should not


be involved in
management
Conflicts of Interest 2017+2019 decisions or

m) When auditors are permitted to provide advice or services other than audit to an audited entity, care should be
taken that these services do not lead to a conflict of interest. In particular, auditors should ensure that such
advice or services do not include management responsibilities or powers, which must remain firmly with the
management of the audited entity.
n) Auditors should protect their independence and avoid any possible conflict of interest by refusing gifts or
gratuities that could influence or be perceived as influencing their independence and integrity. Government
servants, Conduct Rules, 1964 shall also apply in this regard.
o) Auditors should avoid all relationships with managers and staff in the audited entity and other parties that may
influence, compromise or threaten the ability of auditors to act and be seen to be acting independently.
p) Auditors should not use their official position for private purposes and should avoid relationships that involve
the risk of corruption or may raise doubts about their objectivity and independence.
q) Auditors should not use information received in the performance of their duties as a means of securing
personal benefit for themselves or for others. Neither should they divulge information that would provide
unfair or unreasonable advantage to other individuals or organisations, nor should they use such information as
means for harming others.

Attempts to
hinder or
impede the
conduct of the
audit should
Protection of the Auditor- 2021 be brought to
the attention
7

Auditors must have the freedom to carry out audits in a conscientious and thorough manner. There is an onus
on the auditor to carry out the audits in a fair, objective and courteous manner (and comply with the Code of
Ethics presented in the Section above). In turn, the auditor expects to receive cooperation and courtesy from
those being audited.

Any serious attempts to hinder or impede the conduct of the audit should be brought to the attention of the
Audit Manager. Any concern of possible intimidation or threat to the auditor must be taken seriously both by
the auditor and the management of DAGP. A formal process should be followed wherever the auditor, or
the conduct of the audit, is threatened, or a risk of impedance is perceived. This process involves the
following steps:

a) Whenever the auditor senses any problems in the conduct of the audit, he/she should ensure that all meetings
are held with at least two auditors present and that notes of these meetings are clearly documented;
b) The auditor should inform his/her supervisor or Audit Manager in writing of any serious incidents or concerns
with specific details of what transpired;
c) A course of action is proposed by the Audit Manager, if necessary, in consultation with senior management
within DAGP;
d) Depending on the seriousness of the situation, and the nature of the problem, one or more of the
following courses of action should be implemented:

- The Audit Manager raises the issue with the Principal Accounting Officer, or equivalent;
- A letter, signed by the Auditor-General or Deputy Auditor-General, is submitted to the Principal Accounting
Officer, or equivalent, and/or sent to the Controller General;
- The composition of the audit team is changed;
- If necessary, after consultation with the Auditor-General, seek a legal opinion or other course of action; and
- Whenever an individual auditor is not satisfied with the action taken, they have the right to report their
concern to the Assistant Auditor-General, Personnel, a Deputy Auditor-General or the Auditor-General.
8

2. DAGP AUDIT STANDARDS

Audit Evidence 2019

i. Adequate documentation is important for several reasons. It will:

a. Confirm and support the auditor’s opinions and reports;


b. Increase the efficiency and effectiveness of the audit;
c. Serve as a source of information for preparing reports or answering any enquiries from the audited
entity, legislature and its committees or from any other party;
d. Serve as evidence of the auditor’s compliance with Auditing Standards;
e. Facilitate planning and supervision;
f. Help the auditor’s professional development;
g. Help to ensure that delegated work has been satisfactorily performed; and
h. Provide evidence of work done for future reference.

Analysis of Financial Statements [Link]

i. Financial statement analysis aims at ascertaining the existence of the expected relationship within and
between the various elements of the financial statements, identifying any unexpected relationships and any
unusual trends. The auditor should therefore thoroughly analyse the financial statements and ascertain
whether:

a. Financial statements are prepared in accordance with acceptable accounting standards;


b. Financial statements are presented with due consideration to the circumstances of the audited entity;
c. Sufficient disclosures are presented about various elements of financial statements; and
d. The various elements of financial statements are properly evaluated, measured and presented.

ii. The methods and techniques of financial analysis depend to a large degree on the nature, scope and
objective of the audit, and on the knowledge and judgment of the auditor.

iii. If required to report on the execution of budgetary laws, audit by the DAGP shall include:

a. For revenue accounts, ascertaining whether forecasts are those of the initial budget, and whether the
audits of taxes and duties recorded, and imputed receipts, can be carried out by comparison with the
annual financial statements of the audited activity;
b. For expenditure accounts, verifying credits to assist budgets, adjustment laws and, for carryovers, the
previous year’s financial statements.
9

The form and content of all audit opinions and reports are founded on the following general principles.
2017-2014

a) Title. The opinion or report shall be preceded by a suitable title or heading, helping the reader to
distinguish it from statements and information issued by others.

b) Signature and date. The opinion or reports shall be properly signed. The inclusion of a date informs the
reader that consideration has been given to the effect of events or transactions about which the auditor
became aware up to that date (which, in the case of regularity (financial) audits, may be beyond the period
of the financial statements).

c) Objectives and scope. The opinion or report shall include reference to the objectives and scope of the
audit. This information establishes the purpose and boundaries of the audit.

d) Completeness. Opinions shall be appended to and published with the financial statements to which they
relate, but performance reports may be free standing. The auditor’s opinions and reports shall be presented
as prepared by the auditor. In exercising its independence the Department shall be able to include whatever
it sees fit, but it may acquire information from time to time which in the national interest cannot be freely
disclosed. This can affect the completeness of the audit report. In this situation the auditor retains a
responsibility for considering the need to make a report, possibly including confidential or sensitive
material in a separate, unpublished report.

e) Addressee. The opinion or report shall be addressed as per requirements of applicable laws and
procedures.

f) Identification of subject matter. The opinion or report shall identify the financial statements (in the case
of regularity (financial) audits) or area (in the case of performance audits) to which it relates. This includes
information such as the name of the audited entity, the date and period covered by the financial statements
and the subject matter that has been audited.

g) Legal basis. Audited opinions and reports shall identify the legislation or other authority providing for the
audit.

h) Compliance with standards: Audit opinions and reports shall indicate the auditing standards or practices
followed in conducting the audits, thus providing the reader with an assurance the audit has been carried
out in accordance with generally accepted procedures.

i) Timelines: The audit opinion or report shall be available promptly to be of greatest use to readers and
users, particularly those who have to take necessary action.
10

An unqualified opinion is given when the auditor is satisfied in all material respects that: 2013

a) The financial statements have been prepared using acceptable accounting bases and policies which have been
consistently applied;
b) The statements comply with statutory requirements and relevant regulations;
c) The view presented by the financial statements is consistent with the auditor’s knowledge of the audited entity;
and
d) There is adequate disclosure of all material matters relevant to the financial statements

Level 4 - Auditing Guidelines (ISSAIs 1000-4999) [Link]


Level 4 of INTOSAI Auditing Standards consists of two sets of Guidelines, (i) the General auditing guidelines
(ISSAIs 1000- 4999) which contain the recommended requirements of financial, performance and compliance
auditing, and (ii) the Guidelines on specific subjects (ISSAIs 5000-5999) which provide supplementary
guidance on the auditing of specific subject matters or other important issues which may require the special
attention of Supreme Audit Institutions. Complete set of standards and related guidelines are available at
[Link].

ISSAI 1000: General Introduction to the INTOSAI Financial Audit Guidelines

The INTOSAI Financial Audit Guidelines include the International Standards on Auditing (ISAs) issued by the
International Auditing and Assurance Standards Board (IAASB).These guidelines are part of General auditing
guidelines and they draw on International Standards on Auditing developed by the International Auditing and
Assurance Standards Board (IAASB) and published by the International Federation of Accountants (IFAC).

ISSAI 1220: Quality Control for Audits of Historical Financial Information

Guidance on Public Sector Issues


ISA 220 contains application and other explanatory material with considerations specific to public sector
entities in paragraphs A7, A9, A12, A30 and A31 of the ISA. The engagement quality control reviewer shall
perform an objective evaluation of the significant judgments made by the engagement team, and the
conclusions reached in formulating the auditor’s report. This evaluation shall involve:
a) Discussion of significant matters with the head of the FAO;
b) Review of the financial statements and the proposed auditor’s report;
c) Review of selected audit documentation relating to the significant judgments the engagement team made and
the conclusions it reached; and
11

d) Evaluation of the conclusions reached in formulating the auditor’s report and consideration of whether the
proposed auditor’s report is appropriate. (Ref: Para. A26-A27, A29-A31)

The engagement quality control reviewer, on performing an engagement quality control review, shall also consider
the following:
a) The engagement team’s evaluation of the DAGP’s independence in relation to the audit engagement;
b) Whether appropriate consultation has taken place on matters involving differences of opinion or other difficult
or contentious matters, and the conclusions arising from those consultations; and
Whether audit documentation selected for review reflects the work performed in relation to the significant judgments
and supports the conclusions reached. (Ref: Para. A28-A31

ISSAI: 1230 Audit Documentation

Guidance on Public Sector Issues


Paragraph 8(c) of the ISA requires the auditor to prepare audit documentation that is sufficient to enable an
experienced auditor, having no previous connection with the audit, to understand significant matters arising
during the audit, the conclusions reached thereon, and significant professional judgments made in reaching
those conclusions. Paragraph A8 of the ISA explains that judging the significance of a matter requires an
objective analysis of the facts and circumstances, and provides examples of significant matters. Public sector
auditors may be required to report on a broad range of significant matters which may not be part of their report
on the financial statement audit, or matters that may not result in material misstatement of the financial
information or related disclosures. Examples of such matters include lack of compliance with legislation or
approved mandate, violations of contract provisions or grant agreements, unauthorized or inappropriate
expenditures, execution of the budget, certification of the annual deficit/surplus, assessments of program
funding and costs, and information on performance indicators.
1.1.1. ISSAI 1240: The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements

Guidance on Public Sector Issues


ISA 240 contains application and other explanatory material with considerations specific to public sector
entities in paragraphs A6, A57 and A67 of the ISA. Three conditions are normally present when fraud occurs.
These conditions are often present in various ways in the public sector. These include: 2021
a) Incentive or pressure (placed on or perceived by management or employees giving them a reason to commit
fraud) – public sector employees are often under pressure to deliver high quality services with few resources
and to meet budget expectations. This may be especially relevant in tough economic conditions where there is
pressure to maintain user charges and tax rates, resulting in incentives to overstate revenues and understate
expenditures. There may also exist incentives to spend the available budget by the end of the financial year;
b) Opportunity (characteristics or circumstances related to an entity allowing for the perpetration of fraud) – a
difficult recruitment environment or a lack of sufficient qualified personnel may be more prevalent in the
public sector. Such situations may often result in deficiencies in internal control creating the opportunity for
fraud. The widespread use of high volume, low value cash transactions in certain public sector entities such as
cash transactions at police departments or health clinics may add to those risks. Although monetary values may
be small, such situations may lead to violation of public trust, expectations and accountability; and
c) Rationalization or attitude (Behavior, character or ethical values that allow individuals to justify their
reasons for committing fraud)- generally lower salary levels in the public sector compared to the private sector
may lead employees to believe that they can justify misuse of funds. As above, this may violate principles of
public trust, expectations and accountability
12

ISSAI 1300: Planning an Audit of Financial Statements

Guidance on Public Sector Issues


The Practice Note within ISSAI 1300 provides additional guidance for public sector auditors related to:
(a) Overall Considerations.
(b) The Role and Timing of Planning.
(c) Preliminary Engagement Activities.
(d) Planning Activities.
(e) Considerations Specific to Smaller Entities.
(f) Documentation.
(g) Additional Considerations in Initial Audit Engagements.

ISSAI 1315: Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity
and its Environment

Guidance on Public Sector Issues


ISA 315 contains application and other explanatory material with considerations specific to public sector
entities in paragraphs A21, A35, A65 and A113 of the ISA. In obtaining the understanding of the entity
and its environment, public sector auditors take into account that:
(a) Decisions may be initiated outside the entity as a result of political processes. Such decisions influence
management’s activities. Examples include:
 New geographic locations or closures of existing locations;
 Reorganizations, including transfer of activities to other entities;
 New program areas; and
 Budgetary constraints or cut backs.
(b) Relevant regulatory factors include specific laws and regulations to which the entity is subject and the potential
impact of non-compliance with these;
(c) Other external factors, including the applicable financial reporting framework, may influence specific reporting
objectives;
(d) Understanding the business operations may include knowledge of the government activities carried out,
including relevant programs;
(e) Program objectives and strategies may include public policy elements and therefore may have implications for
the risk assessment;
(f) Ownership of public sector entities may not have the same relevance as in the private sector. In the public
sector, focus is on those charged with governance in their role as representatives of the citizens;
(g) Governance structures are affected by the legal structure of the entity, for example whether the entity is a
ministry, department, agency or other type of entity; and
(h) Issues related to management’s assumptions ongoing concern may not be relevant.
13

ISSAI 1505: External Confirmations

Guidance on Public Sector Issues


Confirmations can be used to obtain evidence about the presence or absence of certain conditions. In addition
to assertions related to the audit of financial statements, public sector auditors may find confirmations useful in
obtaining evidence related to additional audit objectives stipulated by their audit mandate or arising from
legislation, regulation, ministerial directives, government policy requirements, or resolutions of the legislature.

Corroborating information obtained from a source independent of the entity may increase the assurance the
auditor obtains from evidence within the accounting records or from representations made by management.
Given the size and complexity of governments, public sector auditors need to be vigilant to ensure that external
confirmation requests are directed to third parties who are independent of the audited entity and the responses
are reliable in light of the relationship between the entity and the confirming party.

ISSAI 1530: Audit Sampling

Guidance on Public Sector Issues


Public sector auditors may use sampling for additional responsibilities in addition to providing an opinion on
the financial statements. The use of audit sampling for testing compliance with authorities is similar to other
uses of audit sampling in that public sector auditors:
 Determine sample design and audit parameters, including materiality, desired confidence level, and sample
selection method;
 Perform relevant audit procedures on each item selected;
 Investigate the nature and causes of non-compliance; and
 Evaluate the results, including projecting the results across the population if the sample was selected using
statistical procedures.

ISSAI 1706: Emphasis of Matter Paragraphs and other Matter(s) Paragraphs in the Independent Auditor’s
Report

Guidance on Public Sector Issues


In the public sector audit mandates or expectations may expand circumstances relevant for reporting by public
sector auditors in an Emphasis of Matter paragraph. Additional examples that may be relevant to report in an
Emphasis of Matter paragraph, if properly disclosed in the financial statements may, in addition to paragraph
A1 of the ISA include:
 Legislative actions on programs or the budget;
14

 Contradictive laws, regulations or directives with a significant effect on the entity;


 Fraud, abuse or losses;
 Significant transactions;
 Significant internal control deficiencies;
 Questionable business practices;
 Transactions entered into without due regard for economy;
 Prior period restatements;
 Lack of fiscal sustainability;
 Environmental issues;
 Corporate social responsibility issues;
 Ethical issues (proper behavior by public officials); or
 Ineffective and uneconomical use of public assets.
 Public sector auditors may also decide to include an Emphasis of Matter paragraph for matters relating to
non-compliance with authorities that have been accurately accounted for and/or disclosed in the financial
statements. An example of such matter is improper stewardship of funds. However, an Emphasis of Matter
paragraph related to non-compliance may only be relevant if there is no requirement to provide a separate
opinion on compliance with authorities.

3. DAGP’s Annual Planning Process


15

DAGP Strategic Audit Objectives 2019

The Auditor-General’s mandate is established by legislation – Auditor-General’s (Functions, Powers and


Terms and Conditions of Service) Ordinance, 2001 (Auditor General’s Ordinance). Two key sections are:

Section 7 of Auditor-General’s (Functions, Powers and Terms and Conditions of Service) Ordinance, 2001
(Auditor General’s Ordinance) states that “The Auditor-General shall, on the basis of such audit as he may
consider appropriate and necessary, certify the accounts” … “of the Federation, of each Province and of each
District”.

Section 8 of the Auditor-General Ordinance mandates an audit of expenditures of the Federation and of each
Province, and Section 12 of the Auditor-General Ordinance mandates an audit of the receipts of the Federal
Government and of each Province and District.

These sections establish the two primary objectives of DAGP audits: financial attest/certification audits and
compliance with authority audits to ensure entities within all three levels of government properly comply with
all rules and regulations pertaining to expenses and revenues.
Note that all attest/certification audits will include a compliance component in accordance with international
auditing standards and that DAGP may also perform independent compliance with authority audits in any
areas which the Auditor-General considers it important to review. Accordingly compliance audit activities
will be a major aspect of DAGP plans for any given time period.

Whether to
Audit perform audit
acitivities activities in
should cover every single
DAGP Audit Scope all entities entity within
whose the federation
operations are is a matter for
the
In determining the scope of audit work the Auditor-General has wide discretion. Auditor-
General to
For attest/certification audits required under Section 7 of the Auditor-General Ordinance, the entity to be
audited will be defined by the applicable accounting policies of the government. For example, to certify the
financial statements of the Federation, the entity to be audited is the aggregate of all of the ministries,
departments, agencies, etc. that the accounting policies require to be included in the financial statements of
the Federation. Whether to perform audit activities in every single entity within the federation is a matter for
the Auditor-General to decide. At a minimum, audit activities should cover all entities whose operations are
material in the context of the financial statements of the Federation. In addition, the Auditor-General may
plan to extend the audit activities to any other entities he considers significant.
16

In the case of compliance with authority audits, the Auditor-General has complete discretion as to which
entities (whether organisational entities, such as agencies, DAOs, DDOs etc., functional entities, such as the
payroll function or the purchasing function; or accounting entities, such as objects of expenditure, grants or
appropriations) will be subject to audit and how often audits will be conducted.

DAGP Strategic Audit Plans 2019+2016+2017+2012+2010

The Auditor-General is responsible for deciding what audit work is necessary to fulfil his mandate. Under his
direction, DAGP produces a multi-year strategic plan for DAGP audit activities. The audits included in the
strategic plan will include:

Mandatory and centrally led. These are audits required by DAGP’s mandate to be performed each year,
where the work performed by an individual directorate is part of a larger audit. An example of such an audit is
the annual audit of the financial statements of the Federation.

Not mandatory and centrally led. These are audits where DAGP’s mandate does not require that they be
performed each year, and the work performed by the directorate is part of a larger audit exercise. An example
of this type of audit could be a government-wide audit of contracting.

Mandatory and not centrally led. Those audits that are required by DAGP’s mandate to be performed each
year, where the work is not part of a larger audit. An example of such an audit is the annual audit of the
financial statements of a specific commercial entity or a foreign-aided project for which the directorate is
required to issue an audit opinion.

In these cases, the Auditor-General schedules the activities and delegates audit work to the audit directorates.

Consolidating the plans for all these audits produces the DAGP strategic audit programme.

4. The Audit Cycle


The audit plan should include: 2021
a) A clear statement of the audit objective(s);
b) Statement of the magnitude of operations (expenditures, revenues, assets, personnel) and for an attest audit,
the significant line items and accounts in the financial statements and significant financial statement
assertions;
c) Summary of significant issues and results of an initial risk assessment;
d) Proposed audit scope, including:
17

- Type(s) of audit activity (attest, compliance, effectiveness of internal controls, safeguarding of assets,
fraud investigation, value-for-money, IT systems, or some combination thereof);
- locations to be visited;
- functions, activities, systems and procedures to be examined;
- aspects of performance to be covered;
- audit methods and tests; and
- samples selected or methods of selecting samples.
e) Budget and schedule;
f) Audit steps; and
g) Assigned audit responsibilitie

DAGP audit teams should plan to perform audits that encompass both financial attest and compliance
components. These two audit components have much in common. Each planning requires the auditor to:
a) Understand the audit entity;
b) Conduct a risk assessment;
c) Define audit objectives and scope;
d) Develop an audit programme
e) Test the controls;
f) Determine sample size (for statistical or non-statistical);
g) Conduct substantive tests;
h) Report; and
i) Follow up.

The audit cycle is shown in Figure 6.1. It contains six basic phases:
a) General audit planning;
b) Detailed activity and resource planning;
c) Fieldwork;
d) Evaluation; six basic phases
e) Reporting; and
f) Follow-up.

Figure 6.1: Audit Cycle for Individual Audits


18
19

Step 6 – Determine financial audit and compliance with authority objectives, and error/irregularity conditions

Specific financial audit objectives. 2015

For a financial statement audit, a component is considered to be in error if:

 It is not valid (the asset or liability does not exist or the revenue or expenditure has not occurred) – the
existence objective; or

 The statement of the asset, liability, revenue or expenditure is not complete – the completeness objective;
or

 The asset is not owned by the entity, or the liability is not owed by the entity – the regularity objective; or

 The asset or liability is not properly valued or is misclassified, or the revenue or expenditure is not properly
measured or is misclassified - the valuation or measurement objective; or

 The financial statement presentation is not proper – the presentation objective.

Step 8 – Determine mix of tests of internal control, analytical procedures and substantive tests of
details

The auditor needs to select a combination of tests of internal control, analytical procedures and substantive
tests of details that, in total, will provide the desired level of assurance that payroll expenditures are not
incomplete by an amount greater than the materiality amount. 2015+2019
20

The auditor can obtain this assurance in a number of ways, for example by:
a. reviewing the internal controls that the entity has in place to ensure the completeness of, using our payroll
example, payroll expenditures, and then performing tests of internal control to ensure that the controls are
functioning properly;
b. performing such analytical procedures as comparing the payroll expenditures by month to each other and to
the equivalent amounts in the previous year; and/or
c. selecting a sample of payroll transactions and performing various substantive tests of details on those
transactions.

These methods can be used in different combinations. For example:

Place a lot of reliance on the internal controls. Under this option, the auditor would perform a lot of tests of
internal control, supplemented by only limited analytical procedures, and select a very small sample of payroll
transactions for substantive tests of details; or,

Place very little reliance on the internal controls. Under this option, the auditor would do fewer tests of
internal control than in the first option, but would perform more rigorous analytical procedures and/or select a
larger sample of payroll transactions for substantive tests of details.

When deciding which combination to use, the auditor should consider several factors, including the cost of
each combination in terms of audit resources.
21

5. Planning the Audit

Step 1 – Establish Audit Objectives and Scope 2016+2017


It is a general principle of DAGP’s audit activities that no audit entity should be subject to more than one
audit in a given year. Accordingly, any individual audit may have to fulfil multiple audit objectives, so it is
important that the audit is well-planned in terms of audit objectives and audit scope.

The step also involves communicating with the entity to ensure management is fully aware of the audit
objectives and audit scope.

Overall Audit Objectives

Each audit will be designed to address one or more of the following objectives:
a) Expressing an opinion on financial statements;
b) Expressing an opinion regarding compliance with authorities;
c) Testing compliance with authority or controls on selected transactions with no opinion being expressed; and
d) Evaluating operational performance.

To express an opinion on financial statements the auditor needs to design audit procedures to obtain a
reasonable level of assurance that the financial statements are not materially misstated. This means reaching a
conclusion as to whether the account balances are valid, are complete, are properly valued, etc.
For compliance with authority work where an opinion is being expressed, the auditor will design audit
procedures to obtain a reasonable level of assurance that the selected transactions in a given period are in
compliance with applicable statutes and regulations. The types of irregularities that the auditor needs to look
for will reflect the objectives of the compliance audit.
For compliance with authority audit work where there is no expression of an opinion the auditor need not
plan the audit to obtain a specified minimum level of overall audit assurance.
Where the audit is to evaluate operational performance the auditor is concerned with economy, efficiency
and effectiveness the auditor will develop specific audit objectives and conclude on the management
framework and/or level of performance.
In summary, the nature and extent of the work that the auditor needs to perform will vary according to the
objectives of the audit. Therefore, a first step in the planning process is to determine the objectives for the
year.
22

Audit Scope
The auditor also needs to determine the overall audit scope – the total population on which to express an
opinion, from which to select transactions, etc. For financial audit purpose, this total population is referred to as the
“audit entity”. The audit entity determines the scope of the audit, and is generally defined by the audit mandate. For
financial statement audits that are required under Section 7 of the Auditor-General Ordinance (see Chapter 2), the
entity to be audited will be defined by the applicable accounting policies of the government.

For example, the accounting policies for the Federation state, “The financial statements have been prepared
by consolidating the accounts of all Centralised and Self Accounting Entities …. Commercial entities owned
or controlled by the Government prepare their own financial statements, which are not included in these
financial statements.” Based on this accounting policy, the audit entity would include all centralised and self-
accounting entities, but would exclude the commercial entities.
For other financial audits, the entity to be audited may need to be carefully determined. For example, a
ministry may make use of a special operating agency to perform some of its functions. In this situation, the
auditor will need to determine whether or not the agency falls under the scope of the audit.
In some cases, the scope of the audit can be at the auditor’s discretion, or can be negotiated with entity
management. For example, DAGP may have planned to audit a particular civil works project. If the internal
audit unit in that entity is planning to do a detailed audit of the project one year later, it may suggest that
DAGP defer its audit by a year so the two audits could be coordinated. DAGP might decide to do so.
The first consideration in defining the scope of audit is to ensure that the work required to complete the
financial attest audit is covered. In determining what else should be audited, it is important that scarce audit
resources be focused on the most important aspects of the operations of the government. The first step in
deciding what to examine is to identify matters of significance, both within the government as a whole and
within the audit entity under examination.

Matters of significance can include one or more of the following:


a) Large expenditures or large revenues;
b) Areas of high risk (significant control weaknesses, potential for large losses/negative impacts);
c) Matters of propriety, or probity (even if not of high materiality or risk);
d) Important aspects of the programme’s performance;
e) Politically sensitive areas, where the reputation of the government could be adversely affected;
f) Substantial errors or misrepresentations in financial and other management reports;
g) Serious problems of compliance, especially regarding laws and regulations; and
h) Areas where the audit is likely to identify opportunities for significant improvement.

Minimum terms of audit engagement 2021+2021

The form and content of entity communication letter may vary according to type of audit, but they
would generally include reference to:2021
a) The objective of the audit;
b) Management’s responsibility;
23

c) The scope of the audit, including reference to applicable legislation, regulations, or pronouncements of
professional bodies to which the auditor adheres;
d) The form of any reports or other communication of results of the engagement;
e) The fact that because of the test nature and other inherent limitations of an audit, together with the inherent
limitations of any accounting and internal control system, there is an unavoidable risk that even some material
misstatement may remain undiscovered; and
f) Unrestricted access to whatever records, documentation and other information requested in connection with
the audit.

The auditor may also wish to include the following in the letter:2021
a) Arrangements regarding the planning and performance of the audit.
b) Expectation of receiving from management written confirmation concerning representations made in
connection with the audit.
c) Request for the auditee to confirm the terms of the engagement by acknowledging receipt of the engagement
letter.
d) Description of any other letters or reports the auditor expects to issue to the auditee.
e) When relevant, the following points could also be made:
f) Arrangements concerning the involvement of other auditors, internal auditors, predecessor auditors and
experts in some aspects of the audit.
g) Any restriction of the auditor’s liability when such possibility exists.
h) A reference to any further agreements between the auditor and the engagement entity.

Step 2 – Understand the Entity’s Business


Information Requirements
Audit objectives are developed on the basis of an understanding of the entity’s business. However, the auditor
does not need to have a complete understanding of all of the entity’s activities. The auditor only needs to have a
detailed knowledge of those aspects of the entity’s business that relate to the audit.
For example, when performing a financial statement audit, the auditor may not need to have a detailed
understanding of all of the entity’s human resource policies. However, should the auditor be performing a
compliance with authority or a performance audit on the staffing and promotion processes, a more detailed
understanding of the human resource policies may be required.

The auditor should assemble the following information for most audits: 2017+15+14
a) government’s plans and priorities;
b) entity’s strategic plans;
c) users of the entity’s services;
d) legislative authorities affecting the entity’s operations;
e) industry in which the entity operates, including any specialised accounting practices followed by that industry;
f) activities in which the entity engages (constructing buildings, providing grants and contributions, collecting
taxes, etc.);
g) size of the entity (its total assets, liabilities, revenue and expenditure);
h) types of transactions and documents that the entity processes;
i) entity’s internal control structure; and
j) economic trends that can affect the valuation of significant assets and liabilities (those held in foreign
currencies, for example).
24

The Standard Audit Working Paper Kit includes forms to help the auditor update his/her understanding of
each of these knowledge areas.

Sufficient knowledge of these matters is required by the auditor to:


a) assess materiality, planned precision and audit risk;
b) understand the internal control structure;
c) determine components and understand how the various components and activities fit together;
d) identify error conditions;
e) assess inherent risk and control risk;
f) understand the substance of transactions, as opposed to their form;
g) identify the nature and sources of audit evidence that are available;
h) update audit programmes;
i) assess whether sufficient appropriate audit evidence has been obtained;
j) assess the appropriateness of the accounting policies being used; and
k) evaluate the presentation of financial statements and the reasonableness of the overall results.
There is a link between these knowledge areas and the tasks to be performed, as follows:
a) an understanding of the users of the entity’s services and the size of the entity is needed to assess materiality;
b) an understanding of the legislative authorities affecting the entity’s operations, the activities in which the entity
engages, and the types of transactions and documents that the entity processes is needed to determine what
components to audit;
c) an understanding of the industry in which the entity operates, the activities in which the entity engages, the size
of the entity, the types of transactions and documents that the entity processes, and economic trends are
needed to assess inherent risk.

Step 3 – Assess materiality, planned precision, and audit risk


Materiality
Definition of materiality: When the auditor states that the financial statements “properly present, in all
material respects”, he/she is stating that the financial statements are not materially misstated. This introduces the
concept of materiality.
Materiality can be defined as follows: “An error (or the sum of the errors) is material if the error (or the
sum of the errors) is big enough to influence the users of the financial statements”.
Materiality is important in the context of the auditor’s report on the financial statements. The opinion
paragraph of a standard unqualified auditor’s report commences, “In my opinion, these financial statements
properly present, in all material respects, the financial position of [the entity] …”

Guidelines: To determine materiality the auditor should perform the following


steps:2021+19+18+15+13
1. Identify the probable users of the financial statements.
2. Identify the information in the financial statements that is expected to be the most important to each of these
users (e.g., total expenditures, total assets or the annual surplus or deficit). One or more of these amounts may
serve as the base amount(s) for computing materiality.
3. Estimate the highest percentage(s) by which the base amount(s) could be misstated without significantly
affecting the decisions of the users of the financial statements.
4. Multiply the percentage(s) times the base amount(s).
25

5. Select the lowest amount – this is the materiality amount. Errors exceeding this value are material.
The auditor normally selects the lowest amount that results from each of these guidelines, and uses that amount for the
audit of the financial statements as a whole. This is because errors often affect more than one component. For example,
an error in cash may also represent an error in expenditures. As a result, the auditor cannot use a higher materiality
amount to audit cash than he/she uses to audit expenditures.
Note that the materiality amount determined at this step in the general planning phase is used for the audit of all
components. There is no need to allocate the amount to the various financial statement components. If materiality is set
at Rs. 3,000,000 for the financial statements as a whole, the same Rs. 3,000,000 can be used for each financial
statement component, and for each specific financial audit objective, related compliance with authority objective, and
error condition.

Quantative Aspects:

There are some guidelines that can be used to determine the base amount(s) and the appropriate percentage(s).
While guidelines should not replace the use of professional judgment, the following may be useful, depending on the
nature of the entity being audited:
Percentage of total expenditures.
This method is the most widely used method for not-for-profit public sector entities. The percentages used generally
range from 2% for "small" entities to 0.5% for "large" entities.
Percentage of normalised pre-tax income.
This method is the most used method for profit-oriented public sector entities (e.g., state-owned enterprises with a
mandate to earn a return on their investments). The percentages used generally range from 5% for entities with
"large" pre-tax incomes to 10% for entities with "small" pre-tax incomes.
Percentage of total revenue.
The same 2% to 0.5% range that is generally used for expenditures (see above) is often recommended.
Percentage of equity.
Usually 1% is suggested. This method would be appropriate only for entities following full accrual accounting and
hence recording such assets as receivables, stocks and fixed assets. Without these assets, the entity would most likely
be in an accumulated deficit position, and the equity amount might not be meaningful to the users.
Percentage of assets.
Usually 0.5% is suggested, which achieves the same materiality amount as the amount in Percentage of Equity if the
debt-to-equity ratio is 1 to 1.
Percentage of the annual surplus or deficit.
For public sector entities, the most often quoted amount in the media is the annual surplus or deficit. It would therefore
seem logical to base materiality on a percentage of the entity’s annual surplus or deficit.
Qualitative aspects.

In addition to the quantitative aspects of materiality discussed above, there is also a qualitative aspect. The inherent
nature or a characteristic of an error may render the error material, even if its value is not. For example, a small error
that is designed to conceal the over-expenditure of a government appropriation could be considered to be material by
the users.
Auditors are not expected to plan financial audits to detect all of these qualitative errors. The cost of such an audit
would be too high. Consequently, auditors normally ignore the qualitative aspects of errors when planning their audits.
However, when reporting on the results of the audit work, they take into account the qualitative aspects of the errors
that they have found when assessing whether the financial statements taken as a whole are presented fairly.
26

Planned Precision
Planned precision is the auditor’s planned allowance for further possible errors.
By testing a sample, the auditor can determine the Most Likely Error (MLE) in the population. However, because the
auditor has only selected a sample, there is a chance that the actual error in the population is larger than that. The
auditor needs to ensure there is sufficient assurance that the maximum possible error in the population is less than the
materiality amount.

To do this, when planning and performing many analytical procedures and substantive tests of details, the auditor
reduces the materiality amount by his/her estimate of the most likely error that will exist in the financial statements as
a whole. This estimate is referred to as the “expected aggregate error.” Planned precision is equal to materiality less the
expected aggregate error.

To determine the expected aggregate error, the auditor should consider:


a) The errors found in previous years;
b) Changes the entity has made to the internal control structure to prevent these errors from recurring; and
c) Other changes to the entity’s business or its internal control structure that could affect the size of the errors.

If the auditor’s estimate of the expected aggregate error had been set at the planning stage at Rs. 816,500, the auditor
would have calculated planned precision as follows:
Materiality Rs. 3,000,000
Expected aggregate error in financial statements 816,500
Planned precision Rs. 2,183,500

As noted in the discussion on materiality, the materiality amount determined at this step of the general planning phase
is used for the audit of all components within the same audit. There is no need to allocate the amount to the various
financial statement components. Consistent with this approach, the expected aggregate error being used for a particular
test is the expected aggregate error in the financial statements as a whole, and not just the expected error in the
population being audited. When auditing the completeness of income tax receipts, for example, the auditor would need
to allow for errors not only in that test, but for errors found in other income tax receipts tests and for errors found in
other financial statement components.

Audit Risk
Definition: 2017+16+13The opinion paragraph of the standard unqualified auditor’s report begins “In my
opinion …” This means that the auditor is not stating that he/she is absolutely certain that the financial statements
properly present the results of operations (i.e. they are not materially misstated). Rather, the auditor is stating that
he/she has some degree of assurance that is less than 100% that the financial statements are not materially misstated.
Generally accepted auditing standards (GAAS) refer to this degree of assurance as “reasonable assurance”.
Stated another way, the auditor is taking some risk of issuing an unqualified opinion on financial statements that
are materially misstated. This risk is referred to as “audit risk”.

For example, if the auditor wants to be 95% confident that the financial statements are not materially misstated, this
means that the auditor is prepared to take a 5% risk that he/she will fail to detect errors summing to more than the
materiality amount. Audit risk is therefore 5%.
27

Using the audit risk and the materiality amount, when the auditor states, “In my opinion, these financial statements
present fairly, in all material respects …”, the auditor is stating, “I have x% assurance that the financial statements are
not misstated by more than the materiality amount”.

An
understanding
Risk Assessment
of risk is
critical to the
development
The audit should focus on the areas of greatest materiality, significance and risk. An understanding of the risk
associated with each audit entity is therefore critical to the development of an audit plan. The auditor should develop
this understanding by conducting a risk assessment as part of planning an audit assignment.

In the case of a financial attest audit, the auditor is concerned with the risk that material misstatements exist in the
financial statements that will not be detected, either by management or by audit procedures.

In the case of compliance audits, the auditor is concerned with the risk that certain material, or significant,
transactions have occurred in a manner that contravene the laws, regulations and management procedures applying to
the area of audit.

Three categories/types of risk


that are normally considered:
1. Inherent Risk
2. Control Risk
3. Detection Risk

1. Inherent risk 2017+16


This is the susceptibility to material/significant error or loss unrelated to any internal control system . Assessing
inherent risk requires the evaluation of numerous judgmental factors, relating to the nature of the entity and its
business environment taken as a whole.

This is done by asking what could go wrong and what would be the likely consequences. If the likelihood of
occurrence is low and the significance of the consequence is low, the auditor need not be concerned. Where the
likelihood is high and the significance is high, then inherent risk is high. In this situation, the auditor must be assured
that either the internal controls are strong enough to detect and prevent such occurrences or the substantive audit
coverage is sufficient to detect such occurrences with a high level of assurance.
2. Control risk 2017+2016
This is the risk that material/significant error or loss is not prevented or detected on a timely basis by the internal
control structure. Control risk is a function of the effectiveness of the design and operation of the internal controls. In
order to assess control risk, the auditor should obtain evidence to support the effectiveness of internal control policies
and procedures in preventing or detecting material error or loss. The auditor should recognise that there are risks of
error or loss that cannot be detected or prevented in a timely manner whatever the controls in place. Further, the
auditor should recognise that the costs of certain controls cannot be justified when compared to the potential losses
they are guarding against.
28

The auditor should identify and evaluate both the control environment and the effectiveness of the individual internal
controls that are in place. Indicators of a positive control environment include:
a) policies and procedures relating to internal controls and to the need for maintaining a proper control
environment exist and are documented;
b) an appropriate organisational structure with clearly identified roles and responsibilities relating to the
administration of internal controls exists; staff are selected and trained to ensure their competence and
dedication in key control positions;
c) senior management is involved in identifying control risks and monitoring performance;
d) actions are taken to correct any identified control deficiencies with an appropriate level of priority; and
e) management displays positive attitudes towards the maintenance of sound internal controls, such as:
recognising dedicated effort; positively responding to audits and reviews of controls; and taking disciplinary
action in response to poor performance.

The auditor is referred to the Control Environment Worksheet in the Standard Audit Working Paper Kit.

To review the effectiveness of controls the auditor should make use of the Internal Control Questionnaires which are
presented in the audit programme guides as part of the Standard Audit Working Paper Kit. The auditor should expect
stronger controls where risks are highest. For example, there should be strong controls in place to ensure contracts
involving large expenditures are well managed: for the selection of the contractor, for drawing up the contract; and for
the control of performance under the contract. On the other hand, there should be minimal effort applied to controlling
small items of inventory where the risk of loss, damage or theft is low.

The auditor should determine how the controls are applied, assess their adequacy, and identify significant control gaps.

The trend in modern government is to “let the managers manage” and take reasonable risks in order to achieve results
with reduced resources. Consequently, the auditor should be conscious of the need for reasonable, but not excessive,
internal controls. The cost of controls should not exceed the potential losses that could occur without those controls.
3. Detection risk 2016+17

This is the risk of material/significant error or loss going undetected by the auditor’s substantive audit procedures.
It is a function of the effectiveness of the substantive audit procedures and audit effort.
Also, less experienced or less knowledgeable auditors are more likely to miss detecting errors than the experienced
auditor. Therefore, without careful supervision, the employment of less experienced auditors increases detection risk.

Audit risk is a composite of these three risks. When planning an audit there is a trade off between the overall risk that
the auditor will accept and the cost of the audit – the lower the overall risk that the auditor is prepared to take, the more
extensive the required work and the more costly the audit becomes. Thus the risk assessment process is particularly
important in determining the extent to which the audit will examine the systems, procedures, practices and transactions
that govern matters at the lower end of the objective and control hierarchy.

Identification of Risk
29

The auditor needs to develop the ability to identify risks. This requires an understanding of what constitutes risk and
how to recognise it. There is a set of steps that the auditor can take, but experience, imagination and judgment are also
critical.

The steps to follow are:2021


1 List the programme objectives, assets to be safeguarded and other results that management need to achieve;
2 Identify threats which could prevent achievement of these objectives;
3 Rate the risks, with the probability of occurrence, assuming no management controls (the inherent risks);
4 List controls and assurances which exist within the systems and practices in place (environment controls and
internal controls);
5 Identify missing controls and assurances;
6 Identify risks that could occur even with the existing controls in place (control risk); and
7 Recommend improved controls and assurances (based on an assessment of the trade-off of the cost of the
controls against the potential savings of lost and waste without the new controls in place).

This activity should be documented on the audit file.

Indicators of Risk 2010


There are certain indicators that can alert the auditor to potential risk situations. Analysis of data may produce
information that does not look right. Managers are often aware of high-risk situations and will assist the auditor to
identify areas needing examination. This is more likely if the manager sees the auditor as an ally rather than a critic
and feels comfortable confiding with the auditor.

Some examples of risk that can be encountered are:


a) Processing risk;
b) Programme risk;
c) Regulatory risk; or
d) Risk of fraud.

Processing risk. Errors can occur inadvertently, especially in situations such as the following:
a) A new government programme where there is little experience in administering it, or the entity has taken over
responsibilities for a new function and the previous administrators are no longer involved.
b) New systems or procedures are introduced, especially a new computerised system.
c) There have been recent changes in management or there is a high turnover of staff (in other words, there is a
poor corporate memory), particularly if administrative procedures are poorly documented.
d) There are unclear responsibilities.

If the process involves large transactions, the risk of inadvertent loss or waste can be serious.

Programme risk. Certain government programmes are particularly susceptible to significant losses, either intended
(fraud) or unintended (the result of poor administration).

Examples of programmes that should be given a careful assessment of risk are:


a) Loans or guarantees, which, by their very nature, usually place the government at risk.
b) Programmes delivered by means of contracts, especially where there are unclear terms and conditions,
insufficient specifications / performance requirements.
30

c) Research and development projects, where often the results are difficult to predict (especially non-standard
software development).
d) Programmes with vague outputs or outcomes, where in return for the government’s expenditures, the benefits
are difficult to identify.

Large expenditures in programmes of such nature should be a high priority for the auditor to examine.

Another aspect of risk relating to programme performance is the risk that adverse publicity can arise. The danger of
criticism of a programme can be out of proportion with the potential or actual loss occurring due to some weakness in
the administration of the programme. There is often a trade-off between the economic and efficient management of a
programme and the cautious avoidance or mistakes that can lead to embarrassment. The auditor should be sensitive to
this and be able to judge what are appropriate levels of control.

Regulatory risk. One means of implementing government policy is through regulatory activities. The usual purpose of
regulations is to protect the public – whether this is health protection, ensuring fair trade practices, transportation
safety, or other law enforcement.

Failures in a government’s regulatory programme can occur at various points within the regulatory system. For
example, regulatory risk can derive from:
a) inadequate laws;
b) inadequate inspection/detection (insufficient resources available; untrained inspectors; poor supervision of the
inspectors);
c) inadequate penalties or other deterrents;
d) poor records and inadequate statistics; and/or
e) environmental factors outside of the regulatory process that impact on the effectiveness of the regulatory
programme.

The impact of regulatory weaknesses on government operations can be significant, although not as obvious as
misappropriations of funds, waste or loss of monies. For example, the non-collection of taxes can represent a huge loss
to the government. Therefore the auditor must focus on regulatory activities just as much as on expenditures.

Risk of fraud. 2016There are many classical indicators of weaknesses that can contribute to fraud. Some of these are:
a) Insufficient separation of duties;
b) Only one person with access to financial information, particularly if this person exhibits defensive or guarded
behaviour;
c) Weak controls;
d) Inadequate management supervision, inspection, challenge or review;
e) Inadequate or untimely reports; and,
f) Late or non-existent reconciliations.

It is often beneficial to provide all auditors with some training in fraud awareness and investigation, and to provide
extensive Forensic Audit training to one or a few auditors. Then one of those who have had extensive training and
experience can be consulted wherever any serious case of fraud has been identified or is suspected.
31

Factors Affecting Audit Risk

To determine how much risk the auditor should accept that an unqualified opinion may be issued on financial
statements that are materially misstated, the auditor would consider such matters as 1) professional
exposure, 2) reporting considerations and 3)ease of audit.
1. Professional Exposure
This is the risk of loss or injury to the auditor's reputation from litigation, adverse publicity or other events arising in
connection with the financial statements reported upon.

Professional exposure risk is often considered to be highest when there is a good chance that the financial statements
and the audit report thereon will undergo a lot of scrutiny. This could occur in special situations such as when an
entity is:
a) Receiving a lot of bad publicity for an authority violation or other matter;
b) Being privatised, transferred to another level of government, or turned into a special operating agency;
c) Issuing new debt; and/or
d) Getting into financial difficulty.

For audit entities such as these, the auditor may elect to reduce their audit risk to reduce their professional exposure
risk.
2. Reporting Considerations
These considerations usually include the number of users and the extent to which they rely on the entity's
financial statements and audit report.

3. Ease of Auditing
Factors to be considered here could include the practical availability of audit evidence and the existence of an
audit trail.

Determining Audit Risk


Even though the determination of audit risk is the auditor's responsibility and not the financial statement users,
it may be prudent to discuss the factors affecting audit risk and the assessed level directly with the users. There
are several reasons for this:
a) One of the factors affecting the required level of audit risk is the extent to which the users rely on the entity's
financial statements and audit report. If the users are placing extensive reliance on the financial statements,
the auditor may wish to use a lower level of audit risk (i.e., obtain a higher level of overall assurance) than if
the users are placing very little reliance on the financial statements. Discussing the level of audit risk with the
users will provide the auditor with direct evidence with respect to this factor.
b) Some of the users, such as government planners and managers as well as legislators, may be aware of special
circumstances that could increase the auditor’s professional exposure risk. These may include circumstances
of which the auditor is not aware.
32

Step 4: Understand the Entity’s Internal Control Structure


Definition and Concepts of Internal Control

INTOSAI defines the internal control structure as the plans and actions of an organisation, including management's
attitude, methods, procedures, and other measures that provide reasonable assurance that the following general
objectives are achieved: 2016+14
a) Assets are safeguarded against loss due to waste, abuse, mismanagement, errors, and fraud and other
irregularities;
b) Laws, regulations, and management directives are complied with; and
c) Reliable financial and management data are developed, maintained and fairly disclosed in timely reports.

General Standards for an Internal Control Structure 2013

INTOSAI describes five general standards that entity management and employees should follow:
a) Reasonable assurance. Internal control structures are to provide reasonable assurance that the general
objectives of the entity will be accomplished.
b) Supportive attitude. Managers and employees are to maintain and demonstrate a positive and supportive
attitude toward internal controls at all times.
c) Integrity and competence. Managers and employees are to have personal and professional integrity and are to
maintain a level of competence that allows them to understand the importance of developing, implementing
and maintaining good internal controls, and to accomplish the general objectives noted in paragraph 7.4.1.
d) Control objectives. Specific control objectives are to be identified or developed for each activity of the
organisation and are to be appropriate, comprehensive, reasonable, and integrated into the overall
organisational objectives.
e) Monitoring controls. Managers are to continually monitor their operations and take prompt, responsive action
on all findings of irregular, uneconomical, inefficient, and ineffective operations.

Detailed Standards for an Internal Control Structure 2018


In addition, INTOSAI describes six detailed standards that entity management and employees should follow:
a) Documentation. The internal control structure and all transactions and significant events are to be clearly
documented, and the documentation is to be readily available for examination.
b) Prompt and proper recording of transactions and events. Transactions and significant events are to be
promptly recorded and properly classified.
c) Authorisation and execution of transactions and events. Transactions and significant events are authorised
and executed only by persons acting within the scope of their authority.
d) Separation of duties. Key duties and responsibilities in authorising, processing, recording, and reviewing
transactions and events should be separated among individuals.
e) Supervision. Competent supervision is to be provided to ensure that internal control objectives are achieved.
f) Access to and accountability for resources and records. Access to resources and records is to be limited to
authorised individuals who are accountable for their custody or use. To ensure accountability, the resources are
33

to be periodically compared with the recorded amounts to determine whether the two agree. The asset's
vulnerability should determine the frequency of the comparison.

Responsibility for Maintaining Internal Controls

Entity management is responsible for ensuring that a proper internal control structure is instituted, reviewed, and
updated to keep it effective.
It is then the responsibility of everyone in the entity to ensure that the internal control structure functions as it
should.

the Controller General of Accounts has some responsibility for maintaining an environment which promotes
adequate internal control. Section 5(d) of the Controller General Ordinance states that one of the functions of the
Controller General shall be “to lay down the principles governing the internal financial control for Government
departments in consultation with the Ministry of Finance and the Provincial Finance departments as the case may be”.

The Elements of Control 2021+2016


There are five basic elements that make up a control structure:
a) Control environment;
b) Risk assessment;
c) Control activities;
d) Information and communication; and
e) Monitoring.

Control environment. The control environment sets the tone for an organisation, influencing the control consciousness
of the staff. It relates to:
a) Management’s philosophy and operating style, including the specific way in which staff are supervised and
controlled;
b) The organisation structure;
c) Methods of assigning authority and responsibility;
d) Human resource policies and practices;
e) Management’s and staff’s integrity and ethical values;
f) Management’s and staff’s commitment to competence;
g) Management’s reaction to change and outside influences; and
h) Existence of an internal audit unit.
Risk assessment. Risk assessment is the identification and analysis of relevant risks to the achievement of objectives.
Management needs to identify these risks in order to know the areas in which the internal control structure needs to be
particularly strong. Conversely, risk assessment may indicate areas where risks are low, and therefore where the entity
does not need to design elaborate internal control structures.

Control activities. Control activities are the policies and procedures that help ensure management directives are carried
out. They help ensure that necessary actions are taken to address the identified risks.

Control activities occur throughout the organisation, at all levels and in all functions. They include a range of
activities such as:
a) Proper authorisation of transactions and activities;
b) Physical control over assets and records;
c) Independent checks on performance; and
34

d) Adequate segregation of duties.

Information and communication. Pertinent information must be identified, captured and communicated in a form that
enables people to carry out their responsibilities.

To have pertinent information for accounting purposes, the entity needs to have adequate documents and records. It
also needs to have prompt and proper recording of transactions and activities. This, in turn, requires a good accounting
system, and a good system of communication within the organisation and with customers, suppliers, and other
government entities.

Monitoring. Monitoring by management involves the ongoing and periodic assessment of internal control performance
to determine if controls are operating as intended, and are modified when needed. Summary information should be
monitored and spot checks made on the quality and timeliness of the information on selected transactions.

The Role of Internal Audit

Internal audit is in itself an internal control. It acts as an independent check on performance. It can be very effective in
helping management fulfil its monitoring role.
To be most effective, internal audit must not become part of the operational controls. The internal audit unit should not
be performing checks on an ongoing basis. It should audit and review after the fact, or as a separate, independent and
additional check, to ensure that the management and staff have been carrying out their duties properly.

Categories of Controls 2021


Controls can take different forms and serve different purposes. Different ways of categorising controls are:

a) Input vs. output;


b) Independent vs. interrelated;
c) Manual vs. electronic;
d) General vs. application;
e) Documented vs. undocumented;
f) Preventive vs. detective; and
g) Compensating.

Input vs. Output


Input controls are controls over the initial input of data. They include password controls to prevent
unauthorised personnel from inputting transactions. Output controls are controls over the output from systems. They
include comparing cheques (output of payment system) to supplier invoices and other supporting documentation, and
reviewing printouts of cash disbursements to ensure that all pre-numbered cheques have been recorded.

Independent vs. Interrelated


A control may work on its own or may need to be part of a series of controls. For example, a reconciliation
may be a powerful control in its own right, but an input control will really only be effective if the entity also has
adequate controls over data processing and output.
35

Manual vs. Electronic


Manual controls, given the fact that they are operated by staff, can be affected by human errors of judgment,
misinterpretation, carelessness, fatigue, and distractions.
In contrast, electronic controls are built into computer programmes and, assuming that the systems are properly
designed, installed and tested, are inherently more reliable. Any problems with the software, however, might be
difficult to detect and often expensive to correct.

General vs. Application


General controls are applicable to the accounting system as a whole, such as passwords restricting access to a
computer network. Application controls relate specifically to a particular processing function to ensure transactions are
authorised, complete and accurate.

Documented vs. Undocumented


Documented controls result in evidence that the control has been performed (e.g., signatures and initials).
Undocumented controls are controls where there is no evidence that the control has been performed. These would
include, for example, many electronic controls where there is no evidence that the appropriate person approved the
transaction. The existence of these controls can often be established through observation, inquiry and
testing/replication.
Another example is when management and staff of an entity follow sound control principles based on experience.
Sound controls may be in place but not documented. This presents a control exposure since the control procedures
may be lost when staff turnover occurs.

Preventive vs. Detective


Preventive controls prevent errors from occurring. Most data entry controls are preventive controls. In contrast,
detective controls detect errors that have occurred. Most output controls and reconciliation controls are detective
controls.
Preventive controls are usually less costly to use than detective controls. It is generally less costly to prevent an error
than it is to detect and correct it after the fact. It is possible, however, to find systems that are so strict in preventing
errors that a lot of valid data can be rejected because of minor errors or missing data elements. This can cause serious
delays and expense in processing data.

Compensating Controls
These are controls that detect errors that occur at earlier control points.

As a general rule, a control over output can act as a compensating control for a weak input control. For example, a
control to review the list of cash disbursements to ensure that there are no missing cheque numbers can compensate for
a weak control over the input of the disbursements. Similarly, if a cheque is recorded for an incorrect amount, the error
will show up when the organisation performs the bank reconciliation. (This assumes that the cheque has been cleared).

Limitations of Internal Control Structures 2014


Internal control can help an entity to:
a) achieve its objectives;
b) comply with laws and regulations;
c) ensure reliable financial reporting; and
d) prevent loss of resources.
36

No matter how well conceived and operated, an internal control structure can only provide reasonable – not
absolute – assurance to management regarding the achievement of its objectives, etc. There are limitations inherent in
all internal control structures. These include the realities that judgments in decision-making can be faulty, and that
breakdowns can occur because of simple errors or mistakes.

Additionally, controls can be circumvented by the collusion of two or more people, and management has the ability to
override the system. In addition, the design of an internal control structure must reflect the fact that there are resource
constraints, and the benefits of controls must be considered relative to their costs.

Multiple Sub-Entities and Locations


In the case of government-wide audits there will be multiple ministries, departments, etc. making up the
reporting entity. Each of these may have multiple locations.

There is no requirement for the auditor to take the same approach with respect to each ministry and so on. The
auditor may decide to place no reliance on the internal control structure at some Drawing and Disbursing Offices, but
place a lot of reliance on some specific controls at the District Accounts Offices. In this case:
a) For the DDOs, the auditor would only need an overview level understanding of controls and a general
understanding of the systems to collect, record and process data and report on the results.
b) For the District Accounts Offices, the auditor would need a more detailed understanding of the control
environment and systems, to justify placing reliance on them.

In terms of level of effort, the auditor should already have a good understanding of the internal control
structure through prior compliance with authority work. Where a given sub-entity is small compared to the
materiality amount, a deep level of understanding is not required.

Understanding and Examining Internal Controls 2018+17

The auditor is expected to review the internal controls as part of the audit.

First, the auditor should review and document the systems and procedures in place to carry out the
transactions and other activities of the operations. Normally, a description of the major systems and procedures should
be maintained on the permanent audit file. In which case, the auditor should review the description of the system and
identify whether there have been any changes to the system.

Next, the auditor should identify points in the accounting system, and in other systems being audited, where he/she
would expect to find controls.

Then the auditor should identify and document the controls at these points and determine that the controls have been
operating.
37

Finally, the auditor should assess the adequacy of the controls and conclude whether any controls are missing or
ineffective. The auditor should make recommendations to management where, in the opinion of the auditor, the
controls should be strengthened. These recommendations should be based on an appreciation of the risk of reduced
performance, loss, damage or waste compared to the additional costs, if any, of implementing improved controls.

Documenting Our Understanding of Controls


The auditor should document the internal controls as part of the audit. A clearly documented description of the
controls enhances the auditor’s ability to assess the controls. Also, the documentation aids supervision of the audit and
improves communications between members of the team. The documentation should form part of the working papers
and should be included on the permanent file.

Methods of understanding the system and application of controls include: 2018+2015


a) Narrative;
b) Flowchart;
c) Internal Control Questionnaire (ICQ); and
d) Walk-through.

Narrative. This is a written description of an entity’s internal controls. Narrative of an accounting system and related
controls includes four characteristics:
a) Information on the origin of every document and record in the system;
b) Description of all processing that takes place;
c) The disposition of every document and record in the system; and
d) An indication of the controls relevant to the assessment of control risk - these typically include separation
of duties, authorisation and approvals and internal verification.

Flowchart. This is a time-consuming exercise and is generally applied only when the effort can be justified, such as
when there is some uncertainty about the processes or the complexity and importance of the procedures indicate a need
for clear representation.

The flowchart is a diagrammatic representation of the entity’s documents and their sequential flow in the organisation
and can be a valuable component of the working paper file. It includes the same four characteristics identified above
for narratives.

The advantages of a flowchart are that it:


a) provides a concise overview of the entity’s system;
b) helps identify inadequacies by showing how the system operates;
c) shows clearly the separation of duties allowing the auditor to judge whether they are adequate; and
d) is easier to follow a diagram than to read a description.

Internal Control Questionnaire. The ICQ is a common tool of the auditor. It contains a series of questions about the
controls in each audit area. There is usually a pre-developed ICQ that may, or may not be tailored for the particular
area under examination by the auditor. It is designed to require a “yes” or a “no” response, with a “no” response
indicating potential internal control deficiencies. IMP

The advantage of using the ICQ is it allows the auditor to thoroughly cover each audit area reasonably quickly at the
beginning of the audit.
38

The disadvantages are:


a) The individual parts of the entity’s systems are examined without providing an overall view;
b) A standard questionnaire may not apply to all audit entities; and
c) There is a danger of taking a mechanical approach rather than thinking through the control needs of the
particular operations under examination.

Walk-Through (Cradle to Grave Test). The walk-through is conducted to confirm that the system and controls are
operating in accordance with the auditor’s understanding. It is used to verify that identified controls have been put into
operation.

To conduct a walk through test the auditor selects a few transactions (generally between 3 and 6), pertaining to each
significant transaction cycle, and traces them through the cycle beginning with initiation of the transaction, through
processing until it is ultimately summarised and included in a general ledger or management report.

The auditor should document the transactions selected for walk-through, the controls that were observed and describe
any enquiries made of client personnel.

Step 6 – Determine financial audit and compliance with authority


objectives, and error/irregularity conditions
Specific Financial Audit Objectives

Having divided the audit into components, the next step is to define what we mean by “properly presents” in the audit
certificate. To do so, the auditor needs to consider what he/she would consider to be an error.

For a financial statement audit, a component is considered to be in error if: 2016+15+14


a) it is not valid (the asset or liability does not exist or the revenue or expenditure has not occurred
b) the asset, liability, revenue or expenditure is not complete;
c) the transactions have not been carried out in proper compliance with relevant laws, regulations and
administrative rules;
d) the asset or liability is not properly valued or is misclassified, or the revenue or expenditure is not properly
measured or is misclassified; or
e) the financial statement presentation is not proper.

To illustrate, payroll expenditures may be materially misstated if:2014


a) the costs are not valid. This could be due to, among other things, ghost workers on the payroll.
b) the costs are not complete. For example, employees have not been paid, or the payments have not been
recorded.
c) the costs are not properly measured. This could be due to paying employees more or less than they should be
paid, or the amounts being recorded being more or less than the actual payments.
d) the financial statement presentation is not proper. This could be due to the failure to disclose all of the
information called for in the New Accounting Model.

Spend 2013
Determine that:
a) the services were actually performed or the goods were actually received;
39

b) the expenditure is consistent with the nature of the appropriation to which it was charged;
c) the expenditure does not result in the total approved expenditure being exceeded; and
d) the expenditure is in accordance with the applicable legislation and the rules and regulations issued by such
legislation have been complied with.

Borrow 2013

Determine that the amount and debt terms (period, interest rates, repayment schedule, etc.) are in accordance
with the appropriate law.

Raise revenue
Determine that the cash received is:
a)for an approved tax or other approved revenue source; and
b) is received in accordance with the applicable legislation and the rules and regulations issued by such
legislation have been complied with.

For the completeness of payroll expenditures, the auditor considers how payroll expenditure figures might not be
complete and may identify the following three error conditions:
a)Services performed have not been paid for;
b) Payments made have not been recorded in the payroll register; and
c)The amounts in the payroll register have not been included in the financial statement amounts

Step 7 – Assess inherent risk and control risk 2016


Inherent risk and control risk may differ by component and audit/compliance objective. As a result, the auditor may
have a large number of different inherent and control risk valuations to deal with.

It is tempting to combine different risks by using a weighted approach. However, this approach is not generally
recommended as it fails to meet the standards for generally accepted auditing standards.

Inherent Risk 2013+2014

Inherent risk is the chance of material error occurring in the first place assuming that there are no internal
controls in place. “Material error” may be one error or the sum of multiple smaller errors.

Inherent risk is evaluated at this stage to determine how much testing of internal controls and substantive testing
(analytical procedures and substantive tests of details) the auditor needs to perform to achieve the desired level of
assurance. In general, the greater the inherent risk, the greater the audit effort required. 2013
40

Inherent risk is assessed assuming that there are no internal controls in place. As such, it needs to be assessed in a
hypothetical environment.

Factors affecting inherent risk include: 2013+2009

The nature of the component. Components such as cash are more susceptible to manipulation or loss than, say, fixed
assets.

The extent to which the items making up the component are similar in size and composition. If the population is
composed of relatively homogeneous items, it would be easier for management (and the auditor) to detect anomalous
transactions and amounts.

The volume of activity. If there are a lot of transactions being processed, the chances of an error occurring may be
higher than if only a few transactions are being processed.

Competence of the staff processing the transactions. If staff are experienced and take their jobs seriously, there is
probably a lower inherent risk than if they are inexperienced or careless.

The number of locations. Entities operating out of a single location with a centralised accounting system may have a
lower inherent risk than those operating out of many locations, each with its own accounting system.

The accounting policies being used. Many components have a lower risk of error when the cash basis of accounting is
being used than when the accrual basis of accounting is being used.

Factors that could affect the risk of fraud. An error could be an intentional one. The auditor should use a questioning
mind and be alert for evidence that contradicts or brings into question the reliability of documents or management’s
representations.

Resulting
Level of Inherent Risk Risk Assurance
High inherent risk 60% 40%
Moderate inherent risk 50% 50%
Low inherent risk 40% 60%
.

Control Risk 2014+13+17

Control risk is the chance that the entity’s internal controls will not prevent or detect material error and is directly
related to the effectiveness of the internal control structure.

Control risk is evaluated at this stage as it limits the amount of assurance that the auditor can obtain from tests of
internal control.
41

While guidelines should not replace the use of professional judgment, the following may be useful when assessing
control risk:

Resulting
Level of Control Risk Risk Assurance
High (poor internal controls) 80% Up to 20%
Moderate (moderate internal controls) 50% Up to 50%
Low (strong internal controls) 20% Up to 80%

Step 8 – Determine mix of tests of internal controls, analytical


procedures and substantive tests of details
Introduction
Financial audit procedures are usually broken down between tests of internal control and substantive tests
supplemented with compliance with authority tests. DAGP also conducts audit activities which focus exclusively on
compliance with authority testing.

Tests of internal control are used to gain assurance that specific controls within the entity’s internal control structure
are operating effectively, and are therefore helping to reduce the chance of material error existing in the accounting
information.

Substantive tests are procedures used to gain direct assurance as to the completeness and accuracy of the data
produced by the accounting systems. They are often broken down between analytical procedures and substantive tests
of details.

Audit procedures that provide both assurance with respect to internal controls and substantive assurance are often
referred to as “dual purpose” tests.

Compliance with authority procedures are used to determine whether entity staff have fulfilled the administrative
requirements of all applicable rules, regulations and legislation.

Tests of Internal Control


Tests of internal control include:
a) Inquiries of appropriate entity personnel;
b) Observation of policies and procedures in use;
c) Walk-through procedures; and
d) Selecting a sample of transactions and verifying that the appropriate control procedures were followed.

.
GAAS do not permit the auditor to obtain all of his/her assurance through tests of internal control – some substantive
testing must always be performed. This is because the ability of the internal control structure to prevent or detect
material error is subject to practical limitations, such as:
a) Members of management may be in a position to override specific internal controls.
b) Collusion can circumvent internal controls that depend on good segregation of duties to be effective.
c) Inexperienced entity officials may not perform their control procedures properly. There is always a possibility
of human error.
42

d) Internal controls are often designed to address transactions arising from the normal course of the entity’s
activities. They may not cover transactions of an unusual nature, or arising from new activities.
e) Management may not be prepared to devote the resources that would be required to prevent or detect all errors.
Rather, management normally requires that the internal controls be cost-effective. This means that the benefits
of having the controls must exceed their costs.

Analytical Procedures 2021+2017


Analytical procedures are techniques used by the auditor to:
a) Form expectations as to what the recorded amounts should be by studying the relationships among elements of
financial and non-financial information;
b) Compare those expectations with the recorded amounts; and,
c) Draw conclusions about entity operations, inherent risk and control risk, and the completeness and accuracy of
the recorded amount.

Analytical procedures are an efficient and effective way to obtain audit assurance. As a result, they should be
performed on every audit.

Analytical procedures may be used in all phases of the audit to achieve various objectives, for example: 2018

Planning phase:
a) to obtain knowledge of the entity’s business operations;
b) to identify unusual items and explore areas of potential high inherent risk; and
c) to obtain some degree of audit assurance.

Fieldwork phase: to obtain some degree of audit assurance.

Evaluation phase:
a) to assess the internal consistency and overall reasonableness of the financial statements using the auditor's
knowledge of the entity; and
b) to obtain some degree of audit assurance.

The auditor can derive various levels of assurance from analytical procedures depending on how rigorously the
analytical procedures are designed and performed.

There are several different types of analytical procedures, as follows: 2017+2021

General reviews for reasonableness.


These analytical procedures involve a high level comparison of current information with previous periods, budgets or
statistics from the entity. No pre-determined threshold amount is specified for identifying significant fluctuations. The
process is sometimes referred to as “eyeballing” the financial statements – looking for accounts that appear to be
unusual in amount, in volume of activity, etc. The objective of this type of analysis is generally to decide where to
focus audit attention.

Comparative analysis.
43

This involves comparing the current year's reported amounts (or ratios) with those of the prior years. Comparative
analysis assumes that the prior year's amount is a sufficiently accurate estimate of the current year's amount and,
therefore, can be used to identify any significant fluctuations from the current year's recorded amount. A pre-
determined threshold amount is specified for identifying significant fluctuations.

Predictive analysis.
Predictive analysis compares the current year's reported amounts (or ratios) with a prediction of what the current year's
amount (or ratio) should be, based upon the trend of the prior years’ amounts (or ratios). The prior years’ data used in
making the prediction is adjusted for all known changes in the factors affecting the data. This usually results in a more
precise estimate than comparative analysis. A pre-determined threshold amount is specified for identifying significant
fluctuations.

Statistical analysis.

This category of analytical procedures involves analysing the known behaviour of variables and developing an
equation (model) that explains the relationship between these variables. Although this category is similar to "predictive
analysis", the distinguishing characteristics of statistical analysis is that it uses more rigorous methods, such as
regression analysis, to provide more accurate predictions and objectively measures the confidence level and the
achieved level of precision.

Overall verification procedures.

This category of analytical procedures involves building up an estimate of an account balance from known and
verified data. For example, the auditor could verify the number of rental units by type of unit, the average rent by type
of unit, and the vacancy rate. The auditor could then compare the product to the revenue received from the rents.
Overall verification procedures usually result in an accurate estimate of the account. A pre-determined threshold
amount is specified for identifying significant fluctuations for the auditor to investigate.

Care is required with this type of analysis. The auditor must not assume that the data are more accurate than the
financial information. For example, the actual vacancy rate may be lower than the recorded vacancy rate, with the
difference being due to fraud. Thus the analytical data might substantiate the financial data, while income being
received is less than income due. The auditor should therefore test whether sources of information are independent or
might be subject to the same potential errors.

Appendix B discusses each of these types of analytical procedures in detail. The discussion includes a description of
how the auditor normally determines the pre-determined threshold amount.

The following table provides guidance as to the amount of assurance that each category of analytical procedure can
provide. While guidelines should not replace the use of professional judgment, the following is typical:

Type of Analytical Procedure Risk Assurance

Overall reviews for reasonableness 100% 0%

Comparative analysis 70% or more Up to 30%

Predictive analysis 50% or more Up to 50%


44

Statistical analysis 30% or more Up to 70%

Overall verification procedures 10% or more Up to 90%

The Audit Risk Model 2014+2015

The audit risk model is a useful way to tie together all of the various sources of audit assurance.

The basic theory behind the audit risk model 2019


is that, for errors adding up to more than materiality to remain in the accounts at the end of the audit (audit
risk - AR), all of the following must have happened:
a) The errors must have occurred in first place (inherent risk - IR);
b) The internal controls must have failed to prevent or detect the errors (control risk - CR); and
c) The auditor’s substantive procedures (analytical procedures and substantive tests of details) must have
failed to detect the errors (detection risk - DR).

Basic probability theory states that, if two events are mutually exclusive (the occurrence of one is not affected by the
occurrence or non-occurrence of the other), then the probability of both events occurring is the probability of the first
event occurring times the probability of the second event occurring.

All of the events in paragraph, as defined, are mutually exclusive, and all must occur before errors adding up to more
than materiality remain in the accounts at the end of the audit. We therefore have the following formula:

AR = IR x CR x DR; where:
AR = Audit risk;
IR = Inherent risk;
CR = Control risk (achieved); and
DR = Detection risk.

The reason for qualifying the control risk as being “achieved” is because the auditor needs to validate his/her control
assurance. What goes in the risk model is the converse of the achieved assurance.

The audit risk model is often expanded upon to split detection risk (DR) into two parts. This is done for two
reasons:

1. Analytical procedures are often effective and efficient at obtaining audit assurance. As a result, they
should normally be performed on every audit. The assurance to be achieved from these procedures needs
to be reflected in the risk model;

2. The auditor often performs more than one substantive test of detail to obtain the required assurance with
respect to each specific financial audit objective and related compliance with authority objective. To link
the risk model to the confidence level to be used for one key substantive test of details, these other
substantive tests of details need to be considered separately.
45

It is done as follows:
AR =IR x CR x DR
= IR x CR x OSPR x STDR; where:
AR = Audit risk;
IR = Inherent risk;
CR = Control risk (achieved);
OSPR=Other substantive procedures risk, being the risk that the auditor’s analytical
procedures, and all substantive tests of details expect one key substantive test of
details, will fail to detect material error; and
STDR =Substantive test of details risk, being the risk that one key substantive test of details
will fail to detect material error.

The reason for splitting out one key substantive test of details in this manner is that the formula can be rearranged as
follows:

STDR = AR .
IR x CR x OSPR
The resulting STDR is the converse of the confidence level that the auditor will use for his/her substantive sample. For
example, if STDR is determined to be 15%, the auditor will use an 85% confidence level for his/her sampling
procedures.
46

6 ACTIVITY AND RESOURCE Planning for Individual


Factors to Consider

When assigning specific staff to audits consider the following: 2018+2014


a) The required skill mix for each specific audit. Ensure that each audit team is composed of staff members
with the technical and supervisory skills that are required to complete the audit.
b) The needs of all the audits in the directorate. Better auditors should be assigned to the more difficult and
risky assignments.
c) The audit deadline. Should the deadline date for an audit be moved forward, the auditors may have less time
after the year end to complete their audit. This may necessitate adding extra staff to the audit to complete it in a
shorter period of time.
d) Audit continuity. Having at least some of the audit staff members return to perform work on the entity the
next year will help to ensure that the audit team has the required knowledge of the entity.
e) Rotation. Changing audit staff every few years can add new ideas to the planning and performance of the
audit. It can also help to ensure that the auditors remain independent of the entity being audited.
f) Learning and advancement. While it is beneficial for some staff to return to an entity, it’s also advantageous
to give them more challenging work each year. At the same time, they could provide advice and assistance to
the more junior auditors who are performing the work that they performed in the previous year.

Factors to Consider

The following factors should be considered when setting the budgets:


a) size of the entity;
b) complexity of the entity and its transactions;
c) audit risk;
d) inherent risk;
e) quality of the internal control structure; and
f) experience of the staff performing the audit.

Each of these is discussed below.

Size of the entity. The size of the entity may only have a limited effect on the required budget. This is because, as the
entity being audited gets bigger, the materiality amount may increase proportionately. The sample size required to
audit the expenditures in a small entity may be just as large as the sample size required to audit the expenditures in a
large entity.

The complexity of the entity and its transactions. This will likely have a considerable impact on the budget. Some
entities are inherently complex, and the substance of their transactions may be difficult to determine. Entities such as
these could require a much larger budget than entities that are straightforward.
47

Audit risk. The lower the audit risk being taken, the more assurance is required. Reducing audit risk from 5% to 3%,
for example, could add 20% to the total required audit work.

Inherent risk. The higher the assessed inherent risk, the more assurance the auditor needs in total from his/her tests of
internal control, analytical procedures and substantive tests of details. Also, the auditor may need to use a higher
expected aggregate error when determining planned precision, further increasing the required amount of work.

The quality of the internal control structure. It is often more efficient to place a lot of reliance on the internal control
structure and reduce the substantive tests of details. Should this not be possible because the internal controls are poor
(control risk is high), the auditor may need to increase the budget. Also, the auditor may need to use a higher expected
aggregate error when determining planned precision, further increasing the required amount of work.

The experience of the staff assigned to the audit. More experienced staff should be able to complete the work in a
fewer number of hours.

The Use of Interim Audits 2009 Defination

An “interim date” is a date in advance of the year-end date. An “interim audit” is an audit performed at an interim date.
To illustrate, the auditors could decide to perform an audit of the transactions for the first six months of the year (1
July to 31 December) in the following February and March. They could then return to the entity in May to do the next
three months (1 January to 31 March). They could then return again after 30 June to complete their audit.

The work performed at an interim date could include:


a) Auditing a sample of revenue and expenditure transactions up to the interim date. A sample of the transactions
for the rest of the year could then be audited at a later interim date, or after the year-end.
b) Reviewing and testing the entity’s internal control structure. Enquiries, observations and walk-through
procedures could then be performed at the year-end date to ensure that the internal controls had not
deteriorated.
c) Note: When high reliance is being placed on the internal controls, the auditor normally needs to also sample
the transaction between the interim date and the year-end date.
d) Discussing accounting policies, the form and content of the financial statements, contentious authority matters,
etc. with entity officials. This could avoid having to deal with these matters at the end of the audit.

Factors to consider when determining the optimum timing


The key benefit of using interim dates/audit is:

To improve the timeliness of the audit reports.

Another benefit of using an interim audit is that it can provide the auditor with an earlier indication that the
planning decisions may need changing. For example, the auditor may have intended to place a lot of reliance on the
internal controls, but may find at an interim date that the controls are not reliable. The auditor would then be able to
amend the audit plan well before the year-end date.

A further benefit of performing an interim audit is that it may solve staffing problems. The required staff may not
be available to do all of the audit work after the year-end date. Also, there may be a need to do some of the work
before the year-end to keep all of the staff fully occupied.
48

The major drawback of doing some work at an interim date is that it may add to the cost of the audit. If, for
example, the bank reconciliations were verified before the year end, the auditor would normally need to review the
transactions that took place between the date of the in term work and the year end.

7. Conducting the Audit


Introduction
By the end of the planning phase and after completing the detailed activity and resource planning work, the auditors
will have updated the:
a) Permanent file;
b) Planning file;
c) Audit planning memorandum;
d) Audit programmes;
e) Staffing requirements, and the staff to be assigned to each component of the audit;
f) Budget requirements;
g) Timing considerations; and
h) List of information to be obtained from entity officials.

Compliance Testing

In conducting the audit, the first step is to evaluate the effectiveness of internal controls. This is done through
compliance testing. During the planning phase, the auditor will have assessed the appropriateness of internal controls
and made an initial judgment as to the extent to which the auditor can rely on the internal controls when deciding on
the sample sizes to take for detailed testing of transactions. 2013

To determine how well internal controls are being applied, the auditor should test the controls with a sample of
transactions. The sample taken for compliance testing will usually be part of the sample required for substantive
testing (see later).

Generally, for compliance testing, basing the assumptions on a zero deviation (or error) rate and a tolerable rate of 5%,
the auditor would take a sample size of between 30 and 60. Thus, with a sample size of, say, 45 items, if the auditor
finds no errors, then the controls can be assessed as having a low control risk. If in this sample, one error is found,
then the auditor can determine control risk is moderate. If, however, more than one error is found in the sample, the
auditor cannot place much reliance on the controls (and therefore would increase the amount of substantive testing).

Compliance tests are designed to determine whether the controls are effective. Any significant misstatements or
instances of non-compliance should lead the auditor to identify weaknesses in controls, report the specific weaknesses
in the controls, consider the implications on the financial statements and reconsider the extent of reliance on the
controls (and therefore the size of sample needed for direct testing of transactions).

A similar approach is taken to sampling and testing compliance with authorities, authorities being one specific type of
internal control over the entity’s operations.
49

Substantive Testing
For financial audit purposes, substantive testing is required to determine how much assurance can be placed on
financial assertions. Some testing is by analysis and other procedures but most assurance is provided through detailed
testing of sampled transactions.

Substantive Analysis

Substantive analysis is a means of deciding whether financial data appear reasonable and acceptable and therefore may
allow the auditor to conduct less detailed testing of transactions. The extent of reliance on substantive analysis
procedures depends on the following factors:
a) Materiality of items involved in relation to the financial information taken as a whole (if the amount is high,
the auditor does not rely on analytical procedures alone in forming an opinion);
b) Other audit procedures relating to the same audit objectives;
c) The likely level of precision and reliability that can be obtained from the analysis (for example, if the
construction of a road is through uniform terrain, a unit cost per kilometre can be applied to provide a
reasonable estimate of expected cost; however, such an analysis would not likely provide a reliable figure if the
road is constructed through variable terrain of mountains and plains);
d) Results of the evaluation of internal controls. If the internal controls are assessed as weak, more reliance
should be placed on tests of detailed transactions than on analytical procedures.

Tests of Details

Tests of details are the application of one or more of the following audit techniques to individual transactions
that make up an account balance: 2021+19+16+15+13
a) Recomputation;
b) Confirmation;
c) Inspection; and
d) Cut-off tests.

Recomputation provides strong evidence of the arithmetical accuracy of the tested operations. It cannot, however, by
itself provide evidence as to the existence, completeness, accuracy or authorisation of components of the computation
and should therefore be supplemented by other procedures directed to those assertions.

Confirmation generally provides strong and documented evidence from an external source. Confirmation procedures
are used for example to confirm cash at banks or amounts owing by creditors. DAGP should maintain control over the
confirmation letters, mailing procedures and any exceptions throughout the process in order to minimise any
interference by the entity’s management.

Paragraph A1 of the ISSAI 1505 (External Confirmation) and paragraph A48 of ISSAI 1330 (The Auditor’s Responses
to Assessed Risks) state that confirmations can be used to obtain evidence about the presence or absence of certain
conditions (e.g. “side agreements” not included in formal arrangements). In addition to assertions related to the audit of
financial statements, public sector auditors may find confirmations useful in obtaining evidence related to additional
50

audit objectives stipulated by their audit mandate or arising from legislation, regulation, ministerial directives,
government policy requirements, or resolutions of the legislature. For example, external confirmations can be used to
obtain evidence about:

a) The presence or absence in agreements or arrangements with third parties of legislated or other terms and
conditions such as guarantees of performance or funding;
b) The commitment of expenditures that have not yet been authorized by the legislature;
c) The continued eligibility of individuals in receipt of pensions, income assistance, annuities or other ongoing
payments; or
d) The presence of “side deals” with suppliers for the return of goods for credit in order to use funding that would
have otherwise lapsed in a subsequent fiscal period.

Use of templates given in Appendix-G of FAM in conjuction with the relevant audit programs given in the Workin
Paper Kit whereever applicable is mandatory for both compliance and financial audits

Inspection procedures are applied both to assets (to obtain evidence about existence) and to documentation (vouching
as to the accuracy of a recorded transaction, such as the date, party, quantity, unit price, description, total amount and
signature of authorisation). Inspection of assets provides evidence of physical existence but does not normally provide
evidence as to ownership, completeness or valuation of the inspected assets. The collection of further evidence
relating to these can often be designed to be tied into the physical inspection procedures.

Cut-off procedures are tests of transactions occurring close to the cut-off date to ensure that the transactions are
recorded in the correct accounting period.

Selecting items for tests of details


Normally only a proportion of the items within an account are tested even though the auditor wants to conclude
about the account as a whole. 2018+2017+2015+2009

This is done by:


a) Selecting key and high value items; or
b) Taking a representative sample; or
c) A combination of both.

Key items are normally selected when:


a) There is reliance on internal controls and there is substantive audit evidence from analytical procedures (and
therefore require relatively little substantive audit evidence from tests of details); or,
b) A small number of high value items form a large proportion of the account (therefore testing these items will
include a high proportion of the total value of the account); or
c) The population consists largely of non-routine transactions and therefore the account is unlikely to consist of
similar items that could be sampled.

As well as having a high value, key items can be other unusual or suspicious items, such as:
a) multiple transactions with very similar values/dates/suppliers;
b) apparently duplicate transactions;
51

c) items which are unmatched; or,


d) items with other specific characteristics that catch the auditors’ attention.

Representative sampling is likely to be most effective when:


a) There is little or no evidence from analytical procedures so the auditor has to rely on substantive audit
evidence from tests of details;
b) The population contains a large number of individually insignificant items; and/or
c) The population contains routine transactions and therefore the account is likely to consist mostly of similar
items (i.e. a homogeneous population).

Substantive Sampling

It is important to ensure that whatever sampling is chosen, an estimate of the total level of errors in the population can
be deduced from the sample on a scientific basis. Without having a scientifically selected sample that is sufficient and
representative, no assurance on the financial statements can be concluded and no projection of other quantitative
concerns can be concluded.

In implementing a substantive sampling plan, the following need to be considered:


a) Decide what is to be tested;
b) Define the sample and select the sample;
c) Audit the sample items; and
d) Evaluate and interpret the results.
52

Evidence
The auditor requires evidence to support all information presented in the audit report. Even the background description
of the entity and generalised statements about the organisation must be supported by appropriate evidence. The final
audit report must be able to withstand all challenges and the auditor must be able to demonstrate his/her
professionalism in the way the audit is carried out and in the presentation and contents of the final report.

Attributes of Evidence 2016+13+10

To support the auditors’ findings, conclusions and recommendations the evidence must be:
a) Sufficient;
b) Relevant;
c) Reliable; and
d) Objective.

Sufficient. Evidence should be sufficient to lead a reasonable person to the same conclusions as the auditor. The
sufficiency of evidence will be influenced by a wide variety of matters including: 2019
a) The auditor’s knowledge of the entity and its environment;
b) The materiality/significance of the matter in hand;
c) Whether the report is addressing only a limited area of coverage or whether it encompasses all activities and
transactions within a large area of management responsibilities;
d) Whether the audit is providing assurance or just identifying particular weaknesses in need of correction;
e) The degree of risk that insufficient evidence will lead to a misleading statement or conclusion or produce an
inappropriate recommendation;
f) The quality and persuasiveness of the evidence; and
g) The degree of acceptance of the evidence by management.

Relevant. The relevance of audit evidence refers to the relationship of the evidence to its use and applicability. The
auditor should have a clear audit programme with distinct audit objectives. The auditor is expected to collect relevant
evidence to conclude against those audit objectives to complete the audit satisfactorily.

Reliable. The auditor has a professional responsibility to ensure that, as far as possible, the evidence obtained is
reliable. That is to say, the evidence is: 2018+19+16
a) based on fact, not opinion;
b) an accurate reflection of reality;
c) from a reliable source;
d) consistent with other evidence; and
e) remains true for all situations within the audit domain.

Interviews are a source of useful evidence but the auditor should appreciate that often statements are based on
opinions, are not necessarily accurate and may on occasion be intentionally false. Wherever possible, a statement from
an interview should be checked against documented evidence. For example, if the auditor is informed that a particular
transaction was delayed for some time, the documentation of the transaction should be sought to confirm what was
said in the interview.
53

Occasionally, even documented evidence can be unreliable. The auditor should be continually reviewing, questioning
and deciding on the reliability of the evidence. Where the auditor is not satisfied with the reliability of the evidence,
and has not been able to resolve the problems, the best approach is to include statements to this effect in the draft
report and seek management’s assistance in getting the most reliable evidence.

Where there is a good system of internal control, the auditor can be more confident of the reliability of information
produced by the entity than where the internal controls are weak.

A particular type of evidence is the non-existence of something – the lack of an anticipated event or expectation (a
control, a study or some other matter that the auditor is expecting to see). The best the auditor can do is document on
file the efforts made to find the evidence of what the auditor would expect to see in the particular circumstances. If the
auditor does not make the appropriate efforts to find what is considered missing, he/she can be criticised by
management for not making reasonable effort. One approach is to use the “audit query” to seek management’s
assistance. Alternatively, through interviews, briefing and, if necessary, within the draft report, the auditor should draw
attention to the fact that no evidence has been found of what the auditor was looking for.

Objective. To be admissible, evidence should be objective and free from bias. The auditor should always maintain an
open mind with regard to the evidence collected. The auditor should guard against assuming that the initial findings or
assumptions are the only interpretation of the situation. If not, there is the danger that the auditor, most likely
inadvertently, seeks evidence that supports the original perception. Whenever there are contradictions in the evidence
collected, the auditor should not reject certain evidence, but rather seek further evidence to determine which
information is correct, or to obtain an explanation as to why the evidence is not consistent.

Evidence should be evaluated objectively; alternative interpretations of the same evidence should be considered and
inconsistencies in the evidence resolved before reaching final conclusions. Wherever possible, the auditor should focus
on the results and systems, not on the individuals involved. The auditor should endeavour to avoid being influenced by
personalities.

Types of Evidence 2017+2014

Evidence can take the form of observation, documentation, analysis, interview responses, and confirmation through
interview or written response.

Evidence can be classified according to the following:


a) Documentary;
b) Observational;
c) Physical;
d) Oral; or,
e) Analytical.
Documentary. 2014 Although the auditor may rely on interviews for determining where to look and what to look for,
the main source of audit evidence is usually documentary, in either physical or electronic form. Documentary evidence
can be further broken down into internal or external. Internal documentary evidence originates within the entity and
may include accounting records, copies of outgoing correspondence, budgets, internal reports and memoranda,
personnel documents, appraisals, organisational charts, and internal policies. External documentary evidence may
include letters or memoranda received by the entity, suppliers’ invoices, leases, contracts and other reports, and third
party confirmations.
54

Auditors should be wary of possible errors or misstatements in documentary evidence. Their reliability depends on
how the source data are collected and manipulated. Although electronic processing is far less prone to error, and errors
that are generated are likely to be systematic, the data input to the electronic systems are frequently manual and
therefore prone to human error. Various analytical tests can be made to confirm consistency and increase the auditor’s
assurance of their reliability.

Observational. Observational evidence is obtained by observing people and events or by examining property. All
observations obtained by the auditor should be recorded, either in the form of notes to file, photographs, or other
pictorial representations. The evidence is strengthened if it is obtained by two auditors, if the observation takes place
several times as opposed to only once, or is discussed at the time of observation with a representative of the entity,
preferably someone responsible for the activities or properties being audited.

An important form of evidence is the confirmation of information contained in records through a physical count of the
actual amount or number of items (such as cash, pieces of equipment, inventory). Inspection of equipment should
include spot checks to ensure that the equipment is complete and in good working order.

Physical. The main physical evidence that would be used by an auditor would be a photograph, for example showing
the condition of a building or piece of equipment. Generally, physical evidence, except of course documents, is not
collected by auditors. In the case of documents, some standards require that the auditor examine an original rather
than a copy, but in most cases, the evidence collected is a copy of a document, or part of a document. The auditor
must clearly identify the source of the document.

Oral. Oral evidence takes the form of statements usually made in response to enquiries or interviews. Interviews can
provide important leads not always obtainable through other forms of audit work. There are many sources of oral
evidence:
a) Various levels of management;
b) Personnel directly involved in operations;
c) Suppliers and contractors;
d) Recipients of government services;
e) Members of the general public;
f) Other ministries/departments/agencies; and
g) Experts and consultants.

Analytical. Analysis of data can provide conclusions that are not necessarily directly available from lists of data,
reports, studies or other sources. The auditor with strong analytical skills can provide information that may not be
known already to managers of the entity.

There are many uses for evidence derived from analysis. These can include:
a) Checking that data from different sources are consistent, and conducting reconciliations;
b) Calculating variability in levels of efficiency;
c) Calculating averages to compare performance;
d) Ensuring interest payments are properly calculated;
e) Confirming payroll and other expenditures are accurate, and comply with regulations, agreements and other
controls on payments; and
f) In general, confirming written and oral statements.

Procedures/Approaches for Gathering Audit Evidence 2018+2009


55

Broad Approach. At the start of an audit, usually during the planning stage, the auditor is taking a broad approach to
the collection of evidence. Interviews are often of a more general nature and questions are more open-ended than
specific. The auditor takes the approach of scanning at this stage. Materials are scanned quickly to obtain a general
understanding. The auditor searches for significant events or transactions that may require further review.

It is usually more efficient to obtain explanations through inquiry, and then later seek to validate these explanations,
than for the auditor to try to find explanations directly by sifting through quantities of detailed evidence. Sometimes,
managers are happy to direct the auditor to those areas in greatest need of examination while others will evade or even
misdirect the auditor in hope that weaknesses will not be discovered.

Specific Approach. Before the main examination phase of the audit, the auditor will have developed a detailed audit
programme. Here the audit objectives have been defined, and the standards and/or audit criteria against which the
observations are compared have been structured. A set of specific questions may be identified, either in the form of a
modified internal control questionnaire or audit guide, or by an analysis of what information is required to answer the
audit objectives and confirm compliance or lack of compliance with the standards/criteria.

Expanded Approach. As the evidence is collected, however, further questions arise and new areas for enquiry are
often discovered. The auditor needs to apply judgement as to what evidence to collect and what to ignore. Cause-and-
effect analysis (see below) will usually raise questions about further evidence.

Experience will guide the auditor, for example, in deciding whether the evidence obtained to a certain point can stand
on its own or further support is required to confirm the validity of the evidence. This further support could include:
a) Corroborating evidence with independent third parties;
b) Physical checks to verify that an asset or liability exists;
c) Analysis to ensure that the evidence is reliable; and
d) Verifying that procedures actually operate as claimed by management.
.
Unanticipated Matters 2008

Although the audit programmes are approved at the detailed planning stage, the auditor performing the work should
not assume that the programmes cannot be changed. The auditor is likely to encounter matters not anticipated in the
audit plan. For example, the entity may have new assets, liabilities, receipts or expenditures that had not been known
about at the planning stage, or may be operating under new legislation. Similarly, the entity may have entered into
significant contracts since the audit was planned.

The auditor should also be alert for matters arising during the fieldwork phase that indicate changes may be required to
the general planning parameters. For example, the audit approach may call for high reliance to be placed on the
internal control structure. However, if the auditor’s tests of internal control reveal a larger than expected number of
internal control deviations, then the sources of assurance, and the nature, extent and timing of the auditor’s substantive
tests, may need reconsideration.

To detect matters such as these, the auditor should not conduct the audit blind to evidence beyond the audit
programme. The auditor needs to remain on the lookout for these unanticipated matters, and to consider their
implications for the audit.

If audit work is performed at an interim date, this can alert the auditor to unanticipated matters at an earlier date. The
auditor could then make the required changes to the audit planning memorandum, audit programmes, etc.
56

Should an unanticipated matter be relatively minor, such as one that requires the addition of one or two audit
procedures to an existing audit programme, the auditor should be able to make the change without going through a
formal approval process. However, if the matter is more significant, such as one that calls for developing new audit
programmes or re-considering the sources of audit assurance, the auditor should discuss the situation with the audit
supervisor. The auditor should then prepare an addendum to the audit planning memorandum. This addendum should
follow the same review and approval process as is used for the audit planning memorandum itself.

In addition, if the matter requires the auditor to pursue an area of investigation substantially outside of the initial audit
scope, it would be appropriate to brief entity officials on the change of scope. This could be done through an
addendum to the entity communication letter.

The Substance of the Transaction

Auditors should be satisfied with the nature, adequacy and relevance of audit evidence before placing reliance upon it.
One aspect of this is to consider the substance of a particular transaction that is being supported by the documentary
evidence.

There may be a significant difference between the form of the transaction and its substance. For example, a bribe may
be disguised as a commission, or a purchase may be disguised as a long-term lease. The auditor needs to ensure that
the documentary evidence is clear enough to determine the real substance of the transaction.

If the auditor suspects that the substance of a transaction is different from its form, the auditor should consider what
the correct substance is. The auditor should discuss his/her findings and conclusions with entity officials. Should the
auditor still believe that the substance of the transaction is different from its form, the auditor should record the most
likely error that arises from the difference on the Summary of Unadjusted Differences.

Conflicting Audit Evidence 2018+16+15

Conflicting audit evidence occurs when the auditor receives evidence regarding a particular balance, transaction or
event that is not consistent with other evidence. Examples of conflicting audit evidence are when:
a) The auditor’s analytical procedures indicate that material error exists in a particular component, while the
auditor’s substantive tests of details indicate that there are no errors in the component.
b) One entity official provides the auditor with information or an explanation that is inconsistent with the
information provided by another entity official.
c) The auditor identifies what appears to be a material error and asks entity officials to investigate. The officials
respond with an analysis or explanation indicating that no error exists.

What the Auditor should do


first step the auditor should take is to re-evaluate the evidence received.

Two, The auditor should maintain an open mind, and guard against assuming that the initial findings are the only
interpretation of the situation.

Three: Evidence should be evaluated objectively, and alternative interpretations of the evidence should be considered.
57

It is not appropriate for the auditor to disregard some of the evidence received. For example, in the first illustration it
would not be appropriate for the auditor to ignore the results of analytical procedures. The auditor should seek further
evidence to determine whether the results of the analytical procedures or the results of the substantive tests of details
are correct.

One way to do this is to seek input from entity officials. For example, entity officials may be able to provide the
auditor with additional information that helps to explain the fluctuation identified by analytical procedures.

Where the auditor receives conflicting information from officials, the auditor should determine whether:

Four: there are legitimate reasons why the two officials would have provided different information or explanations;
and
Five: the information or explanations received from each individual are reliable.
Six: seek corroborating information or explanation from a third or even a fourth individual to determine which of the
two original providers of the information or explanation appears to be incorrect.

Where subsequent analysis by the entity management does not support the auditor’s estimate of error, the auditor
should audit the entity’s analysis and supporting documentation to determine if the further analysis:
a) deals directly with the matter at hand;
b) was sufficient and appropriate, and done correctly; and
c) explains why the auditor’s original estimation of the error was not correct.

Until the conflicting audit evidence is satisfactorily resolved, the auditor should not take any assurance from any of the
affected audit procedures.

Cause and Effect Analysis 2016+15+14


Wherever possible, the auditor should determine the underlying cause(s) of an observed weaknesses or error.
Normally, there is at least one major underlying cause for the weakness or error, such as: 2016+15+14
a) Inexperienced individual carrying out the transaction;
b) Insufficient training of that individual;
c) Lack of proper systems and procedures;
d) Insufficient management involvement / scrutiny; or
e) Unclear accountability.

It is usually a matter of judgment as to which factor, or combination of factors, is generally regarded as the underlying
cause(s).

These underlying causes need to be addressed to obtain long-term improvement of the operations. The auditors’
recommendations for improvement should address these items.

The auditor needs to identify the actual, or potential, effect of the observation. Wherever possible, the auditor should
seek examples of the effects resulting from a weakness observed. However, such evidence may not be readily
available. If this is the case, the auditor should be able to demonstrate the risk associated with the continuation of the
current situation. The risk should be plausible and convincing to management. If not, the auditor will likely find it
difficult to get management support for recommended changes to reduce or eliminate the weaknesses observed.
58

Cause and effect analysis is often difficult. Sometimes clear relationships between observations and the underlying
causes cannot be proved. This is where the auditor’s knowledge, experience and communication skills are important.
Management needs to have confidence in the auditor to accept the recommendations for change.

If the underlying causes of weaknesses are not addressed, the auditor can expect to note the same problems each time
the area is audited. Except to the extent required as part of a follow-up audit, there is no point in repeating audits and
coming up with the same observations. Either the weaknesses are too small to matter, in which case the auditor should
not be concerned with the issues, or there is need to correct the problems.

Cause-and-effect analysis ensures that we direct our

a. effort towards the areas that matter and


b. produce meaningful and significant audit observations. This analysis also ensures that we
c. understand the underlying causes, so that we can
d. develop recommendations that address the most important areas

Cause-and-effect analysis requires the auditor to:

a) identify the fundamental cause(s) of the deficiency. This is important in developing a basis for
recommending remedial actions. Often there is more than one cause and the auditor’s challenge is to determine
which ones are the most relevant.
b) assess and quantify the effect, or the potential effect, of the deficiency. Quantifying the effect of a problem
is an important step in determining the significance of the deficiency. In many cases, the effects can only be
described in terms of risks as opposed to actual losses, or other negative effects, that have occurred
c)
Adequate documentation is important for several reasons. 2018

a) serve as evidence of the auditor's compliance with DAGP’s Auditing Standards;


b) help to ensure that delegated work has been satisfactorily performed;
c) increase the efficiency and effectiveness of the audit;
d) help the auditor's professional development;
e) serve as a source of information for preparing reports;
f) provide information to answer enquiries from entity officials, the Legislature and its committees, or from any
other party;
g) assist in the planning of the audit for the following year; and
h) help auditors in the following year to perform their work.
Supervision is
essential to
Supervision
ensure the
quality of the
As noted in paragraph 3.2.2 of DAGP’s Auditing Standards, “Supervision is essential to ensure the fulfilment of audit
audit work.
objectives and the maintenance of the quality of the audit work. Proper supervision and control is therefore necessary
in all cases, regardless of the competence of individual auditors.”

The Directors and Directors General must ensure that the audit is carried out efficiently, effectively, and with a high
standard of professional competence. This requires auditors to be properly supervised during each audit assignment.

The extent of the required supervision will vary from situation to situation. In general:
a) Junior staff should be supervised more closely than senior staff;
59

b) Auditors who are not familiar with the entity or the audit procedures being performed should be supervised
more closely than auditors who are familiar with the entity and the specific audit procedures; and
c) Auditors performing procedures that require a great deal of experience and professional judgment should be
supervised more closely than auditors performing simple, routine audit procedures.

Supervision involves ensuring that: IMP


a) The members of the audit team fully understand all of the planning decisions before commencing the
fieldwork;
b) The fieldwork is performed in accordance with DAGP’s Auditing Standards;
c) The audit programmes are completed as planned, unless changes are required;
d) If changes are required to the audit plan, the additional areas that require examination, or the areas that require
additional examination, are properly planned and the work is properly performed;
e) Only essential work is performed;
f) Sufficient evidence will have been obtained when the work is completed;
g) Audit findings and conclusions are being adequately supported by evidence in the working papers;
h) The audit is performed within the time budget and by the deadline dates set; and
i) The work is being done in a strong team environment, which promotes the success of the audit and the
development of audit skills within the team.

It is difficult to supervise staff from a distance. Supervision is most effective when the supervisor is on the job with the
audit team.

While each audit situation is different, it would normally be appropriate for the supervisors of the lowest level staff to
be on the job on a full-time basis. Supervisors of more senior staff could be on the job less frequently.
60

8. Evaluating Audit Results


Evaluating Financial Audit Results
By the end of the fieldwork stage the auditors will have completed their audit programmes and documented the results
of their work. Part of this work will have involved the identification of potential monetary errors, compliance with
authority violations, internal control deviations, etc. These errors and deviations need to be dealt with during the
evaluation phase.

Error evaluation is done in stages.

First the auditor reaches a conclusion on the results of each test.


Next, the auditor reaches a conclusion on each component.
Finally, the auditor reaches a conclusion on the financial statements as a whole.

Computer-assisted auditing techniques (CAATs):

Advantages of CAATs over manual evaluation of errors are:


(a) Calculations are much quicker using computer power;
(b) Manual calculations are complex and prone to error – computers produce much more accurate and reliable
results;
Known Errors, Most Likely Errors, Further Possible Errors and Maximum
Possible Errors
Error evaluations are performed by projecting the findings from a representative sample to the population as a whole.
The rest of this Chapter illustrates the process based on sampling from a population of supplier invoices.

Some key terms used in this chapter are Known Error (KE), Most Likely Error (MLE), Further Possible Error (FPE),
Maximum Possible Error (MPE) and Upper Error Limit (UEL). They are illustrated in the figure below for reference
when reviewing later sections of this Chapter.
61

Figure 10.1: Known Error, Most Likely Error, Further Possible Error and Upper Error Limit – Overstatement Errors

Precision Gap
Upper
3,500,000 Widening error
limit
Basic Precision (3,584,850)
3,000,000 (1,644,040)
Further
possible
2,500,000 error
(2,044,700)

2,000,000 Most Likely Error


(1,540,150)
Most
1,500,000 likely
error
(1,540,150)
1,000,000

500,000 Known
error
0 (4,000)

Known Error 2016+2013

The known error is the sum of the errors that the auditor actually finds during the audit.

If for example, the auditor tests a sample of 181 supplier invoices out of a population of 30,000 and finds 5
overstatement errors totalling Rs. 4,000, then the known error is Rs. 4,000.

Most Likely Error (MLE) 2013

The most likely error (MLE) represents the auditor’s best estimate of the error in the population.
62

In the example, the auditor has only selected a sample of 181 supplier invoices out of a population of 30,000. There are
likely to be more overstatement errors than just the Rs. 4,000 found in the sample. The auditor needs to estimate the
most likely error in the population based on the results of the sample.
Using the approach illustrated in Appendix B, the auditor determines the MLE in the population to be Rs. 1,540,150.

Upper Error Limit (UEL) 2016+2013

The auditor has only taken a sample of 181 supplier invoices out of 30,000 supplier invoices. Therefore, it is very
likely that the actual error in the population will not be exactly Rs. 1,540,150. The actual error could be larger or
smaller than Rs. 1,540,150.

The upper error limit (UEL) represents the maximum possible error that could exist in the population at a given
confidence level.

The reason for the phrase “at a given confidence level” is because the upper error limit will be different depending on
the confidence level the auditor wishes to achieve. With a MLE of Rs. 1,540,150, the auditor would be very confident
that the actual error in the population is less than Rs. 10,000,000, but would have less confidence that the actual error
in the population is less than Rs. 2,000,000.

As discussed in detail in Appendix B, the auditor normally does two error evaluations – one for overstatement errors
and one for understatement errors. The auditor then combines the results of the two evaluations.

Using the techniques illustrated in Appendix B, the auditor is able to conclude that:
(1) te population is not overstated by more than Rs. 3,584,850; and
(2) the population is not understated by more than Rs. 103,890.

Further Possible Error 2015+2013

The further possible error is the difference between the UEL and the MLE. It has two components – basic precision
and precision gap widening.

In our example, the further possible error for overstatements is Rs. 2,044,700, being the difference between the UEL of
Rs. 3,584,850 and the MLE of Rs. 1,540,150.

Basic Precision 2016

Basic precision is the possible error that could exist in the population even if no errors are found in the sample. It
therefore represents the upper error limit when the most likely error is nil.

Assume the audit fieldwork uncovers no understatement errors. Therefore, the most likely understatement error is Rs.
nil. However, it is difficult to believe that there isn’t a single understatement error in any of the 30,000 supplier
invoices.
63

In fact, with a desired 95% confidence level, the auditor determines basic precision to be Rs. 1,644,040. The auditor
can therefore conclude with 95% confidence that the understatement errors in the population sum to a maximum of Rs.
1,644,040.

When the basic precision value, Rs. 1,644,040, is netted against the MLE for overstatements of Rs. 1,540,150, the
auditor gets the UEL for understatements of Rs. 103,890.
Note that basic precision is the same amount for both overstatement errors and for understatement errors. The same Rs.
1,644,040 is also used for the evaluation of overstatement errors.

Precision Gap Widening

Basic precision does not represent the total amount of the further possible error. The reason is that, for each additional
Rs. 1 in the MLE, the UEL increases by more than Rs. 1. Precision gap widening is the additional further possible
error that results from finding errors in the population.
In the above illustration, the precision gap widening for overstatement errors is Rs. 400,660. (There is no precision gap
widening for understatement errors as no understatement errors were found in the sample.)

The sum of the Rs. 400,660 precision gap widening amount and the Rs. 1,644,040 basic precision amount is Rs.
2,044,700 – the further possible overstatement error.
Compliance with authority violations and internal control deviations
The above illustration has been based on a monetary error. The same terminology and process are used for compliance
with authority violations and internal control deviations.
For example, assume the auditor tests 184 supplier invoices out of a population of 30,000 and finds 5 invoices that
have not been approved. The auditor could then calculate the most likely amount of the unapproved expenditures, and
the maximum possible amount of the unapproved expenditures. The only difference in the process is that, since we are
dealing with approvals, all errors will be 100% errors i.e. the full amount of the invoice. An invoice cannot be 50%
approved.

Concluding on the Results of Each Test of Internal Control 2019+2017

The auditor should reach a conclusion on a test of an internal control sample by determining the number of internal
control deviations (violations of specific internal controls) in the sample, and the maximum possible deviation rate, and
then comparing the maximum possible deviation rate to the tolerable deviation rate.
Should the maximum possible deviation rate be less than or equal to the tolerable deviation rate, the auditor can place
the desired level of reliance on the control.
Should the maximum possible deviation rate exceed the tolerable deviation rate, the auditor reduces reliance on the
internal control, and obtains additional assurance through other procedures. The auditor may also have other options,
as discussed below.

Suppose the auditor selects a sample of 42 supplier invoices and finds 2 internal control deviations – 2 supplier
invoices that are not properly approved. The auditor can use a CAATs to arrive at a maximum possible deviation rate
64

of 12.18%. Since the tolerable deviation rate was 9%, this is an unacceptable result. The process for doing this is
described in Appendix B.

Dealing with unacceptable results


Where the evaluation of audit work provides unacceptable or ambiguous results, the auditor must determine a course
of action. Actions to be taken in different circumstances are described below.
Most likely error less than materiality; upper error limit greater than materiality
In this case, the auditor has four potential options:
a) Increase the materiality amount;
b) Increase the sample size;
c) Request entity officials to record a correcting entry; or
d) Request entity officials to perform a detailed investigation and then re-audit.

Each is discussed in turn.

Increase the materiality amount. In our case study, materiality was set at Rs. 3,000,000. However, determination of
materiality is not an exact science, but instead depends on the auditor’s professional judgment. As such, setting
materiality at Rs. 3,000,000 does not necessarily mean that an upper limit of Rs. 2,999,000 (or somewhat less) is
always acceptable, or that an upper error limit of Rs. 3,001,000 (or somewhat more) is always unacceptable.

The margin of variance around the materiality amount is a matter of judgment. As a rule of thumb increasing the
materiality amount by 25% would normally be considered acceptable, and increasing the amount by as much as 50%
may be acceptable in some cases.

In our case study, our upper error limit for overstatement errors in cost of sales was Rs. 3,584,850 – only 19.5% more
than the Rs. 3,000,000 materiality amount. In this case, the auditor may decide that the Rs. 3,584,850 really is not
material, and that the results are acceptable.

Increase the sample size. Assuming that the original sample is representative of the population, it is unlikely that
increasing the sample size will change the auditor’s estimate of the most likely error. However, increasing the sample
size will normally decrease both basic precision and precision gap widening.

Increasing the sample size can result in the auditor performing a lot more work and still having unacceptable results.
Therefore, the auditor should only use this option when:
a) The most likely error is significantly less than the materiality amount; and
b) The upper error limit is only slightly higher than the materiality amount.

In the example, the most likely error is more than 50% of the materiality amount. Therefore, it is unlikely that this
approach would work.

At the same time, the upper error limit is 33.7% higher than the materiality amount. Therefore it is unlikely that
increasing the sample size would work. This leads to a third option.
65

Request entity officials to record a correcting entry. The most likely error and the upper error limit can be decreased
by the amount of any corrections made by entity officials. Should the adjustment be large enough, it may result in the
upper error limit dropping below the materiality amount. Care must be taken when choosing this option. If the
correction is made across the whole population and not just for the case within the sample (where the type of error can
be recognised and corrected everywhere) then this is acceptable. Otherwise, even where the sample has been corrected
there is no assurance that the same problem does not persist elsewhere. As a minimum, the auditor should take another
sample and repeat the test.

In our example, if entity officials were to make a correcting entry to decrease the production costs by Rs. 1,540,150 –
the amount of the most likely error – the upper error limit would be reduced to Rs. 2,044,700. This is much less than
the Rs. 3,000,000 materiality amount.

Entity officials will rarely make an adjustment based on a most likely error. They will usually only be prepared to
adjust for known errors. In our example, this would only reduce the upper error limit from Rs. 3,584,850 to Rs
3,580,850 – a negligible change. In this event, the next option is appropriate.

Request entity officials to perform a detailed investigation, and then re-audit. As noted above, entity officials will
usually only be prepared to adjust for known errors. Therefore the auditor needs to get entity officials to perform a
detailed investigation of the transactions in the population in order to arrive at a more accurate estimate of the error in
the component. The auditor should then re-audit the component and request entity officials to record a correcting entry
for the known error.

In our example, entity officials might perform a detailed investigation and conclude that cost of sales were overstated
by Rs. 1,400,000, and make a correcting entry for that amount. The auditor would then audit the work done by the
officials and reach his/her own conclusions as to the most likely error and upper error limit remaining in the
component.

Most Likely Error Greater Than Materiality 2015+2017

Where MLE exceeds materiality, increasing the materiality amount and increasing the sample size would normally not
result in acceptable results. Only two of the options listed above are available to the auditor. They are:
a) Request entity officials to record a correcting entry; and
b) Request entity officials to perform a detailed investigation and then re-audit.
If neither of these options is possible, the auditor should qualify the audit opinion.

Unacceptable Results for Tests of Internal Control 2018

Assume the auditor selects a sample of 44 supplier invoices and finds 2 internal control deviations – 2 supplier
invoices have not been properly approved. This gives a most likely deviation rate of 4.55% (2 divided by 44). The
auditor then uses CAATs to arrive at an upper error limit frequency (maximum possible deviation rate of 12.11%. If
the upper error limit (tolerable deviation rate) selected is 9%, this is an unacceptable result.

In this case, the auditor normally needs to reduce reliance on the internal control structure. There are three other
potential options the auditor can consider:
a) Increase the upper error limit;
b) Increase the sample size; or
66

c) Request entity officials to perform the “missing” controls, adjust the books for all identified errors, and audit
the work performed.

Each is discussed below.

Increase the upper error limit. This is equivalent to increasing the materiality amount in the case of monetary errors,
and the preceding discussion relating to increasing the materiality amount also applies here to increasing the tolerable
deviation rate.

Increase the sample size. Assuming the original sample was representative of the population, it is unlikely that
increasing the sample size would change the auditor’s estimate of the most likely deviation rate, but could decrease the
maximum possible deviation rate.

Increasing the sample size could result in the auditor performing a lot more work and still having unacceptable results.
Therefore, the auditor should normally only make use of this option when:
a) The most likely deviation rate is significantly less than the upper error limit; and
b) The maximum possible deviation rate is only slightly higher than the upper error limit.

In our example, the most likely deviation rate is more than 50% of the tolerable deviation rate, and maximum possible
deviation rate is 34.6% higher than the upper error limit. Therefore, increasing the sample size would most likely not
lead to acceptable results.

Request entity officials to perform the “missing” controls, adjust the books for all identified errors, and audit the
work performed.
The deviation rate can be decreased by the amount of any corrections made by entity officials. Should the adjustment
be large enough, it may result in the deviation dropping below the tolerable deviation rate.

Entity officials will usually only be prepared to adjust for known errors. Therefore the auditor should re-audit the
component and request entity officials to record a correcting entry for the known error. Nevertheless, correction of
internal controls does not alter the fact that the transactions throughout the population as a whole are likely to have
been subject to inadequate controls prior to the correction resulting in both identified and unidentified errors.

Unacceptable Results for Analytical Procedures

The auditor should perform and evaluate analytical procedures to:


a) Determine the threshold amount (the amount above which a difference is considered to be significant);
b) Identify significant fluctuations;
c) Investigate the significant fluctuations found; and
d) Conclude as to whether entity officials have adequately explained all significant fluctuations.
67

9. The Reporting Process

Clearing Observations, Conclusions and Recommendations 2018


Before the auditor can publish a report on findings or an opinion on financial statements, the audit observations,
conclusions and recommendations must be cleared with entity management.

This is accomplished by briefing entity management on audit findings and documenting their responses, which can
also provide additional audit evidence. This process can be based on formal written statements or verbal briefings.

The auditor should make best efforts to obtain a sound understanding of the operations and to obtain sufficient
evidence to support findings. Nevertheless, at the initial stages of clearing observations, not all observations may be
complete or accurate. Where findings are refuted, or modified by the manager’s response further evidence may be
sought to substantiate the manager’s assertions.

It is normal to clear the observations up the management chain, briefing lower level managers and confirming the
auditor’s understanding before briefing more senior managers. When visiting an entity’s local office, it is usual to
brief the senior manager before leaving the site.

The auditor should take detailed minutes of these briefing meetings. The auditor may send a copy of these notes to the
manager for confirmation.

When there is a significant difference between what the auditor would expect to see and the findings, the auditor
should discuss this with management to determine the reasons and then decide whether the expectations are still
appropriate in the particular circumstances. The auditor should conclude whether management has fallen short or
whether the expectations were unreasonable in the context.

In developing recommendations, the auditor can explore options with management through this process before
including them in the draft report. The auditor should ensure it is clear that the conclusions and recommendations are
preliminary at this time.

The effectiveness of the communication of the contents of an audit report is influenced by:
a) Facts;
b) Opinions; and
c) Wording.

In clearing the report, the auditor should first, ensure there is agreement on the facts. The auditor should recognise that
in addition to the facts, there are opinions. For example, a fact may be that there is no control in place. Whether there
should be a control in place is an opinion, even if it is a generally accepted accounting practice. Much of the conflict
between the entity management and the auditor is over wording. The auditor should be careful when making
generalised statements or using adjectives that could be considered to exaggerate a finding.
68

Management representation letter


Purpose: 2018+16+14+13
Entity officials in each ministry, department, agency, etc. are responsible for the completeness and accuracy of
the financial statements or, in the case of the financial statements of the Federation, the provinces and the districts,
their portion of the financial statements. In addition, entity officials have often provided the auditors with
numerous pieces of information – both verbally and in writing – during the course of the audit.
The auditor prepares the management representation letter to have entity officials acknowledge, in writing, their
responsibility for the completeness and accuracy of the financial statements (or their portion thereof), and for the
representations they made during the audit.
Section 7(b) of the Controller General Ordinance requires the Controller General of Accounts to “prepare and
submit to the Auditor-General for each financial year a Consolidated and General Financial Statement
incorporating the summary of the accounts of the Federation, all provinces and district authorities”.
Section 5(d) of the Controller General Ordinance states that one of the functions of the Controller General shall be
“to lay down the principles governing the internal financial control for Government departments in consultation
with the Ministry of Finance and the Provincial Finance departments as the case may be”.

Since the Controller General of Accounts is responsible for the preparation and submission of the financial
statements for the Federation, all provinces and district authorities, and for laying down the principles governing
the internal control structures, the auditors should normally obtain a representation from the Office of the
Controller General on the financial statements of the Federation, each province and each district. The auditors
should also normally obtain a representation from the Office of the Controller General on other relevant financial
statements. This representation is in addition to obtaining a representation from officials in the specific entity that they
are auditing.

For audits that are coordinated by a central team, the central team could obtain the representation letter from the
Office of the Controller General on behalf of all the other audit teams.

Standard Content 2018+16+14+13

A sample management representation letter is included in the Standard Audit Working Paper Kit. In this letter entity
officials are asked to acknowledge their responsibility for the proper presentation of the entity’s financial position,
results of operations, etc., and confirm, to the best of their knowledge and belief, that:
a) all relevant information has been made available to the auditors;
b) they are not aware of any irregularities involving management or employees, or any violations of statutes or
regulations whose effect should be recorded or disclosed in the financial statements;
c) specifically listed asset, liability, revenue and expenditure items are valid, complete, properly valued, etc.;
d) all required disclosures have been made;
e) there are no significant subsequent events that require recording or disclosure in the financial statements; and
f) there are no other matters of significance that require recording or disclosure in the financial statements.
The letter should normally be addressed to the person within DAGP who will be signing the audit opinion (the
Auditor-General, the Deputy Auditor General (Senior) or the responsible Deputy Auditor General).

The letter should normally be signed by the:


a) Head of the Organisation;
69

b) Principal Accounting Officer;


c) Financial Advisor; and
d) Finance and Accounts Officer.

For exempt entities, officials performing the equivalent functions would sign the representation letter.
It is possible that more than one letter will be required on each audit. First, as discussed above, for the audits of the
financial statements for the Federation, the provinces and the districts, the auditors should normally seek a
representation from the Office of the Controller General in addition to officials in the specific entity that they are
auditing.
Furthermore, separate representations may also be required from entity officials at several different locations within
the entity.

The auditor needs to ensure that, if multiple representations are being used, all significant matters are covered off in
the representations, and that at least one senior official is taking responsibility for each representation

Audit completion checklist 2021


The primary purpose of the checklist is to give assurance to the person signing the audit opinion (the Auditor-
General, the Deputy Auditor General (Senior) or the responsible Deputy Auditor General) that:
a) the Director and the Director General have reviewed the working paper files;
b) the audit work is complete;
c) sufficient appropriate audit evidence has been obtained to support the auditor’s opinion;
d) all matters that should be reported are included in the opinion;
e) Either:
i) An unqualified opinion can be issued; or
ii) The auditor’s opinion contains all of the required reservations; and
f) The auditor’s opinion can be signed and released.

A secondary purpose of the audit completion checklist is to act as final review document (supervision instrument)
that the Director and the Director General can use to assure themselves that all of the critical planning, fieldwork,
evaluation and reporting procedures have been completed satisfactorily.
70

[Link] Audit Report


DAGP produces three main types of report: 2018+2014
a) Financial certification report expressing an audit opinion (on the government as a whole, on an audit entity
or on a major project);
b) Individual reports on audit work focused on investigations, compliance or performance (although often these
may be included as part of the certification report); and
c) Annual Report.

The Certification Report and Types of Opinion


The Certification Report is the product of the financial attestation audit work. It follows very specific standards,
modified as necessary to reflect different qualifications that the auditor may wish to express.

Unqualified auditor’s opinion on financial statements

The auditor’s report on a set of financial statements is referred to as the “auditor’s opinion”, even though the report is
often entitled “Auditor’s Report”. This differentiates the report from other audit reports, such as reports dealing with
compliance with authority and performance matters. These other reports are discussed in a subsequent section.

Paragraph 4.0.9 of DAGP’s Auditing Standards states, “An audit opinion is normally in a standard format, relating to
the financial statements as a whole, thus avoiding the need to state at length what lies behind it but conveying by its
nature a general understanding among readers as to its meaning. The nature of these words will be influenced by the
legal framework for the audit, but the content of the opinion shall indicate unambiguously whether it is unqualified or
qualified and, if the latter, whether it is qualified in certain respects or is adverse (paragraph 4.0.14) or a disclaimer
(paragraph 4.0.15) of opinion.”

This Auditing Standard contains several important messages. First, the auditor expresses one opinion on all of the
financial statements, as opposed to having a separate opinion on each financial statement. Second, and probably more
important, it is critical that the readers receive an unambiguous message.

For the readers to receive an unambiguous message from what is normally a very short report, it is important that:
a) The auditor adopt a standard wording for an unqualified opinion, and only deviate from that standard wording
when a reservation of opinion is being expressed; and
b) Any reservations of opinion be very clearly expressed.

When expressing a reservation of opinion the auditor should not issue an opinion that deviates only somewhat from the
standard wording, as the message could be ambiguous. There is a danger that casual readers will read it as an
unqualified opinion. Even readers who are familiar with the standard content of an audit opinion might not be able to
determine whether or not the deviation is intended to be a reservation of opinion.
71

When to Give an Unqualified Opinion

As discussed in Paragraph 4.0.10 of DAGP’s Auditing Standards, “an unqualified opinion is given when the auditor is
satisfied in all material respects that:
a) the financial statements have been prepared using acceptable accounting bases and policies which have been
consistently applied;
b) the statements comply with statutory requirements and relevant regulations;
c) the view presented by the financial statements is consistent with the auditor's knowledge of the audited entity;
and
d) there is adequate disclosure of all material matters relevant to the financial statements.”

Standard Wording
An example of a standard unqualified auditor’s opinion is contained in the Standard Audit Working Paper Kit.
To fully comply with paragraph 4.0.8 of DAGP’s Auditing Standards, the unqualified opinion should contain:
a) A title;
b) An addressee;
c) A signature and a date; and
d) Three standard paragraphs – an introductory paragraph, a scope paragraph and an opinion paragraph - which
contain material that satisfies the other disclosure requirements of paragraph 4.0.8 of DAGP’s Auditing
Standards. Each of these paragraphs is discussed below.

The introductory paragraph. The introductory paragraph identifies the financial statements covered by the auditor's
opinion and distinguishes the responsibilities of management and the responsibilities of the auditor.

The scope paragraph. In this paragraph the auditor informs the reader that the audit was planned and performed in
accordance with professional standards, and that the auditor has made judgments in applying these standards. It also
provides the reader with some explanation of the nature and extent of an audit and the degree of assurance it provides.

The opinion paragraph. In this paragraph the auditor expresses his/her opinion as to the whether:
a) the financial statements properly present, in all material respects, the government’s financial position, the
results of its operations, its cash flows and its expenditures and receipts by appropriation; and
b) the sums expended have been applied, in all material respects, for the purposes authorised by parliament and
have, in all material respects, been booked to the relevant grants and appropriations.

The opinion paragraph may also state whether, in the auditor’s opinion, certain statutes and regulations have been
complied with. (The statutes and regulations should be spelled out in the opinion).

Sometimes the auditor wants to insert a reference in the opinion to an unusual or important matter that is properly
disclosed in the financial statements. Since the auditor does not intend to express a reservation of opinion on the
financial statements, this reference should be included in a fourth paragraph, after the opinion paragraph.

The auditor should not use this additional paragraph to rectify a lack of appropriate disclosure in the financial
statements. It is also not an alternative to, or a substitute for, expressing a reservation of opinion.
72

Even when a matter is placed after the opinion paragraph, there is still a danger that some readers may think that a
reservation of opinion is intended. As a result, this paragraph should only be used in very rare cases.

A better way to provide additional information or recommendations is to use a separate report, such as an audit report.
The fourth paragraph of the auditor’s opinion could then contain a reference to the audit report. Audit reports are
discussed later.

Reservations in the Auditor’s Opinion 2017


There are three general types of reservation that the auditor may express – qualified, adverse, and disclaimer. Each is
discussed in turn in this section. Examples of qualified, adverse and disclaimers of opinion are included in the
Standard Audit Working Paper Kit.

In accordance with paragraph 4.0.12 of DAGP’s Auditing Standards, reservations are issued when any of the
following circumstances occur, and when the auditor believes that the effect is or may be material:
a) a scope limitation;
b) a departure from the government’s accounting principles; or
c) uncertainty affecting the financial statements.

Each is discussed below.

Scope limitation. 2021+2014 A scope limitation has occurred when the auditor has not been able to apply all the tests
and procedures considered necessary in the circumstances and, as a result does not have sufficient appropriate audit
evidence to form an opinion as to whether the financial statements give a true and fair view, in all material respects, in
accordance with the government’s accounting principles.

Scope limitations may arise in a number of situations, including: 2021+2016


a) circumstances beyond the control of the entity or the auditor, such as the destruction of accounting records in a
fire;
b) a limitation imposed by the entity, such as refusing to allow the auditor to perform certain audit procedures;
and
c) a limitation created by the entity, such as or a failure to maintain adequate accounting records or internal
control structures.

When the auditor has a scope limitation, the reporting objective is to inform the reader that the auditor:
2017+2016
a) has been unable to perform specific tests and procedures and obtain certain audit evidence; and, as a result,
b) is unable to determine whether or not there has been a departure from the government’s accounting principles
that materially affects the financial statements.
Departure from government’s accounting principles. A departure from the government’s accounting
principles occurs when there is: 2017+2014
a) An inappropriate accounting treatment, such as the failure to record certain assets or liabilities that are required
to be disclosed by the government’s stated accounting policies;
b) An inappropriate valuation of an item in the financial statements, such as recording fixed assets at an appraised
value;
c) A failure to disclose all of the information required, such as not segregating expenditures into all the categories
that are called for by the government’s accounting principles.
73

In any of these circumstances, the auditor's reporting objective is to inform the reader about the departure from the
accounting principles.
Uncertainty. An uncertainty normally involves a significant contingency or other event that is primarily dependent on
future developments or future decisions by parties other than entity officials.

For example, the government may have guaranteed loans to third parties who are now experiencing financial
difficulties. In these circumstances, the auditor (and entity officials) might not have sufficient information to determine
what amount, if any, the government may ultimately be required to pay.

When the auditor has an uncertainty, the reporting objective is to inform the reader that he/she has been unable to
determine what adjustments, if any, might be needed to the financial statements.

Qualified Opinion 2013

A qualified opinion is issued where the auditor is faced with a scope limitation, a departure from the government’s
accounting principles, or an uncertainty, but the matter at hand:
a) is not critical to an understanding of the financial statements; and
b) can be explained clearly and concisely.

To explain a matter clearly and concisely, it helps if the auditor can quantify the financial effect. Of course, in the case
of a scope limitation, this would not be possible.

The use of a paragraph (called the reservation paragraph) between the scope paragraph and the opinion paragraph is
the usual way of alerting the reader to the fact that there is a qualified opinion. To be most effective the paragraph
needs to explain the matter as clearly and concisely as possible. It is not sufficient to provide only a general indication
of a problem so that the reader is merely warned that further questions should be asked.

To be clear and concise, the auditor should:


a) state the financial effect of the matter. If it cannot be quantified, the auditor should so state.
b) In the case of an audit involving more than one Ministry, identify the specific Ministry (or Ministries) in which
the monetary errors or compliance with authority violations occurred. This is particularly important if the
reservation in the auditor’s opinion was the result of significant errors in only one or two Ministries.

Note: where material monetary errors or compliance with authority violations have occurred, the auditors should
request Ministry officials to investigate the matter and make necessary adjustments to the financial statements. If
Ministry officials refuse, the auditors could request the Controller General of Accounts to make the necessary
adjustment. This is consistent with Sections 5(a) and 5 (i) of the Controller General Ordinance. Once the necessary
adjustments have been made, the financial statements can be considered accurate, and the Auditor-General can issue
and unqualified opinion.

In addition to adding the reservation paragraph, other changes are made to the standard wording of the auditor’s
opinion, as follows:

The opinion paragraph is amended to insert:


a) In the case of a scope limitation or a departure from the government’s accounting principles, an “except for”,
“except that” or “except as”, followed by a brief summary of the matter and a reference to the reservation
paragraph; or
74

b) In the case of an uncertainty, a “subject to”, followed by a brief summary of the matter and a reference to the
reservation paragraph.
In the case of a scope limitation or an uncertainty, the scope paragraph would also contain an “except as” clause.
This is done by inserting “Except as explained in the following paragraph, … ” at the start of the scope paragraph.

The Standard Audit Working Paper Kit contains three examples of qualified opinions – a scope limitation, a departure
from the government’s accounting principles, and an uncertainty.

Adverse Opinion 2019+2018+2014

An adverse opinion is issued when there is a departure from the government’s accounting principles that is:
a) so pervasive and fundamental that the auditor is unable to describe clearly how the financial statements are
affected; or
b) so significant that it overshadows a clear description of how the financial statements are affected.

In these circumstances, a qualified opinion would not be adequate. The wording of an adverse opinion makes it
clear that:2015+2019+2018
a) the financial statements do not properly present, in all material respects, the government’s financial position,
the results of its operations, its cash flows and its expenditures and receipts by appropriation; or,
b) the sums expended have not been applied, in all material respects, for the purposes authorised by parliament
and have not been booked to the relevant grants and appropriations.

As with a qualified opinion, a reservation paragraph should be inserted between the scope paragraph and the opinion
paragraph. The reservation paragraph should clearly and concisely describe all the matters of disagreement, and the
financial effect should be quantified where relevant and practicable.

The opinion paragraph would be amended to state something to the effect that, “In my opinion, because [brief
description of matter] described in the preceding paragraph:
a) these financial statements do not properly present, in all material respects, the government’s financial position,
the results of its operations, its cash flows and its expenditures and receipts by appropriation; or,
b) the sums expended have not been applied, in all material respects, for the purposes authorised by parliament
and have not been booked to the relevant grants and appropriations.…”

The Standard Audit Working Paper Kit contains an example of an adverse opinion.

Disclaimer of Opinion

Where the auditor is unable to arrive at an opinion regarding the financial statements taken as a whole due to a scope
limitation or uncertainty that is so fundamental, pervasive or significant that a qualified opinion would not be adequate,
a disclaimer is given. The wording of the disclaimer makes it clear that an opinion cannot be given.

As with a qualified and an adverse opinion, a reservation paragraph should be inserted between the scope paragraph
and the opinion paragraph. The reservation paragraph should clearly and concisely describe the reason for the
disclaimer.
75

In this case the opinion paragraph would be amended to state something to the effect that, “In view of the possible
material effects on the financial statements of the matter described in the preceding paragraph, I am unable to express
an opinion whether …
a) these financial statements properly present, in all material respects, the government’s financial position, the
results of its operations, its cash flows and its expenditures and receipts by appropriation; or,
b) the sums expended have been applied, in all material respects, for the purposes authorised by parliament and
have been booked to the relevant grants and appropriations.

The scope paragraph should be amended by inserting “Except as explained in the following paragraph” at the start.
76

[Link] and Working Papers

2017Catogeries of working papers;

The auditor’s documentation, in the form of audit files, is referred to as the “Working Papers”. The audit files should
be complete in themselves. Reference to external sources of evidence is not normally considered sufficient. Therefore
the auditor should keep extracts of the relevant external documentation in the working paper file. Working papers are
usually maintained in three categories:

a) Permanent file;
b) Current file; and
c) Briefing file.

The Purpose of Working Paper Files 2017+15+10


Working paper files are maintained to:
a) Provide evidence to support all matters included in the audit report;
b) Demonstrate adherence to auditing standards and procedures;
c) Aid supervision of the work;
d) Facilitate review of work performed; and
e) Assist in planning the subsequent audit assignment (with background information, key issues identified in
previous audits, and matters for follow up).

Form and Content of Working Paper Files

Current File. The Current working paper file should include:

a) Information concerning the government programme(s), the industry, economic environment and legislative
environment within which the entity operates.
b) Evidence of the planning process including audit programmes and any changes thereto.
c) Evidence of the auditor’s understanding of the accounting and internal control systems and programme
performance.
d) Evidence of inherent and control risk assessments and any revisions thereof.
e) Analyses of transactions and balances.
f) A record of the nature, timing and extent of audit procedures performed and the results of such procedures.
g) Evidence that the work performed by junior auditors was supervised and reviewed.
h) An indication as to who performed the audit procedures and when they were performed.
i) Copies of communication with experts and other third parties.
j) Copies of letters or notes concerning audit matters communicated to or discussed with the entity.
k) Copies of the auditor’s report.
77

2015 Permanent File. The permanent audit file includes information that will be of continuing importance to the audit
activity in the particular area of audit. This may include: Copies of relevant government legislation, regulations,
guidelines and other rules affecting operations.
a) Role of entity, Vision and Mission Statements, most recent corporate plan.
b) Copies of the Estimates, kept up-to-date.
c) Copies of long-term contracts/leases.
d) Loan agreements, schedules of amortisation for debts and special assets.
e) Extracts of minutes.
f) Reports to management and management’s response.
g) Organisation charts, telephone book and building layout and/or locations of operation.
h) Chart of accounts.
i) Summary of accounting principles used by the organisation.
j) Special remuneration conditions for senior officers.

Custody and Maintenance of the Working Paper Files 2013


Working paper files are confidential and are the property of DAGP. Material should not be removed from the files
without the specific authority of the responsible Audit Manager.

The auditor is responsible for their custody and safekeeping at all times until they are placed in official archives.
Working papers are not for general disclosure. Where they are to be shared with other auditors, or other bodies, the
following guidelines should be respected: 2013
a) No copies of working papers should be given or shown to members of the audit entity;
b) Working papers should not be made available to third parties except in special circumstances;
c) Where DAGP is prepared to provide access to working papers by third parties, normally, the consent of the
audit entity should be obtained first;
d) Files and papers should be reviewed before they are made available;
e) DAGP should at all times retain control over the papers and documents and inspection should take place under
the supervision of a representative of DAGP;
f) Where DAGP is asked to produce working papers in connection with legal proceedings, or investigations by
government bodies, for example under a court order, legal advice should be obtained before producing them;
and
g) Where DAGP is required to produce original papers or documents in legal proceedings, copies should be
retained.
78

[Link] Follow Up

Introduction

Overview 2014+2015
Follow up is an integral part of the audit function. The auditor’s objective is not fulfilled unless any errors or
deficiencies identified during the audit have been corrected or at least addressed. Both DAGP and the appropriate
Public Accounts Committee (PAC) should ensure that entity officials take action to correct all errors found and deal
with all recommendations made.

Entity officials themselves are responsible for ensuring that their financial statements are as complete and accurate as
possible, and that their internal control structures are operating as efficiently and effectively as possible. They should
be encouraged to view the auditor as an ally in this endeavour, and should actively work with the auditor to address
any concerns.

To achieve these objectives, there should be a formal follow up of every financial audit. All observations, conclusions
and recommendations should be followed up and reported until they are satisfactorily dealt with, or until circumstances
have rendered them no longer relevant.

The follow-up phase involves returning to the entity at a later date to determine if entity officials have:
a) Corrected errors identified during the audit; and
b) Implemented recommendations made by the auditors.

The errors identified during the financial audit could include:


a) Monetary errors or related compliance with authority violations that led to a reservation in the auditor’s
opinion (a qualified, adverse or disclaimer of opinion); and
b) Other monetary errors and compliance with authority violations.

Recommendations made by the auditor can relate to:


a) Reservations being expressed in the audit report;
b) Contentious matters on which DAGP decided not to express a reservation;
c) Comments on the form and content of the financial statements;
d) Comments on the accounting policies used to prepare the financial statements;
e) Compliance with authority violations;
f) Internal control weaknesses; and
g) Performance (value-for-money) matters.

This Chapter discusses:


a) the timing of the follow up of the correction of errors and implementation of recommendations;
b) the two basic levels of assurance that the auditor can plan to achieve during the performance of the follow up;
c) the follow up process which first deals with the correction of errors and then with the implementation of
recommendations;
d) reporting the results of the follow up; and,
e) when the auditor should perform additional follow ups of matters which entity officials have not resolved.
79

[Link] Assurance

Quality Assurance During the Planning Phases for Individual Audits 2012
The detailed discussion of the general and detailed planning phases of an audit in Chapter 7 contains numerous quality
assurance procedures. These procedures are summarised below.

Quality Assurance Through Following a Logical Framework

The audit cycle guides auditors through the general and detailed planning processes in a logical order. This helps
ensure that;
a) the most critical planning decisions are made first;
b) all required planning decisions are made; and
c) the end result is an audit plan that, if followed, will result in an efficient and effective audit that complies fully
with DAGP’s Auditing Standards.

Quality Assurance Through Documentation and Approval of Planning Documents

Audit programmes, checklists and forms, all of which are contained in the Standard Audit Working Paper Kit, support
many of the general and detailed planning decisions.

Most of these audit programmes, checklists and forms, together with the documentation supporting them, are
maintained in an updated permanent file, an updated planning file, an updated audit planning memorandum, and
updated audit programmes for staff to use during the fieldwork, evaluation and reporting phases.

Key to maintaining the quality of the planning process itself is a review of the plan, which the Deputy Auditor General
(Senior) or the responsible Deputy Auditor General should supervise and approve.

Quality Assurance through Assigning Appropriate Staff

Proper staffing of the audit team is essential to assuring a quality audit. This includes having enough team members to
perform all planned audit activities as well as ensuring that all required skills sets, including supervisory and special
technical skills, are available to the audit team as needed

Quality Assurance through Budgets

DAGP encourages a formal process for each audit by which budgets are initially set, reviewed and approved. While
most of the benefits of these budgets are achieved through the monitoring of the time spent and a comparison of actual
hours spent to the budget, the exercise of preparing the budget itself can help to ensure an efficient and effective audit.

Quality Assurance during the Fieldwork Phase for Individual Audits 2014+17
There are various quality assurance measures that guide the auditor in performing and documenting the fieldwork,
such as:
80

a) revising planning decisions should unanticipated matters arise during the fieldwork phase;
b) applying minimum documentation standards;
c) providing on-the-job supervision;
d) reviewing audit working paper files; and
e) reporting and monitoring time spent by each resource on every audit activity.

Quality Assurance during the Evaluation Phase 2017+14+12


Evaluation activities include an appropriately detailed review and approval of:
a) All monetary errors, compliance with authority violations and internal control deviations found, and the
assessment of their causes;
b) The calculation of the most likely error and the upper error limit for each test;
c) The calculation of the most likely error and the upper error limit for each component;
d) The calculation of the most likely error and the upper error limit for the financial statements as a whole;
e) The assessment of the overall financial statement presentation and the reasonableness of the overall results;
f) The assessment of the achieved level of assurance;
g) The documentation supporting the discussion of the results of the error evaluation with entity officials;
h) The follow-up work performed by entity officials; and
i) How unacceptable results were dealt with.

Quality assurance during the reporting phase 2019+18+17+15+12


Quality Assurance for Financial Audit Opinions

The following tools are provided to ensure the quality of the auditors opinions and statements:
a) Management representation letters;
b) Audit completion checklists; and
c) Memoranda recommending signature.

These documents, and the diligent performance of quality assurance procedures for their use, help ensure that DAGP
has the audit evidence that it requires, and that the Auditor-General is signing the most appropriate [Link]
assurance for other audit reports

A formal process governing how audit observations are developed, cleared and reported, and the most appropriate
reporting style has been used. This process helps to ensure that the contents of the report are correct, and the findings,
conclusions and recommendations contained in the report are easily understood and appreciated by the readers of the
reports.

Quality assurance during the follow up phase


The follow up phase is a major component in assuring the quality and the positive impact of the audit process, which
contributes to the quality of the audit work and the use that is made of its findings.

Follow up audits can be designed to provide either an audit level of assurance or a less rigorous review level of
assurance. The work is guided by quality assurance procedures for the planning, fieldwork, evaluation and reporting
phases of the work.
81

Other quality assurance procedures 2011


There are a number of other procedures that contribute to the overall quality of the audit operation, as follows. 2011

Ongoing Supervision and Review

Adequate supervision and review is important throughout all phases of the audit – general planning, detailed planning,
fieldwork, evaluation, reporting and follow up.

Ongoing Involvement By Senior Audit Officials

Ongoing involvement by senior audit officials in the more complex and critical stages of the audit process ensures a
focused, efficient and effective audit. This involvement also provides an opportunity to upgrade the skills of less
senior and experienced audit staff through mentoring to transfer their knowledge.

Audit Staff Development

Since all audits are conducted by human resources, the most critical elements of quality assurance are the proper
composition of the audit team (an appropriate mix of skills and experience) and the adequate preparation of each team
member to fulfil their role in the team.

DAGP’s General Auditing Standards include a requirement to develop and train employees, and to define the basis for
their advancement.

Audit staff can be developed through a formal programme of classroom training on the concepts behind the audit work
supplemented by on-the-job training and continual mentoring by audit seniors. On-the-job training involves more
senior and experienced staff training and supervising less senior and experienced staff. This helps to ensure that the
less senior and experienced staff acquire the skills and knowledge required to take on more senior responsibilities, and
that DAGP’s Auditing Standards for planning, fieldwork, evaluation and reporting are complied with.

Training and advancement should be a key factor when assigning specific staff to audits.

One way of reinforcing the on-the-job learning experience is to provide each auditor with timely feedback on their
performance. Those officials doing the review of the working paper files should provide the auditor with feedback on
their performance shortly after the review, as opposed to waiting until after the reporting phase.

Assignment appraisal forms are one way of documenting the performance of an auditor on an individual assignment,
including strengths and areas where improvements are required. Similarly, annual appraisal forms can be used to
evaluate an employee on his/her work for the year.

Upward appraisals can be used as a means by which auditors can provide constructive feedback about their superiors.
82

Information Technology and Audit Methods Specialists 2015+2013

Proper use of computer technology has a major positive impact on the quality of the records underlying the financial
statements and the auditor’s ability to review them. All staff members should have a sufficient knowledge of
computer-assisted auditing techniques (CAATs) to identify areas where their use would be appropriate, and to assist
someone in applying them. It is normally not essential for every auditor to be able to perform every type of CAAT nor
to perform some of the more sophisticated analytical procedures, such as regression analysis.

These skills should be made available to audit teams as required. Audit offices around the world deal with this by
creating specialist positions and teams. For example, various audit offices have created:
a) Information technology (IT) specialist groups to provide ongoing advice and assistance to audit teams in the
performance of CAATs; and
b) Audit methods specialists to provide ongoing advice and assistance to audit teams in the performance of
analytical procedures, statistical sampling, advanced auditing techniques.

These specialists are often also responsible for keeping the audit office’s methodology up to date in their areas of
expertise, developing and teaching courses, etc.
Entity Feedback
A final quality assurance technique for auditors to assess and improve the quality of their audits is the use of entity
feedback. This feedback could be obtained as part of the quality assurance reviews discussed in Section Error:
Reference source not found, or as a separate exercise.

Entity officials could be asked to comment on matters such as: 2018+2015


a) The extent to which the auditors performing the work appeared to have an understanding of the entity being
audited;
b) The apparent qualifications of the auditors performing the work;
c) The extent to which the auditors liased with, and made use of, the internal audit unit within the entity;
d) The length of time and the number of hours required to perform the work;
e) The extent to which the more senior and experienced DAGP officials were on-site;
f) The extent to which entity input was requested on errors found, contentious issues, etc.;
g) The fairness of the audit opinion and other reports – both the initial versions and the final versions;
h) The readability of the various audit reports; and
i) The overall extent to which they believe the audit will help them to improve their financial statements,
compliance with authorities, internal controls and operations in future years.

Ultimately, the quality of the work performed by DAGP will be determined by the commitment of the organisation to
fulfilling its Mission, Vision and Values, and the enthusiasm of audit staff at all levels to tackle their challenging job
with integrity and pride.

You might also like