Topic 2 Chapter 6 - Risk Assessment
Topic 2 Chapter 6 - Risk Assessment
Topic 2 – Chapter 6
• Materiality
Risk Assessment
• Understanding the entity and its
environment
• Assessing the risks of material
misstatement
• Responding to the risk assessment
• Fraud, law and regulations
• Documentation of risk assessment
00
M
O
NT
H
00
00
BPP LEARNING MEDIA
Syllabus learning outcomes 1
(ISA 200 Overall objectives of the auditor and the conduct of an audit in
accordance with International Standards on Auditing, para.11)
Business risk is the risk inherent to the entity in its operations (at all
levels of the business) (see chapter 5).
Audit risk is the risk that the auditor expresses an inappropriate audit
opinion when the financial statements are materially misstated.
ISAs required auditors to follow a risk-based approach.
Audit risk has three components and is illustrated diagramatically on the
next slide.
AR = IR x CR x DR
Audit Risk Control risk
Inherent Risk
Detection Risk
• Control risk is the risk that a material misstatement that could occur
in an assertion and that could be material, individually or when
aggregated with other misstatements, will not be prevented or
detected and corrected on timely basis by the entity's internal control.
• Examples:
Monthly bank reconciliations not reviewed by a manager
Purchase invoices not matched to goods received notes
References not followed up for new employees
Computer passwords not required to be changed regularly
• We will look at controls in more detail in Chapters 9 and 10.
• But simply increasing sample size and carrying out more work are not
the only way to manage detection risk.
• Detection risk is also a function of the effectiveness of an audit
procedure and the way it is applied by an auditor (ie non-sampling
risk).
• The next slide shows examples of sampling risk and non-sampling
risk.
• We look at audit sampling in detail in Chapter 11.
• Control risk and inherent risk together make up the risk of material
misstatement.
• Audit risk must always be set 'to an acceptably low level' – the risk
of the auditor giving the wrong opinion should obviously be as low as
possible.
• Auditors will assess inherent risk and control risk as high, medium or
low.
• Detection risk is the balancing figure in the audit risk equation. So if
inherent risk and control risk are assessed as high, detection risk
must be as low as possible for audit risk to remain low.
AR = IR x CR x DR
Audit Risk Control risk
Inherent Risk
Detection Risk
IR
CR
DR
AR
AR CR
Benchmark %
Profit before tax 5
Gross profit 0.5 – 1
Revenue 0.5 – 1
Profit after tax 5 – 10
Total assets 1–2
Net assets 2–5
Performance materiality
• The auditor is required to set performance materiality as well as
Overall Materiality (OM) for the financial statements as a whole.
• Performance Materiality (PM) is the amount(s) set by the auditor at
less than materiality for the financial statements as a whole to reduce
to an appropriately low level the probability that the aggregate of
uncorrected and undetected misstatements exceeds materiality for
the financial statements as a whole.
• Performance materiality also refers to the amount or amounts set by
the auditor at less than the materiality level(s) for particular classes of
transactions, account balances or disclosures.
➢ Revision of materiality: Level of materiality should be revised for the financial statements
as a whole if during the audit it appears that actual results are going to be significant
different from expected results, which are used to calculate materiality for the financial
statements as a whole during planning (ISA 320: para. A 12)
➢ Documentation of materiality, IAS requires the following to be document:
• Materiality for the financial statements as a whole
• Materiality level of levels for particular classes of transactions, account balance or
disclosure if applicable
• Performance materiality
• Any revision of the above as the audit progress
(ISA 320: para. 14)
During the planning stages of the final audit, the auditor believes that the probability of giving
an inappropriate audit opinion is too high.
How should the auditor amend the audit plan to resolve this issue?
A Increase the materiality level
B Decrease the inherent risk
C Decrease the detection risk
Increasing the materiality level would mean that the auditor considered the audit to be of a
lower risk. Inherent risk cannot be controlled by the auditor. The only element of audit risk
that is within the auditor's control is detection risk, so if there is a high risk of giving an
inappropriate audit opinion, the auditor needs to ensure that detection risk is as low as
possible.
What does an auditor need to understand about the entity and its
environment?
• Industry, regulatory and external factors (including financial reporting
framework)
• Nature of the entity (eg operations; ownership; governance; structure;
financing)
• Selection and application of accounting policies
• Objectives and strategies and related business risks
• Measurement and review of financial performance
• Internal control
(ISA 315 (revised): paras.11-12)
Have a look at this useful article from the January 2013 edition of
Student Accountant, which covers ISA 315:
[Link]
students/2012s/sa_jan13_fau_f8_p7_isa315.pdf
• The auditor must also consider significant risks, ie those that require
special consideration.
• Factors that give risk to significant risks include:
— The risk of fraud
— Relationship with economic, accounting or other developments
— Degree of subjectivity
— Unusual transaction
— Significant transaction with a related party
— Complexity of transaction
• Audit risk is a key syllabus area and you are very likely to get a
question on risk in the exam.
• This could be tested either as knowledge-based or scenario-
based requirements so could appear in both section A and section
B (either in a 10-mark or a 20-mark question).
• It is very important that you understand what audit risk is and can
distinguish it from business risk.
• This area of the syllabus is best tackled by practising as many
past exam questions as possible.
• Have a look at this article published by the F8 examiner in
November 2011:
[Link]
journey/qual-resource/acca-qualification/f8/technical-articles/audit-
[Link]
• Audit risk questions may present you with a scenario and ask you
to identify the audit risks and explain the auditor's responses to
those risks.
• This type of requirement has come up in June 2011, December
2011, December 2012 and June 2013 (all worth 10 marks) under
the old syllabus. A similar question appears in the Specimen
Paper (section B, question 5a), worth 15 marks.
• For these type of questions, use a columnar format, headed 'Audit
risks' and 'Auditor's responses'.
• Make sure you explain fully the risk to the financial statements –
you won't get full marks for simply writing down the risk factor (eg
'inventory')
• What financial statement risks might arise from inventory? (eg risk
that net realisable value of inventory is lower than cost and
therefore inventory figure is overstated)
• The auditor's responses need to be specific. Writing down things
like 'Discuss with management' is vague – you need to explain
what exactly the auditor needs need to discuss with management.
• Suitable responses to each risk may also depend on the particular
circumstances of the client and the environment in which it
operates. Make sure you tailor any responses you recommend so
that they are appropriate to the scenario.
You are the audit senior of Holtby & Co and are planning the audit of Walters Co (Walters) for
the year ended 31 December 20X4. The company produces printers and has been a client of
your firm for two years; your audit manager has already had a planning meeting with the
finance director. He has provided you with the following notes of his meeting and financial
statement extracts.
Walter's management were disappointed with the 20X3 results and so in 20X4 undertook a
number of strategies to improve the trading results. This included the introduction of a
generous sales-related bonus scheme for their salesmen and a high profile advertising
campaign. In addition, as market conditions are difficult for their customers, they have
extended the credit period given to them.
The finance director of Walters has reviewed the inventory valuation policy and has included
additional overheads incurred this year as he considers them to be production related.
The finance director has calculated a few key ratios for Walters; the gross profit margin has
increased from 44.4% to 52.2% and receivables days have increased from 61 days to 71
days. He is happy with the 20X4 results and feels that they are a good reflection of the
improved trading levels.
Required:
(a) Using the information above:
(i) Calculate an additional THREE ratios, for BOTH years, which
would assist the audit senior in planning the audit; and
(3 marks)
(ii) From a review of the above information and the ratios
calculated, describe SIX audit risks and explain the auditor's
response to each risk in planning the audit of Walters Co.
(12 marks)
• Notice the specific requirements in each part – in (i), you need to calculate an additional
three ratios for both years. Therefore, make sure you do this and remember the ratios you
have already been given in the scenario.
• In (ii), you need to describe six audit risks and the auditor's responses in each case.
Students often misinterpret the part about auditor's responses and instead provide
additional explanation of the risk.
• Part (ii) would be best answered in a columnar format so the risk and response can be
linked.
• Go through the scenario line-by-line and note down the risk areas.
• Use the ratios calculated in (i) to support your answer in (ii).
• Remember not to confuse audit risk and business risk!
The increase in cost of sales (10%) does not match The auditors will need to focus on sales testing
the increase in revenue (28%) in the year. This and the testing of expenses. They should also
gives rise to the risk that revenue has been discuss the reason for the disproportionate
overstated and cost of sales has been increase in the gross margin with the finance
understated. director.
The finance director has included some additional The inventory policy needs to be discussed with
overheads in inventory. Inventory days have the finance director. The auditors should examine
increased from 58 days to 70 days. Inventory may the nature of the additional overheads included
therefore be overstated and expenses in inventory to confirm whether their inclusion is
understated. correct. Detailed cost and NRV testing should be
performed and the aged inventory listing
reviewed to assess the need for write-down.
Receivables days have increased from 61 days to 71 The auditors should carry out detailed substantive testing
days. This means customers are taking longer to pay the on year end receivables, including monitoring post year
company. This gives rise to the risk of receivables end receipts and review of the aged receivables ledger
being overstated if some customers are be unable to to assess recoverability.
pay.
The company now has a significant overdraft. This, The auditors should discuss whether the company can
together with the worsening liquidity position (shown by continue as a going concern with the directors and also
the current and quick ratios), gives rise to the going carry out a detailed going concern review, including
concern risks. review of forecasts and budgets.
Required:
Using the information provided, describe FIVE audit risks and explain
the auditor's response to each risk in planning the audit of Donald
Co. (10 marks)
• Firstly notice the requirement for FIVE audit risks and responses.
Make sure you provide five in your answer.
• You need to describe the audit risks and explain the auditor's
responses.
• Assume one mark for each risk and one mark for each response.
• Go through the scenario line-by-line to pull out the areas of
potential audit risk. This has been done for you in the next two
slides in colour.
• Use a columnar format for your answer (with the risks in one
column and the responses to that risk in the other column).
• Use a ruler for the table and headings to improve your
presentation.
The company has applied for a bank loan Discuss the progress of the loan
of $25m to fund the purchase of new application with directors.
planes and refurbishment costs. There is Perform a going concern review, looking
a risk that the company cannot continue at cash flow forecasts and projections for
as a going concern if the loan is not the next year.
approved.
There is a risk of the receivables balance Increased substantive testing using
in the financial statements being receivables' confirmation and review of
misstated as some balances due from after-date cash. Discuss with directors the
travel agents may not be recoverable. requirement for an allowance for
irrecoverable debts.
Fraud
Fraud is an intentional act by one or more individuals among
management, those charged with governance, employees or third parties
involving the use of deception to obtain an unjust or illegal
advantage. Fraud may be perpetrated by an individual, or colluded in,
with people internal or external to the business.
Fraud risk factors are events or conditions which indicate an incentive
or pressure to commit fraud, or provide an opportunity to commit fraud.
There are two types of fraud:
1. Fraudulent financial reporting
2. Misappropriation of assets
Examples
• Manipulation, falsification or alteration of accounting records and/or
supporting documents
• Misrepresentation (or omission) of events or transactions in the
financial statements
• Intentional misapplication of accounting principles
Misappropriation of assets
Involves the theft of an entity's assets and is often perpetrated by
employees in relatively small and immaterial amounts. However, it can
also involve management who are usually more capable of disguising or
concealing misappropriations in ways that are difficult to detect.
Examples
• Embezzling receipts (for example, diverting them to private bank
accounts)
• Stealing physical assets or intellectual property (inventory, selling
data)
• Causing an entity to pay for goods not received (payments to fictitious
vendors)
• Using assets for personal use
BPP LEARNING MEDIA
Real World Example: Saytam Computer Services
Written representations
ISA 240 requires the auditor to obtain written representations from
management and those charged with governance that:
• They acknowledge their responsibility for the design, implementation
and maintenance of internal control to prevent and detect fraud.
• They have disclosed to the auditor management's assessment of
the risk of fraud in the financial statements.
• They have disclosed to the auditor their knowledge of any fraud or
suspected fraud which could have a material effect on the financial
statements.
• They have disclosed to the auditor their knowledge of any
allegations of fraud or suspected fraud communicated to
employees, former employees, analysts, regulators or others.
Management's responsibility
To ensure that the entity complies with the relevant laws and regulations.
It is not the auditor's responsibility to prevent or detect non-compliance
with laws and regulations.
Auditor's responsibility
To obtain reasonable assurance that the financial statements are free
from material misstatement.
However, auditor must also take into account the legal and regulatory
framework within which the entity operates.
• ISA 240 and ISA 250 are more likely to be tested as a short
requirement worth three or four marks in section B.
• The examiner wants to test your understanding of the respective
responsibilities of management and the external auditor in relation
to fraud and in relation to compliance with laws and regulations.
• The F8 examiner has tested these elements of the syllabus in
previous sittings (December 2011 (question 1c), June 2012
(question 3a) and June 2013 (question 4b)).
• Auditors must document the work they have done at the risk
assessment stage.
• We will look at documentation in greater detail in Chapter 7 when we
discuss the audit strategy and the audit plan.
• But there are a number of matters which need to be documented
during the risk assessment and planning stages of an audit…