0% found this document useful (0 votes)
7 views137 pages

Auditing Master Notes

The document outlines the curriculum for an Advanced Auditing course, detailing key topics such as pre-engagement activities, audit planning, and corporate governance. It emphasizes the importance of professional conduct, including integrity, objectivity, and confidentiality, while also discussing the limitations of audits and the audit risk model. Additionally, it highlights the ethical considerations auditors must adhere to, including threats to compliance with fundamental principles and the importance of maintaining professional skepticism.

Uploaded by

makufadziva
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views137 pages

Auditing Master Notes

The document outlines the curriculum for an Advanced Auditing course, detailing key topics such as pre-engagement activities, audit planning, and corporate governance. It emphasizes the importance of professional conduct, including integrity, objectivity, and confidentiality, while also discussing the limitations of audits and the audit risk model. Additionally, it highlights the ethical considerations auditors must adhere to, including threats to compliance with fundamental principles and the importance of maintaining professional skepticism.

Uploaded by

makufadziva
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ADVANCED AUDITING

ACC 410

1
Module outline
•Pre –engagement activities
•Planning for an audit
•Obtain audit evidence
•Concluding an audit and reporting
•Other engagements
•Corporate governance (King iv)
•The Companies Act
•PAAB Act

2
Admin issues
• COURSE ASSESSMENT
• Course work (Written) 30%
• Examination 70%
• Total 100%
At the end of the semester you are going to write a 3 hr
examination. Application exam (Scenario based)

3
Rules of the game (Cardinal)
1. Answer in point form (very important)
2. Skip a line after each and every point
3. Write legibly
4. Answer each question on a separate
page
5. Use tabular format (wherever possible)

4
Major changes to ISAs
•ISA 260 – Effective 15 Dec 2016

•ISA 570 – Effective 15 Dec 2016

•ISA 701 – Effective 15 Dec 2016 (New)

•ISA 705 – Effective 15 Dec 2016

5
Introduction to Auditing
Overall Audit objective (ISA 200: 3)
•The objective of an audit is to
expression of an opinion on whether
the financial statements are
prepared, in all material respects, in
accordance with an applicable
financial reporting framework.

6
Introduction to Auditing
ISAs do not impose responsibilities on management or those
charged with governance and do not override laws and
regulations that govern their responsibilities. However, an
audit in accordance with ISAs is conducted on the premise
that management and, where appropriate, those charged
with governance have acknowledged certain responsibilities
that are fundamental to the conduct of the audit.

The audit of the financial statements does not relieve


management or those charged with governance of their
responsibilities.

7
Basic Auditing premise
An audit in accordance with ISAs is conducted on the
premise that management and, where appropriate, those
charged with governance have acknowledged and
understand that they have responsibility:
(a) For the preparation of the financial statements in
accordance with the applicable financial reporting
framework
(b) For the design of internal control necessary to enable
the preparation of financial statements that are free from
material misstatement, whether due to fraud or error; and

8
Basic Auditing premise (cont’d)
(c) To provide the auditor with:
• (i) Access to all information of which management is aware
that is relevant to the preparation of the financial statements
such as records, documentation etc
• (ii) Additional information that the auditor may request from
management and for the purpose of the audit
• (iii) Unrestricted access to persons within the entity from
whom the auditor determines it necessary to obtain audit
evidence

9
Basic Auditing premise
Because of the significance of the premise to the
conduct of an audit, the auditor is required to
obtain the agreement of management and,
where appropriate, those charged with
governance that they acknowledge and
understand that they have the responsibilities
set out in the basic premise as a precondition
for accepting the audit engagement. (ISA 200:
A10)

10
Introduction to Auditing
An audit is not conducted on a 100% population , as
such an auditor can only obtain reasonable assurance
(not absolute) about whether the financial statements
as a whole are free from material misstatement,
whether due to fraud or error.
An auditor cannot give an absolute assurance due to
inherent limitations of an audit as well as limitations of
internal controls.

11
Introduction to Auditing
Reasonable assurance is a high level of assurance. It is
obtained when the auditor has obtained sufficient
appropriate audit evidence to reduce audit risk to an
acceptably low level

12
Limitations of an Audit (ISA 200:
A45-52
• An audit is performed on a sample basis (balance
between cost and benefit), there is a need for audit
to be conducted within a reasonable period of time
within a reasonable time at and at reasonable cost
•Audit evidence is persuasive rather than conclusive
•Nature of financial reporting (use of estimates)
•Limitations of internal controls:
❖ management override of controls
❖Collusion

13
Limitations of an Audit Qsn (ACC 214 June 2014 Exam
A junior member of the audit team of 21st Century registered
auditors was at the conclusion of the audit, requested to make
sure that the audit working papers were all properly filed and
finalised. What struck him was the volume of information in the
working papers. Having seen all the evidence together, he really
felt that the audit team was in a strong position to certify the
financial statements as correct, rather than just stating in the
audit report that, “in our opinion, the financial statements,
present fairly in all material respects….”

He asked you, his senior why, having all this work, the financial
statements had not been certified as correct.

14
Limitations of an Audit Qsn Cont’d
Required
Explain in detail to your junior, why the financial
statements cannot be certified. Include in your answer
an explanation of the limitations of the internal
controls and the limitations of an audit.
(12 marks)

15
Key definitions
Audit risk
Audit risk – The risk that the auditor expresses an
inappropriate audit opinion when the financial statements
are materially misstated. Audit risk is a function of the risks
of material misstatement and detection risk.

NB// Audit risk does not include the risk that the auditor
expresses an opinion that the financial statements are
materially misstated when they are not. This risk is
ordinarily insignificant.

16
Key definitions (Cont’d)
Risk of material misstatement (RMM):
Is the risk that the financial statements are
materially misstated prior to an audit being
performed on them. RMM consists of two
components which are ; Inherent risk and
Control risk

17
Key definitions (Cont’d)
Inherent risk
It the susceptibility of an assertion about a
class of transaction, account balance or
disclosure to a misstatement that could be
material either individually or when
aggregated with other misstatements

18
Key definitions (Cont’d)
Control risk
Is the risk that a misstatement could occur in the
financial statements, that could be material,
(either individually or when aggregated with
other misstatements), will not be prevented, or
detected or corrected on a timely basis by the
entity’s internal controls

19
Key definitions (Cont’d)
Detection risk
Is the risk that the procedures performed
by the auditor to reduce audit risk to an
acceptably low level will not detect a
misstatement that exist and that could be
material , either individually or when
aggregated with other misstatements

20
The Audit risk Model

RMM

Audit risk = IR * CR
* DR

21
Key definitions (Cont’d)
Professional skepticism
Is an attitude that includes a questioning
mind, being alert to conditions which may
indicate possible misstatements

22
Professional skepticism (Cont’d)
It includes being alert to:
•Audit evidence that contradicts each other
•Conditions that may indicate possible fraud
•Circumstances that suggest the need for audit
procedures in addition to those required by ISAs
•Information that brings into question the
reliability of documents and responses to
inquiries to be used as audit evidence

23
The CODE OF PROFESSIONAL CONDUCT
ACC 410

24
THE CODE OF PROFESSIONAL CONDUCT
A distinguishing mark of the accountancy and auditing
profession is its acceptance of the responsibility to act in
the public interest. Therefore, an auditor’s responsibility
is not exclusively to satisfy the needs of an individual
client. In acting in the public interest, the auditor has to
comply with the code of professional conduct (CPC)
Code.

25
FUNDAMENTAL PRINCIPLES
[Link]
[Link]
[Link] competence & due care
[Link]
[Link] behaviour

26
FUNDAMENTAL PRINCIPLES (FPs) (Cont’d
Integrity – to be straight forward and honest in all
professional and business relationships

An auditor shall not knowingly be associated with


reports where the auditor believes:
• contains a materially false or misleading statement
•Omits or obscures information required to be
included where such omission or obscurity would
be misleading
27
FUNDAMENTAL PRINCIPLES (FPs) (Cont’d

Objectivity – not to allow bias, conflict of


interest or undue influence of others to
override professional or business
judgements

28
CODE OF PROFESSIONAL CONDUCT
Professional competence and due care – to
maintain professional knowledge and skill at the
level required to ensure that a client receives
competent professional services based on current
developments in practice, legislation and
technical and act diligengtly and in accordance
with applicable technical and professional
standards

29
CODE OF PROFESSIONAL CONDUCT (Cont’d)

Confidentiality – to respect the confidentiality of


information acquired as a result of professional
and business relationships and therefore , not
disclose any such information to third parties
without proper and specific authority, unless
there is a legal or professional right or duty to
disclose, nor use the information for personal
advantage

30
CODE OF PROFESSIONAL CONDUCT (Cont’d)

The following are circumstances where an auditor


may be required to disclose confidential
information:

• disclosure is permitted by law and is authorised


by the client
• disclosure is required by law
•When there is a professional duty to disclose and
when it is not prohibited by law
31
CODE OF PROFESSIONAL CONDUCT (Cont’d)
Professional behaviour – to comply with relevant
laws and regulations and avoid any action that
discredits the auditing profession

Auditors shall be honest and truthful in marketing


their work and not:
a) Make exaggerated claims for the services they
are able to offer
b) Make disparaging references or unsubstantiated
comparisons to the work of others
32
Threats to Compliance with FPs
Self-interest threat - the threat that a financial or other
interest will inappropriately influence the auditor’s
judgment or behaviour;

Examples of circumstances that create self-interest


threats include:
• A member of the assurance team having a direct
financial interest in the client.
• A firm having undue dependence on total fees from a
client.
• A firm entering into a contingent fee arrangement
33
Threats to Compliance with FPs
Self-review threat - the threat that auditor will not
appropriately evaluate the results of a previous judgment
made or service performed by the auditor, or by another
individual within the audit firm, on which the auditor will
rely when forming a judgment as part of providing a
current service;

Eg A member of the assurance team being, or


having recently been, a director or officer of the
client.
34
Threats to Compliance with FPs
Advocacy threat - the threat that the auditor
will promote a client’s position to the point
that the auditor’s objectivity is compromised;

e.g. The firm promoting shares in an audit


client.

35
Threats to Compliance with FPs
Familiarity threat - the threat that due to a
long or close relationship with a client, a
auditor will be too sympathetic to their
interests or too accepting of their work;

E.g A member of the engagement team having a


close or immediate family member who is a director
or officer of the client.
36
Threats to Compliance with fundamental PPs
Intimidation threat - the threat that the
auditor will be deterred from acting
objectively because of actual or perceived
pressures, including attempts to exercise
undue influence over the auditor

E.g A firm being threatened with dismissal from a


client engagement.

37
Firm wide safeguards to reduce threats 200:12

Safeguards are actions or other measures that may


eliminate threats or reduce them to an acceptable level
these include:

• Leadership that stresses the importance of compliance


with fundamental principles
•A disciplinary mechanism to promote compliance with
policies and procedures
•Using different partners & engagement teams with
separate reporting lines for the provision of non
assurance services to an assurance client
38
Safeguards to reduce threats (Cont’d)
•Educational, training and experience requirements for
entry into the profession.
• CPDs
• Corporate governance legislation or regulations.
• Professional standards.
• Professional or regulatory monitoring and disciplinary
procedures.
• External review

39
Recruiting (Sec 150.10)
A registered auditor shall not, directly or indirectly, offer
employment to an employee of another registered auditor without
first informing the latter.

40
Fees and Other Types of Remuneration (Sec 240)
⚫When entering into negotiations regarding professional services, a
registered auditor may quote whatever fee is deemed appropriate.
The fact that one registered auditor may quote a fee lower than
another is not in itself unethical.

⚫Nevertheless, there may be threats to compliance with the


fundamental principles arising from the level of fees quoted.

For example, a self-interest threat to professional competence and


due care is created if the fee quoted is so low that it may be difficult
to perform the engagement in accordance with applicable technical
and professional standards for that price.
41
Fees and Other Types of Remuneration (Sec 240)
Contingent fees
⚫Contingent fees are widely used for certain types of non-assurance
engagements .They may, however, create threats to compliance
with the fundamental principles in certain circumstances. They may
create a self-interest threat to objectivity.

⚫Wef 1 March 2014. SAICA no longer allows any of its member to


charge contingent fees for tax return preparation.

42
Marketing Professional Services (Sec 250)
⚫When a registered auditor solicits new work through advertising or other
forms of marketing, there may be a threat to compliance with the
fundamental principles.
⚫ For example, a self-interest threat to compliance with the principle of
professional behaviour is created if services, achievements, or products are
marketed in a way that is inconsistent with that principle,
A registered auditor shall not bring the profession into disrepute when
marketing professional services. The auditor shall be honest and
⚫truthful and shall not:
⚫(a) Make exaggerated claims for services offered, qualifications possessed,
or experience gained; or
⚫(b) Make disparaging references or unsubstantiated comparisons to the
work of another.
43
Gifts and Hospitality (Sec 260)
⚫Gifts from clients pose a threat to compliance with Fundaments principles.
⚫The existence and significance of any threat depends on the nature,
value, and intent of the offer.

44
Custody of client assets (Sec 270)
⚫A registered auditor shall not assume custody of client monies or other
assets unless permitted to do so by law and, if so, in compliance with any
additional legal duties imposed on a registered auditor holding such assets.
⚫The holding of client assets creates a self interest threat.
⚫A registered auditor entrusted with money (or other assets) belonging to
others shall therefore:
(a) Keep such assets separately from personal or firm assets;
(b) Use such assets only for the purpose for which they are intended;
(c) At all times be ready to account for those assets and any income,
dividends, or gains generated, to any persons entitled to such accounting;
and
(d) Comply with all relevant laws and regulations relevant to the holding of
and accounting for such assets.
45
Custody of client assets (Sec 270)
A registered auditor is required to make appropriate inquiries about
the source of such assets and consider legal and regulatory
obligations. eg, if the registered auditor has reason to believe that
the assets were derived from illegal activities, such as money
laundering, a threat to compliance with the fundamental principles
would be created.

In such situations, the registered auditor shall not accept or hold


the client monies

46
CPC Illustrative Question

Brian Maphosa CA(Z) is a registered auditor and conducts the


audit of MSU (Pvt) Ltd, as well as acting for the company in tax
matters. Barbican Bank, which has a substantial long-term
investment in MSU (Pvt) Ltd, requires, in terms of its agreement
with MSU (Pvt) Ltd, that the company’s annual financial
statements be audited by a registered auditor and submitted to
the bank. During the current year’s audit of this client, Brian
discovers that Tapiwa Kamba, a major shareholder and managing
director of the company, has been maintaining another set of
accounting records which reflect the true situation whilst he has
been auditing and submitting tax returns based on a fraudulent
set of accounting records.
47
CPC Illustrative Question

When Brian confronts Tapiwa Kamba with this evidence, he admits


that he has done this for some years but indicates that he is not at all
worried about it, because he was only able to get away with it due to
the inadequate audit which Brian had conducted over the years. Kamba
further states that should Brian report the matter to anyone, he will
simply state that he was a willing partner to the fraud.

On scrutiny of correspondence from his past dealings with Kamba and


of prior audit working papers, Brian realises that he could indeed
appear to have conspired with Kamba as his audit documentation could
be considered to be inadequate and he had not followed up on a
number of queries concerning the audit. Furthermore, a large
percentage of his professional fees comes from work referred to him by
Kamba. 48
CPC Illustrative Question

REQUIRED
Discuss fully the situation in which Brian finds himself in relation
to the Code of Professional Conduct (13 marks)

-
49
CPC Illustrative Suggested Solution

There is no doubt that Brian has failed to comply with a number


of the fundamental principles on which the code is based.
• Objectivity - Section 120 - by allowing himself to get to a
situation where a large percentage of her professional fees to
come from work referred by Kamba, he has created a
self-interest threat to his independence. (2)

• Professional Competence and Due Care - Section 130. As the


prior year progressed, Brian failed to realise that his poor
performance posed a threat to his compliance with this principle.
It appears that he became too “comfortable” with the
engagement and clearly did not apply the ISAs adequately, e.g. by
- of his poor working papers and his failure to follow up
virtue
queries. 50
CPC Illustrative Suggested Solution

Integrity - Section 110


If Brian was to take no action he would be in breach of this
section which states that professional accountants should be
straightforward, honest and truthful (1)

The only safeguard to prevent this would be to report Tapiwa


Kamba and take the consequences (1)

-
51
CPC Illustrative Suggested Solution
The fraudulent tax returns submitted to ZIMRA. Brian should:
• Promptly advise Kamba to make full disclosure to ZIMRA
concerning the fraudulent submissions previously made. (1)

• He should also advise Kamba of the consequences of him failing


to do so, e.g. potential penalties, and of the powers which ZIMRA
has in these situations e.g. call for information from himself. (1)

• Inform Kamba that he will no longer act for him in any tax matters
and that he will be resigning from his appointment with MSU (Pvt)
Ltd (both tax and audit). (1)
• This is the only safeguard which would adequately address the
threats posed to the fundamental principles
-
52
CPC Illustrative Suggested Solution

Confidentiality – Section 140


• In terms of this section, Brian will be in breach of the Code if he
divulges confidential information about a client unless. (1)
− he has permission to do so (unlikely to get this); (1)
− there is a legal duty to do so (1)
− there is a professional duty to do so . (1)

53
The audit process
1. Preliminary engagement activities

2. Planning
(Establish audit strategy & plan)

3. Obtain audit evidence


( SARs,TOCs,SPs)

4. Evaluate, conclude and report


54
1. Preliminary engagement activities
Background
The first step in the audit process is to perform
preliminary engagement activities. During this step
the auditor assesses whether or not to act as an
auditor for a new client or to continue acting as an
auditor for an existing client. The auditor should take
into consideration the risks of legal liability or
reputational damage, whether a quality audit can be
conducted in terms of ISAs as well as regulatory and
ethical requirements.
55
1. Preliminary engagement activities

1. Client investigation

2. Determination of skills, competence &


resources

3. Set engagement terms (engagement letter)


– ISA 210

56
Client investigation

57
Client investigation (cont’d)
Independence of the auditor and threats to
auditor independence
Ability and willingness of the client to pay
audit fees
Integrity of management
Results of communication with the previous
auditor
Existence of a vacancy in the position of
auditor 58
Determination of skills &
resources

59
b)Determination of skills & resources
- Size of the audit team required
- Whether there is need for use of an
expert (the expert’s availability if
needed)
- Technology required
- Audit deadline (ability to meet it)
60
Agree engagement terms (ISA
210)

61
c) Agree engagement terms (ISA 210)
Agree engagement terms highlighting
management and auditor’s
responsibilities

62
Engagement letter
An engagement letter is a formal
document that defines the legal
relationship between the audit firm and
the client

63
Engagement letter (Cont’d)
Contents of an engagement letter (ISA 210: 10; A23
Standard information
• The responsibilities of an auditor
• The responsibilities of management
• The objective and scope of the audit of the financial
statements
• Identification of the applicable financial reporting
framework .
• the fact that there is an unavoidable risk that some
misstatements may not be detected (due to audit
limitations)
64
Engagement letter (Cont’d)
Contents of an engagement letter (ISA 210: 10; A23
Standard information (cont’d)

• A request for management to acknowledge receipt of


the engagement letter and to agree to its terms
• Date of preparation
• Space for both the auditor and the client to sign

65
Contents of an Engagement letter (Cont’d

Additional information
Planning and audit execution arrangements
•An expectation that management will provide written
representations
•Any restriction of the auditor’s liability when such
possibility exists
•The basis on which fees are computed and any billing
arrangements

66
67
Engagement letter (Cont’d
Audit of components
When the auditor of a parent entity is also the auditor of a
component, the factors that may influence the decision
whether to send a separate audit engagement letter to the
component include the following:

•Who appoints the component auditor;


• Whether a separate auditor’s report is to be issued on the
component;
• Legal requirements in relation to audit appointments;
• Degree of ownership by parent; and
• Degree of independence of the component management
from the parent entity.
68
Engagement letter (Cont’d)
Recurring audits (ISA 210 : 13, A28
The auditor may decide not to send a new audit engagement letter or other
written agreement each period. However, the following factors may make it
appropriate to revise the terms of the audit engagement or to remind the
entity of existing terms:
• Any indication that the entity misunderstands the objective and scope of
the audit.
• Any revised or special terms of the audit engagement.
• A recent change of senior management.
• A significant change in ownership.
• A significant change in nature or size of the entity’s business.
• A change in legal or regulatory requirements.
• A change in the financial reporting framework adopted in the preparation
of the financial statements.
• A change in other reporting requirements.
69
1. Preliminary engagement activities
Types of questions that may be asked
• Discuss your concerns regarding the
acceptance of the audit client.
• Discuss the factors to consider prior to
accepting the audit client.
• Discuss your concerns with regards to the
engagement letter. (Criticise a given
Engagement letter)

70
ISA 220 QUALITY CONTROL FOR AN AUDIT OF FINANCIAL
STATEMENTS

Engagement quality control reviewer (ECQR) A


partner, other person in the firm, suitably
qualified external person, or a team made up of
such individuals, none of whom is part of the
engagement team, with sufficient and appropriate
experience and authority to objectively evaluate
the significant judgments the engagement team
made and the conclusions it reached in
formulating the auditor’s report.
71
Engagement Quality Control Review
For audits of financial statements of listed entities, and those
other audit engagements for which the firm has determined that
an engagement quality control review is required, the
engagement partner shall:
⚫(a) Determine that an engagement quality control reviewer has
been appointed;
⚫(b) Discuss significant matters arising during the audit
engagement, including those identified during the engagement
quality control review, with the engagement quality control
reviewer; and
⚫(c) Not date the auditor’s report until the completion of the
engagement quality control review.
72
Engagement Quality Control Review
The engagement quality control reviewer shall perform an objective
evaluation of the significant judgments made by the engagement
team, and the conclusions reached in formulating the auditor’s report.
This evaluation shall involve:
(a) Discussion of significant matters with the engagement partner;
(b) Review of the financial statements and the proposed auditor’s
report;
(c) Review of selected audit documentation relating to the significant
judgments the engagement team made and the conclusions it
reached; and
(d) Evaluation of the conclusions reached in formulating the
auditor’s report and consideration of whether the proposed auditor’s
73
report is appropriate
ISA 220 QUALITY CONTROL FOR AN AUDIT OF FINANCIAL
STATEMENTS

The engagement partner shall take


responsibility for the overall quality on
each audit engagement to which that
partner is assigned

74
2. Planning (ISA 300, 315,320,330)

75
2. Planning (Cont’d)
After an engagement letter has been signed
and agreed, the auditor goes on to plan for
the audit.

Usually, the key engagement team


members are involved in planning , i.e the
engagement partner, manager and the
AIC.(ISA 300:5)

76
2. Planning (Cont’d)

Advantages of planning
⚫ To identify important aspects to address
⚫ To identify potential problem areas and
risks involved
⚫ To ensure a cost effective audit
⚫ Adds value to the client
⚫ Help with allocation of work to assistants
77
2. Planning (Cont’d)
Scope of planning will depend on:
⚫ The size of the entity
⚫ Complexity of the client
⚫ Knowledge of the client’s business
⚫ Previous experience and findings
⚫ Results of preliminary analytical
procedures

78
Audit strategy
The auditor shall establish an overall audit strategy that sets
the scope, timing and direction of the audit, and that guides
the development of the audit plan.

In establishing the overall audit strategy, the auditor shall:


(a) Identify the characteristics of the engagement (scope)
(b) Ascertain the reporting objectives of the engagement
(c) Consider the risk factors that are significant
(d) Consider results of preliminary engagement activities
(e) Ascertain the nature, timing and extent of resources

79
The Audit Plan
The auditor shall develop an audit plan
that shall include a description of:
The nature, timing and extent of:
• planned risk assessment
•planned further audit procedures at the
assertion level
•Other planned audit procedures

80
The Audit Plan Vs Audit Strategy

An Audit plan is a subset of an


Audit Strategy.

81
The planning process
1. Obtain an understanding of the
entity and its internal controls
(PARs, Discussions, System
documentation, (ISA 315)
2. Identify and Assess risk (@ OFSL
and at AL)
3. Set materiality (ISA 320)
4. Develop Audit plan and Audit
Strategy (Risk response) (ISA330) 82
Understanding the entity & its environment
The Entity , its Environment and Internal Controls
The auditor shall obtain an understanding of the following:
(a) Relevant industry, regulatory, and other external factors
including the
applicable financial reporting framework.
(b) The nature of the entity(operations, governance structures):
(c) The entity’s selection and application of accounting policies
(d) The entity’s objectives and strategies, and those related
business risks
(e) The measurement and review of the entity’s financial
performance.
(f) The entity’s internal controls (culture of the org)
83
Risk assessment

After obtaining knowledge, the auditor shall


identify and assess risk :

• At the overall financial statement level


•At assertion level

84
Risk at overall financial statement level
Risk Indicator Risk Description

Operations in regions or The AFS may be materially misstated as the entity might
countries with strict not comply properly with the relevant laws and
regulations/different regulations possibly resulting in material misstatements
regulations to Zimbabwe. of unrecorded liabilities, expenses, etc.
Going concern issues - The AFS may be materially misstated as the going
concern assumption might not be properly accounted for
and/or disclosed.
- The AFS may be materially misstated by engaging in
fraudulent financial reporting to hide going concern
threat.
Financials to be used to The AFS may be materially misstated as directors
obtain financing from the might engage in fraudulent financial reporting, i.e.
bank. overstatement of assets and profits and understatement
of liabilities and expenses to ensure that financing will be
obtained.
85
Risk at overall financial statement level
Risk Indicator Risk Description

Changes in the industry and The AFS may be materially misstated as the entity might
management does not want not comply with the changes to the laws Companies Act,
to comply. Banking Act etc., in the industry within which it operates.

Expanding into new The AFS may be materially misstated as the control
locations/ decentralisation environment in other locations might not be operating
of the entity. effectively.
Lack of personnel with The AFS may be materially misstated as there might be
appropriate accounting and errors occurring in the preparation of financial records.
financial reporting skills.

Management receives The AFS may be materially misstated as directors


bonuses driven by profits might engage in fraudulent financial reporting, i.e.
overstatement of revenue and understatement of
expenses to maximise bonuses.
86
Risk at overall financial statement level
Risk Indicator Risk Description

New client. The AFS may be materially misstated as the


opening balances might be incorrect since we were not auditors in
prior years.
• The AFS may be materially misstated as material misstatements
could go undetected as we are not familiar with the client.
• The AFS may be materially misstated by management due to the
fact that the new auditors have limited knowledge of the entity.
Management’s The AFS may be materially misstated as the control environment
integrity might be compromised by management who lacks integrity.
questionable.
Use of work of The AFS may be materially misstated as the third party might not be
third party (ISA competent and appropriately qualified in performing the work
600, 610,620) required for audit evidence.

87
Risk at overall financial statement level
Risk Indicator Risk Description

Tight audit - The AFS may be materially misstated as management


deadline. might not have sufficient time to properly account and
disclose post balance sheet events (Subsequent
events).
- There is a risk that the auditor might not have sufficient time to
obtain the audit evidence resulting in material misstatement going
undetected.
Listed on the The AFS might be materially misstated as the company
ZSE. might not comply with ZSE regulations resulting in the delisting of the
company and affecting the going concern of the company.
Change of the The AFS may be materially misstated as the financial data might not
accounting be properly transferred from the old accounting system to the new
software. accounting system.

88
Risk at overall financial statement level
Risk Indicator Risk Description

Group set up The AFS may be materially misstated as errors might occur during
consolidation as it involves an intricate process possibly resulting in
material misstatements.

The AFS may be materially misstated as related party transactions


might not be eliminated on consolidation.

The AFS may be materially misstated as the consolidation


might not be properly done in terms of IAS 27.

Acquired a The AFS may be materially misstated as IFRS 3 might


subsidiary not be properly accounted for.
during the yr

89
Risk at overall financial statement level
MSU Holdings is a company that makes and sells paper
and is listed on the ZSE Ltd. MSU has been audited by
Super Auditors since its inception 14 years ago. MSU has a
year end of 31 December 2016. The audit report is
required on 20 January 2017. During the financial year
under review MSU gained control of GZU (Pvt) Ltd, a
company that leases out printers for a long term. GZU
has a 30 September year end. For the 2016 financial year,
GZU will be audited by one of the major firms in the
country. Directors of MSU receive share options based on
net profit.

90
Risk at overall financial statement level
Required:

Discuss the audit risks at the overall financial


statement level of MSU Ltd and its group for the year
ended 31 December 2016. (8 marks)

Required:

Discuss the risk of material misstatement at the


overall financial statement level of MSU Ltd and its
group for the year ended 31 December 2016. (8
marks) 91
Risk Indicator Risk description
Risk at overall financial statement level
Listed on the ZSE •The AFS may be materially misstated as MSU Holdings might
not comply with ZSE regulations.

•The AFS may be materially misstated as management might


overstate the profits in order to manage the share price

A group set up • Intercompany balances might not be properly eliminated


•Internal controls might not be uniformly applied accross the
group
•The financial statements of GZU might not be properly
adjusted for consolidation purposes

Tight audit • Subsequent events might not be properly identified


deadline • The AFS might contain errors due to time pressure
Control gained • At the date of gaining control assets and liabilities might not
during the year have been measured in accordance with IFRS 3 therefore
misstating goodwill
92
Risk at assertion level
Risk at the assertion level
E.g. Sales are made to foreign customers in their respective
currencies
There is a risk that revenue might not be translated at
the correct exchange rate (accuracy).

93
Risk at assertion level (Example 1)
MSU Ltd has out-sourced the capturing of its financial data to
Japu Solutions (Pvt) Ltd. Japu Solutions is paid a standard fee
plus commission on sales reported for the month. MSU Ltd
reported revenue of US $ 100mil for the year-ended 31
December 2016. Revenue comprises of sales made to local and
foreign customers. Foreign customers are invoiced using the
currency of their respective countries. Directors of MSU Ltd
earn a performance related bonus which is a percentage of the
reported profit

Required:
Discuss the risk of material misstatement at the assertion
level on revenue of MSU Ltd for the year ended 31
December 2016. 94
Risk at assertion level
Risk factor, Risk description
Foreign receipts Sales might not have been translated at the correct exchange
rates as required by IAS 21(Accuracy)
Commission paid to Revenue might be overstated by Japu Solutions by recording
Japu Solutions fictitious sales so as to increase the commission (Occurrence)

Japu Soltuions paid Revenue might be recognised net of the commission paid
commission based (accuracy, completeness).
on sales
Performance Management might recognise fictitious revenue in order to
related bonus receive increase their bonus(occurrence)

Management might recognise receipts of the following period


in the current period so as to increase their bonus (
(cut-off)
95
Risk at assertion level (Example 2)
You are a first year trainee accountant of DBO Chartered
Accountants. The audit senior on the job has provided you with the
following information which you will require in the audit of NUST
(Pvt) Ltd.
Revenue for NUST comprises sales made to local and foreign
customers. Foreign customers are invoiced in their respective
currencies. During the year, NUST entered into a forward exchange
contract (FEC) for the goods NUST sold to one of their once off
foreign customers to protect itself against foreign currency
fluctuations. The normal credit terms are 30 days. NUST provides
for credit losses at 2% of the trade receivables balance.
Management of NUST receives a bonus based on profit for the
year. At year-end, trade receivables were factored to provide NUST
with the cash flow that was required. 96
Risk at assertion level (Example 2)
Required:
Discuss the risk of material misstatement at the assertion
level on revenue and debtors of NUST Ltd for the year
ended 31 December 2016.

Present your answers using assertions

97
Risk at assertion level (Suggested sln)
Revenue - RMM
Risk Indicator Risk description Assertion (s)
Foreign customers There is a risk that revenue from foreign Accuracy
are invoiced in foreign customers might not be translated at the
currencies correct exchange rate.
Management There is a risk that revenue might be Cut-off
receives a bonus recognised in the incorrect period in
based on profit for order to inflate the revenue figure for
the year. bigger bonuses.

There is a risk that management Occurrence


might record fictitious sales in order
to inflate the revenue figure for
bigger bonuses.

98
Risk at assertion level (Suggested sln)
Debtors- RMM
Risk Indicator Risk description Assertion (s)
Foreign customers There is a risk that trade receivables might Valuation
are invoiced not be translated at the correct closing rate
in their foreign at year-end.
currencies.
Once-off FEC for There is a risk that FEC gains/losses might Valuation
goods sold to Foreign not be accurately accounted for resulting in
customers. misstatement of trade receivables account.
Management There is a risk that fictitious debtors could Existence
receive bonuses be recorded in the financial records in order
based on net to inflate the revenue figure for
profit for the year. bigger bonuses.

99
Risk at assertion level (Suggested sln)
Debtors- RMM
Risk Indicator Risk description Assertion (s)

Allowance for There is a risk that the allowance for credit losses is Valuation
credit losses. understated to inflate the trade receivables (Accuracy and
account and reflect NUST’s financial position in a completeness
better light. -afcls

Trade There is a risk that the trade receivables account Rights and
receivables does not belong to NUST Ltd since debtors have obligation
are factored. been factored.

100
Assertions ISA 315 (A124)
These are representations by management
(explicit or otherwise) , embodied in the
financial statements

101
SIGNIFICANT RISKS
What should the auditor consider when deciding if a risk is
significant?

Is the risk a risk of fraud? – e.g. revenue recognition


Is the risk related to recent significant economic, accounting or other
developments? – e.g. major economic downturn (GG)
Is (are) the transaction(s) complex? – e.g. loyalty programmes,
Does the risk involve significant transactions with related parties? –
e.g. significant inter-company loans.
What is the degree of subjectivity in the measurement of financial
information related to the risk? – e.g. provisions requiring judgement.
Does the risk involve significant transactions that are outside the
normal course of business for the entity/or appear unusual? - e.g.
company bakes party cakes but suddenly trades in forex
transactions.
102
Assertions – Class of transactions
Occurrence: transactions and events that have been
recorded have occurred and pertain to the entity.
Completeness: all transactions and events that should
have been recorded have been recorded
Accuracy— all amount have been recorded
appropriately.
Cut – off —transactions and events have been
recorded in the correct accounting period.
Classification—transactions and events have been
recorded in the proper accounts.

103
Assertions – Account balances
Existence— A,L & E exist.
Rights and obligations —the entity holds or controls the
rights to assets & liabilities are truly obligations of the
entity.
Completeness: A,L & E that should have been recorded
have been recorded.
Valuation and allocation — A,L & E are included in the
financial statements at appropriate amounts and any
resulting valuation or allocation adjustments are
appropriately recorded.

104
Risk assessment
After we have identified risk, we then go on to assess the risk identified. Risk is
classified into high/low (significant/not significant)Significant risk are those
risks that require special audit attention. In assessing significant risk the
auditor should consider the following

(a)Whether the risk is a risk of fraud;


(b) Whether the risk is related to recent significant economic, accounting or
other developments and, therefore, requires specific attention;
(c) The complexity of transactions;
(d) Whether the risk involves significant transactions with related parties;
(e) The degree of subjectivity in the measurement of financial information
related to the risk, especially those measurements involving a wide range of
measurement uncertainty; and
(f) Whether the risk involves significant transactions that are outside the
normal course of business for the entity, or that otherwise appear to be
unusual.
105
Planning (Cont’d)
Planning is not a discrete phase of
an audit, it is a continual process

106
Materiality (ISA 320)
• Misstatements, including omissions, are considered to be material if
they could reasonably be expected to influence the economic
decisions of users taken on the basis of the financial statements

• There is an inverse relationship between planning materiality and


inherent risk. i.e. the higher the inherent risk the lower the
materiality and vice versa.

107
Materiality (ISA 320)
• Materiality is subjective, - 10 auditors would probably come up with
ten different decisions when setting a materiality

• Materiality is relative – what is ‘material’ will vary from user and from
audit client to audit client. What is regarded as material for the
financial statements of a medium company , may be totally
insignificant to an international conglomerate.

108
Materiality (ISA 320)
• Materiality is both quantitative and qualitative

• An amount which is quantitatively material will be one which


exceeds the amount which the auditor determines as material.

• A matter which is qualitatively material will be one which is regarded


as material when judged a factor other than amount. Eg important
disclosure may be ommitted from the financial statements

109
Types of Materiality
Planning Materiality – set as planning

Performance materiality – to be used during execution

Final materiality – set at the end of the audit (at the evaluation stage)

110
General Planning Materiality Guides
Quantitative
Turnover ½- 1 %
Gross profit 1-2 %
Total Assets 1 -2 %
Equity 2-5%

Qualitative
Control environment/effectiveness of controls
Integrity of management
111
Responses to assessed risks (ISA 330)

Responses to assessed risks are made at


both overall and at assertion level

112
Overall Audit responses
•Emphasizing to the engagement team the need to maintain
professional skepticism.
• Assigning more experienced staff
• Providing more supervision.
• Incorporating additional elements of unpredictability in the
selection of further audit procedures to be performed.
• Maker changes to the nature, timing or extent of audit
procedures
•Conducting more audit procedures as of the period end rather than
at an interim date.
• Obtaining more extensive audit evidence from substantive
procedures.
• Increasing the number of locations to be included in the audit
scope (lower materiality) 113
Audit approach (Nature)
The auditor needs to decide on whether to go the
combined approach or the substantive approach.

The combined approach incorporates, Tests Of


Controls and less of substantive procedures

114
The combined approach
The combined approach is affected by the following factors:

Necessity
Substantive procedures alone will not result in sufficient audit
evidence

Possibility`1`
• the necessary softwares are there
• the control environment is sound
•Electronic data is there

Desirability
The combined approach is very efficient (less time is consumed
115
Substantive tests – Factors to consider
It is ideal to perform substantive procedures when the
following factors are available:

Weak internal control environment


-Lack of internal controls
-Tests of controls indicate no/ little reliance on internal
controls
-Few transactions
-So requested by the client

116
Planning
Types of questions that may be asked
• Discuss the audit risk / risk of material misstatement at
the overall financial statement level
• Discuss the effect risk assessment at the overall
financial statement level will have on the overall audit
strategy.
• Discuss the risk of material misstatement at the
assertion level. You may be required to limit your answer
to specific assertions
• Discuss the effect risk assessment at the assertion level
will have on the audit plan

117
Suggested solution (cont’d)
Payments made to creditor not appearing on the statement :

- Inspect the statement to confirm if the payments do not appear on


the statement (1)

- Scrutinise the creditors’ ledger and cashbook to confirm that the


payment appear in the creditors’ ledger and the cash book(1)

Agree payment with:


- The credit entry in the cash book (1)
- Agree the payment with the deduction on the bank statement (1)
- Take note of the date on which the RTGS/ Cheque appeared on the
Bank statement (1)
- The deduction/recognition of receipt of the payment on the
subsequent creditor’s statement (1)
118
Suggested solution (cont’d)
Goods returned which no credit on the creditor’s statement

- Inspect the creditor’s statement to confirm if the items do not


appear on the creditors’ statement (1)

- Inspect the creditor’s ledger to confirm if the return indeed exist

Agree the credit with:


- The granting of the credit on the subsequent statement (1)
- The journal entry posted in the ledger as a deduction against the
inventory control account (1)
- Signed proof of receipt of goods from the creditor (AU Ltd) (1)
- Debit note issued by LSU ltd (1)

119
Suggested solution (cont’d)
Goods received note

Inspect the date on the goods returned note (GRN) to confirm if the
goods were returned before 31 December 2013 (1)

Confirm the number of units as they appear on the signed GRN/


(despatch note) correspond with the number of units indicated on the
reconciliation statement (1)

Agree the unit price used for the calculation of the return with the
unit price on the original invoice from AU Ltd (1)

Inspect the credit note from AU Ltd (if already received) and confirm
the validity there of, on official stationery, signature,etc (1)

120
Suggested solution (cont’d)
Audit procedures for goods that were never received
Inspect the creditor’s statement and confirm that the invoice of the
goods involved is indeed included in the monthly statement
(1)
Scrutinise the creditor’s ledger and ensure that this invoice amount is
not included (it is a valid reconciling item) (1)

Confirm the adjustment on the subsequent monthly statement


through inspection of the creditor’s reconciliation statement (1)

Request the creditor (with the client’s permission) to supply a copy of


their proof of delivery to you (1)

Scrutinise the goods receipt notes and confirm that a goods received
note was not made out for these goods concerned (1)
121
June 2015 Exam

LSU, with effect from 1 April 2014, leased 10 rooms


totalling 30 square metres from Hwange Colliery
Company (HCC) for them to conduct lectures in
Hwange. The lease period is 10 years (renewable).
The rentals are US $ 2,000 per month.
REQUIRED
Describe audit procedures that you perform to audit
the Hwange lease arrangement for the year ended 31
December 2014.

122
Substantive audit programme - Income
Statement Completenes Accuracy: Occurrence: Cut-off:
Assertions s
Purchases Compare Obtain Select sample Select a sample
current year purchase of purchase of purchase
purchases with journals and orders and invoices just
previous to cast total totals agree with before and after
assess to confirm it purchase year end to
reasonablenes correctness. invoices and confirm that it
s of variance. good received have been
notes. included and
excluded
respectively.

123
Test of controls
How should a test of control be performed

A test of control should address the following:

How : This is the verb that describes the action to the performed.

What : Here you should make reference to the source document (e.g.
The reconciliation on which the signature is made) and/or the action
(control) being performed (e.g. the password being entered by the
employee to gain access to the system).

Why : This describes the reason for performing a test of control. What
are the internal control objectives?
124
Test of controls
Example 1:
− Inspect the clock card summary reconciliation for
the manager’s signature as evidence of approval.
Inspect = HOW = verb = ISA 500 par A14
Clock card summary reconciliation = WHAT = Source
document
For the manager’s signature as evidence of approval
= WHY =reason authorisation

125
Test of controls
Example 2:
Inquire from management whether all employees should log
into the system with a valid user identification number and
password, to ensure that only authorised employees have
access to the system.

Inquire = HOW = verb


All employees log into system with valid ID and password =
WHAT = action
Ensure only authorised employees have access = WHY =
reason = authorisation
126
Using the work of Internal Auditors (ISA 610
The external auditor has sole responsibility for the audit
opinion expressed, and that responsibility is not
reduced by the external auditor’s use of the work of the
internal audit function on the engagement. Although
the function may perform audit procedures similar to
those performed by the external auditor, neither the
internal audit function nor the internal auditors are
independent of the entity as is required of the external
auditor in an audit of financial statements in accordance
with ISA 200.6
127
Using the work of Internal Auditors (ISA 610
The objectives of the external auditor, where the entity has an
internal audit function and the external auditor expects to use
the work of the function to modify the nature or timing, or
reduce the extent, of audit procedures to be performed directly
by the external auditor are:
(a) To determine whether the work of the internal audit
function can be used, and if so, in which areas and to what
extent;
and having made that determination:
(b) If using the work of the internal audit function, to determine
whether that work is adequate for purposes of the audit.

128
Factors to consider (ISA 610
•Whether the internal audit function is free of any conflicting
responsibilities, for example, having managerial or operational
duties

•Whether those charged with governance oversee employment


decisions related to the internal audit function, for example,
determining the appropriate remuneration policy.

Whether there are any constraints or restrictions placed on the


internal audit function by management or those charged with
governance, for example, in communicating the internal audit
function’s findings to the external auditor.
129
Factors to consider (ISA 610
•Whether the internal auditors are members of relevant
professional bodies and their memberships obligate their
compliance with relevant professional standards relating to
objectivity, or whether their internal policies achieve the
same objectives.

•Whether the internal audit function is adequately and


appropriately resourced relative to the size of the entity and
the nature of its operations.

130
Factors to consider (ISA 610
• Whether activities of the internal audit function are
properly planned, supervised, reviewed or documented

•Whether, and to what extent management acts on the


recommendations of the internal audit function and how
such action is evidenced

131
Using the work of Internal Auditors (ISA 610
The external auditor shall not use the work of the internal
audit function if the external auditor determines that:
(a) The function’s organizational status and relevant policies
and procedures do not adequately support the objectivity of
internal auditors;
(b) The function lacks sufficient competence; or
(c) The function does not apply a systematic and disciplined
approach, including quality control.

132
Using the work of an expert (ISA 620
Auditor’s expert – An individual or organization possessing
expertise in a field other than accounting or auditing, whose
work in that field is used by the auditor to assist the auditor
in obtaining sufficient appropriate audit evidence.

An auditor’s expert may be either an auditor’s internal


expert (who is a partner or staff, including temporary staff,
of the auditor’s firm or a network firm), or an auditor’s
external expert.

133
Using the work of an expert (ISA 620
Auditor’s expert – An individual or organization possessing
expertise in a field other than accounting or auditing, whose
work in that field is used by the auditor to assist the auditor
in obtaining sufficient appropriate audit evidence.

An auditor’s expert may be either an auditor’s internal


expert (who is a partner or staff, including temporary staff,
of the auditor’s firm or a network firm), or an auditor’s
external expert.

134
Using the work of an expert (ISA 620
We can use the work of experts to do the following:

•The valuation of complex financial instruments, land and buildings,


plant and machinery, jewellery, works of art, intangible assets, assets
acquired and liabilities assumed in business combinations and assets
that may have been impaired.
• The actuarial calculation of liabilities associated with insurance
contracts or employee benefit plans.
• The estimation of oil and gas reserves.
• The valuation of environmental liabilities, and site clean-up costs.
• The interpretation of contracts, laws and regulations.
• The analysis of complex or unusual tax compliance issues.

135
Assessing competence and objectivity of the expert
• Personal experience with previous work of that expert.
• Discussions with that expert.
• Discussions with other auditors or others who are familiar
with that expert’s work.
• Knowledge of that expert’s qualifications, membership of
a professional body or industry association, license to
practice, or other forms of external recognition.
• Published papers or books written by that expert.
• The auditor’s firm’s quality control policies and
procedures

136
Evaluating the work of an expert
Procedures to evaluate the adequacy of the auditor’s expert’s
work for the auditor’s purposes may include:
• Inquiries of the auditor’s expert.
• Reviewing the auditor’s expert’s working papers and reports.
• Corroborative procedures, such as:
-Observing the auditor’s expert’s work;
-Examining published data, such as statistical reports
from reputable, authoritative sources;
-Confirming relevant matters with third parties;
-Performing detailed analytical procedures; and
-Reperforming calculations.
137

You might also like