Chapter 6: Risk assessment
00
M
O
NT
H
00
00
BPP LEARNING MEDIA
Syllabus learning outcomes
• Identify the overall objectives of the auditor and the need to conduct an audit in
accordance with ISAs.
• Explain the need to plan and perform audits with an attitude of professional scepticism,
and to exercise professional judgement.
• Explain the components of audit risk.
• Describe the audit risks in the financial statements and explain the auditor's response to
each risk.
• Define and explain the concepts of materiality and performance materiality.
• Explain and calculate materiality levels from financial information.
• Explain how auditors obtain an initial understanding of the entity and its environment.
• Describe and explain the nature, and purpose, of analytical procedures in planning.
• Compute and interpret key ratios used in analytical procedures.
• Discuss the effect of fraud and misstatements on the audit strategy and extent of audit
work.
• Discuss the responsibilities of internal and external auditors for the prevention and
detection of fraud and error.
• Explain the auditor's responsibility to consider laws and regulations
BPP LEARNING MEDIA
Chapter summary diagram
BPP LEARNING MEDIA
Chronology of an audit
BPP LEARNING MEDIA
Introduction to risk
Let's remind ourselves what the overall objective of the external auditor
is:
'To obtain reasonable assurance about whether the financial statements
as a whole are free from material misstatement, whether due to fraud or
error, thereby enabling the auditor to express an opinion on whether the
financial statements are prepared, in all material respects, in accordance
with an applicable financial reporting framework; and to report on the
financial statements, and communicate as required by the ISAs, in
accordance with the auditor's findings.'
ISA 200 Overall objectives of the auditor and the conduct of an audit in
accordance with International Standards on Auditing
BPP LEARNING MEDIA
Introduction to risk
Professional scepticism and judgement
In order to achieve the overall objectives of an external audit, the auditor
needs to plan and perform the audit with professional scepticism and to
apply professional judgement.
Professional scepticism – an attitude that includes a questioning
mind, being alert to conditions which might indicate possible
misstatement due to error or fraud, and a critical assessment of audit
evidence.
Do pieces of evidence contradict other evidence received?
Is information received which brings into question the reliability of audit
evidence already obtained?
BPP LEARNING MEDIA
Introduction to risk
Professional scepticism and judgement (cont’d)
Professional judgement – the application of relevant training,
knowledge and experience in making informed decisions about the
courses of action that are appropriate in the circumstance of the audit
engagement.
The following require professional judgement:
• Determining materiality and audit risk
• Determining nature, timing and extent of audit procedures
• Evaluating whether sufficient appropriate audit evidence has been
obtained
• Drawing conclusions based on the audit evidence obtained
• Evaluating whether management have applied an applicable financial
reporting framework
BPP LEARNING MEDIA
Introduction to risk
In order to obtain assurance that financial statements are free from
material misstatements, the auditor needs to consider HOW and WHERE
misstatements are most likely to arise.
The auditor carries out a risk assessment in order to ensure the areas
which are most susceptible to material misstatement are adequately
investigated during the audit.
We need to understand what risk is in the context of the financial
statements!
It is therefore very important that you understand the difference between
business risk and audit risk.
BPP LEARNING MEDIA
Introduction to risk
Business risk is the risk inherent to the entity in its operations (at all
levels of the business).
Audit risk is the risk that the auditor expresses an inappropriate audit
opinion when the financial statements are materially misstated.
ISAs required auditors to follow a risk-based approach.
Audit risk has three components and is illustrated diagramatically on the
next slide.
BPP LEARNING MEDIA
Introduction to risk
THE AUDIT RISK MODEL
AR = IR x CR x DR
Audit Risk Control Risk
Inherent Risk
Detection Risk
Sampling Risk Non-sampling Risk
BPP LEARNING MEDIA
Introduction to risk
Inherent risk is the susceptibility of an assertion to a misstatement that
could be material individually or when aggregated with other
misstatements, before consideration of any related controls.
Inherent risk is affected by the nature of the entity; for example, the
industry it is in; the regulations it falls under; and the nature of the
strategies it adopts.
Examples of factors which could affect inherent risk:
➢ Integrity of management
➢ Inventory valuation in a jewellery business
➢ High cash business such as retail
➢ Technological obsolescence
BPP LEARNING MEDIA
Introduction to risk
Control risk is the risk that a material misstatement that could occur in
an assertion and that could be material, individually or when aggregated
with other misstatements, will NOT be prevented or detected and
corrected on timely basis by the entity's internal control.
Examples:
- Monthly bank reconciliations not reviewed by a manager
- Purchase invoices not matched to goods received notes
- References not followed up for new employees
- Computer passwords not required to be changed regularly
We will look at controls in more detail in Chapters 9 and 10.
BPP LEARNING MEDIA
Introduction to risk
Detection risk is the risk that the procedures performed by the auditor to
reduce audit risk to an acceptably low level will NOT detect a
misstatement that exists and that could be material, individually or when
aggregated with other misstatements.
This is the only component of audit risk that the auditors have control
over.
Notice the difference in emphasis between IR, CR and DR:
• IR and CR relate to the risk of material misstatement being
present in the financial statements.
• DR relates to the risk that the auditor will not detect that
misstatement.
BPP LEARNING MEDIA
Introduction to risk
Detection risk is made up of two components: sampling risk and non-
sampling risk:
Detection risk = Sampling risk + Non-sampling risk
Sampling risk: Risk that auditor can not examine all available evidence
and only performs audit based on sampling.
Non-sampling risk: Risk that auditor’s procedures do not detect material
misstatement due to factors other than the sample tested.
The next slide shows examples of sampling risk and non-sampling risk.
We look at audit sampling in detail in Chapter 11.
BPP LEARNING MEDIA
Introduction to risk
Sampling risk examples Non-sampling risk examples
Sample chosen not representative of Auditor’s lack of experience
population
Misstatement(s) in transactions not Time pressure and poor planning
selected as part of sample
New client
Lack of industry knowledge
BPP LEARNING MEDIA
Introduction to risk
How can the effectiveness and application of procedures be
improved to help reduce detection risk?
• Adequate planning
• Assignment of more experienced staff to the audit team
• Applying professional scepticism
• Increased supervision and review of audit work
BPP LEARNING MEDIA
Introduction to risk
Control risk and inherent risk together make up the risk of material
misstatement (ROMM).
Audit risk must always be set 'to an acceptably low level' – the risk of
the auditor giving the wrong opinion should obviously be as low as
possible.
• Auditors will assess inherent risk and control risk as high, medium or
low.
• Detection risk is the balancing figure in the audit risk equation. So if
inherent risk and control risk are assessed as high, detection risk must
be as low as possible for audit risk to remain low.
BPP LEARNING MEDIA
Introduction to risk
RISK OF MATERIAL MISSTATEMENT
AR = IR x CR x DR
Audit Risk Control Risk
Inherent Risk
Detection Risk
Sampling Risk Non-sampling Risk
BPP LEARNING MEDIA
Questions
Is the following statement true or false?
Audit risk is a function of two components, inherent risk and control risk.
A. True
B. False
Which risk is under the influence of the auditor?
A. Control risk
B. Detection risk
C. Both
If entity risk is high, what effect would that have on sample sizes for
testing?
A. Make them lower
B. Make them higher
BPP LEARNING MEDIA
Questions
BPP LEARNING MEDIA
Materiality
What is materiality and why does it matter?
The concept of materiality is a fundamental one in the audit of financial
statements.
Remember what the objective of the external audit is:
The objective of an external audit of financial statements is to
enable the auditor to express an opinion on whether the financial
statements are prepared, in all material respects, in accordance
with an applicable financial reporting framework.
The external auditor CANNOT test every transaction and balance that
make up the financial statements – this would simply not be feasible or
cost-effective.
A risk-based approach is required.
Hence the concept of materiality.
BPP LEARNING MEDIA
Materiality
Material: Information is material if its omission or misstatement could
reasonably be expected to influence the decision of users taken on the
basis of the financial statements.
There are two aspects of materiality
1- Quantitative materiality
2- Qualitative materiality
The materiality level set by the auditor will always be a matter of
judgement and will depend on the level of audit risk.
The higher the audit risk, the lower the value of materiality.
BPP LEARNING MEDIA
Materiality
How is materiality calculated?
• During the planning, the auditor establish materiality for the financial
statement as a whole.
• The following benchmarks and percentage may be appropriate in the
calculation of materiality for the financial statement as a whole:
Benchmark %
Profit before tax 5 - 10
Profit after tax 5 – 10
Total assets 1–2
Revenue 0.5 – 1
Net assets 2-5
BPP LEARNING MEDIA
Materiality
Once the auditor set the materiality level for the financial statement as a
whole then the auditor should calculate performance materiality.
Performance materiality is calculated for particular classes of
transactions, balances and disclosures.
Performance materiality lower then the materiality for the financial
statement as whole.
Performance materiality is calculated, usually by applying a percentage
between 50% and 75% to the overall materiality amount. This
calculation is not mechanical, as it also involves professional judgment.
Materiality must be reviewed throughout the audit and revised if
necessary.
BPP LEARNING MEDIA
Question: 2014 Specimen Exam (Sec A, Q10)
During the planning stages of the final audit, the auditor believes that
the probability of giving an inappropriate audit opinion is too high.
How should the auditor amend the audit plan to resolve this
issue?
A Increase the materiality level
B Decrease the inherent risk
C Decrease the detection risk
BPP LEARNING MEDIA
Answer: 2014 Specimen Exam (Sec A, Q10)
C Decrease the detection risk
Increasing the materiality level would mean that the auditor
considered the audit to be of a lower risk. Inherent risk cannot be
controlled by the auditor. The only element of audit risk that is within
the auditor's control is detection risk, so if there is a high risk of giving
an inappropriate audit opinion, the auditor needs to ensure that
detection risk is as low as possible.
BPP LEARNING MEDIA
Risk assessment and understanding the entity and its environment
Risk Assessment
The auditor should identify and assess the risk of material misstatement
whether due to fraud or error.
Therefore the auditor FIRST identifies the risk and then assess their
severity.
But how do we identify what the risks are?
By understanding the entity and its environment.
ISA 315 Identifying and assessing the risks of material misstatement
through understanding the entity and its environment
BPP LEARNING MEDIA
Understanding the entity and its environment
Why does an auditor need to understand the entity and its
environment?
1. To identify and assess the risks of material misstatement in the
financial statements
2. To enable the auditor to design and perform further audit procedures
3. To provide a frame of reference for exercising audit judgement,
eg when setting audit materiality
BPP LEARNING MEDIA
Understanding the entity and its environment
What does an auditor need to understand about the entity and its
environment?
• Industry, regulatory and external factors (including financial reporting
framework)
• Nature of the entity (eg operations; ownership; governance; structure;
financing)
• Selection and application of accounting policies
• Objectives and strategies and related business risks
• Measurement and review of financial performance
• Internal control
BPP LEARNING MEDIA
Understanding the entity and its environment
How does an auditor understand the entity and its environment?
• Inquiries of management, internal auditors and others
• Analytical procedures (these must be used at risk assessment!)
• Observation and inspection
• Prior period knowledge
• Client acceptance or continuance policies
• Discussion by audit team
• Information from other engagements undertaken for the entity
BPP LEARNING MEDIA
Understanding the entity and its environment
BPP LEARNING MEDIA
Assessing the risks of material misstatement
Having obtained an understanding of the entity, an auditor must identify
and assess the risks of material misstatement in the financial
statements.
To do this the auditor should:
– Identify risks throughout the process of obtaining an
understanding of the entity and its environment
– Assess the identified risks and evaluate whether they relate more
pervasively to the financial statements as a whole
– Relate the risks to what can go wrong at the assertion level
(see Chapter 8)
– Consider the likelihood of the risks causing a material
misstatement
BPP LEARNING MEDIA
Assessing the risks of material misstatement
The auditor must also consider significant risks, ie those that require
special consideration.
Factors that give risk to significant risks include:
– The risk of fraud
– Relationship with economic, accounting or other developments
– Degree of subjectivity
– Unusual transaction
– Significant transaction with a related party
– Complexity of transaction
Routine, non-complex transactions are less likely to give rise to
significant risk.
BPP LEARNING MEDIA
Responding to the risk assessment
ISA 330 The auditor's responses to assessed risks
The auditor needs to obtain sufficient audit evidence regarding the
assessed risks.
Overall responses include emphasising to the audit team the
importance of professional scepticism, allocating more staff, using
experts or providing more supervision.
Responses to the risks of material misstatement at the assertion level
include tests of controls and substantive procedures.
The following article on ISA 330 from the April 2010 edition of Student
Accountant may prove useful:
[Link]
students/2012s/sa_apr10_f8.pdf
BPP LEARNING MEDIA
Responding to the risk assessment
Tests of controls are audit procedures designed to evaluate the
operating effectiveness of controls in preventing, or detecting and
correcting, material misstatements at the assertion level.
When carrying out tests of control, an auditor will often use inquiry. Re-
performance and inspection can often also be helpful procedures.
We will look at tests of controls in more detail in Chapters 9 and 10.
BPP LEARNING MEDIA
Responding to the risk assessment
Substantive procedures are audit procedures designed to detect
material misstatements at the assertion level.
They are of two types:
– Tests of detail; and
– Substantive analytical procedures.
Substantive procedures MUST always be carried out on material items.
Some degree of substantive testing will always have to be carried out,
this is due to the inherent limitations which exist in internal control
systems.
BPP LEARNING MEDIA
Responding to the risk assessment
Tests of details may be appropriate to gain information about account
balances, eg inventory, non-current assets.
Substantive analytical procedures are appropriate for large volumes of
predictable transactions, eg wages and salaries.
Tests of detail (rather than analytical procedures) are likely to be more
appropriate in relation to matters which have been identified as
significant risks.
BPP LEARNING MEDIA
Question: 2016 Specimen Exam (Sec B, Q16b) 1
Milla Cola Co (Milla) manufactures fizzy drinks such as cola and
lemonade as well as other soft drinks and its year end is
30 September 20X5. You are an audit manager of Totti & Co and are
currently planning the audit of Milla. You attended the planning meeting
with the audit engagement partner and finance director last week and
the minutes from the meeting are shown below. You are reviewing
these as part of the process of preparing the audit strategy document.
Minutes of planning meeting for Milla
Milla's trading results have been strong this year and the company is
forecasting revenue of $85 million, which is an increase from the
previous year. The company has invested significantly in the cola and
fizzy drinks production process at the factory. This resulted in
expenditure of $5 million on updating, repairing and replacing a
significant amount of the machinery used in the production process.
BPP LEARNING MEDIA
Question: 2016 Specimen Exam (Sec B, Q16b) 2
As the level of production has increased, the company has expanded the
number of warehouses it uses to store inventory. It now utilises 15
warehouses; some are owned by Milla and some are rented from third
parties. There will be inventory counts taking place at all 15 of these
sites at the year end.
A new accounting general ledger has been introduced at the beginning
of the year, with the old and new systems being run in parallel for a
period of two months. In addition, Milla has incurred expenditure of $4.5
million on developing a new brand of fizzy soft drinks. The company
started this process in July 20X4 and is close to launching their new
product into the market place.
As a result of the increase in revenue, Milla has recently recruited a new
credit controller to chase outstanding receivables. The finance director
thinks it is not necessary to continue to maintain an allowance for
receivables and so has released the opening allowance of $1.5 million.
BPP LEARNING MEDIA
Question: 2016 Specimen Exam (Sec B, Q16b) 3
The finance director stated that there was a problem in April in the
mixing of raw materials within the production process which resulted
in a large batch of cola products tasting different. A number of these
products were sold; however, due to complaints by customers about
the flavour, no further sales of these goods have been made. No
adjustment has been made to the valuation of the damaged
inventory, which will still be held at cost of $1 million at the year end.
As in previous years, the management of Milla is due to be paid a
significant annual bonus based on the value of year-end total assets.
BPP LEARNING MEDIA
Question: 2016 Specimen Exam (Sec B, Q16b) 4
Required:
(b) Using the minutes provided, identify and describe SEVEN
audit risks, and explain the auditor's response to each risk, in planning
the audit of Milla Cola Co. (14 marks)
BPP LEARNING MEDIA
Approach: 2016 Specimen Exam (Sec B, Q16b)
You need to describe seven audit risks and the auditor's responses in
each case.
Students often misinterpret the part about auditor's responses and
instead provide additional explanation of the risk. Be warned!
This is best answered in a table so the risk and response can be
linked. Create a table and use headings.
Go through the scenario line-by-line and use a heading to note down
what could go wrong in the financial statements, for example, could a
balance be overstated or understated or a disclosure be missing or
inadequate. Also think about whether there could be problems
conducting the audit, for example, if accounting records have been
lost of key personnel have left.
• Remember not to confuse audit risk and business risk!
BPP LEARNING MEDIA
Answer: 2016 Specimen Exam (Sec B, Q16b) 1
Audit risk Auditor's response
Milla has incurred $5m on updating, repairing and The auditor should review a breakdown of these
replacing a significant amount of the production costs to ascertain the split of capital and revenue
process machinery. expenditure, and further testing should be
undertaken to ensure that the classification in the
If this expenditure is of a capital nature, it should
financial statements is correct.
be capitalised as part of property, plant and
equipment (PPE) in line with IAS 16 Property,
Plant and Equipment. However, if it relates more to
repairs, then it should be expensed to the
statement of profit or loss.
If the expenditure is not correctly classified, profit
and PPE could be under or overstated.
At the year end there will be inventory counts The auditor should assess which of the inventory
undertaken in all 15 warehouses. sites they will attend the counts for. This will be
any with material inventory or which have a history
It is unlikely that the auditor will be able to attend
of significant errors.
all 15 inventory counts and therefore they need to
ensure that they obtain sufficient appropriate audit For those not visited, the auditor will need to
evidence over the inventory counting controls, and review the level of exceptions noted during the
completeness and existence of inventory for any count and discuss with management any issues
warehouses not visited. which arose during the count.
BPP LEARNING MEDIA
Answer: 2016 Specimen Exam (Sec B, Q16b) 2
Audit risk Auditor's response
Inventory is stored within 15 warehouses; some The auditor should review supporting
are owned by Milla and some rented from third documentation for all warehouses included within
parties. Only warehouses owned by Milla should PPE to confirm ownership by Milla and to ensure
be included within PPE. non-current assets are not overstated.
There is a risk of overstatement of PPE and
understatement of rental expenses if Milla has
capitalised all 15 warehouses.
A new accounting general ledger system has been The auditor should undertake detailed testing to
introduced at the beginning of the year and the old confirm that all opening balances have been
system was run in parallel for two months. There is correctly recorded in the new accounting general
a risk of opening balances being misstated and ledger system.
loss of data if they have not been transferred from
They should document and test the new system.
the old system correctly.
They should review any management reports run
In addition, the new accounting general ledger comparing the old and new system during the
system will require documenting and the controls parallel run to identify any issues with the
over this will need to be tested. processing of accounting information.
BPP LEARNING MEDIA
Answer: 2016 Specimen Exam (Sec B, Q16b) 3
Audit risk Auditor's response
Milla has incurred expenditure of $4.5m on Obtain a breakdown of the expenditure and
developing a new brand of fizzy drink. This undertake testing to determine whether the
expenditure is research and development costs relate to the research or development
under IAS 38 Intangible Assets. The standard stage. Discuss the accounting treatment with
requires research costs to be expensed and the finance director and ensure it is in
development costs to be capitalised as an accordance with IAS 38.
intangible asset.
If Milla has incorrectly classified research costs
as development expenditure, there is a risk the
intangible asset could be overstated and
expenses understated.
BPP LEARNING MEDIA
Answer: 2016 Specimen Exam (Sec B, Q16b) 4
Audit risk Auditor's response
The finance director of Milla has decided to Extended post year-end cash receipts testing and
release the opening balance of $1.5m for a review of the aged receivables ledger to be
allowance for receivables as he feels it is performed to assess valuation and the need for an
unnecessary. There is a risk that receivables will allowance for receivables.
be overvalued, as despite having a credit
Discuss with the director the rationale for releasing
controller, some balances will be irrecoverable and
the $1.5m opening allowance for receivables.
so will be overstated if not provided against.
In addition, due to the damaged inventory there is
an increased risk of customers refusing to make
payments in full.
A large batch of cola products has been damaged Detailed cost and net realisable value testing to be
in the production process and will be in inventory performed to assess how much the inventory
at the year end. No adjustment has been made by requires writing down by.
management.
The valuation of inventory as per IAS 2 Inventories
should be at the lower of cost and net realisable
value. Hence it is likely that this inventory is
overvalued.
BPP LEARNING MEDIA
Answer: 2016 Specimen Exam (Sec B, Q16b) 5
Audit risk Auditor's response
Due to the damaged cola products, a number Review the breakdown of sales of damaged
of customers have complained. It is likely that goods, and ensure that they have been
for any of the damaged goods sold, Milla will accurately removed from revenue.
need to refund these customers.
Revenue is possibly overstated if the sales
returns are not completely and accurately
recorded.
The management of Milla receives a significant Throughout the audit, the team will need to be
annual bonus based on the value of year-end alert to this risk. They will need to maintain
total assets. There is a risk that management professional scepticism and carefully review
might feel under pressure to overstate the judgemental decisions and compare treatment
value of assets through the judgements taken against prior years.
or through the use of releasing provisions.
BPP LEARNING MEDIA
Fraud, law and regulations
Fraud
Fraud is an intentional act by one or more individuals among
management, those charged with governance, employees or third parties
involving the use of deception to obtain an unjust or illegal
advantage. Fraud may be perpetrated by an individual, or colluded in,
with people internal or external to the business.
Fraud risk factors are events or conditions which indicate an incentive
or pressure to commit fraud, or provide an opportunity to commit fraud.
There are two types of fraud:
(1) Fraudulent financial reporting
(2) Misappropriation of assets
BPP LEARNING MEDIA
Fraud, law and regulations
Fraudulent financial reporting
Involves intentional misstatements, including omissions of amounts or
disclosures in financial statements, to deceive users of the financial
statements.
Examples
— Manipulation, falsification or alteration of accounting records and/or
supporting documents
— Misrepresentation (or omission) of events or transactions in the
financial statements
— Intentional misapplication of accounting principles
BPP LEARNING MEDIA
Fraud, law and regulations
Misappropriation of assets
Involves the theft of an entity's assets and is often perpetrated by
employees in relatively small and immaterial amounts. However, it can
also involve management who are usually more capable of disguising or
concealing misappropriations in ways that are difficult to detect.
Examples
— Embezzling receipts (for example, diverting them to private bank
accounts)
— Stealing physical assets or intellectual property (inventory, selling
data)
— Causing an entity to pay for goods not received (payments to fictitious
vendors)
— Using assets for personal use
BPP LEARNING MEDIA
Real world example: Saytam Computer Services
In 2009, the Chairman of Saytam Computer Services (in India),
Ramalinga Raju, admitted to falsifying the financial statements of the
company by almost $1.5 billion.
The financial statements contained falsified revenues, margins and
cash balances, resulting in over-inflated revenue figures.
The Chairman admitted the fraud in a letter to the board of directors
of the company.
Here is an extract from his letter:
'What started as a marginal gap between actual operating profit and
the one reflected in the books continued to grow over the years. It
has attained unmanageable proportions as the size of the company's
operations grew over the years.'
BPP LEARNING MEDIA
Fraud, law and regulations
Prevention and detection of fraud
The primary responsibility for the prevention and detection of fraud rests
those changed with governance and management. It is not primarily the
responsibility of the external auditor!
However, as part of their risk assessment, auditors should discuss how
and where the financial statements may be susceptible to fraud.
ISA 240 The auditor's responsibilities relating to fraud in an audit of
financial statements
So what are the responsibilities of the auditor?
The auditor is responsible for obtaining reasonable assurance that the
financial statements are free from material misstatement, whether
caused by fraud or error.
BPP LEARNING MEDIA
Fraud, law and regulations
However, the risk of not detecting a material misstatement from fraud is
higher than from error because:
— Fraud may involve sophisticated schemes designed to conceal it.
— Fraud may be perpetrated by individuals in collusion.
— Management fraud is harder to detect because management is in a
position to manipulate accounting records or override control
procedures.
Professional scepticism is important here – eg the auditor should
consider the possibility of management overriding controls.
BPP LEARNING MEDIA
Fraud, law and regulations
Written representations
ISA 240 requires the auditor to obtain written representations from
management and those charged with governance that:
— They acknowledge their responsibility for the design, implementation
and maintenance of internal control to prevent and detect fraud.
— They have disclosed to the auditor management's assessment of
the risk of fraud in the financial statements.
— They have disclosed to the auditor their knowledge of any fraud or
suspected fraud which could have a material effect on the financial
statements.
— They have disclosed to the auditor their knowledge of any
allegations of fraud or suspected fraud communicated to
employees, former employees, analysts, regulators or others.
BPP LEARNING MEDIA
Fraud, law and regulations
ISA 250 Consideration of laws and regulations in an audit of financial
statements.
Management's responsibility
To ensure that the entity complies with the relevant laws and regulations.
It is not the auditor's responsibility to prevent or detect non-compliance
with laws and regulations.
Auditor's responsibility
To obtain reasonable assurance that the financial statements are free
from material misstatement.
However, auditor must also take into account the legal and regulatory
framework within which the entity operates.
BPP LEARNING MEDIA
Fraud, law and regulations
ISA 315 requires auditors to obtain a general understanding of the
applicable legal and general framework and how the entity complies with
it.
For example, making inquiries of management about laws and
regulations that may affect the entity, and about the entity's policies and
procedures or ensuring its complies with relevant legislation.
The auditor shall remain alert to the possibility that audit procedures may
highlight instances of non-compliance.
Any non-compliance should be reported to those charged with
governance or the audit committee, if the auditor suspects that those
charged with governance are involved.
BPP LEARNING MEDIA
Documentation of risk assessment
Auditors must document the work they have done at the risk assessment
stage.
We will look at documentation in greater detail in Chapter 7 when we
discuss the audit strategy and the audit plan.
But there are a number of matters which need to be documented during
the risk assessment and planning stages of an audit…
BPP LEARNING MEDIA
Documentation of risk assessment
What needs to be documented?
— The discussion among the audit team concerning the susceptibility of t
he financial statements to material misstatements, including any
significant decisions reached
— Key elements of the understanding gained of the entity regarding the e
lements of the entity and its internal control components, sources of
information gained and the risk assessment procedures undertaken
— The identified and assessed risks of material misstatement at the
financial statement level and assertion level
— Risks identified and related controls evaluated
— Overall responses to address the risks of material misstatement at the
financial statement level
BPP LEARNING MEDIA
Documentation of risk assessment (cont’d)
What needs to be documented? (cont’d)
— Nature, extent and timing of further audit procedures linked to the
assessed risks at the assertion level
— Results of audit procedures
— If the auditors have relied on evidence about the effectiveness of
controls from previous audits, conclusions about how this is
appropriate
— Demonstration that the financial statements agree or reconcile with
the underlying accounting records
BPP LEARNING MEDIA