Risk
Audit Risk
Audit risk is a technical term related to the process of auditing. It should be noted that audit risk cannot
be reduced to zero, as an audit cannot provide absolute assurance but reasonable assurance. This is
because an audit has ‘inherent limitations’, for example,
• Part of the nature of financial reporting is that financial statements should include accounting
estimates which necessarily involve judgement
• Audit procedures are designed to gather audit evidence, not to detect intentional misstatement
that has been deliberately concealed.
• As an audit needs to be conducted within a reasonable period of time and at a reasonable cost, it
is not possible to examine everything exhaustively
Audit risk is considered throughout the audit, in particular,
• In understanding the entity – what are the risks? (ISA 315 Identifying and Assessing the Risks of
Material Misstatement through Understanding the Entity and Its Environment)
• In planning the audit – how are risks to be reduced to an acceptably low level? (ISA 330 The
Auditor’s Responses to Assessed Risks)
Definition – Audit Risk
The risk that the auditor gives an inappropriate opinion on the financial statements (i.e. the audit
opinion is that the financial statements show a true and fair view when, in fact, they contain a material
misstatement)
Audit risk is a function of two risks;
Audit
Risk
Risk of Detection
MM Risk
Inherent Control
Risk Risk
20
Therefore, for an inappropriate opinion to have been expressed,
The client's procedures The material error
has not picked it and The auditor must have reaches the published
The error has to occur
failed to detect it
corrected it financial statments
The Audit Risk Model
AR = IR x CR x DR
If both inherent risk and control risks are high, then the only way you will get the audit risk low is to be
very sure that your detection risk is low. This means you would have to do an enormous amount of
audit work.
If, however, the inherent risk and control risks are low themselves, in other words that there is only a
small chance the error occurs in the first place and the client systems and staff are very good, then you
can achieve a relatively low audit risk even with a relatively high detection risk. In other words the
auditor doesn’t have to do so much work
The auditor assesses inherent and control risk - but cannot change them - they are 'givens' specific to
each audit. The auditor must respond to the assessed risks by varying the nature, timing and extent
of work which is actually performed to reduce detection risk to an acceptably low level
Sampling Risk
This risk arises when audit procedures are applied to samples rather than entire populations. The auditor
may conclude, based on a sample, that controls are more effective than they actually are or that there
is no material misstatement when, in fact, there is.
21
Non-Sampling Risk
This risk arises from reasons other than sample size. For example, audit staff were insufficiently
experienced, there is a higher risk that they might use inappropriate audit procedures, misinterpret
evidence or fail to recognize an error.
Non-sampling risk must be minimized through adequate planning, assigning sufficiently skilled staff and
the direction, supervision and review of their work
Inherent Risk
This is the risk that there is a misstatement that could be material, if there were no related internal
controls which could identify and trap that misstatement.
Inherent risks can be increased by complex transactions which are difficult to understand, inexperience
staff, a cash-based business (because cash is usually more difficult to record than bank transfers) etc.
Control Risk
This is the risk that the material misstatement, having occurred, will not be prevented or detected and
corrected by the internal control system. The main factors which affect control risk are the control
environment (essentially the status that the internal control system has in the organization), the design
of the internal control system itself, and finally how well and consistently the internal control system
operates.
Detection Risk
This is the failure of the auditor to detect the material misstatement in the financial statements. This
will be increased if the auditor was relatively inexperienced, if it was a new client, if there was a lot of
time and fee pressure, if planning was poor so the entity was poorly understood, and if the auditor was
straying into an industry where they had little previous experience or expertise
Note - Professional Scepticism
Materiality
Misstatements, including omissions, are considered to be material if they, individually or in the
aggregate, could reasonably be expected to influence the economic decisions of users taken on the basis
of the financial statements.' [ISA 320 Materiality in Planning and Performing an Audit]
ISA 320 recognizes the need to establish a financial threshold and the following benchmarks can be used,
• ½ – 1% revenue
• 5 – 10% profit before tax
• 1 – 2% total assets
22
Material by Nature
• Misstatements that affect compliance with regulatory requirements
• Misstatements that affect compliance with debt covenants.
• Misstatements that, when adjusted, would turn a reported profit into a loss for the year.
• Misstatements that, when adjusted, would turn a reported net-asset position into a net-liability
position.
• Transactions with directors, e.g. salary and benefits, personal use of assets, etc.
• Disclosures in the financial statements relating to possible future legal claims or going concern
issues
Performance Materiality
The amount set by the auditor at less than materiality for the financial statements as a whole to reduce
to an appropriately low level the probability that the aggregate of uncorrected and undetected
misstatements exceeds materiality for the financial statements as a whole. [ISA 320]
Understanding the Entity and its Environment
• Nature of the Entity
We have to understand the nature of the entity. For example, we simply have to understand what
it does, is it in a financial sector, the retail sector, the manufacturing sector?
• Particular Regulations
Banks, insurance companies, and many other operations in the financial sector are subject to
regulation and sometimes the auditor has to ensure that these regulations have been adhered to
• Accounting Policies
We need to understand what the entity’s accounting policies are; different entities have different
ways of valuing inventories perhaps. If you are a building company you will have specific
accounting policies with regard to taking profits from long-term contracts
• Nature of business risks
Most business risks will eventually have financial consequences and therefore an effect on the
financial statements.
• Internal Controls
The auditor has to gain an understanding of the entity’s internal controls. Whether they exist and
to what extent they are expected to operate
• The Control Environment
This refers to the context in which the internal controls operate. The effectiveness of the control
environment has a significant bearing on audit procedures
23
• Financial Performance
Obtaining an understanding of the entity’s performance measures assists the auditor in
considering whether they put pressure on management to act in any way that increases the risks
of material misstatements
Sources of Information
•
•
•
•
Risk Assessment Procedures
Enquiries
Analytical Procedures
ISA 520 – “Evaluations of financial information through analysis of plausible relationships among both
financial and non-financial data and investigation of identified fluctuations, inconsistent relationships or
amounts that differ from expected values by a significant amount”
Analytical procedures are used in order to,
• Identify aspects of the entity of which the auditor was unaware.
• Assist in assessing the risks of material misstatement.
• Help identify unusual transactions or events, and amounts, ratios, and trends that might have
audit implications.
• Help identify risks of material misstatement due to fraud
Analytical procedures include
• Comparable information for prior periods.
• Anticipated results of the entity, such as budgets or forecasts, or expectations of the auditor,
such as an estimation of depreciation.
• Similar industry information
Analytical procedures are used as,
• Preliminary analytical procedures
• Substantive analytical procedures
• Final analytical procedures
Observation
Inspection
24
Business Risk
Business risk is the exposure a company or organization has to factor(s) that will lower its profits or lead
it to fail. Anything that threatens a company's ability to achieve its financial goals is considered a
business risk
Audit Risk Identification and Explanation
Identification of Risk Audit Risk Explanation Business Risk
Customers are struggling to pay
debts.
The client operates in a fast
paced industry
Revenue is falling due to
recession. The cash flow
forecast shows negative cash
flows for the next 12 months
Auditor Responses to Risks
25
Planning
ISA 300 - Planning an Audit of Financial Statements
In accordance with ISA 300 ‘'The objective of the auditor is to plan the audit so that it will be performed
in an effective manner’
Benefits of Planning
Audit Timing
The first thing that has to happen is a planning visit, or if not a visit at least a telephone call. There
would certainly be a visit before the first audit of a new client commenced.
Contact is necessary because, at the very least, you have to agree with the client when the audit staff
will visit. Also at this planning stage, enquiry should be made about what changes may have taken
place at the client’s since the previous audit.
The next stage is what’s known as the interim audit. The interim audit would typically happen perhaps
in July or August of the year to 31 December. The auditor will carry out tests of controls, to ensure that
the system of internal control as they understand it and as specified by the client is actually working in
practice
There will usually be some audit procedures that have to be carried out at the reporting date. For
example, where the value of inventory included in the financial statements will be based on physical
quantities, the auditor will plan to attend the physical count.
26
After the year-end, the auditors will return and carry out a final audit. At this point the client should
have prepared the financial statements and the auditor will be concentrating on obtaining sufficient
appropriate audit evidence to express a conclusion on the financial statements
Planning Process
• Preliminary engagement activities
• Planning activities
Audit Strategy
Audit Plan
• What audit procedures are to be carried out
• Who should do them
• How much work should be done (sample sizes, etc.)
• When the work should be done (interim vs. final)
27
Interim and Final Audit
Interim Audit Final Audit
Timing
Purpose
Work Performed
Importance of an Interim Audit
28
Fraud and Error
Fraud is the deliberate falsifying of records or misappropriation of company asset. Fraud can be,
• Fraudulent financial reporting. For example, overstating profits to attract investors and lenders.
• Misappropriation of assets. For example, the theft of cash, inventory or non-current assets.
Error is the innocent misstatement of amounts. Errors can be,
• A mistake in gathering and processing data from which financial statements are prepared.
• An incorrect accounting estimate arising from oversight or a misinterpretation of facts.
• A mistake in the application of accounting principles relating to measurement, recognition,
classification, presentation or disclosure
It is management’s responsibility to prevent and detect fraud – not the auditor’s. Auditors are not
expected to find every fraud, but they are expected (with reasonable assurance) to find material
misstatements, whether innocent or fraudulent [ISA 240]
At the planning stage the susceptibility of an entity to fraud should be discussed, with the
engagement team members.
Fraud must be communicated to those charged with governance if it results in material misstatement
or if management is implicated. It is important, even for what appears to be a small fraud, to
investigate how long it has been going on for, how much is involved and who is behind the fraud
Note
Internal Auditors
External Auditor's responsibilities in respect of Fraud
1. Assess the risk of material misstatement due to fraud
• Obtain reasonable assurance that the financial statements are free from material misstatement,
whether caused by fraud or error
• Apply professional scepticism
• Consider the potential for management override of controls
29
To achieve the above the auditors should,
• Enquire of management about their processes for identifying and responding to the risk of fraud
• Enquire of management, internal auditors and those charged with governance if they are aware
of any actual or suspected fraudulent activity
• Consideration of relationships identified during analytical procedures
• Consider any incentives to commit fraud such as profit related bonuses or applications for finance
2. Responding to the Assessed Risks
• Review journal entries made to identify manipulation of figures recorded or unauthorised journal
adjustments
• Review management estimates for evidence of bias
• Review transactions outside the normal course of business, or transactions which appear unusual
and assess whether they are indicative of fraudulent financial reporting
• Obtain written representation from management and those charged with governance that they
have disclosed all relevant information relating to fraud risk
Reporting of Fraud and Error
• If the auditor identifies any fraud or suspected fraud it should be communicated to those charged
with governance or the management
• The auditor must also consider whether they have a responsibility to report the occurrence of a
suspicion to a party outside the entity
• If the fraud has a material impact on the financial statements the audit opinion will be modified
Laws and Regulations
Responsibility of Management
It is the responsibility of management, with the oversight of those charged with governance, to ensure
that the entity's operations are conducted in accordance with relevant laws and regulations [ISA 250]
Responsibilities of the Auditor
The auditor is responsible to perform audit procedures to help identify non-compliance with laws and
regulations that may have a material impact on the financial statements
Audit Procedures to identify instances of Non-Compliance
•
30
Audit Procedures when Non-Compliance is identified
Reporting Non-Compliance
• The auditor must report non-compliance to management and those charged with governance
• If the non-compliance has a material effect on the financial statements, a qualified or adverse
opinion should be issued
• The auditor should also consider whether they have any legal or ethical responsibility to report
non-compliance to third parties
Quality Management
ISA 220 Quality Management for an Audit of Financial Statements requires the firm to design,
implement and operate a system of quality management that provides reasonable assurance
that the firm,
31
32
Note
An EQR is an example of a pre-issuance ('hot') review - i.e. it is carried out before the auditor’s report
is signed
Any reviews carried out after the auditor’s report is signed are known as post-issuance ('cold')
reviews. They will not affect the audit for the year being reviewed, but they will help maintain or
improve quality standards in the future
An audit firm may choose to carry out reviews ('hot' or 'cold') where an EQR is not required
33
Audit Documentation
ISA 230 Audit Documentation requires auditors to prepare and retain written documentation that,
• Provides evidence of the auditor’s basis for their report.
• Provides evidence that the audit was planned and performed in accordance with ISAs and
applicable legal and regulatory requirements
In addition audit documentation fulfils the following very important purposes,
• To enable senior staff to review the work of junior staff. The review process is essential in
carrying out a competent audit: the work of junior staff is reviewed by their supervisor, the
supervisor’s work is reviewed by the manager, and finally the partner, who will sign the auditor’s
report, will review everyone else’s work. Review is not possible without recording the work
carried out and evidence obtained
• To help the audit team in future years. An immensely useful planning exercise at the start of the
audit is to examine last year’s file. Were there problems? Were there any errors? How did last
year’s audit team go about gathering evidence?
• To encourage a methodical, high-quality approach. The audit documentation contains information
documenting the client’s accounting system, the tests that have to be performed (eg select 20
invoices at random and ensure that they are authorised). As each part of the audit is completed
the audit program is signed off by the person who carried it out. Outstanding matters are easy to
see.
Form and content of Audit Documentation
• Title
• Date prepared
• Person who prepared the paper and their signature
• References to other schedules
• Purpose of the audit tests being performed
• Precise details of work performed, such as invoices examined, assets inspected, calculations
reperformed.
• Conclusion from the work performed
• Reviewers signatures and date of review
Note
Documentation is retained in an audit file, which should be completed in a timely fashion after the date
of the auditor's report (normally not more than 60 days after) and retained for the period required by
national regulatory requirements (this is normally five years from the date of the auditor's report)
34