0% found this document useful (0 votes)
2 views15 pages

AA RISK

Audit risk refers to the risk that an auditor may provide an inappropriate opinion on financial statements due to material misstatements. It is influenced by inherent risk, control risk, and detection risk, and cannot be eliminated entirely due to the limitations of auditing. The document also discusses various types of risks, including sampling and non-sampling risks, and emphasizes the importance of understanding the entity, planning the audit, and maintaining professional skepticism.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views15 pages

AA RISK

Audit risk refers to the risk that an auditor may provide an inappropriate opinion on financial statements due to material misstatements. It is influenced by inherent risk, control risk, and detection risk, and cannot be eliminated entirely due to the limitations of auditing. The document also discusses various types of risks, including sampling and non-sampling risks, and emphasizes the importance of understanding the entity, planning the audit, and maintaining professional skepticism.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Risk

Audit Risk

Audit risk is a technical term related to the process of auditing. It should be noted that audit risk cannot
be reduced to zero, as an audit cannot provide absolute assurance but reasonable assurance. This is
because an audit has ‘inherent limitations’, for example,

• Part of the nature of financial reporting is that financial statements should include accounting
estimates which necessarily involve judgement
• Audit procedures are designed to gather audit evidence, not to detect intentional misstatement
that has been deliberately concealed.
• As an audit needs to be conducted within a reasonable period of time and at a reasonable cost, it
is not possible to examine everything exhaustively

Audit risk is considered throughout the audit, in particular,

• In understanding the entity – what are the risks? (ISA 315 Identifying and Assessing the Risks of
Material Misstatement through Understanding the Entity and Its Environment)
• In planning the audit – how are risks to be reduced to an acceptably low level? (ISA 330 The
Auditor’s Responses to Assessed Risks)

Definition – Audit Risk

The risk that the auditor gives an inappropriate opinion on the financial statements (i.e. the audit
opinion is that the financial statements show a true and fair view when, in fact, they contain a material
misstatement)

Audit risk is a function of two risks;

Audit
Risk

Risk of Detection
MM Risk

Inherent Control
Risk Risk

20
Therefore, for an inappropriate opinion to have been expressed,

The client's procedures The material error


has not picked it and The auditor must have reaches the published
The error has to occur
failed to detect it
corrected it financial statments

The Audit Risk Model

AR = IR x CR x DR

If both inherent risk and control risks are high, then the only way you will get the audit risk low is to be
very sure that your detection risk is low. This means you would have to do an enormous amount of
audit work.

If, however, the inherent risk and control risks are low themselves, in other words that there is only a
small chance the error occurs in the first place and the client systems and staff are very good, then you
can achieve a relatively low audit risk even with a relatively high detection risk. In other words the
auditor doesn’t have to do so much work

The auditor assesses inherent and control risk - but cannot change them - they are 'givens' specific to
each audit. The auditor must respond to the assessed risks by varying the nature, timing and extent
of work which is actually performed to reduce detection risk to an acceptably low level

Sampling Risk

This risk arises when audit procedures are applied to samples rather than entire populations. The auditor
may conclude, based on a sample, that controls are more effective than they actually are or that there
is no material misstatement when, in fact, there is.

21
Non-Sampling Risk

This risk arises from reasons other than sample size. For example, audit staff were insufficiently
experienced, there is a higher risk that they might use inappropriate audit procedures, misinterpret
evidence or fail to recognize an error.

Non-sampling risk must be minimized through adequate planning, assigning sufficiently skilled staff and
the direction, supervision and review of their work

Inherent Risk

This is the risk that there is a misstatement that could be material, if there were no related internal
controls which could identify and trap that misstatement.

Inherent risks can be increased by complex transactions which are difficult to understand, inexperience
staff, a cash-based business (because cash is usually more difficult to record than bank transfers) etc.

Control Risk

This is the risk that the material misstatement, having occurred, will not be prevented or detected and
corrected by the internal control system. The main factors which affect control risk are the control
environment (essentially the status that the internal control system has in the organization), the design
of the internal control system itself, and finally how well and consistently the internal control system
operates.

Detection Risk

This is the failure of the auditor to detect the material misstatement in the financial statements. This
will be increased if the auditor was relatively inexperienced, if it was a new client, if there was a lot of
time and fee pressure, if planning was poor so the entity was poorly understood, and if the auditor was
straying into an industry where they had little previous experience or expertise

Note - Professional Scepticism

Materiality

Misstatements, including omissions, are considered to be material if they, individually or in the


aggregate, could reasonably be expected to influence the economic decisions of users taken on the basis
of the financial statements.' [ISA 320 Materiality in Planning and Performing an Audit]

ISA 320 recognizes the need to establish a financial threshold and the following benchmarks can be used,

• ½ – 1% revenue
• 5 – 10% profit before tax
• 1 – 2% total assets

22
Material by Nature

• Misstatements that affect compliance with regulatory requirements


• Misstatements that affect compliance with debt covenants.
• Misstatements that, when adjusted, would turn a reported profit into a loss for the year.
• Misstatements that, when adjusted, would turn a reported net-asset position into a net-liability
position.
• Transactions with directors, e.g. salary and benefits, personal use of assets, etc.
• Disclosures in the financial statements relating to possible future legal claims or going concern
issues

Performance Materiality

The amount set by the auditor at less than materiality for the financial statements as a whole to reduce
to an appropriately low level the probability that the aggregate of uncorrected and undetected
misstatements exceeds materiality for the financial statements as a whole. [ISA 320]

Understanding the Entity and its Environment

• Nature of the Entity


We have to understand the nature of the entity. For example, we simply have to understand what
it does, is it in a financial sector, the retail sector, the manufacturing sector?

• Particular Regulations
Banks, insurance companies, and many other operations in the financial sector are subject to
regulation and sometimes the auditor has to ensure that these regulations have been adhered to

• Accounting Policies
We need to understand what the entity’s accounting policies are; different entities have different
ways of valuing inventories perhaps. If you are a building company you will have specific
accounting policies with regard to taking profits from long-term contracts

• Nature of business risks


Most business risks will eventually have financial consequences and therefore an effect on the
financial statements.

• Internal Controls
The auditor has to gain an understanding of the entity’s internal controls. Whether they exist and
to what extent they are expected to operate

• The Control Environment


This refers to the context in which the internal controls operate. The effectiveness of the control
environment has a significant bearing on audit procedures

23
• Financial Performance
Obtaining an understanding of the entity’s performance measures assists the auditor in
considering whether they put pressure on management to act in any way that increases the risks
of material misstatements

Sources of Information




Risk Assessment Procedures

Enquiries

Analytical Procedures

ISA 520 – “Evaluations of financial information through analysis of plausible relationships among both
financial and non-financial data and investigation of identified fluctuations, inconsistent relationships or
amounts that differ from expected values by a significant amount”

Analytical procedures are used in order to,


• Identify aspects of the entity of which the auditor was unaware.
• Assist in assessing the risks of material misstatement.
• Help identify unusual transactions or events, and amounts, ratios, and trends that might have
audit implications.
• Help identify risks of material misstatement due to fraud
Analytical procedures include
• Comparable information for prior periods.
• Anticipated results of the entity, such as budgets or forecasts, or expectations of the auditor,
such as an estimation of depreciation.
• Similar industry information
Analytical procedures are used as,
• Preliminary analytical procedures
• Substantive analytical procedures
• Final analytical procedures

Observation

Inspection

24
Business Risk

Business risk is the exposure a company or organization has to factor(s) that will lower its profits or lead
it to fail. Anything that threatens a company's ability to achieve its financial goals is considered a
business risk

Audit Risk Identification and Explanation

Identification of Risk Audit Risk Explanation Business Risk


Customers are struggling to pay
debts.
The client operates in a fast
paced industry
Revenue is falling due to
recession. The cash flow
forecast shows negative cash
flows for the next 12 months

Auditor Responses to Risks

25
Planning

ISA 300 - Planning an Audit of Financial Statements

In accordance with ISA 300 ‘'The objective of the auditor is to plan the audit so that it will be performed
in an effective manner’

Benefits of Planning

Audit Timing

The first thing that has to happen is a planning visit, or if not a visit at least a telephone call. There
would certainly be a visit before the first audit of a new client commenced.

Contact is necessary because, at the very least, you have to agree with the client when the audit staff
will visit. Also at this planning stage, enquiry should be made about what changes may have taken
place at the client’s since the previous audit.

The next stage is what’s known as the interim audit. The interim audit would typically happen perhaps
in July or August of the year to 31 December. The auditor will carry out tests of controls, to ensure that
the system of internal control as they understand it and as specified by the client is actually working in
practice

There will usually be some audit procedures that have to be carried out at the reporting date. For
example, where the value of inventory included in the financial statements will be based on physical
quantities, the auditor will plan to attend the physical count.

26
After the year-end, the auditors will return and carry out a final audit. At this point the client should
have prepared the financial statements and the auditor will be concentrating on obtaining sufficient
appropriate audit evidence to express a conclusion on the financial statements

Planning Process

• Preliminary engagement activities

• Planning activities

Audit Strategy

Audit Plan

• What audit procedures are to be carried out


• Who should do them
• How much work should be done (sample sizes, etc.)
• When the work should be done (interim vs. final)

27
Interim and Final Audit

Interim Audit Final Audit

Timing

Purpose

Work Performed

Importance of an Interim Audit

28
Fraud and Error

Fraud is the deliberate falsifying of records or misappropriation of company asset. Fraud can be,

• Fraudulent financial reporting. For example, overstating profits to attract investors and lenders.
• Misappropriation of assets. For example, the theft of cash, inventory or non-current assets.

Error is the innocent misstatement of amounts. Errors can be,

• A mistake in gathering and processing data from which financial statements are prepared.
• An incorrect accounting estimate arising from oversight or a misinterpretation of facts.
• A mistake in the application of accounting principles relating to measurement, recognition,
classification, presentation or disclosure

It is management’s responsibility to prevent and detect fraud – not the auditor’s. Auditors are not
expected to find every fraud, but they are expected (with reasonable assurance) to find material
misstatements, whether innocent or fraudulent [ISA 240]

At the planning stage the susceptibility of an entity to fraud should be discussed, with the
engagement team members.

Fraud must be communicated to those charged with governance if it results in material misstatement
or if management is implicated. It is important, even for what appears to be a small fraud, to
investigate how long it has been going on for, how much is involved and who is behind the fraud

Note

Internal Auditors

External Auditor's responsibilities in respect of Fraud

1. Assess the risk of material misstatement due to fraud

• Obtain reasonable assurance that the financial statements are free from material misstatement,
whether caused by fraud or error
• Apply professional scepticism
• Consider the potential for management override of controls

29
To achieve the above the auditors should,

• Enquire of management about their processes for identifying and responding to the risk of fraud
• Enquire of management, internal auditors and those charged with governance if they are aware
of any actual or suspected fraudulent activity
• Consideration of relationships identified during analytical procedures
• Consider any incentives to commit fraud such as profit related bonuses or applications for finance

2. Responding to the Assessed Risks

• Review journal entries made to identify manipulation of figures recorded or unauthorised journal
adjustments
• Review management estimates for evidence of bias
• Review transactions outside the normal course of business, or transactions which appear unusual
and assess whether they are indicative of fraudulent financial reporting
• Obtain written representation from management and those charged with governance that they
have disclosed all relevant information relating to fraud risk

Reporting of Fraud and Error

• If the auditor identifies any fraud or suspected fraud it should be communicated to those charged
with governance or the management
• The auditor must also consider whether they have a responsibility to report the occurrence of a
suspicion to a party outside the entity
• If the fraud has a material impact on the financial statements the audit opinion will be modified

Laws and Regulations

Responsibility of Management

It is the responsibility of management, with the oversight of those charged with governance, to ensure
that the entity's operations are conducted in accordance with relevant laws and regulations [ISA 250]

Responsibilities of the Auditor

The auditor is responsible to perform audit procedures to help identify non-compliance with laws and
regulations that may have a material impact on the financial statements

Audit Procedures to identify instances of Non-Compliance


30
Audit Procedures when Non-Compliance is identified

Reporting Non-Compliance

• The auditor must report non-compliance to management and those charged with governance
• If the non-compliance has a material effect on the financial statements, a qualified or adverse
opinion should be issued
• The auditor should also consider whether they have any legal or ethical responsibility to report
non-compliance to third parties

Quality Management

ISA 220 Quality Management for an Audit of Financial Statements requires the firm to design,
implement and operate a system of quality management that provides reasonable assurance
that the firm,

31
32
Note

An EQR is an example of a pre-issuance ('hot') review - i.e. it is carried out before the auditor’s report
is signed

Any reviews carried out after the auditor’s report is signed are known as post-issuance ('cold')
reviews. They will not affect the audit for the year being reviewed, but they will help maintain or
improve quality standards in the future

An audit firm may choose to carry out reviews ('hot' or 'cold') where an EQR is not required

33
Audit Documentation

ISA 230 Audit Documentation requires auditors to prepare and retain written documentation that,

• Provides evidence of the auditor’s basis for their report.


• Provides evidence that the audit was planned and performed in accordance with ISAs and
applicable legal and regulatory requirements

In addition audit documentation fulfils the following very important purposes,

• To enable senior staff to review the work of junior staff. The review process is essential in
carrying out a competent audit: the work of junior staff is reviewed by their supervisor, the
supervisor’s work is reviewed by the manager, and finally the partner, who will sign the auditor’s
report, will review everyone else’s work. Review is not possible without recording the work
carried out and evidence obtained

• To help the audit team in future years. An immensely useful planning exercise at the start of the
audit is to examine last year’s file. Were there problems? Were there any errors? How did last
year’s audit team go about gathering evidence?

• To encourage a methodical, high-quality approach. The audit documentation contains information


documenting the client’s accounting system, the tests that have to be performed (eg select 20
invoices at random and ensure that they are authorised). As each part of the audit is completed
the audit program is signed off by the person who carried it out. Outstanding matters are easy to
see.

Form and content of Audit Documentation

• Title
• Date prepared
• Person who prepared the paper and their signature
• References to other schedules
• Purpose of the audit tests being performed
• Precise details of work performed, such as invoices examined, assets inspected, calculations
reperformed.
• Conclusion from the work performed
• Reviewers signatures and date of review

Note

Documentation is retained in an audit file, which should be completed in a timely fashion after the date
of the auditor's report (normally not more than 60 days after) and retained for the period required by
national regulatory requirements (this is normally five years from the date of the auditor's report)

34

You might also like