0% found this document useful (0 votes)
35 views5 pages

Audit Risk Assessment Procedures

The document discusses audit risk assessment procedures performed during the planning stage of an audit. It explains that the auditor must obtain an understanding of the company, its environment and internal controls to identify and assess risks of material misstatements. This includes understanding business risks that could impact the financial statements. The auditor assesses control risk to determine the appropriate audit strategy and design audit procedures to test controls and substantive procedures.

Uploaded by

Roite Betero
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
35 views5 pages

Audit Risk Assessment Procedures

The document discusses audit risk assessment procedures performed during the planning stage of an audit. It explains that the auditor must obtain an understanding of the company, its environment and internal controls to identify and assess risks of material misstatements. This includes understanding business risks that could impact the financial statements. The auditor assesses control risk to determine the appropriate audit strategy and design audit procedures to test controls and substantive procedures.

Uploaded by

Roite Betero
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Chapter 8

Before we move on how to carry out audit testing (test of controls and substantive procedures), we
have to further explain some of the procedures that needs to be carried out at the planning stage. The
auditor must assess the risk (materially incorrect) attached to the audit opinion and the elements that
contribute to that risk.

This chapter looks at the auditor’s obligations with regard to assessing the risks that the company is
exposed to, with particular reference to those that will affect the financial statement assertions.

Learning outcomes 8.1.

Understand the importance of audit risk assessment and why it is linked to financial statement
assertions.

Audit risk assessment procedures

 are performed to obtain an understanding of the company and its environment, including
the company's internal control,
 to identify and assess the risks of material misstatement of the financial statements,
whether due to fraud or error.

Referring to the overall objectives of a financial statement audit, as described in paragraph 11 of ASA
200 Overall Objectives of the independent auditor and the conduct of an audit in accordance with
Australian auditing standards (ISA 200), ‘the auditor to express an opinion on whether the financial
report is prepared, in all material respects, in accordance with an applicable financial reporting
framework’.

As part of the audit planning stage, the auditor must obtain an understanding of the entity and its
environment, including internal controls in order to assess the risk that the financial statements contain
material misstatements (the information obtained is not only evidence to support the auditor's risk
assessment but also is used to determine the further audit procedures that are required)

Financial statement assertions referred as set of assertions about each transaction class and account
balances including items that are presented and disclosed which are made by the management of the
entity when preparing the financial statements.

Learning outcomes 8.2.

Explain the importance of business risks in audit planning

First of all, business risk defined as “risk resulting from significant conditions, events, circumstances,
actions or inactions that could adversely affect an entity's ability to achieve its objectives and execute
its strategies, or from the setting of inappropriate objectives and strategies”.

For example

 damage by fire, flood or other natural disasters.


 unexpected financial loss due to an economic downturn, or bankruptcy of other businesses that
owe you money.
 loss of important suppliers or customers.
 decrease in market share because new competitors or products enter the market.
 High financial risk
 Cash flow issues
 High risk of theft and fraud
 Increase in production cost
 Lack of financing
 Decline in demand
 Loss of profitability
 Legal issues
 Increased competition
 Decrease in customers
 Over trading
 Political or economic instability

Having identified the business risks facing an organization, the auditor must consider the extent to
which these risks could lead to a material misstatement in the financial statements and to what extent
the company has implemented controls to reduce these risks.

A business risk approach allows the auditor

 Identify threats faced by the organisation


 Recognises that most business risks will eventually have an effect on the financial statement
 Increase the chances of identifying risks of material misstatements in the financial reports.

The in-depth understanding of the business that the auditor obtains in taking a business risk approach
should increase the chances that the auditor will identify the risks of material misstatement in the
financial statements and therefore improve the quality of the audit and the audit opinion. A well-
informed auditor is of significant benefit to the company, since he or she is able to provide better quality
advice to the company concerning the types of controls that could be implemented to reduce these risks

Business risk has three types

1. Financial risk
 Risks that arise from the company’s financial activities or the financial consequences.
For example, the going concern problems arising from poor performance, the credit risk
of not being able to collect debts and so on.

2. Compliance risk (aki iran te tua ma kainibaire)


 Risk that arise from non-compliance with laws, regulations, policies, procedures and
contract. For example, sued by a customer for supplying faculty goods, breaches of
health and safety requirement leads to the closure of the business
3. Operational risk
 Risks that arise from the operations of the business. For example, no stock on hands
leads to loss of sales, disasters that affect the stock or machinery, loss of key and skills
staff and so on.

Learning Outcomes 8.3.

Describe the procedures performed by an auditor to assess risk

The work the auditor does in obtaining an understanding of the entity, includes obtaining an
understanding of business risks and the company's own risk assessment procedures. These procedures
are known as discussions with management (enquires) as well as performing analytical procedures,
making observations of processes in action and inspecting relevant documents (observations and
inspecting).

Learning outcomes 8.4.

Understand the importance of internal control of an entity and its independent auditors

Generally, as companies grown in size and complexity, the importance of internal control within those
companies has also grown. This is because the size and the complexity have made it difficult for
managers and those charged with governance to manage the company’s risks without appropriate
control systems in place. Similarly, the growth in size and complexity of companies has meant that for
auditors to provide assurance, some reliance on these controls is usually needed.

The fundamental concept of internal control

Internal control defined as “a process, effected by an entity's board of directors, management, and
other personnel, designed to provide reasonable assurance regarding the achievement of objectives
relating to operations, reporting, and compliance.”

• Internal control is a process. It is a means to an end, not an end in itself. It consists of a series of
actions that are pervasive and integrated with, not added onto, an entity’s infrastructure.

• Internal control is effected by people. It is not achieved merely by having policy manuals and
forms, but by the actions and attitudes of people at every level of an organisation, including the
board of directors and management.

• Internal control can be expected to provide only reasonable assurance, not absolute
assurance, for an entity’s management and board. This is because limitations are inherent in all
internal control systems and because the entity must consider the relative costs and benefits of
establishing controls.

• Internal control is geared to the achievement of objectives in the categories of operations,


reporting and compliance.
Internal control systems

 Control environment
 Risk assessment processes
 Information system
 Control activities
 Monitoring of controls.

Learning outcomes 8.5.

Indicate the procedures for obtaining and documenting an understanding of the entity’s internal control.

A sufficient understanding of internal control is essential for an effective audit because it informs the
auditor about where misstatements are likely to occur

a. Procedures to obtain an understanding


 Reviewing previous experience with the entity
 Enquiring of appropriate management, supervisory and staff personnel
 Inspecting documents and records
 Observing entity activities and operations

b. Documenting the understanding

Internal Control Questionnaire (ICQ):


 Consists of a series of questions about accounting and control policies and procedures
the auditor considers necessary to prevent material misstatements in the financial
statements.
Flow chart:
 Is a schematic diagram that uses standardised symbols, interconnecting flow lines and
annotations to portray the steps involved in processing information through the
information system
Narrative memoranda
 May be used to supplement other forms of documentation by summarising the auditor’s
overall understanding of the information system or specific control policies or
procedures.
 In small entities, a narrative memorandum may serve as the only documentation of the
auditor’s understanding.

Learning Outcomes 8.6.

Explain why and how a preliminary assessment of control risk is made

First of all, control risk defined as “is the risk that a material misstatement could occur in an assertion,
either individually or when aggregated with other misstatements, and not be prevented, detected, or
corrected on a timely basis by the entity's internal control structure”.
a. Why a preliminary assessment of control risk is made

The auditor uses preliminary assessment to assess the strengths and weaknesses of those internal
controls and the level of control risk.

• Purpose of preliminary assessment:

– Assessment to obtain a reasonable expectation of controls in place decide on


appropriate audit strategy so as to design a detailed audit program.

How preliminary control risk is made

Assessing control risk

 Evaluating the effectiveness of the design and operation of an entity’s internal controls in
preventing or detecting material misstatements in the financial statements

These are the steps:

– assess the control environment

– assess the design effectiveness of control procedures and their ability to prevent or
correct misstatement

– assess whether controls were effectively applied throughout the period under audit.

Learning outcomes 8.7.

Explain the importance of the concept audit risk and its three components

Audit risk is the risk that the auditor gives an inappropriate audit opinion when the financial
statements are materially misstated

Audit risk is commonly assessed within three components:

• inherent risk - is the possibility that a material misstatement could occur in an assertion,
either individually or when aggregated with other misstatements, assuming there are no
related controls

• control risk - is the risk that a material misstatement could occur in an assertion, either
individually or when aggregated with other misstatements, and not be prevented,
detected, or corrected on a timely basis by the entity’s internal control structure

• detection risk - is the risk that an auditor’s substantive procedures will not detect any
material misstatements that exist in an assertion, either individually or when aggregated
with other misstatements

Common questions

Powered by AI

Assessing an entity’s internal controls is crucial because it informs the auditor where misstatements are likely to occur, thereby directing the audit procedures accordingly. Understanding and evaluating internal controls helps auditors determine the risk of material misstatements and the reliability of the financial reporting process. If internal controls are strong, auditors may be able to rely more on them and reduce the amount of substantive testing required, which in turn affects the audit strategy and efficiency .

Auditors consider several types of business risks, including financial risks (e.g., poor performance, credit risks), compliance risks (e.g., breaches of regulations), and operational risks (e.g., loss of key staff, disasters affecting resources). These risks can impact financial statements by potentially leading to misstatements or financial instability, such as overstated revenues, underestimated liabilities, or incorrect assessments of asset values. Understanding these risks helps auditors assess the areas in financial statements that might be most susceptible to material misstatements and informs the identification of necessary audit procedures to address these risks .

The control environment sets the tone of an organization, influencing the control consciousness of its people. Assessing the control environment involves examining elements like management's integrity and ethical values, governance oversight, and commitment to competence. A strong control environment lays down a foundation for other components of internal control, ensuring that internal controls are designed and implemented effectively. It is essential for auditors to understand the control environment to assess the overall effectiveness of the internal control system and determine how much reliance can be placed on controls .

Audit risk comprises three key components: inherent risk, control risk, and detection risk. Inherent risk is the possibility of a material misstatement occurring in the financial statements before considering internal controls. Control risk is the risk that a company’s internal controls will fail to prevent or detect a material misstatement in a timely manner. Detection risk refers to the risk that the auditor’s procedures will not detect a material misstatement. These components interact such that the auditor adjusts the audit effort to address each risk level identified. A high inherent risk necessitates thorough testing of controls and substantive procedures to adequately lower the audit risk to an acceptable level .

Understanding business risks helps auditors identify potential areas where material misstatements in financial statements might occur. A deep understanding of the business and its environment, including identifying business risks, allows auditors to better assess the likelihood and impact of these risks on the financial statements. This understanding increases the likelihood of identifying risks of material misstatements and ultimately improves the quality of the audit and the audit opinion as auditors can provide more insightful advice on necessary controls to mitigate these risks .

Internal control systems have inherent limitations, including the possibility of human error or judgment mistakes, potential for the circumvention of controls through collusion, and management override of controls. The cost-benefit consideration also implies not all controls will be implemented to avoid excessive costs. Auditors must remain vigilant to these limitations when assessing the reliability of internal controls. As such, they cannot assume absolute effectiveness of any control system and must design substantive procedures that account for these weaknesses. Such limitations necessitate a degree of skepticism and the continuous evaluation of control effectiveness throughout the audit process .

Performing a preliminary assessment of control risk helps auditors evaluate the strengths and weaknesses of internal controls and the associated risk level with financial misstatements. This assessment guides auditors in designing appropriate audit strategies, as it allows them to determine whether to rely on internal controls or whether more substantive testing is necessary. The assessment is a foundational step that ultimately influences the auditor’s approach to collecting audit evidence and aids in designing a detailed audit program .

A business risk approach enhances the auditor’s ability by focusing on understanding significant conditions, events, or circumstances that may lead to material misstatements. By identifying and evaluating business risks, such as changes in market conditions, operational challenges, or regulatory compliance risks, auditors gain deeper insights into strategic areas that affect financial reporting. This understanding helps in pinpointing likely sources of material misstatements, allowing for more targeted and effective audit procedures, and improving the overall audit quality .

Internal control questionnaires (ICQs) consist of a series of structured questions about the company’s accounting and control policies, which help identify areas of potential weakness. They ensure all significant control aspects are considered. Flow charts use standardized symbols to provide a visual representation of processes, highlighting the flow and control points within the system. ICQs offer comprehensive coverage required for effective understanding, while flow charts simplify visualization of processes and can reveal gaps or redundancies in control procedures. Each method supports the thorough documentation of internal control understanding and assists in planning audit procedures .

Substantive audit procedures are direct tests of financial statement balances and transactions to detect material misstatements. In contrast, tests of controls examine the effectiveness of a company’s internal controls in preventing or detecting errors and fraud. Substantive procedures provide evidence on the accuracy of amounts and disclosures in financial statements, while tests of controls provide insights into the internal control environment and help evaluate control risk. Both are crucial for risk assessment: tests of controls can enable auditors to rely more on the internal controls if they are found effective, potentially reducing the extent of substantive testing needed .

You might also like