SECTION A – Important
Performance Audit -
Aim to provide management with assurance and audit regarding the effective
functioning of its operational activities.
A performance audit uses auditing skills and applying them to activities of the
organisation that an external auditor of the financial statements would not
normally consider.
Performance audit may include-
Performance information
Value for money
Operational audit
Value for money -
Economy – obtaining the lowest cost for the requires level of quality.
Efficiency – achieving the maximum output for the minimum input.
Effectiveness – achieving the targets set.
(In the context of public sector organisation, value for money is concerned
with stewardship of the public pound I.e., not wasting taxpayer money.)
Performance information -
Is information published by the public sector bodies regarding their objectives
and the achievement of those objectives.
Public sector organisations have targets set by the government which must be
reported to assess the organisations performance.
This information should have the same qualitative characteristics of general-
purpose financial reports such as relevance, completeness, reliability,
neutrality, understandability, timeliness, validity, and accuracy.
Difficulties encountered when performing Audit of Performance information.
All relevant information may not me reported, therefore it may appear as
though there has been improvement when problems may not have been
recorded completely. Where information is completely recorded, accuracy of
the information may be an issue.
Definitions of certain targets and measures may be ambiguous resulting in
matters going un-recorded due to public sector employees recording
information in a different way. Information may be classified differently by
different members of staff unless specific training is given. Information may
not be comparable between different companies / organisations if each
interpret the information in a different way.
There is also the risk that the public sector departments will falsify the figures
that have been reported if they are failing to meet the targets set by the
government. This may be difficult for the auditor to detect as it unlikely there
will be alternative forms of corroborative evidence to highlight discrepancies.
Aggressive earning management - refers to using accounting policies and
stretching judgements of what is acceptable to present corporate performance in
a more favourable light than the underlying reality.
Matters to consider before placing reliance on the work of auditor’s expert.
ISA 620 Using the work of an Auditor’s expert, contains the
requirements relating to objectivity, competence and capabilities of the
auditor’s expert, the scope, and objectives pf their work, and assessing
their work.
Objectivity – According to ISA 620, the auditor shall evaluate whether
the auditor’s expert has the necessary objectivity and this should include
enquiry regarding interests and any relationship which may create
threat to the expert’s objectivity. The audit firm needs to ensure that the
expert has no connection with the client, for example that they are not
related party of the company or any person in a position of influence
over the financial statements.
If the expert’s objectivity is threatened, little or no reliance can be
placed on their work, and the audit firm should not treat it as a reliable
source of evidence.
Competence – ISA 620 also requires the competence of the expert to be
considered, this should include considering the expert’s membership of
appropriate professional bodies. Any doubts over the competence of the
expert will reduce reliability of audit evidence obtained.
Scope of work – this may include agreement of the objectives of the
work, how the experts work will be used by the auditor and the
methodology and key assumptions to be used.
In assessing the work performed by the expert, the auditor should
confirm that the scope of the work is agreed in the start of the
engagement. If the expert has deviated from the agreed scope of work,
it is likely to be less relevant and reliable.
Relevance of conclusions – ISA 620 states that, the auditor shall evaluate
the relevance and adequacy of the expert’s findings or conclusions. This
will involve consideration of the source data which is used, the
appropriateness of assumptions and the reasons for any changes in
methodology or assumptions. The conclusion should be consistent with
other relevant audit findings and with the auditor’s general
understanding of the business.
If the work involves using source data which is significant to their
workings, the audit teams should plan to assess the relevance,
completeness, and accuracy of the data. Any inconsistencies should be
investigated as they may indicate evidence which is not reliable.
New audit client – Audit risk
Since this is the first time our firm has audited the group / new audit client co,
this gives rise to detection risk as our firm does not have experience with the
client, making it difficult for us to detect material misstatements. However, the
risk can be mitigated by rigorous audit planning, including obtaining a
thorough understanding of the business of the client.
In addition, there is a risk that the opening balances and comparative
information may not be correct. (There is no reason for this to be a particularly
substantial risk, as the previous audit opinions have been unmodified for the
past years) However, because the prior year figures were not audited by our
firm, we should plan to audit opening balances carefully, in accordance with
ISA 510 – initial audit engagements – opening balances, to ensure that opening
balances and comparative information are both from material misstatements.
The extent of involvement the group audit firm should have with the work of
the component auditor.
When working with the component auditor, the group engagement team
should obtain an understanding on several matters as requires by ISA 600.
These matters could include the competence of the component auditor,
whether the component auditor understands the ethical framework relating to
the group and is independent, and the regulatory environment in which the
component auditor operates.
The higher the concerns over competence, independence or diligence of
component auditor, the level of involvement will be higher.
According to ISA 600, if a component auditor performs an audit of the financial
information of a significant component, the group engagement team is
required to be involved in the component auditor’s risk assessment to identify
significant risks of material misstatement of the group financial statements.
The nature and extent of involvement are affected by the group engagement
team’s understanding of the component auditor, but a minimum should
include -
Discussing with the component auditor or component management the
component’s business activities which are significant to the group.
Discussing with the component auditor the susceptibility of the
component to material misstatement of the financial information due to
fraud and error.
Reviewing the component auditor’s documentation of the identified
significant risks of material misstatements of the group financial
statements.
Evaluating the component auditor’s communication on matters relevant
to the group audit and discuss any significant matters arising from that
evaluation with the component auditor / management or group
management as appropriate.
Determine whether it is necessary to review other relevant part of the
component auditor’s audit documentation.
The group audit team may need to have further involvement with the
component audit where significant risk of material misstatements of the group
financial statements have been identified in a component.
ISA 210 – Agreeing the terms of Audit engagement -
The management of the client should acknowledge their responsibility to
provide the auditor with access to information which is relevant to the
preparation of the financial statements which includes unrestricted access to
persons within the entity whom the auditor determines it necessary to obtain
audit evidence from.
This would appear to impose a limitation on the scope of audit and the audit
engagement partner should raise the issue with the audit committee.
ISA 250 – Consideration of laws and regulation in an audit of financial
statements -
It requires that, if an auditor becomes aware of information concerning any
instances of non-compliance or suspected non-compliance with laws and
regulations, the auditor shall obtain an understanding of the act and
circumstances under which it has occurred, and further information to
evaluate the possible effect on the financial statements.
Therefore, the audit plan should contain planned audit procedures which are
sufficient for the audit team to conclude on the accounting treatment and on
whether the auditor has any reporting responsibilities outside the group.
Data Analytics -
It is the science and art of discovering and analysing patterns, deviations and
inconsistencies and extracting other useful information in the data of
underlying or related subject matter of the audit through analysis, modelling,
visualising for the purpose of planning and performing the audit.
Data analytics can allow the interrogation of 100% of the transactions in a
population where the data set is complete and can be provided to the auditor.
It is a progression from using CAAT to perform analytical procedures.
How data analytics can improve audit quality -
Detection risk is reduced as it has the potential to audit 100% of the
transactions.
Audit procedures can be performed more quickly resulting in more time
being available to analyse the information and exercise professional
scepticism.
There is likely to be greater interaction between the audit firm and the
audit committee throughout the year which is likely to result in the
firm’s knowledge of the business being updated on a regular basis
compared with a traditional year-end audit where the understanding is
updated at the planning stage.
Auditor is more likely to issue an unmodified opinion.
Matters to be considered in determining the amount of reliance which can be
placed on the work of client’s internal audit department -
According to ISA 610 – using the work of Internal auditors, the external auditor
may decide to use the work if the internal auditor’s client internal audit
function to modify the nature or timing, or reduce the extent of audit
procedures to be performed directly by the external auditor.
(Note: that in some jurisdictions the external auditor may be prohibited or
restricted by law or regulation in using the work of the internal audit function.)
Evaluate the internal audit function -
Objectivity – one of the key issues to be evaluated is objectivity – the
internal audit department should be unbiased in their work and be able
to report findings without being subject to influence of others. Internal
audit team should directly report to the audit committee or to those
charged with governance to maintain their independence.
Competence – the audit firm should ensure the audit team is staffed
with proper and professionally qualified personal, and whether the
client company has a training programme in place for the internal
auditors, and whether there are sufficient resources for the internal
auditors to carry out their duties.
Scope of work – the scope of work carried out in this area and the
resulted recommendations will need to be reviewed. This may further
suggest that the internal audit department is not free to investigate or
report their findings because of the current reporting chains.
If there are doubts over the objectivity or competence of the internal audit
team at the clients, then the audit firm should not rely on their work.
Systematic and disciplined approach – to determine whether the
internal audit department works in a systematic and disciplined way, the
audit firm should consider matters including the nature of
documentation which is produced by the department and whether
effective quality procedures are in place such as direction, supervision
and review of work are carried out.
Internal audit department providing direct assistance -
If the audit firm wants to use the internal audit function to provide direct
assistance, then the firm should -
Obtain written agreement from an authorised representative of the
entity that the internal auditors will be allowed to follow the external
auditor’s instructions and that the entity will not intervene in the work
the internal auditor performs for the external auditor.
Obtain written agreement from the internal auditors that they will keep
confidential specific matters as instructed by the external auditor and
inform them of any threat to their objectivity.
If these confirmations cannot be obtained, then the internal auditors should
not be used to provide direct assistance.
Joint audit – (with local audit firm at foreign location of a subsidiary or
potential subsidiary)
In a joint audit, two or more audit firms are responsible for conducting the
audit and for issuing the audit opinion. This enables the local audit firm’s
understanding and experience to be retained which will be more valuable
input to the audit. At the same time (our) audit firm can provide additional
skills and resources if necessary.
The foreign subsidiary may have different regulations to the rest of the group,
it makes sense for the local auditors, therefore to retain some input into the
audit as they will have detailed knowledge of such regulations.
The fact that the company is located at a distant location means that t=from a
practical point of view it may be difficult for (our) audit firm to provide staff for
performing the bulk of the audit work. It would be cost effective for this to be
carried out by local auditors.
Two firms can also stand together against aggressive accounting treatments. In
this way the joint audit can enhance the quality of the audit.
The main disadvantage is that for the client group, having a joint audit is likely
to be more expensive that appointing just one audit firm. However, the costs
are likely to be less than if the audit firm took sole responsibility, as having
current auditors retain an involvement will cut down on travel expenses. The
small local firm will probably offer a cheaper audit service.
For the audit firms there may be a problem in deciding on responsibilities,
allocating work, and they will need to work very closely together to ensure that
no duties go underperformed, and that the quality of audit is maintained.
Stock exchange listing and pressure on results – Audit risk.
Any listing obtained during the year or the aim to obtain a listing in the
following financial year can create an inherent risk at the financial statements
level, because management may feel under pressure to achieve good financial
results in this financial year.
There is a risk that revenue and profits may be overstated.
Impact of outsourcing on Audit -
Outsourcing is when certain functions within the business are contracted out
to third parties known as service organisations. It is common for companies to
outsource one or more of its functions for examples – payroll, IT human
resources etc.
According to ISA 2402 – Audit considerations relating to an entity using a
service organisation requires an auditor to obtain an understanding of how the
client uses the service of a service organisation in the client’s operations
including the following matters -
The nature of the services provided by the service organisation and the
significance of those to the client, including effect on internal control/
The nature and materiality of the transactions processed or accounts or
financial reporting processes affected by the service organisations.
The degree of interaction between the activities of the service
organisation and those of the client.
The nature of the relationship between the client and service
organisation, including the relevant contractual terms.
The reason for the audit firm to require an understanding of these matters, is
so that any risk of material misstatements created by the use of the service
organisation can be identified and an appropriate response planned.
The audit firm is also required under ISA 402 – to evaluate the design and
implementation of relevant controls at the client entity which relate to the
services provided by the service organisations. This is to obtain understanding
of the control risk associated with the outsourced function, for example,
whether the transactions and information provided by the service organisation
is monitored and whether checks are performed prior to inclusion in financial
statements.
Information should be available from the client to enable understanding
outlined above. The purpose of obtaining understanding is to help the auditor
to determine the level of competence of the service organisation, and whether
it is independent of the client entity.
Matters to be considered in respect of component auditor work -
ISA 600 requires that if the group engagement team plans to request a
component auditor to perform work on the financial information of a
component, the group engagement team shall obtain an understanding
of following matters -
The group engagement team should ascertain whether the component
auditor understands and will comply with ethical requirements which
are relevant to the group audit and in particular, is independent. When
performing the work on the financial information of a component for
group audit, the component auditor is subject to ethical requirements
which are relevant to the group audit.
The component auditor’s competence should also be assessed, including
whether the component auditor has the relevant industry specific skills
and technical knowledge to adequately obtain evidence on the
component.
The group audit team should also gain an understanding of the
component auditor’s resource base to ensure it can cope with the work
required by the group. There should be evaluation of whether the group
engagement team will be able to be involved in the work of the
component auditor to the extent it is necessary to obtain sufficient
appropriate evidence.
In addition, the risk of material misstatement in the subsidiary being audited
by the component auditor should also be fully assess, as areas of high risk may
require input from the group audit team.