0% found this document useful (0 votes)
12 views26 pages

Chapter 4-2

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
0% found this document useful (0 votes)
12 views26 pages

Chapter 4-2

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
Chapter PHASE I - RISK ASSESSMENT: PERFORMANCE OF RISK ASSESSMENT PROCEDURES Expected Learning Outcomes After studying this chapter, you should be able to: 1. Enumerate and explain the activities involved in the performance of risk assessment procedures. . Know the process of identifying and assessing e Inherent Risk, Business and Fraud Risk ¢ Significant Risk Understand how to design, perform and document risk assessment procedures . Explain how to relate identified risks to material financial statement areas . Understand the design, implementation and documentation of relevant internal control. Explain how to conclude the risk assessment phase QU BS CHAPTER 4 PHASE I - RISK ASSESSMENT: PERFORMANCE OF RISK ASSESSMENT PROCEDURES PERFORMANCE OF RISK ASSESSMENT PROCEDURES This stage involves the identification and asses misstatements whether due to fraud or error a assertion levels, through understanding the entity the entity’s internal control, thereby providin; implementing responses to the assessed risks of m sment of the risk of Material it the financial statement ang and its environment, including iB a basis for designing anf terial misstatement, The following are the activities involv @ in the performance of risk assessment procedures: A. Identification of Inherent Risks (Business and Fraud Risks) and Significant Risks) and Significant Risks B. Understanding the Desi ign / Implementation of Relevant Internal Controls C. Concluding the Risk Assessment Phase RISK IDENTIFICATION AND ASSESSMENT. A. Identification of Inherent Risk (Business and Fraud Risks) and Significant Risks Identification of risk is the foundation of the audit. It is based upon, and forms an integral part of, the auditor’s procedures to understand the entity and its environment. Without a solid understanding of the entity, the auditor may miss certain risk factors. For examples, if a client's sales i increasing, it would be important for the auditor to know that the industry sales as a whole were actually in sharp decline. Phase | - Risk Assessment: Performance of Risk Assessment Procedures _ 81 The objective of the risk assessment phase of the audit is to identify sources of risk, and then to assess whether they could possibly result in a material misstatement in the financial statements. This provides the auditor with the information needed to direct audit effort to areas where the risk of material misstatement is the highest, and away from less risky areas. Risk assessment has two distinct parts: © Risk identification (asking “what can go wrong”); and ‘© Risk assessment (determining the significance of each risk). Risk identification answers the question what could go wrong and result in a misstatement in the financial statement. Performance of risk assessment procedures seeks to determine the significance of each risk by considering the following: a) the entity objectives, b) external factors c)_ performance measures, and d) internal control TYPES OF RISKS There are two major classification of risks: a) Business risk, and b) Fraud risk The difference between business risk and fraud risk is that fraud risk results from a person’s deliberate actions. A risk can be both a business and a fraud risk. y 82 Chapter 4 Business Risk Business. risks resivlt from significant conditions, events, Circumstance actions, ar inactions that could adversely affect the entity's ability to achieye its objectives and execute its Strategies. Business risk also includes events that arise from change, complexity, or the failure to recognize the Need fo, change. Change may arise, for instance, from: a) development of new products that may fail; b) inadequate market even if new products are successfully developedsor ¢) defects in the product that may result in liabilities and damage to the entity’s reputation. Fraud Risk Fraud risk relates to events or conditions that indicate an incentive o, Pressure to commit fraud or provide an Opportunity to commit fraud, The term “fraud” refers to an intentional act by one or more individuals among management, those charged with governance, employees, or third parties involving the use of deception to obtain an unjust or illegal advantage, Fraud involving one or more members of management or those charged with governance is referred to as “management fraud.” Fraud involving only employees of the entity is referred to as “employee fraud.” In either case, there may be collusion within the entity or with third parties outside of the entity. SOURCES OF RISKS Errors and fraud in financial statements arise from risk factors that have their origin in one or more of the six required areas of understanding the entity Sources of business and fraud risks are outlined below: a. Entity objectives and strategies. Examples are © Inappropriate, unrealistic or overly aggressive objectives and strategies New products or services ; * Entering into business areas / transactions with which the entity has little experience * Use of complex financing arrangements Phase | ~ Risk Assessment: Performance of Risk Assessment Procedures 83 b. External factors such as # state of the economy and changes in government regulations * changes in industry ¢ deliberate sabotage of an entity’s products or services © inability to obtain required resources (materials or skilled personal) ¢. Internal factors (nature of entity) © Poor corporate culture and governance © Incompetent personnel in key positions © Complexity in operations, organizational structure or products © Going concern and liquidity issue. d. Performance indicators * Failure to use performance measures that assess the entity’s performance and achievement of objectives * Failure to use measures to improve operations or take corrective actions. e. Accounting policies Inconsistent application of accounting policies © Inappropriate use of accounting policies f. Internal control ® Inadequate management oversight of day-to-day operations Poor or nonexistent controls over entity-level activities as well as transactions. Poor safeguarding of assets HOW TO IDENTIFY INHERENT RISK FACTORS [A three-step risk identification process is suggested as follows: Step 1: Gather Basic Information about the Entity The starting point is to obtain a basic understanding or frame of reference for designing the risk assessment procedures to be performed. Without this understanding, it would be difficult, if not impossible, to identify what errors and fraud could occur in the financial statements. © Obtain (or update) relevant basic information about the entity, its objectives, culture, operations, key personnel, and the internal organization and control. 84 Chapter 4 Sources of Information about Entity The first step in the risk assessment process is to gather (or Update) much relevant information about the entity as possible. This informati brovides an important frame of reference for identifying and agre® possible risk factors. "e Information about the entity and its environment can be obtained from both internal and external sources. Figure 4-1 presents the sources of information about the entity. Figure 4-1: Sources of Information about Entity 5 Internal Sources External Sources | i Financial statements . Information on the Intemet & Budgets Industry information E Reports Competitive intelligence 5 Performance measures Credit rating agencies € Tax returns Creditors = Accounting policies in use Goverment agencies ‘* Judgments and estimates Media and other extemal parties | Vision, values, objectives, and | i strategies Information on the internet | Organization structure Trade association data | 33 Job descriptions Industry forecasts | = Human Resources files Goverment agencies | = — Performance indicators Media articles | § Policy & procedure manuals } The information gained from risk assessment procedures conduct before engagement acceptance a continuance can be used as part of t audit team’s understanding of the entity. Ste misstatements Phase I - Risk Assessment: Performance of Risk Assessment Progedures 85 esign, Perform and Document Risk Assessment Procedures Risk assessment procedures / activities are required to be performed so that: = The sources of risks of material misstatement are identified, - An appropriate understanding of the entity is obtained, and - The necessary supporting audit evidence is obtained. Using the basic understanding of the entity obtained in step | above, design and performs risk assessment procedures and related activities. Hold discussions among the audit team regarding the susceptibility of the entity’s financial statements to material misstatement, caused by error or fraud. Make inquiries of management as to how they identify and manage risk factors (particularly fraud), and what risk factors have in fact been identified and managed. Also ask management if errors or fraud have actually occurred. Document all risk factors identified. Relate or Map the Risks Identified to Material Financial Statement Areas For each risk factor (risk cause) identified, identify the effect (specific such as fraud and error) that could occur in the financial statements as a result. Note that a single risk factor can result in a number of differing statement area. types of misstatements that may affect more than just one financial Identify the material account balances, class of transactions, and disclosures in the financial statements. Relate or map the risk identified to the specific financial statement areas, disclosure, and assertions affected. Is the risk identified is pervasive, then related it to the financial statements as a whole. Identifying the effect of risks by financial statement area helps in assessing risks at the assertion level, Identifying the effect of pervasive risks helps in assessing risks at the financial statement level. a “et ‘ HOW TO IDENTIFY FRAUD RISK ud ecu a any level in the organization, it tends to be, serious (and involve higher monetary amounts) when senior m tig ; ‘anagemen involved. m7 Some of the major conditions that create an environment for fraud include: * Ineffective corporate governance; * Lack of leadership by management and poor “tone at the top”; * High incentives provided for financial performance; * Taxes or other expenses that are considered very high or onerous; * Complexity in the entity's rules, regulations, and policies: * Unrealistic expectations from bankers, investors, or other stakeholders. ° Downward and unexpected shifis in profitability; ‘ * Unrealistic budget targets for staff to attain; and * Inadequate internal control, especially in the presence of organization change. The Fraud Triangle There are three conditions that often provide clues to the existence of fraud. Forensic accountants often refer to this as the “fraud triangle” because when all three conditions are present, it is highly likely that fraud may be occurring. The conditions are: © Pressure This is often generated by immediate needs (such as having significan personal debts or meeting an analyst’s or bank’s expectations for profi) that are difficult to share with others. © = Opportunity A poor corporate culture and a lack of adequate Uy seated procedures can often create confidence that a fraud could go unde! trol © = Rationalization mite Rationalization is the belief that a fraud has not really been oral” at For example, the perpetrator rationalizes that “this is not a big am only taking what I deserve.” | 2 vimokea aeceowan: E : Phase I — Risk Assessment: Performance of Risk Assessment Procedures _ 87 Sources of Fraud Risk Incentives and Pressures * Excessive pressure exists for management to meet the requirements, or expectations of third parties or those charged with governance (such as earnings targets or compliance with onerous environmental regulations, etc.). ‘Personal financial obligations may create pressure on management or employees with access to cash or other assets susceptible to theft to misappropriate those assets. Adverse relationships between the entity and employees with access to cash or other assets. For example: - Known or anticipated future employee layoffs, Recent or anticipated changes to employee compensation or benefit plans, and - Promotions, compens: expectations. ation, or other rewards inconsistent with 2. Altitudes and Rationalizations Attitudes Management has a known history of violations of laws and regulations, or allegations of fraud. Management exhibits changes in behavior or lifestyle that may indicate assets have been misappropriated. © Senior managers demonstrate a poor ethical example (such as inflating expense accounts and committing petty thefts, etc.). Management has overridden existing controls. Rationalizations Management is interested in employing inappropriate means to: ‘Minimize reported earnings for tax-motivated reasons, and Increase reported earnings to avoid violating bank covenants, increase the sale price of the entity, or meet targets set by a third party. Employee behavior indicates displeasure or dissatisfaction with the entity. Low morale exists among senior management. Management does not enforce the entity’s values or ethical standards. RR Chapter 4 3. Opportunities * Large amounts of cash on hand or proc * Inventory items that are small in size, of high value, or high demang, . ily convertible such as bearer bonds, diamonds, 4, computer chips. Inadequ * Inadequate oversight’ by those charged with governance of management's processes for identifying and responding to the risks of fraud. * Inadequate segregation of duties or checks. © Inadequate oversight of senior management expenditures, * Lack of complete and timely reconciliations of assets. HOW TO IDENTIFY SIGNIFICANT RISKS Nature and Determination of Significant risks and the Consequences for the Audit Significant risk is where the assessed risk of material misstatement is so high that in the auditor’s judgment it will required special audit consideration. Examples of significant risks are as follows: 1. High-risks activities These include operations or events where a material misstatemet! could easily occur. Examples are: a) inventory of high-value diamonds or gold bars held by a jewel store; b) identification of new complex accounting system beité introduced, Phase I~ Risk Assessment: Performance of Risk Assessment Procedures _89 2. Large non-routine transactions (size or nature, r These are significant related party transactions outside the entity's : normal course of business, Examples are: a) a major sales or supply content; i 'b) sale of the business to the third party; c) unusual value of routine transactions with a related party. 3. Matters requiring judgment or management intervention Examples are: a) assumptions used by management in developing major estimates. b) complex calculations or accounting principles. 4, Potential for fraud Examples are: a) Possible degree of collusion. b) Intentional misrepresentation being made to the auditor. c) Frequency and extent of manipulation involved Responding to Significant Risks When a risk is classified as being “significant”, the auditor should respond as outlined below: mplementation over lack 1, Evaluate internal control design and significant risk 2. Design an audit response to the identified significant risks. No reliance can be placed on evidence obtained in previous period. 4. Substantive analytical procedures alone are sufficient. a Documenting Significant Risks Documentation is required for identified’ significant risks. This simply may be an extension of the information already documented. 90 Chapter 4 a Mlustrative’ Documentation of Risk Ident Financial Statements CLIENT: XYZ COMPANY — ification and Implication, % Business Risks Risk Event / Sources Implication of the Risk Factor to FS [ Asserig~| 1. Downturn in economy a. Receivable may be difficult to ve collect b. Inventory write-down may be LN equired due to obsolescence ©. Breach of debt covenants [+S 2, New ales being soughtin @. Foreign exchange risks in re other countries receivables 3. General IT controls are weak] a, ina number of areas 4. Inventory clerk known fo make Data integrity may be compromised [> or data may even be lost a. Inventory balance may be ltr error misstated Fraud Pressures 1. Minimize tax burden a Management bias in estimates CAV (such as valuation of inventory) to reduce income. b. Unauthorized journal entries or P Manipulation of financial statements. 2. Bonus to salesman based on Inflated sales to meet thresholds E Sales above certain thresholds 3. Giving bribes to facilitate Damage to reputation, overstatement of | CAE Service oF to obtain contracts _| expenses, unaccrued fines ’ 4. Rapid growth puting pressure_| Financial statement manipulation to P on financing avoid violation of bank covenant Opportunities 1._High incidence of cash sales Goods / Cash stolen E 2. Transactions with related Sales / Purchases may not be valid, nor P patties Properly valued or disclosed in the financial statements 3.” High volume, easily Goods stolen from inventory ES transportable items of 1 inventory — Key: P= Persuasive (all assertions), C=Completeness, A= Accuracy, | E= Existence, V= Valuation Phase I Risk Assessment: Performance of Risk Assessment Procedures _91 Understanding the Design and Implementation of Relevant Internal Controls PAS 315.12 requires that the auditor shall obtain understanding of internal control relevant to the audit. Although most controls relevant to the audit are likely to relate to financial reporting, not all controls that relate to financial reporting are relevant to the audit. It is a matter of the auditor's professional judgment whether a control, individually or in combination with others is relevant to the audit. Specifically the auditor is required to obtain an understanding of the following: a. Control Environment ‘The auditor shall obtain understanding of the control environment. As part of obtaining this understanding, the auditor shall evaluate whether: (a) Management with the oversight of those charged with governance, has created and maintain a culture of honesty and ethical behavior, and (b) The strengths the control environment elements collectively provide an appropriate foundation for the other components of internal control, and whether those other components are not undermined by deficiencies in the control environment. b. Risk Assessment ‘The auditor shall obtain an understanding of whether the entity has a process for: (a) Identifying business risks relevant to financial reporting objectives; (b) Estimating the significance of the risks; (c) Assessing the likelihood of their occurrence; and (d) Deciding about actions to address those risks. c. Information System The auditor shall obtain an understanding of the information system, including the related business processes, relevant to financial reporting, including the following areas: (a) The classes of transactions in the entity’s operations that are significant to the financial statements; oz d. e Chapter 4 ‘ ae — ——__ (b) The procedures, within both information technology (IT) and manual by which those transactions are initiated, recorded, ' ry, transferred to the general ledger ncial statements; system: processed, corrected and reported in the fi (c) The related accounting records, supporting information and Specific accounts in the financial statements that are used to initiate, Fecord, proc nd_report transactions; this includes the correction of incorrect information and how information is transferred to the general ledger. The records may be cither manual or electronic form; (d) How the information system captures events and conditions, other than transactions, that are significant to the financial statements; (ec) The financial reporting process used to Prepare the entity's financial statement, including — significant accounting _ estimates and disclosures; and (f) Controls entries surrounding journal entries, including non-standard journal used to record non-recurring, unusual transactions or adjustments. The auditor shall obtain an understanding of control activities relevant to the audit, being those the auditor judges it necessary to understand in order to assess the risks of material misstatement at the assertion level and design further audit procedures responsive to assessed risks. An audit does not require an understanding of all the control activities related to each significant class of transactions, account balance, and disclosure in the financial statements or to every assertion relevant to them, In understanding the entity's control activities, the auditor shall obtain an understanding of how the entity has responded to risks arising from IT Monitoring The auditor shall obtain an understanding of the major activities Sad entity uses to monitor internal control over financial reporting. inclu Fi those related to those control activities relevant to the audit, and how 's remedial actions to deficiencies in its controls. entity i Phase 1 Risk Assessment: Performance of Risk Assessment Procedures 93 ign and Imple ution Fig Four Steps in ing Control Design and 1. Risk Identification What risks, of not mitigated by internal controls, could result in material misstatements in the financial statements? 2. Evaluate Control Design ‘Are there controls capable of effectively preventing, or detecting and correcting the material misstatements identified in step 1? Yes No 3.84, Evaluate Control Implementation and Document Operation Do the controls exist and is the entity using them? Report significant deficiencies in control to management and those charged with governance Yes Document the results and conclusions reached 94 ee Chapter 4 Illustrative Documentation of Identification and Evaluation of Relevany Internal Control Step 1: Risk Identification This is the first and most important steps in evaluating internal Control. This requires identification of the risks which need to be mitigated by internal control. The question this step seeks to find answer to is: “What risks, if not mitigated by internal control could result in matéria, misstatement in the financial statement?” The risk could be identified as a result of obtaining an understanding Of the entity with persuasive risk factors and the used transactional risk factors associated with business: procedures such as sales purchasing and payrol} Examples are: 1. Risk 1 No emphasis is placed on need for integrity and ethical values 2. Risk 2 Incompetent employees may be hired or retained. 3. Risk 3 Management has a poor attitude toward internal control and / or managing business risk. Step 2: Control Design This step involves inquiry about controls and evaluation of controls that management has put in place to address the risks that have been identified in Step | above. The question answered in this ste “Are there controls capable of effectively preventing or detecting and correcting the material misstatements identified in Step1?” ii it ible In relation to the three risks identified in Step 1, the following. poss! controls may be inquired about and evaluated. Phase I~ Risk Assessment: Performance of Risk Assessment Procedures 95 Risk 1 No emphasis is placed on need for integrity and ethical values. Possible Controls a) Management continually demonstrates through words and actions, a commitment to high ethical standards. b) Management removes or reduces incentives that might, cause personnel to engage in dishonest or ethical acts. ‘Adoption of a Code of Conduct that sets out expected standards of ethical and moral behavior. d) Employees are always disciplined for improper behavior. °) Risk 2 Incompetent employees may be hired or retained Risk 3 Possible Controls a) Management specific required knowledge and skills for employee positions. b) Job descriptions exist and are effectively ©) Management provides personnel with access to training and professional development programs on relevant topics 4) Staff are compensated and rewarded for good performance. Management has a poor attitude toward intemal control and/or managing business risks le Controls a) Management demonstrates positive attitudes and actions toward the establishment and maintenance of sound intemal control cover financial reporting. Management emphasizes appropriate behavior to operating personnel. c) Management has established procedures to prevent unauthorized access to or destruction of assets, documents and records. b) 96 Chapter 4 Step 3: Control Implementation The third step is to determine whether the controls exist and are iN Use by the entity through inquiry and testing, The question answered in the step is: “Do the controls exist and is the entity using them?” If this question is answered yes, the auditor then proceeds to Step 4, Where the auditor documents the result and conclusions reached. If the question is answered no, the auditor then reports significant deficiencies in control to management and those charged with governance The auditor then documents the results and conclusion reached, Step 4: Control Documentation If the auditor determines, through inquiry and testing, that the company has strong risk management and control processes in place, the auditor may be able to focus the audit program on testing internal controls and developing corroborative evidence based on more limited direct tests of account balances. On the other hand, if the company does not have an effective risk Management process in place, the auditor will identify areas where account balances are more likely to be misstated and concentrate direct tests of account balances in those areas. Based on the foregoing, the auditor develops expectations and makes an assessment of the risk that a particular account balance may be misstated. If the may be able to gain satisfaction regarding the account balance ites directly testing it. Other techniques, such as using substantive analyte’ procedures or analyzing the quality of the control system, may aa persuasive evidence about the correctness of an account balance. This ism meant to imply that an auditor can perform a complete audit Sed directly testing some account balances; it means that the amount 0 a can be minimized if risks are adequately addressed. However, i high risk that an account balance may misstated, the auditor shoul more attention to the audit of that account. Phase I ~ Risk Assessment: Performance of Risk Assessment Procedures _97 Mlustrative Documentation of Control Deficiencies and Impact on Audit Response Example 1 Risk factor / Assertion affected ‘Management has not considered or assessed the risks of fraud occurring. ‘Auditor, Thought Process a) Deficiency identified ‘Members of the management team trust each other and are reluctant to introduce costly policies, etc. that address the risk of fraud. 'b) Potential on the financial statements Management could override controls and materially manipulate the financial statements. ¢) Is deficiency considered significant? YES. @) Audit response Review the specific procedures performed on journal entries, related parties and revenue recognition. Example 2 Risk factor/ Assertion affected Salesiservices recorded in wrong accounting period ‘Auditor’s Thought Process No conirols existing to prevent this from a) Deficiency identified cccurring a number of cutoff errors have been found in conducting the test of details. b) Potential effect on the financial statements Revenues misstated could be materially misstated in the financial statements. ¢) Is deficiency considered significant? YES d) Audit response ‘Additional audit procedure should be performed relating to cutoff Example 3 Risk factor / Assertion affected Auditor's Thought Process a) Deficiency identified Client does not provide back-up documents to support their estimates. + b) Potential effect on the financial statements Considering the size of the estimates, an error could result in a material error in financial statement. @)Is deficiency considered significant? YES (d) Audit response Obtain evidences to support the assumption and per‘e-calculation.

You might also like