0 ratings0% found this document useful (0 votes) 12 views26 pagesChapter 4-2
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content,
claim it here.
Available Formats
Download as PDF or read online on Scribd
Chapter
PHASE I - RISK
ASSESSMENT:
PERFORMANCE OF RISK
ASSESSMENT PROCEDURES
Expected Learning Outcomes
After studying this chapter, you should be able to:
1.
Enumerate and explain the activities involved in the
performance of risk assessment procedures.
. Know the process of identifying and assessing
e Inherent Risk, Business and Fraud Risk
¢ Significant Risk
Understand how to design, perform and document risk
assessment procedures
. Explain how to relate identified risks to material financial
statement areas
. Understand the design, implementation and documentation
of relevant internal control.
Explain how to conclude the risk assessment phase
QU BSCHAPTER 4
PHASE I - RISK ASSESSMENT:
PERFORMANCE OF RISK ASSESSMENT
PROCEDURES
PERFORMANCE OF RISK ASSESSMENT PROCEDURES
This stage involves the identification and asses
misstatements whether due to fraud or error a
assertion levels, through understanding the entity
the entity’s internal control, thereby providin;
implementing responses to the assessed risks of m
sment of the risk of Material
it the financial statement ang
and its environment, including
iB a basis for designing anf
terial misstatement,
The following are the activities involv
@ in the performance of risk assessment
procedures:
A. Identification of Inherent Risks (Business and Fraud Risks) and
Significant Risks) and Significant Risks
B. Understanding the Desi
ign / Implementation of Relevant Internal
Controls
C. Concluding the Risk Assessment Phase
RISK IDENTIFICATION AND ASSESSMENT.
A. Identification of Inherent Risk (Business and Fraud Risks) and
Significant Risks
Identification of risk is the foundation of the audit. It is based upon, and
forms an integral part of, the auditor’s procedures to understand the entity
and its environment. Without a solid understanding of the entity, the auditor
may miss certain risk factors. For examples, if a client's sales i
increasing, it would be important for the auditor to know that the industry
sales as a whole were actually in sharp decline.Phase | - Risk Assessment: Performance of Risk Assessment Procedures _ 81
The objective of the risk assessment phase of the audit is to identify sources
of risk, and then to assess whether they could possibly result in a material
misstatement in the financial statements. This provides the auditor with the
information needed to direct audit effort to areas where the risk of material
misstatement is the highest, and away from less risky areas.
Risk assessment has two distinct parts:
© Risk identification (asking “what can go wrong”); and
‘© Risk assessment (determining the significance of each risk).
Risk identification answers the question what could go wrong and result in a
misstatement in the financial statement.
Performance of risk assessment procedures seeks to determine the
significance of each risk by considering the following:
a) the entity objectives,
b) external factors
c)_ performance measures, and
d) internal control
TYPES OF RISKS
There are two major classification of risks:
a) Business risk, and
b) Fraud risk
The difference between business risk and fraud risk is that fraud risk
results from a person’s deliberate actions.
A risk can be both a business and a fraud risk.y
82 Chapter 4
Business Risk
Business. risks resivlt from significant conditions, events, Circumstance
actions, ar inactions that could adversely affect the entity's ability to achieye
its objectives and execute its Strategies. Business risk also includes events
that arise from change, complexity, or the failure to recognize the Need fo,
change. Change may arise, for instance, from:
a) development of new products that may fail;
b) inadequate market even if new products are successfully developedsor
¢) defects in the product that may result in liabilities and damage to the
entity’s reputation.
Fraud Risk
Fraud risk relates to events or conditions that indicate an incentive o,
Pressure to commit fraud or provide an Opportunity to commit fraud,
The term “fraud” refers to an intentional act by one or more individuals
among management, those charged with governance, employees, or third
parties involving the use of deception to obtain an unjust or illegal advantage,
Fraud involving one or more members of management or those charged with
governance is referred to as “management fraud.” Fraud involving only
employees of the entity is referred to as “employee fraud.” In either case,
there may be collusion within the entity or with third parties outside of the
entity.
SOURCES OF RISKS
Errors and fraud in financial statements arise from risk factors that have their
origin in one or more of the six required areas of understanding the entity
Sources of business and fraud risks are outlined below:
a. Entity objectives and strategies. Examples are
© Inappropriate, unrealistic or overly aggressive objectives and
strategies
New products or services ;
* Entering into business areas / transactions with which the entity has
little experience
* Use of complex financing arrangementsPhase | ~ Risk Assessment: Performance of Risk Assessment Procedures 83
b. External factors such as
# state of the economy and changes in government regulations
* changes in industry
¢ deliberate sabotage of an entity’s products or services
© inability to obtain required resources (materials or skilled personal)
¢. Internal factors (nature of entity)
© Poor corporate culture and governance
© Incompetent personnel in key positions
© Complexity in operations, organizational structure or products
© Going concern and liquidity issue.
d. Performance indicators
* Failure to use performance measures that assess the entity’s
performance and achievement of objectives
* Failure to use measures to improve operations or take corrective
actions.
e. Accounting policies
Inconsistent application of accounting policies
© Inappropriate use of accounting policies
f. Internal control
® Inadequate management oversight of day-to-day operations
Poor or nonexistent controls over entity-level activities as well as
transactions.
Poor safeguarding of assets
HOW TO IDENTIFY INHERENT RISK FACTORS
[A three-step risk identification process is suggested as follows:
Step 1: Gather Basic Information about the Entity
The starting point is to obtain a basic understanding or frame of reference for
designing the risk assessment procedures to be performed. Without this
understanding, it would be difficult, if not impossible, to identify what errors
and fraud could occur in the financial statements.
© Obtain (or update) relevant basic information about the entity, its
objectives, culture, operations, key personnel, and the internal
organization and control.84 Chapter 4
Sources of Information about Entity
The first step in the risk assessment process is to gather (or Update)
much relevant information about the entity as possible. This informati
brovides an important frame of reference for identifying and agre®
possible risk factors. "e
Information about the entity and its environment can be obtained from
both internal and external sources.
Figure 4-1 presents the sources of information about the entity.
Figure 4-1: Sources of Information about Entity
5 Internal Sources External Sources |
i Financial statements . Information on the Intemet
& Budgets Industry information
E Reports Competitive intelligence
5 Performance measures Credit rating agencies
€ Tax returns Creditors
= Accounting policies in use Goverment agencies
‘* Judgments and estimates Media and other extemal parties |
Vision, values, objectives, and |
i strategies Information on the internet |
Organization structure Trade association data |
33 Job descriptions Industry forecasts |
= Human Resources files Goverment agencies |
= — Performance indicators Media articles |
§ Policy & procedure manuals }
The information gained from risk assessment procedures conduct
before engagement acceptance a continuance can be used as part of t
audit team’s understanding of the entity.Ste
misstatements
Phase I - Risk Assessment: Performance of Risk Assessment Progedures 85
esign, Perform and Document Risk Assessment Procedures
Risk assessment procedures / activities are required to be performed so
that:
= The sources of risks of material misstatement are identified,
- An appropriate understanding of the entity is obtained, and
- The necessary supporting audit evidence is obtained.
Using the basic understanding of the entity obtained in step | above,
design and performs risk assessment procedures and related activities.
Hold discussions among the audit team regarding the susceptibility of the
entity’s financial statements to material misstatement, caused by error or
fraud.
Make inquiries of management as to how they identify and manage risk
factors (particularly fraud), and what risk factors have in fact been
identified and managed. Also ask management if errors or fraud have
actually occurred.
Document all risk factors identified.
Relate or Map the Risks Identified to Material Financial
Statement Areas
For each risk factor (risk cause) identified, identify the effect (specific
such as fraud and error) that could occur in the financial
statements as a result. Note that a single risk factor can result in a number of
differing
statement area.
types of misstatements that may affect more than just one financial
Identify the material account balances, class of transactions, and
disclosures in the financial statements.
Relate or map the risk identified to the specific financial statement areas,
disclosure, and assertions affected. Is the risk identified is pervasive, then
related it to the financial statements as a whole. Identifying the effect of
risks by financial statement area helps in assessing risks at the assertion
level, Identifying the effect of pervasive risks helps in assessing risks at
the financial statement level.a
“et
‘
HOW TO IDENTIFY FRAUD RISK
ud
ecu a any level in the organization, it tends to be,
serious (and involve higher monetary amounts) when senior m tig
; ‘anagemen
involved. m7
Some of the major conditions that create an environment for fraud include:
* Ineffective corporate governance;
* Lack of leadership by management and poor “tone at the top”;
* High incentives provided for financial performance;
* Taxes or other expenses that are considered very high or onerous;
* Complexity in the entity's rules, regulations, and policies:
* Unrealistic expectations from bankers, investors, or other stakeholders.
° Downward and unexpected shifis in profitability; ‘
* Unrealistic budget targets for staff to attain; and
* Inadequate internal control, especially in the presence of organization
change.
The Fraud Triangle
There are three conditions that often provide clues to the existence of fraud.
Forensic accountants often refer to this as the “fraud triangle” because when
all three conditions are present, it is highly likely that fraud may be
occurring.
The conditions are:
© Pressure
This is often generated by immediate needs (such as having significan
personal debts or meeting an analyst’s or bank’s expectations for profi)
that are difficult to share with others.
© = Opportunity
A poor corporate culture and a lack of adequate Uy seated
procedures can often create confidence that a fraud could go unde!
trol
© = Rationalization mite
Rationalization is the belief that a fraud has not really been oral” at
For example, the perpetrator rationalizes that “this is not a big
am only taking what I deserve.”
|2 vimokea aeceowan:
E
:
Phase I — Risk Assessment: Performance of Risk Assessment Procedures _ 87
Sources of Fraud Risk
Incentives and Pressures
* Excessive pressure exists for management to meet the requirements,
or expectations of third parties or those charged with governance
(such as earnings targets or compliance with onerous environmental
regulations, etc.).
‘Personal financial obligations may create pressure on management or
employees with access to cash or other assets susceptible to theft to
misappropriate those assets.
Adverse relationships between the entity and employees with access
to cash or other assets. For example:
- Known or anticipated future employee layoffs,
Recent or anticipated changes to employee compensation or
benefit plans, and
- Promotions, compens:
expectations.
ation, or other rewards inconsistent with
2. Altitudes and Rationalizations
Attitudes
Management has a known history of violations of laws and
regulations, or allegations of fraud.
Management exhibits changes in behavior or lifestyle that may
indicate assets have been misappropriated.
© Senior managers demonstrate a poor ethical example (such as
inflating expense accounts and committing petty thefts, etc.).
Management has overridden existing controls.
Rationalizations
Management is interested in employing inappropriate means to:
‘Minimize reported earnings for tax-motivated reasons, and
Increase reported earnings to avoid violating bank covenants,
increase the sale price of the entity, or meet targets set by a third
party.
Employee behavior indicates displeasure or dissatisfaction with the
entity.
Low morale exists among senior management.
Management does not enforce the entity’s values or ethical
standards.RR Chapter 4
3. Opportunities
* Large amounts of cash on hand or proc
* Inventory items that are small in size, of high value, or high demang,
. ily convertible such as bearer bonds, diamonds, 4,
computer chips.
Inadequ
* Inadequate oversight’ by those charged with governance of
management's processes for identifying and responding to the risks
of fraud.
* Inadequate segregation of duties or checks.
© Inadequate oversight of senior management expenditures,
* Lack of complete and timely reconciliations of assets.
HOW TO IDENTIFY SIGNIFICANT RISKS
Nature and Determination of Significant risks and the Consequences for
the Audit
Significant risk is where the assessed risk of material misstatement is so high
that in the auditor’s judgment it will required special audit consideration.
Examples of significant risks are as follows:
1. High-risks activities
These include operations or events where a material misstatemet!
could easily occur. Examples are:
a) inventory of high-value diamonds or gold bars held by a jewel
store;
b) identification of new complex accounting system beité
introduced,Phase I~ Risk Assessment: Performance of Risk Assessment Procedures _89
2. Large non-routine transactions (size or nature,
r These are significant related party transactions outside the entity's
: normal course of business, Examples are:
a) a major sales or supply content;
i 'b) sale of the business to the third party;
c) unusual value of routine transactions with a related party.
3. Matters requiring judgment or management intervention
Examples are:
a) assumptions used by management in developing major estimates.
b) complex calculations or accounting principles.
4, Potential for fraud
Examples are:
a) Possible degree of collusion.
b) Intentional misrepresentation being made to the auditor.
c) Frequency and extent of manipulation involved
Responding to Significant Risks
When a risk is classified as being “significant”, the auditor should respond
as outlined below:
mplementation over lack
1, Evaluate internal control design and
significant risk
2. Design an audit response to the identified significant risks.
No reliance can be placed on evidence obtained in previous period.
4. Substantive analytical procedures alone are sufficient.
a Documenting Significant Risks
Documentation is required for identified’ significant risks. This simply may
be an extension of the information already documented.90 Chapter 4 a
Mlustrative’ Documentation of Risk Ident
Financial Statements
CLIENT: XYZ COMPANY —
ification and Implication,
%
Business Risks
Risk Event / Sources Implication of the Risk Factor to FS [ Asserig~|
1. Downturn in economy a. Receivable may be difficult to ve
collect
b. Inventory write-down may be LN
equired due to obsolescence
©. Breach of debt covenants [+S
2, New ales being soughtin @. Foreign exchange risks in re
other countries receivables
3. General IT controls are weak] a,
ina number of areas
4. Inventory clerk known fo make
Data integrity may be compromised [>
or data may even be lost
a. Inventory balance may be ltr
error misstated
Fraud
Pressures
1. Minimize tax burden a
Management bias in estimates
CAV
(such as valuation of inventory) to
reduce income.
b. Unauthorized journal entries or P
Manipulation of financial
statements.
2. Bonus to salesman based on Inflated sales to meet thresholds E
Sales above certain thresholds
3. Giving bribes to facilitate Damage to reputation, overstatement of | CAE
Service oF to obtain contracts _| expenses, unaccrued fines ’
4. Rapid growth puting pressure_| Financial statement manipulation to P
on financing avoid violation of bank covenant
Opportunities
1._High incidence of cash sales Goods / Cash stolen E
2. Transactions with related Sales / Purchases may not be valid, nor P
patties Properly valued or disclosed in the
financial statements
3.” High volume, easily Goods stolen from inventory ES
transportable items of 1
inventory —
Key:
P= Persuasive (all assertions), C=Completeness, A= Accuracy, |
E= Existence, V= ValuationPhase I Risk Assessment: Performance of Risk Assessment Procedures _91
Understanding the Design and Implementation of Relevant Internal
Controls
PAS 315.12 requires that the auditor shall obtain understanding of internal
control relevant to the audit. Although most controls relevant to the audit are
likely to relate to financial reporting, not all controls that relate to financial
reporting are relevant to the audit. It is a matter of the auditor's professional
judgment whether a control, individually or in combination with others is
relevant to the audit.
Specifically the auditor is required to obtain an understanding of the
following:
a. Control Environment
‘The auditor shall obtain understanding of the control environment. As
part of obtaining this understanding, the auditor shall evaluate whether:
(a) Management with the oversight of those charged with governance,
has created and maintain a culture of honesty and ethical behavior,
and
(b) The strengths the control environment elements collectively provide
an appropriate foundation for the other components of internal
control, and whether those other components are not undermined by
deficiencies in the control environment.
b. Risk Assessment
‘The auditor shall obtain an understanding of whether the entity has a
process for:
(a) Identifying business risks relevant to financial reporting objectives;
(b) Estimating the significance of the risks;
(c) Assessing the likelihood of their occurrence; and
(d) Deciding about actions to address those risks.
c. Information System
The auditor shall obtain an understanding of the information system,
including the related business processes, relevant to financial reporting,
including the following areas:
(a) The classes of transactions in the entity’s operations that are
significant to the financial statements;oz
d.
e
Chapter 4 ‘ ae
— ——__
(b) The procedures, within both information technology (IT) and manual
by which those transactions are initiated, recorded,
' ry, transferred to the general ledger
ncial statements;
system:
processed, corrected
and reported in the fi
(c) The related accounting records, supporting information and Specific
accounts in the financial statements that are used to initiate, Fecord,
proc nd_report transactions; this includes the correction of
incorrect information and how information is transferred to the
general ledger. The records may be cither manual or electronic form;
(d) How the information system captures events and conditions, other
than transactions, that are significant to the financial statements;
(ec) The financial reporting process used to Prepare the entity's financial
statement, including — significant accounting _ estimates and
disclosures; and
(f) Controls
entries
surrounding journal entries, including non-standard journal
used to record non-recurring, unusual transactions or
adjustments.
The auditor shall obtain an understanding of control activities relevant to
the audit, being those the auditor judges it necessary to understand in
order to assess the risks of material misstatement at the assertion level
and design further audit procedures responsive to assessed risks. An
audit does not require an understanding of all the control activities
related to each significant class of transactions, account balance, and
disclosure in the financial statements or to every assertion relevant to
them,
In understanding the entity's control activities, the auditor shall obtain an
understanding of how the entity has responded to risks arising from IT
Monitoring
The auditor shall obtain an understanding of the major activities Sad
entity uses to monitor internal control over financial reporting. inclu Fi
those related to those control activities relevant to the audit, and how
's remedial actions to deficiencies in its controls.
entity iPhase 1 Risk Assessment: Performance of Risk Assessment Procedures 93
ign and Imple
ution
Fig Four Steps in
ing Control Design and
1. Risk Identification
What risks, of not mitigated by internal
controls, could result in material
misstatements in the financial statements?
2. Evaluate Control Design
‘Are there controls capable of effectively
preventing, or detecting and correcting the
material misstatements identified in step 1?
Yes No
3.84, Evaluate Control Implementation
and Document Operation
Do the controls exist and is the entity using
them?
Report significant deficiencies in
control to management and
those charged with governance
Yes
Document the results and conclusions reached94
ee
Chapter 4
Illustrative Documentation of Identification and Evaluation of Relevany
Internal Control
Step 1: Risk Identification
This is the first and most important steps in evaluating internal Control. This
requires identification of the risks which need to be mitigated by internal
control. The question this step seeks to find answer to is:
“What risks, if not mitigated by internal control could result in matéria,
misstatement in the financial statement?”
The risk could be identified as a result of obtaining an understanding Of the
entity with persuasive risk factors and the used transactional risk factors
associated with business: procedures such as sales purchasing and payrol}
Examples are:
1. Risk 1 No emphasis is placed on need for integrity and ethical values
2. Risk 2 Incompetent employees may be hired or retained.
3. Risk 3 Management has a poor attitude toward internal control and / or
managing business risk.
Step 2: Control Design
This step involves inquiry about controls and evaluation of controls that
management has put in place to address the risks that have been identified in
Step | above.
The question answered in this ste
“Are there controls capable of effectively preventing or detecting and
correcting the material misstatements identified in Step1?”
ii it ible
In relation to the three risks identified in Step 1, the following. poss!
controls may be inquired about and evaluated.Phase I~ Risk Assessment: Performance of Risk Assessment Procedures 95
Risk 1 No emphasis is placed on need for integrity and ethical values.
Possible Controls
a) Management continually demonstrates through words and
actions, a commitment to high ethical standards.
b) Management removes or reduces incentives that might, cause
personnel to engage in dishonest or ethical acts.
‘Adoption of a Code of Conduct that sets out expected standards
of ethical and moral behavior.
d) Employees are always disciplined for improper behavior.
°)
Risk 2 Incompetent employees may be hired or retained
Risk 3
Possible Controls
a) Management specific required knowledge and skills for
employee positions.
b) Job descriptions exist and are effectively
©) Management provides personnel with access to training and
professional development programs on relevant topics
4) Staff are compensated and rewarded for good performance.
Management has a poor attitude toward intemal control and/or
managing business risks
le Controls
a) Management demonstrates positive attitudes and actions toward
the establishment and maintenance of sound intemal control
cover financial reporting.
Management emphasizes appropriate behavior to operating
personnel.
c) Management has established procedures to prevent
unauthorized access to or destruction of assets, documents and
records.
b)96
Chapter 4
Step 3: Control Implementation
The third step is to determine whether the controls exist and are iN Use by the
entity through inquiry and testing,
The question answered in the step is:
“Do the controls exist and is the entity using them?”
If this question is answered yes, the auditor then proceeds to Step 4, Where
the auditor documents the result and conclusions reached.
If the question is answered no, the auditor then reports significant
deficiencies in control to management and those charged with governance
The auditor then documents the results and conclusion reached,
Step 4: Control Documentation
If the auditor determines, through inquiry and testing, that the company has
strong risk management and control processes in place, the auditor may be
able to focus the audit program on testing internal controls and developing
corroborative evidence based on more limited direct tests of account
balances. On the other hand, if the company does not have an effective risk
Management process in place, the auditor will identify areas where account
balances are more likely to be misstated and concentrate direct tests of
account balances in those areas.
Based on the foregoing, the auditor develops expectations and makes an
assessment of the risk that a particular account balance may be misstated. If
the may be able to gain satisfaction regarding the account balance ites
directly testing it. Other techniques, such as using substantive analyte’
procedures or analyzing the quality of the control system, may aa
persuasive evidence about the correctness of an account balance. This ism
meant to imply that an auditor can perform a complete audit Sed
directly testing some account balances; it means that the amount 0 a
can be minimized if risks are adequately addressed. However, i
high risk that an account balance may misstated, the auditor shoul
more attention to the audit of that account.Phase I ~ Risk Assessment: Performance of Risk Assessment Procedures _97
Mlustrative Documentation of Control Deficiencies and Impact on Audit
Response
Example 1
Risk factor / Assertion affected
‘Management has not considered or assessed
the risks of fraud occurring.
‘Auditor, Thought Process
a) Deficiency identified
‘Members of the management team trust each
other and are reluctant to introduce costly
policies, etc. that address the risk of fraud.
'b) Potential on the financial statements
Management could override controls and
materially manipulate the financial
statements.
¢) Is deficiency considered significant?
YES.
@) Audit response
Review the specific procedures performed on
journal entries, related parties and revenue
recognition.
Example 2
Risk factor/ Assertion affected Salesiservices recorded in wrong accounting
period
‘Auditor’s Thought Process
No conirols existing to prevent this from
a) Deficiency identified
cccurring a number of cutoff errors have
been found in conducting the test of details.
b) Potential effect on the financial
statements
Revenues misstated could be materially
misstated in the financial statements.
¢) Is deficiency considered significant?
YES
d) Audit response
‘Additional audit procedure should be
performed relating to cutoff
Example 3
Risk factor / Assertion affected
Auditor's Thought Process
a) Deficiency identified
Client does not provide back-up documents
to support their estimates. +
b) Potential effect on the financial
statements
Considering the size of the estimates, an
error could result in a material error in
financial statement.
@)Is deficiency considered significant?
YES
(d) Audit response
Obtain evidences to support the assumption
and per‘e-calculation.