AUDITION AND ASSURANCE
Reporting is the final stage in the auditing
1. OVERVIEW TO THE AUDITING process which communicates the auditor’s
PROFESSION findings to users.
Differ in nature, but all must inform readers of the degree
AUDITING of correspondence between the information audited and
established criteria.
The accumulation and evaluation of evidence Differ in form and can vary from the highly technical
about information to determine and report on the type usually associated with financial statement audits to
a simple oral report in the case of an operational audit of
degree of correspondence between the
a small department’s effectiveness.
information (i.e. verifiable form) and established
criteria (i.e. accounting standards).
AUDIT PROCESS
Done by a competent and independent person
1. Pre-engagement Activities
ESTABLISHED 2. Planning Activities
INFORMATION 3. Evidence Gathering
CRITERIA
4. Reporting
- Verifiable form - Standards
- Quantifiable, - subjective, ACCOUNTING AUDITING
financial effectiveness of
statements systems
- Dependent upon - Recording, - Determining
what information classifying, and whether
is audited summarizing of recorded
economic events information
Evidence is any information used by the auditor to provide properly reflects
to determine whether the information being financial the economic
audited is stated in accordance with information for events that
established criteria. decision making occurred during
Auditors must obtain sufficient, in quantity, and the accounting
appropriate, in quality, audit evidence to satisfy the period
purpose of the audit. - To understand
accounting,
Forms: auditors must
- Transaction data possess expertise
- Communication with outsiders in the
accumulation and
- Observations
interpretation of
- Client testimony audit evidence.
COMPETENT INDEPENDENT
ECONOMIC DEMAND FOR AUDITING
- Qualified to - Must not be
Information risk reflects the possibility that the
understand biased in the
criteria used accumulation and information upon which a business decision was
- Know types and evaluation of made was inaccurate.
amounts of evidence Auditing of financial information reduces information
risk to the users of financial information.
evidence to - Of mind, not being
accumulate in influenced easily;
order to reach and in INFORMATION RISK
proper conclusion appearance,
after examining - Code of Ethics for
Causes:
evidence Professional
- Quality control Accountants in - Remoteness of information
(i.e. PSQC) the Philippines - Biases and motives of the provider
- Voluminous data
- Complex exchange transactions
How to reduce it? generally fall outside the scope of assurance
1. User verifies information services.
- The user may go to the business to
verify the information. This is often Independence is not required since no
costly and impractical. assurance is provided.
2. User shares information risk with Examples:
management - Accounting and bookkeeping services
- Management may be held - Tax services
responsible in a lawsuit if - Management consulting services
inaccurate information is provided.
NON-ASSURANCE
ASSURANCE SERVICES
SERVICES
3. Audited financial statements are
provided 1. Attestation 1. Bookkeeping
- External auditors are engaged to Services services
provide assurance that the financial a. Audits 2. Tax services
statements are reliable. (PSA) 3. Agreed upon
b. Reviews procedures
ASSURANCE SERVICES (PSRE) (PSRS)
4. Management
consulting
An independent professional service that services
improves the quality of information for
Other Assurance Services PSQC, Code of Ethics
decision makers. (PSAE)
Can be provided by CPAs or other
ATTESTATION SERVICES
professionals.
Assurance services by CPAs have been common A type of service in which the CPA issues a
for years, especially regarding historical financial report about a subject matter or assertion that
statement information. is made by another party.
OTHER ASSURANCE SERVICES One category of assurance services provided
by CPAs
Do not meet the definition of attestation services.
A written report is not required, and it need not be about Primary categories of attestation services include:
reliability or compliance. - Audits of historical financial statements
- Audits of internal control over financial
Examples: reporting
1. Mystery shopping - Reviews of historical financial statements
- Perform anonymous shopping to - Other attestation that may be applied to a
assess sales personnel dealings broad range of subjects
with customers and procedures
they follow TYPES OF AUDIT
2. ISO 9000 certifications
- Certify a company’s compliance
with ISO 9000 quality control 1. Operational audit
standards, which help ensure - Evaluates the efficiency and
company products are of high effectiveness of any part of an
quality organization’s operating procedures and
methods.
NON-ASSURANCE SERVICES
2. Compliance audit
- Determines whether the auditee is
CPA firms perform numerous other services that
following specific procedures, rules, or
regulations set by some higher CODE OF PROFESSIONAL CONDUCT
authority.
3. Financial statement audit Consists of principles and rules, in addition to
- Determines whether the financial interpretations.
statements are stated in accordance
Five fundamental principles:
with PFRS.
1. Integrity
- Straightforward and honest in all
TYPES OF AUDITORS
professional and business
relationships
1. CPA firms
2. Government auditors 2. Objectivity
3. Internal auditors - Should not allow bias, conflict of
interest or undue influence of
others
ACTIVITIES OF CPA FIRMS
3. Professional Competence and Due
Care
CPA firms provide audit services as well as other - Maintain professional knowledge
attestation and assurance services. and skill at the level required
CPA firms also provide accounting and 4. Confidentiality
bookkeeping services, tax services, and - Should not disclose any such
management consulting and risk advisory information to third parties without
services. proper and specific authority
CPA firms vary in nature and range of services, 5. Professional Behavior
which affects the structure of the firms. - Should comply with the relevant
laws and regulations and should
QUALITY CONTROL avoid any action that discredits
the profession
Includes the methods used to ensure that the firm
meets its professional responsibilities to clients. Threats to compliance:
1. Self-interest threats
Each firm should document quality control policies - May occur as a result of the
and procedures. financial or other interests of a
professional accountant or of an
ETHICS immediate or close family member
2. Self-review threats
A set of moral principles or values - May occur when a previous
judgment needs to be re-
Necessary for a society to function in an orderly evaluated by the professional
manner. accountant responsible for that
judgment
The need for ethics in society is sufficiently
important that many commonly held values are 3. Advocacy threats
incorporated into laws. - May occur when a professional
accountant promotes a position
There are two primary reasons why people act or opinion to the point that
unethically: subsequent objectivity may be
- The person’s ethical standards differ from compromised
general society’s
- The person chooses to act selfishly 4. Familiarity threats
- Which may occur when, because of responsibility for the financial statements.
a close relationship, a professional 3. CEO and CFO must certify quarterly and
accountant becomes too annual financial statements submitted to
sympathetic to the interests of the SEC.
others
AUDITOR’S RESPONSIBILITIES
5. Intimidation threats
- May occur when a professional In conducting an audit of financial statements:
accountant may be deterred from 1. Obtain reasonable assurance about
acting objectively by threats, whether the financial statements as a
actual or perceived whole are free from material
misstatement, whether due to fraud or
Safeguards that may eliminate or reduce such
error, thereby enabling the auditor to
threats to an acceptable level fall into two broad
express an opinion on whether the
categories:
financial statements are presented fairly, in
- Safeguards created by the profession,
all material respects, in accordance with an
legislation or regulation
applicable financial reporting framework.
- Safeguards in the work environment
2. Report on the financial statements, and
2. AUDIT RESPONSIBILITIES AND OVERVIEW communicate as required by auditing
standards, in accordance with the auditor’s
OBJECTIVE TO CONDUCTING AN AUDIT OF findings.
FINANCIAL STATEMENTS
ERROR FRAUD
To provide financial statements users with an
opinion by the auditor whether the financial Unintentional There is a distinction
statements are presented fairly, in all material misstatement of the between
respects, and in accordance with the financial statements, misappropriation of
applicable financial accounting framework. whereas fraud is assets, usually
intentional. committed by employees,
An auditor’s opinion enhances the degree of and fraudulent financial
confidence that intended users can place in the reporting, usually
committed by
financial statements.
management.
The primary focus is on issuing an opinion on the Commented [1]: 1 total reaction
financial statements. Alisha Leigh Mandin reacted with 🤏 at 2023-05-05
AUDITOR’S RESPONSIBILITIES FOR
05:39 AM
STEPS TO DEVELOP AUDIT OBJECTIVES DETECTING MATERIAL ERRORS
Commented [2R1]: _Marked as resolved_
Auditors spend a great portion of their time Commented [3R1]: _Re-opened_
1. Understand objectives and responsibilities planning and performing audits to detect
for the audit. unintentional errors made by management and
2. Divide financial statements into cycles. employees.
3. Know management assertions about
financial statements. AUDITOR’S RESPONSIBILITIES FOR
4. Know general audit objectives for classes DETECTING MATERIAL FRAUD
of transactions, accounts, and disclosures.
5. Know specific audit objectives for classes Auditing standards make no distinction between
of transactions, accounts, and disclosures. the auditor’s responsibilities for detecting errors
versus fraud.
MANAGEMENT’S RESPONSIBILITIES However, the standards do recognize that fraud is more
difficult to detect because those who are committing the
Many public companies include a statement fraud attempt to conceal the fraud.
regarding management responsibility in relation to
the CPA firm. FRAUDULENT MISAPPROPRIATION
FINANCIAL REPORTING OF ASSETS
1. Financial statements and internal controls.
2. Sarbanes-Oxley increases management’s Present users with Harmful to creditors,
incorrect financial stockholders, and others
information that is used because the assets have 2. Suspension of judgment
for decision making. been taken from their - Withholding judgment until
rightful owners, the appropriate evidence is obtained.
company.
AUDITOR’S RESPONSIBILITIES FOR 3. Search for knowledge
DISCOVERING ILLEGAL ACTS - A desire to investigate beyond the
obvious, with a desire to
corroborate.
4. Interpersonal understanding
- Recognition that people’s
motivations and perceptions can
lead them to provide biased or
misleading information.
5. Autonomy
- The self-direction, moral
independence, and conviction to
decide for oneself, rather than
AUDIT PROCEDURES WHEN accepting the claims of others.
NONCOMPLIANCE IS IDENTIFIED OR
SUSPECTED 6. Self-esteem
- The self-confidence to resist
Obtain an understanding of the situation and persuasion and to challenge
discuss the matter with management at a level assumptions or conclusions.
above those involved.
PROFESSIONAL JUDGEMENT
Obtain sufficient evidence regarding material A part of professional skepticism
amounts that are directly affected by laws and
regulations. Elements of Judgement Process:
1. Identify and define the issue.
Laws such as those relating to taxes and pensions 2. Gather the facts and information and
usually have a direct effect on the amounts or identify the relevant literature.
disclosures in the financial statements, and 3. Perform the analysis and identify potential
therefore require the auditor’s attention. alternatives.
4. Make the decision.
REPORTING IDENTIFIED OR SUSPECTED 5. Review and complete the documentation
NONCOMPLIANCE and rationale for the conclusion.
Unless the matter is inconsequential, the auditor STRATEGY TO AVOID
should communicate with those charged with JUDGEMENT
OR MITIGATE
governance of matters of noncompliance. TENDENCY
TENDENCY
PROFESSIONAL SKEPTICISM Confirmation: Make opposing case and
- Put more weight consider alternative
on information that explanations and
Aspects: is consistent with potentially disconfirming
- Questioning mindset initial beliefs or or conflicting information
- Critical assessment of audit evidence preferences.
Overconfidence: Challenge opinions,
Elements: - Overestimate experts, and underlying
one’s own abilities assumptions
1. Questioning mindset
to perform tasks or
- “Trust but verify”—a disposition to to make accurate
inquiry with some sense of doubt.
assessment of
risks or other
judgments and
decisions.
Anchoring: Solicit input and consider
- Make management bias,
assessments by including potential fraud
starting from an or material
initial value and misstatements
then adjusting
insufficiently away SETTING AUDIT OBJECTIVES
from that initial
value
Most efficient way to conduct audits: Obtain
Availability: Consider why something some combination of assurance for each class of
- Consider comes to mind by transactions and for the ending balances in the
information that is obtaining and consider related accounts.
easily retrievable objective data, and Audit objectives for each class of transactions include:
or what is easily consult with others and - Transaction-related objectives
accessible as make the opposing case - Balance-related objectives
being more likely - Presentation and disclosure-related objectives
or more relevant
MANAGEMENT ASSERTIONS
FINANCIAL STATEMENT CYCLES
Implied or expressed representations by
A common form of segmenting is called the management about classes of transactions and
cycle approach, which divides classes of the related accounts and disclosures in the
transactions and account balances that are financial statements.
closely related into segments.
Directly related to the financial reporting
Cycles: framework (U.S. GAAP or IFRS) that forms the
- Sales and collection cycle criteria that management uses to record and
- Acquisition and payment cycle disclose accounting information in financial
- Payroll and personnel cycle statements.
- Inventory and warehousing cycle
- Capital acquisition and repayment cycle Lead to audit objectives therefore, auditors must
have a thorough understanding of management
Transaction flow from journals to financial assertions to perform quality audits.
statements:
Public Company Accounting Oversight Board
(PCAOB) standards describe five categories of
management assertions:
1. Existence or occurrence
- Exist at a given date and recorded
as transactions occurred during
that period.
2. Completeness
- All transactions are presented in
the financial statements.
Relationships among transaction cycles: 3. Valuation or allocation
- Accounts are expressed at
appropriate amounts.
4. Rights and obligations b. Completeness
- The company controls rights and - Existing amounts are
settles obligations at a given date. included.
5. Presentation and disclosure c. Accuracy
- Properly classified, described, and - Amounts included are
disclosed. stated at the correct
amounts.
Association of International Certified Professional
Accountants (AICPA) and International Auditing d. Classification
and Assurance Standards Board (IAASB) - Amounts included in the
standards describe three categories of assertions: client’s listing are properly
1. Classes of transactions and events classified.
a. Occurrence
- Recorded transactions e. Timing/Cut-off
exist. - Transactions near the
balance sheet date are
b. Completeness recorded in the proper
- Existing transactions are period.
recorded.
f. Detail Tie-In
c. Accuracy - Details in the account
- Recorded transactions are balance agree with related
stated at the correct master file amounts, foot to
amounts. the total in the account
balance, and agree with the
d. Posting and Summarization total.
- Recorded transactions are
properly included in the g. Realizable Value
master files and are - Assets are included at the
correctly summarized. amounts estimated to be
realized.
e. Classification
- Transactions included in h. Rights and Obligations
the client’s journals are - Assets are owned or
properly classified. controlled by the entity, and
liabilities are obligations of
f. Timing/Cut-off the entity.
- Transactions are recorded
on the correct dates. 3. Presentation and disclosure
a. Occurrence, rights and
Specific Transaction-Related Audit Objectives obligations
- The specific transaction-related objectives are
tailored to the specific class of transactions being
- Disclosures have occurred
audited. and pertain to the entity.
Relationship Among Management Assertions and b. Completeness
Transaction-Related Audit Objectives
- Disclosures are included in
- For each management assertion, there are general
transaction-related audit objectives as well as the financial statements.
specific transaction-related audit objectives.
c. Accuracy and valuation
2. Account balances - Disclosures are done
a. Existence appropriately and at
- Amounts included exist. appropriate amounts.
Phase IV: Complete the Audit, and Issue and Audit
d. Classification and Report
understandability - After all procedures have been completed,
- Disclosures are the auditor will reach an overall
appropriately presented, conclusion as to whether the financial
described, and clearly statements are fairly presented.
expressed.
- After the conclusion, the auditor must
4 PHASES OF FINANCIAL STATEMENT AUDIT issue an audit report that will
How are audit objectives met? accompany the client’s financial
statements.
Phase I: Plan, Design, and Audit Approach
Main objective: Accumulate enough evidence to
3. AUDIT EVIDENCE
provide an opinion on the financial statements.
Two overriding considerations affect how an AUDIT EVIDENCE DECISIONS
auditor approaches the audit:
1. Sufficient appropriate evidence must be
accumulated to meet the auditor’s The auditor must make four major decisions
professional responsibility. regarding what evidence to gather and how much
2. The cost of accumulating the evidence to accumulate:
should be minimized. 1. Which audit procedures to use?
2. What sample size to select for a given
The audit plan should result in an effective audit at a procedure?
reasonable cost. 3. Which items to select from the
population?
Risk assessment procedures include the
4. When to perform the procedures?
following:
- Obtain an understanding of the entity and An audit program includes all of the above information for
its environment. a given audit.
- Understand internal control and assess
control risk. PERSUASIVENESS OF EVIDENCE
- Assess risk of material misstatement.
Phase II: Perform Tests of Controls and Audit standards require that the auditor
Substantive Tests of Transactions accumulate sufficient appropriate evidence to
- Tests of controls allow the auditor to support the opinion issued.
evaluate the effectiveness of internal
controls and determine whether the
controls can be relied upon to reduce The two determinants of the persuasiveness of
planned control risks. evidence are appropriateness and sufficiency.
- Substantive tests of transactions allow the APPROPRIATENESS
auditor to evaluate the client’s recording
of transactions. Relevance means that the evidence must pertain
to or be relevant to the audit objective that is
Phase III: Perform Substantive Analytical being tested.
Procedures and Tests of Details of Balances
- Analytical procedures consist of
evaluations of plausible relationships Reliability refers to the degree to which
among financial and nonfinancial data. evidence is believable or worthy of trust; and
depends on the following characteristics:
- Tests of details of balances are specific 1. Independence of provider
procedures intended to test for 2. Effectiveness of client’s internal controls
monetary misstatements in the financial 3. Auditor’s direct knowledge
statements. 4. Qualifications of individuals providing the
information recorded transactions
5. Degree of objectivity (occurrence) is called vouching.
6. Timeliness - Testing from source documents
to recorded amounts
(completeness) is called tracing.
SUFFICIENCY
6. Confirmation
Refers to the quantity of evidence obtained. - The receipt of a direct written response
from a third party verifying the accuracy
The sample size that is considered sufficient is
of information that was requested by the
affected by two factors:
auditor.
- Auditor’s expectation of misstatements
- Effectiveness of the client’s internal 7. Analytical Procedures
controls - The evaluation of financial information
through analysis of plausible
relationships among financial and
Combined Effect
nonfinancial data and are required during
- The persuasiveness of the evidence can be evaluated
only after considering the combination of
planning and completion phases of all
appropriateness and sufficiency. audits.
- Purposes of analytical procedures:
1. Understand the Client’s Industry
TYPES OF AUDIT EVIDENCE and Business
- Used in planning to gain
knowledge about the client.
1. Reperformance
- The auditor’s test of client accounting 2. Assess the Entity’s Ability to
procedures or controls. Continue as a Going Concern
- Many ratios can be an
2. Inquiry indicator of potential
- Obtaining written or oral information financial problems.
from the client in response to auditor
questions. 3. Indicate the Presence of
- Usually not considered conclusive Possible Misstatements in the
unless it is corroborated. Financial Statements
- The presence of unusual
3. Observation fluctuations noted in
- Watching a process or procedure being comparing current and prior
performed by others. years could signal
misstatements.
4. Recalculation 4. Provide Evidence Supporting an
- Rechecking a sample of calculations Account Balance
made by the client. - If reliable relationships
exist, substantive analytical
procedures can be used to
5. Inspection
support account balances.
- The auditor’s examination of the client’s
documents and records to substantiate Cost of Types of Evidence:
the information in the financial statements. 1. Most expensive
- Documents can be internal, prepared by - Confirmation
the client’s organization, or external,
prepared or handled by someone outside 2. Moderately costly
the organization who is a party to the - Reperformance
transaction. - Inspection
- Using documents to support - Analytical procedures
The record of the audit procedures performed,
3. Least expensive relevant audit evidence, and conclusions the
- Recalculation auditor reached.
- Inquiries of the client
- Observation
Purposes:
ANALYTICAL PROCEDURES - Basis for planning the audit
- Record of the evidence accumulated and
the results of the tests
Purposes during audit engagement: - Data for determining the proper type of
1. Required in the planning phase as part of audit report
risk assessment to understand the - Basis for review by supervisors and
client’s business and industry. partners
2. Often done during the testing phase of the
audit as substantive tests in support of Ownership of the Audit Files: All audit files are the
property of the auditor.
an account balance.
3. Required during the completion phase of CONFIDENTIALITY OF AUDIT FILES
the audit, serving as a final review for
material misstatements. The AICPA Code of Professional Conduct
states that a member in public practice shall not
TYPES OF AUDIT PROCEDURES disclose any confidential client information
without the specific consent of the client.
Auditors compare client data with:
1. Industry data Requirements for Retention of Audit
2. Similar prior-period data Documentation:
3. Client-determined expected results 1. Auditing standards require records of
4. Auditor-determined expected results private companies be retained for a
minimum of five years.
COMMON FINANCIAL RATIOS 2. Sarbanes-Oxley Act requires auditors of
public companies to maintain audit files for
Short-Term Debt- Liquidity Activity a minimum of seven years.
Paying Ability Ratios
PERMANENT FILES CURRENT FILES
- Cash ratio - Accounts
- Quick ratio receivable Contain data of a Includes all
- Current ratio turnover historical or continuing documentation for the
- Days to collect nature. current year audit.
receivables
- Inventory These provide a Includes:
turnover convenient source of - Audit Program
- Days to sell information that is used - Working Trial
inventory from year to year: Balance
- Copies of - Adjusting Entries
company - Supporting
Ability to Meet Long- Profitability Ratios
documents such Schedules:
Term Debt - Earnings per as articles of - Analysis
Obligations share incorporation, - Trial balance or
- Debt to equity - Gross profit bylaws, bond list
- Times interest percentage - Reconciliation
indentures, and
of amounts
earned - Profit margin long-term - Substantive
- Return on assets contracts analytical
- Return on - Analyses of procedures
common equity accounts from - Summary of
previous years procedures
that have - Examination of
AUDIT DOCUMENTATION supporting
continuing
importance documentation
- Information related - Informational b. Client business risk
to understanding - Outside - The risk that the entity fails to
internal controls documentation
achieve its objectives or execute
and assessing its strategies.
control risk
- Results of
analytical c. Risk of material misstatement
procedures from - The risk that the financial
prior years’ audits statements contain a material
for comparison misstatement due to fraud or
error prior to the audit.
PREPARATION OF AUDIT DOCUMENTATION
STEPS IN AUDIT PLANNING
Should be in sufficient detail to provide a clear 1. Accept client and perform initial audit planning
understanding of the work performed, 2. Understand the client’s business and industry
evidence obtained, and conclusions reached. 3. Perform preliminary analytical procedures
4. Set preliminary judgement of materiality and
Characteristics: performance materiality
- Identified with the client’s name, period 5. Identify significant risks due to fraud or error
covered, description of the contents, 6. Assess inherent risk
initials of the preparer, date of preparation, 7. Understand internal control and assess
and an index code. control risk
- Files should be indexed and cross- 8. Finalize overall audit strategy and audit plan
referenced to aid in organization.
- Documentation should clearly indicate the INITIAL AUDIT PLANNING
audit work performed through memos,
initialing the procedures in the audit The auditor decides whether to accept a new
program, or tick marks on the schedules. client or continue serving an existing client.
- Include sufficient information to fulfill the
audit objectives. The auditor identifies why the client wants or
- Conclusions reached about the segment of needs an audit.
the audit should be clearly stated.
To avoid misunderstandings, the auditor obtains
an understanding with the client about the
4. AUDIT PLANNING AND MATERIALITY terms of the engagement.
PLANNING
The auditor develops the overall strategy for the
Why should the auditor properly plan the audit audit, including engagement staffing and any
engagement? required audit specialists.
1. Enable the auditor to obtain sufficient
appropriate evidence for the CLIENT ACCEPTANCE AND CONTINUANCE
circumstances.
New Client Investigation
2. Help keep audit costs reasonable.
- CPA firms must take care in accepting new
3. Avoid misunderstandings with the client.
clients.
Risk terms relevant to audit planning - The new (successor) auditor is required
a. Acceptable audit risk by auditing standards to communicate
- A measure of how willing the with the predecessor auditor.
- Due to confidentiality requirements, the
auditor is to accept that the client must consent to this
financial statements may be communication.
materially misstated after the - The purpose is to determine if the client
audit is completed and an lacks integrity or if there were disputes
about accounting principles.
unmodified opinion has been
issued.
Continuing Clients
- CPA firms evaluate existing clients to
determine whether a continuing client
presents risks due to lack of integrity.
Identify Client’s Reasons for Audit
- Risk factors associated with the client’s
reasons for an audit include the likely
statement users and the intended uses
of the statements.
Obtain an Understanding with the Client
- A clear understanding of the terms of the
engagement should exist between the
auditor and the client. Industry and External Environment
- Auditing standards require that there be an - There are three primary reasons for
engagement letter which includes the obtaining a good understanding of the
engagement’s objectives. client’s industry and external environment:
1. Risks associated with specific
Develop Overall Audit Strategy
industries may affect the auditor’s
- After understanding the client’s reason for
assessment of client business
an audit, the auditor should develop and
risk.
document a preliminary audit strategy.
2. Many risks are common to all
Select Staff for Engagement and Evaluate clients in certain industries.
Need for Outside Specialists 3. Many industries have unique
- Auditors are responsible for having accounting requirements that the
appropriate competence and auditor must understand to
capabilities to perform the audit evaluate whether the financial
- The CPA firm must select staff for the statements are in accordance with
engagement who are knowledgeable accounting standards.
about the client’s business.
Business Operations and Processes
- If the CPA firm lacks expertise, they may
- The auditor should understand factors
need to hire outside specialists.
such as major sources of revenue, key
customers and suppliers, sources of
UNDERSTAND THE CLIENT’S BUSINESS AND
financing, and information about related
INDUSTRY
parties that may increase client
Auditing standards require the auditor to perform business risk.
risk assessment procedures to obtain an
Tour Client Facilities and Operations
understanding of the client’s business and its
- Touring facilities is helpful in obtaining
environment to assess risk of material
an understanding of the client’s
misstatements.
operations.
The auditor identifies and assesses risks of
Identify Related Parties
material misstatement, whether due to fraud or
- Related party transactions may not be at
error, based on an understanding of the entity and
arm’s length, auditing standards require
its environment, including the entity’s internal
that related parties and related party
control.
transactions be disclosed in the financial
statements.
Management and Governance
- The auditor needs to assess
management’s philosophy and
operating style and its ability to identify
and respond to risk. MATERIALITY
- Governance includes the organizational
structure as well as operations of the The fourth step in audit planning is to make a
board of directors and the audit committee. preliminary judgment about materiality for the
audit.
Code of Ethics
- Public companies must disclose whether The magnitude of misstatements that
they have adopted a code of ethics that individually, or when aggregated with other
applies to senior management. misstatements, could reasonably be expected to
- Auditors should have an understanding of influence the economic decision of users.
the code of conduct and investigate any
changes. Steps in applying materiality
1. Set materiality for the financial statements
Minutes of Meetings as a whole
- Corporate minutes are the official record 2. Determine performance materiality
of the meetings of the board of directors. 3. Estimate total misstatement in segment
- They include key authorizations and 4. Estimate the combined misstatement
summaries of important topics 5. Compared combined estimate with
discussed. preliminary or revised judgement about
- The auditor should read the minutes to materiality
identify matters relevant to the audit.
Factors affecting preliminary materiality judgment:
Client Objectives and Strategies 1. Materiality is a relative rather than an
- The auditor should understand the client absolute concept
objectives related to: 2. Benchmarks
1. Reliability of financial reporting 3. Qualitative factors
2. Effectiveness and efficiency of
operations PERFORMANCE MATERIALITY
3. Compliance with laws and
regulations The allocation of the preliminary judgment
about materiality to segments.
- Business risks can arise that threaten
management’s objectives. PCAOB standards refer to performance materiality
- Knowledge of management’s objectives as tolerable misstatement.
and strategies help the auditor to assess
client business risk and the risk of Major difficulties when allocating materiality to
misstatements. balance sheet accounts:
1. Auditors expect certain accounts to
Measurement and Performance have more misstatements than others.
- A client’s performance measurement 2. Both overstatements and
system includes key performance understatements must be considered.
indicators (KPIs) that management uses 3. Relative audit costs affect the allocation.
to evaluate progress toward its
objectives. ESTIMATE MISSTATEMENT AND COMPARE
Examples: WITH PRELIMINARY JUDGMENT
Market share, sales per employee, unit sales
growth, website visitors, same-store sales, Auditors document all misstatements found for
sales/square foot
each audit segment.
These may be known misstatements or likely
- If the client has set unreasonable misstatements.
objectives, especially when employees are
incentivized to meet performance goals, Known misstatements are those that the auditor
there may be an incentive for can determine the amount of misstatement in
aggressive accounting, which increases the account.
the risk of financial statement
misstatement.
Types of likely misstatements Risk assessment procedures include assessing
1. Differences between management and the the risk of material misstatement due to fraud or
auditor’s judgment about estimates of error.
account balances
2. Projections of misstatements based on the The auditor’s consideration of fraud risk is made at
auditor’s tests of a sample both the
- Financial statement level
- Assertion level for classes of
5. RISK ASSESSMENT transactions, account balances, and
presentation and disclosures.
RISK IN AUDITING
Because several high-profile cases of financial
Auditors accept some level of risk or uncertainty in
statement fraud involve misstatements in revenue
performing audits.
recognition, auditing standards require the
RISK OF MATERIAL MISSTATEMENT AT THE auditor to presume that risks of fraud exist in
OVERALL FINANCIAL STATEMENT LEVEL revenue recognition.
The risks that relate pervasively to the financial IDENTIFICATION OF SIGNIFICANT RISKS
statements as a whole and potentially affect a
number of different transactions and accounts. A significant risk is any risk that the auditor deems
to require special attention.
RISK OF MATERIAL MISSTATEMENT AT THE ● Nonroutine transactions, including
ASSERTION LEVEL related-party transactions, often represent
significant risk.
1. Inherent risk ● Account balances or transactions that
- Susceptibility of an assertion to material require estimates for which significant
misstatement measurement uncertainty exists also may
require more attention.
2. Control risk Auditor must determine whether any of the risks identified
- Risk that internal controls will not prevent are a significant risk.
or detect material misstatement.
All fraud risks are normally considered to be
significant risks.
RISK ASSESSMENT PROCEDURES
Part of audit planning process AUDIT RISK MODEL
The risk of material misstatement at the assertion
Provides input for understanding entity and its level consists of two components: inherent risk
environment, including internal controls and control risk.
Help auditor identify and assess the risk of Auditors consider these risks by applying the audit
material misstatement risk model:
Used to develop audit strategy and audit plan in
response to assessed risks
1. Inquiries of management and others within
the entity
2. Analytical procedures
3. Observation and inspection
4. Discussion among engagement team
members
5. Other risk assessment procedures
CONSIDERING FRAUD RISK
though the report was correct.
- Closely related to client business risk
because the risk that the auditor will be
sued is often related to business failure
after the audit is finished.
FACTORS AFFECTING ACCEPTABLE AUDIT
RISK
Assessing acceptable risk depends on the factors
listed—many of these items are also used in
gaining an understanding of the client, its
business, and the industry in which it operates.
The audit risk model uses all four types of risk
1. The degree to which external users rely on
to determine the risk involved in an audit.
the statements based on these factors:
1. Planned Detection Risk - Client size
- The risk that the audit evidence for an audit - Distribution of ownership
objective will fail to detect misstatements - Nature and amount of liabilities
exceeding performance materiality.
2. The likelihood that a client will have financial
- Dependent on the other three factors in the
difficulties after the audit based on these
model and will change only if the auditor
factors:
changes one of the other factors.
- Liquidity position
2. Inherent Risk - Profits (losses) in previous years
- The auditor’s assessment of the - Method of financing growth
susceptibility of an assertion to - Nature of the client’s operations
material misstatement. - Competence of management
3. Control Risk 3. The auditor’s evaluation of management’s
- The auditor’s assessment of the risk that a integrity
material misstatement could occur in
an assertion and not be prevented or ASSESSING INHERENT RISK
detected by the client’s internal controls.
Inherent risk
4. Acceptable Audit Risk - The amount of risk involved with an
- How willing the auditor is to accept that the account balance or class of
financial statements may be materially transactions that comes from the type of
misstated after the audit is complete and account or transaction that it is.
an unmodified opinion has been issued.
Assessing inherent risk is an attempt by the
auditor to predict where misstatements are
ASSESSING ACCEPTABLE AUDIT RISK
most and least likely in the financial statement
Acceptable audit risk must be determined in order segments.
for the auditor to properly plan the audit.
Affects the amount of audit evidence that the
Auditors must decide appropriate acceptable audit auditor needs to accumulate.
risk.
The auditor must assess the factors that make
Auditors must first decide engagement risk and up the risk and modify procedures for audit
use it to modify acceptable audit risk. evidence to take them into consideration.
This consideration takes place during the planning phase
and is updated throughout the audit process.
Engagement risk
- The risk that the auditor (or firm) will suffer FACTORS TO CONSIDER WHEN ASSESSING
harm after the audit is finished, even INHERENT RISK
1. Nature of the client’s business
6. AUDIT REPORTS
2. Results of previous audits
3. Initial versus repeat engagement AUDIT REPORTS
4. Related parties
5. Complex or nonroutine transactions
6. Judgment required to correctly record Details what the auditor did and how it was
account balances and transactions done in order to form an opinion on the financial
7. Makeup of the population statements.
8. Factors related to fraudulent financial
reporting Auditors’ responsibility versus management
9. Factors related to misappropriation of responsibility is clearly stated.
assets
PARTS OF STANDARD UNMODIFIED OPINION
AUDIT REPORT
RELATIONSHIP OF RISKS TO EVIDENCE AND
FACTORS INFLUENCING RISKS 1. Report title
2. Audit report address
In addition to modifying audit evidence, the auditor 3. Introductory paragraph
can also make the following changes to respond 4. Management’s responsibility
to risks: 5. Auditor’s responsibility
- The engagement may require more 6. Opinion paragraph
experienced staff. 7. Signature and address of CPA firm
- The engagement will be reviewed more 8. Audit report date
carefully than usual.
Audit Risk for Segments CONDITIONS FOR STANDARD UNMODIFIED
- The risk of material misstatement, control OPINION AUDIT REPORT
risk, and inherent risk are assessed for
1. Includes all financial statements
each audit objective in each segment of
2. Sufficient appropriate evidence
the audit.
accumulated
Relating Performance Materiality and Risks to 3. Financial statements are presented fairly
Balance-Related Audit Objectives in accordance with GAAP or other
- Although it is common to assess inherent framework
and control risks for each balance-related 4. No circumstances requiring the addition
audit objective, it is not common to allocate of an emphasis-of-matter paragraph or
materiality to those objectives. modification
STANDARD AUDIT REPORT AND REPORT ON
Measurement Limitations
INTERNAL CONTROL OVER FINANCIAL REPORTING
- One major limitation in the application of UNDER PCAOB AUDITING STANDARDS
the audit risk model is the difficulty of
measuring the components of the Two significant audit reporting differences for
model. public companies.
- It is a highly subjective process, so most 1. The standard unmodified opinion audit
auditors use broad categories such as report is different.
low, medium, and high. 2. Auditors of larger public companies must
also issue an opinion on internal control
RELATIONSHIP OF RISK AND MATERIALITY over financial reporting.
TO AUDIT EVIDENCE
The PCAOB requires that the audit of internal
The concepts of materiality and risk in auditing are control over financial reporting be a part of the
closely related and inseparable. overall financial audit.
The report on internal controls may be combined with the
Risk Materiality audit opinion report, or it may be a separate report.
- Measure of - Measure of
uncertainty. magnitude.
Section 404(b) of the Sarbanes-Oxley Act or continues to have a significant
requires the auditor of a public company to report effect on the entity’s financial
on the effectiveness of internal control over position
financial reporting. - Reports involving other auditors
PCAOB Auditing Standard 5 requires the audit EMPHASIS OF A MATTER
of internal control to be integrated with the audit of
financial statements.
Under certain circumstances, the CPA may want
The auditor may issue separate reports, such as to emphasize specific matters regarding the
the separate report on internal control over financial statements, even though the CPA
financial reporting or a combined report. intends to express an unqualified opinion.
Separate reporting is more common. - Financial Statement Comparability
- Subsequent Events
UNMODIFIED OPINION AUDIT REPORT WITH - Major catastrophe
EMPHASIS-OF-MATTER EXPLANATORY PARAGRAPH
- Related Party Transactions
OR NONSTANDARD REPORT WORDING
- Material Uncertainties
The unmodified opinion audit report with
emphasis-of-matter paragraph or nonstandard MODIFICATIONS TO THE OPINION IN THE
report wording AUDIT REPORT
Meets the criteria of a complete audit with Three conditions requiring a modification to the
financial statements that are fairly presented. audit opinion:
1. The scope of the audit has been
But, the auditor wants to draw attention to certain restricted (scope limitation).
matters or is required to provide additional 2. The financial statements have not been
information. prepared in accordance with generally
accepted accounting principles (GAAP
The most important causes of the addition of departure).
an emphasis-of-matter paragraph or a 3. The auditor is not independent.
modification of wording under both AICPA and
PCAOB audit standards: Three types of reports may be appropriate:
- Lack of consistent application of 1. Qualified opinion
generally accepted accounting principles - Can be used for a scope
- Substantial doubt about going concern limitation or departure from
- Auditor agrees with departure from GAAP, but only when the auditor
promulgated accounting principles concludes that the overall financial
- Emphasis of other matters statements are fairly stated.
- Can include anything that the - Use the language “except for” to
auditor deems important enough indicate what the limitation or
to include in the audit report. GAAP departure is.
- The existence of material related
party transactions 2. Adverse opinion
- Important events occurring - Used when financial statements
subsequent to the balance sheet are so materially misstated or
date misleading that they do not
- The description of accounting present fairly the financial position
matters affecting the comparability of the entity.
of the financial statements with - This is uncommon and is rarely
those of the prior year used.
- Material uncertainties disclosed
in the footnotes such as unusually 3. Disclaimer of opinion
important litigation or regulatory - Used when the auditor cannot
action form an opinion on the financial
- A major catastrophe that has had statement due to a severe scope
limitation, lack of knowledge on the misstatement(s) is
part of the auditor, or lack of pervasive to the
financial statements
independence.
MATERIALITY DECISIONS
MATERIALITY
Decisions regarding materiality in specific audit
A misstatement in the financial statements can be
situations involves judgment on the part of the
considered material if knowledge of the
auditor. These decisions are based on the
misstatement will affect a decision of a
following:
reasonable user of the statements.
As it applies to accounting and auditing
● Materiality decisions
- Non-GAAP condition
Three levels of materiality are used for ● Dollar amounts compared with a
determining the type of opinion to issue: benchmark
1. Amounts are immaterial ● Measurability
- A standard unmodified opinion ● Nature of the item
audit report is appropriate. ● Materiality decisions
- Scope limitations conditions
2. Amounts are material but do not
overshadow the financial statements as There are no simple rules to determine materiality
a whole in an audit. The auditor must consider the above
- A qualified opinion using “except items in each specific situation and use his or her
for” is appropriate. professional judgement to make a determination
on materiality.
3. Amounts are so material or so
pervasive that overall fairness of the DISCUSSION OF CONDITIONS REQUIRING A
statements is in question MODIFICATION OF OPINION
- A disclaimer or adverse opinion is
1. Auditor’s Scope Has Been Restricted
appropriate.
- Caused by the client or by conditions
SIGNIFICANCE IN beyond the control of either the client or
MATERIALITY TERMS OF TYPE OF the auditor.
LEVEL REASONABLE OPINION - A scope restriction can lead to a qualified
USERS DECISIONS report or a disclaimer of opinion,
depending on the facts in the situation.
Immaterial Unlikely to be Unmodified
affected
2. Statements Are Not in Conformity with
Material Likely to be affected Qualified
GAAP
only if information is - A departure from GAAP may result in a
important to specific qualified report or an adverse opinion
decisions being depending on the facts in the situation.
made.
Effect of
In a scope restriction and in a departure from
misstatement(s) is not GAAP situation, the auditor must decide if the
pervasive to the limitation or departure is severe enough to
financial statements warrant a disclaimer of opinion or not. If not, a
and the overall qualified opinion with the “except for” clause is
financial statements
are presented fairly used.
Highly material Most or all decisions Disclaimer or AUDITOR IS NOT INDEPENDENT
based on financial Adverse
statements are likely
to be significantly If the auditor is not independent as specified by the
affected. AICPA Code of Professional Conduct, a
Effect of disclaimer of opinion is required even though
necessary audit procedures were performed.
AUDITOR’S DECISION PROCESS FOR AUDIT
REPORTS
1. Determine whether any condition exists
requiring a departure from a standard
unmodified opinion report.
2. Decide the materiality for each condition.
3. Decide the appropriate type of report for
the condition, given the materiality level.
4. Write the audit report.
5. Determine if more than one condition
requiring a departure or modification
exists.
INTERNATIONAL ACCOUNTING AND
AUDITING STANDARDS
U.S. public companies are required to prepare
financial statements that are filed with the
Securities and Exchange Commission (SEC) in
accordance with U.S. GAAP.
An auditor may be engaged to report on financial
statements prepared in accordance with IFRS.