0% found this document useful (0 votes)
17 views14 pages

Audit Risk Assessment and Response Guide

The document outlines the phases of risk assessment, risk response, and reporting in auditing, detailing the steps involved in each phase. It emphasizes the importance of engagement acceptance, understanding internal controls, and evaluating risks to ensure the integrity of financial statements. Additionally, it highlights the necessity of clear communication between auditors and management regarding responsibilities and expectations throughout the audit process.

Uploaded by

Elvis Rumints
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
17 views14 pages

Audit Risk Assessment and Response Guide

The document outlines the phases of risk assessment, risk response, and reporting in auditing, detailing the steps involved in each phase. It emphasizes the importance of engagement acceptance, understanding internal controls, and evaluating risks to ensure the integrity of financial statements. Additionally, it highlights the necessity of clear communication between auditors and management regarding responsibilities and expectations throughout the audit process.

Uploaded by

Elvis Rumints
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

PHASE I: RISK ASSESSMENT

Risk Assessment Overview

Preliminary Activities

Engagement Acceptance & Continuance

Planning the Audit

Overall Audit Strategy


Determining and Using Materiality
Audit Team Discussions

Performing Risk Assessment Procedures

Inherent risks - Identification


Inherent risks – Assessment
Significant Risks
Understanding Internal Control
Evaluating Internal Control
Communicating Deficiencies in Internal Control
Concluding the Risk Assessment Phase

PHASE II: RISK RESPONSE

Risk Response — An Overview


The Responsive Audit Plan
Determining the Extent of Testing
Documenting Work Performed
Written Representation

PHASE III: REPORTING

Reporting—Overview
Evaluating Audit Evidence
Communicating with Those Charged With Governance
Modifications to the Auditor’s Report
Emphasis of Matter and Other Matter Paragraphs
Comparative Information
RISK ASSESSMENT

A simpler way of describing the three elements is illustrated below.


Exhibit 3.0-1
Risk Assessment

Risk Response
What events* Did the events*

Reporting
What audit opinion,
could occur that would identified occur and
based on the evidence
cause a material result in a material
obtained, is appropriate
misstatement in the misstatement in the
on the financial statements?
financial statements? financial statements?

* An “event” is simply a business or fraud risk factor (see descriptions in Volume 1, Chapter 3, Exhibit
3.2-2) that, if it actually occurred, would adversely affect the entity’s ability to achieve its objective
of preparing financial statements that do not contain material misstatements resulting from error
and fraud. This would also include risks resulting from the absence of internal control to mitigate the
potential for material misstatements in the financial statements.
The major steps involved in the risk assessment phase of the audit, in the order they would normally be
performed, are outlined in the following exhibit.
Exhibit 3.0-2

Quality Controls — Ethics, Independence, and ISAs

Decide to Accept/Continue Engagement

Planning Activities

Determine Team planning Overall audit


Risk Assessment

materiality meeting strategy

Risk Assessment Procedures

Identify & Identify & Conclude:


assess assess
inherent risks control risks Assess RMM*
(fraud & error)
at financial
Communicate statement
significant and assertion
deficiencies levels

Document findings and any changes to the plan

* RMM = Risks of Material Misstatement

The core concepts addressed in the risk assessment phase are set out below.

Volume and
Core Concepts Risk Assessment Phase Chapters
Internal Control V1 - 5
Financial Statement Assertions V1 - 6
Materiality and Audit Risk V1 - 7
Risk Assessment Procedures V1 - 8
Engagement Acceptance
and Continuance

Exhibit 4.0-1
Activity Purpose Documentation

The major steps in the engagement acceptance/continuance process are outlined below.
Exhibit 4.0-2
Process to accept/continue with an audit engagement

Does Firm have Is the firm Are risks involved


Does firm have Is the firm
resources, time & independent & free
independent and
Are risks involved
acceptable? Accept or
competence? from conflict? acceptable? Continue?

Yes
Document
Documentprocedures performedand
procedures performed andhow
how threats
threats andand issues
issues werewere resolved
resolved

Stop
Are the audit Agree on Prepare/sign
Any scope
preconditions terms of engagement
limitations?
present?1 engagement letter
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance

4.1 Overview
One of the most important decisions that a firm can make is determining what engagements to accept or
which client relationships to retain. A poor decision can lead to unbillable time, unpaid fees, additional stress
on partners and staff, loss of reputation, and, worst of all, potential lawsuits.
ISQC 1 and ISA 220 require firms to develop, implement, and document their quality control procedures in
regard to their client acceptance and retention policies. Ideally, these policies and procedures should address
the level of risk (risk tolerance) and the client characteristics (such as poor management integrity, a high-risk
industry, or a publicly-traded company) that would not be acceptable to the firm.
For more information, refer to ISQC 1 and ISA 220, and to IFAC’s Guide to Quality Control for Use by Small- and
Medium-Sized Practices (QC Guide).
Before a firm decides to accept or retain an engagement, the auditor is required to:
• Establish the acceptability of the proposed financial reporting framework;
• Assess whether the firm can comply with relevant ethical requirements;
• Obtain the agreement of management that it acknowledges and understands its responsibility for:
– The preparation of the financial statements in accordance with the applicable financial reporting
framework,
– Such internal control as management determines is necessary to enable the preparation of
financial statements that are free from material misstatement, whether due to fraud or error, and
– To provide the auditor with access to all relevant information and any additional information that
the auditor may request, plus unrestricted access to persons within the entity from whom the
auditor determines it necessary to obtain audit evidence; and
• Perform engagement acceptance or continuance procedures. These procedures would be similar to the
risk assessment procedures outlined in Volume 1, Chapter 8. The results (assuming the engagement is
accepted) can later be used as part of the risk assessment.
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance

The initial and subsequent years’ assessments of the engagement risk help to ensure that the firm is:
• Independent, and that no conflicts of interest exist;
• Competent to perform the work with the required resources and time availability;
• Willing to accept the risks involved in performing the audit. This would include an assessment of
management’s integrity and attitudes toward internal control, industry trends, availability of appropriate
audit evidence, and other factors such as the ability of the client to pay the fees involved; and
• Not aware of any new information about an existing client that would have caused the firm to decline
the engagement if it had been known earlier.

There may be some very small entities requiring an audit where the owner-manager runs the entity,

In these situations, the auditor has to determine whether the absence of control activities or of other
components of control may make it impossible to obtain sufficient appropriate audit evidence. If this is
the case, the auditor would exercise professional judgment in determining whether the engagement
should be declined or a modified opinion provided.

does he/she have a good attitude toward internal control?


Is it possible to develop an overall response and further audit procedures that would respond
appropriately to the assessed risk factors? For example, can substantive procedures be used to
determine that all revenues and liabilities are properly recorded in the accounting records?

Once a decision has been reached to accept or continue with the client engagement, the next step is to:
• Establish whether the preconditions for an audit are present; and
• Confirm a common understanding between the auditor and management (and where appropriate,
those charged with governance) of the terms of the audit engagement.

4.2 Engagement Acceptance


The first step in the client acceptance or continuance process is to assess the auditing firm’s ability to perform
the engagement, and the risks involved. The following exhibit outlines some possible lines of inquiry.
Exhibit 4.2-1
Consider Line of Inquiry
The Firm’s What (firm- and engagement-level) policies and procedures are in place to provide
Quality Control reasonable assurance that the firm will only undertake or continue relationships
Requirements where:
• The firm can comply with the ISA requirements; and
• The engagement risks involved are within the firm’s tolerance for risk?
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance

Consider Line of Inquiry


What Work Is • What is the nature and scope of the audit?
Required? • What accounting framework will be used?
• How will the auditor’s report and financial statements be used?
• What is the deadline (if any) for completing the audit?
Does the Firm • Does the firm have sufficient personnel with the necessary competence and
Have the capabilities?
Competence, • Do the selected firm personnel have:
Resources, and – Knowledge of relevant industries or subject matters,
Time Required? – Experience with relevant regulatory or reporting requirements, or
– Ability to gain the necessary skills and knowledge effectively?
• Are experts available, if needed?
• Where applicable, are there qualified persons available to perform the
engagement quality control review?
• Can the firm and the available staff (in light of timing requirements for other
clients) complete the engagement within the reporting deadline?
Is the Firm • Can the firm and the engagement team comply with ethical and independence
Independent? requirements?
• Where conflicts of interest, lack of independence, or other threats have been
identified:
– Has appropriate action been taken to eliminate those threats or reduce
them to an acceptable level by applying safeguards, or
– Have steps been taken to withdraw from the engagement?
• If the entity being audited is a component of a larger group, the group
engagement team may request certain work to be performed on the financial
information of the component. In such cases, the group engagement would
first obtain an understanding of the following:
– Whether the component auditor understands and will comply with the
ethical (including independence) requirements that are relevant to the
group audit,
– The component auditor's professional competence,
– Whether the group engagement team will be able to be involved in
the work of the component auditor to the extent necessary to obtain
sufficient appropriate audit evidence, and
– Whether the component auditor operates in a regulatory environment
that actively oversees auditors.
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance

Consider Line of Inquiry


Are the Risks • For new engagements, has the firm communicated (as required by ISA 300.13)
Involved with the predecessor auditor to determine if there are any reasons for not
Acceptable? accepting the engagement?
• Has the firm conducted an Internet search and had discussions with firm
personnel and other third parties (such as bankers) to identify any reasons why
the firm should not accept the engagement?
• What are the values (“tone at the top”) and future goals of the entity?
• How competent are the entity’s senior management and staff?
• Are there difficult or time-consuming issues to address (accounting policies,
estimates, compliance with legislation, etc.)?
• What changes have taken place this period that will impact the engagement
(business trends and initiatives, personnel changes, financial reporting, IT
systems, purchase/sale of assets, regulations, etc.)?
• Is there a high level of public scrutiny and media interest?
• Is the entity in good financial health and does it have the ability to pay the firm’s
professional fees?
• Will the entity provide help to the firm in obtaining information and preparing
schedules, analysis of balances, providing data files, etc.?
Can the Client Be • Are there any scope limitations, such as unrealistic deadlines or an inability to
Trusted? obtain the required audit evidence?
• Is there any reason (or recent event) that casts doubt on the integrity of the
principal owners, senior management, and those charged with governance of
the entity? Consider the entity’s operations, including business practices, the
business’ reputation, and history of any ethical or regulatory infringements.
• Are there any indications that the entity might be involved in money laundering
or other criminal activities?
• What is the identity and business reputation of related parties?
• Does management have a poor attitude toward internal control and an
aggressive attitude toward interpretation of accounting standards? Consider
corporate culture, organizational structure, risk tolerance, complexity of
transactions, etc.

Background Checks
To ensure that the information obtained from the entity is accurate, consider what third-party information
could be obtained to validate key aspects of the risk assessment. This simple step could avert problems later
on. Examples include information from sources such as previous financial statements, income tax returns,
credit reports, and possibly (after receiving permission from the prospective client) discussions with key
advisors such as bankers, etc.
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance

Before contacting third parties and collecting information on a prospective client, take steps to ensure
that all partners and staff are aware of:

4.3 Pre-Conditions for an Audit


Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance

Exhibit 4.3-1
Consider Line of Inquiry
Are the Audit Is the financial reporting framework (such as IFRS or a local framework) to be used in
Preconditions preparing the financial statements acceptable? Factors to consider include:
Present? • The nature of the entity (business, public sector, or not-for-profit);
• The purpose of the financial statements (common purpose or for specific users);
• The nature of the financial statements (complete set of financial statements or a
single financial statement); and
• Whether law or regulation prescribes the applicable financial reporting framework.
Does management agree to and acknowledge/understand its responsibility for:
• Preparing the financial statements in accordance with the applicable financial
reporting framework, including (where relevant) their fair presentation;
• Such internal control as management determines is necessary to enable the
preparation of financial statements that are free from material misstatement,
whether due to fraud or error; and
• Providing the auditor with:
– Access to all relevant information such as records, documentation, and
other matters,
– Additional information requested from management for the purpose of
the audit (such as written representations), and
– Unrestricted access to persons within the entity to obtain the necessary
audit evidence?
Is There a Scope Has management or those charged with governance imposed any type of limitation
Limitation? on the scope of the audit? This could include unrealistic deadlines, not accepting
certain firm’s staff to perform the work, and denial of access to a facility, key
personnel, or relevant documents. If such a limitation would result in a disclaimer of
opinion, the firm would decline the engagement, unless the firm is required by law or
regulation to proceed with the engagement.

Where management does not acknowledge its responsibilities or agree to provide the written
representations, the auditor will not be able to obtain sufficient appropriate audit evidence. In such
circumstances, or where the financial reporting framework is not acceptable, the auditor is required by ISA
210.8 to decline the engagement unless required by law or regulation.

4.4 Agreeing the Terms of Engagement


Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance

Note: Paragraphs 18-22 of ISA 210 contain some additional considerations in engagement acceptance, such
as where financial reporting standards are supplemented by law or regulation and where the financial
reporting framework is prescribed by law or regulation.
To ensure a clear understanding between management and the auditor on the terms of engagement, an
engagement letter (or other suitable form of written agreement) is prepared and agreed upon with the appropriate
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance

representative of senior management. To avoid any potential for misunderstanding, the engagement letter would
be finalized and signed before the engagement work commences.
Even in countries where the audit objective, scope, and obligations are established by law, an engagement
letter may still be useful to inform clients about their specific roles and responsibilities.
A sample of an engagement letter based on the example contained in ISA 210 is provided in the case study
materials that follow.
The engagement letter would address the matters set out below.
Exhibit 4.4-1
Terms Description
The Objective, • The accounting framework to be used.
Accounting • Objective of the audit of financial statements and the anticipated form of
Framework, auditor’s report or other communication. Also, the circumstances in which a
Scope, and Form report may differ from its expected form and content.
of Auditor’s • The scope of the audit, including reference to applicable legislation, regulations,
Report Resulting ISAs, and ethical and other pronouncements of professional bodies to which the
from the Audit auditor adheres.
of the Financial • Other parties to whom a report is required to be made (e.g., a regulator).
Statements
The • To conduct the audit in accordance with International Standards on Auditing
Responsibilities (ISAs).
of the Auditor • Recognition that, due to the inherent limitations of an audit and the
limitations of internal control, there is an unavoidable risk that some material
misstatements may not be detected, even though the audit is properly planned
and performed in accordance with ISAs.
The • For the preparation of the financial statements in accordance with the
Responsibilities applicable financial framework, and for designing and implementing such
of Management internal control as management determines is necessary to enable the
preparation of financial statements that are free from material misstatement,
whether due to fraud or error.
• Accept the terms of the engagement as outlined in the engagement letter.
• Provide unrestricted access to any records, documentation, and other
information requested in connection with the audit.
• Provide unrestricted access to persons within the entity
• Confirm auditor’s expectation of receiving written confirmation from
management concerning representations made in connection with the audit.
• Agreement of management to inform the auditor of facts that may affect the
financial statements, of which management may become aware during the
period from the date of the auditor’s report to the date the financial statements
are issued.
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance

Other matters that could be included in the engagement letter are outlined below.
Exhibit 4.4-2
Terms Description
How the Audit Will Address arrangements regarding:
Be Conducted, • The planning and performance of the audit, including the composition of
Any Dispute the audit team and details of what (if any) draft financial statements or other
Resolution, working papers are to be prepared by the client, along with the dates on which
Obligations, and the auditor requires these;
Fee Arrangements • Involvement of other auditors and experts;
• Involvement of the predecessor auditor, if any, with respect to opening
balances; and
• Other matters:
– Any restrictions of the auditor’s liability where such possibility exists,
– The basis on which fees are computed and any billing arrangements,
– Any obligations by the firm to provide audit working papers to other
parties, and
– Reference to any further agreements between the auditor and the client,
or other letters or reports the auditor expects to issue to the client.
Client to confirm the terms of the engagement by acknowledging receipt of the
engagement letter.

Updating the Engagement Letter


When no changes have occurred, the auditor is required to assess whether there is a need to remind the
entity of the existing terms of the audit engagement. The terms of engagement may be reconfirmed at the
time of the auditor’s reappointment without the need to obtain a new letter each year.
The engagement letter is required to be revised when the circumstances change. Matters that may constitute
a change in circumstance include:
• Any revised or special terms of the engagement;
• A recent change in senior management;
• A significant change in ownership;
• A significant change in the nature or size of the entity’s business;
• A change in legal or regulatory requirements;
• A change in the financial reporting framework adopted in the preparation of the financial statements;
• A change in other reporting requirements; and
• Some indication that management misunderstands the objective and scope of the audit.
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance

A Change in the Terms of the Audit Engagement

If management requests changes to the terms of the audit engagement, the auditor would
consider whether there is reasonable justification for the request, and the implications for the
scope of the audit engagement. A reasonable justification could include a change in the
client’s circumstances or a misunderstanding of the nature of the original service requested.
A change would not be reasonable if it is motivated by issues raised during the audit. This
could include audit information that does not support management representations, an
inability to obtain certain audit
information (which would effectively limit the scope of the audit), or evidence that is otherwise
unsatisfactory. An example might be where the auditor is unable to obtain sufficient
appropriate audit evidence regarding inventory balances, and the entity asks for the audit
engagement to be changed to a review engagement to avoid a qualified opinion or a
disclaimer of opinion.
If the change in terms is reasonable, a revised engagement letter or other suitable form of
written agreement would be obtained. If, however, the auditor is unable to agree to the
proposed change in terms and is not permitted by management to continue the original audit
engagement, the auditor is required to:
• Withdraw from the audit engagement where possible under applicable law or regulation;
and
• Determine whether there is any obligation, either contractual or otherwise, to report the
circumstances to other parties, such as those charged with governance, owners, or
regulators.

4.5 Case Study—Client Acceptance and Continuance


Assuming that this is an ongoing audit engagement, the partner or senior manager in the audit
firm would make some inquiries to identify and assess any new or revised risk factors relevant
to deciding to continue with the audit engagement. Include inquiries such as the following.

Common questions

Powered by AI

When deciding to accept or continue an audit engagement, a firm must consider several factors. The firm needs to establish the acceptability of the proposed financial reporting framework and assess whether it can comply with relevant ethical requirements and qualifications for independence . It must ensure it has the necessary resources, time, and competence to perform the audit and assess management’s integrity and attitudes toward internal control . The firm must evaluate if any risks involved are within its risk tolerance, including potential conflicts of interest or high-risk industries . Additionally, if management does not acknowledge its responsibilities or agrees to provide the written representations required for the audit, the firm should decline the engagement unless required by law or regulations .

The engagement acceptance process is closely integrated with risk assessment procedures in an audit. During engagement acceptance, the auditor evaluates whether the proposed financial reporting framework is appropriate and whether the auditor can comply with relevant ethical standards, including independence . This initial assessment also involves evaluating management's integrity and assessing preliminary engagement risks . These findings from engagement acceptance contribute to an informed risk assessment, which identifies the inherent and control risks that will shape the audit strategy. The process helps in establishing an initial understanding of the entity's environment and risks, ultimately informing the responsive audit plan .

An engagement letter is critical in the audit process as it establishes a clear agreement between the auditor and the client on the terms of the audit engagement. It includes the objective and scope of the audit, the responsibilities of both the auditor and management, and the applicable accounting framework . This letter ensures that both parties are aligned on essential aspects, such as the audit's terms, legal obligations, and any specific roles and responsibilities each party must undertake . It prevents misunderstandings and provides a reference document that outlines how disputes could be resolved, fee arrangements, and any other agreed-upon terms .

Assessing management's integrity during the risk assessment phase is crucial as it directly affects the auditor's evaluation of the entity's internal controls and the potential for material misstatements due to fraud or error. Management's integrity influences their attitude toward ethical practices and the implementation of controls within the organization . If management lacks integrity, there is a heightened risk of financial misstatements and fraudulent activity, which must be addressed in the audit's overall strategy . By thoroughly evaluating management's integrity, auditors can better determine where to focus their attention and resources to mitigate the risk of material misstatements .

Before accepting an audit engagement, a firm must assess its independence and competence by evaluating several factors. It should ensure the firm is free from conflicts of interest and can comply with all relevant ethical requirements . The firm should assess whether it has the necessary resources and personnel competent to perform the audit, including industry knowledge and experience with relevant regulatory requirements . If experts are needed, the firm must ascertain their availability. Additionally, the firm should ensure that engagement risks are within its risk tolerance and that there are no new adverse information about an existing client that would warrant declining the engagement .

The risk assessment phase informs the overall audit strategy by identifying inherent and control risks that could lead to material misstatements in the financial statements. This phase involves planning activities, determining materiality, conducting audit team discussions, and performing risk assessment procedures to identify and assess significant risks . By understanding the entity's internal controls and evaluating potential deficiencies, auditors can conclude on the risks of material misstatement (RMM) and tailor the audit approach accordingly . This ensures that the audit strategy is responsive to any identified risks and appropriately addresses them throughout the audit engagement.

Unrestricted access to all relevant information is essential for an auditor as it enables the collection of sufficient and appropriate audit evidence to support their opinion on the financial statements. Access to records, personnel, and documents allows the auditor to thoroughly understand the entity's operations, internal controls, and financial reporting processes, facilitating the identification and assessment of risks . Without unrestricted access, the auditor’s ability to verify the integrity of the financial statements could be compromised, potentially impacting the audit's quality and reliability . This access ensures that auditors can fully comply with auditing standards and offer a credible opinion.

An auditor should consider declining an audit engagement if management imposes limitations that inhibit the audit's scope, potentially affecting its outcome. Such limitations include unrealistic deadlines, refusal to allow access to necessary facilities, key personnel, or documents, and restrictions on the audit firm's staff . If these limitations prevent the auditor from obtaining sufficient appropriate audit evidence, resulting in a potential disclaimer of opinion, the auditor may opt to decline the engagement unless legally obligated to continue . Additionally, if management does not acknowledge its responsibilities or refuses to provide necessary written representations, the auditor should decline the engagement .

Materiality plays a critical role in the risk assessment phase of an audit as it determines the significance threshold for identifying misstatements. By establishing what is considered material, auditors can focus their efforts on areas that have the most potential to impact the financial statements if misstated . Materiality guides auditors in designing audit procedures and determining the nature, timing, and extent of audit tests to be performed. It also aids in assessing risks of material misstatement at both the financial statement level and the assertion level . Effectively, materiality helps auditors prioritize risk areas and allocate resources efficiently throughout the audit process.

When a client requests a change in the terms of the audit engagement, the audit firm must evaluate whether there is a reasonable justification for the request. A change may be reasonable if prompted by a genuine alteration in circumstances, such as changes in the client's business operations or understanding of the audit's scope . The firm should ensure that the request is not driven by efforts to avoid audit findings that conflict with management representations or due to an inability to provide necessary information . If the change is reasonable, the terms of the engagement should be updated with a revised engagement letter. If the firm cannot agree to the proposed changes and management prohibits continuation under original terms, the firm may need to withdraw from the engagement and consider reporting the circumstances to other parties like regulators or governance ."}]}]} umbs_up Thumb up for 1 year, 4 months, 8 days ago!sprevious|next rotationta-newAdd documentsExampleTest Resultoval-resetUndoRotate errorRespDanlav<|vq_6462|>{

You might also like