PHASE I: RISK ASSESSMENT
Risk Assessment Overview
Preliminary Activities
Engagement Acceptance & Continuance
Planning the Audit
Overall Audit Strategy
Determining and Using Materiality
Audit Team Discussions
Performing Risk Assessment Procedures
Inherent risks - Identification
Inherent risks – Assessment
Significant Risks
Understanding Internal Control
Evaluating Internal Control
Communicating Deficiencies in Internal Control
Concluding the Risk Assessment Phase
PHASE II: RISK RESPONSE
Risk Response — An Overview
The Responsive Audit Plan
Determining the Extent of Testing
Documenting Work Performed
Written Representation
PHASE III: REPORTING
Reporting—Overview
Evaluating Audit Evidence
Communicating with Those Charged With Governance
Modifications to the Auditor’s Report
Emphasis of Matter and Other Matter Paragraphs
Comparative Information
RISK ASSESSMENT
A simpler way of describing the three elements is illustrated below.
Exhibit 3.0-1
Risk Assessment
Risk Response
What events* Did the events*
Reporting
What audit opinion,
could occur that would identified occur and
based on the evidence
cause a material result in a material
obtained, is appropriate
misstatement in the misstatement in the
on the financial statements?
financial statements? financial statements?
* An “event” is simply a business or fraud risk factor (see descriptions in Volume 1, Chapter 3, Exhibit
3.2-2) that, if it actually occurred, would adversely affect the entity’s ability to achieve its objective
of preparing financial statements that do not contain material misstatements resulting from error
and fraud. This would also include risks resulting from the absence of internal control to mitigate the
potential for material misstatements in the financial statements.
The major steps involved in the risk assessment phase of the audit, in the order they would normally be
performed, are outlined in the following exhibit.
Exhibit 3.0-2
Quality Controls — Ethics, Independence, and ISAs
Decide to Accept/Continue Engagement
Planning Activities
Determine Team planning Overall audit
Risk Assessment
materiality meeting strategy
Risk Assessment Procedures
Identify & Identify & Conclude:
assess assess
inherent risks control risks Assess RMM*
(fraud & error)
at financial
Communicate statement
significant and assertion
deficiencies levels
Document findings and any changes to the plan
* RMM = Risks of Material Misstatement
The core concepts addressed in the risk assessment phase are set out below.
Volume and
Core Concepts Risk Assessment Phase Chapters
Internal Control V1 - 5
Financial Statement Assertions V1 - 6
Materiality and Audit Risk V1 - 7
Risk Assessment Procedures V1 - 8
Engagement Acceptance
and Continuance
Exhibit 4.0-1
Activity Purpose Documentation
The major steps in the engagement acceptance/continuance process are outlined below.
Exhibit 4.0-2
Process to accept/continue with an audit engagement
Does Firm have Is the firm Are risks involved
Does firm have Is the firm
resources, time & independent & free
independent and
Are risks involved
acceptable? Accept or
competence? from conflict? acceptable? Continue?
Yes
Document
Documentprocedures performedand
procedures performed andhow
how threats
threats andand issues
issues werewere resolved
resolved
Stop
Are the audit Agree on Prepare/sign
Any scope
preconditions terms of engagement
limitations?
present?1 engagement letter
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance
4.1 Overview
One of the most important decisions that a firm can make is determining what engagements to accept or
which client relationships to retain. A poor decision can lead to unbillable time, unpaid fees, additional stress
on partners and staff, loss of reputation, and, worst of all, potential lawsuits.
ISQC 1 and ISA 220 require firms to develop, implement, and document their quality control procedures in
regard to their client acceptance and retention policies. Ideally, these policies and procedures should address
the level of risk (risk tolerance) and the client characteristics (such as poor management integrity, a high-risk
industry, or a publicly-traded company) that would not be acceptable to the firm.
For more information, refer to ISQC 1 and ISA 220, and to IFAC’s Guide to Quality Control for Use by Small- and
Medium-Sized Practices (QC Guide).
Before a firm decides to accept or retain an engagement, the auditor is required to:
• Establish the acceptability of the proposed financial reporting framework;
• Assess whether the firm can comply with relevant ethical requirements;
• Obtain the agreement of management that it acknowledges and understands its responsibility for:
– The preparation of the financial statements in accordance with the applicable financial reporting
framework,
– Such internal control as management determines is necessary to enable the preparation of
financial statements that are free from material misstatement, whether due to fraud or error, and
– To provide the auditor with access to all relevant information and any additional information that
the auditor may request, plus unrestricted access to persons within the entity from whom the
auditor determines it necessary to obtain audit evidence; and
• Perform engagement acceptance or continuance procedures. These procedures would be similar to the
risk assessment procedures outlined in Volume 1, Chapter 8. The results (assuming the engagement is
accepted) can later be used as part of the risk assessment.
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance
The initial and subsequent years’ assessments of the engagement risk help to ensure that the firm is:
• Independent, and that no conflicts of interest exist;
• Competent to perform the work with the required resources and time availability;
• Willing to accept the risks involved in performing the audit. This would include an assessment of
management’s integrity and attitudes toward internal control, industry trends, availability of appropriate
audit evidence, and other factors such as the ability of the client to pay the fees involved; and
• Not aware of any new information about an existing client that would have caused the firm to decline
the engagement if it had been known earlier.
•
There may be some very small entities requiring an audit where the owner-manager runs the entity,
In these situations, the auditor has to determine whether the absence of control activities or of other
components of control may make it impossible to obtain sufficient appropriate audit evidence. If this is
the case, the auditor would exercise professional judgment in determining whether the engagement
should be declined or a modified opinion provided.
does he/she have a good attitude toward internal control?
Is it possible to develop an overall response and further audit procedures that would respond
appropriately to the assessed risk factors? For example, can substantive procedures be used to
determine that all revenues and liabilities are properly recorded in the accounting records?
Once a decision has been reached to accept or continue with the client engagement, the next step is to:
• Establish whether the preconditions for an audit are present; and
• Confirm a common understanding between the auditor and management (and where appropriate,
those charged with governance) of the terms of the audit engagement.
4.2 Engagement Acceptance
The first step in the client acceptance or continuance process is to assess the auditing firm’s ability to perform
the engagement, and the risks involved. The following exhibit outlines some possible lines of inquiry.
Exhibit 4.2-1
Consider Line of Inquiry
The Firm’s What (firm- and engagement-level) policies and procedures are in place to provide
Quality Control reasonable assurance that the firm will only undertake or continue relationships
Requirements where:
• The firm can comply with the ISA requirements; and
• The engagement risks involved are within the firm’s tolerance for risk?
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance
Consider Line of Inquiry
What Work Is • What is the nature and scope of the audit?
Required? • What accounting framework will be used?
• How will the auditor’s report and financial statements be used?
• What is the deadline (if any) for completing the audit?
Does the Firm • Does the firm have sufficient personnel with the necessary competence and
Have the capabilities?
Competence, • Do the selected firm personnel have:
Resources, and – Knowledge of relevant industries or subject matters,
Time Required? – Experience with relevant regulatory or reporting requirements, or
– Ability to gain the necessary skills and knowledge effectively?
• Are experts available, if needed?
• Where applicable, are there qualified persons available to perform the
engagement quality control review?
• Can the firm and the available staff (in light of timing requirements for other
clients) complete the engagement within the reporting deadline?
Is the Firm • Can the firm and the engagement team comply with ethical and independence
Independent? requirements?
• Where conflicts of interest, lack of independence, or other threats have been
identified:
– Has appropriate action been taken to eliminate those threats or reduce
them to an acceptable level by applying safeguards, or
– Have steps been taken to withdraw from the engagement?
• If the entity being audited is a component of a larger group, the group
engagement team may request certain work to be performed on the financial
information of the component. In such cases, the group engagement would
first obtain an understanding of the following:
– Whether the component auditor understands and will comply with the
ethical (including independence) requirements that are relevant to the
group audit,
– The component auditor's professional competence,
– Whether the group engagement team will be able to be involved in
the work of the component auditor to the extent necessary to obtain
sufficient appropriate audit evidence, and
– Whether the component auditor operates in a regulatory environment
that actively oversees auditors.
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance
Consider Line of Inquiry
Are the Risks • For new engagements, has the firm communicated (as required by ISA 300.13)
Involved with the predecessor auditor to determine if there are any reasons for not
Acceptable? accepting the engagement?
• Has the firm conducted an Internet search and had discussions with firm
personnel and other third parties (such as bankers) to identify any reasons why
the firm should not accept the engagement?
• What are the values (“tone at the top”) and future goals of the entity?
• How competent are the entity’s senior management and staff?
• Are there difficult or time-consuming issues to address (accounting policies,
estimates, compliance with legislation, etc.)?
• What changes have taken place this period that will impact the engagement
(business trends and initiatives, personnel changes, financial reporting, IT
systems, purchase/sale of assets, regulations, etc.)?
• Is there a high level of public scrutiny and media interest?
• Is the entity in good financial health and does it have the ability to pay the firm’s
professional fees?
• Will the entity provide help to the firm in obtaining information and preparing
schedules, analysis of balances, providing data files, etc.?
Can the Client Be • Are there any scope limitations, such as unrealistic deadlines or an inability to
Trusted? obtain the required audit evidence?
• Is there any reason (or recent event) that casts doubt on the integrity of the
principal owners, senior management, and those charged with governance of
the entity? Consider the entity’s operations, including business practices, the
business’ reputation, and history of any ethical or regulatory infringements.
• Are there any indications that the entity might be involved in money laundering
or other criminal activities?
• What is the identity and business reputation of related parties?
• Does management have a poor attitude toward internal control and an
aggressive attitude toward interpretation of accounting standards? Consider
corporate culture, organizational structure, risk tolerance, complexity of
transactions, etc.
Background Checks
To ensure that the information obtained from the entity is accurate, consider what third-party information
could be obtained to validate key aspects of the risk assessment. This simple step could avert problems later
on. Examples include information from sources such as previous financial statements, income tax returns,
credit reports, and possibly (after receiving permission from the prospective client) discussions with key
advisors such as bankers, etc.
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance
Before contacting third parties and collecting information on a prospective client, take steps to ensure
that all partners and staff are aware of:
4.3 Pre-Conditions for an Audit
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance
Exhibit 4.3-1
Consider Line of Inquiry
Are the Audit Is the financial reporting framework (such as IFRS or a local framework) to be used in
Preconditions preparing the financial statements acceptable? Factors to consider include:
Present? • The nature of the entity (business, public sector, or not-for-profit);
• The purpose of the financial statements (common purpose or for specific users);
• The nature of the financial statements (complete set of financial statements or a
single financial statement); and
• Whether law or regulation prescribes the applicable financial reporting framework.
Does management agree to and acknowledge/understand its responsibility for:
• Preparing the financial statements in accordance with the applicable financial
reporting framework, including (where relevant) their fair presentation;
• Such internal control as management determines is necessary to enable the
preparation of financial statements that are free from material misstatement,
whether due to fraud or error; and
• Providing the auditor with:
– Access to all relevant information such as records, documentation, and
other matters,
– Additional information requested from management for the purpose of
the audit (such as written representations), and
– Unrestricted access to persons within the entity to obtain the necessary
audit evidence?
Is There a Scope Has management or those charged with governance imposed any type of limitation
Limitation? on the scope of the audit? This could include unrealistic deadlines, not accepting
certain firm’s staff to perform the work, and denial of access to a facility, key
personnel, or relevant documents. If such a limitation would result in a disclaimer of
opinion, the firm would decline the engagement, unless the firm is required by law or
regulation to proceed with the engagement.
Where management does not acknowledge its responsibilities or agree to provide the written
representations, the auditor will not be able to obtain sufficient appropriate audit evidence. In such
circumstances, or where the financial reporting framework is not acceptable, the auditor is required by ISA
210.8 to decline the engagement unless required by law or regulation.
4.4 Agreeing the Terms of Engagement
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance
Note: Paragraphs 18-22 of ISA 210 contain some additional considerations in engagement acceptance, such
as where financial reporting standards are supplemented by law or regulation and where the financial
reporting framework is prescribed by law or regulation.
To ensure a clear understanding between management and the auditor on the terms of engagement, an
engagement letter (or other suitable form of written agreement) is prepared and agreed upon with the appropriate
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance
representative of senior management. To avoid any potential for misunderstanding, the engagement letter would
be finalized and signed before the engagement work commences.
Even in countries where the audit objective, scope, and obligations are established by law, an engagement
letter may still be useful to inform clients about their specific roles and responsibilities.
A sample of an engagement letter based on the example contained in ISA 210 is provided in the case study
materials that follow.
The engagement letter would address the matters set out below.
Exhibit 4.4-1
Terms Description
The Objective, • The accounting framework to be used.
Accounting • Objective of the audit of financial statements and the anticipated form of
Framework, auditor’s report or other communication. Also, the circumstances in which a
Scope, and Form report may differ from its expected form and content.
of Auditor’s • The scope of the audit, including reference to applicable legislation, regulations,
Report Resulting ISAs, and ethical and other pronouncements of professional bodies to which the
from the Audit auditor adheres.
of the Financial • Other parties to whom a report is required to be made (e.g., a regulator).
Statements
The • To conduct the audit in accordance with International Standards on Auditing
Responsibilities (ISAs).
of the Auditor • Recognition that, due to the inherent limitations of an audit and the
limitations of internal control, there is an unavoidable risk that some material
misstatements may not be detected, even though the audit is properly planned
and performed in accordance with ISAs.
The • For the preparation of the financial statements in accordance with the
Responsibilities applicable financial framework, and for designing and implementing such
of Management internal control as management determines is necessary to enable the
preparation of financial statements that are free from material misstatement,
whether due to fraud or error.
• Accept the terms of the engagement as outlined in the engagement letter.
• Provide unrestricted access to any records, documentation, and other
information requested in connection with the audit.
• Provide unrestricted access to persons within the entity
• Confirm auditor’s expectation of receiving written confirmation from
management concerning representations made in connection with the audit.
• Agreement of management to inform the auditor of facts that may affect the
financial statements, of which management may become aware during the
period from the date of the auditor’s report to the date the financial statements
are issued.
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance
Other matters that could be included in the engagement letter are outlined below.
Exhibit 4.4-2
Terms Description
How the Audit Will Address arrangements regarding:
Be Conducted, • The planning and performance of the audit, including the composition of
Any Dispute the audit team and details of what (if any) draft financial statements or other
Resolution, working papers are to be prepared by the client, along with the dates on which
Obligations, and the auditor requires these;
Fee Arrangements • Involvement of other auditors and experts;
• Involvement of the predecessor auditor, if any, with respect to opening
balances; and
• Other matters:
– Any restrictions of the auditor’s liability where such possibility exists,
– The basis on which fees are computed and any billing arrangements,
– Any obligations by the firm to provide audit working papers to other
parties, and
– Reference to any further agreements between the auditor and the client,
or other letters or reports the auditor expects to issue to the client.
Client to confirm the terms of the engagement by acknowledging receipt of the
engagement letter.
Updating the Engagement Letter
When no changes have occurred, the auditor is required to assess whether there is a need to remind the
entity of the existing terms of the audit engagement. The terms of engagement may be reconfirmed at the
time of the auditor’s reappointment without the need to obtain a new letter each year.
The engagement letter is required to be revised when the circumstances change. Matters that may constitute
a change in circumstance include:
• Any revised or special terms of the engagement;
• A recent change in senior management;
• A significant change in ownership;
• A significant change in the nature or size of the entity’s business;
• A change in legal or regulatory requirements;
• A change in the financial reporting framework adopted in the preparation of the financial statements;
• A change in other reporting requirements; and
• Some indication that management misunderstands the objective and scope of the audit.
Guide to Using International Standards on Auditing in the Audits of Small- and Medium-Sized Entities Volume 2 —Practical Guidance
A Change in the Terms of the Audit Engagement
If management requests changes to the terms of the audit engagement, the auditor would
consider whether there is reasonable justification for the request, and the implications for the
scope of the audit engagement. A reasonable justification could include a change in the
client’s circumstances or a misunderstanding of the nature of the original service requested.
A change would not be reasonable if it is motivated by issues raised during the audit. This
could include audit information that does not support management representations, an
inability to obtain certain audit
information (which would effectively limit the scope of the audit), or evidence that is otherwise
unsatisfactory. An example might be where the auditor is unable to obtain sufficient
appropriate audit evidence regarding inventory balances, and the entity asks for the audit
engagement to be changed to a review engagement to avoid a qualified opinion or a
disclaimer of opinion.
If the change in terms is reasonable, a revised engagement letter or other suitable form of
written agreement would be obtained. If, however, the auditor is unable to agree to the
proposed change in terms and is not permitted by management to continue the original audit
engagement, the auditor is required to:
• Withdraw from the audit engagement where possible under applicable law or regulation;
and
• Determine whether there is any obligation, either contractual or otherwise, to report the
circumstances to other parties, such as those charged with governance, owners, or
regulators.
4.5 Case Study—Client Acceptance and Continuance
Assuming that this is an ongoing audit engagement, the partner or senior manager in the audit
firm would make some inquiries to identify and assess any new or revised risk factors relevant
to deciding to continue with the audit engagement. Include inquiries such as the following.