0% found this document useful (0 votes)
16 views34 pages

Assurance Engagements and Corporate Governance

The document outlines the principles and practices of assurance engagements, emphasizing the importance of external audits, corporate governance, and ethical standards in auditing. It details the roles and responsibilities of auditors, the regulatory framework governing audits, and the necessity of maintaining independence and objectivity. Additionally, it discusses the significance of corporate governance codes and ethical guidelines to enhance trust and credibility in financial reporting.

Uploaded by

Taha Waheed
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views34 pages

Assurance Engagements and Corporate Governance

The document outlines the principles and practices of assurance engagements, emphasizing the importance of external audits, corporate governance, and ethical standards in auditing. It details the roles and responsibilities of auditors, the regulatory framework governing audits, and the necessity of maintaining independence and objectivity. Additionally, it discusses the significance of corporate governance codes and ethical guidelines to enhance trust and credibility in financial reporting.

Uploaded by

Taha Waheed
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Chapters

1. Intro to Assurance
2. Rules and regulations
3. Corporate governance
4. Ethics and acceptance
5. Internal controls
6. Specific controls
1- Intro to Assurance

Assurance engagements

 Definition- an engagement in which a practitioner gains sufficient evidence on a subject matter


to compare against criteria in order to give a conclusion with the intention to improve the
confidence of the party using the information rather than the party responsible for it.

 5 Elements- CPSEW- criteria, 3 parties, subject, evidence, written report


 Limited vs reasonable assurance- A reasonable assurance involves collecting higher quality
evidence through thorough testing in order to provide a more confident conclusion that the
information conforms/doesn’t against criteria and the report is worded more positively. The
objectives of a limited and reasonable assurance are different, one sets out to achieve a
plausible conclusion while the other aims to sufficiently test the subject matter against criteria

External Audit

 Purpose- this is an example of a reasonable assurance engagement which intends to enhance


confidence of shareholders in the FS. It is done by providing opinions on 2 aspects, whether or
not the FS are true and fair and are they prepared in all material aspects against a relevant
reporting framework (this framework is different in places but assumed to be the IFRS here).

 Objective of auditor- to obtain reasonable assurance on whether or not the FS are free from
material misstatements, express an opinion on whether or not the FS are complying to the
framework, report on the FS while complying to ISAs.

 Need- some countries have laws requiring the publishing of FS along with a required external
audit for quoted and large companies while other companies might want to get one for benefits.
 Expectation gap- auditors do not test all transactions, only a sample. They do not investigate all
fraud in FS preparation, only assure there aren’t material misstatements (could be caused by
fraud). So, auditors do not provide absolute assurance.

 Review engagement- a limited assurance engagement where tests of control are not performed
on FS, instead only enquiries on management and analytical procedures are used. This is less
disruptive than an audit but provides an indicator for how well FS are conforming to IFRS.

The need for an audit or FS in general is required due to the separation of control. The directors
are the agents and the stewards and have a fiduciary responsibility towards the shareholders-
the principal.

An audit increases usefulness of FS for all stakeholders involved.

An unmodified opinion is the most favorable kind of report which indicates that the FS are true
and fair in all material respects and prepared according to the framework.
2- Rules and Regulations

Legal requirements of auditors and audit

 Need for regulation- to increase trust and credibility in auditors, standard setters and regulators
aim to harmonize the auditing process, adhere to an ethical code and focus on audit quality.
Examples of regulations are national corporate law, international audit standards and the code
of ethics.

 Who needs an audit- Large quoted companies require an audit in most countries while smaller
owner managed companies are exempt since material misstatements in these don’t affect the
wider economy by much and they don’t benefit from audit services.

 Who can audit- to be eligible you need to either be authorized by the state or be a member of a
recognized supervisory body like the ACCA (and allowed by that body). It is possible for both
individuals and firms to audit if they meet these criteria.

 Who can’t audit- Law in countries can prohibit people with incentives tied to a firm from
auditing them and the code of ethics can do this too based on competence, incentive,
confidentiality etc.

 Who appoints auditors- At the AGM, shareholders will vote for an auditor. However, if they fail
to do so, the directors can appoint an auditor with the approval of the shareholders. If neither
the shareholders nor the directors appoint an auditor, then the secretary of state can appoint
one for them.

 Removal of auditor- An auditor can be removed by member votes in a meeting, but there are
safeguards to prevent instant removal. Notice periods are in place, allowing the auditor time to
address any concerns raised and the company to cope. After the meeting, a statement of
circumstances must be sent by the auditor to both the company and the regulatory bodies
(ACCA in our case).

 Auditor rights- access to books and records, answers to questions relating to audit, notification
of AGMs or written resolutions along with participation in the meetings. Upon resignation they
can request a meeting and also have the company be responsible for the sharing of the
statement of circumstances.

 Auditor duties- primary duty is to audit the FS and tell whether or not they give a true and fair
view, but other duties may be imposed by law. On resignation they may also be required to
cooperate with the new auditors

International regulation

 IFAC- main international body of accountants ensuring the profession is regulated


internationally

 IAASB- responsible for producing and promoting ISAs and quality management standards

 ISAs- professional regulations that guide the planning, performance and reporting of audits for
FS (can also apply to other historical financial records). These will lay out principles and
requirements with explanations for auditors that must be followed unless specific exemptions
exist like national legal requirements.

 National regulators- in the UK the FRC is responsible for overseeing the accounting profession
including RSBs like the ACCA. It’s auditing division doesn’t just take up ISAs but instead modifies
them for UK use, they also have their own ethics code, their own auditing standards and
monitor the audit reports in the UK.

 Role of professional bodies- like the ACCA is to not only provide high quality education and
training for members and auditing companies but also to regulate them ethically (for instance
through quality reviews) to ensure they are complying with standards and quality is high. The
government also receives advice from bodies like these.
3- Corporate governance

The corporate governance code

 Good corporate governance- CG is how a company is controlled and operated and the goal with
good governance is to ensure that the interests of shareholders, employees and other
stakeholders are being considered by management.

 Relevance to auditors- good CG will mean better internal and external controls including
financial controls. This means lower chances of material misstatements and therefore less effort
required from auditors. Audit committees will also be crucial in ensuring good communication
and independence for the external auditors. Auditors also have responsibilities with regards to
CG.

 UK code- is similar to the OECD’s CG principles and promotes best practice for large quoted
companies through a comply or explain approach (listing rules require explanations for
deviations from the code). There are 5 parts to the code:

1- Board leadership and company purpose

 Principles- The board should lay out the purpose, values and strategy and have the directors
lead the culture by example. They should make sure every stakeholder has a voice- especially
the workforce with their policies being in line with values, they should promote long run
shareholder wealth maximization and ensure that the company always has resources.

 Major provisions- the board should: explain future risks and what is being done in the annual
report, monitor and ensure compliance with culture throughout the business, meet with major
shareholders to understand views, understand views of stakeholders and discuss them in
meetings, should allow whistleblowing, act against conflict of interest, note down director
problems with the board that aren’t resolved along with hearing out NEDs upon retirement.

 Board roles- The board is made up of EDs, NEDs and a chairman. They may hold their own board
meetings or general meetings where they meet with members (shareholders) who can cast vote
on decisions like auditor change.

o Chair- leads the BODs in meetings in terms of setting agendas and ensuring effective
communication including voices of every stakeholder like auditors being heard.
Monitors sub committees. Must be non-executive and independent

o CEO and EDs- ensure operations of the company

o NEDs- not involved in the day-to-day activities, rather bring independence and
expertise by being a part of sub committees and showing up in important meetings to
strategize with and supervise the ED.

2- Division of responsibilities

 Principles- The chair should lead the board and is responsible for everyone’s equal participation.
The board should have enough resources and its composition should be equal

 Main provisions- the chair should be independent upon assigning and not be the CEO.
NEDs need to make up half of the board, elect a senior designated NED, meet once yearly to
assess the chair’s performance, assess EDs performance against objectives and reappoint them.
Independence tests are to be run for NEDs and reported in the annual report.

3- Composition, success and evaluation

 Principles- The board needs to have a formal succession plan and evaluation must be made
annually to determine whether or not the board is skilled, experienced, diverse and unbiased.
 Main provisions- in order to achieve this a nomination committee is made. This is mostly NEDs
and will evaluate and re-appoint both EDs and NEDs at least once annually. NEDs and the chair
are to be appointed through open advertising or external consulting. Chair can’t be a part of the
NC

4- Audit, risk and internal control

 Principles- the board should create policies to make internal and external auditors independent
and effective. They should present a fair and balanced view of the co position. They should
monitor internal controls and create procedures to manage risk.

 Audit committee- Should be formed made up of only NEDs (at least 2 members) and one of
them has to be skilled in finances while the rest competent in their industry. Chairman can’t be a
part

 Committee role- monitoring and giving advice in the preparation of: FS, financial controls and
risk management, internal audit (if none exists must explain why) and external audit. They
should report on these functions in the annual report.

 Board role in risk- board should do an annual robust assessment of risk and opportunities,
explaining these in the annual report along with information on whether or not they are a going
concern.

 Benefits of AC- improves public confidence in FS and the audit by providing a monitor (listing
requires an AC), expertise can benefit other directors and the external auditors get an
independent communication channel.

 Internal audit- the AC has to monitor the internal audit, communicate with them and ensure
independence and communication lines with the chair. They are also to monitor how well
management is responding to internal audit recommendations.
 Risk committee- to monitor and plan against risks a committee can be created with mostly NEDs
which will advise management. Risks can be reduced by paying their cost, insurance and
effective controls. Directors are responsible for risk management and controls; auditors will only
test internal controls for financial reporting that cause material misstatement and then report
these to those charged with governance (isa 265).

5- Remuneration

 Principles- pay for the board should encourage goal congruence, no director should be able to
select their own pay.

 Main provisions- the committee should only have NEDs and at least 3 members, the chair can
be a part of it but not a lead. They will create a policy and set remuneration for the whole board
and senior management, but NED fees will be determined by the board and cannot be
performance based. Contracts should be annual.

Committee Min members NED comp CEO Chair


nomination - mostly yes Not allowed
remuneration 3 all no Yes but cant lead
audit 2 but 1 exp in fin all no no
risk - mostly - -
4- Ethics and acceptance

 Ethics are guidelines and professional ethics suggest behavior for a particular profession

 Auditors should be neutral- both in intention and perception

 IFAC’s IESBA produces ethical guidelines which are adopted by bodies across the world

 Fundamental ethical principles- Integrity- honesty and straightforward, objective- no conflict of


interest, professional competence and due care- continuous development and no negligence,
professional behavior, confidentiality

 confidentiality exceptions- if you are required by law or professional body to disclose such
information, if you need to disclose such information to protect your firm’s interests in a legal
setting and finally if the client is involved in illegal activities these MUST be reported

 Ethical threats- compromise an auditor’s independency and objectivity and safeguards will
minimize the threat of these to an acceptable level. These safeguards are to be discussed with
audit committee.

 1-Self-interest threat- like owning shares might result in the auditor not giving a modified
opinion since he wants the share price to stay high.

Examples: too high/low fees or ones that depend on something, previous unpaid fees, If
the new client fees > 15% of total revenue of a firm (only from plc not pvt) then this is
not allowed and should be discussed with audit committee if more than 2 years have
been charged consecutively. This cool off period also refers to partners
Safeguards: sell the shares, replace member. Fees should be fixed at market rates
through the AEL audit engagement letter. Should not have any credit.

 2- Self review threat- if employee of client company and now is auditing it. (2 year cool off
period). Providing non audit services does the same.

Safeguards- discuss with audit committee, Chinese wall where there are 2 different
audit engagement partners, members are different and the partners have a
confidentiality agreement with an EQCR engagement quality control reviewer that does
a hot review (before report issuance) and a cold review. This EQCR must be an
independent partner that is unfamiliar with the company.

 3- Familiarity threat- having a relative that can affect FS, taking gifts, continuous same client
audit, a firm member becomes a company employee

Safeguards- replace member, reject gifts or hospitality if they are material, max 7 years
of audit same co (2 year cool off period with partner change required but it can be
extended to 2 more years max if desperate with new 5 year cool off), don't take old
friend in team and change methods

 4- Intimidation threat- Not paying unpaid fees, blackmailing individual members or previous
misconducts.

Safeguards- discuss with audit committee, stand ground, resigning from the audit team
is the last step

 5- Advocacy threat- Supporting in share issuance, legal cases or marketing. The safeguard
against this is to not support the client in matters unless called up by courts

 Advertising- the work of audit firms should be ethical- no degrading others, exaggerating,
specifying time, use ethical channels. ACCA allows its logo use if 50% partners are ACCA
members with 51% profit sharing
 Conflicts of interest between auditor and client- if auditor is the shareholder/partner/any
stakeholder of a direct competitor of the client there is a conflict of interest. Info could be
misused. To prevent this, you replace the person or discuss with the audit committee

 2 competing clients being audited- by the same firm. Again, there is a threat of misuse of
information. To safeguard this, you have to notify the clients and ask their consent, advise them
to get legal advice and get some yourself, use the Chinese wall

 Tendering process- When searching for an auditor a tender is released which is signed and sent
back by firms. Then management and the audit committee will review these. this content is
evaluated and presented as auditor profiles to shareholders in the AGM. Upon selection, before
accepting the audit the auditor mustq consider factors and pre-conditions and then send an
AEL- audit engagement letter

contents- in each firms tender form- name of firm, partners, experience, locality, legal
jurisdiction, audit method, fees, quality standards and other services offered.

Factors before accepting- ensure IESBA compliance, check for conflicts of interest and
ethical threats, if present then set safeguards to reduce risk to acceptable level.

contact previous auditor through the client for a clearance letter detailing whether or
not you should accept the audit. If these guys say no or are not allowed to share info
then don't take the audit. If they never respond, remind them and mention you will take
the audit if they don't respond by a fixed date.

ensure legal restrictions to the firm, resources are enough and how much fees to ask,
screen client's BOD and activities
 Pre-conditions (ISA 210)- Ensure client is using the right framework and you can audit this,
ensure client takes responsibility for financial statement preparation and their necessary
controls. client should acknowledge they will give unrestricted access to info required

 Audit engagement letter- written contractual agreement between the auditor and the client. it
should have the scope of audit (FS), objective of audit (opinion), level of assurance (reasonable),
basis of fees, details of each side’s responsibilities, clause saying management will provide
written representation to auditor at the end.

 Quality standards (ISA 220)- partners in a firm are responsible for the quality control, staff
should only be hired if they are knowledgeable and experienced, their training and supervision
is to be ensured by the firm, ethical threat safeguards must be in place, company should seek
independent legal/professional advice with issues in audit, quality control partners need to be
present and used

 Hierarchy- Trainee- senior- supervisor (ensures quality standards)- manager (manages audit)-
audit partner (gives opinion)
5- Internal Controls

Internal controls- are tested by the auditor (TOC) since they have an effect on FS. Controls are a system
that is designed and operated by the management or those charged with governance.

ISA 315- deals with controls and as an auditor we first need to understand the control system of the
client before testing it. It has 5 components

5 components- control environment, entity’s risk assessment, info system of FR, control activities and
monitoring of controls- (AIMER)

1- control environment- the overall culture surrounding controls. Managements attitude,


commitment and seriousness about internal controls sets the tone for the rest of the company
and effects all elements of controls.

the elements of control environment include- the structure if the organization, attitude to risk,
HR policies, management styles, ethical value enforcement

2- risk assessment process- how management identifies, assesses and manages its risk to financial
reporting. Some may not deem risk significant and leave gaps
3- info system relevant to FR- could be IT or manual and refers to how they initiate, record,
process and report transactions and events regarding our assets, equities and liabilities. Auditors
should understand info systems like Tps, mis, eis, es

4- control activities- these are policies and procedures which ensure that the directives of
management are carried out without fraud, error and try to ensure these are corrected if they
exist. They can be IT or manual based.

Examples- duty segregation, confidential info restricted access, CCTV, approval from seniors
required, performance reviews, internal audit.

5- monitoring- involves checking how effective controls are in achieving their purpose and taking
actions to remedy ineffective internal controls (internal auditors help with this but management
is held responsible)

Controls are divided- into specific and common controls. The former applies to a specific department
and are more relevant to exam case studies and common controls apply to the whole company

specific controls- include the bank, inventory, purchase, nca, sales and payroll system. These
departments have their own control systems and all have an impact on FS.

Why have common controls? To reduce fraud and errors, to prevent misuse of assets and info, to
minimize misstatements in FS, to achieve objectives in time with solid info

Common control activities can be summarized with SPAMSOAP


-Segregation of duties. Physical controls like locks and passwords. Authorization of transactions and
events. Management control oversees every department via analytics like budgets, variances and
internal audit. Supervision of day-to-day activities. Organization chart which identifies authority and
responsibilities and should be in a manual. Arithmetic controls like the trial balances, control accounts
and reconciliations to ensure no mathematical errors. Personnel controls include training, performance
reviewing, disciplining and hiring.

other common controls- backups, recovery IT, proper dates, categorized documents, signatures

limitations to controls- are anything that delay your objective achievement or prevent it. Examples
include collusion from staff, management not following it, controls may have errors in their operations,
expensive, non-routine activities are not benefited, must be updated regularly
6- Specific controls

Cash and bank system

Reasons for controls: maintain complete and accurate records of cash and bank, ensure the bank
statement reconciles and prevent misuse of cash or theft

good petty cash system:

 nature of expenses is to be defined and limited to required amount. Excess cash to be banked

 Duties should be separated- payment, approval and accounting.

 Supervision should be done with restricted access (fixtures).

 Payments received should be documented with receipt copies stamped and kept. Expenses
reimbursed should have detailed vouchers kept that have things like name, department,
amount, number transposition etc.

 Sequential pre-numbering is essential

Good bank system: Cheque book access restricted, large amounts should have multiple signatures,
passwords for online systems, bank statements are to be reviewed regularly and reconciliation
statements prepared (arithmetic control)
Question Tips:

 when answering questions that ask for deficiencies and recommendations, we are to provide a
negative along with why it's bad then suggesting something along with why it's good.
Weaknesses can also just be deficiencies

 another tip for answering questions is to assume if something isn't told that it doesn't exist and
state the obvious solutions

Inventory system

Inventory control- is relevant to auditors since this will reflect how accurately and reliably inventory is
being reflected in the FS. To maintain accurate records, reduce chances of theft/fraud, reduce waste and
holding/stockout costs

Warehouse- should be in good condition, appropriate temperature, surveillance, fire alarms

Inventory records- bin card is a document for recording material, it is labelled with location/quantity
and quality. Store ledger records movement of inventory with monetary values. Inventory master file
records all material information like cost, selling price, date of purchase, frequency of usage

Inventory levels- reorder levels are to be based on lead time and usage and EOQ must be ordered.
Minimum inventory levels are a buffer amount and are based on highest amount of usage in lowest lead
time.

Inventory counting- periodic/perpetual counting is to be maintained. A count can be done at downtimes


with a counter and a recounter independent of inventory maintenance should do the count without
knowing the recorded amount in advance and having been given full guidance. counting sheets are to be
sequentially numbered, areas counted flagged, units sold not included in the count, and counters should
sign.

Computerized controls

General controls- overall controls on the whole digital system of the company that also protect
indirectly FR information. Examples include login passwords, restricted access, training, anti-viruses etc.

Application IT controls- controls over the financial reporting information application process. These
include input, process and output controls which ensure that complete and accurate accounting
information is recorded.

Input controls- ensure data entered into the system is complete and accurate, examples include format,
range, sequence and existence checks along with digit verification and a direct comparison of entered
data with source documents- one for one checking.
Process controls- ensures that data input is processed by the software correctly, these include systems
that notify that processing is complete or warn when an error occurs or you have not processed
information completely.

Output controls- these ensure that only the relevant and authorized people are the ones that are able
to view the processed information and others are restricted from it

Purchase Controls

Division- there is the procurement department which will order goods, the store department which
receives the goods and the accounts department which pays the suppliers. Each will have their own
controls.

Ordering goods- Only BOD approved suppliers to be used, quotations are to be obtained, evaluate and
choose the best based on the purchase mix- includes quantity, quality, discounts, lead time. Send a
purchase order (PO) to the supplier and a copy to the store department (sequentially numbered to
ensure completeness)

Receiving goods- the store department should check against the PO for quality, send a GRN to the
ordering dept and create a record.

Paying suppliers- the PO, invoice and the GRN are to be verified by the accounts dept before they
authorize a crossed check in the supplier’s name
Reasons for control- to ensure that complete and accurate purchases and payables records are kept, to
prevent fraud/collusion, to ensure quality and quantity through double verification and achieve the best
purchase in efficiency.

Sales and dispatch system

Sales- when accepting an old customer’s orders, you need to look at their payment history and limits
and give credit in line with your policy. With new customers you need to check their references,
reputation and credit worthiness. After selling you need to obtain written documentation- PO. You
should also do reconciliation statements with customers and also suppliers

Dispatch- production should be within deadlines and when delivering the responsible manager should
be in place to ensure against the PO that the right goods are being sent. A goods delivery note should be
sent (this needs to be signed and sent back by the client) along with gate passes.

Why have controls- to ensure complete and accurate records of sales and receivables, that the correct
goods are being delivered at the right times and only credit worthy customers are given credit.

Performing TOC

CAIRO- these are procedures used by auditors to test things like controls, detail and analytical
procedures. TOC will only use the last 3
tests- design/existence of controls along with their operations/effectiveness

Exam focus- in the exam you may have to test for design of controls or you may be given controls and
be asked to test their effectiveness. In both cases you have to suggest a procedure CAIRO and then
secondly explain what the purpose of the procedure was.

CAATs- computerized assisted audit techniques are any software or applications used by the auditor to
do either substantive testing through “audit software” or tests of controls through “data testing”. Data
testing involves using dummy data to test controls and looking at past trails of data.

NCA/capital expenditure

Good controls- these are similar to purchasing controls and include having a NCA register, requiring
approval from BOD and high-level management for purchases, surveying markets before purchases and
having security and surveillance measures.
Reasons for- other than maintaining complete and accurate records you want to minimize extra
expenditures and ensure no misuse of NCAs is taking place.

Exam focus- when asked to find controls auditors can rely on you have to identify what seem like good
controls and explain why they are good. Then if asked to test for these controls you have to prepare
procedures and what their purpose is:

Payroll system

Attendance- every employee should have an id card and a computerized attendance system should be
in place with supervision of its usage, ID cards issued are to be compared to HR number of employees to
ensure that there is no fraud/error.

Data entry- attendance should be integrated with the payroll software, data on joiners and leavers is to
be updated regularly with authorization, timesheet calculation and pay are to be separated as duties,
second person should review all payments and tax deductions, payroll department should confirm with
other department heads, pay slips with gross wages and deductions is to be produced.

Staff payment- cash payments must be done with multiple people present and checking of id,
automated bank transfers for salaries are to be reviewed before by a responsible manager.

Clerks- only responsible for entering data and recording, they should not have access to standing data
(confidential info) and should not be able to update payroll software

Reasons for controls- to ensure complete and accurate records of staff wages, prevent ghost employees
fraud and errors

Significant deficiencies for controls- anything that can lead to fraud, material misstatements in the
financial statements, which can cause further deficiencies in controls, subjective estimates being made
by non-experts.

Directors are only to authorize not manage and review, refer to roles. Manager should review payroll.
This director manager cross can be used in many control systems where the manager makes a review
while the director authorizes it upon a second review.

Controls documentation

Auditors must maintain records of control systems a client has and should update this yearly, there are 4
methods
Narrative notes- written descriptions of control systems and stages after discussions from management.
These are thorough and easy to understand but may be a burden to read if extensive.

Flow chart- arrows and small diagrams which are easy to view quickly and understand but can be hard
to amend and lack descriptions

Questionnaires- pre determined questions can categorize whether or not controls exist and if so, how
effective they are. Anyone can ask these and these can be used on other clients, but specialized clients
can't be dealt with

Check list- preparing a list of controls and then ticking them off through sheer observations. Is easy and
standardized but misses out on communication.

Approach to controls- first understand the control system, then document them, then you perform
TOC, write a report to management regarding control deficiencies and recommendations

Management letter- and has a space for Management's response, a copy of Management's response is
to be kept by the auditor
6- Internal Audit

Creation- Internal audit is established by the BOD and acts as the company's agent. Their goal is to
review the other departments and in effect be a management control. Any employee can be in the IA

Requirements- IA must be independent, have no ethical threats or conflicts of interest

Objectives-

 Review controls and FS, distinct from preparation- that is managements role.

 Check for value added with decisions (like buying a new machine)- best value audit

 Perform VFM for every department- economy, efficiency, effectiveness

 review whether operations are running as intended- operational audit

 compliance audit- are rules and regulations being followed

 undertake investigations like fraud, IT audit, purchase audit, customer relation audit, business
risk suggestions.

IA role- is a form of an internal control, good corporate governance, independent internally, should
report to the BOD through the audit committee
Need for IA- history of frauds and breaches of controls, expansion or major change in the business
structure, unusual situations and crises

IA fraud- they are to identify the fraud, quantify it, explain how it was done and who did it. Reports are
given to the audit committee and then they report to the BOD.

ISA 610- refers to the EA using the work of the IA. As part of the TOC, the work of the IA department is
reviewed through discussions with IA staff, reviewing their work and their report.

Direct assistance- a responsibility to be provided by the IA to the EA by giving them necessary


information on their workings.

Before relying on IA- ISA 610 suggests factors are to be considered- independence, competence- both
qualifications and experience, reporting structure, professionality, if outsourced then check reputation
too. The better the strength of IA, the better controls are and so less substantive testing is required.

Advantages- improves the control environment, external parties deem the company to be more
credible, independence in reviews is brought in, BOD can get neutral advice, external auditors can rely
on their work and reduce audit procedures and fees

Disadvantages- no real requirement to be an accounting professional, there may be collusion with staff,
BOD may restrict the IA department to certain areas and not consider advice.
6- FS Assertions

Financial statement assertions- through the FS, management are making explicit/implicit statements
and claims about financial performance and these are then used by auditors as the basis of their audit,
they will try to substantiate these claims and figure out material misstatements.

Types of assertions- ACCA COVER P

 C- Completeness- all FS are asserted to be complete in recorded figures and notes

 A- Accurate- accuracy, valuation and allocation are linked. For instance, appropriate allocation
of 20 depreciation will result in an adjustment to the book value

 C- cut off- assertion that the accruals concept has been followed and all the transactions have
been recorded in the right period

 O- Occurrence- asserts all the transactions have already taken place


 V- Valuation- refers to asset, liability and equity values and the assertion here is that they have
all been recorded at their appropriate year end values (NBV, NRV, FV, Par)

 E- Existence

 R- Rights and obligations- rights on assets and obligations on liabilities are asserted

 P- Presentation- the layout and structure of FS is appropriate

Relevance to FS- all these assertions are not relevant to both FS, the left side are account balances and
refer to the SOFP while the right side are transactions referring to the SOCI.

ISA 500- audit evidence

Audit evidence- information gathered by auditors after applying appropriate audit procedures on FS.
Evidence should be sufficient and appropriate

Audit procedures- CAIRO


Sufficiency- evidence is sufficient if quantity is high and this level will depend on how experienced the
auditor is, how material the item being inspected is, how much risk of estimation the item has, what
sample size is being taken, how reliable the evidence is

Appropriateness- refer to picture (both reliability and relevance)

Management experts- there are certain professionals that may be employed or outsourced that are not
directly linked to FS by not being part of the financial team or having experience in audit and accounting,
but they have an impact on FS. For example, lawyers predicting lawsuits or engineers predicting life or
amortization.
ISA 500- just as with internal auditor’s work, expert’s work can be relied on but only after discussions
with them and evaluations. Similar requirements are in place: competence, professionality,
independence, reputation (if outsourced).

Isa 315 assertion definitions-

Common questions

Powered by AI

Risk management in companies follows structures set by the corporate governance code which involve creating a risk committee predominantly made up of NEDs, advising management on risk mitigation. The board undertakes annual assessments of risks and opportunities, documenting findings in the annual report, along with their effects on the going concern status. These assessments and structures are significant for auditors as they guide the audit process in identifying potential risk areas, ensuring that internal controls are functioning properly, and verifying that financial statements are free from material misstatement due to unidentified risks .

A typical board of directors, according to the corporate governance code, includes executive directors (EDs), non-executive directors (NEDs), and a non-executive independent chairman. The board is responsible for laying out the company's purpose, strategy, and values and ensuring compliance with these across the organization. The board should maintain stakeholder engagement and manage potential conflicts of interest. Evaluation processes include annual assessments of board members' skills, experience, and diversity to ensure effective governance. A nomination committee, mainly composed of NEDs, evaluates and reappoints directors, ensuring board roles align with the company's strategic interests .

When assessing internal controls, auditors are suggested to perform various tests to determine the effectiveness and reliability of these controls. Procedures include walkthroughs to understand processes, testing transaction samples for compliance with controls, and reviewing documented control system descriptions like narrative notes or flowcharts. Expected outcomes involve identifying any control weaknesses, which auditors report in a management letter with recommendations for improvement. By thoroughly documenting these control systems and consistently testing them, auditors can ensure that they meet the intended objectives of ensuring accurate financial reporting .

Auditors face ethical challenges such as self-interest threats, self-review threats, and pressure from client relationships, which could compromise independence and objectivity. For example, owning client shares could bias audit opinions to maintain share prices. Safeguards include prohibiting certain financial relationships with clients, setting fixed fees, and restricting individual auditors who have recently joined from a client position. Ethics guidelines from bodies like IFAC's IESBA call for maintaining integrity, objectivity, professional competence, and confidentiality, with auditor independence reinforced by discussing potential ethical threats with audit committees and implementing protective measures .

Control activities in a company are structured through policies and procedures intended to ensure management directives are accomplished without fraud or error. They include segregation of duties, restricted access to confidential information, performance reviews, and internal audits. These controls can be IT-based or manual and apply company-wide (common controls) or to specific departments (specific controls). By preventing misuse of assets and minimizing financial statement misstatements, they enhance the reliability and accuracy of financial reporting. Regular monitoring ensures effectiveness, with management held accountable for any deficiencies .

Info system controls relevant to financial reporting ensure that transactions are initiated, recorded, processed, and reported accurately, whether through IT or manual systems. These controls, including transactional process systems (TPS), management information systems (MIS), executive information systems (EIS), and expert systems (ES), affect audit processes by providing auditors with assurance over the integrity of financial data. Effective information system controls reduce the risk of errors and fraud in financial statements, thereby guiding auditor focus during testing and helping maintain the reliability of financial reporting .

In the UK, national regulators like the Financial Reporting Council (FRC) play a significant role by overseeing the accounting profession and modifying international auditing standards to suit UK requirements. They have their own ethics code and auditing standards and monitor audit reports to ensure compliance. Professional bodies such as the ACCA provide high-quality education and training, regulate their members ethically, and perform quality reviews to ensure compliance with auditing standards. They also advise the government and interact with national regulators to promote adherence to standards .

The independence of the audit committee is crucial as it ensures objective oversight of financial reporting and audit processes, improving the quality and credibility of financial statements. This independence is ensured by structuring the audit committee with non-executive directors (NEDs) only, one of whom must possess financial expertise. The committee is responsible for monitoring financial controls, risk management, and the internal and external audit functions. Independence is further reinforced by excluding board chairs from audit committees and conducting annual assessments of audit committee members to verify compliance with independence criteria .

Remuneration policies within corporate governance are guided by principles of goal congruence and fairness. The remuneration committee, comprising only non-executive directors and at least three members, designs these policies to prevent any director from setting their own pay and ensures that executive pay reflects performance. To manage conflicts of interest, NED fees are determined separately by the board and are not performance-based. Annual contracts are recommended to maintain alignment with company goals, and all remuneration policies aim to promote transparency and accountability within executive compensation structures .

The corporate governance code promotes good governance by establishing principles and major provisions that emphasize board leadership, accountability, and stakeholder engagement. It requires companies to adopt a 'comply or explain' approach, ensuring they either follow the code or provide reasons for deviations. Key elements include board leadership, independence, balanced composition, and effective internal control and risk management systems. These elements impact audit practices by improving internal and external control effectiveness, reducing the risk of material misstatements, and enhancing communication between audit committees and external auditors, thus ensuring auditors have a clear and independent channel of communication .

You might also like