Auditing: Principles and Practices Guide
Auditing: Principles and Practices Guide
FRONTIER INSTITUTE
AUDITING
.
lOMoARcPSD|28154144
TABLE OF CONTENTS
TOPIC PAGE
Introduction to Auditing 1
Code of Ethics 4
Audit Engagement Letters 8
Fraud and Error 12
Professional Liability of an Auditor 14
Audit Planning 17
Knowledge of the Business 20
Audit Working Papers 21
Internal Control and Risk Assessment 23
Audit Materiality 29
Audit Risk 31
Audit Evidence 33
Analytical Review Procedures 35
Audit Sampling 37
The Work of Internal Audit 41
Auditing Inventories 45
Auditing Accounts Receivable 48
Auditing Cash and Bank Balances 51
Auditing Non Current Assets 54
Auditing Salaries and Wages 58
Auditing Purchases and Expenditure 60
Auditing Creditors and Accruals 63
Auditing Revenue 65
Auditing Share Capital and Reserves 67
lOMoARcPSD|28154144
INTRODUCTION TO AUDITING
Definition
Auditing has developed from what in the 12 th century, was primarily a check of the
accounting for stocks and revenues by authorised officers of the Exchequer of England
into a sophisticated professional assurance services performed by independent auditors for
the interest of their clients and other users of financial statements.
The historical perspective of auditing is very important given the current shift away from
traditional accounting and auditing services to a broad variety of assurance services.
The role of auditing first appeared in the United Kingdom in the 1800s.
The development of the auditing role is very much an account of Court case decisions at
the end of that century.
The increasing use of the company form of business organisation led to the growth to
managers who handled large sums of capital on behalf of shareholders.
In 1844 the Joint Stock Companies Act stipulated that “Directors shall cause the books of
the Company to be balanced and a full and fair Balance Sheet to be made up”.
The Act then provided for appointment of auditors who were empowered to examine the
accounts of the company.
In 1900 the appointment of an auditor became compulsory for all public companies to
appoint an auditor and in 1948 auditors were required to have appropriate professional
qualifications.
Objectives of an audit
general meeting during his term of office and the report shall contain the following
statement :
“Whether in his opinion , the balance sheet and income statement of the company or group
of companies are properly drawn up in accordance with legislation so as to give a true and
fair view of the company‟s affairs at the date of its balance sheet and income statement
for its` financial year ended on that date.”
The primary purpose of an audit is to establish whether, in the auditor`s opinion, the
financial statements are a true and fair reflection of the company‟s financial position.
If he does not believe that they are, then he will decline to confirm them or issue a
qualified report.
The auditor shall include in his report, statements which in his opinion are necessary if :
He has not obtained all the information and explanations which to the best of his
knowledge and belief were necessary for the purpose of the audit.
So far as appeared from his examination proper book of accounts have not been kept by
the company.
Proper returns adequate for the purpose of the audit have not been received from the
branches not visited by him.
The company‟s balance sheet and income statement are not in agreement with the book of
accounts and returns from the branches.
Rights of an auditor.
Every auditor of a company shall have a right of access at all times to the books, accounts,
vouchers and securities of a company and shall be entitled to require from the officers of
the company such information and explanations as he thinks necessary.
Every auditor of a holding company shall have a right to attend a general meeting of the
company and receive all notices relating to any general meeting of the company.
The auditor is entitled to be heard at any general meeting which he attends.
Legal background.
The companies Act lays down the legal background to an audit that includes the
appointment of an auditor, the disqualification for appointment as auditor and the rights
and duties.
The first auditors of a company shall be appointed by the directors within one month of
issue of the certificate that the company is entitled to commence business in the case of a
public company and other companies within one month of the issue of the certificate of
incorporation.
lOMoARcPSD|28154144
An auditor so appointed shall hold office until the conclusion of the first Annual General
meeting.
The directors shall at each AGM appoint an auditor to hold office from the conclusion of
that meeting until the conclusion of the next AGM.
The directors may fill any casual vacancy in the office of auditor but while any such
vacancy continues, the continuing auditor, if any, may act.
The remuneration of the auditor of a company shall be fixed by the company in general
meeting, or in such manner as the company in general meeting may determine.
Any sums paid by the company in respect of the auditors` expenses shall be deemed to be
included in the remuneration.
None of the following persons shall be qualified for appointment as auditors of a company:
Auditors may be removed from office by resolution of the company at an Annual General
Meeting for which a notice of twenty eight days is required.
The company must send such a notice of the resolution to the auditor in writing.
The auditor is then given an opportunity to make presentations in writing with copies of
presentations sent to all members.
Auditors may be removed so as to strengthen audit independence by appointing another
auditor.
Auditors who qualify their opinion on the financial statements cannot be removed by
directors for qualifying the financial statements.
When resigning the auditor should notify the company in writing.
The notice must be accompanied by any circumstances to be brought to the attention of
members or creditors or a statement that no such circumstances exist.
lOMoARcPSD|28154144
CODE OF ETHICS
The auditor‟s objectivity is likely to be jeopardised where the fees for audit and other
recurring work paid by one client or group of clients exceeds 15% of the gross practice
income or 10% of the gross practice income in the case of listed and other public interest
companies.
A new practice seeking to establish itself or an established practice seeking to reduce its
activities may not be able to comply with this criteria.
2. Overdue fees
The existence of significant overdue fees from an audit client or a group of connected
clients may be a threat to objectivity similar to that of a loan.
Litigation between the auditor and the client is likely to represent a breakdown in the
relationship of trust between them.
lOMoARcPSD|28154144
Problems may arise where a practice or anyone closely connected with it has a mutual
business interest with a client, and an officer or an employee of a client or where an officer
or employee is closely connected with a partner or staff member.
A practice should ensure that it should not have as an audit client a company in which a
partner or employee or anyone closely connected with a partner or employee who is a
holder of a beneficial investment nor should it employ on the audit a member of staff, if
that member of staff or a person closely connected with him is a beneficial holder of such
investment.
6. Loans
A practice or anyone closely connected with it should not, either directly or indirectly or
by way of a trust or other intermediary:
Make a loan to or guarantee borrowings by a company or organisation audited by the
practice.
Accept a loan from such a company or organisation.
Have borrowings guaranteed by such a company or organisation
This rule is not intended to preclude a loan, overdraft or home mortgage being accepted
from an audit client financial institution in the normal course of business and on normal
commercial terms by a partner or staff member.
Goods or services should not be accepted by a practice or anyone closely connected with it
unless the value of any such benefit is modest.
Acceptance of undue hospitality poses a similar threat.
In the case of a listed company or public interest company audit client a practice should
not participate in the preparation of accounting records except in :
(a) In relation to assistance of a mechanical nature for example consolidations and tax
provisions.
lOMoARcPSD|28154144
Conflict of interests
There is, on the face of it, nothing improper in having two or more clients whose interests
may be in conflict provided that the work that the auditor undertakes is not in itself, likely
to be the subject of conflict between the clients.
Where the acceptance or continuance of an engagement would even with safe guards,
materially prejudice the interests of a client, the appointment should not be accepted or
continued.
Where the auditor becomes aware of possible conflicts between the interests of two or
more clients, all reasonable steps should be taken to manage them.
These steps may include some or all of the following safeguards :
The use of different partners and teams for different engagements.
Standing instructions to prevent the leakage of confidential information between different
teams and sections within the audit firm.
Regular review of the situation by a senior partner or compliance officer not personally
involved with either client.
Advising one or both clients to seek additional independent advice.
Scope of an audit
The term scope of an audit refers to the audit procedures necessary to achieve the
objective of an audit that is n audit should be conducted in accordance with International
Standards on Auditing, rules of professional conduct, legislation and the terms of an audit
engagement.
The auditor is responsible for forming and expressing an opinion on the financial
statements.
The responsibility for preparing and presenting the financial statements rests with
management.
The audit of financial statements does not relieve management of its responsibility.
The auditor should comply with the code of ethics for professional accountants issued by
the International Federation of Accountants.
(a)Independence
(b)Integrity
(c)Objectivity
lOMoARcPSD|28154144
The auditor should plan and perform the audit with an attitude of professional skepticism
recognising that circumstances may exist which cause the financial statements to be
materially misstated.
The responsibility rests with management through the implementation and continued
operation of an adequate system of internal control which reduces the possibility of fraud
and error.
Audit objective
While the existence of an effective system of internal control reduces the probability of
misstatements of financial information resulting from fraud and error, there will always be
some risk of internal controls failing to operate as designed.
AUDIT ENGAGEMENT LETTERS
Objective of the audit of financial statements and managements‟ responsibility for the
preparation of financial statements.
Managements‟ responsibility for the preparation of financial statements.
Basis on which fees are computed and other billing arrangements.
Provision of accounting and other services such as taxation.
The purpose of this letter is to set out the basis on which we are to act as auditors of the
company and its subsidiaries and the respective areas of responsibility of the directors
and of ourselves.
1. As directors of the above company, you are responsible for ensuring that the
company maintains proper accounting records and for preparing financial statements
which give a true and fair view and have been prepared in accordance with the Companies
Act. You are also responsible for making available to us as and when required, all the
company’s accounting records and all other relevant records and related information,
including minutes of all management and shareholder’s meetings.
(a) whether proper accounting records have been kept by the company and proper
returns adequate for our audit have been received from branches not visited by us;
(b) whether the company`s balance sheet and income statement are in agreement with
the accounting records;
(c) whether we have obtained all the information and explanations which we think
necessary for the purposes of our audit; and
lOMoARcPSD|28154144
(d) whether the information in the director’s report is consistent with the financial
statements.
In addition, there are certain other matters which, according to circumstances, may need to
be dealt with in our report.
Where the financial statements do not give full details of the directors’ remuneration or of
their transactions with the company the Companies Act requires us to disclose such matters
in our report.
Our audit will be conducted in accordance with International Standards issued by the
Auditing Practices Board, and will include such tests of transactions and of the existence,
ownership and valuation of assets and liabilities as we consider necessary. We shall obtain
an understanding of the accounting and internal control systems in order to assess their
adequacy as a basis for the preparation of the financial statements and to establish whether
proper accounting records have been maintained by the company. We shall expect to obtain
such appropriate evidence as we consider sufficient to enable us to draw reasonable
conclusions there from.
The nature and extent of our procedures will vary according to our assessment of the
company’s system and, where we wish to replace reliance on it, the internal control system,
and may cover any aspect of the business’s operations. Our audit is not designed to
identify all significant weaknesses in the company’s systems but, if such weaknesses come
to our notice during the course of our audit which we think should be brought to your
attention, we shall report them to you. Any such report may not be provided to third parties
without our prior consent. Such consent will be granted only on the basis that such reports
are not prepared with the interest with the interests of anyone other than the company in
mind and that we accept no duty or responsibility to any other party as concerns the report.
As part of our normal audit procedures, we may request you to provide written
confirmation of oral representations which we have received from you during the course of
the audit on matters having a material effect on financial statements.
In order to assist us with the examination of your financial statements, we shall request
sight of all documents or statements, including the chairman’s statement and directors`
report which are due to be issued with the financial statements. We are also entitled to
attend all general meetings of the company and to receive notices of all such meetings.
The responsibility for safeguarding the assets of the company and for the prevention of
fraud, error and non compliance with laws rests with yourselves. However, we shall
endeavour to plan our audit so that we have a reasonable expectation of detecting material
misstatements in the financial statements or accounting records, but our examination
should not be relied upon to disclose all such material misstatements or frauds.
lOMoARcPSD|28154144
9. Where appropriate we shall not be treated as having notice, for the purposes of our
audit responsibilities, of information provided to members of our firm other than those
engaged on the audit.
10. Once we have issued our report we have no further direct responsibility in relation
to the financial statements for that financial year. However we expect that you inform us of
any material event occurring between the date of our report and of the Annual General
Meeting which may affect the financial statements.
Other services
11. You have requested that we provide other services in respect of taxation. The terms
under which we provide these other services are dealt with in a separate letter. We will also
agree in a separate letter of engagement the provision of other services.
Fees
12. Our fees are computed on the basis of the time spent on your affairs by the partners and
our staff and on the level of skill and responsibility involved. Unless otherwise agreed, our
fees will be billed at appropriate intervals during the course of the year and will be due on
presentation.
Applicable law
13. This engagement letter shall be governed and construed in accordance with Roman
Dutch law .The Courts of Zimbabwe shall have exclusive jurisdiction relating to any claim,
dispute or difference concerning the engagement and any matter arising from it Each party
irrevocably waives any right it may have to object to an action brought in those Courts, to
claim that the action has been brought in an inconvenient forum, or to claim that those
Courts do not have jurisdiction.
14. Once it has been agreed, this letter will remain effective, from one audit
appointment to another, until it is replaced.
We shall be grateful if you could confirm in writing your agreement to these terms by
signing and returning the enclosed copy of this letter, or let us know if they are not in
accordance with your understanding of our terms of engagement.
Yours faithfully
Recurring audits
An auditor may decide not to send a new engagement letter each year.
However, the auditor may decide to send a new engagement letter where there is:
lOMoARcPSD|28154144
(i) any indication that the client misunderstands the scope and objective of the audit.
(iv) any significant change in the nature and size of the client`s business.
The responsibility rests with management through the implementation and continued
operation of an adequate system of internal control which reduces the possibility of fraud
and error.
While the existence of an effective system of internal control reduces the probability of
misstatements of financial information resulting from fraud and error, there will always be
some risk of internal controls failing to operate as designed.
Any system of internal controls may be ineffective against fraud involving collusion
among employees or fraud committed by management.
The following conditions may indicate the existence of fraud and error:
(a) questions with respect to the integrity or competence of management.
lOMoARcPSD|28154144
The auditor should communicate to management on a timely basis if fraud and error is
actually found to exist or if he believes fraud or error may exist even if the potential effect
on the financial statements is immaterial.
PROFESSIONAL LIABILITY OF AN AUDITOR
Auditors are liable under statute and common law to the shareholders for any
negligent performance of statutory duties.
Auditors are also liable for cases of fraud and defamation in the same manner as
any other citizen.
Negligence if proven to be wilful may constitute a conspiracy with management to
defraud the company or other parties.
Some auditors have found themselves in Court on the criminal charge of fraud
after issuing unqualified reports on financial statements subsequently found to be
misleading.
In respect of the provision of auditing services auditors are liable to compensate
the plaintiff if the plaintiff is able to prove that: (a) A duty of care is owed to the
plaintiff
(b) The audit is negligently performed or the opinion negligently given
(c) The plaintiff has suffered a quantifiable loss as a result of the auditor‟s
negligence.
lOMoARcPSD|28154144
For several years the manager of Kingston Cotton Mills had been exaggerating the
quantities and values of the company‟s stocks so as to fraudulently overstate the
company‟s profits.
This came to light when the company was unable to pay its debts and its true financial
position was revealed.
The auditor had relied on a certificate signed by the manager and ensured that the
amount appearing in the accounts as being as “per manager‟s certificate”.
In line with contemporary practice, the auditor did not physically observe stocks or
attempt to verify the valuation of individual items.
Neither did the auditor reconcile stocks with the opening balance and purchases and
sales made during the year, all of which would have alerted the auditor that something
was amiss.
“I confess that I cannot see that their omission to check his[manager’s] returns was a
breach of their duty to the company. It is no part of the auditor’s duty to take stock. No
–one contends that it is. He must rely on other people for details of the stock in-trade in
hand. In the case of a cotton mill he must rely on some skilled person for the materials
necessary to enable him to enter the stocks-in trade at its proper value in the balance
sheet.
In relation to the auditor‟s responsibilities in general particularly the detection of fraud,
the following points from the judgement of Justice Lopes are important:
“It is the duty of an auditor to bring to bear on the work he has to perform that skill,
care and caution which a reasonably competent, careful and cautious would use. What
is reasonable skill, care and caution must depend on the particular circumstances of
each case. An auditor is not bound to be detective, or as was said, to approach his work
with suspicion or with a foregone conclusion that there is something wrong. He is a
watchdog and not a bloodhound. He is justified in believing in tried servants of the
company in whom confidence is placed by the company. He is entitled to assume that
they are honest, and to rely upon their representations, provided he takes reasonable
care. If there is anything calculated to Excite suspicion, he should probe it to the bottom
but, in the absence of anything he is only bound to be reasonably cautious and careful.
The duties of auditors must not be rendered too onerous. Their work is responsible and
laborious, and the remuneration moderate.
Auditors must not be made responsible for not tracking out ingenious and carefully laid
schemes of fraud, where there is nothing to arouse their suspicion and when those
lOMoARcPSD|28154144
frauds are perpetrated by tried servants of the company and are undetected for several
years by the directors. So to hold will make the work of an auditor intolerable”.
The Kingston Cotton Mill Case laid some fundamental auditing principles such as
the “watch dog” rule and the notion of reasonable skill and care.
A third party (a person who has no contractual relationship with the auditor) may sue the
auditor for negligence and claim damages.
In Herdley Byrne vs Heller & Partners Case [1964] it was stated that a duty of care
exists where there is a special relationship between the parties(where the auditor knew or
ought to have known) that the audited accounts would be made available to and would be
relied upon by a particular person or group of persons.
In Caparo Indusries vs Dickman and others[1990] case it was held that a duty of care
was not owed to potential investors or take over bidders having regard to the lack of
proximity between the auditor and potential investors.
Fidelity accounts had been audited by Touche [Link] alleged that the accounts
overstated profits of Fidelity PLC and that its purchases of shares and take over bid were
all made in reliance on the audited accounts.
AUDIT PLANNING
The auditor should plan the audit work so that the audit will be performed in an effective
manner.
Planning means developing a general strategy and a detailed approach for the expected
nature, timing and extent of the audit.
lOMoARcPSD|28154144
Purposes of planning
1 .Planning helps to unsure that appropriate attention is denoted to important areas of the
audit.
[Link] problems are identified and the work is completed expeditiously.
Extent of planning
Preliminary arrangements
When planning the auditor may discuss audit procedures and the overall audit plan with
management, audit committee and the client`s staff in order to improve the efficiency and
effectiveness of the audit.
General economic factors and industry conditions affecting the entity`s business.
Management competence.
Involvement of experts
Staffing and quality control
Use of another auditor
Audit Programme
The auditor should develop and document an audit programme setting out the nature,
timing and extent of planned audit procedures required to implement the audit plan.
During the course of the audit, the audit plan and audit programme should be revised
where necessary.
1.- Select the names of some new customers from the sales ledger.
Trace to the relevant application forms completed by the customer.
Note that established credit limits are in line with the company`s criteria.
2.- Agree invoice details to the corresponding customer orders and delivery notes for selected
sales transactions.
4 - Check entries in the sales journal with the copies of the invoices paying particular
attention to the dates, names of customers ,the amounts and the nature of the sales.
5 - Check additions of the sales journal including cross additions in analysis columns
lOMoARcPSD|28154144
6 – Check the postings of selected invoices to customer`s accounts in the sales journal.
In performing an audit of financial statements, the auditor should have or obtain knowledge
of the business sufficient to identify and understand the events, transactions and practices
that in the auditor‟s judgement may have a significant effect on the financial statements or
the audit report.
The auditor can obtain knowledge of the industry and the entity from a number of sources
that include:
ISA 230 Documentation states that the auditor “should document matters which are
important in providing evidence to support the audit opinion and evidence that the
audit was carried out in accordance with International Standards on Auditing.
Working papers should be “sufficiently complete and detailed to provide an overall
understanding of the audit”.
Working papers should record:
lOMoARcPSD|28154144
All companies should maintain internal controls that will provide reasonable assurance
that fraudulent financial reporting will be prevented or subject to early detection.
Internal control is a process, effected by an entity‟s board of directors, management
and other personnel, designed to provide reasonable assurance regarding the
achievement of objectives in the following categories:
(a) reliability of financial reporting.
(b) compliance with applicable laws and regulations. (c) effectiveness
and efficiency of operations.
Before commencing an audit on an entity‟s financial statements, the auditor must have
a thorough understanding of the entity‟s accounting system.
Control Procedures
Control procedures are those policies and procedures in addition to the control
environment, that management has established to ensure as far as possible, that
specific entity objectives will be achieved.
(c ) Physical Controls
CONTROL ENVIRONMENT
The control environment means the overall attitude, awareness and actions of
management regarding internal control and its importance in the entity.
Numerous factors comprise the control environment.
Amongst these are:
Integrity and ethical values.
Commitment to competence.
Management’s philosophy and operating style.
Organisational structure.
Assignment of authority and responsibility.
Internal Audit.
Use of information technology.
Human resource policies and practices.
Board of directors and audit committee.
Internal controls can provide reasonable assurance to management and the board of
directors regarding the achievement of an entity’s objectives.
(c ) Collusion
(d) Breakdowns
The auditor should understand and document the internal control system.
Relevant documents and records of the entity should be inspected including
organisation charts, policy manual, charts of accounts, journals and source documents.
To reinforce the understanding of internal control system the auditor should perform
walk through tests.
A few transactions within each major class of transactions is traced through the
transaction trail and the related control policies and procedures are identified and
observed.
Documentation in the working papers may take the form of completed questionnaires,
flow charts and narrative memoranda.
Questionnaires
1. Are there regular meetings of the board Yes Board has nine board
and are minutes of the board prepared on members three of whom
a timely basis? serve on the audit
committee.
1. Does existing personnel policies and procedures Yes Formal job descriptions
result in the recruitment or development of are provided for all
competent and trustworthy employees needed to positions. Normal labour
lOMoARcPSD|28154144
AUDIT MATERIALITY
The auditor should consider materiality and its relationship with audit risk when
conducting an audit.
Information is material if its omission or misstatement could influence the economic
decisions of its users taken on the basis of the financial statements.
Materiality depends on the size of the item or error judged in the particular circumstances
of its omission or misstatement.
Materiality
In designing the audit plan the auditor establishes an acceptable materiality level so as to
detect qualitatively material misstatements.
However, both the amount (quantity) and nature (quality) of misstatements need to be
considered for example failure to disclose the breach of regulatory requirements when it is
likely that the imposition of regulatory restrictions will significantly impair operating
capability.
The auditor needs to consider the possibility of misstatements of relatively small amounts
that cumulatively could have a material effect on financial statements.
The auditor considers materiality at both the overall financial statement level and in
relation to classes of transactions, accounting balances and disclosures.
Materiality should be considered by the auditor when determining the nature, timing and
extent of audit procedures, and evaluating the effects of misstatements.
There is an inverse relationship between materiality and the level of audit risk.
The higher the materiality level the lower the audit risk and vice versa.
When planning for specific audit procedures, if the auditor determines that the acceptable
materiality level is lower, audit risk is increased.
The auditor would compensate for this by:
(a) reducing the assessed risk of material misstatement by carrying out extended or
additional tests of control or
(b) reducing detection risk by modifying the nature, timing and extent of planned
substantive procedures.
The auditor should assess whether the aggregate of uncorrected misstatements that had
been identified during the audit is material.
2
9
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
the auditor‟s best estimate of other misstatements which cannot be specifically identified.
If the auditor concludes that the misstatement may be material, the auditor needs to
consider reducing audit risk by extending audit procedures or requesting management to
adjust the financial statements.
If management refuses to adjust the financial statements and the results of extended audit
procedures do not enable the auditor to conclude that the aggregate of uncorrected
misstatement is not material, the auditor should consider appropriate modification of the
auditor‟s report.
AUDIT RISK
Audit risk is the risk that the auditor will get the audit opinion wrong.
In practice, this nearly always means that the auditor will fail to qualify an audit report
that he should have qualified.
In order for this situation to arise, there needs to be a material error in the accounting
records or the financial statements which was not corrected before the financial statements
were published and which the auditor did not refer to in the audit report.
Audit risk is the product of inherent risk, control risk and detection risk.
integrity of management
competence and commitment of staff
time pressure as a result of unrealistic deadlines being set for reporting dates.
Control risk is the risk that an error which could occur and which individually or when
aggregated with others could be material to the financial statements will be prevented or
detected on a timely basis with the internal controls.
30
Control risks arises because the accounting systems lacks in built internal controls to
prevent inaccurate, incomplete and invalid transaction recording or due to the intrinsic
limitations of internal controls such as collusion among employees or management
overriding controls.
a preliminary assessment of control risk once the auditor has enquired into the accounting
system and has identified controls on which it might be effective and efficient to rely in
conducting the audit.
a final assessment of control risk after the performance of compliance test aimed at
determining whether or not controls to be relied upon by the auditor were performed
adequately as they were designed and they were applied throughout the whole period of
intended reliance.
The auditor would assess control risk as high if internal controls are insufficient to prevent
or timely detect errors.
Detection risk is the risk that the auditor‟s procedures will fail to detect errors which,
individually or when aggregated with others could be material to the financial statements
due to the following:
The level of detection risk the auditor can accept is influenced by the assessment of
inherent and control risks together.
The lower the auditor‟s combined assessment of inherent and control risk, the higher the
detection risk and vice versa.
In order to make use of the model it is important to realise that only some elements of the
model are within the auditor‟s control.
In particular the auditor can do little about inherent risks and control risks.
The auditor can however make detection risk as low as possible.
3
1
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
The auditor will need to do less substantive testing if inherent risk or control risks are low.
If the system of internal control is good then control risk will be low leading to less
substantive testing.
On the other hand the auditor might decide to take no comfort from inherent or control
factors and to base the audit opinion purely on substantive procedures including analytical
reviews.
AUDIT EVIDENCE
Audit evidence means the information obtained by the auditor in arriving at the conclusions
on which the audit opinion is based.
32
The aspects of accounting and internal control systems which the auditor would obtain
audit evidence are:
Design - whether the accounting and internal control systems are suitably designed to
prevent and or detect and correct material misstatements.
Operation- whether the systems exist and have operated effectively throughout the period.
The reliability of audit evidence is influenced by it‟s source and by it‟s nature and is
dependent on the individual circumstances under which it was obtained.
Audit evidence is more reliable when it is obtained from independent sources outside the
entity.
Audit evidence that is generated internally is more reliable where the related internal
controls are effectives.
Audit evidence obtained directly by the auditor is more reliable than audit evidence
obtained indirectly.
Documentary audit evidence is more reliable than oral audit evidence.
Audit evidence obtained from original documents is more reliable than evidence provided
by facsimiles.
The auditor should use one or more of the following procedures in gathering audit
evidence:
Inspection
This consist of the examination of supporting documents, records, or tangible assets for
example the inspection of plant and machinery against the asset register.
Observation
This consists of looking at a process or procedure being performed by others for example
the observation of a stock count.
33
Computation
This consists of checking the arithmetic accuracy of documents and accounting records or
performing independent calculations for example performing a bank reconciliation.
Analytical procedures
This consists of the analysis of ratios, trends and relationships and the investigation of
fluctuations.
Financial information is compared with prior periods, budgets and forecasts and industry
averages.
Relationships are considered between elements of financial and non financial information.
ANALYTICAL PROCEDURES
The auditor should apply analytical procedures as risk assessment procedures to obtain an
understanding of the entity and its environment.
34
Analytical procedures are used for the following purposes:
Extent of use
Extent of reliance
the risk that analytical procedures will fail to identify a material misstatement.
the less significant an account balance or class of transactions, the more reliance
can be placed on analytical procedures.
a reduction in the extent of tests of detail will be justified where significant fluctuations
and inconsistencies have been corroborated.
Income and expenditure accounts tend to be more predictable than balance sheet items.
Non recurring accounting entries such as asset revaluations do not lend themselves to
effective analytical procedures.
If control risk is high more reliance on tests of details for drawing conclusions may be
required.
3
5
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
AUDIT SAMPLING
Audit sampling means “the application of audit procedures to less than 100% of the
items within an account balance or class of transactions to enable auditors to obtain
and evaluate audit evidence about some characteristic of the items selected in order to
form or assist in forming a conclusion concerning the population which makes up the
account balance or class of transactions”.
Sampling risk
Sampling risk relates to the possibility that a properly drawn sample may, by chance,
not be representative of the population.
36
It is the risk that the auditor’s conclusion about internal controls or the details of
transactions and balances based on a sample may be different from the conclusion that
would result from an examination of the entire population.
Non – sampling risk refers to the component of audit risk that is not due to examining
only a portion of the data.
Sources of sampling risk include failing to recognise errors in documents and relying
on erroneous information received from third parties.
Non sampling risk can never be mathematically measured.
Tests of control
The overall purpose of tests of control is to evaluate the effectiveness of the design
and operation of internal controls.
Sampling is applicable only in testing the operation of controls when there is a trail of
documentary evidence of the performance of control procedures.
Each sample tested will have one of two attributes either that the control has been
properly performed or not.
The outcome of testing is known as a deviation rate, representing the proportion of
transaction tested which have not been processed according to laid down procedures.
Substantive tests
Substantive testing refers to details testing either to obtain evidence that an account
balance is not materially misstated or to make an independent estimate of some
amount for example to value stock where there are no records.
A transaction may be tested from the book of original entry to the ledger and finally to
the financial statements.
In carrying out substantive tests, transactions should be traced to supporting
documentation.
Population
Refers to all the transactions from which the auditor wishes to take samples.
The population should consist of consist of homogenous items so that all items will
have an equal chance of being selected.
For tests of control the auditor must consider the possibility that the apparent
population may not be homogenous with respect to the design of the internal control
system.
Audit efficiency is improved by only testing very small samples of low value items
and larger samples from high value items.
3
7
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
Sampling Unit
Statistical Sampling
In non-statistical sampling, the auditors use judgement both to determine sample size
and to interpret results against the audit objective.
The choice of non statistical or statistical sampling does not affect the selection of
auditing procedures to be applied to a sample.
Sampling Methods
The test objectives and sample size will be determined in the audit programme.
The audit staff members involved in the audit will then be required to select the
required number of individual samples of the population for testing, perform the test
and evaluate the result.
Each transaction should have an equal chance of being selected.
The methods which can be used to select samples for testing are:
The random numbers drawn from the table are not in sequence, which makes drawing
a sample from a sequentially ordered file a time consuming task.
Money unit sampling involves using the amount rather than the items as the sampling
population.
38
Money unit sampling takes each $1 of the population as the sampling unit and then
tests whether it is correctly stated.
Each individual currency unit in the population is given an equal chance of selection.
If a sample of 100 $1m is required from a population of 10 000 $1millions it is taken
systematically by taking each 100th $1m.
The audit test is then applied to the item such as an invoice containing that $1m.
This technique is also referred to as the “ probability proportionate to size sampling,
referring to the fact that the more $1m an invoice contains the more likely it is that one
of the $1m will be selected for sampling.
Disadvantages
(a) It is unsuitable for detecting errors or misstatements in small amounts since smaller
Items are less likely to be sampled.
(b) If detected errors exceed those expected when drawing a sample plan, the auditor is
likely to be forced to conclude that the whole population is materially misstated and
has to conduct further audit work.
(c) The required cumulative addition of the population for purposes of drawing the sample
might not be convenient.
3
9
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
Haphazard selection is a selection process in which the auditor attempts to give all
items in a population a chance of being selected by choosing items haphazardly.
Sometimes this is the only practical method where the population is not ordered in any
numerical sequence.
The auditor must take care to avoid any bias as avoiding the first or last entry on each
page of the ledger.
A tendency to favour items that appear to be easy should also be avoided.
The method is not recommended where other methods are available because the
absence of bias cannot be subsequently evidenced.
40
Risk is the probability that an event or action may adversely affect the organisation or
activity under audit.
Risk management is the process of evaluating and controlling risk to ensure that the
organisation is managed as effectively as possible.
Risk management functions can exist within the organisation to identify, monitor and
measure risk and publish risk management policies.
Internal audit can ensure that it best adds value by using a risk based internal audit
approach that maximises the benefits to the organisation and uses language that line
management can understand.
This means explaining why controls are important on the basis of how they can minimise
the impact of risk materialising.
Working with line management to understand the risks within the activity or organisation.
Identifying in a systematic way the types of risks and the significant and likelihood of
risks materialising.
Assessing controls to manage risk, including those expected against those in place.
Testing controls to ensure that they operate and that they provide effective management of
risk.
Making recommendations to line management for improving the operation, indicating the
type and level of risk exposure.
There is an increasing trend in the outsourcing of internal audit either wholly or in part.
The pressures to provide best value, and to provide competitive tendering have resulted in
internal audit department facing challenges to the provision of an in house service.
4
1
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
The internal audit function is responsible for evaluating and commenting on the
effectiveness of risk management, control and corporate governance processes.
However management remains responsible for identifying and managing risk, reporting
on risk and ensuring that the right policies are in place.
An internal audit charter approved by the board of directors, and the audit committee
should be put in place setting out the objectives, scope and authority of internal audit.
This should include a statement requiring access to everywhere in the organisation.
Internal audit is part of the overall control framework of the organisation.
Independence
Internal and external auditors should work closely together with reliance by external
auditors on the work of internal audit.
This is dependent on the two functions having a common understanding of the
organisation‟s needs.
Corporate governance is the system by which business corporations are directed and
controlled.
42
It is concerned with holding the balance between economic and social goals and between
individual and communal goals.
The corporate governance structure specifies the distribution of rights and
responsibilities among different participants in the corporation, such as the board,
managers, shareholders, and other stakeholders and spells out the rules and procedures
for making decisions on corporate affairs.
By doing this, it also provides the structure through which the company objectives are
set, and the means of attaining those objectives and monitoring performance.
Corporate governance set a yardstick by which all companies should seek to be
measured. The code of corporate practices and conduct is based on principles of
openness, integrity and accountability. Internal audit is thus there to assist the
company in measuring their compliance to governance issues.
Internal Audit assists the Audit committee to perform its duties without limitations and
provides a valuable service by helping as follows:
Provide the audit committee with orientation, training, and support regarding the
committee‟s charter, operations, roles and responsibilities.
Allow reasonable amount of time for the audit committee to hear about control
systems from both external and internal auditors.
Provide the audit committee with leading-edge information on new laws, new
resources, and other developments that affect the governance process as well as the
organization as a whole.
Making recommendations concerning risk management and governance process.
In essence therefore, Internal Audit should be seen as „the eye of the Board‟ confirming to the
Board that:
The systems and procedures of internal control are adequate, well designed and work
in practice to safeguard and secure the assets and resources of the
organization.
The board is informed about, and has considered, all relevant risks.
The board receives all the information relevant to its role and that the information is
accurate, reliable and complete.
AUDITING INVENTORIES
Work in progress
Finished goods
Audit objectives
For entities that rely entirely on stock take at or near balance sheet date, the auditor
will adopt a predominantly substantive approach in obtaining evidence as to the
existence and completion assertions.
The auditor should understand the accounting and internal control system relating to
the recording of stock transactions.
Reliance should be placed only on records of purchases in obtaining evidence as to
valuation.
For manufacturing entities it will be necessary to obtain an understanding of the
procedures for determining recording costs of production.
Manufacturing entities need to keep records of stocks of raw materials, work in
progress and finished goods.
Internal Controls
[Link] stock records should be maintained detailing purchases and issues of stocks.
Use of a computer system in recording stocks will enable automatic updating of stock
records after receipts and issues.
[Link] stock purchases should be authorised and made on an official purchase order .
Purchase orders should be signed and sequentially numbered.
44
Valuation of inventories
Inadequate or inappropriate inventory held to meet the demands of sales and production.
High inventory levels resulting in poor cash flows and financial loss.
Obsolete inventory held or incorrectly supplied to customers resulting in financial loss and
damage to reputation.
4
5
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
It is not the responsibility of the auditor to count inventory but the client‟s.
Where the count is not attended on the date planned due to unforeseen circumstances, the
auditor should take or observe some physical counts on an alternative date if possible.
Where attendance is impracticable, due to the nature or location of the inventories,
auditors should consider whether sufficient evidence is available to avoid a qualification
of the audit report.
The auditor should familiarise himself with the nature, volume and location of inventories
and consider the timing of the inventory count.
The auditor should arrange third party confirmation of inventories held by third parties.
AUDITING ACCOUNTS RECEIVABLE
When the accounts receivable are material to the financial statements and when it is
reasonable to expect debtors to respond, the auditor should plan to obtain direct
confirmation of account balances of individual entries in an account balance.
Direct confirmation provides reliable audit evidence as to the existence of debtors and the
accuracy of account balances but does not ordinarily provide evidence as to the
collectability of balances or as to the existence of unrecorded balances.
When it is expected that debtors will not respond, the auditor should plan to perform
alternative procedures.
Audit Procedures
46
Analytical procedures
One of the most effective methods for confirming receivable balances is by the auditor
communicating directly with the customers of the client to seek direct confirmation of the
amounts outstanding.
This provides reliable evidence as to the existence of receivables and the accuracy of
recorded balances.
Letters are sent by the auditor and customers are requested to reply directly to the auditor.
When management requests the auditor not to contact a customer the auditor should
consider whether there are valid grounds for such a request.
This can arise where there are disputes between the client and the customer and requests
for confirmation may aggravate sensitive negotiations.
If no other evidence is available, the auditor might have to consider qualifying the audit
opinion.
Forms of confirmation.
4
7
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
The circularisation of debtors should be carried out at the year end as this provides
evidence of the balance sheet figure.
There are two types of confirmation:
Positive confirmation – a customer is asked to confirm to the auditor directly or
indirectly if he agrees or disagrees with the balance.
Negative- customer only asked to respond if he disagrees.
This method may be appropriate where there are a large number of small balances and
the system is well controlled.
Positive confirmation provides more reliable evidence than negative confirmation.
The choice depends on the auditor‟s assessment of risk.
The positive form is preferred when control risk is high.
Customers to be circularised should be selected by the auditor from a sales ledger listing
agreed to the general ledger control accounts.
Particular attention should be given to:
old accounts.
accounts written off during the period under review.
accounts with credit balances.
accounts with nil balances.
accounts which have been paid by the date of examination.
30 April 2006
Dear Sirs
Confirmation of indebtedness
As part of their normal audit procedures we have been requested by our auditors,
Ernest and Young, to ask you to confirm directly to them the balance on your account
with us as at 31 March 2005. We enclose a statement of your account up to that date.
48
If you are in agreement with the balance shown please sign this letter in the space
provided below and return it direct to Ernest and Young.
If you disagree with the balance, please send this letter to our auditors showing details
of the items making up the difference in the space provided below.
Please note that this request is made for audit purposes only, and remittance should be
made to us in the normal way.
Yours faithfully
I.T. Ruvando
Cash and bank balances are the most liquid assets and are therefore subject to a high
risk of misappropriation.
The auditor should ensure that the audit procedures minimise the risk of this occurring
undetected.
Audit Objectives
Procedures
The auditor should obtain a bank letter from all banks at which accounts were
open at any time during the year.
This procedure should be followed even if the client has changed their bank during
the year and closed old accounts.
Bank letters should be checked against other audit evidence, to ensure that they are
consistent.
Where there is any inconsistency, either in respect of a balance or in respect of
other information, the bank should be approached again to confirm the information
contained in the bank letter.
Letters should be sent to the banks at least two weeks in advance of the date of
confirmation.
4
9
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
The auditor should obtain and prepare bank reconciliations from all accounts and
complete the following audit tests:
The bank balances should be checked to the bank statement and bank letter.
The cash book balance should be checked to the nominal ledger.
Uncleared items should be checked to after date bank statements noting the dates
items cleared.
Any item that have taken longer to clear should be followed up.
The auditor should obtain explanations and substantiate all adjustments on the
bank reconciliation.
Cut off testing should be undertaken by reviewing the paying-in book and
Cheque stubs to ensure that receipts and payments have been recorded in the
correct period.
Where the client receives cash income the auditor should ensure that un banked
takings before and after the year end have been accounted for in the correct period.
All cash should be promptly banked.
Cash count
Where the client has material cash balances the auditor should carry out a cash count.
The following procedures should be undertaken:
Cash should be counted in the presence of a member of the client’s staff who is
responsible for cash and all cash balances should be counted at the same time.
The member of staff should be asked to sign to confirm the amount counted.
The cash balance should be agreed to the nominal ledger.
Explanations should be obtained for any material differences.
Cash count should be undertaken at the year end at the same time when a stock take is
undertaken.
Internal Control
The duties of the person writing up the Cash Book should be separated from the
person responsible for making payments or handling receipts and checking bank
reconciliations.
Opening of a new bank account should only be possible with the authorisation of the
board of directors.
There should be adequate security over blank cheques and under no circumstances
should signed cheques be kept.
Cash book balances should be regularly reconciled to the nominal ledger.
Cheques should be dispatched immediately after signature and not returned to the
person who prepared them.
A senior member of staff should independently check bank reconciliations.
Cash counts should be undertaken on a regular basis. Petty cash vouchers should be
authorised.
50
The auditor should review material receipts and payments in the final month of the
year and for a reasonable period after the year end to assess whether they appear
unusual.
Investigate delays in banking receipts.
The auditor should investigate delays in the presentation of cheques and this may
indicate that cheques are being held back.
Risks
Cash and bank are financial assets and there is a primary risk of financial loss because of:
Inappropriate or inadequate banking arrangements for the area under review resulting
in financial loss.
Inappropriate or inadequate banking arrangements for the area under review resulting
in loss or overdraft.
Bank reconciliations
Verification
5
1
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
TANGIBLE ASSETS
Audit Objectives
Audit Procedures
The auditor should determine the most appropriate procedures for the particular
circumstances of the particular client.
The auditor should select a sample of fixed assets from the fixed asset register or any
record of assets maintained including additions during the year.
Property
The auditor should inspect title deeds to ensure that the client’s name is shown on
deeds.
The description of land should be the same as shown on the balance sheet.
Where property is mortgaged the auditor should verify the deeds with the lender.
52
The auditor should write to the lender asking for specific details of the mortgaged
property and confirm that the client is the registered owner of the property.
The auditor should ensure that finance leases are capitalised and shown as assets in the
balance sheets.
The auditor should review loan agreements to determine if any assets have been
pledged as security.
If costs brought forward from earlier years have been audited, the auditor should
concentrate on purchases during the current year.
The auditor should ensure that additions are audited only if they are material.
The auditor should ensure that the client has claimed capital allowances on capital
expenditure.
The purchase invoices should be traced to entries in the ledger accounts.
The existence of the tangible non-current assets should be verified by the auditor.
The auditor should examine a sample of assets to test the existence of such assets.
Where physical verification is not possible because an asset is not available or is
inaccessible, the auditor should confirm with third parties for example insurers.
Revaluation
Where assets have been re-valued the auditor should consider whether the revaluation
has been performed by a third party.
(i) whether the valuer is professionally qualified and independent of the client.
(ii) whether any assets were excluded.
(iii) whether the basis of the valuation comply with IAS 16 Property , Plant and
Equipment that is at the current cost or at market value at the balance sheet date.
(iv) whether the useful economic life of the asset should be revised.
(v) whether the disclosures are adequate.
(vi) whether the valuers were given all relevant facts.
(vii) whether the valuation is reasonable compared to the auditor’s knowledge of the
client.
5
3
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
Where a revaluation has occurred the auditor should ensure that any revaluation
surplus or deficit is correctly treated.
The increase or decrease should be reflected in the revaluation reserve.
If this results in a reserve with a deficit then the balance should be written off or
charged to the profit and loss account.
The auditor should consider whether any events have occurred after the date of
valuation that are likely to affect the value and whether any adjustment is required.
The auditor should ensure that historical cost information is kept to allow disclosure of
the historical cost equivalent of re-valued assets.
Depreciation
The auditor should assess the reasonableness of depreciation charges for categories of
fixed assets when compared to the accounting policy and previous audit experience
with the client.
Ensure or consider whether depreciation policy has been consistently applied.
Procedures
Analytical Procedures
INVESTMENTS
Long term investments should be included in the balance sheet at cost, less any
impairment, or at market value.
54
Audit Objectives
Audit Procedures
The auditor should inspect documents of title where these are held by the client or
obtain confirmation from third parties that they are holding such documents on the
client’s behalf.
Details of the investments should agree to the client’s records and it should be clearly
shown that the client is the beneficial owner.
All rights issues or conversions should be correctly accounted fro and reflected in
share certificates.
The auditor should obtain details of any investments that have been pledged as
security via discussions with management, reviewing bank letters or similar
documents.
Examine details for dividends and interest income received.
The auditor should ensure that any holdings are properly classified as subsidiaries or
as associates where appropriate.
If the client is a parent undertaking the auditor should ensure that consolidated
financial statements are prepared.
The auditor should review contract notes and purchase agreements.
5
5
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
The auditor should agree details of any disposals to the contract note or other relevant
documentary evidence.
All disposals should be properly authorised.
The auditor should test for the updating of the nominal ledger after the disposal of
investments.
The nominal ledger should be credited after the sale of an investment.
If there are any doubts regarding the independence of the broker the auditor should
consider if the selling price for unlisted investments is reasonable.
The auditor should ensure that all related income has been properly recorded.
This can be achieved by comparing expected income on fixed rate investments with
actual income reported.
Analytical Reviews
Compare investments held during the current period with investments held during the
previous financial year.
Compare expected income with actual income from investments.
Wages and salaries expenditure is often substantial and material to the financial
statements.
Wages and salaries is a debit balance and therefore the auditor should ensure that the
expense item is not overstated.
Objectives
(a) To ensure that wages costs are not overstated in the financial statements.
(b) To ensure that all paid employees exist and work for the client company.
(c) To ensure that payroll costs are accurately stated.
(d) To ensure that regulations relating to PAYE and National Insurance have been
complied with.
56
Internal Controls
Audit Procedures
The auditor should select a sample for testing from the payroll.
Where the number of employees is small the auditor should test all transactions in a
particular month or week.
Prepare a summary of wages and salaries giving details of the wages and salaries and
the number of employees month or week by week.
Trace the totals from the payroll to the nominal ledger.
Trace the net to the cash book.
Trace a sample of payments made and agree the details back to the personnel records.
For starters the auditor should ensure that wages have only been paid from the actual
starting date.
For leavers the auditor should ensure that wages were paid up to the date of leaving.
The auditor should enquire on any unclaimed wages and verify their reasonableness.
Re-perform the wages calculations for a sample of employees including starters and
leavers.
Ensure that proper authorisation has been obtained for any deductions other than
PAYE, Pension and National Insurance.
Where applicable the auditor should check hours to time records.
The auditor should ensure that all overtime has been authorised.
Examine directors’ emoluments paid and payable including benefits in kind to ensure
that they have been accounted for correctly and full payment has been made for any
liability in respect of PAYE.
The auditor should check the system to ensure that all relevant forms have been
completed and submitted to tax authorities.
Ensure PAYE has been applied to all employees including payment to casual
employees, part time employees and commission.
Analytical Procedures
5
7
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
The list should also include details of gross wages, deductions, net wages and national
insurance.
Ascertain the average number of employees and calculate average wages.
Compare annual wage bill with budget.
Analyse wages according to departments.
AUDITING PURCHASES AND EXPENDITURE
Expenditure
The audit objectives when auditing expenditure are to ensure that expenditure is correctly
classified, authorised and accurately disclosed.
Procedures
The auditor should select samples for testing from the nominal ledger.
The details of the samples should then be traced to supporting documentation checking the
following:
that the payment of the invoice is properly authorised.
that the invoice is correctly classified.
that the totals on the invoice are correct.
that the details on the invoice have been agreed to the goods received notes and orders.
that the invoice has been paid.
that the paid cheque is made out to the company specified on the invoice, and is signed
by an authorised signatory.
Controls
Purchases
Purchased goods or services are only ordered as necessary for the proper conduct of the
business operations and are ordered from suitable suppliers.
Goods received are effectively inspected for quality, quantity and condition.
Invoices and related documentation are properly checked and approved.
All valid transactions relating to purchases are accurately recorded in the accounting
records.
Receipt of goods
5
9
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
The invoice should be checked against the order and the Goods Received Note. The
invoices should be signed as approved for payment by a responsible official independent
of the ordering and receipt of goods.
A record of goods returned should be kept and checked to the credit notes received from
suppliers.
Details of credit notes should be agreed to the supplier‟s invoices.
All returns should be posted to the purchases returns ledger.
Tests of control
Tests of control should be drawn up so as to check that control procedures are being
applied.
The auditor should list the documents in a transaction cycle and generate appropriate
tests of control for each document:
1. Purchase order
2. Purchase Invoice
Substantive procedures
60
Purchases can be made on credit and thus the purchases cycle includes control objectives
for payables.
Audit objectives
Audit Procedures
The auditor should select a sample of creditors from the creditors’ ledger.
The auditor should select accounts with a lot of activities during the financial year.
The sample should also include accounts with nil balances.
The supplier should be asked to confirm the balance outstanding giving details of the
invoices still outstanding.
The auditor should review creditors’ reconciliations
Creditors’ reconciliation should be agreed to supplier’s statements.
If suppliers statements are not available the auditor should agree the balances to the
confirmations from creditors.
Balances on the suppliers’ accounts should be traced to the purchases account and the
purchases ledger.
The auditor should review invoices received and amounts paid after the year end to verify if
any represent creditors that should have been included in the current financial year. Select
accounts with debit balances in the control account before the year end and review
evidence of payments, purchases returns and other supporting documentation.
Review transactions recorded in the next month after the year end to identify any material
returns which should be adjusted for within the financial statements.
6
1
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
Analytical Procedures
Accruals
AUDITING REVENUE
The objective when auditing income is to ensure that income from all sources have
been fully recorded that is the income of the entity has not been under or overstated.
The auditor should ensure that all items are processed in the correct period.
Audit procedures
62
The auditor should first ascertain all the major sources of income, how they are recorded
and their respective importance in the accounting system.
Where any other material source of income has been identified this should be traced to
supporting documentation.
The auditor should then check that no changes have been made to the system and that there
are no new sources of revenue.
Detailed tests should be used and the auditor should ensure that a sample is selected from
the earliest stage in the recording process.
Records examined need to be complete and the auditor should extend procedures by
examining records independent of the sales recording system.
Such records include despatch notes, customer orders and transfers of goods from stock.
Details should be traced from the source document through to the sales invoices. Invoices
should be agreed through to the day books, nominal ledger, sales ledger and the system of
recording debtors.
The auditor should ensure that the items are being accounted for in the correct period.
Where pre-numbered invoices are used the auditor should check the sequence and
investigate missing items.
Where the client deals in cash the auditor should ensure that cash sales are banked regularly
and in accordance with the entity‟s procedures.
Where there are material cash sales a cash account should be prepared.
The auditor should also select a sample of till rolls or sales invoices and trace them to
supporting documentation.
Where any other material source of income has been identified this should be traced to
supporting documentation to ensure that it is correctly described and fully accounted for.
6
3
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
The following types of income could be material in the client‟s financial statements:
rental income – the auditor should trace to lease agreements
interest on overdue accounts
income from insurance claims
investment income
The auditor should consider whether there are any factors which could result in turnover
not being recognised in the correct period for example:
the date when title of goods pass.
the date that the goods leave the client‟s premises.
Internal Controls
Controls are very important in a sales system to ensure that all sales are fully recorded.
The types of internal controls that may exist are as follows:
(a) pre-printed and sequentially numbered invoices.
(b) invoices being raised in a department separate from the sales department.
(c) goods should only be allowed to leave premises with a valid despatch note.
(d) access to the despatch area is restricted to those staff working within the department.
(e) regular stock takes to ensure that the records agree to goods despatched notes.
(f ) despatch notes are independently checked to invoices.
(g) customer orders are controlled and unfulfilled items followed up.
The auditor should identify the controls in existence and design tests to ensure that they are
operating effectively before reducing the level of detailed testing.
Analytical procedures
Share Capital
There are many distinct types of shares of limited companies, but capital is most often
divided into preferred and ordinary shares.
The rights of the respective shareholders are governed by legislation, contract and the
company‟s constitution.
Preference shares are entitled to a fixed dividend out of profits.
The surplus profits after such payments belong to the ordinary shareholders.
64
Share capital represents part of the capital invested in the company by its shareholders.
Reserves represent the balance of net assets accruing to the shareholders and may include
part of past issues of share capital (share premium), retained earnings and revaluation gains
on the revaluation of non-current assets.
Auditing procedures
Sampling would not be appropriate when auditing share capital and reserves.
Check authorised capital limit to legislation and company constitutional documents.
Check changes to issued capital in the year and agree to board minutes.
Changes in share capital are likely to be a material transaction which is subject to special
legal requirements.
Trace all transactions involving cash to the cash book and bank statement.
Ensure that any necessary registrations have been made and that the company‟s register of
members has been updated.
Ensure disclosure as either debt or equity.
Ensure that all transactions are legal and share premium has been accounted for properly.
The treatment of reserves can be affected by both legislation and the company‟s
constitution.
Possible categories of reserves include, share premium account, revaluation reserve and
retained income.
The auditors should prepare a schedule of retained reserves showing movements in the year.
Check material movements and ensure compliance with legal regulations.
Ensure all gains and losses have been included in the income statement or other reserves as
appropriate
6
5
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
A contingent asset or liability is “a possible asset or liability that arises from past
events and whose existence will be confirmed only by the occurrence or
nonoccurrence of one or more uncertain future event not wholly within the entity’s
control”.
The auditor should not only examine items that need to be recognised or provided for
within the financial statements, but also any possible contingent assets or liabilities
that have been identified during the course of the audit.
The financial commitments include a number of potential liabilities such as:
Audit Objectives.
Audit Procedures
Review the current funding of any provision schemes and ensure that adequate
provision has been made in the financial statements for any liabilities.
Obtain details of any other liabilities and charges to ensure that adequate provision has
been made where necessary.
The auditor can obtain such information by discussion with employees of the entity.
Review minutes of the board or other management meetings.
Review terms and conditions of any major contracts and agreements.
The auditor should consider whether it is appropriate to send a letter to the client’s
lawyers requesting details of all contingent liabilities noted.
The reply from the lawyers should be reviewed against the disclosures made in the
financial statements.
The auditor should prepare or obtain a schedule of the major insurance policies
maintained.
The schedule should state the amount insured, the premium payable, the period
covered and the date of the last renewal.
The auditor should assess whether the client is adequately insured.
66
Controls
The auditor should consider what controls are in place to ensure that the entity
complies with all relevant laws and regulations.
This may involve that there is a member of senior management responsible for such
compliance who ensures that compliance is maintained.
MANAGEMENT REPRESENTATIONS
The auditor should obtain written representations from management on matters material to
the financial statements when other sufficient appropriate audit evidence cannot reasonably
be expected to exist.
The possibility of misunderstandings between the auditor and management is reduced when
oral representations are confirmed by management in writing.
Written representations requested from management may be limited to matters that are
considered either individually or collectively to be material to the financial statements.
During the course of an audit, management makes many representations to the auditor.
When such representations relate to matters that are material to the financial statements, the
auditor will need to:
seek corroborative audit evidence from sources inside or outside the entity.
evaluate whether or not the representations made by management appear reasonable and
consistent with other audit evidence obtained, including other representations.
consider whether or not the individuals making the representations can be fully expected
to be sufficiently well informed on the particular matters.
6
7
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
If management refuses to provide any representation that the auditor considers necessary
in order to provide sufficient, appropriate audit evidence, this constitutes a scope
limitation and the auditor should express a qualified opinion or a disclaimer of opinion.
In such circumstances, the auditor would evaluate any reliance placed on other
representations made by management during the course of the audit, and consider if the
other implications of the refusal may have any additional effects.
68
A post balance sheet event is an event both favourable or unfavourable which occurs
between the balance sheet date and the date on which the financial statements are approved
by directors.
It is an event which warrants an adjustment to the financial statements or an event which
need disclosure in the financial statements but may not result in an adjustment to the
financial statements.
The audit objective when reviewing post balance sheet events is to ensure that material
adjusting and non adjusting post balance sheet events are identified and correctly treated
and disclosed in the financial statements.
6
9
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
The initial post balance sheet events review should be one of the last exercises that is
undertaken during the audit.
The procedures undertaken during a post balance sheet events review, require review and
enquiry in respect of events that have occurred since the balance sheet date.
The auditor should review the Cash Book, invoices and bank statements, minutes of
meetings and major contracts to ensure that nothing has occurred since the year end
which should be disclosed or provided for within the financial statements.
The auditor should discuss the situation with management to ensure that all material
items have been identified.
The auditor should consider whether the client has effective procedures to ensure that
all adjusting and non adjusting events have been identified.
The auditor should read the management minutes of meetings held since the year end
and enquire about matters discussed at meetings for which minutes are not yet
available.
Before the audit report is signed the auditor should specifically enquire in respect of the
following:
Whether any new commitments, borrowing or guarantees have been entered into.
Whether sales of assets have occurred or are planned.
Whether there has been an issue of new shares or debentures or an agreement to
liquidate has been made.
Whether any events have occurred or are likely to occur which might bring into
question the
completeness of the financial statements.
70
GOING CONCERN
The going concern concept is defined as the assumption that the enterprise will continue
in operational existence in the foreseeable future.
This means that the income statement and balance sheet assume no intention or necessity to
liquidate or curtail significantly the scale of operations.
If financial statements are not prepared on a going concern basis, that fact should disclosed,
together with the reasons for such a treatment.
When preparing financial statements, management must make an assessment of the
enterprise‟s ability to continue as a going concern. The auditor will then consider
management‟s assessment.
Management should generally look ahead at least one year from the balance sheet date, in
assessing the validity of the going concern basis, but there are circumstances in which it is
appropriate to look further ahead.
This depends on the nature of the business and the associated risks.
7
1
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
In the absence of a clear note to the contrary, there is a presumption that the financial
statements have been prepared on a going concern basis.
Indicators of problems
Events or conditions which individually or collectively may cast significant doubt about
going concern are:
(1) Financial
(2) Operating
(3) Other
In planning the audit, the auditor should consider whether there are events or
conditions which may cast significant doubt on the entity‟s ability to continue as a going
concern.
72
The auditor should remain alert of evidence or conditions which may cast significant
doubt on the entity‟s ability to continue as a going concern throughout the audit.
If such events or conditions are identified, the auditor should, in addition to
performing the procedures, consider whether they affect the auditor‟s assessment of audit
risk.
The auditor should evaluate management ‟s assessment of the ability to continue as a
going concern.
The auditor does not have a responsibility to design procedures other than enquiries of
management to test for indications of problems beyond the period of at least twelve months
assessed by management.
Where events or conditions have been identified which may cast significant doubt on the
entity‟s ability‟s to continue as a going concern, the auditor should:
Review management‟s plans for future actions based on it‟s going concern
assessment.
Gather appropriate audit evidence to confirm or dispel whether or not a material
uncertainty exists through carrying out additional or extended audit procedures
considered necessary by the auditor.
Seeking written representations from management regarding it‟s plans for future
action.
Possible procedures
Analysing and discussing cash flows and profit forecasts with management.
Analysing the entity‟s latest available financial statements after the balance sheet date.
Enquiring from the entity‟s lawyers regarding the existence of litigation and claims and the
reasonableness of management‟s assessment of their outcome and the estimate of their
financial implications.
On completion of the detailed audit testing the auditor must now consider whether or
not the organisation is a going concern.
If it is considered that the organisation is not a going concern or that there is some
doubt then the auditor needs to discuss the issues with the organisation‟s management to
determine how the financial statements are best prepared.
The auditor should report going concern problems and if material the auditor may
qualify the audit report.
7
3
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
The auditor should be familiar with the following components of a computer system:
Computer hardware.
74
Computer software.
Data organisation and processing.
Computer Hardware
The CPU comprises the control unit, an internal storage unit and an arithmetic logic unit.
The control unit is usually the “processor” and it directs and co-ordinates the entire
computer system.
The arithmetic logic unit performs the required calculations (additions, subtractions,
multiplication and division).
Keying Devices (keyboards, point of sale systems, touch screens), pointing devices
(touch pads track balls, the mouse) and other devices such as (optical character recognition,
bar code readers, magnetic ink character readers and voice recognition devices.
Bar code readers are connected to a computer that records the data, prepares a
document and stores information.
Bar code readers are commonly used to record the movement of goods in and out of
stock. They are also incorporated into cash registers or point of sale computers connected
to price files stored on the computer.
Computer Software
Software falls into two categories: systems software and application software.
Systems software
7
5
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
Application software
Transaction files
1. Floppy disks
Are removable and useful for archiving, off site storage and for software distribution.
2. Magnetic tape
3. Compact Disk
Is a removable medium and has a much larger storage capability than a floppy disk.
76
Transaction files contain details of individual transactions which affect a master file,
for example credit sales transactions affect the debtors master file.
Transaction files are created for control purposes primarily for back up in case of error
or computer malfunction.
Master files
Internal Controls
The use of computers to process information and generate much of the output is likely
to affect the entity‟s internal control system.
The overall audit objective in a computer information system environment however,
does not change.
The existence of a computer will affect the client‟s inherent and control risk.
The auditor should consider whether specialised computer information system skills
are required in the audit.
Internal controls may be divided into:
Application controls are designed and implemented to detect errors before, during and
after processing.
7
7
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
These controls are designed to provide reasonable assurance that the recording,
processing and reporting of data by the computer system are properly and accurately
performed.
The auditor must consider these controls separately for each significant application
such as invoicing customers and preparing payroll cheques.
Input controls are of vital importance because most errors occur at this point. Data
received for processing should be properly authorised and complete.
Incorrect data should be rejected by the computer and resubmitted after correction.
Individual transactions may be authorised in the form of a signature or stamp on the
source document.
The system should produce control totals known as batch totals at the end of each day
of processing.
This control includes calculation of record totals that is the number of documents
processed and financial totals computed from the source document.
Management should design controls to ascertain that input data have not been lost,
added, duplicated, or changed during the processing or between departments.
Data should be checked for sequence if possible, for example consistency of receipt
numbers.
Processing controls are designed to provide reasonable assurance that computer
processing has been performed as intended for the particular application.
Processing errors should be identified and corrected on a timely basis.
Reports from the computer should be obtained before and after processing of
transactions for comparison.
Processed data should be printed for visual inspection to determine if processing is
correct.
Only authorised personnel should be able to obtain the output from the computer after
processing.
Output totals that are generated by the computer programs should be reconciled to
input and processing totals.
Source documents should be compared to processed information.
78
Test data involves the auditor using a sample of data to assess whether logic errors
exist in a program.
The review of application software will provide information about internal controls
built in the system.
During the audit the auditor should obtain sufficient, relevant and useful evidence to
achieve the audit objectives effectively.
With systems having different hardware and software environments, different data
structures, record formats and processing functions, it is almost impossible for the
auditor to collect evidence without a software tool to collect and analyse the records.
Computer Assisted Audit Techniques facilitate data collection, analysis and sampling.
7
9
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
However this places more problems to the audit because electronic transactions take
more time to verify.
(b) Auditability
The use of EDI alters the traditional audit trails.
Source documents and associated paper based reports such as purchase orders,
invoices, cheques and goods received notes may be eliminated.
Evidence of authorisation of orders such as a signature or initials will no longer exist.
Unauthorised individuals may initiate transactions or modify audit trails.
There is a possible loss or contamination of data since records are kept in magnetic
media.
Messages may be read by unauthorised persons.
(c ) Application failures.
Application failures expose clients to potential material losses.
Contingent plans are needed to provide for quick recovery and reduce the effects of
power failures.
(d) Potential disclosure of confidential information to unauthorised parties.
(e) Erroneous or deliberate invoicing for services not rendered.
(f) Loss of audit trail as messages are transmitted from one network to another.
(g) Loss of transactions either en route to client entity or due to disruption of data
processing at the third party site.
80
This is an auditing approach where the auditor ignores the data processing functions
and focuses attention on source documents, which form the basis for input into the
computer and printouts produced by the computer.
The computer is accepted as a “black box” that accepts and produces output.
This is an audit approach where the auditor focuses attention on all phases of the
electronic data processing functions.
The auditor studies and evaluates the overall control environment in which
computerised accounting applications are developed, operated and maintained as well
as the specific application controls to ensure that only authorised transactions are
processed.
The final audit report should normally be drafted by the audit manager and signed by
the audit partner.
Auditors‟ reports on financial statements should contain a clear expression of an
opinion, based on the review and assessment of the conclusions drawn from the
evidence obtained in the course of the audit.
Auditors should distinguish between their responsibilities and those of the directors by
including the following in their report:
(i) a statement that the financial statements are a responsibility of the directors. (ii)
a reference to a description of those responsibilities when set out in the financial
statements.
(iii) a statement that the auditor‟s responsibility is to express an opinion on the
financial statements.
The directors are responsible for keeping proper accounting records which disclose
with reasonable accuracy at any time, the financial position of the company to enable
them to ensure that the financial statements comply with the Companies Act and
relevant legislation.
Directors are responsible for safeguarding the assets of the company and hence for
taking reasonable steps for the prevention and detection of fraud and other
irregularities.
Basis of opinion
Auditors should explain the basis of their opinion by including in their report:
(a) a statement as to the basis of their compliance with International Standards on
Auditing, together with the reasons for any departure there from.
82
(iii) considering whether the accounting policies are appropriate to the reporting
entity‟s circumstances, consistently applied and adequately disclosed.
(c) a statement that they planned and performed the audit so as to obtain
reasonable assurance that the financial statements are free from material
misstatements, and that they have evaluated the overall presentation of the
financial statements.
Expression of an opinion
In the auditor’s judgement the effect of the matter is or may be material to the
financial statements and therefore those financial statement may not or do not
show a true and fair view.
8
3
Downloaded by Christine (iamelsy2@[Link])
lOMoARcPSD|28154144
Where there has been a limitation on the scope of the auditor’s work that prevents him
from obtaining sufficient evidence to express an unqualified opinion:
(a) the auditor’s report should include a description of the factors leading to the limitation
on the scope.
(b) the auditor should issue a disclaimer of opinion when the possible effect of a
limitation on scope is so material or pervasive that they are unable to express an
opinion on the financial statements.
(c) a qualified opinion should be issued when the effect of the limitation is not so material
or pervasive as to require a disclaimer and the wording of the opinion should indicate
that it is qualified as to the possible adjustments to the financial statements that might
have been determined to be necessary had the limitation not existed.
A description of factors leading to a limitation enables the reader to understand the
reasons for the limitation.
Where the auditor disagrees with the accounting treatment or disclosure of a matter in
the financial statements and in the auditor’s opinion the effect of that disagreement is
material to the financial statements, the auditor should include in the opinion section
of his report, a description of all substantive factors giving rise to the disagreement
and their implications for the financial statements.
When the auditor concludes that the effect of the matter giving rise to disagreement is
so material or pervasive that the financial statements are seriously misleading, they
should issue an adverse opinion.
The auditor should not express an opinion on financial statements until those financial
statements and other financial information contained in a report of which the audited
financial statements form part, have been approved by the directors and the auditor
have considered all necessary available evidence.
84
The date of an auditor’s report on a client’s financial statements is the date on which
the auditor signed the report expressing an opinion on those statements.
The auditor should sign the audit report after completion of all procedures necessary
to form an opinion on the financial statements including a review of post balance sheet
events.
We have audited the accompanying balance sheet, income statement, and cash flow
statements of Africa Banking Corporation Limited as of 31 December 2005. These
financial statements are the responsibility of the company’s management. Our
responsibility is to express an opinion on these financial statements based on our audit.
In our opinion, the financial statements give a true and fair view of the financial
position of the company as at 31 December 2005 and of the results of its operations and
its cash flows for the year then ended and comply with the Banking Act.
8
5
Downloaded by Christine (iamelsy2@[Link])