CA FINAL NEW COURSE
ADVANCED AUDITING, ASSURANCE AND PROFESSIONAL ETHICS
Chapter-4 (MATERIALITY, RISK ASSESSMENT AND INTERNAL CONTROL)
Solution
Part-A
1. C
2. D
3. C
4. C
5. C
(5 x 1 = 5 marks)
Part-B
A-1 Concept of COSO:
COSO’s Internal Control – Integrated Framework was introduced in 1992 as guidance on how to
establish better controls so companies can achieve their objectives. COSO categorizes entity-
level objectives into operations, financial reporting, and compliance. The framework includes
more than 20 basic principles representing the fundamental concepts associated with its five
components: control environment, risk assessment, control activities, information and
communication, and monitoring. Some of the principles include key elements for compliance,
such as integrity and ethical values, authorities and responsibilities, policies and procedures,
and reporting deficiencies.
Five Components of COSO are as follows:
(i) Control Environment
(ii) Risk Assessment
(iii) Control Activities
(iv) Information and Communication
(v) Monitoring
The COSO Framework is designed to be used by organizations to assess the effectiveness of the
system of internal control to achieve objectives as determined by management. The
Framework lists three categories of objectives as below:
1. Operations Objectives – related to the effectiveness and efficiency of the entity’s
operations, including operational and financial performance goals, and safeguarding assets
against loss.
2. Reporting Objectives – related to internal and external financial and non-financial reporting
to stakeholders, which would encompass reliability, timeliness, transparency, or other
terms as established by regulators, standard setters, or the entity’s policies.
3. Compliance objectives – In the Framework, the compliance objective was described as
“relating to the entity’s compliance with applicable laws and regulations.” The Framework
considers the increased demands and complexities in laws, regulations, and accounting
standards.
(5 marks)
A-2 The Internal Control structure in an organization is referred to as the policies and
procedures established by the entity to provide reasonable assurance that the objectives are
achieved. The control structure in an organization basically has the following components:
1. Control Environment - Control environment covers the effect of various factors like
management attitude; awareness and actions for establishing, enhancing or mitigating the
effectiveness of specific policies and procedures.
2. Accounting System - Accounting system means the series of task and records of an entity by
which transactions are processed for maintaining financial records. Such system identifies,
assemble, analyze, calculate, classify, record, summarize and report transactions and other
events.
3. Control Procedure - Policies and procedures means those policies and procedures in
addition to the control environment and accounting systems which the management has
established to achieve the entity’s specific objectives.
In this regard, the management is responsible for maintaining an adequate accounting system
incorporating various internal controls to the extent that they are appropriate to the size and
nature of the business. There should be reasonable assurance for the auditor that the
accounting system is adequate and that all the accounting information required to be recorded
has in fact been recorded.
Internal controls normally contribute to such assurance. The auditor should gain an
understanding of the accounting system and related internal controls and should study and
evaluate the operation of those internal controls upon which he wishes to rely in determining
the nature, timing and extent of other audit procedures. Where the auditor concludes that he
can rely on certain internal controls, he could reduce his substantive procedures which
otherwise may be required and may also differ as to the nature and timing.
Specific Requirement under SA 315 - “Identifying and Assessing the Risks of Material
Misstatement through Understanding the Entity and its Environment” deals with the auditor’s
responsibility to identify and assess the risks of material misstatement in the financial
statements, through understanding the entity and its environment, including the entity’s
internal control.
(5 marks)
A-3 According to SA-200, “Overall Objectives of the Independent Auditor and the Conduct of an
Audit in Accordance with Standards on Auditing”, the Audit Risk is a risk that Auditor will issue
an inappropriate opinion while Financial Statements are materially misstated.
Audit Risk has two components namely: Risk of material Misstatement and Detection Risk.
The relationship can be defined as follows.
Audit Risk = Risk of material Misstatement x Detection Risk
Risk of material Misstatement: - Risk of Material Misstatement is anticipated risk that a
material
Misstatement may exist in Financial Statement before start of the Audit. It has two components
namely inherent risk and Control risk.
The relationship can be defined as
Risk of material Misstatement = Inherent risk X control risk
Inherent risk: it is a susceptibility of an assertion about account balance; class of transaction,
disclosure towards misstatements which may be either individually or collectively with other
Misstatement becomes material before considering any related internal control which is 40% in
the given case.
Control risk: it is a risk that there may be chances of material Misstatement even if there is a
control applied by the management and it has prevented defalcation to 75%.
Hence, control risk is 25% (100%-75%)
Risk of material Misstatement: Inherent risk X control risk i.e. 40% X 25 % = 10%
Chances of material Misstatement are reduced to 10% by the internal control applied by
management.
Detection risk: It is a risk that a material Misstatement remained undetected even if all Audit
procedures were applied; Detection Risk is 100-60=40%
In the given case, overall Audit Risk can be reduced up to 4% as follows:
Audit Risk: Risk of Material Misstatement X Detection Risk = 10X 40% = 4%
(5 marks)
A-4 In the given case of Acharya Ltd, Auditors, while conducting audit has come across
significant deficiency existing in the internal control system and also auditors wanted to
ascertain that deficiency.
As per SA 265, “Communicating Deficiencies in Internal Control to Those Charged with
Governance and Management “, Indicators of significant deficiencies in internal control include,
for example:
(i) Evidence of ineffective aspects of the control environment, such as:
(a) Indications that significant transactions in which management is financially
interested are not being appropriately scrutinized by those charged with
governance.
(b) Identification of management fraud, whether or not material, that was not
prevented by the entity’s internal control.
(c) Management’s failure to implement appropriate remedial action on significant
deficiencies previously communicated.
(ii) Absence of a risk assessment process within the entity where such a process would
ordinarily be expected to have been established.
(iii) Evidence of an ineffective entity risk assessment process, such as management’s failure
to identify a risk of material misstatement that the auditor would expect the entity’s risk
assessment process to have identified.
(iv) Evidence of an ineffective response to identified significant risks (e.g., absence of
controls over such a risk).
(v) Misstatements detected by the auditor’s procedures that were not prevented, or
detected and corrected, by the entity’s internal control.
(vi) Disclosure of a material misstatement due to error or fraud as prior period items in the
current year’s Statement of Profit and Loss.
(vii) Evidence of management’s inability to oversee the preparation of the financial
statements.
(5 marks)