0% found this document useful (0 votes)
15 views6 pages

Understanding Internal vs External Auditing

The document outlines the roles and responsibilities of internal and external auditors, emphasizing the importance of testing internal controls to ensure reliability and compliance in financial reporting. It discusses audit risk components, including sampling risk, control risk, and detection risk, and the necessity of maintaining independence and objectivity in auditing practices. Additionally, it highlights the significance of effective communication, risk assessment, and the use of data analytics in enhancing audit efficiency and effectiveness.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views6 pages

Understanding Internal vs External Auditing

The document outlines the roles and responsibilities of internal and external auditors, emphasizing the importance of testing internal controls to ensure reliability and compliance in financial reporting. It discusses audit risk components, including sampling risk, control risk, and detection risk, and the necessity of maintaining independence and objectivity in auditing practices. Additionally, it highlights the significance of effective communication, risk assessment, and the use of data analytics in enhancing audit efficiency and effectiveness.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

INTERNAL AUDITING – less independent, employed by  Ensure Reliability: Confirm that financial

the company, to protect the interest of the owners. reporting processes produce accurate and
Focused in company’s transaction and not on its compliant information.
financial statements. Ensures all transactions are
In short, testing internal controls is key to both
properly check and documented before payments are
mitigating risk and streamlining the audit process.
made.
WHEN ARE WE GOING TO TEST THE CONTROL?
EXTERNAL AUDITING - independent to third parties.
Examines the financial statements if his/her client  Internal controls are tested at key points during the
company and certifies its fair presentation. audit to evaluate their design and operating
effectiveness. Typically, this testing is conducted:
PRIMARY OBJECTIVE ON CONDUCTING AN AUDIT:
 During the Planning Phase:
 EXCAVATE, USE PROCEDURES, EXPRESS OPINION,
Auditors assess the overall control
AND ISSUE AN AUDIT REPORT.
environment and identify key controls to
determine the level of risk.
WHAT IS AUDIT SAMPLING?
 At Interim Periods:
 Sampling in auditing is selecting a subset of or Early testing allows auditors to evaluate
balances to evaluate the entire population, controls as they operate throughout the year,
ensuring efficiency and reliability. It can be providing time to address any issues before
statistical (using mathematical methods) or non- year-end.
statistical (based on auditor judgment). Sampling
 Near Year-End:
helps test controls, verify transactions, and assess
Additional testing may occur to confirm that
financial statements without examining every item.
controls have operated effectively up to the
 Selective representatives in audit sampling refer to
reporting date.
the chosen items that best reflect the
characteristics of the entire population. These Testing may also be performed whenever significant
samples are selected based on risk, materiality, changes occur in the control environment. This timing
and relevance to ensure reliable audit conclusions. ensures that auditors can rely on effective controls to
Methods include random selection, systematic reduce the extent of substantive testing and enhance
sampling, and stratified sampling to improve the overall audit efficiency.
accuracy and efficiency.
ANALYTICAL PROCEDURES – evaluate financial data by
WHEN ARE WE GOING TO REQUIRE SAMPLING OR examining relationships, trends, and ratio and compare
NOT? them.
 Substantive sampling is the process of selecting a  INDEPENDENCE VS. OBJECTIVITY
subset of transactions or balances to test the
details of financial assertions (such as existence, INDEPENDENCE refers to the organizational status of
completeness, and valuation). It is used during the internal audit function, while OBJECTIVITY refers to
substantive testing to obtain direct audit evidence. the mental attitude of individual internal auditors.
Techniques can be statistical (using random or Independence is an attribute of the internal audit
stratified methods) or non-statistical (based on function, and objectivity is an attribute of the
auditor judgment), chosen based on the risk and individual auditor.
materiality of the area under review. Results from Independence:
the sample help form conclusions about the entire
population. ◦ It is the freedom from conditions that threaten the
ability of the internal audit activity to carry out its
responsibilities in an unbiased manner.
WHY WE TEST INTERNAL CONTROLS? ◦ It is achieved when the chief audit executive (CAE)
 We test internal controls to ensure that the reports to a level within the organization that allows
systems designed to prevent and detect errors or the internal audit function to fulfill its responsibilities.
fraud are effective. This evaluation helps auditors: ◦ The CAE must report to a level within the
 Assess Risk: Identify areas where organization that has sufficient authority to ensure
misstatements or fraud might occur. broad engagement coverage, due consideration of
engagement outcomes, and appropriate responses to
 Plan the Audit: Determine how much reliance those outcomes.
can be placed on the controls, which influences
the extent of further testing. ◦ The CAE should report functionally to the
organization's board of directors.
◦ Organizational independence facilitates the been if the entire population had been tested.
objectivity of individual auditors. Sampling risk is controlled by using statistical
sampling methods.
◦ For the internal audit function to be independent, it
must be free from interference in determining the o In tests of controls, there are two types of
scope of internal auditing, performing work, and sampling risk:
communicating results.
 The risk of assessing control risk too low (Type II or
Objectivity: beta risk) which means the auditor incorrectly
concludes a control is more effective than it actually
◦ It is an unbiased mental attitude that allows internal
is.
auditors to perform engagements in such a manner
that they believe in their work product and that no  The risk of assessing control risk too high (Type I or
significant quality compromises are made. alpha risk) which means the auditor incorrectly
concludes a control is less effective than it actually
◦ It requires internal auditors not to subordinate their
is.
judgment on audit matters to that of others.
o In tests of monetary values, there are also
◦ Internal auditors should not involve themselves in
two types of sampling risk:
day-to-day operations, make management decisions,
or otherwise put themselves in situations that result in  The risk of incorrect acceptance (Type II or beta
actual or potential conflicts of interest. risk) which means the auditor concludes a recorded
value is not materially misstated when it is.
◦ Objectivity means that an auditor is able to make
impartial, unbiased judgments.  The risk of incorrect rejection (Type I or alpha risk)
which means the auditor concludes a recorded
◦ To ensure objectivity, if an individual moves into the
amount is materially misstated when it is not.
internal audit function from another area of the
organization, the internal auditor may not provide  Non-sampling Risk: This risk occurs when an
assurance services to that area for one year9. The auditor fails to perform their work correctly,
reasoning behind this policy is that the internal auditor regardless of whether they are using sampling. This
would be put in a position of auditing his or her own can happen due to inappropriate audit procedures,
work. misapplication of procedures, or misinterpreting
results. Non-sampling risk is reduced through
◦ Objectivity is a state of mind and is defined as
proper audit planning, supervision, and quality
freedom from bias. It involves the use of facts without
assurance.
distortions by personal feelings or prejudices.
Managing Audit Risk:
INDEPENDENCE relates to the structure and position of
the internal audit function within the organization,  Understanding the Auditee: Internal auditors
ensuring it is free from undue influence, while should understand the auditee's objectives, risks,
OBJECTIVITY relates to the mindset and behavior of and controls before starting an audit.
individual internal auditors, ensuring they make
 Risk Assessment:
unbiased judgments. Both independence and
objectivity are essential for internal audit to provide o Internal auditors should identify and assess
value-adding services. risks, considering both the potential impact
and likelihood of each risk.

o This assessment should consider inherent risks


AR= IR x CR x DR
which are the risks present before any
AUDIT RISK is the risk of reaching invalid audit controls are in place.
conclusions or providing faulty advice based on the
o A risk assessment is a key part of planning an
audit work conducted. It is important to understand
that audit risk exists in both assurance and consulting audit.
engagements. o The risk assessment process also includes
Here's a breakdown of how audit risk is viewed and considering potential fraud risks.
managed, based on the sources:  Professional Skepticism: Internal auditors must
Components of Audit Risk: exercise professional skepticism, which means they
should question information and critically assess
 Sampling Risk: This risk arises when an auditor audit evidence. They should not assume that
uses sampling to evaluate less than 100% of a auditee personnel are either honest or dishonest.
population, and the conclusions drawn from the
sample are different from what they would have
 Gathering Persuasive Audit Evidence: Internal  CONTROL RISK - is the risk that an organization's
auditors should obtain sufficient appropriate audit internal controls will fail to prevent or detect
evidence to support their conclusions and significant misstatements or errors in a timely
recommendations. manner. It is a key component of audit risk. Here's
a breakdown of what control risk entails:
o Sufficiency refers to the quantity of evidence.
 Definition: Control risk is the risk that controls will
o Appropriateness refers to the quality of
not effectively reduce controllable risk to an
evidence, including its relevance and
acceptable level. Controllable risk is the portion of
reliability.
inherent risk that management can directly
 Testing Controls: The operating effectiveness of influence through day-to-day business activities.
controls should be tested to ensure that risks are
 Relationship with Inherent and Residual Risk:
being managed effectively.
o Inherent risk is the risk that exists in the
 Data Analytics: The use of data analytics allows
absence of any internal controls.
internal auditors to focus on high-risk transactions
and provide a higher level of assurance. o Controllable risk is the portion of inherent risk
that management can mitigate with controls.
 Using a Risk-Based Approach: An audit plan should
be based on a risk assessment, and the chief audit o Residual risk is the risk that remains after
executive should consider risks when prioritizing controls have been implemented.
and scheduling audits.
o The goal of implementing controls is to reduce
 Considering Management's Risk Tolerance: controllable risk, and thereby residual risk, to
Internal auditors should understand management's a level that aligns with management's risk
tolerance levels for risks in order to effectively tolerance.
assess and respond to those risks.
 Control Effectiveness and Risk Tolerance: If
 Evaluating Audit Results: Internal auditors must residual risk is higher than the organization's risk
evaluate the results of their audit work to tolerance, it means that controls are inadequate
determine whether risks are being appropriately and/or not operating effectively. Conversely, if
managed and whether controls are operating residual risk is managed to a level below
effectively. management’s risk tolerance, then internal
controls are presumed to be designed adequately
 Proper Communication: Conclusions should be
and operating effectively.
supported by sufficient evidence, and any
limitations of the audit should be communicated  Types of Controls: Controls can be categorized in
clearly. several ways, including:

 Appropriate Use of Sampling Techniques: Auditors o Entity-level controls which operate at the
must select appropriate statistical or non-statistical organization level and include governance and
sampling methods to test controls and monetary management oversight.
values.
o Process-level controls are established by
o Statistical sampling enables the auditor to process owners to reduce the risk that
quantify and control sampling risk. threatens the achievement of process
objectives.
o Nonstatistical sampling relies on the auditor's
judgment to evaluate the population. o Transaction-level controls which reduce risk
related to operational tasks and transactions.
 Audit Risk in Consulting Engagements: Even
though consulting engagements are advisory in o Key controls which are designed to reduce the
nature, audit risk is relevant. Consultants must be risk associated with critical business
aware of risks related to the advice they provide to objectives.
the organization as well as risks to achieving the
o Secondary controls which either mitigate risks
objectives of the engagement itself.
that are not key to business objectives, or
By understanding and effectively managing these partially reduce risk when key controls are
aspects of audit risk, internal auditors can provide ineffective.
valuable assurance and consulting services to their
organizations. o Compensating controls which are designed to
supplement key controls that are ineffective,
or cannot fully mitigate risk on their own.
o Preventive controls which are designed to assessing control risk too low or Type II error)
prevent errors or irregularities from occurring which can lead to an incorrect conclusion
in the first place. regarding risk.

o Detective controls which are designed to By understanding the concept of control risk, internal
detect errors or irregularities after they have auditors can effectively assess and mitigate the risks
occurred. that their organizations face, ultimately contributing to
the achievement of business objectives.
 Internal Auditor's Role:
 Detection risk is the risk that an auditor's
o Internal auditors evaluate the design
procedures will fail to detect a material
adequacy and operating effectiveness of
misstatement or error that exists in an
controls in responding to risks.
organization's financial statements or other
o They also assess if controls are designed and information. It is a component of audit risk, which
operating effectively to reduce controllable is the risk of reaching invalid audit conclusions or
risk to an acceptable level and to provide providing faulty advice.
reasonable assurance that objectives will be Understanding Detection Risk
achieved.
 Detection risk is influenced by the nature,
o If controls are inadequate, the internal auditor timing, and extent of the audit procedures
must communicate that finding so performed.
management can take appropriate corrective
action.  It is the risk that an auditor will fail to find a
problem when it exists, which can lead to an
o Internal auditors must consider if controls are inappropriate conclusion about the financial
excessive, using more resources than health or compliance of an organization.
required.
 Unlike control risk, which relates to the
 Impact of Ineffective Controls: internal controls of an organization, detection
o Ineffective controls can result in the failure to risk is directly linked to the auditor's work and
achieve business objectives. their ability to identify issues.

o They can also expose the organization to Factors Influencing Detection Risk
potential losses, noncompliance with laws, Several factors affect detection risk, and the auditor's
and fraud. goal is to reduce it to an acceptably low level through
 Testing Controls appropriate audit planning and execution:

o Internal auditors perform tests of controls to  Audit Procedures: The effectiveness of the
determine if they are operating as designed. audit procedures that the auditor chooses to
perform directly impacts the level of detection
o If a control is determined to be inadequately risk.
designed, testing the operating effectiveness
of the control is not necessary.  Sampling: If the auditor is using sampling
techniques, there is a risk that the sample will
o Testing is documented in a risk and control not accurately reflect the population. This is
matrix which can be used to show the link called sampling risk, and it is related to
between controls and risk and provide testing detection risk.
results.
 Non-sampling Error: This is the risk that the
o Testing results can be used to evaluate the auditor makes a mistake such as
operating effectiveness of the controls. misinterpreting results or performing
procedures incorrectly, regardless of sampling.
 Control Risk and Audit Risk:
 Auditor Competence and Objectivity: The skill,
o Control risk is a component of audit risk.
experience, and objectivity of the auditor all
o An internal auditor can incorrectly conclude play a critical role in whether misstatements or
that a specified control is less effective than it errors are identified.
really is (risk of assessing control risk too high
 Technology: The use of technology can affect
or Type I error). This may lead to over auditing
detection risk. For example, data analytics can
when it is not required.
help identify patterns or anomalies that might
o An internal auditor can incorrectly conclude a not be apparent through manual procedures.
control is more effective than it is (risk of
 Fraud: The presence of fraud risk impacts o Non-statistical sampling is a subjective
detection risk, as fraud can be intentionally method and the auditor's conclusion is
concealed and can be more difficult to detect based on their judgment.
than unintentional errors.
 Monitoring Internal auditors should monitor risk
Internal Auditor's Role in Managing Detection Risk management processes, to ensure that they
operate efficiently and effectively, as well as
Internal auditors have an important responsibility to
assess the effectiveness of management's
manage detection risk by:
monitoring activities.
 Planning: Careful planning helps to ensure that
Relationship with Other Risks
audit procedures are appropriate for the risks
involved.  Inherent risk is the risk of misstatement that
exists before considering controls.
o Planning includes understanding the
auditee's business, objectives, risks and  Control risk is the risk that internal controls
internal controls. will not prevent or detect misstatements.

o It also involves assessing the potential for  Detection risk is the risk that the auditor will
fraud. fail to detect misstatements.

 Performing Appropriate Procedures: Internal  These three risks (inherent, control, and
auditors should choose appropriate audit detection) combine to determine overall audit
procedures that are likely to detect any material risk.
misstatements. The procedures should be
 If inherent risk and control risk are high,
relevant to the risks and objectives of the
detection risk should be low and more audit
engagement.
work is needed.
 Testing Controls: When evaluating control risk,
In Summary
the auditor should understand and test controls
to determine if they are operating effectively. Detection risk is an important consideration for
This is an important step in determining how internal auditors. It directly impacts the quality and
much testing is required to detect an existing reliability of audit work. By taking appropriate steps,
problem. internal auditors can mitigate detection risk and
provide assurance to their organizations regarding the
 Data Analysis: Internal auditors should utilize
accuracy and reliability of information and
data analysis tools to analyze financial and
effectiveness of controls.
operational data to identify potential issues.

 Professional Skepticism: Maintaining a


questioning attitude helps to ensure that auditors 1. RISK OF INCORRECT ACCEPTANCE
do not rely solely on management's - thought of being right but it’s not reliable to
representations, but seek out objective evidence accept.
to support conclusions. 2. RISK OF INCORRECT REJECTION
 Appropriate Documentation: The auditor should Risk of incorrect rejection, also known as a Type I
keep records of all procedures performed, error or alpha risk, is the risk that a sample supports
findings, and conclusions, to provide a clear audit the conclusion that a recorded amount (for example,
trail. an account balance) is materially misstated when it is
not. In other words, the internal auditor incorrectly
 Quality Assurance: Internal auditors should have
concludes that a recorded value is materially misstated
a system of quality assurance in place to ensure
when it is fairly stated. This type of risk is associated
that their work meets professional standards.
with sampling risk, which arises when an auditor tests
 Sampling and Testing: Internal auditors use both less than 100% of a population.
statistical and non-statistical sampling techniques
Here are some key points about the risk of incorrect
to perform tests on a sample from a population.
rejection:
o When using statistical sampling, the auditor
 Definition: It is the risk that the sample supports
is able to quantify and control the risk of
the conclusion that a recorded amount is
making an incorrect decision about the
materially misstated when it is not. It is the risk of
population based on the evidence from the
under-reliance.
sample.
 Impact on Testing: This risk can lead an internal
auditor to incorrectly conclude that a control is
less effective than it really is, which could cause In summary, the risk of incorrect rejection is a type of
an auditor to overstate the reliance that sampling risk that can lead to inefficiencies and
management can place on the control to reduce unnecessary audit work. It is an important concept for
risk. internal auditors to understand so they can make
informed decisions about the nature, timing, and
 Relationship with Sampling: The risk of incorrect
extent of their testing procedures.
rejection is associated with sampling because
when an auditor tests less than 100% of a
population, there is a chance that the sample
may not accurately represent the population.
This can result in the auditor reaching a different
conclusion than if they had tested the entire
population.

 Tests of Monetary Values: This type of risk is a


concern when performing tests designed to
obtain direct evidence about the correctness of
monetary values, such as the recorded value of
an account balance.

 Probability-Proportional-to-Size Sampling (PPS):


This risk can be increased when using PPS
sampling, which is a modified form of attribute
sampling used to reach conclusions regarding
monetary amounts rather than rates of
occurrence. PPS sampling is most applicable for
testing recorded monetary amounts for
overstatement, especially when the expected
number of individual overstatements in the
population is small. However, PPS sampling
produces overly conservative results when errors
are detected, which increases the risk of
incorrect rejection.

 Classical Variables Sampling: Unlike PPS


sampling, with classical variables sampling, the
internal auditor may need to use a computer
program to cost-effectively design and evaluate a
sample.

 Effect on Sample Size:

o The risk of incorrect rejection has an


inverse effect on sample size.

o This means, if an auditor is willing to


accept a higher risk of incorrectly
rejecting a fairly stated value, then a
smaller sample size can be used.
Conversely, if an auditor wants to reduce
the risk of incorrect rejection, a larger
sample size will be required.

Risk of Incorrect Rejection vs. Risk of Incorrect


Acceptance

It is important to understand how the risk of incorrect


rejection relates to the risk of incorrect acceptance,
which is also a component of sampling risk. The risk of
incorrect acceptance, also known as a Type II error or
beta risk, is the risk that the sample supports the
conclusion that a recorded value is not materially
misstated when it is.

You might also like