0% found this document useful (0 votes)
21 views21 pages

Risk Assessment in Auditing Standards

Chapter 5 of the document focuses on risk assessment in auditing, emphasizing the importance of identifying areas susceptible to material misstatement to ensure effective audit procedures. It outlines the auditor's overall objectives, the necessity of professional scepticism and judgement, and the distinction between audit risk and business risk. Additionally, it discusses the components of audit risk, including inherent risk, control risk, and detection risk, while highlighting the need for auditors to manage these risks to maintain audit quality.

Uploaded by

Ray Rose
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
21 views21 pages

Risk Assessment in Auditing Standards

Chapter 5 of the document focuses on risk assessment in auditing, emphasizing the importance of identifying areas susceptible to material misstatement to ensure effective audit procedures. It outlines the auditor's overall objectives, the necessity of professional scepticism and judgement, and the distinction between audit risk and business risk. Additionally, it discusses the components of audit risk, including inherent risk, control risk, and detection risk, while highlighting the need for auditors to manage these risks to maintain audit quality.

Uploaded by

Ray Rose
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

RTHE CATHOLIC UNIVERSITY OF EASTERN AFRICA

A.M.E.C.E.A
SCHOOL OF BUSINESS
BCOM- INTRODUCTION TO AUDITING (CAC- 312)

CHAPTER 5

RISK ASSESSMENT

Introduction to risk

FAST FORWARD
A risk assessment carried out under the ISAs helps the auditor to identify financial statement areas
susceptible to material misstatement and provides a basis for designing and performing further audit
procedures.

1.1 The overall objectives of the auditor


At all stages of the audit, including during risk assessment, the auditor must bear in mind what the overall
objectives are. The auditor's objectives are given in ISA 200 Overall objectives of the independent auditor and
the conduct of an audit in accordance with International Standards on Auditing. This ISA states that, in
conducting an audit of financial statements, the overall objectives are:
'To obtain reasonable assurance about whether the financial statements as a whole are free from material misstatement,
whether due to fraud or error, thereby enabling the auditor to express an opinion on whether the financial statements are
prepared, in all material respects, in accordance with an applicable financial reporting framework; and to report on the financial
statements, and communicate as required by the ISAs, in accordance with the auditor's findings.'
In order to obtain assurance about whether the financial statements are free from material misstatement, the auditor needs to
consider how and where misstatements are most likely to arise. A risk assessment under the ISAs helps the auditor to ensure
the key areas more susceptible to material misstatement are adequately investigated and tested during the audit. It also helps
the auditor identify low risk areas where reduced testing may be appropriate, ensuring time is not wasted by over-testing these
areas.

Note, each ISA has its own individual objective followed by requirements and explanatory material.

1.1.1 Conducting the audit in accordance with ISAs


Conducting the audit in accordance with ISAs and achieving each individual objective will allow the auditor to achieve the
overall objective stated above. Consequently, ISA 200 requires that the auditor must fully understand and comply with all the
ISAs relevant to the audit. Furthermore, the auditor must go beyond the requirements in the ISA if they consider it necessary in
order to achieve an ISA's objective.

In order to achieve the overall objective, auditors also need to plan and perform the audit with professional
scepticism and apply professional judgement, which we look at in detail in the following section.
The ISAs also deal with the general responsibilities of the auditor, as well as the auditor's further
considerations relevant to the application of those responsibilities to specific topics. If the auditor does not
conduct an audit in accordance with a recognised set of auditing standards (such as the ISAs), important
responsibilities may not be fulfilled.
Furthermore, the auditor needs to be able to refer to globally recognised standards in the audit report. If all
audits are conducted in accordance with standards setting out what is expected of auditors, this means that
users of the financial statements should be able to be as confident in one auditor's opinion as another's.
The fact that audits are conducted in accordance with ISAs also gives regulators of the audit profession a
framework against which to judge auditors. If auditors are not carrying out audits in accordance with ISAs, they
will be prohibited from undertaking audit assignments. The overall effect is that the quality of audit assignments
is maintained at a high standard.

1
1.2 Professional scepticism, professional judgement
and ethical requirements
FAST FORWARD
Auditors are required to carry out the audit with an attitude of professional scepticism,
exercise professional judgement and comply with ethical requirements.

Key terms Professional scepticism is an attitude that includes a questioning mind, being alert to conditions which
may indicate possible misstatement due to error or fraud, and a critical assessment of audit evidence.

Professional judgement is the application of relevant training, knowledge and experience


in making informed decisions about the courses of action that are appropriate in the
circumstances of the audit engagement.

1.2.1 Professional scepticism


ISA 200 states that auditors must plan and perform an audit with an attitude of professional scepticism
recognising that circumstances may exist that cause the financial statements to be materially misstated.

This requires the auditor to be alert to:

Audit evidence that contradicts other audit evidence obtained



Information that brings into question the reliability of documents and responses to enquiries
to be used as audit evidence

Conditions that may indicate possible fraud

Circumstances that suggest the need for audit procedures in addition to those required by
ISAs

Professional scepticism needs to be maintained throughout the audit to reduce the risks of
overlooking unusual transactions, over-generalising when drawing conclusions, and using
inappropriate assumptions in determining the nature, timing and extent of audit procedures
and evaluating the results of them.

Professional scepticism is also necessary to the critical assessment of audit evidence. This
includes questioning contradictory audit evidence and the reliability of documents and
responses from management and those charged with governance.

1.2.2 Professional judgement


ISA 200 also requires the auditor to exercise professional judgement in planning and performing
an audit of financial statements. Professional judgement is required in the following areas:

 Materiality and audit risk


 Nature, timing and extent of audit procedures
 Evaluation of whether sufficient appropriate audit evidence has been obtained
 Evaluating management's judgements in applying the applicable financial reporting framework
Drawing conclusions based on the audit evidence obtained

1.2.3 Ethical requirements


ISA 200 states that the auditor must comply with the relevant ethical requirements,
including those relating to independence, that are relevant to financial statement audit
engagements.

2
1.3 Audit risks
Auditors usually follow a risk-based approach to auditing as required by ISAs. In this approach,
auditors analyse the risks associated with the client's business, transactions and systems which
could lead to misstatements in the financial statements, and direct their testing to risky areas.

1.3.1 How to identify audit risks


A competent auditor needs to be able to identify those risks that may lead to a misstatement in
the financial statements. One of the most important things to realise is what makes a risk an
audit risk (as opposed to a general operational or business risk) is the link to the financial
statements. If an auditor does not maintain a focus on those risks that may lead to a
misstatement in the financial statements, the audit will be a very long process and not at all
efficient.
Imagine you are auditing a manufacturing company (XYZ Co with a profit before tax of Ksh
60 million and the following information comes to light about your client.

'XYZ Co has significant plant and machinery which it uses to make its products. During the year the
efficiency of the company's machinery was improved significantly. This was because a comprehensive
review of each piece of machinery was undertaken and an assessment was made as to whether a
minor repair, extensive refurbishment or a complete replacement was needed. XYZ then took the
appropriate action in each case and spent a total of Ksh 15 million in doing so.'

From the above you can see management had identified a general risk from their point of view –
that the plant and machinery was not efficient enough for the needs of the business. Management
has taken what they consider to be the appropriate action by replacing, overhauling or repairing the
machinery. There may also be further operational risks arising as a result, such as staff not being
used to the new machinery and taking some time to get up to speed.
However, auditors need to look past these and ask themselves how the issues above could
ultimately lead to a misstatement in the financial statements. This will bring out the audit
risks. Where will the repairs, refurbishment and new machinery end up in the financial
statements and what could go wrong? Where should it end up?
Your knowledge of IAS 16 from your earlier studies tells you that the expenditure must
generate future economic benefit in order to be included in non-current assets. Other costs
that do not meet this criterion

3
should be included as repairs in the statement of profit or loss. In our scenario we appear to have some
expenditure on replacement assets, some on extensive refurbishment and some on general repairs.

There is judgement involved here as to whether some of the expenditure is capital or revenue
expenditure and the situation is unlikely to be clear-cut. Therefore, there is a risk that the
Ksh15 million has not been correctly accounted for.
In addition: Amounts included in non-current assets might not actually exist, as they are
really repairs (related assertion is existence of non-current assets).
The repairs expense may be incomplete (or indeed the non-current assets may be
incomplete if expenditure of a capital nature has also been included in repairs).
Perhaps using auditors judgment, the audit risks arising is 'Expenditure on repairs is
incorrectly recorded as non-current assets, resulting in assets that do not exist being
included in the statement of financial position'.

Once the auditor has identified the audit risks, procedures can be put in place in response to that
risk.

1.3.2 The procedural approach


This is in contrast to a procedural approach which is not in accordance with ISAs. In a
procedural approach, the auditor would perform a set of standard tests regardless of the
client and its business. The risk of the auditor providing an incorrect opinion on the truth and
fairness of the financial statements might be higher if a procedural approach was adopted.

1.4 Overall audit risk


Audit risk is the risk that the auditor expresses an inappropriate audit opinion when the financial
statements are materially misstated. It is a function of the risk of material misstatement (inherent risk
and control risk) and the risk that the auditor will not detect such misstatement (detection risk).

In the previous section we looked at identifying individual risks that could lead to misstatements in
FAST FORWARD the financial statements and we referred to these risks as audit risks . The ISAs refer to the individual
risks as the risks of material misstatement.
Each of these individual risks can contribute to the overall audit risk that the auditor expresses
an inappropriate audit opinion when the financial statements are materially misstated.
Now we will consider the concept of the overall audit risk and in particular the audit risk
model. Understanding this model helps the auditor to take action to reduce overall audit
risk to an acceptable level. Where we refer to audit risk below we are referring to the
overall risk that an inappropriate audit opinion is expressed.

4
statements (detection risk). We shall look in detail at the concept of materiality in the next
section of this chapter. Audit risk can be represented by the audit risk model:

Audit risk = Inherent risk × control risk × detection risk

1.4.1 Inherent risk


Key term
Inherent risk is the susceptibility of an assertion to a misstatement that could be material individually
or when aggregated with other misstatements, assuming there were no related internal controls.

Inherent risk is the risk that items will be misstated due to the characteristics of those items,
such as the fact they are estimates or that they are important items in the accounts. The
auditors must use their professional judgement and all available knowledge to assess
inherent risk. If no such information or knowledge is available then the inherent risk is high.
Inherent risk is affected by the nature of the entity; for example, the industry it is in and the
regulations it falls under, and also the nature of the strategies it adopts. We shall look at
more examples of inherent risks later in this chapter.

1.4.2 Control risk


The other element of the risk of material misstatements in the financial statements is control risk.
Key term
Control risk is the risk that a material misstatement, that could occur in an assertion and that
could be material, individually or when aggregated with other misstatements, will not be
prevented or detected and corrected on a timely basis by the entity's internal control.

1.4.3 Detection risk

Detection risk is the risk that the procedures performed by the auditor to reduce audit
Key term
risk to an acceptably low level will not detect a misstatement that exists and that could
be material, either individually or when aggregated with other misstatements.

The third element of audit risk is detection risk. This is the component of audit risk that the auditors
have a degree of control over, because if risk is too high to be tolerated, the auditors can carry out
more work to reduce this aspect of audit risk and, therefore, audit risk as a whole.
One way to decrease detection risk is to increase sample sizes. Sampling risk and non-
sampling risk are components of detection risk.
However, increasing sample sizes and carrying out more work is not the only way to manage
detection risk. This is because detection risk is a function of the effectiveness of an audit
procedure and of its application by the auditor.
Although increasing sample sizes or doing more work can help to reduce detection risk, the
following actions can also improve the effectiveness and application of procedures and
therefore help to reduce detection risk:

 [Link] planning
 [Link] of more experienced personnel to the engagement team
 [Link] application of professional scepticism
[Link] supervision and review of the audit work performed
All the above reduce the possibility that an auditor might select an inappropriate audit
procedure, misapply an appropriate audit procedure or misinterpret the audit results.

5
1.5 Management of audit risk
ISA 200 states that 'to obtain reasonable assurance, the auditor shall obtain sufficient
appropriate audit evidence to reduce audit risk to an acceptably low level and thereby enable
the auditor to draw reasonable conclusions on which to base the auditor's opinion.'
Auditors will want their overall audit risk to be at an acceptable level, or it will not be worth
them carrying out the audit. In other words, if the chance of them giving an inappropriate
opinion and being sued is high, it might be better not to do the audit at all.
The auditors will obviously consider how risky a new audit client is during the acceptance
process and may decide not to go ahead with the relationship. However, they will also
consider audit risk for each individual audit and will seek to manage the risk.
As we have seen above, it is not in the auditors' power to affect inherent or control risk. These
are risks integral to the client, and the auditor cannot change the level of these risks. The
auditors therefore manage overall audit risk by manipulating detection risk, the only element of
audit risk they have control over. This is because the more audit work the auditors carry out,
the lower detection risk becomes, although it can never be entirely eliminated due to the
inherent limitations of audit. The auditors will decide what level of overall risk is acceptable and
then determine a level of audit work so that detection risk is as low as possible.
It is important to understand that there is not a standard level of audit risk which is generally considered by
auditors to be acceptable. This is a matter of audit judgement and so will vary from firm to firm and audit to
audit. Audit firms are likely to charge higher fees for higher risk clients. Regardless of the risk level of the
audit, however, it is vital that audit firms always carry out an audit of sufficient quality.

6
1.6 Business risk
The other major category of risk which the auditor should be aware of is business risk

It is important that you do not confuse the concepts of audit and business risks. Remember – audit risk is focused on the
financial statements of a company, whereas business risk is related to the company as a whole.

2 Materiality
FAST FORWARD
Materiality for the financial statements as a whole and performance materiality must be calculated at
the planning stages of all audits. The calculation or estimation of materiality should be based on
experience and judgement. Materiality for the financial statements as a whole must be reviewed
throughout the audit and revised if necessary.

ISA 320 Materiality in planning and performing an audit provides guidance for auditors in this area and
states that the objective of the auditor is to apply the concept of materiality appropriately in planning and
performing the audit.
ISA 320 does not define materiality (in relation to the financial statements as a whole) but notes that while
it may be discussed in different terms by different financial reporting frameworks the following are
generally the case:
(a) Misstatements are considered to be material if they, individually or in aggregate, could reasonably
be expected to influence the economic decisions of users.
(b) Judgements about materiality are made in the light of surrounding circumstances, and are affected
by the size and nature of a misstatement or a combination of both.
(c) Judgements about matters that are material to users of financial statements are based on a
consideration of the common financial information needs of users as a group.

7
T to be concerned with identifying 'material' errors, omissions and misstatements.
h Both the amount (quantity) and nature (quality) of misstatements need to be considered,
e eg lack of disclosure regarding ongoing litigation is likely to be considered material.
p
To implement this, the auditor therefore has to set their own materiality levels –
r this will always be a matter of judgement and will depend on the level of audit
a risk. The higher the anticipated risk, the lower the value of materiality will be.
c
The materiality level will impact on the auditor's decisions relating to:
t
How
 manyi items to examine
Which
 items
c to examine
Whether
 a to use sampling techniques
What level
l of misstatement is likely to result in a modified audit opinion
Conforming
i amendments to ISA 320 published in 2015 make it clear that auditors must consider the risks of material
m in qualitative disclosures. In doing so, the auditor should consider:
misstatement
p
The circumstances of the entity (eg any business acquisitions or disposals during the period)
 l
The applicable
i financial reporting framework (eg new qualitative disclosures may be required by a new
financialcreporting standard)

Qualitative
a disclosures that are important to the users of the financial statements because of the nature of the
entity (egt liquidity risk disclosures for a financial institution)
i
may make normal materiality considerations irrelevant.
o
n
Materiality has qualitative aspects. Some misstatements may fall under specified
o
benchmarks, but are still considered material overall due to their qualitative effects.
f
Magnitude by itself, without regard to the nature of the item and the circumstances in which the
t
judgement has to be made, may not be a sufficient basis for a materiality judgement. As a result,
h
qualitative factors may cause misstatements of quantitatively small amounts to be material.
i
Examples
s of this are given in ISA 320:
i
Law, regulation or the applicable financial reporting framework affect users' expectations regarding
s
the measurement or disclosure of certain items (for example, related party transactions, and the
remuneration
t of management and those charged with governance).

h
Some disclosures are key disclosures in relation to the industry in which the entity operates (for
a
example, research and development costs for a pharmaceutical company).
 t
Attention is sometimes focused on a particular aspect of the entity's business that is separately
t
disclosed in the financial statements (for example, a newly acquired business).
h
e
2.2 Revision of materiality
a
The level
u of materiality must be revised for the financial statements as a whole if the auditor
becomesd aware of information during the audit that would have caused the auditor to have
determined
i a different amount during planning.
t
If the auditor concludes that a lower amount of materiality for the financial statements as a whole
o
is appropriate, the auditor must determine whether performance materiality also needs to be
revised, rand whether the nature, timing and extent of further audit procedures are still
appropriate.
m A revision to materiality might be required for example if during the audit it appears
that actual
u results are going to be significantly different from the expected results, which were
used to calculate materiality for the financial statements as a whole during planning.

FAST FORWARD

8
4. Assessing the risks of material misstatement

When the auditor has obtained an understanding of the entity, (s)he shall assess the risks of material
misstatement in the financial statements, also identifying significant risks.
.
4.1 Identifying and assessing the risks of material misstatement
ISA 315 says that the auditor shall identify and assess the risks of material misstatement at the financial
statement level and at the assertion level for classes of transactions, account balances and disclosures.

It requires the auditor to take the following steps:


 Identify risks throughout the process of obtaining an understanding of the
entity and its environment
 Assess the identified risks and evaluate whether they relate more pervasively to
the financial statements as a whole
 Relate the risks to what can go wrong at the assertion level
 Consider the likelihood of the risks causing a material misstatement

Key term Assertions are representations by management, explicit or otherwise, that are embodied in the financial
statements, as used by the auditor to consider the different types of potential misstatements that may
occur..

4.2 Significant risks


FAST FORWARD
Significant risks are complex or unusual transactions that may indicate fraud, or other special risks.

Key term Significant risks are those that require special audit consideration.

As part of the risk assessment described above, the auditor shall determine whether any of
the risks are significant risks.
The following factors indicate that a risk might be significant.

 Risk of fraud 
 Its relationship with recent economic, accounting or other developments
 The degree of subjectivity in the financial information
 It is an unusual transaction
 It is a significant transaction with a related party
The complexity of the transaction
Routine, non-complex transactions are less likely to give rise to significant risk than unusual transactions or
matters of management judgement. This is because unusual transactions are likely to have more:

 Management intervention
 Complex accounting principles or calculations
 Manual intervention
Opportunity for control procedures not to be followed
When the auditor identifies a significant risk, if they have not done so already, they
shall obtain an understanding of the entity's controls relevant to that risk.

Answer

9
5 Responding to the risk assessment
The auditor shall formulate an approach to the assessed risks of material misstatement.

The main objective of ISA 330 The auditor's responses to assessed risks is to obtain sufficient appropriate audit
evidence regarding the assessed risks of material misstatement, through designing and implementing
appropriate responses to those risks.
Once the auditor has assessed the risks of material misstatement, there must be a suitable response.

10
Dec 07

11
5.1 Overall responses
Overall responses include such issues as emphasising to the team the importance of
professional scepticism, allocating more staff, using experts or providing more supervision.
Overall responses to address the risks of material misstatement at the financial statement level will be changes to
the general audit strategy or re-affirmations to staff of the general audit strategy. For example:

 Emphasising to audit staff the need to maintain professional scepticism


 Assigning additional or more experienced staff to the audit team
 Providing more supervision on the audit
 Incorporating more unpredictability into the audit procedures
Making general changes to the nature, timing or extent of audit procedures
The evaluation of the control environment that will have taken place as part of the assessment of the client's
internal control systems will help the auditor determine what type of audit approach to take.

5.2 Responses to the risks of material misstatement at the assertion


level
The ISA says that the auditor shall design and perform further audit procedures whose nature,
timing and extent are based on and are responsive to the assessed risks of material misstatement
at the assertion level. 'Nature' refers to the purpose and the type of test that is carried out, which
include tests of controls and substantive tests.
identified risks.
5.2.1 Tests of controls

Key term Tests of controls are audit procedures designed to evaluate the operating effectiveness of controls in
preventing, or detecting and correcting, material misstatements at the assertion level.

When the auditor's risk assessment includes an expectation that controls are operating effectively, the
auditor shall design and perform tests of controls to obtain sufficient appropriate audit evidence that the
controls were operating.
The auditor shall also undertake tests of controls when it will not be possible to obtain sufficient
appropriate audit evidence simply from substantive procedures. This might be the case if the entity
conducts its business using IT systems which do not produce documentation of transactions.
In carrying out tests of control, auditors shall use enquiry, but shall also use other procedures.
Reperformance and inspection will often be helpful procedures.
When considering timing in relation to tests of controls, the purpose of the test will be important. For
example, if the company carries out a year-end inventory count, controls over the inventory count can only
be tested at the year end. Other controls will operate all year round, and the auditor may need to test that
those controls have been effective throughout the period.

Some controls may have been tested in prior audits and the auditor may choose to rely on that evidence of their
effectiveness. If this is the case, the auditor shall obtain evidence about any changes since the controls were
last tested and shall test the controls if they have changed. In any case, controls shall be tested for effectiveness
at least once in every three audits.
If the related risk has been designated a significant risk, the auditor shall not rely on testing done in prior years,
but shall perform testing in the current year.

5.2.2 Substantive procedures

Key term Substantive procedures are audit procedures designed to detect material misstatements at the assertion
level. They consist of tests of details (of classes of transactions, account balances and disclosures) and
substantive analytical procedures.

The auditor shall always carry out substantive procedures on material items. The ISA says that,
12
irrespective of the assessed risk of material misstatement, the auditor shall design and perform
substantive procedures for each material class of transactions, account balance and disclosure.
In addition, the auditor shall carry out the following substantive procedures:
 Agreeing or reconciling the financial statements to the underlying accounting records
 Examining material journal entries
 Examining other adjustments made in preparing the financial statements
Substantive procedures fall into two categories: analytical procedures and tests of details. The auditor
must determine when it is appropriate to use which type of substantive procedure.

Analytical procedures as substantive procedures tend to be appropriate for large volumes of predictable
transactions (for example, wages and salaries). Tests of detail may be appropriate to gain information
about account balances; for example, inventory and trade receivables.
Tests of detail rather than analytical procedures are likely to be more appropriate with regard to matters
which have been identified as significant risks, but the auditor must develop procedures that are
specifically responsive to that risk, which may include analytical procedures. Significant risks are likely to
be the most difficult to obtain sufficient appropriate audit evidence about.

5.3 Examples of responses to audit risks


The best way to understand how the auditor can respond to the risks identified during audit planning is to
consider some examples of audit risks along with an adequate response to each risk.

Examples of risks Possible responses


Risk that inventory has a lower net realisable Examine the instructions to identify slow moving
value than cost and is therefore overstated (eg inventory lines when attending the inventory count.
NRV falls due to the client being in an industry Increase the emphasis on reviewing the year end aged
where tastes/fashions change quickly). inventory analysis for evidence of slow moving
inventory.
Ascertain sales values for items sold post year end that
were in inventory at the year end to ensure their NRV
was higher than the cost recorded as part of the
inventory value in the financial statements.

Examples of risks Possible responses


Assets are desirable / more susceptible to theft Focus on testing internal controls over those assets
leading to a risk that recorded assets do not (including physical controls to prevent theft).
exist (eg inventory/non-current assets). Increase sample sizes for inspecting recorded assets,
ensuring any material assets are verified (in the context
of performance materiality).
Increased risk of revenue expenditure being Obtain a breakdown of related costs and review
incorrectly classified as capital (or vice versa), accounting entries against invoices/details of work done
leading to misstatement of assets/expenses to ensure expenditure is correctly treated as
(eg extensive refurbishment of non-current capital/revenue.
assets where judgement is needed to establish
Perform a detailed review of repairs accounts for any
whether the nature of the work is to enhance
items which should be included in non-current assets.
the asset or repair/replace it).
Review the asset register to ensure only capital items
have been included.
Increased risk of incomplete or unrecorded Perform analytical procedures focusing on comparing
income due to fraud or theft (eg large amounts revenue with expected seasonal/monthly patterns.
13
of cash collected and held prior to banking). If a retail client, perform/reperform a reconciliation of a
sample of till records to actual bankings.
Receipts/invoicing significantly in For a sample of revenue entries recorded prior to the
advance/arrears of providing services or year end, agree the transactions as relating to pre year
goods, therefore leading to an increased risk of end sales by inspecting the contract / other supporting
revenue being in the wrong period (eg deposits documentation.
received in advance, reservation fees, Trace post year end transactions back to a supporting
contracts spanning the year end). contract/documentation to test that revenue was
recorded in the proper period.
For a sample of contracts or GDNs, verify the revenue
was recognised according to the provision of
services/goods.
Perform analytical procedures where monthly revenue is
compared to expectations and budgeted revenue.
Unexpected deviations should be investigated.
Invoices received (or payments made) in Review post year end bank statements / cash book
advance/arrears of goods or services delivery payments for evidence of amounts relating to the
date leading to overstatement or financial year but not included in liabilities.
understatement of costs and/or liabilities. For a sample of documents pre and post year end
indicating date of delivery of goods/services (eg GRNs),
verify the cost and liability were recorded in the
appropriate period.
There is an increased risk of irrecoverable Identify year end receivable balances still outstanding at
debts (eg due to the nature of the client's the date of the audit by reviewing post year end receipts
industry or customers), resulting in assets from customers. For amounts still outstanding establish
being potentially overstated. whether these are provided for.
Review aged receivables analysis and customer
correspondence files for evidence of disputes with
receivables and consider the adequacy of any related
receivables allowance.

Examples of risks Possible responses


Significant client borrowing and/or overdraft Review correspondence with the bank/lender for any
with cash flow problems which may indicate evidence of withdrawal or extension of facilities.
going concern problems. If there are bank covenants linked to performance on
which facilities depend, review compliance with these,
and increase testing on areas where management could
manipulate performance indicators (such as provisions).
Review post year end results and cash flow forecasts (if
prepared) for evidence the company can continue as a
going concern.
New client systems/controls/staff impacting on Undertake additional visits (eg interim audit) to assess
amounts recorded in the financial statements, the effectiveness of controls operating over areas
increasing the risk of errors and the risk of affected.
internal controls not operating effectively. Perform extra work to document and evaluate new
systems/controls, performing tests of controls where
necessary.
Increase sample sizes for substantive testing over
financial statement areas impacted.
Management has an incentive to manipulate Focus on and increase testing on judgemental areas in
performance, increasing the risk of profits the financial statements (eg provisions, revenue
being overstated (eg remuneration or bank recognition accounting policies).
funding is reliant on performance).

14
Above are just some examples of risks you may encounter in an exam question on audit
risks and responses. The best response to each risk will depend on the particular
circumstances of the client and the environment in which it operates.
Your approach should not be to simply learn a list of responses. Instead, your focus should be
on understanding the link between audit risks and responses, and being able to identify and
explain risks and suitable responses when presented with different scenarios.

6 Fraud, law and regulations


FAST FORWARD
When carrying out risk assessment procedures, the auditor shall also consider the risk of fraud or non -
compliance with law and regulations causing a misstatement in the financial statements.

6.1 What is fraud?


Key terms Fraud is an intentional act by one or more individuals among management, those charged with
governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal
advantage. Fraud may be perpetrated by an individual, or colluded in, with people internal or external to
the business.
Fraud risk factors are events or conditions that indicate an incentive or pressure to commit fraud or
provide an opportunity to commit fraud.

Fraud is a wide legal concept, but the auditor's main concern is with fraud that causes a material
misstatement in financial statements. It is distinguished from error, which is when a material
misstatement is caused by mistake, for example, in the misapplication of an accounting policy.
Specifically, there are two types of fraud causing material misstatement in financial statements:
 Fraudulent financial reporting
 Misappropriation of assets

134

15
6.1.1 Fraudulent financial reporting
Key term Fraudulent financial reporting involves intentional misstatements, including omissions of
amounts or disclosures in financial statements, to deceive financial statement users.

This may include:


 Manipulation, falsification or alteration of accounting records / supporting documents 
 Misrepresentation (or omission) of events or transactions in the financial statements 
Intentional misapplication of accounting principles 
Such fraud may be carried out by overriding controls that would otherwise appear to be
operating effectively, for example by recording fictitious journal entries and improperly
adjusting assumptions or estimates used in financial reporting.

6.1.2 Misappropriation of assets

Key term Misappropriation of assets involves the theft of an entity's assets and is often perpetrated by employees in
relatively small and immaterial amounts. However, it can also involve management who are usually more
capable of disguising or concealing misappropriations in ways that are difficult to detect.

This is the theft of the entity's assets (for example, cash, inventory). Employees may be
involved in such fraud in small and immaterial amounts, but it can also be carried out on a
larger scale by management who may then conceal the misappropriation, for example, by:
 Embezzling receipts (for example, diverting them to private bank accounts) 
 Stealing physical assets or intellectual property (inventory, selling data) 
 Causing an entity to pay for goods not received (payments to fictitious vendors)
Using assets for personal use

6.2 Fraud and the auditor


ISA 240 The auditor's responsibilities relating to fraud in an audit of financial
statements provides guidance for auditors in this area.

6.2.1 Responsibilities of management compared with responsibilities of auditors


The primary responsibility for the prevention and detection of fraud is with those charged with
governance and the management of an entity.
This is effected by having a commitment to creating a culture of honesty and ethical behaviour and
active oversight by those charged with governance.
The auditor is responsible for obtaining reasonable assurance that the financial statements are
free from material misstatement, whether caused by fraud or error. The risk of not detecting a
material misstatement from fraud is higher than from error because of the following reasons :
Fraud may involve sophisticated schemes designed to conceal it.

Fraud may be perpetrated by individuals in collusion.

Management fraud is harder to detect because management is in a position to
manipulate accounting records or override control procedures.

16
The auditor is responsible for maintaining professional scepticism throughout the audit,
considering the possibility of management override of controls, and recognising that audit
procedures effective for detecting errors may not be effective for detecting fraud.

6.2.2 Risk assessment


ISA 315 requires a discussion among team members that places particular emphasis on
how and where the financial statements may be susceptible to fraud.
Risk assessment procedures to obtain information in identifying the risks of material
misstatement due to fraud shall include the following:
Enquiries of management regarding:

–Management's assessment of the risk that the financial statements may be
misstated due to fraud

–Management's process for identifying and responding to the risk of fraud

–Management's communication to those charged with governance in respect of its
process for identifying and responding to the risk of fraud

–Management's communication to employees regarding its views on business
practices and ethical behaviour

–Knowledge of any actual, suspected or alleged fraud

Enquiries of internal audit for knowledge of any actual, suspected or alleged fraud,
and its views on the risks of fraud

Obtaining an understanding of how those charged with governance oversee
management's processes for identifying and responding to the risk of fraud and the
internal control established to mitigate these risks

Enquiries of those charged with governance for knowledge of any actual,
suspected or alleged fraud

Evaluating whether any unusual relationships have been identified in performing
analytical procedures that may indicate risk of material misstatement due to fraud

Considering whether any other information may indicate risk of material misstatement due to fraud

Evaluating whether any fraud risk factors are present
In accordance with ISA 315, the auditor shall identify and assess the risks of material misstatement
due to fraud at the financial statement level and at the assertion level for classes of transactions,
account balances and disclosures. These risks shall be treated as significant risks.
In accordance with ISA 330, the auditor shall determine overall responses to address the assessed risks of
material misstatement due to fraud at the financial statement level. In this regard, the auditor shall:

 Assign and supervise staff responsible taking into account their knowledge, skill and ability
 Evaluate whether the accounting policies may be indicative of fraudulent financial reporting
Incorporate unpredictability in the selection of the nature, timing and extent of audit procedures

As we mentioned above, management fraud is more difficult to detect than employee fraud
because of management's ability to override controls and therefore manipulate accounting
records. ISA 240 states that irrespective of the auditor's assessment of the risks of
management override of controls, the auditor shall design and perform audit procedures to:
Test the appropriateness of journal entries and other adjustments

Review accounting estimates for bias

For significant transactions outside the normal course of business, evaluate
whether they have been entered into to engage in fraudulent financial reporting or to
conceal misappropriation of assets

17
6.2.3 Written representations
ISA 240 requires the auditor to obtain written representations from management and those
charged with governance that:
They acknowledge their responsibility for the design, implementation and maintenance
of internal control to prevent and detect fraud.
They have disclosed to the auditor management's assessment of the risk of fraud in
the financial statements.
They have disclosed to the auditor their knowledge of fraud / suspected fraud
involving management, employees with significant roles in internal control, and
others where fraud could have a material effect on the financial statements.
They have disclosed to the auditor their knowledge of any allegations of fraud / suspected
fraud communicated by employees, former employees, analysts, regulators or others.

6.2.4 Communication to management and those charged with governance


If the auditor identifies fraud or receives information that a fraud may exist, the auditor shall
report this on a timely basis to the appropriate level of management.
If the auditor identifies or suspects fraud involving management, employees with significant roles in
internal control, and others where fraud could have a material effect on the financial statements,
they shall communicate this on a timely basis to those charged with governance.
The auditor also needs to consider whether there is a responsibility to report to the
regulatory or enforcement authorities – the auditor's professional duty of confidentiality
may be overridden by laws and statutes in certain jurisdictions.

6.3 Law and regulations


The auditor is also required to consider the issue of law and regulations in the audit.
Auditors are given guidance in ISA 250 Consideration of laws and regulations in an audit of
financial statements. The objectives of the auditor are:
To obtain sufficient appropriate audit evidence regarding compliance with the provisions
of those laws and regulations that have a direct effect on the determination of
material amounts and disclosures in the financial statements
To perform specified audit procedures to help identify non-compliance with other laws
and regulations that may have a material effect on the financial statements
To respond appropriately to non-compliance / suspected non-compliance identified
during the audit

6.3.1 Responsibilities of management compared with auditors

It is management's responsibility to ensure that the entity complies with the relevant laws and regulations.
NB:It is not the auditor's responsibility to prevent or detect non-compliance with laws and
regulations.

18
The auditor's responsibility is to obtain reasonable assurance that the financial statements
are free from material misstatement and, in this respect, the auditor must take into account
the legal and regulatory framework within which the entity operates.
ISA 250 distinguishes the auditor's responsibilities in relation to compliance with two different
categories of laws and regulations:
Those that have a direct effect on the determination of material amounts and
disclosures in the financial statements
Those that do not have a direct effect on the determination of material amounts and
disclosures in the financial statements but where compliance may be fundamental to
the operating aspects, ability to continue in business, or to avoid material penalties
For the first category, the auditor's responsibility is to obtain sufficient appropriate audit
evidence about compliance with those laws and regulations.
For the second category, the auditor's responsibility is to undertake specified audit
procedures to help identify non-compliance with laws and regulations that may have a
material effect on the financial statements. These include enquiries of management and
inspecting correspondence with the relevant licensing or regulatory authorities.

6.3.2 Audit procedures


In accordance with ISA 315, the auditor shall obtain a general understanding of:

 The applicable legal and regulatory framework


How the entity complies with that framework
The auditor can achieve this understanding by using their existing understanding and updating
it, and making enquiries of management about other laws and regulations that may affect the
entity, and about its policies and procedures for ensuring compliance and about its policies and
procedures for identifying, evaluating and accounting for litigation claims.
The auditor shall remain alert throughout the audit to the possibility that other audit
procedures may bring instances of non-compliance or suspected non-compliance to the
auditor's attention. These audit procedures could include:
Reading minutes

Making enquiries of management and in-house/external legal advisers regarding
litigation, claims and assessments

Performing substantive tests of details of classes of transactions, account balances or disclosures

The auditor shall request written representations from management that all known instances of
non-compliance or suspected non-compliance with laws and regulations whose effects should be
considered when preparing the financial statements have been disclosed to the auditor.

6.3.3 Audit procedures when non-compliance is identified or suspected


The following factors may indicate non-compliance with laws and regulations:
Investigations by regulatory authorities and government departments

Payment of fines or penalties

Payments for unspecified services or loans to consultants, related parties,
employees or government employees

Sales commissions or agents' fees that appear excessive

Purchasing at prices significantly above/below market price

Unusual payments in cash

19
Unusual transactions with companies registered in tax havens

Payment for goods and services made to a country different to the one in which the
goods and services originated

Payments without proper exchange control documentation

Existence of an information system that fails to provide an adequate audit trail
or sufficient evidence

Unauthorised transactions or improperly recorded transactions

Adverse media comment
The following table summarises audit procedures to be performed when non-compliance is
identified or suspected.

Non-compliance: audit procedures


Obtain understanding of nature of act and circumstances
Obtain further information to evaluate possible effect on financial statements
Discuss with management and those charged with governance
Consider need to obtain legal advice if sufficient information not provided and matter is material
Evaluate effect on auditor's opinion if sufficient information not obtained
Evaluate implications on risk assessment and reliability of written representations

6.3.4 Reporting identified or suspected non-compliance


The auditor shall communicate with those charged with governance, but, if the auditor
suspects that those charged with governance are involved, the auditor shall communicate
with the next highest level of authority, such as the audit committee or supervisory board.
If this does not exist, the auditor shall consider the need to obtain legal advice.
The auditor shall consider the impact on the auditor's report if they conclude that the non-compliance
has a material effect on the financial statements and has not been adequately reflected or is prevented
by management and those charged with governance from obtaining sufficient appropriate audit evidence
to evaluate whether non-compliance is material to the financial statements.
The auditor shall determine whether identified or suspected non-compliance has to be reported to the
regulatory and enforcement authorities. Although the auditor must maintain the fundamental principle
of confidentiality, in some jurisdictions the duty of confidentiality may be overridden by law or statute.

7 Documentation of risk assessment


FAST FORWARD
Auditors must ensure they have documented the work done at the risk assessment stage, such as the
discussion among the audit team of the susceptibility of the financial statements to material
misstatements, significant risks, and overall responses.

The following matters shall be documented during planning.


The discussion among the audit team concerning the susceptibility of the financial
statements to material misstatements, including any significant decisions reached

Key elements of the understanding gained of the entity regarding the elements of the
entity and its internal control components specified in ISA 315, the sources of the
information gained and the risk assessment procedures carried out

20
The identified and assessed risks of material misstatement at the financial statement level and at the
assertion level

Risks identified and related controls evaluated

The overall responses to address the risks of material misstatement at the financial statement level

Nature, extent and timing of further audit procedures linked to the assessed risks at the assertion level

Results of audit procedures

If the auditors have relied on evidence about the effectiveness of controls from previous audits,
conclusions about how this is appropriate

Demonstration that the financial statements agree or reconcile with the underlying accounting records

21

Common questions

Powered by AI

Auditors must address significant fraud risks by designing specific procedures to focus on areas susceptible to fraud, emphasizing professional skepticism, and maintaining vigilance for management override of controls . Unlike errors, fraud involves intentional deception, making it more complex to detect, as it often involves collusion or management manipulation . To address fraud risks, auditors should include unpredictable audit tests, evaluate the risk of fraudulent financial reporting, and test the rigor of internal controls . Fraud assessment requires addressing both the entity's control environment and its specific fraud risks, while errors may necessitate procedure improvements to catch unintentional misstatements.

Materiality guides the auditor's judgment on the nature, timing, and extent of audit procedures. It defines the threshold above which misstatements become material, influencing how audit risk model components are applied . Materiality affects the assessment of inherent risk, as it determines sensitivity to potential misstatements, and influences control risk evaluations through the focus on significant controls . It also prescribes acceptable detection risk by dictating audit effort extent needed to identify material misstatements . Materiality ensures audit efforts are directed efficiently, addressing only those discrepancies that could sway financial statement users' economic decisions .

Auditors can reduce detection risk by increasing the quantity and quality of audit procedures. Strategies include increasing sample sizes to enhance the representativeness of audit tests, improving the planning and execution of procedures, and assigning more experienced personnel to the audit team . Professional skepticism and rigorous supervision also mitigate detection risk . Additionally, auditors can incorporate unpredictability in audit procedures and employ continuous learning and improvements to their audit methodologies . These strategies collectively ensure high-quality audit outcomes by focusing audit efforts on areas with a higher risk of material misstatement.

The audit risk model consists of three main components: inherent risk, control risk, and detection risk . Audit risk is the product of these three factors. Inherent risk is the susceptibility of an assertion to a material misstatement assuming the absence of internal controls, influenced by item characteristics and entity nature . Control risk is the risk that a misstatement will not be prevented or detected by the entity's internal controls . Detection risk is the probability that an auditor's procedures will not detect a material misstatement . Detection risk is manageable by the auditors, whereas inherent and control risks are not . Each component's level affects the necessary extent and nature of audit procedures needed to maintain overall audit risk to an acceptable level.

Materiality impacts inherent and control risk assessments by defining the level at which auditors consider misstatements to be significant. For inherent risk, materiality affects the focus on susceptible items or transactions that could cause material misstatement if misjudged or misvalued . It requires auditors to gauge the impact of potential misstatements considering the entity's industry and operations. For control risk, it guides the evaluation of the effectiveness of controls over material misstatements and the necessary audit response if controls are deemed inadequate . This approach ensures that audit work is focused and aligned with risks that could affect decision-making by stakeholders .

Incorporating unpredictability in audit procedures prevents clients from anticipating auditor actions, potentially deterring fraudulent activities that might exploit predictable audit patterns . Unpredictability involves varying the nature, timing, and extent of audit tests or procedures, choosing different items for testing, or integrating unexpected audit techniques. This discourages attempts to conceal misstatements and allows auditors to detect unusual transactions or anomalies . By diversifying the audit approach, unpredictability enhances the thoroughness and effectiveness of an audit, ultimately bolstering overall audit credibility and stakeholder confidence in the financial statements .

Under ISA standards, the primary responsibility for preventing and detecting fraud lies with management, who must establish a culture of honesty and ethical behavior and ensure active oversight . Management's duties include implementing and maintaining internal controls designed to prevent fraudulent activities. Auditors, on the other hand, are responsible for obtaining reasonable assurance that financial statements are free from material misstatement due to fraud or error . They must maintain professional skepticism, understand fraud risks, and properly design and execute audit procedures to detect fraud, recognizing that these may differ from error detection .

Tests of controls evaluate the effectiveness of the entity's internal controls in preventing or detecting misstatements at the assertion level, while substantive tests directly check for material misstatements in financial transactions or balances . Selecting appropriate tests is crucial as tests of controls provide a basis for determining the extent of substantive testing needed. Where controls are effective, less substantive testing may be warranted, reducing detection risk effectively . Conversely, in weak control environments, substantive tests increase in scope to ensure misstatements are captured. Properly choosing test types maintains audit quality and efficiency .

Auditors balance procedural and risk-based approaches by using judgment to tailor audit procedures to the specific client's risks, avoiding a one-size-fits-all procedural approach which is non-compliant with ISAs . A procedural-only approach may lead to higher audit risk and incorrect audit opinions as it doesn't consider unique client circumstances . Conversely, a risk-based approach allows auditors to focus on areas of higher risk to refine audit efforts efficiently, though it requires more auditor judgment and knowledge . Sole reliance on one method may increase the risk of audit failure, as procedural approaches might overlook specific risks and risk-based approaches depend heavily on accurate risk assessments.

Business risk pertains to the broader environment impacting a company's operations and success, while audit risk is specific to the financial statements and the likelihood of an auditor issuing an incorrect opinion due to material misstatements . It is crucial for auditors to distinguish between them because business risks might affect the client's ability to continue as a going concern, but they do not directly implicate the financial statement audit's primary focus . Misalignment between the two can lead to incorrect audit procedures and evaluations, potentially leading to audit failure or misstatements not being detected .

You might also like