Auditing 1B Course Overview and Objectives
Auditing 1B Course Overview and Objectives
FACULTY OF COMMERCE
AIM
1 Audit module is in two parts( 1&2)Aim of the whole audit is to develop students
knowledge and understanding of carrying out an audit ,its application in the context of
the professional ethics, conduct and regulatory framework.
2 Aim of Part 2;
To provide knowledge of auditing procedures, presentation and reporting of the findings of the
audit.
Objectives
COURSE OUTLINE
4. AUDIT EVIDENCE
Working papers
Internal audit
1
Test of controls
Substantive tests
6 Audit Sampling
7 AUDITORS’ REPORTS
Going concern
RECOMMENDED TEXTS
[Link] G and Van Esch S. The Principles and Practice of Auditing, Juta & Co.
STUDENTS ASSESSMENT
Students shall be assessed at the end of the semester through coursework and final examination.
COURSEWORK
(one assignment consisting of 5 questions shall be given to students at the beginning of the semester)
EXAMINATION
An examination to be marked out of 100 shall be administered at the end of the semester. It will contribute
75% to the final mark.
2
A 3hr paper based exam consisting of 5 compulsory questions. The bulk questions are discursive but some
questions involving computational elements will be set from time to time.
3
Introduction
History of auditing
Background
Economic decisions in every society must be based upon the information available at the time the
decision is made. For example, the decision of a bank to make a loan to a business is based upon
previous financial relationships with that business, the financial condition of the company as
reflected by its financial statements and other factors.
If decisions are to be consistent with the intention of the decision makers, the information used in
the decision process must be reliable. Unreliable information can cause inefficient use of resources
to the detriment of the society and to the decision makers themselves. In the lending decision
example, assume that the bank makes the loan on the basis of misleading financial statements and
the borrower Company is ultimately unable to repay. As a result the bank has lost both the principal
and the interest. In addition, another company that could have used the funds effectively was
deprived of the money.
As society become more complex, there is an increased likelihood that unreliable information will
be provided to decision makers. There are several reasons for this: remoteness of information,
voluminous data and the existence of complex exchange transactions
As a means of overcoming the problem of unreliable information, the decision-maker must develop
a method of assuring him that the information is sufficiently reliable for these decisions. In doing
this he must weigh the cost of obtaining more reliable information against the expected benefits.
A common way to obtain such reliable information is to have some type of verification (audit)
performed by independent persons. The audited information is then used in the decision making
process on the assumption that it is reasonably complete, accurate and unbiased.
The Vedas contain reference to accounts and auditing. Arthasashthra by Kautilya detailed rules for
accounting and auditing of public finances.
The original objective of auditing was to detect and prevent errors and frauds.
Auditing evolved and grew rapidly after the industrial revolution in the 18th century. With the growth
of the joint stock companies the ownership and management became separate. The shareholders
who were the owners needed a report from an independent expert on the accounts of the company
managed by the board of directors who were the employees.
The objective of audit shifted and audit was expected to ascertain whether the accounts were true
and fair rather than detection of errors and frauds.
4
4
In India the companies Act 1913 made audit of company accounts compulsory .With the increase
in the size of the companies and the volume of transactions the main objective of audit shifted to
ascertaining whether the accounts were true and fair rather than true and correct. Hence the
emphasis was not on arithmetical accuracy but on a fair representation of the financial efforts
The companies Act.1913 also prescribed for the first time the qualification of auditors
The International Accounting Standards Committee and the Accounting Standard board of the
Institute of Chartered Accountants of India have developed standard accounting and auditing
practices to guide the accountants and auditors in the day to day work .The later developments in
auditing pertain to the use of computers in accounting and auditing.
In conclusion it can be said that auditing has come a long way from hearing of accounts to taking
the help of computers to examine computerized accounts
-Stewardship Mathew 25
Separate concept
Accountability
Assurance
Confidence
The audit environment is the inter-relationship between the audit being performed, the auditing
profession and society. Governing this inter-relationship are various laws, rules and codes.
The society in which the auditor functions determines the need for and the entirety of the audit
process.
Audit objectives
Audit assumptions
5
THE STRUCTURE OF THE ACCOUNTANCY PROFESSION
In Zimbabwe, the Public Accountants and Auditors Board heads the profession and the Accounting
Practices Board sets accounting standards.
The Zimbabwe Public Accountants and Auditors Board is a statutory body established in 1996 under the
Public Accounts and Auditors Act (Cap: 27:12). The Zimbabwe Accounting Practices Board has statutory
recognition in the Companies Act but is an independent body with its own constitution set up, on the initiative
of the ICAZ in the 1970’s.
The Board has established minimum criteria for membership of the Board by other bodies. These
criteria relate to the educational qualification and practical training provided by would-be member
bodies and also require them to maintain an office in Zimbabwe and to be capable of meeting their
obligations under the PAAB Act (primarily disciplinary).
The Board’s primary function is to register qualified accountants and auditors and to provide
assurance to the public and employers regarding the quality of accountancy services. Members of
the profession are registered as either Registered Public Accountants or as Registered Public
Auditors. Neither category may practise (provide services directly to the public) without a Practising
Certificate issued by the Board.
An appraisal activity
Established by management
For the review of accounting and internal control systems
As a service to the entity
Similarities
6
Internal audit reviews External audit
objective To add value and improve an To provide assurance on a
organization’s operation particular area of business
operations
Regularity Ongoing ,regular reviews One off exercise
Scope Flexible, depending on Focused on specific area
findings
Reviewers Internal team External experts
output Highlight areas of weakness , Provide assurance that area
make recommendations for under review is as expected
improvement
Intended audience Management team and Management team,
responsible parties shareholders, or whoever is
the intended recipient of the
assurance report
7
Chapter 1
What is assurance?
In many situations, there are people who need to be assured about something;
Parents need assurance that schools are suitably educating their children.
Diners need assurance that a restaurant is serving food that is safe to eat
Shareholders need assurance that the published Financial statements of a company are not wrong
Directors need assurance that the systems inside the company they run are working.
It is often not possible to check for yourself –so they are likely to want to rely on someone else to check it
for you;
In each case ;
Report will be written so that those requiring assurance can read it and get assurance
The person doing the checks will have some standards to check against
The amount of checking will need to be decided.
Practitioner
Criteria
Subject matter
If a lot of detailed checking is done, ‘the assurance-provider ‘will be able to able to conclude that the
responsible person has done their job properly, or has not. This is known as ‘positive assurance’.
8
If a smaller amount of checking is done ,the assurance provider may only be able to report that “no errors
/problems were found “,but may not feel able to confirm that there are no errors…because they have not
checked enough to be sure .This is known as ‘negative assurance.
Assurance is voluntary but maybe imposed on the other party by another party. Examples;
Benefits of assurance
Enhances credibility
Management bias is reduced
Recommendations addresses risk
Information reporting is improved.
A team of auditor (qualified accountants) from outside the company will come in to check whether the FS
are “true and fair’-a term meaning that the FS have no “material’ (important) errors.
The criteria that the auditors will use to check the FS are the accounting standards.
An audit report will be written to the shareholders ,stating whether ,in the auditors opinion, the FS do, or do
not ,present a true and fair view ( i.e. positive assurance).
Definition of Auditing-An Independent examination of and expression of opinion on the financial statements
of an entity by a duly appointed auditor in pursuant of that appointment
Independent person-An auditor is independent in status and mind. STATUS –position, occupation,
firm independent from client. MIND-state of mind –objective, partial and free from environmental
influence.
Examination-he examines and, not certify (verifies for evidence, accuracy and validity).
Expression of an opinion –own point of view/own judgment (given in form of a report).
Financial statements-statement of financial position, statement of comprehensive income,
statement of changes in equity, cash flow statement, notes to the accounts and management
representation.
Duly appointed-procedures of appointing and dismissal of an auditor
Pursuant of that appointment-professional, ethical procedures followed
9
Internal Audit
Companies have many internal systems-risk management, internal controls, accounting systems.
A team of auditors, who may be from inside or outside the company, will check whether these systems are
working properly.
The criteria that the auditors will use are likely to be their own experience of what makes a good system,
combined with legal requirements and corporate governance.
He audit report will be written to the directors, stating whether the systems are working and making
recommendations for future improvements.
Assurance reports are written for the benefits of the people reading the .The readers need to be able to
trust that the reports are reliable and correct. If they sense any links between the auditors and the things
being audited, they may not trust the opinion given.
If they are any links between the auditors and the things being audited, the report loses credibility and the
assurance is undermined.
It is therefore a requirement if the auditors are independent of those they are auditing.
REVISION QUESTIONS
1 Explain the terms international standards on auditing, estimates and judgments, reasonable
assurance, true and fair view, and materiality. (2 marks each)=10marks
2 You are the involved in the audit of a manufacturer.
Required
(a) Briefly explain the external audit process, including a definition of test of control and substantive
procedures and a flow diagram of the audit process. (4mks)
(b) Explain the difference between a controls approach and a substantive approach to
audit.(3maks)
(c) Explain the difference between an interim audit and final audit.(3marks)
10
CHAPTER 2
The Company’s act requires that all auditors be members of a professional group recognized by [Link]
In Zimbabwe one has to save articles for 6 years and pass qualifying exams to become a Chartered
Accountant (CPA) Certified Public Accountants examination.
Qualifications obtained outside the country are to be converted by writing a conversion course on
company law and taxation organized by the local Institute.
2.1 Disqualifications
Company’s act specified people who are disqualified to become auditors of a firm
-A body corporate
Company’s Act states that every company shall at its general meeting appoint an auditor or joint
auditors from that joint meeting until the next general meeting.
Directors may appoint the first auditors of the company subject to the approval of members at any
a time before the first general meeting of company ,to hold office until the conclusion of that first
meeting ( new company)
The directors or the company in general meeting may fill /appoint an auditor as a casual vacancy
and serve until the next general meeting.
Where the shareholders fail to appoint an auditor the company shall inform the secretary of the
ministry of Trade and the ministry shall appoint an auditor.
Dismissal/Removal of auditors
11
A company may by ordinary resolution remove an auditor before the expiration of his term of
office where a resolution is passed at a general meeting. And within 14 days of notice the
company must send a copy also to the registrar and if it contains a statement which creditors
should know about, then a copy of the notice should be sent to them .
An auditor may call upon directors to call upon an immediate general meeting and the
directors are legal bound to do so within 21 days after the notice.
The proposed auditor must seek permission of the company’s offices to contact the retiring
auditors. If this permission is refused the accountant should decline nomination. When given the
permission, the proposed auditor then communicate in writing with the retiring auditor to request
that he be provided with the relevant information to enable him to decide whether or not to accept
nomination.
Before complying with this request the retiring auditor should obtain the client‘s permission to
discuss his affairs fully with the proposed auditor.
If the client refuses, then the present auditor should inform the proposed auditor accordingly and
the latter should decline nomination.
If the present auditor is authorized to discuss the company’s affairs with the proposed auditor, he
should communicate to the proposed auditor any relevant information he believes to be true,
including the reasons for the proposed change and any other matter of which he considers the
proposed auditor should be aware, including any professional reasons why he should not accept
appointment.
The purpose of the procedures is to enable the proposed auditor to ascertain the circumstances in which
the change has been proposed so that he can decide whether or not it is proper for him to accept or
whether he wishes to accept.
It serves to protect the new auditor and also members of the company none of whom may be fully aware
of the circumstances surrounding the proposed change. It also serves to protect the existing auditor
where the proposed change arises from, or is an attempt to interfere with, the conscientious discharge of
his duty.
RIGHTS
Auditors are usually given rights by law, to help ensure they can do their job properly.
12
The right to receive any notice of intention to remove from office.
The right to call for EAGM on their resignation.
Duties
Auditor duties are also typically set by government, so will vary by country.
Typical duties;
To report to shareholders whether FS show a true and fair view in accordance with IAS AND
IFRS.
Right to form an opinion
1. Adequate returns have been received (from divisions not visited)
2. Accounting records are consistent with FS
3. Proper accounting records have been kept
4. All information have been received from the officers
5. Directors ‘s report is consistent with FS
When leaving a client, to issue a statement of circumstances explaining whether there are any
specific reasons for them leaving.
After leaving a client, to respond to any request for information from the firm of auditors who
replace them.
-appointed by shareholders
by directors but have to be approved by shareholders
by the audit committee
By resignation
By removal
By not accepting nomination
13
2.8 Professional and code of conduct
enforcement
Fundamental principles of
professional ethics
Engagement letters
5 fundamental principles which members, affiliate and students must follow accronome PICCO
P=Professional Behavior; comply with relevant laws and regulations and avoid action that discredit the
profession.
C=Competence and due care-Maintain professional knowledge and skills and ensure all relevant
professional standards are followed, in all professional work undertaken.
O=Objectivity- Accountants should not allow bias, conflict of interest, and undue influence to override
professional judgment
14
Intimidation-threats of removal
Management-offering management services
2.11 Confidentiality
Information confidentiality to the client or to the employer acquired in the course of business should not
be disclosed to a third party;
Exercises
1 Explain the five fundamental principles of the Code of ethics and conduct.
2 It is important that an auditor‘s independence is beyond question, and that he should behave
with integrity and objectivity in all professional and business situations. The following are a
series of questions which were asked by auditors of Deloite & touch at a recent update
seminar on professional ethics;
a) Can I audit my brother’s company?
b) Can I prepare the financial statements of a public company and still remain as
auditor?
c) My client has threatened to sue the firm for negligence. Can I still remain as
auditor?
d) I am a student of the Chartered Accountants .Am I bound by the ethical
guidelines of the Association?
e) If I discover evidence of money laundering, should I continue to protect client
confidentiality and therefore keep quiet?
Discuss the answers you would give to the above questions posed by the auditors.
15
Chapter 3
AUDIT PROCESS
3.0 Before considering the detail involved in the audit process of a financial statement it is important
to understand the process of audit from start to the end.
Stage 1 of the process can be termed “preliminary engagement activities” and involves the following;
Performing procedure to determine whether the auditor wants to establish a relationship (in
respect of a new client) or continue the relationship.
Establishing whether the audit firm has the capacity and capability to service the client company
Evaluation of the firm if it will be able to comply with the ethical requirements of the engagement.
Establishing an understanding of the terms of the engagement.
Stage 2 Planning
Responding to assessed risk at financial statement level (e.g. assigning more experienced staff)
Responding to assessed risks at assertion level by carrying tests of controls and substantive tests
so as to gather sufficient and appropriate evidence to reduce risk to acceptable levels.
NB Role of International standards on [Link] Zimbabwe we have adopted the IFAC auditing
[Link] standards provide quidance on how an audit process is to be [Link] are
applicable at each stage of the audit.
16
ISA 320-Materiality in planning and performing an audit.
Engagement
Planning & Review of internal controls
Evidence
Report
Engagagement
Planning
Review of internal
control
Full substantive
test Control
Control test
Review of evidence
Report
Members may advertise their services and products in the way they think fit.
Advertise using a medium that do not reflect adversely on the member, accountancy profession
17
Advertise or promotional material should not bring disrepute to the profession, discredit others, mislead,
and fall short to the advertisement requirement
-Prospective clients-Before accepting a new client, the audit firm should determine whether it wishes to
establish a relationship with the prospective client. There are reasons that an audit firm may not wish to
enter into a relationship with a prospective client;
Before accepting an engagement the firm of auditors must consider the followings;
If…..
NB Compliance with standards; ISA and ISQC 1 –Quality control for firms that perform audits and
reviews of financial statements etc requires that the firm;
18
a) Acceptance of a client
Assuming the above procedures have all gone smoothly, the incoming firms are almost appointed. Final
procedures;
b) Engagement letter
It reduces misunderstanding
It creates a legal basis for payment.
Each audit assignment is different and hence need a different engagement letter immediately after
appointment.
c) Standard Format
Objective of the audit (I e to check the Financial statements and report on them)
To clarify responsibilities of management –the principal responsibilities of the client (maintain
proper accounting records and to prepare the FS which give a true and fair view and comply with
company act and relevant legislation) and that of the auditor ( to report if the FS not comply with
the standard accounting practice)
Duty to prepare the financial statements rests with the management.
To provide all information and explanations ,and books and records
Scope of audit –done with reference to the relevant and audit standards to be followed ,and any
other laws and regulations that will guide the process
An explanation of the audit report and any other communication that will occur during the
process.
Auditors have no duty to discover fraud and irregularities. Duty to prevent fraud and errors rests
with the management.
Provision for accounting and taxation services should be done on a separate engagement.
How fees are billed.=based on time spent and grade of staff.
A request to management that they should confirm their agreement to the terms of engagement
in writing.
Before acceptance of the audit firm to the client, the audit firm should undertake
pre-audits or pre-acceptance considerations. It is an ethical requirement for an
The audit firm might consider the following before accepting:
Skills
Timing
Knowledge of the industry system
Special requirements of the Audits
Management
Integrity of management (is the firm capable of paying fees) and compliance
to rules and regulations.
20
The purpose of an ethical clearance letter is to assist the proposed Auditor to make
a decision about whether or not to accept the appointment.
Where an ethical clearance letter is sent to a retiring auditor, the proposed auditor
is asking whether there are matters known to the existing auditor which would
inform this consideration of threats to the fundamental principles. An extreme
example might be where a client was known to be engaging in illegal activities.
Knowledge of this would inform the proposed auditor assessment of the threat to
their integrity.
This then is the "ethical clearance" that is being sought. The existing auditor
provides a clearance in the sense that he indicates that there are no matters known
to him which would inform the consideration of threats to the ethical principles of
auditing.
4. Acceptance of a client
Assuming the above procedures have all gone smoothly, the incoming firms are
almost appointed. Final procedures;
-Engagement Letter
21
According to International Standard on Auditing (ISA) 210 the purpose is to
establish standards and provide guidance on:
Agreeing the terms of the engagement with the client; and
The auditor’s response to a request by a client to change the terms of an
engagement to one that provides a lower level of assurance.
Definition
An Engagement letter is a key document in the relationship between the auditor
and the client providing a written confirmation of the work that will be carried out
The engagement letter documents and confirms the auditor's acceptance of
the appointment, the objective and scope of the audit, the extent of the
auditor's responsibilities to the client and the form of any reports.
It reduces misunderstanding and it creates a legal basis for payment.
It is written by the auditor to the client
22
Scope of Audit
That is done with reference to the relevant audit standards to be followed
and any other laws and regulations that will guide the process.
The scope of the audit, including reference to applicable legislation,
regulations, or pronouncements of professional bodies to which the auditor
adheres.
When the auditor of a parent entity is also the auditor of its subsidiary, branch or
division (component), the factors that influence the decision whether to send a
separate engagement letter to the component include:
PLANNING
Planning an Audit
According ISA 300 (Redrafted), Planning and auditing of financial statements .The
auditor should properly plan the audit. This standard describes the auditor's
responsibilities for properly planning the audit.
Planning the audit includes establishing the overall audit strategy for the
engagement and developing an audit plan, which includes, in particular, planned
risk assessment procedures and planned responses to the risks of material
misstatement. Planning is not a discrete phase of an audit but, rather, a continual
and iterative process that might begin shortly after (or in connection with) the
completion of the previous audit and continues until the completion of the current
audit.
There is more than one way to audit a company’s financial statements. However
for each client there is need to draft a an appropriate strategy which covers the
scope, timing and direction of the process
A brief summary of the company’s activities and any changes during the last
year
What is the reporting framework (e.g. what accounting standards does the
company follow, and what audit standards will be followed)
Understand the key dates
Decide on the audit approach(test of control or substantive tests)
Preliminary test of materiality
Timing of audit work (interim audits or year-end audit ,locations to be
visited and when)
Identification of higher risk in the financial statements
Detailed plan
25
A detailed plan is a document that follows the strategy. It includes
Allocation of work to team members Understanding the Entity and its environment
26
Auditors must ensure they understand the business that they are auditing
otherwise it would be difficult to understand whether the company’s control
system is appropriate, or its Financial statements accurate.
Examples
27
CHAPTER 4
28
PLANNING
4.0 An audit planning is addressed by ISA 300 (Redrafted) Planning an Audit of Financial
[Link] planning is the key to effective and efficient auditing. The importance of planning cannot
be overemphasized.
There is more than one way to audit a company’s financial statements. However for each client there is
need to draft a an appropriate strategy which covers the scope, timing and direction of the process
A brief summary of the company’s activities and any changes during the last year
What is the reporting framework (e.g. what accounting standards does the company
follow, and what audit standards will be followed)
Understand the key dates
Decide on the audit approach(test of control or substantive tests)
Preliminary test of materiality
Timing of audit work (interim audits or year-end audit ,locations to be visited and when)
Identification of higher risk in the financial statements
29
A description of the nature ,timing and extent of planned risk assessments and
procedures to assess these risk of material misstatements
Assessment of the inherent and control risk at both the entity and assertion level (e.g. plan to
understand and assess the control environment of the organization).
Audit procedures
Explanations for the plan to carry out test of controls or to carry out substantive tests.
Timetable of detailed audit work
Allocation of work to team members
Helping the auditor to devote appropriate attention to important areas of the audit
Identify and resolve potential problems on a timely basis
Helping the auditor to properly organize and manage the audit engagement so that it is performed
in an effective and efficient ways.
Assist in the selection of the engagement team members with appropriate levels of capabilities
and competence to respond to anticipated risks and the proper assignment of work to them.
Facilitate the direction and supervision of engagement
Co-ordination of work done by the experts
Auditors must ensure they understand the business that they are auditing…otherwise it would be difficult
to understand whether the company’s control system is appropriate, or its Financial statements accurate.
Examples
Revision questions
Question 1
30
In terms of ISA300, the audit plan must contain a description of the nature, timing and extent of planned
risk assessment procedures sufficient to assess the risk of material misstatements. Audit is a combination
of inherent risk, control risk and detection risk. The auditor must there evaluate the materiality and risks
specific to the company. Materiality limits should be set at the planning stage of the audit to act as a
guideline for deciding whether adjustments should be made to the financial statements.
Required
(a) Briefly describe the terms ‘inherent risk’, ‘control risk’,’ detection risk’ and ‘audit risk’ (4 marks)
(b) List the eight factors which the auditor would bear in mind when assessing the audit risk of a
company. Your answer should talk of inherent and control risk. ( 4 marks)
(c) Define and explain the Risk Equation, describing how it should be used in auditing planning.
(5 marks)
(d) Discuss the considerations which would determine whether an item is material in relation to
financial statements ( 3 marks )
(e) Discuss the validity of the statement that “materiality limits should be set at the planning stage of
the audit and should be rigidly be adhered to throughout the audit.” ( 4 marks)
Question 2
Joyous ltd appointed a new sales manager towards the end of the last year. This manager devised a plan
to increase sales and profit by means of a reduction in selling price and extended credit terms to customers.
This included consideration to invest in new machinery early in the current year in order to meet the demand
which the change in sales policy had created.
The draft statements for the year ended December current and comparative are shown below. The sales
manager has argued that the new policy has been a resounding success because sales and, more
importantly, profits have increased dramatically;
Income statement
Current comparative
$’000 $’000
Interest (112) ( 9)
31
Profit Retained 78 76
Current comparative
3 540 1 332
Current assets
inventory
Chapter 5
AUDIT EVIDENCE
Sufficient
Appropriate (relevant & reliable) evidence
Sufficient has to do with the quantity of audit evidence. It is assessed based on the auditor ‘knowledge of
the client, experience with the client, and degree of misstatements and persuasiveness of the evidence.
An appropriate deal with how reliable and relevant is the audit evidence. In this regard we can say
External evidence is better than the entities records (e.g. a bank statement /bank statement is
more reliable than the cashbook)
Evidence obtained directly by the auditor is better than evidence passes on by the
clients.(problem is that it comes from the client which might be suppressed by the client)
32
Audit evidence is better if there is a good internal control
Written evidence is better than oral
Originals are better than photocopies
Primary documents
The accounting system and the underlying records of the enterprise (documentation & accounting
records)
Other records-e.g. registers, memorandum and articles of association, board minutes.
Management and employees
Customers, suppliers and other third parties
Company assets (physical existence)
All audit tests (substantive or control tests) are aimed at testing the accuracy of the financial statements
figures and disclosures. Testing for accuracy means checking for errors;
There are many reasons why financial statements may have errors
As such there are five things the auditor must test for in the FS given by the acronome PROVE
(Know them and practice them for each type of transactions on the Fs)
33
5.3 Types of tests
For both sustentative tests and tests of controls there are a number of procedures that can be carried out;
I- inspection
O -observation
U-Recalculation
Or AEIOU
The last 4 in the list –EIOU-are referred to as substantive tests of detail. As you would inspect a single
invoice, or observe a single procedure at a time.
Analytical review procedures usually try to check the accuracy of the entire balance in one go, by
comparing it with other date ,breaking it down on a month –by –month basis, etc.
Examples
To test the existence of an asset, the auditor will select a sample of assets and then physically inspect the
asset in use by the company.
To test the occurrence of a sale, the auditor will inspect the sales invoice, goods dispatch note, and
maybe original order to make sure that the sale has taken place and cannot be called.
OR
ACCACOVER
A=ACCURACY
C-=Complete
C=-Cutoff
A=-ALLOCATE
C=-Classification
0=-occurrence
V-=valuation
E=-Existance
34
Chapter 6
The definition is provided for by ISA [Link] controls comprises the internal control environment and
control procedures. It includes all the policies and procedures adopted by the directors and management
of an entity in achieving their objectives as far as practical the orderly and efficient conduct of the
business including the adherence of the internal policies, the safeguarding of assets, the prevention and
detection of fraud and error, the accuracy and completeness of the accounting records and the timely
preparation of reliable financial information.
35
Internal controls may be incorporated within computerized accounting systems. Internal controls extend
beyond accounting systems.
Both ISA 400 and COSO provide five elements of internal controls which are;
The control environment means the overall attitude, awareness and actions of directors and
management regarding internal controls and their importance in the entity. The control
environment encompasses the management style, and corporate culture and values shared by all
employees. It provides the background against which the various other controls are operated.
However, a strong control environment does not, by itself, ensure the effectiveness of the of the
overall internal control system. Factors reflected in the control environment include
(i) the philosophy and operating style of the directors and management;
(ii) the entity’s organizational structure and methods of assigning authority and responsibility
[ including segregation of duties and supervisory controls ] and
(iii) the directors’ methods of imposing control, including the internal audit function, the
functions of board of directors and personnel policies and procedures.
The risk assessment process. This is how the entity assesses its material risks which might arise .it
estimates the significance of those risks and the likelihood that they are occurring. After this assessment
the entity would decide what to do with them.
‘’control procedures’’ are those policies and procedures in addition to the control environment which are
established to achieve the entity’s specific objectives. They include in particular procedures designed to
prevent or to detect and correct errors. Specific control procedures include;
External auditors are internal controls since, if they can confirm that an effective internal control system is
in operation, and then they can reduce the scope of their detailed substantive testing.
36
Internal auditors are interested in internal controls since management employs them to ensure that the
internal control system is operating satisfactorily. They must report promptly if they find problems in
internal control.
‘’OAP SPASM’’ can be used as a mnemonic to remember the types of internal controls
Organisation structure
Authorisation procedures
Segregation of duties
Personnel controls
Accounting controls
Supervision
Managerial review
PRACTICAL ISSUES
ISA 400 is at pains to point out that internal controls are inherently limited by various factors. These are
described below. Internal controls established by the directors relating to the accounting system are
concerned with achieving objectives such as:
The following stages are followed when assessing the system’s internal control system
37
(a) Find out what the system client/ascertain the system that the client is using. You can do this
by asking the client/inquire, read through their internal procedure manual.
(b) Documentation/ record the system-May use flowcharts, questionnaires, narrative , charts,
checklist or simply write it out in form of notes using own words
(c)
(a) Inventory
The accounting system for trading inventory/ stock consist of a whole series of activities, including the
accounting for transactions, to obtain satisfaction that all the transaction that have been recorded are
valid, accurate and complete.
(i) activities/ actions that form part of the accounting system for trading inventory
The following activities or actions usually form part of the accounting system for trading inventory
(1) The store man takes possession of trading inventory upon receipt. After taking the possession,
the store man would ensure that physical items of which he is taking possession corresponds to
the particulars on the supporting documentation. The purchase invoice, the delivery note and the
goods received on note are generally the principal source documents here.
(2) Recording of trading inventory received in the store records. If the enterprise uses perpetual
inventory records, the number of items and the cost price of the entire inventory purchased and
sold should be recorded in the inventory records. The result is that the number of items on hand
and their value can be established at any given moment. The comparison of physical inventory on
hand and the perpetual inventory records as an internal control is to be realized. Any differences
exposed in this way should be investigated by management and corrective action should be
taken.
Where an enterprise does not have perpetual inventory records , the only way of determining the
quantity of trading inventory a physical stock take as described In point 5 below
(3) The control of trading inventory and the issue of goods. The store man is responsible for the
inventory under his control. Necessary measures for ensuring the safety of inventory include
adequate physical security in a warehouse and segregation of duties between persons
responsible for the physical handling of inventory and the recording of inventory transactions. It is
also necessary to pack and arrange inventory in an orderly manner so that items can be traced
and identified immediately.
(4) The keeping of inventory control account in the general ledger. If an inventory control account is
kept in the general ledger in which the value of all inventory purchases and sales is accounted for
at cost price, figures showing the value of inventory on hand can be kept up to date.
(5) Carrying out physical inventory counts. Physical stock-taking (stock counting) is a management
task aimed at finding out what inventory is actually on hand. If an enterprise does not have
perpetual inventory records , physical stock- taking is the only reliable method of determining the
value of inventory at financial [Link] this case it is extremely important to count inventory at
the date of financial year –end. Where perpetual inventory records are kept. However the result of
the inventory counting can be compared with the perpetual inventory records. In this case the
value of the inventory as at year –end can be worked out from the perpetual inventory records. In
38
practice, however, the perpetual inventory records at year-end are usually supported by a
physical count at that date or as close as possible to the end of the financial period.
(ii) Control objectives
That inventory is not stolen
That inventory is not damaged
That inventory records are accurate
(iii) Control procedures
Valuable inventory items kept in secure warehouses with CCTV
Security guards patrols
Where necessary, inventory kept in areas where temperature is properly regulated
Staff trained in how to handle delicate inventory items
Regular stocktakers
(iv) Stocktaking
Annual year-end stocktake is maybe the most obvious , with every single item counted as
close to the accounting year end as possible
o Gives assuarence that the year -end figure in the Financial Statements is accurate
o Such a big exersice it may require the company to close for a day
o It may discover a problem (e.g theft) 364 days after it happened
Continous Stocktacking is where a company counts part of its inventory every few weeks ,
the aim being that over the course of a year all items have been checked to stock records at
least once
o A thief may be put off stealing if he knows his theft could be discovered by a count
tomorrow
o Less disruptive than a full count
Full count near the year- end is sometimes necessary where the year-end date is not
appropriate (e.g company is too big that day). The figures counted are rolled forward/back by
adding /subtracting purchases and sales in the gap between the count and the year end.
Since payroll is essentially a mechanical exercise, with standard calculations being done for each
employee, it is typical competed using computer software. Assuming the software can be trusted, the
main problems with payroll are likely to occur with the information being input into the system. In addition ,
there could problems with actual payments made to staff and the tax authorities .
Before the computer can do its calculations, the following information needs to be available:
~ employees names, addresses, annual salaries, tax details etc. – this information will be needed every
time payroll is run , so it will stay on the computer system permanently. It is called standing data
39
~ the hours that each employee work (taken from the clocking-in cards , or timesheets)
~Details of new employees to be added and employees who needs to added to the payroll (starters an
leavers)
Purchases of non-current assets are controlled in virtually the same way as purchases in general. The
only differences are that assets:
Are likely to have been individually budgeted for at the start of the year, because each
purchase involves a significant sum of money
40
Are likely to be quality checked in more detail on arrival, as an asset that does not work could
bring a stop to production processes
Are likely to require more authorization, as an asset purchase could be an employee trying to
use company funds to buy something for personal use.
Audit evidence
Sampling
An auditor may decide to apply tests such as analysis, enquiry, inspection, observation and recalculation on an entire
set of data (100% testing), or he decide to draw conclusions about the entire set of data by testing a representative
sample of items from it; this procedure is known as audit sampling.
Sampling is an example of a selective testing procedure (examining less than 100% of the items in a population) with
the aim to draw conclusions about the entire set of data by testing a representative sample of items from it.
A complete check of all transactions and balances of a business is not plausible in auditing due to
(a) The cost in terms of audit resources would be uneconomical
(b) Complete check would take so long that accounts would be ancient by the time the users saw them
(c) Users of financial information do not require 100% accuracy ( due to materiality concept)
(d) A complete check would be so boring that audit staff would become ineffective and errors would be missed.
(e) A complete check would not add much to the worth of figures (emphasis of audit is not on correctness but
on truth and fairness).
41
(d) Any area where the auditor is put to task/to inquiry
(e) High risk areas.
Approaches to Sampling
They are two approaches to sampling;
(a) Statistical sampling
(b) Judgemental sampling i.e. non-statistical sampling
Statistical Sampling
It involves the random selection of a sample, followed by the use of probability theory to evaluate the sample results.
It involves the use of tables, graphs,
•In the most general terms, CAATs can be referred to as any computer program utilized to improve the
audit process
•The overall objectives and scope of an audit do not change when an audit is conducted in a computer
information systems (CIS) environment.
•The application of auditing procedures may, however, require the auditor to consider techniques known as
CAATs that use the computer as an audit tool for enhancing the effectiveness and efficiency of audit
procedures.
Traditionally auditors have been criticized because they reach conclusions based upon limited samples. It
is not uncommon for an auditor to sample 30–50 transactions and declare a problem or conclude that
"controls appear to be effective. Management upon hearing the verdict of the auditors may question the
validity of the audit conclusions
Management realizes that they conduct thousands or perhaps millions of transactions a year and the auditor
only sampled a handful. The auditor will then state that they conducted the sample based upon generally
accepted audit standards (GAAS) and that their sample was statistically valid. The auditor is then forced to
defend their methodology.
•Another common criticism of the audit profession occurs after a problem emerges. Whenever a problem
emerges within a department, management might ask, “Where were the auditors?" If the audit department
had reviewed the area recently it becomes a tricky situation as the audit manager attempts to explain the
reason why the problem wasn't identified was because the problem was outside of the scope of the audit.
The audit manager might also try to explain that the sample was "a statistically valid sample with a 95%
confidence level."
•The audit committee doesn't care that the audit was conducted according to GAAS, they only care that a
problem went unnoted by the audit department.
Caats as an alternative
42
CAATs, as it is commonly used, is the practice of analyzing large volumes of data looking for anomalies.
A well designed CAATs audit will not be a sample, but rather a complete review of all transactions.
Using CAATTs the auditor will extract every transaction the business unit performed during the period
reviewed.
The auditor will then test that data to determine if there are any problems in the data.
IMPORTANCE OF CAATS
43
CAATs are important tools for the auditor in performing audits.
•They may be used in performing various auditing procedures, including the following:
•Tests of details of transactions and balances, for example, the use of audit software for recalculating
interest or the extraction of invoices over a certain value from computer records
•Analytical procedures, for example, identifying inconsistencies or significant fluctuations
•Check the operating system to ensure that the version of the program in use is the version approved by
management
•Sampling programs to extract data for an audit testing
•Performing calculations performed by the entity’s accounting systems
TYPES OF CAATS
•CAATs may consist of package programs, purpose-written programs, utility programs or system
management program.
•Regardless of the origin of the programs, the auditor substantiates their appropriateness and validity for
audit purposes before using them:
•Package Programs are generalized computer programs designed to perform data processing functions,
such as reading data, selecting and analyzing information, performing calculations, creating data files and
reporting in a format specified by the auditor.
•Purpose-Written Programs perform audit tasks in specific circumstances. .These programs may be
developed by the auditor, the entity being audited or an outside programmer hired by the auditor.
In some cases, the auditor may use an entity's existing programs in their original or modified state because
it may be more efficient than developing independent programs.
•Utility Programs are used by an entity to perform common data processing functions, such assorting,
creating and printing files.
These programs are generally not designed for audit purposes, and therefore may not contain features
such as automatic record counts or control totals
•System Management Programs are enhanced productivity tools that are typically part of a sophisticated
operating systems environment, for example, data retrieval software or code comparison software.
Considerations in the use of CAATS
As with utility programs these tools are not specifically designed for auditing use and their use requires
additional care.
When planning an audit, the auditor may consider an appropriate combination of manual and computer
assisted audit techniques.
In determining whether to use CAATs, the factors to consider include:
•The IT knowledge, expertise and experience of the audit team
•The availability of CAATs and suitable computer facilities and data
•The impracticability of manual tests
•Effectiveness and efficiency
USING CAATS
The major steps to be undertaken by the auditor in the application of CAAT are to:
•Set the objective of CAAT application
•Determine the content and accessibility of the entity’s files
44
•Identify the specific files or databases to be examined
•Understand the relationship between the data tables where a database is to be examined
•Define the specific tests or procedures and related transactions and balances affected
•Define the output requirements
•Arrange with the user and IT departments, if appropriate, for copies of the relevant files or database tables
to be made at the appropriate cutoff date and time
•Identify the personnel who may participate in the design and application of CAAT
•Refine the estimates of costs and benefits
•Ensure that the use of CAAT is properly controlled
•Arrange the administrative activities, including the necessary skills and computer facilities
•Reconcile data to be used for CAAT with the accounting and other records
•Execute CAAT application
•Evaluate the results
•Document CAATs to be used including objectives, high level flowcharts and run instructions
•Assess the effect of changes to the programs/system on the use of CAAT
TESTING CAATS
The auditor should obtain reasonable assurance of the integrity, reliability, usefulness, and security of CAAT
through appropriate planning, design, testing, processing and review of documentation.
•When using CAAT, the auditor may require the cooperation of entity staff with extensive knowledge of the
computer installation.
•In such circumstances, the auditor considers whether the staff improperly influenced the results of CAAT.
.
Documentation
The various stages of application of CAATs should be sufficiently documented to provide adequate audit
evidence.
•The audit working papers should contain sufficient documentation to describe CAAT application, including
the details set out in the sections below:
Planning
•CAAT objectives
•CAAT to be used
•Controls to be exercised
•Staffing, timing and cost
Execution
•CAAT preparation and testing procedures and controls
•Details of the tests performed by CAAT
•Details of inputs (e.g., data used, file layouts), processing (e.g., CAATs high-level flowcharts, logic) and
outputs (e.g., log files, reports)
•Listing of relevant parameters or source code
•Relevant technical information about the entity's accounting system, such as file layouts.
45
Audit Evidence
•Output provided
•Description of the audit work performed on the output
•Audit findings
.audit conclusions
EXAMPLES OF CAATS
AuditAutomation
ImageComparison
Snapshots
DatabaseAnalysers
LogAnalysers
On-lineTesting
EmbeddedCode
•AuditSoftware
•Software used by the auditor to read data on client's files, to provide information for the audit and/or to re-
perform procedures carried out by the client's programs e.g.:
•Audit Command Language (ACL) ,Interactive Data Extraction and Analysis (IDEA) ,Active Data For Excel
,D B Secrets ,etc
ACLCommands
46
•Commands in ACL lets you ask questions about data
•Verify,Count,Total,Statistics(confirmation&discovery),sequence(order),gaps(completeness),duplicates(un
iqueness),stratify,classify,age,summarise(concentration),sort,index(reordering)
Acl BENEFITS
Data Access: Gain visibility into your organization’s information through the ability to directly access and
query each and every transaction (from a multitude of sources and systems).
•Save time and reduce the need to request data from busy IT departments.
•Conduct the in-depth analysis necessary in today’s complex business and regulatory environments.
•Examine 100% of your transactional data improving the accuracy and effectiveness of your analysis.
Data Integrity:
•ACL features read-only access to all your enterprise data; source data is never changed, altered or deleted.
•ACL reads the data at the source-the data is neither constricted nor aggregated.
Limitations of CAATS
However, the CAATs driven review is limited only to the data saved on files in accordance with a systematic
pattern.
•Much data is never documented this way .In addition saved data often contains deficiencies, is poorly
classified, is not easy to get, and it might be hard to become convinced about its integrity.
•So, for the present CAATs is complement to an auditor's tools and techniques .In certain audits CAATTs
can’t be used at all.
•But there are also audits which simply can't be made with due care and efficiently without CAATs.
47
48
CAATs enhance the audit process by allowing auditors to analyze large volumes of data to identify anomalies, thus addressing concerns associated with traditional audits that often rely on limited samples. CAATs enable auditors to perform a complete review of all transactions rather than a sample. They help perform various auditing procedures, such as tests of details and analytical procedures, and ensure checks on the operating system . Additionally, CAATs provide tools like Audit Command Language (ACL) that allow for analysis of entire data populations, identification of trends, potential fraud, and compliance issues without altering source data .
Traditional audits typically rely on sampling a limited number of transactions and drawing conclusions based on these samples, often leading to criticisms regarding their validity, especially when issues arise outside the sampled data . Modern techniques using CAATs allow for full data analysis, reviewing every transaction instead of a sample, significantly enhancing accuracy and identifying anomalies across the entire dataset . CAATs can perform detailed audits through package or purpose-written programs, offering a broader, more reliable examination of financial data . This comprehensive approach reduces uncertainties tied to sample sizes and enhances audit reliability and credibility .
The application of CAATs involves several steps: setting objectives, determining file content and accessibility, identifying specific files or databases, understanding data table relationships, defining tests or procedures, arranging data collection with the IT department, and refining cost-benefit estimates. The application also requires controlling the CAAT process, planning administrative activities, reconciling data, executing tests, evaluating results, and documenting objectives, procedures, and results thoroughly to provide audit evidence .
Involving the entity's staff with extensive computer knowledge can influence audit outcomes if not properly managed, as they may unintentionally or intentionally affect CAAT results. Auditors need to exercise caution and maintain independence by critically evaluating staff input and ensuring CAAT processes remain unbiased and valid. Maintaining control over CAAT means validating and documenting processes, and auditors should independently verify data integrity and results through robust planning and testing, minimizing staff influence on audit conclusions .
The responsibility of preparing financial statements that give a true and fair view, complying with the company's act and relevant legislation, rests with management. Management must maintain proper accounting records and provide all necessary information to the auditors. Meanwhile, it is the auditor's responsibility to report if the financial statements do not comply with standard accounting practice, but auditors have no duty to discover fraud and irregularities; that duty rests with management .
Before accepting a new client, an audit firm should consider the client's ethical standing and integrity, potential association risks with the client's industry, the client's reputation with auditors and risk of legal actions, payment reliability, and adherence to an acceptable financial reporting framework. Additionally, consideration of the firm's competence, including skills, timing, industry knowledge, and any special audit requirements, is necessary .
CAATs play a significant role in maintaining data integrity and ensuring audit compliance by allowing for comprehensive data analysis without altering source data. Tools like Audit Command Language (ACL) provide read-only access to data, preserving its original state while facilitating thorough examination. This aids auditors in identifying anomalies, ensuring alignment with regulatory standards, and enhancing accuracy in reporting. CAATs help firms meet stringent audit requirements more effectively, as entire data populations can be analyzed for complete assurance .
Audit planning is crucial as it ensures the right team is selected, allocates tasks effectively, addresses material areas of risk, and identifies potential issues early. It involves establishing an audit strategy that includes scope, timing, and direction. Key components include understanding the client's activities, accounting standards, key dates, audit approach (controls or substantive tests), high-risk areas, staffing, and budgeting . A detailed plan follows, outlining specific tests, procedures, risk assessments, and timeframes for the audit work and team allocation, ensuring compliance with relevant audit standards .
The selection between manual and computer-assisted audit techniques depends on several criteria, including the audit team's IT knowledge and expertise, availability of suitable CAATs, and practicality of manual testing. Factors such as the effectiveness and efficiency of each technique in addressing the audit's objectives, as well as the availability of necessary computer facilities and data, influence the decision. The choice should optimize the audit process, enhancing accuracy and depth of analysis .
Ethical requirements dictate that audit firms should consider numerous factors before accepting new clients, such as the client's ethics and integrity, industry reputation, potential legal risks, and financial practices like adherence to acceptable reporting frameworks and timely payment of fees. Firms are to avoid relationships with clients who may pose ethical risks or where the firm lacks necessary competencies, as these factors affect the firm's ethical standing and professional integrity .