Regulation in the Auditing Profession
Regulation in the Auditing Profession
• The accounting and auditing professions have become under strict regulations more than ever due to
certain events that make the public to lack confidence on how companies are run and audited. (eg the high
level scandals by Ernon and its auditor Arthur Anderson)
• In the US, this resulted in the Sarbanes-Oxley Act 2002 which has not only radically changed the
regulation of the accounting profession in the US but also influenced such issues worldwide.)
■ Need for Regulation
In order to regain trust in the auditing profession, national and international standard setters and regulators have tried
to introduce three initiatives:
– Harmonization of auditing procedures, -to increase users confidence in the nature of audits around the
world
– Focus on audit quality
– Auditing Standards
– Code of Ethics
Appointments of Auditors
• Auditors have to be reappointed at every annual general meetings(AGM)
• Reappointment is not automatic, to prevent auditors from simply staying in office
• Prior to the firs AGM, the directors can appoint the first auditors,
• If an auditor resigns for some reason, directors can appoint another auditor to fill the casual vacancy.
These appointments only last until the next AGM.
• In any case, Government ensure that all companies have auditor
■ Need for Regulation
Auditors Rights
In order to carryout their duties properly, auditors have very powerful rights:
They have access to all records they require
They have a right to receive information and explanation of all transactions
They have a right to attend and receive notice about general meetings (where all shareholders appear) and
they have right to speak at general meetings
They have the right to receive in advance information about any resolutions that are proposed to be put at
these general meetings
They have the right to require the Company’s FSs should be presented at the general meeting
The right to be informed about, attend, speak and be heard at general meetings gives auditors an
opportunity to communicate with shareholders
■ Need for Regulation
Auditors Duties
The External Auditor’s primary duty is to audit the financial statements and provide an opinion on
whether the financial statements give a true and fair view (or are fairly presented in all material respects)
They may have additional reporting responsibilities required by local national law, such as confirming
that the financial statements are properly prepared in accordance with those laws, reporting on internal
control system as requires by Sarbanes Oxley Act of US)
■ Need for Regulation
Resignation of an Auditor
In practice, if the auditor and management find it difficult to work together, the auditor will usually
resigns
On resignation, auditors give written notice and statement of circumstances to the shareholders and
regulatory authority
Why they are required to issue a statement of circumstances?
• Auditors may have resigned because they are deeply concerned about some aspect of the
company’s activities
• Statement of circumstances explains why the auditor has resigned (may be due to innocent
reasons, eg. The auditor feels that the Co. is now too large for the audit firm to deal with. )
• If the auditors are really concerned about the Company, and that is why they have resigned, they
may insist the directors to call a general meeting , to explain for shareholders the reason for their
resignation
■ Need for Regulation
Dismissal of Auditors
• Auditors can be removed from office Directors begin the process to remove the auditor, but the resolution
must be passed by the shareholders (by simple majority at AGM)
• The reason for the removal should be legitimate, eg, the auditor may have failed to detect a material fraud
and directors have lost confidence in their competence; or because of the increase in the company’s size,
international/larger audit firm may be needed)
• The reason may be due to disagreement b/n the auditors and the Mgt. (eg. When auditors insist a change
in some part of financial statement, or when they issue a modified opinion, directors may decide to
remove the auditors). It is for this reason that auditors are required to deposit a ‘statement of
circumstances’, a copy of it will be sent to regulatory bodies.
• The auditors can also receive notices, speak at a general meetings to explain what has happened , if the
removal is without good reason
• Need for Regulation
• International Regulation
• The ASB Clarity Project was intended to make the U.S. auditing standards easier to read, understand, and
apply.
• The ASB redrafted existing AICPA auditing standards to align them with respective ISAs
■ The PCAOB considers International Standards on Auditing (ISA) when developing its standards.
• IASs are issued by the International Auditing and Assurance Standards Board (IAASB) of the
International Federation of Accountants (IFAC)
• The IAASB works to improve the uniformity of auditing practices and related services throughout the
world
• Currently, International Audit Standards have 37 Standard And 1 Quality Control Standard:
■ Need for Regulation
• ISAs are professional guidance that the auditor must follow to ensure each audit is performed consistently
and to a required standard of quality
• ISAs are not legal requirements. If a country has a law in place which is inconsistent with the
requirements of ISAs, local law should be followed
• ISAs are written in the context of and audit of FSs, but can be applied to the audit of other historical
financial information
• ISAs must be applied in all, but exceptional cases., where the auditor deems it necessary to depart from
ISA to achieve the overall aim of the audit, the departure must be justified
• ISAs contain basic principles and requirements followed by application and other explanatory materials to
aid the auditor on how to follow the requirements
■ Need for Regulation
• ISA 200: Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance with
International Standards on Auditing
• ISA 210: Agreeing the Terms of Audit Engagements
• ISA 220: Quality Control for an Audit of Financial Statements
• ISA 230: Audit Documentation
• ISA 240: The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
• ISA 250: Consideration of Laws and Regulations in an Audit of Financial Statements
• ISA 260: Communication with Those Charged with Governance
• ISA 265: Communicating Deficiencies in Internal Control to Those Charged with Governance and Management
■ Need for Regulation
• The principles are not requirements and do not carry authority, but they provide structure for the Codification.
The structure is organized around the following principles:
1. Purpose of an audit: To Provide opinion about financial statements
2. Responsibilities: Personal responsibilities of an auditor,
• Possess appropriate competence and capabilities
• Comply with ethical requirements
• Maintain professional skepticism and
• Exercise professional judgment
■ Need for Regulation
3. Performance
• Obtain reasonable assurance about whether financial statements are free of material misstatement
• Plan work and supervise assistants
• Determine and apply materiality level or levels
• Identify and assess risks of material misstatement based on understanding of entity and its environment,
including internal controls
• Obtain sufficient appropriate audit evidence
■ Need for Regulation
4. Reporting
Express opinion on financial statements in a written report
• Whether financial statements are presented fairly in accordance with financial reporting
framework
5. Need for Regulation
6. Auditing Standards (How it is structured)
7. Principles versus auditing Standards
The principles underlying auditing standards are too general to provide meaningful guidance
The principles are not requirements and do not carry authority, but they provide structure for the
Codification.
Auditing standards are regarded as authoritative literature, and every member who performs audits of
historical financial statements is required to follow them under the AICPA Code of Professional Conduct.
■ Need for Regulation
■ Quality control
1. Leadership responsibilities for quality within the firm — The firm should promote a culture that quality is
essential in performing engagements and should establish policies and procedures that support that culture.
2. Relevant ethical requirements — All personnel on engagements should maintain independence in mind and in
appearance, perform all professional responsibilities with integrity and maintain objectivity in performing their
professional responsibilities.
■ Need for Regulation
3. Acceptance and continuation of client relationships and engagements — Policies and procedures should be
established for deciding whether to accept or continue a client relationship or specific engagement.
These policies and procedures should minimize the risk of associating with a client whose management lacks integrity.
The firm should also only undertake engagements that can be completed with professional competence.
■ Need for Regulation
4. Human resources — Policies and procedures should be established to provide the firm with reasonable assurance
that:
• all new personnel are qualified to perform their work competently,
• work is assigned to personnel who have adequate technical training and proficiency,
• all personnel should participate in continuing professional education and professional development
activities that enable them to fulfill their assigned responsibilities, and
• personnel selected for advancement should have the qualifications necessary for the fulfillment of their
assigned responsibilities.
■ Need for Regulation
5. Engagement performance — Policies and procedures should exist to ensure that the work performed by
engagement personnel meets applicable professional standards , legal and regulatory requirements, and the firm's
standards of quality.
6. Monitoring — Policies and procedures should exist to ensure that the other quality control elements are being
effectively applied.
Quality control standards are established by:
• the Auditing Standards Board for auditors of private companies and
• the Public Company Accounting Oversight Board for auditors of public companies.
Chapter no:4
Management Fraud and Audit Risk
Management Fraud Overview
Financial Statements:
Errors, Frauds and Illegal Acts
• Errors are unintentional misstatements or omissions of amounts or disclosures in financial statements.
• Management Fraud is intentional misstatements or omissions of amounts or disclosures in financial statements.
• Direct-effect illegal acts are violations of laws or government regulations by the company or its management or
employees that produce direct and material effects on dollar amounts in financial statements.
– "Illegal acts" (far-removed) are violations of laws and regulations that are far removed from financial
statement effects (for example, violations relating to insider securities trading, occupational health and
safety, food and drug administration, environmental protection, and equal employment opportunity).
Overview of Auditors’ and Other Professionals’ Responsibilities:
• External Auditors
– Consideration of Fraud in a Financial Statement Audit
• Design audit to provide reasonable assurance of detecting fraud that could have a material effect
on the financial statements.
• Perform fraud-related procedures
– Illegal Acts
• Focused primarily is on direct-effect illegal acts
– “The Auditor’s Communication with Those Charged with Governance”
• Other Professional’s Responsibilities
– Internal Auditors
• Internal auditors support management's efforts to establish a culture that embraces ethics, honesty,
and integrity. They assist management with the evaluation of internal controls used to detect or
mitigate fraud, evaluate the organization's assessment of fraud risk, and are involved in any fraud
investigations.
– Governmental Auditors
• Focus on laws and regulations (compliance), design audit to detect abuse and illegal acts, report to
the appropriate authority
– Certified Fraud Examiners (CFEs)
Assignments begin with predication (probable cause)
Considering the Risk of Fraud:
Step 4: Respond to risk assessment
Risk Factors:
Industry conditions
• Company profits lag the industry.
• New requirements are passed that could impair stability or profitability.
• The company’s market is saturated due to fierce competition.
• The company’s industry is declining.
• The company’s industry is changing rapidly.
Risk Factors:
Operating Characteristics
• A weak internal control environment prevails.
• The company is not able to generate sufficient cash flows to ensure that it is a going concern.
• There is pressure to obtain capital.
• The company operates in a tax haven jurisdiction.
• The company has many difficult accounting measurement and presentation issues.
• The company has significant transactions or balances that are difficult to audit.
• The company has significant and unusual related-party transactions.
• Company accounting personnel are lax or inexperienced in their duties.
Step 3b:
Assess Fraud Risks
• Type of risk
• Significance of risk
• Likelihood of risk
• Pervasiveness of risk
• Assess controls and programs
Required Risk Assessments
• Presume that improper revenue recognition is a fraud risk.
• Identify risks of management override of controls.
– Examine journal entries and other adjustments.
– Review accounting estimates for biases.
– Evaluate business rationale for significant unusual transactions.
Step 4:
Respond to Assessed Risks
• Overall effect on audit
– Assignment of personnel
– Choice of accounting principles
– Predictability of auditing procedures
– Examination of journal entries and other adjustments
– Retrospective review of prior year accounting estimates
• Extended procedures
– Surprise inventory counts
– Contract confirmations
More Examples of Extended Procedures
• Count the petty cash twice in one day. • Match payroll with addresses.
• Investigate suppliers/vendors. • Retrieve customer checks.
• Investigate customers. • Use marked coins and currency.
• Examine endorsements on canceled checks. • Measure deposit lag time.
• Add up the accounts receivable summary. • Examine documents.
• Audit general journal entries. • Inquire, ask questions.
• Match payroll to life and medical insurance • Covert surveillance.
deductions. • Horizontal and vertical analysis.
• Match payroll to social security numbers. • Net worth analysis.
• Expenditure analysis.
Step 5:
Evaluate Audit Evidence
• Discrepancies in the accounting records.
• Conflicting or missing evidential matter.
• Problematic or unusual relationships between the auditor and management.
• Results from substantive of final review stage analytical procedures.
• Vague, implausible or inconsistent responses to inquiries.
Step 6:
Communicate Fraud Matters
• SAS 99: Evidence that fraud may exist must be communicated to appropriate level of management.
• Sarbanes Oxley: Significant deficiencies must be communicated to those charged with governance.
• Any fraud committed by management (no matter how small) is material.
Step 7:
Document Fraud Matters
• Discussion of engagement personnel.
• Procedures to identify and assess risk.
• Specific risks identified and auditor response.
• If revenue recognition not a risk—explain why.
• Results of procedures regarding management override.
• Other conditions causing auditors to believe additional procedures are required.
• Communication to management, audit committee, etc.
Illegal Acts
• Illegal acts are violations of laws or government regulations by the company or its management or employees.
– Direct-effect illegal acts produce direct and material effects on the financial statements (e.g., income
tax evasion).
Indirect-effect illegal acts are far removed from financial statement (e.g., violations relating to insider securities
trading, occupational health and safety, food and drug administration, environmental protection, and equal employment
opportunity).
Red Flags of Potential Illegal Acts
• Unauthorized transactions.
• Government investigations.
• Regulatory reports of violations.
• Payments to consultants, affiliates, or employees for unspecified services.
• Excessive sales commissions and agents’ fees.
• Unusually large cash payments.
• Unexplained payments to government officials.
• Failure to file tax returns or to pay duties and fees.
Auditor Responsibility for Detecting Errors, Frauds, and Illegal Acts
Detection?
(Audit Committee)
Internal Controls
Accounting
Financial
Events, Information Substantive
Transactions
Statements
System
INHERENT RISK AUDIT RISK
DETECTION RISK
The likelihood that, CONTROL RISK The likelihood that
The likelihood that
in the absence of an error or fraud will
The likelihood that an error an error or fraud
internal controls, will not be caught
occur,
an error or fraud or fraud will not get caught by the by the auditor’s and not get caught
procedures.
ARMwill enter the
Concepts
client’s internal controls. by either the internal
ARMaccounting
concepts: controls
• The auditor cannot affect inherent risk or control risk. The auditor can only ASSESS them. or auditor’s
Risk of Material Misstatement (RMM) procedures.
• The auditor can only affect detection risk—generally by examining more evidence.
• Detection risk is inversely related to control risk and inherent risk.
• Detection risk is inversely related to competence and reliability of evidence.
Inherent Risk
• Inherent Risk (IR) is the likelihood that, in the absence of internal controls, a material misstatement could
occur. In other words, it is a measure of the susceptibility of an account to misstatement.
• Factors affecting account inherent risk include:
– Dollar size of the account
– Liquidity
– Volume of transactions
– Complexity of the transactions
• New accounting pronouncements
– Subjective estimates
Other Factors Affecting
Overall Inherent Risk
• Competition
• Economy
• Nature of Industry
• Management Style
• Leverage
Inherent Risk:
General Categories of Errors and Frauds
• Invalid transactions are recorded.
• Valid transactions are omitted from the accounts.
• Unauthorized transactions are executed and recorded.
• Transaction amounts are inaccurate.
• Transactions are classified in the wrong accounts.
• Transaction accounting and posting is incorrect.
• Transactions are recorded in the wrong period.
Inherent Risk:
General Categories of Errors and Frauds
Invalid transactions are A computer malfunction causes a sales Fictitious sales are recorded and
recorded transaction to be recorded twice charged to nonexistent customers
Valid transactions are omitted Shipments to customers are never recorded Shipments are made to an
from the accounts because of problems in the company’s employee’s friend and purposely
information processing system never recorded
Unauthorized transactions are A customer’s order is not approved for credit Unauthorized purchases are made
executed and recorded yet the goods are shipped, billed, and and shipped to an employee’s house
charged to the customer without requiring
payment in advance
Transaction amounts are An employee calculates depreciation A company “short ships” a shipment
inaccurate incorrectly to a customer and bills the customer
for the full amount ordered
Transactions are classified in Sales to a subsidiary company are recorded A loan to the company’s CEO (not
the wrong accounts as sales to outsiders instead of intercompany permitted under Sarbanes-Oxley) is
sales or the amount is charged to the wrong classified as an account receivable to
customer account receivable record conceal the transaction
Transaction accounting and Sales are posted in total to the accounts Capital leases are accounted for as
posting are incorrect receivable control account, but some are not operating leases in order to keep
posted to individual customer account related liabilities off the balance
records sheet
Transactions are recorded in the The company fails to record a shipment that Shipments made in January (of the
wrong period was sent by a supplier FOB shipping point next fiscal year) are backdated and
in December, but the shipment was not recorded as sales in December
received (or recorded) until January
Control Risk
• Control Risk (CR) is the likelihood that a material misstatement would not be caught by the client’s internal
controls.
• Factors affecting control risk include:
– The environment in which the company operates (its “control environment”).
– The existence (or lack thereof) and effectiveness of control procedures.
– Monitoring activities (audit committee, internal audit function, etc.).
Detection Risk
• Detection risk (DR) is the risk that a material misstatement would not be caught by audit procedures.
• Factors affecting detection risk include:
– Nature, timing, and extent of audit procedures
– Sampling risk
• Risk of choosing an unrepresentative sample.
– Nonsampling risk
• Risk that the auditor may reach inappropriate conclusions based upon available evidence.
Detection Risk and the Nature, Timing, and Extent of Audit Procedures
Control Risk
AR IR CR DR?
Materiality
Materiality refers to an amount (or transaction) that would influence the decisions of users (i.e., an amount (or event)
that would make a difference). The emphasis is on user, rather than management or the audit team.
Materiality Criteria:
• Ultimately, materiality is
a matter of professional
Materiality Table: judgment.