0% found this document useful (0 votes)
10 views21 pages

Regulation in the Auditing Profession

The document discusses the need for regulation in the auditing profession, highlighting the impact of scandals on public trust and the resulting legislative changes like the Sarbanes-Oxley Act. It outlines the legal requirements for audits, the roles and responsibilities of auditors, and the importance of adhering to international standards and ethical codes. Additionally, it details the structure of auditing standards and the quality control measures necessary for maintaining high professional standards in auditing practices.

Uploaded by

Taha Akbar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views21 pages

Regulation in the Auditing Profession

The document discusses the need for regulation in the auditing profession, highlighting the impact of scandals on public trust and the resulting legislative changes like the Sarbanes-Oxley Act. It outlines the legal requirements for audits, the roles and responsibilities of auditors, and the importance of adhering to international standards and ethical codes. Additionally, it details the structure of auditing standards and the quality control measures necessary for maintaining high professional standards in auditing practices.

Uploaded by

Taha Akbar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Chapter no:2

The Auditing Profession


The Auditing Profession
■ Need for Regulation

• The accounting and auditing professions have become under strict regulations more than ever due to
certain events that make the public to lack confidence on how companies are run and audited. (eg the high
level scandals by Ernon and its auditor Arthur Anderson)
• In the US, this resulted in the Sarbanes-Oxley Act 2002 which has not only radically changed the
regulation of the accounting profession in the US but also influenced such issues worldwide.)
■ Need for Regulation

Auditors are regulated by


■ Need for Regulation

In order to regain trust in the auditing profession, national and international standard setters and regulators have tried
to introduce three initiatives:
– Harmonization of auditing procedures, -to increase users confidence in the nature of audits around the
world
– Focus on audit quality

– Adherence to a strict ethical code of conduct

In order to achieve this, practitioners have to follow regulatory guidance: -


– National Corporate Law (The Companies act 2006 in UK, The Sarbanes Oxley Act in US)

– Auditing Standards

– Code of Ethics

■ Need for Regulation

Legal Requirements for Audits and Auditors


– Different countries may have different requirements, but the same principles apply across the world.

National Law includes:


• Which companies are required to have an audit
• Who can and can not carry out an audit
• Auditor appointment, resignation and removal
• The rights and duties of an auditor
■ Need for Regulation

Which companies are required to have an audit?


• In most countries, companies are required by law to have an audit
• Small or owner managed companies are often exempt, because of the less value in an audit for these
companies
• However, these exemptions do not apply to companies in certain regulated sectors, (eg. Financial services
companies or companies listed on stock exchange)
Who can and can not carry out an audit?
 To be eligible to act as auditor, a person must be
• A member of a Recognized Supervisory Body (RSB) eg. ACCA, AICPA and allowed by the rules
of that body to be an auditor or
• Someone directly authorized by the state (sole practitioners, partners in partnership, members of
limited liability partnership, Directors of an audit Company)
 Need for Regulation
 Who may not act as an auditor?
• Excluded by Law: The law in most countries excludes:
 those who manage or work for a company
 those who have business or personal connections with them from auditing that company
• Excluded by the code of Ethics: Auditors must also comply with a code of Ethics. The code of
Ethics require the auditor to consider any factors that would prevent them from acting as auditor
such as independence, competence, or issues regarding confidentiality.
■ Need for Regulation

Who Appoints the Auditor?


• Members/shareholders of the company appoint the auditor by voting.
• Auditors of public Companies are appointed from one Annual General Meeting to the next one
• Auditors of private companies are appointed until they are removed
■ Need for Regulation

Appointments of Auditors
• Auditors have to be reappointed at every annual general meetings(AGM)
• Reappointment is not automatic, to prevent auditors from simply staying in office
• Prior to the firs AGM, the directors can appoint the first auditors,
• If an auditor resigns for some reason, directors can appoint another auditor to fill the casual vacancy.
These appointments only last until the next AGM.
• In any case, Government ensure that all companies have auditor
■ Need for Regulation

Auditors Rights
In order to carryout their duties properly, auditors have very powerful rights:
 They have access to all records they require
 They have a right to receive information and explanation of all transactions
 They have a right to attend and receive notice about general meetings (where all shareholders appear) and
they have right to speak at general meetings
 They have the right to receive in advance information about any resolutions that are proposed to be put at
these general meetings
 They have the right to require the Company’s FSs should be presented at the general meeting
 The right to be informed about, attend, speak and be heard at general meetings gives auditors an
opportunity to communicate with shareholders
■ Need for Regulation

Auditors Duties
 The External Auditor’s primary duty is to audit the financial statements and provide an opinion on
whether the financial statements give a true and fair view (or are fairly presented in all material respects)
 They may have additional reporting responsibilities required by local national law, such as confirming
that the financial statements are properly prepared in accordance with those laws, reporting on internal
control system as requires by Sarbanes Oxley Act of US)
■ Need for Regulation

Resignation of an Auditor
 In practice, if the auditor and management find it difficult to work together, the auditor will usually
resigns
 On resignation, auditors give written notice and statement of circumstances to the shareholders and
regulatory authority
 Why they are required to issue a statement of circumstances?
• Auditors may have resigned because they are deeply concerned about some aspect of the
company’s activities
• Statement of circumstances explains why the auditor has resigned (may be due to innocent
reasons, eg. The auditor feels that the Co. is now too large for the audit firm to deal with. )
• If the auditors are really concerned about the Company, and that is why they have resigned, they
may insist the directors to call a general meeting , to explain for shareholders the reason for their
resignation
■ Need for Regulation

Dismissal of Auditors
• Auditors can be removed from office Directors begin the process to remove the auditor, but the resolution
must be passed by the shareholders (by simple majority at AGM)
• The reason for the removal should be legitimate, eg, the auditor may have failed to detect a material fraud
and directors have lost confidence in their competence; or because of the increase in the company’s size,
international/larger audit firm may be needed)
• The reason may be due to disagreement b/n the auditors and the Mgt. (eg. When auditors insist a change
in some part of financial statement, or when they issue a modified opinion, directors may decide to
remove the auditors). It is for this reason that auditors are required to deposit a ‘statement of
circumstances’, a copy of it will be sent to regulatory bodies.
• The auditors can also receive notices, speak at a general meetings to explain what has happened , if the
removal is without good reason
• Need for Regulation
• International Regulation

■ Need for Regulation

IFAC(The International Federation of Accountants)


• It is a global organization for the accountancy profession
• The IFAC promotes international regulation of the accountancy profession by ensuring minimum
requirements for :
• the accountancy qualifications,
• post qualification experience,
• guidance on accounting and assurance for accountants around the world, so that there will be
greater confidence in the profession as a whole.
■ The Purpose of IFAC is to serve the public interest by establishing and promoting adherence to high quality
professional standards
■ Need for Regulation

IFAC(The International Federation of Accountants), has a number of boards including:


• ISSAB (International Auditing and Assurance Standards Board)-sets International Standards on
Auditing (ISAs) and other assurance standards
• IESBA(International Ethics Standards Board for Accountants)issues the International Code of
Ethics for professional Accountants)
International Standards on Auditing (ISAs)
– Set by ISSAB
– Currently there are 37 ISAs and one International Standards on Quality Control (ISQC)

■ Need for Regulation

Audit standards used in professional practice by audit firms in US,


1. International Standards on Auditing (ISAs) issued by the International Auditing and Assurance Standards
Board (IAASB).
2. AICPA Auditing Standards (referred to as U.S. Generally Accepted Auditing Standards (GAAS), set by
the Auditing Standards Board (ASB) of the AICPA
3. PCAOB Auditing Standards
■ Need for Regulation

How these standards relate?


■ The International Standards on Auditing (ISAs) have many of the same standards as the Auditing Standards
Board (ASB)
■ The Auditing Standards Board has revised most of its standards to converge with the international standards.

• The ASB Clarity Project was intended to make the U.S. auditing standards easier to read, understand, and
apply.
• The ASB redrafted existing AICPA auditing standards to align them with respective ISAs
■ The PCAOB considers International Standards on Auditing (ISA) when developing its standards.

■ Need for Regulation

■ International Standards on Auditing (ISAs)

• IASs are issued by the International Auditing and Assurance Standards Board (IAASB) of the
International Federation of Accountants (IFAC)
• The IAASB works to improve the uniformity of auditing practices and related services throughout the
world
• Currently, International Audit Standards have 37 Standard And 1 Quality Control Standard:
■ Need for Regulation

■ Main features of International Standards on Auditing (ISAs)

• ISAs are professional guidance that the auditor must follow to ensure each audit is performed consistently
and to a required standard of quality
• ISAs are not legal requirements. If a country has a law in place which is inconsistent with the
requirements of ISAs, local law should be followed
• ISAs are written in the context of and audit of FSs, but can be applied to the audit of other historical
financial information
• ISAs must be applied in all, but exceptional cases., where the auditor deems it necessary to depart from
ISA to achieve the overall aim of the audit, the departure must be justified
• ISAs contain basic principles and requirements followed by application and other explanatory materials to
aid the auditor on how to follow the requirements
■ Need for Regulation

■ International Standards on Auditing (ISAs)

1. 200 Series: General Principles and Responsibilities


2. 300 and 400 Series: Assessment and Response to Assessed Risks
3. 500 Series: Evidence
4. 600 Series: Using the work of others
5. 700 Series: Audit conclusions and reporting
6. International Standard on Quality Control (ISQC)
■ Need for Regulation

■ 200 Series: General Principles and Responsibilities

• ISA 200: Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance with
International Standards on Auditing
• ISA 210: Agreeing the Terms of Audit Engagements
• ISA 220: Quality Control for an Audit of Financial Statements
• ISA 230: Audit Documentation
• ISA 240: The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
• ISA 250: Consideration of Laws and Regulations in an Audit of Financial Statements
• ISA 260: Communication with Those Charged with Governance
• ISA 265: Communicating Deficiencies in Internal Control to Those Charged with Governance and Management
■ Need for Regulation

300 and 400 Series: Assessment and Response to Assessed Risks


• ISA 300: Planning an Audit of Financial Statements
• ISA 315: Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its
Environment
• ISA 320: Materiality in Planning and Performing an Audit
• ISA 330: The Auditor’s Responses to Assessed Risks
• ISA 402: Audit Considerations Relating to an Entity Using a Service Organization
• ISA 450: Evaluation of Misstatements Identified during the Audit
■ Need for Regulation

500 Series: Evidence


• ISA 500: Audit Evidence
• ISA 501: Audit Evidence-Specific Considerations for Selected Items
• ISA 505: External Confirmations
• ISA 510: Initial Audit Engagements-Opening Balances
• ISA 520: Analytical Procedures
• ISA 530: Audit Sampling
• ISA 540: Auditing Accounting Estimates, Including Fair Value Accounting Estimates, and Related Disclosures
• ISA 550: Related Parties
• ISA 560: Subsequent Events
• ISA 570: Going Concern
• ISA 580: Written Representations
■ Need for Regulation

600 Series and 700 Series


• ISA 600: Special Considerations-Audits of Group Financial Statements (Including the Work of Component
Auditors)
• ISA 610: Using the Work of Internal Auditors
• ISA 620: Using the Work of an Auditor’s Expert
• ISA 700: Forming an Opinion and Reporting on Financial Statements
• ISA 701:Communicating Key Audit Matters in the Independent Auditors Report
• ISA 705: Modifications to the Opinion in the Independent Auditor’s Report
• ISA 706 Emphasis of Matter Paragraphs and Other Matter Paragraphs in the Independent Auditor’s Report
• Need for Regulation
• ISA 710: Comparative Information-Corresponding Figures and Comparative Financial Statements
• ISA 720: The Auditor’s Responsibilities Relating to Other Information in Documents Containing Audited
Financial Statements
• International Standard on Quality Control (ISQC) 1, Quality Controls for Firms that Perform Audits and
Reviews, and Other Assurance Services
■ Need for Regulation

■ Organization of U.S. Auditing Standards (How it is structured)

• The principles are not requirements and do not carry authority, but they provide structure for the Codification.
The structure is organized around the following principles:
1. Purpose of an audit: To Provide opinion about financial statements
2. Responsibilities: Personal responsibilities of an auditor,
• Possess appropriate competence and capabilities
• Comply with ethical requirements
• Maintain professional skepticism and
• Exercise professional judgment
■ Need for Regulation

■ Organization of U.S. Auditing Standards (How it is structured)

3. Performance
• Obtain reasonable assurance about whether financial statements are free of material misstatement
• Plan work and supervise assistants
• Determine and apply materiality level or levels
• Identify and assess risks of material misstatement based on understanding of entity and its environment,
including internal controls
• Obtain sufficient appropriate audit evidence
■ Need for Regulation

4. Reporting
 Express opinion on financial statements in a written report
• Whether financial statements are presented fairly in accordance with financial reporting
framework
5. Need for Regulation
6. Auditing Standards (How it is structured)
7. Principles versus auditing Standards
 The principles underlying auditing standards are too general to provide meaningful guidance
 The principles are not requirements and do not carry authority, but they provide structure for the
Codification.
 Auditing standards are regarded as authoritative literature, and every member who performs audits of
historical financial statements is required to follow them under the AICPA Code of Professional Conduct.
■ Need for Regulation
■ Quality control

■ The Six Elements of Quality Control Standards

1. Leadership responsibilities for quality within the firm — The firm should promote a culture that quality is
essential in performing engagements and should establish policies and procedures that support that culture.
2. Relevant ethical requirements — All personnel on engagements should maintain independence in mind and in
appearance, perform all professional responsibilities with integrity and maintain objectivity in performing their
professional responsibilities.
■ Need for Regulation

3. Acceptance and continuation of client relationships and engagements — Policies and procedures should be
established for deciding whether to accept or continue a client relationship or specific engagement.
These policies and procedures should minimize the risk of associating with a client whose management lacks integrity.
The firm should also only undertake engagements that can be completed with professional competence.
■ Need for Regulation

4. Human resources — Policies and procedures should be established to provide the firm with reasonable assurance
that:
• all new personnel are qualified to perform their work competently,
• work is assigned to personnel who have adequate technical training and proficiency,
• all personnel should participate in continuing professional education and professional development
activities that enable them to fulfill their assigned responsibilities, and
• personnel selected for advancement should have the qualifications necessary for the fulfillment of their
assigned responsibilities.
■ Need for Regulation

5. Engagement performance — Policies and procedures should exist to ensure that the work performed by
engagement personnel meets applicable professional standards , legal and regulatory requirements, and the firm's
standards of quality.
6. Monitoring — Policies and procedures should exist to ensure that the other quality control elements are being
effectively applied.
Quality control standards are established by:
• the Auditing Standards Board for auditors of private companies and
• the Public Company Accounting Oversight Board for auditors of public companies.
Chapter no:4
Management Fraud and Audit Risk
Management Fraud Overview

Financial Statements:
Errors, Frauds and Illegal Acts
• Errors are unintentional misstatements or omissions of amounts or disclosures in financial statements.
• Management Fraud is intentional misstatements or omissions of amounts or disclosures in financial statements.
• Direct-effect illegal acts are violations of laws or government regulations by the company or its management or
employees that produce direct and material effects on dollar amounts in financial statements.
– "Illegal acts" (far-removed) are violations of laws and regulations that are far removed from financial
statement effects (for example, violations relating to insider securities trading, occupational health and
safety, food and drug administration, environmental protection, and equal employment opportunity).
Overview of Auditors’ and Other Professionals’ Responsibilities:
• External Auditors
– Consideration of Fraud in a Financial Statement Audit
• Design audit to provide reasonable assurance of detecting fraud that could have a material effect
on the financial statements.
• Perform fraud-related procedures
– Illegal Acts
• Focused primarily is on direct-effect illegal acts
– “The Auditor’s Communication with Those Charged with Governance”
• Other Professional’s Responsibilities
– Internal Auditors
• Internal auditors support management's efforts to establish a culture that embraces ethics, honesty,
and integrity. They assist management with the evaluation of internal controls used to detect or
mitigate fraud, evaluate the organization's assessment of fraud risk, and are involved in any fraud
investigations.
– Governmental Auditors
• Focus on laws and regulations (compliance), design audit to detect abuse and illegal acts, report to
the appropriate authority
– Certified Fraud Examiners (CFEs)
Assignments begin with predication (probable cause)
Considering the Risk of Fraud:
Step 4: Respond to risk assessment

Step 1: Audit team discussion(“brainstorming”)


Step 5: Evaluate audit evidence

Step 2: Identify information necessary to assess


fraud risk factors Step 6: Communicate fraud matters

Step 3: a. Identify and


Step 7: Document fraud matters
b. Assess fraud risk factors

• Gather information to identify risks.


• Identify risks.
• Assess risks taking into account entity’s programs and controls.
• Respond to results of assessment.
Step 1:
Audit team discussion (“brainstorming”)
• Required procedure
• Objectives
– Gain understanding of
• Previous experiences with client
• How a fraud might be perpetrated and concealed in the entity
• Procedures that might detect fraud
– Set proper tone for engagement
• Discussions should be ongoing throughout the engagement
Step 2:
Obtain Information to Identify Risks
• Inquiries
– Management
– Audit committee
– Internal auditors
– Others
• Planning analytical procedures
– Net income to cash flows (total accruals to total assets)
– Days sales in receivables
– Gross margin
– Asset quality index (non current assets- p,p&e to total assets)
– Sales growth index
Step 3a:
Identify Risk Factors Related to Fraudulent Financial Reporting
• Management’s characteristics and influence
• Industry conditions
• Operating characteristics and financial stability
Risk Factors:
Management’s Characteristics and Influence
• Management has a motivation to engage in fraudulent reporting.
• Management decisions are dominated by an individual or a small group.
• Management fails to display an appropriate attitude about internal control.
• Managers’ attitudes are very aggressive toward financial reporting.
• Managers place too much emphasis on earnings projections.
• Nonfinancial management participates excessively in the selection of accounting principles or determination of
estimates.
• The company has a high turnover of senior management.
• The company has a known history of violations.
• Managers and employees tend to be evasive when responding to auditors’ inquiries.
• Managers engage in frequent disputes with auditors.

Risk Factors:
Industry conditions
• Company profits lag the industry.
• New requirements are passed that could impair stability or profitability.
• The company’s market is saturated due to fierce competition.
• The company’s industry is declining.
• The company’s industry is changing rapidly.
Risk Factors:
Operating Characteristics
• A weak internal control environment prevails.
• The company is not able to generate sufficient cash flows to ensure that it is a going concern.
• There is pressure to obtain capital.
• The company operates in a tax haven jurisdiction.
• The company has many difficult accounting measurement and presentation issues.
• The company has significant transactions or balances that are difficult to audit.
• The company has significant and unusual related-party transactions.
• Company accounting personnel are lax or inexperienced in their duties.
Step 3b:
Assess Fraud Risks
• Type of risk
• Significance of risk
• Likelihood of risk
• Pervasiveness of risk
• Assess controls and programs
Required Risk Assessments
• Presume that improper revenue recognition is a fraud risk.
• Identify risks of management override of controls.
– Examine journal entries and other adjustments.
– Review accounting estimates for biases.
– Evaluate business rationale for significant unusual transactions.

Step 4:
Respond to Assessed Risks
• Overall effect on audit
– Assignment of personnel
– Choice of accounting principles
– Predictability of auditing procedures
– Examination of journal entries and other adjustments
– Retrospective review of prior year accounting estimates
• Extended procedures
– Surprise inventory counts
– Contract confirmations
More Examples of Extended Procedures

• Count the petty cash twice in one day. • Match payroll with addresses.
• Investigate suppliers/vendors. • Retrieve customer checks.
• Investigate customers. • Use marked coins and currency.
• Examine endorsements on canceled checks. • Measure deposit lag time.
• Add up the accounts receivable summary. • Examine documents.
• Audit general journal entries. • Inquire, ask questions.
• Match payroll to life and medical insurance • Covert surveillance.
deductions. • Horizontal and vertical analysis.
• Match payroll to social security numbers. • Net worth analysis.
• Expenditure analysis.

Step 5:
Evaluate Audit Evidence
• Discrepancies in the accounting records.
• Conflicting or missing evidential matter.
• Problematic or unusual relationships between the auditor and management.
• Results from substantive of final review stage analytical procedures.
• Vague, implausible or inconsistent responses to inquiries.
Step 6:
Communicate Fraud Matters
• SAS 99: Evidence that fraud may exist must be communicated to appropriate level of management.
• Sarbanes Oxley: Significant deficiencies must be communicated to those charged with governance.
• Any fraud committed by management (no matter how small) is material.

Step 7:
Document Fraud Matters
• Discussion of engagement personnel.
• Procedures to identify and assess risk.
• Specific risks identified and auditor response.
• If revenue recognition not a risk—explain why.
• Results of procedures regarding management override.
• Other conditions causing auditors to believe additional procedures are required.
• Communication to management, audit committee, etc.
Illegal Acts
• Illegal acts are violations of laws or government regulations by the company or its management or employees.
– Direct-effect illegal acts produce direct and material effects on the financial statements (e.g., income
tax evasion).
Indirect-effect illegal acts are far removed from financial statement (e.g., violations relating to insider securities
trading, occupational health and safety, food and drug administration, environmental protection, and equal employment
opportunity).
Red Flags of Potential Illegal Acts
• Unauthorized transactions.
• Government investigations.
• Regulatory reports of violations.
• Payments to consultants, affiliates, or employees for unspecified services.
• Excessive sales commissions and agents’ fees.
• Unusually large cash payments.
• Unexplained payments to government officials.
• Failure to file tax returns or to pay duties and fees.
Auditor Responsibility for Detecting Errors, Frauds, and Illegal Acts

Responsible for Must Communicate Findings?

Detection?

Material Immaterial Material Immaterial

Errors Yes No Yes No

(Audit Committee)

Fraud Yes No Yes Yes

(Audit Committee) (One level above)

Illegal Acts Yes No Yes Yes

(Direct Effect) (Audit Committee) (One level above)


The AUDIT RISK MODEL (ARM)
• Audit risk (AR) is the risk (likelihood) that the auditor may unknowingly fail to modify the opinion on
financial statements that are materially misstated (e.g., an unqualified opinion on misstated financial
statements.)
• The AUDIT RISK MODEL decomposes overall audit risk into three components: inherent risk (IR), control risk
(CR), and detection risk (DR):
AR = IR x CR x DR
(IR x CR = Risk of Material Misstatement (RMM))
Inherent, Control and Detection Risk:

Internal Controls

Accounting
Financial
Events, Information Substantive
Transactions
Statements
System
INHERENT RISK AUDIT RISK
DETECTION RISK
The likelihood that, CONTROL RISK The likelihood that
The likelihood that
in the absence of an error or fraud will
The likelihood that an error an error or fraud
internal controls, will not be caught
occur,
an error or fraud or fraud will not get caught by the by the auditor’s and not get caught
procedures.
ARMwill enter the
Concepts
client’s internal controls. by either the internal
ARMaccounting
concepts: controls

• The auditor cannot affect inherent risk or control risk. The auditor can only ASSESS them. or auditor’s
Risk of Material Misstatement (RMM) procedures.
• The auditor can only affect detection risk—generally by examining more evidence.
• Detection risk is inversely related to control risk and inherent risk.
• Detection risk is inversely related to competence and reliability of evidence.
Inherent Risk
• Inherent Risk (IR) is the likelihood that, in the absence of internal controls, a material misstatement could
occur. In other words, it is a measure of the susceptibility of an account to misstatement.
• Factors affecting account inherent risk include:
– Dollar size of the account
– Liquidity
– Volume of transactions
– Complexity of the transactions
• New accounting pronouncements
– Subjective estimates
Other Factors Affecting
Overall Inherent Risk
• Competition
• Economy
• Nature of Industry
• Management Style
• Leverage
Inherent Risk:
General Categories of Errors and Frauds
• Invalid transactions are recorded.
• Valid transactions are omitted from the accounts.
• Unauthorized transactions are executed and recorded.
• Transaction amounts are inaccurate.
• Transactions are classified in the wrong accounts.
• Transaction accounting and posting is incorrect.
• Transactions are recorded in the wrong period.

Inherent Risk:
General Categories of Errors and Frauds

Error Examples Fraud Examples

Invalid transactions are A computer malfunction causes a sales Fictitious sales are recorded and
recorded transaction to be recorded twice charged to nonexistent customers

Valid transactions are omitted Shipments to customers are never recorded Shipments are made to an
from the accounts because of problems in the company’s employee’s friend and purposely
information processing system never recorded

Unauthorized transactions are A customer’s order is not approved for credit Unauthorized purchases are made
executed and recorded yet the goods are shipped, billed, and and shipped to an employee’s house
charged to the customer without requiring
payment in advance
Transaction amounts are An employee calculates depreciation A company “short ships” a shipment
inaccurate incorrectly to a customer and bills the customer
for the full amount ordered

Transactions are classified in Sales to a subsidiary company are recorded A loan to the company’s CEO (not
the wrong accounts as sales to outsiders instead of intercompany permitted under Sarbanes-Oxley) is
sales or the amount is charged to the wrong classified as an account receivable to
customer account receivable record conceal the transaction

Transaction accounting and Sales are posted in total to the accounts Capital leases are accounted for as
posting are incorrect receivable control account, but some are not operating leases in order to keep
posted to individual customer account related liabilities off the balance
records sheet

Transactions are recorded in the The company fails to record a shipment that Shipments made in January (of the
wrong period was sent by a supplier FOB shipping point next fiscal year) are backdated and
in December, but the shipment was not recorded as sales in December
received (or recorded) until January

Control Risk
• Control Risk (CR) is the likelihood that a material misstatement would not be caught by the client’s internal
controls.
• Factors affecting control risk include:
– The environment in which the company operates (its “control environment”).
– The existence (or lack thereof) and effectiveness of control procedures.
– Monitoring activities (audit committee, internal audit function, etc.).

Detection Risk
• Detection risk (DR) is the risk that a material misstatement would not be caught by audit procedures.
• Factors affecting detection risk include:
– Nature, timing, and extent of audit procedures
– Sampling risk
• Risk of choosing an unrepresentative sample.
– Nonsampling risk
• Risk that the auditor may reach inappropriate conclusions based upon available evidence.

Detection Risk and the Nature, Timing, and Extent of Audit Procedures

Lower Detection Risk Higher Detection Risk

Nature More effective tests. Less effective tests.

Timing Testing performed at year-end. Testing can be performed at Interim.

Extent More tests. Fewer tests.

Example of the Audit Risk Model

• AR =.05 (set by firm) • Low


• IR =.90 (nature of account) • High
• CR =.70 (assessed by • Medium High
auditor)
• DR =.08 [.05/(.90 X .70)] • Low
=.08

Matrix Approach to Detection Risk Determination

Control Risk

Low Moderate High

Inherent Low High Moderate to Moderate


High
Risk Detection Risk Detection Risk
Detection Risk
Moderate Moderate to High Moderate Low to
Moderate
Detection Risk Detection Risk
Detection Risk
High Moderate Low to Moderate Low
More Examples:

AR IR CR DR?

.05 1.0 .50 .10

.05 .50 .05 2.0?

Low Moderate Moderate Low

Very Low Low High Mediam

Materiality
Materiality refers to an amount (or transaction) that would influence the decisions of users (i.e., an amount (or event)
that would make a difference). The emphasis is on user, rather than management or the audit team.
Materiality Criteria:

• Ultimately, materiality is
a matter of professional
Materiality Table: judgment.

Quantitative Criteria: Qualitative Criteria


– Absolute size – Nature of the
General Audit Procedures
• Inspection of records and documents
– Vouching
– Tracing
– Scanning
• Inspection of tangible assets
• Observation
• Inquiry
• Confirmation
• Recalculation
• Reperformance
• Analytical Procedures

You might also like