IDENTIFYING AND ASSESSING THE involved in planning the audit,
RISK OF MATERIAL MISTATEMENT including planning and
participating in the discussion
Audit Opinion Formulation Process among engagement team
members.
preliminary engagement
activities include:
Risk Assessment Risk Response Reporting
a. Performing procedures
required by PSA 220, “Quality
Control for Audits of Historical
Financial Information”
regarding the continuance of
the client
Phase I – Risk Assessment
relationship and the specific audit
Preconditions for an audit engagement;
Engagement letter
Identifying RoMM b. Evaluating compliance with
Respond to identify risks of ethical requirements,
RoMM including independence, as
required by PSA 220; and
Phase II – Risk Response
b. Establishing an
Select controls to test understanding of the terms of
Perform test of controls the engagement, as required
Result of TOC by PSA 210, “Terms of Audit
Perform substantive tests Engagements.”
Phase III – Reporting Example: The auditor
Complete review and maintains the necessary
communication activities independence and ability to
Determine the appropriate perform the engagement,
type of opinion to issue there are no issues with
management integrity that
may affect the auditor’s
willingness to continue the
PLANNING AN AUDIT OF engagement, and there is no
FINANCIAL STATEMENTS misunderstanding with the
engagement partner and client as to the terms of the
other key members of the engagement.
engagement team shall be
overall audit strategy sets the a continual and iterative
scope, timing and direction of process
the audit, and that guides the
development of the audit plan ---------------------------------------------------
such as the resources to ------------------------------IDENTIFYING
deploy for specific audit areas AND ASSESSING THE RISKS OF
MATERIAL MISSTATEMENT
audit plan can be developed THROUGH UNDERSTANDING THE
to address the various ENTITY AND ITS ENVIRONMENT
matters identified in the
overall audit strategy, taking Audit Risk- the risk that an auditor
into account the need to gives an incorrect opinion on financial
achieve the audit objectives statements, even when those
through the efficient use of statements contain material
the auditor’s resources. misstatements. (There is an inverse
relationship between materiality and
the auditor shall document: audit risk)
(a) The overall audit strategy; Risk of Material Misstatement - the
probability that a company's financial
(b) The audit plan; and statements contain errors or fraud that
(c) Any significant changes made are significant enough to alter a user's
during the audit engagement to the understanding of the company's
overall audit strategy or the audit plan, financial position
and the reasons for such changes. Risk assessment procedures – The
additional considerations: audit procedures performed to obtain
an understanding of the entity and its
a. Performing procedures environment, including the entity’s
required by PSA 220 internal control, to identify and assess
regarding the acceptance of the risks of material misstatement,
the client relationship and the whether due to fraud or error, at the
specific audit engagement; financial statement and assertion
and levels.
b. Communicating with the Risk assessment procedures
predecessor auditor, where by themselves, do not
there has been a change of provide sufficient appropriate
auditors, in compliance with audit evidence on which to
relevant ethical requirements. base the audit opinion.
planning is not a discrete Include inquiries of
phase of an audit, but rather management, analytical
procedures, and observation for a segment will fail to detect
and inspection misstatements exceeding a tolerable
amount, should such misstatements
Auditor’s assessment of the
exist.
risks of material misstatement
at the assertion level may - It determines the amount of
change during the course of substantial evidence that the
the audit as additional audit auditor plans to accumulate,
evidence is obtained inversely with the size of
Audit Risk - Detection Risk (DR) x planned detection risk.
RoMM PDR = AAR/ (IRxCR)
RoMM = Inherent Risk (IR) x Control Required Understanding of the
Risk (CR) Entity and its Environment,
Including the Entity’s Internal
Inherent Risk - susceptibility of an Control
assertion (a claim about the financial
statements) to misstatement, a. Entity and Its Environment
assuming there are no related internal (relevant industry, regulatory,
controls. It's a measure of how easily a and other external factors
particular area of the financial including the applicable
statements could be misstated due to financial reporting framework,
its nature or the environment it the nature of the entity,
operates in. entity’s selection and
application of accounting
Control Risk - This is the risk that a policies, entity’s objectives
material misstatement will not be and strategies, and those
prevented or detected on a timely related business risks that
basis by the entity's internal controls. It may result in risks of material
reflects the effectiveness of the misstatement, and
company's internal controls in measurement and review of
mitigating potential misstatements. the entity’s financial
performance)
Detection Risk - the possibility that an
auditor's procedures will fail to detect a b. Entity’s Internal Control
material misstatement that exists in (matter of the auditor’s
the financial statements. professional judgment
whether a control, individually
Allowable detection risk or Planned or in combination with others,
detection risk is the amount of risk the is relevant to the audit)
auditor can allow for an assertion or a
measure of the risk that audit evidence
auditor shall evaluate the (c) Assessing the likelihood of their
design and implementation of occurrence; and
those controls other than
inquiry (such as walkthrough) (d) Deciding about actions to address
those risks.
Internal control – The process
designed, implemented and iii. Control activities relevant
maintained by those charged with to the audit: to assess the
governance, management and other risks of material misstatement
personnel to provide reasonable at the assertion level and
assurance about the achievement of design further audit
an entity’s objectives with regard to procedures responsive to
reliability of financial reporting, assessed risks.
effectiveness and efficiency of iii. Monitoring of controls:
operations, and compliance with obtain understanding and
applicable laws and regulations. how the entity initiates
Components are as follows: corrective actions to its
i. Control environment: controls.
evaluate whether *Business risk – A risk resulting from
Management, with the significant conditions, events,
oversight of those charged circumstances, actions or inactions
with governance, has created that could adversely affect an entity’s
and maintained a culture of ability to achieve its objectives and
honesty and ethical behavior; execute its strategies, or from the
and the strengths in the setting of inappropriate objectives and
control environment elements strategies.
collectively provide an
appropriate foundation for the **Significant risk – An identified and
other components of internal assessed risk of material misstatement
control that, in the auditor’s judgment,
requires special audit consideration. In
ii. Risk assessment process: exercising judgment as to which risks
obtain an understanding of are significant risks, the auditor shall
whether the entity has a
process for: consider at least the following:
(a) Identifying business risks* relevant Whether the risk is a risk of
to financial reporting objectives; fraud;
(b) Estimating the **significance of the Whether the risk is related to
risks; recent significant economic,
accounting or other
developments and, therefore, consider the different types of potential
requires specific attention; misstatements that may occur.
The complexity of ---------------------------------------------------
transactions; ------------------------------
Whether the risk involves
significant transactions with
related parties
The degree of subjectivity in
the measurement of financial
information related to the risk,
especially those
measurements involving a
wide range of measurement
uncertainty; and
Whether the risk involves
significant transactions that
are outside the normal course
of business for the entity, or
that otherwise appear to be
unusual.
If significant risks exist, the auditor
shall obtain an understanding of the
entity’s controls, including control
activities, relevant to that risk.
Auditor identify risks of
material misstatements at:
a. The financial statement level
b. The ***assertion level for
classes of transactions,
account balances, and
disclosures
***Assertions – Representations by
management, explicit or otherwise,
that are embodied in the financial
statements, as used by the auditor to