0% found this document useful (0 votes)
2 views4 pages

Auditor's Response to CEO Fraud Risks

The document outlines the auditor's responsibilities in response to suspected fraud by the CEO, emphasizing the need for understanding the nature of non-compliance, reporting to the Independent Regulatory Board for Auditors (IRBA), and discussing the matter with management. It highlights the increased fraud risk due to lack of approval for journal entries and the need for heightened professional skepticism and corroborating evidence. The auditor must adjust their approach during execution and completion phases, including modifying the audit report based on management's responses to the identified irregularities.

Uploaded by

mahlalelatrevar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views4 pages

Auditor's Response to CEO Fraud Risks

The document outlines the auditor's responsibilities in response to suspected fraud by the CEO, emphasizing the need for understanding the nature of non-compliance, reporting to the Independent Regulatory Board for Auditors (IRBA), and discussing the matter with management. It highlights the increased fraud risk due to lack of approval for journal entries and the need for heightened professional skepticism and corroborating evidence. The auditor must adjust their approach during execution and completion phases, including modifying the audit report based on management's responses to the identified irregularities.

Uploaded by

mahlalelatrevar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Class Example 1 – Response to Fraud

1) Impact on Reporting Duties

-​ Obtaining an understanding of the matter

The auditor will need to obtain an understanding of the nature of the non-compliance or
SUSPECTED non-compliance, the circumstances thereof, potential implications for users and
entities, and sufficient further information to evaluate the effect on the financial statements

The auditor would need to obtain an understanding regarding the journals that were
processed and if there is a potential of fraud occurring. This would include enquiry with
management to understand the rationale behind the journal.

The journals might indicate that there is a breach of fiduciary duty as the CEO did not
provide reasons in the narration to the journals which manipulate the financial statements.

The matter appears to be significant as it is fraud committed by the CEO, the auditor may
need to obtain legal advice regarding the matter to ensure that the allegations have truth.

If the auditor identifies or suspects non-compliance the auditor shall discuss the matter with
an appropriate level of management or those charged with governance.

o​ The auditor would have to report the matter to IRBA* in terms of section 45
of the Auditing Professions Act as there is possible fraud being committed by
management of the company. As a result the auditor would first report the
matter to IRBA.
o​ Once the matter is reported to IRBA the auditor can then discuss the matter
with management. In this case the auditor can discuss the fraud with those
charged with governance.
o​ The matter should be reported to the Board of Directors or the Audit
Committee as there is a significant deficiency in the internal controls related
to the journals.

* IRBA - The Independent Regulatory Board for Auditors.

-​ Addressing the matter

When discussing the non-compliance with management/those charged with governance,


the auditor shall advise them to remediate the consequences of the fraud and disclose the
matter to the appropriate authorities.

-​ Determine whether further action is required

Depending on the appropriateness of management’s response, the auditor must consider


whether further action is required.
o​ As the audit team has already reported the matter to IRBA, they need to
consider the response from management, including the steps taken by
management to address the reportable irregularity.
o​ The auditor will then have to report back to IRBA to state if the reportable
irregularity is taking place, never took place or has been resolved.
o​ Withdraw from management – this is a consideration that the auditor should
consider.

However, the auditor cannot resign until his/her reporting responsibility to IRBA has been
fulfilled.

Additionally, the fact that a reportable irregularity is reported is not an automatic reason for
the auditor to resign from an audit.

2) Impact on Risk and Response

The CEO has processed and approved a series of journals without any other level of approval
or information provided in the journal narration, bringing into question the integrity of the
CEO.

The fraud risk at the overall financial statement level is to increase based upon the following
factors:
o​ The financial director initiates and approves journal entries (therefore
weakness in the overall control environment as there are no segregation of
duties/overriding of controls with regards to journal entries.
o​ The suspicious narration of the journal entries involved, which could indicate
that actual, valid transactions are being removed from the financial
statements by means of invalid reversals, or that fictitious transactions are
being recorded with them (affects management’s integrity, as might indicate
management override of controls.

With an increased risk of material misstatement at the overall level due to fraud, the auditor
must respond through incorporating overall responses.

o​ Increase the level of professional scepticism through selecting journal entries


on a more unpredictable basis.
o​ Due to the increased risk and the doubt placed on the integrity of the CEO,
place less reliance on all representations from the CEO.
o​ For all representations that have been made by the CEO or others within the
company, obtain more corroborating evidence.
o​ Assign more experienced personnel (such as a manager or other members
who have experience with journal entries or fraud risks) to audit the journals.
The audit team should ensure that more experienced personnel are placed on the audit to
review the work done by juniors to ensure that representations made by management have
been sufficiently and appropriately corroborated.

o​ Given the level of fraud risk, the audit partner should review the work that
has been completed by the trainees.
o​ The audit manager and audit partner, having more experience, should inspect
the accounting policy to determine if there is any sign of earning
management through using aggressive accounting policies.
o​ The audit team should also review the directors performance management
policy to determine any financial performance indicators linked to revenue or
PPE, which could create an incentive for the CEO to manipulate the financial
statements.

As there is an increased risk of material misstatement, the overall materiality and overall
performance materiality should be decreased.

As the overall materiality level is decreasing, the sample sizes used in testing should increase
to ensure sufficient levels of testing.

The auditor should consider whether control testing can still be relied upon when
determining the nature, timing and extent of audit procedures.

The auditor should discuss specifically the increase in fraud risk with the audit team to
identify if there might be any other indicators of fraud.

3) Impact on Execution phase

Select journal entries and other adjustments made at the end of a reporting period and
consider the need to test the journal entries and other adjustments throughout the period.

* This is due to the fact that most instances of fraud are committed towards the year
end of an entity.

All journals processed by the CEO should be tested substantively and all information should
be supported with corroborating evidence.

As the journals affect the PPE balance, change the sampling method used for testing
additions to PPE and select PPE additions that are below performance materiality (or that
are immaterial) to identify any fictitious PPE additions during the year.

The sample sizes for revenue transactions should be increased to identify if there were any
revenue transactions that have occurred which is not supported by the necessary
documentations.
4) Impact of Completion Activities

As there is a reportable irregularity or non-compliance with laws and regulations, the


auditor will have to modify the audit and report and include a section on Other Regulatory
Matters, depending on the outcome of the investigation into the matter.

If management (the board or the audit committee) do not respond sufficiently to the matter,
the auditor may resign from the audit, only once the reportable irregularity process has
been completed.

You might also like