Chapter-2
1. Qualification of an auditor as per the company act
2. The rights and power of an audit as per the company act
3. The responsibilities of management and auditors regarding laws and regulations in an
audit of financial statement
4. Describe the audit procedures to identify non-compliance with laws and regulations ?
Chapter-1
1. Define assurance . explain the elements of assurance arrangement
2. Define audit ? the purpose and objective of audit?
3. What is expectations gap in audit give an example?
4. Benefits of auditing
5. Audit is reasonable assurance engagement rather than absolute assurance.
6. Evaluate the quote,” every international business, large or small, should have an
annual audit by an independent auditor? Why should an auditor review the financial
statement of a company each year?
7. The general public thinks that an auditor guarantees the accuracy of financial
statement . is this true? Why? What other things does the public believe about
audited financial statement?
Assurance: An assurance engagement is when a professional reviews something (like financial
data or a report) and gives an opinion to help users—other than the ones who prepared it—feel
more confident that it meets certain standards or criteria.
Reasonable assurance engagement
Gathers enough good evidence: The inspector collects a lot of reliable information to be
confident in their findings. Imagine them checking everything carefully, not just taking
someone's word for it.
Decides if things meet the standards: They then check if what they inspected (the "subject
matter," like a company's internal controls) meets all the important rules or guidelines (the
"suitable criteria"). If there are any big problems, they'll notice them.
Gives a positively worded assurance opinion.
Positive form (reasonable assurance engagement): “In our opinion internal control is effective,
in all material respects, based on XYZ criteria.
Limited Assurance engagement
In a limited assurance assignment, the practitioner:
• Gathers sufficient appropriate evidence to be able to draw limited conclusions.
• States that the subject matter seems reasonable based on the set criteria.
• Gives a negatively worded assurance opinion.
Negative form (limited assurance engagement): “Based on our work described in this
report, nothing has come to our attention that causes us to believe that internal control is
not effective, in all material respects, based on XYZ criteria.
Objective of the auditor’s
ISA 200 Overall Objectives of the Independent Auditor and the Conduct of an Audit.
Auditor's fundamental objectives are to
Deliver reasonable assurance that the financial statements are free from major errors
or fraud.
Give an informed opinion on whether the financials are accurately prepared as per the
relevant accounting standards.
Report findings clearly, and communicate any key matters as required by
International Standards on Auditing (ISAs).
In short: The auditor checks for major issues, gives a professional judgment, and reports
transparently to stakeholders.
Benefits of audit
Enhances information quality and reliability, supporting sound business decisions.
Builds investor confidence and strengthens market reputation.
Provides independent validation, which is often insightful for management.
An audit may reduce the risk of management bias, fraud and error by acting as a
deterrent.
Boosts credibility of financials with tax authorities, lenders, and regulators.
Identifies control weaknesses, helping to strengthen internal systems.
Auditors recommending improvements in company systems..
The purpose and objective of an audit
Purpose: The purpose of an audit is to enhance the degree of confidence of the intended users in
the financial statements
objective: The main goal of an external audit is to let the auditor give an opinion on whether
the financial statements:
Show a true and fair picture of the company’s financial position.
Follow the correct accounting rules and standards (financial reporting framework).
Review engagement: Small companies that aren't required by law to get a full audit, can still
choose to have a financial review. This helps them present their accounts—such as to banks or
other potential lenders—to build trust and improve credibility.
A review engagement is a type of limited assurance engagement. The goal is for the auditor
to check the financial statements using fewer procedures than a full audit. Based on this
limited work, the auditor states whether anything seems wrong or not in line with the
required reporting standards. This is called giving “negative” or “limited” assurance.
1. Evaluate the quote,” every international business, large or small, should have an annual
audit by an independent auditor? Why should an auditor review the financial statement
of a company each year?
This quote highlights a strong recommendation for good financial practices. Whether big
or small, international companies benefit from yearly audits for several reasons:
1. Builds Trust and Transparency
An independent audit shows that a company’s financial statements are honest and follow
proper rules. This builds trust with banks, investors, suppliers, and governments.
2. Helps Find Problems Early
Auditors can spot errors, fraud, or weaknesses in how the company handles money.
Fixing these early reduces financial risk.
3. Makes It Easier to Get Loans or Investment
Lenders and investors usually want to see audited financials before giving money. An
audit improves a company’s chances of getting funding.
4. Supports Better Decisions
The audit report helps management understand the company’s financial health. This leads
to smarter business decisions.
5. Shows Good Governance
Even small international businesses that get audited show they take responsibility
seriously. It’s a sign of professionalism and good management.
Why Should an Auditor Review the Financial Statements Each Year?
5. To check if the financial statements are accurate and reliable.
6. To give confidence to shareholders, investors, and lenders.
7. To find and correct mistakes or fraud.
8. To help improve internal systems and controls.
9. To make sure the company follows accounting rules and laws.
-
CHAPTER-4
The fundamental principles
Objectivity: Members must stay fair and neutral—no bias, personal interest, or outside
pressure should affect their decisions.
Professional Behaviour: Members must follow the law and avoid doing anything that could
damage the reputation of the profession.
Professional Competence and Due Care: Members must keep their skills and knowledge up
to date so they can give clients or employers high-quality service.
Integrity: Members must always be honest and transparent in all professional and business
dealings.
Confidentiality: Members must keep sensitive information private and not share it unless
legally or professionally required. It must never be used for personal gain.
Threats and safeguards
1. Self-interest
2. Self-review
3. Advocacy
4. Familiarity
5. Intimidation: An intimidation threat happens when the auditor feels
pressured, threatened, or influenced—either directly or indirectly—by
powerful individuals at the client organization (like the CEO, CFO, or
board members) or by an aggressive corporate culture.
Objective of engagement letter:
The roles and responsibilities of both the auditor and management must be clearly defined
and reviewed every year.
The auditor must provide written confirmation (engagement letter) when accepting the
audit.
If the scope or nature of the audit changes, a new engagement letter must be issued.
To reinforce the importance of the audit, a new engagement letter should be sent annually,
even if there are no changes.
Any additional reports required beyond the standard audit report must be clearly listed in
the engagement terms.
Why External Audit Is Needed (Simplified)
The Need for External Audit (Simplified Explanation)
1. Separation of Ownership and Control
o Shareholders own the company but are not involved in daily operations.
o Directors run the company on behalf of shareholders.
2. Trust and Transparency
o Directors prepare financial statements to show the company's performance.
o Without oversight, they may have incentives to manipulate the results.
3. Independent Assurance
o An external audit provides objective verification of financial information.
o This builds confidence among shareholders, creditors, and other stakeholders.
4. Legal and Regulatory Compliance
o In many countries, large and listed companies must be audited by law.
o It ensures the company complies with financial reporting standards.
5. Enhanced Credibility
o Audited accounts increase the credibility of financial statements.
o This supports investment decisions, credit approval, and business reputation.
6. Voluntary Assurance
o Even if not legally required, companies may opt for an audit to meet the
expectations of investors, banks, or regulators.
Chapter-2
Rules and regulations
Questions
Qualification of an auditor as per the company act
The rights and power of an audit as per the company act
The responsibilities of management and auditors regarding laws and regulations in an
audit of financial statement
Describe the audit procedures to identify non-compliance with laws and regulations ?
To help rebuild trust in the auditing profession, national and international regulators have taken
three key steps:
Standardizing audit procedures so people everywhere can trust that audits are done the
same way globally.
Improving audit quality to meet the expectations of users.
Following a strict ethical code to show that auditors are independent and fair.
Qualification of an auditor:
importance of Qualification for Auditors
Qualification is very important for doing any job well. It includes specific skills and experience
needed to complete a task successfully. Like any other profession, auditing also requires proper
qualifications.
An auditor is the person appointed to carry out auditing work, and the success of that work
depends heavily on the auditor’s qualifications. To be an auditor for a company, a person must
meet certain requirements.
1. Professional or Legal Qualification:
According to Section 212(1) of the Companies Act 1994, an auditor must be a Chartered
Accountant as defined under the Bangladesh Chartered Accountants Act, 1973.
If all partners in a firm are qualified, the firm can be appointed as the company’s auditor. In such
cases, any partner from the firm may carry out the audit on behalf of the firm.
2. General Qualifications:
Besides the professional qualification, an auditor should also have the following:
Good knowledge of accounting
Understanding of the Companies Act, Income Tax Act, and industry-related laws
Knowledge of business operations, industrial and financial management
Familiarity with bookkeeping systems
Sharp, skilled, and intelligent
Honest and unbiased
Disqualification of an auditor:
According to Section 212(2) of the Companies Act 1994, the following people cannot be
appointed as auditors of a company:
1. A company or body corporate (only individuals or firms are allowed).
2. Any officer or employee of the company.
3. Anyone who is a partner or employee of the company’s officer or employee.
4. Anyone who owes the company more than Tk 1000, or who has given a guarantee or
security for someone else's debt to the company over Tk 1000.
5. Anyone who is a director or member of a private company, or a partner in a firm that is
a managing agent of the company.
6. Anyone who is a director or owns more than 5% of the shares (in nominal value) of a
managing agent company.
According to Section 212(3):
If someone is disqualified from being an auditor for a company, they are also disqualified
from auditing its holding company, subsidiary, or fellow subsidiary.
The same rule applies even if the other company isn’t technically a “company” under the
law.
According to Section 212(4):
If an auditor becomes disqualified after being appointed, they will automatically lose
their position immediately.
Appointment of an Auditor:
Appointment of First Auditor:
The first auditor of a company must be appointed by the directors within one month
from the date the company is registered.
This auditor will stay in office until the first general meeting of the company.
There are two additional important points:
1. The members (shareholders) of the company can remove the first auditor at the first
general meeting and appoint someone else, if a nomination has been submitted at least
14 days before the meeting.
2. If the directors fail to appoint the first auditor within one month, then the shareholders
can appoint the auditor in the general meeting.
If a partnership firm is appointed as the auditor, it means all partners of that firm at the
time are considered appointed as auditors.
Subsequent Appointment of Auditors
(According to Section 210(1) of the Companies Act)
1. At every annual general meeting (AGM), the company must appoint an auditor to
hold office until the next AGM.
2. If no auditor is appointed or reappointed at the AGM, the government will appoint
one to fill the vacancy.
3. The company must inform the government within 7 days if the government needs to
appoint an auditor.
If the company fails to give this notice, both the company and the responsible officers
may be fined up to Tk 100.
4. If the auditor's appointment at the AGM is found to be invalid, a new auditor must be
appointed at a general meeting of shareholders.
Casual Vacancy in the Office of Auditor
(According to Section 210(7))
If an auditor resigns or dies during their term, the following rules apply:
1. If the vacancy is not due to resignation, the board of directors can fill the position.
However, any remaining auditors can continue to work until it’s filled.
2. If the vacancy is caused by resignation, only the general meeting can appoint a new
auditor.
3. An auditor appointed to fill a casual vacancy will stay in office until the next annual
general meeting.
Appointment of Branch Auditor
(According to Section 214(1))
1. A branch office of a company can be audited by the main company auditor.
2. If the company wants someone other than the main auditor to audit the branch, the
shareholders can appoint that person in a general meeting.
3. If allowed by the shareholders through a resolution, the board of directors can appoint
the branch auditor.
o In this case, the board must consult the company’s main auditor before making
the appointment.
Removal of Auditor – Simplified Explanation
REMUNERATION OF AN AUDITOR : The remuneration of an auditor of a company shall be
fixed as under sec .252(8). The rules are given below:
1) If the auditor has been appointed by the board of Director, it is the board which fixes his
remuneration.
2) If the auditor has been appointed by the Government under certain circumstances, the
government fixes his remuneration.
3) If the auditor has been appointed by the shareholders at the general meeting, it is the company
which determines his remuneration
4→ If an auditor is re-appointed automatically at the Annual General Meeting, and no
resolution changes the fee, they will continue to receive the same remuneration as before.
5.→ If the auditor is asked to perform additional tasks (e.g., preparing final accounts or tax
returns), they are entitled to extra payment beyond normal audit fees
Right and power of an auditor from the sheet
Chapter-3
Governance issues in Financial Service Audit
Qualifications of Committee Members (Simplified):
1. The member should be honest, committed, and able to give enough time to the
committee's work.
2. Each member should be able to contribute effectively to the committee’s activities.
3. Members should understand their duties well and be familiar with the bank’s business,
operations, and risks.
4. People with professional experience in banking or financial institutions, especially those
with education in Finance, Banking, Management, Economics, or Accounting, will be
given preference.
Roles and responsibilities of audit committee:
(i) Internal Control:
1. Promote Compliance Culture
Ensure that management encourages a culture of compliance, risk management, and that
all staff understand their roles clearly.
2. Review Digital Systems
Check how well the bank is implementing technology, including computer systems and
the Management Information System (MIS).
3. Follow-Up on Audit Recommendations
See if the management has implemented internal control measures suggested by internal
and external auditors.
4. Address Issues Like Fraud
Review reports of fraud, errors, or control failures from auditors or regulators, and check
if management has taken the right steps to fix them. Report these to the board.
(vi) Other Responsibilities
1. Report to the Board
Submit a quarterly report to the board on how issues like fraud, mistakes, and other
irregularities (found by auditors or regulators) have been fixed.
2. Request Auditor Reports
Ask for specific reports from internal or external auditors when needed.
3. Additional Duties
Do other monitoring tasks assigned by the Board and regularly review the committee’s
own performance.
Meetings
1. The audit committee must meet at least 4 times a year, and more if needed.
2. It can invite the CEO, Head of Internal Audit, or other officers to join the meetings
when necessary.
3. A detailed agenda should be shared with members before each meeting to ensure active
participation.
4. All decisions and discussions must be recorded in the meeting minutes.
Chapter-5
RISK
Audit risk is the risk that an auditor may unknowingly fail to detect material misstatements in
a company's financial statements. In simple terms, it's the risk that the auditor gives the wrong
opinion—usually stating that the financial statements are accurate when they actually contain
serious errors or fraud.
There are three categories of misstatements:
Factual misstatements: a misstatement about which there is no doubt.
Judgmental misstatements happen when:
The company makes an accounting estimate, but the auditor thinks it’s unreasonable, or
The company uses an accounting method or rule that the auditor thinks is not
appropriate.
In short:
It's a disagreement in judgment between the auditor and the company
Projected misstatements are the auditor’s best guess of the total errors in a large group of
items, based on the mistakes found in a sample.
In simple words:
If the auditor checks a small part (sample) and finds errors, they estimate how many similar
errors may exist in the whole group.
The importance of risk assessment:
Risk analysis is a key part of the audit. It helps auditors to:
Identify the areas of the financial statements where misstatements are likely to occur.
Plan audit steps to focus on those risky areas.
Do the audit more efficiently and effectively.
Lower the chance of giving a wrong audit opinion.
Protect their reputation and avoid penalties.
Audit risk is made up of two components:
(a) Risk of material misstatement and
(b) Detection risk.
(a) Risk of material misstatement: Risk of material misstatement means there’s a chance
the financial statements have big errors before the audit starts.
It has two key components:
Inherent risk – is the chance that a mistake could happen in a transaction, account, or disclosure
before looking at any internal controls.
This risk exists because of factors like:
The nature of the business or industry
The complexity or judgment involved in the item
Or how prone the item is to error
Control risk – is the risk that a serious error in the financial statements won’t be caught or
corrected in time by the company’s internal controls.
this risk is high if:
The control system is poorly designed, or
The controls weren’t used properly during the year
(b).Detection risk: Detection risk is the chance that the auditor's work misses a big mistake in
the financial statements, even after doing all the planned audit procedures. Detection risk has
two parts:
1. Sampling risk: This is the risk that the sample the auditor checks doesn’t represent the
whole population, so the auditor might come to the wrong conclusion.
Example: The sample looks fine, but if the whole data were checked, there might be
problems.
2. Non-sampling risk: This is the risk of error for any other reason, like using the wrong
audit method or failing to notice a mistake during testing.
Example: The right data is checked, but the auditor misses a clear error.
Professional scepticism: Professional scepticism is: 'An attitude that includes a questioning
mind, being alert to conditions which may indicate possible misstatement due to fraud or error,
and a critical assessment of audit evidence.' [ISA 200, 13l]
How to apply professional scepticism (in simple terms):
Auditors must stay alert to:
1. Evidence that disagrees with other evidence.
2. Information that makes you doubt if documents or answers are reliable.
3. Signs that there could be fraud.
4. Situations where more checks are needed beyond the normal rules (ISAs).
In short: always question, cross-check, and look deeper if something feels off.
What is materiality?
A mistake or missing information in the financial statements is material if it could affect the
decisions of people using those statements — even if it's just one big mistake or many small
ones added together.
In short:
Materiality means how much an error matters to users of the financial report.
How is materiality determined?
Materiality is based on the auditor’s professional judgment. To decide, the auditor thinks about:
Whether the mistake could affect users' financial decisions
The size (amount) and nature (type) of the mistake
What kind of information the users need
In short:
Materiality depends on the situation, the users, and how much a mistake might matter to
them.
Material by nature (not just about money):
Some things are important (material) not because of their amount, but because of what they are.
Examples include:
Mistakes that break laws or rules
Mistakes that break loan agreements
A correction that changes profit into a loss
A correction that changes net assets into net liabilities
Deals with directors (like salaries or personal use of company property)
Notes about legal problems or if the business might shut down (even if there’s no number
involved)
In short:
Some items are material just because they’re important in nature, even if the amount is small.
What is performance materiality?
Performance materiality is a smaller limit set by the auditor (lower than overall materiality) to
help catch more mistakes during the audit.
It helps the auditor spot more errors.
It reduces the chance of missing several small mistakes that could add up to a big
(material) problem.
In short:
It’s a safety buffer to make sure even small errors are checked, so nothing important is missed.
Risk Assessment Procedures (ISA 315):
Auditors must gather information to understand the business and find any risks. They do this by:
1. Asking questions – Talk to management, internal auditors, and others in the company to
learn about changes and issues.
2. Doing analytical checks – Compare numbers and trends to spot anything unusual.
3. Watching how things work – Observe how controls and processes are actually done.
4. Reviewing documents – Look at important files like company policies, strategy plans,
and manuals.
In short:
Auditors ask, check, watch, and review to spot any risks that could lead to errors in the financial
statements.
Audit Risk = Inherent Risk × Control Risk × Detection Risk
This model shows the chance that the auditor gives a wrong opinion because they miss a
material misstatement in the financial statements.
1. Inherent Risk (IR)
Risk that something is wrong before any controls are applied.
Caused by things like:
Complex or unusual transactions
Inexperienced staff
Businesses dealing mostly in cash
Pressure to hit targets
Example: A fast-growing tech startup with new staff and complex contracts = high inherent risk.
2. Control Risk (CR)
Risk that the company’s internal controls fail to stop or fix errors.
Depends on:
How well the controls are designed
If the controls are actually working
Example: Weak approval systems or missing documentation = high control risk.
3. Detection Risk (DR)
Risk that the auditor doesn’t catch a mistake.
Caused by:
Poor audit planning
Lack of experience
Rushed work due to time or fee pressure
Not knowing the industry well
Example: A new auditor working in a complex industry without proper planning = high
detection risk.
🔁 Summary:
Inherent risk = Natural risk in the business
Control risk = Risk controls won’t catch it
Detection risk = Risk auditor won’t find it
The lower the detection risk you want, the more careful and detailed your audit needs to
be.
📊 Analytical Procedures (ISA 520)
What are they?
Analytical procedures mean examining financial info by looking at relationships and trends in
the data — both financial and non-financial.
🔍 Why do auditors use them?
As part of the risk assessment (ISA 315), auditors use analytical procedures to:
1. Learn new things about the business they didn’t know before
2. Spot risks of mistakes in the financial statements
3. Find unusual items – strange numbers, trends, or transactions that need more attention
4. Detect possible fraud by noticing patterns that don’t make sense
Analytical Procedures – Simplified
Analytical procedures involve evaluating financial data by comparing it with:
Previous periods (e.g., last year’s figures).
Planned results, such as budgets or forecasts.
Industry benchmarks, like average ratios in similar businesses.
They also involve looking at logical relationships, such as:
Patterns within financial data (e.g., stable gross margin percentages).
Links between financial and non-financial data (e.g., payroll expense vs. number of
employees).
These comparisons help auditors identify unusual trends or possible errors.
Chapter-6
Audit planning
Audit planning: audit planning should include specific description of nature,
timing and the extent of risk assessment procedure.
The audit strategy: the audit strategy set the scope, timing and the direction of the
audit.
Internal vs final audit:
Internal audit: An interim audit is done before the end of the financial year.
It helps the auditor:
Spread out the audit work, and
Plan better for the final audit.
Main focus of interim audit:
Understanding and recording the client's systems
Checking how well the internal controls are working
It may be possible to:
• test specific and complete material transactions, e.g. purchasing new noncurrent
assets
• attend interim inventory counts
• carry out an interim receivables circularization
External audit: The final audit happens after the year ends. It focuses on the most
important and risky areas—like year-end balances and estimates that require
judgment.
Interim Audit
An interim audit happens before year-end. It’s usually done for larger clients
because it adds extra cost. However, it helps identify risks early and makes the
final audit faster and more efficient.
Criteria Internal Audit External Audit
Add value by improving internal Provide independent
Objective controls, risk management, and assurance on the fairness of
governance processes financial statements
Shareholders or Board of
Appointed by Management or Audit Committee
Directors
Broad—includes operational
Narrow—focused primarily
Scope of Work efficiency, compliance, and
on financial reporting
controls
Reports to senior management or Reports to shareholders or
Reporting Line
Audit Committee external stakeholders
Regulatory Not mandatory, but considered Mandatory for listed and
Requirement best practice regulated companies
Ongoing or periodic throughout Conducted annually, post
Frequency
the year financial year-end
International Standards on
Standards Internal auditing standards (e.g.,
Auditing (ISA) or local
Followed IIA Standards)
equivalents
Operates within the organization Completely independent
Independence
but must remain objective from the organization
Controls effectiveness, fraud
True and fair view of
Focus detection, operational
financial statements
improvements
Examples of Risk assessments, compliance Audit opinion on income
Work checks, process audits statement, balance sheet, etc.
What is fraud: ISA 240 the Auditor’s Responsibilities Relating to Fraud in an
Audit of Financial Statements recognises that misstatement in the financial
statements can arise from either fraud or error. The distinguishing factor is whether
the underlying action that resulted in the misstatement was intentional or
unintentional
In the context of auditing, fraud refers to intentional deception carried out by
management, employees, or even third parties to gain an unfair or illegal
advantage. Fraud is a broad legal concept; it is a criminal activity. It is not the
responsibility of the auditor to prove whether fraud has actually occured, that is the
role of the country's legal system. The auditor's role is to determine whether there
is a material misstatement in the financial statements as a result of fraud
Fraud can be split into two types:
• fraudulent financial reporting– deliberately misstating the accounts to
make the company look better/worse than it actually is.
• misappropriation– the theft of the company’s assets such as cash or
inventory.
The external auditor responsibilities
What is the External Auditor Responsible For?
The external auditor must make sure the financial statements are free from major (material)
mistakes, whether caused by fraud or error.
To do this, the auditor must:
Key Responsibilities:
1. Stay professionally sceptical: This means that the auditor must recognize the possibility
that a material misstatement due to fraud could occur, regardless of the auditor's prior
experience of the client's integrity and honesty
2. Identify and assess fraud risk
o Look for areas where fraud is more likely to happen.
3. Team discussion on fraud risk
o The audit team should discuss how and where fraud could happen in the
client’s business.
4. Ask management about fraud
o Find out how management identifies and deals with fraud risks.
5. Enquire within the organization
o Talk to management, internal auditors, and board members to check if they know
of any actual or suspected fraud.
6. Perform targeted audit procedures
o Plan specific audit tests to respond to the fraud risks identified and gather solid
evidence.
Reporting of fraud:
Report it quickly to management
If fraud is identified, the auditor must inform the right level of management as soon as
possible.
Report to those in charge if management is involved
If the fraud involves management, the auditor must report it to those in charge of
oversight (like the board or audit committee).
Think about whether to report it outside the company
The auditor must also consider if they need to inform external parties, such as
regulators or legal authorities.