Corporate Governance and Audit Compliance Guide
Corporate Governance and Audit Compliance Guide
A - Regulatory Environment:
Corporate Governance:
Corporate governance is the system that controls and directs companies. It also includes the
relationships between the stakeholders and the corporate goals.
▪ Is about rules on how to run a company – it’s stricter for listed companies than private
companies. As there more public interest and wider stakeholders than private companies.
▪ The agency problem can be reduced if corporate governance principles are followed. Agency
problem - Companies are owned by shareholders but controlled by the directors.
▪ Corporate governance is a key element of the control environment (the tone at the top). If
the company is seen to be well run, with the directors leading by example, workers are more
likely to comply with internal controls.
▪ Non-Executive Directors (NEDs): Appoint NEDs with industry experience to the board. The
NEDs role is to hold the executive directors to account, to challenge the decision makers.
They represent the shareholders’ interests in board meetings.
▪ Remuneration: Pay structure for directors should promote the long-term interests of the
company / shareholders. Director pay should be set by the Remuneration Committee
(staffed by at least three NEDs).
▪ Leadership: Role of the Chairperson (runs the board) and Chief Executive (runs the
company, implements strategy) not to be held by the same person. It’s important that the
chairperson can effectively hold the Chief Executive to account.
- You must have for listed companies and its good practice to have for non-listed
companies.
- Three NEDs: the audit committee should be made up of at least 3 NEDs, one should
have relevant financial experience.
- No Executive Directors’: Members of the audit committee should not be involved in the
running of the company.
- Independence: This maintains independence and allows the audit committee to fulfil its
roles without bias.
▪ Effectiveness: Appoint board members with a range of skills and experiences, with strong
NEDs. A stronger board is less likely to be dominated by a single individual.
▪ Board Meetings: Must take place regularly and there must be board minutes to correctly
detail and record discussions and decisions made in the meeting.
▪ Audit Risk: This is the risk that the fin stats are materially misstated due to fraud or error
which goes undetected. If a company is poorly run/has poor corporate governance, it means
that the control environment is likely to be weak and non-compliance with rules & controls
that the business has in place. Staff will think they can cut corners and not comply with rules.
This means that there is a greater possibility of misstatement due to error & fraud.
▪ Money Laundering:
- Due Diligence (passports & certificate of incorporation)
- Assess the risk of ML (Potential Placement & layering of transactions)
- Train staff (Placement, Layering & Integration)
- Appoint MLRO
- Record Keeping – Up to 5 years.
▪ Laws & Regs:
Management Responsibility:
- It’s managements responsibility to ensure compliance with Laws & Regs
- Mang must develop internal control to promote compliance with relevant laws & regs.
Auditors Responsibility:
Material Misstatements:
- Breaches of laws and regulations can lead to the accounts being incorrect.
- There may be unrecorded liabilities for any fines or penalties.
- Auditors should identify material misstatements be caused by noncompliance with laws
& regulations.
B - Ethics:
Auditors Responsibility:
Management Responsibility:
- Management is responsible for preventing and detecting fraud and error.
- They must design, implement and monitor controls – for example segregation of duties.
- Business risks change; therefore, the system of internal control must evolve.
- Mang must lead by example and set the tone at the top.
International UK
- Audit Partner: Should be rotated after - Audit Partner: Should be rotated after
7 years (EQR also). 5 years.
- PIE: There must be a EQR for listed - PIE: There must be a EQR for listed
clients as they are a public-interest clients as they are a public-interest
entity (mandatory). entity (mandatory).
- Audit Tender: It’s recommended that - Rotate staff: Senior manager, Lead
the audit should be put out to tender Partner and EQR should be rotated
every 10 years. after 7 years.
- Remove any team member with a - Audit Tender: The audit should be put
personal relationship to the client. out to tender every 10 years under the
ethical standards.
- Resign: If an Audit partner joins the
client, the firm must resign as auditor - Max Years: There can be a max of 20
unless the partner hasn’t been years before rotating the audit firm.
involved with the audit for more than
12 months.
- For unlisted (Intl): The partner can serve for more than 8 years, however familiarity threat
should be accessed.
- For unlisted (UK): The firm should actively consider rotating the audit partner after 10 years.
International UK
- Fees from a single client should not - Fees from a single client should not
exceed 15% for 2 consecutive years. exceed 10% for 2 consecutive years.
- If fees reach 10%, safeguards must be - If fees reach 5%, safeguards must be
applied, for example EQR. applied, for example EQR.
International UK
- Fees from a single client should not - Fees from a single client should not
exceed 30% for 5 consecutive years. exceed 15% for 2 consecutive years.
A self-review threat exists is figures prepared/ calculated by the audit team are included in the Fin
Stats audited by the team members.
International UK
- Non – Audit services NOT ALLOWED. - Non-Audit services Are Allowed.
- Unless directly related to the audit Only - Internal audit services are NOT
Interim Audit ALLOWED. ALLOWED.
- For example, Valuation of shares a are - The fee should not exceed 70% of audit
NOT allowed. fee over 3 years (Based on average).
IMPORTANT: For listed companies, the level of public interest is greater. Hence, the auditor is more
likely to conclude that performing non-audit work isn't ok.
However, for unlisted entities it’s fine if safeguards are in place that reduce the risk to an acceptable
level.
International UK
- Non-Audit services Are Allowed. - Non-Audit services Are Allowed.
- Robust safeguards must be in place (e.g. - Internal audit services are NOT
separate teams used). ALLOWED for ALL CLIENTS.
Services Allowed:
▪ Secondment for a short period of time, providing it doesn’t involve prohibited services.
▪ The individual will not hold management positions or make management decisions
- If an auditor is joining the client, they should be removed from the team.
- An independent review of their work should be carried out
▪ Overdue Fees:
- If there are overdue fees, the firm CANNOT carry out the audit.
- The audit firm must refuse to act until outstanding fees are paid.
C – Quality Management
- Direction: Audit should start with a planning meeting with the partner.
- Supervision: Tracking audit process to ensure adequate resources have been assigned.
- Review: All audit work should be reviewed by a more senior team member & sufficient
evidence on file to support conclusions.
1. Leadership: Audit leaders should design, implement and establish a System of Quality
Management (SQM) and evaluate for effectiveness.
3. Acceptance & Continuance: Accept new audit client if appropriate to do so (resourcing &
skill).
4. Human resources: The firm must recruit, train and support audit staff appropriately
5. Engagement Performance: There must be clear Direction, Supervision and Review of the
audit work performed.
6. Monitoring: Ensure that the SQM was followed during the audit and make Improvements for
future audits.
7. Audit Partner: Should be actively involved, ensure judgments & conclusions reached are
appropriate.
8. Documentation: There must be sufficient evidence on file to support any conclusions drawn
A Cold review:
A Hot review:
▪ Resourcing: Should be adequate, staff resources with the required level of skill (Prof
Competence & due care).
▪ Lowballing:
- Setting an inappropriate low fee to earn other income from the client.
- This is NOT ALLOWED, as the following ethical principles would be compromised.
▪ Tendering:
- Outline experience/expertise of the audit team – resources available for audit
- Outline audit approach - controls testing vs substantive testing.
▪ Advertising:
- Inform rather than sell (Integrity)
- Only advertise services that you are experienced in (Professional competence & Due Care).
- Do not bring the profession into disrepute (Professional Behaviour).
Audit Risk:
Inherent Risk: A misstatement occurs because of the nature of the company’s business.
Control Risk: The company’s systems don’t prevent or detect the misstatement.
IMPORTANT: Audit risk scenarios will also give you marks for issues relating to the auditor (e.g. they
lack experience of the client so may overlook things).
How to lower detection risk?
▪ Test of Controls:
- An audit procedure designed to evaluate the operating effectiveness of controls.
- This tests how controls prevent, detect and correct material misstatements at the
assertion level.
▪ Substantive testing:
- An audit procedure designed to detect material misstatements at the assertion level.
- Tests of details (of classes of transactions, account balances, and disclosures
- Analytical Procedures
Business Risk:
An issue that could impact the company’s ability to achieve its objectives. Business risks relate to the
COMPANY rather than to the audit.
You must explain why a business risk is an issue for the specific COMPANY in the particular scenario,
for example, how the risk:
Materiality:
▪ Revenue: 0.5% – 1%
▪ Total Assets: 1% - 2%
▪ PBT: 5% - 10%
Material by Nature:
▪ Director Pay
▪ Debt Covenant’s
▪ Related Party Transactions
▪ Illegal Activity
Group Audit:
The GROUP Auditor MUST confirm the following for audits involving component auditors:
1. Assess the competence (qualification & experience) and independence (reputation of the
component auditor
2. Send out group audit instructions to the component auditor, setting out:
- Ethical requirements relevant to the group audit, and in particular the independence
requirements.
- Set the materiality level for component auditor
- Significant risks of material misstatement relevant to the component.
- Send list of related parties for the entire group.
- Expectation of the level of reporting that is required (Progress of the audit,
misstatements etc.).
3. Review the reporting that is received from the component auditor and evaluate significant
matters arising.
▪ Significant Components:
- subsidiaries that make up 15% and more of revenue, assets and profits
- Group auditor should review the audit files of the component auditor.
- Assess if the evidence gathered is sufficient to support the conclusions drawn.
▪ Joint Audits:
Benefits:
- This is where Two audit firms provide a joint opinion on the financial statements.
- Wider range of resources, skills & experiences and familiarity threat reduced.
Drawbacks:
- Duplication of work, cost for clients and disagreements over audit approach.
If the auditor lacks the technical knowledge & skill to gather evidence, they may use an expert for the
following:
▪ Valuing a property.
▪ Valuing work in progress.
▪ Legal case.
▪ Cost vs benefit
▪ Reputation & experience of the expert.
▪ Competence & qualifications (professional body membership).
▪ Objectivity & Independence.
▪ Consistency of their findings with other evidence.
Many companies outsource functions that drive key areas of the financial statements. Such as
payroll, debt collection, internal audit.
Audit Opinion:
▪ Unmodified Opinion
The financial statements are:
▪ Modified Opinion:
Material Misstatement:
- Qualified (Material): Having obtained evidence, we conclude that the accounts are true
& fair and free from material misstatements except for xx.
- Adverse (Material & Pervasive): Having obtained evidence, there is a material &
pervasive misstatement. Due to the significance of the matter, we CANNOT conclude
that the fin stats are true & fair.
Insufficient Evidence:
- Qualified (Material): Due to insufficient evidence regarding xx, we conclude that the fin
stats are true & fair and free from material misstatements except for xx.
- Disclaimer: We are unable to obtain sufficient evidence on xx. The issue is material &
pervasive; therefore, we are UNABLE to give an opinion on whether financial statements
give a true and fair view.
Key Points:
▪ Basis of Opinion:
- Explains why the audit opinion has been given.
Unmodified Opinion:
- Statement that fin stats have been prepared correctly with ISA
- The auditor is independent & complied with Ethical standards.
- Sufficient and appropriate evidence has been obtained.
Modified Opinion:
- A description of the matter that has led to the opinion being modified.
- The matter should be quantified with enough details provided for users to understand.
- The auditor reports on the Why the area was considered high risk by the auditor.
If there is 100% certainty that the company is not a Going Concern, it must be prepared on a
BREAK-UP Basis:
This is where other information is presented alongside the fin stats that are not audited, for example:
▪ Director’s report
▪ Strategic Report
▪ Sustainability
▪ Statement that the audit opinion does NOT cover the ‘other information’.
▪ Auditor’s responsibility to review the ‘other information’ and repost on any inconsistencies
with the fin stats.
▪ No Inconsistencies: A statement that the auditor has nothing to report (i.e. there are no
material inconsistencies).
▪ If there is a significant matter, related to the audit, that is NOT present in the Fin Stats.
▪ Or the company’s results are consolidated into group Fin Stats that report under different
financial reporting standards.
IMPORTANT - Application:
▪ If any of the above have not takin place, for example insufficient evidence due to information
being destroyed in a fire, you would report by exception.
▪ If all the requirements have been met, you would state : “If all the requirements for
compliance with the Companies Act were not met, we would report by exception to you,
however, they have been met therefore there are no matters to report by exception”.
Reporting to Management:
▪ Management run the company and are involved day-to-day running of the business.
▪ The auditor will share information to help them to better run the company.
▪ For example, weakness found in controls or a poorly performing staff member - reporting to
management will allow them to ‘fix’ the issue.
Reporting To TCWG:
▪ TCWG oversee management, making sure that the business is being run properly.
▪ TCWG have an oversight role and are responsible for making sure that the business is run
effectively (Governance).
▪ They should be informed of any SIGNIFICANT FINDINGS from the audit to help them to
assess how well the business is being run.
▪ Listed Entity: TCWG team includes the audit committee and non-executive directors.
▪ Unlisted Entity: TCWG may include executive directors also.
IMPORTANT: Although Management and TCWG have different uses for the reports, they are sent
the SAME REPORT - They just use it in a different way.
Significant Findings:
Independence Matters:
This is a signed document, printed on Company letter headed paper, signed by management. It is
prepared by the auditor but printed & signed by management.
IMPORTANT:
▪ If management representations are not reliable or provided, then an audit opinion CANNOT
be given.
▪ DISCLAIMER OF OPINION: would be given in this case, as the matter would be a material &
pervasive lack of evidence.
F – Other Assignments
▪ Due Diligence
▪ Financial forecasts (PFI)
▪ Forensic Audit (Fraud)
▪ Integrated Reporting
▪ Review of interim financials
Opinion Given:
▪ A Negative assurance conclusion is given: “Nothing has come to our attention that suggest
the Forecast have been prepared incorrectly”.
- A lower level of assurance is given compared to audit which gives ‘reasonable assurance’.
- This is because we are reliant of management representations.
- Therefore, less work is carried out as there is no third-party evidence.
▪ Assurance Opinion: The same opinion given as audit – Material (Except for) , Material
(insufficient info, Adverse and Disclaimer.
Due Diligence
Selling a business can be risky, therefore the buyer will need assurance that the target company is in
sound financial health, and that the sellers aren’t hiding anything. This helps the buyer to make
informed decisions.
▪ Professional competence:
- Resources: staff available & staff experience & skill.
- Tight deadline to complete work to close of the deal.
- The speed in which staff can complete work should be considered.
▪ Self-review:
- A lot of the information reviewed during the due diligence work will be reflected in the
Fin Stats to be audited in the next year.
- There’s a threat that the numbers in the Fin Stats won’t be challenged robustly as its
been completed and signed off by members of staff.
- The audit team may not want to highlight any issues and errors found as it would reflect
badly on the firm.
▪ Self-interest:
- Due diligence work is lucrative – firm may not robustly challenge management to retain
fees.
- This creates a risk of fee dependence – the size of the DD fee should be compared to the
audit fee to ensure it doesn’t create a self-interest fee.
▪ Confidentiality:
- For due diligence work you have access to ALL company data.
- The firm should obtain written informed consent from both parties (competitors).
- The firm should inform both parties of safeguards in place i.e. separate teams &
information barriers.
- All members of the team should be briefed on the confidentiality requirements and
should sign confidentiality agreements.
▪ Conflict of interest:
- Acting for two companies in the same sector.
- If the firm also completes work for competitors, sensitive information could leak.
▪ Listed entities (UK): Companies must release interim results every 6 months.
For interim financial review, it’s not a full audit therefore less work to do.
Banks will require forecasts that have been reviewed by an assurance practitioner before lending
money to a company. Moreover, forecast are also required for the due diligence process when
there’s an ongoing deal.
The conclusion of the assurance provider adds credibility to the forecasts, making it more likely that
the bank will lend money.
▪ Duty of care: Forecast is used by a bank; therefore firm could be liable to lawsuit.
▪ Management Threat:
- Directors must make assumptions & prepare the forecasts.
- In the scenario Manag may not have the relevant experience, therefore there is a risk
that the auditor will take on management role.
▪ Advocacy Threat: If company is also an audit client, this could be seen as taken on an
advocacy role on behalf of the client before the bank (Objectivity threat for audit).
▪ Self-review:
- Some of the figures in the forecast will be included in the Fin Stats to be audited.
- The firm are unlikely to highlight discrepancies & errors as they could be sued by the
bank.
▪ Self-interest:
- Lucrative fees, therefore risk of fee dependence – the firm may overlook issues with the
audit to retain the fees from the assurance engagement.
- Continuation of fees from reoccurring work – the firm may not challenge management
robustly to keep the reoccurring fees.
Materiality:
▪ There is no specific materiality level as we are looking at all information for the investigation.
Ethical Threats:
▪ Professional competence & due care: Forensic audits are specialised engagements that
require staff with specialised experience.
▪ Advocacy: Due to risk of potentially representing client to third party for the insurance claim
if company is also an audit client.
▪ Intimidation:
- If management are suspected to be involved in the threat (CFO, FD), there could be an
intimidation threat.
- We also cannot rely on any information provided by management; we would need 3rd
party evidence.
▪ Confidentiality:
- There could be an ongoing criminal case and potential court appearance.
- We would need the client’s permission to cooperate with the police.
- IMPORTANT: This requires time and therefore should be reflected in the fee.
- For example, looking at the number & value of transactions posted by an employee
suspected of the fraud.
- For example, if fraud committed by a sales staff, look at their bonus and how many sales
recorded for that individual.
- For example, looking at postings at unusual times (late at night) and unusual days
(weekends) and duplicate transactions.
- However, you cannot trust the account of any individual suspected to be involved in the
fraud.
▪ LOR:
- Document all findings and interactions during the forensic audit as the forensic audit
may lead to a criminal investigation.
Integrated Reports:
Integrated reports typically include Key Performance Indicators (KPI) that demonstrate the
company’s commitment to social and environmental matters.
Normally IR are reviewed alongside the financial statements, however a company may decide to pay
for a separate assurance engagement on the IR.
▪ Metrics:
- Considering the appropriateness of the KPIs.
- Agreeing KPI’s over which assurance can be provided.
▪ Accuracy:
- Recalculating KPIs to ensure they have been calculated correctly.
▪ Third-Party Evidence:
- Obtain third party evidence to support each KPI
▪ LOR:
- Obtain written confirmation of key matters should be obtained in writing.
Key Challenges:
▪ Management Bias:
- Management only report KPI/measures which present the business in a more favourable
light.
- Reports are not comparable with other companies, as each company report on different
measures.
▪ Assurance Evidence:
- The evidence is more persuasive and not conclusive.
- For example, survey on employee satisfaction, results may not be a true reflection as
employees may not give honest answers in fear of losing their jobs.
▪ Internal Controls:
- Robust controls may not be in place.
- For example, controls to ensure that each employee completes a survey.
▪ Professional Competence:
- The metrics used in the IR may be too technical for the assurance provider.
- For example, reporting on sustainability/ CO2 emissions.
G – Current Issues
Data Analytics
Data analytics can be used to aid the efficiency and effectiveness of the audit:
Features (Benefits):
▪ Data Visualisation:
- The audit team can use data visualisations to better understand the client.
- For example, comparing sales and costs to market data over time.
- This helps the audit team to identify risk areas to focus on during the audit.
▪ Controls: Can be used to test the segregation of duties – Whether invoices were raised,
approved and paid by separate people.
▪ Duplication: Testing on the duplication of transactions can be tested – 13th monthly payroll
expense/ fake employees set up and paid (duplicate name & account detail).
Advantages:
▪ Efficiency: Less time is spent manually checking items - Can test whole & large populations
more quickly – Audit completed more quickly.
▪ Sampling Risk: Can test ALL items in the population, therefore reducing detection risk.
▪ Added Value:
- Due to testing all transactions within the population, therefore given assurance that
controls are working effectively or identify issues with controls.
- Audit is completed more efficiently therefore, saving time and potentially cost which can
be passed on to the client.
- Audit is completed more quickly, therefore Fin Stats can be signed and published much
sooner.
Disadvantages:
- The client provides the auditor with sensitive data on business info (clients).
- This exposes the client to risk if the auditor’s system is hacked and sensitive data is
leaked on the client.
▪ Data compatibility: Incompatibility of data for clients with bespoke accounting software (no
longer a key risk).
▪ Data integrity: Completeness and accuracy of client data. Client might not provide all the
data, especially for back ups (client may delete info).
Sustainability Reporting
Key Challenges:
▪ No Set Standards:
- The standards are currently being developed. It’s an ongoing process and constantly
changing.
- Regulations are changing constantly, and are different dependent on the jurisdiction,
therefore it’s difficult to specialise in this area.
- New standards will need to be confirmed and implemented to support consistency and
comparability.
Double Materiality:
- This is highly subjective and involves judgement – Management will only select and
report on the metrics that paint the company favourably.
- For example, CO2 emissions – this requires experts such as engineers who understand
the technicalities and can challenge management robustly.
- The metrics used in sustainability reporting are very technical and require expertise.
- A standard assurance provider may not have the professional competence to challenge
Management on these metrics.
▪ Carbon Scopes:
- Companies tend to report on scope 1 emissions which is direct emissions linked to their
operating activities.
- However, it’s difficult to report on scope 2 & 3 emissions which are indirect carbon
emissions from their supply chain.
- Therefore, this does not truly reflect companies position on sustainability and whether
their operations are environmentally friendly/ sustainable.
- This is why Limited assurance is given – A negative opinion “Nothing has come to our
attention..”
- Disclosures are usually wordy – long narrative paragraphs with little numbers, making it
difficult to vouch.
▪ Ethical Threat:
- Self-Review: Companies are using their standard external auditors to give assurance on
their sustainability report – this creates a self-review threat.
- The reason for this is because there is a lot of overlap between the sustainability report
and information provided within the fin stats.
- It’s efficient for companies to use their auditors, however this gives rise to ethical
threats. This is especially a risk for listed companies as it falls under non-audit work.
Insolvency – UK Variant:
A company is insolvent when:
▪ Trading stops
▪ Employees are made redundant
▪ Liquidator takes over from Directors
▪ Actions for recovery of debts are stopped
▪ Legal actions are stopped Floating charges crystalise
Members Voluntary Liquidation (Company is solvent):
The members decide to liquidate the company even though it’s SOLVENT
Companies may be obliged to liquidate if a winding up order is presented to a court for the following:
1. A public company has not been issued with a trading certificate within 1 year of
incorporation.
2. A creditor is owned more than £750, a formal demand was served and company unable to
pay within 21 days.
3. It is proven within the courts that assets are less than liabilities (cash flow test).
Alternatives to Liquidation:
▪ Reconstruction:
- Restructure the business.
- Creditors consent is needed
▪ Administration:
- Administrator runs the company, attempting to save it.
- Creditors consent is needed.
▪ The director(s) of a company continue to trade and enter into more debts/loans knowing
that the company will NOT be in a position to repay those debts.
IMPORTANT: Fraudulent trading would need to be proven ‘Beyond reasonable doubt’ in court.
▪ This is often combined with an audit evidence & quality control question.
▪ You’ll be asked to comment on the audit evidence obtained and the potential impact on the
auditor’s report Risk & Procedures.
▪ Assess the materiality of the issue vs the most relevant benchmark, then conclude if it is
material. e.g. the doubtful receivable is 8% of PBT and therefore material.
▪ Calculate both the lowest & highest materiality threshold and justify why you’ve chosen to
either go with the highest or lowest (increased risk – mitigate against detection risk)
2. Consistency: Look for inconsistencies between the financial and non-financial data
presented.
3. Cash: How quickly the client expects to receive cash from customers (receivables).
- For example, the narrative might say cash is received from customers in 60 days,
however the forecast is prepared on the basis of cash receipts in just 25 days.
4. LOR: Specify with clear details which items management representations should be obtained
for.
- These are judgmental areas that only management will know.
- This offers protection to the firm if there’s a legal case and if management have been
dishonest.
- For example, written representation that management will launch a new product.
5. Lawyers: Look at correspondence between the company and its lawyers to ensure it’s
consistent with details/circumstances given in the scenario.
6. Board Minutes: Do a board minute review – specify exactly what you’re looking out for.
- For example, if the company intends to cut staff cost by 15%, you expect discussions of
redundancies within the bord minutes.
- REMEMBER - a board minutes review is to look for evidence of sensitive matters not yet
disclosed publicly.
7. Key contracts: Confirm key details with signed contracts, for example staff salary, payment
terms with customers and supplier contracts.