Advanced Audit & Assurance Overview
Advanced Audit & Assurance Overview
Examination Structure
The syllabus is assessed by a three-hour 15 minutes examination.
The examination is constructed in two sections.
Questions in both sections will be largely discursive.
However, candidates will be expected, for example, to be able to assess materiality and calculate relevant
ratios where appropriate.
Section A Section A will comprise a Case Study, worth 50 marks, set at the planning stage of the
audit, for a single company, a group of companies or potentially several audit clients.
Candidates will be provided with detailed information, which will vary between
examinations, but is likely to include extracts of financial information, strategic,
operational and other relevant financial information for a client business, as well as
extracts from audit working papers, including results of analytical procedures.
The 50 marks will comprise of 40 technical marks and 10 professional skills marks.
Page | 1
Please note that other syllabus areas, excluding E, may also be drawn on as part of the
Case Study.
Section B Section B will contain two compulsory 25-mark questions, with each being predominately
based around a short scenario which may relate to more than one client.
The 25 marks will comprise of 20 technical marks and five professional skills marks.
Each question will examine a minimum of two professional skills from analysis and
evaluation, professional scepticism and judgement and commercial acumen
One question will always predominantly come from syllabus section E, and consequently
candidates should be prepared to answer a question relating to completion, review and
reporting. There are a number of formats this question could adopt, including, but not
limited to, requiring candidates to assess going concern, the impact of subsequent events,
evaluating identified misstatements and the corresponding effect on the auditor’s report.
Candidates may also be asked to critique an auditor’s report or evaluate the matters to
be included in a report which is to be provided to management or those charged with
governance.
The other Section B question can be drawn from any other syllabus section, including A,
B, C, D and F.
Page | 2
Using These Notes
It is VERY important to understand that the nature of the AAA exam is such that it cannot be passed
without extensive written practice so these notes HAVE to be used in combination with past exam papers.
When you are attempting questions from past exams, focus on ‘knowing’ the language used and
understanding the ‘answer technique’; remember, it’s not the English language which will help you get
through the exam- it is the ‘audit language’!
Lastly, ensure you read the technical articles on the ACCA website.
Page | 3
Assurance and No Assurance Engagements; A Summary
Assurance on Prospective
Financial Information (PFI)
External Review of
Audit of F/S historical Due diligence review
financial
ISA information Audit of social,
(International environmental &
standards on ISRE integrated reporting
auditing) (International
standards in Audit of performance
review [Link] the public sector
engagements)
Review of
interim
financial
information.
Page | 4
Laws and Regulations
An important part of an external audit is the consideration by the auditor as to whether the client has
complied with laws and regulations.
The auditor needs to consider the requirements of ISA 250, which states that while it is management’s
responsibility to ensure that the entity’s operations are conducted in accordance with the provisions of
laws and regulation, the auditor does have some responsibility in relation to compliance with laws and
regulations, especially where a non-compliance has an impact on the financial statements.
The Details
The auditing standard that is relevant to this article is ISA 250, Consideration of Laws and Regulations in
an Audit of Financial Statements, and the objectives of the auditor are:
• To obtain sufficient appropriate audit evidence regarding compliance with the provisions of those
laws and regulations that have a direct effect on the determination of material amounts and
disclosures in the financial statements
• To perform specified audit procedures to help identify non-compliance with other laws and
regulations that may have a material effect on the financial statements
• To respond appropriately to non-compliance or suspected non-compliance identified during the
audit.
Page | 5
This ISA distinguishes the auditor’s responsibilities in relation to compliance with two different categories
of laws and regulations as follows:
(a) The provisions of those laws and regulations generally (b) Other laws and regulations that
recognized to have a direct effect on the determination of do not have a direct effect on the
material amounts and disclosures in the financial determination of the amounts
statements such as tax and pension laws and regulations. and disclosures in the financial
statements, but compliance with
which may be fundamental to the
operating aspects of the business,
The auditor shall obtain sufficient appropriate audit evidence to an entity’s ability to continue
regarding compliance with the provisions of those laws and its business, or to avoid material
regulations generally recognized to have a direct effect on the penalties (for example,
determination of material amounts and disclosures in the compliance with the terms of an
financial statements operating license, compliance
with regulatory solvency
The auditor shall perform the following audit procedures to requirements, or compliance
help identify instances of non-compliance with other laws and with environmental regulations);
regulations that may have a material effect on the financial non-compliance with such laws
statements: and regulations may therefore
(a) Inquiring of management and, where appropriate, those have a material effect on the
charged with governance, as to whether the entity is in financial statements
compliance with such laws and regulations; and
During the audit, the auditor shall remain alert to the possibility
that other audit procedures applied may bring instances of non-
compliance or suspected non-compliance with laws and
regulations to the auditor’s attention.
Page | 6
Indications that non-compliance may have occurred:
– Investigations by government departments or payment of fines or penalties
– Payment for unspecified services or loans to consultants, related parties, employees or government
employees
– Sales commission or agent’s fees that appear excessive in relation to those ordinarily paid by the entity
or in its industry or to the services actually received
– Purchasing at prices significantly above or below market price
– Unusual payments in cash, purchases in the form of cashier’s checks payable to bearer or transfers to
numbered bank accounts
– Unusual transactions with companies registered in tax havens
– Payments for goods or services made other than to the country from which the goods or services
originated
– Payments without proper exchange control documentation
– Existence of an information system which fails, whether by design or by accident, to provide an
adequate audit trail or sufficient evidence
– Un-authorised transactions or improperly recorded transactions
– adverse media comment
If the auditor becomes aware of information concerning an instance of non-compliance or suspected non-
compliance with laws and regulations, the auditor shall:
Procedures when non-compliance is suspected- these need to be tailored to the scenario given in the
AAA exam
1. Obtain an understanding of the nature of the act and the circumstances in which it has occurred
2. Evaluate effect on F/S (financial consequences, double entries and disclosures)
3. Discuss with the management and ask them to provide sufficient information that the entity is
complying
4. Perform audit procedures to determine the amount, materiality and probability of payment of any
such fine or penalty imposed.
5. Determine whether they have a responsibility to report the identified or suspected non-compliance
to parties outside the entity.
Page | 7
Reporting of Identified or Suspected Non-Compliance
The auditor shall communicate with those charged with governance matters involving non-compliance
with laws and regulations that come to the auditor’s attention during the course of the audit.
If the auditor suspects that management or those charged with governance are involved in non-
compliance, the auditor shall communicate the matter to the next higher level of authority at the entity,
if it exists, such as an audit committee or supervisory board.
Where no higher authority exists, or if the auditor believes that the communication may not be acted
upon or is unsure as to the person to whom to report, the auditor shall consider the need to obtain legal
advice.
If the auditor concludes that the non-compliance has a material effect on the financial statements, and
has not been adequately reflected in the financial statements, the auditor shall, in accordance with ISA
705, express a qualified opinion or an adverse opinion on the financial statements
If the auditor is precluded by management or those charged with governance from obtaining sufficient
appropriate audit evidence to evaluate whether non-compliance that may be material to the financial
statements has, or is likely to have, occurred, the auditor shall express a qualified opinion or disclaim an
opinion on the financial statements on the basis of a limitation on the scope of the audit in accordance
with ISA 705.
If the auditor has identified or suspects non-compliance with laws and regulations, the auditor shall
determine whether the auditor has a responsibility to report the identified or suspected non-compliance
to parties outside the entity.
External auditor
✓ CANNOT prevent non- compliance
✓ CANNOT detect ALL non-compliance
Page | 8
✓ Needs to fully understand the legal and regulatory environment of the client
✓ Needs to perform procedures to identify non-compliance and on suspected non-compliance to
evaluate their direct or indirect effect on F/S.
✓ Need to report to appropriate authorities (within the organisation and outside the organisation where
appropriate)
In the exam, you may be expected to evaluate the audit implications of non-compliance with laws and
regulations.
Page | 9
Money Laundering
Process of ML
The basic money laundering process has three steps:
Placement: This is the introduction or placement of the illegal funds into the financial system. This is when
cash obtained through criminal activity is first placed into the financial system. Business owners who have
illegally obtained funds can use a cash-intensive business to mix legitimate cash receipts from business
activity with the funds they wish to launder.
Layering: layering involves moving the money through various financial transactions to change its form
and make it difficult to locate the original source. Layering may involve:
– Several bank-to-bank transfers
– Wire transfers between different accounts in different names in different countries
– Making deposits and withdrawals so that the amount of money in the accounts varies continually
– Purchasing high value items such as diamonds to change the form of the money
– making numerous purchases and sales of investments;
– making fake sales between controlled companies (this can often be extremely subtle, eg through the
use of invoices that do involve a transfer of goods, but which exaggerate the price).
Integration: the illegitimate funds re-enter the legitimate economy in a legitimate form. At this stage, it
becomes very difficult to catch a launderer if there is no documentation during the previous stages,
therefore launderers can use the money without getting caught. The launderer might choose to invest
the funds into real estate, luxury assets or business ventures.
Page | 10
Methods of ML
Structuring deposits/smurfing: In this case, large amounts of money are broken down into smaller
amounts so that these appear less suspicious. These amounts are then deposited into one or more bank
accounts. This may be done either by several people (also called ‘smurfs’) or by a single person over a long
time period. This method is also known as smurfing.
Shell companies: These are bogus companies that exist solely for the purpose of money laundering. They
accept illegal money as "consideration" for goods or services. However, in reality neither good nor services
are provided.
Overseas banks: Money laundering can be done by sending money through various bank accounts in
certain offshore locations / countries. These locations / countries allow anonymous banking for all
purposes. Hong Kong, the Bahamas, Bahrain, the Cayman Islands, Singapore and Panama have been
identified as the major offshore centres by the International Monetary Fund.
Alternative banking: Some countries have deep-rooted, unconventional banking systems that enable
undocumented deposits, withdrawals and fund transfers to take place. Such banking systems operate
outside the control of the government and transact without leaving a paper trail, making it difficult to
unearth the transaction that took place.
Appointment of Money The MLRO is a nominated officer who is responsible for receiving and
Laundering Reporting evaluating reports of suspected money laundering from colleagues
Officer (MLRO) within the firm, and making a decision as to whether further enquiry is
required and if necessary, making reports to the appropriate external
body. The MLRO should have an appropriate level of seniority and
experience and would usually be a senior partner.
Main Responsibilities
– Consider internal reports of money laundering
– Decide if there are sufficient grounds for suspicion
– Prepare external report for appropriate authority when needed
– Advise the engagement team/individual on how to continue their
work and interact with the client to balance professional
responsibilities, risk to the business and legal responsibilities under
the money laundering legislation (need to ensure tipping off doesn’t
take place)
– Train the firm’s employees in anti-ML and reporting suspicion
procedures
– Design and implement internal anti-ML systems and procedures in
the firm
Page | 11
External Report Contents
1. Full name of the reporting business
2. Identification information on each subject (e.g. full name, date of
birth, nationality, occupation)
3. The role of each subject in the matter being reported (suspect,
victim)
4. Any bank account or transaction details (for
identification/reference)
5. Details of transactions or activities giving rise to suspicion or
knowledge (including amounts, dates, currencies, sources)
6. Information on the location of any laundered property
7. Any other relevant information (for example persons associated
with the suspect)
Customer Identification This is often referred to as customer due diligence (CDD), or ‘know your
Procedures. client’(KYC) procedures.
The point of these procedures is to ensure that the firm has verified the
identity of clients (whether the client is an individual or an entity), and
has obtained evidence of that identity.
Page | 12
Examples of ‘high-risk’ situations include:
- where the new client has not been physically present for
identification purposes
- where the new client is a ‘politically exposed person’ (PEP) – a PEP
is someone who is or has in the last year exercised a prominent
public function in a foreign country or an international body, or a
family member or known close associate of such a person. The
purpose of making special provision for PEPs is, quite clearly, to
recognise the possibility that persons holding political power may
have or have had means of access to public funds, and means of
transporting them, that other citizens will not have, and to ensure
that accountants are doubly aware of the heightened risk that such
persons may consequently present.
Methods of verification
Individuals – Name, Date of Birth, Residential Address
Page | 13
Enhanced record keeping. Records must be kept of clients’ identity, the firm’s business relationship
with them, and details of transactions with the client. All records should
be kept for five years after the end of the business relationship or
completion of the transactions. Internal and external reports made in
connection to money laundering should also be securely kept for five
years.
Communication and All relevant employees should receive training so that they are aware of
training. the main provisions of money laundering regulations, and so that they
know how to recognise and deal with activities which may be money
laundering.
Include responsibilities
regarding ML in the
engagement letter
Page | 14
AAA- Key exam focus points
Questions in the AAA exam will not always flag up that candidates need to consider laws and regulations
or money laundering; the challenging nature of exam will mean that candidates will have to conclude
for themselves that questions are testing a specific subject area of the syllabus
You may be asked to evaluate whether there are indicators of money laundering in the given scenario.
Ensure what you explain which each is an indicators instead of simply stating that this raises ML
suspicions.
In the exam, remember that auditors need to be particularly careful where money laundering issues
are concerned – especially for a business that is predominantly cash-based because the scope for
money laundering in such businesses is wide. There are usually three stages in money laundering which
should be linked to the scenario where possible.
1. Placement – which is the introduction or ‘placement’ of illegal funds into a financial system.
2. Layering – which is where the money is passed through a large number of transactions. This is done
so that it makes it difficult to trace the money to its original source.
3. Integration – which is where the ‘dirty’ money becomes ‘clean’ as it passes back into a legitimate
economy.
The steps can also be known by the terms, hide, move and invest.
There are many countries in which money laundering is a criminal offence and, where an accountant
or an auditor discovers a situation which may give rise to money laundering, the accountant or auditor
must report such suspicions to a ‘money laundering reporting officer’ (MLRO) whose responsibility it is
to report such suspicions to an enforcement agency.
It is an offence to fail to report suspicions of money laundering to NCA or the MLRO as soon as
practicable, and it is also an offence if the MLRO fails to pass on a report to the NCA. Where the entity
is actively involved in money laundering, the signs are likely to be similar to those where there is a risk
of fraud, and can include:
Page | 15
TIPPING OFF
The term ‘tipping off’ means that the MLRO discloses something that will prejudice an investigation. It
is an offence to make the perpetrators of money laundering aware that the auditor has suspicions or
knowledge regarding their money laundering activities or that these suspicions or knowledge have been
reported. It is unnecessary for the auditor to gain all the facts, or to ascertain without a doubt, that an
offence has occurred. The auditor only needs to satisfy themselves that their suspicions are reasonable,
and obtain sufficient evidence to show the allegations are made in good faith.
Page | 16
Code of Ethics for Professional Accountants
Objectivity – to not allow bias, conflict of interest or undue influence of others to override professional
or business judgments
Professional Competence and Due Care – to maintain professional knowledge and skill at the level
required to ensure that a client or employer receives competent professional services based on current
developments in practice, legislation and techniques and act diligently and in accordance with applicable
technical and professional standards.
Confidentiality
The principle of confidentiality imposes an obligation on all professional accountants to refrain from:
(a) Disclosing outside the firm or employing organization confidential information acquired as a result
of professional and business relationships without proper and specific authority or unless there is a
legal or professional right or duty to disclose; and
(b) Using confidential information acquired as a result of professional and business relationships
The following are circumstances where professional accountants are or may be required to disclose
confidential information or when such disclosure may be appropriate:
(a) Disclosure is permitted by law and is authorized by the client or the employer;
(b) Disclosure is required by law, for example:
(i) Production of documents or other provision of evidence in the course of legal proceedings;
or
(ii) Disclosure to the appropriate public authorities of infringements of the law that come to
light; and by law:
(i) To comply with the quality review of a member body or professional body;
(ii) To respond to an inquiry or investigation by a member body or regulatory body;
(iii) To protect the professional interests of a professional accountant in legal proceedings; or
(iv) To comply with technical standards and ethics requirements.
Professional Behavior – to comply with relevant laws and regulations and avoid any action that discredits
the profession.
Page | 17
Threats to those fundamental principles
a) Self-interest threat – the threat that a financial or other interest will inappropriately influence the
professional accountant’s judgment or behavior;
b) Self-review threat – the threat that a professional accountant will not appropriately evaluate the
results of a previous judgment made or service performed by the professional accountant, or by
another individual within the professional accountant’s firm or employing organization, on which the
accountant will rely when forming a judgment as part of providing a current service;
c) Advocacy threat – the threat that a professional accountant will promote a client’s or employer’s
position to the point that the professional accountant’s objectivity is compromised;
d) Familiarity threat - the threat that due to a long or close relationship with a client or employer, a
professional accountant will be too sympathetic to their interests or too accepting of their work; and
e) Intimidation threat – the threat that a professional accountant will be deterred from acting
objectively because of actual or perceived pressures, including attempts to exercise undue influence
over the professional accountant.
- The basic ethical standards at this level are the same as those examined previously in F8; what sets
apart the level of the questions is your ability to apply those standards to more complex situations
and show that you understand both threats and safeguards.
- Often the marks for this area will be spread over more than one question and may be combined
with planning, professional issues or as a standalone!
Important terms:
Independence of mind: the state of mind that permits the provision of an opinion without being affected
by influences that compromise professional judgment, allowing an individual to act with integrity, and
exercise objectivity and professional skepticism.
Independence in appearance: the avoidance of facts and circumstances that are so significant that a
reasonable and informed third party, having knowledge of all relevant information, including any
safeguards applied, would reasonably conclude a firms, or a member of the assurance team’s, integrity,
objectivity or professional skepticism had been compromised.
Page | 18
QCR( Quality control review)
✓ Having an appropriate reviewer who was not involved in providing the service review the audit work
or service performed
Segregation of teams
✓ Using professionals who are not audit team members to perform the service
Actual or threatened litigation by client - QCR (have an appropriate reviewer review the
When litigation with an audit client occurs, or work performed.
appears likely- Such adversarial positions might - If a team member involved, remove from team
affect management’s willingness to make - Withdraw from engagement if very significant
complete disclosures.
To evaluate the level of threat, it’s important to
Threats: consider the materiality of the litigation and
self-interest Whether the litigation relates to a prior audit
intimidation threats. engagement.
self-interest
familiarity
Compensation and evaluation: When an audit CANNOT evaluate or compensate a key audit
team member is evaluated on or compensated partner based on that partner’s success in selling
for selling non-assurance services to that audit non-assurance services to the partner’s audit
client, client.
Page | 19
Threat: Revise the compensation plan or evaluation
self-interest process for that
individual.
Need to evaluate:
(a) What proportion of the compensation or
evaluation is based on the sale of such services;
(b) The role of the individual on the audit team; and
(c) Whether the sale of such non-assurance services
influences promotion decisions.
Page | 20
Threat to objectivity and professional
competence and due care:
self-interest
Page | 21
Threats: CAN be extended to an extra year IF rotation is not
self-interest (concerned about losing the possible for genuine reasons. Need to inform client’s
client or interest in maintaining a close TCWG about this and the safeguards that are being
relationship with the senior management) implemented to manage this.
familiarity
Cooling-off Period
Private clients
- Depends on the firm’s structure and seniority of
the people involved
- Rotate members
- QCR, External QCR
Recent Service with an Audit Client - Consider the position he was at and the role he
now has in the team
If an audit team member has recently served as
a director or officer, or employee of the audit - Remove from team if worked at the client in the
client. year being audited at a position to exert
significant influence over the subject matter.
Threats: (remember, the F/s contain comparatives as well
self-interest so the same safeguard would apply if he has
self-review worked in the previous year as well)
familiarity - QCR if he has already done some work at the
client
Page | 22
Temporary staff assignments: Lending of staff - Should ideally then not be made a part of the
to the client audit team (Not including the loaned personnel
as an audit team member might address a
Threats: familiarity or advocacy threat).
self-interest
familiarity - IF in the team, Not giving the loaned staff audit
advocacy responsibility for any function or activity that the
management threat staff performed during the temporary staff
assignment ( this might address the self-review
threat)
Ensure
- only for a short period of time
- seconded staff should not assume management
responsibilities
- the audit client is responsible for directing and
supervising the activities of the personnel.
Employment with the client: the director or a Public interest: 12 months should have passed since
senior member of the audit client has been a the individual was Partner.
member of the audit team or partner of the firm
in the past - Ensure no significant connection remains
between the firm and the individual ( e.g.
Threats: material amounts owed by the firm to the
self-interest individual, participation in firm’s professional
familiarity activities etc)
intimidation - Modify the audit plan;
- Assign individuals to the audit team who have
sufficient experience in relation to the individual
who has joined the client; or
- QCR of the former member of the audit team.
Page | 23
Firm policies and procedures shall require members
of an audit team to notify the firm when entering
employment negotiations with the client. On
receiving such notification, the significance of the
threat shall be evaluated and safeguards applied
when necessary to eliminate the threat or reduce it
to an acceptable level. Examples of such safeguards
include:
- Removing the individual from the audit team; or
- A review of any significant judgments made by
that individual while on the team.
Family and personal relationship Remove from team if the relationship is with a senior
person at the client with influence over the f/s.
Close relationships between an audit team
member and a director or officer or,certain If not, consider work allocated to the team
employees of the audit client who are in a member(Structuring the responsibilities of the audit
position to exert significant influence over the team so that the professional does not deal with
client’s financial position, financial performance matters that are within the responsibility of the
or cash flows. immediate family member.)
Threats:
self-interest
familiarity
intimidation
Page | 24
Threats:
self-interest
intimidation (due to actual or perceived
pressure about losing the audit
assignment)
Threat:
self-interest
Threats:
self-interest (threat to objectivity and
confidentiality)
Conflict of interest In general, the more direct the connection between
the professional service and the matter on which the
A conflict of interest creates threats to parties’ interests conflict, the more likely the level of
compliance with the principle of objectivity and the threat is not at an acceptable level.
might create threats to compliance with the
other fundamental principles. Such threats Examples of actions that might be safeguards to
might be created when: address threats created by conflicts of interest
a) Firm provides a professional service related include
to a particular matter for two or more
Page | 25
clients whose interests with respect to that Notify all parties (disclose the nature of the
matter are in conflict; or conflict of interest and how any threats created
b) The interests of the firm with respect to a were addressed to the relevant parties)
particular matter and the interests of the - Get Written consent from the affected
client for whom the firm provides a clients to act
professional service related to that matter
are in conflict. - Segregation of teams
Page | 26
Second opinion
Firm might be asked to provide a second - With the client’s permission, obtaining
opinion on the application of accounting, information from the existing or predecessor
auditing, reporting or other standards or accountant.
principles to (a) specific circumstances, or (b)
transactions by or on behalf of a company or an - Ensure same set of facts given as existing auditor
entity that is not an existing client.
Threat:
self-interest (threat to compliance with the
principle of professional competence and
due care)
Custody of Client Assets Before taking custody
(assume custody of client money, documents or - Check if allowed by laws and regulations
other assets for a fee) - Make inquiries about the source of such assets(
might reveal that the assets were derived from
Threat to professional competence and due illegal activities, such as money laundering)
care and objectivity
self-interest After taking custody
- Confidentiality to be ensured
- Keep such assets separately from personal or
firm assets;
- Use such assets only for the purpose for which
they are intended;
- Internal control in firm for security
Page | 27
Non-Assurance Services to Audit Clients
Threats
Self-review
self-interest threats
familiarity threat
Accounting and bookkeeping services Audit Clients that are Public Interest Entities- Not
allowed.
Accounting and bookkeeping services comprise
a broad range of services including: Other clients: may provide accounting and
- Preparing accounting records and bookkeeping services if a routine or mechanical
financial statements. if safeguards are implemented.
- Recording transactions.
- Payroll services.
Page | 28
Threat Safeguards for routine and mechanical services:
Self-review
- Segregation of teams: Using professionals who
It is the management’s responsibility to: are not audit team members to perform the
- Determine accounting policies and the service.
accounting treatment in accordance with - QCR: Having an appropriate reviewer who was
those policies. not involved in providing the service review the
- Prepare or change source documents or audit work or service performed
originating data, in electronic or other form,
evidencing the occurrence of a transaction.
Examples include Purchase orders, Payroll
time records, Customer orders.
- Originating or changing journal entries.
- Determining or approving the account
classifications of transactions.
Page | 29
- Preparing payroll calculations or reports
based on client originated data for approval
and payment by the client.
- Recording recurring transactions for which
amounts are easily determinable from
source documents or originating data, such
as a utility bill where the client has
determined or approved the appropriate
account classification.
- Calculating depreciation on fixed assets
when the client determines the accounting
policy and estimates of useful life and
residual values.
- Posting transactions coded by the client to
the general ledger.
- Posting client-approved entries to the trial
balance.
- Preparing financial statements based on
information in the client-approved trial
balance and preparing related notes based
on client-approved records.
Page | 30
Safeguards to be implemented to address threats if
immaterial and doesn’t involve significant degree of
judgment:
- Segregation of teams
- QCR
Internal audit Audit Clients that are Public Interest Entities: Not
allowed if they relate to a significant part of the
Internal audit services involve assisting the internal controls over financial reporting or
audit client in the performance of its internal relate amounts/disclosures that are material
audit activities.
Safeguards for self-review and management
Threat threats for clients that aren’t public interest or
Self-review (the results of internal audit for internal audit service that don’t relate to
service might be used in conducting the financial reporting:
external audit). - Segregation of teams
Performing a significant part of the client’s - The client designates an appropriate and
internal audit activities increases the competent senior management to be
possibility that firm will assume a responsible at all times for internal audit
management responsibility. activities
- The client acknowledges responsibility for
designing, implementing, monitoring and
maintaining internal control.
Page | 31
Internal audit activities might include: - The client evaluates and determines which
- Monitoring of internal control – reviewing recommendations resulting from internal
controls, monitoring their operation and audit services to implement and manages
recommending improvements to them. the implementation process
- Examining financial and operating
information by:
✓ Reviewing the means used to identify,
measure, classify and report financial
and operating information.
✓ Inquiring specifically into individual
items including detailed testing of
transactions, balances and procedures.
- Reviewing the economy, efficiency and
effectiveness of operating activities
including non-financial activities of an
entity.
- Reviewing compliance with:
✓ Laws, regulations and other external
requirements.
✓ Management policies, directives and
other internal requirements.
Page | 32
However, the IT systems might also involve - The client should make all management
matters that are unrelated to the audit client’s decisions with respect to the design and
accounting records or the internal control over implementation process;
financial reporting or financial statements.
Recruiting services might include activities such Cannot act as a negotiator on the client’s behalf
as developing a job description, developing a
process for identifying and selecting potential Cannot provide a recruiting services (related to
candidates, searching for or seeking out searching for candidate and conducting
candidates, Screening potential candidates for reference checks) to an audit client with respect
the role by reviewing the professional to the following positions:
qualifications or competence of applicants and - A director or officer of the entity; or
determining their suitability for the position, - A member of senior management in a
Undertaking reference checks of prospective position to exert significant influence over
candidates, Interviewing and selecting suitable the preparation of the F/S
candidates and advising.
For other positions (excluding the above)
on candidates’ competence and determining - The client makes all management decisions with
employment terms and negotiating details, respect to the hiring process, including
such as salary, hours and other compensation. determining the suitability of prospective
candidates and selecting suitable candidates for
Threats the position and determining employment terms
Self-interest, and negotiating details, such as salary, hours and
Familiarity other compensation.
intimidation
assuming management responsibility
Corporate finance services to an audit client Corporate Finance Services that are Prohibited
- promoting, dealing in, or underwriting the
Threats audit client’s shares.
Self-review - where the effectiveness of such advice
Advocacy depends on a particular material accounting
treatment or presentation in the F/S and the
Examples of corporate finance services: audit team has reasonable doubt as to the
- Assisting an audit client in developing appropriateness of the related accounting
corporate strategies. treatment or presentation under the
- Identifying possible targets for the audit relevant financial reporting framework.
client to acquire.
- Advising on disposal transactions.
Page | 33
- Assisting in finance raising transactions. For other services:
- Providing structuring advice. - Segregation of teams
- Providing advice on the structuring of a - QCR
corporate finance transaction or on
financing arrangements that will directly
affect amounts that will be reported in the
financial statements on which the firm will
express an opinion.
Page | 34
Tax Planning and Other Tax Advisory Services
Page | 35
Not allowed if relates to material amounts and/or
the services involve acting as an advocate for the
audit client before a public tribunal or court in the
resolution of a tax matter
Otherwise:
- Segregation of teams
- QCR
Advocacy examples
Legal services, corporate finance work like negotiating with banks on client’s behalf, contingent fee
When asked to evaluate ethical considerations in the exam, the following answering techniques should
be followed:
1. Identify and explain the threat: for example, audit client has asked the firm to prepare consolidated
financial statements as a separate engagement. This would give rise to self-review (explain how) and
management threats (explain how).
Page | 36
2. Evaluate the threat: the code says that cannot provide services related to the preparation of
accounting records and financial statements to an audit client unless the services are of a routine and
mechanical nature. Preparing the Group accounts would not be routine and mechanical – it would
involve the auditor making judgements and taking responsibility for the whole of the consolidated
financial statements.
3. Address the threat: Decline.
Page | 37
Fraud
Fraud: ISA 240 (Redrafted) defines fraud as: ‘An intentional act by one or more individuals among
management, those charged with governance, employees, or third parties, involving the use of deception
to obtain an unjust or illegal advantage.’
Irregularity includes:
– Financial reporting which renders the financial statements misleading
– Misappropriation of assets
Two types of intentional misstatements are relevant to the auditor – misstatements resulting from
fraudulent financial reporting and misstatements resulting from misappropriation of assets.
Fraudulent financial reporting often involves management override of controls that otherwise may appear
to be operating effectively. Fraud can be committed by management overriding controls using such
techniques as intentionally:
• Recording fictitious journal entries, particularly close to the end of an accounting period, to
manipulate operating results or achieve other objectives.
• Inappropriately adjusting assumptions and changing judgments used to estimate account balances.
• Omitting, advancing or delaying recognition in the financial statements of events and transactions
that have occurred during the reporting period.
• Omitting, obscuring or misstating disclosures required by the applicable financial reporting
framework, or disclosures that are necessary to achieve fair presentation.
• Concealing facts that could affect the amounts recorded in the financial statements.
• Engaging in complex transactions that are structured to misrepresent the financial position or
financial performance of the entity
Page | 38
Altering records and terms related to significant and unusual transactions
Misappropriation of assets involves the theft of an entity’s assets and is often perpetrated by employees
in relatively small and immaterial amounts. However, it can also involve management who are usually
more able to disguise or conceal misappropriations in ways that are difficult to detect. Misappropriation
of assets can be accomplished in a variety of ways including:
• Embezzling receipts (for example, misappropriating collections on accounts receivable or diverting
receipts in respect of written-off accounts to personal bank accounts).
• Stealing physical assets or intellectual property (for example, stealing inventory for personal use or
for sale, stealing scrap for resale, colluding with a competitor by disclosing technological data in return
for payment).
• Causing an entity to pay for goods and services not received (for example, payments to fictitious
vendors, kickbacks paid by vendors to the entity’s purchasing agents in return for inflating prices,
payments to fictitious employees).
• Using an entity’s assets for personal use (for example, using the entity’s assets as collateral for a
personal loan or a loan to a related party).
Earnings Management
An example of fraud is management overriding controls and manipulating information i.e. ‘earnings
management’.
Earnings management occurs when companies deliberately manipulate their revenues and/ or expenses
in order to inflate (or deflate) figures relating to profits and earnings per share. In other words, it is when
companies use ‘creative accounting’ to construct reported figures that show the position and
performance that management want to show.
Earnings management does not always mean that the applicable financial reporting framework has not
been followed. Earnings management is often described as ‘bending the rules. It may be that the
manipulation of published figures is the result of selecting an accounting policy which is allowed under
the financial reporting framework, but which does not reflect economic reality. For example, changing the
estimated life of a non-current asset is allowed under financial reporting standards, but if it is done purely
to manipulate the depreciation charge (and therefore earnings), then it becomes an example of earnings
management.
Page | 39
Responsibilities of External Auditors and Management in Relation to the Detection of Fraud
Management/TCWG
ISA 240 makes it clear that the primary responsibility for the prevention and detection of fraud rests with
both those charged with governance and management of an entity. By establishing a sound system of
operational and financial controls, management should reduce opportunities for fraud to take place, and
establish a culture which should persuade individuals not to commit fraud due to the likelihood of
detection and punishment. In some jurisdictions, codes of corporate governance require specific actions
to be taken in respect of internal controls by management.
External Auditor
The external auditor may provide recommendations and advice on the improvement of internal controls,
but it is not their responsibility to put the recommendations into practice.
The auditor’s responsibility is to consider the risk of material misstatement in the financial statements
due to fraud. This means that the auditor is more focused on fraud that impacts on the accounts than on
operational fraud which may not cause a material misstatement.
A fraud with an immaterial impact may not be detected by audit procedures. Because the external auditor
will use sampling techniques based on a level of materiality, not all balances and transactions will be
subject to detailed testing, so small frauds are not likely to be detected. A similarity is that both
management and the external auditor should assess the strength of controls in place within the entity,
and in doing so, evaluate the likelihood of a fraud occurring. The auditor will perform this evaluation
while planning the audit.
ISA 240
1. Professional Skepticism: the auditor shall maintain professional skepticism throughout the audit,
recognizing the possibility that a material misstatement due to fraud could exist. If conditions
identified during the audit cause the auditor to believe that a document may not be authentic or that
terms in a document have been modified but not disclosed to the auditor, the auditor shall investigate
further.
2. Discussion among the Engagement Team: Led by the engagement partner. Particular emphasis
should be placed on how and where the entity’s financial statements may be susceptible to material
misstatement due to fraud, including how fraud might occur.
3. Risk Assessment Procedures and Related Activities (Obtain information for use in identifying the risks
of material misstatement due to fraud.)
Page | 40
The auditor shall make inquiries:
Regarding management’s assessment of the risk that the financial statements may be materially
misstated due to fraud
Regarding management’s process for identifying and responding to the risks of fraud in the
entity
to determine whether they the management/TCWG have knowledge of any actual, suspected
or alleged fraud affecting the entity
For those entities that have an internal audit function, the auditor shall make inquiries of appropriate
individuals within the function to determine whether they have knowledge of any actual, suspected
or alleged fraud affecting the entity, and to obtain its views about the risks of fraud.
The auditor shall evaluate whether unusual or unexpected relationships that have been identified in
performing analytical procedures that may indicate risks of material misstatement due to fraud.
The auditor shall consider whether other information obtained by the auditor indicates risks of
material misstatement due to fraud. The auditor shall evaluate whether the information obtained
from the other risk assessment procedures and related activities performed indicates that one or
more fraud risk factors are present.
Overall responses to address the assessed risks of material misstatement due to fraud at the financial
statement level
In determining the overall responses to address the assessed risks of material misstatement due to fraud
at the financial statement level, the auditor shall:
a) Assign engagement responsibilities to personnel based on knowledge, skill and ability. For example,
assigning additional individuals with specialised skill and knowledge, such as forensic and IT experts,
or by assigning more experienced individuals to the engagement;
b) Evaluate whether the selection and application of accounting policies by the entity may be
indicative of fraudulent financial reporting resulting from management’s effort to manage earnings.
This is particularly applicable to those accounting policies which involve subjective measurements and
complex transactions, and
c) Incorporate an element of unpredictability in the selection of the nature, timing and extent of audit
procedures, such as performing audit procedures at different locations or at particular locations,
unannounced.
To those charged with governance: fraud involving management or when fraud is ignored by
management
Page | 41
To regulators: when the duty of confidentiality is overridden by law
1. Sometimes the auditor may come across situations which will not permit the auditor to continue
performing the audit.
2. All entities have various complexities. Hence fraud occurs under different situations in different
entities. Therefore there are no clear guidelines of the situations in which the auditor can withdraw
from the engagement. However the auditor may decide to withdraw from the assignment when the
auditor is worried about the implications of the involvement of those charged with governance or the
effect on the auditor of continuing the association with the entity. For example, the auditor of the
arms manufacturer may be worried about being associated with the client on account of the client’s
dealings.
3. The auditor will also need to consider the professional and legal responsibilities applicable in the
circumstances, including whether there is a requirement for the auditor to report to the person or
persons who made the audit appointment or, in some cases, to regulatory authorities.
4. However, according to ISA 240, auditors of public sector entities often do not have the option of
withdrawing from the engagement due to public interest considerations.
Page | 42
AAA- Key exam focus points
Fraud has been tested in the AAA exam in combination with various other topics like professional
liability where you are expected to evaluate if the auditors had been negligent in not identifying fraud.
You may also be asked to evaluate if sufficient appropriate evidence had been gathered by the auditors
regarding an area in which fraud was identified later.
Your answer needs to be specific to the scenario. Additionally, keep in mind the following.
Where possible, outline the type of fraud that has been identified at the client.
1. Fraudulent financial reporting ( fake journal entries, manipulating estimates and judgments,
omitting transactions and events or recording them in the incorrect period, omitting or misstating
F/S disclosures, altering records and supporting documents etc.)
Management:
Prevent and detect fraud through strong internal controls and a culture of honesty.
External Auditor:
NOT primary responsibility to detect fraud- needs to gain reasonable assurance that F/S are free from
material fraud. The auditor might not be able to detect fraud (and error) because evidence is persuasive
not conclusive, sophisticated accounting techniques may have been used to commit fraud, collusion
may have occurred, sampling is used so immaterial fraud may not be detected etc.
Page | 43
Professional Liability
Accountants who do not discharge their services responsibly face the following legal liabilities:
1. Criminal liability for negligence
2. Specific statutory liability
3. Civil liability for negligence
1. Criminal liability
Breach of trust: the auditor Right Accountants are the auditors of Dvyne Plc. Dvyne Plc has
not maintaining the recently tendered for a catering contract with Cat Airlines. The
confidentiality of partner of Right informed his brother-in-law (who was a caterer)
information or not using about the value of the tender.
client information for the
benefit of the client. This is a criminal liability involving a breach of trust since:
– Confidentiality is not maintained i.e. information about the client
was passed to the auditor’s brother-in-law
– Client information was not used for the benefit of the client i.e.
it was used for the benefit of the auditor’s brother-in-law.
Breaches of contract: An auditor is required to exercise sufficient care and skill while
continuation of an audit executing his duties. The ACCA clarifies this under Fundamental
engagement after the term Principles in the Rules of Professional Conduct.
of appointment is
completed.
A company enters into a contract with its auditors. Therefore, the
appointment of an auditor by a company is governed by contract
laws.
Insider trading: the auditor makes use of unpublished price sensitive information to obtain
personal benefit. Auditors generally avoid purchasing shares in the client company so that the
probability of insider trading will not occur.
Page | 44
2. Specific statutory liability
Liability arising from Rex is a professional accountant. On 25 April 20X8, he was appointed
insolvency legislation the liquidator of Minerex Plc, a mining company located in the UK.
The tasks which were performed for the winding up of the company
included selling off all free assets and obtaining as much dividend as
possible.
Liability arising from For example, when the auditor does not disclose creative accounting
statute such as tax practices made by the client with the intention of paying lower taxes
legislation.
Liability arising under e.g. non-compliance with stock exchange regulations, Sarbanes-Oxley
regulatory legislation Act provisions
3. Civil liability
A professional accountant can face civil liabilities for negligence, when he conducts his duties
negligently. The liability of the auditor towards third parties is called a liability in tort. The term
liability in tort means a third-party liability.
Page | 45
– to client or third party to whom duty of care is owed.
Not carry out further audit procedures on occasions when auditors suspect
that there are material misstatements in the financial statements.
by member / his or Professional accountant is expected to take responsibility for his work. In
her employee / short, the work of the accountant, if performed by his employee or his
associate associate, needs to be carried out under the supervision of the accountant.
Therefore, even if the accountant takes the assistance of either his employees
or his associates, the accountant cannot be absolved of his responsibility.
must lead to Professional accountants can be charged with liabilities for negligence, only if
financial loss either their clients or third parties suffer from financial loss on account of acts
of negligence by auditor. The financial loss suffered by a client must be a direct
financial loss, i.e. not an indirect or remote loss.
ii. The accountant is sometimes informed before carrying out the work
that a third party would rely on the statements (or work) carried out by
the accountant. For example, an accountant who is asked to prepare a
project report for the purpose of getting a bank loan will be in a position
to know, in advance, that the project report will be used by the bank
for the purpose of vetting the loan application.
Page | 46
However, even when the accountant is not explicitly informed by the
client that a third party would rely upon the results of his work, the
accountant is expected to understand the likely parties who would
rely on his work.
Jay, the auditor of Sea Shells Resorts, certifies a report solely for Prego
Hotels, which has requested and commissioned this report. In this case,
Jay will only have a duty of care towards Prego Hotels since he has
‘proximity’ with them.
All audit firms want to avoid litigation, due to the bad publicity that is likely to follow, the financial
consequences, and the potential collapse of the audit firm. There are several ways that an audit firm can
reduce its exposure to claims.
Client acceptance Firms should carefully assess the risk associated with potential audit clients.
procedures Screening procedures should be used to identify matters that create potential
exposure for the audit firm. For example, it would be unwise to take on a new
client with significant going concern problems. The issue is that a client should
only be accepted if the associated risk can be managed to an acceptably low
level given the skills and resources of the audit firm.
Performance and Audit firms should ensure that professional standards are maintained, and
documentation of that International Standards on Auditing. (ISAs) are adhered to. It is crucial
audit work that full documentation is maintained for all aspects of the audit, including
planning, evaluation of evidence, and consideration of ethical issues. A claim
of negligence is unlikely to be successful if the audit firm has documentary
evidence that ISAs have been followed.
Page | 47
Quality control Firms must ensure they have implemented firm-wide quality control
procedures, as well as procedures applicable to the individual audit
engagement. Quality control acts as an internal control for the audit firm,
helping to ensure that ISAs and internal audit methods have been followed at
all times.
Firms should make use of external specialists when the need arises, for
External consultations example obtaining legal advice where appropriate, to ensure that the
auditor’s actions are acceptable within the legal and regulatory framework.
Issue disclaimer In recent years it has become common in some jurisdictions for audit firms to
include a disclaimer paragraph in the audit report. This is an attempt to
restrict the duty of care of the audit firm to the shareholders of the company,
thereby attempting to restrict legal liability to that class of shareholders.
Disclaimers, however, may not always be effective.
“This report has been marked ‘CONFIDENTIAL’. It has been prepared solely
for the members of Cosby Company in accordance with the Companies Act
2006. The audit report consists of those matters that are required to be
undertaken for an audit and to be stated in an audit report and not for any
other purpose. In the circumstances, with the full support of law, I am not
held responsible for any other party other than the company and the
company members for the audit report or for the audit opinion.”
The ACCA (according to ACCA Fact sheet 84) discourages the use of standard
disclaimers. This is because standard disclaimers amount to reducing the
value of the audit report. Furthermore, the disclaimer can be misused by
auditors as a safeguard against an improper audit.
Use engagement The engagement letter should be used to clearly state the responsibilities of
letter the auditor, and of management. As it forms a contract between the audit
firm and the client, it should be updated on an annual basis, with care being
taken to ensure the client is fully aware of any changes in the scope of the
audit, or the reporting responsibilities of the audit firm.
Capping or setting a The auditor’s liability can be restricted by capping or setting a limit on the
limit on amount of amount of liability which can be imposed on any specific party.
liability
Page | 48
This amount can be determined as a multiple of audit fees for a particular
engagement, i.e. there will be a direct relationship between the audit fees
and the amount of liability or the liability will be a proportion of the turnover
of the company.
Operating as In many jurisdictions, auditors are allowed to operate only as sole traders or
incorporation partners i.e. firms have joint and several liabilities. This means that a partner
can face liability on account of negligence by other partners of the firm as well
as the directors of the client company.
This is because:
– it makes the audit company fully liable for the total amount of any
judgment which exceeds the professional indemnity insurance
– it makes the audit partners and the company liable for negligent acts by
any partner of the company
– it protects the private assets of the ‘innocent’ audit partners
– partners who are ‘guilty’ of negligence owe joint and several
responsibilities
– the firm can be forced into liquidation
– the firm would need to publish its financial statements and also be
subjected to audit
Choosing limited Under an LLP, ‘innocent’ members are not personally liable for the acts of
liability partnership negligence by other members. Their liability is restricted to their share in the
assets of the business. In short there is no difference between the liabilities
of members of incorporation and an LLP. The only difference between the two
entities is the taxation implications, i.e. incorporation has to pay taxes like any
other ‘company’. However, an LLP does not pay tax. Only its members pay
taxes for the income earned through the LLP. Ernst & Young in the UK is an
example of an LLP.
Page | 49
Obtaining Accountants who do not discharge their services responsibly face several legal
professional liabilities. Accountant’s face legal claims from clients and third parties due
indemnity insurance to negligent services provided to clients.
External auditor’s liability towards client External auditor’s liability towards a 3rd party
-contract -no contract
-duty of care owed to client -3rd party has to prove duty of care owed to
them
-client has to prove breach of -3rd party has to prove that there has been a
contract/breach of duty of care breach of duty of care
-client has to prove financial loss -3rd party has to prove financial loss
Page | 50
Quality Management
AAA students are expected to understand and apply three standards related to Quality management (at
the firm and engagement level).
For audits to be effective and maintain public trust, they must be performed in a way that ensures firms
and their personnel fulfil their responsibilities in accordance with applicable legal and professional
standards. It is imperative that audit firms adopt a culture of best practice in accordance with these
standards, enabling audit partners in issuing appropriate auditor’s reports. The threats of self interest
caused by increasing financial pressure on audit partners will compromise auditor reports, as will the
issues of poor planning, inadequate risk assessment and lack of resources and audit evidence. The
International Auditing and Assurance Standards Board (IAASB) issues quality standards to support firms
in achieving this aim.
The current standards in this area are International Standard on Quality Management (ISQM) 1, Quality
Management for Firms that Perform Audits or Reviews of Financial Statements and ISQM
2, Engagement Quality Reviews, alongside ISA 220 (Revised), Quality Management for an Audit of
Financial Statements.
These standards are examinable in Advanced Audit and Assurance (AAA) and candidates are expected to
be able to demonstrate an understanding and application of the key principles. Quality management is
pervasive to the performance of audits and so it is also pervasive to the AAA exam with aspects potentially
arising multiple times within a single exam.
This article focuses on ISQM 1; a second article will look at ISQM 2 and ISA 220 (Revised). There are
examples provided demonstrating how certain aspects of quality management may be examined. These
are intended to indicate potential ways candidates may encounter questions on quality, however, these
are illustrative examples only and should not be considered comprehensive; alternative examples and
aspects are also examinable.
Page | 51
There is a need to ensure audit quality evolves; there must be scope within quality guidance for a firm’s
processes to change as technology and business practices change.
There is also focus on improving both internal and external monitoring of firms and their networks and
on improving communication, both internally and to external parties such as those charged with
governance (TCWG) and regulators.
ISQM 1, Quality Management for Firms that Perform Audits or Reviews of Financial Statements, or Other
Assurance or Related Services Engagements
ISQM 1 embeds this approach through a principle driven requirement for firms to create a system of
quality management (SoQM) which is tailored to the firm and its client base. This scalability enables firms
to design a system which addresses their specific circumstances and risks.
This approach will allow the firm to tailor to address the specific risks within their firm, and it will vary
according to the size of the audit firm and their client portfolio.
By maintaining this tailored focus on risks and their mitigation, the firm should be able to focus on
ensuring the right engagement or audit report is issued for each assignment. This may be due to more
competent and well-trained individuals performing complex or risky audits, audit partners feeling more
empowered to issue modified audit reports, by ensuring acceptance procedures fully identify threats to
independence and ensure safeguards are enacted and many other factors. The most crucial point is that
this approach is tailored to address the specific risks arising in specific firms and not expected to be the
same for every audit firm regardless of size or client portfolio.
Exam focus
In the AAA exam, candidates may be required to explain and/or evaluate a firm’s risk assessment
process and make recommendations for improvement.
Page | 52
2. Governance and leadership
Firms should create an environment which demonstrates a commitment to quality through its culture and
recognises its role in serving the public interest. This responsibility is firm wide rather than at the individual
audit level, with the chief executive or managing partner assigned the responsibility and accountability
for the SoQM. This should ensure the ‘tone at the top’ enforces a commitment to quality and ethics across
the whole firm.
Systems and policies should be in place to reward commitment to quality rather than focusing on client
retention and engagement profit. This should allow audit engagement partners to challenge client
judgements without fear of the negative consequences of losing the revenue arising from the loss of the
client. In this way, all employees of the firm are supported to fulfil their legal and regulatory requirements
without undue commercial pressures or self-interest resulting in inappropriate decision making.
Exam focus
Candidates may be required to explain the importance of governance and leadership in maintaining the
SoQM or may be required to evaluate a scenario’s weaknesses in this area, alongside recommendations
for improvement.
Not only must a firm ensure its own personnel understanding of and compliance with relevant ethical
requirements, for example, through training and ethical declarations such as independence forms, firms
must also ensure that any component auditors in a group understand and apply the ethical regulations
applicable to the group auditor.
Relevant ethical requirements for a firm depend on the jurisdiction it operates in; these may go beyond
those set out in the IESBA International Code of Ethics for Professional Accountants (the Code). It is also
the case that many firms will have in place policies to mitigate ethical threats which go beyond the
minimum required by the Code and regulatory requirements of the jurisdiction in which the firm operates:
ISQM 1 requires firms to ensure these requirements are also captured by the SoQM. For example, many
firms or jurisdictions prohibit the acceptance of gifts, even of trivial value. Failure to adhere to the firm’s
policies would be seen as a failure of its SoQM despite not giving rise to a breach of the Code.
Scalability of the standard enables firms to mitigate for ethical risks arising which are appropriate to the
firm, for example, a firm which is part of a large network will require more detailed processes to identify
possible conflicts of interest between clients than those in a smaller firm.
Page | 53
Exam focus
Candidates may be asked to appraise ethical threats arising in the scenario, whilst also considering
whether the firm is compliant with the firm’s SoQM. The issues of quality management and ethical
issues are inherently interlinked and as such, they may need to consider the significance of such threats
and the availability of suitable safeguards within the context of the engagement, the firm and the
SoQM as well as other available information. This enables candidates to obtain professional skills marks
in addition to the technical marks as they are recognising the inherent ethical requirements regarding
quality management on a firm wide basis.
Candidates may be asked to identify breaches of the SoQM which may not breach the Code but are
relevant to the given scenario addressing any resulting implications for the engagement, the firm or
making recommendations to prevent future breaches.
Existing business relationships should be reassessed at the start of each new year prior to reappointment
as auditor. This may mean performing fresh identity checks, reperformance of independence declarations
of employees, and re-evaluating conflicts of interest and/or competence to perform the audit. It will also
involve assessing whether new information, had it been known at point of acceptance, would have
prevented the firm from accepting the client. For example, a client involved in breaches of regulations
may not be a client with values compatible with the audit firm.
Exam focus
Candidates may have to discuss the importance of acceptance and continuation assessments or to apply
the requirements of ISQM 1 in this regard when evaluating whether to accept a new client, undertake
additional work for existing clients or accept reappointment for the audit of a continuing client. The ISQM
1 framework provides a starting point for evaluating the scenario and this may be extended into other
professional and commercial considerations. Candidates should consider legal, regulatory, and ethical
considerations as well as professional and availability of resources when considering a new client
engagement.
Page | 54
Candidates should be aware that the ability to perform the engagement within legal and professional
requirements will incorporate legal, regulatory, and ethical considerations, including the availability of
resources when considering a new client engagement. and requirements covering acceptance may be
extended into other professional and commercial considerations.
The cyclical nature of continuation considerations means that this aspect of quality management may
impact questions at all stages of the audit process and the considerations regarding client acceptance are
likely to apply to audit and non-audit assignments.
5. Engagement performance
Engagement teams must understand their responsibilities for ensuring a quality audit. Less experienced
engagement team members should be appropriately supervised and reviewed. ISQM 1 specifically
references the need for the audit engagement partner to be sufficiently and appropriately involved
throughout the engagement.
Audit teams should ensure professional scepticism and judgement are exercised. Processes should ensure
professional scepticism and judgement are exercised by engagement teams. If an audit team has
insufficient time to perform necessary procedures, or team members are not experienced enough to
challenge management or identify misstatements, then detection risk increases and audit quality will be
compromised. For audits to be effective, and to maintain public trust, they must be performed in such a
way as to ensure the audit reports issued are appropriate in the circumstances and that firms and their
personnel fulfil their responsibilities in accordance with applicable legal and professional standards.
The SoQM should ensure that teams can consult on contentious matters; differences of opinion within
the engagement team are addressed and any issues raised by the engagement quality reviewer are
brought to the attention of the firm and resolved.
Further detail on these aspects will be addressed in the second article where ISA 220 (Revised) will be
examined, including examples of how these may be examined.
6. Resources
A firm must ensure that appropriate resources are available in a timely manner. This includes employees
with the required competence, training, and capabilities to perform the engagements to which they are
assigned. Firms should ensure more experienced individuals to work on areas of a complex nature
requiring additional judgement and ensuring sufficient review by senior team members or allowing
adequate time to do sufficient testing and analysis of the issues.
Consideration should be made to use independent experts where the firm does not have appropriate
personnel, or if the firm requires additional specialist technological resources.
Page | 55
Exam focus
Candidates may have to evaluate scenarios where inappropriate resources have been employed within an
audit and make recommendations for improvements to the firm’s SoQM.
ISQM 1 considers information and communication to be pervasive to all components of the SoQM as
without it, the system cannot operate. The full range of information and communications within the SoQM
is extensive; the boxed text below considers just a few examples in some of the elements of ISQM 1 for
context.
Engagement performance
• Audit programmes devised/produced
• Role assignments delegated and recorded
• Client information obtained and input into automated audit tools
• Conclusions documented in audit file
• Reports to management and TCWG
Communications should be made in a timely manner supporting the firm’s culture to exchange
information where appropriate, for example where an ethical threat precludes the assignment of a team
member to a specific client, the team member would be expected to inform the firm.
Page | 56
ISQM 1 also makes specific reference to external communications required to maintain audit quality. This
includes communication within the firm’s network and with service providers, communications required
by law or professional standards, such as when there is a specific requirement to report a client’s non-
compliance with certain laws and regulations to TCWG.
Exam focus
Candidates may have to evaluate scenarios with respect to these issues and make recommendations for
improvements to the firm’s SoQM in this area. Candidates should remember that I&C is embedded within
all aspects of a SoQM and may not be isolated as a topic.
Exam focus
Candidates may have to explain how this contributes to continuous improvement of a firm’s SoQM.
Candidates may also take the role of a reviewer performing this element of the process: identifying
deficiencies and making recommendations to remediate them.
Conclusion
ISQM 1 provides a focus on audit quality and a process of risk management with respect to quality that
aims to ensure all firms have quality as a priority when performing audits and other assurance
engagements. The standard is principles driven with a focus on scalability, flexibility and continuous
improvement.
Quality management is core to audit, and a detailed understanding of the importance of both audit quality
and quality management underlies the performance of an audit. Quality is a key part of ensuring that
audits are fit for purpose and retain the public trust. As such, it is key to every audit and every stage of
the audit process and candidates should expect to see aspects of quality management examined at all
stages of an audit in exam questions and in either section of the exam.
Candidates can find more explanation of the requirements of ISQM 1 in the appendix to the standard,
available on the IAASB website.
Page | 57
ISQM 2 ( International Standard on Quality Management)- technical article
This second article on quality management focuses on two specific areas. International Standard on
Quality Management 2, Engagement Quality Reviews (‘ISQM 2’), and ISA 220 (Revised), Quality
Management for an Audit of Financial Statements. Candidates are expected to have an understanding of
the requirements of these two standards and may face discussion questions regarding the purpose and
content of these standards. Candidates are also expected to be able to apply this knowledge to scenarios.
Candidates should note this is a very specific term and should avoid the use of ‘second partner review’,
‘concurring review’, ‘independent partner review’ or ‘hot review’ in the exam as these terms are subject
to different interpretations and may not mean the same thing. Candidates should also be aware, when
proposing an EQR, that they specify which engagement would be subject to such a review if the firm is
providing more than one service.
ISQM 2 aims to ensure the right person is appointed to perform the review and clarifies the responsibilities
associated with the role. It seeks to emphasise the importance of, and to improve the effectiveness of,
EQRs.
• Audits where significant issues have been encountered, such as a material restatement of
comparatives.
• Audits or engagement for which unusual circumstances have been identified during acceptance and
continuance procedures, such as a disagreement with the previous auditor.
Page | 58
• Engagements involving reporting to be included in regulatory findings which may contain a high
degree of judgement, such as a listing prospectus.
• Audits and engagements for which the firm has no prior experience.
Exam focus
Candidates may be required to identify situations where an EQR should be performed either because it
is required by legal or professional requirements or because it is an appropriate response to a situation or
quality management risk arising in a scenario.
• The reviewer must be competent and capable of performing the role including understanding the
legal and professional framework, firm policies relevant to the engagement and have an appropriate
knowledge of the client industry. They should have an understanding and experience of similar
engagements and understand the responsibilities in performing and documenting an EQR.
• Reviewers must have appropriate authority within the firm to allow them to challenge the audit
engagement partner. The culture of the firm should be one where the views of the engagement
quality reviewer are treated with respect and not subject to influence or pressure from the audit
engagement partner.
• The reviewer must comply with relevant ethical requirements and the provisions of laws and
regulations relevant to the jurisdiction in which they are operating. In the same way that an audit
partner may be impacted by intimidation by a client, and reviewer may be impacted by intimidation,
for example if the audit partner for the client is aggressive or dominant individual or the reviewer has
a reporting line to the engagement partner.
• The reviewer may be a member of the audit firm or external to the firm.
Page | 59
Exam focus
Candidates may be required to demonstrate an understanding of why these criteria are in place either
through discussion, or through application to a scenario, for example, recognising and explaining where
an ineligible person has assigned the role of the reviewer or has been prevented from performing their
role effectively.
The reviewer is required to review and understand the significant judgements made by the engagement
team. They will assess whether the audit engagement documentation supports those judgements and
whether the conclusions reached are appropriate. In doing so, the review will specifically evaluate
whether the engagement team has exercised professional scepticism in reaching those conclusions.
ISQM 2 also includes a ‘stand back’ requirement for the reviewer to determine whether all the
requirements for the EQR have been met and whether the review is complete. An audit report cannot be
dated before the reviewer determines the process is complete.
Exam focus
Understanding the full responsibilities of the reviewer will enable candidates to evaluate a scenario
to determine whether an EQR has been performed as required and to identify where deficiencies in the
process have occurred.
Documentation
ISQM 2 specifically requires the reviewer to be responsible for the documentation of the EQR which must
be filed with the audit documentation. This must be sufficient to allow an experienced practitioner, having
no previous connection to the engagement to understand the nature, timing and extent of the EQR
procedures performed. Individual firms may have policies and procedures that go further than this as part
of the System of Quality Management (SoQM) of the firm.
Page | 60
Exam focus
Candidates may be required to evaluate whether sufficient appropriate documentation exists within a
scenario or recommend improvements to the firm’s SoQM to mitigate any weaknesses.
The audit engagement team is required to plan and perform the audit with professional scepticism, whilst
exercising professional judgment in order to ensure a quality audit is performed supporting the correct
audit opinion. An audit should be performed in such a way to mitigate where there may be problems
exercising appropriate professional scepticism – eg those arising through unconscious bias (for example,
assuming the client is correct) or resource constraints. The audit partner is ultimately responsible for the
quality of the specific audit which gives reasonable assurance that:
• the audit has been conducted in accordance with professional standards and applicable legal and
regulatory requirements, and
• the auditor’s report issued is appropriate in the circumstances.
Two key areas where ISA220 (Revised) provides specific guidance over and above that in ISQM 1 are those
relating to engagement resources and engagement performance. These topics are regularly examined in
the context of scenarios in a quality management question. Whilst the full standard is examinable,
candidates’ responses in these two specific areas are often poorly constructed or vague and hence a more
detailed understanding of the requirements in this area will be valuable.
Page | 61
Engagement resources
ISA220 (Revised) states that the audit engagement partner is responsible for ensuring sufficient and
appropriate resources are available to the engagement team in a timely manner and in line with the firms
policies and procedures. This includes changes to resources required as circumstances change during the
audit. The partner is also responsible for ensuring the engagement team and any external expert and
internal auditors providing direct assistance to the team have appropriate competence to perform their
assigned roles.
Exam focus
Candidates may be required to evaluate quality management issues in a scenario and, are expected to be
specific in their descriptions. See the example described below:
Consider a situation where the audit supervisor was off work for health reasons and the audit engagement
manager was too busy to help out the team performing the audit fieldwork. As a result, the audit juniors
have been left to perform all the audit procedures on their own including the impairment of properties
which were identified as high-risk during planning.
The first answer will be more likely to obtain professional skill marks for scepticism and judgement as they
have demonstrated challenged the ability of the junior to perform the task sufficiently to provide audit
evidence. Note that the first answer doesn’t just state that quality is poor, they explain why this is audit
area may not be performed with sufficient quality.
Page | 62
Engagement Performance
ISA220 (Revised) provides specific guidance on the performance of individual audits. The audit
engagement partner is responsible for the direction and supervision of the engagement team’s work and
the review of their work. In order to do this, the engagement partner must determine that the audit is
planned and performed in accordance with the firm’s policies and procedures, professional standards and
applicable legal and regulatory requirements, and also that changes can be made to the resources
available to the team where circumstances change.
The audit partner is expected to review the audit documentation relating to significant matters and
judgements, contentious issues and the conclusions reached. This is performed at appropriate stages
during the audit. For example, the audit partner would be expected to review the determination of
materiality for the audit which would likely be most appropriately reviewed at the planning stage of the
audit. If circumstances change and materiality is reassessed, then the audit partner may be expected to
review this during the audit itself. The audit partner must also ensure that sufficient appropriate evidence
has been obtained to support the opinion in the auditor’s report before the audit report is issued.
In addition to these responsibilities on each and every audit, it is also required the partner takes
responsibility for the audit team undertaking consultation on difficult and contentious matters. This
consultation may be within the audit team, where a more junior member may seek guidance from more
senior team members or it may be external to the team, either within the firm, for example with the firm’s
own experts and specialists or external to the firm.
The audit engagement partner is also required to ensure an engagement quality reviewer is appointed
where necessary and that the engagement team cooperate with the reviewer, including ensuring all
significant matters and judgements arising with respect to the audit are discussed with the reviewer. The
audit partner should not date the audit report until the EQR is complete and any differences of opinion
are resolved.
Exam focus
Candidates are often required to evaluate quality deficiencies in an audit, sometimes pre-issuance of the
audit report, sometimes post-issuance. The evaluation should refer to specific deficiencies and their
implications rather than make broad comments that the audit was not properly supervised or reviewed. It
would be expected that candidates identify the specific instance where review was omitted or when more
supervision should have occurred and how that would have altered the outcome of events.
Candidates should also note that without the analysis documented, it is not possible to credit
a reasoned conclusion so simply stating ‘a quality audit was not performed’.
Page | 63
Actions proposed by candidates in response to the quality management issues identified must be
appropriate for the stage in the audit. A review identifying a lack of evidence prior to the issuance of the
audit report can be mitigated by obtaining that evidence before signing the audit report, identifying a
material misstatement at this stage can lead to a qualification of the audit report.
However, where an audit report has already been issued, the option to qualify the audit report is not
available, and other actions are required.
Conclusion
The quality standards provide the fundamental framework for embedding quality into every audit and
reducing audit failures, helping to identify where professional standards may not have been followed or
an inappropriate audit report may have been issued. These standards firmly place the responsibility for
audit quality at the firm level rather than the level of an individual audit partner and have been designed
to be flexible and scalable whist permeating every part of every audit.
A focus on quality throughout the audit firm should lead to better audits and more accountability.
Candidates should expect quality management to permeate all areas of the exam and should familiarise
themselves with the standards.
When asked to evaluate quality management issues in the AAA exam, you will need to apply the content
covered in this chapter.
Page | 64
Obtaining and Accepting Professional Appointments
Advertising
Basic Guidelines
Advertising is allowed as long as the advertising does not go against any of the fundamental principles
contained in ACCA’s Code of Ethics and Conductor IFAC’s Code of Ethics for Professional Accountants.
1. Advertisements should be truthful and not make false claims. For example, it would be inappropriate
to claim that a firm could promise to offer a cheaper audit service than the competitor firm. Equally,
it would be inappropriate to make exaggerated claims regarding the experience or the qualifications
possessed by the firm’s partners and employees.
2. In addition, any advertisement should not make disparaging remarks about any other audit or
accountancy firm, for example, it would be inappropriate to state that a firm offered a higher quality
service than any other provider.
3. Any advertisements should also be in compliance with any local rules and regulations. For example,
in some jurisdictions it is prohibited for professionals such as auditors to advertise on television, and
most jurisdictions will have some kind of regulatory authority, such as the Advertising Standards
Authority in the UK, which imposes rules on advertising to ensure it is not misleading and is in good
taste.
Practice Descriptions
Members:
– can use ACCA or FCCA after their names
– not permitted to add Honours/ hons after ACCA or FCCA
Page | 65
Firm names should not
– Hamper the reputation/dignity of accountancy profession
– Bring discredit to other accountants
– Be the same as existing firm’s name
– Be misleading
Use of the ACCA logo: The ACCA logo, also known as the ACCA mark, can be used on the letterheads,
other professional stationery or on the website of a firm which has at least one partner or director who
is a member of the ACCA.
The logo should be exactly as recommended by the ACCA in respect to its colour, size and positioning. If
the firm has a logo of its own, it should be distinguishable from the ACCA logo
Tendering
Auditors are often approached by interested clients to submit quotations for fees to conduct particular
work. The process of calling for quotations and submitting quotes is known as tendering.
Tendering is a process through which an interested party (i.e. the client) tries to obtain quotations for
fees from the provider of services (i.e. the auditor) for a particular kind of work to be done. It is customary
to submit tenders in sealed envelopes. Such sealed offers, including firm / company information, a project
outline, and a price quote are known as tenders or bids. When an invitation to submit a proposal or fee
quote is received by the auditor, the auditor must decide whether it wants to undertake that work.
1. What is the business of the prospective client? Is it a new business or an existing one?
The bidder must have information about the client’s business, number of branches or subsidiaries,
processes and products and internal control systems. This will help the bidder to evaluate the work
involved and the expertise required. For example, if the client has undertaken an acquisition, expert
knowledge on the accounting of acquisitions would be helpful. Similarly, knowledge of a client’s
business can help the bidder to decide whether or not it wants to take up the engagement, as there
may be some issues which the bidder does not want to be involved with.
Page | 66
2. What exactly does the prospective client expect the auditor to do? (statutory audit, taxation work
etc)
The duties of the bidder must be clearly defined i.e. what the bidder is being hired for. Similarly, the
timeline that the auditor is required to follow must be communicated. This will help the bidder to plan
his work properly and also give an idea of the total time required to complete the assignment.
This will help the bidder to assess his own future prospects by working with the prospective client.
It can also help the bidder prepare for any future challenges that he might have to face while working
for the client.
4. Why does the prospective client intend to change the existing auditor?
If the client is seeking to change his existing auditor, the bidder may be interested to know the reason
for this change.
1. Brief outline of firm: This should include a short history of the firm, a description of its organisational
structure, the different services offered by the firm (such as audit, tax, corporate finance, etc), and
the locations in which the firm operates. The document should also state whether it is a member of
any international audit firm network.
2. Specialisms of the firm: Describe the areas in which the firm has particular experience of relevance
to the prospective client.
3. Identification of the needs of the prospective client: The tender document should outline the
requirements of the client, for example that each subsidiary is required to have an individual audit on
its financial statements, and that the consolidated financial statements also need to be audited.
4. Outline of the proposed approach: This is likely to be the most detailed part of the tender document.
For example, in case of a tender for an audit, typically contained in this section would be a description
of the audit methodology used by the firm, and an outline of the audit cycle including the key
deliverables at each phase of work. For example:
– How the firm would intend to gain business understanding at group and subsidiary level.
– Methods used to assess risk and to plan the audits.
– Procedures used to assess the control environment and accounting systems.
Page | 67
5. Quality control: The firm should emphasize the importance of quality control and therefore should
explain the procedures that are used within the firm to monitor the quality of the services provided.
This should include a description of firm-wide quality control policies, and the procedures applied to
individual assignments. The firm may wish to clarify its adherence to International Standards on
Quality Control.
6. Communication with management: The firm should outline the various reports and other
communication that will be made to management.
9. Fees: The proposed fee for the audit of the group should be stated, and the calculation of the fee
should be explained.
Accepting Engagements
A firm must consider and document various factors in relation to accepting or continuing an engagement.
These inclide the integrity of the client, whether the firm is competent to do the work and whether the
firm meets the ethical requirements in relation to the work.
Page | 68
Does the firm have sufficient personnel with the necessary capabilities and
competence?
Are individuals meeting the criteria and eligibility requirements to perform the
engagement quality control review available where applicable?
Is the firm able to complete the engagement within the reporting deadline
Page | 69
(iii) To provide the auditor with:
a. Access to all information of which management is aware that is relevant to the
preparation of the financial statements such as records, documentation and other
matters;
b. Additional information that the auditor may request from management for the purpose
of the audit***; and
c. Unrestricted access to persons within the entity from whom the auditor determines it
necessary to obtain audit evidence
***Additional information: Additional information that the auditor may request from management for
the purpose of the audit may include when applicable, matters related to other information in accordance
with ISA 720 (Revised). When the auditor expects to obtain other information after the date of the
auditor’s report, the terms of the audit engagement may also acknowledge the auditor’s responsibilities
relating to such other information including, if applicable, the actions that may be appropriate or
necessary if the auditor concludes that a material misstatement of the other information exists in other
information obtained after the date of the auditor’s report
Page | 70
Agreeing the Terms of the Engagement
Once the accountant agrees to work for a client, he must decide the terms of engagement in writing with
the client. Such written communication is known as an ‘engagement letter’. ISA 210 Agreeing the Terms
of Audit Engagements provides guidance on agreeing terms with a client and changes in the engagement
terms. It assists the accountants in preparing audit engagement letters for accepting audit assignments,
tax, accounting, or management advisory services.
2. Scope of the audit: Elaboration of the scope of the audit, including reference to applicable legislation,
regulations, ISAs, and ethical and other pronouncements of professional bodies to which the auditor
adheres.
5. The requirement for the auditor to communicate key audit matters in the auditor’s report in
accordance with ISA 701
6. Deliverables: The form of any other communication of results of the audit engagement.e.g. letters,
certificates or audit report.
8. The basis on which fees are computed and any billing arrangements.
9. Permission to communicate with the previous accountant (by sending the etiquette letter)
10. Access to all the records, documentation and other information requested in connection with the
audit, e.g. customs documents to verify whether the goods are being held by customs
11. Management’s responsibility for establishing and maintaining effective internal controls, e.g.
maintenance of proper accounting records
12. The fact that because of the inherent limitations of an audit, together with the inherent limitations of
internal control, there is an unavoidable risk that some material misstatements may not be detected,
even though the audit is properly planned and performed in accordance with ISAs.
Page | 71
13. Arrangements regarding the planning and performance of the audit, including the composition of the
engagement team.
14. The expectation that management will provide access to all information of which management is
aware that is relevant to the preparation of the financial statements, including an expectation that
management will provide access to information relevant to disclosures.
15. The agreement of management to make available to the auditor draft financial statements including
all information relevant to their preparation, whether obtained from within or outside of the general
and subsidiary ledgers (including all information relevant to the preparation of disclosures), and the
other information,3 if any, in time to allow the auditor to complete the audit in accordance with the
proposed timetable.
16. The agreement of management to inform the auditor of facts that may affect the financial statements,
of which management may become aware during the period from the date of the auditor’s report to
the date the financial statements are issued.
17. A request for management to acknowledge receipt of the audit engagement letter and to agree to
the terms of the engagement outlined therein.
Where the auditor is replacing an existing auditor while accepting a new client, he should contact the
existing auditor and communicate his intentions for taking up the work of that client.
This must be done after taking prior permission from the client. Such communication usually takes place
in the form of an etiquette letter or professional enquiry letter. If the client does not give permission to
approach the outgoing auditor, the auditor should refuse the engagement.
An etiquette letter / professional enquiry letter enables the new auditor to communicate with the existing
auditor and know if there are any areas of concern which he must consider before accepting the new
engagement.
Many times, the apparent reason for a change of auditors may not fully reflect the facts and may indicate
disagreements with the existing accountant that may influence the decision to accept the appointment.
Audit of the components in a group: If the client entity comprises various subsidiaries, divisions, units or
branches, the auditor should consider sending separate engagement letters to each such subsidiary,
division, unit or branch, if he is appointed as the auditor for the entire group. This is because the terms of
the audit’s legal requirements for appointment of auditors of different business units (i.e. subsidiaries,
divisions etc.) may be different and may not apply to the group as a whole.
It also depends upon factors such as the extent of independence of the components in a group and the
degree of ownership by the parent company.
Page | 72
Recurring audits: In recurring audits, the auditor should consider whether circumstances require the
terms of the engagement to be revised and whether there is a need to remind the client of the existing
terms of the engagement.
2. Resources (need to link to the scenario. Each is a separate mark when linked!)
✓ Staff
✓ Time
✓ Competence of the firm including knowledge and experience of relevant industry, regulatory and
reporting requirements
3. Scale of engagement: if global: travel cost, language, time. (need to link to the scenario)
4. Client/ management integrity (try and link to the scenario)- affect’s firm’s reputation too (separate
mark for this)
5. Commercial considerations: level of fee, profitability of the engagement etc. (if too high, sel-interest
or if too low, quality of work might be affected)
8. Professional liability implication (e.g. audit required by lender)-liable to a 3rd party in case of
negligence?
9. Professional etiquette letter (clearance from outgoing auditor)- ‘any professional or ethical issues?’
Page | 73
The Planning Stage of Audit
Obtaining an Understanding of the Client and Its Environment, the Applicable Financial Reporting
Framework and the Client’s System of Internal Control
The auditor has to perform risk assessment procedures to obtain an understanding of the following areas.
It is important to remember that this is an on-going process of gathering, updating and analyzing
information and so it continues throughout the audit. Therefore, the auditor’s expectations may change
as new information is obtained.
This understanding may also assist the auditor in developing initial expectations about the classes of
transactions, account balances and disclosures that may be significant classes of transactions, account
balances and disclosures.
- The client’s organizational structure, ownership and governance, and its business model, including
the extent to which the business model integrates the use of IT;
- Industry, regulatory and other external factors
- The measures used, internally and externally, to assess the client’s financial performance
- The applicable financial reporting framework, and the client’s accounting policies and the reasons for
any changes thereto
- Client’s system of internal control
Why an Understanding of the Client and Its Environment, and the Applicable Financial Reporting
Framework Is Required
The auditor can understand factors which can affect risk and the degree to which they do so.
This then assists the auditor in planning the audit and exercising professional judgment and professional
skepticism throughout the audit, for example, when:
- Identifying and assessing risks related to fraud
- identifying or assessing risks related to accounting estimates
- Performing procedures to help identify instances of non-compliance with laws and regulations that
may have a material effect on the F/S
Page | 74
- Determining materiality or performance materiality in accordance
- Considering the appropriateness of the selection and application of accounting policies, and the
adequacy of financial statement disclosures.
The Client’s An understanding of the client’s organizational structure and ownership may
Organizational enable the auditor to understand such matters as:
Structure, Ownership
- The complexity of the client’s structure (individual, group, multiple
locations etc). The ownership, and relationships between owners and
other people or entities, including related parties. This understanding may
assist in determining whether related party transactions have been
appropriately identified, accounted for, and adequately disclosed in the
financial statements.
- The distinction between the owners, those charged with governance and
management (the distinction is clearer in listed companies as opposed to
owner managed companies)
The client’s Understanding the client’s governance may assist the auditor with
governance understanding the client’s ability to provide appropriate oversight of its
system of internal control.
Page | 75
Client’s business Examples of matters that the auditor may consider when obtaining an
model understanding of the client’s business model, objectives, strategies and
related business risks that may result in a risk of material misstatement of the
financial statements include:
- Industry developments, such as the lack of personnel or expertise to deal
with the changes in the industry;
- Expansion of the client’s business, and demand has not been accurately
estimated;
- New accounting requirements where there has been incomplete or
improper implementation;
- Regulatory requirements resulting in increased legal exposure;
- Current and prospective financing requirements, such as loss of financing
due to the client’s inability to meet requirements;
- Use of IT, such as the implementation of a new IT system that will affect
both operations and financial reporting; or
- The effects of implementing a strategy, particularly any effects that will
lead to new accounting requirements.
Understanding the client’s objectives, strategy and business model helps the
auditor to understand the client at a strategic level, and to understand the
business risks the client takes and faces. An understanding of the business risks
that have an effect on the financial statements assists the auditor in identifying
risks of material misstatement, since most business risks will eventually have
financial consequences and, therefore, an effect on the financial statements.
Industry, Regulatory Relevant industry factors include industry conditions such as the competitive
and Other External environment, supplier and customer relationships, and technological
Factors developments. Matters the auditor may consider include:
- The market and competition, including demand, capacity, and price
competition.
- Cyclical or seasonal activity.
- Product technology relating to the client’s products.
The industry in which the client operates may give rise to specific risks of
material misstatement arising from the nature of the business or the degree
of regulation.
Example:
In the construction industry, long-term contracts may involve significant
estimates of revenues and expenses that give rise to risks of material
misstatement. In such cases, it is important that the engagement team include
members with sufficient relevant knowledge and experience.
Page | 76
Regulatory factors
Measures Used by An understanding of the client’s measures assists the auditor in considering
Management to whether such measures create pressures on the client to achieve performance
Assess the Client’s targets. These pressures may motivate management to take actions that
Financial Performance increase the susceptibility to misstatement due to management bias or fraud
(e.g., to improve the business performance or to intentionally misstate the
financial statements)
Page | 77
Understanding the The client’s financial reporting practices in terms of the applicable financial
Applicable Financial reporting framework, such as:
Reporting Framework - Accounting principles and industry-specific practices, including for
and the Client’s industry-specific significant classes of transactions, account balances and
Accounting Policies related disclosures in the financial statements (for example, loans and
investments for banks, or research and development for
pharmaceuticals).
- Revenue recognition.
- Accounting for financial instruments, including related credit losses.
- Foreign currency assets, liabilities and transactions.
- Accounting for unusual or complex transactions including those in
controversial or emerging areas (for example, accounting for
cryptocurrency).
- Financial reporting standards and laws and regulations that are new to the
client and when and how the client will adopt, or comply with, such
requirements.
Risk assessment process provides the basis for the identification and assessment of the risks of material
misstatement, and the design of further audit procedures.
As a part of risk assessment procedures, auditors are expected to gather information from the
following sources
- Information from client acceptance and continuance and other engagements for the client
- Information from auditor’s previous experience and previous audits
- Obtaining an Understanding of the Client and Its Environment, the Applicable Financial Reporting
Framework and the Client’s System of Internal Control
- Risks arising from the use of IT – Susceptibility of information processing controls to ineffective design
or operation, or risks to the integrity of information (i.e., the completeness, accuracy and validity of
transactions and other information) in the client’s information system, due to ineffective design or
operation of controls in the client’s IT processes
- Inquiries of management and of other appropriate individuals within the client, including individuals
within the internal audit function
- Analytical procedures.
- Observation and inspection
Page | 78
- Information from Other Sources like the auditor’s procedures regarding acceptance or continuance
of the client relationship or the audit engagement; and when applicable, other engagements
performed by the engagement partner for the client.
- Engagement Team Discussion: The engagement partner and other key engagement team members
should discuss the application of the applicable financial reporting framework and the susceptibility
of the client’s financial statements to material misstatement.
ISA 200 requires the auditor to plan and perform an audit with professional skepticism recognizing that
circumstances may exist that cause the financial statements to be materially misstated.
Professional skepticism is necessary for the critical assessment of evidence gathered when performing
risk assessment procedures.
It is an attitude that is applied by the auditor when making professional judgments that then provides the
basis for the auditor’s actions.
Analytical procedures help identify inconsistencies, unusual transactions or events, and amounts, ratios,
and trends that indicate matters that may have audit implications. Unusual or unexpected relationships
that are identified may assist the auditor in identifying risks of material misstatement especially due to
fraud.
Example:
In the audit of many entities, including those with less complex business models and processes, and a less
complex information system, the auditor may perform a simple comparison of information, such as the
change in interim or monthly account balances from balances in prior periods, to obtain an indication of
potentially higher risk areas
Page | 79
Automated tools and techniques
Analytical procedures can be performed using a number of tools or techniques, which may be automated.
Applying automated analytical procedures to the data may be referred to as data analytics.
Example:
The auditor may use a spreadsheet to perform a comparison of actual recorded amounts to budgeted
amounts, or may perform a more advanced procedure by extracting data from the client’s information
system, and further analyzing this data using visualization techniques to identify classes of transactions,
account balances or disclosures for which further specific risk assessment procedures may be warranted.
Page | 80
Important- Technical Article summary
ISA 315 (Revised 2019), Identifying and Assessing the Risks of Material Misstatement
ISA 315 (Revised 2019) has been structured in such a way that the revised requirements address ‘what’
the auditor needs to do, and the application material addresses the questions around ‘why’ and ‘how’.
The starting point for the auditor is to obtain an understanding of the client’s business, specifically in
relation to:
• The entity and its environment, and
• The application of the financial reporting framework
• The entity’s system of internal control
Overall, the requirements in relation to obtaining an understanding have been enhanced and clarified to
ensure that a well-informed risk assessment is performed.
Based on the auditor’s understanding of the client’s business, the auditor must then identify and assess
the RoMM at both financial statement and assertion level.
This process is best explained through the use of an example: Based on the auditor’s understanding of the
business, completeness of inventory has an identified RoMM. The relevant assertion would therefore be
completeness and the significant account balance would be inventory. Another important point to note
is that the determination of a relevant assertion is made before considering any controls that the client
may have implemented to mitigate the risk.
Once the RoMM has been identified by the auditor, this need to be assessed. In doing so, the auditor must
not forget the requirement to assess inherent and control risk separately
Remember:
Audit Risk = Inherent Risk (IR) x Control Risk (CR) x Detection Risk (DR)
Page | 81
A Inherent Risk Control Risk Detectio
R Assess separately from CR Assess separately from IR n Risk
Understanding the Understand the CR is the risk that weak or absent risk that
entity financial reporting controls so misstatements in f/s the
framework won’t be prevented or detected on a procedur
timely basis. es
performe
d by the
auditor
to reduce
audit risk
to an
acceptab
ly low
level will
fail to
detect a
misstate
ment
which
exists
that
could be
material.
We
should
keep in
mind
that
detection
risk is the
only risk
under
the
control
of the
auditor.
FIVE new inherent Must consider impact Components of system of internal
risk factors have been of the following control
introduced to help in
risk assessment. -accounting policies
Page | 82
-financial reporting Indirect controls (imp. For auditor to
-Can be qualitative or framework understand as affect risk of material
quantitative -industry specific misstatement at f/s level)
regulations - Control environment
-Need to consider: - Risk assessment (how risks are
Consider IFRS/IAS identified and analyzed by the
1. complexity that are easier to mngt. Including IT risks)
2. subjectivity manipulate ( for - Monitoring of internal
3. change example IFRS 15, IAS control(how is effectiveness of
4. uncertainty 37, IFRS 9 etc.) internal control evaluated, are
5. risk of mng remedial actions taken, is there
bias/fraud Also consider new an internal audit department?)
requirements/emerg
ing issues like cyrpto
Examples: currencies, Direct controls (imp. For auditor to
environmental understand as affect risk of material
Complexity(Arises reporting and other misstatement at assertion level)
because of the nature technological
of the information or changes as these are - Information system and
the way that it is affected by mngt’s communication (activities,
prepared) judgment and there policies, accounting records etc
won’t be standards used to initiate, record and
-Operations that are related to these process transactions..)
subject to a high leading to - Control activities( authorization
degree of complex inconsistent and approval, reconciliations,
regulation. valuation and verification, physical or logical
disclosure. controls, segregation of duties)
-The existence of
complex alliances and (continued on the next page)
joint ventures.
-Accounting
measurements that
involve complex
processes.
Subjectivity(Results
from inherent
limitations in the
ability to prepare the
Page | 83
information The standard recognizes that
objectively) there could be risks of material
misstatement from the entity’s
-management’s use of IT such as, risks to the
recognition of integrity of information in the
depreciation entity’s information system due
-Management’s to ineffective design or
selection of a operation of controls in the
valuation technique entity’s IT processes.
or model for a non- Therefore, there is a need for more
current asset, such as robust understanding of the
investment entity’s control environment
properties. including its IT controls.
Accordingly, the standard
Change(Events or introduces new definition of
conditions which ‘general IT controls’ and
affect the entity’s ‘information processing controls’
business, industry, which are explained in the figure
regulatory or below:
economic
environment)
-Operations in
regions that are
economically
unstable, for
example, countries
with significant
currency devaluation At the planning stage, auditor has to
or highly inflationary decide if audit procedures will be
economies. conducted to test effectiveness of
internal control.
-Going concern and
liquidity issues Auditor has to understand each
including loss of component of internal control to
significant customers. evaluate control risk.
Page | 84
or moving into new the operating effectiveness of
lines of business. controls.
Page | 85
guarantees and
environmental
remediation.
-Susceptibility to
misstatement due to
management bias or
other fraud risk
factors insofar as they
affect inherent risk
Susceptibility to
misstatement due to
management bias or
other fraud risk
factors insofar as they
affect inherent risk
(Conditions which
create susceptibility
for intentional or
unintentional failure
by management to
maintain neutrality)
-Opportunities for
management and
employees to engage
in fraudulent financial
reporting, including
omission, or
obscuring, of
significant
information in
disclosures.
-Significant
transactions with
related parties.
Page | 86
-Significant amount
of non-routine or
non-systematic
transactions
including
intercompany
transactions and
large revenue
transactions at period
end.
Spectrum of IR ( to
see if the risks are
significant)
Some account
balances/classes of
transactions/disclosu
res are more risky
that others. The
degree to which they
vary is called
spectrum of risk.
Risks are the
upper/higher end are
significant risks.
Consider the
likelihood of
misstatement and
magnitude of
misstatement.
Likelihood:
probability that a
misstatement would
occur
Page | 87
Magnitude: can be
material due to size,
nature or
circumstances
Examples
Cash at supermarket:
high likelihood of
fraud but magnitude
depends on whether
a lot of people pay in
cash in that area. If
not, this won’t be a
significant risk.
Page | 88
The auditor would
then prioritize risks
and decide next
steps. For significant
risks, auditor would
need:
-more evidence
-more persuasive
evidence
-to check if controls
over these risks are
designed and
implemented
effectively
-tell TCWG about
them
- include in KAM
-to ensure detailed
review of these areas
by Engagement
Partner
To understand where risks arise at the financial statement level, the auditor must identify significant
classes of transactions and balances in which material misstatements may arise.
Where RoMM exist at the assertion level, this will arise through a combination of inherent
risk and control risks. Both must be assessed if controls are expected to be relied on as part of the overall
assessment of the RoMM.
Page | 89
Inherent risks
ISA 315 (Revised 2019), Identifying and Assessing the Risks of Material Misstatement identifies five types
of inherent risk factors:
• complexity
• subjectivity
• change
• uncertainty
• susceptibility to management bias or other fraud risk factors
Candidates should consider whether these factors are present in the scenario provided to assist in
identifying RoMM.
Spectrum of risk
The auditor will then assess where on the spectrum of inherent risk these risks sit. This requires an
assessment of likelihood and magnitude of the potential misstatement. Significant audit risks are those
at the upper end of the spectrum of inherent risk. This will determine what is a significant RoMM.
Judging what is, or is not, a significant risk is a crucial skill for auditors and in the exam, the ability to make
this judgement relevant to a specific scenario is critical to obtaining the credit required to pass.
Worked example
Example
A company has a newly purchased and highly material intangible asset, such as a brand name. The
scenario the issue is compounded by management who are under pressure to achieve a certain
interest cover ratio or earnings per share. The company has also purchased a plot of land for $3million.
Management will use their judgement to decide the useful life of the intangible asset.
The purchase of land is factual, and unless there is evidence to the contrary, this will be stated at cost
in the financial statements.
However, we have both judgement and management bias as inherent risk indicators in respect of the
brand name. This is more likely to be a significant risk than the land purchase.
The assessment of inherent risk is the first stage of identifying and evaluating a significant RoMM.
Page | 90
Control risk
An assessment of control risk is also required in assessing whether this RoMM is likely to occur in the
financial statements. If there is information provided about controls in the scenario, this should form part
of candidates’ judgement in determining whether a risk is significant or not.
Sometimes this will be at the assertion level, for example, in the example of Winberry (September 2022),
information was given in the scenario regarding the valuation of inventory:
Although these perishable items were ‘a significant proportion’, the scenario stated that the items are
monitored by ‘experienced food and product technology professionals. Many candidates discussed that
this would be a valuation risk as inventory may be obsolete however, the scenario provides mitigation
against these risks of valuation.
The statement that ‘the company complies with all food safety legislation’ also mitigated the risk that the
groceries may breach health and safety legislation.
Note: Candidates should note that this definition of ‘significant’ is a specific audit concept and should
not be switched for other words with a similar meaning. Similarly, the word ‘material’ has a specific
definition in audit and should not be replaced by similar words, such as ‘significant’.
Significant risk – an identified and assessed risk of material misstatement that, in the auditor’s judgement,
requires special audit consideration.
Candidates will be required to identify and assess those significant RoMMs in the context of the specific
scenario. Candidates may be asked to evaluate and prioritise significant RoMM arising in a scenario, or
to explain why a significant RoMM has been identified (see the separate article on ‘Answering Section A
questions in the AAA exam’ – access via the 'Related links' box).
Candidates can use the potential materiality of a misstatement alongside the inherent risk factors to help
them assess which issues give rise to significant RoMM.
Page | 91
Materiality
For guidance on how materiality is examined, see the specimen exam and the associated Read the Mind
of the Marker (Q1) material on the ACCA website. The Examiners Report for the September 2022
examination will also provide additional guidance.
In Winberry (Sept 2022), the scenario stated that the data breaches might give rises to fines from
regulators. Management had not self-reported the breach in an attempt to avoid a fine. Although, most
candidates identified there was a RoMM associated with the recording and disclosure of the potential
fine, few evaluated how significant an issue this may be.
One way to evaluate this would be to use the recognition criteria for a provision.
Application of judgement:
These are demonstrations of a candidate's judgement as they are assessing the information in the scenario
to draw conclusions and to evaluate the extent of the risk.
‘Given that the company do not wish to disclose the breach to the regulator, it is likely that a fine would be
probable should the regulator be made aware of the breach’
Page | 92
‘If the breach is not reported to the regulator and is not disclosed by any other party, then the fine is not
probable’
‘However, if it is possible the regulator would be made aware then there would be a contingent liability
which would require disclosure in the financial statements’
Demonstration of the wider commercial aspects of the lack of disclosure (credit for commercial
acumen):
‘The disclosure of the contingent liability would effectively notify the regulator of the breach, making the
likelihood of a fine more probable ‘
‘As a result, a provision might be omitted from the company liabilities and profits may be overstated’
‘The amounts payable might be higher as a result of failure to self-report which increases the impact of the
misstatement’
‘The potential impact of the understated expenses on the interest cover covenant may make this material
by nature if it would result in a breach of covenants’
This demonstrates that the candidate has assessed the materiality of the breach, and even without a
specific figure being stated, management’s attitude and the risk of breaching the bank covenants, are likely
to make this risk material to the audit.
Page | 93
Where more complex financial reporting is examined, such as those topics examined only at Strategic
Business Reporting (SBR) level, additional credit will be available for the relevant underlying financial
reporting knowledge, or where the candidate provides additional guidance on the relevant area of
financial reporting raised in the scenario.
Audit risk
Audit risk is the combination of RoMM and detection risk. Detection risks arise where there is a risk that
a material misstatement may not be detected. Where a question requires audit risks, both detection risks
and RoMM should be considered.
Professional marks awarded in audit risk and RoMM questions typically fall into the following broad
categories.
A second professional skill mark is available for saying why that risk was selected. This may be justified
based on the likelihood or potential magnitude of the material misstatement. The mark here is for the
demonstration of that evaluation to determine why something is important. There is no specific correct
answer that the examining team are looking for, but rather a demonstration of the thought process behind
the judgement.
This can be demonstrated in a conclusion at the end of the relevant requirement or through specific
numbering and ordering of paragraphs. The former approach is likely to be easier for candidates in exam
conditions.
Page | 94
Professional scepticism and judgement
These skills will test the ability of the candidate to challenge management’s accounting decisions and
treatments, or to draw conclusions on why risks are significant in the specific scenario as well as the
identification of areas of risk and bias. Often the examining team will allow credit for identifying
a specific risk of bias from the scenario and additional marks for drawing conclusions on the accounting
treatments used by management. Scepticism is required to link risks and issues to management motives
and consider the wider implications of the issue.
Commercial acumen
This skill can also be demonstrated through the evaluation of risks. Commercial acumen can sometimes
be thought of as ‘how the world works as opposed to how the auditor thinks. For example, in a scenario
assessing the risks arising in a group where a subsidiary has a year-end date a month earlier than the
parent company, there are several risks arising from the group accounting implications of this situation.
There are, however, further risks arising because the additional month of management accounts will make
up the difference. Knowing that this extra month will not have been subject to audit, as well as that the
company month end procedures are often less comprehensive than their year-end procedures,
demonstrates a knowledge of commercial reality and this would form part of the assessment of
commercial acumen.
Summary
Candidates will be required to evaluate risks in the context of specific information provided in a scenario
in the exam. The examining team are looking for depth of evaluation of significant risks, rather than brief
and untailored answers covering large numbers of risks. Candidates are recommended to use past
published questions to practice evaluating risks in scenarios and remember to tailor their answer to the
specific information in their current exam scenario, little credit will be awarded.
Candidates who follow the rules of WHAT/WHY/IMPLICATION are likely to maximise their technical marks
as well as demonstrating good professional skills (and therefore professional skill marks).
Written by a member of the AAA examining team
Relationship between business risk and risk of material misstatement in the financial statements
The business risk approach places the auditor ‘in the shoes’ of management, and therefore provides
deeper insight into the operations of the business and generates extensive business understanding
The business risk model is not a replacement for the traditional audit risk model but rather a vehicle, or
mechanism, for the identification of audit risk, recognising that most business risks will eventually have
financial consequences and, therefore, an effect on the financial statements.
Business risk is defined in ISA 315 Identifying and Assessing the Risks of Material Misstatement Through
Understanding the Entity and its Environment. The definition states that business risk is a risk resulting
from significant conditions, events, circumstances, actions or inactions which could adversely affect an
Page | 95
entity’s ability to achieve its objectives and execute its strategies, or from the setting of inappropriate
objectives and strategies.
Risk of material misstatement is defined in ISA 200 Overall Objectives of the Independent Auditor and the
Conduct of an Audit in Accordance with ISAs as the risk that the financial statements are materially
misstated prior to audit.
ISA 315 states that the auditor shall perform risk assessment procedures to provide a basis for the
identification and assessment of risks of material misstatement at the financial statement and assertion
levels.
Business risks can be broken down into operational risk, financial risk and compliance risk.
1. Financial risk: risk arising from the financial activities or financial consequences of an operation
2. Compliance risk: risk that arises from non-compliance with laws and regulations
3. Operational risk: risk arising with regard to operations
Each of these components can have a direct impact on the financial statements, and therefore
understanding the components of business risk can help the auditor to identify risks of misstatement, and
to design a response to that risk.
Some business risks impact the inherent risk component of risk of material misstatement. For example,
the auditor may have identified that an audited entity has significant levels of debt with covenants
attached. The business risk is that the covenants are breached and the debt recalled. An associated
inherent risk at the financial statement level is that the financial statements could be manipulated to avoid
breaching the debt covenant.
Other business risks impact on the control risk component of risk of material misstatement. For example,
the auditor may have identified that an audited entity has a business risk due to having lost key members
of personnel in the accounting department. This has a clear impact on control risk, as it means the
accounting department is short of competent staff and errors are likely to go undetected and uncorrected.
Therefore the ISAs’ approach to planning an audit is underpinned by the concept that it is essential for an
auditor to understand the business risks of an audited entity in order to effectively identify and respond
to risks of material misstatement.
Page | 96
Materiality
The concept of materiality is applied by the auditor both in planning and performing the audit, and in
evaluating the effect of identified misstatements on the audit and of uncorrected misstatements, if any,
on the financial statements and in forming the opinion in the auditor’s report.
Determining materiality involves the exercise of professional judgment. A percentage is often applied to
a chosen benchmark as a starting point in determining materiality for the financial statements as a whole.
Performance materiality means:
– The amounts set by the auditor at less than materiality for the financial statements as a whole
– To reduce the probability that the aggregate of uncorrected/undetected misstatements exceeds
materiality for the financial statements as a whole
Performance materiality also refers to the amount or amounts set by the auditor at less than the
materiality level or levels for particular classes of transactions, account balances or disclosures.
In order to calculate a level of planning materiality, auditors will often take a range of values and use an
average/weighted average.
• Profit before tax: 5- 10%
• Revenue: 0.5- 1%
• Total assets: 1-2%
When assessing materiality in exam questions calculate the relevant matter as a percentage of the
relevant indicator and assess whether it falls within these ranges.
According to ISA 520 Analytical Procedures, analytical procedures are the evaluation of financial
information through analysis of plausible relationships between both financial and non-financial data.
Analytical procedures can involve comparisons of financial data including trend analysis and the
calculation and comparison of ratios. Analytical procedures include comparisons of the Group’s financial
information with, for example:
• Comparable information for prior periods;
• Anticipated results of the Group, such as budgets or forecasts;
• Expectations of the auditor; or
• Comparable information from competitors.
Page | 97
Analytical procedures performed at the planning stage help the auditor to identify and respond
appropriately to risk, and to assist the auditor in obtaining an understanding of the client.
ISA 315 Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity
and its Environment requires the auditor to perform analytical procedures as part of risk assessment
procedures at the planning stage of the audit to provide a basis for the identification and assessment of
risks of material misstatement at the financial statement and assertion levels.
An example of how analytical procedures assist the auditor is that performing analytical procedures may
alert the auditor to a transaction or event of which they were previously unaware, therefore prompting
the auditor to investigate the matter, obtain understanding of the matter and plan appropriate audit
procedures to obtain sufficient appropriate audit evidence. Therefore analytical procedures are an
essential part of developing the audit strategy and audit plan.
Analytical procedures may also help the auditor to identify the existence of unusual transactions or
events, such as significant one-off events. Unusual amounts, ratios, and trends might also indicate matters
which indicate risk. Unusual or unexpected relationships which are identified by these procedures may
assist the auditor in identifying risks of material misstatement, especially risks of material misstatement
due to fraud.
Without performing analytical procedures, the auditor would be unable to identify risks of material
misstatement and respond accordingly. This would increase detection risk, making it more likely that an
inappropriate audit opinion could be issued.
Preliminary analytical review- Ratios normally used by the THE ADVANCED AUDIT & ASSURANCE
EXAM examiner
Profitability
1. GP Margin = Gross profit/revenue x 100
2. Operating profit margin= operating profit/revenue x 100
3. Return on capital employed = Operating profit/capital employed x100
Liquidity
1. Current ratio = Current assets/current liabilities
2. Quick ratio = Current assets – inventory/current liabilities
3. Inventory holding period= Inventory/cost of sales x 365
4. Receivables collection period = Receivables/revenue x 365
5. Trade payables payment period = Trade payables/cost of sales x 365
Page | 98
Gearing
1. Gearing ratio =Long-term liabilities/equity
2. Interest cover = Operating profit/finance costs
Important
Analytical procedures help identify inconsistencies, unusual transactions or events, and amounts,
ratios, and trends that indicate matters that may have audit implications. Unusual or unexpected
relationships that are identified may assist the auditor in identifying risks of material misstatement
especially due to fraud.
Example:
In the audit of many entities, including those with less complex business models and processes, and a
less complex information system, the auditor may perform a simple comparison of information, such
as the change in interim or monthly account balances from balances in prior periods, to obtain an
indication of potentially higher risk areas
Example:
The auditor may use a spreadsheet to perform a comparison of actual recorded amounts to budgeted
amounts, or may perform a more advanced procedure by extracting data from the client’s information
system, and further analyzing this data using visualization techniques to identify classes of transactions,
account balances or disclosures for which further specific risk assessment procedures may be warranted.
Page | 99
Additional Considerations in Initial Audit Engagements
First audit? (New client with previous audit by another firm OR New client no audit before)
In an initial audit engagement there are several factors which should be considered in addition to the
planning procedures which are carried out for every audit
1. Performing procedures regarding the acceptance of the client relationship and the specific audit
engagement;
2. Communicating with the predecessor(outgoing) auditor (with client’s permission)- ask for
information and working papers from previous audit ( accounting policies, risks assessed and how
they were dealt with)
3. Review opening balances (Working papers from previous audit will help)-if no previous audit, more
detailed testing will be needed. Particular care should be taken in planning the audit procedures
necessary to obtain sufficient appropriate audit evidence regarding opening balances, and procedures
should be planned in accordance with ISA 510 Initial Audit Engagements –Opening Balances. For
example, procedures should be performed to determine whether the opening balances reflect the
application of appropriate accounting policies and determining whether the prior period’s closing
balances have been correctly brought forward into the current period.
4. Consider if previous audit report was modified- affecting this year? Risks identified change? Previous
modifications of the opinion could be indicative of lack of trust in management
6. Consider matters discussed with the management at the time of appointment. For example, there
may have been discussion of significant accounting policies which may impact on the planned audit
strategy.
7. Need to develop thorough business understanding. With an initial audit engagement it is particularly
important to develop an understanding of the business, including the legal and regulatory framework
applicable to the company. This understanding must be fully documented and will help the audit team
to perform effective analytical review procedures and to develop an appropriate audit strategy.
Obtaining knowledge of the business will also help to identify whether it will be necessary to plan for
the use of auditors’ experts.
10. The firm may have quality control procedures in place for use in the case of initial engagements, for
example, the involvement of another partner or senior individual to review the overall audit strategy
Page | 100
prior to commencing significant audit procedures. Compliance with any such procedures should be
fully documented.
Business Risk
- 2 marks per well explained risk
- 1 mark for identification and implication on the business
- 1 mark for evaluating how and why it is significant for the business. For example, could INCREASE
liquidity problem, if stakeholders like customers and regulators find out about the breach, would
tarnish the image, a new product could fail if customer preferences aren’t evaluated, management
might be distracted due to the new expansion etc.) You basically need to consider the wider impact
on the business for the 2nd mark!
ROMM
- up to 3-4 marks for EACH risk IF answering technique followed
1. Mention whether it is material or not (for risks where amounts are given)- NO calculation! Just a
simple English line to say it’s material based on our base decided.
2. Relevant accounting treatment
3. Risks- can be more than one. Use the scenario as much as possible!
4. F/S impact- complete the double entry
Example
Materiality: The carrying amount of the impaired factory is material.
Relevant accounting treatment: The damage to the factory has triggered an impairment review but a
review of the calculation provided indicates that the determination of value in use is not correct.
The cash flow projections which are used to determine the value in use of the impaired asset should
relate to the asset in its current condition – expenditures to improve or enhance the asset’s
performance should not be anticipated.
Risks/Scenario specific issues: The FD’s estimate of value in use is based on the assumption that the
building is repaired and new machinery purchased – neither of these assumptions should be included in
the determination of value in use. It is likely that the value in use is much lower than the FD’s estimate,
so the impairment loss to be recognised is greater than the $210,250.
Page | 101
Audit Evidence and Audit Procedures
This is a very important part of the syllabus. Procedures are tested in Section A and evidence is often a
part of Section B questions.
You are not expected to learn the procedures. Read through this section carefully to understand how
audit procedures can be used to gather evidence regarding the accounting treatment that has been
used in the financial statements.
In the AAA exam, the examiner will often ask for ‘matters to consider’ for a certain scenario. This
requirement is then combined with either audit evidence or audit procedures.
Step 1: Comment on materiality ( it will either be given in the scenario or you will need to calculate and
decide if it is material)
Step 2: Explain the accounting treatment from the relevant IFRS/IAS
Step 3: Use the information given to discuss issues/risks
Step 4: Explain the impact on the financial statements ( under/over statement or a disclosure which is
inadequate or missing)
Example:
▪ The right-of-use asset value exceeds the materiality threshold of $11 million and as such is
material.
▪ IFRS 16 leases requires that right-of-use asset should be depreciated over the term of the
[Link], depreciation should be charged as the entity has the use of the asset, even if no
lease payments have been yet been made.
▪ The depreciation which should have been charged on the asset in the first year is $4. 1 million ($28
.9 million/7 years). This amount is significantly over the materiality threshold for the audit.
▪ This means that non-current assets are overstated and expenses are understated by a material
amount.
Audit Procedures/Evidence
When a question asks for audit procedures, remember that there are some useful checklists:
❖ What documents would be available.
❖ Any 3rd Parties who can provide written confirmations.
❖ Would a written management representation help?
Page | 102
❖ What post year-end events may have occurred, that would help assess the year-end accounting
treatment.
❖ Could this have happened in previous years – if so compare.
Another way to think of the above issues is that you will need to use Analytical procedures, Enquiry,
external confirmation, Inspection, Observation and Recalculation to confirm that the accounting
treatment is correct.
When you write the procedures/evidence, ensure the ‘what’ and the ‘why’ are covered
Example
✓ Evidence that a physical inspection was performed to confirm the existence of the building and its
condition to determine if there are any indicators of impairment.
✓ A copy of management's calculation of the present value of the lease obligation and right-of-use
asset agreed back to the underlying lease amount.
Audit Work On: Inventory, Work in progress & Standard costing systems
Inventory
Audit evidence
According to ISA 501, Audit Evidence – Additional Considerations for Specific Items, when inventory is
material to the financial statements, the auditor should obtain sufficient appropriate audit evidence
regarding its existence and condition by attending physical inventory counting, unless this is
impracticable.
When attendance is impracticable, the auditor has to consider whether alternative procedures provide
sufficient and appropriate audit evidence of the existence and condition of inventory.
ISA 501 requires the auditor to review the instructions issued by the management for physical
verification, focussing particularly on the following:
a) Control activities: count and recount procedures and control over used and unused stationery that is
used to record inventory during the inventory count. The instructions should be simple and clear. They
should lay down the responsibilities of different persons and state which location will be covered by
which persons.
They should also specify the procedure to be followed and the identification marks to be made.
The intention should be to count each item and count it only once.
Page | 103
b) Accurate identification of slow moving / damaged items, inventory owned by third party, for example,
goods received on consignment, stage of completion of WIP.
c) Arrangements regarding the movement of inventory: dispatch and receipt of inventory before and
after cut-off date, movement of inventory between areas during the process of counting.
Therefore, while auditing standard costing systems, the auditor needs to ensure that standard costing is
a valid basis for valuing inventory and that the standard cost has been reasonably calculated.
Audit procedures
a) Review the purchase invoices and price index and enquire with management, to establish whether
or not the prices have fluctuated. The source documents should also be reviewed in order to verify
the standard cost calculations.
b) Discuss with management, whether or not standard costing is a valid costing system to use for the
company’s inventory.
c) Consider if the inventory is still comparable with the previous year’s inventory due to a change in
accounting policies, with appropriate disclosures of changes in accounting policies.
d) Check the reasonableness and accuracy of the standard cost calculation sheet by:
– Tracing the costs relating to purchases with the purchase invoices, wages with the wage sheets
and personnel records and overheads with the expense invoices
Page | 104
– Verifying the invoices mentioned above and checking whether the calculations are reasonable
– Casting the calculation sheet
– Verifying the standard cost calculations, including arithmetical calculations with the account totals
in the income statement.
Standard cost can also be verified by using analytical procedures such as comparison with the total related
expense in the income statement. For example the proportion of total overhead expenses (in the income
statement) to the total production during the year, would be the standard overhead cost
Factors to consider before accepting standard costs as an appropriate basis for the estimation of cost:
How often are the standard costs updated? --Do significant price variances arise? --Have the standard
costs been acceptable in the past?--What controls are there over the amendment of standard cost data?
Statements of cash flows are accounted for under the provisions of IAS 7 Statement of cash flows. The
statement of cash flows is essentially a reconciliation exercise between items in the operating profit and
the statement of financial position (cash).
As such, the statement of cash flows is often audited by the auditor reproducing it from the audited
figures in the other financial statements. This can be done quickly and easily in the modern era by use of
computer programmes.
However, if the auditor wished to audit it another way, he could check and recalculate each reconciliation
with the financial statements. This would involve checking each line of the statement by working through
the client's workings and agreeing items to the accounting records and backing documentation (for
example, tax paid to the bank statements) and the other financial statements.
Financial reports are obliged to include a statement of cash flows under IAS 7 in order to show a true and
fair view. The auditors must therefore assess the truth and fairness of the statement of cash flows as
required by IAS 7.
Page | 105
Analytical review
The information in the statement of cash flows will be used by the auditors as part of their analytical
review of the accounts, for example, by adding further information on liquidity. This will be particularly
helpful when comparing the statement to previous periods.
Going concern
The statement of cash flows may indicate going concern problems due to liquidity failings, overtrading
and over gearing. However, the statement is an historical document, prepared well after the year-end,
and is therefore unlikely to be the first indicator of such difficulties.
Audit evidence
The auditors will obtain very little direct audit evidence from the statement of cash flows. It has been
prepared by the company (not the auditors or an independent third party) from records which are under
scrutiny by the auditors in any case. Thus the auditors will already have most of this information, although
in a different format.
However, the statement of cash flows should provide additional evidence for figures in the accounts, for
example, the purchase or sale of tangible non-current assets. Consistency of evidence will be important
and complementary evidence is always welcome.
This will enable assessment of the ratios with reference to previous years as well as with the
industry.
b) By drawing up a statement of cash flow from the audited financial statements. The use of computers
has made this task very quick and easy.
Page | 106
Audit work: Changes in accounting policy
According to IAS 8 Accounting Policies, Changes in Accounting Estimates and Errors, due to its materiality,
the error must be adjusted for retrospectively by amending comparatives and restating retained earnings
at the beginning of the earliest period presented.
The effect of a change in accounting estimates should be accounted for prospectively, and included in
profit or loss from the date of the change in estimate. In other words, it is only current and future periods
which are affected by the change in estimate.
In addition, IAS 8 requires a note to the financial statements to disclose the nature and amount of a change
in an accounting estimate that has an effect in the current period or is expected to have an effect in future
periods.
The effect of a change in accounting policy is treated as a retrospective adjustment to the opening balance
of each affected component of equity as if the accounting policy had always applied.
IAS 8 Accounting policies, changes in accounting estimates and errors states that changes in accounting
policies are rare, and only allowed if required by statute or if the change results in more reliable and
relevant information.
Take care not to confuse a change in accounting policy with a change in accounting estimate. A change
in policy is rare and per IAS 8 should be accounted for retrospectively, but a change in estimate (such as
the method for calculating depreciation) is accounted for going forward (prospectively).
An example of a change in accounting estimate is a change to an entity’s depreciation policy. In this case,
the entity’s accounting policy is to depreciate non-current assets, and the ‘depreciation policy’(which
would include eg reducing balance or straight line depreciation, estimates of useful lives, etc) is merely
the policy chosen by management in order to estimate how much depreciation should be charged.
The standard highlights two types of event which do not constitute changes in accounting policy.
(a) Adopting an accounting policy for a new type of transaction or event not dealt with previously by the
entity.
(b) Adopting a new accounting policy for a transaction or event which has not occurred in the past or
which was not material.
Page | 107
Audit work: Taxation
(not very frequently tested so you might not see practice questions in the past exams)
IAS 12 Income Taxes requires deferred tax to be recognised in respect of taxable temporary differences
which arise between the carrying amount and tax base of assets and liabilities, including the differences
which arise on the revaluation of non-current assets, regardless of whether the assets are likely to be
disposed of in the foreseeable future. There is no profit impact, however, as the deferred tax would be
recognised in equity.
IAS 12 states that a deferred tax asset can only be recognised where the recoverability of the asset can be
demonstrated.
Unutilised tax losses can be carried forward for offset against future taxable profits, so the client must
demonstrate, using budgets and forecasts, that future tax profits will be available for the losses to be fully
utilised
Examiner feedback: Students should remember there will be 3 types of adjustments (current tax ,
under/over provision tax provision from previous year, deferred tax)
1. Verify that current tax expenses are properly calculated.
2. Review the provision to make sure that it is in accordance with IAS 12.
3. Check the accounting for and disclosures related to current tax expenses, asset, and liability.
4. Carry out a numerical reconciliation between tax expense and accounting profit multiplied by the
applicable tax rate.
5. Check the arithmetical accuracy of the deferred tax calculations. This would include checking the
opening balances of the deferred tax account against the previous year’s financial statements.
6. Obtain schedule of temporary differences : agree to tax computation and accounting records. Match
the figures used to calculate the temporary differences to those on the financial statements. For
example, trace the schedule of carrying amount (i.e. cost or revalued amounts net of accumulated
depreciation) of non-current assets to the general account balances and agree these to tax
computations and the asset register.
7. Ensure the rate applied is in accordance with IAS 12 (substantially enacted)
8. Enquire with management and verify that the tax computations include all differences which need to
be adjusted. Obtain a written representation..
9. Ensure that all necessary disclosures have been made- Disclosure: items on which deferred tax has
been calculated, the change in liability (reconciliation of opening and closing balance) and major
components of income tax expense.
10. If a tax software is used, perform TOCs.
11. Review any correspondence with the tax authorities.
Page | 108
Principal audit procedures – recoverability of deferred tax asset
– Obtain a copy of current tax computation and deferred tax calculations and agree figures to any
relevant tax correspondence and/or underlying accounting records.
– Develop an independent expectation of the estimate to corroborate the reasonableness of
management’s estimate.
– Obtain forecasts of profitability and agree that there is sufficient forecast taxable profit available for
the losses to be offset against. Evaluate the assumptions used in the forecast against business
understanding.
– Assess the time period it will take to generate sufficient profits to utilise the tax losses. If it is going to
take a number of years to generate such profits, it may be that the recognition of the asset should be
restricted.
– Using tax correspondence, verify that there is no restriction on the ability of the client to carry the
losses forward and to use the losses against future taxable profits.
IFRS 8 Operating Segments requires listed companies to disclose in a note to the financial statements the
performance of the company disaggregated over its operating or geographical segments, as the
information is viewed by management.
a) The identification of the operating segments and the amounts related to prior period that are included
in segment information must agree with the segment information included in the financial statements
of the earlier year.
b) The totals of the segment information disclosure must be cast.
c) The turnover and operating profit totals must be agreed with the amounts shown on the face of the
income statement.
d) The segment results (i.e. segment revenue less segment expense) must be agreed with the internal
MIS reports of the entity.
e) The appropriateness of the geographic segments identified for the primary reporting format must be
confirmed. For this:
– The auditor must review the MIS information of the entity to ascertain whether it indicates that
the chief operating decision maker (like the board) of the entity reviews the performance of the
operating segments and also takes decisions relating to allocation of resources based on this
information. The auditor will confirm that operating results include segment information.
– The entity must have a system of recording segment information in its accounting systems e.g.
cost centre wise information. This will provide assurance that discrete financial information
relating to operating segments is available.
– The numerical thresholds must be recalculated.
– The auditor would also discuss the basis of allocation with the entity. Furthermore on a sample
basis the information must be verified with source data such as segment revenue with invoices.
– The auditor would also look at segments which were slightly too small and double check to see if
they need to be included.
Page | 109
f) Revenue expenses that arise at the enterprise level on behalf of segments (e.g. head office costs)
which are not directly attributable to a segment need to be allocated between the different segments
on a reasonable basis. However, the IFRS has not explained how this is to be done. Furthermore the
basis for allocation which is chosen can have a material effect on the segment result. Therefore the
auditor needs to review the basis on which such expenses are attributed to segments and confirm
that it is reasonable (i.e. whether it is in agreement with prior year basis).
Page | 110
If the total external revenue reported by operating
segments constitutes less than 75% of the entity's revenue,
additional operating segments must be identified as
reportable segments (even if they do not meet the
quantitative thresholds set out above) until at least 75%of
the entity's revenue is included in reportable segments.
The key risk in relation to initial recognition is of costs being incorrectly recognised as assets, when they
should in fact have been expensed to the income statement.
Non-current assets will be carried at cost or valuation (if an item has been revalued).
For assets that are measured at cost, the auditor would have to verify the cost from the asset’s purchase
invoice.
The carrying value of non-current assets is therefore depreciated cost, or depreciated valuation.
Once a company has revalued assets, it is required to continue revaluing them regularly so that the
valuation is not materially different from the fair value at period end. The auditors should therefore check
that valuation is comparable to market value. They would do this by comparing the existing valuation to
current market values (for example, in an estate agent’s window).
Assets are depreciated, so their carrying value will not be original cost or valuation.
Often a ‘proof-in-total’ check will be sufficient, where auditors calculate the relevant depreciation
percentage on the whole class of assets to see if it is comparable to the depreciation charged for that class
of assets in the year.
Page | 111
The depreciation rate is determined by reference to the useful life of the asset. This is determined by
management based on expectations of how long the asset is expected to be in use in the business. The
auditors will audit this by scrutinising those expectations and verifying them where possible – for example,
to the minutes of the meeting where management decided to buy the asset, to capital replacement
budgets, to past practice in the business.
Assets purchased during the year should be correctly classified under their own account headings. In the
case of additions and disposals to the assets made during the year the auditor should inspect ledger
accounts to ensure that the additions and disposals are not recorded as purchases and sales revenue.
Appropriate Cut off: This means that transactions and events have been recorded in the correct
accounting period. In this case, when auditing non-current assets, the auditor has to ensure that all
additions and disposals to the non-current assets account that have occurred during the year are recorded
and that no transactions occurring in prior years have been recorded in the current year’s accounts
Rights and obligations: This means that the entity has the right to use and dispose of the asset. Any
liability arising from the asset has to be paid by the entity. Only when the rights of ownership are in the
hands of the entity can it record the asset in its accounts. For property purchased during the year, the
auditor would have to look at any legal documentation that would indicate ownership of the asset e.g.
title deed documents.
Existence: By existence, it means that the non-current asset does really exist at the end of the reporting
period. The auditor would have to visit the site of the assets and physically verify that the asset exists as
at the end of the reporting period. If the auditor is not able to physically verify the assets the auditor can
make a surprise physical check of significant assets. Furthermore the auditor will confirm whether physical
verification of non-current assets was carried out by the entity. Existence will ensure that the items exist,
but will not confirm the valuation. Hence valuation methods need to be used to confirm the valuation e.g.
looking at the purchase invoices and confirming the original cost and then estimating depreciation based
on past experience with the entity etc.
Fair value accounting is increasingly important and affects the audit of valuation for both assets and
liabilities. Examples of accounting treatments where fair values are relevant include financial instruments,
employee benefits and share-based payments.
Page | 112
For auditors, the determination of fair value will generally be more difficult than determining historical
cost. It will be more difficult to establish whether fair value is reasonable for complex assets and liabilities
than for more straightforward assets or liabilities which have a market and therefore a market value. For
example, for an apartment held as an investment property, a fair value might be relatively easy to
estimate, as there may be a large and active market for similar properties that can be used as a guide to
the value of the property in question. If, on the other hand, an entity has a large pension scheme, for
which the fair value of the assets depends on actuarial assumptions about the future, then the fair value
will be extremely difficult to measure, and the auditor will have to be very careful about the assumptions
made in arriving at a valuation.
Generally speaking, balances held at fair value carry the following risks.
Component of Risk
audit risk
Inherent risk Estimates are inherently imprecise, and involve judgements, eg about market
conditions, timing of cash flows, or the intentions of the entity.
However, obtaining a fair value for some assets will be straight forward, eg assets
that are regularly traded on a stock exchange.
Control risk Fair value assessment is likely to take place once a year, outside of normal internal
control systems. Therefore it may not be monitored as stringently as more routine
transactions and balances. Alternatively, management may take extra care over a
fair value assessment because it is a material amount, in which case control risk is
low.
Detection risk The auditor minimises detection risk through understanding the entity and its
environment at the planning stage, determining whether and where fair values
are present, and what the level of risk associated with them is.
Page | 113
Management’s processes for determining fair values will vary considerably from organisation to
organisation. Some companies will habitually value items at historical cost where possible, and may have
very poor processes for determining fair value if required. Others may have complex systems for
determining fair value if they have a large number of assets and liabilities which they account for at fair
value, particularly where a high degree of estimation is involved in determining the fair value.
Once the auditors have assessed the risks associated with determining fair value, they should determine
further procedures to address those risks.
However, in some cases, there may be a great deal of estimation and management assumption related to
a fair value. Where this is the case, the auditor needs to consider matters such as the intent and ability of
management to carry out certain actions stated in the assumptions. This includes:
• Considering management’s past history of carrying out its stated intentions with respect to assets or
liabilities
• Reviewing written plans and other documentation, including, where applicable, budgets, minutes etc
• Considering management’s stated reasons for choosing a particular course of action
• Considering management’s ability to carry out a particular course of action given the entity’s
economic circumstances, including the implications of its contractual commitments
The auditor should consider the following when considering fair value measurements:
• The length of time any assumptions cover (the longer, the more subjective the value is)
• The number of assumptions made in relation to the item
• The degree of subjectivity in the process
• The degree of uncertainty associated with the outcome of events
• Any lack of objective data
• The timings of any valuations used
• The reliability of third party evidence
The impact of subsequent events on the fair value measurement
Where a fair value measurement is based on assumptions reflecting management’s intent and ability to
carry out certain actions, then the auditor should obtain written representations from management that
these assumptions are reasonable and achievable.
Page | 114
Fair values – acquisition of new subsidiaries
When a parent company acquires a new subsidiary, it will pay the fair value of the acquired company as
a whole. This is because the previous owners tend to be unwilling to sell their company for less than its
fair value. In order to bring in a fair estimate of the initial value of goodwill, IFRS 3, Business Combinations
requires that the individual net assets of the acquired company be valued at their fair value at the date of
the acquisition. Often, the acquirer will have investigated their assessment of value of material assets,
liabilities and contingent liabilities of the target company as part of a pre-acquisition due diligence
investigation. In these circumstances, the values ascribed to individual assets and liabilities in this due
diligence will be an appropriate value to use for the initial recognition of each asset and liability. This
means that fair value often becomes fair value through the eyes of the acquirer. This is not always the
most appropriate valuation basis, however, since the value given by the acquirer may include some degree
of the acquirer’s intentions. For example, it is common for a new acquirer to plan to restructure an
acquired business shortly after the acquisition. This might include an intention to pay off any litigation in
progress at the date of acquisition in order to fee management time for integration of the subsidiary into
its new group. This could result in incorrect recognition of provisions that are higher than the true value
of the obligation.
Scheme assets – Obtain direct confirmations of scheme assets from the investment
(including professional in charge of the plan assets.
quoted and unquoted – Obtain reconciliations from the company’s management of the valuation
securities, debt as at the scheme year end date with the entity’s reporting date.
instruments, – Consider requiring scheme auditors to perform procedures
properties)
Scheme liabilities Work done by the actuary can be relied upon after evaluating his work in
accordance with the provisions of ISA 620 Using the Work of an Auditor’s
Expert. Auditors must assess whether it is appropriate to rely on the actuary's
work
Specific matters would include
– The source data used
– The assumptions and methods used
– The results of actuaries' work in the light of auditors' knowledge of the
business and results of other audit procedures
Page | 115
Actuarial assumptions – Discuss with the actuaries the basis used to calculate assumptions and
( for example review whether or not the assumptions appear to be reasonable based
retirement ages, on their knowledge of the entity’s financial information.
mortality rates, – Compare the assumptions used in the current year with those used in the
employee previous years, for consistency.
turnover/termination – Obtain written representations from the entity’s management regarding
rate, changes in salary the appropriateness of the assumptions in relation to their knowledge of
and benefits, funds’ business.
assets performance) – Auditors should determine whether the assumptions used by the entity
Remember that it is are similar to the assumptions used by other entities in the industry.
unlikely that auditors – Evaluate the reasonableness of assumptions by using your knowledge of
will have the same the business and results of other audit procedures
level of expertise as
the actuary!
– Recalculate actuarial gain/loss
A government grant is recognised only when there is reasonable assurance that (a) the entity will comply
with any conditions attached to the grant and (b) the grant will be received
Risks
IAS 20 Accounting for Government Grants and Disclosure of Government Assistance requires that a grant
is recognised as income over the period necessary to match the grant received with the related costs for
which they are intended to compensate. This means that the amount received should not be recognised
as income on receipt, but the income deferred and released to profit over the estimated useful life of the
assets to which it relates.
The risk is that the grant has been recognised on an inappropriate basis leading to over or understated
profit for the year.
Page | 116
The part of the grant not recognised in profit should be recognised in the statement of financial position.
IAS 20 allows classification as deferred income, or alternatively the amount can be netted against the
assets to which the grant relates. There is therefore also a risk that the amount is recognised elsewhere
in the statement of financial position, leading to incorrect presentation and disclosure.
If the terms of the grant have been breached, the grant or an element of it may need to be repaid. There
is therefore a risk that if there is any breach, the associated provision for repayment is not recognised,
understating liabilities.
Revenue Grant-A grant receivable as compensation for costs, either: Already incurred or For immediate
financial support, with no future related costs.
Grants where related costs have already been incurred offer no difficulties to account for or to audit. To
audit them, the auditor should:
• Obtain documentation relating to the grant and confirm that it should be classified as revenue
• The value may be agreed to the documentation (for example, a letter outlining the details of the grant,
or a copy of an application form sent by the client)
• The receipt of the grant can be agreed to bank statements
The grant is recognised as income over the period necessary to match it with the related costs, for which
it is intended to compensate on a systematic basis and should not be credited directly to equity.
Audit procedures:
• Consider whether the basis of accounting is comparable to the previous year.
• Discuss the basis of accounting with the directors to ensure that the policy used is the best one
• Ensure that any changes in accounting policy are disclosed.
Under IAS 20, the grant should be presented on the statement of financial position either as deferred
income, or by deducting the grant in arriving at the asset’s carrying value.
Page | 117
Audit procedures in respect of the recognition and measurement of the government grant
– Obtain the documentation relating to the grant to confirm the amount, the date the cash was
received, and the terms on which the grant was awarded.
– Review the documentation for any conditions attached to the grant
– Discuss with management the method of recognition of the amount received, in particular how much
of the grant has been recognised in profit and the treatment of the amount deferred in the statement
of financial position.
– Confirm that the grant criteria have been complied with ( scenario specific information needs to be
incorporated)
– Using the draft financial statements, confirm the accounting treatment outlined by discussion with
management has been applied and recalculate the amounts recognised. {Recalculate ‘release’ to
match with costs (revenue grant) or depreciation (capital grant)}
– Confirm the cash received to bank statement and cash book
– Review Disclosures for adequacy and completeness:
Disclosure
• Accounting policy note.
• Nature and extent of government grants and other forms of assistance received.
• Unfulfilled conditions and other contingencies attached to recognised government assistance.
Non-monetary grants, such as land or other resources, are usually accounted for at fair value.
Page | 118
Audit work: Related parties
Examples of related parties: subsidiaries, JV, shareholder with significant influence, directors, other senior
management like CFO
Indicators: loans (with no interest, low interest, no specific repayment terms), non-monetary exchange of
property, sale of real estate at a market value , loan from a stockholder to hide liquidity problems
(iii) Where the applicable financial reporting framework establishes minimal or no related party
requirements:
a. A person or other entity that has control or significant influence, directly or indirectly through
one or more intermediaries, over the reporting entity;
b. Another entity over which the reporting entity has control or significant influence, directly or
indirectly through one or more intermediaries; or
c. Another entity that is under common control with the reporting entity through having:
i. Common controlling ownership;
ii. Owners who are close family members; or
iii. Common key management.
ISA 550 Related Parties requires that the auditor evaluates whether identified related party relationships
and transactions have been appropriately accounted for and disclosed in accordance with the applicable
financial reporting framework.
Page | 119
absence of alternative procedures other than management enquiry, the auditor could not know of
the existence of some related party relationships, especially the family members of key management
personnel. ISA 550 Related Parties identifies that related party relationships may represent a greater
opportunity for collusion, concealment or manipulation by management.
5. The accounting system may not be set up to identify related party transactions. For example, cash
payments made to a related party may not be separately identified from payments to trade suppliers
within the ledgers.
6. Finally, some related party transactions occur at minimal value, and sometimes at nil value. This
makes the transaction almost impossible for the auditor to detect, other than relying on management
to disclose the transaction on enquiry.
Page | 120
3. Not adhering to the set methods of processing transactions: Transactions that are not processed in
the routine manner may be on account of related party transactions.
4. Terms of trade different from normal: If the terms of trade are different and not according to routine
business transactions, there can be a related party transaction.
5. High volume with one customer / supplier: An extraordinary high volume of sales or purchases with
one customer or vendor is also a risky area as this can be construed as a related party transaction.
6. Unrecorded transaction: If there are any unrecorded transactions, the auditor can assess whether
there is a genuine error or whether the mistake had been made on purpose.
7. Transactions not having adequate evidence: An auditor always asks for the audit evidence which is
sufficient and reasonable to cover the risk. If any particular transaction is effected without adequate
documentary evidence, there is a probability of the transaction being a related party transaction e.g.
absence of documentary evidence to support an investment made in the shares of a company.
8. Unusual transactions entered at the start and end of year
Audit work
ISA 550 requires that where a significant related party transaction outside of the entity’s normal course
of business is identified, the auditor shall:
1. Inspect the underlying contracts or agreements, if any, and evaluate whether:
a) The business rationale (or lack thereof) of the transactions suggests that they may have been
entered into to engage in fraudulent financial reporting or to conceal misappropriation of assets;
b) The terms of the transactions are consistent with management’s explanations; and
c) The transactions have been appropriately accounted for and disclosed in accordance with the
applicable financial reporting framework.
2. The auditor shall also obtain audit evidence that the transactions have been appropriately authorised
and approved.
3. IAS 24 states that a related party transaction should be disclosed if it is material In relation to a
material related party transaction, IAS 24 requires disclosure of the nature of the related party
relationship along with information about the transaction itself, such as the amount of the
transaction, any relevant terms and conditions, and any balances outstanding.
4. The auditor needs to get a written representation from management stating that management has
disclosed to the auditor the identity of the entity’s related parties and all the related party
relationships and transactions of which they are aware, and that management has appropriately
accounted for and disclosed such relationships and transactions in accordance with the requirements
of IAS 24.
5. Auditor shall inquire of management:
– The identity of related parties including changes from prior period
– The nature of the relationships between the entity and its related parties
– Whether any transactions occurred between the parties, and if so, what
– What controls the entity has to identify, account for and disclose related party relationships and
transactions
– What controls the entity has to authorise and approve significant transactions and arrangements
with related parties
Page | 121
– What controls the entity has to authorise and approve significant transactions and arrangements
outside the normal course of business
6. Perform procedures specific to the transaction given in the question
Audit issues
The size of the figure is unlikely to be material in itself, but it is a key investor figure. As it will be of interest
to all the investors who read it, it is material by its nature.
When considering earnings per share, the auditor must consider two issues:
• Whether it has been disclosed on a comparable basis to the prior year, and whether any changes in
accounting policy have been disclosed, and
• Whether it has been calculated correctly
A key audit risk is that the entity fails to meet IAS 33’s disclosure requirements. These are:
(a) The amounts used as the numerators in calculating basic and diluted EPS, and a reconciliation of
those amounts to the net profit or loss for the period
(b) The weighted average number of ordinary shares used as the denominator in calculating basic and
diluted EPS, and a reconciliation of these denominators to each other.
IAS 33 requires EPS to be calculated based on the profit or loss for the year attributable to ordinary
shareholders as presented in the statement of profit or loss, EPS based on an alternative profit figure is
only allowed to be disclosed in the notes to the financial statements as an additional figure, and should
not be disclosed on the face of the financial statements.
The denominator used in the EPS calculation should be based on the weighted average number of shares
which were in issue during the financial year.
Page | 122
– Read the notes to the financial statements in respect of EPS to confirm that disclosure is complete
and accurate and complies with IAS 33.
When auditing an entity’s non-current assets, the auditor would, use the same criteria as set out by the
management in accordance with IAS 36 Impairment of Assets, check for indicators that may suggest a
possibility for impairment on assets.
The auditors will consider whether there are any indicators of impairment when carrying out risk
assessment procedures. They will use the same impairment criteria laid out in IAS 36 as management do.
If there is an indication of impairment on an asset, the auditors should request the management for a
copy of the impairment review. If the management has carried out an impairment review, that
impairment review should be audited.
If the management has not conducted an impairment review, then the auditors should propose an
impairment review and qualify their report depending on whether or not the management agrees to carry
out the impairment review.
Recoverable amount: this depends on the fair value, cost to sell and value in use.
Page | 123
Fair value and cost to sell: both are subject to estimations. Therefore they need to be reviewed carefully.
The risk assessment procedures to assess the risks of material misstatement in relation to accounting
estimates and fair values would have to be carried out. Additionally while reviewing cost to sell the items
which can be included and excluded must be in accordance with the provisions of IAS 36.
Cost to sell should be checked for arithmetical accuracy. Furthermore, cost of delivery can be verified
from the rates published by delivery companies. Cost to sell includes transaction taxes. These can be
recalculated by applying the applicable tax rate to the fair value. Stamp duty can be recalculated based
on the regulatory requirements.
Value in use
If the management has used the asset’s value in use, the auditor must conduct the following audit
procedures.
1. Physically inspect the asset; this provides evidence of existence and condition of asset as on the
reporting date.
2. Obtain the document containing value in use (along with the working papers) from the entity.
3. Trace the projected cash flows in the workings with budgets and projections, to ensure that they are
approved by the board and are reasonable (e.g. asset days available and average daily utilisation per
asset).
4. Calculate/obtain from analysts the long term average growth rate for the products and ensure that
the growth rates assumed in the calculation of value in use do not exceed it
5. Check the arithmetical accuracy of the document.
6. Cash flows need to be discounted to present values. Confirm that the present values used for
discounting should be in accordance with the published market rates expected by the market.
7. Recalculate on a sample basis, the makeup of the cash flows included in the forecast..
8. Compare to previous calculations of value in use to ensure that all relevant costs of maintaining the
asset have been included
9. Ensure that the cost/income from disposal of the asset at the end of its life has been included
10. Review calculation to ensure cash flows from financing activities and income tax have been excluded
11. Written representation: regarding expected future performance and that the management’s
assumptions are reasonable.
Page | 124
Audit procedures – impairment of goodwill
The auditor should perform the following procedures:
– The assumptions used in the impairment test should be confirmed as agreeing with the auditor’s
understanding of the business based on the current year’s risk assessment procedures, e.g. assess the
reasonableness of assumptions on cash flow projections.
– Confirm that the impairment review includes the goodwill relating to all business combinations.
– Consider the impact of the auditor’s assessment of going concern on the impairment review, e.g. the
impact on the assumption relating to growth rates which have been used as part of the impairment
calculations.
– Obtain an understanding of the controls over the management’s process of performing the
impairment test including tests of the operating effectiveness of any controls in place, for example,
over the review and approval of assumptions or inputs by appropriate levels of management and,
where appropriate, those charged with governance.
– Confirm whether management has performed the impairment test or has used an expert.
– The methodology applied to the impairment review should be checked by the auditor, with inputs to
calculations, e.g. discount rates, agreed to auditor-obtained information.
– Develop an independent estimate of the impairment loss and compare it to that prepared by
management.
– Confirm that the impairment calculations exclude cash flows relating to tax and finance items.
– Perform sensitivity analysis to consider whether, and if so how, management has considered
alternative assumptions and the impact of any alternative assumptions on the impairment
calculations.
– Check the arithmetic accuracy of the calculations used in the impairment calculations
According to IAS 37 Provisions, Contingent Liabilities and Contingent Assets, a provision should be
recognised where there is a present obligation as a result of a past event, a probable outflow of economic
benefit and a reliable estimate can be made.
Contingent Assets should not be recognised until such time as the inflow of economic benefits is virtually
certain. If the inflow of benefits is probable rather than virtually certain, then the matter should only be
disclosed in a note to the financial statements.
ISA 540 directs the auditor’s work from a starting point of uncertainty rather than the materiality of the
draft figure in the financial statements. The greater the estimation uncertainty, rather than the size of
the draft figure, the greater the amount of evidence that the auditor will need to obtain.
– The schedule forming part of the financial statements relating to provisions and contingent assets and
liabilities should be obtained from the client. The schedule must include opening balances,
movements during the current period and the closing balances. The amounts relating to opening
balances should be agreed with the previous period’s financial statements.
Page | 125
– Considering the nature of the entity’s business the auditor must consider whether appropriate
provisions are made. For example the auditor of a mining company would verify whether provisions
for site restoration are made on mines.
Obtain an When performing risk assessment procedures, the auditor shall obtain an
understanding understanding of the following:
Use an independent The auditor may make or obtain an independent estimate and compare it
estimate, either made with the accounting estimate prepared by management.
or obtained by the
auditor, for comparison When using an independent estimate the auditor would ordinarily evaluate
with that prepared by the data, consider the assumptions and perform audit procedures on the
management; calculation procedures used in its development.
Page | 126
It may also be appropriate to compare independent estimates made for prior
periods with actual results of those periods.
Review subsequent Transactions and events which occur after period end, but prior to
events which provide completion of the audit, may provide audit evidence regarding an accounting
audit evidence of the estimate made by management. The auditor's review of such transactions
reasonableness of the and events may reduce, or even remove, the need for the auditor to review
estimate made. and perform audit procedures on the process used to develop the
accounting estimate or to use an independent estimate in assessing the
reasonableness of the accounting estimate.
The auditor shall obtain sufficient appropriate audit evidence about whether the disclosures in the
financial statements related to accounting estimates are in accordance with the requirements of the
applicable financial reporting framework.
Provisions: nature of obligation, timing of outflow, any uncertainty regarding amount or time, any
assumptions about future events, numerical reconciliation of opening and closing balances
The auditor shall review the judgments and decisions made by management in the making of
accounting estimates to identify whether there are indicators of possible management bias.
The auditor shall obtain written representations from management and, where appropriate, those
charged with governance whether they believe significant assumptions used in making accounting
estimates are reasonable
Consider the need for 3rd party confirmation or inspection of client’s correspondence with 3rd parties.
Management Bias
“Management bias” according to ISA 540 Auditing accounting estimates is a lack of neutrality by
management in the preparation of financial information. In theory, management should be unbiased or
neutral when preparing financial information because the information itself needs to be unbiased so users
can rely on it. However, management may find it difficult to take an objective view simply because they
normally have an inherent interest in that information. For example, bonus payments may vary as a direct
result of reported profit or share price change resulting from publication of financial information
Page | 127
Audit work: Intangible assets
Examples of items that might be considered as intangible assets include computer software, patents,
copyrights, motion picture films, customer lists, franchises and fishing rights. An item should not be
recognised as an intangible asset, however, unless it fully meets the definition in the standard.
IAS 38 Intangible Assets states that an intangible asset with a finite useful life is amortised, and an
intangible asset with an indefinite useful life is not.
An intangible asset with an indefinite useful life shall not be amortised BUT has to be tested for
impairment annually, and whenever there is an indication that the intangible asset may be impaired
When an intangible asset has a finite useful life, it should be amortised systematically over that life.
For a development asset, the amortisation should correspond with the pattern of economic benefits
generated from the sale of associated goods. There is a risk that the amortisation period has not been
appropriately assessed.
– Check project reports (from the management as well as experts) to ensure that the expenditure
relating to the research and development project can be separately identified and feasible to be
completed.
– Confirm that all the conditions relating to development cost are completed before the development
expenses are capitalised. For this confirm:
o The technical feasibility and viability by verifying reports from technical experts, results of test
runs, etc.
o The market research documents, budgets, forecasts to conclude whether the entity believes that
a market for the internally developed asset exists.
Page | 128
o That the various significant expenses are supported with valid invoices in order to confirm that
expenditure that would be incurred from developing the asset and can be reliably measured.
o View the budgeted revenues and costs and calculations for future cash flows to ensure that
resources required to fulfil the budgets actually exist.
– Check the appropriateness of amortisation i.e. the asset should be amortised over its useful life.
Therefore the auditor should verify the expert’s report relating to useful life of the development costs.
– The auditor should also verify the accounting entries to confirm that the financial statements are
correctly drawn up.
– Review adequacy and completeness of the Disclosure (useful life or amortisation rate, amortisation
method, accumulated amortisation and impairment losses, basis for determining that an intangible
has an indefinite life, intangible assets carried at revalued amounts , the amount of research and
development expenditure recognised as an expense in the current period)
– Ensure Initial measurement: at cost. Measurement subsequent to acquisition: cost model and
revaluation models allowed.
If a brand has been purchased separately (that is, not as part of goodwill) then auditors should test the
value of the brand according to the sales documentation.
Page | 129
Audit work: Financial Instruments
When auditing financial instruments, the auditors will have to ensure that recognition and valuation is in
accordance with IFRS 9 Financial instruments.
Financial assets
Initial recognition of a financial asset is at the fair value of the consideration. Subsequent to this initial
recognition, IFRS 9 requires that financial assets are classified as measured at either:
• Amortised cost, or
• Fair value
An application of these rules means that equity investments may not be classified as measured at
amortised cost and must be measured at fair value. This is because contractual cash flows on specified
dates are not a characteristic of equity instruments. In addition, all derivatives are measured at fair value.
A debt instrument may be classified as measured at either amortised cost or fair value depending on
whether it meets the criteria above.
Financial liabilities
As with financial assets, a financial liability is initially measured at the fair value of the consideration
received. Subsequent to this, IFRS 9 requires that financial assets are classified as measured at either:
(a) Fair value through profit or loss, or
(b) Amortised cost under the effective interest rate method
Page | 130
Two types of disclosure need to be made: about the significance of the financial instruments, and about
the nature and extent of risks arising from the financial instruments.
IFRS 7 requires disclosures about the significance of financial instruments to be made in relation to the
SOFP and the SOCI. For example, entities must disclose the carrying amounts included within each IAS
39/IFRS 9 category on the SOFP, and the reason for any reclassification between these categories. The
SOCI must then disclose the net gain/loss that is attributable to each of these categories.
Regarding the nature and extent of risks, IFRS 7 requires disclosures in respect of credit risk, currency
risk, interest rate risk, liquidity risk, loans payable, market risk, other price risks, and instruments that are
past due.
Compound financial instruments: Convertible debt is a commonly-examined example here, where the
debt and equity elements of the instrument need to be presented separately in the financial statements.
Accounting in this area requires a level of judgement, which can be risky from an auditor’s point of view.
For example, judgement is required when calculating the present value of debt repayments (e.g. in
selecting an appropriate discount rate).
Audit Risk
Classification: inaccurate classification of financial instruments can cause material misstatements in the
financial statements as they will reflect incorrect gearing ratios and hence the risk profile of the entity.
Financial instruments, particularly complex ones, increase audit risk. Factors which increase audit risk
include the following:
(a) Lack of management understanding of financial instruments and therefore inadequate management
control.
(b) Inappropriate classification of financial instruments, particularly between debt and equity may lead
to off-balance sheet financing. This will affect gearing and therefore the risk profile of the business.
This is particularly an issue where hybrid or compound instruments have been issued with both debt
and equity elements.
(c) The use of fair values involves the use of valuation techniques including market estimates.
Judgements will need to be made to determine whether the valuation techniques and any estimates
made are reasonable.
Page | 131
(d) Recognition of the costs associated with the instrument is not necessarily straightforward. For
example, the discount on a discounted debenture should be treated as part of the overall cost of the
instrument and recognised over the life of the debenture.
Audit procedures
Classification Review the terms of the financial instrument and confirm that they have been
classified in accordance with their substance.
Agree fair value to transaction price (the cost of shares can be verified by checking
the purchase documentation).
Where part of the consideration has been given for something other than the
financial instrument, assess valuation technique adopted, eg discounting of future
cash flows.
Page | 132
– Where there is an active market agree fair value to quoted market price
(current bid price).
– Where there is no active market assess the valuation technique adopted
by management and any assumptions made.
Ownership Ownership of shares in another company should be checked to the share
certificate.
The share certificate may be kept in a bank or at a brokers, in which case the
auditor should confirm with these parties that the share certificate exists.
Presentation and Check that disclosures comply with IFRS 7. This includes eg qualitative disclosures
disclosure about exposure to risk and risk management, and quantitative disclosures of
summary data about exposures.
Loan
Evidence
– Re-performance of management’s calculation of the finance charge in relation to the loan,
– Agreement of the loan receipt and interest payment to bank statement and cash book.
– Review of board minutes for approval of the loan to be taken out.
– A copy of the loan agreement, reviewed to confirm terms including the maturity date, any premium
to be paid on maturity and annual interest payments.
– A copy of the note to the financial statements which discusses the loan to ensure all requirements of
IFRSs 7 and 13 have been met.
Page | 133
Audit work: Investment properties
A key factor to consider when auditing investment properties is whether one exists according to the
criteria of IAS 40 Investment property.
Investment property is property (land or a building – or part of a building – or both) held (by the owner
or by the lessee under a finance lease) to earn rentals or for capital appreciation or both, rather than for:
• Use in the production or supply of goods or services or for administrative purposes, or
• Sale in the ordinary course of business
Recognition
Investment property should be recognised as an asset when it is probable that the future economic
benefits that are associated with the property will flow to the entity, and the cost of the property can be
reliably measured.
Procedures
Initial measurement: Investment property is initially measured at cost, including transaction costs.
Review breakup of cost and ensure Cost does not include start-up costs, abnormal waste, or initial
operating losses incurred before the investment property achieves the planned level of occupancy.
Subsequent measurement :can choose between the fair value and the cost model. Ensure the
accounting policy choice must be applied to all investment property.
Cost model
– Investment property is measured in accordance with requirements set out for that model in IAS
16….cost less accumulated depreciation and less accumulated impairment losses
Carry out the normal property Existence, rights and obligation, valuation documents
procedures
Page | 134
Disclosure: The auditor should review the disclosures made in the financial statements in relation to
investment properties to ensure that they have been made appropriately, in accordance with IAS 40.
– Whether the fair value or the cost model is used
– The methods and significant assumptions applied in determining the fair value of investment
property
– The extent to which the fair value of investment property is based on a valuation by a qualified
independent valuer; if there has been no such valuation, that fact must be disclosed
Ascertain the major terms of – Obtain the details of the share-based payment plan to ascertain
the plan from the contractual the major terms of the plan including:
documentation • The grant date and vesting date
• The number of executives and senior managers awarded
options
• The number of share options awarded to each individual
• The required conditions attached to the options
• The fair value of the share options at the grant date.
– Scrutinise the conditions attached to the options to confirm any
market conditions and non-market conditions according to IFRS 2
Fair value of instruments 1. For equity-settled schemes check that fair value is estimated at
grant date. The grant date fair value is recognised over the vesting
period.
2. For cash-settled schemes check that the fair value is recalculated
at the year end and at the date ofsettlement
3. Review the assumptions used, and inputs into the option pricing
model used by management to estimate the fair value of the
share options at the grant date.
4. Consider the appropriateness of the model used to generate a
fair value for the share options.
5. Consider the use of an expert possessing specialist skills in share
option pricing, such as a chartered financial analyst, to provide
evidence as to the validity of the fair value of share options used
in the calculations.
6. Consider whether assumptions used appear reasonable. For
example, Obtain and review a forecast of staffing levels or
employee turnover rates relevant to executives and senior
managers over the vesting period and consider whether
assumptions used appear reasonable.
Page | 135
7. Check the sensitivity of the calculations to a change in the
assumptions used in the valuation.
Risks can be discussed relating to the use of option pricing models .In
determining the expense to be recognised, client needs to use a
valuation method for estimating the fair value of the share options at
the grant date. Various models can be used, but all are based on inputs
such as share price, exercise price, rate of return and estimated
dividend yield. The risk is that inappropriate assumptions have been
input to the valuation model, resulting in an unrealistic estimate of the
fair value of share options at the grant date. Further, there is a risk
that the wrong valuation model has been used.
Page | 136
Audit work: Assets Held For Sale and discontinued operations
Audit work
1. Discuss with the management about the existence of assets held for sale.
2. Confirm that the assets meet the definition of assets held for sale:
❖ Written representations from the management regarding its intention to sell
❖ Discuss with management the availability of asset for sale
❖ Written representation from management on the opinion that the assets will be sold
❖ Assess management commitment, for example A copy of the board minutes at which the disposal
was agreed by management.
❖ Evaluate and assess practical steps being taken to sell the asset eg appropriate agents appointed
❖ Determine when the sale is expected to take place by assessing progress to date
❖ Determine and assess the basis on which the sale price has been set
❖ Discuss with management any significant changes to the plans
3. Confirm that the asset has been valued as held for sale in accordance with IFRS 5 and assess how fair
value has been determined. {Confirm assets measured at lower of: Carrying value and FV- costs to sell
(any impairment loss to P & L)}
4. A copy of the client’s depreciation calculations, to confirm that depreciation was not charged
subsequent to the reclassification of the assets as held for sale.
5. Confirm separate disclosure in accordance with IFRS 5 {to include a description of the non-current
assets classified as held for sale, a description of the facts and circumstances of the sale and its
expected timing, and a quantification of the impairment loss and where in the statement of profit
or loss and other comprehensive income it is recognised}
6. Subsequent events review, including a review of post year-end board minutes and a review of
significant cash transactions, to confirm if any non-current assets are sold in the period after the year
end.
7. Details of any impairment review conducted by management on the non-current assets
8. Ensure accurate presentation: must be presented separately on the face of the statement of financial
position
Discontinued operations
Audit procedures
Page | 137
5. Carry out the audit procedures to assess the reasonableness of the fair vales and cost to sell.
6. Compare the opening balance of the carrying value of the asset from the previous year’s financial
statements. Recalculate the depreciation for the current year (up to the date of classification as
discontinued operations).
7. To audit whether the disclosures have been made correctly, the auditor should undertake the
following procedures:
a) Obtain a copy of the client's workings to disclose the discontinued operations.
b) Review the workings to ensure that the figures are reasonable and agree to the financial
statements.
c) Trace a sample of items disclosed as discontinuing items to backing documentation (invoices) to
ensure that they do relate to discontinued operations.
Remember, the results of discontinued operations should be presented separately in the statement of
comprehensive income for the entire period, and not just the results since the operation became
discontinued.
Individual company
For an individual company conducting trade in foreign currencies, there are two separate accounting
issues: conversion and translation.
Conversion is uncontroversial, and relates to an entity conducting transactions in a foreign currency, and
which incurs exchange gains/losses in relation to these transactions.
According to IAS 21 The Effects of Changes in Foreign Exchange Rates, foreign currency transactions
should be initially recognised having been translated using the spot rate, or an average rate may be used
if exchange rates do not fluctuate significantly.
The rule is simple: the gain or loss on conversion is recognised directly in profit and loss in the period in
which it occurs. The principal risk here is of the wrong exchange rate being used, resulting in misstatement
of the gain/loss in the financial statements.
Translation is more complex. Translation is required at the end of an accounting period when a company
still holds assets or liabilities in its statement of financial position which were obtained or incurred in a
foreign currency. IAS 21 distinguishes between monetary items and non-monetary items. The basic rule
is that monetary items (e.g. cash, receivables) should be retranslated using the rate rule at the end of each
accounting period. Non-monetary items such as inventory are left at the amount recognised at the date
of the transaction.
Page | 138
The risk is that the yearend retranslation does not take place, or that an inappropriate exchange rate is
used for the retranslation
Groups
It is also possible that a parent company may have overseas subsidiaries. It must translate the financial
statements of those operations in to its own reporting currency before they can be consolidated in to
group accounts. There are two methods of achieving this. The method used depends on whether the
foreign operation has the same functional currency as the parent.
Non-monetary items: Translate using an historic rate at the date of purchase (or revaluation to fair value,
or reduction to realisable/recoverable amount). This includes inventories and long-term assets (and their
depreciation).
Assets and liabilities: Translate at the closing rate at the period end. (The balancing figure on the translated
statement of financial position represents the reporting entity's net investment in the foreign operation.
Page | 139
Income statement: Translate items at the rate ruling at the date of the transaction (an average rate will
usually be used for practical purposes)
Exchange differences: Taken to equity- IAS 21 states that exchange gains and losses arising as a result of
the restranslation of the subsidiary’s balances are recognised in other comprehensive income. The risk is
incorrect classification, for example, the gain or loss could be recognised incorrectly as part of profit for
the year
Page | 140
Audit work: Borrowing costs
( not very frequently tested so you might not see practice questions in the past exams)
According to IAS 23 Borrowing Costs, borrowing costs that are directly attributable to the acquisition,
construction or production of a qualifying asset should be capitalised as part of the cost of that asset.
The borrowing costs should be capitalised only during the period of construction, with capitalisation
ceasing when substantially all the activities necessary to prepare the qualifying asset for its intended use
or sale are complete
Audit work
1. Review an original copy of the loan agreement, confirming the amount borrowed, the date of the cash
receipt, the interest rate and whether the loan is secured on any assets.
2. Confirm: only directly attributable costs capitalized: ask for the breakdown and review supporting
documents
3. Confirm: Capitalized only during construction- cease when suspended or completed; THEN
depreciate.
4. Interest can be verified by performing analytical reviews as the relationship of various loans and the
interest amounts is predictable.
5. Recalculate and agree the following figures to the draft financial statements.
– The borrowing cost (Amount= borrowing cost less temp investment income OR if generally
obtained loan, weighted average of borrowing costs applicable to borrowing outstanding)
– Depreciation charge
– Carrying value of the asset at the year end,
6. Agree figures in respect of interest payments made to statements from lender and/or bank
statements
7. Ensure the adequacy and completeness of disclosures (Amount of borrowing costs capitalized during
the period; Capitalisation rate used to determine borrowing costs eligible for capitalisation.)
Page | 141
Audit work: Using the work of others
Auditor’s expert – An individual or organization possessing expertise in a field other than accounting or
auditing, whose work in that field is used by the auditor to assist the auditor in obtaining sufficient
appropriate audit evidence.
Management’s expert – An individual or organization possessing expertise in a field other than accounting
or auditing, whose work in that field is used by the entity to assist the entity in preparing the financial
statements.
Written instructions should have been provided by the auditor to the expert prior to them carrying out
the work. The instructions should include matters such as the scope of the work, the applicable financial
reporting framework and any specific matters to be addressed. As a first step, the auditor should consider
if these instructions have been followed by the expert.
ISA 620 Using the Work of an Auditor’s Expert contains requirements relating to the objectivity and
capabilities of the auditor’s expert, the scope and objectives of their work, and assessing their work.
1. Objectivity: The auditor shall evaluate whether the auditor’s expert has the necessary objectivity
and that this should include inquiry regarding interests and relationships which may create a threat
to the expert’s objectivity. The audit firm will need to ensure that the expert has no connection to
the client, for example, that they are not a related party of the company or any person in a position
of influence over the financial statements. If the expert’s objectivity is threatened, less reliance can
be placed on their work.
Page | 142
2. Competence: ISA 620 also requires the competence of the expert to be considered; this should
include considering the expert’s membership of appropriate professional bodies. Any doubts over
the competence of the expert will reduce the reliability of audit evidence obtained.
3. Scope of work: ISA 620 requires the auditor to agree the scope of work with the expert. This may
include agreement of the objectives of the work, how the expert’s work will be used by the auditor
and the methodology and key assumptions to be used. In assessing the work performed by the
expert, the auditor should confirm that the scope of the work is as agreed at the start of the
engagement. If the expert has deviated from the agreed scope of work, it is likely to be less relevant
and reliable.
4. Relevance of conclusions: ISA 620 a) Review the auditor’s expert’s working papers and reports
states that the auditor shall to ensure that:
evaluate the relevance and – The work meets the objectives of the audit
adequacy of the expert’s findings – The evidence contained in the report is consistent
or conclusions. This will involve with other evidence obtained by the auditor
consideration of the source data – The work is based on the correct period and takes into
which was used, the account events after the reporting date where
appropriateness of assumptions necessary.
and the reasons for any changes in b) Evaluate the appropriateness of models used by the
methodology or assumptions. The expert
conclusion should be consistent c) Compare the findings of the expert with results produced
with other relevant audit findings by management, eg compare the fair values determined
and with the auditor’s general by the expert with those determined by management.
understanding of the business. d) Re-perform any calculations contained in the expert’s
Any inconsistencies should be working papers, eg recalculate movements in fair value on
investigated as they may indicate the derivatives.
evidence which is not reliable. e) Evaluate the assumptions used by the expert, including:
– Whether the assumptions are consistent with the
requirements of the relevant financial reporting
framework
– If the assumptions are consistent with the auditor’s
knowledge and understanding of the client’s
operations and environment.
– Verify the origin of source data used in the expert’s
work, e.g. agree figures used in calculations to the
general ledger and documentation maintained by the
client.
Page | 143
Relying on Internal Auditor’s work
Internal audit function – A function of an entity that performs assurance and consulting activities
designed to evaluate and improve the effectiveness of the entity’s governance, risk management and
internal control processes.
Direct assistance – The use of internal auditors to perform audit procedures under the direction,
supervision and review of the external auditor.
According to ISA 610 Using the Work of Internal Auditors, the external auditor may decide to use the work
of the audit client’s internal audit function to modify the nature or timing, or reduce the extent, of audit
procedures to be performed directly by the external auditor.
Note that in some jurisdictions the external auditor may be prohibited, or restricted to some extent, by
law or regulation from using the work of the internal audit function.
The firm should consider whether it is prohibited by the law or regulations from relying on the work of
internal audit department or using the internal auditors to provide direct assistance.
The firm must evaluate the internal audit department to determine whether its work is suitable by
evaluating:
1. The extent to which the internal audit function’s organisational status and relevant policies and
procedures support the objectivity of the internal auditors.
2. The level of competence of the internal audit function.
3. Whether the internal audit function applies a systematic and disciplined approach, including quality
control.
One of the key issues to be evaluated is objectivity – the internal audit department should be unbiased in
their work and be able to report their findings without being subject to the influence of others. The
internal audit department should report directly to the audit committee or to those charged with
governance in order to maintain their independence.
The Factors that may affect the external auditor’s determination include whether the internal audit
function is adequately and appropriately resourced relative to the size of the entity and the nature of its
operations. whether there are established policies for hiring, training and assigning internal auditors to
internal audit engagements and whether the internal auditors have adequate technical training and
proficiency in auditing.
In order to determine whether the internal audit department works in a systematic and disciplined way,
the firm should consider matters including the nature of documentation which is produced by the
department and whether effective quality control procedures are in place such as direction, supervision
and review of work carried out.
Page | 144
Determining Whether, in Which Areas, and to What Extent Internal Auditors Can Be Used to Provide
Direct Assistance
If the firm wants to use the internal audit function to provide direct assistance, then the firm should:
– obtain written agreement from an authorised representative of the entity that the internal auditors
will be allowed to follow the external auditor’s instructions, and that the entity will not intervene in
the work the internal auditor performs for the external auditor; and
– obtain written agreement from the internal auditors that they will keep confidential specific matters
as instructed by the external auditor and inform the external auditor of any threat to their objectivity.
If these confirmations cannot be obtained, then the internal auditors should not be used to provide direct
assistance.
The external auditor shall not use internal auditors to provide direct assistance to perform procedures
that:
(a) Involve making significant judgments in the audit;
(b) Relate to higher assessed risks of material misstatement where the judgment required in performing
the relevant audit procedures orevaluating the audit evidence gathered is more than limited
The external auditor shall direct, supervise and review the work performed by internal auditors on the
engagement.
Outsourcing
Outsourcing is when certain functions within a business are contracted out to third parties known as
service organisations.
In sourcing: In sourcing is when an organization decides to retain a centralised department for the key
function, but brings experts in from an external market on a short-term basis to account for 'peak' and
'trough' periods.
It is a business decision that is often made to maintain control of certain critical production or
competencies.
In sourcing is therefore a business practice in which work that would otherwise have been contracted out
is performed in house.
Page | 145
Impact of outsourced functions on External Audit
Key terms
Service auditor – An auditor who, at the request of the service organization, provides an assurance report
on the controls of a service organization.
Service organization – A third-party organization (or segment of a third-party organization) that provides
services to user entities that are part of those entities’ information systems relevant to financial reporting.
User auditor – An auditor who audits and reports on the financial statements of a user entity. User entity
– An entity that uses a service organization and whose financial statements are being audited.
It is increasingly common for functions such as data processing, payroll, and internal audit to be
outsourced. ISA 402 Audit Considerations Relating to Entities Using Service Organisations contains
guidance for auditors on how outsourcing should be considered during the audit process.
The matters to be considered in planning the audit approach of the outsourced function are:
– Materiality of the outsourced area
– Accessibility: the auditors do not necessarily have the right of access to books and records held at the
service organisation.
– Control risk: Extent of controls operated by service organisation; Extent of quality assurance within
the service organisation (e.g. internal audit); Degree of monitoring by client (e.g. monthly review of
records maintained by the service organisation)
– Experience of errors within the outsourced area since outsourcing commenced.
– Existence of independent records relating to the outsourced area (independent back up records
maintained by the client)’
– Compliance with the relevant laws and regulations by the service organisation
Outsourcing does have an impact on audit planning. ISA 402 Audit Considerations Relating to an Entity
Using a Service Organisation requires the auditor to obtain an understanding of how the audited entity
(also known as the user entity) uses the services of a service organisation in the user entity’s operations,
including the following matters:
1. The nature of the services provided by the service organisation and the significance of those services
to the audited entity, including the effect on internal control;
Page | 146
2. The nature and materiality of the transactions processed or accounts or financial reporting processes
affected by the service organisation;
3. The degree of interaction between the activities of the service organisation and those of the audited
entity;
4. The nature of the relationship between the audited entity and the service organisation, including the
relevant contractual terms.
The reasons for the auditor being required to understand these matters is so that any risk of material
misstatement created by the use of the service organisation can be identified and an appropriate response
planned.
The auditor is also required under ISA 402 to evaluate the design and implementation of relevant controls
at the audited entity which relate to the services provided by the service organisation, including those
which are applied to the transactions processed by the service organisation. This is to obtain
understanding of the control risk associated with the outsourced function, for example, whether the
transactions and information provided by the service organisation is monitored and whether checks are
performed prior to inclusion in the financial statements.
Information should be available from the audited entity to enable the understanding outlined above to
be obtained, for example, through reports received from the service organisation, technical manuals and
the contract between the audited entity and the service organisation.
The auditor may decide that further work is necessary in order to evaluate the risk of material
misstatement associated with the outsourcing arrangement’s impact on the financial statements. It is
common for a report on the description and design of controls at a service organisation to be obtained.
A type 1 report focuses on the description and design of controls, whereas a type 2 report also covers the
operating effectiveness of the controls. This type of report can provide some assurance over the controls
which should have operated at the service organisation.
Alternatively, the auditor may decide to contact the service organisation to request specific information,
to visit the service organisation and perform procedures, probably tests on controls, or to use another
auditor to perform such procedures. All of these methods of evaluating the service organisation’s controls
require permission from the client and can be time consuming to perform.
The purpose of obtaining the understanding above is to help the auditor to determine the level of
competence of the service organisation, and whether it is independent of the audited entity. This will then
impact on the risk of material misstatement assessed for the outsourced function.
Page | 147
Audit work: Other Information in documents containing Audited Financial Statements
Other information – Financial or non-financial information (other than financial statements and the
auditor’s report) included in an entity’s annual report/Integrated report
Misstatement of the other information – A misstatement of the other information exists when the
other information is incorrectly stated or otherwise misleading.
Reading and The auditor shall read the other information and, in doing so shall:
Considering (a) Consider whether there is a material inconsistency between the other
the Other information and the financial statements.
Information (b) Consider whether there is a material inconsistency between the other
information and the auditor’s knowledge obtained in the audit, in the context of
audit evidence obtained and conclusions reached in the audit.
Responding If the auditor identifies that a material inconsistency appears to exist (or becomes
When a aware that the other information appears to be materially misstated), the auditor
Material shall discuss the matter with management and, if
Inconsistency necessary, perform other procedures to conclude whether:
Appears to (a) A material misstatement of the other information exists;
Exist or Other (b) A material misstatement of the financial statements exists; or
Information (c) The auditor’s understanding of the entity and its environment needs to be
Appears to Be updated.
Materially
Misstated
If the auditor concludes that a material misstatement of the other information exists,
the auditor shall request management to correct the other information. If
management:
Page | 148
(a) Agrees to make the correction, the auditor shall determine that the correction
has been made; or
(b) Refuses to make the correction, the auditor shall communicate the matter with
those charged with governance and request that the correction be made.
Reporting
The auditor’s report shall include a separate section with a heading “Other Information”.
When the auditor’s report is required to include an Other Information section, this section shall include:
Page | 149
Audit work: Opening balances in initial audit engagements
( not very frequently tested so you might not see practice questions in the past exams)
Opening balances – Those account balances that exist at the beginning of the period. Opening balances
are based upon the closing balances of the prior period and reflect the effects of transactions and events
of prior periods and accounting policies applied in the prior period. Opening balances also include matters
requiring disclosure that existed at the beginning of the period, such as contingencies and commitments.
ISA 510 Initial Audit Engagements – Opening Balances requires certain audit procedures to be carried out
in an initial engagement where the prior year financial statements were not audited.
1. It is required that the auditor shall read the most recent financial statements for information relevant
to opening balances, including disclosures.
2. Then the auditor shall obtain sufficient appropriate evidence about whether the opening balances
contain misstatements that materially affect the current year’s financial statements.
– This evidence is obtained by firstly determining whether the prior period’s closing balances have
been correctly brought forward.
– The auditor shall also determine whether the opening balances reflect the application of
appropriate accounting policies.
3. Depending on the The auditor needs to consider performing one or more of the following:
nature of the – Where the prior year financial statements were audited, reviewing the
opening balances, predecessor auditor’s working papers to obtain evidence regarding the
specific audit opening balances;
procedures are – Evaluating whether audit procedures performed in the current period
performed to gain provide evidence relevant to the opening balances(***)
specific evidence
on those opening ***For current assets and liabilities, some audit evidence about opening
balances. balances may be obtained as part of the current period’s audit procedures. For
Additional example, the collection (payment) of opening accounts receivable (accounts
procedures would payable) during the current period will provide some audit evidence of their
be required if it existence, rights and obligations, completeness and valuation at the beginning
appears that the of the period. In the case of inventories, however, the current period’s audit
opening balances procedures on the closing inventory balance provide little audit evidence
contain regarding inventory on hand at the beginning of the period. Therefore,
Page | 150
misstatements that additional audit procedures may be necessary, and one or more of the
could materially following may provide sufficient appropriate audit evidence:
affect the current • Observing a current physical inventory count and reconciling it to the
period’s financial opening inventory quantities.
statements. • Performing audit procedures on the valuation of the opening inventory
items.
For non-current assets and liabilities, such as property, plant and equipment,
investments and long-term debt, some audit evidence may be obtained by
examining the accounting records and other information underlying the
opening balances. In certain cases, the auditor may be able to obtain some
audit evidence regarding opening balances through confirmation with third
parties, for example, for long-term debt and investments. In other cases, the
auditor may need to carry out additional audit procedures.
4. Finally, the auditor shall obtain sufficient appropriate evidence about whether the accounting policies
reflected in the opening balances have been consistently applied in the current period’s financial
statements, and that any changes in accounting policies have been accounted for and disclosed in
accordance with IAS 8 Accounting Policies, Changes in Accounting
When the financial statements include comparative financial information, the requirements and guidance
in ISA 710 (comparative information) also apply.
The auditor shall communicate the misstatements with the appropriate level of management and those
charged with governance.
Page | 151
Audit work on: Corresponding figures and comparatives
( not very frequently tested so you might not see practice questions in the past exams)
Corresponding figures – Comparative information where amounts and other disclosures for the prior
period are included as an integral part of the current period financial statements, and are intended to be
read only in relation to the amounts and other disclosures relating to the current period (referred to as
“current period figures”). The level of detail presented in the corresponding amounts and disclosures is
dictated primarily by its relevance to the current period figures.
Comparative financial statements – Comparative information where amounts and other disclosures for
the prior period are included for comparison with the financial statements of the current period but, if
audited, are referred to in the auditor’s opinion. The level of information included in those comparative
financial statements is comparable with that of the financial statements of the current period
Audit procedures
The auditor shall determine whether the financial statements include the comparative information
required by the applicable financial reporting framework and whether such information is appropriately
classified.
The auditor shall evaluate whether the comparative information agrees with the amounts and other
disclosures presented in the prior period or, when appropriate, have been restated
The auditor shall evaluate whether the accounting policies reflected in the comparative information are
consistent with those applied in the current period or, if there have been changes in accounting policies,
whether those changes have been properly accounted for and adequately presented and disclosed.
If the auditor becomes aware of a possible material misstatement in the comparative information while
performing the current period audit, the auditor shall perform such additional audit procedures as are
necessary in the circumstances to obtain sufficient appropriate audit evidence to determine whether a
material misstatement exists.
If the prior period financial statements are amended, the auditor shall determine that the comparative
information agrees with the amended financial statements.
The auditor shall request written representations for all periods referred to in the auditor’s opinion. The
auditor shall also obtain a specific written representation regarding any restatement made to correct a
material misstatement in prior period financial statements that affect the comparative information.
Page | 152
Audit work on: Revenue from contracts with customers
Valuation
- Client’s workings of lease liability: Recalculate. Also recalculate interest and ensure implicit interest
accounted for in accordance with IFRS 16.
- New assets matched to lease agreements
- Lease payments matched to bank statements
One of the trickiest parts of IFRS 16 is determining whether or not the contract is a lease at all. Leases may
be found in many contracts that until recently were not treated as leases, so there is a risk regarding the
completeness of leasing transactions – have any been missed out?
The definition of a lease refers to the 'right to control the use' of an asset. Determining whether there is
control involves judgment, which introduces an element of risk for the auditor. Likewise the assessment
of lease term which requires judgment where there are options for either extension or termination.
Page | 153
IFRS 16 requires lease and non-lease components to be separated from one another. For example, a lease
might be for just one part of a building, in which case it is necessary to allocate the consideration between
the part that is leased and the part that is not leased. Again, this requires judgment and is therefore risky.
Many entities will not want to recognise assets and liabilities for lease transactions, so auditors need to
be alert to the risk of distortion in relation to any of these areas of judgment.
The auditor needs to be alert to the possibility of sale and leaseback transactions. If there is a sale and
leaseback, then you need to check that gains are treated in line with IFRS 16, along with any prepayments
or additional financing.
Payroll
Substantive Analytical procedures
1. Total expense to last year and budget
2. Monthly expense to corresponding periods last year and budget
3. Proof in total: take last year’s expense, incorporate changes due to joiners and leavers and the annual
pay increase. Compare this to the actual wages and salaries in the financial statements and investigate
any significant differences.
Other procedures
1. Cast a sample of payroll records: accuracy and completeness
2. For a sample of employees:
a) Recalculate Gross pay and net pay and match to the payroll records to confirm accuracy.
b) Re-perform the calculation of statutory deductions
3. Select a sample of joiners and leavers, agree their start/leaving date to supporting documentation,
recalculate that their first/last pay packet was accurately calculated and recorded.
4. Match total NET PAY to Bank transfer list and cashbook.
5. Agree the individual wages and salaries per the payroll to the personnel records for a sample to
confirm bona fide (genuine) employees.
6. Select a sample of weekly overtime sheets and trace to overtime payment in payroll records to
confirm completeness of overtime paid
Page | 154
Audit work on: Biological Assets
(not very frequently tested so you might not see practice questions in the past exams)
Measurement
Biological assets should be measured at initial recognition, and at the end of each reporting period, at fair
value less estimated costs to sell.
Agricultural produce is measured, at the point of harvest, at fair value less estimated costs to sell at the
point of harvest.
The point of harvest represents the transition between accounting for agricultural produce assets under
IAS 41 and IAS 2.
Fair value less costs to sell at the point of harvest forms ‘cost’ for the purposes of IAS 2.
Costs to sell are incremental costs directly attributable to the disposal, excluding taxation and finance
costs, and would include commissions to brokers and dealers, levies by regulatory agencies and
commodity exchanges, and transfer taxes and duties. They exclude transport and other costs necessary
to get assets to a market (these are taken into account in arriving at fair value).
Exception: AT INITIAL recognition, if the fair value cannot be determined due to the lack of quoted market
prices or if alternative estimates of fair value are clearly unreliable, the asset is carried on the statement
of financial position at cost less any accumulated depreciation and any accumulated impairment losses
but only until such time as a fair value becomes measurable with reliability, IAS 41 contains additional
disclosure requirements in such a situation
Page | 155
The change in fair value (less costs to sell) of a biological asset between reporting dates is reported as a
gain or loss in the statement or profit or loss.
A gain or loss arising on initial recognition of agricultural produce at fair value less selling costs is included
in profit or loss for the period in which it arises.
IAS 41 requires disclosure of the aggregate gain or loss arising during the current period on initial
recognition of biological assets and agricultural produce and from the change in fair value less costs to sell
of biological assets.
Presentation
Biological assets and agricultural produce should be presented as separate line items under the following
headings:
Non-current assets
1. Property, Plant and Equipment – would include bearer plants
2. Biological assets – would include all agricultural produce to be harvested
more than 12 months from the reporting date, livestock to be held for
more than 12 months and trees cultivated for lumber and fruit.
Current assets
3. Biological assets – would include produce to be harvested within 12
months of reporting date, livestock to be slaughtered within 12 months
and annual crops e.g. wheat, maize
4. Inventories – includes the inventories produced from agricultural
produce e.g. the Tea to be sold, produced from the tea leaves
Disclosure
5. the aggregate gain or loss for the period on
a. initial recognition of biological assets
b. initial recognition of agricultural produce
c. change in fair value less estimated costs to sell of biological assets
6. a description of, and the nature of its activities involving, each group of
biological assets
7. restrictions on title, pledges and commitments in respect of biological
assets
An unconditional government grant related to a biological asset measured at its fair value less costs to sell
shall be recognised in profit or loss when the government grant becomes receivable.
Page | 156
If the government grant is conditional, including when a government grant requires an entity not to
engage in specified agricultural activity, the grant is recognised when the conditions are met.
Audit work
✓ Discuss with the management how they had estimated the fair value, the basis, the data used.
✓ Enquire from the management whether an expert has been used.
✓ Obtain written representations from management whether they believe significant assumptions used
in determining fair value are reasonable.
✓ Review quoted market prices (where available) for basis of fair value estimation.
✓ Conduct procedures on estimated costs to sell (for example, correspondence/agreement with brokers
for commission to be given, copies of laws and regulations for levies by regulatory agencies and
transfer taxes etc.)
✓ Test the operating effectiveness of the controls over how management determined the fair (for
example who reviewed and approved it)
✓ Review the F/S disclosure to ensure they are adequate and complete as per the requirements of IAS
41.
✓ Consider the need of auditor’s expert (consider whether specialized skills or knowledge is required)
✓ Recalculate gains/losses at initial recognition and changes in fair value to confirm accuracy and ensure
recorded correctly in the statement of profit or loss
✓ Review financial statements to ensure presentation (non-current assets and current assets) is
appropriate.
Page | 157
Group Audit
Group audits are frequently examined in the AAA exam and are examinable in a variety of ways across
many syllabus areas. Candidates are expected to have strong knowledge of the underlying accounting
issues and audit implications arising in a group context.
The key point to understand is that the audit process for group audits is the same as for audits of individual
financial statements. There are however additional requirements at each stage of audit that need to be
followed.
Important terms
A group may be organized in various ways. For example, a group may be organized by legal or other
entities (e.g., a parent and one or more subsidiaries, joint ventures, or investments accounted for by
the equity method).
Alternatively, the group may be organized by geography, by other economic units (including branches
or divisions), or by functions or business activities. In group audit, these different forms of organization
are collectively referred to as “entities or business units.”
Group auditor: The group engagement partner and members of the engagement team other than
component auditors. The group auditor is responsible for:
- Establishing the overall group audit strategy and group audit plan;
- Directing and supervising component auditors and reviewing their work;
- Evaluating the conclusions drawn from the audit evidence obtained as the basis for forming an
opinion on the group financial statements.
Group financial statements – Financial statements that include the financial information of more than
one entity or business unit through a consolidation process. For purposes of this ISA, a consolidation
process includes:
- Consolidation, proportionate consolidation, or an equity method of accounting;
- The presentation in combined financial statements of the financial information of entities or
business units that have no parent but are under common control or common management; or
- The aggregation of the financial information of entities or business units such as branches or
divisions.
A consolidation process involves considerations such as the elimination of intra-group transactions and
balances and, when applicable, implications of different reporting periods for entities or business units
included in the group financial statements. The term “consolidation process” as used in this ISA is not
intended to have the same meaning as “consolidation” or “consolidated financial statements” as
defined or described in financial reporting frameworks. Rather, the term “consolidation process” refers
more broadly to the process used to prepare group financial statements.
Page | 158
What is a component?
Component – An entity, business unit, function or business activity, or some combination thereof,
determined by the group auditor for purposes of planning and performing audit procedures in a group
audit.
The group auditor uses professional judgment in determining components at which audit work will be
performed. The financial information of certain entities or business units may be considered together
for purposes of planning and performing audit procedures. However, the group auditor’s responsibility
for the identification and assessment of the risks of material misstatement of the group financial
statements encompasses all of the entities and business units whose financial information is included in
the group financial statements.
Based on the understanding of the group’s organizational structure and information system, the group
auditor may determine that the financial information of certain entities or business units may be
considered together for purposes of planning and performing audit procedures. For example, a group
may have three legal entities with similar business characteristics, operating in the same geographical
location, under the same management, and using a common system of internal control, including the
information system. In these circumstances, the group auditor may decide to treat these three legal
entities as one component.
A group may also centralize activities or processes that are applicable to more than one entity or
business unit within the group, for example through the use of a shared service center. When such
centralized activities are relevant to the group’s financial reporting process, the group auditor may
determine that the shared service center is a component.
Another consideration that may be relevant to the group auditor’s determination of components is how
management has determined operating segments in accordance with the disclosure requirements of
the applicable financial reporting framework.
Component Auditor
ISA 220 (Revised) requires the engagement partner to determine that sufficient and appropriate
resources to perform the engagement are assigned or made available to the engagement team in a
timely manner. In a group audit, such resources may include component auditors. Therefore, this ISA
requires the group auditor to determine the nature, timing and extent of involvement of component
auditors.
Component auditor – An auditor who performs audit work related to a component for purposes of the
group audit. A component auditor is a part of the engagement team for a group audit.
Component auditors may be from a network firm, a firm that is not a network firm, or the group
auditor’s firm (e.g., another office within the group auditor’s firm).
Page | 159
The group auditor may involve component auditors to provide information, or to perform audit work.
Component auditors may have greater experience with, and a more in-depth knowledge of, the
components and their environments (including local laws and regulations, business practices, language,
and culture) than the group auditor. Accordingly, component auditors can be, and often are, involved
in all phases of the group audit.
When the group auditor plans to use the audit work from an audit of component financial statements
that has already been completed, there are different ways in which the group engagement partner may
take responsibility for directing and supervising component auditors and reviewing their work.
For example:
✓ Communications with component auditors throughout the course of the group audit
✓ Meetings or calls with component auditors to discuss identified and assessed risks, issues, findings
and conclusions
✓ Reviews of the component auditor’s audit documentation in person
✓ Participating in the closing or other key meetings between the component auditors and component
management.
Component management refers to management responsible for the financial information or other
activity (e.g., processing of transactions at a shared service center) at an entity or business unit that is
part of the group. When the group auditor considers the financial information of certain entities or
business units together as a component or determines that a shared service center is a component,
component management refers to the management that is responsible for the financial information or
transaction processing that is subject to the audit procedures being performed in relation to that
component. In some circumstances, there may not be separate component management and group
management may be directly responsible for the financial information or other activities of the
component
The following technical article covers the key considerations for Group Audits in the AAA exam.
The audit of group financial statements is an area frequently examined in the AAA exam. It can be tested
at any stage of the audit cycle and therefore in any section of the examination. It is important that
candidates are able to identify risks arising from aspects of group audits and the responsibility of auditors
in this regard.
ISA 600 (Revised) deals with special considerations that apply to a group audit, including when component
auditors are involved. The standard aligns the standard with recently revised standards which emphasise
the assessment of risk, including ISQM1 and ISA 220 (Revised) and ISA 315 (Revised 2019). There is
increased emphasis on the responsibilities of auditors s relating to professional scepticism; planning and
Page | 160
performing a group audit; two-way communications between the group auditor and component auditors;
and documentation.
ISA 600 (Revised) sets out the responsibilities of the group auditor for providing the audit opinion on the
group financial statements, including components of such as subsidiaries, associates, joint ventures and
non-controller entities.
The components may be audited by the group auditor or may be audited by a different firm of auditors
known as the ‘component auditors’. The group auditor will provide an opinion on the consolidated
financial statements, it is therefore essential that they are satisfied with work completed by component
auditors or local audit teams. The group auditor will form an opinion on the parent company’s individual
financial statements.
It is important for students to note that under the risk-based approach, component auditors can be, and
often are, involved in all stages of the group audit.
Exam focus
Students may be required to recognise the specific matters to be considered before accepting
appointment as group auditor in a given situation.
The specific circumstances highlighted in the scenario should be considered and may include:
• The components where audit work will be performed.
• The resources needed to perform the group audit at those components.
• Any specific risks relevant in the scenario.
Where the group audit involves component auditors the group engagement partner should consider:
• Confirmation of co-operation of the component auditors.
• Awareness of the component auditors of the relevant ethical requirements of the group audit
engagement.
• Determination of the appropriate competence and capabilities of the component auditors.
Whereas a majority of examination questions are from the perspective of the group auditor, there may
also be the requirement to explain the responsibilities of the component auditor before accepting
appointment, and the procedures to be performed in a group situation.
Page | 161
2. Group audit planning
Students can reasonably be expected to identify and describe the matters to be considered and the
procedures to be performed at the planning stage, when a group auditor considers the use of the work of
component auditors.
Exam focus
Section A of the AAA examination may include a scenario involving an existing group or a company making
an acquisition to become a group for the first time. One of the first steps would be to decide at which
components group audit work should be performed.
ISA 600 (Revised) does not specify a qualitative benchmark to determine and therefore greater judgement
is required when determining the components at which to perform audit work.
Examples of matters that may influence the group auditor’s determination include, but are not limited to:
• The nature of events or conditions that may give rise to risks of material misstatement at the assertion
level of the group financial statements that are associated with a component, for example:
• The risk of not being able to obtain sufficient appropriate audit evidence from the component.
• The nature and extent of misstatements or control deficiencies identified at a component in prior
period audits.
Group audit planning questions may require the explanation of matters including:
• assessment of group and component materiality
• the impact of non-coterminous year ends within a group
• changes in group structure or a complex group structure.
The group auditor shall determine component materiality above which misstatements identified in the
component financial information are to be communicated to the group auditor. Setting component
materiality is a matter for group auditors, because they provide the audit opinion on the consolidated
group financial statements. This may differ from materiality set at group level.
Page | 162
3. Communication with component auditors
ISA 600 (Revised) strengthens and clarifies the importance of two-way communication throughout the
whole audit process between the group auditor and the component auditors. The standard specifies the
following areas as required areas of contact:
• Communication of the financial information on which the component auditor has been requested to
perform audit procedures
• Whether the component auditor has performed the work requested by the group auditor
• Compliance with relevant ethical requirements by the component auditor
• Information about instances of non-compliance with laws or regulations
• Corrected and uncorrected misstatements of the component financial information identified by the
component auditor
• Indicators of possible management bias
• Description of any deficiencies in the system of internal control
• Fraud or suspected fraud involving component management
• Other significant matters that the component auditor communicated or expects to communicate to
component management or Those Charged with Governance of the component
• Any other matters that may be relevant to the group audit
• The component auditor’s overall findings or conclusions.
Exam focus
Candidates might be expected to identify specific weaknesses or risks arising in the consolidation process.
For example:
• Differences in reporting dates which may cause a risk of inappropriate figures being included in the
consolidation for a component
• A client producing group accounts for the first time may have increased inherent and control risk
arising from a lack of experience.
The group auditor must plan the audit procedures to be performed on the consolidation process. For
some groups, the consolidation will be complex and is likely to involve some areas of judgement and so
there is a high degree of audit risk. Thorough planning will be essential to ensure that audit risk is
minimised.
Page | 163
The group auditor will require an understanding of the group-wide controls relevant to the consolidation
process, for example the instructions issued to components by management. The group auditor will need
to assess the adequacy of such controls and their operating effectiveness in determining whether reliance
can be placed upon those controls in determining the nature, extent and timing of procedures on the
consolidation.
Candidates should be confident in their knowledge of the relevant group financial reporting standards,
which include IFRS® 3 Business Combinations, IAS® 28 Investments in Associates and Joint Ventures, IFRS
9 Financial Instruments, IAS 32 Financial Instruments: Presentation
Page | 164
Some of the evidence required to meet the above objectives will be gathered by the component auditor,
and it is the group auditor’s responsibility to communicate to the component auditor the evidence which
they are expected to gather. This communication ideally occurs at the audit planning stage.
Exam focus
Candidates may be required to assess the audit work performed by a component auditor:
The results of component auditor’s work could also be considered in a quality management
question. The responsibilities to review, supervise and direct the work completed by component
auditors, and applying professional scepticism to the conclusions made by the group audit engagement
partner, would be under scrutiny. Recommendations for improvements in firm wide procedures may be
requested, in line with the requirements of ISQM1.
A completion question may require candidates to evaluate whether sufficient appropriate audit
evidence has been obtained with regards to the group financial statements in order to determine an
appropriate audit opinion. Candidates may also be asked to identify matters to communicate to
management or to Those Charged with Governance or to assess ethical and professional issues in a
group context.
Page | 165
Examples of Conditions or Events that May Indicate Risks of Material Misstatement of the Group
Financial Statements
The examples provided cover a broad range of conditions or events; however, not all conditions or events
are relevant to every group audit engagement and the list of examples is not necessarily complete.
• A complex group structure, especially where there are frequent acquisitions, disposals or
reorganizations.
• Poor corporate governance structures, including decision-making processes, that are not transparent.
• Non-existent or ineffective group-wide controls, including inadequate group management
information on monitoring of components’ operations and their results.
• Components operating in foreign jurisdictions that may be exposed to factors such as unusual
government intervention in areas such as trade and fiscal policy, and restrictions on currency and
dividend movements; and fluctuations in exchange rates.
• Business activities of components that involve high risk, such as long-term contracts or trading in
innovative or complex financial instruments.
• Uncertainties regarding which components’ financial information require incorporation in the group
financial statements in accordance with the applicable financial reporting framework, for example,
whether any special-purpose entities or non-trading entities exist and require incorporation.
• Unusual related party relationships and transactions.
• Prior occurrences of intra-group account balances that did not balance or reconcile on consolidation.
• The existence of complex transactions that are accounted for in more than one component.
• Components’ application of accounting policies that differ from those applied to the group financial
statements.
• Components with different financial year-ends, which may be utilized to manipulate the timing of
transactions.
• Prior occurrences of unauthorized or incomplete consolidation adjustments.
• Aggressive tax planning within the group, or large cash transactions with entities in tax havens.
• Frequent changes of auditors engaged to audit the financial statements of components.
Page | 166
‘Support letters’
Tutorial note: Although there are different types and uses of such letters (eg for registering a prospectus),
the only reference to them in the THE ADVANCED AUDIT & ASSURANCE EXAM Syllabus and Study Guide
is in the context of group audits.
Consolidated financial statements are prepared on a going concern basis when a group, as a single entity,
is considered to be a going concern. However, the going concern basis may only be appropriate for certain
separate legal entities (e.g. subsidiaries) because the parent undertaking (or a fellow subsidiary) is able
and willing to provide support. Many banks routinely require a letter of reassurance from a parent
company stating that the parent would financially or otherwise support a subsidiary with cash flow or
other operational problems.
As audit evidence:
• Formal confirmation of the support will be sought in the form of a letter of support or ‘comfort letter’
confirming the parent company’s intention to keep the subsidiary in operational existence (or
otherwise meet its obligations as they fall due).
• The letter of support should normally be approved by a board minute of the parent company (or by
an individual with authority granted by a board minute).
• The ability of the parent to support the company should also be confirmed, for example, by examining
the group’s cash flow forecast.
• The period of support may be limited (eg to one year from the date of the letter or until the date of
disposal of the subsidiary). Sufficient other evidence concerning the appropriateness of the going
concern assumption must therefore be obtained where a later repayment of material debts is
foreseen.
• The fact of support and the period to which it is restricted should be noted in the financial statements
of the subsidiary.
Page | 167
Transnational Audit
Transnational audit means an audit of financial statements which are or may be relied upon outside the
audited entity’s home jurisdiction for the purpose of significant lending, investment or regulatory
decisions.
Examples: Private company in UK raising debt finance in Canada; International charity taking donations
through various national branches and making grants around the world; Project financial statements for
the construction of an electrical generation facility in Nigeria using funds loaned by World Bank
[Link] and oversight of auditors: Similar to the previous comments on the use of ISAs, across the
world there are many different ways in which the activities of auditors are regulated and monitored. In
some countries the audit profession is self-regulatory, whereas in other countries a more legislative
approach is used. This also can impact on the quality of audit work in a transnational situation.
[Link] reporting framework: Some countries use International Financial Reporting Standards,
whereas some use locally developed accounting standards. Within a transnational group it is likely that
adjustments, reconciliations or restatements may be required in order to comply with the requirements
of the jurisdictions relevant to the group financial statements (i.e. the jurisdiction of the parent company
in most cases). Such reconciliations can be complex and require a high level of technical expertise of the
preparer and the auditor.
4. Corporate governance requirements and consequent control risk: In some countries there are very
prescriptive corporate governance requirements, which the auditor must consider as part of the audit
process. In this case the auditor may need to carry out extra work over and above local requirements in
order to ensure group wide compliance with the requirements of the jurisdictions relevant to the financial
statements. However, in some countries there is very little corporate governance regulation at all and
controls are likely to be weaker than in other components of the group. Control risk is therefore likely to
differ between the various subsidiaries making up the group.
Page | 168
JOINT AUDIT
A joint audit is when two or more audit firms are jointly responsible for giving the audit opinion. This is
very common in a group situation where the principal auditor is appointed jointly with the auditor of a
subsidiary to provide a joint opinion on the subsidiary’s financial statements.
Advantages
It can be beneficial in terms of audit efficiency for a joint audit to be conducted, especially in the case of
a new subsidiary. A joint audit will allow sufficient resources to be allocated to the audit, assuring the
quality of the opinion provided.
If there is a tight deadline, as is common with the audit of subsidiaries, which should be completed before
the group audit commences, then having access to two firms’ resources should enable the audit to be
completed in good time. The audit should also benefit from an improvement in quality. The two audit
firms may have different points of view, and would be able to discuss contentious issues throughout the
audit process. Joint audits increase competition in the profession. In particular, joint audits have been
proposed as a way for ‘mid tier’ audit firms to break into the market of auditing large companies and
groups, which at the moment is monopolized by the ‘Big 4’.
Disadvantages
For the client, it is likely to be more expensive to engage two audit firms than to have the audit opinion
provided by one firm.
From a cost/benefit point of view there is clearly no point in paying twice for one opinion to be provided.
Despite the audit workload being shared, both firms will have a high cost for being involved in the audit
in terms of senior manager and partner time.
These costs will be passed on to the client within the audit fee. The two audit firms may use very different
audit approaches and terminology. This could make it difficult for the audit firms to work closely together,
negating some of the efficiency and cost benefits discussed above. Problems could arise in deciding which
firm’s method to use, for example, to calculate materiality, design and pick samples for audit procedures,
or evaluate controls within the accounting system. It may be impossible to reconcile two different
methods and one firm’s methods may end up dominating the audit process, which then eliminates the
benefit of a joint audit being conducted. It could be time consuming to develop a ‘joint’ audit approach,
based on elements of each of the two firms’ methodologies, time which obviously would not have been
spent if a single firm was providing the audit
Potentially, problems could arise in terms of liability. In the event of litigation, because both firms have
provided the audit opinion, it follows that the firms would be jointly liable. The firms could blame each
other for any negligence which was discovered, making the litigation process more complex than if a single
audit firm had provided the opinion. However, it could be argued that joint liability is not necessarily a
drawback, as the firms should both be covered by professional indemnity insurance.
Page | 169
The Review Stage of Audit
Overall Review
Before the audit report is signed, the auditor needs to know that the work is finished and that all necessary
issues have been dealt with. The easiest way to do this is to use a series of checklists:
• The audit plan should be reviewed, to verify that all issues raised have been resolved.
• An Accounting Standards Checklist will be completed, forcing the auditor to consider every possible
accounting issue that could affect the client’s Financial Statements.
• Additional checklists may be necessary (e.g. Company Law) to make sure that any other issues have
been fully considered
All audit work should be subject to review. This is a basic quality management requirement and serves to
ensure that sufficient appropriate audit evidence has been obtained in respect of transactions and
balances included in the financial statements.
In performing a file review, the reviewer should consider the sufficiency of evidence obtained and may
need to propose further audit procedures if evidence is found to be insufficient or contradictory. ISA 230,
Audit Documentation requires that documentation of the review process includes who reviewed the
audit work completed and the date and extent of such review.
Typically, the auditor will present the client with a list of misstatements (often referred to as the ‘audit
error schedule’), quantifying the amount of each misstatement, and proposing the necessary adjustment
to the financial statements. The proposed adjustment may be in the form of a journal entry, an
amendment to the presentation of the financial statements, or a correction to a disclosure note. When
management makes the necessary adjustments to the financial statements, the auditor should confirm
that the adjustments have been made correctly.
One of the objectives of the auditor in complying with ISA 520 (analytical procedures) is to design and
perform analytical procedures near the end of the audit that assist in forming an overall conclusion as
to whether the financial statements are consistent with the auditor’s understanding of the entity.
Page | 170
The analytical procedures performed at this stage of the audit are not different to those performed at the
planning stage – the auditor will perform ratio analysis, comparisons with prior period financial
statements and other techniques to confirm that trends are as expected, and to highlight unusual
transactions and balances that may indicate a risk of misstatement.
The key issue is that, near the end of the audit, the auditor should have sufficient audit evidence to explain
the issues highlighted by analytical procedures, and should therefore be able to conclude as to the overall
reasonableness of the financial statements.
When the analytical procedures performed near the end of the audit reveal further previously un-
recognized risk of material misstatement, the auditor is required to revise the previously assessed risk
of material misstatement and modify the planned audit procedures accordingly. This means potentially
performing further audit procedures in relation to matters that are identified as high risk.
As well as reviewing the main elements of the financial statements, the auditor must at this stage carefully
review the notes to the financial statements for completeness and compliance with the applicable
financial reporting framework. In many situations, this will be the first opportunity for the auditor to
review this information, as clients often prepare the notes to the financial statements towards the end of
the audit process.
At this stage, the auditor should also read the other information to be issued with the financial
statements for consistency with the financial statements.
This is important as inconsistencies may have implications for the auditor’s report. Specific items of other
information are subject to specific regulation in some jurisdictions – for example, in the UK and Ireland
the auditor’s report must state whether the Directors’ Report is consistent with the financial statements.
Page | 171
Going Concern Review
When the use of the going concern basis of accounting is appropriate, assets and liabilities are recorded
on the basis that the entity will be able to realize its assets and discharge its liabilities in the normal course
of business.
Management’s Responsibilities
Management should assess going concern in order to decide on the most appropriate basis for the
preparation of the financial statements.
IAS 1 Presentation of Financial Statements (revised) requires that where there is significant doubt over an
entity’s ability to continue as a going concern, the uncertainties should be disclosed in a note to the
financial statements.
Where the directors intend to cease trading, or have no realistic alternative but to do so, the financial
statements should be prepared on a ‘break up’ basis.
Thus the main focus of the management’s assessment of going concern is to ensure that relevant
disclosures are made where necessary, and that the correct basis of preparation is used.
Auditor’s Responsibilities
The auditor’s responsibility is to consider the appropriateness of the management’s use of the going
concern assumption in the preparation of the financial statements and to consider whether there are
material uncertainties about the entity’s ability to continue as a going concern that need to be disclosed
in a note.
The auditor should also consider the length of the time period that management have looked at in their
assessment of going concern.
The auditor will therefore need to come to an opinion as to the going concern status of an entity but the
focus of the auditor’s evaluation of going concern is to see whether they agree with the assessment made
by the management ( whether they agree with the basis of preparation of the financial statements, or the
inclusion in a note to the financial statements, as required by IAS 1, of any material uncertainty).
Page | 172
Indicators of going concern problems
Events or Conditions That May Cast Significant Doubt on the Entity’s Ability to Continue as a Going Concern
Financial
• Net liability or net current liability position.
• Fixed-term borrowings approaching maturity without realistic prospects of renewal or repayment; or
excessive reliance on short-term borrowings to finance long-term assets.
• Indications of withdrawal of financial support by creditors
• Negative operating cash flows indicated by historical or prospective financial statements.
• Adverse key financial ratios.
• Substantial operating losses or significant deterioration in the value of assets used to generate cash
flows.
• Arrears or discontinuance of dividends.
• Inability to pay creditors on due dates.
• Inability to comply with the terms of loan agreements.
• Change from credit to cash-on-delivery transactions with suppliers.
• Inability to obtain financing for essential new product development or other essential investments.
Operating
• Management intentions to liquidate the entity or to cease operations.
• Loss of key management without replacement.
• Loss of a major market, key customer(s), franchise, license, or principal supplier(s).
• Labor difficulties.
• Shortages of important supplies.
• Emergence of a highly successful competitor.
Other
• Non-compliance with capital or other statutory or regulatory requirements, such as solvency or
liquidity requirements for financial institutions.
• Pending legal or regulatory proceedings against the entity that may, if successful, result in claims that
the entity is unlikely to be able to satisfy.
• Changes in law or regulation or government policy expected to adversely affect the entity.
• Uninsured or underinsured catastrophes when they occur
The significance of such events or conditions often can be mitigated by other factors.
For example, the effect of an entity being unable to make its normal debt repayments may be counter-
balanced by management’s plans to maintain adequate cash flows by alternative means, such as by
disposing of assets, rescheduling loan repayments, or obtaining additional capital.
Page | 173
Similarly, the loss of a principal supplier may be mitigated by the availability of a suitable alternative
source of supply.
These risk assessment procedures are likely to be an important issue and have an impact on planning the
audit. These procedures allow for more timely discussions with management, including a discussion of
management’s plans and resolution of any identified going concern issues.
Auditor’s procedures
When going concern problems are discovered, the auditor is required by IAS 570 to carry out additional
procedures.
If events or conditions have been identified that may cast significant doubt on the entity’s ability to
continue as a going concern, the auditor shall obtain sufficient appropriate audit evidence to determine
whether or not a material uncertainty exists related to events or conditions that may cast significant doubt
on the entity’s ability to continue as a going concern through performing additional audit procedures,
including consideration of mitigating factors.
These procedures shall include:
Where management has not - Analyzing and discussing cash flow, profit and other relevant
yet performed an assessment forecasts with management.
of the entity’s ability to - Analyzing and discussing the entity’s latest available interim
continue as a going concern, financial statements.
requesting management to - Reading the terms of debentures and loan agreements and
make its assessment. determining whether any have been breached.
- Reading minutes of the meetings of shareholders, those charged
Their assessment is then with governance and relevant committees for reference to
evaluated. financing difficulties.
- Inquiring of the entity’s legal counsel regarding the existence of
litigation and claims and the reasonableness of management’s
assessments of their outcome and the estimate of their financial
implications.
- Confirming the existence, legality and enforceability of
arrangements to provide or maintain financial support with related
and third parties and assessing the financial ability of such parties
to provide additional funds.
- Evaluating the entity’s plans to deal with unfilled customer orders.
- Performing audit procedures regarding subsequent events to
identify those that either mitigate or otherwise affect the entity’s
ability to continue as a going concern.
Page | 174
- Confirming the existence, terms and adequacy of borrowing
facilities.
- Obtaining and reviewing reports of regulatory actions.
- Determining the adequacy of support for any planned disposals of
assets
- Analyzing and discussing cash flow, profit and other relevant
forecasts
Evaluating Management’s Evaluating management’s plans for future actions may include inquiries
Plans for Future Actions of management as to its plans for future action, including, for example,
its plans to liquidate assets, borrow money or restructure debt, reduce
or delay expenditures, or increase capital.
Written Representations The auditor may consider it appropriate to obtain specific written
representations in support of audit evidence obtained regarding
management’s plans for future actions in relation to its going concern
assessment and the feasibility of those plans.
Page | 175
In auditor’s judgment, appropriate determines that the other basis of accounting is
disclosure of the nature and implications acceptable in the circumstances.
of the uncertainty is necessary.
Page | 176
opinion is not
modified in respect
of the matter.
Example
Material
Uncertainty
Related to Going
Concern
We draw attention
to Note 6 in the F/S,
which indicates
that the Company
incurred a net loss
of ZZZ during the
year ended
December 31, 20X1
and, as of that date,
the Company’s
current liabilities
exceeded its total
assets by YYY. As
stated in Note 6,
these events or
conditions, along
with other matters
as set forth in Note
6, indicate that a
material
uncertainty exists
that may cast
significant doubt on
the Company’s
ability to continue
as a going concern.
Our opinion is not
modified in respect
of this matter.
Page | 177
Subsequent Events Review
Subsequent events are defined as those events occurring between the date of the financial statements
and the date of the auditor’s report, and also facts discovered after the date of the auditor’s report.
The auditor has an active duty to perform audit procedures designed to identify, and to obtain sufficient
appropriate evidence of all events up to the date of the auditor’s report that may require adjustment of,
or disclosure in, the financial statements.
These procedures should be performed as close as possible to the date of the auditor’s report, and in
addition, representations would be sought on the date that the report was signed.
Page | 178
– Reading the entity’s latest subsequent interim financial statements, if any
– The auditor shall request management and, where appropriate, those charged with governance, to
provide a written representation that all events occurring subsequent to the date of the financial
statements and for which the applicable financial reporting framework requires adjustment or
disclosure have been adjusted or disclosed.
Where a material subsequent event is discovered, the auditor should consider whether management have
properly accounted for and disclosed the event in the financial statements in accordance with IAS 10
Events After the Reporting Period.
Facts discovered after the date of the auditor’s report but before the date the financial statements are
issued.
The auditor does not have any responsibility to perform audit procedures or make any enquiry regarding
the financial statements or subsequent events after the date of the auditor’s report.
In this period, it is the responsibility of management to inform the auditor of facts which may affect the
financial statements.
When the auditor becomes aware of a fact which may materially affect the financial statements, the
matter should be discussed with management.
If the financial statements are appropriately amended then a new audit report should be issued, and
procedures relating to subsequent events should be extended to the date of the new audit report.
If management do not amend the financial statements to reflect the subsequent event, in circumstances
where the auditor believes they should be amended, a qualified or adverse opinion of disagreement
should be issued.
After the financial statements have been issued, the auditor has no obligation to perform any audit
procedures regarding such financial statements. However, if, after the financial statements have been
issued, a fact becomes known to the auditor that, had it been known to the auditor at the date of the
auditor’s report, may have caused the auditor to amend the auditor’s report, the auditor shall:
(a) Discuss the matter with management and, where appropriate, those charged with governance;
(b) Determine whether the financial statements need amendment; and, if so,
(c) Inquire how management intends to address the matter in the financial statements.
Page | 179
Communicating with Those Charged with Governance
Auditor’s responsibilities in - Forming and expressing an opinion on the F/S (in accordance with
relating to F/S ISAs)
- Auditor’s responsibility to determine and communicate KAM
- This does not relieve the management and TCWG of their
responsibilities re F/S
Planned scope and timing - Significant risks identified by the auditor and how auditor plans to
of audit address them
- Auditor’s approach to internal control relevant to audit
- Application of concept of materiality
- Use of auditor’s expert (if needed)
- If applicable, discussion about planned use of internal auditor’s work
- Discussions about entity’s objectives, strategies, related business
risks
Significant findings from the - Auditor’s views about accounting policies, accounting estimates, F/S
audit disclosures
- Significant difficulties encountered during the audit (delays in
receiving information, unavailability of info etc.)
- Significant weaknesses/deficiencies in internal control and
recommendations for improvement (important: significant
deficiencies are those which have caused a material fraud/error in
the f/s OR can cause material problems in the f/s in the future)
- Significant matters that were discussed with the management
- Written representations that the auditor is requesting
- Circumstances that affect form and content of auditors report ( for
example modified opinion, KAM, EOMP etc.)
- Audit adjustments, whether or not recorded by the entity, that have,
or could have, a material effect on the entity’s financial statements.
For example, the bankruptcy of a material receivable shortly after
the year-end that should result in an adjusting entry.
Auditor independence - Auditor has complied with relevant ethical requirements
(listed companies) - All relationships that may have an impact on independence (
including total fee charged during the period for audit and non-audit
services)
- Safeguards that have been applied to eliminate or reduce these
threats
Page | 180
Key Audit Matters
Key audit matters: Those matters that, in the auditor’s professional judgment, were of most significance
in the audit of the financial statements of the current period. Key audit matters are selected from matters
communicated with those charged with governance.
Objectives: The objectives of the auditor are to determine key audit matters and, having formed an
opinion on the financial statements, communicate those matters by describing them in the auditor’s
report.
Determining KAM
The auditor shall determine, from the matters communicated with those charged with governance, those
matters that required significant auditor attention in performing the audit. In making this determination,
the auditor shall take into account the following:
1. Areas of higher assessed risk of material misstatement, or significant risks identified in accordance
with ISA 315 (Revised).
2. Significant auditor judgments relating to areas in the financial statements that involved significant
management judgment, including accounting estimates that have been identified as having high
estimation uncertainty.
3. The effect on the audit of significant events or transactions that occurred during the period.
4. Other considerations
Areas of higher assessed ISA 260 (Revised) requires the auditor to communicate with those charged
risk of material with governance about the significant risks identified by the auditor.
misstatement, or
significant risks The auditor may also communicate with those charged with governance
identified in accordance about how the auditor plans to address areas of higher assessed risks of
with ISA 315 (Revised). material misstatement.
ISA 315 (Revised) explains that the auditor’s assessment of the risks of
material misstatement at the assertion level may change during the course
of the audit as additional audit evidence is obtained. Revision to the
auditor’s risk assessment and re-evaluation of the planned audit procedures
with respect to a particular area of the financial statements (i.e., a significant
change in the audit approach, for example, if the auditor’s risk assessment
was based on an expectation that certain controls were operating effectively
and the auditor has obtained audit evidence that they were not operating
effectively throughout the audit period, particularly in an area with higher
assessed risk of material misstatement) may result in an area being
determined as one requiring significant auditor attention.
Page | 181
Significant auditor ISA 260 (Revised) requires the auditor to communicate with those charged
judgments relating to with governance the auditor’s views about significant qualitative aspects of
areas in the financial the entity’s accounting practices, including accounting policies, accounting
statements that estimates and financial statement disclosures.
involved significant
management judgment, In many cases, this relates to critical accounting estimates and related
including accounting disclosures, which are likely to be areas of significant auditor attention, and
estimates that have also may be identified as significant risks.
been identified as
having high estimation
uncertainty.
The effect on the audit Events or transactions that had a significant effect on the financial
of significant events or statements or the audit may be areas of significant auditor attention and
transactions that may be identified as significant risks.
occurred during the
period. For example, the auditor may have
had extensive discussions with management and those charged with
governance at various stages throughout the audit about the effect on the
financial statements of significant transactions with related parties or
significant transactions that are outside the normal course of business for
the entity or that otherwise appear to be unusual.
Page | 182
• The nature and materiality, quantitatively or qualitatively, of corrected
and accumulated uncorrected misstatements due to fraud or error
related to the matter, if any.
• The nature and extent of audit effort needed to address the matter,
including:
✓ The extent of specialized skill or knowledge needed to apply audit
procedures to address the matter or evaluate the results of those
procedures, if any.
✓ The nature of consultations outside the engagement team
✓ regarding the matter.
The introductory language in this section of the auditor’s report shall state that:
a) Key audit matters are those matters that, in the auditor’s professional judgment, were of most
significance in the audit of the financial statements [of the current period]; and
b) These matters were addressed in the context of the audit of the financial statements as a whole, and
in forming the auditor’s opinion thereon, and the auditor does not provide a separate opinion on
these matters.
The auditor shall not communicate a matter in the Key Audit Matters section of the auditor’s report when
the auditor would be required to modify the opinion in accordance with ISA 705 (Revised) as a result of
the matter.
Page | 183
Descriptions of Individual Key Audit Matters
The description of each key audit matter in the Key Audit Matters section of the auditor’s report shall
include a reference to the related disclosure(s),
Interaction between Descriptions of Key Audit Matters and Other Elements Required to Be Included in
the Auditor’s Report
A matter giving rise to a modified opinion in accordance with ISA 705 (Revised), or a material uncertainty
related to events or conditions that may cast significant doubt on the entity’s ability to continue as a going
concern in accordance with ISA 570 (Revised), are by their nature key audit matters.
However, in such circumstances, these matters shall not be described in the Key Audit Matters section of
the auditor’s report. Rather, the auditor shall:
(a) Report on these matter(s) in accordance with the applicable ISA(s);
and
(b) Include a reference to the Basis for Qualified (Adverse) Opinion or the Material Uncertainty Related
to Going Concern section(s) in the Key Audit Matters section.
Form and Content of the Key Audit Matters Section in Other Circumstances
If the auditor determines, depending on the facts and circumstances of the entity and the audit, that there
are no key audit matters to communicate, the auditor shall include a statement to this effect in a separate
section of the auditor’s report under the heading “Key Audit Matters.”
Page | 184
Evaluation of Misstatements
During the completion stage of the audit, the effect of uncorrected misstatements must be evaluated by
the auditor.
If the management refuses to correct some or all of the misstatements communicated by the auditor, the
auditor needs to obtain an understanding of management’s reasons for not making the corrections and
should take that understanding into account when evaluating whether the financial statements as a whole
are free from material misstatement. Therefore a discussion with management is essential in helping the
auditor to form an audit opinion.
The auditor needs to communicate with those charged with governance about uncorrected
misstatements and the effect that they, individually or in aggregate, may have on the opinion in the
auditor’s report.
Page | 185
Auditor’s work
– The auditor shall communicate on a timely basis all misstatements accumulated during the audit with
the appropriate level of management, unless prohibited by law or regulation. The auditor shall
request management to correct those misstatements.
– If management refuses to correct some or all of the misstatements communicated by the auditor, the
auditor shall obtain an understanding of management’s reasons for not making the corrections and
shall take that understanding into account when evaluating whether the financial statements as a
whole are free from material misstatement
– Prior to evaluating the effect of uncorrected misstatements, the auditor shall reassess materiality
determined in accordance with ISA 320 to confirm whether it remains appropriate in the context of
the entity’s actual financial results.
– The auditor shall determine whether uncorrected misstatements are material, individually or in
aggregate. In making this determination, the auditor shall consider:
(a) The size and nature of the misstatements
(b) The effect of uncorrected misstatements related to prior periods
The auditor shall communicate with those charged with governance uncorrected misstatements and the
effect that they, individually or in aggregate, may have on the opinion in the auditor’s report, unless
prohibited by law or regulation.
The auditor shall request a written representation from management and, where appropriate, those
charged with governance whether they believe the effects of uncorrected misstatements are immaterial,
individually and in aggregate, to the financial statements as a whole. A summary of such items shall be
included in or attached to the written representation.
In the AAA Exam, as a part of a completion and review question, you may be asked to evaluate the
appropriateness of the engagement quality reviewer in a given scenario and recommend further actions
which may be taken within the firm.
Page | 186
Audit Opinion & Audit Report
Exam Technique
Questions in AAA will often ask students to evaluate, as part of the final review, the matters the auditor
would consider and audit evidence he would obtain to confirm if sufficient and appropriate evidence has
been obtained with regards to the scenario given.
And THEN write further audit procedures that the auditor would perform at this stage to gather sufficient
appropriate evidence regarding that matter.
The requirement may then go on to ask for the impact on the audit opinion AND the audit report if these
issues are not resolved.
Remember, Opinion would either be unmodified or modified (qualified OR adverse OR disclaimer). There
is no other type of opinion!
Impact on report means the student is expected to consider any additional paragraphs that may be
needed AND changes to the audit report due to the unresolved issues above.
Audit Opinion
Unmodified opinion
Auditor concludes that the financial statements are prepared, in all material respects, in accordance
with the applicable financial reporting framework.
Page | 187
Page | 188
Additional Paragraphs in the Audit Report (if needed)
It is important to note that these do not impact the wording of the opinion and do not constitute either
a qualified, adverse or disclaimer of opinion.
This is included when there is a material uncertainty regarding the going concern status which the
directors have correctly disclosed in the financial statements and the disclosure is adequate and
complete. The auditor uses this section to draw the attention of the user to the client's disclosure note.
Key terms
The auditor cannot obtain sufficient appropriate audit evidence on which to base the opinion. The
auditor’s inability to obtain sufficient appropriate audit evidence is also referred to as a limitation on the
scope of the audit and could arise from:
➢ Circumstances beyond the entity’s control (e.g. accounting records destroyed)
Page | 189
➢ Circumstances relating to the nature or timing of the auditor’s work (e.g. the timing of the auditor’s
appointment prevents the observation of the physical inventory count).
➢ Limitations imposed by management (e.g. management prevents the auditor from requesting
external confirmation of specific account balances).
Pervasiveness
Pervasive – A term used, in the context of misstatements, to describe the effects on the financial
statements of misstatements or the possible effects on the financial statements of misstatements, if any,
that are undetected due to an inability to obtain sufficient appropriate audit evidence. Pervasive effects
on the financial statements are those that, in the auditor’s judgment:
(i) Are not confined to specific elements, accounts or items of the financial statements;
(ii) If so confined, represent or could represent a substantial proportion of the financial statements;
or
(iii) In relation to disclosures, are fundamental to users’ understanding of the financial statements.
Pervasiveness is a matter that confuses many candidates as; once again, it is a matter that requires
professional judgment. In this case the judgment is whether the matter is isolated to specific components
of the financial statements, or whether the matter pervades many elements of the financial statements,
rendering them unreliable as a whole.
The bottom line is that if the auditor believes that the financial statements may be relied upon in some
part for decision making then the matter is material and not pervasive. If, however, they believe the
financial statements should not be relied upon at all for making decisions then the matter is pervasive.
The auditor shall form an opinion on whether the financial statements are prepared, in all material
respects, in accordance with the applicable financial reporting framework in particular, the auditor shall
evaluate whether, in view of the requirements of the applicable financial reporting framework:
a) The financial statements adequately disclose the significant accounting policies selected and applied;
Page | 190
b) The accounting policies selected and applied are consistent with the applicable financial reporting
framework and are appropriate;
c) The accounting estimates made by management are reasonable;
d) The information presented in the financial statements is relevant, reliable, comparable, and
understandable;
e) The financial statements provide adequate disclosures to enable the intended users to understand
the effect of material transactions and events on the information conveyed in the financial
statements; and
f) The terminology used in the financial statements, including the title of each financial statement, is
appropriate.
Unmodified opinion: The auditor shall express an unmodified opinion when the auditor concludes that
the financial statements are prepared, in all material respects, in accordance with the applicable financial
reporting framework.
There are three types of modified opinions, namely, a qualified opinion, an adverse opinion, and a
disclaimer of opinion.
The decision regarding which type of modified opinion is appropriate depends upon:
(a) The nature of the matter giving rise to the modification, that is, whether the financial statements are
materially misstated or, in the case of an inability to obtain sufficient appropriate audit evidence, may
be materially misstated; and
(b) The auditor’s judgment about the pervasiveness of the effects or possible effects of the matter on the
financial statements.
Page | 191
Determining the Type of Modification to the Auditor’s Opinion
Form and Content of the Auditor’s Report
When the Opinion Is Modified
Qualified The auditor shall express a qualified the auditor shall use the heading “Qualified
Opinion opinion when: Opinion,”
(a) The auditor, having obtained
sufficient appropriate audit the auditor shall state in the opinion
evidence, concludes that paragraph that, in the auditor’s opinion,
misstatements, individually or in the except for the effects of the matter(s)
aggregate, are material, but not described in the Basis for Qualified Opinion
pervasive, to the financial paragraph:
statements; or (a) The financial statements present fairly, in
(b) The auditor is unable to obtain all material respects (or give a true and
sufficient appropriate audit evidence fair view) in accordance with the
on which to base the opinion, but the applicable financial reporting framework
auditor concludes that the possible when reporting in accordance with a fair
effects on the financial statements of presentation framework; or
undetected misstatements, if any, (b) The financial statements have been
could be material but not pervasive. prepared, in all material respects, in
accordance with the applicable financial
reporting framework when reporting in
accordance with a compliance
framework.
Page | 192
Adverse The auditor shall express an adverse the auditor shall state in the opinion
Opinion opinion when the auditor, having paragraph that, in the auditor’s opinion,
obtained sufficient appropriate audit because of the significance of the matter(s)
evidence, concludes that misstatements, described in the Basis for Adverse Opinion
individually or in the aggregate, are both paragraph:
material and pervasive to the financial (a) The financial statements do not present
statements. fairly (or give a true and fair view) in
accordance with the applicable financial
reporting framework when reporting in
accordance with a fair presentation
framework; or
(b) The financial statements have not been
prepared, in all material respects, in
accordance with the applicable financial
reporting framework when reporting in
accordance with a compliance
framework.
Disclaimer The auditor shall disclaim an opinion When the auditor disclaims an opinion due to
of Opinion when the auditor is unable to obtain an inability to obtain sufficient appropriate
sufficient appropriate audit evidence on audit evidence, the auditor shall state in the
which to base the opinion, and the opinion paragraph that:
auditor concludes that the possible (a) Because of the significance of the
effects on the financial statements of matter(s) described in the Basis for
undetected misstatements, if any, could Disclaimer of Opinion paragraph, the
be both material and pervasive. auditor has not been able to obtain
sufficient appropriate audit evidence to
The auditor shall disclaim an opinion provide a basis for an audit opinion; and,
when, in extremely rare circumstances accordingly.
involving multiple uncertainties, the (b) The auditor does not express an opinion
auditor concludes that, notwithstanding on the financial statements.
having obtained sufficient appropriate
audit evidence regarding each of the
individual uncertainties, it is not possible
to form an opinion on the financial
statements due to the potential
interaction of the uncertainties and their
possible cumulative effect on the
financial statements.
Page | 193
Basis for Opinion
When the auditor modifies the opinion on the financial statements, the auditor shall, in addition to
the specific elements required by ISA 700 (Revised):
1. Amend the heading “Basis for Opinion” to “Basis for Qualified Opinion,” “Basis for Adverse
Opinion,” or “Basis for Disclaimer of Opinion,” as appropriate; and
2. Within this section, include a description of the matter giving rise to the modification.
If there is a material misstatement of the financial statements that relates to specific amounts in the
financial statements (including quantitative disclosures), the auditor shall include in the Basis for Opinion
section a description and quantification of the financial effects of the misstatement, unless impracticable.
If it is not practicable to quantify the financial effects, the auditor shall so state in this section.
If there is a material misstatement of the financial statements that relates to qualitative disclosures, the
auditor shall include in the Basis for Opinion section an explanation of how the disclosures are misstated.
If there is a material misstatement of the financial statements that relates to the non-disclosure of
information required to be disclosed, the auditor shall:
- Discuss the non-disclosure with those charged with governance
- Describe in the Basis for Opinion section the nature of the omitted information; and
- include the omitted disclosures, provided it is practicable to do so and the auditor has obtained
sufficient appropriate audit evidence about the omitted information.
If the modification results from an inability to obtain sufficient appropriate audit evidence, the auditor
shall include in the Basis for Opinion section the reasons for that inability.
When the auditor expresses a qualified or adverse opinion, the auditor shall amend the statement about
whether the audit evidence obtained is sufficient and appropriate to provide a basis for the auditor’s
opinion to include the word “qualified” or “adverse”, as appropriate.
When the auditor disclaims an opinion on the financial statements, the auditor’s report shall not include
these elements:
- A reference to the section of the auditor’s report where the auditor’s responsibilities are described;
and
- A statement about whether the audit evidence obtained is sufficient and appropriate to provide a
basis for the auditor’s opinion.
Even if the auditor has expressed an adverse opinion or disclaimed an opinion on the financial statements,
the auditor shall describe in the Basis for Opinion section the reasons for any other matters of which the
auditor is aware that would have required a modification to the opinion, and the effects thereof.
Page | 194
Contents: Auditor’s report
Title The auditor’s report shall have a title that clearly indicates that it is the
report of an independent auditor
Addressee The auditor’s report shall be addressed, as appropriate, based on the
circumstances of the engagement.
Auditor’s opinion Heading “Opinion.”
Wording
In our opinion, the accompanying financial statements present fairly, in all
material respects, […] in accordance with [the applicable
financial reporting framework]
or
In our opinion, the accompanying financial statements give a true and fair
view of […] in accordance with [the applicable financial reporting
framework]
Basis for opinion The auditor’s report shall include a section, directly following the Opinion
section, with the heading “Basis for Opinion”, that:
1. States that the audit was conducted in accordance with International
Standards on Auditing;
2. Refers to the section of the auditor’s report that describes the auditor’s
responsibilities under the ISAs;
3. Includes a statement that the auditor is independent of the entity in
accordance with the relevant ethical requirements relating to the audit,
and has fulfilled the auditor’s other ethical responsibilities in
accordance with these requirements. The statement shall identify the
jurisdiction of origin of the relevant ethical requirements or refer to the
International Ethics Standards Board for Accountants’ Code of Ethics for
Professional Accountants (IESBA Code); and
4. States whether the auditor believes that the audit evidence the auditor
has obtained is sufficient and appropriate to provide a basis for the
auditor’s opinion.
Page | 195
Key Audit Matters For audits of complete sets of general purpose financial statements of listed
entities, the auditor shall communicate key audit matters in the auditor’s
report in accordance with ISA 701.
“Key audit matters are those matters that, in our professional judgment,
were of most significance in our audit of the financial statements of the
current period. These matters were addressed in the context of our audit of
the financial statements as a whole, and in forming our opinion thereon, and
we do not provide a separate opinion on these matters.”
Other information The auditors needs to obtain the final version of the other information
before the date of the auditor’s report. They will read it to identify any
material inconsistencies with the financial statements or the auditor’s
knowledge obtained during the audit.
If the auditor identifies a material inconsistency they should:
• Perform limited procedures to evaluate the inconsistency. The auditor
should consider whether it is the financial statements or the other
information that requires amendment.
• Discuss the matter with management and ask them to make the
correction
• If management refuses to make the correction, communicate the
matter to those charged with governance.
• The auditor must also describe the material misstatement in the
auditor's report in this OI section.
Page | 196
Auditor’s responsibilities This section of the auditor’s report shall:
for the audit of F/S
(a) State that the objectives of the auditor are to:
✓ Obtain reasonable assurance about whether the financial statements
The description of the as a whole are free from material misstatement, whether due to
auditor’s responsibilities fraud or error; and
for the audit of the ✓ Issue an auditor’s report that includes the auditor’s opinion.
financial statements
shall be included: (b) State that reasonable assurance is a high level of assurance, but is not a
(a) Within the body of guarantee that an audit conducted in accordance with ISAs will always
the auditor’s report; detect a material misstatement when it exists; and
(b) Within an appendix
to the auditor’s report, (c) State that misstatements can arise from fraud or error, and provide a
in which case the definition or description of materiality in accordance with the applicable
auditor’s report shall financial reporting framework.
include a reference to
the location of the
appendix; or (d) State that, as part of an audit in accordance with ISAs, the auditor
(c) By a specific exercises professional judgment and maintains professional skepticism
reference within the throughout the audit; and
auditor’s report to the
location of such a (e) Describe an audit by stating that the auditor’s responsibilities are:
description on a website ✓ To identify and assess the risks of material misstatement of the
of an appropriate financial statements, whether due to fraud or error;
authority, where law, ✓ To design and perform audit procedures responsive to those risks;
regulation or national ✓ and to obtain audit evidence that is sufficient and appropriate to
auditing standards provide a basis for the auditor’s opinion.
expressly permit the ✓ To obtain an understanding of internal control relevant to the audit
auditor to do so in order to design audit procedures that are appropriate in the
circumstances, but not for the purpose of expressing an opinion on
the effectiveness of the entity’s internal control.
✓ To evaluate the appropriateness of accounting policies used and the
reasonableness of accounting estimates and related disclosures
made by management.
✓ To conclude on the appropriateness of management’s use of the
going concern basis of accounting and, based on the audit evidence
obtained, whether a material uncertainty exists related to events or
conditions that may cast significant doubt on the entity’s ability to
continue as a going concern. If the auditor concludes that a material
uncertainty exists, the auditor is required to draw attention in the
Page | 197
auditor’s report to the related disclosures in the financial
statements or, if such disclosures are inadequate, to modify the
opinion. The auditor’s conclusions are based on the audit evidence
obtained p to the date of the auditor’s report. However, future
events or conditions may cause an entity to cease to continue as a
going concern.
✓ To evaluate the overall presentation, structure and content of the
financial statements, including the disclosures.
“Report on Other Legal In some jurisdictions, the auditor may have additional responsibilities to
and Regulatory report on other matters that are supplementary to the auditor’s
Requirements” responsibilities under the ISAs
For example, the auditor may be asked to report certain matters if they
come to the auditor’s attention during the course of the audit of the
financial statements.
Page | 198
Auditing standards in the specific jurisdiction often provide guidance on the
auditor’s responsibilities with respect to specific additional reporting
responsibilities in that jurisdiction
Name of the
Engagement Partner
Signature of the auditor
Auditor’s address
Date of the auditor’s
report
Page | 199
Additional Paragraphs
Emphasis of Matter paragraph :A paragraph included in the auditor’s report that refers to a matter
appropriately presented or disclosed in the financial statements that, in the auditor’s judgment, is of such
importance that it is fundamental to users’ understanding of the financial statements.
If the auditor considers it necessary to draw users’ attention to a matter presented or disclosed in the
financial statements that, in the auditor’s judgment, is of such importance that it is fundamental to users’
understanding of the financial statements, the auditor shall include an Emphasis of Matter paragraph in
the auditor’s report provided:
- The auditor would not be required to modify the opinion in accordance with ISA 705 (Revised) as a
result of the matter; and
- When ISA 701 applies, the matter has not been determined to be a key audit matter to be
communicated in the auditor’s report. (When ISA 701 applies, the use of Emphasis of Matter
paragraphs is not a substitute for a description of individual key audit matters.)
There may be a matter that is not determined to be a key audit matter in accordance with ISA 701 (i.e.,
because it did not require significant auditor attention), but which, in the auditor’s judgment, is
fundamental to users’ understanding of the financial statements (e.g., a subsequent event). If the auditor
considers it necessary to draw users’ attention to such a matter, the matter is included in an Emphasis of
Matter paragraph in the auditor’s report in accordance with this ISA.
When the auditor includes an Emphasis of Matter paragraph in the auditor’s report, the auditor shall:
(a) Include the paragraph within a separate section of the auditor’s report with an appropriate heading
that includes the term “Emphasis of Matter”;
(b) Include in the paragraph a clear reference to the matter being emphasized and to where relevant
disclosures that fully describe the matter can be found in the financial statements. The paragraph
shall refer only to information presented or disclosed in the financial statements; and
(c) Indicate that the auditor’s opinion is not modified in respect of the matter emphasized.
Examples of circumstances where the auditor may consider it necessary to include an Emphasis of
Matter paragraph are
1. An uncertainty relating to the future outcome of exceptional litigation or regulatory action.
2. A significant subsequent event that occurs between the date of the financial statements and the
date of the auditor’s report.
Page | 200
3. Early application (where permitted) of a new accounting standard that has a material effect on
the financial statements.
4. A major catastrophe that has had, or continues to have, a significant effect on the entity’s
financial position.
5. When a financial reporting framework prescribed by law or regulation would be unacceptable but
for the fact that it is prescribed by law or regulation.
6. When facts become known to the auditor after the date of the auditor’s report and the auditor
provides a new or amended auditor’s report (i.e., subsequent events)
Other Matter paragraph – A paragraph included in the auditor’s report that refers to a matter other than
those presented or disclosed in the financial statements that, in the auditor’s judgment, is relevant to
users’ understanding of the audit, the auditor’s responsibilities or the auditor’s report.
Other Matter Paragraphs in the Auditor’s Report
If the auditor considers it necessary to communicate a matter other than those that are presented or
disclosed in the financial statements that, in the auditor’s judgment, is relevant to users’ understanding
of the audit, the auditor’s responsibilities or the auditor’s report, the auditor shall include an Other Matter
paragraph in the auditor’s report, provided:
When the auditor includes an Other Matter paragraph in the auditor’s report, the auditor shall include
the paragraph within a separate section with the heading “Other Matter,” or other appropriate heading.
1. Relevant to Users’ Understanding of the Audit: In the rare circumstance where the auditor is
unable to withdraw from an engagement even though the possible effect of an inability to obtain
sufficient appropriate audit evidence due to a limitation on the scope of the audit imposed by
management is pervasive, the auditor may consider it necessary to include an Other Matter
paragraph in the auditor’s report to explain why it is not possible for the auditor to withdraw from
the engagement.
2. Relevant to Users’ Understanding of the Auditor’s Responsibilities or the Auditor’s Report: Law,
regulation or generally accepted practice in a jurisdiction may require or permit the auditor to
elaborate on matters that provide further explanation of the auditor’s responsibilities in the audit
of the financial statements or of the auditor’s report thereon.
Page | 201
3. Reporting on more than one set of financial statements: An entity may prepare one set of financial
statements in accordance with a general-purpose framework (e.g., the national framework) and
another set of financial statements in accordance with another general-purpose framework (e.g.,
International Financial Reporting Standards), and engage the auditor to report on both sets of
financial statements. If the auditor has determined that the frameworks are acceptable in the
respective circumstances, the auditor may include an Other Matter paragraph in the auditor’s
report, referring to the fact that another set of financial statements has been prepared by the same
entity in accordance with another general-purpose framework and that the auditor has issued a
report on those financial statements.
The placement of an Emphasis of Matter paragraph or Other Matter paragraph in the auditor’s report
depends on the nature of the information to be communicated, and the auditor’s judgment as to the
relative significance of such information to intended users compared to other elements required to be
reported
EOMP:
1. immediately following the Basis of Opinion section to provide appropriate context to the auditor’s
opinion: When the Emphasis of Matter paragraph relates to the applicable financial reporting
framework,
2. May be presented either directly before or after the Key Audit Matters section, based on the auditor’s
judgment as to the relative significance of the information included in the Emphasis of Matter
paragraph. The auditor may also add further context to the heading “Emphasis of Matter”, such as
“Emphasis of Matter – Subsequent Event”, to differentiate the Emphasis of Matter paragraph from
the individual matters described in the Key Audit Matters section
Page | 202
Quality management procedures prior to issuing the audit report
We know that an engagement quality control reviewer must be appointed for audits of financial
statements of listed entities and other high-risk clients.
The audit engagement partner then discusses significant matters arising during the audit engagement
with the engagement quality control reviewer.
The engagement quality control reviewer must review the financial statements and the proposed
auditor’s report, in particular focusing on the conclusions reached in formulating the auditor’s report and
consideration of whether the proposed auditor’s opinion is appropriate.
The audit documentation will be carefully reviewed, and the reviewer is likely to consider whether
procedures performed in relation to risky balances were appropriate.
Any modification to the auditor’s report will be scrutinised, and the firm must be sure of any decision to
modify the report, and the type of modification made.
The engagement quality control reviewer should ensure that there is adequate documentation regarding
the judgements used in forming the final audit opinion, and that all necessary matters have been brought
to the attention of those charged with governance.
The auditor’s report must not be signed and dated until the completion of the engagement quality control
review.
In the AAA exam, you may be asked to critically evaluate an extract of an audit report.
It is important that you know the contents of the audit report and its modifications in detail. This includes
the headings, the sequence, the content of each paragraph and how it changes when the report is
modified.
It is recommended that you evaluate the given extract in the following sequence:
Recommended steps/sequence
Page | 203
6. KAM (ONLY for listed clients)
✓ Do matters identified as KAM actually fulfill the criteria of being called KAM?
✓ Introduction given? (‘Key audit matters are those matters which in our professional judgment
were of most significance in our audit. There matters were addressed in the context of our audit
as a whole. We do not provide a separate opinion on these matters’)
✓ Does it mention WHY it is a key audit matter?
✓ Does it mention HOW each KAM was addressed in the audit?
✓ Placement of the paragraph, correct?)
7. Any other changes to the audit report?
8. Unprofessional wording?
Page | 204
Assurance & No-Assurance Engagements
The definition of an assurance engagement is set out below but you should be familiar with it from your
earlier auditing studies.
An assurance engagement is one where a professional accountant evaluates or measures a subject matter
that is the responsibility of another party against suitable criteria, and expresses an opinion which
provides the intended user with a level of assurance about the subject matter.
Page | 205
for expressing a conclusion in a Direct reporting engagement
form that conveys whether, based
on the procedures performed and A direct reporting engagement involves the following:
evidence obtained, a matter(s) – an independent examination of financial information or
has come to the practitioner’s other information that has been prepared for use by another
attention to cause the party
practitioner to believe the subject – engaging party may or may not make a written assertion or
matter information is materially a set of assertions (e.g. the engaging party may not state
misstated. The nature, timing and that the financial statements follow IAS. However, the
extent of procedures performed in examining party will still need to state which standards have
a limited assurance engagement is been used)
limited compared with that – expressing an opinion in accordance with the agreed terms
necessary in a reasonable of the engagement
assurance engagement but is
planned to obtain a level of In a direct reporting engagement, the accountant is engaged to
assurance that is, in the make enquiries into the accounts, organisation or activities of an
practitioner’s professional entity.
judgment, meaningful. To be
meaningful, the level of assurance The following table summarises the differences between an
obtained by the practitioner is attestation engagement and a direct reporting engagement:
likely to enhance the intended
users’ confidence about the Attestation Direct reporting
subject matter information to a Assurance is provided on Assurance is provided
degree that is clearly more than the written assertion, or irrespective of whether the
inconsequential. set of assertions, made by written assertion, or set of
one party, responsible for a assertions, is made.
matter of accountability, to
another party.
An audit of historical A direct reporting engagement
financial statements is an is a kind of review engagement
example of an attestation where opinion is provided but
engagement where not always on the assertions
management makes an made by the engaging party.
assertion e.g. the financial Due diligence review is an
statements give a true and example of a direct reporting
fair view and are free of engagement.
material misstatements.
The assurance The assurance engagement risk
engagement risk is reduced is reduced to a moderate level.
to an acceptably low level.
Page | 206
Comparatively extensive Comparatively limited audit
audit procedures are procedures are performed.
performed. Audit Procedures generally comprise
procedures generally enquiry and analytical
comprise inspection, procedures.
observation, confirmation,
recalculation, re
performance, analytical
procedures and enquiry.
“Reasonable assurance” is “Limited assurance” is provided.
provided.
The opinion is expressed The opinion is expressed
positively such as “in our negatively such as “nothing has
opinion subject matter come to our attention that
conforms in all material causes us to believe that subject
respects to criteria.” matter does not conform in all
material respects to criteria.”
The following table summarises the difference between the two types of services:
Audit of historical financial statements Audit related services
Audit provides reasonable assurance Review: offers limited but negative assurance.
Agreed-upon procedures: no assurance, only
factual findings.
Compilation: no assurance.
The auditor decides the scope of the work to be Review: reviewer decides the scope of audit.
carried out in an audit. Agreed-upon procedures: client entity decides
the scope
Compilation: client entity decides the scope of
work.
In many countries, an audit is required by law (for These services are not required by law.
large and public companies).
Audit risk i.e. risk of mistakes, omissions or Risk of mistakes, omissions etc. is greater in
incorrect disclosures is lower in audit as compared review and other services than in audit, as
to other engagements. generally less work is carried out or concentrated
on certain areas.
Page | 207
Cost is higher than cost of review and other Cost is significantly less than cost of audit.
services.
Agreed-upon procedures
Agreed upon procedures assignments are discussed in ISRS 4400 Engagements to perform agreed-upon
procedures regarding financial information.
In an ‘agreed-upon procedures’ engagement, the auditor is engaged to perform certain procedures which
have been agreed between the auditor, the entity and any other interested third party e.g. fraud
investigations, verifying accounts payables, verifying accounts receivables and verifying non-financial
data, such as waiting times in hospitals.
The procedures applied in an agreed-upon procedures engagement may include the following:
– enquiry and analysis
– recomputation, comparison and other clerical accuracy checks
– observation
– inspection
– obtaining confirmations
In an agreed upon procedure engagement, auditor does not express his opinion; instead, he gives only
the factual findings.
Agreed upon procedures engagements are required in the following circumstances for example:
– investigating fraud or irregularity
– verifying insurance claims
– reporting on non-financial data e.g. number of units sold
Compilation engagements- Compilation does not provide assurance; it only gives compiled information.
Page | 208
In other words, it is an engagement which requires more accounting expertise than auditing expertise
and involves collecting, classifying and summarising financial information. Data is presented in a
manageable and understandable form without a requirement to test the assertions underlying that
information.
Examples
– Preparing financial statements
– Calculating taxable income
Page | 209
Review Engagements
Many clients (for whom audit is not compulsory) require some assurance on their financial statements.
However, they do not want to incur the heavy cost of audit. For these clients, a review engagement may
be the appropriate service to provide this assurance. This is because review provides limited assurance
that the financial statements are reasonable and one can believe in them.
Generally, when a client approaches a bank for a loan, the bank asks for a review report.
The objective of a review engagement is to enable the auditor to obtain moderate assurance as to
whether the financial statements have been prepared in accordance with an identified financial
reporting framework. This is defined in ISRE 2400 Engagements to Review Financial Statements.
In order to obtain this assurance, it is necessary to gather evidence using analytical procedures and
enquiries with management. Detailed substantive procedures will not be performed unless the auditor
has reason to believe that the information may be materially misstated.
The auditor should approach the engagement with a high degree of professional scepticism, looking for
circumstances that may cause the financial statements to be misstated.
As a result of procedures performed, the auditor’s objective is to provide a clear written expression of
negative assurance on the financial statements. In a review engagement the auditor would state that
‘we are not aware of any material modifications that should be made to the financial statements….’
This is normally referred to as an opinion of ‘negative assurance’.
Negative assurance means that the auditor has performed limited procedures and has concluded that
the financial statements appear reasonable. The user of the financial statements gains some comfort
that the figures have been subject to review, but only a moderate level of assurance is provided. The
user may need to carry out additional procedures of their own if they want to rely on the financial
statements.
In comparison, in an audit, a high level of assurance is provided. The auditors provide an opinion of
positive, but not absolute assurance. The user is assured that the figures are free from material
misstatement and that the auditor has based the opinion on detailed procedures.
The assurance provided in review engagements is limited and negative i.e. the practitioners (those
carrying out review engagements) are required to state in their report whether anything has come to their
attention that causes them to believe that the financial statements are not prepared, in all material
respects, in accordance with an identified financial reporting framework.
Page | 210
Negative assurance concentrates on the fact that the practitioner is stating that from the limited work he
has carried out, everything looks reasonable and plausible. There is no detailed testing, hence using the
phrase,‘ nothing comes to our attention to believe that the accounts do not give a true and fair view’.
The procedures to be performed in a review engagement will vary depending on the specific requirements
of the engagement. They are generally based on:
– gaining an understanding of the client’s activities, including knowledge of the accounting practices of
the industry or area in which the client operates
– enquiry into the entity’s accounting principles and practices, the entity’s procedure from recording of
transactions and events to preparing the financial statements and all material assertions in the
financial statements
– analytical review the whole premise behind a review is that the auditor does not do the detailed
testing to gain positive assurance that the figures are true and fair. He is just looking to ensure that
they are plausible and reasonable under the circumstances.
Interim financial information is financial information that is prepared and presented in accordance with
an applicable financial reporting framework and comprises either a complete or a condensed set of
financial statements for a period that is shorter than the entity’s financial year.
In many countries, listed companies are required to publish quarterly or half-yearly interim financial
information which has been reviewed by a professional accountant. In order to comply with this,
companies may appoint professional accountants (who may or may not be the company’s auditors) to
review the interim financial information.
The review of interim financial information enables the accountant to express a conclusion on whether,
based on the review, anything has come to his attention that causes him to believe that the interim
financial information has not been prepared, in all material respects, in accordance with an applicable
financial reporting framework.
If, during the review, the accountant comes across matters that require modification in order for the
information to be presented in conformity with the international financial reporting framework, he should
communicate with the engaging party about the modifications required.
The auditor should obtain an understanding of the entity and its environment as it relates to both the
interim review and final audit.
Page | 211
The key elements of the review will be:
Analytical procedures
Ordinarily procedures would include:
– Reading the minutes of meetings of shareholders, those charged with governance and other
appropriate committees
– Considering the effect of matters giving rise to a modification of the audit or review report, accounting
adjustments or unadjusted misstatements from previous audits
– If relevant, communicating with other auditors auditing different components of the business
– Analytical procedures designed to identify relationships and unusual items that may reflect a material
misstatement
– Reading the interim financial information and considering whether anything has come to the auditors'
attention indicating that it is not prepared in accordance with the applicable financial reporting
framework
– Agreeing the interim financial information to the underlying accounting records
Auditors should make enquiries of members of management responsible for financial and accounting
matters about:
– Whether the interim financial information has been prepared and presented in accordance with the
applicable financial reporting framework
– Whether there have been changes in accounting policies
– Whether new transactions have required changes in accounting principle
– Whether there are any known uncorrected misstatements
– Whether there have been unusual or complex situations, such as disposal of a business segment
– Significant assumptions relevant to fair values
– Whether related party transactions have been accounted for and disclosed correctly
– Significant changes in commitments and contractual obligations
– Significant changes in contingent liabilities including litigation or claims
– Compliance with debt covenants
– Matters about which questions have arisen in the course of applying the review procedures
– Significant transactions occurring in the last days of the interim period or the first days of the next
– Knowledge or suspicion of any fraud
– Knowledge of any allegations of fraud Knowledge of any actual or possible non-compliance with laws
and regulations that could have a material effect on the interim financial information
– Whether all events up to the date of the review report that might result in adjustment in the interim
financial information have been identified
– Whether management has changed its assessment of the entity being a going concern
Page | 212
The auditor should evaluate discovered misstatements individually and in aggregate to see if they are
material.
The auditor should obtain written representations from management that it acknowledges its
responsibility for the design and implementation of internal control, that the interim financial information
is prepared and presented in accordance with the applicable financial reporting framework and that the
effect of uncorrected misstatements are immaterial (a summary of these should be attached to the
representations). The auditor should also obtain representations that all significant facts relating to
frauds or non-compliance with law and regulations has been disclosed to the auditor and that all
significant subsequent events have been disclosed to the auditor.
The auditor should read the other information accompanying the interim financial information to ensure
that it is not inconsistent with it.
If the auditors believe a matter should be adjusted in the financial information, they should inform
management as soon as possible. If management does not respond within a reasonable time, then the
auditors should inform those charged with governance. If they do not respond, then the auditor should
consider whether to modify the report or to withdraw from the engagement and the final audit if
necessary. If the auditors uncover fraud or non-compliance with laws and regulations, they should
communicate that promptly with the appropriate level of management. The auditors should
communicate matters of interest arising to those charged with governance.
Page | 213
Due Diligence Review
Due diligence reviews are a specific type of review engagement. A typical due diligence engagement is
where an advisor (often an audit firm) is engaged by one company planning to take over another to
perform an assessment of the material risks associated with the transaction (including validating the
assumptions underlying the purchase), to ensure that the acquirer has all the necessary facts and that the
perceived business opportunities are in fact real. This is important when determining purchase price.
Similarly, due diligence can also be requested by sellers.
An accountant may be asked to perform a due diligence review of the company, unit or other assets, as
the case may be acquired in mergers and acquisitions. The accountant is supposed to identify risks such
as the risk of non-disclosure of any relevant information and non-disclosure of any liability. The
accountant can review target companies and comment on whether it is worth investing into these
companies.
– Financial due diligence (a review of the financial position and obligations of a target to identify such
matters as covenants and contingent obligations)
– Operational and IT due diligence (extent of operational and IT risks, including quality of systems,
associated with a target business)
– People due diligence (key staff positions under the new structure, contract termination costs and cost
of integration)
– Regulatory due diligence (review of the target's level of compliance with relevant regulation)
– Environmental due diligence (environmental, health and safety and social issues in a target)
1. Competency of firm: the audit firm should have the experience and skill to perform the review
2. Independence issues: as required in any assurance assignment, the accountant should be
independent of both the parties
3. Sufficiency of resources: whether the firm has adequate manpower to perform the engagement
4. Degree of confidentiality: who the assignment will be performed for and who will see the results
5. Scope of work: what areas are to be concentrated on
6. Purpose of the acquisition e.g. whether the acquiring company is interested in acquiring the company
(i.e. the share capital) or its trading assets. This is because the auditor will accordingly concentrate his
work on that particular area, if any.
7. Planning due diligence assignments. In due diligence assignments, the scope of the work should be
written down in the engagement letter and agreed to by both the accountant and the client. The
engagement letter should also include the following:
– scope of work
– a clear demarcation of the responsibilities of the management and the accountant
– a clarification of interim report requirements
– confidentiality
Page | 214
Apart from the usual considerations of the audit / review plan, a due diligence plan should include
preparing a list of required information and the people to be interviewed
In due diligence, the accountant analyses the information supplied by the target company and interviews
a member of the management of the target company. In order to do this more effectively, the required
information and interviewees should be identified well in advance and included in the plan. The target
company needs to be informed well in advance about the required information and the interviewees
required so that the company can make these resources available.
In a review engagement, the auditor will rely more heavily on procedures such as enquiry and analytical
review than on more detailed substantive testing.
1. Before purchasing a company, it is crucial that the purchaser undertake a comprehensive survey of
the business in order to avoid any operational or financial surprises post-acquisition. Due diligence
can simply be seen as ‘fact finding’, and as a way to minimise the risk of making a bad investment
2. Investigative due diligence is the process by which information is gathered about a target company,
for the purpose of ensuring that the acquirer has full knowledge of the operations, financial
performance and position, legal and tax situation, as well as general commercial background.
Essentially the aim is to uncover any ‘skeletons in the closet’ and therefore to reveal any potential
problem areas before a decision regarding the acquisition is made.
Page | 215
3. Verification of specific management representations: the vendor may make representations to the
potential acquirer which it is essential to verify.
4. Identification of assets and liabilities: From an accounting perspective it is crucial that all of the
assets of the target company are identified. This is important because internally generated
intangibles such as customer databases, trade dress, and brand names are unlikely to be recognised
in the individual company statement of financial position (balance sheet), but should be identified
and valued for the purpose of calculating goodwill on acquisition. As these assets are, by definition,
without physical substance, only a detailed due diligence investigation will uncover them. As well
as being important for the goodwill calculation, it is crucial to identify these assets as they represent
‘hidden wealth’ within the target company, and should be taken into account when negotiating the
acquisition price.
5. Contingent liabilities must also be identified, as the acquirer will need to understand the likelihood
of the liability crystallising, and the potential financial consequence.
6. Operational issues: One of the key benefits of due diligence is to discover problems or risks within
the entity. These risks may not necessarily arise in the context of a contingent liability, but could
instead be operational issues such as high staff turnover, or the need to renegotiate contract terms
with suppliers or customers. The directors of the acquiring company will need to carefully consider
whether such matters constitute deal breakers, in which case the investment would be considered
too risky and so would not go ahead. Alternatively, the risks uncovered could be useful in
negotiation to reduce the consideration paid, or the target company could be asked to provide
assurance that these problems will be resolved pre acquisition.
7. Acquisition planning: The due diligence investigation will also assess the commercial benefits, and
potential drawbacks, of the acquisition. On the positive side, it will highlight matters such as
expected operational synergies to be created post acquisition, and potential economies of scale to
be exploited. On the downside there will be acquisition expenses to pay, costs in terms of
reorganisation and possible redundancies, as well as the important but hard to quantify issue of
change management. The due diligence provider may be able to offer recommendations as to the
best way to integrate the new company into the group.
Page | 216
9. Credibility: An external investigation will also provide an independent, impartial view on the
situation, enhancing the credibility of the investment decision, and the amount paid for the
investment.
The aim of due diligence, in contrast to an audit, is NOT to provide assurance that financial data is free
from material misstatement, but rather to provide the acquirer with a set of information that has been
reviewed. Consequently, no detailed audit procedures will be performed unless there are specific issues
which either cause concern, or have been specifically selected for further verification.
For example, the acquirer may specifically request that the due diligence exercise provides an estimate
of the valuation of acquired intangible assets, as discussed above.
The type of work performed will therefore be quite different, as a due diligence investigation will
primarily use analytical procedures as a means of gathering information. Very few, if any substantive
procedures would be carried out, unless they had been specifically requested by the client.
Due diligence is much more ‘forward looking’ than an audit. Much of the time during a due diligence
investigation will be spent assessing forecasts and predictions. In comparison audit procedures only
tend to cover future events if they are directly relevant to the yearend financial statements, for
example, contingencies, or going concern problems.
In contrast to an audit, when it is essential to evaluate systems and controls, the due diligence
investigation will not conduct detailed testing of the accounting and internal control systems, unless
specifically requested to do so.
Requirements
Year-end audits are legally required for all limited companies exceeding the minimum audit thresholds.
They are also subject to strict regulations in the guise of International Standards of Auditing.
Page | 217
Due diligence is initiated at the request of directors and subject to fewer prescribed rules. An outline
of the processes that should be followed can be found in: ISRE 2400 Engagements to Review Financial
Statements; ISRS 4400 Engagements to Perform Agreed upon Procedures Regarding Financial
Information; ISAE 3400 The Examination of Prospective Financial Information; and ISAE 100 Assurance
Engagements.
Audience
An audit opinion is offered to the shareholders of the business subject to audit.
In contrast, the reports from due diligence engagements are provided to the directors of the company.
Form of Assurance
The opinion offered on an audit is one of reasonable assurance. This means that sufficient, appropriate
evidence has been gathered to support an opinion as to whether the accounts are free from material
misstatement.
Absolute assurance cannot be given for reasons such as: the use of accounting estimates; the nature of
fraud (i.e. it is hidden); and the necessary use of audit sampling.
As the timescale for a due diligence review is often relatively short but wide in scope clients may not
always request the expression of an opinion. However, the accountant will be engaged to report upon
certain criteria requested specifically by the client. If sought, the assurance offered would be limited
assurance.
Wording of Opinion
In an audit report a positive statement of opinion is offered as to whether the accounts are – or are not
– a true and fair representation of the position and performance of the business under scrutiny.
In a limited assurance report a negative statement of opinion is given. This indicates whether anything
has come to light during the review to indicate a departure from the criteria initially agreed with the
client.
Evidence
During audit evidence is usually gathered using a mixture of analytical review, enquiry, inspection of
documentation, observation of procedures, and recompilations of certain balances.
During due diligence evidence is restricted, at least initially, to analytical review and enquiry. Further
corroborative evidence might be sought if any material concerns were identified.
Page | 218
Due diligence conclusion
Due diligence is a specific example of a direct reporting assurance engagement. The form of the report
issued in this type of engagement is covered by ISAE 3000 Assurance Engagements other than Audits or
Reviews of Historical Financial Information, and ISRE 2400 Engagements to Review Historical Financial
Statements also contains relevant guidance.
The main difference between a review report and an audit report is the level of assurance that is given. In
a review report a conclusion is expressed in a negative form. The conclusion would start with the wording
‘based on our review, nothing has come to our attention...’
This type of conclusion is used because the nature of a due diligence review is that only limited assurance
has been obtained over the subject matter. The procedures used in a review engagement are mainly
enquiry and analytical review which can only provide limited assurance.
In comparison, in an audit of historical information, the auditor will use a wide variety of procedures to
obtain evidence to give reasonable assurance that the financial statements are free from material
misstatement. This means that an opinion expressed in a positive form can be given.
Page | 219
Prospective Financial Information
Basic Understanding
Forecasts: A financial forecast consists of prospective financial statements that present, to the best of the
responsible party's knowledge and belief, an entity's expected financial position, results of operations,
and cash flows.
Projections: A financial projection consists of prospective financial statements that present, given one or
more hypothetical assumptions, an entity's expected financial position, results of operations, and cash
flows. A financial projection is sometimes prepared to present one or more hypothetical courses of action
for evaluation, as in response to a “what if?” scenario.
The key difference between a forecast and a projection is the nature of the assumptions. In a forecast, the
assumptions represent the company's expectations of actual future events. A projection is used when the
assumptions desired are not those believed to be most likely (essentially, the "what if? “scenario).
Definitions
Prospective financial information (PFI):‘financial information based on assumptions about events that
may occur in the future and possible actions by an entity.’
‘Assumptions about future events’ can be in the form of a forecast or a projection, or a combination of
both.
Assumptions for a probable future event are highly subjective in nature and can vary from situation to
situation.
‘A forecast means PFI prepared on the basis of assumptions as to future events which the management
expects to take place and the actions the management expects to take as of the date the information is
prepared (best-estimate assumptions).’
A forecast is usually made for a period of no more than one year. Unlike a forecast, a projection is made
generally for a period of more than one year. Usually, it is made for the period ranging from two to twenty
years.
Page | 220
There are two other terms commonly associated with PFI:
Hypothetical illustration. PFI based on assumptions about uncertain future events and management
actions which have not yet been decided on.
Target. PFI based on assumptions about the future performance of the entity.
Listed companies should have procedures that allow them to generate reliable PFI, compare it to market
expectations, publish it when necessary and subsequently report actual performance against it.
Prospective financial information can include financial statements or one or more elements of financial
statements and may be prepared:
(a) As an internal management tool, for example, to assist in evaluating a possible capital investment; or
(b) For distribution to third parties in, for example:
(i) A prospectus to provide potential investors with information about future expectations.
(ii) An annual report to provide information to shareholders, regulatory bodies and other
interested parties.
(iii) A document for the information of lenders which may include, for example, cash flow
forecasts.
Page | 221
Matters to consider and include in the term of engagement for prospective financial information
Management’s The terms of the engagement should set out management’s responsibilities for the
responsibilities preparation of the business plan and forecast financial statements, including all
assumptions used, and for providing the auditor with all relevant information and
source data used in developing the assumptions. This is to clarify the roles and
reduce the scope for any misunderstanding.
The intended use This will establish the potential liability to third parties, and help to determine the
of the report , for need and extent of any liability disclaimer that may be considered necessary.
example, is it
intended for
internal or external
use?
The elements to be The extent of the review should be agreed. For example, determine whether they
included in the are being asked to report just on the forecast financial statements. This will help
review and report to determine the scope of the work involved and its complexity.
The period This should be confirmed when agreeing the terms of the engagement, as
covered by the assumptions become more speculative as the length of the period covered
forecasts increases, making it more difficult to substantiate the acceptability of the figures,
and increasing the risk of the engagement.
The nature of the It is crucial to determine the nature of assumptions, especially whether the
assumptions used assumptions are based on best estimates or are hypothetical. This is important
because ISAE 3400 The Examination of Prospective Financial Information states
that the auditor should not accept, or should withdraw from, an engagement when
the assumptions are clearly unrealistic or when the auditor believes that the
prospective financial information will be inappropriate for its intended use.
The planned The engagement letter should confirm the planned elements of the report to be
contents of the issued, to avoid any misunderstanding with management. In particular, it clarify
assurance report that their report will contain a statement of negative assurance as to whether the
assumptions provide a reasonable basis for the prospective financial information,
and an opinion as to whether the prospective financial information is properly
prepared on the basis of the assumptions and is presented in accordance with the
relevant financial reporting framework
Page | 222
Level of assurance provided
Prospective financial information is difficult to give assurance about because it is highly subjective and
this makes it a difficult area to examine and report on. Hence the level of assurance provided is negative,
as opposed to external audits, which examine historical financial information, and where the assurance
provided is reasonable.
Guidance on reporting on it is given in ISAE 3400 the examination of prospective financial information.
Due to the nature of PFI, the audit firm will be unable to conclude on whether the results forecast will be
achieved. Also there may be insufficient evidence available to conclude that the assumptions are free
from material misstatement. Therefore, the audit firm can generally only provide a limited level of
assurance.
The audit firm will normally provide negative assurance. This means they will state that "nothing has come
to their attention" which causes them to believe that the assumptions are not a reasonable basis for the
forecast.
Examination procedures
General:
– The auditor should obtain sufficient appropriate evidence as to whether management's assumptions
on which the PFI is based are not unreasonable.
– The auditor should obtain a sufficient knowledge of the business to be able to evaluate whether the
assumptions are justified.
– The auditor should review whether information is properly prepared on the basis of the assumptions.
– The auditor should review whether the information is properly presented and all material assumptions
are adequately disclosed.
– The auditor should review whether the PFI is prepared on a consistent basis with historical financial
statements, using appropriate accounting policies. The historical information will be used as a
yardstick to assess the assumptions underlying the information.
– Obtain backing schedules for the information, cast and ensure they are numerically accurate. Re-
perform calculations to confirm the arithmetic accuracy of the forecast financial statements.
Page | 223
– Obtain management representation with regard to the completeness and accuracy of information
and assumptions used. Also, this should contain a statement that it is management's responsibility to
produce the information.
– Identify and document internal controls over the process. Consider the role played by the internal
audit department.
– Consider the accuracy of forecasts prepared in prior periods by comparison with actual results and
discuss with management the reasons for any significant variances.
– Perform analytical procedures to assess the reasonableness of the forecast financial statements. For
example, finance charges should increase in line with the additional finance being sought.
– Consider the reasonableness of forecast trends in the light of auditor’s knowledge of business and the
current and forecast economic situation and any other relevant external factors.
– Whether the forecast under review is based on forecasts regularly prepared for the purpose of
management or whether it has been separately and specially prepared for the immediate purpose
– Whether the forecast under review represents the management's best estimate of results which they
reasonably believe can and will be achieved rather than targets which the management have set as
desirable
– The extent to which profits are derived from activities having a proven and consistent trend and those
of a more irregular, volatile or unproven nature
– How the forecast takes account of any material extraordinary items and prior year adjustments, their
nature, and how they are presented
– Whether adequate provision is made for foreseeable losses and contingencies and how the forecast
takes account of factors which may cause it to be subject to a high degree of risk, or which may
invalidate the assumptions
Specific matters
The following list of procedures may also be relevant when assessing prospective financial information.
The auditor should undertake the review procedures discussed above in addition to these.
Profit forecasts
**Verify projected income figures to suitable evidence. This may involve:
– Comparison of the basis of projected income to similar existing projects in the firm
– Review of current market prices for that product or service
**Verify projected expenditure figures to suitable evidence. There is likely to be more evidence available
about expenditure in the form of:
– Quotations or estimates provided to the firm
– Current bills for things such as services which can be used to reliably estimate
– Market rate prices, for example, for advertising
– Interest rate assumptions can be compared to the bank's current rates
– Costs such as depreciation should correspond with relevant capital expenditure projections
Page | 224
Capital expenditure
The auditor should check the capital expenditure for reasonableness. For example, if the projection
relates to buying land and developing it, it should include a sum for land.
Cash forecasts
**The auditors should review cash forecasts to ensure the timings involved are reasonable.
**The auditor should check the cash forecast for consistency with any profit forecasts
(income/expenditure should be the same, just at different times)
Page | 225
Report on Examination of Prospective Financial Information
The assurance report should make it clear that management is responsible for the PFI and also the
assumptions on which it is based. Given the subjective and speculative nature of the PFI, an opinion cannot
be given on whether the results shown in the report will be achieved, so only negative assurance can be
given.
Contents
1. Title and Addressee
4. A statement that management is responsible for the prospective financial information including the
assumptions on which it is based
5. When applicable, a reference to the purpose and/or restricted distribution of the prospective
financial information
6. A statement of negative assurance as to whether the assumptions provide a reasonable basis for the
prospective financial information
7. An opinion as to whether the prospective financial information is properly prepared on the basis of
the assumptions and is presented in accordance with the relevant financial reporting framework
8. Appropriate warnings concerning the achievability of the results indicated by the prospective
financial information
9. Date of the report which should be the date procedures have been completed
Page | 226
Forensic Accounting
Forensic accounting is the term used to describe the type of engagement. It is the whole process of
carrying out a forensic investigation, including preparing an expert’s report or witness statement, and
potentially acting as an expert witness in legal proceedings.
Forensic investigation is a part of a forensic accounting engagement. Forensic investigation is the process
of gathering evidence so that the expert’s report or witness statement can be prepared. It includes
forensic auditing, but incorporates a much broader range of investigative techniques, such as interviewing
witnesses and suspects, imaging or recovering computer files including emails, physical searches of
premises etc.
Forensic auditing is the application of traditional auditing procedures and techniques in order to gather
evidence as part of the forensic investigation.
TYPES OF INVESTIGATION
The forensic accountant could be asked to investigate many different types of fraud. It is useful to
categorise these types into three groups to provide an overview of the wide range of investigations that
could be carried out. The three categories of frauds are corruption, asset misappropriation and financial
statement fraud.
Corruption
There are three types of corruption fraud: conflicts of interest, bribery, and extortion. Research shows
that corruption is involved in around one third of all frauds.
• In a conflict of interest fraud, the fraudster exerts their influence to achieve a personal gain which
detrimentally affects the company. The fraudster may not benefit financially, but rather receives an
undisclosed personal benefit as a result of the situation. For example, a manager may approve the
expenses of an employee who is also a personal friend in order to maintain that friendship, even if
the expenses are inaccurate.
• Bribery is when money (or something else of value) is offered in order to influence a situation.
• Extortion is the opposite of bribery, and happens when money is demanded (rather than offered) in
order to secure a particular outcome.
Page | 227
Asset misappropriation
By far the most common frauds are those involving asset misappropriation, and there are many different
types of fraud which fall into this category. The common feature is the theft of cash or other assets from
the company, for example:
• Cash theft – the stealing of physical cash, for example petty cash, from the premises of a company.
• Fraudulent disbursements – company funds being used to make fraudulent payments. Common
examples include billing schemes, where payments are made to a fictitious supplier, and payroll
schemes, where payments are made to fictitious employees (often known as ‘ghost employees’).
• Inventory frauds – the theft of inventory from the company.
• Misuse of assets – employees using company assets for their own personal interest.
Forensic accounting engagements are normally agreed-upon procedures engagements, not assurance
engagements. The forensic accountant will not provide an assurance opinion – that is the role of the
auditor when reviewing the amount of loss included in the financial statements.
This will normally involve determining an appropriate value or quantifying a loss as discussed above;
this is quite distinct from an assurance engagement in which the engagement team would review an
amount determined by the client.
As an agreed-upon procedures engagement, the forensic accountant will normally prepare a report for
the client that sets out their findings, based on the scope agreed in the engagement letter. This report
may be addressed to management, often in the case of a fraud, or to the insurer.
It may be that a witness statement/report for submission to the court/arbitrator is required in addition
to or instead of a report to the client.
Page | 228
Stages Involved
Accepting the The forensic accountant must initially consider whether their firm has the necessary
investigation skills and experience to accept the work. Forensic investigations are specialist in
nature, and the work requires detailed knowledge of fraud investigation techniques
and the legal framework. Investigators must also have received training in interview
and interrogation techniques, and in how to maintain the safe custody of evidence
gathered.
Commercial considerations are also important, and a high fee level should be
negotiated to compensate for the specialist nature of the work, and the likely
involvement of senior and experienced members of the firm in the investigation.
Planning the Planning will commence with a meeting with the client in which the engagement team
investigation will develop an understanding of the issue/events (the fraud, theft etc) and actions
taken by the client since it occurred.
A key part of planning is to confirm exactly what format the output is required in, and
exactly what matters are required to be covered within it.
At this stage any key documentation will be obtained and scrutinised – for example,
the insurance policy, the partnership agreement, the evidence that led to the
discovery of the fraud, etc.
The team will agree with the client, what access to other information or personnel
will be required and this will be arranged.
Based on the above, the team will design procedures that enable them to meet the
requirements of the client, as agreed. This may or may not include test of controls,
depending on the circumstances. There would be no need to tests control when
valuing a business for a matrimonial dispute. However, testing controls will be key to
determining how a fraud took place.
The investigating team must carefully consider what they have been asked to achieve
and plan their work accordingly. The objectives of the investigation could include:
– Identifying the type of fraud, its duration, and how it was committed
Page | 229
– Identifying the parties involved in the fraud
– Quantifying the financial loss suffered due to the fraud
– Gathering evidence to be used in court proceedings
– Providing recommendations to avoid the recurrence of the fraud
The investigators should also consider the best way to gather evidence – the use of
computer assisted audit techniques, for example, is very common in fraud
investigations.
Gathering Forensic engagements will include a detailed and wholesale review of all
evidence documentation and electronic evidence available. The opinion given by the expert
accountant must be reasoned, and backed up by evidence. Their opinion cannot be
objective if only based on what they are told; they must corroborate that information.
To be awarded marks in the exam, your procedures cannot be vague. They must be
specific enough that the engagement team could actually follow your instructions.
For example, it would not be sufficient to write 'interview the suspect'. You must
suggest questions that should be asked of the suspect in interview, depending on the
circumstances in the scenario. For example, the suspect could be asked to explain
their job role and what access that gives them to systems, cash, inventory etc.
Equally it is not sufficient to suggest the use of computer assisted auditing techniques
(CAATs). You must specify how the CAATs could be used. For example, data matching
bank accounts used for paying suppliers with bank accounts for paying employees,
exception reports identifying employees who are not taking holiday, etc.
In order to design appropriate procedures you must identify the type of forensic
accounting engagement, and the specific type of fraud, insurance or negligence claim.
For example, quantifying the theft of goods will be very different from quantifying a
loss from payroll or ‘ghost employee’ fraud or loss of profits following a business
interruption (as discussed above).
Page | 230
In order to gather detailed evidence, the investigator must understand the specific
type of fraud that has been carried out, and how the fraud has been committed. The
evidence should be sufficient to ultimately prove the identity of the fraudster(s), the
mechanics of the fraud scheme, and the amount of financial loss suffered. It is
important that the investigating team is skilled in collecting evidence that can be used
in a court case, and in keeping a clear chain of custody until the evidence is presented
in court.
If any evidence is inconclusive or there are gaps in the chain of custody, then the
evidence may be challenged in court, or even become inadmissible. Investigators
must be alert to documents being falsified, damaged or destroyed by the suspect(s).
The ultimate goal of the forensic investigation team is to obtain a confession by the
fraudster, if a fraud did actually occur. For this reason, the investigators are likely to
avoid deliberately confronting the alleged fraudster(s) until they have gathered
sufficient evidence to extract a confession. The interview with the suspect is a crucial
part of evidence gathered during the investigation.
With reference to court proceedings (see below) evidence may also be gathered to
support other issues which would be relevant in the event of a court case. Such issues
could include:
• The suspect’s motive and opportunity to commit fraud
• Whether the fraud involved collusion between several suspects
• Any physical evidence at the scene of the crime or contained in documents
• Comments made by the suspect during interviews and/or at the time of arrest
• Attempts to destroy evidence.
Page | 231
Audit procedures examples-to be read NOT learnt!
The specific procedures which would be performed as part of a forensic audit will
depend on the specific nature of the investigation. However, using a fraud
investigation as an example, the following would normally apply.
• Develop a profile of the entity under investigation including its personnel
• Identify weaknesses in internal control procedures and basic record keeping, e.g.
banker conciliations not performed
• Perform trend analysis and analytical procedures to identify significant
transactions and significant variations from the norm
• Identify changes in patterns of purchases/sales, particularly where a limited
number of suppliers/customers are involved
• Identify significant variations in consumption of raw materials and consumables,
particularly where consumption appears excessive
• Identify unusual accounts and account balances, e.g. closing credit balances on
debit accounts and vice versa
• Review accounting records for unusual transactions and entries, e.g. large
numbers of accounting entries between accounts, transactions not executed at
normal commercial rates
• Review transaction documentation (e.g. invoices) for discrepancies and
inconsistencies
• Once identified trace the individual responsible for fraudulent transactions
• Obtain information regarding all responsibilities of the individual involved
• Inspect and review all other transactions conducted by the individual of a similar
nature
• Consider all other aspects of the business which the individual is involved with
and perform further analytical procedures targeting these areas to identify any
additional discrepancies
Reporting The client will expect a report containing the findings of the investigation, including a
summary of evidence and a conclusion as to the amount of loss suffered as a result
of the fraud. The report will also discuss how the fraudster set up the fraud scheme,
and which controls, if any, were circumvented. It is also likely that the investigative
team will recommend improvements to controls within the organization to prevent
any similar frauds occurring in the future
Court The investigation is likely to lead to legal proceedings against the suspect, and
proceedings members of the investigative team will probably be involved in any resultant court
case. The evidence gathered during the investigation will be presented at court, and
team members may be called to court to describe the evidence they have gathered
and to explain how the suspect was identified. It is imperative that the members of
the investigative team called to court can present their evidence clearly and
Page | 232
professionally, as they may have to simplify complex accounting issues so that non-
accountants involved in the court case can understand the evidence and its
implications.
A witness will provide a written report/statement to the court, and may also be
required to attend court to give live evidence, in person, and be cross-examined by
the ‘other side’.
Either way, a key skill necessary in being a successful forensic accountant is the ability
to explain complex accounting concepts in simple terms to someone who is not
themselves an accountant, whether that be as an expert witness explaining matters
to the judge or jury, or when explaining matters to the client. Forensic accounting
integrates investigative, accountancy, and communication skills.
Following are some of the main duties of the forensic accountant as an expert
witness:
1. To exercise reasonable skill and care in helping the court on matters within their
expertise
2. To comply with any relevant code of ethics, Civil Procedure Rules and court orders
3. To provide assistance so as to enable the court to deal with cases in accordance
with the overriding objective. However, such overriding duty does not mean that
experts should act as mediators between the parties or intrude upon the role of
the court in deciding facts.
Page | 233
4. To provide an independent opinion that is free from any litigation pressures. The
forensic accountant should neither engage in the role of an advocate nor promote
the viewpoint of the party by whom he is paid.
If any matters fall outside the purview of an expert’s expertise, he should disclose
such matters without delay and refrain from providing an opinion in relation to such
matters.
Computer-aided Data mining is a key part of many investigation processes. It allows the accountant
techniques to access and analyse thousands or millions of transactions that have passed through
an accounting system, and identify, say. Unusual trends far more quickly than by
traditional documentary analysis.100% of an entity's transactions can be checked for
characteristics such as date. Time, amount, approval, payee etc. If possible, data
should be gathered prior to the initial field visit to reduce the risk of the data being
compromised.
IFAC’s Code of Ethics for Professional Accountants applies to all ACCA members involved in professional
assignments, including forensic investigations. There are specific considerations in the application of each
of the principles in providing such a service.
Page | 234
Integrity: The forensic investigator is likely to deal frequently with individuals who lack integrity, are
dishonest, and attempt to conceal the true facts from the investigator. It is imperative that the
investigator recognises this, and acts with impeccable integrity throughout the whole investigation.
Objectivity: As in an audit engagement, the investigator’s objectivity must be beyond question. The report
that is the outcome of the forensic investigation must be perceived as independent, as it forms part of
the legal evidence presented at court. The investigator must adhere to the concept that the overriding
objective of court proceedings is to deal with cases fairly and justly. Any real or perceived threats to
objectivity could undermine the credibility of the evidence provided by the investigator.
This issue poses a particular problem where an audit client requests its auditors to conduct a forensic
investigation. In this situation, the audit firm would be exposed to threats to objectivity in terms of
advocacy, management involvement and self review.
The advocacy threat arises because the audit firm may feel pressured into promoting the interests and
point of view of their client, which would breach the overriding issue of objectivity in court proceedings.
Secondly, the investigators could be perceived to be involved in management decisions regarding the
implications of the fraud, especially where the investigator acts as an expert witness. It is however the
self-review threat that would be the most significant threat to objectivity. The self review threat arises
because the investigation is likely to involve the estimation of an amount (i.e. the loss), which could be
material to the financial statements.
For the reasons outlined above, The Code states that the firm should evaluate threats and put appropriate
safeguards in place, and if safeguards cannot reduce the threats to an acceptable level, then the firm
cannot provide both the audit service and the forensic investigation.
Professional competence and due care: Forensic investigations will involve very specialist skills, which
accountants are unlikely to possess without extensive training.
Such skills would include:
– Detailed knowledge of the relevant legal framework surrounding fraud,
– An understanding of how to gather specialist evidence,
– Skills in the safe custody of evidence, including maintaining a clear ‘chain’ of evidence, and
– Strong personal skills in, for example, interview techniques, presentation of material at court, and
tactful dealing with difficult and stressful situations.
It is therefore essential that forensic work is only ever undertaken by highly skilled individuals, under the
direction and supervision of an experienced fraud investigator. Any doubt over the competence of the
investigation team could severely undermine the credibility of the evidence presented at court.
Page | 235
Confidentiality: Normally accountants should not disclose information without the explicit consent of
their client. However, during legal proceedings arising from a fraud investigation, the court will require
the investigator to reveal information discovered during the investigation. There is an overriding
requirement for the investigator to disclose all of the information deemed necessary by the court.
Outside of the court, the investigator must ensure faultless confidentiality, especially because much of
the information they have access to will be highly sensitive.
Professional behavior: Fraud investigations can become a matter of public interest, and much media
attention is often focused on the work of the forensic investigator. A highly professional attitude must be
displayed at all times, in order to avoid damage to the reputation of the firm, and of the profession. Any
lapse in professional behaviour could also undermine the integrity of the forensic evidence, and of the
credibility of the investigator, especially when acting in the capacity of expert witness.
During legal proceedings, the forensic investigator may be involved in discussions with both sides in the
court case, and here it is essential that a courteous and considerate attitude is presented to all parties.
Forensic audit and accounting is a rapidly-growing area. The major accountancy firms all offer forensic
services, as do a number of specialist companies. The demand for these services arises partly from the
increased expectation of corporate governance codes for:
• Company directors to take seriously their responsibilities for the prevention and detection of fraud,
and also from
• Governments concerned about risks arising from criminal funding of terrorist groups.
Page | 236
Audit of Performance Information in the Public Sector
❖ Measurable
✓ Should have a good system to generate performance info (completeness and accuracy of data
ensured)
✓ Consistency in how information captured
✓ Consistency in how information reported
✓ Measures should be clearly defined
✓ Some measures might be more subjective if cannot measure precisely (for e.g. customer
satisfaction)
❖ Relevant
✓ Should address a valid concern
✓ Specific info needs of stakeholders
❖ Reliable
✓ Sample or 100%?
✓ Source and how info was generated- Internal control over this procedure
Reporting
- No specific format or wording.
- Generally, the auditor will provide a conclusion on whether the public sector entity has achieved its
objectives as shown by the reported performance information and concludes on the information
itself.
- The auditor will agree the type of conclusion with the public sector organisation and usually its
regulating body.
Often the performance information will be provided as part of the public sector organisation’s integrated
report, in which case the auditor’s conclusion will be included within the integrated report.
Page | 237
Technical Article: Performance Information in the Public Sector
The syllabus and study guide for THE ADVANCED AUDIT & ASSURANCE EXAM (INT), Advanced Audit and
Assurance (and SGP adapted paper) includes a section entitled ‘The audit of performance information
(pre-determined objectives) in the public sector’. This article is intended to provide insight into this
syllabus area and explain some of the issues of which candidates should be aware when studying this
aspect of the syllabus.
BACKGROUND
While the specifics will vary from country to country, in general public sector organisations are funded
wholly or partly by the government, and in turn by the tax payers in a particular jurisdiction. Public sector
organisations may include hospitals and other health care facilities such as ambulance services, schools
and universities, the police force and organisations responsible for public transport and the road network.
In some cases, such as the UK university sector, organisations do charge for services provided but still rely
on government funding to support their activities.
The government as well as other stakeholders will pay close attention to the performance of these
organisations to evaluate whether public funds are being used appropriately. The organisations should
aim to demonstrate that public monies allocated to them are being used effectively, that specific targets
are being met, and that appropriate decisions are being made in respect of long term planning. Essentially
the management and those charged with governance of a public sector organisation need to show that
the organisation is meeting its objectives and performing its role in society, and performance information
is likely to be required in order for this to be demonstrated. If a public sector organisation is not
performing well then, its funding may be cut and its management may be replaced; in extreme situations
the organisation may even be shut down.
This is supported by guidance issued by the public sector board of IFAC which notes that the primary
function of governments and most public sector entities is to provide services to constituents.
Consequently, their financial results need to be assessed in the context of the achievement of service
delivery objectives. Reporting non-financial as well as financial information about service delivery
activities, achievements and/or outcomes during the reporting period is necessary for a government or
other public sector entity to discharge its obligation to be accountable.
An example of how this is implemented is given below, taken from the UK’s National Health Service (NHS)
website:
Page | 238
• indicate where there is potential to improve the cost effectiveness of services through comparison
with other organisations
Source: [Link]/quality_and_service_improvement_tools/
Performance measures should be measurable and relevant if they are to be effective. Measurability
means trying to ensure that there is consistency in how performance information is captured and
reported. The measures should be clearly defined and unambiguous, but measurability is sometimes
difficult where the subject matter of the performance information is subjective in nature. For example for
an ambulance service it would be quite easy to measure the average time taken for an ambulance to
respond to an emergency as this is quantifiable, but more difficult to measure the patient’s satisfaction
with the service provided as this is based on the patient’s opinion.
An issue linked to measurability is the existence of data to generate the performance information. Much
of the work involved in setting up a good system for reporting on performance information is focussed on
ensuring the completeness and accuracy of supporting information and that the information is sufficiently
robust to withstand scrutiny.
Relevance means that the performance information addresses a valid concern and public sector
organisations should consider the specific needs of their stakeholders in developing relevant performance
measures. Continuing to using the UK’s NHS as an example, identified stakeholders who regularly review
the NHS performance information include:
• The government department responsible for health services
• Medical staff
• NHS management team and non-executive committee members
• Patients
• Private companies who supply to the NHS
• Academics and students researching the NHS
The NHS therefore has to produce a range of performance measures relevant to the needs of this wide
range of stakeholders. Different stakeholders have different needs, for example patients may focus on
the effectiveness of a certain medical procedure, whereas management may focus on the cost of
Page | 239
providing that procedure. Therefore, a very wide range of performance information may be required yet
it would be pointless to set targets and produce performance information on an issue which is not relevant
to any stakeholder.
In some jurisdictions it is part of the audit requirement for public sector organisations that the auditor
should report on performance information. In jurisdictions where this is not a requirement, the auditor
may be asked to perform a separate engagement to the financial statement audit, the objective of which
is to report specifically on the performance information. In either case, the auditor will need to plan
procedures in much the same way as in a conventional audit scenario. Candidates are therefore
encouraged to apply their existing knowledge of audit planning (risk assessment) and evidence gathering
techniques to this type of information. The auditor is still looking to ultimately report on the validity of
the information included in this respect. The auditor may find the principles of ISAE 3000 Assurance
Engagements other than Audits or Reviews of Historical Financial Information provide a useful framework
for planning and performing the work on performance information.
As with any engagement to provide assurance, this would likely start with an understanding of the entity
to ensure knowledge of the predetermined performance measures, an evaluation of the systems and
controls used to derive and capture the performance information and also performing substantive
procedures on the reported measures. The auditor will also need to understand the rationale behind the
measures that are being reported on, considering the relevance and suitability of them in terms of the
objectives of the public sector organisation in order to help assess the usefulness of the information being
provided.
Page | 240
Of course, the procedures must be specifically tailored to the performance information subject to the
audit. Further as in any audit, the working papers must contain a summary of findings and clear
conclusions on the procedures that have been performed.
Generally, the auditor will provide a conclusion on whether the public sector entity has achieved its
objectives as shown by the reported performance information and concludes on the information itself.
This conclusion may be in the form of a reasonable assurance conclusion – ie an opinion is expressed, or
may be in the form of a negative assurance conclusion – ie no opinion is expressed. Essentially, in the
absence of any jurisdiction specific requirements, the auditor will agree the type of conclusion with the
public sector organisation and usually its regulating body.
Often the performance information will be provided as part of the public sector organisation’s integrated
report, in which case the auditor’s conclusion will be included within the integrated report.
CONCLUSION
The audit of performance information in public sector organisations can be approached in a similar way
to the audit of KPIs in private sector organisations, and conventional audit techniques can be employed,
though they will need to be tailored to the specific measures that are subject to audit. In approaching
scenarios based on this syllabus area, candidates are encouraged to apply their understanding of audit
techniques to the specific information in the question and to avoid vague and unfocussed remarks.
Page | 241
The Audit of Social, Environmental, Sustainability and Integrated
Reporting
Sustainability in business
In business, sustainability refers to minimising the negative ( and maximising the positive) impact of the
organisation’s activities on the environment and society as a whole.
Instead of making decisions purely on financial basis, sustainable organisations consider different
environmental and social factors in their short, medium and long-term strategy.
For instance, sustainability in business can mean:
• Sourcing 100% renewable energy ( for example, solar, wind or hydro energy)
• Optimising supply chains to reduce greenhouse gas emissions (Supply chains include the handling of
the entire flow of goods and services, starting from purchasing the raw components from suppliers to
delivering the final product to customers. Green house gas emissions can be reduced by phasing out
fossil fuels such as coal, oil and gas and moving to renewable energy.)
• Using recycled paper only
• Donations and in-kind contributions to local community projects
• Fair and equitable performance appraisal and promotions of employees
Sustainability metrics
Sustainability metrics (also called key performance indicators or KPIs) are designed to measure the
company’s sustainability performance. They are tools with which the success of a company’s sustainability
strategies can be measured.
The main reason for using these indicators is to determine whether the company is meeting its objectives.
In case of a deviation, corrective measures can be introduced.
Each industry and organisation will have different metrics that are material to their business, but some
common sustainability metrics include:
Environmental metrics
- Energy consumption in kilowatt hour
- Water usage in metric tons
- Waste reduction in cubic meters
- Plastic reduction in metric tons
- Compliance with environmental standards
Social metrics
- Hours of volunteering carried out by employees
- Diversity and inclusion ( these are numerical statistics that can be monitored directly)
Page | 242
Governance metrics
- Board and management diversity metrics (in terms of gender, age, nationality, experience etc.)
- Disclosure and reporting programs ( for example, does the company publish a sustainability report
using reporting frameworks, set targets and report progress)
Sustainability reporting
- A sustainability report is an assessment of environmental factors, social responsibility and governance
matters in the organisation’s policies and practices.
- It looks at the organisation’s strategy for future sustainability and its achievements in this area.
- In selecting what to report, organisations are likely to start off by creating a list of relevant
topics(metrics and information) for inclusion in the sustainability report. They would then prioritise
the information based on significance to stakeholders and the organisation and decide the level and
detail of coverage to be included in the report. They need to ensure that the report provides a
reasonable and balanced representation of the organisation’s sustainability performance.
Assurance plays an important role in building trust around the robustness of reported information. It
verifies the organisation’s claims of environmental friendliness and ethical conduct, which can help in
building trust in sustainability reports, making them more credible.
The following is a summary of the technical article written by the AAA exam team. This should be
comprehensively prepared for the AAA exam.
Page | 243
The Assurance of Social, Environmental and Sustainability Information
The background
Management prepares reports on social, environmental and sustainability information. When
management provides this type of information it is known as Extended External Reporting (EER), which is
a requirement for listed and larger private companies in some jurisdictions.
Companies can choose to include this type of information within their annual report or to produce stand-
alone reports on social, environmental and sustainability matters.
In the last decade, Integrated Reporting <IR> has become common, which aims to provide a holistic view
of the company’s financial and non-financial performance and its potential for long term value creation.
Auditors may be asked to review the information as part of their review of the annual report, or as a
separate assurance engagement ( a highly specialist area).
• Stakeholder needs: Increasingly shareholders, especially larger investors like pension funds, are
demanding more information of the impact of a company on the environment and society.
• Voluntary disclosure: Companies may seek to gain a competitive advantage by declaring their ‘green
credentials’. Such voluntary disclosure may be subject to management bias as the reporting
requirements are not specified under legislation.
Page | 244
Examples of performance measures
Assurance providers are faced with understanding what is being reported upon and why (legislative or
commercial reasons), as well how the information is being obtained, collated and presented.
The reporting of these benchmarks may be presented in different ways, for example, one company may
produce a table of financial information to report on subject matter, whereas another may choose to report
using non-financial or narrative disclosures. Comparison between companies, even within the same
industry, is problematic due to the lack of consistency in selecting which measures to disclose, how the
information is presented and how metrics are quantified.
Example of a water consumption disclosure within the sustainability reporting section of the Annual
Report 2020 for MMC Corporation:
Page | 245
The assurance of social, environmental and sustainability information
1. Review of the contents of the annual report as part of the statutory financial statements audit
engagement
OR
In both cases, when faced with planning an assurance engagement of non-financial criteria, such as those
relating to the environment or sustainability, the fundamentals of existing auditing and assurance
standards may be used as a basis for the engagement team (for example risk assessment)
1. Review of non-financial information which is part of the annual report or integrated report
Guidance on the review of non-financial information as part of the annual report is covered by ISA
720 (Revised).
Auditors need to consider whether there is a material inconsistency between the other information
and the financial statements.
Auditors should consider all auditing standards, but a few key ones which may be relevant to the
review of other information are:
Page | 246
• Appropriateness of • If there has been a • There may be industry
methods of calculation breach of regulations, standard
and whether the basis for for example if any measurements which are
estimations are required environmental used (example) or the criteria
reasonable and disclosures are not may be more widely
appropriate – this may be given, there may be recognised, such as
an issue where there are implications for the greenhouse gas emissions.
no industry standard financial statements,
measurements such as provisions for • Internal controls of the
established and fines. This increases client – consideration of the
management is audit risk. Breaches of reliance which can be placed
responsible for deciding laws or regulations may on the information and
on the parameters of the even impact the ability whether this information is
estimation. of the company to internally or externally
continue to trade, for generated.
example licences to
trade may be subject to • Information from third
adhering to laws and parties, these could include
regulations, or fines or environmental bodies
penalties may be (governmental or private) and
substantial enough to the reliance which can be
significantly impact the placed on this information.
cash flow of an entity.
Page | 247
Example from the Annual Report 2021 from Kier Plc 2021
Page | 248
Challenges in Providing assurance on performance measures
Information There may be deficiencies in the controls and internal tools used by the
internally generated company to collect and measure the information, and the controls may not be
(firm might not as established or robust as those within the financial reporting system which is
identify internal more familiar to the assurance practitioner.
control deficiencies) This means that there is a higher risk of the assurance provider not identifying
control deficiencies.
Information from This may include information from sources such as:
third party sources • entities within the supply chain (suppliers, contractors)
• external agencies e.g. carbon offset registries, industry benchmark
specialists, external carbon dioxide calculation tools.
✓ The reliance which can be placed upon the evidence from third party
sources will need to be assessed by the assurance provider using their
professional judgement.
✓ There will need to be an understanding of how the information is
collected and what, if any, recognized standards it adheres to.
✓ This is an area where the use of an independent expert may be
required in order to identify whether any specialist information is
consistent and relevant to the industry.
However, there may be financial evidence to support some of the information in the report, as well as
discussions with management or review of the board minutes.
In the AAA exam, these will need to be tailored to the scenario given where possible.
The audit evidence obtained, depending on the level of assurance required by the scope of the
engagement (limited or reasonable), should be reviewed using the professional judgement of the
assurance provider.
Responses from management should be viewed with an element of professional scepticism and
considered in the light of the substantive work undertaken.
Page | 249
Professional scepticism may need to be applied to mitigate the risk of management bias in the reported
figures, especially where there are significant impacts on the business if the report is to be relied upon
by third parties, such as financial institutions, government bodies or those issuing licences to trade, which
is common in regulated industries like energy production and supply.
Example
A manufacturer reports on the wastage and pollution in its sustainability report.
The content and scope of the assurance provider’s report must be considered
1. Consider if the report is to be included within the financial statements + which stakeholders will be
relying upon it + what level of assurance is required.
2. There should be an explicit reference to national or international standards for quality management
and any reporting requirements which have been adhered to.
ISAE 3000 also requires that the practitioner should be aware of whether any errors in the final assurance
report may lead to reputational damage to the assurance provider.
EER and sustainability reporting is a rapidly changing specialism, and the assurance provider will need to
ensure that they have sufficient expertise and experience when accepting engagements of this type.
Page | 250
Exam technique
The AAA exam does not require knowledge of specific sustainability or climate reporting standards,
however students may be asked in the exam to assess a scenario whereby the assurance provider is asked
to consider the risks of a non-financial engagement.
Students should apply their knowledge of auditing and assurance standards and evaluate the risks in an
exam question:
1. Read the requirement carefully – consider whether the engagement is part of the statutory review of
the annual report (and the application of ISA 720 is required) or a separate assurance engagement.
2. Evaluate the risks in the engagement and consider how may the assurance practitioner mitigate
these. Think about some of the problems faced by assurance providers such as challenges in
measuring and comparing information across companies and industries (see 'Measuring and
reporting' in this article).
3. Application of knowledge of auditing and assurance standards (such as those stated above, although
some scenarios may also benefit from reference to other standards) when asked to review or provide
assurance on a report.
4. Justify the responses, if procedures are requested in the exam, then consider what reasonable
evidence may be obtained and why it is that this is being reviewed.
International Standard on Sustainability Assurance (ISSA) 5000, General Requirements for Sustainability
Assurance Engagements.
International Standard on Sustainability Assurance (ISSA) 5000, General Requirements for Sustainability
Assurance Engagements is being developed by the International Sustainability Standards Board (ISSB) with
the aim of providing guidance about assurance on sustainability information disclosed in sustainability
reports. It is expected to be issued by the end of 2024.
The standard will be ‘profession-agnostic’ which means that it can be used by professional accountants as
well as non-professional accountant assurance practitioners in performing sustainability assurance
engagements.
The following technical article by the AAA exam team is very important for September 2024 to June
2025 exam attempts.
Page | 251
For the profession, there is an increased demand for independent assurance to be provided on this
information. For example, in the European Union, the Corporate Sustainability Reporting Directive
requires organisations that fall within its scope to report sustainability information and over the next few
years they will also be required to obtain assurance on their reported sustainability information.
For assurance providers, increased demand for assurance provides a commercial opportunity. There are
challenges in undertaking such engagements, but there are there are steps that the assurance provider
can take to mitigate these. One specific area of potential difficulty relates to ethics, and this article will
also consider how assurance providers should identify and respond to ethical threats.
Multiple frameworks
• ISSA 5000 (ED) is intended to apply under ‘multiple frameworks’. There are many different reporting
frameworks which organisations may be required, or choose to, comply with. Reporting frameworks
such as the Global Reporting Initiative, Integrated Reporting, and the Task Force on Climate-Related
Financial Disclosures (TCFD) have developed over time. The International Sustainability Standards
Board (ISSB) has issued two Sustainability Reporting Standards – IFRS S1 and IFRS S2. There are local
regulations too, for example the EU has endorsed European Sustainability Reporting Standards (ESRS).
Many organisations report under the scope of several frameworks, which is why it is important that
ISSA 5000 (ED) can be applied whichever framework(s) are being applied.
The second point to note is that ISSA 5000 (ED) is ‘profession agnostic’. This means that it can be used by
any assurance practitioner as long as:
1. They adhere to relevant ethical requirements, and
2. Apply a system of quality management system which is at least as rigorous as those used by
accounting practitioners.
This means that non-accountancy professionals can use ISSA 5000, for example, experts in environmental
matters or scientists.
Page | 252
What is ‘sustainability’ in the context of sustainability reporting?
ISSA 5000 (ED) defines ‘sustainability matters’ as ‘environmental, social, economic and cultural matters,
including the impacts of an entity’s activities, products and services on the environment, society, economy
or culture, or the impacts on the entity; and the entity’s policies, performance, plans, goals and
governance relating to such matters’.
ISSA 5000 (ED) goes further and provides examples of topics which may be included in sustainability
information:
• Climate, including emissions.
• Energy, such as type of energy and consumption.
• Water and effluents, such as water consumption and water discharge
• Biodiversity, such as impacts on biodiversity or habitats protected and restored.
• Labour practices, such as diversity and equal opportunity, training and education, and occupational
health and safety.
• Human rights and community relations, such as local community engagement, impact assessments
and development programs.
• Customer health and safety.
• Economic impacts, such as government assistance, tax strategy, anti-competitive behaviour, anti-
corruption and market presence.
There is a wide range of information that may be provided, and it could be provided in various ways, for
example, in narrative disclosures, in tables of figures including performance indicators, in diagrams or
graphics.
Objectives
The objectives of ISSA 5000 (ED) are:
(a) To obtain reasonable assurance or limited assurance, as applicable, about whether the sustainability
information is free from material misstatement;
(b) To express a conclusion on the sustainability information through a written report that conveys a
reasonable assurance or a limited assurance conclusion, as applicable, and describes the basis for the
conclusion; and
(c) To communicate further as required by this ISSA and any other relevant ISSA’.
Page | 253
ISSA 5000 (ED) contains an appendix which illustrates different forms of assurance reports which can be
provided, distinguishing between those reports which include limited and reasonable assurance
conclusions. In line with other types of assurance engagement, the higher the level of assurance that is to
be provided, more robust evidence is required to support the conclusion given by the assurance
practitioner.
ISSA 5000 (ED) highlights the importance of both firm-level and engagement-level quality management,
stating that the engagement leader shall take overall responsibility for managing and achieving quality on
the engagement and also requiring that the engagement leader must have competence and capabilities
in assurance skills and techniques developed through extensive training and practical application. The
engagement leader is also responsible for ethical considerations and ensuring that sufficient and
appropriate resources are allocated to the engagement.
There is detailed guidance relating to the assurance team, with particularly emphasis on the relationship
between the engagement team and ‘other practitioners’ and whether it is appropriate to use the work of
others. There is also recognition that information on which assurance is provided is often derived from
sources up and down the value chain of the reporting entity, so careful planning is required to ensure that
the assurance team can obtain sufficient appropriate evidence in a timely manner.
Page | 254
The assurance practitioner must use risk assessment procedures, including procedures relating to fraud.
The requirements vary depending on whether the engagement is to provide limited or reasonable
assurance. For example, in reasonable assurance engagements, more work is needed on understanding
the system of internal control.
Materiality
Materiality is a significant issue, and it needs to be applied using a ‘bifurcated’ approach. This means
considering materiality for qualitative disclosures and determining materiality for quantitative
disclosures. Materiality for a reasonable assurance engagement is the same as for a limited assurance
engagement because materiality is based on the information needs of intended users.
However, it is important to understand that the organisation will have its own materiality process,
including ‘double materiality’. This means consideration of the significance of the impact of a sustainability
matter on the organisation, as well as the significance of the impacts of the business activity on the outside
world (‘impact materiality’). The assurance provider needs to understand the organisation’s materiality
process, but this is separate from their own materiality considerations.
Where the concept of double materiality is relevant, the assurance practitioner should consider both
financial and impact materiality when determining their materiality level for the purposes of planning and
performing the engagement. It should be noted that the IAASB’s view is that it will not be relevant to
every engagement.
It is important to note that when considering the materiality of potential misstatements, as with
performance materiality, these may be both quantitative and qualitative in nature.
Obtaining evidence
When responding to risks of material misstatement, in designing and performing further audit procedures,
the requirements vary depending on whether it is a limited assurance or a reasonable assurance
engagement. For a reasonable assurance engagement:
ISA 5000 (ED) acknowledges that qualitative sustainability information and estimates or forward-looking
information are both potentially difficult areas over which to obtain evidence. Therefore, the assurance
practitioner must exercise significant professional judgement in evaluating what constitutes sufficient
appropriate evidence in these circumstances.
Often, sustainability information is forward-looking and based on estimates and future plans.
Organisations produce scenarios based on best-estimate or hypothetical assumptions which might be
subject to management bias or great uncertainty. Evidence can therefore be difficult to obtain, and the
assurance practitioner may need to exercise a significant level of judgement in determining whether they
have obtained sufficient and appropriate evidence.
Page | 255
Also, as already stated, this is in addition to the evidence which may be required from external experts
and parties within the entity’s value chain. It is essential that sufficient time and resources are assigned
to the engagement.
Reporting
It is important that users of assurance reports understand the level of assurance being provided. The
report must state that ‘the procedures in a limited assurance engagement vary in nature and timing from,
and are less in extent than for, a reasonable assurance engagement and, consequently, the level of
assurance obtained in a limited assurance engagement is substantially lower than the assurance that
would have been obtained had a reasonable assurance engagement been performed’.
These risks, when coupled with the potential difficulties of obtaining evidence over qualitative disclosures
and future-oriented information means that there can be danger of issuing an inappropriate assurance
opinion. There is a reputation risk for the assurance provider if they report positively on sustainability
information which turns out to the incorrect, inaccurate or exaggerated.
Given the risks of greenwashing mentioned previously, there is a need to apply professional scepticism
and to document how this has been applied as part of obtaining the evidence which backs up the
assurance conclusion.
Perhaps the most obvious threat to ethics relates to the assurance provider’s professional competence.
While many organisations have been reporting on sustainability matters for years, for assurance providers
the new reporting standards are largely unfamiliar territory, so there is a real issue that professional
accountants lack the necessary knowledge to provide assurance on sustainability information. Knowledge
can be developed but a deeper level of understanding cannot be developed overnight. An assurance
provider could have a self-interest threat in securing an engagement to report on sustainability
Page | 256
information, giving the firm a foothold in a potentially lucrative new line of work. So, for purely
commercial reasons, the audit firm might take on the job even if they are not competent to do it.
There could also be a self-review threat if an assurance provider is performing the external audit of
financial statements as well as working on the sustainability information of the organisation. In this case,
the assurance provider should make sure that separate teams are used for the different aspects of work.
Ultimately the audit firm would need to apply appropriate professional behaviour, ensuring that
commercial objectives are not prioritised over principles of integrity.
Exam focus
Candidates may be required to consider scenario specific risks in the exam, such as pressures to meet
reporting deadlines, requirements or meeting finance covenants. There may be estimations or other
areas where management judgement has been applied. As in a financial assurance engagement,
candidates should be aware of potential bias by management and the need to obtain sufficient and
appropriate audit evidence.
SBR re-cap
IFRS S1 ‘General Requirements for Disclosure of Sustainability-related Financial Information’ and IFRS
S2 ‘ Climate-related Disclosures’ by The International Sustainability Standards Board (ISSB) .
These standards provide a common language for sustainability related disclosures and have been
developed to work with any financial reporting framework.
They are designed to ensure that companies provide information regarding their sustainability related
risks and opportunities which are relevant to decision-making by investors as they can influence an
company’s cash flows or access to finance.
IFRS S1
IFRS S1 provides a set of disclosure requirements designed to enable companies to communicate to
investors about the identified sustainability-related risks and opportunities they face over the short,
medium and long term.
Page | 257
Risk management The processes the company uses to identify, assess, prioritise and monitor
sustainability-related risks and opportunities
Metrics and The company’s performance in relation to sustainability-related risks and
targets opportunities, including progress towards any targets the company has set or is
required to meet by law or regulation
IFRS S1 provides important guidance on the assessment of materiality which determines which particular
disclosures the company needs to give, given its particular circumstances.
A company must disclose ‘material information’ about its sustainability related risks and opportunities.
Information is considered to me material “if omitting, misstating or obscuring that information could
reasonably be expected to influence decisions that primary users of general purpose financial reports
make on the basis of those reports.”
IFRS S1 also requires that the information provided provides a “complete, neutral and accurate
depiction” of sustainability related risks and opportunities.
The sustainability-related disclosures must be reported in the annual report. at the same time as the
company’s related financial statements and are required to cover the same reporting period as the
related financial statements.
IFRS S2
IFRS S2 builds on the requirements of IFRS S1 and is focused on climate-related disclosures.
Its core content mirrors the four topics from IFRS S1 (i.e. governance, strategy, risk management and
metrics and targets) but require further detail with a focus on climate related physical and transition risks
and opportunities .
Physical risks relate to the physical impact of climate change. Examples of climate related physical risks
include floods, wildfires, rising temperatures, increased severity of extreme weather events, such as
cyclones, hurricanes etc.
Transition risks are business-related risks associated with moving to a more climate-friendly future. This
may include extensive policy, legal,technology and market changes to address the changing regulatory
requirements, consumer preferences and investor expectations. Examples of changes which could lead to
risks include new energy procurement practices and potential carbon taxes etc.
Investors needs this information to see how climate affects the company’s current performance and
future prospects.
Examples of disclosures that need to be made under IFRS S2 include climate targets that the company has
set such as emission targets and how it plans to achieve them and the current and anticipated effects of
climate related risks and opportunities on the company’s financial performance, position and cash flows.
Page | 258
Data Analytics and the Auditor
Technical Article
Data analytics has been around in various forms for a long time, but businesses are finding increasingly
sophisticated and timely methods to utilise data analytics to enhance their operations. Data analytics
enable businesses to identify new opportunities, to harness costs savings and to enable faster more
effective decision making. Whether it is the ability to identify potential for new products and services or
to detect the potential loss of clients in order to direct efforts to encourage them to stay, data analytics is
everywhere in business today.
At a basic level data analytics is examining the data available to draw conclusions. This isn’t a new concept
but there are growing trends towards more integrated and more timely use of data from multiple sources
to help inform business decisions or to draw conclusions. The data used by companies is likely to be both
internal and external and include quantitative and qualitative data.
This is often aided by specialised software which may have to be developed to enable the information
from many different sources and formats to be first combined and then analysed. In some cases, the
formats covered include audio and visual analysis in addition to the usual text and number formats.
Page | 259
The larger audit firms and increasingly smaller firms utilise data analytics as part of their audit offering to
reduce risk and to add value to the client. Bigger firms often have the resources to create their own data
analytics platforms whereas smaller firms may opt to acquire an off the shelf package. There is no one
universal audit data analytics tool but there are many forms developed inhouse by firms. These tools are
generally developed by specialist staff and use visual methods such as graphs to present data to help
identify trends and correlations.
For auditors, the main driver of using data analytics is to improve audit quality. It allows auditors to more
effectively audit the large amounts of data held and processed in IT systems in larger clients. Auditors can
extract and manipulate client data and analyse it. By doing so they can better understand the client’s
information and better identify the risks. Data analytics tools have the power to turn all the data into pre-
structured forms/presentations that are understandable to both auditors and clients and even to
generate audit programmes tailored to client-specific risks or to provide data directly into computerised
audit procedures thus allowing the auditor to more efficiently arrive at the result.
Page | 260
✓ data can be more easily manipulated by the auditor as part of audit testing, for example performing
sensitivity analysis on management assumptions
✓ increased fraud detection through the ability to interrogate all data and to test segregation of duties,
and information obtained through data analytics can be shared with the client, adding value to the
audit and providing a real benefit to management in that they are provided with useful information
perhaps from a different perspective
Page | 261
Conclusion
Data analytics tools which can interact directly with client systems to extract data have the ability to allow
every transaction and balance to be analysed and reported. The increase in computerisation and the
volumes of transactions has moved audit away from an interrogation of every transaction and every
balance and the risk-based approach which was adopted increased the expectation gap further.
With data analytics, there is a chance to redress some of this balance and for auditors to have the ability
to test more transactions and balances. This may increase the chances of detecting certain types of fraud
or the ability to identify inefficiencies and opportunities for a clients’ business however as yet it still can’t
predict the future and the need for auditors to assess judgements and the future of the firm as well as the
past means auditors aren’t replaced by computers just yet.
Although audit analytics are most frequently applied to transactions in financial or operational audits,
they have also been proven to be very effective in IT audit and security reviews, where, for example, they
are used for analysis of Segregation of Duties, of system configuration settings and of systems access logs.
Using analytical The procedures listed below are taken from the applicable audit standards
procedures brings more and their appendices. Data analysis software is a critical tool for effectively
details to the auditor's performing these procedures.
attention and will lower
the risk that the auditor • Analyze unusual or unexpected relationships identified in earlier
might not be able to analytical procedures
detect material fraud or • Perform disaggregated analysis of revenue (by month or quarter, by
error. product line, etc.)
• Disaggregated analysis of expenses/expenditures and Payroll
• Identify and test journal entries made at the end of reporting periods
Analytical procedures and other unusual entries
include everything from • Identify accounting estimates for review; analyze underlying details
simple financial • Perform cut-off procedures at period end
statement balance and
ratio comparisons to
Page | 262
complex correlations, • Compare inventory quantities for current period with prior periods by
time series and trend class or category of inventory, location or other criteria, or comparison
analyses; however, they of quantities counted with perpetual records
also include visually • Perform a computerized match of the vendor list with a list of
scanning records to employees to identify matches of addresses or phone numbers
identify large and • Perform a computerized search of payroll records to identify duplicate
unusual items. addresses, employee identification or taxing authority numbers or bank
Scanning the general accounts
ledger or subsidiary • Analyze sales discounts and returns for unusual patterns or trends
accounts looking for • Review the propriety of large and unusual expenses (requires data
unusual items is highly extraction)
effective with data
analysis software, which
provides the ability to
summarize the details
then drill down to
further investigate
anything that raises
concerns or questions
about errors that might
exist.
For example, all transactions for the period can be summarized by account
and by journal source. A quick review of the results can tell the auditor such
things as:
- What types of entries exist
- Whether there are a high number of manual journal entries and what
accounts are most often affected
- Volume of activity in loan accounts
Page | 263
Materiality
Control assessment and Internal controls over the major transaction classes include manual and
testing automated control activities that assure management's directives are
carried out.
With the use of data
analytics, the following In most companies today, IT significantly affects control activities, especially
can be done in the areas of authorization and segregation of duties (through passwords
- Examination of and other access controls), accuracy, and completeness (through IT general
100% of controls over program change control and processing controls in each
transactions to significant application).
determine whether
each transaction Testing controls to determine reliability of details will be needed if the
appears to comply information system data is to be used for these kinds of analytical
with a specific procedures.
control rule
- Examination of Data analysis software is useful in facilitating tests of controls: it calculates
100% of sample sizes based on the desired confidence level and precision, and
transactions to computes achieved confidence to help the auditor document his or her
determine whether conclusions.
there is an
indication of
activities occurring
for which no control
has been
implemented
Substantive Testing Analysis of transactions (or a statistical sample) to determine whether they
are complete, valid and accurate.
• Comparing the last time an item was bought with the last time it was
sold, for cost/NRV purposes.
• Inventory ageing and how many days inventory is in stock by item.
Page | 264
• Receivables and payables ageing and the reduction in overdue debt over
time by customer.
• Analyses of revenue trends split by product or region.
• Analyses of gross margins and sales, highlighting items with negative
margins.
• Detailed recalculations of depreciation on fixed assets by item, either
using approximations (such as assuming sales and purchases are mid-
month) or using the entire data set and exact dates.
• Analyses of capital expenditure v repairs and maintenance.
In the AAA Exam, the examiner expects you to be able to evaluate and interpret results of data analytics
tools in order to ensure that you understand the use of and output from data analytics.
Please read through the examples below in order to meet the examiner’s expectations.
Example 1
The Center for Audit Quality, affiliated with the American Institute of CPAs (AICPA), released a Practice
Aid on Journal Entry Testing. The guide lists the following 16 queries that can be performed using data
analysis software:
Find journal entries that do not Find gaps in journal entry Find high-dollar journal entries
balance number sequence
Find possible duplicate account Find round-dollar journal entries Show journal entry information
entries by employee
Find all entries made by a Show value for the ‘journal entry Find manual entries
specific employee type code
Sample journal entries (random Find specific journal entries (by Find all entries containing
or high dollar) month, day or number) specific accounts
Find all entries within a range of Find post-dated entries Find entries with unusual/non-
accounts standard descriptions
Find journal entries posted on weekends
Page | 265
Example 2
The following is an example of how data analysis can be used early and often to save time and minimize
the risk of material misstatement:
Big Kachina, Inc. is a rapidly expanding multi-location retailer of business equipment. Total assets are
$12,000,000, including $9,914,148 in accounts receivable. The accounts receivable aging report provided
by the client showed more than $252,000 past due by 120 days or more. An electronic version of the
detailed report was obtained and further analysis helped document a decision to examine more current
account receivable balances separately from those past due by 120 or more days.
In less than 20 minutes, the auditor was able to perform the following steps:
Example 3
Page | 266
FIXED ASSETS TESTS ACCOUNTS RECEIVABLE TESTS
• Fixed assets additions • Aging by due date or invoice date
• Asset category summary • Accounts with balances or transactions
• Recalculate straight line depreciation exceeding credit limits
• Recalculate declining balance depreciation • Accounts with credit balances
• Depreciation exceeding cost • Transactions around a date range
• Duplicate field search • Duplicate transactions
• Debtor transaction summary
Page | 267