PSAE 3000 (Revised), Assurance Engagements Other than Audits or Reviews of
Historical Financial Information
Assurance Vs Non-assurance Engagement
a) Assurance engagement―An engagement in which a practitioner aims to obtain
su4icient appropriate evidence in order to express a conclusion designed to enhance the
degree of confidence of the intended users other than the responsible party about the
subject matter information (that is, the outcome of the measurement or evaluation of an
underlying subject matter against criteria). Each assurance engagement is classified on two
dimensions: (Ref: Para. A3)
(i) Either a reasonable assurance engagement or a limited assurance engagement:
a. Reasonable assurance engagement―An assurance engagement in which the
practitioner reduces engagement risk to an acceptably low level in the circumstances of the
engagement as the basis for the practitioner’s conclusion. The practitioner’s conclusion is
expressed in a form that conveys the practitioner’s opinion on the outcome of the
measurement or evaluation of the underlying subject matter against criteria.
b. Limited assurance engagement―An assurance engagement in which the practitioner
reduces engagement risk to a level that is acceptable in the circumstances of the
engagement but where that risk is greater than for a reasonable assurance engagement as
the basis for expressing a conclusion in a form that conveys whether, based on the
procedures performed and evidence obtained, a matter(s) has come to the practitioner’s
attention to cause the practitioner to believe the subject matter information is materially
misstated. The nature, timing, and extent of procedures performed in a limited assurance
engagement is limited compared with that necessary in a reasonable assurance
engagement but is planned to obtain a level of assurance that is, in the practitioner’s
professional judgment, meaningful. To be meaningful, the level of assurance obtained by the
practitioner is likely to enhance the intended users’ confidence about the subject matter
information to a degree that is clearly more than inconsequential.
b) Non-Assurance engagement – are those which are not assurance engagement.
Examples:
(a) Engagements covered by International Standards on Related Services (ISRS), such as agreed-upon
procedure and compilation engagements;2
(b) The preparation of tax returns where no assurance conclusion is expressed; and
(c) Consulting (or advisory) engagements, such as management and tax consulting.
Types of Assurance Engagements
Assurance engagements include both attestation engagements, in which a party other
than the practitioner measures or evaluates the underlying subject matter against the
criteria, and direct engagements, in which the practitioner measures or evaluates the
underlying subject matter against the criteria.
a. Attestation engagement―An assurance engagement in which a party other than the
practitioner measures or evaluates the underlying subject matter against the criteria. A party
other than the practitioner also often presents the resulting subject matter information in a
report or statement. In some cases, however, the subject matter information may be
presented by the practitioner in the assurance report. In an attestation engagement, the
practitioner’s conclusion addresses whether the subject matter information is free from
material misstatement. The practitioner’s conclusion may be phrased in terms of:
(i) The underlying subject matter and the applicable criteria;
(ii) The subject matter information and the applicable criteria; or
(iii) A statement made by the appropriate party.
b. Direct engagement―An assurance engagement in which the practitioner measures or
evaluates the underlying subject matter against the applicable criteria and the practitioner
presents the resulting subject matter information as part of, or accompanying, the
assurance report. In a direct engagement, the practitioner’s conclusion addresses the
reported outcome of the measurement or evaluation of the underlying subject matter
against the criteria.
Scope
This ISAE covers assurance engagements other than audits or reviews of historical
financial information, as described in the International Framework for Assurance
Engagements (Assurance Framework).
Question: How do you know if the engagement is other than audit or review, refer to the level
of assurance required of the auditor.
Source: PSAE 3000 (Revised), Assurance Engagements Other than Audits or Reviews of
Historical Financial Information.
[Link]
Philippine Standards on Review Engagements 2400
ENGAGEMENTS TO REVIEW FINANCIAL STATEMENTS
Objective of a Review Engagement
The objective of a review of financial statements is to enable an auditor to state whether, on
the basis of procedures which do not provide all the evidence that would be required in an
audit, anything has come to the auditor's attention that causes the auditor to believe that
the financial statements are not prepared, in all material respects, in accordance with
generally accepted accounting principles in the Philippines (negative assurance).
General Principles of a Review Engagement
The auditor should comply with the “Code of Professional Ethics for Certified
Public Accountants” promulgated by the Board of Accountancy. Ethical
principles governing the auditor's professional responsibilities are:
(a) independence;
(b) integrity;
(c) objectivity;
(d) professional competence and due care;
(e) confidentiality;
(f) professional behavior; and
(g) technical standards.
The auditor should plan and perform the review with an attitude of professional
skepticism recognizing that circumstances may exist which cause the financial
statements to be materially misstated.
For the purpose of expressing negative assurance in the review report, the
auditor should obtain su4icient appropriate evidence primarily through inquiry
and analytical procedures to be able to draw conclusions.
Moderate Assurance
A review engagement provides a moderate level of assurance that the information
subject to review is free of material misstatement, this is expressed in the form of
negative assurance.
Terms of Engagement
The auditor and the client should agree on the terms of the engagement. The
agreed terms would be recorded in an engagement letter or other suitable form such
as a contract.
Matters that would be included in the engagement letter include:
• The objective of the service being performed.
• Management's responsibility for the financial statements.
• The scope of the review, including reference to this Philippine Standard on Auditing.
• Unrestricted access to whatever records, documentation and other information requested
in connection with the review.
• A sample of the report expected to be rendered.
• The fact that the engagement cannot be relied upon to disclose errors, illegal acts or other
irregularities, for example, fraud or defalcations that may exist.
• A statement that an audit is not being performed and that an audit opinion will not be
expressed. To emphasize this point and to avoid confusion, the auditor may also consider
pointing out that a review engagement will not satisfy any statutory or third party
requirements for an audit.
Planning
The auditor should plan the work so that an e4ective engagement will be performed.
In planning a review of financial statements, the auditor should obtain or update the
knowledge of the business including consideration of the entity's organization, accounting
systems, operating characteristics and the nature of its assets, liabilities, revenues and
expenses.
Work Performed by Others
When using work performed by another auditor or an expert, the auditor should be satisfied
that such work is adequate for the purposes of the review.
Documentation
The auditor should document matters which are important in providing evidence to support
the review report, and evidence that the review was carried out in accordance with this PSA.
Procedures and Evidence
• Obtaining an understanding of the entity's business and the industry in which it operates.
• Inquiries concerning the entity's accounting principles and practices.
• Inquiries concerning the entity's procedures for recording, classifying and
summarizing transactions, accumulating information for disclosure in the
financial statements and preparing financial statements.
• Inquiries concerning all material assertions in the financial statements.
• Analytical procedures designed to identify relationships and individual items
that appear unusual. Such procedures would include:
- Comparison of the financial statements with statements for prior periods.
- Comparison of the financial statements with anticipated results and financial
position.
- Study of the relationships of the elements of the financial statements that would be
expected to conform to a predictable pattern based on the entity's experience or
industry norm.
Conclusions and Reporting
The review report should contain a clear written expression of negative assurance. The
auditor should review and assess the conclusions drawn from the evidence obtained as the
basis for the expression of negative assurance.
Based on the work performed, the auditor should assess whether any information obtained
during the review indicates that the financial statements are not presented fairly, in all
material respects, in accordance with generally accepted accounting principles in the
Philippines.
Source: Philippine Standards on Review Engagements 2400 ENGAGEMENTS TO REVIEW
FINANCIAL STATEMENTS
[Link]
PHILIPPINE STANDARD ON RELATED SERVICES 4400 (REVISED)
AGREED-UPON PROCEDURES ENGAGEMENTS
Source: PHILIPPINE STANDARD ON RELATED SERVICES 4400 (REVISED)
AGREED-UPON PROCEDURES ENGAGEMENTS
[Link]
Philippine Standards on Related Services 4410
ENGAGEMENTS TO COMPILE FINANCIAL INFORMATION
Objective of a Compilation Engagement
The objective of a compilation engagement is for the accountant to use accounting
expertise, as opposed to auditing expertise, to collect, classify and summarize financial
information. This ordinarily entails reducing detailed data to a manageable and
understandable form without a requirement to test the assertions underlying that
information. The procedures employed are not designed and do not enable the accountant
to express any assurance on the financial information. However, users of the compiled
financial information derive some benefit as a result of the accountant's involvement
because the service has been performed with professional competence and due care.
A compilation engagement would ordinarily include the preparation of financial statements
(which may or may not be a complete set of financial statements) but may also include the
collection, classification and summarization of other financial information.
General Principles of a Compilation Engagement
The accountant should comply with the "Code of Professional Ethics for Certified Public
Accountants" promulgated by the Board of Accountancy. Ethical principles governing the
accountant's professional responsibilities for this type of engagement are:
(a) integrity;
(b) objectivity;
(c) professional competence and due care;
(d) confidentiality;
(e) professional behavior; and
(f) technical standards.
Independence is not a requirement for a compilation engagement. However, where the
accountant is not independent, a statement to that e4ect would be made in the
accountant's report.
In all circumstances when an accountant's name is associated with financial information
compiled by the accountant, the accountant should issue a report.
Defining the Terms of the Engagement
The accountant should ensure that there is a clear understanding between the client and the
accountant regarding the terms of the engagement. Matters to be considered include the:
• Nature of the engagement including the fact that neither an audit nor a review will be
carried out and that accordingly no assurance will be expressed.
• Fact that the engagement cannot be relied upon to disclose errors, illegal acts or other
irregularities, for example, fraud or defalcations that may exist.
• Nature of the information to be supplied by the client.
• Fact that management is responsible for the accuracy and completeness of the
information supplied to the accountant for the completeness and accuracy of the compiled
financial information.
• Basis of accounting on which the financial information is to be compiled and the fact that
it, and any known departures therefrom, will be disclosed.
• Intended use and distribution of the information, once compiled.
• Form of report to be rendered regarding the financial information compiled, when the
accountant's name is to be associated therewith.
An engagement letter will be of assistance in planning the compilation work. It is
in the interests of both the accountant and the entity that the accountant send an
engagement letter documenting the key terms of the appointment. An
engagement letter confirms the accountant's acceptance of the appointment and
helps avoid misunderstanding regarding such matters as the objectives and scope
of the engagement, the extent of the accountant's responsibilities and the form of
reports to be issued. An example of an engagement letter for a compilation
engagement appears in Appendix 1 to this PSA.
Procedures
The accountant should obtain a general knowledge of the business and operations of the
entity and should be familiar with the accounting principles and practices of the industry in
which the entity operates and with the form and content of the financial information that is
appropriate in the circumstances.
To compile financial information, the accountant requires a general understanding of the
nature of the entity's business transactions, the form of its accounting records and the
accounting basis on which the financial information is to be presented. The accountant
ordinarily obtains knowledge of these matters through experience with the entity or inquiry
of the entity's personnel.
Other than as noted in this PSA, the accountant is not ordinarily required to:
(a) make any inquiries of management to assess the reliability and completeness of the
information provided;
(b) assess internal controls;
(c) verify any matters; or
(d) verify any explanations.
If the accountant becomes aware that information supplied by management is incorrect,
incomplete, or otherwise unsatisfactory, the accountant should consider performing the
above procedures and request management to provide additional information. If
management refuses to provide additional information, the accountant should withdraw
from the engagement, informing the entity of the reasons for the withdrawal.
The accountant should read the compiled information and consider whether it appears to
be appropriate in form and free from obvious material misstatements. In this sense,
misstatements include:
• Mistakes in the application of generally accepted accounting principles in the Philippines.
• Nondisclosure of generally accepted accounting principles in the Philippines and any
known departures therefrom.
• Nondisclosure of any other significant matters of which the accountant has become
aware.
The generally accepted accounting principles in the Philippines and any known departures
therefrom should be disclosed within the financial information, though their e4ects need not
be quantified.
If the accountant becomes aware of material misstatements, the accountant should try to
agree appropriate amendments with the entity. If such amendments are not made and the
financial information is considered
Responsibility of Management
The accountant should obtain an acknowledgment from management of its responsibility
for the appropriate presentation of the financial information and of its approval of the
financial information. Such acknowledgment may be provided by representations from
management which cover the accuracy and completeness of the underlying accounting
data and the
Source: Philippine Standards on Related Services 4410 ENGAGEMENTS TO COMPILE
FINANCIAL INFORMATION
[Link]
Here is an expanded explanation of the four Philippine Standards on Auditing, with a detailed
focus on the application and explanatory material for each standard.
PSA 200 (Revised and Redrafted): Overall Objectives of the
Independent Auditor and the Conduct of an Audit in Accordance with
Philippine Standards on Auditing
This foundational standard establishes the independent auditor's overall responsibilities and
objectives when conducting an audit of financial statements in accordance with PSAs. It
explains the nature and scope of an audit, defines key terms, and sets forth the core principles
that govern the auditor's professional conduct.
Overall Objectives of the Auditor
In conducting an audit of financial statements, the overall objectives of the auditor are twofold:
● To obtain reasonable assurance about whether the financial statements as a whole are
free from material misstatement, whether due to fraud or error, which enables the auditor
to express an opinion on whether the financial statements are prepared, in all material
respects, in accordance with an applicable financial reporting framework.
● To report on the financial statements and communicate as required by the PSAs, in
accordance with the auditor's findings.
If reasonable assurance cannot be obtained and a qualified opinion is insufficient, the PSAs
require the auditor to disclaim an opinion or withdraw from the engagement where legally
permissible.
Governing Principles and Concepts
To achieve the overall objectives, the auditor must adhere to a set of fundamental principles
throughout the audit engagement.
● Ethical Requirements: The auditor is required to comply with all relevant ethical
requirements, including those pertaining to independence, for financial statement audit
engagements. These requirements are ordinarily composed of Parts A and B of the Code
of Ethics for Professional Accountants in the Philippines.
● Professional Skepticism: The auditor must plan and perform an audit with professional
skepticism, which is defined as an attitude that includes a questioning mind, being alert to
conditions that may indicate possible misstatement due to error or fraud, and a critical
assessment of audit evidence.
● Professional Judgment: The auditor must exercise professional judgment in planning
and performing an audit of financial statements. This is the application of relevant training,
knowledge, and experience in making informed decisions about the appropriate courses
of action in the context of the audit.
● Sufficient Appropriate Audit Evidence and Audit Risk: To obtain reasonable
assurance, the auditor must obtain sufficient appropriate audit evidence to reduce audit
risk to an acceptably low level.
● Conduct of an Audit in Accordance with PSAs: The auditor must comply with all PSAs
relevant to the audit. An auditor cannot represent compliance with PSAs unless they have
complied with all requirements of this PSA and all other relevant PSAs.
Key Application and Explanatory Material
● Inherent Limitations of an Audit: The auditor cannot obtain absolute assurance
because of inherent limitations in an audit. These limitations do not justify being satisfied
with less-than-persuasive evidence, but they explain why audit risk can only be reduced,
not eliminated. They arise from:
○ The Nature of Financial Reporting: The preparation of financial statements
involves judgment by management. Many financial statement items involve
subjective decisions or a degree of uncertainty, such as the development of
accounting estimates. This creates an inherent level of variability that cannot be
eliminated by audit procedures.
○ The Nature of Audit Procedures: There are practical and legal limitations on the
auditor's ability to obtain evidence. For instance, management may not provide
complete information. More critically, fraud may involve sophisticated schemes
designed to conceal it, such as forgery or collusion, which can make audit evidence
appear valid when it is not. The auditor is not trained as an expert in document
authentication, and an audit is not an official investigation into wrongdoing.
○ Timeliness and Cost: Users of financial statements expect an opinion within a
reasonable period of time and at a reasonable cost. This creates a practical need to
balance the reliability of information with the cost of obtaining it, making it
impracticable to address all information that may exist or to pursue every matter
exhaustively.
● Application of Professional Skepticism: This principle requires the auditor to remain
alert throughout the audit and is necessary to reduce the risk of overlooking unusual
circumstances or making flawed assumptions. In practice, this means being alert to:
○ Audit evidence that contradicts other evidence obtained.
○ Information that brings into question the reliability of documents and responses to
inquiries.
○ Conditions that may indicate possible fraud.
○ Circumstances that suggest the need for audit procedures in addition to those
required by PSAs.
● Application of Professional Judgment: Professional judgment is not arbitrary; it must
be exercised by an auditor with the necessary competencies and be based on the facts
and circumstances known at the time. It is particularly critical when making decisions
about:
○ Materiality and audit risk.
○ The nature, timing, and extent of audit procedures needed to meet PSA
requirements and gather evidence.
○ Evaluating whether sufficient appropriate audit evidence has been obtained.
○ Evaluating management's judgments in applying the accounting framework and
assessing the reasonableness of accounting estimates.
PSA 210 (Redrafted): Agreeing the Terms of Audit Engagements
This standard outlines the auditor's responsibilities in establishing that the necessary conditions
for an audit are present and in agreeing on the terms of the engagement with management.
Objective
The objective of the auditor is to accept or continue an audit engagement only when the basis
for its performance has been agreed upon by establishing whether the preconditions for an audit
are present and confirming a common understanding of the engagement terms.
Preconditions for an Audit
The auditor must establish that the preconditions for an audit are present before accepting an
engagement. These are defined as the use by management of an acceptable financial reporting
framework and the agreement of management to the premise on which an audit is conducted.
Specifically, the auditor shall:
1. Determine the Acceptability of the Financial Reporting Framework: The auditor must
determine whether the financial reporting framework to be applied in preparing the
financial statements is acceptable.
2. Obtain Management's Agreement to Its Responsibilities: The auditor must obtain
management's agreement that it acknowledges and understands its responsibility for:
○ The preparation of the financial statements in accordance with the applicable
financial reporting framework.
○ The design, implementation, and maintenance of internal control necessary to
enable the preparation of financial statements that are free from material
misstatement.
○ Providing the auditor with access to all relevant information, such as records and
documentation; any additional information the auditor may request; and unrestricted
access to persons within the entity from whom the auditor needs to obtain
evidence.
If management imposes a limitation on the scope of work so severe that the auditor believes it
will result in a disclaimer of opinion, the auditor shall not accept such a limited engagement.
Agreement on Audit Engagement Terms
The agreed terms of the audit engagement must be recorded in an audit engagement letter or
another suitable form of written agreement. This letter must include:
● The objective and scope of the audit.
● The responsibilities of the auditor.
● The responsibilities of management.
● Identification of the applicable financial reporting framework.
● Reference to the expected form and content of any reports to be issued by the auditor.
Key Application and Explanatory Material
● Purpose of the Engagement Letter: It is in the interests of both the entity and the
auditor that an engagement letter is sent, preferably before the start of the audit, to help
avoid misunderstandings regarding their respective roles and responsibilities. This is
especially important in clarifying that management retains responsibility for the financial
statements even when a third party may have assisted in their preparation.
● Additional Content in the Engagement Letter: For greater clarity, the engagement letter
may also include other items to manage expectations and formalize arrangements, such
as:
○ An elaboration of the audit scope, referencing applicable PSAs and ethical
pronouncements.
○ A statement about the inherent limitations of an audit, explaining that even a
properly planned audit carries an unavoidable risk that some material
misstatements may not be detected.
○ Arrangements for planning the audit, including the composition of the audit team.
○ The expectation that management will provide written representations at the end of
the audit.
○ The basis on which fees are computed and any billing arrangements.
○ A request for management to acknowledge receipt of the letter and agree to the
terms.
● Recurring Audits: The auditor does not need to send a new engagement letter every
period. However, it may be appropriate to revise the terms or send a new letter if certain
factors exist, including:
○ Any indication that the entity misunderstands the objective and scope of the audit.
○ A recent change of senior management, a significant change in ownership, or a
significant change in the entity's business.
○ A change in legal requirements or the financial reporting framework.
● Acceptance of a Change in Terms: A request from the client to change the engagement
terms (e.g., from an audit to a review) must be carefully considered.
○ A reasonable basis for the change might include a change in circumstances that
affects the entity's requirements or a genuine misunderstanding about the nature of
the service originally requested.
○ A change would not be considered reasonable if it appears to be requested
because of incorrect, incomplete, or otherwise unsatisfactory information. For
example, if the auditor is unable to obtain sufficient evidence about receivables and
the client asks to change the engagement to a review to avoid a qualified opinion or
a disclaimer of opinion, this would not be a reasonable justification.
PSA 300 (Redrafted): Planning an Audit of Financial Statements
This standard deals with the auditor's responsibility to plan the audit of financial statements so it
can be conducted effectively.
Objective
The objective of the auditor is to plan the audit so that it will be performed in an effective
manner.
Key Requirements in Planning
● Involvement of Key Engagement Team Members: The engagement partner and other
key members of the engagement team must be involved in planning the audit.
● Preliminary Engagement Activities: At the start of the engagement, the auditor must
undertake activities such as performing client continuance procedures, evaluating
compliance with ethical requirements, and understanding the terms of the engagement
per PSA 210.
● Planning Activities: Planning involves two main components:
1. Overall Audit Strategy: The auditor shall establish an overall audit strategy that
sets the scope, timing, and direction of the audit and guides the development of the
audit plan.
2. Audit Plan: The auditor shall develop a more detailed audit plan that includes a
description of the nature, timing, and extent of planned risk assessment procedures
(per PSA 315) and further audit procedures (per PSA 330).
● Updating Plans: The auditor shall update and change the overall audit strategy and the
audit plan as necessary during the course of the audit.
● Documentation: The auditor is required to document the overall audit strategy, the audit
plan, and any significant changes made.
Key Application and Explanatory Material
● Benefits and Timing of Planning: Adequate planning is not a one-time event but a
continual and iterative process that often begins shortly after the previous audit is
completed and continues until the current audit is done. The benefits of this ongoing
process include:
○ Helping the auditor to devote appropriate attention to important areas of the audit.
○ Helping to identify and resolve potential problems on a timely basis.
○ Assisting in the proper organization and management of the engagement so it is
performed in an effective and efficient manner.
○ Assisting in the selection of competent team members and the proper assignment
of work.
● The Overall Audit Strategy in Practice: The strategy is a high-level blueprint that assists
the auditor in making practical decisions about the engagement. Once established, it
helps determine:
○ The resources to deploy, such as using team members with specialized skills for
complex areas or involving experts.
○ The amount of resources to allocate, for example, the number of team members
needed to observe inventory counts at material locations or the audit budget in
hours for high-risk areas.
○ When these resources are to be deployed, such as during an interim period
before year-end or at key cut-off dates.
○ How such resources are managed, directed, and supervised, including the timing
of team meetings and the nature of reviews by the engagement partner and
manager.
● Communicating with Management: The auditor may discuss planning elements with
management to coordinate work, for instance, aligning planned audit procedures with the
work of the entity's personnel. However, the auditor must be careful not to compromise
the effectiveness of the audit. For example, discussing the nature and timing of detailed
audit procedures with management may make those procedures too predictable and
therefore less effective at detecting misstatements.
● Planning in Smaller Entities: Planning for a smaller entity can be less complex and
time-consuming. The overall strategy may be documented in a brief memorandum that is
updated from the prior year based on discussions with the owner-manager. For the audit
plan, standard audit programs or checklists can be used, provided they are tailored to the
entity's circumstances and the auditor's risk assessments.
PSA 315 (Redrafted): Identifying and Assessing the Risks of Material
Misstatement Through Understanding the Entity and Its Environment
This standard provides detailed guidance on a crucial part of the planning process:
understanding the entity to identify and assess risks, which forms the basis for designing further
audit procedures.
Objective
The objective of the auditor is to identify and assess the risks of material misstatement, whether
due to fraud or error, at the financial statement and assertion levels, through understanding the
entity and its environment, including its internal control.
Risk Assessment Procedures
The auditor shall perform risk assessment procedures to obtain this understanding. These
procedures must include:
● Inquiries of management and other employees.
● Analytical Procedures.
● Observation and Inspection.
Required Understanding of the Entity, Its Environment, and Internal Control
● The Entity and Its Environment: This includes understanding relevant industry factors,
the nature of the entity (its operations, ownership, investments, etc.), its accounting
policies, its objectives and strategies, and how it measures financial performance.
● The Entity's Internal Control: The auditor must obtain an understanding of internal
control relevant to the audit, evaluating the design of those controls and determining if
they have been implemented. This understanding must cover the five components of
internal control:
1. The Control Environment.
2. The Entity's Risk Assessment Process.
3. The Information System, including related business processes.
4. Control Activities relevant to the audit.
5. Monitoring of Controls.
Identifying and Assessing Risks
Using the information gathered, the auditor shall identify and assess the risks of material
misstatement at both the financial statement and the assertion levels. The auditor must also use
judgment to determine if any identified risks are a "significant risk"—one that requires special
audit consideration.
Key Application and Explanatory Material
● Understanding Internal Control Components:
○ Control Environment: This is the foundation for the other components and "sets
the tone of an organization". It includes management’s commitment to integrity and
ethical values, its philosophy and operating style, and the oversight provided by
those charged with governance. A weak control environment can undermine the
effectiveness of other controls.
○ The Entity's Risk Assessment Process: This is the process management uses to
identify and manage business risks relevant to financial reporting. If the auditor
identifies a risk that management failed to identify, the auditor should evaluate why
management's process failed and whether this signifies a material weakness in
internal control.
○ Information System: Understanding this component involves learning how
transactions are initiated, recorded, processed, and reported. The auditor needs to
understand the flow of both standard, recurring journal entries and non-standard
entries used for unusual transactions or adjustments, as the latter are often a
source of risk.
○ Control Activities: These are the policies and procedures that ensure
management's directives are carried out. Practical examples include:
■ Authorization: Approvals for transactions.
■ Performance Reviews: Comparing actual results to budgets or forecasts.
■ Physical Controls: Securing assets and records.
■ Segregation of Duties: Assigning different people the responsibilities of
authorizing transactions, recording transactions, and maintaining custody of
assets to reduce opportunities for fraud or error.
○ Monitoring of Controls: This is a process to assess the effectiveness of controls
over time. It can be an ongoing activity, such as a manager reviewing daily
exception reports, or a separate evaluation, such as an internal audit project.
● The Use of Assertions: Auditors use management's assertions to form a basis for
assessing risks and designing audit procedures. By breaking down financial statement
items into assertions, auditors can focus on specific potential misstatements. The
assertions fall into three categories:
○ About classes of transactions and events (Occurrence, Completeness,
Accuracy, Cutoff, Classification).
○ About account balances at period end (Existence, Rights and Obligations,
Completeness, Valuation and Allocation).
○ About presentation and disclosure (Occurrence and Rights and Obligations,
Completeness, Classification and Understandability, Accuracy and Valuation).
● Significant Risks: A significant risk is one that, in the auditor’s judgment, requires special
audit consideration. These often relate to:
○ Significant non-routine transactions: Transactions that are unusual due to either
size or nature and occur infrequently (e.g., a major business acquisition).
○ Significant judgmental matters: This includes the development of accounting
estimates where there is significant measurement uncertainty (e.g., accounting for
complex financial instruments or fair value estimates). When a significant risk is
identified, the auditor must obtain an understanding of the entity’s specific controls
related to that risk.