0% found this document useful (0 votes)
5 views7 pages

Understanding Audit Risk and Controls

This document outlines the International Auditing Standards related to risk assessment and internal control, emphasizing the need for auditors to understand accounting systems and internal controls to effectively plan audits. It details the components of audit risk, including inherent risk, control risk, and detection risk, and provides guidelines for assessing and documenting these risks. Additionally, it highlights the auditor's responsibility to communicate any significant weaknesses in internal controls to management.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views7 pages

Understanding Audit Risk and Controls

This document outlines the International Auditing Standards related to risk assessment and internal control, emphasizing the need for auditors to understand accounting systems and internal controls to effectively plan audits. It details the components of audit risk, including inherent risk, control risk, and detection risk, and provides guidelines for assessing and documenting these risks. Additionally, it highlights the auditor's responsibility to communicate any significant weaknesses in internal controls to management.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

International Auditing Standards

Internal Control
400. RISK ASSESSMENT AND INTERNAL CONTROL

Introduction

The purpose of this International Auditing Standard is to establish


standards and provide guidelines for achieving an understanding
of accounting systems and internal control over risk of
audit and its components: inherent risk, control risk and
detection risk.

The auditor must obtain an understanding of the systems of


accounting and internal control sufficient to plan the
audit and develop an effective audit approach. The
the auditor should use professional judgment to assess the risk
of auditing and design the audit procedures for
ensure that the risk is reduced to an acceptably level
low.

Inherent risk

When developing the overall audit plan, the auditor should


evaluate the inherent risk at the financial statement level. To
develop the audit program, the auditor should
relate that evaluation at the level of balance assertions
of account and classes of transactions of relative importance, or
assume that the inherent risk is high for the assertion.

Accounting and internal control systems

The internal controls related to the accounting system are directed


to achieve objectives such as:

Transactions are executed according to the authorization


general or specific to the administration.
All transactions and other events are promptly
recorded in the correct amount, in the appropriate accounts and in the
appropriate accounting period.
Access to assets and records is only allowed in accordance with the
authorization of the administration.
The registered assets are compared with the existing assets.
at reasonable intervals and appropriate action is taken regarding
any difference.

Understanding accounting systems and internal control


When gaining an understanding of accounting systems and
internal control to plan the audit, the auditor obtains a
knowledge of accounting and control systems design
internal, and of its operation.

Accounting system

The auditor should obtain an understanding of the system of


sufficient accounting to identify and understand:

the main types of transactions in operations


of the entity;
(b) how such transactions are initiated;
(c) important accounting records, supporting documents and
accounts in the financial statements; and
(d) the accounting and financial reporting process, from the
start of important transactions and other events until their
inclusion in the financial statements.

Control environment

The auditor should gain an understanding of the environment of


sufficient control to evaluate attitudes, awareness and
actions of directors and management regarding the
internal controls and their importance in the entity.

Control procedures

The auditor should obtain an understanding of the


sufficient control procedures to develop the plan
of [Link] obtaining this understanding, the auditor would consider the
knowledge about the presence or absence of procedures of
control obtained from the understanding of the control environment and of
accounting system to determine if any is necessary
additional understanding of control procedures.

Control Risk

Preliminary risk assessment of control

The preliminary assessment of control risk is the process of


evaluate the effectiveness of accounting and control systems
internal of an entity to prevent or detect and correct
misrepresentations of relative importance. There will always be
some risk of control due to inherent limitations of
any accounting and internal control system.
After gaining an understanding of the systems
accounting and internal control, the auditor should make a
preliminary assessment of control risk, at the level of
statement, for each account balance or class of
transactions, of relative importance.

The preliminary assessment of control risk for a


The assertion of the financial statement should be high unless
that the auditor:

(a) can identify relevant internal controls to the


assertion that is likely to prevent or detect and
correct a misrepresentation of relative importance;
y

(b) plan to perform control tests to support the


evaluation.
Documentation of the understanding and assessment of control risk
The auditor should document in the working papers of the
audit

the understanding obtained from accounting systems and


of the entity's internal control; and
the assessment of control [Link] the risk of
control is assessed as less than high, the auditor should
also document the basis for the conclusions.

Control tests

The auditor should obtain audit evidence through


control tests to support any evaluation of
control risk that is less than high. The lower it is
the assessment of control risk, more support should
obtain the auditor that the accounting systems and
internal controls are adequately designed and operating
effectively.

Based on the results of the control tests, the auditor


should evaluate if the internal controls are designed and
operating as contemplated in the preliminary evaluation of
control [Link] evaluation of deviations can result in
result that the auditor concludes that the assessed level of risk of
control needs to be reviewed. In such cases, the auditor would modify the
nature, opportunity and scope of substantive procedures
planned.

Quality and timeliness of audit evidence


When determining the appropriate audit evidence to support a
Conclusion on control risk, the auditor may consider the
audit evidence obtained in previous audits. In a work
Continuing, the auditor will be aware of the accounting systems.
and internal control through the work carried out previously
but it will need to update the acquired knowledge and consider the
need to obtain additional audit evidence of any
changes in [Link] relying on procedures
applied in previous audits, the auditor should obtain
audit evidence that supports this [Link] auditor
You should obtain evidence about the nature, opportunity, and scope.
of any changes in the accounting and control systems
internal of the entity, since such procedures were applied
and you should assess its impact on the trust you are trying to place
in them. The more time has passed since it has
applying those procedures reduces the level of security.

The auditor should consider whether the internal controls


they were in effect throughout the [Link] they were modified
substantially the controls on several occasions during the period,
the auditor should consider each one separately. A failure in
internal controls for a specific portion of the period require
separate consideration of the nature, opportunity, and scope
of the audit procedures to be applied to the transactions
and other events from that period.

The auditor may decide to conduct some control tests.


during an interim visit before the end of the period. However, the
the auditor cannot trust the results of such tests without
consider the need to obtain additional audit evidence
related to the rest of the period.
Final evaluation of control risk

Before the conclusion of the audit, based on the


results of substantive procedures and others
audit evidence obtained by the auditor, the auditor
you should consider whether the control risk assessment was
suitable.

Relationship between inherent risk assessments and


control

The administration often reacts to risky situations.


inherently designing accounting and internal control systems
to prevent or detect and correct misleading representations and therefore
both, in many cases, inherent risk and control risk
are highly interrelated. In these situations, if the auditor
It is decided to evaluate the inherent and control risks separately.
There would be a possibility of an inappropriate risk assessment. Like
result, the audit risk can be more appropriately
determined in such situations by making an evaluation
combined.

Detection risk

The risk level of detection is directly related to the


substantive procedures of the auditor. The auditor's evaluation of
control risk, along with the evaluation of inherent risk, influences
in nature, opportunity and scope of the procedures
nouns that need to be developed to reduce the risk of
detection, and therefore the audit risk, to an acceptable level-
low profile. Some risk of detection would always be present even
If an auditor were to examine 100 percent of the balance of an account
class of transactions because, for example, most of the
Audit evidence is persuasive and not conclusive.

The auditor should consider the assessed levels of risks.


inherent and control when determining the nature,
opportunity and scope of substantive procedures
required to reduce the audit risk to a level
[Link] this regard, the auditor would consider:

(a)the nature of substantive procedures, for example,


use tests directed towards independent parts outside of the
entity and not tests directed at parts or documentation within
from the entity, or use test details for a particular objective
of auditing in addition to analytical procedures;

(b)the opportunity for substantive procedures, for example,


developing them at the end of the period and not on an earlier date; and

(c)the scope of substantive procedures, for example, using


a larger sample size.

The assessed levels of inherent and control risks cannot


be low enough to eliminate the need for the auditor
to develop some substantive [Link] of the
evaluated levels of inherent and control risks, the
auditor should to develop some procedures
nouns for account balances and classes of
important transactions.

The higher the assessment of inherent risk and of


control, more audit evidence should the auditor obtain
of the development of substantive [Link] both the
inherent risk as control are assessed as high, the
the auditor needs to consider whether the substantive procedures can
provide sufficient appropriate audit evidence to reduce the
detection risk, and therefore audit risk, to a level
acceptably [Link] the auditor determines that the risk
of detection regarding a statement of the states
financial for the balance of an account or class of
transactions of relative importance, cannot be reduced
at an acceptably low level, the auditor should express
a qualified opinion or an abstention of opinion.

Communication of weaknesses

As a result of gaining an understanding of the systems of


accounting and internal control and control tests, the
auditors can detect weaknesses in [Link] auditor
should inform the management as soon as feasible and
at an appropriate level of responsibility, regarding the weaknesses
of importance in the design or operation of the systems of
accounting and internal control, that have reached the
audit attention. Communication to management of
the weaknesses of ordinarily serious importance due to
[Link], if the auditor judges that oral communication is
appropriate, said communication would be documented in the papers of
audit work. It is important to indicate in the communication that
only weaknesses have been reported that have come to the attention of
auditor as a result of the audit and that the examination has not been
designed to determine the adequacy of internal control for purposes
of the administration.

Illustration of the interrelationship of risk components


of auditing

The following table shows how the acceptable level can vary
detection risk, based on assessments of inherent risks
and control.
The auditor's assessment of risk

High Media Low

The evaluation High There more More Media


of the auditor of low low
risk
Media Lower Media Higher
inherent
The more
Lower Media Higher
high

The bold areas in this table refer to the detection risk.

There is an inverse relationship between the risk of detection and the level.
combined inherent risks and control. For example,
when the inherent and control risks are high, the levels
acceptable detection risk levels need to be low to reduce the
audit risk at an acceptably low level. On the other hand,
when the inherent and control risks are low, an auditor can
accept a higher detection risk and still reduce the risk of
audit at an acceptably low level.

The basic principles and essential procedures of the Standards


International Audit Standards are identified in bold.

You might also like