0% found this document useful (0 votes)
12 views4 pages

Audit Firm Risk Assessment Overview

The document outlines the risk assessment procedures for audits, emphasizing the importance of understanding the entity and its environment to identify material misstatements. It details components of audit risk, including inherent, control, and detection risks, and highlights the significance of internal controls and management assertions. Additionally, it discusses various audit evidence types and procedures for obtaining sufficient and appropriate evidence to support audit conclusions.

Uploaded by

itsme161135121
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views4 pages

Audit Firm Risk Assessment Overview

The document outlines the risk assessment procedures for audits, emphasizing the importance of understanding the entity and its environment to identify material misstatements. It details components of audit risk, including inherent, control, and detection risks, and highlights the significance of internal controls and management assertions. Additionally, it discusses various audit evidence types and procedures for obtaining sufficient and appropriate evidence to support audit conclusions.

Uploaded by

itsme161135121
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

RISK ASSESSMENT (PSA 315) •Engagement partner and other key members

shall discuss the susceptibility of the FS to


Risks related to an Audit Firm material misstatements
1. Business risk à affects an entity’s ability to achieve its Understanding the Entity and Its Environment
objectives A. Industry & Regulatory
à(financial losses, business failure, a. Industry factors à market and competition,
e.g.) seasonal activity, product technology, and
2. Engagement risk à practitioner expresses an energy supply and cost.
inappropriate conclusion b. Regulatory factors à accounting principles and
àinc. risk through loss from litigation practices, regulatory framework, legislation and
3. Audit risk à engagement risk in an audit regulation, taxation, govt policies, and
engagement environmental requirements
Audit failure à result of an inappropriate audit conclusion
Components of Audit Risk
Occurs in the FS c. Other external factors à general economic
Only be assessed by the
1. Risk of Material Misstatement auditor conditions, interest rates and availability of
a. Inherent risk àsusceptibility to material misstatement financing, and inflation
in the absence of controls B. Nature of the Entity
b. Control risk àfailure of controls to prevent, detect, a. Operations àrevenue sources, geographic
or correct material misstatements on a timely basis dispersion, key customers and suppliers, R&D
Controlled to a certain extent by the auditor activities
2. Detection risks à the failure of the auditor to detect b. Ownership and Governance Structures à sole
material misstatements prop, corpo, OPC
c. Investment Plans à acquisitions or divestitures
AR= IR x CR x DR and capital investment
d. Structuring and Financing à subsidiaries and
Planned detection risk= Acceptable audit risk associates, debt structure, and related parties
IR x CR e. Financial Reporting à PFRS and other
standards to be used
Risk assessment à understanding of the entity and its C. Accounting policies
environment, incl. entity’s internal control, to identify and assess a. Method of accounting significant and unusual
the risk of material misstatement. transactions
àa continuous, dynamic process of b. Effect of significant accounting policies in
gathering, updating and analyzing information controversial or emerging areas
àauditor uses professional judgment to c. Changes in accounting policies
determine the extent of understanding required D. Objectives and Strategies
àinformation obtained may be used as a. Objectives à overall plans for the entity
audit evidence b. Strategies à approaches by which
Risk Assessment Procedures management intends to achieve its objectives
1. Inquiry of Management and Others within the Entity E. Financial Performance
• May also inquire employees other than a. Examples of measure and review factors
management and those charged with àkey performance indicators and key ratios,
governance May include both financial and non- trends and operating statistics
2. Analytical Procedures
financial information àperiod-on-period financial performance
• May help identify the existence of unusual analysis
transactions or events, and amounts, ratios àbudgets, forecasts, variance analysis, and
and trends segment reports
3. Observation and Inspection à employee performance measures and
incentive compensation policies
• May support inquiries of management and
àcomparison of an entity’s performance with
others, and provide information about the
that of competitors
entity and its environment
b. Auditor considers whether pressures to achieve
4. Other considerations
performance targets may result in management
• Info obtained from acceptance or
actions that increase the risk of material
continuance process
misstatements.
• Info obtained from other engagements for the
Identifying and Assessing Risks of Material
entity
Misstatements
• Changes in info obtained from prior periods,
a. Financial statement levelàfrom weak control
if the entity intends to use that information
environment
5. Discussion among the engagement team
b. Assertion level for classes of transactions,
account balances, and disclosuresà directly
affect further audit procedures
A. Management assertions Documentation of auditor’s understanding of internal
• Representations by management, explicit or control
otherwise, that are embodied in the FS Can be done through:
a. Standardized Internal Control Questionnaire
àadvantage: easy to prepare; easily identify
deficiencies
àdisadvantage: lacks flexibility; tendency to be filled
mechanically
b. Written Narratives
B. Significant Risksà require special audit considerations àadvantage: show the level of auditor’s
Documentation understanding
a. Discussion among the engagement team àdisadvantage: deficiencies can’t be easily identified
b. Key elements of understanding obtained c. Flowcharts
c. Identified and assessed risk of material misstatements àadvantage: clearer and more specific portrayal of
at financial statement level and at the assertion level client’s system
d. Risks identified and related controls àdisadvantage: deficiencies can’t be easily identified;
INTERNAL CONTROL needs sufficient understanding of flowcharts
Objectives (but not limited to): Test of Controls
• Adherence to management policies Procedures:
• Safeguarding assets - Inquiry of entity personnelàby itself, is not sufficient
• Prevention and detection of fraud and error - Observing the application of controls
• Accuracy and completeness of accounting records - Inspecting the documents and reports
• Timely preparation of financial information - Reperforming control activities
Limitations of Internal Control (PSA 315)
“Internal control can only provide reasonable assurance about Strong design- perform test of controls
the entity’s financial reporting objectives.”
Weak design- don’t perform test of controls
1. Inherent limitations
a. Human error àIf there are no significant changes to such controls, test
• Misunderstanding it only once in every third audit.
• Faulty judgment Deficiency in Internal Control
• Carelessness 1. Unable to prevent, or detect and correct,
• Distraction misstatements on a timely basis
• Fatigue 2. Control is missing
b. Employee collusion Levels of deficiency
c. Management override a. Material weakness- material misstatement of the FS
Responsibilities Over Controls will not be prevented or detected on a timely basis In
A. Management b. Significant deficiency- less severe than material writing
à designing, implementing and maintaining internal weakness, yet of sufficient importance to merit the
control. attention of those charged with governance May be
àneeds to maintain sufficient and appropriate c. Other deficiencies- not significant deficiencies made
internal control documentation Components of Internal Control (CRIME) orally
B. Auditor a. Control Environment (CHOPPER)
àassess the risk of material misstatement through àfoundation for other components
obtaining an understanding of the entity and its àsets the tone of an organization
environment, including entity’s internal control àsatisfactory control environment is not an absolute
Controls relevant to the Audit deterrent to fraud
Factors to determine a control’s relevance to audit
- Materiality and significance of related risk
- Nature and characteristics of the entity and its internal
control
- Legal and regulatory requirements
- Prevents, detects, and correct material b. Entity’s Risk assessment Process (IDEA)
misstatements àauditor’s matter of judgment is used to determine
Understanding controls appropriateness of risk assessment
Procedures may include:
- Inquiry of entity personnelàby itself, is not sufficient
- Observing the application of controls
- Inspecting the documents and reports
- Tracing transactions through the systemà aka “walk-
throughӈperformed after documentation
c. Information System and Communication (DPIPS) transactions, and disclosures.
Classification Of Substantive Tests Procedures
▪ Tests of details
- Transactions
- Balances
d. Control Activities (PARIS) a. Transactions b. Balances
Used in SCI and SFP SFP
*Number of Few Many
transactions
Amount Large Small
Example Non-trade accounts Trade accounts (e.g.
application (e.g. PPE) A/R, MI, Cash)
e. Monitoring of Controls (CAR) (SFP)
àassesses the effectiveness of internal control ▪ Analytical tests
performance over time ANALYTICAL PROCEDURES- Evaluations of
financial information made by a study of plausible
relationships among both financial and non-financial
data
Timing of audit procedures
Audit Evidence (PSA 500)
• At the Balance Sheet Date
àinformation used by the auditor in arriving at the conclusions
• After the Balance Sheet Date
on which the auditor’s opinion is based
• Interim date
àcumulative in nature (includes info from previous audits and
i. Allows earlier completion
acceptance and continuance procedures)
ii. Appropriate when internal controls are
àcould corroborate or contradict management’s assertions
effective
àincludes
iii. Additional procedures at or after the BS
a. Information contained in the accounting records
date are needed to make sure that no
àrecords of initial accounting entries and supporting
misstatements occurred
records (checks, invoices, contracts, etc.)
• Cutoff period- several days before and after the
b. Other information
BS date
àminutes of meetings, confirmation from 3rd parties,
Selecting items for testing
etc.
a. All items
Sufficient Appropriate Evidence
- Small number of large value items
a. Sufficiency- quantity of audit evidence
- Significant risk
- Cost effective
b. Specific items
b. Appropriateness- quality of audit evidence - High value or key items only
- evidence is considered appropriate - All items over a certain amount
when it is both relevant and reliable. - Items to obtain information
c. Audit sampling
- Making inference from testing the sample
*Application of any one or combination of these
• Tracing -for completeness or understatement means may be appropriate depending on the
Source documentsàFinancial Statements circumstances and the practicality an efficiency of the
• Vouching -for existence or overstatement different means
Source documents ß Financial Statements RAP FAP
Examples Of Audit Evidence Assessment Internal Test of Substantive
▪ Related to Expenditure Cycle: Purchase Requisition, Purchase Procedure Control Controls Testing
Order, Receiving Report or Warehouse Receipts, Vouchers, Inquiry ✔ ✔ ✔ ✔
Debit Memos, Fund Transfer forms, Cheques, Observation ✔ ✔ ✔ ✔
▪ Related to Revenue Cycle: Sales order, Delivery Receipt, Inspection ✔ ✔ ✔ ✔
Sales Invoice, Official Receipt, Deposit Slips, Credit Memos Reperformance ✔
Audit Procedures for Obtaining Evidence Recalculation ✔ ✔
a. Risk Assessment Procedures *can be
b. Further Audit Procedures done
i. Test of Controls- used to test the operating already
effectiveness of controls in preventing or Confirmation ✔
detecting and correcting material Analytical ✔ ✔
procedures
misstatements.
ii. Substantive Procedures- used to detect material
misstatements in account balances, classes of
Types of External Confirmationà a type of test of
balances
Positive Negative

Consideration is likely

RMM High Low


# of acct balance Few Many

*Amt of balance Large Small

Degree of reliability More Less

Positive Negative
Non- 1. Follow-up Assumed no
response 2. Alternative discrepancy
procedures
With 1. No discrepancy Investigate
response 2. With discrepancy- difference
investigate

Common questions

Powered by AI

Auditors use analytical procedures in risk assessment to evaluate financial information through the study of plausible relationships among both financial and non-financial data. These procedures help identify variances that might indicate unusual transactions or trends requiring further investigation. For example, an unexpected fluctuation in financial ratios or trends might suggest misstatements or undetected errors. Analytical procedures can also identify areas of risk for significant transactions, helping to direct the auditor's attention to unusual results that need more detailed exploration .

Auditors should approach the documentation and assessment of internal control systems with a systematic strategy that includes the use of standardized questionnaires, narratives, and flowcharts to gain a comprehensive understanding of the controls. These methods help in identifying deficiencies by enabling a thorough examination of the design and operation of controls. To effectively pinpoint deficiencies, auditors should perform tests of controls to evaluate their effectiveness, observe control activities in practice, inspect relevant documents, and interview personnel to understand the practical aspects of control implementation. This approach ensures that the audit plan is responsive to identified risks and adequately addresses areas needing improvement .

Internal control documentation plays a critical role in audit planning and execution as it provides a comprehensive understanding of control mechanisms and helps identify potential areas of risk. Different methods, such as standardized internal control questionnaires, written narratives, and flowcharts, offer varied advantages. Questionnaires are easy to prepare and identify deficiencies but lack flexibility. Narratives demonstrate an auditor's understanding but do not easily highlight deficiencies. Flowcharts provide a clear, specific portrayal of systems but require adequate understanding and may not readily indicate deficiencies. These methods guide auditors in deciding which controls to test and the extent of testing required .

Management's assertions in financial statements present specific risks, such as the risk of material misstatements due to overstatement or understatement of assets, liabilities, and equity. These assertions include existence, completeness, rights and obligations, valuation, and presentation and disclosure, each carrying its unique challenges. Auditors must design procedures to gather sufficient appropriate evidence to address these risks. For example, misstatement risks in existence assertions might require confirmation with third parties, while completeness assertions might involve tracing source documents to financial statement entries to detect omissions .

Inherent risk refers to the susceptibility of an account balance or class of transactions to misstatement before considering any related controls, while control risk pertains to the likelihood that the entity's controls fail to prevent or detect such misstatements. These components, along with detection risk, make up the audit risk model: Audit Risk = Inherent Risk x Control Risk x Detection Risk. High inherent or control risks require the auditor to lower detection risk by adjusting audit procedures, such as increasing sample sizes, collecting more persuasive evidence, or applying additional testing techniques to reduce overall audit risk to an acceptable level .

Understanding an entity's environment and industry factors is crucial for assessing audit risks because these elements provide context for inherent risks and affect the entity's operations and financial reporting. Industry-specific factors such as regulatory changes, economic conditions, competitive pressures, and technological innovations influence risks differently across sectors. These insights allow auditors to develop more targeted audit plans by pinpointing areas prone to misstatement linked to industry characteristics and external conditions. This comprehensive understanding aids in crafting effective responses to the risks posed by the external and internal environment .

Management pressures to achieve performance targets can increase audit risk by incentivizing aggressive accounting practices or manipulation of financial results. This can lead to heightened risk of material misstatements if management employs unethical measures to meet targets. Auditors should respond by maintaining professional skepticism, increasing the depth of substantive testing in areas tied to performance pressures, and expanding the scope of audit procedures where discrepancies are likely. By remaining vigilant and performing more in-depth analyses, auditors can better identify and evaluate the implications of such pressures on financial statements' integrity .

An auditor assesses the risk of material misstatement at the financial statement level by evaluating the overall control environment's strength, which reflects the risk of pervasive misstatements, and at the assertion level by analyzing specific transactions, account balances, and disclosures that might be prone to errors or fraud. This detailed assessment impacts audit procedures by determining the nature, timing, and extent of further audit activities, namely tests of controls and substantive procedures, to address identified risks .

Discussions among engagement team members regarding financial statement susceptibility to material misstatements are important because they facilitate the exchange of insights and professional judgments, enhancing collective understanding of risks. These discussions allow team members to share observations on potential misstatements, consider different perspectives on significant risks, and develop a cooperative audit strategy tailored to the specific context of the engagement. Such interactions promote a comprehensive risk assessment approach, ensuring that variabilities in team members' expertise contribute to a robust audit plan capable of addressing identified vulnerabilities .

Standard audit procedures can have limitations such as not capturing unusual transactions due to their routine nature or failing to detect misstatements that require deeper analysis. To address these limitations, auditors can incorporate more tailored procedures like analytical tests for specific accounts or detailed examination of high-risk areas. Adjustments may include using more advanced sampling techniques, applying substantive procedures with increased focus, or employing technology-driven tools for data analytics. By adapting their approach, auditors can more effectively respond to the unique risks of each audit engagement, ensuring comprehensive coverage beyond the limits of standard procedures .

You might also like