SALESIAN UNIVERSITY OF BOLIVIA
PUBLIC ACCOUNTING
FINANCIAL AUDIT II
MBA Lic. KAREN DANEIDA TAPIA CAMARGO
LP-12/09/2019
CLASS NOTES 2
THEME IV RISK-BASED AUDITING
Risk-based auditing is a way to conduct external audits based on
the planning and development in critical risks, that is, those that could cause the greatest
negative impact on the achievement of the organization's objectives (strategic,
operational, informational, and compliance) in order to identify if the
operations and the products or services conform to what is established in the business rules,
the good and best practices of internal control and security, and the legal standards
applicable.
To adequately understand what has been said above, it is worth remembering that the risks of
business results from events, circumstances, actions, or inactions that could affect
adversely affecting the entity's ability to achieve its goals and execute strategies.
From the perspective of financial statement auditing, the understanding
deepening the business risks increases the possibility of identifying risks of
misstatement. In other words, it contributes to the auditor performing tasks
Life is a constant learning process and learning is to live constantly. 1
SALESIAN UNIVERSITY OF BOLIVIA
PUBLIC ACCOUNTING
FINANCIAL AUDIT II
MBA Lic. KAREN DANEIDA TAPIA CAMARGO
LP-12/09/2019
aimed at mitigating the risk of ineffective and inefficient detection.
Specifically, the auditor faces three types of risks when developing an audit.
external financial statements:
Inherent risk. It is directly related to economic activity.
of the company, regardless of the internal control systems.
Control risk. For which internal control systems influence
implemented in the company, which could prove insufficient or
inadequate for the timely application and detection of irregularities.
Detection risk. It is directly associated with the procedures regarding
audit. It is about the non-detection of errors in the process carried out.
risk-based external audit focuses precisely on assessing risks of
business to understand in what aspect of an organization's activities
there is a greater exposure to the occurrence of erroneous financial information. The
risk-based external audit focuses the auditor's efforts on evaluating
categories, transactions, balances or relevant operations, giving less attention to the
of a lower level.
Life is a constant learning, and learning is to live constantly. 2
SALESIAN UNIVERSITY OF BOLIVIA
PUBLIC ACCOUNTING
FINANCIAL AUDIT II
MBA Lic. KAREN DANEIDA TAPIA CAMARGO
LP-12/09/2019
HOW IS IT APPLIED?
Initially, it requires identifying the existing risks, without considering their magnitude or the
significant that they are. This will allow for the consideration of a wide spectrum of events,
which will be evaluated to determine their treatment.
In the second instance, it is necessary to analyze the importance of the risks. To this end, for
for each risk identified in the initial stage, the auditor must take its probability into account
the impact, a key part of the meaningful accounts process. Then, the auditor must
establish the responses to the risk to be developed. For the external audit of states
Financial responses to risk are clearly defined in ISA 330.
substantive tests are clear examples of risk response measures by the
auditors. However, and this must be emphasized, it is not the only possible answer. The theory
it states that risk can never be eliminated, but responses can be applied
tending to mitigate, avoid, accept, and transfer it.
In particular, ISA 330 warns that the financial statement auditor must design and
apply audit procedures, whose nature, timing of execution and extent
(scope) must be based on the assessed risks of material misstatement (errors) in
the statements about the financial statements, and that respond to such risks. Such
responses to risk, classified according to the stipulations on the actions taken to
mitigate, avoid, accept or transfer the risk, are usually differentiated among procedures
nouns (detailed and substantive tests) and control tests. A combination of
both, according to the audit methodology that is defined and implemented, may
contribute appropriately to focus on the significant risks identified in the
audit course.
For each risk identified in the initial stage, the auditor must consider probability and
impact. Then, it will establish the responses to be developed:
Prioritization of relevant risks
Develop the different revisions according to what the organization has identified as
relevant risks. Every relevant risk must have a policy, strategy, limits and
clear structure of how the organization manages it. It is there where the audit team
you must concentrate your hours, reviews, and understanding with the business areas or monitoring
of the entity, since to the extent that the most important risks are better controlled,
it is more likely that the entity is within acceptable limits.
Focused on processes and risks
Mapping the critical processes of the organization is essential prior to management.
risk. It is in critical processes, whether from the perspective of continuity or impact,
in which the audit must focus its reviews, possible errors or possible
improvements in the process. The audit is already concerned with going into detail about the transactions and
generally linked to strictly financial issues is not the predominant one.
Life is a constant learning and learning is constantly living. 3
SALESIAN UNIVERSITY OF BOLIVIA
PUBLIC ACCOUNTING
FINANCIAL AUDIT II
MBA Lic. KAREN DANEIDA TAPIA CAMARGO
LP-12/09/2019
Specialize in the business
Effective audit plans understand the functioning of the business lines and
they evaluate the integrity of the risks by understanding the specificity and scope of each one,
where regulation is becoming increasingly extensive and detailed. The approach has ceased to be effective.
audit standard that applied the same tests in any industry. That's why, the
training plans for auditors must now be designed to strengthen the
quantitative and data analysis, the evaluation of methodologies and management models.
CONCLUSIONS
Risk-based auditing allows strengthening the development of the practice.
providing professionals with a modern tool to focus efforts on
those truly relevant aspects. In some way, this type of audit raises a
new paradigm: if the auditor focuses their attention only on transactions, activities or
balances of critical importance, will be able to perform selective tests and precise procedures,
directed at specific aspects that add value to your work and client:
Without a doubt, in this era where technology is at the service of
community, computer tools help auditors to perform
their tasks more efficiently, from automating database analysis to
cross relevant information to present the data appropriately. The analysis of the
results derived from the application of risk-based auditing contributes to the
auditor develop quality work and be a good support for your client, the
audited, make decisions in a more appropriate and precise manner.
Life is a constant learning and learning is to live constantly 4