1 Overview of the audit process
Section overview
The audit is designed to enable the auditor to obtain sufficient, appropriate evidence.
1.1 Overview
While there may be variations between specific procedures adopted by individual firms, the audit
process as set out in auditing standards is a well-defined methodology designed to enable the auditor to
obtain sufficient, appropriate evidence.
This process can be summarised in a number of key stages:
Client acceptance/
1 establishing
engagement terms
Establish materiality
2
and assess risks
Plan and design
3
the audit approach
Audit of internal
4
control
5 Tests for evidence
Complete the
6 audit and evaluate
results
7 Issue audit report
&IGURE 3UMMARY OF !UDIT 0ROCESS
In this chapter we will consider stages 1 to 4. In Chapter 6 we will consider stage 5, and in Chapter 8,
stages 6 and 7. However, it is important not to view the audit as a series of discrete stages and
individual audit procedures. For example, it can be argued that all audit procedures which provide
evidence are risk assessment procedures whether they are conducted during planning, control
evaluation, substantive testing or completion. The audit process will adopt a strategy where
complementary evidence is acquired and evaluated from a range of sources. The process is repeated
C
until the auditor has obtained sufficient, appropriate audit evidence which is adequate to form an
H
opinion. A
P
T
E
R
The statutory audit: planning and risk assessment 201
2 Audit planning
Section overview
You should be familiar with the basic planning process.
2.1 Introduction
Auditors are required to plan their work to ensure that attention is paid to the correct areas of the audit,
and the work is carried out in an effective manner.
In order to produce this plan the auditor must do the following:
x Understand the business, its control environment, its control procedures and its accounting system
x Assess the risk of material misstatement
x Determine materiality
x Develop an audit strategy setting out in general terms how the audit is to be carried out and the
type of approach to be adopted
x Produce an audit plan which details specific procedures to be carried out to implement the strategy
taking into account all the evidence and information collected to date
You have already covered planning and risk assessment issues in your earlier studies. The relevant ISAs
are:
x ISA (UK) 210 (Revised June 2016) !GREEING THE 4ERMS OF !UDIT %NGAGEMENTS
x ISA (UK) 300 (Revised June 2016) 0LANNING AN !UDIT OF &INANCIAL 3TATEMENTS
x ISA (UK) 315 (Revised June 2016) )DENTIFYING AND !SSESSING THE 2ISKS OF -ATERIAL -ISSTATEMENT
4HROUGH 5NDERSTANDING OF THE %NTITY AND )TS %NVIRONMENT
x ISA (UK) 320 (Revised June 2016) -ATERIALITY IN 0LANNING AND 0ERFORMING AN !UDIT
x ISA (UK) 330 (Revised June 2016) 4HE !UDITORgS 2ESPONSES TO !SSESSED 2ISKS
A number of issues are developed in the remainder of this chapter; however, it is assumed that you are
already familiar with the basic principles of planning and risk assessment. A summary of these and other
related ISAs can be found in the technical reference section at the end of the chapter.
3 Professional scepticism
Section overview
The auditor must maintain an attitude of professional scepticism throughout the audit.
3.1 Requirement
Definition
Professional scepticism: An attitude that includes a questioning mind, being alert to conditions which
may indicate possible misstatement due to error or fraud, and a critical assessment of audit evidence.
Professional scepticism includes being alert to:
x audit evidence that contradicts other audit evidence;
x information that brings into question the reliability of documents and responses to enquiries to be
used as audit evidence;
202 Corporate Reporting
x conditions that may indicate possible fraud; and
x circumstances that suggest the need for audit procedures in addition to those required by the ISAs.
ISA (UK) 200 (Revised June 2016) /VERALL /BJECTIVES OF 4HE )NDEPENDENT !UDITOR AND THE #ONDUCT OF AN
!UDIT IN !CCORDANCE WITH )NTERNATIONAL 3TANDARDS ON !UDITING requires that the auditor 'shall plan and
perform an audit with professional scepticism recognising that circumstances may exist that cause the
financial statements to be materially misstated'. Maintaining professional scepticism throughout the
audit reduces the risks of overlooking unusual circumstances, overgeneralising when drawing
conclusions and using inappropriate assumptions in determining the nature, timing and extent of the
audit procedures and evaluating the results. ISA 200 also makes the following points:
(a) The auditor may accept records and documents as genuine unless there is reason to believe the
contrary. Where there is doubt, for example where there are indications of possible fraud, the
auditor must investigate further and determine whether to modify or increase the audit
procedures.
(b) A belief that management and those charged with governance are honest and have integrity does
not relieve the auditor of the need to maintain professional scepticism.
The same points are reiterated in ISA (UK) 240 4HE !UDITORgS 2ESPONSIBILITIES 2ELATING TO &RAUD IN AN !UDIT OF
&INANCIAL 3TATEMENTS. This standard emphasises that where there are potential fraud issues the auditor's
professional scepticism is particularly important when considering the risks of material misstatement.
3.2 Importance of professional scepticism
The importance of professional scepticism cannot be overemphasised. An effective and compliant audit
cannot be carried out without it.
Given that it is fundamental that professional scepticism is applied for all audits of financial statements,
the audit engagement partners of audit firms must lead by example and firms should ensure that
professional scepticism is given the degree of prominence it warrants during the training of audit staff.
Following the global financial crisis in 2008 and 2009 a common theme in a number of regulator
reports was that professional scepticism could have been more clearly demonstrated by auditors when
looking at a number of audit areas. It continues to be at the top of the agenda for regulators and
standard setters, including the Financial Reporting Council (FRC). In the FRC's annual report for
2012/2013, the importance of embedding the exercise of professional scepticism in the culture of audit
firms, and in audit work, is highlighted as key to improving audit quality.
This section deals with the theoretical background of professional scepticism and the use of professional
scepticism in an audit planning context. We will look at professional scepticism again in the more
practical context of audit fieldwork in Chapter 6.
3.3 Briefing paper
In March 2012 the Auditing Practices Board (APB) (now FRC) issued a briefing paper, 0ROFESSIONAL
3CEPTICISM %STABLISHING A #OMMON 5NDERSTANDING AND 2EAFFIRMING ITS #ENTRAL 2OLE IN $ELIVERING !UDIT
1UALITY. This document is unusual in comparison to other briefing papers, as it is discursive in style and
draws analogies from a diverse group of areas. This approach has been adopted to encourage
international debate on this issue. The document is in seven sections. These are summarised below. C
H
A
3.3.1 Section 1 Introduction P
T
This aims to put the document into context. It states that the purpose of the document is to set out the E
APB's considered views on the nature of auditor scepticism and its role in the audit, given the R
significance of scepticism to the quality of individual audits.
The statutory audit: planning and risk assessment 203
3.3.2 Section 2 Exploring the roots of scepticism and identifying lessons for its role in the
conduct of an audit
Section 2 considers the philosophical origins of scepticism in ancient Greece and how it later influenced
scepticism in the scientific method that flourished in the 17th century. The paper explains that the
following can be learnt from early Greek philosophical scepticism:
x The essence of scepticism is doubt and doubt stimulates informed challenge and inquiry. The
sceptics' doubt stimulated them to challenge conventional wisdom and inquire after a better
understanding of the nature of knowledge.
x In the face of doubt the sceptics would suspend their judgement about the truth.
x In its extreme form scepticism is not pragmatic as it may lead to the conclusion that no
judgements about the truth can be made.
Section 2 also looks at the relationship between doubt and trust in the context of scepticism. It argues
that where levels of both are low there is uncertainty which will either lead to the indefinite suspension
of judgement or stimulate inquiry to pursue the truth or falseness of the assertion. Only when trust or
doubt are sufficiently high will belief in the assertion be accepted or rejected.
3.3.3 Section 3 Scientific scepticism and the scientific method
This section seeks to provide insight into the mindset required to develop the audit strategy and plan
and to evaluate the audit evidence obtained by demonstrating how science has developed a sceptical
approach that now commands respect. It states that scientists are required to:
(a) critically appraise existing theories, actively looking for alternative plausible mechanisms of cause
and effect that are consistent with their rigorous assessment of the empirical (observed) evidence;
(b) undertake experiments that are repeatable and transparent, to look for evidence that contradicts
rather than supports the validity of a given theory; and
(c) suspend judgement about the validity of any given theory (ie, to defer making an active decision to
believe or disbelieve it) until it has both survived destructive testing and has been subjected to
critical experiments the evidence from which makes it possible to conclude that one theory is
superior to all other current plausible theories.
While the subject matter of scientific and audit inquiry are different and there are limitations to the
analogy between the two, elements of the scientific method suggest critical audit activities which will
underpin appropriate scepticism in the audit:
(a) Empirical observation suggests developing a good understanding of the business of the audited
entity and the environment.
(b) Constructing falsifiable hypotheses suggests actively considering that material misstatements may
exist and designing audit tests to identify them, rather than only considering how well the
evidence obtained by management supports their conclusion that there are none.
(c) Transparency and repeatability suggest the importance of documentation in underpinning
transparency and repeatability of the audit work to internal reviewers and external inspectors.
3.3.4 Section 4 The origins of the modern audit
Section 4 seeks to provide further insight into the mindset of the auditor by considering the nature of
the agency relationships, and the resultant need for assurance that gave rise to early auditing traditions
from the 14th century onwards. The origins of the modern audit can be seen in the tradition of auditing
household servants in manorial estates. This was then built on by the Joint Stock Companies Act of 1844
which included a default provision for auditors to be appointed.
Historically, the audit was essentially a check, carried out on behalf of a principal by their trusted
associate or agent, on the fidelity of the other agents to whom the principal's resources were entrusted.
The trust that existed between principal and auditor was a critical ingredient. The strong bond between
the principal and the auditor and the principal's need for assurance about the fidelity of those to whom
they had entrusted their assets would have determined the mindset of the auditor. That would have
guided the appropriate degree of scepticism in the auditor when questioning those entrusted with the
principal's assets.
204 Corporate Reporting
This issue of fidelity remains an issue today; however, the development and increased complexity of
business activity and the increased size and reach of businesses combined with the technological
advances mean that there are many other areas in relation to which shareholders (and other users) seek
information and reassurance. This suggests that while the sceptical mindset is a constant, the degree of
action taken by a sceptical auditor is a 'sliding scale', responsive to both the expectations of shareholders
(and other stakeholders) and what emerges as the audit proceeds.
The paper also states that scepticism should embed the perspective of shareholders and other
stakeholders in the making of all audit judgements. Because of this the APB believes that when
undertaking a modern audit the following factors accentuate the need for the auditor to be especially
vigilant and aware of their responsibilities for the exercise of professional scepticism:
(a) There is the potential for auditors not to be sceptical or thought not to be sceptical because they
are engaged and paid by the company in a way that is relatively detached from shareholders. This
emphasises the need for strong governance generally and, in particular, the role of audit
committees in assessing and communicating to investors whether the auditors have executed a
high quality, sceptical audit.
(b) Auditors have strong working relationships with management and audit committees, which may
lead them to develop trust that may lead to either a lack of, or reduced, scepticism.
(c) The audit firms' business model encourages a culture of building strong relationships with clients.
This introduces the risk of the auditor putting their interests ahead of those of the shareholders and
could lead the audit firm and the auditor to develop trust or self-interest motivations that may
compromise either their objectivity or their willingness to challenge management to the extent
required.
The auditor must lean against unjustified trust in management developing. There is also a risk that audit
committees' views may be seen too readily as a surrogate for those of the shareholders. Just addressing
the concerns of the audit committee does not necessarily amount to meeting the expectations of
shareholders.
3.3.5 Section 5 Conclusions about professional scepticism in the audit
Section 5 sets out the APB's conclusions from the foregoing analysis as to what a sceptical audit looks
like and suggests that professional scepticism is the cornerstone of audit quality. In particular, it makes
the following statements with regards to an appropriately sceptical audit:
(a) The auditor's risk assessment process should involve a critical appraisal of management's assertions,
actively looking for risks of material misstatement.
(b) The auditor develops a high degree of knowledge of the entity's business and the environment in
which it operates, sufficient to enable it to make its risk assessment through its own fresh and
independent eyes rather than through the eyes of management.
(c) This enables the auditor to make informed challenge of consensus views and to consider the
possible incidence of low probability high impact events. The traditional pyramid structure of the
audit team may not always be appropriate and different models may need to be explored, such as
including experienced business people on the team.
(d) The auditor designs audit procedures to consider actively if there is any evidence that would
contradict management assertions not only to consider the extent to which management has
identified evidence that is consistent with them. C
H
(e) The auditor must be satisfied that: A
P
(i) there has been sufficient inquiry and challenge; T
(ii) sufficient testing of management's assertions has been undertaken; E
R
(iii) the quality of the resulting evidence obtained has been critically appraised and judged by the
auditor to be sufficiently persuasive; and
(iv) where there are plausible alternative treatments of an item in the financial statements (such as 5
different valuation bases) an assessment has been made as to whether one is superior and whether
sufficient disclosure of the alternatives has been given, in order to give a true and fair view.
The statutory audit: planning and risk assessment 205
(f) The auditor approaches and documents audit judgements and audit review processes in a manner
that facilitates challenge and demonstrates the rigour of that challenge.
(g) The auditor's documentation of audit judgements is conclusive rather than conclusionary and
therefore always sets out not only the auditor's conclusion but also their rationale for the conclusion.
3.3.6 Section 6 Fostering conditions necessary for auditors to demonstrate the appropriate
degree of professional scepticism
This section sets out the APB's views about the conditions that are necessary for auditors to demonstrate
the appropriate degree of professional scepticism. It highlights the APB's expectations of individual
auditors, engagement teams and audit firms as follows:
Individual auditors
x Develop a good understanding of the entity and its business
x Have a questioning mind and are willing to challenge management assertions
x Assess critically the information and explanations obtained in the course of their work and
corroborate them
x Seek to understand management motivations for possible misstatements of the financial
statements
x Investigate the nature and cause of deviations or misstatements identified and avoid jumping to
conclusions without appropriate audit evidence
x Are alert for evidence that is inconsistent with other evidence obtained or calls into question the
reliability of documents and responses to inquiries
x Have the confidence to challenge management and the persistence to follow things through to a
conclusion
Engagement teams
x Have good business knowledge and experience
x Actively consider in what circumstances management numbers may be misstated, whether due to
fraud or error
x Develop a good understanding of the entity and its business in order to provide a basis for
identifying unusual transactions and share information on a regular basis
x Partners and managers are actively involved in assessing risk and planning the audit procedures to
be performed
x Partners and managers actively lead and participate in audit team planning meetings to discuss the
susceptibility of the entity's financial statements to material misstatement
x Partners and managers are accessible to other staff during the audit and encourage them to
consult with them on a timely basis
x Engagement teams document their key audit judgements and conclusions, especially those
reported to the audit committee, in a way that clearly demonstrates that they have exercised an
appropriate degree of challenge to management and professional scepticism
x Partners and management bring additional scepticism to the audit by carrying out a diligent
challenge and review of the audit work performed and the adequacy of the documentation
prepared
Audit firms
x The culture within the firm emphasises the importance of:
– understanding and pursuing the perspective of the shareholders;
– coaching less experienced staff to foster appropriate scepticism;
– sharing experiences/consultation with others about difficult audit judgements; and
– supporting audit partners when they need to take and communicate difficult audit judgements.
206 Corporate Reporting
x Scepticism is embedded in the firm's training and competency frameworks used for evaluating and
rewarding partner and staff performance.
x The firm requires rigorous engagement quality control reviews that challenge engagement teams'
judgements and conclusions.
x Firm methodologies and review processes emphasise the importance of, and provide practical
support for auditors in:
– developing a thorough understanding of the entity's business and its environment;
– identifying issues early in the planning cycle to allow adequate time for them to be
investigated and resolved;
– rigorously taking such steps as are appropriate to the scale and complexity of the financial
reporting systems, to identify unusual transactions;
– changing risk assessments, materiality and the audit plan in response to audit findings;
– documenting audit judgements in a conclusive rather than a conclusionary manner;
– raising matters with the Audit Committee regarding the treatment or disclosure of an item in
the financial statements where the auditor believes that the treatment adopted is different to
the perspective of the shareholders; and
– ensuring that disclosures of such matters are carefully assessed.
This section also emphasises the supporting role that can be played by Audit Committees and
management.
3.3.7 Section 7 Taking these matters forward
The final section of the paper considers the ways in which the APB plans to take this issue forward,
particularly by stimulating debate. It acknowledges that currently it is possible to follow the 'letter' of
existing standards without conducting a truly sceptical audit. It also acknowledges that standards may
have to be improved in future to address this.
4 Understanding the entity
Section overview
x The auditor obtains an understanding of the entity in order to assess the risks of material
misstatement.
x Information will be sought regarding the industry in which the business operates and the different
business processes within the entity itself.
4.1 Procedures
ISA 315 (UK) (Revised June 2016) paragraph 3 states that 'the objective of the auditor is to identify and
assess the risks of material misstatement, whether due to fraud or error, at the financial statement and
assertion levels, through understanding the entity and its environment, including the entity's internal C
H
control, thereby providing a basis for designing and implementing responses to the assessed risks of A
material misstatement'. P
T
E
R
The statutory audit: planning and risk assessment 207
Understand and identify risks
arising from the entity and its
environment, including
Document and communicate risk assessment
relevant internal controls
Assertions:
Discuss risks amongst Classes of transactions
engagement team
Occurrence; Completeness; Accuracy;
Cutoff; Classification
Identify risk of material Account balances
misstatement at the financial
statement and assertion levels Existence; Rights and obligations;
Completeness; Valuation and
allocation
Evaluate the design and
determine the implementation Presentation and disclosure
of controls relevant to the audit
and for risks which cannot be Occurrence; Rights and obligations;
reduced to an acceptable level Completeness; Classifications and
with substantive procedures only understandability; Accuracy and
measurement
Determine whether any risks
are so significant that they
require special audit
consideration
&IGURE !UDIT 2ISK !SSESSMENT
(Source: ICAEW Audit and Assurance Faculty, !UDITING 3TANDARDS n !LL #HANGE ! 3HORT 'UIDE TO 3ELECTED
)NTERNATIONAL 3TANDARDS ON !UDITING 5+ AND )RELAND , 2004)
You will have studied the financial statement assertions in your earlier studies and you will find a more
detailed recap including changes resulting from the June 2016 revised standards in Chapter 6.
ISA 315 (UK) (Revised June 2016) sets out various methods by which the auditors may obtain this
understanding:
x Enquiries of management and others within the entity
x Analytical procedures
x Observation and inspection
x Audit team discussion of the susceptibility of the financial statements to material misstatement
x Prior period knowledge (subject to certain requirements)
The auditors must use a combination of the top three techniques, and must engage in discussion for
every audit. The auditor may use their prior period knowledge, but must carry out procedures to ensure
that there have not been changes in the year meaning that it is no longer valid.
The ISA sets out a number of areas of the entity and its environment that the auditor should gain an
understanding of. These are summarised as follows:
x Industry, regulatory and other external factors
x Nature of the entity
x The entity's selection and application of accounting policies, including reasons for any changes
x Objectives, strategies and related business risks
x Measurement and review of the company's performance
x Internal control relevant to the audit
The purpose of obtaining the understanding is to assess the risks of material misstatement in the
financial statements for the current audit. The ISA says that 'the auditor shall identify and assess the risks of
material misstatement at the financial statement level, and at the assertion level for classes of transactions,
account balances and disclosures'.
208 Corporate Reporting
It requires the auditor to take the following steps:
Step 1
Identify risks throughout the process of obtaining an understanding of the entity
Step 2
Evaluate whether the risks relate pervasively to the financial statements as a whole
Step 3
Relate the risks to what can go wrong at the assertion level
Step 4
Consider the likelihood of misstatement (including the possibility of multiple misstatements)
Step 5
Consider the likelihood of the risks causing a material misstatement
Notice therefore that the stages of the planning process often take place simultaneously rather being
performed in sequence. For example, as the auditor learns more about the business, certain risks will come
to light as a result. So the auditor is both gaining an understanding of the business and identifying risk by
adopting the same procedures. We will look at risk specifically in sections 5 and 6 of this chapter.
Worked example: Ockey Ltd
The audit team at Ockey Ltd has been carrying out procedures to obtain an understanding of the entity.
In the course of making enquiries about the inventory system, they have discovered that Ockey Ltd
designs and produces tableware to order for a number of high street stores. It also makes a number of
standard lines of tableware, which it sells to wholesalers. By the terms of its contracts with the high
street stores, it is not entitled to sell unsold inventory designed for them to wholesalers. Ockey Ltd
regularly produces 10% more than the high street stores have ordered, in order to ensure that they
meet requirements when the stores do their quality control check. Certain stores have more stringent
control requirements than others and regularly reject some of the inventory.
The knowledge above suggests two risks, one that the company may have obsolescent inventory, and
another that if its production quality standards are insufficiently high, it could run the risk of losing custom.
We shall look at each of these risks in turn and relate them to the assertion level.
Inventory
If certain items of the inventory are obsolescent due to the fact that it has been produced in excess of the
customer's requirement and there is no other available market for the inventory, then there is a risk that
inventory as a whole in the financial statements will not be carried at the appropriate value. Given that
inventory is likely to be a material balance in the statement of financial position of a manufacturing company,
and the value could be up to 10% of the total value, this has the capacity to be a material misstatement.
The factors that will contribute to the likelihood of these risks causing a misstatement are matters such as:
x whether management regularly review inventory levels and scrap items that are obsolescent;
x whether such items are identified and scrapped at the inventory count; or
x whether such items can be put back into production and changed so that they are saleable.
Losing custom
The long-term risk of losing custom is that in the future the company will not be able to operate (a
going concern risk). It could have an impact on the financial statements, if sales were disputed, revenue
and receivables could be overstated; that is, not carried at the correct value. However, it appears less
likely that this would be a material problem in either area, as the problem is likely to be restricted to a C
few customers, and only a few sales to those customers. H
A
Again, review of the company's controls over the recording of sales and the debt collection procedures P
of the company would indicate how likely these risks to the financial statements are to materialise. T
Some risks identified may be significant risks (indicated by the following factors), in which case they E
R
present special audit considerations for the auditors:
x Risk of fraud
x Its relationship with recent developments 5
x The degree of subjectivity in the financial information
x The fact that it is an unusual transaction
x It is a significant transaction with a related party
x The complexity of the transaction
The statutory audit: planning and risk assessment 209
Routine, non-complex transactions are less likely to give rise to significant risk than unusual transactions
or matters of director judgement because the latter are likely to have more management intervention,
complex accounting principles or calculations, greater manual intervention or lower opportunity for
control procedures to be followed.
When auditors identify a significant risk, if they have not done so already, they should evaluate the
design and implementation of the entity's controls in that area.
4.2 Industries and processes
During the initial planning phase, the audit firm will need to obtain information about the specific
nature of the entity being audited and the different business processes within the entity itself.
4.2.1 Industry
The type of entity being audited will have a significant impact on the audit plan. For example:
Service industry Manufacturing industry
Little or no inventory Complex costing systems to allocate costs to
inventory and work in progress
Focus on salaried employees Many production staff based paid on hours
worked including various overtime and incentive
schemes
Payment by commission May have payment by piece rates
Sales dependent on services provided Sales dependent on products sold
Relatively little investment in plant and Large investment in plant and equipment; office
equipment; office space main building cost space relatively small in comparison to production
facilities
An understanding and appreciation of these differences will assist the auditor in identifying risk areas
and in developing an appropriate audit approach.
From the auditor's point of view, the different entities will result in a different audit approach for each
entity. For example, the lack of inventory in service industries will obviously mean less time will be
devoted to that area. Conversely, the use of complicated costing systems will require use of specialist
computer-auditors to identify, record and test various computerised systems.
4.2.2 Business processes
From the comments above, it is possible to identify the different business processes that the auditor will
need to focus on. The five main processes are summarised in the diagram below.
Financing Purchasing
Obtaining capital by borrowing Acquiring goods to support
or third parties investing in the production and sales of
company company's own products
Revenue Human resources
Procedures for hiring, training,
Generating revenue through
sales of goods and obtaining Business processes evaluating, promoting and in
some situations making
cash from debtors
employees redundant
Inventory management
Process of accumulating and
allocating costs to inventory
and work in progress
&IGURE "USINESS 0ROCESSES
210 Corporate Reporting
An understanding of each process focuses the auditor's attention on specific parts of the business.
Process Audit focus
Financing Verification of new share issues / confirming current account and loan balances
and where necessary bank support for the business.
Purchasing Audit of the purchases transaction cycle and payables balance.
Human resources Audit of wages and salaries, including bonuses linked to production and
commission on sales.
Inventory Audit of work in progress systems, including year-end inventory valuation and
management identification of inventory below cost price.
Revenue Audit of sales transaction cycle and receivables balance.
The actual audit approach will depend partly on the audit methodology used.
5 Business risk model
Section overview
x Business risk is the risk arising to the business that it will not achieve its objectives.
x Corporate governance guidelines emphasise the importance of risk management processes within
a business.
x The business risk model of auditing requires the auditor to consider the entity's process of
assessing business risk and the impact this might have in terms of material misstatement.
5.1 Business risk
Business risk is the risk arising to entities that they will not achieve their objectives. It includes risks at all
levels of the business.
Business risks can be classified into three categories.
x Financial risks
x Operating risks
x Compliance risks
Definitions
Financial risks: Risks arising from the company's financial activities (eg, investment risks) or the financial
consequences of operations (eg, receivables risks).
Examples: going concern, market risk, overtrading, credit risk, interest rate risk, currency risk, cost of
capital, treasury risks.
Operating risks: Risks arising from the operations of the business. C
H
Examples: loss of orders; loss of key personnel; physical damage to assets; poor brand management; A
technological change; stock-outs; business processes unaligned to objectives. P
T
Compliance risks: Risks arising from non-compliance with laws, regulations, policies, procedures and E
contracts. R
Examples: breach of company law, non-compliance with accounting standards; listing rules; taxation;
health and safety; environmental regulations; litigation risk against client.
5
The statutory audit: planning and risk assessment 211
Business risk may be caused by many factors, or a combination of factors, including the following:
x Complex environment
x Dynamic environment
x Competitors' actions
x Inappropriate strategic decision-making
x Operating gearing
x Financial gearing
x Lack of diversification
x Susceptibility to currency fluctuations
x Inadequate actual or contingent financial resources
x Dependence on one or few customers
x Regulatory change or violation
x Adequacy and reliability of suppliers
x Overtrading
x Developing inappropriate technology
x Macroeconomic instability
x Poor management
5.2 Business risk management
Most working environments now have some form of risk management system. In Chapter 4 we
discussed the UK Corporate Governance Code and the FRC's 'UIDANCE ON RISK MANAGEMENT INTERNAL
CONTROL AND RELATED FINANCIAL AND BUSINESS REPORTING that highlight its importance. Typically the process of
risk management for the business is as follows:
x Identify significant risks which could prevent the business achieving its objectives
x Provide a framework to ensure that the business can meet its objectives
x Review the objectives and framework regularly to ensure that objectives are met
In practice, each of these stages is complex.
5.3 Audit methodology: business risk model
5.3.1 Principle behind the model
ISA 315 requires that auditors consider the entity's process for assessing its own business risks, and
the impact that this might have on the audit in terms of material misstatements. Auditors consider the
following:
x What factors lead to the problems which may cause material misstatements
x What the audit can contribute to the business pursuing its goals
The business risk audit approach tries to mirror the risk management steps that have been taken by the
directors. In this way, the auditor will seek to establish that the financial statement objectives have been
met, through an investigation into whether all the other business objectives have been met by the
directors.
The application of the business risk model (BRM) is therefore related to the client's:
x objectives
x business strategy
x risk management procedures
x industry environment
x economic environment
This approach to the audit has been called a 'top down' approach, because it starts with the business
and its objectives and works back down to the financial statements, rather than working up from the
financial statements which has historically been the approach to audit involving detailed tests of
transactions and balances. The BRM therefore looks at the 'big risks' that may significantly threaten the
valuation, profitability or even the going concern of the business. Those who support this approach
argue that the key audit risks are more likely to relate to the failure of the company's strategy than the
misstatement of a transaction.
212 Corporate Reporting
The following table demonstrates the way in which business risks can have implications for the financial
statements and therefore the audit.
Principal risk Immediate Financial Statement implications
Economic pressures causing reduced unit sales Inventory values (IAS 2)
and eroding margins Going concern
Economic pressures resulting in demands for Receivables recoverability
extended credit
Product quality issues related to inadequate Inventory values – net realisable value and inventory
control over supply chain and transportation returns
damage
Customer dissatisfaction related to inability to Going concern
meet order requirements
Customer dissatisfaction related to invoicing Receivables valuation
errors and transportation damage
Unacceptable service response call rate related to Going concern
poor product quality Litigation – provisions and contingencies
Inventories – net realisable value
Out of date IT systems affecting management's Anywhere
ability to make informed decisions
Extensive use of freelance and contract labour Employees' NI (may be understated if
resulting in issues regarding their employment freelancers/contract workers are deemed to be
status employees)
Fines – provisions and contingencies
Interactive question 1: Financial risk
On 1 January 20X8 a steel production company has significant steel inventories with a total value of
£20 million.
To protect the inventory from changes in value, the entity enters into a futures contract on a
commodities exchange to fix the selling price in 18 months' time. This is the first time that the entity
has entered into this type of transaction.
Requirements
(a) Identify the business risk in this situation.
(b) Identify the issues which the auditor would need to consider.
See Answer at the end of this chapter.
5.3.2 Impact on audit procedures
This can be summarised as follows:
Audit procedure Effect of business risk model C
H
Tests of controls As the auditor pays greater attention to the high level controls used by A
directors to manage business risks, controls testing will be focused on items P
such as the control environment and corporate governance rather than the T
detailed procedural controls tested under traditional approaches. E
R
Analytical procedures Analytical procedures are used more heavily in a business risk approach, as
they are consistent with the auditor's desire to understand the entity's
business rather than to prove the figures in the financial statements. 5
Detailed testing The combination of the above two factors, particularly the higher use of
analytical procedures, will result in a lower requirement for detailed testing,
although substantive testing will not be eliminated completely.
The statutory audit: planning and risk assessment 213
Interactive question 2: Audit procedures
You are using the business risk model in the statutory audit of a major international pharmaceutical company.
You are told that the key determinant of profitability is the development of new types of drug, which
are superior to those of competitors. This is achieved by significant investment in research and
development (R&D). However, you are also informed that such drugs may take as many as ten years
before gaining regulatory approval for use. One major R&D project is a joint venture with another
pharmaceutical company.
Requirements
Outline
(a) The key risks facing the company
(b) Controls that management might use to mitigate such risks
(c) Audit procedures to be carried out in respect of such risks
See Answer at the end of this chapter.
Interactive question 3: Identifying business risks
KidsStuff Ltd imports children's toys from a supplier in the Far East into its warehouse in Liverpool and
distributes them to retailers throughout the UK. The company was set up by Joseph Cooper 40 years
ago and is managed by Joseph and his two sons. The company had experienced reasonable growth
until the last five years, but recent performance has been poor and the company now relies on a
substantial overdraft. Joseph feels that the decline is due in part to the competitiveness of the market
and the trend towards computer games. KidsStuff Ltd does not have a strong market presence in this
area but this is currently being addressed by Joseph's son, Neil, who is confident that performance has
improved.
You have received the following email from the engagement partner.
From Allan Partner
To Audrey Senior
Subject KidsStuff Ltd
I know you are about to start work on your planning of this audit. Can you make sure that you
specifically identify the business risks faced by KidsStuff Ltd and set out the effect of those on the audit.
Can you also make a list of the further information you need in order to plan the audit so that I can
request it from the directors?
Requirement
Respond to the engagement partner's email.
See Answer at the end of this chapter.
6 Audit risk model
Section overview
x Audit risk is the risk that the auditors may give an inappropriate opinion when the financial
statements are materially misstated.
x The risk of material misstatement is made up of inherent risk and control risk.
x The audit risk model expresses the relationship between the different components of risk as follows:
Audit risk = Inherent risk u Control risk u Detection risk
x Business risk forms part of the inherent risk associated with the financial statements.
x Information gained in obtaining an understanding of the business is used to assess inherent risk.
x Assessment of control risk involves assessing the control environment and control activities.
214 Corporate Reporting
6.1 Audit risk
Definitions
Audit risk: The risk that auditors may give an inappropriate audit opinion when the financial statements
are materially misstated. Audit risk has two key components: risk of material misstatement in financial
statements (financial statement risk) and the risk of the auditor not detecting the material misstatements
in financial statements (detection risk). The risk of material misstatement breaks down into inherent risk
and control risk.
Inherent risk: The susceptibility of an assertion about a class of transaction, account balance or
disclosure to a misstatement that could be material, either individually or when aggregated with other
misstatements, before consideration of any related controls.
Control risk: The risk that a misstatement could occur in an assertion about a class of transaction,
account balance or disclosure and that could be material, either individually or when aggregated with
other misstatements, will not be prevented, or detected and corrected, on a timely basis by the entity's
internal control.
Detection risk: The risk that the procedures performed by the auditor to reduce audit risk to an
acceptably low level will not detect a misstatement that exists and that could be material, either
individually or when aggregated with other misstatements.
Point to note:
The ISAs do not ordinarily refer to inherent risk and control risk separately but rather to the combined
'risks of material misstatement'. Firms may assess them together or separately depending on their
preferred methodology and audit techniques.
6.2 Audit methodology: the audit risk model
The audit risk model (ARM) expresses the relationship between the different components of risk as
follows:
AR = IR u CR u DR
In using this model the auditor will follow three key steps:
(1) The auditor will set a planned level of audit risk for each account balance or class of transaction.
(2) Inherent risk and control risk are assessed, either separately or in combination. This will involve an
assessment of business risk and the risk of material misstatement (due to fraud or error).
(3) Detection risk is then set at an appropriate level by 'solving' the audit risk equation.
This approach can be demonstrated as follows:
Example Audit risk Inherent risk Control risk Detection risk
1 Acceptable High High Low
2 Acceptable Low High Moderate
C
3 Acceptable High Low Moderate H
A
This model will then assist in the determination of the extent and type of procedures to be performed. P
For example, the higher the assessment of inherent and control risk, the lower the assessment of T
detection risk resulting in more evidence being obtained from the performance of substantive E
procedures. R
Points to note:
1 One of the criticisms of the ARM is the 'compensatory' approach it takes. In the table above, high 5
inherent and control risk is compensated for by low detection risk. Arguments have been put
forward that evidence should be complementary rather than compensatory.
The statutory audit: planning and risk assessment 215
2 Inherent risk and control risk are either 'high' or 'low' in the above table. This 'all or nothing'
approach is adopted by some audit firms. Thus, for instance, where there is a significant risk event
with respect to an audit area, then the inherent risk would always be deemed to be high. Other
audit firms may see risk as a spectrum with, for instance, an intermediate rating of 'moderate risk'
where there would be some reliance gained from inherent assurance, despite there being some
measure of risk observed.
6.2.1 The risk assessment process
This can be summarised as follows:
Perform risk assessment procedures
to obtain an understanding of the
entity and its environment, including
internal control
Identify business risks that may
result in material misstatements
in the financial statements
Evaluate the entity’s response to
those business risks and obtain
evidence of their implementation
Assess the risk of material misstatement
at the assertion level and determine the
audit procedures that are necessary
based on that risk assessment
&IGURE 2ISK !SSESSMENT 0ROCESS
(Source: !UDITING AND !SSURANCE 3ERVICES )NTERNATIONAL %DITION, 2005 Aasmund Eilifsen, William F. Messier
Jr, Steven M. Glover, Douglas F. Prawitt)
Point to note:
Notice the relationship between business risk (which we looked at in detail above) and audit risk.
Business risk includes all risks facing the business. In other words, inherent audit risk may include
business risks.
In response to business risk, the directors institute a system of controls. These will include controls to
mitigate against the financial aspect of the business risk. These are the controls that audit control risk
incorporates.
Therefore, although audit risk is very financial statements focused, business risk does form part of the
inherent risk associated with the financial statements (ie, is part of financial statement risk) not least
because, if the risks materialise, the going concern basis of the financial statements could be affected.
216 Corporate Reporting
The following illustrates the link between business risk and financial statement risk:
Business risk Financial statement risk
Computer viruses could lead to significant loss of Uncertainties over going concern may not be fully
sales disclosed
Weaknesses in cyber security and corporate data Provisions relating to breaches of regulations may
security could result in breaches of data protection be omitted or understated
law and other regulations resulting in financial
penalties
The business may suffer losses from credit card Losses arising from frauds may not be recognised
fraud in the financial statements
6.2.2 Inherent risk
As we saw in section 6.1, the risk of material misstatement is made up of:
x inherent risk
x control risk
Inherent risk is the risk that items will be misstated due to characteristics of those items, such as the fact
they are estimates and that they are important items in the accounts. The auditors must use their
professional judgement and the understanding of the entity they have gained to assess inherent risk. If
no such information or knowledge is available then the inherent risk is high.
Factors affecting client as a whole
Integrity and attitude to risk of directors and Domination by a single individual can cause
management problems
Management experience and knowledge Changes in management and quality of financial
management
Unusual pressures on management Examples include tight reporting deadlines, or
market or financing expectations
Nature of business Potential problems include technological
obsolescence or overdependence on single product
Industry factors Competitive conditions, regulatory requirements,
technological developments, changes in customer
demand
Information technology Problems include lack of supporting documentation,
concentration of expertise in a few people, potential
for unauthorised access
Factors affecting individual account balances or transactions
Financial statement accounts prone to Accounts which require adjustment in previous
misstatement period or require high degree of estimation C
H
Complex accounts Accounts which require expert valuations or are A
subjects of current professional discussion P
T
Assets at risk of being lost or stolen Cash, inventory, portable non-current assets E
(computers) R
Quality of accounting systems Strength of individual departments (sales, purchases,
cash etc) 5
High volume transactions Accounting system may have problems coping
The statutory audit: planning and risk assessment 217
Factors affecting individual account balances or transactions
Unusual transactions Transactions for large amounts, with unusual names,
not settled promptly (particularly important if they
occur at period end)
Transactions that do not go through the system, that
relate to specific clients or are processed by certain
individuals
Staff Staff changes or areas of low morale
Interactive question 4: Inherent risks from financial reporting policies
Fonesforall is a mobile phone network provider with its own retail outlets. It is currently offering the
following package for £30 per month.
ZX4 mobile phone handset
12-month subscription to the network
300 'free' call minutes per month (for 12 months)
500 'free' texts per month (for 12 months)
Any unused call minutes or texts may be carried forward to the following month
The fair value of this package is estimated to be £500
Requirement
Identify the risks associated with the treatment of revenue in relation to this package in the financial
statements of Fonesforall.
See Answer at the end of the chapter.
6.2.3 Control risk
Control risk is the risk that client controls fail to detect material misstatements. A preliminary
assessment of control risk at the planning stage of the audit is required to determine the level of
controls and substantive testing to be carried out.
In this respect, a key initial audit question is 'how does management control the business?'. An
understanding of this issue is a key element in an initial assessment of control risk.
Substantive and reliance strategies
For an ongoing client, the auditor will already have significant information on file regarding the control
systems at the audit client. The audit strategy will therefore focus on updating this control information.
For a new client, a judgement on audit strategy will normally be deferred until after a more detailed
understanding of internal control is obtained. For the new client, the auditor will obtain information
on the control systems and then perform an initial testing of those controls to determine whether or
not they are working correctly. Where these risk assessment procedures indicate that controls are not
working correctly, then it is unlikely that the auditor will place reliance on those controls, as control risk
will be set to maximum. Substantive procedures will be used instead. However, if the risk assessment
procedures indicate that controls are working correctly, then some reliance will be placed on internal
controls. Control risk may be set only as either 'high' or 'low' in an all or nothing approach, as previously
noted. Alternatively, there may be a possibility of setting control risk to an intermediate amount(s)
within some firms' audit methodologies.
So, providing an initial determination of the nature, timing and extent of audit procedures, two possible
audit strategies are normally identified:
x Substantive strategy – focusing on substantive testing (ie, tests of details and analytical procedures)
x Reliance strategy – focusing on tests of controls and reliance from inherent assurance
Points to note:
1 There will not be one strategy for the entire audit. Each business process or specific audit assertion
will be allocated its own strategy. Similarly, each audit assertion may be allocated a different 'mix'
of reliance and substantive strategy.
218 Corporate Reporting
2 Auditing standards do require some substantive testing for each material class of transactions,
account balances and disclosure, so the audit strategy for any one assertion will never be
completely a reliance strategy.
3 However, it is possible (but unusual) that substantive testing may comprise entirely of analytical
procedures, without any tests of details being carried out.
An auditor is more likely to follow a reliance strategy where:
x an entity uses electronic data interchange to initiate orders; there will be no paper
documentation to verify;
x an entity provides electronic services to its customers eg, an internet service provider or telephone
company. No physical goods are produced, with all information being collected and billing carried
out electronically; and
x the test is for understatement.
An auditor is more likely to follow a substantive strategy where:
x there are no controls available for a specific audit assertion;
x the controls are assessed as ineffective;
x it is inefficient to test the effectiveness of the controls; and
x the test is for overstatement.
Whichever strategy is chosen, the auditor will document the reasons for choosing that strategy and
then perform detailed auditing procedures in accordance with that strategy.
Control environment
Within an entity, the control system works within the control environment. A poor control
environment implies that the control system itself will also be poor, because the entity does not place
sufficient emphasis on having a good control environment.
So, the control environment sets the philosophy of an entity effectively influencing the 'control
consciousness' of directors and employees. The importance of the enforcement of integrity and ethical
values was illustrated in July 2011, with the closure of the .EWS OF THE 7ORLD newspaper resulting from
phone hacking allegations.
Factors affecting the control environment include:
Factor Explanation
Communication and An organisation should try to maintain the integrity and ethical standing
enforcement of integrity of the employees. Membership of a professional body helps enforce
and ethical values ethical standards for professional staff. Ethics in other areas are maintained
by ensuring rules do not encourage unethical conduct (eg, unrealistically
high sales targets to earn commissions).
Commitment to Each job should have a job description showing the standards expected in
competence that job. Employees should then be hired with the competences to carry
out the job without compromising on the quality of work produced.
Participation by those Those charged with governance should take an active role in ensuring
charged with governance ethical standards are maintained. For example, the audit committee
should ensure that directors carry out their duties correctly in the context C
of the audit. Similarly, those charged with governance must ensure H
appropriate independence from the company they are governing. A
P
Management philosophy Management should set the example of following ethical and quality T
standards. Where management establish a risk management system and E
regularly discuss the effect of risks on an organisation then the auditor will R
gain confidence that the overall control environment is effective.
Structure of the The structure of the organisation should ensure that authority is 5
organisation delegated appropriately so that lower management levels can
implement appropriate risk management procedures. However,
responsibility for risk management overall is maintained by the board.
The statutory audit: planning and risk assessment 219
Factor Explanation
Reporting hierarchy Within the organisation's hierarchy, each level of management has
responsibilities for risk included in their job description. There should also
be a clear reporting system so that objectives for risk management are
communicated down the hierarchy, while identified risks are
communicated back up the hierarchy for action.
HR policies and HR policies should have appropriate policies for ensuring the integrity of
procedures staff, both for new employees and for continued training and
development.
From a review of these factors, the auditor will form an opinion on the effectiveness of the control
environment. The auditor will also consider the means by which the entity monitors controls eg, by the
internal audit department. This in turn affects the opinion on how well the internal control systems will
be implemented and operated.
Control risk will also increase where specific events occur within an organisation. Events that tend to
increase control risk include the following:
x Use of new technology
x New or substantially amended information systems
x Hiring of new personnel, especially into key management roles
x Changes to the regulatory or operating environment
x Significant growth in the organisation
x Restructuring of the company or group
x Expansion of overseas operations
Control activities
Having assessed the control environment, the auditor will then identify and assess the control activities
carried out by management. Control activities in this context are the policies and procedures that help
ensure management's directives are carried out.
Control activities that the auditor will investigate include:
Control Explanation
activity
Physical Controls to ensure the security of assets including data files and computer programs
controls (eg, not simply tangible assets such as company motor vehicles).
Segregation Segregation of the authorisation of transactions, recording of transactions and custody
of duties of any related assets. For example, employees receiving cash should not be responsible
for recording that cash in the receivables ledger – teeming and lading could occur.
Performance Reviews to check the performance of individuals are carried out on a regular basis. The
reviews review includes comparing actual performance against agreed standards and budgets
and accounting/obtaining reasons for any variances.
Information These are controls to check the completeness, accuracy and authorisation of the
processing processing of transactions. Two types of controls are generally recognised:
controls
x General controls – over the information processing environment as a whole, for
example to ensure the security of data processing operations and maintenance of
adequate backup facilities.
x Application controls – over the processing of individual transactions, again ensuring
the completeness and accuracy of recording.
Where the auditor is satisfied regarding the ability of the control environment to process transactions
correctly and control activities to identify deficiencies in that processing, then control risk can be set to a
low figure. Obviously, where the control environment is weak, and control activities are missing, then
control risk will be set to a higher level.
220 Corporate Reporting
Control activities for transaction assertions
Within each class of transactions, the auditor will ensure that specific audit assertions have been achieved.
Remember that for each assertion, a different 'mix' of control and substantive procedures may be used.
For each of the audit assertions relevant to transaction testing, specific control activities are normally available.
The assertions and control activities are summarised below.
Assertion Explanation Typical control activities
Occurrence Transactions and events that have x Segregation of duties
been recorded have occurred and
pertain to the entity x Daily/monthly reconciliation of
subsidiary records with an independent
review
x Prenumbering of documents (with
completeness of numbering confirmed)
Completeness All transactions and events that should x Segregation of duties
have been recorded have been
recorded, and all related disclosures x Prenumbering of documents (with
that should have been included in the completeness of numbering confirmed)
financial statements have been x Daily/monthly reconciliation of
included subsidiary records with an independent
review
Accuracy Amounts and other data relating to x Internal confirmation of amounts and
recorded transactions and events have calculations
been recorded appropriately, and
related disclosures have been x Monthly reconciliation of subsidiary
appropriately measured and described records by an independent person
Cut-off Transactions and events have been x Procedures for the prompt recording of
recorded in the correct accounting transactions
period
x Internal verification of cut-off at year
end
Classification Transactions and events have been x Agreeing transactions against chart of
recorded in the proper accounts accounts
x Internal verification of the accuracy of
posting
Monitoring controls
The auditor should also assess the means by which management monitors internal control over financial
reporting. In many entities internal auditors fulfil this function. The impact on the audit of the existence
of an internal audit function is dealt with in ISA (UK) 610 (Revised 2016) 5SING THE 7ORK OF )NTERNAL
!UDITORS.
6.2.4 Detection risk C
H
Detection risk is the risk that audit procedures will fail to detect material errors. Detection risk relates to the A
inability of the auditors to examine all evidence. Audit evidence is usually persuasive rather than conclusive P
so some detection risk is usually present, allowing the auditors to seek 'reasonable confidence'. T
E
The auditor's inherent and control risk assessments influence the nature, timing and extent of R
substantive procedures required to reduce detection risk and thereby audit risk.
6.2.5 Risk assessment and data analytics 5
Data analytics tools may be used in risk analysis. Data analytics is discussed further in section 13.
The statutory audit: planning and risk assessment 221
Interactive question 5: Audit risk
Forsythia is a small limited company offering garden landscaping services. It is partly owned by three
business associates, Mr Rose, Mr White and Mr Grass, who each hold 10% of the shares. The major
shareholder is the parent company, Poppy Ltd. This company owns shares in 20 different companies,
which operate in a variety of industries. One of them is a garden centre, and Forsythia regularly trades
with it. Poppy Ltd is in turn wholly owned by a parent, White Holdings Ltd.
The management structure at Forsythia is simple. Of the three non-corporate shareholders, only
Mr Rose has any involvement in management. He runs the day to day operations of the company
(marketing, sales, purchasing etc) although the company employs two landscape gardeners to actually
carry out projects. The accounts department employs a purchase clerk and a sales clerk, who deal with
all aspects of their function. The sales clerk is Mr Rose's daughter, Justine. Mr Rose authorises and
produces the payroll. The company ledgers are kept on Mr Rose's personal computer. Two weeks after
the year end, the sales ledger records were severely damaged by a virus. Justine has a single printout of
the balances as at the year end, which shows the total owed by each customer.
Forsythia owns the equipment which the gardeners use and pays them a salary and a bonus based on
performance. Mr Rose is remunerated entirely on a commission basis relating to sales and, as a
shareholder, he receives dividends annually, which are substantial.
Forsythia does not carry any inventories. When materials are required for a project, they are purchased
on behalf of the client and charged directly to them. Most customers pay within the 60-day credit
period, or take up the extended credit period which Forsythia offers. However, there are a number of
accounts that appear to have been outstanding for a significant period.
Justine and her father do not appear to have a very good working relationship. She does not live at
home and her salary is not significant. However, she appears to have recently purchased a sports car,
which is not a company car.
The audit partner has recently accepted the audit of Forsythia as a new client. You have been assigned
the task of planning the first audit.
Requirement
Identify and explain the audit risks arising from the above scenario.
See Answer at the end of this chapter.
7 Creative accounting
Section overview
x There is a spectrum of activity with respect to accounting policy choice. Creative accounting
attempts to change users' perceptions of the performance and position of a business.
x The occurrence of creative accounting depends on both incentives and opportunity.
x The consequences of creative accounting depend upon a range of factors that change over time
but are specific to individual companies.
x Creative accounting can be overt (disclosed) or covert (not disclosed).
x Red flags exist which may indicate that creative accounting practices have taken place.
x Empirical evidence supports the notion that creative accounting occurs on a widespread basis.
7.1 Introduction
One of the factors affecting the overall level of financial statement risk is the potential for creative
accounting.
Directors have choices and they may exercise those choices to recognise values that do not reflect
economic reality. A prime example is the choice of the cost model when an asset's fair value is
222 Corporate Reporting
significantly higher than cost. (Note: If an asset's fair value and value in use were lower than cost,
then an impairment would be required under IAS 36 and directors would not have the discretion to
disclose at cost.) Directors are more likely to make use of their discretion to mislead financial
statement users if they have the opportunity (eg, imprecise accounting regulations, weak auditors)
and incentives (eg, approaching the breach of a debt covenant, an impending takeover, profit-
based bonus) to do so.
Creative accounting is covered from a financial reporting perspective in Chapter 24.
7.2 The nature of creative accounting
Definition
Creative accounting: The active manipulation of accounting results for the purpose of creating an
altered impression of the underlying financial position or performance of an enterprise by using
accounting rules and guidance in a spirit other than that which was intended when the rules were
written.
This well-documented practice is a potential problem for auditors in assessing the underlying
performance and position of a company and recent evidence suggests that it is one of the major issues
facing financial reporting.
Accounting measures involve a degree of subjectivity, choice and judgement and it would be wrong to
describe all such activity as creative accounting. Moreover, creative accounting normally falls within
permitted regulation and is not therefore illegal. It is therefore often a question of fine judgement as to
when creative accounting is of such an extent that it becomes misleading.
The spectrum of creative accounting practices may include the following (commencing with the most
legitimate):
x Exercise of normal accounting policy choice within the rules permitted by regulation (eg, first in,
first out and average cost for inventory valuation)
x Exercise of a degree of estimation, judgement or prediction by a company within reasonable
bounds (eg, non-current asset lives)
x Judgement concerning the nature or classification of a cost (eg, expensing and capitalising costs)
x Systematic selection of legitimate policy choices and estimations to alter the perception of the
position or performance of the business in a uniform direction
x Systematic selection of policy choice and estimations that fall on the margin of permitted
regulation (or are not subject to regulation) in order to alter materially the perception of the
performance or position of the business
x Setting up of artificial transactions to create circumstances where material accounting
misrepresentation can take place
x Fraudulent activities.
It can thus be a matter of fine judgement for an auditor as to where within this spectrum creative C
accounting becomes unacceptable. H
A
Companies may also seek to manipulate the perception of their performance and position by altering P
underlying transactions, rather than just the way they are recorded. Accounting regulation seeks to limit T
the effects of this behaviour in a number of ways as previously discussed. Nevertheless, while it may seek E
R
to report faithfully transactions that actually take place, it cannot regulate for transactions which do not
take place, or which are delayed in order to manipulate the perception of performance or position.
These might include:
5
x deferring discretionary expenditure (eg, maintenance costs, R&D);
x changing the timing of the sale of investments or other assets; or
x delaying investment or financing decisions.
The statutory audit: planning and risk assessment 223
Worked example: Tesco
Tesco has been in the news recently after an accounting scandal arising because the company delayed
and deducted millions of pounds from suppliers and also charged its suppliers twice for money owed, in
order to improve its financial position. The accounting treatment resulted in an overstatement of profits
of £263 million in its half-year results in 2014. Three of the company's senior directors were charged
with fraud by abuse of power and fraud by false accounting. The company and its auditors, PwC, were
investigated by the SFO, FCA and FRC.
The latest position on this scandal is that Tesco has been ordered to pay a fine of £129 million and
£85 million in compensation to investors who bought shares or bonds between 29 August and
19 September 2014, under a deferred prosecution agreement.
The former auditor of the company, PwC, was also under investigation by the FRC but in June 2017, the
investigation was closed and the firm avoided official censure over the scandal.
7.3 Causes of creative accounting – opportunity
The causes of creative accounting have two key elements:
x Opportunity
x Incentives
Where these two elements both exist then the risks of creative accounting taking place are greatest.
This section looks at opportunity. The following section looks at incentives.
It is important for the auditor to be aware of the causes of creative accounting in order to highlight the
circumstances, where there is the greatest risk or incentives for creative accounting to take place.
The causes of opportunity for creative accounting include the following:
x Subjectivity – Areas of subjectivity lend themselves to a greater degree of choice, judgement and
uncertainty.
x Complexity – Complex industries and transactions are difficult to regulate precisely and give more
scope for manipulation.
x Inadequate corporate governance – Inadequate or inappropriate controls over directors may
permit greater discretion.
x Insufficiently independent auditors n Auditors may come under increased managerial pressure to
approve creative accounting practices.
x Imprecise regulations n Where regulations are imprecise or inadequate, companies have greater
scope to exercise discretion, and auditors have a poor benchmark to challenge the selected
accounting procedures.
x Inadequate sources of information – Where reliable sources of audit evidence exist (eg, to
challenge management estimations) the scope for effective manipulation is more limited.
x Inadequate penalties n Where creative accounting is discovered to have misled users, the
penalties for the company, and for the directors, are regarded by some as inadequate to provide
sufficient disincentives.
7.4 Causes of creative accounting – incentives
The following have been put forward as incentives for companies/managers engaging in creative accounting:
x Income smoothing – Companies normally prefer to show a steady trend of growth in profits,
rather than volatility with significant rises and falls. Income smoothing techniques (eg, declaring
higher provisions and deferring income recognition in good years) contribute to reducing volatility
in reported earnings.
x Achieving forecasts – Where forecasts of future profits have been made, reported earnings may be
manipulated to tie in with these forecasts.
x Profit enhancement – This is where current year earnings are boosted to enhance the short-term
perception of performance.
224 Corporate Reporting
x Maintain or boost share price – Where markets can be made to believe that increased earnings
represent improved underlying commercial performance, then share price may rise, or at least be
higher than it would be in the absence of creative accounting.
x Accounting-based contracts n Where accounting-based contracts exist (eg, loan covenants,
profit-related pay) then any accounting policy that falls within the terms of the contract may
significantly impact on the consequences of that contract. For example, the breach of a gearing-
based debt covenant may be avoided by the use of off balance sheet financing.
x Incentives for directors n There may be personal incentives for directors to enhance profit in order
to enhance their remuneration. Examples might include: bonuses based on earnings per share
(EPS), or share incentive schemes and share option schemes that require a given EPS before they
become operative. Directors may also benefit more indirectly from creative accounting by
increasing the security of their position.
x Taxation n Where accounting practices coincide with taxation regulations there may be an
incentive to reduce profit in order to reduce taxation. In these circumstances, however, it may be
necessary to convince not only the auditor but also HMRC.
x Regulated industries n Where an industry is currently, or potentially, regulated then there may
be an incentive to engage in creative accounting to reduce profit in order to influence the
decisions of the regulator. This may include utilities where regulators may curtail prices if it is
perceived that excessive profits are being earned. It may also be relevant to avoid a reference to
the Competition Commission.
x Internal accounting – A company as a whole may have reason to move profits from division to
division (or subsidiary to subsidiary) in order to affect tax calculations or justify the
closure/expansion of a particular department.
x Losses – Companies making losses may be under greater pressure to enhance reported
performance.
x Commercial pressures n Where companies have particular commercial pressures to enhance the
perception of the company there is increased risk of creative accounting; for example, a takeover
bid, or the raising of new finance.
Thus, a range of stakeholders may have incentives to engage in creative accounting. In particular,
however, an appropriate degree of professional scepticism should be applied where benefits arise for
directors, as they are also the group responsible for implementing creative accounting practices.
7.5 The consequences of creative accounting
It is important for the auditor to understand the consequences of creative accounting, as:
x It enables an understanding of the motivations and reasons for the company's directors to
engage in the practice. (For instance, the existence and nature of a debt covenant that may be
affected by creative accounting.)
x It enhances the understanding of whether the practice is material ie, whether it would
reasonably influence decisions made.
x It enables an understanding of the continued impact of a particular creative accounting practice
in future years' financial statements and whether the impact will be sustainable year on year.
C
The consequences of creative accounting depend crucially upon whether or not it is disclosed. H
A
Overt creative accounting refers to practices, which may change reported profits or the statement of P
financial position, but that are disclosed externally to financial statement users. Examples may include: T
E
x Not depreciating non-current assets R
x Capitalising development costs
x Significant provisioning
x Changing depreciation policy 5
Covert creative accounting refers to practices that are used to enhance profitability or asset values but
are not disclosed. Examples might be:
x The timing of revenue recognition on complex long-term transactions
The statutory audit: planning and risk assessment 225
x The treatment of overhead allocations
x Many decisions to capitalise or expense cash outlays
As a result, such covert practices are not readily identifiable by outside users, who are thus unable, in
some cases, to distinguish increases in reported earnings arising as a result of accounting manipulation,
from those arising from improvements in substantive underlying transactions. The potential
consequences of covert creative accounting (eg, for share price movements) are therefore likely to be
more substantial than for overt creative accounting.
7.6 Sustainability
Some creative accounting practices are sustainable in the long term while others may only serve to
enhance the current year's profit, but only with the effect that future profits are correspondingly reduced.
Sustainable practices may include the following:
x Income smoothing – assuming it is smoothed at a normal level of profitability, it may be sustained
indefinitely
x Off balance sheet financing
Unsustainable practices include the following:
x Capitalisation of expenses – if, for instance, annual development costs are inappropriately
capitalised and amortised over 10 years then, after that period, assuming constant expenditure,
the profit will be equivalent for either write-off or amortisation policies (though not the
statement of financial position) as there will be 10 amounts of 10% amortisation recognised in
profit or loss
x Revenue recognition – bringing forward the recognition of revenues may initially enhance profit,
but at the cost of reducing future profits
7.7 Some specific consequences
Share price effects
Where creative accounting practices are disclosed then one would expect that, in a semi strong efficient
market, investors would see through the manipulation and correctly price shares, with creative
accounting having little effect. However:
x the market may not always be efficient;
x accounting-based contracts may be affected; and
x complex series of transactions may mean that markets fail to appreciate fully the impact of creative
accounting.
Covert creative accounting is likely to include all the above effects but in addition, even where the
market is semi-strong efficient, it cannot always 'see through' the creative accounting and shares could
be mispriced. This may result in shareholders suffering an undue loss.
Recent revelations regarding creative accounting have resulted in significant falls in the share prices of
the companies concerned providing evidence of previous mispricing. However, shares prices also fell in
other companies, as markets generally placed less trust in reported earnings and auditors were
perceived as being unable to prevent creative accounting.
Accounting-based contracts
Whether creative accounting is covert or overt, it can affect the application of accounting-based
contracts, so long as the selected accounting treatment falls within the terms of that contract. Typically,
a restrictive covenant on gearing, or interest cover, may be avoided by enhancing equity or earnings.
This may benefit one stakeholder (eg, shareholders) but disadvantage another (eg, debtholders).
7.8 Red flags and detection
The best detection techniques for creative accounting are a good knowledge of financial reporting
regulations and a good understanding of the business. There may, however, be more general
techniques and indicators that can suggest that a company is engaging in creative accounting practice.
These include the following:
226 Corporate Reporting
x Cash flows – Operating cash flows are systematically out of line with reported operating profits
over time.
x Reported income and taxable income – Is financial reporting income significantly out of line with
taxable income with inadequate explanation or disclosure?
x Acquisitions – Where a significant number of acquisitions have taken place, there is increased
scope for many creative accounting practices.
x Financial statement trends – Indicators include: unusual trends, comparing revenue and EPS
growth, atypical year-end transactions, flipping between conservatism and aggressive accounting
from year to year, level of provisions compared to profit indicating smoothing, EPS trend, timing of
recognition of exceptional items.
x Ratios – Ageing analyses revealing old inventories or receivables, declining gross profit margins but
increased net profit margins, inventories/receivables increasing more than sales, gearing changes.
x Accounting policies – Consider if there is the minimum disclosure required by regulation, changes
in accounting policies, examine areas of judgement and discretion. Consider risk areas of off
balance sheet refinancing, revenue recognition, capitalisation of expenses, significant accounting
estimates.
x Changes of accounting policies and estimates – Is the nature, effect and purpose of these
changes adequately explained and disclosed?
x Management – Estimations proved unreliable in the past, minimal explanations provided.
x Actual and estimated results – Culture of always satisfying external earnings forecasts, absence of
profit warnings, inadequate or late profit warnings leading to 'surprises', interim financial
statements out of line with year-end financial statements.
x Incentives – Management rewarded on reported earnings, profit-orientated culture exists, other
reporting pressures eg, a takeover.
x Audit qualifications – Are they unexpected and are any auditors' adjustments specified in the audit
report significant?
x Related party transactions – Are these material and how far are the directors affected?
The above is not a comprehensive list, but merely includes some main factors. Also, it is not suggested
that the above practices necessarily mean there is creative accounting but, where a number of these
factors exist simultaneously, then the auditor should be put 'on inquiry' to make further investigations.
7.9 Examples of creative accounting techniques
A number of examples of creative accounting have been given above and throughout these learning
materials in the context of their application. The following list draws some of these together and
provides further examples under key headings. The list is not meant to be comprehensive.
7.9.1 Timing of operating expenses
x Underprovisioning in poor years
x Overprovisioning in good years
C
x Manipulation of reserves H
x Aggressive capitalisation of costs A
x Optimistic asset lives P
T
x Accelerating expenses in good years E
x Increased write-downs and write-offs in good years R
x Exceptional gains timed to offset exceptional losses
7.9.2 Revenue recognition 5
x Premature recognition of revenues
x Recording out of period revenue
x Recognition of revenue of service contracts before the service being performed
The statutory audit: planning and risk assessment 227
x Recognition of sales before physical movement of goods
x Front-end recognition of sales that should be spread over more than one accounting period
x Percentage of completion estimates in construction industry
x Cut-off misapplied
7.9.3 Off balance sheet financing
In some circumstances transactions may be structured in order to allow a particular accounting
treatment (eg, making a finance lease appear to be an operating lease) rather than presenting the fairest
view. This is one of the primary reasons for the large quantity of disclosure standards (as against
measurement standards) in previous years.
8 Materiality
Section overview
x Materiality considerations are important at the planning stage.
x An item might be material due to its nature, value or impact on readers of financial statements.
8.1 Revision of materiality
Definition
ISA (UK) 320 -ATERIALITY IN 0LANNING AND 0ERFORMING AN !UDIT states that the auditor's frame of reference
for materiality should be based on the relevant financial reporting framework. IAS 1 gives the following
definition:
Materiality: Omissions or misstatements of items are material if they could, individually or collectively,
influence the economic decisions that users make on the basis of the financial statements. Materiality
depends on the size and nature of the omission or misstatement judged in the surrounding
circumstances. The size or nature of the item, or combination of both, could be the determining factor.
Materiality criteria
An item might be material due to its:
Nature Given the definition of materiality that an item would affect the readers of the
financial statements, some items might by their nature affect readers. Examples
include transactions related to directors, such as remuneration and contracts with
the company.
Value Some items will be significant in the financial statements by virtue of their size; for
example, if the company had bought a piece of land with a value which comprised
three-quarters of the asset value of the company, that would be material. That is
why materiality is often expressed in terms of percentages (of assets, of profits).
Impact Some items may by chance have a significant impact on financial statements; for
example, a proposed journal which is not material in size could convert a profit into
a loss. The difference between a small profit and a small loss could be material to
some readers.
Although there are general guidelines on how materiality might be calculated in practice, the
calculation involves the application of judgement. It should be reassessed throughout the course of the
audit as more information becomes available. Note that as materiality has both quantitative and
qualitative aspects risk assessment must include the analysis of both quantitative and qualitative data.
228 Corporate Reporting
Users' needs
The auditor must consider the needs of the users of the financial statements when setting materiality.
The ISA indicates that it is reasonable for the auditor to assume that users:
x Have a reasonable knowledge of the business and economic activities and accounting and a
willingness to study the information in the financial statements with reasonable diligence
x Understand that financial statements are prepared and audited to levels of materiality
x Recognise the uncertainties inherent in the measurement of amounts based on the use of
estimates, judgement and the consideration of future events
x Make reasonable economic decisions on the basis of the information in the financial statements
8.2 Applying materiality
The application of materiality to an audit can be summarised in three key steps:
Establish a preliminary judgement
Step 1
about materiality
Determine performance
Step 2
materiality
Estimate likely misstatements and
Step 3 compare totals to the preliminary
judgement about materiality
&IGURE 3TEPS IN !PPLYING -ATERIALITY ON AN !UDIT
Steps 1 and 2 would normally be performed as part of the planning process. Step 3 is normally
performed as part of the review stage of the audit when the auditor evaluates the audit evidence.
Auditors of companies applying the UK Corporate Governance Code are required to make significant
disclosures in the auditor's report about how they have applied materiality in their audit.
8.2.1 Preliminary judgement
Materiality considerations during audit planning are extremely important. The assessment of materiality
at this stage should be based on the most recent and reliable financial information and will help to
determine an effective and efficient audit approach. Materiality assessment will help the auditors to:
x determine the amount of audit work necessary to facilitate audit efficiency and effectiveness;
x put audit risk in context;
x decide whether to use sampling techniques;
x determine the applicability of accounting standards which normally apply only to material items;
x evaluate uncorrected misstatements during the audit; and
x evaluate what level of error is likely to lead to a modified audit opinion. C
H
In specifying materiality, an auditor should establish a benchmark (or benchmarks) to which a A
percentage factor is applied. Factors that may affect the identification of an appropriate benchmark P
include the following: T
E
x The elements of the financial statements R
x Items on which the attention of the users tends to be focused
x The nature of the entity, where it is in its life cycle and the industry and economic environment in 5
which it operates
x The entity's ownership structure and the way it is financed
x The relative volatility of the benchmark
The statutory audit: planning and risk assessment 229
The following benchmarks are typically used:
Benchmark Threshold
Profit before tax Approx. 5%
Adjusted profit before tax Approx. 5%
Total revenue Approx. 1%
Total assets Approx. 1–2%
Equity Approx. 1–2%
(The benchmarks suggested above are based on information from the FRC publication %XTENDED !UDITORgS
2EPORTS ! REVIEW OF %XPERIENCE IN THE &IRST 9EAR, 2015.)
The following points should be noted:
x There is some variation used in the methods to determine materiality within and between audit
firms.
x Multiple measures are sometimes used to determine materiality.
x Adjusted profit before tax and profit before tax are the most commonly used measures.
Determining the level of materiality is a matter of professional judgement, rather than applying
benchmarks mechanically. In applying such judgements, the auditor should consider any relevant
qualitative factors, including:
x whether it is a first-year engagement;
x deficiencies in controls;
x material misstatements in prior years;
x risk of fraud;
x significant management turnover;
x unusually high market pressures;
x sensitivity of covenants in loan agreements to changes in the financial statements; and
x effect of changes in results on earnings trends.
The auditor's assessment of materiality is then communicated in the auditor's report (ISA 700.38(c)). By
far the most common level of materiality for listed company auditors is 5% of adjusted profit before tax.
It is also necessary to determine a materiality threshold for reporting any unadjusted differences to the
audit committee. This will be much lower than overall materiality, and may be communicated in the
auditor's report.
In the case of a group audit, the group auditor will also set materiality for the group as a whole, as well
as component materiality for any component auditors. Component materiality is always less than group
materiality.
8.2.2 Performance materiality
The preliminary assessment of materiality, as referred to above, is in the context of the financial
statements as a whole. However, if the audit procedures are planned solely to detect individually
material misstatements this would:
x overlook the fact that the aggregate of individually immaterial misstatements could cause the
financial statements to be materially misstated; and
x leave no margin for possible undetected misstatements.
Further materiality levels must therefore be set before audit procedures are designed and performed.
The requirement to do so was introduced into ISA 320 as part of the IAASB's Clarity Project, and these
lower materiality levels are referred to as performance materiality. Seen as a 'working level of
materiality', performance materiality is a concept that most experienced auditors would have applied
throughout their careers.
230 Corporate Reporting
The auditor must set an amount or amounts at less than the materiality for the financial statements as a
whole and this is known as performance materiality. This could be set in two ways:
x as a judgemental estimate to reduce the probability that the aggregate of uncorrected and
undetected misstatements exceeds the materiality for the financial statement as a whole; or
x specific materiality levels may be set for particular classes of transactions, account balances or
disclosures that could have a particular influence on users' decisions in the particular circumstances
of the entity.
Different levels of materiality may therefore be used in the various audit procedures carried out.
The following example illustrates, in a simplistic way, the role of performance materiality in an audit.
Worked example: Performance materiality
The auditor of Company A has set materiality for the financial statements as a whole at £100,000.
During the audit, the following misstatements were identified:
(1) Misclassification of abortive research and development expenses as an intangible asset of £41,000.
This is the only intangible asset on the statement of financial position.
(2) Overstatement of non-current assets by £50,000 due to cut-off errors.
(3) Overstatement of receivables by £29,000 representing the unpaid balance from a customer which
has been liquidated during the period.
Considering each of the misstatements on an individual basis, the auditor may overlook the
misstatements above. This would give rise to an aggregate of uncorrected misstatements of £120,000 –
exceeding materiality for the financial statements as a whole.
In addition, the uncorrected misstatement (1) could have misled the users of the financial statements,
whose attention would have been drawn to the company's new, and only, intangible assets.
The auditor would avoid the risk of giving an inappropriate audit opinion by applying performance
materiality:
(1) Set a general performance materiality at £50,000 to reduce the probability that the
aggregate of uncorrected misstatements would exceed materiality for the financial
statements as a whole: This would identify misstatement (2) as requiring adjustment.
(2) Set performance materiality specific to intangible assets at £40,000 to reflect the specific risks
associated with this account: This would identify misstatement (1) as requiring adjustment.
(3) Now, provided management agrees to correct misstatements (1) and (2), the only adjustment
which remains uncorrected is misstatement (3). At £29,000, this is now less than 30% of
materiality for the financial statements as a whole.
Performance materiality should be used in both the planning and fieldwork stages of the audit. In the
November 2011 issue of the )#!%7 !UDIT !SSURANCE &ACULTY NEWSLETTER, the article 'Living in a material
world' by David Gallagher usefully sets out four circumstances in which performance materiality can be
applied:
C
At the planning stage: H
A
(a) To determine when no work is necessary, and where evidence is required, the extent of that P
evidence. T
E
(b) To help identify which items to test (for example, if a substantive test of detail approach is R
adopted, the auditor may consider selecting all items above performance materiality first, and then
consider whether any, and if so how many, further items should be sampled).
5
At the fieldwork stage:
(c) To help evaluate the results of sample tests (for example, if on a particular test the extrapolated
difference of potential misstatements is less than materiality, the auditor may conclude that
sufficient audit evidence had been obtained in this area).
The statutory audit: planning and risk assessment 231
(d) To help evaluate the results of analytical procedures (for example, if the results of a reasonableness
test produced a difference between the predicted and actual amounts which is less than
performance materiality, the auditor may conclude that sufficient audit evidence had been
obtained in this area).
Students who work in an audit practice may have come across tolerable misstatement (previously called
'tolerable error') in carrying out audit engagements. Essentially, tolerable misstatement is an example of
how the concept of performance materiality is applied to sampling (points (b) and (c) above).
What constitutes sufficient audit evidence, and the different audit procedures, are covered in further
detail in Chapter 6. However, you should already be familiar with these topics from your earlier studies.
8.2.3 Estimation of likely misstatements
Towards the end of the audit, the auditor will aggregate the misstatements from each account balance,
class of transaction or disclosure (including both known and likely misstatements) and compare this with
the preliminary assessment of materiality. Where additional information has come to light the
preliminary assessment of materiality may need to be revised. If this is the case, the circumstances
should be adequately documented. Comparison of the aggregated misstatements and materiality will
determine whether the financial statements require adjustment.
Like materiality for the financial statements as a whole, performance materiality is linked to audit risk.
Where the audit risk has been revised during an audit, and the materiality level for the financial
statements as a whole has been reduced, the auditor must consider whether performance materiality
also needs to be revised. This may affect the nature, timing and extent of further audit procedures.
8.2.4 Auditor's report
Auditors of companies applying the UK Corporate Governance Code must disclose the materiality level
used in the audit for the financial statements as a whole. This area is covered in more detail in Chapter 8
of this Study Manual, but for now it may be helpful to see a real-life example of such a disclosure. For
instance, PwC's auditor's report for Barclays plc (in relation to the 2016 Annual Report) included the
following statement.
'Overall group materiality [was set at]: £320 million [which represents] 5% of Barclays Core profit before
tax excluding notable items. The use [of this measure of profit] is appropriate as it reflects the
underlying business management is focusing upon and will be what is left once disposals from Non-core
have occurred.'
(Source:
[Link]
/Barclays%20PLC%20Annual%20Report%[Link])
Deloitte's auditor's report for Tesco plc (in relation to the 2016 Annual Report) includes the following
description of the basis on which materiality was derived, making reference to the effect on the
materiality level of the change of auditors.
'We determined materiality for the Group to be £50 million (2014/15: materiality determined by the
previous auditor of £50 million). Professional judgement was applied in determining an appropriate
level of materiality and we considered a number of profit based and other measures with reference to
the Group's performance. We concluded that it was appropriate to determine materiality with reference
to the Group's average profitability over a three year period (2013/14, 2014/15, and 2015/16), adjusted
for exceptional items.
In our professional judgement, we believe that the use of an adjusted profit measure is appropriate as
the amounts which have been excluded from the Group's profit before tax are one-off items which
would otherwise skew the level of materiality determined and are not reflective of the Group's trading
activity. However, we capped the materiality determined to that applied by the previous auditor in the
light of the Group's lower level of profit in the current year and as a result of 2015/2016 being our first
year of appointment.'
(Source: [Link]
Ernst and Young's auditor's report for J Sainsbury plc (in relation to the 2016 Annual Report) provides
information about both overall materiality and performance materiality as follows:
'We determined materiality for the Group to be £31.9 million, which is 5% of profit before tax excluding
one-off items of £90 million as described in note 3. We believe that this materiality basis provides us
with the best assessment of the requirements of the users of the financial statements. This is consistent
with the approach taken by auditors in the prior period.
232 Corporate Reporting
On the basis of our risk assessments, together with our assessment of the Group's overall control
environment and this being our first period of engagement, our judgement was that performance
materiality was approximately 50% of our planning materiality, namely £16 million.'
(Source: [Link]/HostedData/AnnualReports/PDF/LSE_GB0767628_2016.pdf)
8.3 Problems with materiality
As discussed above, materiality is a matter of judgement for the auditor. Therefore, prescriptive rules will
not always be helpful when assessing materiality. A significant risk of prescriptive rules is that a
significant matter, which falls outside the boundaries of the rules, could be overlooked, leading to a
material misstatement in the financial statements.
The percentage guidelines of assets and profits that are commonly used for materiality (eg, those
referred to in section 8.2.1) must be handled with care. The auditor must bear in mind the focus of the
company being audited.
In some companies, post-tax profit is the key figure in the financial statements, as the level of dividend
is the most important factor in the accounts.
In owner-managed businesses, if owners are paid a salary and are indifferent to dividends, the key
profit figure stands higher in the statement of profit or loss and other comprehensive income, say at
gross profit level. Alternatively in this situation, the auditor should consider a figure that does not
appear on the statement of profit or loss and other comprehensive income: profit before directors'
salaries and benefits.
Some companies are driven by assets rather than the need for profits. In such examples, higher
materiality might need to be applied to assets. In some companies, say charities, costs are the driving
factor, and materiality might be considered in relation to these.
While rules or guidelines are helpful to auditors when assessing materiality, they must always keep in
mind the nature of the business they are dealing with. Materiality must be tailored to the business
and the anticipated user of financial statements, or it is not truly materiality. The extracts from
auditors' reports included in section 8.2.4 above demonstrate how these principles are applied in
practice.
Interactive question 6: Materiality (1)
You are the manager responsible for the audit of Albreda Ltd. The draft consolidated financial
statements for the year ended 30 September 20X6 show revenue of £42.2 million (20X5 £41.8 million),
profit before taxation of £1.8 million (20X5 £2.2 million) and total assets of £30.7 million (20X5
£23.4 million). In September 20X6, the management board announced plans to cease offering 'home
delivery' services from the end of the month. These sales amounted to £0.6 million for the year to 30
September 20X6 (20X5 £0.8 million). A provision of £0.2 million has been made at 30 September 20X6 for the
compensation of redundant employees (mainly delivery van drivers).
Requirement
Comment upon the materiality of these two issues.
See Answer at the end of this chapter.
C
H
A
Interactive question 7: Materiality (2) P
T
You are the auditor of Oscar Ltd and are in the process of planning the audit for the year ended E
31 December 20X8. In the past the audit of this company has been straightforward. The following R
information is available:
20X8 20X7
£'000 £'000 5
Total assets 1,800 1,750
Total revenue 2,010 1,900
Profit before tax 10 300
The statutory audit: planning and risk assessment 233
Materiality has been calculated by a colleague as follows:
Profit before tax = £10,000 u 5% = £500
Requirement
Comment on the suitability of the planning materiality figure.
See Answer at the end of this chapter.
9 Responding to assessed risks
Section overview
Further audit procedures should be designed in response to the risks identified.
As a result of the auditor's risk assessment and assessment of materiality an audit strategy will be
developed in response. ISA (UK) 330 (Revised June 2016) 4HE !UDITORgS 2ESPONSES TO !SSESSED 2ISKS makes
the following points in this context which you should be familiar with.
9.1 Overall responses
The auditor should design and implement overall responses to address the risks of material
misstatement at the financial statement level. This may include the following:
x Emphasising to the audit team the need to maintain professional scepticism in gathering and
evaluating audit evidence
x Assigning more experienced staff, those with special skills or using experts
x Providing more supervision
x Incorporating additional elements of unpredictability in the selection of further audit
procedures
The auditor may also make general changes to the nature, timing or extent of audit procedures, for
example by performing substantive procedures at the period end instead of at an interim date. These
decisions will take into account the auditor's assessment and understanding of the control
environment.
9.2 Audit procedures responsive to risks of material misstatement at the
assertion level
The auditor is required to design and perform procedures which will address the risks identified. The ISA
emphasises the link between further audit procedures and the risk assessment process. Factors
which the auditor will consider include the following:
x The reasons for the risk assessment at the assertion level for each class of transaction, account
balance or disclosure
x The likelihood of material misstatement due to the particular characteristics of the class of
transaction, account balance or disclosure involved
x Whether the risk assessment takes account of relevant controls and so requires the auditor to
obtain evidence to determine whether the controls are operating effectively
The auditor shall obtain more persuasive audit evidence the higher the assessment of risk.
The auditor will then determine the nature, timing and extent of further audit procedures. We will
look at this aspect of the audit in detail in Chapter 6.
234 Corporate Reporting
9.3 Evaluating the sufficiency and appropriateness of audit evidence obtained
Based on the audit procedures performed and the evidence obtained, the auditor should conclude
whether sufficient, appropriate audit evidence has been obtained to reduce the risk of material
misstatement to an acceptably low level. While this will be considered by the auditor throughout
the audit, it is of particular relevance at the review stage of the audit. We will consider this in more
detail in Chapter 6.
9.4 Documentation
The ISA emphasises the need to document the link between the audit procedures and the assessed risks.
These matters should be recorded in accordance with ISA (UK) 230 (Revised June 2016) !UDIT
$OCUMENTATION You should be familiar with the principles of this ISA from your earlier studies.
10 Other audit methodologies
Section overview
Other audit methodologies include:
x systems audit;
x transaction cycle approach; and
x balance sheet audit approach.
10.1 Introduction
In this chapter we have looked in detail at the business risk model and the audit risk model. However
there are a number of other audit approaches which may be adopted.
10.2 Systems audit
An auditor may predominantly test controls and systems, but substantive testing can never be
eliminated entirely. It is always used in conjunction with another approach.
You should be familiar with the systems and controls approach to auditing from your previous studies.
Management are required to implement a system of controls which is capable of fulfilling its duty of
safeguarding the assets of the shareholders.
Auditors assess the system of controls put in place by the directors and ascertain whether they believe it
is effective enough for them to be able to rely on it for the purposes of their audit.
If they believe that the system is effective, they carry out tests of controls to ensure that the control
system operates as it is supposed to. If they believe that the control system is ineffective, they assess
control risk as high and undertake higher levels of substantive testing.
The key control objectives and procedures over the main cycles of sales, purchases and wages were
studied at length in your previous studies. If you do not feel confident in what they are, you should go
C
back to your learning materials in these areas and revise them now.
H
An auditor may choose predominantly to carry out substantive tests on the transactions and balances of A
P
the business in the relevant period, but if internal control systems are particularly weak then no amount T
of substantive testing may give adequate assurance (eg, if point of sales controls over cash receipts are E
inadequate, then substantive testing may never detect material understatement of revenues). R
Two approaches to substantive testing are:
x the transaction cycle approach; and 5
x the balance sheet approach.
The statutory audit: planning and risk assessment 235
10.3 Transaction cycle approach
Cycle testing is in some ways closely linked to systems testing, because it is based on the same systems.
When auditors take a cycle approach, they test the transactions which have occurred, resulting in the
entries in the statement of profit or loss and other comprehensive income (for example, sales
transactions, inventory purchases, asset purchases, wages payments, other expenses).
They would select a sample of transactions and test that each transaction was valid and complete and
processed correctly throughout the cycle. In other words, they substantiate the transactions which
appear in the financial statements.
The key business cycles are outlined below. Remember that you know what the processes should be in
the cycle (you have assessed the system and controls previously). Under this approach, you are ensuring
that individual transactions were processed correctly. Hence, the cycles outlined below should
correspond to the controls processes you are already aware of.
You should be aware of
controls over ordering
Take
orders
Document
orders
Receive
payment Chase
payment
Despatch Send Make
invoice statement order
Account for Raise
invoice invoice
You should be aware of the
Despatch
controls over recording and
accounting
order
Raise goods
despatched note
&IGURE 3ALES CYCLE
236 Corporate Reporting
You should be aware of
Raise controls over ordering
requisition
Supplier will Purchasing
extend credit in department
the future raise order
Send payment
Receive goods
Carry on
production
Raise goods
Record and received note
account for invoice
Accounts
department match
You should be aware of controls GRN to invoice
over accounting and recording
&IGURE 0URCHASES CYCLE
The auditor should be able to find an audit trail for each transaction, for example in the purchases cycle:
x Requisition
x Invoice
x Order
x Ledger and daybook entries
x GRN
x Payment in cash book/cheque stub
10.4 Balance sheet approach
An alternative to the cycles (or transactions) approach to auditing is to take the balance sheet approach.
This is the most common approach to the substantive part of the audit, after controls have been tested.
The statement of financial position (balance sheet) shows a snapshot of the financial position of the
business at a point in time. It follows that if it is fairly stated and the previous snapshot was fairly stated
then it is reasonable to undertake lower level testing on the transactions which connect the two
snapshots; for example, analytical procedures.
Under this approach, therefore, the auditors seek to concentrate efforts on substantiating the closing
position in the year, shown in the statement of financial position, having determined that the closing
position from the previous year (also substantiated) has been correctly transferred to be the opening C
position in the current year. H
A
You should be aware of the financial statement assertions and the substantive tests in relation to the P
major items on the statement of financial position from your previous studies. We will also review these T
E
in more detail in Chapter 6.
R
10.4.1 Relationship with business risk approach
The substantive element of an audit undertaken under a business risk approach is restricted due to the 5
high use of analytical procedures. However, the element of substantive testing which remains in a
business risk approach can be undertaken under the balance sheet approach.
The statutory audit: planning and risk assessment 237
In some cases, particularly small companies, the business risks may be strongly connected to the fact
that management is concentrated in one person. Another feature of small companies may be that their
statement of financial position is uncomplicated and contains one or two material items, for example
receivables or inventory.
When this is the case, it is often more cost effective to undertake a highly substantive balance sheet
audit than to undertake a business risk assessment, as it is relatively simple to obtain the assurance
required about the financial statements from taking that approach.
10.4.2 Limitations of the balance sheet approach
When not undertaken in conjunction with a risk-based approach or systems testing, the level of
detailed testing can be high in a balance sheet approach, rendering it costly.
11 Information technology and risk assessment
Section overview
x A huge number of organisations now use computer systems to run their businesses and to process
financial information.
x The main risks associated with using computerised systems include infection by viruses and access
by unauthorised users. Both these risks could potentially have a very damaging effect on the
business.
x This means that a number of the controls which the directors are required to put into place to
safeguard the assets of the shareholders must be incorporated into the computer systems.
x Auditors have to assess the effectiveness of the controls in place within computer systems and can
do this by performing a systems audit as part of their initial assessment of risk during the planning
stage of the audit.
11.1 The use of information technology
Most organisations and businesses, even very small entities, now use information technology (IT) to
some degree. The first use of a computerised accounting system is thought to have been back in 1954
by General Electric, and rapid advances in computer technology since then are allowing companies to
conduct business globally, making them indispensable and essential to an entity's operations.
However, the increasing use of computer systems brings with it certain risks to the business which can
also have an impact on the risk of the financial statements being misstated. These risks have
increased with the development of the internet in the last few years and with it the facility for
transactions to be conducted electronically.
11.2 Risks associated with the use of computerised systems
Cyber-security is becoming an increasingly important issue for businesses to address. The two key
business risks of organisations using computerised systems are as follows:
x The system being put at risk by a virus or some other fault or breakdown which spreads across the
system
x The system being invaded by an unauthorised user, who could then:
– affect the smooth operation of the system; or
– obtain commercially sensitive information.
238 Corporate Reporting
Worked example: British Airways
In May 2017, IT failures at British Airways resulted in hundreds of flights at Heathrow and Gatwick airports
being cancelled and thousands of passengers disrupted. There have been suggestions that the failure could
have been avoided if the company had not outsourced its IT work. In 2016 the company made hundreds
of its IT staff redundant and outsourced its IT services to India. The failure in May led to planes not being
able to take off, baggage not being allowed to move and boarding passes not being able to be issued to
passengers.
A few days after the failure, the Chief Executive of British Airways' parent company stated that the
disruption had been caused by an engineer disconnecting a power supply, leading to a power surge when
it was reconnected.
Worked example: NHS
Also in May 2017, the NHS was affected by a global cyber attack which resulted in patients' operations
being cancelled, ambulances being diverted and some patient records being unavailable in England and
Scotland. The attack affected not just the UK but almost 100 other countries and originated from malware
that was using technology stolen from the National Security Agency in the USA. The malware blocks
access to PC files until a ransom is paid, in this case $300. There was no confirmation from the UK
government that NHS patient data had been backed up. The attacks used software called
WanaCryptor 2.0 or WannaCry which made use of a vulernability in Windows – Microsft had issued an
update to fix this in March 2017 but not all computers had installed this.
Risks and relevant controls related to cyber-security are dealt with in more detail in Chapter 7.
11.3 Systems audit
As part of any audit, auditors are required to assess the quality and effectiveness of the accounting
system. Increasingly, this necessarily includes a consideration of the computer systems in place within
the organisation.
The following are the key areas they are likely to concentrate on to establish how reliable the systems are:
x Management policy
x Segregation of duties
x Security
You should be aware that these are important control considerations in a computer environment.
The details that the auditor will consider within each area are outlined below.
Management policy
x Does management have a written statement of policy with regard to computer systems?
x Is it compatible with management policy in other areas?
x Is it adhered to?
x Is it sufficient and effective?
x Is it updated when the systems are updated?
x Does it relate to the current system?
Segregation of duties C
H
x Is there adequate segregation of duties with regard to data input? A
x Are there adequate system controls (eg, passwords) to enforce segregation of duties? P
T
Security E
R
x Is there a security policy in place?:
– Physical security (locked doors/windows)
– Access security (passwords) 5
– Data security (virus shields)
x Is it adhered to?
x Is it sufficient and effective?
The statutory audit: planning and risk assessment 239
11.4 Internal controls in a computerised environment
ISA 315 specifically requires the auditor to gain an understanding of the entity's accounting systems and
control environment as part of the risk assessment process at the planning stage of the audit. Today,
almost any accounting system and control an auditor will encounter will involve some form of IT.
The management policies, segregation of duties and security issues established by the organisation are
examples of the internal control activities in a computerised environment. There are two categories of
internal controls: general controls and application controls.
General IT controls are the policies and procedures that relate to many IT applications at the same
time. They support application controls by maintaining the overall integrity of information and security
of data. Examples include procedure manuals, password protection and back-up facilities.
Application controls are manual or automated procedures that typically operate at a business process
level and apply to the processing of transactions by individual applications. They are designed to ensure
the integrity of the accounting records: that transactions occurred, are authorised, and are completely
and accurately recorded and processed. Examples include edit checks of input data and numerical
sequence checks with manual follow up of exception reports.
You should already be familiar with these two types of controls from your earlier studies. We will look at
them in further detail in Chapter 7.
Worked example: EY GAM
The Big Four accountancy firm EY has developed its own Global Audit Methodology ('EY GAM') which is
applied by its audit teams worldwide. EY GAM sets out a risk-based approach to audit, accessed via the
firm's internal email server, that includes the following:
x Requirements: the firm's typical audit process
x Supplementary guidance: requirements and guidance on specific situations that may arise in the
course of an audit
x Supporting forms, templates and examples: checklists and working paper templates to document
audit procedures, as well as best practice illustrations
The illustration below shows a simplified version of the EY GAM Roadmap. As you can see, EY GAM
covers the entire audit process, from preliminary client engagement procedures through to archiving
the audit work papers. The requirements, guidance and templates relating to each part of the process
are classified into specific steps: clicking on the tab relating to 'determine PM, TE, and SAD nominal
amount', for example, will open a database of information relating to the determination of materiality
levels.
Planning and risk Strategy and risk Conclusion and
identification assessment Execution reporting
Identify SCOTs, significant
Complete preliminary disclosure processes and related IT
Understand service requirements, determine audit scope, and establish the team
engagement activities applications Execute tests of controls Prepare summary of audit
Understand differences
Team planning event and discussion of fraud and error
SCOTs and Sig
disclosure Understand and
Understand the business processes evaluate the
FSCP Execute tests of journal entries
Perform financial statement
Reassess combined risk assessments
Perform and perform other mandatory
fraud procedures procedures
walkthroughs
Wrap-up the engagement
Determine the need for Understand
specialized skill on the team ITGCs
Post-interim event
Select controls Design and Prepare summary review
to test execute tests of memorandum
Understand entity-level ITGCs Update tests Update tests
controls of controls of ITGCs
Evaluate ITGCs
Perform overall review and
Identify risks of material Make combined risk assessments approval
misstatement due to fraud
and determine responses Design tests of controls
Design tests of journal entries and Prepare and deliver client
Determine PM, TE, and SAD other mandatory fraud procedures Perform substantive procedures communications
nominal amount
Design Plan general
substantive audit
Identify significant accounts procedures procedures Complete documentation and
Perform general audit
and disclosures and relevant procedures archive engagement
assertions
Prepare audit strategies memorandum
(Source: [Link]
/Professional_Resources/Conference_Materials/2012/[Link])
240 Corporate Reporting
EY GAM is supplemented by GAMx, the audit support platform designed to ensure consistent
application of the firm's audit methodology. GAMx provides a secure online team-collaboration
environment where the audit team members create, record, review and share the results of audit
procedures and conclusions. A chat function allows audit team members to communicate with each
other in real time without having to log on to the firm's intranet – a useful thing at certain client sites!
Besides GAMx, a variety of in-house analytics and audit sampling tools provide a range of computer-
assisted audit techniques that audit teams can use.
EY's Transparency Report 2013, setting out its audit methodology and quality assurance systems, can be
found via this link:
[Link]/Publication/vwLUAssetsPI/UK_Transparency_Report_2013/$FILE/EY_UK_Transparency_Rep
ort_2013.pdf
The report (page 19) points out that 'EY GAM [...] emphasises applying appropriate professional
scepticism in the execution of audit procedures.' Accordingly, the walkthrough template embedded in
EY GAM contains specific sections requiring the audit team to consider whether any observations noted
during the walkthrough of controls indicate the potential for management override of controls. Audit
teams are required to complete a checklist, confirming that they have applied professional scepticism
while carrying out audit procedures.
12 Big data
Section overview
Big data is a broad term for data sets which are large or complex.
12.1 Big data
Advances in technology have helped to make data an increasingly important resource in business.
Making use of the insights that can be gained from data analysis has made data management a
strategic issue for many organisations. The increased emphasis on the importance of data has given rise
to the now widely used terms of big data and data analytics (Data analytics is discussed in more detail in
section 13). As businesses have changed the way that they use data, auditors have had to respond to
the opportunities and challenges that this development has created.
Definition
Big data: Is a term that describes those 'datasets whose size is beyond the ability of typical database
software to capture, store, manage and analyse.' McKinsey Global Institute, "IG DATA 4HE NEXT FRONTIER
FOR INNOVATION COMPETITION AND PRODUCTIVITY, 2011
Today, organisations have access to greater quantities of data than in the past, with vast amounts of
transactional data available from a number of internal and external sources, such as suppliers and C
customers. H
A
The growth in the amount of data now available has been largely fuelled by increasing internet usage P
and by developments in communication methods such as wireless networks, social media sites and T
smartphones. An increasing number of organisations have embraced the so-called 'internet of things' by E
R
embedding sensor technologies, such as RFID tags (Radio Frequency Identification) and tracking
devices, into their operations to gather data from a diverse range of activities. Companies including
British Gas, an energy supplier in the UK, have introduced so-called smart meters as a way of measuring
5
the amount of electricity consumers are using on a daily basis. Such meters also allow home owners to
better manage their household energy costs as the meter records and wirelessly transmits the level of
energy consumption back to the energy provider.
Leading data analytics software firm, SAS, offers the following explanation of big data.
The statutory audit: planning and risk assessment 241
Big data is a term that describes the large volume of data --- both structured and unstructured --- that
inundates a business on a day-to-day basis. But it's not the amount of data that's important. It's what
organisations do with the data that matters. Big data can be analysed for insights that lead to better
decisions and strategic business moves.'
(Source: SAS, "IG DATA 7HAT IT IS AND WHY IT MATTERS. [Online] Available at: [Link])
12.2 Features of big data
As explained in the ICAEW IT Faculty document "IG DATA AND ANALYTICS n WHATgS NEW big data is often
characterised by the 3 Vs:
x Large volumes of data
x High-velocity data
x Wide variety of data
Doug Laney, an analyst with technology research firm Gartner, also suggests that big data can be
defined with reference to the three Vs of volume, velocity and variety.
Volume
The vast quantities of data generated are a key feature of big data. Advances in technology and data
analytics software have enabled very large data sets to be processed. This is helping organisations to
gain a deeper understanding of customer requirements. For example, organisations can collect large
amounts of external data about their customers from customers' use of the internet and social media.
This data can now be combined with internally generated data for example, from customer loyalty cards
or transactions recorded at shop tills, to build up a more detailed profile of the customer. The volume
aspect of big data has challenged the strategic capabilities of many organisations wishing to exploit its
potential. Most notably, these have involved enhancing existing IT infrastructures through the use of
cloud computing architectures so that they are capable of holding greater amounts of data.
Velocity
Velocity refers to the speed at which 'real time' data flows into the organisation and the speed at which
the data is processed by the organisation's systems to produce a meaningful output. Many online
retailers have developed capabilities which enable them to record the movements and 'clicks' made by a
customer when using the organisation's website. As such, online retailers are now able to build up a
better picture of those products and services the customer found most interesting as opposed to only
recording the final sale transaction with the customer. Analysing the customers' clicks while still visiting
the website has enabled online retailers to recommend relevant additional items for purchase based on
those items already viewed. Online websites including Amazon and eBay use this tactic to encourage
customers to make extra purchases.
Variety
Variety is concerned with the diverse range of forms that big data can take. An increasing amount of
data generated comes in an unstructured form, ie, data which is not easy to hold in a database.
Unstructured data may take the form of words used by people on social media sites such as Facebook
and Twitter, along with shared content such as photographs or video recordings. Capturing, processing
and storing unstructured data presents further challenges to organisations which may need to develop
their existing IT/IS capabilities to be able to firstly store such data and secondly extract meaning from
the data they hold. Data which is too large, moves too fast or fails to fit neatly with existing IT
infrastructures reduces the value which can be derived from it.
The three Vs of big data can also be extended to include an additional characteristic: veracity.
Veracity
Veracity (value) is concerned with the truthfulness of the data collected. For data to have any value
when being used for decision-making in an organisation, it needs to be truthful, ie, it must not present a
bias or contain inconsistencies. The use of poor quality data may have expensive and far reaching
consequences for those organisations which rely on it for making strategically important decisions. For
example, an organisation may decide to introduce a type of product in the belief that there is sufficient
customer demand for it when in reality this may not be the case.
242 Corporate Reporting
The trend in big data is being propelled by three factors: a growth in computer power, new sources of
data and infrastructure for knowledge creation. The combination of these three factors is enabling
businesses to use data in ways which were not previously possible or viable. In particular they are using
big data to:
x Gain insights eg, using more granular data about customers
x Predict the future eg, customer service functions personalise services based on predictions about
individual customers
x Automate non-routine decisions and tasks eg, using machine learning techniques to automate a
medical diagnosis
Like business, auditors have had to respond to the changing environment brought about by big data.
Historically auditors have reviewed structured data (eg, transactions recorded in the general ledger)
however the analysis of unstructured data can provide new insights (eg, data extracted from emails,
texts and social media). Audit firms have invested heavily in recent years in data analytics tools which
will enable them to use this data to better understand their clients, identify risks and add value.
13 Data analytics
Section overview
Some firms are currently investing in data analytics to provide a better quality audit and to reduce risk
and liability for the auditor.
13.1 Data analytics
Large firms in particular have been developing a data analytics offering with many clients now
expecting their auditors to adopt this approach. However with the growing range of generic data
analytics tools becoming available it is also becoming more relevant to small and medium sized firms
too.
There are many definitions of data analytics.
Definitions
Data analytics: The process of collecting, organising and analysing large sets of data to discover
patterns and other information which an organisation can use for its future business decisions.
Closely linked to the term data analytics is data mining.
Data mining: The process of sorting through data to identify patterns and relationships between
different items. Data mining software, using statistical algorithms to discover correlations and patterns,
is frequently used on large databases. In essence, it is the process of turning raw data into useful
information.
The ICAEW Audit and Assurance faculty document $ATA ANALYTICS FOR EXTERNAL AUDITORS describes data
analytics as follows:
C
'Data analytics involves the extraction of data using fields within the basic data structure, rather than the H
format of records. A simple example is Power view, an Excel tool which can filter, sort, slice and A
P
highlight data in a spreadsheet and then present it visually in variety of bubble, bar and pie charts'.
T
In simpler terms data analytics is about examining raw data with the purpose of drawing conclusions E
about it. The Audit and Assurance faculty document identifies the following as commonly performed R
data analytics routines:
x Comparing the last time an item was bought with the last time it was sold, for cost/NRV purposes 5
x Inventory ageing and how many days inventory is in stock by item
x Receivables and payables ageing and the reduction in overdue debt over time by customer
x Analysis or revenue trends split by product or region
The statutory audit: planning and risk assessment 243
x Analyses of gross margins and sales, highlighting items with negative margins
x Matches of orders to cash and purchases to payments
x 'Can do did do testing' of user codes to test whether segregation of duties is appropriate, and
whether any inappropriate combinations of users have been involved in processing transactions
x Detailed recalculations of depreciation of fixed assets by item, either using approximations (such as
assuming sales and purchases are mid-month) or using the entire data set and exact dates
x Analyses of capital expenditure v repairs and maintenance
x Three-way matches between purchases/sales orders, goods received/despatched documentation
and invoices
Data analytics can also draw on external market data as well as internal data, for example third-party
pricing sources and foreign exchange rates can be accessed to recalculate the valuation of investments.
('Coming your way' by Katherine Bagshaw and Phedra Diomidous, !UDIT AND "EYOND, 2016).
Data analytics can analyse unstructured data as well as structured data. For example an analysis of
emails could be a more effective means of identifying fraud than an analysis of journals. Data analytics
tools allow the auditor to analyse this type of information in a level of detail which would not be
possible manually.
13.2 Improved audit quality
One of the key drivers behind the use of data analytics is improved audit quality. The Audit and
Assurance faculty document identifies the following as the unique features of data analytics which
contribute to improved risk assessment:
x The ability to graphically visualise results: this makes it easier to drill down to the underlying data
and obtain a better understanding of findings
x Sophistication, and the breadth of interrogation options: this includes wide-ranging query and filter
options
x Ease of use by non-specialists: the identification of anomalies, outliers and trends could highlight
issues that would otherwise have gone unnoticed
x Scale and speed: resulting in time efficiencies
By using data analytics tools the auditor can navigate much bigger data sets much faster than before so
that while the analyses performed are not fundamentally different to those performed in the past they
are now at a more granular level. The quality of the analyses is enhanced and therefore the judgments
made on the basis of this information are enhanced too.
For example, the following is taken from PwC's 'Halo for Journals'
(Source: ICAEW Audit and Assurance Faculty: $ATA ANALYTICS FOR EXTERNAL AUDITORS
(Illustration from PwC Halo))
244 Corporate Reporting
This might suggest that someone from outside the department is posting journals. Data analytics can be
used to 'drill down' into the data in order to identify which journals need to be tested. In this way
substantive procedures are better directed.
Example 1: Extract and examine all journal entries credit entries to the Revenue Account where the
corresponding debit is not either receivables or cash (which would be the normal expected entries).
These extracted exceptions can then be investigated.
Example 2: Extract and examine all journal entries which are: Dr PPE account; Cr an expense account.
This would be an unusual entry in the normal course of business and there is a risk of creative
accounting by capitalising expenditure that should be expensed. These can be investigated including
requiring management explanations.
The Audit and Beyond article also highlights the role of data analytics in supporting the application and
demonstration of professional scepticism. For example, predictive data analytics tools might be used to
help assess the reasonableness of management representations.
A recent article by KPMG 'Data, Analytics and Your Audit' discusses the impact of big data and how it
affects auditors. The article emphasises that the use of data by auditors is not a new thing by any means
since auditors have always had to analyse data. Data analytics allows auditors to analyse data at much
greater speeds than before. For example, data analytics will allow auditors to sample much higher
volumes of transactions up to 100% in some cases, which will allow auditors to identify high risk
transactions over a vast array of data and in minutes rather than over weeks. The article cites the
example of a clothing retailer and shows how data analytics can allow auditors to evaluate the three-
way match between purchase orders, delivery confirmations and invoice documentation in a graphical
way that can show account relationships and transaction flows and control issues over segregation of
duties. Data analytics can also be used to examine supplier relationships (supplier contracts, payment
terms, controls over procurement processes etc).
The article includes a very useful table on the use of data analytics which is shown below.
Area Use of data analytics
Revenue and accounts receivable Identify discrepancies in price and quantity
between invoices, sales orders and shipping
documentation
Identifies stockouts and customer orders coming
in faster than shipped products
Segregation of duties Identifies areas of increased risk
Highlights internal control deficiencies through
inefficient segregation of duties
Purchases and accounts payable Identifies significant or unusual items such as
invoice price discrepancies against original
purchased products
Shows purchase trends and activities with
suppliers that are unauthorised or where there
are concentrations of spending activities
Supply chain Identifies risks resulting from the concentration of C
H
suppliers in a particular region
A
Can highlight possible issues if suppliers are P
T
affected by regional disruptions
E
R
The statutory audit: planning and risk assessment 245
13.3 Technical challenges
While data analytics can be seen as the solution to many problems it is also the cause of new ones.
13.3.1 Data capture, extraction, validation and transformation
In order to apply data analytics effectively the auditor needs to be able to extract data from the client's
system in a usable format. In order to do so they need to be able to interface with clients' systems. This
can involve a considerable amount of investment in mapping different systems, particularly where they
are bespoke to the client.
The issue of 'transformation' also has to be addressed. This relates to the way in which data is made
useable. This normally involves changing the data by simplifying it. Before changes are made careful
thought is required regarding the impact this will have on the quality of the evidence.
13.3.2 Data protection
Confidentiality and security of information are critical issues. This is particularly the case where there is
the potential for the creation of new personal data when analyses refer to individuals. In these cases the
auditor must ensure that relevant data protection laws and regulations are complied with.
13.3.3 Quality
Data analytics tools must be developed to the highest quality assurance standards. As the Audit and
Assurance Faculty document indicates procedures should include pilot and parallel running with the
'normal' audit process together with contingency plans should the software crash. There also need to be
proper controls to ensure that individuals using the tools are using them properly.
13.3.4 Data retention
The audit process has always allowed the auditor access to and retention of information which is not its
own. However the scope of data analytics is such that the volume has reached a new scale. While there
are differing views about the amount of information that should be retained and how long it should be
kept there is a consensus that 'If an item has been tested, information about it should be retained such
that it could be identified again if necessary'.
13.4 Data analytics and auditing standards
Current auditing standards are risk-based. They require risk analysis, controls testing and sampling
against a 'materiality' benchmark. It could be argued that data analytics and its possibilities challenges
these concepts and therefore the audit itself. Two aspects of the audit in particular are potentially
affected as the technology is developing:
Tests of controls
ISAs require evaluation and testing of controls where the auditor is to rely on them, as a means of
obtaining comfort that transactions processed by the system are properly recorded in the financial
statements. However if auditors are able to use data analytics tools which allow them to see what has
happened to all of the transactions and these tools show that they are properly valued and recorded
why would the auditor need to test the controls applied in the system?
Sampling
Sampling has historically been adopted on the basis that it is not cost-effective (or necessary if risk
assessment has been performed) to audit 100% of all balances in the financial statements. Again data
analytics could challenge this principle. For example if it is possible to examine 100% of the invoices
automatically, both cheaply and efficiently why would the auditor choose to examine only a sample?
246 Corporate Reporting
13.5 Current developments
13.5.1 IAASB Request for input
At the time of writing, the way in which changes taking place in the market place are addressed in the
audit approach is being considered. For example, the IAASB has set up a Data Analytics Working Group
to determine how developments in IT including data analytics might be reflected in new or revised
standards. In September 2016 it issued Request for input: Exploring the growing use of technology in
the audit, with a focus on data analytics. This aimed to inform stakeholders of the ongoing work by the
IAASB in this area, but also to obtain stakeholder input, particularly with respect to whether all of the
relevant considerations have been identified.
It makes the following points.
Data analytics and the financial statement audit – benefits
x The quality of the financial statement audit can be enhanced by the use of data analytics.
x The use of data analytics enables the auditor to obtain a more effective and robust understanding
of the entity (in an increasingly complex and high volume data environment), improving the
application of professional scepticism and professional judgement.
x The auditor is able to obtain audit evidence from the analysis of larger populations.
x The auditor obtains a better insight into the entity and its environment which in turn provides the
entity with additional information to inform its own risk assessment and business operations.
Data analytics and the financial statement audit – limitations
x Auditors need to have a clear understanding of the data they are analysing and in particular the
relevance to the audit.
x Being able to test 100% of a population does not change the fact that reasonable assurance is
provided.
x The use of data analytics does not replace the need for professional judgement and professional
scepticism, particularly in relation to accounting estimates and qualitative information.
x Care must be taken not to have 'overconfidence' in technology ie, adopting the attitude that if a
computer software program produced it, it must be right.
Technology and the ISAs
x The ISAs do not prohibit, nor stimulate, the use of data analytics.
x ISAs need to be robust and relevant, however they must be based on principles which drive
appropriate auditor performance rather than being tied to current practice or trends.
x Technology solutions can increase the amount of time which auditors can spend on judgemental
aspects of analysis as the amount of time spent on manual analysis is reduced.
x There is a current challenge to fit audit evidence derived from data analytics into the current audit
evidence model set out in the ISAs.
x A lack of reference to data analytics in ISAs (with the exception of CAATs) may act as a barrier to
their adoption more widely.
x The lack of reference in ISAs to data analytics could also suggest that their use does not reduce the C
procedures required by ISAs, even where these may appear to have been made redundant as a H
result of the information gained from the use of data analytics. A
P
x Risks arise where new techniques are used for which there is no strong framework within the T
standards. E
R
Unanswered questions
The IAASB document identifies a number of unanswered questions and challenges.
5
$ATA ACQUISITION
Entity data being transferred to the auditor raises security and privacy issues together with storage
problems for large volumes of data.
The statutory audit: planning and risk assessment 247
#ONCEPTUAL CHANGES
The approach, information required and questions asked of the client may be quite different to the
traditional approach which may be challenging for the client.
,EGAL AND REGULATORY CHALLENGES
These may relate to data security and potential restrictions on data being transferred from one
jurisdiction to another.
2ESOURCE AVAILABILITY
There may not be sufficient centralised resources with the required IT expertise to support the
engagement teams.
-AINTAINING OVERSIGHT
There are challenges for oversight authorities and regulators who may have little experience of data
analytics themselves.
)NVESTMENT IN RE TRAINING
Training will be required to change the auditor's mind set to that required where data analytics has
been used.
Next steps
The IAASB states that an evolutionary, rather than revolutionary process should be adopted. ISAs need
to take account of the changing technological developments but care must be taken not to commence
standard-setting activities prematurely to avoid unintended consequences.
(Source: Request for Input: %XPLORING THE 'ROWING 5SE OF 4ECHNOLOGY IN THE !UDIT WITH A &OCUS ON $ATA
!NALYTICS, IAASB, 2016. Available from: [Link]/system/files/publications/files/IAASB-Data-
[Link] [Accessed 14 March 2017])
13.5.2 FRC Audit Quality Thematic Review
In January 2017 the FRC issued Audit Quality Thematic Review: The Use of Data Analytics in the Audit of
Financial Statements. The purpose of this review was to look at firms' policies and procedures in respect
of data analytics and to make comparisons between firms to identify areas of good practice and areas of
weakness. The review was based on the use of audit data analytics at the six largest firms in the UK:
BDO LLP, Deloitte LLP, Ernst & Young LLP, Grant Thornton UK LLP, KPMG LLP and KPMG Audit plc and
PricewaterhouseCoopers LLP.
Use of data analytics
The review document notes that the use of data analytics in the audit is not as prevalent as the market
might expect. At the time of the review the only standard tool used widely (ie, accepted norm) by all six
firms was journal entry testing. General ledger analysis/third party tools were used regularly (ie, part of
the standard auditor 'tool kit') by three firms, with two more using them in a limited capacity. Revenue
analytics tools were used widely by one firm and on a limited basis by another whilst derivatives
valuation tools were used regularly by one firm only. Process analytics tools and impairment modelling
tools were either used on a limited basis or not at all.
Audit quality
The review identified that the use of audit data analytics could improve audit quality in a number of
ways including the following:
x Deepening the auditor's understanding of the entity
x Facilitating the focus of audit testing on the areas of highest risk through stratification of large
populations
x Aiding the exercise of professional scepticism
x Improving consistency and central oversight in group audits
x Enabling the auditor to perform tests on large or complex data sets where a manual approach
would not be feasible
248 Corporate Reporting
x Improving audit efficiency
x Identifying instances of fraud
x Enhancing communications with audit committees
From its observations of specific applications the Review team observed the following examples of audit
data analytics being used to produce good quality audit evidence:
x Tracing individual revenue transactions to debtors and subsequent cash received
x Reproduction of debtors aging
x Valuation of financial instruments
x Tracing supplier income to agreements and cash received
x Recalculation of fund management fees based on value of assets under management
Data capture for use in audit data analytics
The review notes that 'effective and efficient data capture is the key to the successful use of audit data
analytics'. At an early stage the audit team needs to ascertain whether the quality of the data that can
be provided by the entity's management is sufficient to support the analytic which is to be used. In
many instances specialist staff may be used to perform data capture and this may mean that the audit
team, the data analytics specialists and the data may be in different geographical locations. This may
create issues in relation to data governance, security and privacy.
Appropriate use of audit analytics tools
The Review document states that 'Audit teams need to have a clear understanding of the purpose of the
audit data analytics technique to ensure that they obtain sufficient and appropriate audit evidence'. This
is of particular relevance at the planning stage of the audit. The Review indicates that the following
areas need to be considered when deciding whether to use an audit data analytics tool:
x Whether the tool is a 'good match' for the client's specific environment
x The need to ensure that all relevant assertions are still covered for the balance being tested
x Whether testing in other areas needs to be flexed to provide the necessary supporting evidence for
the use of audit data analytics
Evidencing of audit data analytics
The Review emphasises the point that audit documentation should enable an experienced auditor to
understand the nature, timing and extent of the audit procedures performed, including where data
analytics have been used. In particular it notes that the data analytics specialists must be considered as
part of the audit team. Auditing standards in relation to evidence and documentation therefore cover
the data analytics specialists' work as they do any other audit work.
C
H
A
P
T
E
R
The statutory audit: planning and risk assessment 249
Summary and Self-test
Summary
Audit planning
Professional Understanding
scepticism the entity
Risks: Use of Risk Materiality Performance
– System breakdown IT assessment materiality
– Unauthorised access
Internal controls:
– General IT controls Business Audit
– Application controls risk model risk model
Data analytics
Financial risk Responding to Risk of material
Operating risk assessed risk misstatement
Compliance risk Detection risk
Creative
accounting
250 Corporate Reporting