0% found this document useful (0 votes)
10 views4 pages

Audit Risk Assignment

The document outlines a systematic approach for auditors to identify and assess risks associated with government programs, including steps for evaluating objectives, threats, and existing controls. It highlights various types of risks such as processing, program, regularity, and fraud risks, and emphasizes the importance of documenting risk assessment activities. Additionally, it discusses factors affecting audit risk and provides guidelines for determining acceptable levels of audit risk based on professional judgment.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views4 pages

Audit Risk Assignment

The document outlines a systematic approach for auditors to identify and assess risks associated with government programs, including steps for evaluating objectives, threats, and existing controls. It highlights various types of risks such as processing, program, regularity, and fraud risks, and emphasizes the importance of documenting risk assessment activities. Additionally, it discusses factors affecting audit risk and provides guidelines for determining acceptable levels of audit risk based on professional judgment.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

47 The auditor needs to develop the ability to identify risks.

48 The steps to follow are: 1 List the programme objectives, assets to be safeguarded and
other results that management need to achieve; 2 Identify threats which could prevent
achievement of these objectives; 3 Rate the risks, with the probability of occurrence,
assuming no management controls (the inherent risks); 4 List controls and assurances which
exist within the systems and practices in place (environment controls and internal controls);
5 Identify missing controls and assurances; 6 Identify risks that could occur even with the
existing controls in place (control risk); and 7 Recommend improved controls and assurances
(based on an assessment of the trade-off of the cost of the controls against the potential
savings of lost and waste without the new controls in place).

4.

50 There are certain indicators that can alert the auditor to potential risk situations.

Managers are often aware of high-risk situations and will assist the auditor to identify areas
needing examination.

51 Some examples of risk that can be encountered are: a) Processing risk; b) Programme
risk; c) Regularity risk; or d) Risk of fraud.

Errors can occur inadvertently, especially in situations such as the following: a) A new
government programme where there is little experience in administering it, or the entity has
taken over responsibilities for a new function and the previous administrators are no longer
involved.

53 If the process involves large transactions, the risk of inadvertent loss or waste can be
serious.

Certain government programmes are particularly susceptible to significant losses, either


intended (fraud) or unintended (the result of poor administration).

55 Examples of programmes that should be given a careful assessment of risk are: a) Loans
or guarantees, which, by their very nature, usually place the government at risk.

d) Programmes with vague outputs or outcomes, where in return for the government`s
expenditures, the benefits are difficult to identify.

56 Large expenditures in programmes of such nature should be a high priority for the
auditor to examine.

The danger of criticism of a programme can be out of proportion with the potential or actual
loss occurring due to some weakness in the administration of the programme.

For example, regularity risk can derive from: a) inadequate laws; b) inadequate
inspection/detection (insufficient resources available; untrained inspectors; poor supervision
of the inspectors); c) inadequate penalties or other deterrents; d) poor records and
inadequate statistics; and/or e) environmental factors outside of the regularity process that
impact on the effectiveness of the regularity programme.

60 The impact of regularity weaknesses on government operations can be significant,


although not as obvious as misappropriations of funds, waste or loss of monies.

Therefore the auditor must focus on regularity activities just as much as on expenditures.

Some of these are: a) Insufficient separation of duties; b) Only one person with access to
financial information, particularly if this person exhibits defensive or guarded behaviour; c)
Weak controls; d) Inadequate management supervision, inspection, challenge or review; e)
Inadequate or untimely reports; and, f) Late or non-existent reconciliations.

4.63 To determine how much risk the auditor should accept that an unqualified opinion may
be issued on financial statements that are materially misstated, the auditor would consider
such matters as professional exposure, reporting considerations and ease of audit.

4.64 This is the risk of loss or injury to the auditor`s reputation from litigation, adverse
publicity or other events arising in connection with the financial statements reported upon.

4.65 Professional exposure risk is often considered to be highest when there is a good
chance that the financial statements and the audit report thereon will undergo a lot of
scrutiny.

This could occur in special situations such as when an entity is: a) Receiving a lot of bad
publicity for an authority violation or other matter; b) Being privatised, transferred to
another level of government, or turned into a special operating agency; c) Issuing new debt;
and/or d) Getting into financial difficulty.

66 For audit entities such as these, the auditor may elect to reduce their audit risk to reduce
their professional exposure risk.

4.67 These considerations usually include the number of users and the extent to which they
rely on the entity's financial statements and audit report.
Steps for Identifying Risks

1. List Objectives: Identify the program objectives and assets that need safeguarding.

2. Identify Threats: Recognize potential threats that could hinder achieving these
objectives.

3. Rate Inherent Risks: Assess the probability of risks occurring without management
controls.

4. List Existing Controls: Document current controls and assurances in place.

5. Identify Missing Controls: Determine any gaps in controls and assurances.

6. Assess Control Risks: Identify risks that may still occur despite existing controls.

7. Recommend Improvements: Suggest enhanced controls based on a cost-benefit


analysis.

Documentation

 All risk assessment activities should be documented in the audit file.

Indicators of Risk

 Auditors should be aware of various indicators that may signal potential risks,
including:

 Processing Risk: Errors due to lack of experience, new systems, management


changes, or unclear responsibilities.

 Programme Risk: Risks associated with specific government programs,


especially those involving loans, contracts, or vague outcomes.

 Regularity Risk: Risks arising from failures in regulatory activities, such as


inadequate laws or inspection processes.

 Risk of Fraud: Indicators of fraud risk include insufficient separation of duties,


weak controls, and inadequate supervision.

Factors Affecting Audit Risk

1. Professional Exposure: The risk to the auditor's reputation from potential litigation
or adverse publicity.

2. Reporting Considerations: The number of users relying on the financial statements


and the extent of that reliance.

3. Ease of Auditing: The availability of audit evidence and the existence of a clear audit
trail.

Determining Audit Risk


 The auditor must assess the level of audit risk based on the factors mentioned above
and may discuss these with users of the financial statements to gauge their reliance
and any special circumstances that could affect risk.

Guidelines for Audit Risk Assessment

 The assessment of audit risk is subjective and requires professional judgment.


However, general guidelines suggest:

 For high-risk entities, a lower audit risk (e.g., 3%) is preferred, requiring
higher overall assurance (e.g., 97%).

 For all other entities, a standard audit risk (e.g., 5%) may be acceptable, with
a corresponding overall assurance of 95%.

Conclusion

 The relationship between audit risk and overall assurance is inverse; reducing audit
risk necessitates increased audit work. The guidelines provided can help auditors
make informed decisions while maintaining the necessary professional judgment
throughout the audit process.

You might also like