0% found this document useful (0 votes)
19 views25 pages

Identifying Inherent Risks in Auditing

The document discusses the concept of risk, emphasizing its two components: likelihood and effect. It outlines the importance of risk assessment in auditing, including the identification and evaluation of inherent, control, and detection risks, as well as distinguishing between business and fraud risks. Additionally, it highlights the significance of understanding the entity and its environment to effectively identify potential risks and implement anti-fraud controls.

Uploaded by

Elvis Rumints
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
19 views25 pages

Identifying Inherent Risks in Auditing

The document discusses the concept of risk, emphasizing its two components: likelihood and effect. It outlines the importance of risk assessment in auditing, including the identification and evaluation of inherent, control, and detection risks, as well as distinguishing between business and fraud risks. Additionally, it highlights the significance of understanding the entity and its environment to effectively identify potential risks and implement anti-fraud controls.

Uploaded by

Elvis Rumints
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

LECTURE 0624

Inherent Risks - Identification


What is risk?
• Risk is anything that could go wrong
• It has two components
• The likelihood of it happening
• And if it does happen then what is the effect

• E.g. The risk of the cashier pocketing K 10 everyday is high, but the
effect on the cash flow is negligible or very low
• The risk of shops being burnt down completely through looting is very
low (it happens only in extreme cases), but its effect is catastrophic
Importance of Risk Assessment
• Identify the risks
• Assess and determine severity of each risk (chance & effect)
• See if they could result in material misstatements
• Direct focus of audit in high risk areas where material misstatements
high, and away from less risky areas.
Audit Risk Model
• Audit Risk = Control Risk x Detection Risk x Inherent Risk

• Control Risk – controls may not prevent or detect material


misstatements
• Detection Risk – audit procedures may not pick up material
misstatements
• Inherent Risk – material misstatements occur in the absence of
internal controls
Types of Risks
• Business Risk
INHERENT RISK
• Fraud Risk

• Business risk is any risk associated with the operation & management
of the organisation
• Fraud risk results from a person’s deliberate actions compared to
business risk.
Business Risks
• Business risks are not just risks of material misstatements.
• They include risks associated with achieving objectives of the entity
• Understanding business and fraud risk factors increases the likelihood
of identifying risks of material misstatement.
• However, there is no responsibility for the auditor to identify or assess
all of the possible business risks.
Fraud Risks
• Wrongful actions taken intentionally for financial or personal gain.
• E.g. intentionally deferring revenue to the next accounting period in
order to declare less profit hence less income tax payable
Business Risk & Fraud Risk
• In many instances, a risk can be both a business and a fraud risk.

• E.g. Introduction of a new accounting system may cause staff to make


errors while learning the new system.
• However, it provides opportunity for someone to take advantage of
the fact that not many people know how to use the system and
misappropriate assets or manipulate the financial statements.
Sources of Information about Entity
• First, gather enough information about the entity in order to identify
risk factors
It’s the first step in
risk assessment

• Get internal information first


and check for consistency
with external sources.
• Eg. Confirm GDP growth with
BPNG or tax changes with IRC
Previous Auditor’s Working File

They always
contain valuable
information
about the entity
Risk Assessment Procedures

• Understand and identify risks


emanating from each of these
areas.
• How much to know depends on
professional judgement.
Benefits Obtained from
Understanding the Entity
• Identify risks &
develop responses
• Assess accounting
policies used,
adequacy of
disclosures and
areas requiring
special
consideration.
Sources of Risk
• Errors and fraud in financial statements arise from risk factors from
one or more of six required areas of understanding the entity
• An example would be a new and complex tax being imposed on the
entity. This would be an external risk factor. A risk of misstatement in
the financial statements could be a misinterpretation of the new law,
resulting in an incorrect calculation of tax payable and the amount
owed. Note that the source (or cause) of the risk is the new tax that
affects the entity, and not the error in calculation, which is the effect
of the risk factor. As a consequence of the new tax, the risk of a
calculation error increases.
Six Areas as Potential Areas of Risk
• Moving into new lines of business
• Adopting a new IT system
• Inadequate oversight of day-to-
day operations
• Poor or nonexistent controls

• State of Economy
• Regulation etc.
• Inconsistent application
of accounting policies.
• Inappropriate use of
accounting policies.
• Poor corporate culture &
governance
• Incompetent personnel in key
positions
• Performance not measured
against Key Performance
Indicators
• Corrective actions are not taken
Fraud Risk
• “Fraud” is intentional act involving the use of deception to obtain an
unjust or illegal advantage.
• “Management Fraud” involves one or more members of management
or those charged with governance involving in fraud.
• “Employee Fraud” involves only employees of the entity committing
fraud.
• In either case, there may be collusion within the entity or with third
parties outside of the entity.
Types & Characteristics of Fraud
Types & Characteristics of Fraud
• When senior management is involved in fraud, it is serious.
• Some of the major conditions that create an environment for fraud include:

• Ineffective corporate governance;


• Lack of leadership by management and poor “tone at the top”;
• High incentives provided for financial performance;
• Taxes or other expenses that are considered very high or onerous;
• Complexity in the entity’s rules, regulations, and policies;
• Unrealistic expectations from bankers, investors, or other stakeholders;
• Downward and unexpected shifts in profitability;
• Unrealistic budget targets for staff to attain; and
• Inadequate internal control, especially in the presence of organizational change.
An Effective Anti-Fraud Internal
Control
• Board and management have a strong commitment to doing the right
thing.
• Setting the tone at the top
• Articulate the entity values and ensure commitment to ethics on a
day-to-day basis.
• It cascades down to everyone in the organsiation
• Its contagious regardless of any size of organization.
Fraud Triangle

You have immediate needs You do not see it as fraud


such as personal debts etc. and come up with reason to
justify your action.

Opportunity for fraud


presents itself due to
ineffective or lack of
controls.
Example
• E.g. An owner-manager wins a contract to build a house and it’s a cash only
transaction with no paperwork.
• The “pressure” on the owner-manager might be to reduce taxes that would
otherwise be payable.
• The “opportunity” is for the owner-manager to override the internal
controls over revenue recognition and not record the revenue from the
sale.
• The “rationalization” could be that the owner-manager is already paying
far too much in taxes.
• Note: If any one of the three conditions is not present, the cash sale is
unlikely to take place.
Professional Skepticism
How to Identify Inherent Risk Factors

1. Obtain understanding of entity, its environment & internal controls


2. Identify, assess and document the risks
3. Relating identified risks to possible errors and fraud in the financial
statements. (account balances, class of transactions & disclosures)

• E.g. Security at the warehouse is poor resulting in staff stealing stocks


hence errors in inventory balance.
Documenting the Risk Identification
Process
• Record all risks in a structured manner
• Record them in one document
• Record all risks that you come across and assess and rank
ENDS

You might also like