0% found this document useful (0 votes)
13 views89 pages

Overview of Auditing Standards

The document discusses auditing standards, including International Standards on Auditing (ISAs), U.S. Generally Accepted Auditing Standards (GAAS), and PCAOB Auditing Standards, outlining their objectives, requirements, and the importance of auditor independence and professional ethics. It emphasizes the necessity of obtaining sufficient evidence and understanding legal frameworks to ensure compliance during audits. Additionally, it addresses ethical dilemmas faced by auditors and the frameworks available for resolving such dilemmas.

Uploaded by

oliifan Hunde
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views89 pages

Overview of Auditing Standards

The document discusses auditing standards, including International Standards on Auditing (ISAs), U.S. Generally Accepted Auditing Standards (GAAS), and PCAOB Auditing Standards, outlining their objectives, requirements, and the importance of auditor independence and professional ethics. It emphasizes the necessity of obtaining sufficient evidence and understanding legal frameworks to ensure compliance during audits. Additionally, it addresses ethical dilemmas faced by auditors and the frameworks available for resolving such dilemmas.

Uploaded by

oliifan Hunde
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

CHAPTER two

THE AUDITING PROFESSION

By: Mulu M. 11/15/2025


AUDITING STANDARDS
2
Auditing standards are general guidelines to
aid auditors in fulfilling their professional
responsibilities in the audit of historical financial
statements.
They include consideration of professional
qualities such as competence and independence,
reporting requirements, and evidence.
The three main sets of auditing standards are
International Standards on Auditing, U.S.
Generally Accepted Auditing Standards for
entities other than public companies, and PCAOB
Auditing Standards.
By: Mulu M. 11/15/2025
International Standards on
Auditing
3
 International Standards on Auditing (ISAs) are
issued by the International Auditing and
Assurance Standards Board (IAASB) of the
International Federation of Accountants (IFAC).
 IFAC is the worldwide organization for the
accountancy profession, with 159 member
organizations in 124 countries, representing
more than 2.5 million accountants throughout the
world.
 The IAASB works to improve the uniformity of
auditing practices and related services
throughout the world by issuing
pronouncements on a variety of audit and attest
functions
By: Mulu M. and by promoting their acceptance11/15/2025
International Standards on
Auditing
4
ISA 250 Objective
The objective of auditor are;
 To obtain sufficient & appropriate audit evidence regarding
compliance with the provisions of those laws and regulations
generally recognized to have a direct effect on the determination of
material amounts and disclosures in the financial statements;
 To perform specified audit procedures to help identify instances of
non-compliance with other laws and regulations that may have a
material effect on the financial statements; and
 To respond appropriately to non-compliance or suspected non-
compliance with laws and regulations identified during the audit.
By: Mulu M. 11/15/2025
International Standards on
Auditing
5
ISA 250 Requirements

 Auditor shall obtain understanding of legal and regulatory framework applicable to the entity and how
entity is complying with it.
 Audit shall obtain sufficient and appropriate audit evidence regarding compliance with the provisions
of those laws and regulations generally recognized to have a direct effect on the determination of
material amounts and disclosures in the financial statements.
 Auditor shall perform following procedure to help identify instances of non-compliance with other
laws and regulations that may have a material effect on the financial statements;
o Inquiring of management and, where appropriate, those charged with governance, as to whether
the entity is in compliance with such laws and regulations; and
o Inspecting correspondence, if any, with the relevant licensing or regulatory authorities.
 Auditor shall remain alert for instances of non-compliance
 Obtain written representation on all known instances of non-compliance or suspected non-compliance
with laws and regulations whose effects should be considered when preparing financial statements
have been disclosed to the auditor.

By: Mulu M. 11/15/2025


International Standards on Auditing
6
 ISAs do not override a country’s regulations governing
the audit of financial or other information, as each
country’s own regulations generally govern audit
practices.
 These regulations may be either government statutes or
statements issued by regulatory or professional bodies,
such as the Australian Auditing & Assurance Standards
Board or Spain’s Instituto de Contabilidad y Auditoría
de Cuentas.
 Most countries, including the United States, base their
auditing standards on ISAs, modified as appropriate for each
country’s regulatory environment and statutory
requirements.
 International auditing standards as adopted by
standard-setting bodies in individual countries apply to
audits of entities outside the United States.
By: Mulu M. 11/15/2025
Public Company Accounting Oversight Board
Auditing Standards (PCAOB)
7

 The PCAOB initially adopted existing auditing standards


established by the ASB as interim audit standards.
 In addition, the PCAOB considers international auditing
standards when developing new standards.
 As a result, auditing standards for U.S. public and private
companies are mostly similar.
 Standards issued by the PCAOB are referred to as PCAOB
Auditing Standards in the audit reports of public companies
and when referenced in the text, and apply only to the audits
of public companies.
 PCAOB auditing standards apply to audits of U.S public
companies and other SEC registrants.

By: Mulu M. 11/15/2025


The relations among international auditing standards,
generally accepted auditing standards, and PCAOB
auditing standards.
8

By: Mulu M. 11/15/2025


9

By: Mulu M. 11/15/2025


10

By: Mulu M. 11/15/2025


11

By: Mulu M. 11/15/2025


12

By: Mulu M. 11/15/2025


13

By: Mulu M. 11/15/2025


14

By: Mulu M. 11/15/2025


15

By: Mulu M. 11/15/2025


16

By: Mulu M. 11/15/2025


17

By: Mulu M. 11/15/2025


18

By: Mulu M. 11/15/2025


19

By: Mulu M. 11/15/2025


U. S Generally Accepted Auditing
Standards
20
 Generally accepted auditing standards are
similar to international auditing standards and apply
to the audits of private companies and other
entities in the United States.
 Auditing standards for private companies and other
entities in the United States are established by the
Auditing Standards Board (ASB) of the AICPA.
 These standards are referred to as Statements on
Auditing Standards (SASs).
 These Generally Accepted Auditing Standards (GAAS)
are similar to the ISAs, although there are some
differences.
By: Mulu M. 11/15/2025
U. S Generally Accepted Auditing
Standards
21

 If an auditor in the United States is auditing


historical financial statements in accordance
with ISAs, the auditor must meet any ISA
requirements that extend beyond GAAS.
 Prior to passage of the Sarbanes–Oxley Act, the
ASB established auditing standards for private
and public companies.
 The PCAOB now has responsibility for auditing
standards for public companies, while the ASB
continues to provide auditing standards for
private companies and other entities.

By: Mulu M. 11/15/2025


U. S Generally Accepted Auditing
Standards
22

 The broadest guidelines available to auditors in the U.S. are


the ten generally accepted auditing standards (GAAS),
which were developed by the AICPA.

By: Mulu M. 11/15/2025


1) General Standards
23

i. Adequate Technical Training and Proficiency


 This standard require the auditor to have formal education in auditing and
accounting, adequate practical experience for the work being performed,
and continuing professional education.
 Recent court cases clearly demonstrate that auditors must be
technically qualified and experienced in those industries in which
their audit clients are engaged.
 In any case in which the CPA or the CPA’s assistants are not
qualified to perform the work, a professional obligation exists to
acquire the requisite knowledge and skills, suggest someone else
who is qualified to perform the work, or decline the engagement.

By: Mulu M. 11/15/2025


1) General Standards
24

ii. Independence in mental attitude


 The Code of Professional Conduct and SASs
stress the need for independence.
 CPA firms are required to follow several practices to
increase the likelihood of independence of all
personnel.
 The auditors who provides auditing and other
attestation services should be independent in fact
and appearance.
 For example, there are established procedures
on larger audits when there is a dispute
between management and the auditors
By: Mulu M. 11/15/2025
1) General Standards
25

iii. Due Professional Care: auditors are


professionals responsible for fulfilling their duties
diligently and carefully.
 Diligence involves application of relevant technical
and ethical standards.
 Due care includes consideration of the
completeness of the audit documentation, the
sufficiency of the audit evidence, and the
appropriateness of the audit report.
 As professionals, auditors must not act negligently
or in bad faith, but they are not expected to be
infallible.
By: Mulu M. 11/15/2025
2) Standards of Field Work
26

The standards of field work concern evidence


accumulation and other activities during the actual
conduct of the audit.
i. Adequate Planning and Supervision: The audit be
sufficiently planned to ensure an adequate audit and proper
supervision of assistants.
 Adequate planning means determining the audit scope,
timing, objectives, criteria and methodology to be used and
the resource required to ensure that the audit will achieve the
predetermined level of assurance in an efficient manner.
 Supervision is the process of directing the effort of assistants
in conjunction with the objectives of the audit and
determining whether the objectives are achieved.
 Supervision is essential in auditing because a considerable
portion of the field work is done by less experienced staff
By: Mulu M. 11/15/2025
members.
2) Standards of Field Work
27

ii. Sufficient understanding of the auditee's


internal control: the auditor must obtain a
sufficient understanding of the entity and its
environment, including its internal control, to
assess the risk of material misstatement of the
financial statements whether due to error or
fraud, and to design the nature, timing, and extent
of further audit procedures.
 One of the most widely accepted concepts in
the theory and practice of auditing is the
importance of the client’s system of internal
control for mitigating client business risks,
safeguarding assets and records, and generating
reliable financial information.
By: Mulu M. 11/15/2025
2) Standards of Field Work
28

iii. Sufficient, competent and relevant evidence:


the auditor must obtain sufficient appropriate
audit evidence by performing audit procedures to
afford a reasonable basis for an opinion regarding
the financial statements under audit.
 Sufficient, competent, and relevant evidence is to
be obtained to afford a reasonable basis for the
auditors’ findings and conclusions.
 Decisions about how much and what types of
evidence to accumulate for a given set of
circumstances require professional judgment.

By: Mulu M. 11/15/2025


c) Standards of Reporting
29

 The four standards of reporting require that the


auditor consider each of the following issues before
rendering an audit report:
1. The financial statement are presented in
accordance with generally accepted accounting
principles,
2. Those principles are consistently applied,
3. All informative disclosures have been made and
4. In all cases where an auditor's name is associated with
financial statements, the auditor should clearly indicate the
character of the auditor's work, if any, and the degree of
responsibility the auditor is taking, in the auditor's report.
By: Mulu M. 11/15/2025
Statements on auditing
standards
30

 The 10 generally accepted auditing standards are


too general to provide meaningful guidance, so
auditors turn to the SASs issued by the ASB for
more specific guidance.
 Generally accepted auditing standards and SASs
are regarded as authoritative literature, and every
member who performs audits of historical financial
statements is required to follow them under the
AICPA Code of Professional Conduct.
 The ASB issues new statements when an auditing
problem arises of sufficient importance to warrant
an official interpretation.
By: Mulu M. 11/15/2025
PROFESSIONAL ETHICS
31

 Ethics – can be defined broadly as a set of moral


principles or values.
 .Examples of prescribed sets of moral principles or
values at the implementation level include laws and
regulations, codes of business ethics for
professional groups such as CPAs, and codes of
conduct within individual organizations.
 Special Needs for Ethics: Ethical behavior is
necessary for a society to function in an orderly
manner.
 The underlying reason for a high level of
professional conduct by any profession is the need
By: for public confidence in the quality of services11/15/2025
Mulu M.
PROFESSIONAL ETHICS
32

 Why people act unethically?: Most people define


unethical behavior, as a conduct that differs from
what they believe would have been appropriate
given circumstances.
 It is believed that there are two primary reasons why
people act unethically:
 Person’s Ethical Standards Differ from General
Society: Extreme examples of people whose
behavior violates almost everyone’s ethical
standards are drug dealers, bank robbers, and
larcenists.
 Most people who commit such acts feel no remorse
when they are apprehended because their ethical
By: Mulu M. 11/15/2025
standards differ from those of society as a whole.
PROFESSIONAL ETHICS
33

 When people cheat on their tax returns, treat other


people with hostility, lie on resumes and
employment applications, or perform below their
competence level as employees, most of us regard
that as unethical behavior
 If the other person has decided that this behavior is
ethical and acceptable, there is a conflict of ethical
values that is unlikely to be resolved.
 The Person Chooses to Act Selfishly: A
considerable portion of unethical behavior results
from selfish behavior.
 The person knows that the behavior is
inappropriate but chooses to do it anyway because
By: Mulu M. 11/15/2025
of the personal sacrifice needed to act ethically.
Ethical Dilemmas
34

 An ethical dilemma is a situation a person faces in


which a decision must be made about the
appropriate behavior.
 A simple example include, finding a diamond ring,
which necessitates deciding whether to attempt to
find the owner or to keep it, accepting money
informally as a tip of corruption.
 Auditors, accountants, and other business people
face many ethical dilemmas in their business
careers.
 Deciding whether to confront a supervisor who has
materially overstated departmental revenues as a
means of receiving a large bonus is difficult ethical
By: Mulu M. 11/15/2025
dilemma
Ethical Dilemmas
35

 The common rationalizations of ethical dilemmas


include:
 Everybody does it – the argument that it is
acceptable to falsify things because it is done by
everybody. Examples include, falsify tax returns,
cheat on exams, or sell defective products.
 If it’s Legal, it’s Ethical – using the argument that
all legal behavior is ethical relies heavily on the
perfection of laws. Under this philosophy, one would
have no obligation to return a lost object unless the
other person could prove that it was his or hers.
 Likelihood of Discovery and Consequences – this
philosophy relies on evaluating the likelihood that
By: Mulu M. 11/15/2025
someone else will discover the behavior.
Resolving Ethical Dilemmas
36

 In recent years, formal frameworks have been


developed to help people resolve ethical dilemmas.
a relative simple approach to resolve ethical
dilemma.
1. Obtain the relevant facts.
2. Identify the ethical issues from the facts.
3. Determine who is affected by the outcome of the
dilemma and how each person or group is affected.
4. Identify the alternatives available to the person
who must resolve the dilemma.
5. Identify the likely consequence of each alternative.
6. Decide the appropriate action.
By: Mulu M. 11/15/2025
…. Professional Ethics
Special Need for Ethical Conduct in Professions
 The society has attached a special meaning to the term
professional.
 Professionals are expected to conduct themselves at a
higher level than most other members of society.
 For example, when the press reports that a physician,
clergyperson, a Lawyer, or CPA has been indicted for a
crime, most people feel more disappointment than when
the same thing happens to people who are not labeled as
professionals.
 Professional Ethics is one pillar up on which the audit
profession stands
Audting Part I 37
…. Professional Ethics
 Code of professional ethics is necessary in that:
 It is not practical for most customers to evaluate the quality of the performance of
professional services because of their complexity.
Eg. A patient cannot be expected to evaluate whether an operation was properly
performed.
A financial statement user cannot be expected to evaluate audit performance.
Most users have neither the competence nor the time for such an evaluation.
Public confidence in the quality of professional services is enhanced when the
profession encourages high standards of performance and conduct on the part of
all practitioners.
Thus, Code of professional ethics
 is a means of self regulation by imposing the codes in addition to the rule of the
land and other rules and regulations by which we have to abide by whether we
like it or not .
 is a means of recognition as a profession.
 enhances the profession’s stature
Audting Part I 38
…. Professional Ethics

 The most important factors that encourage CPAs to


conduct themselves appropriately and perform
high-quality audits and related services include:
 Applications of the GAAS and their interpretations,
 The CPA examination,
 Quality control,
 Peer review requirements,
 Regulations by different bodies eg. SEC,
 Continuing education.
 The existence of legal liability of CPA firms
Audting Part I 39
Code of Professional Conduct
 The AICPA Code of Professional Conduct provides both general standards of
ideal conduct and specific enforceable rules of conduct.
 It provides a standard of conduct for all members of the AICPA.
 There are four parts to the code:
1. Principles,
2. Rules of conduct,
3. Interpretations of the rules of conduct, and
4. Ethical rulings.
The parts are listed in order of increasing specificity:
 The principles provide ideal standards of conduct, they are not enforceable
 Rules of conduct, are minimum standards of ethical conduct stated as specific rules,
they are enforceable
 Interpretations of Rules of conduct they are not enforceable but the practitioner must
justify departure
 Ethical rulings are highly specific, they are not enforceable but the practitioner must
justify departure Audting Part I 40
Section I- Ethical
Principles
Ethical Principles
Article 1. Responsibilities: In carrying out their responsibilities as professionals, members
should exercise sensitive professional and moral judgments in all their activities.
Article 2. The Public Interest: Members should accept the obligation to act in a way that will
serve the public interest, honor the public trust, and demonstrate commitment to
professionalism.
Article 3. Integrity: To maintain and broaden public confidence, members should perform all
professional responsibilities with the highest sense of integrity.
Article 4. Objectivity and Independence: A member should maintain objectivity and be free of
conflicts of interest in discharging professional responsibilities. A member in public practice
should be independent in fact and appearance when providing auditing and other attestation
services.
Article 5. Due Care: A member should observe the profession’s technical and ethical standards,
strive continually to improve competence and quality of services, and discharge professional
responsibility to the best of the member’s ability.
Article 6. Scope and Nature of Services: A member in public practice should observe the
principles of the Code of Professional Conduct in determining the scope and nature of
services to be provided. Audting Part I 41
…. Section I- Ethical
Principles
 Article 1: Responsibilities
 CPAs (Audit firms) have responsibility to all who use their service
 Thy have to provide the service with highest level of integrity
 Members have to cooperate each other to improve the art of the service and
maintain public confidence
In general they are responsible to the following groups:
 To the society or the public in general. (to those that relies on audited financial
statements. )
 To the clients. Specifically, the CPA owes it to his client to be competent, honest,
loyal, independent, and solicitous. The auditor should not disclose this information
to others, without the consent of the client. (Example: Officer’s salaries,
engineering specifications of a new type of computer).
 To fellow practitioners. Colleagues norms help build and maintain internal
cohesion within a profession. The advancement of a profession is dependent upon
goodwill and mutual trust among practitioners. The auditor should promote
cooperation and good Audting
relations
Part Iamong other members of the profession. 42
…. Section I- Ethical
Principles
 Article 2: Public interest
 The distinguishing feature of a profession is acceptance of
its responsibility to the public.
 The accounting profession’s public consists of clients, credit
grantors, governments, employers, investors, the business
and financial community
 The public interest is the collective well-being of the
community of people and institutions, the profession serves
including all who rely on the objectively verified financial
information for the orderly function of commerce
 Thus those in the profession are required to commit
themselves for public interest
Audting Part I 43
…. Section I- Ethical
Principles
Article 3: Integrity
 Integrity means that the auditor will give his own honest opinion,
in spite of what the consequences might be. It requires the auditor
to be impartial.

Article 4: Objectivity and Independence


 Independence and objectivity are very closely bound together.
 If the auditor is not independent, it is almost impossible for him
to be objective.
 Independence is said to be the cornerstone of the auditing
profession.
 It is because the auditor is expected to be independent, that third
parties believe that hisPartreport
Audting I will be unbiased, or objective. 44
…. Section I- Ethical
Principles
 Article 5: Due Care
 Due Care is a standard for competence and technical standards
 According to this standard, the auditor should not accept an
engagement unless he is certain that he has the essential skills
to do the work well, including a thorough knowledge of
GAAP.
 Then, having accepted the engagement, the auditor is required
to work carefully, including planning and supervising the work
of staff members.
 Finally, the auditor is required to do the work completely,
accumulating and examining a sufficient amount of evidence
to support his opinion.
Audting Part I 45
…. Section I- Ethical
Principles
Article 6: Scope and Nature of Service
 This rule can be considered as a constraint on the nature of
the non audit service that may be rendered to the client
 The rule requires members:
 to practice in firms that have in place internal quality-control
procedures, to ensure that services are competently delivered and
adequately supervises
 To determine, in their individual judgments, whether the scope
and nature of other services provided to an audit client would
create a conflict of interest in the performance of the audit
function for that client
 Asses in their own judgments, whether an activity is consistent
with their role as professional
Audting Part I 46
Section II- Rules of Conduct
Rules of Conduct
 This part of the Code includes the explicit rules that must be
followed by every CPA in the practice of public accounting.
 Those individuals holding the CPA certificate but not practicing
public accounting must follow most, but not all requirements.
 Because the section on rules of conduct is the only enforceable
part of the code, it is stated in more precise language than the
section on principles.
 Because of their enforceability, many practitioners refer to the
rules as the AICPA Code of Professional Conduct.
(Note: Since this Section II, the rules of conducts (Rule 101-
505) are enforceable, they will be discussed in this chapter,
after the nature of interpretations and ethical rulings are
Audting Part I 47
Section III- Interpretations of Rules
of Conduct
Interpretations of Rules of Conduct
 The need for published interpretations of the rules of conduct arises when there are
frequent questions from practitioners about a specific rule.
 The Professional Ethics Executive Committee of the AICPA prepares each
interpretation based on a consensus of a committee made up principally of public
accounting practitioners.
 Before interpretations are finalized, they are issued as exposure drafts to the
profession and others for comment.
 Interpretations are not officially enforceable, but a departure from the interpretations
is difficult if not impossible for a practitioner to justify in a disciplinary hearing.
 The most important interpretations are discussed as a part of each section of the
rules.

Audting Part I 48
Section IV- Ethical Rulings
Ethical Rulings
 The AICPA also issues Ethical rulings
 Ethical Rulings explain the application of the
Rules and Interpretations to specific factual
circumstances involving professional ethics
 Ethical rulings are highly specific, they are not
enforceable but the practitioner must justify
departure

Audting Part I 49
..Legal Responsibility & Liability of
Auditors
 Thus, when CPAs take any engagement, they are
obliged to render the service with due professional
care, this obligation exists whether it is written in
the contract or not.
 Auditors are liable to their clients for negligence and/or
breach of contract if they fail to provide the services or
fail to exercise due care in their performance.
 Based on precedents in common law, clients and third
parties have the right to recover damages caused by
auditors for ordinary negligence
Audting Part I 50
…..Legal Responsibility & Liability of
Auditors
 Potential liability of CPAs due to improper professional
practices is considered to be higher as compared to the case
in other professions. Why?
 The parties that will be injured is larger in the case of
improper practices of CPAs
 Eg: Physician/attorney- the injured parties could be the
client
 If CPAs are negligent in expressing opinions on financial
statements – millions of investors could sustain losses
 Trends show that legal liability of auditors are increasing

Audting Part I 51
..Legal Responsibility & Liability of
Auditors
 What increased auditors responsibility to
safeguard public interest ?
 The increase in the number of investors
 The increase in the number of corporate form of
businesses (where ownership is separated from
control),
 The increased need for independent financial
information by different parties, (eg. investors,
owners, govt.)
 The increase in the reliance of government on
accountingAudting
information.
Part I 52
…..Legal Responsibility & Liability of
Auditors
 Studies show legal liability of auditors has increased over
time due to:
 Users growing awareness of the responsibility of auditors
 Governments increased awareness on the need for protection of
investor’s interests.
 Increased audit complexity caused by computerized systems, new types
of transactions and operations, more complicated accounting standards,
more international business
 More demanding audit standards for detection of errors and fraud
 Pressures to reduce audit time and improve audit efficiency
 Misunderstanding by users that an unqualified opinion is an insurance
policy against misstatements (Expectation gap) mainly due to inability to
distinguish between Business failure, Audit failure, and Audit Risk
Audting Part I 53
…..Legal Responsibility & Liability of
Auditors
 Joint and several liability statutes that permit a plaintiff to collect
the full amount of the settlement from any defendant, even those
only partially responsible for the loss (i.e. deep pockets theory)
 Courts’ difficulties in understanding and interpreting accounting
and auditing matters.
 Contingent-fee-based compensation for law firms
Implications of increased legal liability of Auditors:
 The need to be aware of the legal liability inherent in the
practice before deciding to enter in the auditing profession
 Auditors must approach every engagement with the
expectation that they may appear in court to defend their work

Auditing I 54
…. ..Legal Responsibility & Liability
of Auditors
What will happen if the trend is not changed?
 The cost of professional liability insurance will continue to
increase
▪ Not only the cost issue, but reputations of audit firms will also
be damaged
 Performing tasks with due care is essential to reduce the costs
and keep the image of the profession
 It is obvious that, no matter how careful a CPA firm is, it may
occasionally find it self as defendant in litigation, however:
▪ CPAs are never liable to any party, if they perform their
services with due professional care
▪ Having exercised due professional care (due diligence)
Auditing I 55
…. ..Legal Responsibility & Liability
of Auditors
Legal Concepts Pertinent to Auditors Liability
1. Prudent Person Concept
2. Liability for the Acts of Others
3. Lack of Privileged Communication

1. Prudent Person Concept : It is considered as a standard of due care. It requires CPA


firms:
 To exercise due diligence- Those who provide services should have the
required skills and competence, if this is not the case, it is considered as
fraud (deceiving others)
 To provide service in good faith and highest level of integrity- It is
understood that auditors can provide only reasonable assurance, not a
guarantee about the accuracy of financial statements (It means, errors may
occur in the process since no one is perfect (infallibility is not assumed).
Negligence and dishonesty makes auditors liable to others, but not an error
occurred in providing services in good faith.
Auditing I 56
…. ..Legal Responsibility & Liability
of Auditors
2. Liability for the Acts of Others
 CPA firms provide service to others through their
employees, or may involve other CPA firms to do part of
the work, and may also invite specialists to provide
technical information
 Thus, if an employee performs improperly in doing an
audit, the partners can be held liable for the employee’s
performance.
 In general, partners of the CPA firms are liable for the work
of others on whom they rely

Auditing I 57
…. ..Legal Responsibility & Liability
of Auditors
3. Lack of Privileged Communication
 Information is said to be privileged information if legal
proceedings cannot require a person to provide the
information, even if there is a subpoena.
 Information communicated by a client to an attorney or by
a patient to a physician is privileged.
 But Information obtained by a CPA from a client generally
are confidential but not privileged.
 They are confidential (are not revealed without the consent
of the client), but exceptionally they are communicated eg.
by court orders.
Auditing I 58
Legal Terms Affecting CPAs’
Liability
Terms Related to Negligence and Fraud
 Ordinary negligence:-Absence of reasonable care that
can be expected of a person in a set of circumstances.
For auditors, it is in terms of what other competent
auditors would have done in the same situation.
 Gross negligence:-Lack of even slight care,
tantamount to reckless behavior, that can be expected of
a person.
 Some states do not distinguish between ordinary and
gross negligence.
Auditing I 59
Legal Terms Affecting CPAs’
Liability
 Constructive fraud:-Existence of extreme or
unusual negligence even though there was no intent
to deceive or do harm. Constructive fraud is also
termed recklessness.
 Recklessness in the case of an audit is present if the
auditor knew an adequate audit was not done but
still issued an opinion, even though there was no
intention of deceiving statement users.
 Fraud:-Occurs when a misstatement is made and
there is both the knowledge of its falsity and the
Auditing I 60
Legal Terms Affecting CPAs’
Liability
Terms Related to Contract
 Breach of contract:-Failure of one or both parties in a contract
to fulfill the requirements of the contract.
 An example is the failure of a CPA firm to deliver a tax return
on the agreed-upon date.
 Parties who have a relationship that is established by a contract
are said to have privity of contract.
 Third-party beneficiary:-A third party who does not have
privity of contract but is known to the contracting parties and is
intended to have certain rights and benefits under the contract.
 A common example is a bank that has a large loan outstanding
at the balance sheet date and requires an audit as a part of its
loan agreement. Auditing I 61
Legal Terms Affecting CPAs’
Liability
Other Terms
Common law:-Laws that have been developed
through court decisions rather than through
government statutes.
 Statutory law:-Laws that have been passed by the
U.S. Congress and other governmental units.
 The Securities Acts of 1933 and 1934 and
Sarbanes–Oxley Act of 2002 are important statutory
laws affecting auditors.
Auditing I 62
Legal Terms Affecting CPAs’
Liability
Joint and several liability
 The assessment against a defendant of the full loss
suffered by a plaintiff, regardless of the extent to
which other parties shared in the wrongdoing.

 For example, if management intentionally misstates


financial statements, an auditor can be assessed the
entire loss to shareholders if the company is
bankrupt and management is unable to pay.
Auditing I 63
Legal Terms Affecting CPAs’
Liability
Separate and proportionate liability
 The assessment against a defendant of that portion
of the damage caused by the defendant’s
negligence.
 For example, if the courts determine that an
auditor’s negligence in conducting an audit was the
cause of 30% of a loss to a defendant, only 30% of
the aggregate damage will be assessed to the CPA
firm.
Auditing I 64
…. ..Legal Responsibility & Liability
of Auditors
Civil and Criminal Liabilities
Civil Liability: occurs when the rights of a specific individual or group
have been violated (torts fall under the heading of civil liability)
 Tort – a private wrong other than contractual, i.e. personal injury or
property damage, resulting from negligence. The wronged (ill treated)
person may get redress (compensation) in a law court.
Tort is civil wrong ( a wrongful act) for which damages can be sought by
the injured party
Auditors may be held civilly liable by clients and third parties who use
audited financial statements. This civil liability is based
 Contract law
 Common law
 Statute (statutory law)
Auditing I 65
…. ..Legal Responsibility & Liability
of Auditors
 Criminal liability – occurs when an act,
considered to be a wrong against society, is
committed
 Statutory laws provide for criminal actions
against auditors - guilty persons can be fined
or imprisoned.
 So, auditors can also be held with criminal
liability

Auditing I 66
…..Legal Responsibility & Liability of
Auditors
 Auditors liabilities may arise from improper performance
of any type of engagement, ie.: an audit, tax services,
accounting services, or management advisory services
 Terms related to negligence such as ordinary, gross
represent different degrees of improper performance by
the CPA.
 The extent to which the CPA’s services are found to be
improper determines the parties to whom the CPAs are
liable for losses caused by their improper action.
 Ordinary (simple) negligence is a sufficient degree of
misconduct to make CPAs liable for damages caused to
their clients Audting Part I 67
…..Legal Responsibility & Liability of
Auditors
Knowing the following terms is helpful to understand the discussions related to legal
liability Links Ch 3\Ch 3 Link 2 Definition of [Link]
How to determine the level of negligence as ordinary and gross?
 Reference to Professional Stds (GAAS)
 CPA as an Expert Witness

Four Major Sources of Auditor’s Liability:


1. Clients-most common source of law suits against CPAs
2. Third party beneficiary
3. Federal Securities Law
4. Criminal Liability
Thus, the plaintiffs include clients, third party beneficiaries and the
Government (for violation of security laws)

Auditing I 68
……..Legal Responsibility & Liability
of Auditors
Clients may sue the auditor mainly for the following:
For Breach of Contract: this occurs when auditor fails to
perform a contractual duty: Breach actions include:
 failing to complete the engagement within the agreed-upon
time (Eg. Late F.S. or Tax Returns),
 withdrawing from the engagement without sufficient
justification
 violating client confidentiality (Disclosure of Confidential
Information)
 failing to provide professional quality work (eg Failure to
detect Fraud, Errors in Proposed F.S. Adjustments, Errors
in Tax Returns, )
AuditingI 69
……..Legal Responsibility & Liability
of Auditors
 Auditor’sResponsibility for the detection of errors
and irregularities:
Failure to uncover an embezzlement/defalcation against
clients by client employees is one source of CPAs
liability to clients
Key factor in determining whether the auditor is liable/not:
The key factor is not whether the auditor is unable to
uncover the fraud, but, the issue is whether this failure
stems from the auditor’s negligence
What does Auditing Standards (SAS 53) states about
auditor’s responsibilities?
Auditing I 70
……..Legal Responsibility & Liability
of Auditors
Auditing Standards (SAS 53) require auditors:
1. To design their audit to provide reasonable assurance of detecting errors and
irregularities that are material to the financial statements;
2. To exercise due care and professional skepticism in planning and conducting
their examinations
[Link] communicate irregularities of any consequence and proposed audit adjustments
to the audit committee of the client’s board of directors.
So what does this standard imply?
 These requirements do not imply that auditors were negligent when ever errors
and irregularities are later found to exist in audited financial statements
 An audit has certain limitation; for cost reason, it is conducted on test (sample)
basis, so can not provide absolute assurance that financial statements are free
from errors and irregularities (those that do not fall in the sample ( the parts no
checked) may contain errors and irregularities )
 In addition, if collusions exist, errors and irregularities can be skillfully/expertly
concealed, and this creates
Auditing I difficulty to reveal errors and irregularities71by
……..Legal Responsibility & Liability
of Auditors
 The Burden of Proof Under Common Law
 Legal actions under common law require the plaintiff to
bear most of the burden of proof.
 Plaintiffs seeking damages from CPAs must prove that
they sustained losses, due to their reliance on audited
financial statements that were misleading, and auditors
were guilty of a certain degree of negligence.

Auditing I 72
……..Legal Responsibility & Liability
of Auditors
 Auditor's Defense: Auditors can refute by showing the
following:
▪ auditor did not breach the contract
▪ client was contributory negligent
▪ client losses were not caused by the breach
In sum, auditors defend that 1) they were not negligent in the
performance of their duties, 2) their negligence was not the
proximate cause for the client loss
▪ Eg by demonstrating the existence of contributory negligence (when client's
negligence contributes to the loss. Eg. a loss resulted from failure to implement
auditor’s recommendation)
▪ Contributory negligence may eliminate auditor’s liability or the concept of
comparative negligence may be applied to allocate the damage between the
auditor and theAuditing
client I(Read the illustrative case on Megs et al, 9th edition Page
73
……..Legal Responsibility & Liability
of Auditors
 Auditor's Defense: Auditors can refute by showing the
following:
▪ auditor did not breach the contract
▪ client was contributory negligent
▪ client losses were not caused by the breach
In sum, auditors defend that 1) they were not negligent in the
performance of their duties, 2) their negligence was not the
proximate cause for the client loss
▪ Eg by demonstrating the existence of contributory negligence (when client's
negligence contributes to the loss. Eg. a loss resulted from failure to implement
auditor’s recommendation)
▪ Contributory negligence may eliminate auditor’s liability or the concept of
comparative negligence may be applied to allocate the damage between the
auditor and theAuditing
client I(Read the illustrative case on Megs et al, 9th edition Page
74
……..Legal Responsibility & Liability
of Auditors
 Auditor's Defense: Auditors can refute by showing the
following:
▪ auditor did not breach the contract
▪ client was contributory negligent
▪ client losses were not caused by the breach
In sum, auditors defend that 1) they were not negligent in the
performance of their duties, 2) their negligence was not the
proximate cause for the client loss
▪ Eg by demonstrating the existence of contributory negligence (when client's
negligence contributes to the loss. Eg. a loss resulted from failure to implement
auditor’s recommendation)
▪ Contributory negligence may eliminate auditor’s liability or the concept of
comparative negligence may be applied to allocate the damage between the
auditor and theAuditing
client (Read
I
the illustrative case on Megs et al, 9th edition Page
75
Materiality and Assessment of Risks
76

 MATERIALITY: Materiality is defined as the magnitude of


an omission or misstatement of accounting information that
is the right of surrounding circumstances, makes if probable
that the judgment of a reasonable person relying on the
information would have been changed or influenced by the
omission or misstatement.
 steps while applying materiality is auditing judgment:
 Setting preliminary judgment: revised: the auditor might do

is revising judgment based on the results of audit tests and


new information as the audit progresses.
 Allocating the preliminary judgment to segments: because

evidence is accumulated by segments rather than for


financial statements as a whole.
 Compute the errors in each segments,

 Combining errors, and Comparing and contrasting the

errors with the preliminary judgment. Saturday, November 15, 2025


By: Mulu.M
Cont’d…
77

 Several factors affect the auditor’s preliminary judgment about


materiality for a given set of financial statements. The most important
of these are:
A. Materiality Is a Relative Rather Than an Absolute Concept:- A
misstatement of a given magnitude might be material for a small
company, whereas the same dollar misstatement could be immaterial
for a large one.
B. Bases Are Needed for Evaluating Materiality:- Because materiality is
relative, it is necessary to have bases for establishing whether
misstatements are material.
C. Qualitative Factors Also Affect Materiality:- Certain types of
misstatements are likely to be more important to users than others,
even if the dollar amounts are the same. For example:-
 Amounts involving fraud are usually considered more important than
unintentional errors of equal dollar amounts because fraud reflects on
the honesty and reliability of the management or other personnel
involved.
By: Mulu.M Saturday, November 15, 2025
..Legal Responsibility & Liability of
Auditors
 Difficulties often arise when a business failure, not an audit failure,
occurs.
 Eg. A company is bankrupt or cannot pay its debts, but the most
recently issued auditor’s report indicates that the financial statements
were fairly stated. In this case, statement users commonly claim that
an audit failure has occurred, but actually this is a business failure.
 some users even believe that the auditor guarantees the financial
viability of the business. (expectation gap)
 The situation will be even worse, if a business failure happens and
the financial statements are later determined to have been misstated,
users may claim the auditor was negligent even if the audit was
conducted in accordance with auditing standards (due to audit risk).
 This conflict between statement users and auditors often arises
because of an “expectation gap” between users and auditors.
By: Mulu M. 78
..Legal Responsibility & Liability of
Auditors
 Audit Failure: It occurs when the auditor issues an erroneous audit opinion as the
result of an underlying failure to comply with the requirements of generally accepted
auditing standards (GAAS).
 It is a good reason for taking complaints to courts
 the law often allows parties who suffered losses to recover some or all of the losses
caused by the audit failure
 But, the complexity of the auditing process makes it difficult to easily decide on the
existence of failure to comply with GAAS
 Audit Risk: It represents the risk that the auditor will conclude that the financial
statements are fairly stated and an unqualified opinion can be issued when, in fact,
they are materially misstated.
 This is unavoidable, since audits are performed on test basis (sample);
 So, it may occur even if an audit is conducted as per GAAS.
 Auditors can not give guarantee that financial statements are accurate, they can
give only a reasonable assurance, but some users expect auditors to give guarantee
about the accuracy of financial statements (expectation gap)-another cause for
Audting Part I 79
Assess Materiality and Determine Acceptable &
Inherent Audit Risks
80

 AUDIT RISK: The second standard of fieldwork


requires the auditor to obtain an understanding of the
entity and its environment, including its internal
control, to assess the risk of material misstatements in
the client’s financial statements.
 Risk, in auditing, is defined as some level of uncertainty
that an auditor accept in performing the audit function.
 Audit Risk Model: The audit risk model is used
primary for planning purpose in deciding how much and
type of evidence
AAR = PDR Xto
CR accumulate
X IR in each side. The audit
risk model is stated as follows:
AAR
PDR 
CR x IR

By: Mulu.M Saturday, November 15, 2025


AUDIT RISK MODEL COMPONENTS
81
 Planned detection risk (PDR) is the risk that audit evidence for a
segment will fail to detect misstatements exceeding tolerable
misstatement.
 Planned detection risk is dependent on the other three factors in the
model. It will change only if the auditor changes one of the other risk
model factors.
 Planned detection risk determines the amount of substantive evidence that the
auditor plans to accumulate, inversely with the size of planned detection risk.
 If planned detection risk is reduced, the auditor needs to accumulate
more evidence to achieve the reduced planned risk.
 Detection risk is usually grouped into two categories –substantive tests of
details and other substantive procedures.
 Substantive test of details risk (STDR) – the risk that one key substantive
test (usually a sample) will fail to detect material error. For example,
inappropriate sample size determination.
 Other substantive procedures risk (OSPR) – the risk that the auditor’s
analytical procedures and all of his/her other substantive tests directed at
the same component/assertion/objective will fail to detect material error.
By: Mulu.M Saturday, November 15, 2025
Assess Materiality and Determine Acceptable &
Inherent Audit Risks
82
 Inherent Risk (IR): Inherent risk measures the auditor’s
assessment of the likelihood that there are material
misstatements due to error or fraud in a segment before
considering the effectiveness of internal control.
 If the auditor concludes that a high likelihood of misstatement
exists, the auditor will conclude that inherent risk is high.
 Internal controls are ignored in setting inherent risk because
they are considered separately in the audit risk model as control
risk.
 Inherent risk is inversely related to planned detection risk and
directly related to evidence.
 For example, if inherent risk for inventory obsolescence is
extremely high, it makes sense for the CPA firm to assign an
experienced staff person to perform more extensive tests for
inventory obsolescence and to more carefully review the audit
results.
By: Mulu.M Saturday, November 15, 2025
Audit planning process - Assess Materiality and
Determine Acceptable & Inherent Audit Risks
83

Factors Affecting Inherent Risk


 The auditor must assess the factors that make up the
risk and modify audit evidence to take them into
consideration. The auditor should consider several
major factors when assessing inherent risk:
 Nature of the client’s business
 Results of previous audits
 Initial versus repeat engagement
 Related parties
 Non-routine transactions
 Judgment required to correctly record account balances
and transactions
 Factors related to fraudulent financial reporting
 Factors related to misappropriation of assets
By: Mulu.M Saturday, November 15, 2025
Audit planning process - Assess Materiality and
Determine Acceptable & Inherent Audit Risks
84

Control Risk (CR): Control risk measures the auditor’s


assessment of whether misstatements exceeding a tolerable
amount in a segment will be prevented or detected on a
timely basis by the client’s internal controls.
 Control risk is the risk that client controls fail to detect
material misstatements.
 Assume that the auditor concludes that internal controls
are completely ineffective to prevent or detect
misstatements.
 The auditor will therefore assign a high, perhaps 100
percent, risk factor to control risk.
 The more effective the internal controls, the lower the risk
factor that can be assigned to control risk.
 The more effective the internal controls, the lower the risk
factor that can be assigned to control risk.
By: Mulu.M Saturday, November 15, 2025
Audit planning process - Assess Materiality and
Determine Acceptable & Inherent Audit Risks
85

 The more effective the internal controls, the lower


the risk factor that can be assigned to control risk.
 The audit risk model shows the close relationship
between inherent and control risks.
 The combination of inherent risk and control risk is
referred to in auditing standards as the risk of
material misstatement.

By: Mulu.M Saturday, November 15, 2025


Audit planning process - Assess Materiality and
Determine Acceptable & Inherent Audit Risks
86
 As with inherent risk, the relationship between control risk and
planned detection risk is inverse, whereas the relationship
between control risk and substantive evidence is direct.
 If the auditor concludes that internal controls are effective,
planned detection risk can be increased and evidence
therefore decreased.
 The auditor can increase planned detection risk when controls
are effective because effective internal controls reduce the
likelihood of misstatements in the financial statements.
 Acceptable Audit Risk (AAR): Acceptable audit risk is a
measure of how willing the auditor is to accept that the
financial statements may be materially misstated after the
audit is completed and an unqualified opinion has been issued.
 When auditors decide on a lower acceptable audit risk, they
want to be more certain that the financial statements are not
materially misstated.
By: Mulu.M Saturday, November 15, 2025
Audit planning process - Assess Materiality and
Determine Acceptable & Inherent Audit Risks
87
 Zero risk is certainty, and a 100 percent risk is complete
uncertainty.
 Complete assurance (zero risk) of the accuracy of the
financial statements is not economically practical.
 Audit assurance or any of the equivalent terms is the
complement of acceptable audit risk, that is, one minus
acceptable audit risk. In other words, acceptable audit risk of
2 percent is the same as audit assurance of 98 percent.
 Example: Assume the following risks expected by Mr. A,
auditor for XYZ Company and ABC Company respectively.
a) IR = 100% CR = 100% AAR = 5% XYZ Co.
b) IR = 10% CR = 10% AAR = 5% ABC Co.

 Required: calculate planned detection risk

By: Mulu.M Saturday, November 15, 2025


Audit planning process - Assess Materiality and
Determine Acceptable & Inherent Audit Risks
88

RISK Vs EVIDENCES
 Assuming AAR and CR being constant, if IR is high DR will be lower,
and more evidence is needed
 Assuming AAR and IR being constant, if CR is high DR will be lower,
and more evidence is needed
 Assuming AAR being constant, if IR if CR are high DR will be lower, and
more evidence is needed
 Assuming AAR and CR being constant, if IR is low DR will be higher,
and little evidence is needed
 Assuming AAR and IR being constant, if CR is low DR will be higher,
and little evidence is needed
 Assuming AAR being constant, if IR and CR are low DR will be higher,
and little evidence is needed
 Assuming IR and CR being constant, if AAR is high DR will be higher,
and little evidence is needed
 Assuming IR and CR being constant, if AAR is low DR will be lower, and
more evidence is needed.
By: Mulu.M Saturday, November 15, 2025
n d
e E !
h u
T yo
n k
h a
T

You might also like