Chapter 3
Planning and Conducting the Audit
Chapter objectives
This chapter aims at discussing:
The need for adequate audit planning
How client acceptance decisions are made
How to perform initial audit planning.
The need for understanding the client’s business and
industry for proper planning
The purposes of audit documentation.
How organized audit documentation is prepared.
Auditing Part I 1
3.1 Need for Audit
Planning
3.1 Need for Audit planning
Auditing is a task which involves risk, thus proper planning is
essential.
Knowledge of client’s business is very important part of planning; it
helps to reduce risk associated with the client.
Benefits of planning engagements:
[Link] obtain sufficient appropriate evidence
2. To keep audit costs reasonable
3. To avoid misunderstandings with the client
Proper planning helps to avoid two extremes: under audit (which increases
auditors risk of legal liability) and over audit (which results in high cost of
audit/inefficiency).
Auditing Part I 2
…3.1 Need for Audit
Planning
The major part of audit planning include
Preliminary risk assessment and
Preliminary analytical procedures
Preliminary risk assessment
This is done to minimize the possibility of not
detecting an error/fraud
Much of audit planning is used :
To assess the level of risk which is normal/acceptable
To exclude any non acceptable risk
Auditing Part I 3
…3.1 Need for Audit
Planning
The auditing profession has no official standards for an
acceptable level of overall audit risk, except that it should
be “acceptably low”
Zero risk is certainty,
A 100 percent risk is complete uncertainty.
Planning the audit helps to keep the risk with in
acceptable/normal limit
When auditors prefer lower acceptable audit risk, it
means that they want to be more certain that the
financial statements are not materially misstated and
vise versa.
Auditing Part I 4
…3.1 Need for Audit
Planning
Factors indicating that risk is above normal:
New business area/high technology sector
Poor accounting system, with little/no internal controls
Dominance by a single person (no separation of duty)
Strong possibility of management override
Problems inherent in the nature of business-eg. Direct
cash payments to the beneficiaries from public fund
Auditing Part I 5
3.2 Parts of Audit Planning
Eight Major Parts of Audit Planning
1. Accept 2.
client and Understand 3. Assess
perform the client’s client's business
initial business risk
planning industry
5. Set
4. Perform Materiality 6. Understand
Preliminary & Assess Internal Control
Analytical Inherent & & Assess Control
Procedures Business Risk
Risk
7. Gather
Information to 8. Develop Overall
Assess Fraud Audit Plan & Audit
Risk program
Auditing Part I 6
3.2.1 Preplanning the Audit
I. Preplanning the Audit- it involves the
following four issues:
1. Decision to accept new client or continue serving
an existing
2. Identifying why the client needs an audit.
[Link] an understanding of the client about the
terms of the engagement
4. Developing an overall strategy for the audit,
including engagement staffing and any required
audit specialists.
Auditing Part I 7
..3.2 .1 Preplanning the
audit
1. Client Acceptance/continuance decision
is a decision that is made before incurring any significant costs
that cannot be recovered.
General Information needed
▪ About client's reputation/integrity
▪ Does it complain about auditing procedures, does it tried to cheat auditors etc -
Accepting such clients will be more risky
About risk factors
Is the client’s business involve high risk (eg a high-
technology sector such as software development, insurance
industry, health etc) -Accepting such clients will be more risky
Auditing Part I 8
..3.2 .1 Preplanning the
audit
…..1. Client Acceptance/continuance decision
An auditor is unlikely to accept a new client or continue
serving an existing client, if acceptable audit risk is below
the risk threshold the firm is willing to accept.
Information required about new/prospective client
Standing in the business community- Source : eg. attorney
Financial stability (financial strength-financial history, credit rating),
Source : eg. banker
Relations with its previous auditor.
▪ Source : previous audit firm (This firm should obtain
permission from the client to provide information to adhere to
the rule of confidentiality)
Auditing Part I 9
..3.2 .1 Preplanning the
audit
…..1. Client Acceptance/continuance decision
Obtaining information from previous Audit firm
Auditing standards require the new (successor) auditor to
communicate with the predecessor auditor. (communication is
initiated by the new/successor auditor).
Though the burden of initiating the communication rests with the
successor auditor, the predecessor auditor is required to respond to
the request for information, with client’s permission.
Information is usually about: Whether the client lacks integrity,
about the existence of disputes over accounting principles, audit
procedures, or fees.
Auditing Part I 10
..3.2 .1 Preplanning the
audit
…..1. Client Acceptance/continuance decision
What if unusual circumstances such as legal problems or disputes
between the client and the predecessor exists? Will complete
information be available?
The predecessor’s response can be limited to stating that no information will be
provided.
What if client will not permit the communication or the predecessor will not
provide a comprehensive response?
In general, in such unusual cases, it is not advisable to accept the new client
without further investigation and gathering of information eg from local
attorneys, other CPAs, banks, and other businesses.
Even, a professional investigator may be hired to obtain more information
about the reputation and background of key members of management
especially, when there has been no previous auditor to provide
information Auditing Part I 11
..3.2 .1 Preplanning the
audit
…..1. Client Acceptance/continuance decision
Major factors considered in deciding to drop/not to drop an existing client:
Previous conflicts on issues such as scope of the audit, the type of opinion to
issue, unpaid fees, or other matters
Client lack of integrity
Presence of excessive risk
Eg. If regulatory conflict exists between a governmental agency and a
client, which could result in financial failure of the client and ultimately
lawsuits against the CPA firm, the auditor will decide not to accept
engagement even if it is profitable, since the long-term risk may exceed
the short-term benefits of doing the audit.
Investigating new clients and reevaluating existing ones is an essential part of
deciding acceptable audit risk.
Auditing Part I 12
..3.2 .1 Preplanning the
audit
Result of the New Client Investigation
A potential client operates in a reasonably risky industry, but
its management has a reputation of integrity, and also known to
take aggressive financial risks.
Will the client be accepted?
1. No Acceptance 2. Accept
If the CPA firm decides that Even if acceptable audit risk is low but
acceptable audit risk is extremely low the audit firm will increase the fee
proposed to the client.
Audits with a low acceptable audit risk will normally result in
higher audit costs, which should be reflected in higher audit fees.
Auditing Part I 13
..3.2 .1 Preplanning the
audit
2. Identifying Client’s Reasons for Audit
Knowledge of statement users and their intended
uses of the statements affect the decision on
acceptable audit risk.
The auditor is likely to accumulate more evidence:
-when the statements are to be used extensively, eg
in the case of publicly held companies, those with
extensive indebtedness, and companies that are to
be sold in the near future.
Auditing Part I 14
..3.2 .1 Preplanning the
audit
3. Obtaining an understanding of the client about the terms of
the engagement (This helps avoid misunderstandings)
A clear understanding of the terms of the engagement should exist
between the client and the auditor.
Auditing standards require that auditors document their
understanding with the client in an engagement letter, including:
▪ the engagement’s objectives, the responsibilities of the auditor
and management, about assistants to be assigned for the
auditor (data providers), fees, impositions like deadline for the
work, and the engagement’s limitations (to inform what
auditors are not responsible for eg guaranteeing for complete
discovery of fraud).
Auditing Part I 15
..3.2 .1 Preplanning the
audit
4. Develop Overall Audit Strategy
After understanding the client’s reasons for the audit, the auditor should develop a
preliminary audit strategy.
This strategy helps the auditor determine the resources required for the engagement,
including engagement staffing.
The auditor must assign the appropriate staff (skilled, experienced) to the
engagement:
- to meet International auditing standards and
-to promote audit efficiency
Major decisions in staffing:
1. Should staff continuity exist from year to year?
Advantage of Continuity:
To maintain familiarity with the technical requirements and
To have closer interpersonal relations with client personnel
Inexperienced staff will acquire more experience
Auditing Part I 16
..3.2 .1 Preplanning the
audit
2. Another major staffing decision is about the need for
outside specialists, should they be invited/not?
Decision: understand the nature of business, then call for
outside specialists if no one within the firm is qualified to
evaluate a certain evidence important for the audit
Auditor’s responsibility:
To evaluate the specialist’s professional qualifications and
understand the objectives and scope of the specialist’s work.
To consider the specialist’s relationship to the client, including
circumstances that might impair the specialist’s objectivity.
Auditing Part I 17
3.2.2 Obtaining Background
Information
II. Understand the Client’s Business and Industry
A through understanding of the client’s business and industry is
essential to conduct an adequate audit.
Reasons for Understanding Clients Business & Industry:
Many industries have unique accounting requirement that
the auditor must understand to evaluate whether the client’s
F/Ss are in accordance with applicable financial reporting.
Risks in the industry has an effect on the auditor’s
assessment of acceptable audit risk (client 'acceptance
decision).
There are inherent risks that are typically common to all
clients in certain industries.
Auditing Part I 18
….3.2.2 Obtaining Background
Information
Understanding Clients Business & Industry
requires the auditors to know about:
1. Industry & External Environment
2. Business Operations & Practices
3. Management & Governance
4. Objectives & Strategies
5. Measurement & Performance
Auditing Part I 19
….3.2.2 Obtaining Background
Information
1. Knowledge of Industry & External Environment
It helps the auditor to identify risks associated with
specific industries –assists client acceptance decision
2. Knowledge of Business Operations & Practices .
How to have it?
-Touring/visiting client facilities and operations
Advantage:
▪ to have better understanding of the operations and meet client's
employees
▪ To assess physical safeguards of assets
▪ To identify unused assets (equipments and inventories)
In general, it enables the auditor to assess inherent risks
Auditing Part I 20
….3.2.2 Obtaining Background Information
3. Knowledge about Client's Management and Governance
Assessment of management’s philosophy and
operating style, its ability to identify and respond to
risk, are important since they influence the risk of
material misstatements in the financial statements.
Information about client’s governance system is
obtained from:
Corporate bylaws
Code of ethics
Minutes of meetings of boards
Auditing Part I 21
….3.2.2 Obtaining Background
Information
4. Knowledge about Client Objectives and Strategies
Knowledge of client objectives and strategies helps the auditor to
assess client business risk and inherent risk in the financial statements.
Eg product quality can have a significant impact on the financial
statements through lost sales and through warranty and product
liability claims.
Knowledge of client's objectives and strategies also help the auditor to
know matters for which compliance is checked such as:
contracts and other legal obligations including long-term notes and bonds
payable, stock options, pension plans, contracts with vendors for future delivery
of supplies, government contracts for completion and delivery of manufactured
products, royalty agreements, union contracts, and leases.
Auditing Part I 22
….3.2.2 Obtaining Background Information
5. Knowledge about Client’s Measurement and
Performance
Performance indicators include non-financial items such as market
share, sales per employee etc
Inherent risk of F/S misstatements may increase if the client has set
unreasonable performance measurement system that encourages
aggressive accounting.
Eg: Objective-leading market share of industry
Reward- based on the volume of sales
This may lead to the recording of sales before they have been earned or
recording sales for nonexistent transactions.
Thus, auditor is likely to increase assessed inherent risk, increase the
extent of testing for the occurrence transaction-related audit objective for
sales. Auditing Part I 23
3.2.3 Assess Client’s Business Risk
3. Assess Client’s Business Risk
Knowledge gained from the understanding of the client’s
business and industry is used to assess client business
risk-the risk that the client will fail to achieve its
objectives.
Sources of Business Risk: -
Significant declines in the economy that threaten the client’s
cash flows,
New technology eroding a client’s competitive advantage, or
Client’s failure to execute its strategies as well as its
competitors.
Auditing Part I 24
3.2.4 Performing Preliminary Analytical Reviews
4. Perform Preliminary Analytical Procedures
Analytical procedures used in planning are often based on aggregate,
companywide data.
They are used to gain better understanding of the client’s business and to assess
client business risk, they serve as attention directing tools
Eg. Comparison of client’s ratios to industry or competitor benchmarks to
provide an indication of the company’s performance.
Computing ratios indicating
short-term debt paying ability (liquidity)
ability to meet long-term obligations and preferred dividends ,
activity and profitability ratios etc.
Such preliminary tests can reveal unusual changes in ratios compared to prior
years, or to industry averages, and help the auditor identify areas with increased
risk of misstatements that require further attention during the audit.
Auditing Part I 25
3.3 Audit Program
An Audit program
An audit program is a collection of audit procedures for an audit
area or an entire audit (for a component of F/S or entire F/S),
each including sample size, item to choose and the timing of the
sample
Preparation of an audit program is part of planning an audit.
It shows the steps in the audit process that helps to achieve the
audit objectives, the work that has to be done
It is prepared for each component of an audit to guide the
auditor: What procedure to apply, When to apply the
procedure, How to apply and so on
It is used as a base to assign auditors and also follow up the work
It also reduces supervisor’s time spent on guiding new auditors
k
Auditing Part I 26
3.4 Audit Documentation/Audit
Working papers
Audit documentation/working papers are the connecting link
between the client’s accounting records and the audit report.
They contain all of the work done by the auditor and provide
justification for the audit report.
They contain:
audit procedures applied,
evidence obtained, and
conclusions reached by the auditor in the engagement.
Working papers should include all information relevant to express
an opinion on the fairness of financial statements.
Auditing Part I 27
….Audit Documentation
Audit files should document:
Items tested if samples of transactions/balances are
tested
Significant audit findings or issues,
Actions taken to address them and the basis for the
conclusions reached
Eg. documenting significant misstatements in
account balance, procedures performed including
adjustments made, and conclusions whether the
account balances affected are fairly stated, and
whether any audit adjustments should be proposed.
Auditing Part I 28
….Audit Documentation
Purpose of Audit Documentation
The overall objective of audit documentation is to aid the auditor in providing
reasonable assurance that an adequate audit was conducted in accordance with ISA.
Working papers assist auditors in several ways:
1. They provide information to plan current audit, (provide a means of assigning and
coordinating audit works )
-most audit works require joint efforts, so working papers coordinates the efforts of
auditors assigned on different areas of the audit
2. They aid seniors, managers, and partners in supervising and reviewing the work
of assistants
-Working papers completed by staff assistants are reviewed at successive levels i.e, by the senior, by the
manger, and finally by the partner
Reviews at different levels provide assurance that the work of the audit staff is carefully reviewed and
supervised
After each review is completed, the reviewer sill put signature on the working paper
Auditing Part I 29
….Audit Documentation
….. Purpose of Audit Documentation
3. They serve as a base for determining the
proper type of audit report
Partners (owners of the audit firm) know
that issuing an opinion on financial statement
has some risk, so they want to ascertain that
the working paper contains sufficient
competent evidence that justify the report
Auditing Part I 30
….Audit Documentation
….Purpose of Audit Documentation
4. They document the evidences accumulated and results of
tests
Working papers are means by which auditors can
demonstrate their compliance with the ISA, and defend their
work when ordered by regulatory agencies such as courts.
Thus working papers should document:
Adequate planning and proper supervision of assistants,
Proper understanding of internal control system, and
Gathering of appropriate and sufficient evidences to show that the
audit was properly conducted.
Auditing Part I 31
….Audit Documentation
…. Purpose of Audit Documentation
[Link] provide a base for planning and conducting future
audits of the client
eg they provide information about the time spent on each
activity, the nature of the client internal control
system,
In addition they provide information useful:
To prepare tax returns
To recommend improvements on the existing internal
control system
To new auditors on how to prepare and organize working
papers
Auditing Part I 32
Ownership of Audit files
Who owns Audit file, Audit Firm/client?
Audit documentation/working papers, including schedules
prepare by the client, are the property of the auditors not of
the client.
The only time anyone else, including the client, has a legal
right to examine the files is when they are subpoenaed
(demanded) by a court as legal evidence.
At the completion of the engagement, audit files are retained
with the audit firm for future reference and to comply with
auditing standards related to document retention.
Auditors may allow clients to refer to some important data
on the working paper
Auditing Part I 33
Confidentiality of Audit
files
Confidentiality of Audit files
Auditors working papers usually contain a considerable
amount of information of a confidential nature.
‘A member shall not disclose any confidential information
obtained in the course of a professional engagement except
with the consent of the client’.
Audit files should be kept with care, if it is accessible to all,
there is a risk of alteration by clients employees, leakage of
confidential information to client's employees and also to
outsiders
Thus audit working papers are highly confidential, must be
safeguarded at all times (eg. keeping in lock)
Auditing Part I 34
For how long should auditors keep
working papers?
For how long should auditors keep working papers?
Auditing standards require that records for audits of
private companies be retained for a minimum of five
years.
The Sarbanes–Oxley Act requires auditors of public
companies to prepare and maintain audit files and
other information related to any audit report for a
period of not less than seven years.
The law considers deliberate destruction of audit files
as a crime
Auditing Part I 35