Showing posts with label ISA 315. Show all posts
Showing posts with label ISA 315. Show all posts

Sunday, August 15, 2010

Risk Assessment Procedures and Related Activities

ISA 315, Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment, para. 5 to 10 prescribes the audit risk assessment procedures and related activities.

The auditor shall perform risk assessment procedures to provide a basis for the identification and assessment of risks of material misstatement at the financial statement and assertion levels. Risk assessment procedures by themselves, however, do not provide sufficient appropriate audit evidence on which to base the audit opinion.

The risk assessment procedures shall include the following :

(a)  Inquiries of management, and of others within the entity who in the auditor's judgment may have information that is likely to assist in identifying risks of material misstatement due to fraud or error. Much of the information obtained by the auditor's inquiries is obtained from management and those responsible for financial reporting. However, the auditor may also obtain information, or a different perspective in identifying risks of material misstatement, through inquiries of others within the entity and other employees with different levels of authority.

(b)  Analytical procedures; the analytical procedures performed as risk assessment procedures may identify aspects of the entity of which the auditor was unaware and may assist in assessing the risk of material misstatement in order to provide a basis for designing and implementing responses to the assessed risks. Analytical procedures performed as risk assessment procedures may include both financial and non-financial information, for example, the relationship between sales and square footage of selling space or volume of goods sold.

(c)  Observation and inspection; the observation and inspection procedures may support inquiries of management and others, and may also provide information about the entity and its environment. Examples of such audit procedures include observation or inspection of the following : (i) the entity's operations, (ii) documents (such as business plans and strategies), records, and internal control manuals, (iii) reports prepared by management (such as quarterly management reports and interim financial statements) and those charged with governance (such as minutes of board of directors' meetings), (iv) the entity's premises and plant facilities.

The auditor shall consider whether information obtained from the auditor's client acceptance or continuance process is relevant to identifying risks of material misstatement.

If the engagement partner has performed other engagements for the entity, the engagement partner shall consider whether information obtained is relevant to identifying risks of material misstatement.

Where the auditor intends to use information obtained from the auditor's previous experience with the entity and from audit procedures performed in previous audits, the auditor shall determine whether changes have occurred since the previous audit that may affect its relevance to the current audit. This is because changes in the control environment, for example, may affect the relevance of information obtained in the prior year. To determine whether changes have occurred that may affect the relevance of such information, the auditor may make inquiries and perform other appropriate audit procedures, such as walk-through of relevant systems.

The auditor's previous experience with the entity and audit procedures performed in previous audits may provide the auditor with information about such matters as : (i) past misstatements and whether they were corrected on a timely basis, (ii) the nature of the entity and its environment, and the entity's internal control (including deficiencies in internal control), (iii) significant changes that the entity or its operations may have undergone since the prior financial period, which may assist the auditor in gaining a sufficient understanding of the entity to identify and assess risks of material misstatement.

Further, the standard states that the engagement partner and other key engagement team members shall discuss the susceptibility of the entity's financial statements to material misstatement, and the application of the applicable financial reporting framework to the entity's facts and circumstances. The engagement partner shall determine which matters are to be communicated to engagement team members not involved in the discussion (Hrd) ***

Monday, August 2, 2010

IAASB proposed enhanced standard on using the work of Internal Auditors, revised to ISA 315 and ISA 610

On July 15, 2010, IAASB issued an Exposure Draft (ED) for the proposed revision of ISA 610, Using the Work of Internal Auditors. The standard is being revised in recognition of developments in the internal auditing environment as well as the evolving relationship between internal and external auditors. As a result of the revision of ISA 610, changes are also being proposed to ISA 315, Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment.

The IAASB's objective in revising ISA 315 and ISA 610 is to enhance the performance of external auditors by, (a) enabling them to better consider and leverage, as appropriate, the knowledge and findings of an entity's internal audit function in making risk assessments in the external audit, and (b) strengthening the framework for the evaluation and, where appropriate, use the work of internal auditors in obtaining audit evidence. The IAASB believes that the proposed revision will enhance the quality of audits internationally.

In determining whether the work of the Internal Audit function can be used, the IAASB proposes that the external auditor's initial assessment should be based on an evaluation of the internal audit function's degree of objectivity (as supported by its organization status, and relevant policies and procedures), level of competence and application of a systematic and disciplined approach, including quality control. The related requirements and guidance on factors to consider in making this evaluation have been updated to reflect developments in internal audit practice.

In some jurisdictions, internal auditors provide direct assistance to the external auditor through performance of audit procedures on the audit engagement under the direction, supervision, and review of the external auditor. Extant ISA 610 states explicitly that it does not deal with such instances. There is ambiguity about whether the fact that ISA 610 does not deal with direct assistance meant that the IAASB does not support its use, or whether it was simply not addressed in the scope of the ISA. However, national auditing standards of a number of jurisdictions allow for direct assistance, and it is common practice in many; while in others, it is not allowed. The IAASB concluded that continued ambiguity about its intent is not in the public's interest.

The IAASB believes, that, the proposed requirements will :

(a)  provide a framework for determining the nature and extent of the work of the internal audit function that can justifiably the used in the external audit; and

(b)  set out clear boundaries to guard against use of the work of the internal audit function in circumstances in which it would be inappropriate.

Comments for this ED are requested by November 15, 2010. Respondents are asked to submit their comments electronically through the IAASB website (www.iaasb.org), using the "Submit a Comment" link on the Exposure Draft and Consultation Papers page.

Comments can also be faxed to the attention of the IAASB Technical Director at +1 (212) 856-9420, or mailed to : Technical Director - International Auditing and Assurance Standards Board, 545 Fifth Avenue, 14th Floor, New York, New York 10017 USA.

Copies of the exposure draft may be downloaded free of charge from the IAASB website at www.iaasb.org, or just follow the download link in here : Proposed ISA 315 (Revised), Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and its Environment, and ISA 610 (Revised), Using the Work of Internal Auditors

Monday, July 12, 2010

Audit Risk Model, an introduction

ISA 315 states that the auditor should identify and assess the risks of material misstatement of the financial statement level, and  at the assertion level for classes of transactions, account balances, and disclosures.

Audit risk, as it directly affects the specific audit approach to the engagement, is generally considered at the account balance or class of transaction level.

At this level, audit risk consists of :

  • The risk (consisting of inherent and control risk) that the account balance or class of transactions contain misstatements  that could be material to the financial statements whether individually or when aggregated with misstatements in other balances or classes.
  • the risk (detection risk) that the auditor will not detect such misstatements.

Audit Risk Model :  AR = IR X CR X DR, where AR = Audit Risk, IR = Inherent Risk, CR = Control Risk, DR = Detection Risk

INHERENT RISK

Inherent risk is the susceptibility of an account balance or class of transactions to material misstatement, individually or when aggregated with misstatements in other balances or classes assuming that there were no related internal controls. The inherent risk of misstatement is greater for some types of transactions or accounts than for others. For example :

  • Account balances and transactions subject to complex calculations are more susceptible to error than those based on simple calculations.
  • Assets such as cash are more susceptible to theft than assets such as fixed assets.
  • Account balances subject to judgment and estimation are more likely to be misstated than account balances based on historical, factual data.

CONTROL RISK

Control risk is the risk that a misstatement, that could occur in an account balance or class of transactions and that could be material individually or when aggregated with misstatements in other balances or classes, will not be prevented or detected and corrected on a timely basis by the accounting and internal control systems.

Control risk will vary inversely with the level of effectiveness of the internal control structure. However, because of the inherent limitations of any internal control structure (e.g. those due to human error), there will always be some level of control risk within internal control structure.

It is often difficult to distinguish between inherent and control risk because of the close relationship between the two.

Assume, for example, the auditor believes there is a 50 percent inherent risk that inventory is misstated by more than tolerable error because of technological changes that have taken place in the client's industry during the past year. The auditor also concludes that internal accounting controls are sufficiently effective to assign a control risk of 30 percent.  Using a portion of the audit risk model, AR = IR X CR X DR, the likelihood of an error occurring is 15 percent (IR X CR = 50% X 30%).

Before an auditor can use a control risk of less than 100 percent, he is required to do two things : evaluate how well a client's internal control system functions and test the system for effectiveness.

DETECTION RISK

Detection risk is the risk that auditor's substantive procedures will not detect a misstatement that exist in an account balance or class of transactions that could be material, individually or when aggregated with misstatements in other balances or classes.

Detection risk is a function of the effectiveness of auditor's audit procedures and how well the auditor apply them. Such risk exists partly because auditor typically examine less than 100% of an entity's transactions (sampling risk) and partly because auditor may select inappropriate audit procedures, apply audit procedures incorrectly, or misinterpret the results of audit procedures.

The level of detection risk that auditor can accept varies inversely with the level of inherent and control risk. The higher the inherent and control risk, the less detection risk that auditor can accept to keep the risk of material misstatement at an acceptably low level.

The less detection risk that auditor can accept, the more reliable of substantive procedures must be.

Using the example discussed in the control risk section, assume there was a detection risk of 20 %. The audit risk is therefore 3 % (IR X CR X DR = 0,50 x 0,30 x 0,20). The auditor can conclude there is a 3 percent risk that inventory is misstated by more than tolerable error. This conclusion is based upon the assumption that the auditor can measure the component risks in a precise manner (Hrd) ***

Saturday, July 10, 2010

WHY We Need to Know the Client's Business ?

Obtaining an understanding of the client’s business is key to an effective and efficient audit. It enables us not only to tailor our work to meet the individual facts and circumstances of each client, but also to carry out that work and to evaluate our findings in an informed manner. Our knowledge of the client’s business also helps us to develop and maintain a positive professional relationship with the client.

International Standards on Auditing (ISA) 315 states that the auditor should obtain an understanding of the entity and its environment, including its internal control, sufficient to identify and assess the risks of material misstatement of the financial statements whether due to fraud or error, and sufficient to design and perform further audit procedures.

Understanding the entity is an iterative process, continuing throughout the entire duration of the audit.

Prior the accepting an audit engagement, we should obtain a preliminary knowledge of the industry and of the ownership, management and operations of the entity to be audited.

Detailed information is required at the planning stage of our audit to enable us to plan our work adequately. We need to understand the nature of client’s business, its organization, its method of operation and the industry in which it is involved. This understanding enables us to appreciate which events and transactions are likely to have a significant effect on the financial statements.

Specifically, such an understanding helps us to :

  • Identify the areas of high risk where we should concentrate our audit effort
  • Maximize efficiency in other areas of audit significance
  • Assess the potential for use of analytical procedures, by enabling us to identify the information which we can use to make predictions and comparisons
  • Obtain an understanding of the internal control structure
  • Assess the inherent and control risks in the key areas of audit significance
  • Develop an audit strategy enabling us to obtain the necessary audit evidence in the most effective and efficient manner possible.

Knowing the client’s business helps us in a number of ways both during the conduct of the audit, and when we come to complete our work.

This includes, for example, helping us in :

  • Recognising errors in the financial statements
  • Asking the right questions and evaluating the reasonableness of the answers we receive
  • Making judgements about the appropriateness of the client’s accounting principles, policies and procedures
  • Identifying unusual or unexpected transactions and related party transactions
  • Interpreting the results of audit tests and evaluating their effect
  • Carrying out appropriate procedures to review events occurring after the balance sheet date
  • Carrying out an overall review of the financial statements.

Knowledge of the client’s business and the industry in which it operates is essential also to the development of a positive relationship and it helps us as follows :

  • In understanding the management’s philosophy and aspirations for the business
  • Understanding the business strategy and plans
  • Providing relevant and practical business advice to the client
  • Identifying areas in which the client might benefit from other professional services which we provide.

ISA 315 states that :

  • the auditor should obtain an understanding of relevant industry, regulatory, and other external factors including the applicable financial reporting framework
  • the auditor should obtain an understanding of the nature of the entity
  • the auditor should obtain an understanding of the entity's selection and application of accounting policies and consider whether they are appropriate for its business and consistent with the applicable financial reporting framework and accounting policies used in the relevant industry
  • the auditor should obtain an understanding of the entity's objectives and strategies, and the related business risks that may result in material misstatement of the financial statements
  • the auditor should obtain an understanding of the measurement and review of the entity's financial performance.

Each year, the auditor's understanding of the entity should be updated and details of significant changes documented (Hrd) ***