Showing posts with label Audit Risk. Show all posts
Showing posts with label Audit Risk. Show all posts

Saturday, December 11, 2010

Audit Risk and Materiality – Desired and Achieved Audit Risk

Audit risk is the risk that the financial statements are materially misstated and the auditor fails to detect such a misstatement.

Audit risk and materiality are closely related. Materiality must be established before audit risk has any meaning. For example, a 4% risk of a $20,000 misstatement of income has a completely different meaning than a 4% risk of a $200,000 misstatement.

Desired audit risk is the subjectively determined risk that the auditor is willing to take that the financial statements are not fairly stated after the audit is completed and an unqualified opinion has been reached. The lower the desired audit risk, the more sure the auditor wants to be that the financial statements are not materially misstated. Zero risk would be certainty, and a 100% risk would be complete uncertainty. Audit risk can range anywhere from zero to one (0 to 100 percent), but no more or less. Complete assurance (zero risk) of the accuracy of the financial statements is not economically practical. The auditor cannot guarantee the complete absence of material errors and irregularities.

The concept of desired audit risk can be more easily understood by thinking in terms of a large number of audits, say ten thousand. What portion of these audits could include material errors without having an adverse effect on society? Certainly, the portion would be below ten percent. It is probably much closer to one or one-half of 1% or perhaps even one-tenth of 1%. If an auditor feels the appropriate percentage for a given audit is one, desired audit risk is 1%.

Achieved audit risk is the actual level of risk, after the audit is completed and an unqualified opinion issued, that the statements are materially misstated. Achieved risk must be less than desired risk or the auditor should not issue an unqualified opinion.

The auditor achieves a reduction of audit risk by gathering evidence. The lower the desired audit risk, the more evidence the auditor must obtain. Since an increased amount of evidence means increased cost, the decision concerning the proper audit risk is one of cost versus benefit. The important question is : at what point does the cost of acquiring more evidence exceed the benefit obtained from the additional information? When the desired risk is reached, the auditor should stop accumulating evidence.

The auditor will have sufficient competent evidence when the achieved audit risk equals desired audit risk. Lower audit risk could be achieved, but cost would be increased.

If the auditor believes the additional cost exceeds the additional benefit from continuing the accumulate evidence, but audit risk is still not satisfactory, he has several options. He may negotiate for a higher audit fee, issue a disclaimer of opinion, bear the additional costs himself, or withdraw from the engagement (Hrd).

Source of this article : Auditing – An Integrated Approach, Alvin A.Arens & James K. Loebbecke

Thursday, December 9, 2010

The Nature of Audit Risk and Materiality

Audit risk is the risk that the financial statements are materially misstated and the auditor fails to detect such a misstatement. The auditor must perform the audit to reduce audit risk to a low level.

Audit risk is a function of two components :

  1. Risk of material misstatement, which is the risk that an account or disclosure item contains a material misstatement, and
  2. Detection risk, which is the risk that the auditor will not detect such misstatements.

To reduce audit risk to a low level requires the auditor to :

  1. Assess the risk of material misstatement, and, based on that assessment,
  2. Design and perform further audit procedures to reduce overall audit risk to an appropriately low level.

The concept of materiality recognizes that some matters are more important for the fair presentation of the financial statements than others. In performing your audit, you are concerned with matters that, individually or in the aggregate, could be material to the financial statements. Your responsibility is to plan and perform the audit to obtain reasonable assurance that you detect all material misstatement, whether caused by error or fraud.

The accounting standards define Materiality as the magnitude of an omission or misstatement of accounting information that, in light or surrounding circumstances, makes it probable that the judgment of a reasonable person relying on the information would have been changed by the omission or misstatement.

Thus, materiality is influenced by your perception of the needs of financial statement users who will rely on the financial statements to make judgments about your client.

ISA 320 Materiality in Planning and Performing an Audit, in paragraph A1 states that :

In conducting an audit of financial statements, the overall objectives of the auditor are to obtain reasonable assurance about whether the financial statements as a whole are free from material misstatement, whether due to fraud or error, thereby enabling the auditor to express an opinion on whether the financial statements are prepared, in all material respects, in accordance with an applicable financial reporting framework; and to report on the financial statements, and communicate as required by the ISAs, in accordance with the auditor’s findings. The auditor obtains reasonable assurance by obtaining sufficient appropriate audit evidence to reduce audit risk to an acceptably low level.

Audit risk is the risk that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated. Audit risk is a function of the risks of material misstatement and detection risk.

Materiality and audit risk are considered throughout the audit, in particular, when :

  1. Identifying and assessing the risks of material misstatement;
  2. Determining the nature, timing and extent of further audit procedures; and
  3. Evaluating the effect of uncorrected misstatements, if any, on the financial statements and in forming the opinion in the auditor’s report.

Source : WILEY – Practitioner’s Guide to GAAS 2010, Steven M.Bragg and ISA 320 Materiality in Planning and Performing an Audit

Tuesday, October 5, 2010

A guide to an initial assessment of Control Risk

Control Risk is the risk that a material error in an account will not be prevented or detected on a timely basis by the client’s internal control structure.

Assessing control risk is the process of evaluating the effectiveness of an entity’s internal control structure in preventing or detecting material misstatements in the financial statements.

Control risk must ultimately be assessed in terms of financial statement assertions. For example, there should be separate assessments of the existence and completeness assertions for sales.

Control risk may be assessed at the maximum level or below the maximum.

An initial assessment of control risk at the maximum occurs when (1) controls do not pertain to an assertion, (2) controls that pertain are unlikely to be effective, or (3) evaluating the effectiveness of relevant controls would be inefficient. An assessment of control risk below the maximum means that there are effective controls to prevent or detect misstatements in a financial statement assertion. The assessment of control risk below the maximum should be based on evidence of the operating effectiveness of the controls.

Control risk may be expressed qualitatively such as low, moderate, or high. Alternatively, the risk may be stated quantitatively as a percentage or a numerical probability such as .75 or 1.0. The initial assessment of control risk starts with the auditor’s understanding of the control environment followed by his knowledge of the accounting system. If management’s attitude toward controls is good, the likelihood of making an initial assessment of control risk below the maximum is enhanced. In some cases, the initial assessment may be based on the effectiveness of the controls in the prior year’s audit, provided that the auditor has determined that such controls are still effective in the current year.

Assessing control risk is a matter of professional judgment. In making the assessment, it is necessary for the auditor to :

  1. Identify misstatements that could occur in financial statement assertions.
  2. Identify the controls that could likely prevent or detect the misstatements.
  3. Obtain evidence from test of controls as to whether the controls are operating effectively.

The first two steps should be performed for all material financial statement assertions. The third step is required only when the auditor assesses control risk below the maximum (Hrd).

Source : Modern Auditing – Walter G. Kell, William C. Boynton & Richard E. Ziegler

Sunday, August 15, 2010

Risk Assessment Procedures and Related Activities

ISA 315, Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment, para. 5 to 10 prescribes the audit risk assessment procedures and related activities.

The auditor shall perform risk assessment procedures to provide a basis for the identification and assessment of risks of material misstatement at the financial statement and assertion levels. Risk assessment procedures by themselves, however, do not provide sufficient appropriate audit evidence on which to base the audit opinion.

The risk assessment procedures shall include the following :

(a)  Inquiries of management, and of others within the entity who in the auditor's judgment may have information that is likely to assist in identifying risks of material misstatement due to fraud or error. Much of the information obtained by the auditor's inquiries is obtained from management and those responsible for financial reporting. However, the auditor may also obtain information, or a different perspective in identifying risks of material misstatement, through inquiries of others within the entity and other employees with different levels of authority.

(b)  Analytical procedures; the analytical procedures performed as risk assessment procedures may identify aspects of the entity of which the auditor was unaware and may assist in assessing the risk of material misstatement in order to provide a basis for designing and implementing responses to the assessed risks. Analytical procedures performed as risk assessment procedures may include both financial and non-financial information, for example, the relationship between sales and square footage of selling space or volume of goods sold.

(c)  Observation and inspection; the observation and inspection procedures may support inquiries of management and others, and may also provide information about the entity and its environment. Examples of such audit procedures include observation or inspection of the following : (i) the entity's operations, (ii) documents (such as business plans and strategies), records, and internal control manuals, (iii) reports prepared by management (such as quarterly management reports and interim financial statements) and those charged with governance (such as minutes of board of directors' meetings), (iv) the entity's premises and plant facilities.

The auditor shall consider whether information obtained from the auditor's client acceptance or continuance process is relevant to identifying risks of material misstatement.

If the engagement partner has performed other engagements for the entity, the engagement partner shall consider whether information obtained is relevant to identifying risks of material misstatement.

Where the auditor intends to use information obtained from the auditor's previous experience with the entity and from audit procedures performed in previous audits, the auditor shall determine whether changes have occurred since the previous audit that may affect its relevance to the current audit. This is because changes in the control environment, for example, may affect the relevance of information obtained in the prior year. To determine whether changes have occurred that may affect the relevance of such information, the auditor may make inquiries and perform other appropriate audit procedures, such as walk-through of relevant systems.

The auditor's previous experience with the entity and audit procedures performed in previous audits may provide the auditor with information about such matters as : (i) past misstatements and whether they were corrected on a timely basis, (ii) the nature of the entity and its environment, and the entity's internal control (including deficiencies in internal control), (iii) significant changes that the entity or its operations may have undergone since the prior financial period, which may assist the auditor in gaining a sufficient understanding of the entity to identify and assess risks of material misstatement.

Further, the standard states that the engagement partner and other key engagement team members shall discuss the susceptibility of the entity's financial statements to material misstatement, and the application of the applicable financial reporting framework to the entity's facts and circumstances. The engagement partner shall determine which matters are to be communicated to engagement team members not involved in the discussion (Hrd) ***

Monday, July 26, 2010

The new rules of Audit Confirmation Process

The Public Company Accounting Oversight Board (PCAOB) on July 13, 2010 approved the publication of a proposed auditing standard regarding Confirmation. In a statement issued with the proposed new standard, PCAOB Acting Chairman Daniel L. Goelzer said the proposal modernizes the current confirmation standard, AU Section 330, The Confirmation Process, and strengthens the confirmation requirements to better protect investors and other users of audited financial statements.

This proposed standard comprises of 36 paragraphs which provides guidance about the confirmation process in audits performed in accordance with generally accepted auditing standards.

It defines the confirmation process (see par. 04), discusses the relationship of confirmation procedures to the auditor’s assessment of audit risk (see par. 05 through 10), describes certain factors that affect the reliability of confirmations (see par. 16 through 27), provides guidance on performing alternative procedures when responses to confirmation requests are not received (see par. 31 and 32). It also provides guidance on evaluating the results of confirmation procedures as states in par. 33.

In par. 05 the standards states that in determining the audit procedures to be applied, including whether they should include confirmation procedure, the auditor uses the audit risk assessment.

In relation with the audit risk assessment (read about the concept of audit risk in here), par. 07 states that the greater the combined assessed level of inherent and control risk, the greater the assurance that the auditor needs from substantive tests related to the financial statement assertion. In this situation, the auditor might use confirmation procedures rather than or in conjunction with tests directed toward documents or parties within the entity.

While par. 06 states that confirmation is undertaken to obtain evidence from third parties about financial statement assertions made by management. In general, as states in Section 326, Evidential Matter, it is presumed that “when evidential matter can be obtained from independent sources outside an entity, it provides greater assurance of reliability for the purposes of an independent audit than that secured solely within the entity.”

There are two types of confirmation requests : the positive and the negative form. If the auditor uses the positive form of confirmation, he or she should considering since there is a risk that recipients of a positive form of confirmation request with the information to be confirmed contained on it may sign and return the confirmation without verifying that the information is correct, blank forms may be used as one way to mitigate this risk.

When the auditor has not received replies to positive confirmation requests, he or she should apply alternative procedures to the non-responses to obtain evidence necessary to reduce audit risk to an acceptably low level. However, the omission of alternative procedures may be acceptable in several circumstances as stated in par. 31 to the standard.

The nature of alternative procedures varies according to the account and assertion in question. In the examination of account receivable, for example, the auditor may conduct the examination of subsequent cash receipts, shipping documents, or other client documentation to provide evidence for the existence assertion.

The complete proposed standard and another related materials are downloadable in here

Comments for the proposed auditing standard are due on September 13, 2010.

Friday, July 16, 2010

Audit Approach

The Audit Approach is a risk analysis methodology that focuses on the combined impact of the environment in which a client operates, the client's management information and financial results, and the effectiveness of the client's internal controls. It is based on a thorough, up-to-date understanding of the client's business and industry, which is obtained through a comprehensive analysis of the external and internal operating environments. It enables us to design an audit programme that includes the most effective and efficient combination of test responsive to a client's unique circumstances. In addition, it provides a uniform method for developing and documenting the basis for the audit programme.

The Audit Approach enables us to plan our effort to be proportionate to the risk of material error in specific accounts and transactions. This provides the basis for planning the minimum effort necessary to limit audit risk in each area to a low level. As a result, every audit procedure has a specific purpose that is related to the company's particular situation – nothing is "routine" and hence potentially unnecessary. By following this approach we can avoid overauditing and underauditing, and we can distribute our audit work more evenly throughout the year.

MATERIALITY AND AUDIT RISK

Professional standards require us to consider materiality and audit risk when planning the nature, timing and extent of our audit procedures, and when evaluating the results of those procedures. Materiality is determined at two levels during the initial planning stage :

  1. An overall level as relates to the accounts taken as a whole – planning materiality; and
  2. An individual balance or class of transactions level – tolerable error.

Audit risk is defined as the risk that an auditor may unknowingly fail to modify his or her opinion on accounts that are materially misstated. We address materiality and audit risk at an overall level to help us develop an audit strategy that will provide sufficient evidence to enable us to evaluate whether the accounts are materially misstated.

At the account balance or class of transactions level, audit risk is the product of the risks that :

  1. Factors in a company's internal or external operating environment, before considering the functioning of internal controls, will lead to a material error – inherent risk;
  2. A material error will not prevented or detected on a timely basis by the system of internal control – control risk; and
  3. The auditor's procedures will fail to detect a material error not detected by the system of internal control – detection risk.

The Audit Approach provides a methodology for relating these risk concepts to materiality and correlating them to the nature, timing, and extent of our audit procedures. This is accomplished through the Specific Risk Analysis and the Preliminary Audit Approach.

SPECIFIC CONTROL OBJECTIVES

A key element of the Audit Approach is the relationship of specific control objectives to transactions and accounts. Specific control objectives are derived from the five general control objectives that an accounting system should be expected to achieve. The first three of the five – authorization, recording, and safeguarding – relate to establishing the system of accountability and provide for the prevention of errors and irregularities. The fourth general objective – reconciliation – ties together the system of accountability established by the first three and, along with the fifth objective – valuation – provides for the detection of errors and irregularities.

We have translated these general objectives into specific control objectives that are related to the accounts and transactions of a business. Specific control objectives relate to the activities in each operating component that originate and process transactions. Each type of transaction results in either debits or credits to various accounts. Because a number of accounts and transactions are normally affected by a single specific control objective, the specific control objectives provide convenient and efficient reference points for considering the inputs to the Specific Risk Analysis.

PHASES OF THE AUDIT APPROACH

We can divide an audit into three phases – initial planning, programme development, and programme execution. On paper, each phase – and each step within it – appears as a separate activity. However, in practice, the phases and steps are closely interrelated and should not be regarded as distinct steps that are set aside when done. Throughout any audit, we should be alert for new developments that may affect the client's business or industry. We should continue to challenge the effectiveness and efficiency of audit procedures, and modify them if necessary (Hrd).

Monday, July 12, 2010

Audit Risk Model, an introduction

ISA 315 states that the auditor should identify and assess the risks of material misstatement of the financial statement level, and  at the assertion level for classes of transactions, account balances, and disclosures.

Audit risk, as it directly affects the specific audit approach to the engagement, is generally considered at the account balance or class of transaction level.

At this level, audit risk consists of :

  • The risk (consisting of inherent and control risk) that the account balance or class of transactions contain misstatements  that could be material to the financial statements whether individually or when aggregated with misstatements in other balances or classes.
  • the risk (detection risk) that the auditor will not detect such misstatements.

Audit Risk Model :  AR = IR X CR X DR, where AR = Audit Risk, IR = Inherent Risk, CR = Control Risk, DR = Detection Risk

INHERENT RISK

Inherent risk is the susceptibility of an account balance or class of transactions to material misstatement, individually or when aggregated with misstatements in other balances or classes assuming that there were no related internal controls. The inherent risk of misstatement is greater for some types of transactions or accounts than for others. For example :

  • Account balances and transactions subject to complex calculations are more susceptible to error than those based on simple calculations.
  • Assets such as cash are more susceptible to theft than assets such as fixed assets.
  • Account balances subject to judgment and estimation are more likely to be misstated than account balances based on historical, factual data.

CONTROL RISK

Control risk is the risk that a misstatement, that could occur in an account balance or class of transactions and that could be material individually or when aggregated with misstatements in other balances or classes, will not be prevented or detected and corrected on a timely basis by the accounting and internal control systems.

Control risk will vary inversely with the level of effectiveness of the internal control structure. However, because of the inherent limitations of any internal control structure (e.g. those due to human error), there will always be some level of control risk within internal control structure.

It is often difficult to distinguish between inherent and control risk because of the close relationship between the two.

Assume, for example, the auditor believes there is a 50 percent inherent risk that inventory is misstated by more than tolerable error because of technological changes that have taken place in the client's industry during the past year. The auditor also concludes that internal accounting controls are sufficiently effective to assign a control risk of 30 percent.  Using a portion of the audit risk model, AR = IR X CR X DR, the likelihood of an error occurring is 15 percent (IR X CR = 50% X 30%).

Before an auditor can use a control risk of less than 100 percent, he is required to do two things : evaluate how well a client's internal control system functions and test the system for effectiveness.

DETECTION RISK

Detection risk is the risk that auditor's substantive procedures will not detect a misstatement that exist in an account balance or class of transactions that could be material, individually or when aggregated with misstatements in other balances or classes.

Detection risk is a function of the effectiveness of auditor's audit procedures and how well the auditor apply them. Such risk exists partly because auditor typically examine less than 100% of an entity's transactions (sampling risk) and partly because auditor may select inappropriate audit procedures, apply audit procedures incorrectly, or misinterpret the results of audit procedures.

The level of detection risk that auditor can accept varies inversely with the level of inherent and control risk. The higher the inherent and control risk, the less detection risk that auditor can accept to keep the risk of material misstatement at an acceptably low level.

The less detection risk that auditor can accept, the more reliable of substantive procedures must be.

Using the example discussed in the control risk section, assume there was a detection risk of 20 %. The audit risk is therefore 3 % (IR X CR X DR = 0,50 x 0,30 x 0,20). The auditor can conclude there is a 3 percent risk that inventory is misstated by more than tolerable error. This conclusion is based upon the assumption that the auditor can measure the component risks in a precise manner (Hrd) ***

Friday, July 2, 2010

PCAOB Issues Staff Audit Practice Alert on Auditor Considerations of Significant Unusual Transactions

On April 7, 2010, The Public Company Accounting Oversight Board  issued a Staff Audit Practice Alert to remind auditors of public companies about their responsibilities to assess and respond to the risk of material misstatement of the financial statements due to error or fraud posed by significant unusual transactions.

Staff Audit Practice Alert No. 5, Auditor Considerations Regarding Significant Unusual Transactions (Practice Alert No. 5) compiles relevant requirements from existing PCAOB auditing standards regarding significant unusual transactions to assist the auditor in reviews of interim financial information and audits of financial statements.

"The PCAOB’s message to auditors, in this challenging economic environment, has consistently emphasized attention to audit risk and adherence to existing audit requirements," said Martin F. Baumann, Chief Auditor and Director of Professional Standards.

Practice Alert No. 5 complements Staff Audit Practice Alert No. 3, Audit Considerations in the Current Economic Environment, by further addressing risks of material misstatement associated with significant unusual transactions, a risk that the staff believes continues to exist today.

Practice Alert No. 5 compiles existing requirements from PCAOB auditing standards regarding significant unusual transactions and groups them into the following categories:

  • Identifying and assessing risks of material misstatement
  • Responding to risks of material misstatement
  • Consulting others
  • Evaluating financial statement presentation and disclosure
  • Communicating with audit committees
  • Reviewing interim financial information

"Practice Alert No. 5 will assist auditors as they begin their work related to 2010 quarterly reviews and audits of financial statements," said Mr. Baumann.

These alerts are prepared to highlight new, emerging, or otherwise noteworthy circumstances that may affect how auditors conduct audits under the existing requirements of PCAOB standards and relevant laws.

Auditors should determine whether and how to respond to these circumstances based on the specific facts presented. The statements contained in Staff Audit Practice Alerts are not rules of the Board and do not reflect any Board determination or judgment about the conduct of any particular firm, auditor, or any other person.

Source : PCAOB Website

Read also a related article from Journal of Accountancy in here