Aaa116 CSG Au
Aaa116 CSG Au
Aaa116 CSG Au
(AAA) 116
February 2016
Copyright © Chartered Accountants Australia and New Zealand 2015. All rights reserved.
This publication is copyright. Apart from any use as permitted under the Copyright Act 1968 (Australia) and
Copyright Act 1994 (New Zealand), as applicable, it may not be copied, adapted, amended, published, communicated
or otherwise made available to third parties, in whole or in part, in any form or by any means, without the prior
written consent of Chartered Accountants Australia and New Zealand.
Dear Candidate,
Welcome to the Audit & Assurance (AAA) module of the Chartered Accountants Program.
On completion of this module you will be one step closer to becoming a Chartered Accountant.
Inside this pack you will find your Candidate Study Guide (CSG) which includes the entire core
content, the scenario and task for the activities and the readings for each unit. We would like to take
this opportunity to direct you to some of the key resources available online through myLearning:
Announcements
The Announcement area is our primary point of contact with you, where we provide directives on
assessments, virtual classrooms, etc. It is important that you log in immediately on commencement of
the module and read any messages. Please ensure you check the announcements regularly.
Module orientation
•• Study support tools – getting started, tools and techniques for successful completion of the module
•• Assumed knowledge, Module outline and Module plan.
•• Candidate code of conduct.
Learning materials
•• CSG, worked examples, activities and their solutions.
•• Quick reference guides.
•• Unit quizzes – for self-assessment.
Discussion forums
•• Technical issue of the week – additional tools and/or questions to assist with your studies.
•• Unit forums – where you can discuss individual units with module leaders and your peers.
•• An informal peer-to-peer forum – where you can interact with other candidates.
Virtual classrooms
•• Timetables and links to resources for virtual classrooms.
Online assessments
•• Online assessment tests (multiple choice) – short, graded tests that count towards your final mark.
•• Practice tests (multiple choice) – to help you prepare for online assessments.
Exam
•• Exam tips, techniques and administration information.
•• Past exam papers and exam preparation series questions.
My Grades
•• Results for online assessments – score for each and access to detailed feedback.
•• Results for exam and module overall.
Online learning is an exciting way to learn, and the best part about studying online is that education
comes to you no matter where you are. Above all, work hard to achieve the exam results you want and
to set yourself up for a successful career as a Chartered Accountant wherever your career may take
you around the globe.
Yours sincerely,
Introduction i
Unit 5: Analysing audit risks, financial statement assertions and initial audit engagements
Core content 5-1
Readings 5-27
Activities 5-29
Unit 12: Responding to assessed risk – using the work of others, external confirmations and
written representations
Core content 12-1
Readings 12-23
Activities 12-25
Introduction
Welcome to the Audit & Assurance (AAA) module. This module will provide you with the
opportunity to understand key concepts and to practise applying your understanding to a
variety of practical scenarios.
Learning model
The Chartered Accountants Program (the Program) material has been constructed applying the
learning principles of ‘tell, show, do’ to learning outcomes devised for each unit. Each unit is
made up, primarily, of core content, worked examples, activities and a unit quiz.
TELL SHOW DO
Tell me the relevant + Show me how to + Can I do the task
theory do the task unassisted?
Where do I start?
A good place to start is with the assumed knowledge quiz and our orientation video on
myLearning. You may also like to look at a past exam paper to see how topics are addressed in
examination format.
Once you’ve done this, open your Candidate Study Guide (CSG), and begin unit 1. It is best to
work through the units in order. If you’re working through the hard copy, don’t forget to logon
to myLearning to:
•• see our new technical videos in selected units
•• check announcements regularly
•• review your activity solutions
•• complete worked examples
•• do the end of unit quiz.
Introduction Page i
Audit & Assurance Chartered Accountants Program
to complete the activity offline. You can compare your response to the suggested
solution provided online. If you struggle with completing the activity’s task, refer to the
recommended approach located after each suggested solution. The recommended approach
provides a suggested step approach for the successful completion of the task.
•• Readings – there are two types of reading: required readings and further readings.
Required readings provide additional examinable content. Further readings provide an
extension of knowledge and are not examinable.
You will find that as you work through the worked examples in myLearning you will
be required to actively participate in completing the task, by responding to a range of
questions. For example, you may be required to do a calculation or to select an appropriate
response from a range of options. As you respond to these questions, you will be provided
with immediate feedback confirming your answer or explaining why the response made
is incorrect. The questions asked (i.e. the interactivity component) focus on areas that
candidates have typically struggled with in past exams. You are encouraged to complete
the worked examples online to help maximise your understanding and application of the
theory.
•• Unit quiz – most units have a quiz with up to 10 questions aimed at checking your
understanding of the learning outcomes for the unit. Feedback is provided on both the
correct and the incorrect responses. These questions are to ensure you have understood key
aspects of the unit content, but they are often simpler than the Online Assessment questions.
In addition to interactive worked examples, you will find additional non-interactive examples
within some units which you can download and review, to support your learning.
•• Activity solutions – Copies of suggested solutions for all activities are provided to allow
you to assess your knowledge. In addition to the solutions, you will find Excel spreadsheets
for certain activities which are provided to help you work through these activities in an
efficient manner as well as enabling you to explore common uses of Excel within a business
environment.
•• Technical issue of the week – within the discussion forum, the AAA team will regularly
post questions for candidates to consider and discuss. These questions are designed to help
candidates explore their understanding of key topic areas within AAA.
•• Quick reference guides – key summaries for selected units.
•• Technical videos – these new short videos aim to help candidates to cut through the detail,
to quickly master the core principles in selected units.
•• Past exams – copies of the AAA215 main and supplementary exams are available in
myLearning. These papers are made available to help you further test your knowledge and
identify any knowledge gaps you may have prior to the exam. Solutions and feedback on
these papers are also available.
•• Exam preparation series – these are exam style questions. The feedback on these questions
is based around the type of answer an exam marking panel would expect from a merit list
candidate in answering each of these questions. The series is released after the final online
assessment.
You will be able to access all online material at commencement of the module. A navigation bar
will assist you with identifying each learning element.
Page ii Introduction
Chartered Accountants Program Audit & Assurance
Discussion forums
In myLearning you will be able to access a number of discussion forums. Some of these forums
are designed for you to communicate informally with your peers who are also undertaking
AAA while others are designed for you to ask technical questions and receive feedback and
support from peers and technical specialists.
The peer-to-peer forum is great for helping you establish study groups and linking with your
fellow candidates. The unit forums are best used to get help when you are having difficulty
withy content, examples or activities. Do not underestimate the benefit you can gain by
participating in these forums.
Additional support
In addition to the material listed above, ensure you regularly read the announcements (in
myLearning), as this is our primary source of communication with you.
To get started, we suggest you download the module plan (available in myLearning).
This module plan provides a suggested timeline for completing each unit within the allocated
12 weeks of study. It has been devised around the key assessment dates for the module.
We will also assist you in working through the material, with regular discussion forum posts
providing guidance.
Learning outcomes
Learning outcomes provide an outline of the expected knowledge and skill level achieved
on completion of the unit. Each learning outcome commences with a verb, such as explain,
calculate, demonstrate etc. These taskwords are defined in the Exam tips and techniques
document (available in myLearning).
All learning elements are written based on the learning outcomes for the unit. Each learning
element starts by identifying the learning outcome(s) being explored by the material. To
succeed in the online assessments and the exam, you should ensure you understand the topic
the learning outcome is covering and also the level you are expected to achieve.
OTHER TOPICS
Future developments
Unit 19 Case study, and current and future trends
To optimise your learning it is recommended that you complete each unit sequentially. As you
progress through the module, the material covered in a unit may be written assuming you have
the understanding of the content from an earlier unit. It will also ensure that you have covered
the material which will be examined in the online assessment tasks.
Page iv Introduction
Chartered Accountants Program Audit & Assurance
Date convention
Generally, the date format is as follows:
Dates for the current decade are expressed as 20XX, the preceding decade are expressed
as 20WX and future years outside of this decade dates are expressed as 20YX. For example,
20X3 would be the equivalent of 2013 and 20W6 would be 2006, and 20Y3 would be equivalent
to 2023. All years are treated as having 365 days.
Assumed knowledge
Each unit has been constructed based on levels of assumed knowledge relevant to the topic
area being covered in that unit. Details of the assumed knowledge for the module are identified
in the Module outline document, which is available online. You can complete an assumed
knowledge quiz, which is also available online, to check on your initial understanding of the
content prior to commencing the module. Should you have any gaps in your knowledge we
recommend that you refer to your university notes or the appropriate text(s).
The assumed knowledge quiz can be accessed via My Learning > Audit & Assurance (1) 2016 >
Module orientation.
Six-month rule
Legislation changes constantly. In the Chartered Accountants Program modules, you are
expected to be up to date with relevant legislation, Standards, cases, rulings, determinations
and other guidance as they stand six months before the exam date unless otherwise stated.
You are always encouraged to be aware of current developments in all areas.
The relevant date for legislation is the date the legislation receives royal assent. The relevant
date for cases is the date the case decision was handed down. The relevant date for Auditing
Standards and other material is the issue date, early adoption of Standards is generally
encouraged.
Assessment
To pass the module, you must pass the exam and pass the module overall. The assessment
components are outlined below:
Online assessment 20% Three (3) online assessments. Each assessment will consist of
10 single response, multiple-choice questions
The exam makes up 80% of your assessment, and you must pass the exam (achieve 50% or
more of the available marks) to pass the module. It is therefore critical to practise your exam
technique and make the most of the time that you have. The exam is:
•• based on content covered in the learning elements
•• supervised
•• three (3) hours writing time, plus 15 minutes reading time
•• made up of four (4) compulsory, written, multi-part questions
•• open book
Introduction Page v
Audit & Assurance Chartered Accountants Program
•• centrally marked
•• critically important, as you must pass the exam in order to pass the module.
Good luck!
The Chartered Accountants Program is challenging. It is designed to be the best educational
product it can be for you, the future practitioners in this profession. As it constantly evolves,
Chartered Accountants Australia and New Zealand will continue to seek your feedback to
ensure the Program meets the learner’s needs now and for future development.
We hope you find your journey through the Program a rewarding and enjoyable experience and
encourage you to work steadily through the material in the recommended way. If you require
further assistance, post your questions, in a professional manner, in the Discussion Forums.
Finally, best of luck with your studies.
Myself and the AAA team look forward to conversing with you on the technical query forum
online over the course of your studies.
Eija Burt
Senior Module Leader, AAA module
Page vi Introduction
Chartered Accountants Program Audit & Assurance
CC
Core content
Unit 1: Assurance purpose and framework
Learning outcomes
At the end of this unit you will be able to:
1. Outline an overview of the Framework.*
2. Identify and apply the elements and objectives of an assurance engagement.*
3. Demonstrate how Auditing Standards, Standards on Review Engagements and Standards
on Assurance Engagements are to be applied.*
4. Demonstrate the auditor’s overall objectives and responsibilities when conducting an audit
of financial statements.
5. Identify which entities are required to be audited by legislation.*
* Customised for Australia
Introduction
Businesses, public and voluntary organisations, investors, governments, market regulators,
policymakers, non-government organisations and other interest groups need to rely on credible
information to make effective economic decisions and formulate policy. Trust and integrity are
important attributes that underpin credible information flows.
‘Assurance’ is a term commonly used to refer to any type of work that provides confidence to
the users. There are many ways to increase users’ confidence in the reliability of information.
Business entities and their stakeholders can build trust through actions such as engaging with
stakeholders, establishing an internal audit function or obtaining external assurance. External
assurance is the provision of an independent report by an assurance practitioner (such as a
Chartered Accountant) on information that is prepared by one party for the benefit of another
party or parties.
This unit introduces the assurance framework and regulatory environment that applies to
accountants performing audit and assurance engagements, starting with the international and
local regulatory environment. It then identifies the different types of international and local
Auditing and Assurance Standards.
This unit looks at the following International Standards on Auditing (ISAs) and other
pronouncements:
• The Preface to the International Quality Control, Auditing, Review, Other Assurance, and Related
Services Pronouncements (International Preface).
• The International Framework for Assurance Engagements (International Framework).
• ISA 200 Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance
with International Standards on Auditing (ISA 200).
aaa11601_au_csg
CC
In addition to performing assurance engagements, audit and assurance skills can be applied
to a wide range of other services, such as consulting and advisory services, and investigative
services to provide forensic reports or due diligence.
Learning outcome
1. Outline an overview of the Framework.
2. Identify and apply the elements and objectives of an assurance engagement.
International Responsibilities
body
IFAC As the global organisation for the accounting profession, IFAC protects the public interest
by supporting the development of all sectors of the profession internationally. This helps to
provide the necessary infrastructure for the world’s financial markets to function effectively
IAASB The IAASB is ‘an independent standard-setting body that serves the public interest by setting
high-quality international standards for auditing, quality control, review, other assurance, and
related services, and by facilitating the convergence of international and national standards’
(www.ifac.org)
IESBA The IESBA is ‘…an independent standard-setting board that develops and issues, in the
public interest, high-quality ethical standards and other pronouncements for professional
accountants worldwide’ , including the Code of Ethics for Professional Accountants (IESBA Code)
CC
Further information can be obtained from IFAC website at www.ifac.org. The relationship
between IFAC, IAASB and IESBA and their respective roles are shown in the following
diagram:
IFAC
International Federation
of Accountants
oversees operations of
IAASB IESBA
International Auditing and International Ethics
Assurance Standards Board Standards Board for Accountants
Required reading
International Framework paras 1–4.
CC
Australia-specific
Australian regulatory regime
Australian Auditing, Assurance and Ethical Standards largely follow the international
equivalents issued by the IAASB and IESBA.
The Australian financial reporting and assurance regulatory framework is illustrated in the
following diagram:
Financial Reporting and Assurance Regulatory Framework (Australia)
Lobby groups:
CAANZ/CPA/IPA
ASX
ASIC
AASB AUASB
(Australian Accounting (Auditing and Assurance
Standards Board) Standards Board)
Issues: Issues:
• AASBs (Accounting Standards) • ASAs (Auditing Standards)
• Interpretations • ASREs (Review Standards)
• ASAEs (Assurance Standards)
• ASRSs (Related Services Standards)
• Guidance Statements
Australian Conceptual
Framework
AASB Framework for the Australian Conceptual
Preparation and Presentation of Framework
Financial Statements
Framework for Assurance
Engagements
SAC 1
Definition of the Reporting Entity
OUTPUT
Australian general purpose financial report1
Note
1.
A non‑reporting entity may be required to prepare a financial report. Where a financial report
is prepared, the output may be a special purpose financial report.
Details on the roles and responsibilities of each regulatory body can be obtained from their
respective websites. A brief summary is also provided in the ‘Regulatory Bodies’ document,
available in the Unit 1 folder in myLearning.
CC
• Suitable criteria;
The relationship between these elements becomes clearer when shown in the following
diagram:
Responsible party
provides subject
issues written matter and report to
report to prepared by
obtains
Practitioner (auditor) evidence Subject matter Intended users
about
uses
to evaluate
Criteria
CC
For example, in the audit of entity XYZ’s general purpose financial statements, the five elements
are as follows:
XYZ’s
directors
provides subject
issues written matter and report to
report to prepared by
Shareholders and
obtains XYZ’s general
evidence other interested
XYZ’s auditor purpose financial
about users of the financial
statements
statements
uses
to evaluate
International
Financial Reporting
Standards
CC
Levels of assurance
In conducting an assurance engagement, the quality and quantity of the evidence that the
assurance practitioner gathers is determined by the level of assurance that users of the subject
matter require.
The International Framework divides assurance engagements into two types:
•• Reasonable assurance engagements.
•• Limited assurance engagements.
The higher the level of assurance required (e.g. an audit versus a review), the greater the quality
and quantity of the evidence gathered and, consequently, the more confidence users can have in
the subject matter. This level of confidence is reflected in the form and wording of the assurance
practitioner’s report on the subject matter.
Note that related services (e.g. agreed-upon procedures) are classified as non-assurance
engagements as they provide no assurance on the subject matter and fall outside the scope of
the International Framework.
The relationship between the levels of assurance and the degree of confidence expressed by
each is illustrated in the diagram below:
Non-assurance Assurance
engagement engagement
Level of
assurance Audit:
• Provide reasonable
Reasonable assurance
• Express a positive
opinion (e.g. ‘... in
our opinion’)
Review:
• Provide limited
assurance
Limited • Express a negative
conclusion (e.g. ‘...
nothing has come
to our attention’)
Related services
(e.g. agreed-upon
procedures)
• Provide no assurance
None • Do not express an
opinion or conclusion
CC
The relationship between reasonable and limited assurance engagements, the types of opinions
or conclusions they produce and the quality and quantity of evidence required for each is
illustrated below:
CC
Ethical principles and The assurance practitioner must only accept an assurance engagement where:
Engagement acceptance
•• The assurance practitioner believes they will be able to satisfy relevant ethical
(International Framework Standards – for example, independence
paras 5–8 and 22–25) •• The five elements of an assurance engagement (as discussed above) are
present
Professional ‘skepticism’ The assurance practitioner must adopt an attitude of professional scepticism
in order to determine whether any material misstatements exist in the subject
(International Framework
matter (e.g. financial statements). This involves:
paras 51–55)
•• Using a questioning mind when evaluating the validity of the evidence
obtained
•• Being alert to evidence that contradicts the reliability of documents or
representations made by the responsible party
Professional judgement The assurance practitioner must be able to exercise professional judgement in
an assurance engagement based on the facts and circumstances that are known.
(International Framework
This involves:
paras 56–66)
•• Consultation on difficult or contentious matters during the engagement, both
within the team and with others at an appropriate level inside or outside the
firm in making informed and reasonable judgements
•• Evaluating whether sufficient appropriate evidence has been obtained in
relation to the level of assurance being provided
Engagement risk The assurance practitioner must reduce assurance engagement risk to an
acceptably low level by obtaining sufficient appropriate evidence
(International Framework
para. 72) Engagement risk is the risk that the assurance practitioner expresses an
inappropriate conclusion when the subject matter information is materially
misstated. As the assurance practitioner is not testing every transaction or
amount that makes up a set of financial statements, there will always be some
engagement risk
These key principles from the International Framework are expanded on in later units of the
AAA module.
CC
Required reading
Framework for Assurance Engagements
CC
Learning outcome
3. Demonstrate how Auditing Standards, Standards on Review Engagements and Standards on
Assurance Engagements are to be applied.
Earlier in this unit, we discussed the various international bodies involved in setting Auditing
and Assurance Standards. The next step is to look at the pronouncements that are issued by
these bodies and how they apply to different types of assurance engagements.
The relevant international pronouncements issued by the IAASB are set out in the following
diagram:
PRONOUNCEMENTS
OVERARCHING
Engagements Governed by the Standards of the IAASB
ENGAGEMENTS
Adapted from: IAASB, Handbook of International Quality Control, Auditing, Review, Other Assurance, and Related Services
Pronouncements, 2014 edn, vol. 1, p. 11.
CC
The various types of international pronouncements are discussed below.
Pronouncement Purpose
International Preface Facilitates understanding of the scope and authority of the pronouncements
issued by the IAASB
ISQC 1 Prescribes the mandatory minimum quality control requirements for firms of
professional accountants who perform assurance engagements that are needed
to ensure all engagements are performed to the appropriate Standard
For example: ISQC 1 requires a firm’s managing partner (or equivalent) to assume
responsibility for the firm’s quality control policies and procedures. This helps to
ensure that quality control is given an appropriate level of priority by the firm
International Framework Defines and describes the elements and objectives of an assurance engagement
and thus establishes the basic principles under which these engagements are
conducted. Does not apply to non-assurance Standards issued by the IAASB
The identification of the type of engagement a client might request and the applicable guidance
is determined by both the level of assurance provided and the subject matter of the engagement.
Applicable Standards
As indicated in the IAASB flow chart diagram, the IAASB issues a range of Standards, as
follows:
•• International Standards on Auditing (ISAs).
•• International Standards on Review Engagements (ISREs).
•• International Standards on Assurance Engagements (ISAEs).
•• International Standards on Related Services (ISRSs).
CC
The focus of this module is largely on the audit of general purpose financial statements (GPFS)
to which ISAs 200–720 apply. However, there are also audits of historical financial information
not presented in GPFS. These include:
•• Special purpose financial statements (SPFSs) under ISA 800 Special Considerations—Audits of
Financial Statements Prepared in Accordance with Special Purpose Frameworks (ISA 800).
•• Single financial statements or components of financial statements under ISA 805
Special Considerations—Audits of Single Financial Statements and Specific Elements, Accounts
or Items of a Financial Statement (ISA 805).
•• Summary financial statements (SFSs) under ISA 810 Engagements to Report on Summary
Financial Statements (ISA 810).
These special purpose audit engagements involve auditing information prepared for special
circumstances for specific users. Special purpose audit engagements are discussed in the unit on
other assurance engagements and agreed-upon procedures engagements.
CC
Australia-specific
Australian auditing and assurance pronouncements
Australian pronouncements follow the structure and content of their international
counterparts. The relevant Australian pronouncements issued by the AUASB are set out in the
following diagram:
PRONOUNCEMENTS
OVERARCHING
ASQC 1 Quality Control for Firms that Perform Audits and Reviews of Financial Reports
and Other Financial Information, Other Assurance Engagements and
Related Services Engagements
ENGAGEMENTS
Audits of Reviews of Assurance Related services
TYPES OF
historical historical engagements other (Non-assurance
financial financial than audits or reviews engagements)
information information of historical financial
information
Adapted from: CA ANZ, Auditing Assurance and Ethics Handbook 2015, Appendix 1 and Appendix 2
to the ‘Foreword to AUASB Pronouncements’, pp. 35–6.
The structure of the AUASB pronouncements is similar to that used by the IAASB, as below:
Collectively, ASAs, ASREs, ASAEs and ASRSs are referred to as the ‘AUASB Standards’.
CC
Force of law
Certain Standards in Australia have the ‘force of law’. The AUASB is required to issue Auditing
Standards under s. 336 Corporations Act 2001, for use in the audit of entities regulated under the
Act. This is commonly referred to as ‘force of law’.
These ‘force of law’ Standards are called ‘Auditing Standards’ and include:
•• Most ASAs.
•• ASQC 1 Quality Control for Firms that Perform Audits and Reviews of Financial Reports and
Other Financial Information, Other Assurance Engagements and Related Services Engagements
(ASQC 1).
•• ASRE 2410 Review of a Financial Report Performed by the Independent Auditor of the Entity
(ASRE 2410) and ASRE 2415 Review of a Financial Report: Company Limited by Guarantee
or an Entity Reporting under the ACNC Act or Other Applicable Legislation or Regulation
(ASRE 2415).
Complying with Australian Auditing and Assurance Standards
Australia has a single set of Auditing and Assurance Standards issued by the AUASB, which are
used by assurance practitioners for all engagements they perform.
Australian assurance practitioners are required to comply with these Auditing and Assurance
Standards as follows:
•• For assurance engagements performed under the Corporations Act, s. 307A requires
assurance practitioners to comply with AUASB Standards. Audits and reviews conducted
under the Corporations Act are enforced by ASIC.
•• For other assurance engagements, APES 210 Conformity with Auditing and Assurance
Standards (APES 210) requires members of CA ANZ (also CPA Australia and the IPA) to
comply with AUASB Standards. This is enforced by the professional accounting bodies (e.g.
via the CA ANZ Quality Review Program).
APES 210 also requires CA ANZ members to:
–– Observe and comply with public interest obligations (see APES 110 s. 100 ‘Introduction
and Fundamental Principles’).
–– Comply with independence requirements (see APES 110 ss 290 and 291 on
independence).
Paragraph Aus 0.1 in each ASA refers to Corporations Act audits and reviews. Making this
paragraph mandatory reflects the legal enforceability of ASAs in relation to engagements
conducted under the Corporations Act.
Paragraph Aus 0.2 in each ASA is explanatory material. This is because para. Aus0.2 in each ASA
refers to non-Corporations Act audits and reviews. For these engagements, ASAs are not legally
enforceable.
Differences between IAASB and AUASB pronouncements
There are two key differences between the IAASB and AUASB pronouncements. In Australia:
•• The Foreword to AUASB Pronouncements (AUASB Foreword) sets out the:
–– Functions, composition and operating procedures of the AUASB.
–– Range of pronouncements issued by the AUASB.
•• ASA 101 Preamble to Australian Auditing Standards (ASA 101) sets out how the AUASB
Standards should be understood, interpreted and applied. ASA 101 was issued because
ASAs are mostly legally enforceable.
Internationally, the IAASB has issued the Preface to the International Quality Control, Auditing,
Review, Other Assurance, and Related Services Pronouncements (discussed above under
international auditing and assurance pronouncements). It explains how the IAASB Standards
are to be used and applied.
CC
Required reading
AUASB, Foreword to AUASB Pronouncements.
AUASB, Australian Framework for Assurance Engagements.
ASA 101.
Corporations Act ss 336, 307 and 307A.
APES 210.
Worked example 1.2: Identifying the type of engagement and the applicable Standards
[Available online in myLearning]
CC
Learning outcome
4. Demonstrate the auditor’s overall objectives and responsibilities when conducting an audit of
financial statements.
Having covered international and Australian auditing and assurance pronouncements, this unit
now looks at an auditor’s objectives and responsibilities in conducting an audit under the ISAs
and ASAs. This section begins a more in-depth examination of the requirements of individual
Standards that will continue throughout the other units in this module.
The first international Standard to be examined in detail in the module is ISA 200. This
Standard deals with the auditor’s overall responsibilities when conducting an audit of financial
statements, in accordance with the ISAs. Later ISAs expand on and provide more detail about
these responsibilities.
Requirements
ISA 200 contains five key requirements for an auditor in the conduct of an audit, which relate to:
1. Ethics.
2. Professional scepticism.
3. Professional judgement.
4. Sufficient appropriate audit evidence and audit risk.
5. Conduct of an audit in accordance with ISAs.
1. Ethics
The auditor needs to comply with relevant ethical requirements, including independence, when
conducting an audit (ISA 200 para. 14). At the international level, these ethical requirements
include IESBA’s Code of Ethics.
2. Professional scepticism
The auditor needs to plan and perform an audit with professional scepticism (ISA 200 para. 15).
Professional scepticism, as mentioned earlier, means ‘an attitude that includes a questioning
mind, being alert to conditions which may indicate possible misstatement due to error or fraud,
and a critical assessment of evidence’ (IAASB Glossary of Terms). This includes being alert to the
following (ISA 200 para. A18):
CC
Area Example
Audit evidence that contradicts Management may have given the auditor verbal assurances that an
other audit evidence obtained entity has no obsolete inventory. However, the auditor notices boxes of
goods in the warehouse that were there the previous year
Information that brings into Management may claim to have increased profit margins during the
question the reliability of documents period, but press reports and industry journals have consistently
and responses to enquiries reported falling margins in that sector
Conditions that may indicate A senior staff member of the entity being audited appears to have
possible fraud a lifestyle beyond their earnings
Circumstances that suggest the need External confirmation of bank balances is not mandatory under ISAs.
for audit procedures in addition to However, if the auditor has doubts about client-produced evidence
those required by ISAs relating to bank balances, it may be appropriate to obtain written
confirmation from the client’s bankers
3. Professional judgement
The auditor needs to exercise professional judgement in planning and performing an audit
(ISA 200 para. 16). This is because interpreting ISA requirements and making informed
decisions throughout an audit can only be made with the application of relevant knowledge
and experience.
As outlined in ISA 200 para. A23, professional judgement is particularly necessary regarding
decisions involving:
•• Assessing materiality and audit risk.
•• Determining the nature, timing and extent of audit procedures.
•• Evaluating whether sufficient appropriate audit evidence has been obtained.
•• Evaluating management’s judgements.
•• Drawing conclusions based on evidence obtained.
There is no easy measurement or rule of thumb to assess whether evidence is sufficient and
appropriate – it is a matter of professional judgement.
CC
Audit evidence is commonly sourced from clients’ accounting records (e.g. ledgers, journals and
invoices); discussions with the client and external sources such as banks; and share registries.
Audit risk is the risk that the auditor expresses an unmodified (i.e. ‘clean’) opinion when the
financial statements are materially misstated. Auditors always aim to keep audit risk low;
however, it is not possible to eliminate audit risk entirely. This is because an audit engagement
is to provide reasonable assurance (not absolute assurance) and, therefore, the auditor would
not test all transactions or amounts that make up the financial statements.
Required reading
ISA 200 paras 1–24, A1, A12–A31, A45, A58–A69 and A72–A76.
Institute of Chartered Accountants in Australia and Chartered Professional Accountants of Canada,
2013, ‘Practical ways to improve the exercise and documentation of professional scepticism in an
ISA audit’, May [available online in myLearning].
Audit quality
As stated in ISA 200 para. 3, the purpose of an audit is to enhance the degree of confidence
of intended users in financial reports. This is achieved by the expression of an opinion by the
auditor on whether the financial report is prepared, in all material respects, in accordance
with an applicable financial reporting framework. Under A Framework for Audit Quality (the
Framework) issued by the IAASB, for an external audit to fulfil its objective, the users of audited
financial statements must have confidence that the auditor has worked to a suitable standard
and that ’a quality audit has been performed’.
Audit quality is a widely debated topic, both internationally and locally, among the audit
profession, regulators and other audit stakeholders. It is a complex topic for which there is
no universal definition. The framework explains that the term audit quality includes ‘the key
elements that create an environment which maximizes the likelihood that quality audits are
performed on a consistent basis’.
Paragraph 2 of the framework states:
A quality audit is likely to have been achieved by an engagement team that:
• Exhibited appropriate values, ethics and attitudes;
• Was sufficiently knowledgeable, skilled and experienced and had sufficient time allocated to
perform the audit work;
• Applied a rigorous audit process and quality control procedures that complied with law,
regulation and applicable standards;
• Provided timely reports; and
• Interacted appropriately with relevant stakeholders.
CC
Subsequent units of the AAA module explore concepts contributing to audit quality in more
detail.
Australia-specific
Auditor’s objectives and responsibilities in conducting an audit in Australia – ASA 200
ASA 200 Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance
with Australian Auditing Standards (ASA 200) largely follows its international equivalent, ISA 200,
discussed above.
Differences between ISA 200 and ASA 200
The key differences between ISA 200 and ASA 200 are as follows:
•• ASA 200’s application paragraphs state that audits conducted under the Corporations Act
must be conducted in accordance with ASA 200.
•• In relation to compliance with Auditing Standards, ASA 200 para. Aus 22.1 contains an
additional requirement which permits non-compliance with mandatory requirements of
the ASAs where the amount in question is immaterial.
Required reading
ASA 200 paras Aus 0.1–Aus 0.3, Aus 12.1, Aus 13.1–Aus 13.4, Aus 22.1, Aus 23.1, Aus A14.1,
Aus A66.1 and Aus A74.1
CC
Learning outcome
5. Identify which entities are required to be audited by legislation.
Australia-specific
There are a number of pieces of legislation that specify the requirements for an entity to be
audited or reviewed. Some of these are outlined below.
Corporations Act 2001 (Cth)
The Corporations Act requires certain entities registered under the Act to prepare an annual
financial report (s. 292) and have it audited (s. 301). Examples include:
•• Disclosing entities.
•• Public companies.
•• Large proprietary companies.
•• Registered schemes.
The financial report prepared by these entities must include (s. 295(1)):
•• Financial statements for the year and related notes.
•• A directors’ declaration about the statements and notes.
The financial report must be prepared in accordance with Accounting Standards and the
Corporations Regulations 2001 (Cth), which are made under the Corporations Act (s. 296). In
addition, disclosing entities need to prepare half-yearly financial reports (s. 302(a)) and have
these audited or reviewed (s. 302(b)).
Companies limited by guarantee with annual or consolidated revenue of less than $1 million
may elect to have their annual financial report reviewed rather than audited (s. 301(3)).
When conducting an audit or review under the Corporations Act, the auditor must comply with
the Act’s requirements, which include:
•• Forming an opinion as to whether the financial report is in accordance with Accounting
Standards and gives a true and fair view (s. 307(a)).
•• Conducting the engagement in accordance with Auditing Standards (s. 307A). It is this
section which gives rise to the expression ‘force of law’ in relation to Auditing Standards.
•• Retaining work papers for seven years after the date of the audit report to which they relate
(s. 307B).
•• Providing the directors of the client with an independence declaration (s. 307C).
•• Reporting to members of the client whether the financial report is in accordance with the
Corporations Act (s. 308(1)).
•• Reporting to ASIC any contraventions and suspected contraventions of the Corporations
Act during the conduct of an audit (s. 311).
Financial statements versus financial report
The Corporations Act and ASAs both refer to ‘financial report’, comprising the financial
statements, notes, and the directors’ declaration about the statements and notes (Corporations
Act) or an assertion statement by those charged with governance (AUASB Glossary).
However, ISAs apply to ‘financial statements’. The definition in the IAASB’s Glossary of Terms
defines this as complete set of financial statements as determined by the requirements of the
applicable financial reporting framework. A complete set of financial statements is defined
in para 10. of Australian Accounting Standard AASB 101 Presentation of Financial Statements
(AASB 101).
CC
For the purposes of this module, ‘financial statements’ will be used, except where referring
specifically to the Australian regulatory environment.
ASIC class orders – exemptions from specified financial reporting and audit requirements
ASIC has the power, in certain circumstances, to provide entities with relief from certain
financial reporting and audit requirements of the Corporations Act through class orders. ASIC’s
class orders commonly entail extensive prerequisites for any entity that wishes to apply for
relief.
ACNC Act
The Australian Charities and Not-for-profits Commission (ACNC) is the independent national
regulator of charities. The Australian Charities and Not-for-profits Commission Act 2012 (Cth) (the
ACNC Act) sets out the objects and functions of the ACNC, as well as the framework for the
registration and regulation of charities.
The audit or review requirements of charities depend on the size of the charity. A large charity
must have its financial report audited and submit the financial report and auditor’s report to
the ACNC. Medium-sized charities must submit a financial report, but they can choose to have it
reviewed or audited. More information can be found on the ACNC website at (www.acnc.govt.au).
Other legislation
While the focus of this module is primarily on audits of financial reports prepared under the
Corporations Act, there are many entities across Australia that require auditing or review under
other legislation, for example:
•• Solicitors and real estate agents’ trust accounts, which are audited under state legislation.
•• Government departments, which are audited under various state and federal legislation.
Required reading
Corporations Act ss 292, 295, 296, 301, 302, 307, 307A, 307B, 307C, 308 and 311.
Audit and review requirements for Australian entities (available on myLearning).
Quiz
[Available online in myLearning]
Readings
Required reading
Relevant International Standards on Auditing and national equivalents and guidance
International Australia New Zealand
International Framework for Framework for Assurance Explanatory Guide Au1 Overview of
Assurance Engagements Engagements (June 2014) Auditing and Assurance Standards
(EG Au1)
Explanatory Guide Au1A
Framework for Assurance
Engagements (EG Au1A)
Preface to the International Quality Foreword to AUASB Pronouncements XRB Standard Au1 Application of
Control, Auditing, Review, Other Auditing and Assurance Standards
Assurance, and Related Services (XRB Au1)
Pronouncements
ISA 200 Overall Objectives of the ASA 200 Overall Objectives of XRB Standard Au1 Application of
Independent Auditor and the the Independent Auditor and the Auditing and Assurance Standards
Conduct of an Audit in Accordance Conduct of an Audit in Accordance (XRB Au1)
with International Standards on with Australian Auditing Standards
Auditing
•• Paragraphs 1–24, A1, A12–A31, •• Paragraphs 1–24, A1, A12–A31,
A45, A58–A69 and A72–A76 A45, A58–A69, A72–A76,
AUS 0.1–AUS 0.3, AUS 12.1,
AUS 13.1–AUS 13.4, AUS 22.1,
AUS 23.1, AUS A14.1 and
AUS A74.1
APES 210 Conformity with Auditing ISA (NZ) 200 Overall Objectives of
and Assurance Standards the Independent Auditor and the
Conduct of an Audit in Accordance
with International Standards on
Auditing (New Zealand)
•• Paragraphs 1–24, A1, A12–A31,
A45, A58–A69 and A72–A76
ASA 101 Preamble to Australian
Auditing Standards
Corporations Act 2001 (Cth) Auditors Regulation Act 2011
•• Sections 292, 295, 296, 301, 302, •• Sections 5, 8–10, 17 and 20
307, 307A, 307B, 307C, 308, 311
and 336
Financial Markets Conduct Act 2013
•• Sections 451 and 461
Further reading
ACT
Activity 1.1
Identifying assurance engagements
Introduction
To meet the definition of an assurance engagement, an engagement must possess five elements
as defined by the International Framework for Assurance Engagements (International
Framework).
This activity links to learning outcome:
•• Identify and apply the elements and objectives of an assurance engagement.
At the end of this activity you will be able to identify and apply the five elements of an
assurance engagement, in accordance with the International Framework.
It will take you approximately 20 minutes to complete.
Scenario
You are an audit senior at AAA Partners Chartered Accountants (AAA Partners). AAA
Partners provides a variety of services to its clients. As part of an internal review of AAA’s
quality control procedures, the audit managers have asked you to assess which of the given
engagements are assurance engagements under the International Framework.
Task
For this activity you are required to assess each the following engagements and identify
whether it is an assurance engagement. Justify your response.
1. Reporting on retail store turnover reports provided to the stores’ lessors under the terms of
the lease agreements.
2. Investigating management’s compliance with internal risk management policies for clients
in the financial services industry.
3. Valuation services.
4. Assisting boards of directors to develop corporate strategies.
5. Reporting to regulatory bodies on adherence to environmental laws and regulations.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 1.2
Applying professional scepticism and
professional judgement
Introduction
It is important for the auditor to exhibit professional scepticism and judgement when
conducting an audit.
The International Framework for Assurance Engagements (International Framework) provides
guidance on professional scepticism and professional judgement for assurance engagements
generally. ISA 200 Overall Objectives of the Independent Auditor and the Conduct of an Audit in
Accordance with International Standards on Auditing (ISA 200) contains the requirements and
guidance in respect of audits.
This activity links to learning outcome:
•• Demonstrate the auditor’s overall objectives and responsibilities when conducting an audit
of financial statements.
At the end of this activity you will be able to identify how professional scepticism and
professional judgement should be exercised in the conduct of an assurance engagement, in
accordance with ISA 200.
It will take you approximately 15 minutes to complete.
Scenario
You are an audit manager at Addup Chartered Accountants (Addup), a successful accounting
firm. Addup is the auditor of the annual financial statements of Ratchet, a large private
company. Ratchet’s audit is to be conducted in accordance with International Standards on
Auditing (ISAs).
Kathy Gull is the engagement partner assigned to the audit of Ratchet, which has experienced
some instability over the last two years, culminating in the departure of key members of the
senior management team. The new chief executive officer (CEO), John Swan, has subsequently
stabilised the company through his hands-on leadership style and detailed involvement in key
aspects of the business.
You are the audit manager assigned to the audit of Ratchet. Before the audit commences Kathy
has informed you that over the last six months, she noted the following in relation to Ratchet’s
operations:
•• Changes in key operating ratios that cannot be adequately explained, particularly in relation
to profit margins.
•• A lack of qualified staff in the accounting area.
•• Reduced compliance with, and awareness of, internal controls.
Kathy has also informed you that John leads an extravagant lifestyle which his salary alone does
not seem able to support.
ACT
Task
For this activity, you are required to:
•• Outline the ways that the audit team should exercise professional scepticism in response to
Kathy’s concerns regarding Ratchet.
•• Outline the key areas in which the audit team will need to exercise professional judgement.
CC
Core content
Unit 2: Auditing Standards and quality
control
Learning outcomes
At the end of this unit you will be able to:
1. Outline the audit process.
2. Illustrate the overall responsibilities of firms with regard to ethics and quality control.
3. Demonstrate the nature and purpose of audit documentation, and the objective and
requirements of preparing audit documentation.
Introduction
Conducting an audit under the International Auditing and Assurance Standards Board (IAASB)
International Framework for Assurance Engagements (International Framework) requires
understanding the:
•• Importance of complying with ethical requirements to ensure the integrity of the audit
process.
•• Significance of quality control policies and procedures in ensuring audits are consistently
conducted to the same high standard.
•• Overall audit process, including understanding that audit is an ongoing process of
interaction between the auditor and the audited entity.
•• Importance of audit documentation in providing evidence that the work was carried out in
accordance with applicable Standards and regulations.
These topics are covered in this unit. This unit looks at the following International Standards on
Auditing (ISAs) and other guidance and legislation:
•• ISQC 1 Quality Controls for Firms that perform Audits and Reviews of Financial Statements, and
other Assurance and Related Services Engagements (ISQC 1).
•• ISA 220 Quality Control for an Audit of Financial Statements (ISA 220).
•• ISA 230 Audit Documentation (ISA 230).
aaa11602_csg
CC
This section addresses the overall audit process for auditing general purpose financial
statements and how this process is covered in the Audit & Assurance (AAA) module.
CC
The initial units of the AAA module work through the audit process in a logical manner, similar
to that set out in the diagram below.
AUDIT PROCESS
CC
there are often interrelated issues – for example, a subsequent event can lead to a going
concern issue.
4. Finalising the audit. This covers formulation of the auditor’s opinion and reporting
activities.
It is important to remember that many Auditing Standards apply to more than one step in
the audit process and are therefore relevant to more than one unit in this module. These are
referred to as continuous audit activities. For example, ISA 570 Going Concern is referred to
during the planning stage and, again, when undertaking the audit and finalising the audit.
Communicate with ISA 260 Communication with Those Charged with Governance (ISA 260).
management and
•• Requires the auditor to communicate specific matters to those charged with
those charged with
governance (ISA 260 para. 3). Additional matters to be communicated which
governance
complement these requirements are identified in other Auditing Standards, such as:
ISA 265 Communicating Deficiencies in Internal Control to Those Charged with
Governance and Management (ISA 265)
•• Requires the auditor to ‘communicate in writing significant deficiencies in internal
control identified during the audit to those charged with governance on a timely
basis’ (ISA 265 para. 9)
ISA 450 Evaluation of Misstatements Identified during the Audit (ISA 450)
•• Requires the auditor to ‘communicate on a timely basis all misstatements
accumulated during the audit’ to ‘the appropriate level of management’ and
request that they be corrected (ISA 450 para. 8)
These may result in a number of communications throughout the audit
CC
ISA 220
•• Requires the engagement partner to ‘take responsibility for’ and ‘be satisfied that
members of the engagement team have undertaken appropriate consultation
during the course of the engagement, both within the engagement team and
between the engagement team and others at an appropriate level within or outside
the firm’ (ISA 220 paras 18(a) and (b))
Consider going ISA 240 The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
concern and fraud (ISA 240)
•• Requires the auditor to maintain ‘professional scepticism throughout the audit’ and
recognise that a material misstatement due to fraud could exist (ISA 240 para. 8)
ISA 570 Going Concern (ISA 570)
•• Requires the auditor to ‘remain alert throughout the audit for … evidence of events
or conditions that may cast significant doubt on the entity’s ability to continue as a
going concern’ (ISA 570 para. 11)
CC
Learning outcome
2. Illustrate the overall responsibilities of firms with regard to ethics and quality control.
ISQC 1, issued by the IAASB, deals with a firm’s responsibilities for its system of quality control
in respect of assurance and related services engagements (ISQC 1 para. 1), and it applies to all
firms of professional accountants. Under ISQC 1 para. 3, a system of quality control consists of:
•• Policies designed to achieve particular objectives.
•• Procedures ‘necessary to implement and monitor compliance with those policies’.
In the accounting profession, firms need to establish policies for accepting new clients and
performing engagements. They also need procedures for implementing these policies.
ISQC 1 para. 11 states that the objective of a firm’s quality control system is to provide
reasonable assurance that:
(a) The firm and its personnel comply with professional standards and applicable legal and regulatory
requirements; and
(b) Reports issued by the firm or engagement partners are appropriate in the circumstances.
Required reading
ISQC 1 paras 1–15, 17 and 57–59.
(f) Monitoring.
Further, ISQC 1 para. 17 requires firms to document the policies and procedures, and
to communicate these to their personnel.
Each element of an audit firm’s quality control system supports and reinforces the other
elements. For example:
CC
•• Strong ethical leadership helps ensure requirements are met.
•• Professional human resources practices help ensure engagements are performed
by appropriately skilled staff.
In addition, the system needs to be monitored to ensure its objectives are being achieved.
The elements of a quality control system for an audit firm can be shown diagrammatically
as follows:
Documentation and
communication of system
of quality control
Leadership responsibilities
for quality
Elements of
quality control Engagement performance
system
Ethical requirements
Human resources
Monitoring
Required reading
ISQC 1 paras 16, 18–19, A2 and A4–A6.
CC
Ethical requirements
A firm’s quality control system needs to provide ‘reasonable assurance that the firm and its
personnel comply with relevant ethical requirements’ (ISQC 1 para. 20). In order to achieve this,
ISQC 1 requires firms to establish policies and procedures that enable the firm and its personnel
to maintain independence when required by relevant Standards (ISQC 1 para. 21). Under these
policies and procedures:
•• Engagement partners must provide the firm with relevant information about client
engagements to allow the impact on the firm’s independence to be assessed (ISQC 1
para. 22(a)). For example, partners must disclose any personal relationships they have with
the directors of a new client entity.
•• Personnel must notify the firm immediately of any circumstances or relationships that
constitute a threat to the firm’s independence (ISQC 1 para. 22(b)) – for example, when a
family member is employed by, or has a significant investment in, the audit client.
•• Under ISQC 1 para. 22(c), the firm must accumulate and communicate any relevant
information to personnel so that:
–– The firm and its personnel can determine whether they satisfy independence
requirements.
–– The firm can update its independence records, as well as take ‘appropriate action’ with
regard to threats to its independence.
For example, the firm might circulate a list of prospective clients to its personnel
on a monthly basis and request they confirm that they are not aware of any threats to their
personal or the firm’s independence that would be created by the firm accepting the
engagements.
•• The firm must establish procedures that facilitate prompt communication of any breaches
of independence, so that the appropriate action to resolve these situations can be taken
(ISQC 1 para. 23).
•• The firm must obtain, at least once a year, written confirmation from all the relevant
personnel of their compliance with the firm’s independence policies and procedures
(ISQC 1 para. 24).
•• The firm must establish criteria for determining the need for safeguards of independence
when the same senior personnel work on a particular assurance client for numerous
engagement periods (ISQC 1 para. 25(a)). For example, a firm might implement a policy
that requires a second audit partner to review the work papers of every non-listed entity
assurance engagement where the engagement partner and manager have both been
assigned to the client for five years or more.
•• For audits of listed entities, the firm must ensure that rotation of the engagement
partner and others is carried out in accordance with relevant ethical requirements
(ISQC 1 para. 25(b)).
Required reading
ISQC 1 paras 20–25.
In order to achieve this, ISQC 1 para. 26 obligates firms to establish policies and procedures
designed to collect necessary information prior to accepting a new engagement or continuing
CC
with an existing one. For example, the engagement partner might be required to record current,
publicly available information regarding the integrity of the directors of a prospective client.
The firm must determine whether an engagement should be accepted, or an existing
engagement continued, when a conflict of interest is identified and document the resolution of
the issue (ISQC 1 paras 27(b) and (c)). The firm must also document how the issue was resolved,
irrespective of whether the engagement was accepted or declined.
The firm must address the circumstances in which it ‘obtains information that would have
caused it to decline the engagement had that information been available earlier’ (ISQC 1
para. 28). For example, the firm may become aware of an independence issue only after a new
audit engagement has already commenced. The firm then needs to determine what action it
should take to address that issue. This would include determining:
•• whether appropriate safeguards can be implemented
•• the firm’s external reporting obligations, and
•• whether or not the firm needs to withdraw from the engagement.
Required reading
ISQC 1 paras 26–28, A7, A9 and A18–A19.
Human resources
A firm’s quality control system needs to provide reasonable assurance that it has sufficient,
appropriately skilled personnel to:
•• Perform engagements in accordance with relevant Standards and legislation.
•• Enable appropriate reports to be issued.
To achieve this, ISQC 1 para. 29 obliges firms to establish policies and procedures that require:
•• The client to be informed of the identity and role of the engagement partner (ISQC 1
para. 30(a)). This may be done in the engagement letter.
•• Each engagement to be assigned to an engagement partner with the appropriate skills
and authority to perform the role, and whose responsibilities are clearly defined and
communicated to them (ISQC 1 paras 30(b) and (c)). For example, the firm may maintain
a register of each partner’s industry experience to enable an appropriate partner to be
assigned to any new clients.
•• That the firm assign personnel to engagements who can perform the work in accordance
with the relevant Standards and legislation, and whose work allows the firm to issue
appropriate reports (ISQC 1 para. 31). For example, some larger firms organise audit staff
into specialist groups (e.g. banking and finance, manufacturing, mining, information
technology and communications, retail, etc.) to ensure that appropriately skilled staff are
assigned to engagements within specific industries.
CC
Required reading
ISQC 1 paras 29–31.
Engagement performance
The performance of engagements is critical to a firm’s quality control system. Without adequate
quality processes surrounding engagement performance, a firm would have greater exposure
to the risk of providing an inappropriate auditor’s report. Accordingly, ISQC 1 sets down
numerous requirements regarding this element.
As with the human resources element, a firm’s engagement policies and procedures need to
provide reasonable assurance that it has sufficient, appropriately skilled personnel to:
•• Perform engagements in accordance with relevant Standards and legislation.
•• Enable the firm to issue appropriate reports.
In order to achieve this, ISQC 1 para. 32 requires firms to establish policies and procedures that
include:
•• Methods to promote a consistent level of quality in the performance of engagements
(ISQC 1 para. 32(a)). For example, the firm may use an audit manual and specific audit
software to ensure its audit documentation is prepared consistently across all engagements.
•• Supervision responsibilities (ISQC 1 para. 32(b)). For example, the audit manager might
keep track of each team member’s progress in working through their assigned tasks, and
provide additional instructions where required.
•• Review responsibilities (ISQC 1 para. 32(c)). For example, the audit manager might review
each file section and determine whether the work performed is sufficient to support the
conclusions reached.
•• Regarding review responsibilities, the work of less experienced team members must always
be reviewed by more experienced team members (ISQC 1 para. 33). A practical example of
how a firm might apply this requirement would be to establish a policy requiring the work
of a first-year auditor to be reviewed by a senior auditor, the work of a senior auditor to
be reviewed by a manager, and the work of a manager to be reviewed by the engagement
partner.
•• The work has been performed in accordance with professional Standards and applicable
legal and regulatory requirements.
•• Significant matters have been raised for further consideration.
•• Appropriate consultations have taken place and the resulting conclusions have been
documented and implemented.
•• There is a need to revise the nature, timing and extent of work performed.
•• The work performed supports the conclusions reached and is appropriately documented.
•• The evidence obtained is sufficient and appropriate to support the report.
•• The objectives of the engagement procedures have been achieved.
ISQC 1 also requires a firm to implement further policies and procedures on engagement
performance, in relation to:
•• Consultation.
•• Engagement quality control review (EQCR).
•• Differences of opinion.
•• Documentation, confidentiality and safe custody, and document retention.
CC
These performance areas are outlined below.
Consultation
Policies and procedures related to consultation need to provide reasonable assurance that:
•• Where ‘difficult or contentious matters’ are involved, consultation will occur (ISQC 1
para. 34(a)). For example, a firm may require a second audit partner to review an
engagement file where it appears a qualified audit opinion may be issued.
•• There are sufficient resources to allow proper consultations to occur (ISQC 1 para. 34(b)).
For example, a firm may allocate all or part of a senior staff member’s time to a technical
support role, to ensure specialised resources are available when required.
•• Details of consultations are documented and agreed to by the parties involved, and
conclusions resulting from consultations are implemented (ISQC 1 paras 34(c) and (d)). For
example, the firm might have a standard work paper or form that must be used to record all
consultations and any action subsequently taken.
EQCRs are therefore aimed at engagements involving riskier, high-profile clients where the risk
of reaching an inappropriate conclusion is higher than normal, and the negative consequences
of an erroneous conclusion are greater.
Under ISQC 1 para. 37, firms must, at a minimum, implement policies and procedures that
require an EQCR to include:
•• Discussing ‘significant matters’ with the engagement partner. For example, changes in a
client’s accounting policies are often considered a significant matter (para. 37(a)).
•• Reviewing the subject matter and proposed report. For a financial statements audit, this
would include review of both the financial statements and auditor’s report (para. 37(b)).
•• Reviewing documentation regarding significant judgements made and conclusions
reached. For example, a mining company may have complex accounting issues related to
asset impairment that require the engagement team to exercise significant judgement in its
evaluation (para. 37(c)).
•• Evaluating the conclusions reached and considering if the auditor’s report is appropriate
in the circumstances of the engagement. For example, if a qualified opinion is planned, the
EQCR would check that the proposed wording properly reflects the conclusions reached
(para. 37(d)).
For listed entities, under ISQC 1 para. 38, the policies and procedures related to EQCRs also
need to include:
•• The engagement team’s evaluation of the firm’s independence with regard to the
engagement (para. 38(a)).
•• Whether ‘appropriate consultation’ has occurred regarding matters over which there are
differences of opinion or which are contentious (para. 38(b)).
•• Whether documentation that has been selected for review is supportive of the engagement’s
conclusions (para. 38(c)).
CC
In order to be effective, EQCRs need to be carried out by an appropriate engagement quality
control reviewer. ISQC 1 requires firms to establish policies and procedures that provide
reasonable assurance that reviewers:
•• Have the necessary technical qualifications, experience and authority (ISQC 1 para. 39(a)).
For example, the firm may require that reviewers are only appointed to engagements where
they have prior experience in the client’s industry.
•• Are only consulted by engagement partners and staff to an extent that does not compromise
their objectivity (ISQC 1 para. 39(b)).
•• Are replaced in circumstances where they are unable to perform an objective review
(ISQC 1 para. 41) – for example, where the reviewer is required to provide extensive
technical assistance to an engagement team due to changes in the client’s operations.
As with all audit and assurance-related matters, documentation is important. ISQC 1 para. 42
requires that documentation of an EQCR should provide evidence that:
•• The procedures required by the firm have been performed – for example, procedures
related to the appointment of an appropriate reviewer (para. 42(a)).
•• The review was completed on or before the date of the report (para. 42(b)).
•• No unresolved matters have come to the reviewer’s attention that would cause them to
believe that the conclusions reached are inappropriate (para. 42(c)).
Differences of opinion
Where there are differences of opinion within the engagement team – with those consulted, and
between the engagement partner and engagement quality control reviewer – the firm’s policies
and procedures shall require any conclusions reached to be documented and implemented, and
the report to be dated only once the matter is resolved (ISQC 1 paras 43–44).
Required reading
ISQC 1 paras 32–47 and A35 and A54.
Monitoring
The five elements of a quality control system addressed so far form the basis of a firm’s quality
control system. Such a system can only work effectively if it is regularly checked and corrections
made when the system does not function as planned.
ISQC 1 para. 48 requires firms to establish a ‘monitoring process’ that is designed to provide
reasonable assurance that the quality control system’s policies and procedures are ‘relevant,
adequate, and operating effectively’. The monitoring process is required to:
•• Include ongoing evaluation of the quality control system, including inspection of at least
one completed engagement for each partner by an independent (of the engagement) party.
(The explanatory material provided by ISQC 1 para. A66 notes that an inspection cycle may
span three years.)
•• Assign responsibility of the process to a person with appropriate experience and authority.
CC
ISQC 1 also requires a firm to implement monitoring policies and procedures that cover
a number of other issues, including:
•• Evaluating, communicating and remedying identified deficiencies.
•• Complaints and allegations.
For example, if independence breaches in an audit are revealed during the monitoring
process, the action taken might include informing the relevant staff member and engagement
partner, and requesting that the matter be included as an example in upcoming training and
development programs.
When the monitoring process indicates that a report issued by the firm may be inappropriate,
the firm needs to determine what further action is required and consider whether to obtain legal
advice (ISQC 1 para. 52).
Once a year at a minimum, the firm needs to communicate the results of the monitoring process
to engagement partners and other relevant parties (ISQC 1 para. 53).
The information communicated must:
•• Describe the monitoring procedures that were performed (para. 53(a)).
•• Provide the conclusions of the procedures (para. 53(b)).
•• Where relevant, describe the systemic or repetitive deficiencies of the quality control system
as well as the remedial action that was taken (para. 53(c)).
CC
If the firm’s investigations into complaints and allegations reveal deficiencies in its quality
control policies and procedures, appropriate remedial action must be taken.
As an auditor rises in seniority, the more relevant ISQC 1’s monitoring requirements
(as described above) become. However, even junior auditors need to understand the purpose of
the monitoring process and the key activities performed in this regard.
Required reading
ISQC 1 paras 48–56 and A66.
This section, relating to audit documentation, demonstrates the interrelationship between the
elements of quality control. Establishing appropriate documentation policies and procedures is
fundamental to the provision of assurance services.
Required reading
ISQC 1 paras 17, 45–47, 57 and 59.
CC
Australia-specific
Quality control in Australia
There are four key Standards relating to quality control in Australia:
•• ASQC 1 Quality Control for Firms that Perform Audits and Reviews of Financial Reports and
Other Financial Information, Other Assurance Engagements and Related Services Engagements
(ASQC 1).
•• APES 320 Quality Control for Firms (APES 320).
•• ASA 102 Compliance with Ethical Requirements when Performing Audits, Reviews and Other
Assurance Engagements (ASA 102).
•• ASA 220 Quality Control for an Audit of a Financial Report and Other Historical Financial
Information (ASA 220).
ASQC 1
ASQC 1, issued by the Auditing and Assurance Standards Board (AUASB), deals with a firm’s
responsibility for a system of quality control in its assurance practices. It does not apply
to individual auditors within a firm. As with the Australian Auditing Standards (ASAs), ASQC 1
is based on its international equivalent, ISQC 1. In issuing ASQC 1, the AUASB brings the
international Standard into the suite of Australian Standards that are legally enforceable under
the Corporations Act 2001 (Cth) (Corporations Act) for engagements governed by that Act.
While ASQC 1 conforms to ISQC 1, the differences are denoted by the prefix ‘Aus’ in the relevant
paragraph numbers. There are two key differences:
•• The annual independence confirmation is required to also cover compliance with legal
and regulatory requirements, as well as with ethical requirements. This brings, for example,
compliance with the independence requirements of the Corporations Act into the scope
of the confirmation (ASQC 1 para. Aus 24.1).
•• In relation to consultation, Australian practices must comply with an additional
requirement to document the reasons for undertaking alternative courses of action from
consultation (ASQC 1 para. Aus 34.1).
In addition:
•• Requirements in ISQC 1 in relation to compliance with ethical requirements have been
moved to ASA 102 (discussed below), and therefore do not appear in ASQC 1. There is no
international equivalent to ASA 102.
Unlike ISQC 1:
•• ASQC 1 requires that work papers be retained for seven years in relation to all audits and
reviews performed under the Corporations Act.
ASQC 1 also incorporates the terminology and definitions that are used in Australia. These are
found in paras Aus 12.1–Aus 12.2.
APES 320
Prior to the AUASB issuing ASQC 1, the APESB issued APES 320, which is based on ISQC 1 but,
due to different drafting conventions, appears different. This is largely because APES 320
applies to all firms, regardless of whether they conduct assurance engagements. Accordingly,
for each of the quality control elements, APES 320 outlines the requirements that are relevant
to all firms, and then separately lists the requirements that apply only to assurance practices.
The content of APES 320 and ASQC 1 is, for all practical purposes, the same. Therefore,
compliance with APES 320 ensures compliance with ASQC 1.
ASA 102
The AUASB issued ASA 102 for Australian legislative purposes – that is, to bring the
requirements of APES 110 into the suite of Standards that are legally enforceable under the
Corporations Act, for engagements carried out under that Act. For example, in Australia,
CC
under APES 110, the key audit partner is normally required to rotate off a listed entity audit
after a period of no more than seven years (APES 110 para. 290.152). However, further
to the requirements of APES 110, more stringent rotation requirements apply to the audits
of listed entities and registered schemes in Australia. Under s. 324DA of the Corporations Act,
an individual who plays a significant role in the audit of such entities for five successive financial
years must not play a significant role in the audit for at least two successive years before playing
a significant role on the audit again. There is, therefore, no international equivalent to ASA 102.
The single objective and requirement of ASA 102 is that individuals and firms comply with
relevant ethical requirements, including those pertaining to independence, when conducting
assurance engagements.
ASA 220
ASQC 1 and APES 320 prescribe quality control requirements at the firm level, while ASA 220
prescribes them at the individual engagement level.
For example, ASQC 1 requires partners (or their equivalents) to be responsible for the firm’s
overall quality control system, while ASA 220 requires the engagement partner to take
responsibility for quality control on all audits to which that partner is assigned.
ASA 220 is based on its international equivalent, ISA 220, and is discussed further in the unit on
pre-engagement activities.
The relationship between the four Australian quality control Standards above and their
international equivalents can be shown as follows:
forms basis of
AUASB-issued APESB-issued
essentially
ASQC 1 the same APES 320
INDIVIDUAL
ENGAGEMENT LEVEL
CC
Required reading
ASQC 1 paras Aus 0.1–Aus 0.2, Aus 1.1, Aus 4.1–Aus 4.2, Aus 12.1–Aus 12.12, Aus 24.1,
Aus 34.1, Aus A1.1, Aus A10.1, Aus A12.1, Aus A13.1, Aus A14.1, Aus A61.1–Aus A61.2,
Aus A63.1 and Aus A68.1.
APES 110 paras 1.2, 2 and s. 290.
APES 320 paras 1–18.
ASA 102.
ASA 220.
Corporations Act (Cth) s. 324DA.
New Zealand-specific
Quality control in New Zealand
There are two key Standards relating to quality control in New Zealand:
•• PES 3 (Amended) Quality Control for Firms that Perform Audits and Reviews of Financial
Statements, and Other Assurance Engagements (PES 3).
•• ISA (NZ) 220 Quality Control for an Audit of Financial Statements (ISA (NZ) 220).
PES 3
PES 3, issued by the New Zealand Auditing and Assurance Standards Board (NZAuASB), deals
with a firm’s responsibility for a system of quality control in its assurance practices. It does
not apply to individual auditors within a firm. As with the New Zealand Auditing Standards
(ISAs (NZ)), PES 3 is based on its international equivalent, ISQC 1. In issuing PES 3, the NZAuASB
brings the Standard in line with international requirements. These Standards are legally
enforceable under the Financial Markets Conduct Act 2013 (FMCA), the Companies Act 1993
and Financial Reporting Act 1993 (FRA93) by virtue of the requirement for audits of financial
statements to comply with applicable auditing and assurance standards. With the change in
legislation discussed in the unit on assurance purpose and framework, this requirement exists
in the FMCA for FMC reporting entities, Companies Act 1993 for large entities that are not FMC
reporting entities, and FRA93 for entities that have not yet transitioned to the new legislation.
While PES 3 conforms to ISQC 1, the differences are denoted by the prefix ‘NZ’ in the relevant
paragraph numbers. These include:
•• NZ 31.1 – An emphasis on the requirement of sufficient time being a consideration when
assigning the engagement team.
•• NZ 34.1 – In relation to consultation, New Zealand practices must comply with an
additional requirement to document the reasons for undertaking alternative courses of
action from consultation.
Unlike ISQC 1:
•• PES 3 does not apply to related service engagements (i.e. agreed-upon procedures and
compilation engagements).
ISA (NZ) 220
ISA (NZ) 220 deals with quality control on audit engagements. It is based on its international
equivalent, ISA 220, and is consistent with PES 3, which prescribes quality control requirements
for all assurance engagements. ISA (NZ) 220 is discussed further in the unit on pre-engagement
activities.
CC
Required reading
PES 3 paras NZ 1.1, NZ 3.1, NZ 4.1, NZ 12.1–NZ 12.9, NZ 31.1 and NZ 34.1.
ISA (NZ) 220.
Audit documentation
Learning outcome
3. Demonstrate the nature and purpose of audit documentation, and the objective and
requirements of preparing audit documentation.
A number of regulators have audit oversight responsibilities and conduct inspection programs
related to audits performed by registered auditors. In conducting these inspections, there
is usually a presumption that if audit work has not been documented, then it has not been
done. This assumption is supported by the requirements of the Auditing Standards regarding
audit documentation at the engagement level, and by separate obligations regarding the
establishment and maintenance of quality control policies and procedures applicable to all audit
engagements conducted by the audit firm.
Guidance on audit documentation is provided by ISA 230.
Audit documentation is critical to the audit process, as it provides a record of:
•• audit procedures performed and the reasons behind selecting those procedures
•• evidence obtained, and
•• conclusions reached based on that evidence.
It also helps to demonstrate that an audit was performed in accordance with relevant Auditing
Standards and legal and regulatory requirements. This is particularly important in the event
that the auditor’s report is ever called into question – for example, during a court case brought
about by the financial collapse of a client, or during an examination by a regulatory authority.
Under ISA 230 para. 3, audit documentation also:
•• Assists the engagement team in planning and performing the audit – for example,
by providing a record of the audit procedures to be performed.
•• Assists senior staff in supervising the audit work and carrying out their review
responsibilities – for example, the audit partner can initial work papers prepared by junior
staff as evidence of the audit partner’s review.
•• Retains records of matters of ongoing significance to future audits – for example, work
papers describing the entity’s internal controls.
•• Enables the conduct of quality reviews by relevant professional bodies, or regulatory
reviews by relevant authorities.
CC
documentation requirements (refer ISA 230 para. 1, Appendix). Audit documentation should
include (but is not limited to):
•• Descriptions of a client’s internal control systems (ISA 315 (Revised) Identifying and Assessing
the Risks of Material Misstatement through Understanding the Entity and Its Environment
(ISA 315) para. 32(b)).
•• Analysis of the risks of material misstatement of the various amounts in the financial
statements (ISA 315 para. 32(c)).
•• The audit strategy and plan, and any significant changes made to the audit strategy or plan
(including the reasons for changes) (ISA 300 para. 12).
•• External confirmations, such as those received from the client’s bankers (ISA 230 para. A3).
•• Trial balance and final financial statements, cross-referenced to the relevant audit work
papers (ISA 330 The Auditor’s Response to Assessed Risks (ISA 330) para. 30).
•• Minutes of meetings with the client and among engagement team members (ISA 230
paras A7 and A14).
•• Management representation letters (ISA 230 para. A3).
•• Evidence of the use of professional scepticism (ISA 230 para. A7) – for example, where there
are doubts about an entity’s ability to continue as a going concern and the matter is further
investigated in order to determine whether management’s view is justified.
In addition to the above, ISA 230 para. 12 requires that if, ‘in exceptional circumstances’, there is
a need to depart from a relevant requirement in an ISA, the following is to be documented:
•• How alternative audit procedures met the aim of the requirement.
•• The reasons for using alternative procedures.
Specific audit documentation requirements are covered in the relevant units of the
AAA module.
CC
Once the final audit file has been completed, none of the contents are to be deleted or discarded
before the end of the appropriate retention period (ISA 230 para. 15).
Required reading
ISA 230.
CC
Australia-specific
Audit documentation in Australia
ASA 230 Audit Documentation (ASA 230) is based on its international equivalent, ISA 230, with
only three key differences (denoted by the prefix ‘Aus’ in the relevant paragraph numbers):
•• In ASA 230 para. Aus 12.1, where factors ‘outside the auditor’s control’ prevent the auditor’s
compliance with an ‘essential procedure’ of a requirement, there is a need to document:
–– the circumstances preventing the auditor’s compliance (para. Aus 12.1(a))
–– the reasons for their inability to comply (para. Aus 12.1(b)), and
–– a justification of how alternative audit procedures meet the aim of the requirement
(para. Aus 12.1(c)).
For example, if some of the client’s accounting records were destroyed in a fire, the auditor
might not be able to carry out all the required procedures, and may have to obtain audit
evidence by other means.
•• The auditor needs to ‘adopt appropriate procedures for maintaining the confidentiality,
safe custody, integrity, accessibility and retrievability of the audit documentation’
(ASA 230 para. Aus 16.1).
CC
•• Under the Corporations Act, the auditor or audit firm is required to ‘retain all audit
working papers prepared by or for, or considered or used by, the auditor in accordance
with the requirements of the Australian Auditing Standards until the end of seven
years after the date of the audit report’ or a time otherwise determined by the
Australian Securities Investment Commission (ASIC) (see s. 307B), or for a period of
time specified by relevant legislation or regulation other than the Corporations Act
(ASA 230 paras Aus A23.1–A23.2).
Required reading
ASA 230 paras Aus 12.1, Aus 16.1 and Aus A23.1–A23.2.
Corporations Act s. 307B.
Quiz
[Available online in myLearning]
Readings
Required reading
International Standard on Quality Auditing Standard ASQC1 Quality PES 3 (Amended) Quality Control
Control ISQC 1 Quality Controls Controls for Firms that Perform for Firms that Perform Audits and
for Firms that Perform Audits and Audits and Reviews of Financial Reviews of Financial Statements,
Reviews of Financial Statements, Reports and Other Financial and Other Assurance Engagements
and Other Assurance and Related Information, Other Assurance
Services Engagements Engagements and Related Services
Engagements
•• Paragraphs 1–59, A2, A4–A7, A9, •• Paragraphs 1–59, A2, A4–A7, A9, •• Paragraphs 1–59, A2, A4–A7, A9,
A18–A19, A54 and A66 A18–A19, A54 and A66 A18–A19, A54 and A66
•• Paragraphs Aus 0.1–Aus 0.2, •• Paragraphs NZ 1.1, NZ 3.1,
Aus 1.1, Aus 4.1–Aus 4.2, NZ 4.1, NZ 12.1–NZ 12.9, NZ 31.1
Aus 12.1–Aus 12.12, Aus 24.1, and NZ 34.1
Aus 34.1, Aus A1.1, Aus A10.1,
Aus A12.1, Aus A13.1, Aus A14.1,
Aus A61.1–Aus A61.2, Aus A63.1
and Aus A68.1
ISA 220 Quality Control for an Audit ASA 220 Quality Control for an Audit ISA (NZ) 220 Quality Control for an
of Financial Statements of a Financial Report and Other Audit of Financial Statements
Historical Financial Information
ISA 230 Audit Documentation ASA 230 Audit Documentation ISA (NZ) 230 Audit Documentation
Code of Ethics for Professional APES 110 Code of Ethics for PES 1 (Revised) Code of Ethics for
Accountants (IESBA Code) (2015) Professional Accountants Assurance Practitioners
•• Definitions and s. 290 •• Paragraphs 1.2, 2 and s. 290 •• Paragraphs NZ 1.2, NZ 210.12.1,
NZ 220.10.1, NZ 290.11.1 and
NZ 291.10.1, Definitions and
s. 290
ACT
Activity 2.1
Consultation and documentation
Introduction
ISA 230 Audit Documentation (ISA 230) contains the documentation requirements applicable to
individual audit engagements.
ISQC 1 Quality Control for Firms that Perform Audits and Reviews of Financial Statements, and Other
Assurance and Related Services Engagements (ISQC 1) provides audit firms with the framework for
establishing a system of quality controls that is applicable to all audits they conduct.
One aspect of ISQC 1 is the requirement for firms to establish policies and procedures for
consultation on contentious issues. Closely related to this is the ISA 230 requirement for firms to
document significant matters arising during the audit. That is, matters requiring consultation,
by nature, are likely to be significant items regardless of the conclusions reached.
This activity considers how audit documentation at the engagement level can provide evidence
to support the existence and implementation of appropriate audit quality controls at the firm
level, while also demonstrating compliance with audit documentation obligations that are
specific to the engagement.
This activity links to learning outcomes:
•• Illustrate the overall responsibilities of firms with regard to ethics and quality control.
•• Demonstrate the nature and purpose of audit documentation, and the objective and
requirements of preparing audit documentation.
At the end of this activity, you will be able to identify appropriate audit documentation
requirements in respect of contentious issues for a listed company.
It will take you approximately 30 minutes to complete.
Scenario
You are a first year auditor at a large accounting firm, Green Tick, reporting to Adam Ant, the
senior manager on an audit engagement with Slick Oil Refinery Limited (Slick). Slick is a locally
listed company that has a significant shareholder, Good Oil Inc. (Good Oil), a large energy
company listed on the New York Stock Exchange.
Due to a major oil spill that occurred in January 20X3, Slick recognised a large remediation
provision. Green Tick’s audit team has been able to gain reasonable assurance over the estimate
of this provision. However, because of the provision, Slick has a net liability of $15 million as at
the year ended 30 June 20X3, which raises a going concern issue for the company.
Slick has obtained a letter of financial support from Good Oil stating that it will financially
support Slick in the event that Slick is unable to meet its financial obligations. Slick has
prepared its financial statements on a going concern basis. The letter of financial support is one
factor in Slick’s assessment of the going concern assumption.
Adam has reviewed Good Oil’s audited financial report for the year ended 30 April 20X3 and
notes that it has a cash and cash equivalents balance of US$400 million. Good Oil also has other
financial assets totalling US$800 million and net assets of US$10 billion.
ACT
Adam has also consulted with Green Tick’s in-house legal counsel, John Frost, and the firm’s
technical partner, Joanne Abbot. These consultations have indicated that Good Oil’s letter of
financial support can be relied on and provides evidence to support the appropriateness of
Slick’s going concern assumption.
Adam has discussed this matter with Eduardo Priestly, the engagement partner, and Joanne
Abbot. Joanne has requested that the engagement team ensures the financial statements contain
appropriate disclosure of both the going concern assumption and the existence of the letter of
financial support. Joanne has also requested that the auditor’s report include an Emphasis of
Matter paragraph that refers to that note of disclosure dealing with the entity’s going concern
assumption.
The following file note is contained in the engagement file:
ACT
Tasks
Adam is coaching you on the importance of audit documentation. He has requested that you
review the file note and then perform the following tasks:
1. Identify the relevant requirements of:
•• ISQC 1 regarding engagement performance, consultation and engagement quality
control review, and
•• ISA 230 regarding the form, content and extent of audit documentation.
2. State whether the file note provides evidence that the requirements identified in Task 1 have
been met.
3. Justify your conclusion from Task 2.
Adam points out that there may be other existing documentation that demonstrates the firm’s
compliance with requirements of the Auditing Standards. However, for the purpose of this
exercise, consider the file note as the only evidence of compliance with the relevant Standards.
You may wish to use the consultation and documentation template provided below:
For this activity, you do not need to consider the requirements of ISA 570 Going Concern or
ISA 706 Emphasis of Matter Paragraphs and Other Matter Paragraphs in the Independent Auditor’s
Report.
[Solutions to activities are available online. Please access myLearning to view]
CC
Core content
Unit 3: Pre-engagement activities
Learning outcomes
At the end of this unit you will be able to:
1. Apply the code of ethics and relevant guidance, statements and legislation regarding
auditor independence.
2. Apply the elements of quality control that must be applied at the individual engagement
level.
3. Outline the auditor’s responsibilities in agreeing the terms of the audit engagement,
including the mandatory items to be included in an engagement letter.
4. Describe and explain the auditor’s responsibility to communicate audit matters to those
charged with governance.
Introduction
This unit addresses the activities and processes an auditor must undertake prior to commencing
an engagement, which are collectively known as the pre-engagement activities.
The major steps in the pre-engagement process are shown below:
YES NO
Document procedures performed and how threats and issues were resolved
STOP
Are the audit Are there any Agree on the Prepare/sign
preconditions scope limitations? terms of engagement
present?1 engagement letter
1
The preconditions are the steps set out in the top three boxes of the diagram.
CC
This unit looks at the following International Standards on Auditing (ISAs) and other guidance
that applies to pre-engagement activities:
•• ISA 200 Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance
with International Standards on Auditing (ISA 200).
•• ISA 210 Agreeing the Terms of Audit Engagements (ISA 210).
•• ISA 220 Quality Control for an Audit of Financial Statements (ISA 220).
•• ISA 260 Communication with Those Charged with Governance (ISA 260).
•• International Ethics Standards Board for Accountants (IESBA), Code of Ethics for Professional
Accountants (IESBA Code).
•• International Standard on Quality Control ISQC 1 Quality Control for Firms that Perform
Audits and Reviews of Financial Statements and Other Assurance and Related Services
Engagements (ISQC 1).
Auditor independence
Learning outcome
1. Apply the code of ethics and relevant guidance, statements and legislation regarding auditor
independence.
Chartered Accountants can face a broad range of relationships and circumstance, some of which
may pose a threat to their compliance or perceived compliance with the fundamental principles
of the IESBA Code. This section addresses the ethical and other guidelines, as well as legislative
obligations, that an auditor must comply with when undertaking audit and assurance
engagements.
IESBA Code
The IESBA issues the IESBA Code, which sets out the ethics requirements for professional
accountants. The IESBA Code is structured in three parts:
•• Part A – General Application of the IESBA Code.
•• Part B – Professional Accountants in Public Practice.
•• Part C – Professional Accountants in Business Practice.
Part A establishes the fundamental principles and provides a conceptual framework that can be
applied to:
(a) Identify threats to compliance with the fundamental principles;
(c) Apply safeguards, when necessary, to eliminate the threats or reduce them to an acceptable level.
Safeguards are necessary when the professional accountant determines that the threats are not
at a level at which a reasonable and informed third party would be likely to conclude, weighing
all the specific facts and circumstances available to the professional accountant at that time, that
compliance with the fundamental principles is not compromised.
A professional accountant shall use professional judgment in applying this conceptual framework.
Parts B and C describe how the conceptual framework applies in specific circumstances. They
provide examples of safeguards that may appropriately address threats to compliance with the
fundamental principles. Where no safeguard is available in the circumstance, the threat must be
avoided altogether.
CC
It is important to note that accountants are expected to be guided not merely by the words, but
also by the spirit of the IESBA Code, using the conceptual framework (paras 100.6–100.11).
While all sections of the IESBA Code are equally important, this unit focuses on Part A and
s. 290 of Part B.
Fundamental principles
The IESBA Code lists its five fundamental principles in para. 100.5, as outlined below:
100.5(a) Integrity To be straightforward and honest in all professional and business relationships
100.5(b) Objectivity To not allow bias, conflict of interest or undue influence of others to override
professional or business judgments
100.5(c) Professional To maintain professional knowledge and skill at the level required to ensure
competence that a client or employer receives competent professional services based on
and due care current developments in practice, legislation and techniques and act diligently
and in accordance with applicable technical and professional standards
100.5(e) Professional To comply with relevant laws and regulations and avoid any action that
behaviour discredits the profession
Each of these principles is discussed in more detail in the IESBA Code ss 110–150.
100.12(a) Self-interest The threat that a financial or other •• Loans to or from an audit client
interest will inappropriately influence •• Concern about the possibility of
the professional accountant’s judgment losing a recurring client
or behaviour
•• The temptation to accept gifts
offered by a client
CC
100.12(c) Advocacy The threat that a professional •• Promoting shares in a listed audit
accountant will promote a client’s client
or employer’s position to the point •• Acting as an advocate on behalf of
that the professional accountant’s an audit client in resolving disputes
objectivity is compromised with third parties
100.12(d) Familiarity The threat that due to a long or close •• Accepting preferential treatment
relationship with a client or employer, unless the value is clearly
a professional accountant will be too insignificant
sympathetic to their interests or too •• Close or immediate family
accepting of their work relationship with a director or
officer of a client, or with an
employee who has a position
of influence over the subject of
the engagement (applies to any
member of the engagement team)
100.12(e) Intimidation The threat that a professional •• Being threatened with dismissal
accountant will be deterred from or replacement in a client
acting objectively because of actual engagement
or perceived pressures, including •• Being threatened with litigation
attempts to exercise undue influence
•• Being pressured to reduce the
over the professional accountant
extent of work required in order to
reduce fees
Source: IESBA Code Part A para. 100.12 and Part B paras 200.4–200.8.
Safeguards are actions or other measures that may eliminate threats or reduce them to an
acceptable level. There are two broad categories of safeguards (IESBA Code paras 100.13–
100.14):
•• Those created by the profession, legislation or regulation – for example, professional
Standards, professional or regulatory monitoring, and disciplinary procedures.
•• Those created in the workplace – for example, documented internal policies or a firm’s
quality control policies and procedures.
Required reading
IESBA Code 2015 ss 100–150.
CC
Independence
IESBA Code s. 290 addresses the independence requirements for audit and review engagements
in which the accountant expresses a conclusion on the financial statements (either a complete
set of financial statements or a single financial statement).
The independence requirements for other types of assurance engagements are addressed in
IESBA Code s. 291.
The following parties are required under IESBA Code para. 290.4 to be independent of the audit
client:
•• Members of the audit team.
•• The firm.
•• Any network firms.
Each of these, including the term ‘audit client’, is defined in the IESBA Code Definitions.
It should be noted that these are broad definitions. For example, a ‘firm’ is defined as:
(a) A sole practitioner, partnership or corporation of professional accountants;
(b) An entity that controls such parties, through ownership, management or other means; and
(c) An entity controlled by such parties, through ownership, management or other means.
The audit of an entity is relevant to a wide range of potential users, and so the actual and
perceived independence of the audit is of particular significance. The IESBA Code ‘Definitions’
(and also para. 290.6) defines ‘independence’ as:
(a) Independence of mind – the state of mind that permits the expression of a conclusion without being
affected by influences that compromise professional judgment, thereby allowing an individual to
act with integrity, and exercise objectivity and professional skepticism.
(b) Independence in appearance – the avoidance of facts and circumstances that are so significant that
a reasonable and informed third party would be likely to conclude, weighing all the specific facts
and circumstances, that a firm’s, or a member of the audit or assurance team’s, integrity, objectivity
or professional skepticism has been compromised.
The objective of IESBA Code s. 290 is to assist firms and members of audit teams in applying the
conceptual framework approach to achieving and maintaining independence.
As set out in IESBA Code para. 290.7, the conceptual framework is applied by an accountant to:
•• identify threats to independence
•• evaluate the significance of the threats identified, and
•• apply safeguards (when necessary) to eliminate or reduce the threats to an acceptable level.
If the accountant determines that no appropriate safeguards are available, or that appropriate
safeguards do not reduce the threats to an acceptable level, either the circumstance or
relationship that creates the threat must be eliminated, or the accountant should decline or
terminate the audit engagement.
The application of the conceptual framework approach to independence is addressed in
IESBA Code paras 290.100–290.228. These paragraphs describe specific circumstances and
relationships that create, or may create, threats to independence; the types of safeguards that
may be appropriate; and circumstances in which no safeguards could reduce the threats to an
acceptable level.
Required reading
IESBA Code 2015 ss 200–290.
IESBA Code 2015 paras 291.1–291.3.
IESBA Code ‘Definitions’.
CC
Australia-specific
APES 110
APES 110 Code of Ethics for Professional Accountants (APES 110) is issued by the Accounting
Professional and Ethical Standards Board (APESB) and is the Australian equivalent of the IESBA
Code.
As noted in the unit on Auditing Standards and quality control, the requirements of APES 110
are within the suite of Standards that are legally enforceable under the Corporations Act 2001
(Cth) (Corporations Act). APES 110 para. 1.4 states:
This Code is not intended to detract from any responsibilities which may be imposed
by law or regulation. AUASB has issued auditing standards as legislative instruments
under the Corporations Act 2001 (the Act). For audits and reviews under the Act, those
standards have legal enforceability. To the extent that those auditing standards make
reference to relevant ethical requirements, the requirements of APES 110 have legal
enforceability due to Auditing Standard ASA 102 Compliance with Ethical Requirements
when Performing Audits, Reviews and Other Assurance Engagements.
Under ‘Compliance with the IESBA Code’ at the end of APES 110, the Standard notes that the
principles and requirements of APES 110 and the IESBA Code are consistent, with the following
exceptions:
•• The addition of a Scope and Application section in APES 110;
•• The addition of paragraphs and definitions prefixed as AUST in APES 110. The
additional definitions are of AASB, Administration, AuASB, AUASB, Auditing and
Assurance Standards, Australian Accounting Standards and Member;
•• APES 110 generally refers to Members whereas the IESBA Code refers to
professional accountants;
•• Defined terms are in title case in APES 110;
•• The definition of Engagement Team in APES 110 does not exclude individuals
within the client’s internal audit function who provide direct assistance on an Audit
Engagement as the AUASB has prohibited the use of direct assistance in Auditing
and Assurance Standard ASA 610 Using the Work of Internal Auditors (November
2013);
•• APES 110 tailors the following IESBA defined terms to the Australian environment:
Audit Engagement, Engagement Team, Financial Statements, Firm, Member in
Public Practice, and Review Engagement;
•• Paragraph 290.25 of APES 110 expresses Public Interest Entity in the singular form
consistent with its definition in section 2;
•• Paragraph 290.26 in APES 110 mandates Firms to determine whether additional
entities are Public Interest Entities and the reference to member bodies has been
removed; and
•• Unless strict requirements are met, APES 110 prohibits Members in Public
Practice from providing accounting and bookkeeping services and preparing tax
calculations for Audit Clients which are Public Interest Entities, even in emergency
situations (refer APES 110 paras 290.169–290.170, and 290.182).
Required reading
APES 110 para. 1.4.
CC
Part 2M.3
Division 3 Auditor’s independence declaration – the auditor must give the directors of the
s. 307C entity a written statement that there have been no contraventions of the auditor
independence requirements of the Corporations Act in relation to the audit, unless
set out in that declaration
Part 2M.4
Division 3 Sets out the general requirements for audit independence for individual auditors,
ss 324CA–324CC members of audit firms and directors of audit companies
Division 3 Sets out the specific requirements for audit independence for individual auditors,
ss 324CE–324CG members of audit firms and directors of audit companies
Division 3 Relevant relationships that may result in contravention of the above sections
s. 324CH
Division 3 Special rules applicable to former audit firm partners or audit company directors.
ss 324CI–324CK A two-year waiting period applies to such personnel before they can be engaged as
officers of the audited body
Division 4 Details circumstances in which an individual, audit firm or audit company are
s. 324CM deliberately disqualified from being appointed as an auditor of an entity requiring
an audit, in accordance with the Corporations Act
Division 5 Deals with the requirements for auditor rotation of listed companies and registered
ss 324DA–324DD schemes
Required reading
Corporations Act s. 307C and Part 2M.4 Divisions 3–5.
CC
New-Zealand specific
PES 1 (Revised) Code of Ethics for Assurance Practitioners (PES 1)
PES 1 is the New Zealand equivalent of the IESBA Code. The requirements of PES 1 are within
the suite of Standards that are legally enforceable under the Financial Markets Conduct Act 2013
and the Financial Reporting Act 1993.
PES 1 was issued by the by the External Reporting Board (XRB) and the New Zealand Audit
and Assurance Standards Board (NZAuASB). It is applicable to all assurance engagements and
practitioners.
The principles and requirements of PES 1 are generally consistent with the IESBA Code,
including the numbering of the IESBA Code being used as the structure of PES 1. Additional
paragraphs for the New Zealand environment are denoted by the prefix ‘NZ’ in the relevant
paragraph numbers.
The key differences between PES 1 and IESBA Code include:
•• PES 1 has a narrower scope and is only applied to assurance practitioners, whereas the
IESBA Code applies to all professional accountants.
•• Sections have been deleted if they don’t apply, including sections that do not relate to
assurance engagements.
•• More stringent requirements, including paragraphs added with the prefix ‘NZ’, such as:
–– Extending the independence requirements to all public interest entities.
–– Extending partner rotation requirements to all key audit partners.
–– Key audit partners are not allowed to be compensated for selling non-assurance.
As noted in the unit on Auditing standards and quality control, NZICA has a statutory obligation
to have a code of ethics which governs the professional conduct of members of Chartered
Accountants Australia and New Zealand that reside in New Zealand. The NZAuASB mandate
covers Professional and Ethical Standards, which govern the professional conduct of assurance
practitioners. Therefore, both NZICA and NZAuASB maintain a code of ethics; however, the
requirements of both are aligned with each other to ensure that assurance practitioners are not
subject to differing obligations.
Required reading
PES 1 paras NZ 1.2 and NZ 1.4, and the New Zealand Preface.
Worked example 3.1: Applying the code of ethics regarding auditor independence
[Available online in myLearning]
CC
Learning outcome
2. Apply the elements of quality control that must be applied at the individual engagement
level.
Australia-specific
ASIC audit inspection and surveillance programs
In Australia, the quality control systems of auditors of entities that are required to be audited
in accordance with the Corporations Act are subject to review by the Australian Securities and
Investments Commission (ASIC).
Responsibility for the surveillance, investigation and enforcement of the financial reporting and
auditing requirements of the Corporations Act lies with ASIC.
CC
ASIC’s audit inspection program aims to promote high-quality external audits under
Chapter 2M of the Corporations Act, and to raise the standard of conduct in the auditing
profession.
The ASIC inspection program is focused on audit quality and promoting compliance with
the requirements of the Corporations Act, Auditing Standards, and professional and ethical
standards. Audit firms are selected for inspection based on a number of criteria, with an
emphasis on auditors of publicly listed or public interest entities.
The audit inspection process is designed to gain an understanding of the key elements of
quality control as required by:
•• ASA 220 Quality Control for an Audit of a Financial Report and Other Historical Financial
Information.
•• APES 320 Quality Control for Firms.
•• ASQC 1 Quality Control for Firms that Perform Audits and Reviews of Financial Reports
and Other Financial Information, Other Assurance Engagements and Related Services
Engagements.
At the completion of the review, ASIC prepares a private and confidential report for the firm
that has been inspected, describing the inspection process, observation and findings, and
suggested remedial actions. A public report is periodically published by ASIC. This report does
not identify either the audit firm or the clients, and is aimed at better informing interested
stakeholders of the key observations and findings of the inspection program.
ASIC undertakes auditor surveillance generally as a result of complaints from the public to
ASIC, media reports, or intelligence from other areas within ASIC – for example, the financial
reporting surveillance program, in which queries are sometimes raised about the performance
of an auditor or the nature of the auditor’s report.
New Zealand-specific
Audit inspection and surveillance program
In New Zealand, the quality control systems of auditors of FMC reporting entities are subject to
review by the Financial Markets Authority (FMA).
The FMA enforces the Auditor Regulation Act 2011. The Act establishes an independent audit
oversight regime for the auditors of FMC reporting entities within New Zealand. All registered
audit firms and individual auditors who are not members of a registered audit firm will be
subject to a quality review at least once every four years. The review will include an assessment
of the design of the internal control systems of the audit firm or licensed auditor, as well as a
review of selected audit files for compliance with Auditing and Assurance Standards. It is the
FMA’s responsibility to conduct these reviews – however, it may arrange for accredited bodies
to carry out a quality review, in whole or in part, on its behalf.
Required reading
ISA 220 paras 2–14, A4, A8 and A11.
CC
Learning outcome
3. Outline the auditor’s responsibilities in agreeing the terms of the audit engagement, including
the mandatory items to be included in an engagement letter.
After evaluating any prospective new client or an existing client as part of pre-engagement
activities, and deciding whether to accept a new engagement or continue with an existing one,
the auditor must agree on the terms of the engagement (i.e. what is to be done, by whom and
when) with the client.
This is typically done by the auditor sending the client an audit engagement letter. This is sent
before the beginning of the audit to help avoid misunderstandings regarding the engagement.
The engagement letter documents and confirms the:
•• Auditor’s acceptance of the appointment.
•• Objective and scope of the audit.
•• Extent of the auditor’s responsibilities to the entity.
•• Form of any reports.
ISA 210 deals with the auditor’s responsibilities in agreeing the terms of the engagement with
the client’s management. This includes establishing that certain preconditions (which are the
responsibility of management) are present. The aspects of client acceptance that are within the
control of the auditor are addressed in ISA 220.
In accordance with ISA 210 para. 7, if management imposes ‘a limitation on the scope of the
auditor’s work in terms of a proposed audit engagement such that the auditor believes the
limitation would result in the auditor disclaiming an opinion on the financial statements’,
the auditor should not accept the engagement unless it is required to do so by either law or
regulation.
ISA 210 para. 8 sets out other factors that the auditor needs to consider if the preconditions for
an audit are not present.
CC
Terms Description
Responsibilities of •• Preparation of the financial statements in accordance with the applicable financial
management framework, and for designing and implementing such internal control as management
determines is necessary to enable the preparation of financial statements that are free
from material misstatement, whether due to fraud or error
•• Accept the terms of the engagement as outlined in the engagement letter
•• Provide auditors with unrestricted access to any records, documentation and other
information requested in connection with the audit
•• Provide auditors with unrestricted access to persons within the entity
•• Confirm auditor’s expectation of receiving written confirmation from management
concerning representations made in connection with the audit
•• Agreement to inform the auditor of facts that may affect the financial statements,
of which management may become aware during the period from the date of the
auditor’s report to the date the financial statements are issued
CC
In addition, an audit engagement letter may also make reference to a number of other issues,
as detailed in ISA 210 paras A22–A25 and set out in the table below:
Terms Description
Recurring engagements
Where the auditor is engaged to work on recurring engagements, it must assess whether there
has been a change in circumstances that would require the terms of the audit engagement to
be revised, and whether there is a need to remind the entity of the existing terms of the audit
engagement (ISA 210 para. 13). Examples of such a change in circumstances are detailed in
ISA 210 para. A28, and include significant changes in ownership, senior management, and legal
or regulatory requirements.
If there is a change in the terms of an audit engagement, the auditor should not agree to them
unless there is reasonable justification for doing so. If the auditor has agreed to such a change,
the new terms should be agreed on and recorded in a new engagement letter or other suitable
form of written agreement (ISA 210 paras 14–17).
Required reading
ISA 210 paras 6–10, 13–17 and A21–A25, and Appendix 1.
ASA 210/ISA (NZ) 210 Appendix 1.
CC
Learning outcome
4. Describe and explain the auditor’s responsibility to communicate audit matters to those
charged with governance.
It is important for the auditor to develop a constructive working relationship with the
audit client in a financial statement audit by having effective two-way communication with
management and those charged with governance. Similar to mandatory requirements regarding
documentation, the communication of audit matters that are of interest to those charged with
an entity’s governance must occur at all stages of the audit. Effective two-way communication
benefits both the auditor and those charged with governance.
The objectives of the auditor in an audit of financial statements regarding communication with
those charged with governance are to:
•• Communicate the responsibilities of an auditor in relation to the financial statements audit.
•• Communicate an overview of the planned scope and timing of the audit.
•• Provide those charged with governance timely observations arising from the audit that are
significant and relevant to their responsibility to oversee the financial reporting process.
• In some jurisdictions, a supervisory (wholly or mainly non-executive) board exists that is legally
separate from an executive (management) board (a two-tier board structure). In other jurisdictions,
both the supervisory and executive functions are the legal responsibility of a single, or unitary,
board (a one-tier board structure).
• In some entities, those charged with governance hold positions that are an integral part of the
entity’s legal structure, for example, company directors. In others, for example, some public sector
entities, a body that is not part of the entity is charged with governance.
• In some cases, some or all of those charged with governance are involved in managing the entity.
In others, those charged with governance and management comprise different persons.
• In some cases, those charged with governance are responsible for approving the entity’s financial
report (in other cases management has this responsibility).
CC
communicate. In deciding this, the auditor’s understanding of an entity’s governance structure
and processes is relevant and necessary. The appropriate person(s) with whom to communicate
may also vary depending on the matter to be communicated.
When the entity is a component of a group, the appropriate person(s) with whom the
component auditor communicates depends on the engagement circumstances and the matter to
be communicated.
ISA 260 Appendix 1 identifies paragraphs in ISQC 1 and other Auditing Standards that require
communication of specific matters to those charged with governance.
Some of the more common matters of interest to those charged with governance that may be
communicated (preferably in writing) are outlined in the following table:
Accounting policies The selection of (or changes in) significant accounting policies and
practices that have, or could have, a material effect on the entity’s financial
statements
Significant matters, if any, These matters are discussed with those charged with governance, unless
arising from the audit that they are all involved in managing the entity. This ensures that those
were discussed with, or charged with governance have the same understanding of the facts and
communicated to, management circumstances that management does
Significant deficiencies in As set out in ISA 265 Communicating Deficiencies in Internal Control to
internal control Those Charged with Governance and Management, the auditor needs to
communicate significant deficiencies in internal control identified during
the audit on a timely basis
Audit misstatements ISA 450 Evaluation of Misstatements Identified during the Audit requires the
auditor to communicate to those charged with governance uncorrected
misstatements and the effect they, individually or in aggregate, may have
on the auditor’s opinion
Written representations that the Written representations are required by the auditor to confirm certain
auditor requests matters or support other audit evidence
Required reading
ISA 260 paras 14–17 and A9–A27, Appendix 1.
Worked example 3.3: Describing the auditor’s responsibilities to communicate with those
charged with governance
[Available online in myLearning]
CC
Australia-specific
ASA 260 Communication with Those Charged with Governance
ASA 260 Communication with Those Charged with Governance (ASA 260) deals with
communication by an auditor with those charged with governance. It is based on its
international equivalent, ISA 260, and, while it conforms to the international Standard, the
differences are denoted by the insertion of the prefix ‘Aus’ in the relevant paragraph numbers.
There are two key additional requirements in ASA 260:
•• In the case of entities that are audited in accordance with the Corporations Act, the auditor
is required to provide those charged with governance with the auditor’s independence
declaration required by Corporations Act s. 307C (discussed earlier in this unit) (ASA 260
para. Aus 17.1).
•• If the auditor is concerned that a written report intended for those charged with
governance has not been, or may not be, distributed to all members of that group, the
auditor is required to endeavour to ensure that all members are appropriately informed of
the contents of the report (ASA 260 para. Aus 19.1).
New Zealand-specific
ISA (NZ) 260 Communication with Those Charged with Governance
ISA (NZ) 260 Communication with Those Charged with Governance (ISA (NZ) 260) deals
with communication by an auditor with those charged with governance. It is based on its
international equivalent, ISA 260, and, while it conforms to the international Standard, the
differences are denoted by the insertion of the prefix ‘NZ’ the relevant paragraph numbers.
There is one additional requirement in ISA (NZ) 260:
•• If the auditor is concerned that a written report intended for those charged with
governance has not been, or may not be, distributed to all members of that group, the
auditor is required to endeavour to ensure that all members are appropriately informed of
the contents of the report (ASA 260 para. NZ19.1).
Quiz
[Available online in myLearning]
Readings
Required reading
Relevant International Standards on Auditing and national equivalents and legislation and guidance
ISA 200 Overall Objectives of the ASA 200 Overall Objectives of ISA (NZ) 200 Overall Objectives of
Independent Auditor and the the Independent Auditor and the the Independent Auditor and the
Conduct of an Audit in Accordance Conduct of an Audit in Accordance Conduct of an Audit in Accordance
with International Standards on with Australian Standards on with International Standards on
Auditing Auditing Auditing (New Zealand)
ISA 210 Agreeing the Terms of Audit ASA 210 Agreeing the Terms of Audit ISA (NZ) 210 Agreeing the Terms of
Engagements Engagements Audit Engagements
•• Paragraphs 6–10, 13–17, •• Paragraphs 6–10, 13–17, •• Paragraphs 6–10, 13–17,
A21–A25, and Appendix 1 A21–A25, and Appendix 1 A21–A25, and Appendix 1
ISA 220 Quality Control for an Audit ASA 220 Quality Control for an Audit ISA (NZ) 220 Quality Control for an
of Financial Statements of a Financial Report and Other Audit of Financial Statements
Historical Financial Information
•• Paragraphs 2–14, A4, A8 and •• Paragraphs 2–14, A4, A8 and •• Paragraphs 2–14, A4, A8 and
A11 A11 A11
ISA 260 Communication with Those ASA 260 Communication with Those ISA (NZ) 260 Communication with
Charged with Governance Charged with Governance Those Charged with Governance
•• Paragraphs 14–17 and A9–A27, •• Paragraphs 14–17 and A9–A27, •• Paragraphs 14–17 and A9–A27,
and Appendix 1 and Appendix 1 and Appendix 1
Code of Ethics for Professional APES 110 Code of Ethics for PES 1 (Revised) Code of Ethics for
Accountants (IESBA Code) (2015) Professional Accountants Assurance Practitioners
•• Sections 100–290 •• Sections 100–290 •• Sections 100–290
•• Paragraphs 291.1–291.3 •• Paragraphs 1.4 and 291.1–291.3 •• Paragraphs NZ 1.2, NZ 1.4,
291.1–291.3 and the New
•• Definitions
Zealand Preface
Further reading
There are no further readings for this unit.
References
International Federation of Accountants 2011, Guide to using ISAs in the audits of small- and
medium-sized entities, 3rd edn (IFAC Guide), vol. 2, Exhibit 4.0-2, p. 27; Exhibit 4.4-1, p. 36;
Exhibit 4.4-2, p. 37
ACT
Activity 3.1
Identifying and safeguarding against threats
to independence
Introduction
Chartered Accountants can face a broad range of relationships and circumstances, some of
which may pose a threat to their compliance, or perceived compliance, with the fundamental
principles of the Code of Ethics for Professional Accountants (IESBA Code). A relationship or
circumstance can also affect compliance with more than one fundamental principle. In deciding
whether to accept or continue an audit engagement, the auditor needs to identify and evaluate
potential threats to independence.
This activity, links to learning outcome:
•• Apply the code of ethics and relevant guidance, statements and legislation regarding
auditor independence.
At the end of this activity you will be able to apply the IESBA Code to identify and evaluate
threats to auditor independence, and recommend relevant safeguards to eliminate or reduce the
identified threats.
It will take you approximately 30 minutes to complete.
Scenario
You are a newly qualified Chartered Accountant working for A&C Partners Chartered
Accountants (A&C). As part of your continuing professional education and training, one
of the partners of A&C has asked you to read through six situations and conclude on the
independence issues involved to ensure you are alert to independence and ethical issues before
your next audit engagement.
The six situations the partner gives you are as follows:
Situation 1
Louis Jones, chief financial officer (CFO) of Shanti Limited (a large textile manufacturer),
is thrilled that the audit for the 20X2 financial year was completed in a timely manner and
within budget, and, even better, that it resulted in an unmodified audit opinion. To express his
gratitude, he insists on offering each engagement team member a dinner voucher for two at Vue
de Monde, a famous Melbourne restaurant. The approximate value of a dinner voucher for two
is $400.
Situation 2
Elsa, your work colleague, was seconded to the Sydney office of your audit firm for three
months to assist with achieving urgent deadlines in an audit engagement with one of the firm’s
biggest clients, Lagaf Limited (Lagaf). One month into her secondment, on the audit firm’s
online chat system, Elsa asks you whether she can speak to you in confidence. She then admits
ACT
that she started ‘hanging out’ with Herbert, the financial controller of Lagaf, but that they are
just friends. The following week, she calls you and advises that their friendship has developed
into a closer relationship. The audit of Lagaf is yet to be finalised.
Situation 3
Your engagement team has recently completed the audit of SocaDance Limited (SocaDance),
a large manufacturer of various musical instruments. You are the audit manager. A number of
issues were identified and, following a review, you determine that one of the issues requires
adjustments to the financial statements in order for an unmodified audit opinion to be issued.
The issue relates to the valuation of some warehouse real estate held by SocaDance and, as
the valuation of the real estate is outdated, you are of the view that there is insufficient audit
evidence to support the valuation and allocation assertion.
You therefore organise a meeting with Kaolin, the financial controller of SocaDance, and express
your concerns to him. Numerous times during the meeting, Kaolin reminds you that he has
significant experience in property valuations, and has worked for a number of other companies
in the property industry. When it is clear that Kaolin will not agree to change the value of the
real estate, you advise that this might lead to a modified audit opinion. Kaolin then advises
that, if this is the case, he will see to it that your audit firm is dismissed from the SocaDance
engagement for the next financial year.
Situation 4
You are the auditor of Ushuaia Limited (Ushuaia), a manufacturer of beauty products aimed at
a niche market of very wealthy customers. Ushuaia’s trademark is its most valuable marketing
tool, as the public identifies its trademarked goods as being of top quality. Ushuaia has
approached your audit firm with a major concern that one of its competitors is trying to steal
its trademark and has asked you to assist by providing legal services to help in resolving the
imminent litigation with the competitor.
Situation 5
You are the senior auditor in charge of the audit of Indochine Limited (Indochine), one of the
largest clients of your firm. The year-end audit is being undertaken and, while reviewing the
file, the manager on the job informs you that it is absolutely crucial for the engagement to go
well and for an unmodified opinion to be issued. If this is not the case, the likelihood of you and
the manager being promoted within the firm is very remote.
Situation 6
You are the audit manager in charge of the audit of the Yeye Managed Investment Fund (Yeye),
a new client. A few years ago, Yeye acquired a parcel of shares in an unlisted Russian energy
company, and have no idea what the shares are worth. You note that the shares have been
valued at the same amount for the last five years, and that it is material to the financial report.
You notify the directors of Yeye that a third-party valuation will be required, to determine what
the shares are worth in the 20X3 financial year. The directors are more than happy to oblige and
have approached your audit firm to provide the valuation services.
ACT
Task
For this activity, you are required to apply the conceptual framework of the IESBA Code to each
of the six situations the partner has given you and:
•• Identify potential threats to independence.
•• Recommend safeguards to reduce the independence threats.
•• Determine whether audit independence can be achieved.
ACT
Activity 3.2
Outlining the terms of audit engagements
Introduction
After evaluating a prospective client or an existing client and deciding whether to accept the
new client or continue with the existing client, the auditor must agree on the terms of the
engagement with the client. This is typically done by sending an engagement letter.
The auditor sends the engagement letter prior to beginning the audit, to help avoid any
potential misunderstandings regarding the engagement. The engagement letter documents and
confirms the auditor’s acceptance of the appointment, the objective and scope of the audit, the
extent of the auditor’s responsibilities to the entity, and the form of any reports.
This activity links to learning outcomes:
•• Apply the code of ethics and relevant guidance, statements and legislation regarding
auditor independence.
•• Outline the auditor’s responsibilities in agreeing the terms of the audit engagement,
including the mandatory items to be included in an engagement letter.
At the end of this activity, you will be able to outline the terms to be included in an engagement
letter under particular circumstances, in accordance with ISA 210 Agreeing the Terms of Audit
Engagements (ISA 210).
It will take you approximately 20 minutes to complete.
Scenario
You are a Chartered Accountant working for the accountancy firm A&C Partners (A&C). You
have been a member of the audit team for one of the firm’s audit clients, O’Brien’s Newspapers
Limited (ONL), a non-listed entity, for the past two years.
You have researched ONL and prepared the following summary. It contains your findings for
the lead audit partner on this audit engagement, Gerald Hiraldo, and will help to inform his
decision on whether the firm will continue as auditors of this client in the upcoming financial
year, ending 30 June 20X3. If it is decided to continue the audit engagement, this summary will
also serve to highlight elements that need to be included in the engagement letter.
ACT
Consideration Findings
Have the audit preconditions been met? ONL’s financial statements will be prepared by management
using the International Financial Reporting Standards (IFRS)
Management agrees (and will confirm in a signed engagement
letter) that it acknowledges and understands its responsibility
to:
•• Make available all information as requested
•• Provide unlimited access to personnel
•• Design and implement such internal controls as
management determines is necessary to enable the
preparation of financial statements that are free from
material misstatement, whether due to fraud or error
Have the acceptance/continuance Yes. Refer to policies 3 and YY of the A&C Quality Control manual
requirements in the firm’s quality control
manual been followed?
Any change in the terms of reference or No
requirements for the audit engagement?
Any independence issues or conflicts of A&C and several A&C staff members have subscriptions to ONL
interest? publications for which they paid the retail price. This is not
considered a threat to our independence
Any circumstances that would cast doubt on No. However, Maria (daughter of the ONL marketing manager)
the integrity of the client’s owners? received some negative publicity in recent months. She was an
advisor in a land deal where government officials were accused
of receiving bribes from developers. This matter has also been
noted on our listing of risk factors for the audit
Does the engagement team have sufficient Yes. We plan to use the same senior staff as last period to
knowledge of accounting principles complete the engagement
and industry practices to perform the
engagement?
Are there areas where specialised We will need to bring in an expert to correctly value intangible
knowledge is necessary? assets (newspaper mastheads) recognised by the entity
Does the firm have the capacity in time, Yes. See the firm’s resource planning and budget for the year
competencies and resources to complete
the engagement in accordance with
professional Standards and the firm’s
guidelines?
Are there any issues identified in previous Falling circulation for a number of the ONL publications has
audits and other engagements for this entity been an issue in previous audits. This matter has also been
that need to be addressed? noted on our listing of risk factors for the audit
Are there any new circumstances that No. Management has a professional attitude towards internal
increase our engagement risk? control, and no new circumstances have arisen to increase the
engagement risk in this regard
Can the client continue to pay our fees? Yes
Conclusion Overall assessment of engagement risk is low. Recommend
that we should continue with this client and prepare the audit
engagement letter accordingly
Gerald has reviewed your summary and accepts the comments and conclusions reached with
only minor adjustments.
Task
For this activity, you are required to outline the key contents of the engagement letter for
the ONL audit engagement for the year ended 30 June 20X3. Assume that ONL’s financial
statements are prepared on a true and fair basis.
[Solutions to activities are available online. Please access myLearning to view]
CC
Core content
Unit 4: Understanding the entity and its
environment
Learning outcomes
At the end of this unit you will be able to:
1. Discuss and demonstrate the auditor’s responsibility to gain a thorough understanding of
the entity and its environment.
2. Discuss and demonstrate the auditor’s responsibility to identify and assess the risks of
material misstatement in financial statements.
3. Demonstrate how the identification of risks and internal controls affect the audit of an
entity.
4. Explain an auditor’s responsibilities when a client uses a service organisation.
Introduction
Every entity is affected by unique events, transactions and practices, and, therefore, unique
risks. Many of these risks have the potential to impact on the financial statements. Therefore, in
order to adequately plan an audit, the auditor must understand the entity and its environment,
and also how the entity responds to the risks it faces.
The auditor uses the understanding of an entity obtained to identify and assess risks of material
misstatements in the financial statements, and to plan audit procedures to respond to those
risks.
The following diagram summarises the steps in the risk assessment process:
Understand Respond to
Identify the risks Assess the risks
the entity the risks
This unit focuses on ISA 315 (Revised) Identifying and Assessing the Risks of Material Misstatement
through Understanding the Entity and Its Environment (ISA 315 (Revised)). The concepts and
requirements in ISA 315 (Revised) extend across several units in the Audit & Assurance
(AAA) module.
aaa11604_csg
CC
Key steps in the planning and risk assessment process are covered in multiple units throughout
the AAA module as follows:
1. Gather information The auditor is required to To provide a frame of Understanding the entity
about the entity gather information about: reference within which and its environment
the auditor plans the
•• The entity and its
audit and revises the audit
environment
strategy and audit plan
•• Internal controls throughout the audit
2. Perform risk The auditor is required To identify sources Analysing audit risks,
assessment to: of risks of material financial statement
procedures misstatement due to assertions and initial
•• Make enquiries
error or fraud, and to audit engagements
•• Perform analytical obtain audit evidence to
procedures Analysing audit risks –
support the assessment
fraud
•• Observe and inspect of risk at both the
financial statement and
assertion levels
3. Use information The auditor is required To enable the auditor to Analysing audit risks,
to assess the to assess the risks of direct the audit work to financial statement
risks of material material misstatement at where it is most needed assertions and initial
misstatement the financial statement – that is, to areas where audit engagements
and assertion levels the risks of material
Analysing audit risks –
misstatement are highest
fraud
5. Determine audit The auditor is required To enable the auditor to Developing an overall
strategy and plan to set and document the plan and perform the audit plan
overall audit strategy and audit in an efficient and
audit plan effective manner
This unit also covers what the auditor needs to consider when auditing an entity that uses a
service organisation to operate part of its business processes, in accordance with ISA 402 Audit
Considerations Relating to an Entity Using a Service Organization (ISA 402).
CC
Learning outcomes
1. Discuss and demonstrate the auditor’s responsibility to gain a thorough understanding of the
entity and its environment.
2. Discuss and demonstrate the auditor’s responsibility to identify and assess the risks of material
misstatement in financial statements.
Understand Respond to
Identify the risks Assess the risks
the entity the risks
Understanding the entity and its environment enables the auditor to identify risks that the
entity faces. When the auditor understands the entity, they are able to identify risks that could
result in a material misstatement in the financial statements. Therefore, risk identification is an
integral part of understanding the entity. Using this approach, the auditor can focus the audit
work on risks that are relevant to each audit.
In addition to forming a basis for assessing risks and designing audit procedures,
understanding the entity and its environment is used for (ISA 315 (Revised) para. A1):
•• Determining materiality.
•• Considering the appropriateness of an entity’s accounting policies and financial statement
disclosures.
•• Identifying areas where specific testing is required, such as complex transactions, significant
estimates/judgements, and management’s use of the going concern assumption.
•• Designing audit procedures, such as tests of controls and/or substantive procedures that
directly respond to the risk(s) identified.
•• Evaluating whether the audit evidence is sufficient and appropriate.
CC
Examples – Identify the risks and the practical implications for audit planning
AUDIT ENTITY 1
AUDIT ENTITY 2
In practice, an auditor gains an understanding of the entity and its environment, including the
entity’s internal control, from a variety of sources and activities, such as discussions with the
client, preliminary financial data about the entity, regulators and the media. This information
is gathered throughout the client acceptance and planning stages of the audit, and when
performing the audit procedures.
CC
The following chart shows areas that are potential sources of risks for material misstatement in
the financial statements, which the auditor is required to understand:
RC E S O F R I S K
SOU
Entity objectives
and strategies
Internal External
control factors
RMM* in the
financial
statements
Accounting Internal factors
policies (nature of entity)
Industry
performance
indicators
Source: Adapted from Australian audit manual and toolkit 2015 for small and medium sized entities, Exhibit 23.5-1,
p. 283.
The following diagram uses the example of sales revenue to illustrate this:
Revenue is
recorded in the What chance is there What controls are in place to prevent
correct financial it will go wrong? (or detect and correct) an error?
period
CC
(ISA 315 (Revised) para. 11) (ISA 315 (Revised) paras 12−24)
CC
Industry factors
Different industries have different risks, and the impact on the entity depends on its position in
that industry. For instance, operating in an industry that experiences rapid technological change
presents a risk of falling behind its competitors. This may lead to products becoming obsolete,
and a risk of the entity overvaluing its inventory on hand.
Regulatory factors
The regulatory environment may govern an entity’s operations, its financial reporting
requirements, or both. Regulations over operations may have an economic impact, which in
turn affects the financial statements. Financial reporting regulations may create specific risks for
particular industries.
Australian financial services Imposes operating and reporting obligations on AFSL holders,
licence (AFSL) regulations increasing compliance risks
Australian Prudential Regulation Imposes financial and reporting obligations on certain financial
Authority (APRA) services businesses, including entities involved in banking, insurance
and superannuation, increasing compliance risks
External factors
Other external factors include the general economic environment. This will impact on
businesses differently. The auditor will need to consider how factors such as a declining
economy, interest rates and the availability of financing affect the entity.
ISA 315 (Revised) paras A24–A29 provide further guidance on the auditor’s consideration of
industry, regulatory and other external factors.
CC
Types of investments
The entity and
Accounting policies
its environment
Structure and finance
Operations
Information about the entity’s operations includes:
•• How an entity earns revenue.
•• Products and services.
•• Customer and supplier relationships.
•• Geographic locations.
•• Workforce profile.
Information on operations will assist the auditor to understand which account balances should
be present and which should be absent in the financial statements, and may also provide an
understanding of the appropriate accounting treatment.
A manufacturer has high fixed costs and operates Financial risk if sales decline
at low margins/high volumes to earn profits
Risk of net realisable value of inventory falling
below cost
A service entity enters into long-term sales Risk that revenue will not be recognised in the
contracts correct accounting period
Potential risk that losses on long-term contracts
will not be accounted for appropriately
CC
A company has an active and appropriately Reduces risk due to enhanced oversight of the
constituted audit committee comprising integrity of financial reporting
non‑executive directors, the majority of whom are
independent
Types of investments
Investing potentially covers a wide range of activities, including investments in income-
producing assets, new business operations, and joint ventures and associates. The auditor
needs to consider what the appropriate accounting treatment for each investment is (e.g. fair
value, depreciated cost), as well as any related risks, such as impairment. Investments in other
businesses will carry risks related to each type of business.
A retail group acquires a significant subsidiary Accounting for acquisitions can be complex
offering insurance products
Risks related to insurance operations and the type
of industry
A company carries a relatively high level of debt The going concern assumption may become
inappropriate if trading conditions decline
The terms of a bank loan contain strict financial Covenants could motivate management to
covenants misstate related account balances
A company has a high level of debt owed to its The classification of debt versus equity and
shareholders current versus non-current liabilities may be
difficult to ascertain
CC
Accounting policies
In accordance with ISA 315 (Revised) paras 11(c) and A35, the auditor needs to understand the
entity’s selected accounting policies in order to:
•• Assess whether the accounting policies are appropriate.
•• Design audit procedures that address the accounting policies.
Most business risks have a potential financial consequence and, therefore, an effect on the
financial statements. However, the auditor does not need to identify or assess all business
risks because not all give rise to risks of material misstatement (ISA 315 (Revised) para. A38).
The term ‘business risk’ encompasses more than just the risk of material misstatement in the
financial statements.
The ‘Application and Other Explanatory Material’ in ISA 315 (Revised) para. A39 provides
examples of matters the auditor may consider in obtaining an understanding of the entity’s
objectives, strategies and related business risks.
Examples – Matters the auditor may consider in obtaining an understanding of the entity’s objectives,
strategies and related business risks
Expanding to new locations Risks relating to control over remote operations (e.g. have all sales
transactions been recorded? Are payments appropriately authorised?
Is cash handling managed and controlled?)
Developing new products or The risk that new products or services will fail; therefore corresponding
services pressure on management to meet expected results and a risk that the
inventory of new products and assets used to manufacture those new
products, may be overvalued
Significant new competitor The risk that inventory is overvalued at more than can be recovered
enters the market through potential sales of inventory; pressure on management from
poor sales results
CC
ISA 315 (Revised) Appendix 2 contains a useful list of conditions and events that may indicate
risks of material misstatement.
Complexity
The more complex an entity, the greater the risk that something could go wrong and therefore
the greater the risk of material misstatement.
For example, the accounting that is required to produce financial statements for a large
multinational organisation with multiple subsidiaries, joint ventures and associates, foreign
operations, and acquisitions and disposals of investments, will be more complex and difficult
than that required for a small, simple one-entity business.
Specific examples of potential risks associated with complex entities include:
•• Not correctly distinguishing between, and accounting for, joint ventures, associates,
subsidiaries and special purpose entities.
•• Not identifying special purpose entities that require consolidation.
•• Impairment of significant goodwill and intangibles balances.
•• Not identifying related parties and related party transactions.
•• Errors in the consolidation process.
•• Translation of foreign currency transactions and balances.
The importance of understanding complexity is outlined in ISA 315 (Revised) para. A30.
Signficant changes
Significant changes in the entity from prior periods may give rise to, or change, risks of material
misstatement (ISA 315 (Revised) para A32), and consequently are a key audit focus area.
Installation of a new Risks over proper implementation and transfer of balances and supporting
accounting software data from previous system
system
Change in IT controls
Staff may need extensive training – increased risk of error due to lack of
familiarity with system
Acquisition of a New risk profile for all amounts relating to the new business (e.g. potentially
significant new business different products, management, controls and markets)
CC
A retail business uses revenue per store as a key The auditor identifies a risk that management are
measure of performance for the business and store motivated to overstate reported revenue
managers
When reviewing management’s analysis of The auditor identifies a risk that accounts
variances between actual, forecast and prior period receivable balances may be overstated
results, the auditor notes that accounts receivable
balances and accounts receivable to sales ratios
are significantly higher than forecast and previous
financial periods
Investment analysts focus on consistent gross The auditor identifies a risk that direct costs could
margins be overstated or understated from one financial
period to the next to ‘smooth’ reported gross
margins
Required reading
ISA 315 (Revised) paras 1–5, 7–9, 11, A1–A5, A24–A27, A29–A32 and A35–A48, and Appendix 2.
CC
Internal control
A key part of understanding the entity includes understanding the entity’s internal control:
(ISA 315 (Revised) para. 11) (ISA 315 (Revised) paras 12−24)
Internal control is implemented by management to mitigate business risks that are related to
(ISA 315 (Revised) para. A51):
•• Financial reporting.
•• Efficiency and effectiveness of operations.
•• Compliance with laws and regulations.
It is important to understand, however, that internal control cannot completely mitigate risks.
Importance of internal control to the auditor
Understanding the entity’s internal control allows the auditor to assess where material
misstatements are likely to occur. The auditor is also identifying business risks that create risks
of material misstatements. When the auditor then understands the entity’s controls over those
business risks, a more complete risk profile emerges. According to ISA 315 (Revised) para. 12:
The auditor shall obtain an understanding of internal control relevant to the audit. Although most
controls relevant to the audit are likely to relate to financial reporting, not all controls that relate to
financial reporting are relevant to the audit. It is a matter of the auditor’s professional judgement
whether a control, individually or in combination with others, is relevant to the audit.
The auditor is only concerned with those controls that relate to a risk of material misstatement
in the financial statements. Some controls that address operational or compliance risks will also
impact on financial reporting, others will not.
Management prepares monthly actual to budget Identifies potential errors in the financial reporting
statements of profit or loss and statements of process and is therefore relevant to the audit
financial position. All significant variances are
investigated and explained
Regular health and safety inspections are Not relevant to the audit. However, if an accident
performed at all warehouses occurred, that event could be relevant to the audit
as a contingent or actual liability
CC
ISA 315 (Revised) para. A68 lists some factors that the auditor should consider in determining
whether a control is relevant to the audit.
When obtaining an understanding of controls that are relevant to the audit, the auditor must
evaluate the design of those controls and determine whether they have been implemented
by the entity. The process of evaluating the design and implementation of controls will be
discussed in detail in the unit on controls testing.
Required reading
ISA 315 (Revised) paras 12–13 and A68.
Examples: Example:
• Approval of transactions • Controls embedded in computer
• Review of transactions programs
• Follow-up of reconciling items
Manual controls operate over the manual elements of the accounting system. An example of a
manual control is a review of payroll exception report.
Automated controls include general IT controls (GITCs) and IT application controls.
IT application controls are fully automated controls designed to ensure complete and accurate
processing of data. An example of an IT application control is numerical sequence check. GITCs
are controls over the environment in which computer systems and databases operate. Controls
over program changes is an example of a GITC.
The different types of controls are often interrelated. For example, a review of payroll exception
reports (manual control) is reliant on the automated controls (both general and application) to
process payroll data and to generate the exception reports.
CC
Control environment
Components of
Information system
internal control
Control activities
Monitoring of controls
ISA 315 (Revised) allows the auditor to use different terminology or frameworks to describe the
various aspects of internal control, provided all the components described in the Standard are
addressed.
Control environment
The control environment provides the foundation on which the other components of internal
control are built. It comprises the attitude, awareness and actions of the entity’s governing body
and management concerning the importance of internal control (ISA 315 (Revised) para. A76). It
is often referred to as the entity’s governance culture or ‘tone at the top’.
Internal controls in the control environment are often pervasive to the financial statements as a
whole and are commonly referred to as entity-wide controls or entity-level controls.
The control environment does not in itself prevent or detect errors. However, a poor control
environment is likely to undermine the other components of internal control. For instance,
employees are more likely to ignore or bypass an internal control process if it is perceived that
management is indifferent to overall governance in the organisation.
For this reason, the auditor is concerned that as per ISA 315 (Revised) para. 14:
•• Management (overseen by the governing body) maintains a culture of honesty and
integrity.
•• The control environment provides a strong foundation for the other components of internal
control and does not undermine those components.
CC
Communication and If people understand what is expected of them, they are less likely to ignore or
enforcement of integrity bypass internal controls
and ethical values
Commitment to Errors are more likely if employees are not competent in relation to their
competence responsibilities
Participation by those Independent, competent directors who are actively involved in overseeing
charged with governance management will have a positive influence on management
Human resources policies Competent, ethical and well-trained people reduce the risks of errors or control
and practices breaches
Information system
The information system is how the entity initiates, records, processes and reports transactions,
as well as how it accounts for assets and liabilities. It includes the accounting system and will
generally comprise automated and manual processes (ISA 315 (Revised) para. A89).
The information system includes the computer hardware and software, manual records, people
and procedures that are designed to:
•• Initiate, record, process and report transactions.
•• Account for assets, liabilities and equity.
•• Resolve incorrect processing of transactions.
•• Process and account for system overrides.
•• Transfer information from transaction processing systems to the general ledger.
•• Capture information for non-transaction events and conditions that are relevant to financial
reporting, such as depreciation and asset impairments.
•• Ensure transactions and disclosures are presented appropriately in the financial statements.
CC
An important feature of an information system is the audit trail. This is made up of the
documents and records that can be used to trace individual transactions through the system to
the financial statements.
Initiate
ACCOUNTING RECORDS
INFORMATION SYSTEM
Non-
transaction
events Record
Process
General
ledger
journals
Financial reporting
process
Financial statements
CC
Examples − GITCs
The following examples illustrate GITCs.
General IT controls
Security over data, the •• Acquisitions, installations, configurations, integration and maintenance of
IT infrastructure and the IT infrastructure
daily operations •• Delivery of information services to users
•• Management of third-party providers
•• Use of system software, security software, database management systems
and utility programs
•• Incident tracking, system logging and monitoring functions
Access to programs and •• Issuance/removal and security of user passwords and IDs
application data •• Internet firewalls and remote access controls
•• Data encryption and cryptographic keys
•• User accounts and access privilege controls
•• User profiles that permit or restrict access
Source: Australian audit manual and toolkit 2015 for small and medium sized entities, Exhibit 3.7.1, pp 65–6.
The auditor generally focuses on the key GITCs that support the effective functioning of ITACs
that the auditor plans to rely on.
Required reading
ISA 315 (Revised) paras A103–A105.
CC
Control activities
The auditor must obtain an understanding of control activities relevant to the audit. To identify
relevant controls, the auditor uses professional judgement. This may involve considering
previously identified risks of misstatement and then identifying controls that address those
risks. However, as per ISA 315 (Revised) para. A97, the auditor would always consider control
activities to be relevant to the audit where:
•• Control activities relate to ‘significant risks’.
•• Substantive procedures alone will not provide sufficient appropriate audit evidence, and
thus tests of controls are needed to supplement substantive procedures
Control activities are policies and procedures that help ensure that management’s directives are
carried out (ISA 315 (Revised) para. A96). Control activities are applied over the information
system to ensure the information recorded is accurate, complete and reliable.
Performance reviews Senior management and the board review actual results against those
forecast on a monthly basis
Information processing IT system performs a validity check on employee numbers as they are
entered
Physical controls Regular cyclical counts of inventory are conducted and compared to
recorded amounts
Segregation of duties Different people are responsible for credit control, receipts, banking,
and initiating and authorising sales transactions
In understanding the entity’s control activities, the auditor must obtain an understanding of
how the entity has responded to risks arising from IT (ISA 315 (Revised) para. 21). From the
auditor’s perspective, controls over IT systems are effective when they maintain the integrity of
information and the security of the data such systems process, and include effective general IT
controls and application controls (ISA 315 (Revised) para. 103).
Control activities are further discussed in the unit on responding to risks – controls testing.
Monitoring of controls
An entity may have a formal process for monitoring the design and implementation of internal
controls. This may include an internal audit function. In this case, the auditor will need to
obtain an understanding of the internal audit function (ISA 315 para. 23). Using the work of
internal auditors is considered in the unit on responding to assessed risk – using the work of
others.
The auditor is required to obtain an understanding of the major monitoring activities (ISA 315
(Revised) para. 22). This assists the auditor in:
•• Assessing the quality of internal control.
•• Identifying any breakdowns or deficiencies in internal controls.
CC
Required reading
ISA 315 (Revised) paras 4(c), 12–24, A49–A59, A67– A71, A73–A83, A87–A92, A94, A96–A117 and
Appendix 1.
Worked example 4.1: Understanding the entity and its environment and identifying risk
factors
[Available online in myLearning]
Worked example 4.2: Understanding the entity’s internal control and identifying control
strengths and weaknesses
[Available online in myLearning]
CC
Learning outcome
3. Demonstrate how the identification of risks and internal controls affect the audit of an entity.
Earlier in this unit, we identified the auditor’s responsibility to understand the entity and
its environment in order to identify and assess risks of material misstatement (see ISA 315
(Revised) para. 3).
In this section, we will begin to consider how the auditor applies their understanding of the
entity to respond to the risks identified. The relevant Standard, ISA 330 The Auditor’s Responses
to Assessed Risks (ISA 330), is also introduced.
The following diagram illustrates the risk assessment process and how the auditor responds to
the identified risks:
IR × CR × DR = AR
Determined from the auditor’s Controlled by the auditor Set by the auditor
understanding of the entity, through design and to an acceptably
including its internal control performance of audit low level
procedures
CC
Before discussing the audit risk model further, the definition of each component will be
considered and some examples provided.
Audit risk
ISA 200 para. 13(c) defines ‘audit risk’ as follows:
Audit risk – The risk that the auditor expresses an inappropriate audit opinion when the financial report
is materially misstated. Audit risk is a function of the risks of material misstatement and detection risk.
Inherent risk
ISA 200 para. 13(n)(i) defines ‘inherent risk’ as:
The susceptibility of an assertion about a class of transaction, account balance or disclosure to a
misstatement that could be material, either individually or when aggregated with other misstatements,
before consideration of any related controls.
In other words, inherent risks are risks that result from an entity’s operations, activities or
industry. They are risks that management faces in running the business. The auditor identifies
inherent risks in the process of obtaining an understanding of the entity.
Examples – Inherent risk factors and the impact on risk in the financial statements
High technology industry Products may become outdated, which could lead to
inventory being overvalued
Complex revenue recognition criteria for Revenue may be recognised in wrong period
revenue from services
Opportunity for management or employees to manipulate
revenue recognition
Control risk
According to ISA 200 para. 13(n)(ii), ‘control risk’ is:
The risk that a misstatement that could occur in an assertion about a class of transaction, account
balance or disclosure and that could be material, either individually or when aggregated with other
misstatements, will not be prevented, or detected and corrected, on a timely basis by the entity’s
internal control.
Management implements internal controls to respond to the risks to an entity’s objectives. The
auditor has a responsibility concerning the risks and related controls that relate to the financial
statements. Control risk is the risk that management’s internal controls over risks to the
financial statements are not effective or do not exist at all.
Internal controls are either:
•• pervasive to the financial statements as a whole – in the control environment, controls are
commonly pervasive
or
•• relate to specific accounts in the financial statements.
CC
Example – Control risk factors pervasive to the financial statements and the impact on risk
Control risk factor Impact on risk
An active and appropriately constituted audit Control strength over the financial statements as a
committee comprising non-executive directors, whole (i.e. pervasive) – reduces control risk
the majority of whom are independent
Examples – Control risk factors relating to specific accounts in the financial statements
Control risk factor Impact on risk
Purchase orders must be approved by the Control strength over purchases and inventory –
purchasing manager reduces control risk
All cheques and electronic funds transfers must be Control strength over cash at bank and expenses –
approved by two authorised managers from a list reduces control risk
of four
There are no adequate controls to ensure sales Control weakness over revenue – increases control
transactions are recorded at the date that risk
responsibility for goods passes to customers
Detection risk
As per ISA 200 para. 13(e), ‘detection risk’ is:
The risk that the procedures performed by the auditor to reduce audit risk to an acceptably low level
will not detect a misstatement that exists and that could be material, either individually or when
aggregated with other misstatements.
Detection risk is the component of risk that is controlled by the auditor, since it is the risk that
audit procedures will not detect risks of material misstatement. Detection risk is inversely
proportional to the level of testing (i.e. increasing the amount of audit testing decreases
detection risk).
In contrast, inherent risks and control risks relate to the entity and its environment and are
outside auditor’s control. These risks are identified through the auditor’s knowledge of the
business. Together, these two types of risks comprise the risk of material misstatement (RMM).
IR × CR × DR = AR
RMM
The auditor uses the audit risk model as a framework for designing the audit procedures that
are required to reduce audit risk to an acceptable level, as follows:
Step 1: Determine the acceptable level of audit risk – this relates to the level of assurance being
provided by the auditor. Overall, audit risk must be sufficiently low.
Step 2: Understand the entity and its environment, including internal control.
Step 3: Identify and assess inherent risks and control risks.
Step 4: Determine the risk of material misstatement (RMM) using the audit risk model:
Risk of material misstatement (RMM) = inherent risk (IR) × control risk (CR).
Step 5: Determine the level of detection risk that is necessary to achieve the audit risk as
determined by the auditor using their professional judgement.
CC
The auditor applies the audit risk model and determines the RMM at two levels:
•• the overall financial reporting level, and
•• the assertion level for classes of transactions, account balances, and disclosures.
The following diagram illustrates how the auditor will then respond to assessed risks:
AUDITOR’S RESPONSE
Examples include:
• Professional scepticism Substantive Test of
• Level of staff assigned procedures control
• Ongoing staff supervision
• Evaluate accounting policies
• Nature/extent/timing and
unpredictability of planned
procedures Test of Substantive
• Other further procedures detail Analytical
RESULT
CC
There are two main types of audit procedures that auditors use to obtain audit evidence: tests of
controls and substantive procedures. These are illustrated in the following diagram:
Audit procedures
Substantive analytical
Tests of details
procedures
Tests of controls and substantive procedures will be discussed in detail in later units on
responding to assessed risks – controls testing and substantive testing.
The following diagram summarises some of the considerations in developing the appropriate
audit approach for an account balance or class of transactions:
CC
Determining the audit approach will be discussed in detail in the unit on developing an overall
audit plan.
Risk of
material
misstatement
Professional judgement is needed to determine the required balance between quality and
quantity. By increasing the quality of evidence, the auditor will often be able to reduce
the quantity. However, if the quality is poor, increasing the quantity will not necessarily
compensate (ISA 500 para. A4).
Required reading
ISA 500 paras 5–7 and A1–A33.
Worked example 4.3: Understanding the impact of control risk on the audit
[Available online in myLearning]
Worked example 4.4: Identifying inherent and control risks and the impact on detection risk
[Available online in myLearning]
Activity 4.1: Understanding the entity and its environment – inherent and control risks
[Located at the end of this unit]
Activity 4.2: Identifying internal control strengths and weaknesses in a sales process
[Located at the end of this unit]
CC
Learning outcome
4. Explain an auditor’s responsibilities when a client uses a service organisation.
Many entities outsource aspects of their business to external organisations that provide services
ranging from performing a specific task under the direction of an entity, to replacing an entire
business unit or function on behalf of the entity. In certain circumstances, the systems of these
external service providers (service organisations) effectively become part of the entity’s own
financial reporting information systems.
This section examines the auditor’s responsibilities when conducting an audit for an entity that
uses a service organisation as part of its business processes. These responsibilities are covered in
ISA 402 Audit Considerations Relating to an Entity Using a Service Organization (ISA 402).
This section will cover:
•• Which types of services are commonly outsourced to a service organisation.
•• The impacts on both the organisation that outsources its functions and its auditor.
•• The auditor’s responsibility to obtain an understanding of the services provided and their
effect on the entity’s internal controls.
•• How the auditor’s responsibility to design and perform appropriate audit procedures is
affected when a service organisation is used.
•• The two different types of reports that an auditor of the user entity can request from the
auditor of a service organisation to assist in understanding and assessing the service
organisation’s systems and controls that are relevant to the services it provided.
CC
•• How the user entity’s information system captures events and conditions other than
transactions, which are significant to the financial statements.
•• The process for preparing the financial statements.
•• Controls over journal entries.
Payroll function provided by service organisation’s Payroll expense and payroll-related provisions
computerised payroll system (e.g. annual leave)
The following types of services are not likely to be relevant, because these would not directly
affect the financial statements of the user entity:
•• Human resources services.
•• Marketing services.
•• Health and safety.
Required reading
ISA 402 paras 1–8.
CC
USER CONTROLS
Financial records Financial records
DATA DATA
Processes Processes
and and
controls controls
In the earlier section on gaining an understanding of the entity and its environment,
we discussed the auditor’s objective (ISA 315 (Revised) para. 3), which is to obtain an
understanding of the entity being audited and its environment, including internal control. The
requirements of ISA 402 reflect those of ISA 315 (Revised), but are adapted to circumstances in
which a service organisation is used.
CC
The following diagram illustrates the relationship between the auditor’s responsibilities and the
controls and evidence at both the user entity and service organisation:
Required reading
ISA 402 paras 7 and A12.
How the auditor addresses these responsibilities is best explained through the following four-
step process:
•• Step 1 – Understanding the user entity – information located at the user.
•• Step 2 – Understanding the user entity – information located at the service organisation.
•• Step 3 – Audit procedures – information located at the user entity.
•• Step 4 – Audit procedures – information located at the service organisation.
CC
Services provided
by service
organisation
Consider
Evaluate
user entity’s controls over the
service organisation
NO YES
Obtain additional
information from the
service organisation
Auditor understands
user entity’s use of
service organisation
ISA 402 para. 9 requires the auditor to understand how the entity uses a service organisation,
including:
•• The nature of the services provided by the service organisation and the significance of those
services to the user, including the effect on internal control.
•• The nature and materiality of the transactions that are processed, or accounts or financial
reporting processes affected.
•• The degree of interaction between the activities of the service organisation and those of the
user.
•• The nature of the user entity’s relationship with the service organisation, including relevant
contractual terms.
CC
In certain circumstances, the user entity may have sufficient controls in place for the auditor to
rely on, regardless of the controls at the service organisation. In such cases, the auditor does not
need to consider the controls at the service organisation.
Does the user entity information provide the auditor with sufficient understanding?
If the auditor gains a sufficient understanding of the user entity from information at the user,
then the risk assessment is complete. If not, the auditor must then consider the controls and
procedures in place at the service organisation (ISA 402 para. 11).
Required reading
ISA 402 paras 7, 9–11 and A1–A14.
To obtain additional
information from the
service organisation
Type 1 and Type 2 reports are assurance reports provided by another auditor and are discussed
in more detail later in this section.
Required reading
ISA 402 paras 12–14 and A15–A23.
CC
If not:
•• How can the auditor obtain sufficient appropriate audit evidence from the service
organisation?
Note: For a description of the types of audit procedures, candidates may wish to refer back to
the section on how the identification of risks and internal controls affects the audit of an entity.
How the auditor determines their response can be summarised as follows:
YES
Consider if need to
Perform substantive perform substantive
tests at user entity procedures at service
organisation
Testing controls
This involves testing the controls the user entity has over the outsourced function, such as
authorising data that is sent to the service organisation, and reviewing information that comes
back into the user entity’s financial reporting systems.
Substantive testing
This involves testing any records that are held by the user entity, including any reports from
the service organisation, and performing analytical procedures on the reasonableness of the
information.
Required reading
ISA 402 paras 15 and A24–A28.
CC
Testing controls
The following diagram shows what procedures are appropriate for testing a service
organisation’s internal controls:
Substantive testing
If the auditor decides it is necessary to perform substantive procedures on information and
documentation that is held by the service organisation, this could comprise a combination of:
•• Obtaining written confirmations of amounts directly from the service organisation.
•• Visiting the service organisation to inspect records.
•• Using another auditor to inspect records.
Required reading
ISA 402 paras 16–22 and A29–A44.
CC
Type 1 report
A Type 1 report is a report prepared by another auditor on the description and design of
controls at a service organisation. According to ISA 402 para. 8(b), a Type 1 report comprises:
(i) A description, prepared by management of the service organization, of the service organization’s
system, control objectives and related controls that have been designed and implemented as at a
specified date; and
(ii) A report by the service auditor with the objective of conveying reasonable assurance that includes
the service auditor’s opinion on the description of the service organization’s system, control
objectives and related controls and the suitability of the design of the controls to achieve the
specified control objectives.
Type 2 report
A Type 2 report is a report prepared by another auditor on the description, design and
operating effectiveness of controls at a service organisation. According to ISA 402 para. 8(c),
a Type 2 report comprises:
(i) A description, prepared by management of the service organization, of the service organization’s
system, control objectives and related controls, their design and implementation as at a specified
date or throughout a specified period and, in some cases, their operating effectiveness throughout
a specified period; and
(ii) A report by the service auditor with the objective of conveying reasonable assurance that includes:
a The service auditor’s opinion on the description of the service organization’s system, control
objectives and related controls, the suitability of the design of the controls to achieve the
specified control objectives, and the operating effectiveness of the controls; and
b A description of the service auditor’s tests of the controls and the results thereof.
Required reading
ISA 402 para. 8.
CC
Australia-specific
In Australia, for audits that are performed under the Corporations Act 2001 (Cth) (Corporations
Act), the auditor has additional responsibilities regarding the use of service organisations.
Corporations Act s. 307(c) and (d) require the auditor to ‘form an opinion on whether the
entity has kept proper financial records, and other records and registers as required by that
Act’ (ASA 402 Audit Considerations Relating to an Entity Using a Service Organisation (ASA 402)
para. Aus 5.1). The auditor needs to be aware of this when obtaining an understanding of
records that are held by the user and those that are held by the service organisation. In other
words, if a service organisation is not keeping proper financial records, the user organisation
may be in breach of the Corporations Act.
Required reading
ASA 402 para. Aus 5.1.
Corporations Act s. 307(c) and (d).
New Zealand-specific
In New Zealand, s. 455 of the Financial Markets Conduct Act 2013 (FMCA) requires that proper
accounting records be kept by a FMC reporting entity. The audit must be completed in
accordance with auditing and assurance standards. If the auditor’s report indicates that any
of the provisions of Part 7 have not been met, the auditor is required to notify the Financial
Markets Authority and the External Reporting Board within seven working days of signing the
report (FMCA s. 461G). This would include the requirement to keep proper accounting records.
Similar provisions in the Companies Act apply for the audit of entities that are not FMC reporting
entities: see ss 207–207C.
Required reading
Financial Markets Conduct Act 2013 ss 455 and 461G.
Companies Act 1993 ss 207–207C.
Quiz
[Available online in myLearning]
Readings
Required reading
Relevant International Standards on Auditing and national equivalents, and other relevant national
pronouncements
ISA 315 (Revised) Identifying ASA 315 Identifying and Assessing ISA (NZ) 315 (Revised) Identifying
and Assessing the Risks of the Risks of Material Misstatement and Assessing the Risks of
Material Misstatement through through Understanding the Entity Material Misstatement through
Understanding the Entity and Its and Its Environment Understanding the Entity and Its
Environment Environment
•• Paragraphs 1–5, 7–9,11–24, •• Paragraphs 1–5, 7–9,11–24, •• Paragraphs 1–5, 7–9,11–24,
30–31, A1–A5, A24–A27, 30–31, A1–A5, A24–A27, 30–31, A1–A5, A24–A27,
A29–A32, A35–A59, A67–A71, A29–A32, A35–A59, A67–A71, A29–A32, A35–A59, A67–A71,
A73– A83, A87–A92, A94, A73– A83, A87–A92, A94, A73– A83, A87–A92, A94,
A96–A121, A127– A128 and A96–A121, A127– A128 and A96–A121, A127– A128 and
A140–A143 A140–A143 A140–A143
•• Appendix 1 •• Appendix 1 •• Appendix 1
•• Appendix 2 •• Appendix 2 •• Appendix 2
ISA 402 Audit Considerations ASA 402 Audit Considerations ISA (NZ) 402 Audit Considerations
Relating to an Entity Using a Service Relating to an Entity Using a Service Relating to an Entity Using a Service
Organization Organisation Organisation
ISA 200 Overall Objectives of ASA 200 Overall Objectives of ISA (NZ) 200 Overall Objectives of
the Independent Auditor and the the Independent Auditor and the Independent Auditor and the
Conduct of an Audit in Accordance the Conduct of an Audit in Conduct of an Audit in Accordance
with International Standards on Accordance with Australian with International Standards on
Auditing Auditing Standards Auditing (New Zealand)
•• Paragraphs 13(c), 13(e) and 13(n) •• Paragraphs 13(c), 13(e) and 13(n) •• Paragraphs 13(c), 13(e) and 13(n)
ISA 320 Materiality in Planning and ASA 320 Materiality in Planning and ISA (NZ) 320 Materiality in Planning
Performing an Audit Performing an Audit and Performing an Audit
•• Paragraph 2 •• Paragraph 2 •• Paragraph 2
ISA 330 The Auditor’s Responses to ASA 330 The Auditor’s Responses to ISA (NZ) 330 The Auditor’s Responses
Assessed Risks Assessed Risks to Assessed Risks
•• Paragraphs 3 and 4 •• Paragraphs 3 and 4 •• Paragraphs 3 and 4
Relevant International Standards on Auditing and national equivalents, and other relevant national
pronouncements
Further reading
References
Chartered Accountants Australia and New Zealand 2015, Australian audit manual and toolkit for
small and medium sized entities, Thomson Reuters (Professional), Australia, Exhibit 3.7-1, pp 65–6;
Exhibit 23.5-1, p. 283.
International Federation of Accountants 2011, Guide to using ISAs in the audits of small- and
medium-sized entities, 3rd edn (IFAC) Guide, vol. 1, Exhibit 9.0-1, p. 109; vol.2, p. 116.
ACT
Activity 4.1
Understanding the entity and its
environment – inherent and control risks
Introduction
The auditor is required to obtain an understanding of the entity being audited, including its
internal control, in accordance with ISA 315 (Revised) Identifying and Assessing the Risks of
Material Misstatement through Understanding the Entity and Its Environment (ISA 315 (Revised)).
This understanding forms the basis for identifying and assessing risks of material misstatement
to the financial statements.
This activity links to learning outcomes:
•• Discuss and demonstrate the auditor’s responsibility to gain a thorough understanding of
the entity and its environment.
•• Discuss and demonstrate the auditor’s responsibility to identify and assess the risks of
material misstatement in financial statements.
•• Demonstrate how the identification of risks and internal controls affect the audit of an
entity.
At the end of this activity, you will be able to identify inherent and control risks from an
understanding of an entity and its environment, including its internal control, in accordance
with ISA 315 (Revised).
It will take you approximately 30 minutes to complete.
Scenario
Respingo is a private company in the retail swimwear industry in Queensland that has been
operating for a number of years. Factfigs Chartered Accountants (Factfigs) is Respingo’s
auditor. You are an audit senior at Factfigs assigned to the audit of Respingo for the year ending
30 June 20X3. Respingo is run by Charlotte Smith, the managing director, and one of two equal
shareholders, and a staff of 15. After the success of its first retail store, the company has grown
rapidly, opening five new stores along Queensland’s Sunshine Coast.
You visited the office of Respingo two months before the end of the financial year to perform
some audit planning procedures. During the visit, you performed procedures to obtain and
update your understanding of Respingo and its environment, including its internal control, in
accordance with ISA 315 (Revised).
You obtained the following information:
•• Respingo is currently renegotiating its financing arrangements, and the bank has requested
a copy of the June 20X3 audited financial statements.
•• The accounting records are maintained by a part-time accountant, who is able to assist
Respingo when he can. At other times, transactions are processed by a variety of staff
members.
•• Charlotte prepares a monthly budget for each financial year. The part-time accountant
prepares monthly management accounts using an accounting software package that
ACT
was purchased off-the-shelf. Charlotte reviews the monthly management accounts and
compares actual results to the budget.
•• Charlotte continues to be actively involved in all aspects of the business.
•• Charlotte authorises all payments and controls all inventory orders and deliveries.
•• Traditionally, the company focused on ladies’ swimwear and accessories. In response to a
fall in sales, Charlotte has diversified the product range this year by introducing male and
infant swimwear to all stores.
•• Sales at the stores have faced competition from the rapidly growing online market.
Charlotte is currently investigating options for Respingo to access this market through a
partnership with an online retailer.
•• Previous recommendations of the auditors, including internal control recommendations
contained in Factfigs’ management letters to Respingo, have received little attention from
Charlotte, and internal control recommendations have not been adopted.
Task
For this activity, you are required to identify risk factors from the information provided above,
determine whether each risk factor impacts inherent risk or control risk, and explain whether
each risk factor could lead to a material misstatement in the 20X3 financial statements.
You may wish to present your answer in the form of a table as follows:
ACT
Activity 4.2
Identifying internal control strengths and
weaknesses in a sales process
Introduction
It is recommended you work through Worked examples 4.1, 4.2 and 4.3 before attempting this
activity.
To identify and assess the risks of material misstatement, the auditor is required to obtain an
understanding of the entity being audited and its environment. This includes obtaining an
understanding of the entity’s internal control.
ISA 315 (Revised) Identifying and Assessing the Risks of Material Misstatement through
Understanding the Entity and Its Environment (ISA 315) requires the auditor to obtain an
understanding of internal control relevant to the audit, and provides a useful framework for
components of internal control.
This activity links to learning outcomes:
•• Discuss and demonstrate the auditor’s responsibility to gain a thorough understanding of
the entity and its environment.
•• Discuss and demonstrate the auditor’s responsibility to identify and assess the risks of
material misstatement in financial statements.
•• Demonstrate how the identification of risks and internal controls affect the audit of an
entity.
At the end of this activity, you will be able to identify control strengths and weaknesses through
gaining an understanding of an entity’s internal control.
It will take you approximately 20 minutes to complete.
Scenario
You are the audit senior assigned to the audit of International Cookie for the year ended
30 June 20X3. The audit manager, Santiago Toro, has asked you to review International Cookie’s
process for accepting and processing sales orders.
This activity follows on from the scenarios in Worked examples 4.1–4.3. The following
information is additional to the information in Worked examples 4.1–4.3.
AuditUs Partners Chartered Accountants (AuditUs) has evaluated the control environment
and pervasive controls over International Cookie’s financial reporting. The pervasive controls
have been assessed as robust enough to rely on for audit purposes, and sufficient appropriate
evidence is expected to exist to test their operating effectiveness.
ACT
Sales process
In relation to the sales process, you have obtained the following information:
•• Different staff members are responsible for initiating sales by taking orders, despatching
goods, raising sales invoices and creating delivery documentation.
•• The credit controller performs credit checks on all new customers prior to approving them.
Once new customers are approved, the credit controller enters the customer’s credit limit
into the system. Credit limits can only be overridden by the general manager or chief
financial officer (CFO).
•• Before processing, sales orders must be signed and then faxed or emailed to International
Cookie. Sales orders must be authorised by the sales manager.
•• Sales orders are entered into the accounting system, which then produces pre-numbered
packing slips for use by warehouse staff to pick inventory for shipping.
•• When goods are ready for delivery, they are checked by the warehouse supervisor against
the packing slips and approved sales orders. A pre-numbered delivery note is then
produced by the accounting system and checked against the goods and the sales order by
the warehouse supervisor.
•• The accounting department uses the pre-numbered delivery notes on the computer system
to prepare sales invoices for recording on Wednesdays and Fridays. There are no further
checks to ensure invoice dates and processing in the system match the actual delivery dates.
Task
For this activity, you are required to:
•• Identify and explain internal control strengths and weaknesses relating to the sales process
described in the scenario.
•• Outline the impact of each internal control strength and weakness on the planned audit
procedures of International Cookie.
•• Identify the key financial statement account at risk of misstatement.
You may wish to present your answer in the form of a table as follows:
CC
Core content
Unit 5: Analysing audit risks, financial
statement assertions and initial audit
engagements
Learning outcomes
At the end of this unit you will be able to:
1. Explain and apply the process of risk identification.
2. Explain and apply the use of assertions in assessing the risks of material misstatement at
the financial statement level and at the assertion level.
3. Describe and explain the steps that the auditor shall take in order to obtain sufficient,
appropriate audit evidence in regard to opening balances.
4. Describe and explain the objectives and responsibilities of the auditor with respect to
accounting estimates.
Introduction
The previous unit on understanding the entity and its environment outlined the auditor’s
responsibility to gather information about the entity and its environment, including the entity’s
system of internal control. It also outlined how this information is used to identify and assess
the risks of material misstatement. This unit will further explore the risk assessment process,
and discuss the auditor’s specific responsibilities in relation to particular audit issues.
The unit is divided into two sections. The first section addresses risk identification, including
identifying specific items in the financial statements that are at risk of material misstatement,
and their specific characteristics (or assertions) that are at risk. The second section of this unit
will address the auditor’s specific responsibilities in relation to initial audit engagements and
accounting estimates.
This unit looks at the following International Standards on Auditing (ISAs):
•• ISA 250 Consideration of Laws and Regulations in an Audit of Financial Statements (ISA 250).
•• ISA 315 (Revised) Identifying and Assessing the Risks of Material Misstatement through
Understanding the Entity and Its Environment (ISA 315 (Revised)).
•• ISA 510 Initial Audit Engagements – Opening Balances (ISA 510).
•• ISA 540 Auditing Accounting Estimates, Including Fair Value Accounting Estimates, and Related
Disclosures (ISA 540).
•• ISA 570 Going Concern (ISA 570)
aaa11605_csg
CC
Learning outcome
1. Explain and apply the process of risk identification.
ISA 315 (Revised) para. 5 states that an auditor must perform sufficient risk assessment
procedures to provide a basis for the identification and assessment of risks of material
misstatement at both the financial statements and assertion levels. However, note that risk
assessment procedures, by themselves, do not provide sufficient appropriate audit evidence on
which to base an audit opinion.
Enquiries of
management
and others
Observation Analytical
and inspection procedures
In practice, these three types of procedures (enquiries, analytical procedures and observation
and inspection) overlap and work together. For example, the results of analytical procedures
might lead the auditor to make certain enquiries of management regarding year-to-date
results or reactions to market changes. Discussions with management may then lead to other
procedures.
Each of these categories of risk assessment procedures is discussed separately below.
CC
Analytical procedures
Analytical procedures that are used as risk assessment procedures are typically performed at
a high level, which means that the results can only provide a broad indication of whether a
material misstatement may exist. However, using analytical procedures does help to identify
matters that have financial statements and audit implications.
The auditor could inspect documents related to the entity, such as:
•• Business plans, strategies and proposals.
•• Industry studies and media reports on the entity.
•• Major contracts and commitments.
•• Regulations and correspondence with regulators.
•• Correspondence with lawyers, bankers and other stakeholders.
•• Accounting policies and records.
•• Internal control manuals.
•• Reports prepared by management.
•• Other reports, such as the minutes from meetings of those charged with governance, and
reports from consultants.
Related activities
As well as considering the results of the specific risk assessment procedures described
above, ISA 315 (Revised) also requires the auditor to consider other sources of information
to determine whether they provide additional evidence that is relevant to identifying risks of
material misstatement. For example:
•• Information obtained from the client acceptance and continuance procedures
(ISA 315 (Revised) para. 7).
Example – Information obtained from the client acceptance and continuance procedures
When considering whether to accept the current year’s audit engagement, the auditor may
become aware of a substantial change in the board of directors, leading to the entity adopting
a more entrepreneurial focus. If this change results in the entity moving into new markets
and taking greater risks, it may increase the risks of material misstatement in the financial
statements.
CC
•• If the engagement partner has previously performed other engagements for the entity,
information that was obtained in performing those engagements (ISA 315 (Revised)
paras 8–9).
Once the auditor has gathered all available information from the risk assessment procedures,
ISA 315 (Revised) para. 10 requires the engagement partner and other key team members to
meet and discuss the financial statements’ susceptibility to material misstatement.
The purpose of this meeting is to ensure that key information is shared and understood by all
team members. It also helps team members to understand how the results of the procedures
they perform may affect other audit areas.
Required reading
ISA 315 (Revised) paras 6–10, A6–A23 and A74.
Required reading
ISA 315 (Revised) paras 25, 26 and A118–A126.
CC
Learning outcome
1. Explain and apply the process of risk identification.
When assessing the risks of material misstatement, ISA 315 (Revised) para. 27 requires the
auditor to determine whether any of the risks identified are, in the auditor’s judgement, a
significant risk. Significant risks are defined as risks that require ‘special audit consideration’
(ISA 315 (Revised) para. 4(e)), and are attached to items in the financial statements for which the
risks of material misstatement are highest. Therefore, these items require more audit time and
effort than other items in the financial statements.
Significant risks are assessed on their inherent risk, and before considering any related
mitigating controls. This means that significant risks are those items that are inherently risky
because of their nature, not because of the absence of internal controls. This is because internal
controls are ignored when assessing significant audit risks.
If all assessments of risks were charted as illustrated below, the two risks falling within the high
impact/high likelihood quadrant would be considered significant risks. Not all audits have risks
that fall into this quadrant, and therefore not all audits have significant risks.
Impact
(magnitude)
of risk
CC
•• Whether the risk is related to recent significant economic, accounting or other developments
that require specific attention.
•• The degree of subjectivity in the measurement of financial information that is related to the
risk.
•• Whether the risk involves significant transactions outside the entity’s normal course of
business.
Example – Significant risk related to significant transactions outside the normal course of business
A milk processing company decides to purchase a large dairy farm to ensure a consistent
supply of fresh milk. It will require significant expertise on the company’s behalf to correctly
account for the purchase. Therefore, the auditor might assess all material balances affected by
the purchase as significant audit risks.
CC
Whenever the auditor determines that a significant risk exists, they need to obtain an
understanding of the entity’s internal controls, including control activities, related to the
risk (ISA 315 (Revised) para. 29). Testing control activities is covered in detail in the unit on
responding to assessed risks – controls testing.
Required reading
ISA 315 (Revised) paras 4(e), 27–29 and A129–A139, and Appendix 2.
Going concern
While ISA 315 (Revised) includes the fundamental principles of risk assessment, including
the procedures the auditor shall perform and the types of information ordinarily gathered,
a number of other Auditing Standards include additional guidance on issues that may affect the
auditor’s risk assessment. One of these is ISA 570.
When preparing the financial statements, an entity’s management is required to make an
assessment of the entity’s ability to continue as a going concern. For financial statements that
are prepared on a going concern basis, the auditor needs to consider whether it is appropriate
to assume that the entity will remain a going concern when planning and performing the audit,
and when evaluating the results of the audit.
At the risk assessment stage of an audit, the auditor should:
•• Consider and ask management about the existence of any events/conditions that may cast
doubt on the entity’s ability to continue as a going concern.
•• Review management’s assessment of possible events/conditions, and any response/plans.
•• Remain alert for possible conditions or events.
An auditor’s responsibilities and response in relation to going concern are covered in the unit
on subsequent events and going concern.
Required reading
ISA 570 paras 10 and A2.
CC
Even for a fairly simple business, the extent of laws and regulations and their effects is far-
reaching. In considering more complex businesses – for example, those involved in food
handling, mining or aged care – it quickly becomes apparent how integral laws and regulations
are to the operations of any business, and why it is important for an auditor to consider how
they have impact on an audit.
ISA 250 recognises the wide range of laws and regulations that exist, and notes that the auditor
is not expected to detect non-compliance with all laws and regulations that affect an entity.
Required reading
ISA 250 paras 1–5.
ISA 250 requirements
The requirements of ISA 250 therefore involve considering:
•• The relevant legal and regulatory framework within which an entity operates.
•• When it is identified or suspected that an entity is not complying with the relevant laws and
regulations.
•• Reporting identified or suspected non-compliance.
If an entity fails to comply with the relevant laws and regulations, this will generally
have a direct, and possibly material effect on the financial statements. For example, non-
compliance with the Accounting Standards may result in a lack of appropriate recognition,
measurement or disclosure of transactions. In Australia, non-compliance is a breach of the
entity’s reporting obligations under the Corporations Act.
2. Other laws and regulations that do not have a direct effect on the financial statements,
but which may be fundamental to the business. These might include:
•• Licensing laws – for example, a club that has poker machines must hold the relevant
licence to do so, and comply with responsible gambling regulations.
•• Environmental regulations – for example, a fish market that discharges waste into the
ocean must comply with relevant wastewater regulations.
•• Workplace safety laws – for example, a trucking company must allow set rest breaks
and enforce maximum shift times in relation to its drivers.
Failure to comply with these laws and regulations may have a material effect on the
financial statements of the company concerned. For example, non-compliance with
environmental regulations may lead to fines and/or restrictions on operations.
CC
The requirements of ISA 250 in relation to these two categories of laws and regulations can
be illustrated as follows:
In addition to the above, ISA 250 also requires the auditor to remain alert to the possibility that
other audit procedures might reveal non-compliance (ISA 250 para. 15). For example, analytical
procedures that are performed on expenses may reveal material fines paid for non-compliance
with laws and regulations.
The auditor also needs to obtain appropriate written representations from management
regarding the entity’s compliance with laws and regulations (ISA 250 para. 16). These would be
included in management’s representation letter.
Required reading
ISA 250 paras 6–17.
CC
If the auditor becomes aware of actual or suspected non-compliance, they need to obtain:
•• An understanding of the act(s) of non-compliance and related circumstances (ISA 250
para. 18(a)).
•• Further information to enable them to evaluate the effect of this non-compliance on the
financial statements (ISA 250 para. 18(b)).
Required reading
ISA 250 paras 18–21 and A13–A18.
CC
Required reading
ISA 250 paras 22–29 and A19–A21.
CC
Australia-specific
ASA 250 Consideration of Laws and Regulations in an Audit of Financial statements (ASA 250) is
based on its international equivalent, ISA 250, with the following differences (identified by the
prefix ‘Aus’ in the relevant paragraph numbers):
– ASA 250 para. Aus A18.1 clarifies that if, in the case of an audit conducted under the
Corporations Act, the auditor identifies non-compliance with an Australian Accounting
Standard, defects or irregularities in the financial report or deficiencies, failures or
shortcomings in respect of s. 307 of the Act, the auditor’s report needs to include the
information required by the Act. The auditor needs to consider any other relevant laws and
regulations.
– ASA 250 para. Aus A19.1 includes a statutory responsibility by the auditor to report
certain instances of non-compliance with laws and regulations. For example, in certain
circumstances, the auditor is required under the Corporations Act to report to the
Australian Securities and Investments Commission (ASIC).
New Zealand-specific
ISA (NZ) 250 Consideration of Laws and Regulations in an Audit of Financial statements (ISA (NZ)
250) is based on its international equivalent, ISA 250, with the following differences (identified
by the prefix ‘NZ’ in the relevant paragraph numbers):
– ISA (NZ) 250 para. NZ3.1 states that, in New Zealand, those charged with governance often
have a statutory responsibility for the preparation of financial statements. In these cases the
process of financial reporting is usually delegated to management, but the responsibility
for such matters remains with those charged with governance. In applying ISA (NZ) 250
the auditor must apply professional judgement, their knowledge of New Zealand legal
requirements and corporate governance practices to determine whether ISA (NZ) 250
applies to management or those charged with governance.
– (ISA (NZ) 250 paras NZ16.1 and NZA12.1 explain that the auditor needs to request written
representations from those charged with governance that all known instances of non-
compliance or suspected non-compliance with laws and regulations whose effects should
be considered when preparing financial statements have been disclosed to the auditor.
CC
Audit assertions
Learning outcome
2. Explain and apply the use of assertions in assessing the risks of material misstatement at the
financial statement level and at the assertion level.
Audit assertions are important, as they help the auditor identify the specific characteristics of
the items in the financial statements that are likely to be materially misstated.
Underlying all account balances included in the financial statements by an entity’s management
are a number of implicit assertions (ISA 315 (Revised) para. A123). For example, a recorded cash
balance of $1,520,000 includes the implicit assertions that the cash balance:
•• Is complete (i.e. all cash belonging to the entity has been included).
•• Is valued in the appropriate currency.
•• Exists (i.e. no fictitious amounts are included).
•• Is actually the property right of the entity (i.e. the cash doesn’t belong to another entity).
All classes of transactions, account balances and disclosures in the financial statements contain
similar implicit assertions, and part of the auditor’s role is to assess the risks of material
misstatement at the assertion level.
Required reading
ISA 315 (Revised) paras 4(a) and A123.
CC
The three categories of assertions prescribed by ISA 315 (Revised) para. A124 are shown in the
following table:
Classes of transactions Occurrence Transactions and events that have been recorded have occurred
and events for the and pertain to the entity
period
Completeness All transactions and events that should have been recorded have
been recorded
Rights and The entity holds or controls the rights to assets, and liabilities are
obligations the obligations of the entity
Completeness All assets, liabilities and equity interests that should have been
recorded have been recorded
Valuation and Assets, liabilities and equity interests are included in the financial
allocation statements at appropriate amounts and any resulting valuation or
allocation adjustments are appropriately recorded
Presentation and Occurrence Disclosed events, transactions and other matters have occurred
disclosure and rights and and pertain to the entity
obligations
Completeness All disclosures that should have been included in the financial
statements have been included
Accuracy and Financial and other information are disclosed fairly and at
valuation appropriate amounts
Required reading
ISA 315 (Revised) para. A124.
CC
Overstate assets and/or understate liabilities To improve entity’s net asset position
This general assumption can help the auditor to identify the assertions that are at greatest risk
of material misstatement at the risk assessment stage of the audit, as illustrated by the table
below:
Revenues Overstated Occurrence – are the entity’s recorded revenue transactions genuine?
Accuracy – are the entity’s revenue transactions recorded appropriately
(e.g. at the correct dollar amount)?
Cut-off – are the entity’s revenue transactions recorded in the correct
accounting period (e.g. next period’s revenue is not incorrectly recorded in
the current period and, similarly, last period’s revenue was not carried over
and included in the current period)?
Expenses Understated Completeness – has the entity recorded all its expenses?
Accuracy – are the entity’s expenses recorded appropriately (e.g. at the
correct dollar amount)?
Cut-off – are the entity’s expenses recorded in the correct accounting period
(i.e. this period’s expenses are not incorrectly recorded in another period)?
Liabilities Understated Completeness – has the entity recorded all its liabilities?
Valuation and allocation – are the entity’s liabilities recorded at the proper
amount?
Therefore, while it is true that the auditor needs to obtain audit evidence in relation to all
the assertions that are applicable to each class of transaction, account balance and disclosure,
having a knowledge of the assertions that are at the greatest risk of misstatement helps the
auditor to direct effort to where it is most needed.
It is also important to understand the linkages between related accounts and assertions. For
example, there is a an interrelationship between revenue and trade receivables: being opposite
sides of a journal entry (i.e. a trade receivable is generally created by a revenue transaction).
If the auditor determines that there is a risk of material misstatement in a class of transactions,
there will be a corresponding risk of material misstatement in the related account balance. For
example, a risk of material misstatement in revenue that is due to an inaccurate cut-off also
means there is a corresponding risk that trade receivables are materially misstated (i.e. do the
year-end trade receivables exist and are they complete?).
CC
The relationships between classes of transaction and account balance assertions and the
potential extent of errors arising are represented in the diagram below:
Existence/Occurrence
(invalid transactions)
CC
Learning outcome
3. Describe and explain the steps that the auditor shall take in order to obtain sufficient,
appropriate audit evidence in regard to opening balances.
As stated in the introduction to this unit, auditors have additional responsibilities when dealing
with an initial audit engagement. Such an engagement is defined in ISA 510 para. 4(a) as being
one in which either:
•• ‘The financial statements for the prior period were not audited’ – this may occur, for
example, when a company grows and meets audit requirements for the first time, for
example, in Australia becoming a ‘large proprietary’ company under the Corporations Act
for the first time.
•• ‘The financial statements for the prior period were audited by a predecessor auditor’ – this
may occur, for example, when an entity puts its audit out to tender and selects a new audit
firm.
Initial audit engagements present a particular challenge for the auditor because there is no
evidence from the prior year’s audit regarding the opening balances (and disclosures) on which
the current year’s financial statements are based.
The auditor must perform specific audit procedures, as prescribed by ISA 510, to gather
sufficient appropriate audit evidence about whether:
•• Opening balances contain misstatements that materially affect the current period’s financial
statements.
•• Appropriate accounting policies have been consistently applied to the current period’s
financial statements.
Required reading
ISA 510 paras 1–4.
The auditor also needs to perform one or more of the following procedures:
•• If the prior period financial statements were audited, obtain evidence regarding the opening
balances for that audit by reviewing their predecessor auditor’s working papers (ISA 510
para. 6(c)(i)).
Taking this step requires the auditor to follow specific ethical and professional
requirements. For example, APES 110 Code of Ethics for Professional Accountants (in Australia)
and PES 1 (Revised) Code of Ethics for Assurance Practitioners (in New Zealand) detail specific
procedures for communicating with a predecessor auditor.
•• Evaluate whether audit procedures performed in the current period will provide evidence
that is relevant to the opening balances (ISA 510 para. 6(c)(ii)).
•• Perform specific procedures to obtain evidence regarding opening balances
(ISA 510 para. 6(c)(iii)).
CC
(a) The auditor was appointed after the commencement of the current financial reporting period and
accordingly was unable to attend the physical counting and inspection of inventory or other assets.
(c) The prior financial reporting period was audited and the predecessor auditor:
(d) the predecessor auditor does not, or cannot, provide access to the audit working papers for the
previous reporting period.
(e) The auditor cannot obtain sufficient appropriate audit evidence through:
(ii) specific procedures designed to obtain audit evidence regarding opening balances.
The overall objectives of the auditor include obtaining reasonable assurance about whether
the financial statements as a whole are free of material misstatement. Accordingly, where the
auditor is faced with any of the circumstances outlined above, they are required to determine
the effect of those circumstances on the financial statements as a whole. The auditor then
expresses an opinion on the financial statements as a whole, as they cannot express separate
opinions on each element of the financial statements.
Required reading
ISA 510 paras 5–7, 9 and A1–A7.
CC
Required reading
ISA 510 para. 8.
Required reading
ISA 510 paras 10–13 and A8–A9.
CC
Learning outcome
4. Describe and explain the objectives and responsibilities of the auditor with respect to
accounting estimates.
Accounting estimates are defined in ISA 540 para. 7(a) as ‘an approximation of a monetary
amount in the absence of precise means of measurement’. ISA 540 uses this term to describe:
•• Fair value accounting estimates. The measurement of a fair value estimate is prescribed by
the relevant financial reporting framework, and is often based on an assumed hypothetical
transaction between knowledgeable, willing parties in an arm’s-length transaction.
Examples of fair value accounting estimates include (ISA 540 para. A7):
–– Complex financial instruments that are not traded in an active and open market.
–– Property or equipment that is held for disposal.
–– Certain assets or liabilities that have been acquired in a business combination, including
goodwill and intangible assets.
–– Impairment testing of assets. This is an additional example provided by ASA 540
para. Aus A7.1 and ISA 540 (NZ) para. NZ.A.7.1.
•• Other accounting estimates that do not require a fair value determination (ISA 540 para. A6).
Examples include:
–– Allowance for doubtful accounts.
–– Inventory obsolescence.
–– Warranty obligations.
–– Depreciation or useful life of assets.
–– Costs arising from the settlement of litigation.
Accounting estimates can cause particular issues for the auditor because of the degree of
judgement and uncertainty involved in their measurement, which, in turn, increases the risks
of material misstatement. For example, it is generally much easier for the auditor to obtain
sufficient appropriate audit evidence in relation to an entity’s cash balance than for warranty
provision.
The auditor’s objective in relation to accounting estimates is to obtain sufficient appropriate
audit evidence about whether:
•• The accounting estimates, whether recognised or disclosed, are reasonable.
•• The disclosures related to the accounting estimates are adequate.
CC
The following diagram gives an overview of the procedures that ISA 540 requires the auditor to
perform in order to achieve this objective:
Reporting
Required reading
ISA 540 paras 1–7 and A6–A7.
For example, the national equivalent of IFRS 13 Fair Value Measurement forms part of the
applicable financial reporting framework in both Australia and New Zealand.
•• How management identifies circumstances that may give rise to the need for accounting
estimates to be included in the financial statements (ISA 540 para. 8(b)).
For example, management may identify the need for recognition and disclosure of
accounting estimates through the entity’s formal risk management process.
•• How management makes accounting estimates, including (ISA 540 para. 8(c)):
–– The method used to determine the estimates. This may, for example, be prescribed by
Accounting Standards.
–– Relevant controls. For example, there may be controls in place in relation to the review
and approval of accounting estimates.
–– Whether management has used an expert.
–– The underlying assumptions used, and whether these are reasonable.
CC
•• The outcome of accounting estimates included in the prior period financial statements
(ISA 540 para. 9). For example, the auditor might compare the prior year’s warranty
provision with the actual warranty expense in that year to gain information about the
effectiveness of management’s estimation process.
As part of identifying and assessing the RMM, the auditor also needs to consider estimation
uncertainty. ISA 540 para. 7(c) defines this as ‘the susceptibility of an accounting estimate and
related disclosures to an inherent lack of precision in its measurement’. Items with a low level of
estimation uncertainty give rise to a relatively low risk of material misstatement and vice versa
(ISA 540 para. 10).
Examples of items that display low and high estimation uncertainty are shown in the table below:
Low level of uncertainty (lower RMM) High level of uncertainty (higher RMM)
Business activities that are not complex Highly dependent on judgement, such as the outcome of
litigation or the amount and timing of future cash flows,
dependent on uncertain events many years in the future
Derived from data (referred to as ‘observable’ in Results of the auditor’s review of similar accounting
the context of fair value accounting) that is readily estimates made in the prior period financial statements
available, such as published interest rate data or indicate a substantial difference between the original
exchange-traded prices of securities accounting estimate and the actual outcome
The method of measurement prescribed by the Fair value accounting estimates for derivative financial
applicable financial reporting framework is simple instruments that are not publicly traded
and easily applied
Fair value accounting estimates, where the model Fair value accounting estimates for which a highly
used to measure the accounting estimate is well specialised entity-developed model is used, or for which
known or generally accepted, provided that the there are assumptions or inputs that cannot be observed
assumptions or inputs to the model are observable in the marketplace
Required reading
ISA 540 paras 7–10.
The auditor must use one or more of the following audit procedures in responding to assessed
risks of material misstatement with regard to an accounting estimate:
•• Determine whether events after the reporting date (i.e. events up to the date of the audit
report) provide evidence regarding the estimate (ISA 540 para. 13).
•• Test how management made the estimate, including whether the method is appropriate and
the assumptions used in estimation are reasonable.
CC
For example, in relation to a warranty provision, the auditor might:
–– Test the data on which the warranty is based (sales levels, or average cost of repair).
–– Test the assumptions underlying the provision (e.g. whether future warranty expenses
are likely to be higher or lower than existing expenses, and why management has
reached this conclusion).
The auditor only needs to perform this procedure when they intend to rely on controls, or
where substantive procedures alone do not provide enough evidence (though the latter is
rare). Tests of controls are covered in detail in the unit on responding to assessed risks –
controls testing.
•• Perform substantive procedures.
For example, the auditor might verify the proceeds from the sale of equipment held for
disposal and sold after year end by agreeing the amount received to the entity’s bank
statements. Substantive procedures are covered in detail in the unit on responding to
assessed risks – substantive testing.
•• Develop a point estimate or a range to evaluate management’s point estimate.
A point estimate is a single amount (e.g. an allowance for doubtful accounts of $1 million),
whereas a range covers a number of points (e.g. where the amount expected to be paid in
the event of losing a court case is in the range of $1.5 million–$2 million).
In performing this type of test, the auditor can either use management’s assumptions and
methods or develop their own, providing the relevant variables are taken into account.
In undertaking the procedures described above, the auditor needs to consider whether
specialised skills are required that are additional to those possessed by the audit team. For
example, the auditor may need to engage an expert to provide an estimate of the extractable ore
remaining in a mineral deposit.
The auditor also needs to obtain appropriate written representations from management,
and where appropriate, those charged with governance whether they believe significant
assumptions used in making accounting estimates are reasonable. In New Zealand, the auditor
obtains the written representations from those changed with governance (ISA 540 (NZ)
para. NZ22.1)
Further information on using the work of an expert and obtaining written representations is
provided in the unit on responding to the assessed risk – using the work of others, external
confirmations and written representations.
Management bias
Finally, the auditor needs to determine whether there is evidence of management bias in any/all
of the accounting estimates. Estimates are at particular risk of management bias because of the
inherent uncertainty that is involved in arriving at a reasonable amount. Management could,
for example, make small adjustments in the assumptions that are used to arrive at a number of
provisions (e.g. inventory obsolescence or allowance for doubtful accounts) in order to achieve a
target profit figure, thereby triggering a bonus payment.
Indicators of possible management bias include:
•• Changes in the method used to make an accounting estimate that do not appear to be valid
changes.
•• Use of assumptions for fair value accounting estimates that are inconsistent with general
marketplace assumptions.
•• A selection of assumptions that yield an estimate that is favourable to management’s
objectives.
CC
Required reading
ISA 540 paras 12–14, 21, 23, A52–A101, A125 and A128.
It is also important to recognise that a seemingly immaterial accounting estimate may have
the potential to result in a material misstatement that is due to estimation uncertainty. That is,
the amount shown in the financial statements may be small but the potential error, due to
estimation uncertainty, may be large.
Where the auditor determines that an accounting estimate with a high estimation uncertainty
is a significant risk, ISA 540 requires the auditor to perform certain procedures in addition to
those prescribed by ISA 315 (Revised) in relation to significant risks. These procedures are set
out below.
CC
•• Management’s selected measurement basis for the accounting estimates (e.g. fair value
estimates).
Required reading
ISA 540 paras 10–11, 15–17, A45–A51 and A102–A115.
Reporting
Once the auditor has gathered sufficient appropriate audit evidence, they need to evaluate
whether the accounting estimates are reasonable and appropriately disclosed, in accordance
with the applicable financial reporting framework.
The next step is to determine whether the misstatement is material and its effect, if any, on
the auditor’s report. These topics are covered in the units on responding to assessed risks –
evaluating audit evidence, and forming an opinion and issuing an auditor’s report.
Documentation
In documenting the work performed and conclusions reached, the auditor needs to include in
audit documentation:
•• The basis for the auditor’s conclusions about the reasonableness of accounting estimates,
and their disclosure, that give rise to significant risks.
•• Indicators of possible management bias, if any.
In Australia, audit documentation must also include the auditor’s evaluation of any indicators
of possible management bias in making accounting estimates, including whether the
circumstances giving rise to the indicators of bias represent a RMM due to fraud (ASA 540.Aus
23.1).
Required reading
ISA 540 paras 18–20, 22–23 and A116–A123.
Quiz
[Available online in myLearning]
Readings
Required reading
ISA 250 Consideration of Laws and ASA 250 Consideration of Laws and ISA (NZ) 250 Consideration of Laws
Regulations in an Audit of Financial Regulations in an Audit of a Financial and Regulations in an Audit of
Statements Report Financial Statements
•• Paragraphs 1–29 and A13–A21 •• Paragraphs 1–29, A13–A18, •• Paragraphs 1–29 and A13–A21
Aus A18.1, A19, Aus A19.1 and
A20–A21
ISA 315 (Revised) Identifying ASA 315 Identifying and Assessing ISA (NZ) 315 (Revised) Identifying
and Assessing the Risks of the Risks of Material Misstatement and Assessing the Risks of
Material Misstatement through through Understanding the Entity Material Misstatement through
Understanding the Entity and Its and Its Environment Understanding the Entity and Its
Environment Environment
•• Paragraphs 3–10, 25–29, •• Paragraphs 3–10, 25–29, •• Paragraphs 3–10, 25–29,
A6– A23, A74, A118–A126, A6– A23, A74, A118–A126, A6– A23, A74, A118–A126,
A129–A139 and Appendix 2 A129–A139 and Appendix 2 A129–A139 and Appendix 2
ISA 510 Initial Audit Engagements – ASA 510 Initial Audit Engagements – ISA (NZ) 510 Initial Audit
Opening Balances Opening Balances Engagements – Opening Balances
•• Paragraphs 1–13 and A1–A9 •• Paragraphs 1–13 and A1–A9 •• Paragraphs 1–13 and A1–A9
ISA 540 Auditing Accounting ASA 540 Auditing Accounting ISA (NZ) 540 Auditing Accounting
Estimates, Including Fair Value Estimates, Including Fair Value Estimates, Including Fair Value
Accounting Estimates, and Related Accounting Estimates, and Related Accounting Estimates, and Related
Disclosures Disclosures Disclosures
•• Paragraphs 1–23, A6–A7, •• Paragraphs 1–23, Aus 23.1, A6– •• Paragraphs 1–23, A6–A7,
A45–A123, A125 and A128 A7, A45–A123, A125 and A128 A45–A123, A125 and A128
ISA 570 Going Concern ASA 570 Going Concern ISA (NZ) 570 Going Concern
•• Paragraphs 10 and A2 •• Paragraphs 10 and A2 •• Paragraphs 10 and A2
Further reading
References
International Federation of Accountants 2011, Guide to using ISAs in the audits of small and
medium-sized entities, 3rd edn (IFAC Guide), vol. 1, Exhibit 6.0-1, p. 80; Exhibit 8.0-1, p. 99;
Exhibit 11.0-1, p 142; Exhibit 11.1-1, p. 144; vol.2, Exhibit 10.3-1, p. 121.
Australian Auditing Standards Board, Opening Balances, Explanatory Guide, May 2012.
ACT
Activity 5.1
Identifying risk at the assertion level
Introduction
An auditor can use risk assessment procedures, including analytical procedures, during the
planning stage of the audit to identify areas of the financial statements at risk of material
misstatement.
This activity links to learning outcomes:
•• Explain and apply the process of risk identification.
•• Explain and apply the use of assertions in assessing the risks of material misstatement at the
financial statement level and at the assertion level.
At the end of this activity, you will be able to identify risks at the assertion level, in accordance
with ISA 315 (Revised) Identifying and Assessing the Risks of Material Misstatement through
Understanding the Entity and Its Environment (ISA 315 (Revised)).
It will take you approximately 30 minutes to complete.
Scenario
You are an audit senior at AuditUs Partners Chartered Accountants (AuditUs). Gianni Corti, the
audit partner, has asked you to begin planning for the 30 June 20X3 audit of The Beauty Spot
Limited (TBS), a listed company whose main activities are the marketing and distribution of a
range of men and women’s cosmetics and toiletries.
Due to the company’s market diversification, sales do not have a significant seasonal trend.
Price structures and terms of trade are the same for all segments of TBS’s market.
From discussions with management, you have obtained the following information:
•• The company’s market comprises pharmacies/chemists, supermarkets and, more recently,
upmarket boutique perfumeries.
•• The company has acquired a reputation for always having the latest and most fashionable
brands and products available, purchased from both local and overseas suppliers.
•• From the beginning of June 20X3, at the request of TBS’s suppliers, most local purchases
have been on a cash on delivery (COD) basis.
ACT
The two previous financial statements were given unmodified audit opinions by AuditUs.
Half‑year management financial statements (unaudited), together with the comparative figures
for the two previous years (audited), are as follows:
Current assets
Non-current assets
Current liabilities
Non-current liabilities
ACT
Income
Cost of sales
Expenses
Tasks
For this activity, in relation to trade receivables and inventory, you are required to:
•• Perform relevant analytical procedures.
•• Identify the key assertion at risk and justify your selection.
ACT
Activity 5.2
Identifying risk at the financial statement
level
Introduction
An auditor can use risk assessment procedures, including analytical procedures, during the
planning stage of the audit to identify areas of the financial statements at risk of material
misstatement.
This activity links to learning outcomes:
•• Explain and apply the process of risk identification.
•• Explain and apply the use of assertions in assessing the risks of material misstatement at the
financial statement level and at the assertion level.
At the end of this activity, you will be able to identify risk at the financial statement level, in
accordance with ISA 315 (Revised) Identifying and Assessing the Risks of Material Misstatement
through Understanding the Entity and Its Environment (ISA 315 (Revised)) and ISA 570 Going
Concern (ISA 570).
It will take you approximately 30 minutes to complete.
Scenario
This activity is related to Activity 5.1 ‘Identifying risk at the assertion level’.
You are an audit senior at AuditUs Partners Chartered Accountants (AuditUs). Gianni Corti, the
audit partner has asked you to begin planning for the 30 June 20X3 audit of The Beauty Spot
Limited (TBS), a listed company whose main activities are the marketing and distribution of a
range of men’s and women’s cosmetics and toiletries.
Due to the company’s market diversification, sales do not have a significant seasonal trend.
Price structure and terms of trade are the same for all segments of TBS’s market.
From discussions with management, you have obtained the following information:
1. The company’s market comprises pharmacies/chemists, supermarkets and, more recently,
upmarket boutique perfumeries.
2. The company has acquired a reputation for always having the latest and most fashionable
brands and products available, purchased from both local and overseas suppliers.
3. From the beginning of June 20X3, at the request of TBS’s suppliers, most local purchases
have been on a cash on delivery (COD) basis.
ACT
The two previous financial statements were given unmodified audit opinions by AuditUs.
Half‑year management financial statements (unaudited) together with the comparative figures
for the two previous years (audited) are as follows:
Current assets
Non-current assets
Current liabilities
Non-current liabilities
ACT
Income
Cost of sales
Expenses
Task
For this activity, you are required to extend your analysis to encompass risk at the financial
statements level. Outline factors in the information you have gathered that may indicate that
TBS has a going concern problem.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 5.3
Identifying risks in accounting for estimates
Introduction
During the planning phase of an audit, the auditor has certain objectives and responsibilities
when identifying risks in accounting for estimates. These objectives and responsibilities are laid
down in ISA 315 (Revised) Identifying and Assessing the Risks of Material Misstatement through
Understanding the Entity and Its Environment (ISA 315 (Revised)) and ISA 540 Auditing Accounting
Estimates, Including Fair Value Accounting Estimates, and Related Disclosures (ISA 540).
This activity links to learning outcomes:
•• Explain and apply the process of risk identification.
•• Describe and explain the objectives and responsibilities of the auditor with respect to
accounting estimates.
At the end of this activity, you will be able to identify account balances that include estimates
and related assertions at risk of material misstatement and assess the impact on the audit plan,
in accordance with ISA 315 (Revised) and ISA 540.
It will take you approximately 30 minutes to complete.
Scenario
You are an audit senior with AuditUs Partners Chartered Accountants (AuditUs) and assigned
to the Global Entertainment Network Limited (GEN) audit for the year ended 30 June 20X3.
GEN is an Australian company listed on the Australian Securities Exchange (ASX).
In January 20X3, GEN changed the payroll system to a new off-the-shelf system. Since this
‘go‑live’ date, there have been some complaints by staff about underpayment of wages and
annual leave entitlements due to incorrect salary packages and hourly rates being recorded in
the system.
Task
For this activity, you are required to:
•• Identify GEN’s key accounts that are most at risk of misstatement if the new payroll system
does not operate as expected, and explain the reasons for identifying each account.
•• Identify and explain the key assertions at risk related to the accounts identified.
•• Outline how the change in the payroll system could impact GEN’s 30 June 20X3 audit plan.
CC
Core content
Unit 6: Analysing audit risks – fraud
Learning outcomes
At the end of this unit you will be able to:
1. Explain and identify the characteristics of fraud in the context of an audit.
2. Identify who has primary responsibility for fraud prevention and detection.
3. Demonstrate the objectives and responsibilities of an auditor with respect to fraud.
4. Identify and assess the risks of material misstatement in financial statements due to fraud.
5. Identify and assess fraud risk factors arising from related party relationships and
transactions.
Introduction
As discussed in earlier units of the Audit & Assurance (AAA) module, one of the objectives of
the auditor in conducting a financial statements audit is to ‘obtain reasonable assurance about
whether the financial statements as a whole are free from material misstatement, whether due
to fraud or error, thereby enabling the auditor to express an opinion on whether the financial
statements are prepared, in all material respects, in accordance with an applicable financial
reporting framework’ (ISA 200 Overall Objectives of the Independent Auditor and the Conduct of an
Audit in Accordance with International Standards on Auditing (ISA 200) para. 11(a)).
To be able to form an opinion on the financial statements, the auditor must consider the many
risks that may lead to a material misstatement, including fraud risk. This unit discusses the
importance of identifying and evaluating the risks of material misstatement due to fraud, and
the appropriate responses to such risks. In addition, it looks at specific risks arising from related
party relationships and transactions.
The unit also examines the audit procedures required in all three phases of the audit process
(i.e. planning, risk response and reporting) in relation to fraud, and clarifies the responsibilities
of the auditor and those charged with governance and management regarding fraud.
aaa11606_csg
CC
In addition to ISA 200, the following Standards are central to this unit:
•• ISA 240 The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
(ISA 240).
•• ISA 315 (Revised) Identifying and Assessing the Risks of Material Misstatement through
Understanding the Entity and Its Environment (ISA 315).
•• ISA 330 The Auditor’s Responses to Assessed Risks (ISA 330).
•• ISA 550 Related Parties (ISA 550).
Learning outcome
1. Explain and identify the characteristics of fraud in the context of an audit.
Fraud can have different meanings depending on the legal definitions in particular jurisdictions.
This unit only looks at fraud as defined in ISA 240.
Fraud is defined in ISA 240 para. 11(a) as ‘an intentional act by one or more individuals among
management, those charged with governance, employees, or third parties, involving the use of
deception to obtain an unjust or illegal advantage’.
The distinction between ‘fraud’ and ‘error’ lies in whether the underlying action that results in
the misstatement of the financial statements is intentional or unintentional (ISA 240 para. 2).
Drivers of fraud
ISA 240 para. A1 identifies the conditions that can lead to fraud:
Drivers Explanation
Incentive or pressure Pressure from sources outside or inside the entity to achieve unrealistic financial results
For example, management is put under pressure to achieve an expected earnings
target or financial outcome
Rationalisation The ability or capacity that enables people to justify or rationalise committing fraud
For example, some people rationalise fraudulent acts as ‘this is not a big deal’ or
‘I am only taking what I deserve’, because their attitude, character or ethical values
allow them to knowingly and intentionally commit a dishonest act
Collectively, these drivers are commonly referred to as the ‘fraud triangle’ because, when all
three are present, it is highly likely that fraud is occurring.
Ra
tio
re
ssu
na
lisa
Pre
tio
n
Opportunity
CC
Incentive or pressure: Sam has an incentive to reduce taxes that would otherwise be payable.
Opportunity: Sam, as the owner-manager, is able to override the internal controls over
revenue recognition and not record the income from this service.
Rationalisation: Sam could justify this to himself as just being work for a friend and that he is
entitled to the money, and also that it is acceptable for him not to record the revenue from this
service as he already pays too much in taxes.
Adapted from: IFAC Guide, vol. 2, pp. 90–91.
Types of fraud
Although fraud is a broad legal concept, in the context of an audit, the auditor is mainly
concerned with fraud that causes a material misstatement in the financial statements.
There are two types of intentional misstatements that are relevant to the auditor (ISA 240
para. 3):
•• Fraudulent financial reporting.
•• Misappropriation of assets.
CC
Misappropriation of assets
‘Misappropriation of assets involves the theft of an entity’s assets and is usually perpetrated by
employees in relatively small and immaterial amounts’ (ISA 240 para. A5). However, even these
amounts can become material when the misappropriation is perpetrated over a period of time.
When the transactions are disguised or concealed, misappropriations can be difficult to detect.
As set out in ISA 240 para. A5, misappropriation of assets can be accomplished in a variety of
ways, including:
Theft of physical assets or Stealing inventory for personal use or for sale
intellectual property
Stealing scrap for resale
Colluding with a competitor by disclosing technological data in return for payment
Inappropriate use of Using the entity’s assets as collateral for a personal loan or a loan to a related party
an entity’s assets for
personal use
ISA 240 para. A5 notes that the misappropriation of assets is ‘often accompanied by false or
misleading records or documents in order to conceal the fact that the assets are missing or have
been pledged without proper authorisation’.
The risk of an auditor not detecting a material misstatement due to fraud is even greater when
the fraud is perpetrated by management rather than other employees. Management often has
the ability to manipulate accounting records and override control procedures designed to
prevent misstatements being made by other employees (ISA 240 para. 7).
CC
ISA 240 para. A4 states that ‘fraudulent financial reporting often involves management override
of controls that otherwise may appear to be operating effectively’. Management override is the
deliberate interference with internal controls by managers in the processing or treatment of
financial information. The risk that management may override existing controls is particularly
relevant when assessing the risk of fraudulent financial reporting.
ISA 240 para. A4 provides examples of techniques used by management to override controls:
• Recording fictitious journal entries, particularly close to the end of an accounting period, to
manipulate operating results or achieve other objectives.
• Inappropriately adjusting assumptions and changing judgments used to estimate account balances.
• Omitting, advancing or delaying recognition in the financial statements of events and transactions
that have occurred during the reporting period.
• Concealing, or not disclosing, facts that could affect the amounts recorded in the financial
statements.
• Engaging in complex transactions that are structured to misrepresent the financial position or
financial performance of the entity.
• Altering records and terms related to significant and unusual transactions.
Smaller entities may not necessarily have a written code of conduct, an internal audit function,
or even a dedicated audit committee; however, the auditor would consider the tone set by
senior management (or owners) regarding honest and ethical conduct and the degree of
authorisation required for transactions (ISA 240 para. A27).
Consequently, the auditor must maintain professional scepticism throughout the entire audit
process. At all phases of the audit, the auditor must consider the potential for management
override and also recognise that standard procedures for detecting errors may not be effective
in detecting fraud. The requirements of ISA 240 are intended to assist auditors to identify and
assess fraud risks, and design audit procedures to address such risks (ISA 240 para. 8).
The news articles listed in the further reading below highlight how misleading accounting
practices can result in extreme consequences.
The article on Melbourne Storm highlights fraudulent financial reporting, while those on
Leighton and the IRD discuss the consequences of misappropriation of assets. The article on
Sims Metal highlights the consequences of management overriding controls.
Required reading
ISA 200 para. 11(a).
ISA 240 paras 2–3, 6–11, A1–A6, A23, A26–A27 and Appendix 1.
CC
Learning outcome
2. Identify who has primary responsibility for fraud prevention and detection.
Management and those charged with governance have primary responsibility for not only
detecting, but also preventing, fraud within the entity (ISA 240 para. 4). This includes creating
a culture of integrity and honesty, so that people understand how they are expected to act in
circumstances where potential conflicts of interest or other ethical matters may arise.
Management should lead by example. A weak ethical culture increases the risk that employees
will bypass, override or breach any controls that an entity has in place because employees
perceive that management is doing the same. In other words, a good system of controls is at risk
of failing if the ethical culture is weak.
ISA 240 acknowledges that while an auditor may suspect fraud, the likelihood of an auditor
identifying its occurrence is low. This is generally because fraud is a crime and, although the
auditor may suspect or, in rare cases, identify the occurrence of fraud, they are neither trained
nor responsible for making a legal determination (ISA 240 para. 3) of whether fraud has actually
occurred. Nonetheless, the incidence of corporate fraud is quite high.
The auditor obtains evidence about the ethical culture of an entity, and of management’s
attitude to fraud risk from a variety of sources, including written policies and procedures
regarding conduct, whistleblower protection, the overall control environment and the auditor’s
experience with management.
Required reading
ISA 240 paras 3–4.
CC
Learning outcomes
3. Demonstrate the objectives and responsibilities of an auditor with respect to fraud.
4. Identify and assess the risks of material misstatement in financial statements due to fraud.
The auditor is responsible for planning and performing the audit to obtain reasonable assurance
that the financial statements are free from material misstatement relating either to error or
fraud. This means that the auditor needs to understand the risks of fraud when planning and
conducting the audit. However, as noted in ISA 240 para. 5, due to ‘the inherent limitations
of an audit, there is an unavoidable risk that some material misstatements of the financial
statements may not be detected, even though the audit is properly planned and performed’.
The responsibilities of the auditor and the potential effects of the audit’s inherent limitations are
discussed in ISA 240 paras 6–8.
ISA 240 para. 10 lists the objectives of the auditor in relation to fraud in a financial statement
audit, as follows:
(a) To identify and assess the risks of material misstatement of the financial statements due to fraud;
(b) To obtain sufficient appropriate audit evidence regarding the assessed risks of material
misstatement due to fraud, through designing and implementing appropriate responses; and
(c) To respond appropriately to fraud or suspected fraud identified during the audit.
It is therefore important that the auditor consider fraud throughout the three phases of the audit
process.
Risk response The auditor executes the tests designed to detect material misstatement
Required reading
ISA 240 paras 5–8 and 10.
CC
The audit team discusses the potential for material misstatement in financial statements due
to fraud
One of the specific planning procedures mandated by both ISA 315 and ISA 240 is a team
discussion that places emphasis on how and where the audit client’s financial statements might
be susceptible to material misstatement – in the case of ISA 240, due to fraud (ISA 240 para. 15).
This discussion is a critical part of the audit planning process, as it helps to direct and focus the
audit team’s attention to areas where material misstatement may lie. In addition, there are three
other benefits that arise from this discussion (ISA 240 para. A10):
1. It provides an opportunity for more junior audit team members to gain insights from senior
team members about how and where financial statements may be susceptible to material
fraud.
2. It enables the audit partner to consider the appropriate responses to areas of susceptibility,
and which team members should perform certain audit procedures.
3. It helps the audit partner determine how the results of the audit procedures are to be
communicated among the team, and how to address any allegations of fraud that may arise.
ISA 240 para. A11 provides guidance on matters that could be discussed at this audit team
discussion.
As noted in the IFAC Guide, vol. 2, s. 8.8 (discussion on fraud risk), members of the audit
team may identify a fraud risk factor that relates to one or more of the fraud triangle elements.
However, it is less likely that any one audit team member will identify all three of the drivers
together. It is therefore important for the audit team to continually discuss their findings
throughout the engagement. This process is illustrated in the diagram below.
CC
Enquiries of management
Management bears primary responsibility for fraud. Therefore, as part of the planning process,
the auditor will make enquiries of management, specifically in relation to fraud.
ISA 240 para. 17 requires the auditor to make enquiries of management regarding:
•• Management’s assessment of the risk of material misstatement due to fraud, including the
nature and frequency of such assessments.
•• Management’s process for identifying and responding to the risks of fraud, including
specific risks identified, or brought to their attention, or classes of transactions, account
balances, or disclosures for which the risk of fraud is likely to exist.
•• Management’s communication with those charged with governance relating to its processes
for identifying and responding to fraud risks; and
•• Management’s communications to employees regarding its views on business practices and
ethical behaviour.
The regularity and scope of management’s assessments are relevant to the auditor’s
understanding of the entity’s control environment and attitude towards fraud prevention and
detection. While not conclusive evidence, an entity that performs detailed regular assessments
may provide the auditor with more confidence in the appropriateness of management’s attitude
regarding fraud prevention and detection than an entity that performs ad hoc, surface-level
assessment of the risk of material misstatement due to fraud. However, the auditor also needs
to understand that the formality and regularity of assessments will vary depending on the size
and complexity of each entity (ISA 240 para. A12).
Because management is usually in the best position to perpetrate fraud, the auditor may decide
to corroborate management’s responses with other information (ISA 240 para. A17).
CC
Identify fraud risk factors arising from related party relationships and transactions
As related parties are not independent of each other, related party relationships and
transactions may carry higher risks of material misstatement due to fraud than transactions
with unrelated parties. ISA 550 requires the auditor to assess fraud risk factors from related
party relationships and transactions. Details of these procedures are discussed later in this unit.
While the analytical procedures are not specified, they generally involve ratio analysis and
benchmarking. Analytical review is usually performed by comparing year-on-year fluctuations
within the entity itself. Where fluctuations are not consistent with the auditor’s understanding
of the entity or of the audit client’s industry, the auditor needs to investigate further by
obtaining explanations of variances from management.
CC
Required reading
ISA 240 paras 12–27, 47 and A7–A32.
Worked example 6.2: Using CAATs and data tools to identify risks of fraud in management
override of controls
[Available online in myLearning]
CC
To help the auditor meet the above requirement, ISA 240 para. A37 suggests changing the
procedures as follows:
•• Changing the nature of audit procedures to obtain more reliable and relevant audit
evidence – for example, by performing more detailed or targeted sample selection through
the use of computer-assisted audit techniques (CAATs), or by obtaining more extensive
corroborative evidence, such as obtaining third-party confirmations of account balances.
•• Modifying the timing of audit procedures – for example, by performing some substantive
procedures at year end, rather than at the interim stage, if better able to address an
identified fraud risk.
•• Changing the extent of the audit procedures – for example, increasing the test sample sizes
for accounts or transactions concerned.
Transactions and balances that require the application of estimates and judgements may present
a particular fraud risk, as management may have the opportunity to manipulate financial
reporting through bias in selecting estimates and assumptions.
ISA 240 Appendix 2 includes examples of responses and changes to audit procedures that
the auditor can make where there are identified fraud risks relating to fraudulent financial
reporting and misappropriation of assets.
(ii) Select journal entries and other adjustments made at the end of a reporting period; and
(iii) Consider the need to test journal entries and other adjustments throughout the period.
CC
•• Financial reporting processes and the nature of evidence that can be obtained – that is,
whether the journals are automated or manual, the nature of controls and the audit trail.
•• Characteristics of fraudulent journals or adjustments. CAATs are commonly used by
auditors for testing journal entries. The auditor may use CAATs to select entries that are:
–– made to unrelated, unusual, or seldom used accounts
–– made or requested by those who do not usually post journal entries
–– posted around period end without adequate explanation
–– made in preparing the financial statements, without identifying the relevant general
ledger accounts
–– round numbers.
•• The nature and complexity of the accounts. The auditor may select journals and adjustments
from specific accounts that are complex or unusual, contain significant estimates, have been
misstated in the past, or are not regularly reconciled.
•• Journal entries or other adjustments processed outside the normal course of business.
The auditor may direct journal testing towards accounts that have specific fraud risk factors.
For example:
•• Complex, unbilled revenue accounts based partly on estimates.
•• Significant business combinations.
•• Journals to accounts where a specific fraud risk has been identified – for example, sales.
The auditor is specifically required to select journal entries made at the end of the reporting
period (ISA 240 para. 32(a)(ii)), because this is when fraudulent entries are often made.
However, there is also a requirement to consider the need to test journal entries and other
adjustments made throughout the period (ISA 240 para. 32(a)(iii)).
ISA 240 para. A44 reminds us that perpetrators of fraud can exert extensive efforts to conceal
how the fraud is accomplished, which may involve posting a series of entries across a number
of months throughout the period. Therefore, where the risk of fraud arising from management
override and the use of journal entries is high, the auditor should consider extending the journal
entry testing procedures to journals posted throughout the period.
The auditor needs to be aware that individual estimates may not show signs of bias, but when
a number of estimates are examined together, a pattern of bias may emerge. For example,
management may make a downward adjustment in its estimation of a make-good provision
while at the same time making a change in its estimate of doubtful debts that reduces
the balance of doubtful debts. The net impact of the two changes may result in a material
overstatement of the net assets of the company.
CC
Unusual transactions
As part of the procedures to address fraud risk arising from the potential for management
override, the auditor is required to evaluate the business rationale regarding unusual
transactions, or transactions made outside the normal course of business (ISA 240 para. 32(c)).
If a transaction lacks an appropriate business rationale, it may indicate that the transaction was
entered into for the purpose of fraudulent financial reporting or to hide the misappropriation of
assets.
ISA 240 para. A48 provides guidance to assist the auditor in evaluating whether unusual
transactions may have been entered into for fraudulent purposes. Indicators of potential fraud
include:
•• Overly complex transactions – for example, transactions that involve multiple entities.
•• Where those charged with governance have not been made aware of the unusual
transaction.
•• Where management places an emphasis on a particular accounting treatment rather than
on the substance of the transaction.
•• Transactions that involve non-consolidated related parties.
•• Transactions involving previously unidentified related parties.
•• Transactions involving parties that do not have the financial strength to support the
transaction without the assistance of the entity under audit.
Required reading
ISA 240 paras 28–33, 39–47 and A33–A49, and Appendices 2 and 3.
ISA 200 para. A35.
ISA 315 para. A124.
ISA 330 para. 6.
Use of CAATs, data analysis and data assurance tools in response to fraud risk
Introduction
As discussed in an earlier unit, advancements in technology and the exponential growth in
data are transforming the audit, ushering in new audit tools such as CAATs and data assurance
techniques. These tools enable auditors to better identify not only financial reporting risks and
operational business risks but also fraud risks. They also deliver a more relevant audit through
tailoring of the approach. Such tools are effectively changing the core approach to the audit.
Data analysis
In the unit on auditing standards and quality control, you were introduced to the difference
between data analysis and obtaining assurance from data. Before responding directly to the risk
of ‘management override of controls’ under Auditing Standards, data analysis can assist the
auditor by highlighting results that may be indicative of fraudulent activity.
For example, by using a combination of visualisation technology and exploration tools, an
auditor can derive a lot of useful information very quickly from client systems, including
unusual patterns or trends across general ledger accounts, frequency of general ledger postings
by individuals and the timing of postings.
According to the Technical Query Home website (tech.queryhome.com → Tags → Search for:
data visualisation), data visualisation is:
…a general term that describes any effort to help the user understand the significance of data by placing
it in a visual context. Patterns, trends and correlations that might go undetected in text-based data can
be exposed and recognized easier with data visualization software and exploration tools
CC
A high volume of manual journal entries may be a leading indicator that your finance system
and processes are inefficient or overly complex. Other key insights that can be uncovered
include:
•• A high amount of journal postings just below authorisation limits.
•• Analysis of gender pay by grade/function.
•• Someone outside the finance department posting journals.
•• Time wasted by posting entries twice, or reversing them.
In short, a data-driven audit process cannot only provide assurance, but also deliver business-
ready information and feedback that may not have previously been available to the company.
While the use of such tools does not directly respond to the risk of fraud, it may assist the
auditor in assessing the risk of fraud and help shape further audit procedures where an
assessed risk of fraud exists.
Based on the output for a given parameter, the auditor would then have a broad, yet tailored
range of accurate and complete data from which they can direct their journal entry testing.
In addition to responding to the fraud risk, the auditor can also use these outputs to offer
value‑adding insights to the company. Refer to the unit on responding to assessed risk –
substantive testing for further discussion on how CAATs, data analysis and data assurance can
be used from a substantive testing perspective.
Worked example 6.3: Identifying audit procedures in response to assessed fraud risks
[Available online in myLearning]
CC
Where the auditor identifies any unusual relationships, they must obtain, in the first instance,
an explanation for variances from expectations. Where necessary, the auditor may also need
to obtain further audit evidence to support the amounts presented in the financial statements.
The implications of not being able to obtain sufficient appropriate audit evidence are discussed
below. The use of final analytical procedures is discussed further in the unit reviewing the
financial statements and audit results.
CC
Written representations
Under ISA 240 para. 39, the auditor is required to obtain a written representation from
management and, where appropriate, those charged with governance that they:
•• Acknowledge their responsibility for the design, implementation and maintenance of
controls to prevent and detect fraud.
•• Confirm they have disclosed to the auditor the results of management’s assessment
regarding the risk of material misstatement in the financial statements due to fraud.
•• Confirm they have disclosed to the auditor their knowledge of fraud or suspected fraud
involving either management, employees with significant roles in internal control, or others
where the fraud could have a material impact on the financial statements.
•• Confirm they have disclosed to the auditor any allegations of fraud or suspected fraud
communicated by current or past employees, analysts, regulators or others.
ISA 240 para. A53 refers the auditor to ISA 450 Evaluation of Misstatements Identified during
the Audit and ISA 700 for guidance on the evaluation of misstatements and the effect on the
auditor’s opinion. The requirements of ISA 700 Forming an Opinion and Reporting on Financial
Statements (ISA 700) are discussed in more detail in the unit on forming an opinion and issuing
an auditor’s report. Under ISA 700 para. 11, the auditor must attempt to obtain sufficient
appropriate audit evidence to support the financial statement assertions, in accordance with
ISA 330.
In accordance with ISA 330, the auditor is also required to evaluate whether the initial
assessments of the risks of material misstatement remain appropriate at the end of the audit
(ISA 240 para. A49). This assessment includes risks of material misstatement due to fraud.
Required reading
ISA 240 paras 34–39, 43 and A49–A66.
ISA 520 para. 6.
ISA 700 para. 11.
CC
Professional scepticism
Professional scepticism, as introduced in the unit on assurance purpose and framework,
is particularly important when assessing the risk of fraud. This is due to the characteristics of
fraud, including the likelihood of concealment and the intentional nature.
ISA 240 para. A7 articulates the meaning of professional scepticism:
Maintaining professional skepticism requires an ongoing questioning of whether the information
and audit evidence obtained suggests that material misstatement due to fraud may exist. It includes
considering the reliability of the information to be used as audit evidence and the controls over
its preparation and maintenance where relevant. Due to the characteristics of fraud, the auditor’s
professional skepticism is particularly important when considering the risks of material misstatement
due to fraud.
CC
In addition, ISA 240 para. 42 mandates the auditor to communicate with those charged with
governance ‘any other matters related to fraud that are, in the auditor’s judgment, relevant
to their responsibilities’. ISA 240 para. A64 includes examples of matters the auditor may
communicate directly to those charged with governance, and broadly covers concerns regarding
management’s performance relevant to fraud and authorisation of transactions outside the
normal course of business.
Communication of fraud matters to members of management or those charged with governance
is a sensitive area and one that is usually handled by the engagement partner or the next most
senior member of the audit team. Any evidence supporting or indicating fraud is thoroughly
reviewed, and careful consideration is given as to how the communication is made.
Documentation
ISA 240 para. 44 requires that the following information be included in the audit documentation
of the auditor’s understanding of the entity and its environment and the assessment of the risks
of material misstatement, as required by ISA 315:
(a) The significant decisions reached during the discussion among the engagement team regarding the
susceptibility of the entity’s financial statements to material misstatement due to fraud; and
(b) The identified and assessed risks of material misstatement due to fraud at the financial statement
level and at the assertion level.
Further, ISA 240 para. 45 requires that the following is included in the audit documentation of
the auditor’s responses to the assessed risks of material misstatement, as required by ISA 330:
(a) The overall responses to the assessed risks of material misstatement due to fraud at the financial
statement level and the nature, timing and extent of audit procedures, and the linkage of those
procedures with the assessed risks of material misstatement due to fraud at the assertion level; and
(b) The results of the audit procedures, including those designed to address the risk of management
override of controls.
The auditor is also required to include in the audit documentation communications about fraud
made to management, those charged with governance, regulators and others (ISA 240 para. 46).
Required reading
ISA 240 paras 12–14, 40–42, 44–46, A7–A9 and A60–A64.
ISA 260 para. A38.
CC
Learning outcome
5. Identify and assess fraud risk factors arising from related party relationships and transactions.
As mentioned earlier, as part of the planning process, the auditor needs to assess fraud risk
factors arising from related party relationships and transactions.
Related party relationships involve control or significant influence by one party over another.
As related party relationships may present a greater opportunity for collusion, concealment or
manipulation by management, their existence increases the opportunity for fraud and errors.
There is an inherent limitation on the auditor’s ability to detect other undisclosed, related
party transactions because management may be unaware of the existence of all related party
relationships and transactions. Therefore, professional scepticism is particularly important
(ISA 550 Related Party Disclosures (ISA 24) paras 6–7).
A person (or close family member) who has control of the reporting entity
A person (or close family member) who has joint control of the reporting entity
A person (or close family member) who has significant influence over the reporting entity
Key managers of the reporting entity
Key managers of the parent entity
DO EXIST
Parent entities
Subsidiaries
Fellow subsidiaries
CC
Overly complex •• Related parties may operate through an extensive and complex range of
transactions relationships and structures
Relationships and •• Related party relationships may be concealed, as they present a greater
transactions not identified opportunity for collusion, concealment or manipulation by management
•• The entity’s information systems may be ineffective at identifying or
summarising transactions and outstanding balances between the entity and its
related parties
•• Management may be unaware of the existence of all related party relationships
and transactions
Transactions not •• Related party transactions may not be conducted under normal market terms
conducted in the normal and conditions, such as above or below fair values or even with no exchange of
course of business consideration at all
CC
Required reading
ISA 550 paras 2–22 and A9.
ISA 240 paras A5, A48 and Appendix 1.
IAS 24 paras 9–10 and 13–24.
Quiz
[Available online in myLearning]
Readings
Required reading
ISA 200 Overall Objectives of the ASA 200 Overall Objectives of ISA (NZ) 200 Overall Objectives of
Independent Auditor and the the Independent Auditor and the the Independent Auditor and the
Conduct of an Audit in Accordance Conduct of an Audit in Accordance Conduct of an Audit in Accordance
with International Standards on with Australian Auditing with International Standards on
Auditing Standards Auditing (New Zealand)
•• Paragraphs 11(a) and A35 •• Paragraphs 11(a) and A35 •• Paragraphs 11(a) and A35)
ISA 240 The Auditor’s ASA 240 The Auditor’s ISA (NZ) 240 The Auditor’s
Responsibilities Relating to Responsibilities Relating to Fraud Responsibilities Relating to
Fraud in an Audit of Financial in an Audit of a Financial Report Fraud in an Audit of Financial
Statements Statements
•• Paragraphs 2–47, A1–A66, •• Paragraphs 2–47, A1–A66, •• Paragraphs 2–47, A1–A66,
Appendices 1, 2 and 3 Appendices 1, 2 and 3 Appendices 1, 2 and 3
ISA 260 Communication with ASA 260 Communication with ISA (NZ) 260 Communication with
Those Charged with Governance Those Charged with Governance Those Charged with Governance
•• Paragraph A38 •• Paragraph A38 •• Paragraph A38
ISA 315 (Revised) Identifying ASA 315 Identifying and Assessing ISA (NZ) 315 (Revised) Identifying
and Assessing the Risks of the Risks of Material Misstatement and Assessing the Risks of
Material Misstatement through through Understanding the Entity Material Misstatement through
Understanding the Entity and Its and Its Environment Understanding the Entity and Its
Environment Environment
•• Paragraph A124 •• Paragraph A124 •• Paragraph A124
ISA 330 The Auditor’s Responses to ASA 330 The Auditor’s Responses ISA (NZ) 330 The Auditor’s
Assessed Risks to Assessed Risks Responses to Assessed Risks
•• Paragraph 6 •• Paragraph 6 •• Paragraph 6
ISA 520 Analytical Procedures ASA 520 Analytical Procedures ISA (NZ) 520 Analytical
Procedures
•• Paragraph 6 •• Paragraph 6 •• Paragraph 6
ISA 550 Related Parties ASA 550 Related Parties ISA (NZ) 550 Related Parties
•• Paragraphs 2–22 and A9 •• Paragraphs 2–22 and A9 •• Paragraphs 2–22 and A9
ISA 700 Forming an Opinion and ASA 700 Forming an Opinion and ISA (NZ) 700 Forming an Opinion
Reporting on Financial Statements Reporting on a Financial Report and Reporting on Financial
Statements
•• Paragraph 11 •• Paragraph 11 •• Paragraph 11
IAS 24 Related Party Disclosures AASB 124 Related Party NZ IAS 24 Related Party
Disclosures Disclosures
•• Paragraphs 9–10 and 13–24 •• Paragraphs 9–10 and 13–24 •• Paragraphs 9–10 and 13–24
Further reading
References
The following source was referred to in the preparation of content for this unit:
•• IFAC 2011, Guide to using ISAs in the audits of small- and medium-sized entities, 3rd edn, vols 1
and 2 (IFAC Guide).
ACT
Activity 6.1
Identifying fraud risks
Introduction
An auditor conducting an audit in accordance with the applicable Auditing Standards is
responsible for obtaining reasonable assurance that the financial statements taken as a whole
are free from material misstatement, whether caused by fraud or error. This requires the auditor
to firstly identify any fraud risks.
This activity links to learning outcomes:
•• Explain and identify the characteristics of fraud in the context of an audit.
•• Identify and assess the risks of material misstatement in financial statements due to fraud.
•• Identify and assess fraud risk factors arising from related party relationships and
transactions.
At the end of this activity you will be able to identify fraud risk factors relating to an audit of
financial statements, in accordance with ISA 240 The Auditor’s Responsibilities Relating to Fraud in
an Audit of Financial Statements (ISA 240).
It will take you approximately 30 minutes to complete.
Scenario
You are a newly qualified Chartered Accountant working for X&Y Partners Chartered
Accountants (X&Y). You have been assigned to the audit of Zizzling Limited (Zizzling) for the
year ended 30 June 20X3 (FY 20X3) and are in the planning stage of the final audit.
Zizzling is a national fashion retail chain with stores located throughout Australia. The major
shareholders of Zizzling are the Bear siblings, Morgan, Lulu and Amy. The remaining minority
shares are held by independent third parties. Both Amy and Morgan Bear are employees of
Zizzling. Morgan is the chief executive officer (CEO), and is the only Bear sibling on the board.
All of the other board members are independent.
Zizzling specialises in expensive women’s swimwear and summer resort wear. Zizzling designs
its garments in Australia and manufactures them in China from Italian-sourced fabrics. The
only exception is the material for Zizzling’s resort wear, which is purchased at commercial rates
from Cherry Bear, the fourth Bear sibling, through her company Cherry Clothes Pty Ltd (CC).
The details of this arrangement are contained in a note in the financial statements.
Zizzling has been struggling to meet its projected profit forecasts in recent years due to an
influx of both local competitors and foreign imported products, increased competition from
online shopping, the increasingly high local dollar against the US dollar, and constant changes
in consumer trends due to the global financial crisis.
Senior employees are entitled to an annual bonus which can be up to 20% of their base salary
on the achievement of their KPIs. Their bonus entitlement reduces to 5% of their base salary if
profit forecasts are not met.
ACT
You have identified the following matters:
Matter 1
During the interim audit, Zizzling’s chief financial officer (CFO) confided that he suspected
Zizzling was in breach of its bank loan covenants during the course of FY 20X3. This would put
his bonus in jeopardy, as maintaining covenants is one of his KPIs. A refinancing with BigBank
was due to occur on 31 July 20X3. No refinancing documents had been provided by BigBank
as at 30 June 20X3 and Zizzling had not attempted to secure financing from other financial
institutions.
Matter 2
Since X&Y started auditing Zizzling four years ago, Zizzling has been plagued by poor internal
controls over accounts payable operations. In past audits, X&Y has brought this issue to
management’s attention. For example, Jamie Potts, one of the accounts payable clerks, is able
to approve and pay invoices of up to $50,000 per transaction. You have learned he is currently
having trouble paying his mortgage. Despite X&Y drawing these weaknesses to management’s
attention, processes at Zizzling remain unchanged.
Matter 3
Zizzling changed a key supplier of material in January 20X3. A cheaper overseas supplier was
sourced who happened to be an old friend of Lulu Bear’s and was used to save costs. However,
you notice that the number of product returns has significantly increased since March 20X3.
Initial discussions with management confirm the reason for the returns has been customer
complaints over fabric quality. Cost savings have not been as much as expected.
Matter 4
Zizzling owns 80% of its manufacturing operations in China, with the remaining 20% being
owned by a Chinese company, Yi. Morgan Bear’s wife is a clothing designer and has her fashion
line manufactured in Zizzling’s Chinese plant at a reduced rate. To help support his wife’s
business, Morgan has asked for the manufacturing costs incurred by his wife to be written off
as a bad debt. Yi is not aware of this arrangement.
Matter 5
Amy Bear is in charge of purchases, and in October 20X2, she renegotiated Zizzling’s contract
with CC. Amy and CC agreed that Zizzling would pay cash on delivery for all CC materials.
Zizzling’s normal creditor terms are 45-day settlement. No one outside the purchasing
department is aware of the renegotiation.
CC advises Zizzling’s purchasing department of its intended deliveries three days in advance
of any delivery to allow Zizzling time to withdraw cash to settle the deliveries. The value of the
deliveries is material to Zizzling.
ACT
Task
For this activity you are required to identify and explain how each matter is a fraud risk in
relation to the audit of Zizzling.
Present your solution in the following table format:
ACT
Activity 6.2
Assessing fraud risks
Introduction
When conducting an audit in accordance with the applicable Auditing Standards, an auditor is
responsible for obtaining reasonable assurance that the financial statements taken as a whole
are free from material misstatement, whether caused by fraud or error. This requires the auditor
to both identify fraud risks and assess their potential impact.
This activity links to learning outcomes:
•• Identify and assess the risks of material misstatement in financial statements due to fraud.
•• Identify and assess fraud risk factors arising from related party relationships and
transactions.
At the end of this activity you will be able to assess fraud risk factors relating to an audit
of financial statements and recommend internal controls or procedures that could be
implemented, in accordance with ISA 240 The Auditor’s Responsibilities Relating to Fraud in an
Audit of Financial Statements (ISA 240).
It will take you approximately 30 minutes to complete.
Scenario
This activity follows on from Activity 6.1 ‘Identifying fraud risks’.
You are a newly qualified Chartered Accountant working for X&Y Partners Chartered
Accountants (X&Y). You have been assigned to the audit of Zizzling Limited (Zizzling) for the
year ended 30 June 20X3 (FY 20X3) and are in the planning stage of the final audit.
Zizzling is a national fashion retail chain with stores located throughout Australia. The major
shareholders of Zizzling are the Bear siblings, Morgan, Lulu and Amy. The remaining minority
shares are held by independent third parties. Both Amy and Morgan Bear are employees of
Zizzling. Morgan is the chief executive officer (CEO), and is the only Bear sibling on the board.
All of the other board members are independent.
Zizzling specialises in expensive women’s swimwear and summer resort wear. Zizzling designs
its garments in Australia and manufactures them in China from Italian-sourced fabrics. The
only exception is the material for Zizzling’s resort wear, which is purchased at commercial rates
from Cherry Bear, the fourth Bear sibling, through her company Cherry Clothes Pty Ltd (CC).
The details of this arrangement are contained in a note in the financial statements.
Zizzling has been struggling to meet its projected profit forecasts in recent years due to an
influx of both local competitors and foreign imported products, increased competition from
online shopping, the increasingly high local dollar against the US dollar, and constant changes
in consumer trends due to the global financial crisis.
Senior employees are entitled to an annual bonus, which can be up to 20% of their base salary,
on the achievement of their KP1s. Their bonus entitlement reduces to 5% of their base salary if
profit forecasts are not met.
ACT
You have identified the following matters as audit fraud risks:
Matter 1
During the interim audit, Zizzling’s chief financial officer (CFO) confided that he suspected
Zizzling was in breach of its bank loan covenants during the course of FY 20X3. This would put
his bonus in jeopardy, as maintaining covenants is one of his KPIs. A refinancing with BigBank
was due to occur on 31 July 20X3. No refinancing documents had been provided by BigBank
as at 30 June 20X3 and Zizzling had not attempted to secure financing from other financial
institutions.
Fraud risk
The CFO’s bonus is linked to the achievement of KPIs, which themselves are based
on calculations that are within his control to manipulate, including the maintenance of bank
loan covenants.
Matter 2
Since X&Y started auditing Zizzling four years ago, Zizzling has been plagued by poor internal
controls over accounts payable operations. In past audits, X&Y has brought this issue to
management’s attention. For example, Jamie Potts, one of the accounts payable clerks, is able
to approve and pay invoices of up to $50,000 per transaction. You have learned he is currently
having trouble paying his mortgage. Despite X&Y drawing these weaknesses to management’s
attention, processes at Zizzling remain unchanged.
Fraud risk
There is an inadequate separation of duties: an accounts payable clerk is able to both approve
and pay invoices.
Matter 3
Zizzling changed a key supplier of material in January 20X3. A cheaper overseas supplier was
sourced who happened to be an old friend of Lulu Bear’s and was used to save costs. However,
you notice that the number of product returns has significantly increased since March 20X3.
Initial discussions with management confirm the reason for the returns has been customer
complaints over fabric quality. Cost savings have not been as much as expected.
Fraud risk
The use of inferior materials in the production of swimwear and resort wear is based on
realising cost savings and meeting financial performance targets. However, the savings have not
been as much as expected.
Matter 4
Zizzling owns 80% of its manufacturing operations in China, with the remaining 20% being
owned by a Chinese company, Yi. Morgan Bear’s wife is a clothing designer and has her fashion
line manufactured in Zizzling’s Chinese plant at a reduced rate. To help support his wife’s
business, Morgan has asked for the manufacturing costs incurred by his wife to be written off as
a bad debt. Yi is not aware of this arrangement.
Fraud risk
There is a related party transaction that is not conducted under normal market terms and
conditions.
ACT
Matter 5
Amy Bear is in charge of purchases, and in October 20X2, she renegotiated Zizzling’s contract
with CC. Amy and CC agreed that Zizzling would pay cash on delivery for all CC materials.
Zizzling’s normal creditor terms are 45-day settlement. No one outside the purchasing
department is aware of the renegotiation.
CC advises Zizzling’s purchasing department of its intended deliveries three days in advance
of any delivery to allow Zizzling time to withdraw cash to settle the deliveries. The value of the
deliveries is material to Zizzling.
Fraud risk
The non-arm’s length contract between Zizzling and CC. CC is an entity controlled by a family
member of senior Zizzling management.
Zizzling also holds significant amounts of cash on hand to pay cash on delivery for materials.
Task
For this activity you are required to describe internal controls or processes that you would
recommend Zizzling implement in order to minimise the fraud risk identified for each matter.
[Solutions to activities are available online. Please access myLearning to view]
CC
Core content
Unit 7: Materiality in planning and
performing an audit
Learning outcomes
At the end of this unit you will be able to:
1. Define materiality and explain factors that impact its determination.
2. Apply the concept of materiality appropriately in planning an audit and in determining audit
procedures to be performed in an audit.
3. Describe how materiality influences the nature, timing and extent of audit procedures.
4. Explain how revisions to materiality can occur during the course of an audit.
Introduction
In auditing, the concept of materiality recognises that some matters, either individually or in
aggregate, are important to users making economic decisions based on an entity’s financial
statements. This could include decisions that involve investing in, purchasing, doing business
with or lending money to, an entity. When a misstatement or omission of information in the
financial statements is significant enough to change or influence such a decision, a material
misstatement has occurred.
This unit explores how an auditor expresses materiality or materiality levels numerically.
However, materiality when quantified is not black and white; rather, it represents a ‘grey’
area between what is very likely to be material and what is very likely not to be material.
Consequently, the assessment of what is ‘material’ is always a matter of professional judgement.
In practice, it is not realistic for auditors to test, examine or verify every single transaction,
account balance or operational process of an entity to identify all misstatements or omissions.
Applying the concept of materiality appropriately enables the auditor to focus their attention
and effort on the high risk areas of the entity’s financial statements. ISA 320 Materiality in
Planning and Performing an Audit (ISA 320) provides guidance on how auditors should apply the
concept of materiality in planning and performing an audit.
aaa11607_csg
CC
Defining materiality
Learning outcome
1. Define materiality and explain factors that impact its determination.
Misstatements
A misstatement is any difference between the actual amount, classification, presentation or
disclosure of a reported financial statement item and the required amount, classification,
presentation or disclosure in accordance with the applicable financial reporting framework
(ISA 450 Evaluation of Misstatements Identified during the Audit (ISA 450) para. 4(a)).
In some situations, a misstatement with a value that is well below the materiality level set
(based on size) for the financial statements may be determined as material based on the
nature of the item or the circumstances related to its occurrence. For example, information on
transactions with related parties may be very significant to a person making a decision based on
an entity’s financial statements.
CC
The diagram below illustrates how misstatements relate to materiality:
Extent of misstatements
(Quantitative and qualitative)
Financial
Statements
Materiality
threshold
Adapted from: Australian audit manual and toolkit 2015 for small and medium sized entities, Exhibit 5.3-2, p. 87.
Required reading
ISA 320 paras 1–8 and A1.
CC
Learning outcome
2. Apply the concept of materiality appropriately in planning an audit and in determining audit
procedures to be performed in an audit.
An auditor is required to apply the concept of materiality throughout the audit process (ISA 320
para. 5):
•• In planning the audit.
•• In performing the audit.
•• In evaluating the effect of identified misstatements on the audit.
•• In evaluating the effect of uncorrected misstatements on the financial statements and in
forming the audit opinion.
Reporting
Evaluating the effect of
uncorrected misstatements
Forming the opinion in the
auditor’s report
Adapted from: Australian audit manual and toolkit 2015 for small and medium-sized entities, Exhibit 5.0-1, p. 83.
This unit looks at ISA 320, which specifically deals with how an auditor determines and applies
materiality in the first two phases (risk assessment and risk response) of an audit.
During the audit reporting phase at the conclusion of an audit, overall materiality is applied
to evaluate the effect of any identified misstatements on the financial statements and the
appropriateness of the auditor’s opinion, as discussed in the unit on responding to assessed
risks – evaluating audit evidence.
CC
Levels of materiality
As part of planning the audit, an auditor makes judgements about the size of misstatements
that will be considered material (ISA 320 para. 6). This includes establishing various materiality
levels.
ISA 320 describes four materiality levels, which can be broadly categorised as:
•• Overall materiality.
•• Performance materiality.
•• Specific materiality.
•• Specific performance materiality.
Each materiality level is discussed in further detail in this unit. The definitions of the different
materiality levels and the relationships between them are illustrated in the following diagram:
Note: The terms ‘overall materiality’ and ‘specific materiality’ are used here only for the
purpose of this unit. These terms are not used in ISA 320.
CC
Overall materiality
Overall materiality refers to ‘materiality for the financial statements as a whole’ (ISA 320
para. 10). It is the dollar amount that the auditor sets for the financial statements above which
any misstatement (individual or in aggregate) would result in the financial statements being
materially misstated.
The auditor establishes overall materiality based on their understanding of the financial
information needs of the users, as a group, of the financial statements. In doing so, the
auditor assumes that users have a reasonable knowledge of business, economic activities and
accounting, and use reasonable diligence in studying and making reasonable decisions based on
the financial statements (ISA 320 para. 4).
CC
When identifying an appropriate benchmark to use, an auditor would determine who are the
likely users of the financial report and would consider matters such as those outlined in the
following table:
Factors Considerations
Users’ primary Identify what information in the financial statements items is of the most interest to users
focus
For example:
•• Users interested in evaluating financial performance will focus on profits, revenues
or net assets. Profit before tax from continuing operations is commonly used as a
benchmark for profit-focused entities
•• Users interested in the resources utilised to achieve certain goals will focus on the nature
and extent of revenues and expenditures – for example, not-for-profit entities
Relevant elements Identify what major elements of the financial statements will be of interest to users of the
of financial financial statements (e.g. assets, liabilities, equity, income, and expenses)
statements
Nature of the Consider the nature of the entity, where it fits in the life cycle (i.e. whether growing,
entity mature, declining, etc.), and the industry and economic environment in which the entity
operates
Adapted from: Australian audit manual and toolkit 2015 for small and medium-sized entities, Exhibit 21.2-2, pp. 347–8.
Once an appropriate benchmark is identified, relevant financial data is considered. This might
be, for example, prior period financial results, forecasts for the current period or period to
date results. Circumstances might cause an exceptional variation that may lead the auditor
to conclude that they should use a ‘normalised’ benchmark base. For example, income from
continuing operations could be adjusted for:
•• Unusual or non-recurring revenue/expense items.
•• Items such as management bonuses, which may be based on profits before the bonuses or
simply paid out to reduce any income left in the company.
CC
Benchmarks and percentages that are commonly used to determine overall materiality
in practice are included in the table below:
Publicly listed entities Profit before tax from continuing activities 3–10
Required reading
ISA 320 paras 9–11 and A2–A9.
CC
Performance materiality
Performance materiality is established based on overall materiality but set at a lower amount
(ISA 320 para. 9). The auditor uses this lower level of materiality to determine the nature and
extent of audit procedures to be performed. Using this lower level of materiality instead of
overall materiality when determining the nature and extent of audit procedures means that
more audit procedures are performed. This reduces the probability that the total amount of
uncorrected and undetected misstatements exceeds overall materiality, resulting in the financial
statements being materially misstated. It also increases the chance of detecting misstatements, if
they exist.
The table below provides some percentages that are commonly used in practice to calculate
performance materiality:
High 50–60
Medium 65–75
Low 80–90
Note: These percentages are only guidelines. In practice, different audit firms would have
different guidance in their audit manuals.
Required reading
ISA 320 paras 9–11 and A12.
CC
RISK OF MATERIAL
PERFORMANCE
MISSTATEMENT PERFORMANCE MATERIALITY
MATERIALITY RISK OF MATERIAL
MISSTATEMENT
Specific materiality
Specific materiality refers to the ‘materiality of particular classes of transactions, account
balances or disclosures’ as described in ISA 320 para. 9. In some audit engagements, there may
be a need to identify misstatements of amounts that are less than overall materiality that would
affect economic decisions of users of the financial statements. Such misstatements could relate
to sensitive areas, such as particular note disclosures regarding senior executives’ remuneration.
The auditor would consider the existence of specific matters, such as the examples provided in
the following table, which indicate a need to establish a specific materiality level for a particular
class of transactions, account balance or disclosure.
CC
Factors Examples
Laws, regulations, and accounting •• Sensitive financial statements disclosures, such as the
framework requirements remuneration of management and those charged with
governance
•• Related party transactions
•• Non-compliance with loan covenants, contractual agreements,
regulatory provisions and statutory/regulatory reporting
requirements
•• Certain types of expenditure, such as illegal payments or
executives’ expenses
Key industry disclosures •• Reserves and exploration costs for a mining entity
•• Research and development costs for a pharmaceutical entity
This concept of applying professional judgement is not an exact science, and therefore requires
careful consideration of the facts and circumstances in each case.
Required reading
ISA 320 paras 10 and A10–A11.
CC
Worked example 7.2: Specific materiality for classes of transactions, account balances or
disclosures
[Available online in myLearning]
CC
Documenting materiality
As materiality is based on the auditor’s professional judgement, it is important that the auditor
document not only the amounts determined for various levels of materiality, but also the factors
considered in their determination (ISA 320 para. 14).
This will occur:
•• During the planning phase.
•• During the audit if revisions are required to any of the performance levels.
Required reading
ISA 320 para. 14.
CC
Learning outcome
3. Describe how materiality influences the nature, timing and extent of audit procedures.
In planning an audit, the nature, timing and extent of audit procedures designed by the auditor
are based on the entity’s assessed risk of material misstatement. Determining materiality levels
directly impacts on this process, since the overall materiality level quantifies exactly what
classifies as a ‘material misstatement’ for an audit.
The nature, timing and extent of audit procedures are defined in ISA 330 paras A5–A7 as
follows:
•• Nature refers to a procedure’s purpose (i.e. tests of controls or substantive procedures) and
type (i.e. inspection, observation, analytical procedures, etc.).
•• Timing refers to when a procedure is performed, or the period or the date when audit
evidence applies.
•• Extent refers to the quantity of audit procedures to be performed (i.e. a sample size).
Performance materiality directly affects the extent of audit procedures that the auditor will
carry out in an audit. There is an inverse relationship between performance materiality
and the extent of audit procedures that will be performed: the lower the performance
materiality, the more procedures that will be performed, and vice versa.
Required reading
ISA 320 paras 5, 6 and A1.
CC
Learning outcome
4. Explain how revisions to materiality can occur during the course of an audit.
It is important to understand that the overall materiality calculated at the planning stage of an
audit may not necessarily remain unchanged throughout the audit. During the course of the
audit, information may come to light that requires the auditor to revise the original overall
materiality level.
For example, overall materiality might be revised when:
•• A change in circumstances occurred during the audit that would impact on the decisions of
users, such as the sale of a part of the business.
•• There is a change in the auditor’s understanding of the entity and its operations, such as
actual financial results being very different from anticipated results.
Similarly, performance materiality may have to be revised at any time during an audit (without
impacting on overall materiality) to reflect revised risk assessments, audit findings and any new
information obtained. Changes in performance materiality will, in turn, result in the nature,
timing and extent of audit procedures being modified. Further, if overall materiality is revised,
a corresponding change is likely to be required to performance materiality.
Required reading
ISA 320 paras 12, 13 and A13.
Quiz
[Available online in myLearning]
Readings
Required reading
ISA 320 Materiality in Planning and ASA 320 Materiality in Planning and ISA (NZ) 320 Materiality in Planning
Performing an Audit Performing an Audit and Performing an Audit
Further reading
There are no further readings for this unit.
References
Chartered Accountants Australia and New Zealand 2015, Australian audit manual and toolkit 2015
for small and medium sized entities, 5th edn, Thomson Reuters, (Professional) Australia, Exhibit
5.01, p. 83; Exhibit 5.3-2, p. 87; Exhibit 21.2-2, pp. 347–8.
ACT
Activity 7.1
Identifying materiality factors and
benchmarks
Introduction
An auditor is engaged to provide only reasonable or limited assurance, not absolute assurance.
Materiality assists in planning and performing audit work, and in assessing the impact of
identified misstatements in the financial statements.
In setting levels of materiality for an audit, the auditor applies professional judgement, taking
into account their knowledge of the entity and its environment, the needs of users of the
financial statements and the assessed risks.
This activity links to learning outcomes:
• Define materiality and explain factors that impact its determination.
• Apply the concept of materiality appropriately in planning an audit and in determining
audit procedures to be performed in an audit.
At the end of this activity, you will be able, in accordance with ISA 320 Materiality in Planning
and Performing an Audit (ISA 320), to:
• Select an appropriate benchmark to use when determining overall materiality in planning
an audit.
•• Identify qualitative or quantitative factors from information about an entity and its
environment that should be considered when determining performance materiality during
planning of an audit.
•• Assess the impact of each qualitative or quantitative factor on the risk of material
misstatement.
Scenario
Hammer and Nail (HN) is a listed entity operating in the hardware store industry, with a
network of large warehouse stores and trade centres. HN caters to both the general public and
commercial customers. Assurance Advantage Chartered Accountants (AA) is HN’s auditor.
AA’s years of experience with HN have shown that its forecasts are generally reliable.
ACT
1. How it began
Terry Carpenter, a former builder, started HN as a family partnership in 19W6 with his three
brothers. The brothers began by converting a warehouse into a showroom, and used their
networks to source reliable products. For the first 10 years, the company sold exclusively to
commercial customers. However, in response to increasing requests from home owner-builders
and renovators, the brothers decided to expand the entity’s client base and began selling to the
general public in 19X5.
Forecast Audited
30 June 20X3 30 June 20X2
$’000 $’000
Assets
ACT
Forecast Audited
30 June 20X3 30 June 20X2
$’000 $’000
Liabilities
Equity
ACT
Forecast Audited
30 June 20X3 30 June 20X2
$’000 $’000
Revenue 100,160 96,636
Cost of sales (55,708) (56,186)
Gross profit 44,452 40,450
Other income 1,095 315
Distribution expenses (17,984) (18,012)
Administrative expenses (17,142) (15,269)
Research and development expenses (1,109) (697)
Other expenses (860) (30)
Results from operating activities 8,452 6,757
Finance income 1,161 480
Finance costs (1,707) (1,646)
Net finance costs (546) (1,166)
Share of profit of equity-accounted investees (net of tax) 467 587
Net profit before tax 8,373 6,178
Income tax expense (2,549) (1,861)
Net profit for the period, after tax 5,824 4,317
Other comprehensive income for the period, net of income tax 639 442
ACT
Tasks
You are a senior accountant working at AA. You are planning the audit of HN and have been
asked to assist with the determination of materiality levels for the audit.
For this activity, you are required to:
1. Select an appropriate benchmark to be used for determining the overall materiality in the
planning phase of the audit. Justify your response.
2. Identify three (3) qualitative or quantitative factors that should be considered when
determining performance materiality for the HN audit engagement.
3. For each qualitative or quantitative factor identified above, determine whether it would
increase, decrease or have no effect on the assessed risk of material misstatement. Justify
your answer with reference to the facts of the scenario.
4. For each qualitative or quantitative factor identified above and its subsequent effect on the
assessed risk of material misstatement, outline whether it would increase, decrease or have
no effect on the performance materiality figure you are setting in the planning phase of the
audit.
You may wish to present your answers to Tasks 2 – 4 in the form of a table, as follows:
ACT
Activity 7.2
Revising materiality
Introduction
In planning an audit, the auditor makes judgements about the size of misstatements that will be
considered material. In addition, revision of materiality levels may be necessary if the auditor
becomes aware, as work progresses, of information that would have led to different materiality
levels during audit planning.
This activity links to learning outcomes:
•• Define materiality and explain factors that impact its determination.
•• Explain how revisions to materiality can occur during the course of an audit.
Scenario
This activity follows on from Activity 7.1. It is now August 20X3. You are a senior accountant
working at Assurance Advantage Chartered Accountants (AA), assigned to the Hammer and
Nail (HN) audit engagement. Your manager calculated the following materiality levels using
information gathered during planning, and by applying his professional judgement:
•• Overall materiality at $669,840 (8% of forecast net profit before tax, as of 30 April 20X3).
•• Performance materiality at $535,872 (80% of overall materiality).
During audit planning work, your manager did not deem it necessary to determine specific
materiality for any account balances, classes of transactions or disclosures. Assume that actual
net profit before tax for the 20X3 financial year equals the 30 April 20X3 forecast net profit
before tax.
During the course of the audit, your testing has not uncovered any unusual or unexpected
outcomes, and internal controls appear to be operating effectively. You have, however,
identified three matters resulting from audit procedures and enquiries.
The following three matters have been uncovered as a result of audit procedures and enquiries:
ACT
Tasks
You have been asked to determine whether the materiality levels set during audit planning
for the HN audit need to be revised, as a result of the matters uncovered during audit work
performed in August 20X3.
For this activity, you are required to:
1. Explain the impact (if any) of each matter uncovered on the overall and performance
materiality levels set for the HN audit during planning. Justify your answer.
You may wish to present your answer in the form of a table:
2. As a result of the three matters uncovered during audit work performed, determine
whether the auditor should establish specific materiality levels for any account balances,
classes of transactions, or disclosures. Explain your answer.
CC
Core content
Unit 8: Developing an overall audit plan
Learning outcomes
At the end of this unit you will be able to:
1. Outline the auditor’s responsibilities with respect to documenting the overall audit plan.
2. Explain how to develop an overall audit plan to ensure an effective and efficient audit.
3. Assess how the nature, timing and extent of tests of controls and substantive procedures
are impacted by factors discovered in the audit planning process.
Introduction
Audit planning is important as it ensures that the audit engagement is performed in an efficient
and effective manner and that audit risk has been reduced to an acceptably low level. A well-
planned audit ensures that:
•• The audit effort is directed to address high-risk areas.
•• Audit procedures performed are relevant in addressing the identified risks.
•• Audit staff is well-informed and knows what is expected of them.
The previous units covered performing risk assessment procedures to identify and assess risks
of material misstatement (RMM) at both the financial statement level and the assertion level.
This unit focuses on examining how the auditor uses this information in developing an audit
strategy and an audit plan.
This unit focuses on the auditor’s requirements under the following International Standards on
Auditing (ISAs):
•• ISA 300 Planning an Audit of Financial Statements (ISA 300).
•• ISA 315 (Revised) Identifying and Assessing the Risks of Material Misstatement through
Understanding the Entity and Its Environment (ISA 315 (Revised)).
•• ISA 320 Materiality in Planning and Performing an Audit (ISA 320).
•• ISA 330 The Auditor’s Responses to Assessed Risks (ISA 330).
•• ISA 500 Audit Evidence (ISA 500).
•• ISA 520 Analytical Procedures (ISA 520).
aaa11608_csg
CC
Learning outcome
1. Outline the auditor’s responsibilities with respect to documenting the overall audit plan.
As a result of pre-engagement activities and audit planning and risk assessment procedures the
auditor establishes an overall audit strategy and develops an audit plan that is tailored to the
entity and to the audit engagement.
(b) Ascertain the reporting objectives of the engagement to plan the timing of the audit and the nature
of the communications required;
(c) Consider the factors that, in the auditor’s professional judgment, are significant in directing the
engagement team’s efforts;
(d) Consider the results of preliminary engagement activities and, where applicable, whether
knowledge gained on other engagements performed by the engagement partner for the entity is
relevant; and
(e) Ascertain the nature, timing and extent of resources necessary to perform the engagement.
Audit plan
The audit plan is a record of all the audit procedures the auditor intends to perform in order to
obtain sufficient appropriate audit evidence in an audit engagement.
It is developed based on the overall audit strategy, and includes a description of (ISA 300
para. 9):
•• The nature, timing and extent of planned risk assessment procedures.
•• The nature, timing and extent of planned further audit procedures.
•• Other planned audit procedures that are required to be carried out so that the engagement
complies with the relevant ISAs.
Required reading
ISA 300 paras 7–9, A12 and A16–A17.
CC
It is therefore essential for the auditor to plan the audit so that it will be performed in an
effective manner.
Required reading
ISA 300 paras 1–6, 11–13, A5–A7 and A19–A20.
CC
Learning outcome
2. Explain how to develop an overall audit plan to ensure an effective and efficient audit.
This section discusses how the auditor uses the information gathered in the planning phase
of an audit to establish the overall audit strategy and develop the audit plan, which includes
the overall responses and further audit procedures. Using the example of an audit planning
document of a fictitious audit engagement, the section also shows how an auditor documents
these procedures.
The relationship of the planning and risk assessment activities and the documentation of the
audit strategy and audit plan can be shown diagrammatically, as follows:
COVERED IN
DETAIL IN Performing risk assessment procedures
PREVIOUS
UNITS AND • Obtain an understanding of the entity and its environment
REVISITED IN • Obtain an understanding of the entity’s internal controls
THIS UNIT • Determine materiality levels for the audit engagement
• Perform preliminary analytical procedures
• Assess the RMM
Document overall
audit strategy and
audit plan
COVERED IN
THIS UNIT
Developing overall
Determining further
responses
procedures
(financial statement
(assertion level)
level)
The planning and risk assessment activities were discussed in detail in earlier units of the
Audit & Assurance (AAA) module. This unit summarises these activities and, using an overall
example of an audit planning document (in Examples 1–10 below), explains how they are
documented and link to the development of overall responses and further audit procedures.
CC
Industry The furniture industry is currently experiencing challenging times due to:
information
•• Declining economy as a result of the recession
•• Increased competition from overseas manufacturers selling at lower prices
•• Some furniture retailers, including a few of FF’s customers, are going out of
business
Ownership
FF is owned by the Smith family. The shareholding structure is as follows:
•• Sam Smith, the founder, owns 50% of the shares. Sam retired two years ago
•• Mark Smith, the managing director and Sam’s son, owns 10% of the shares
•• Daniel Smith, the head of production and another son of Sam, owns 10% of the
shares
•• 10 other independent persons own 30% of the shares
CC
Showroom 10%
Internet 15%
SALES
Custom-made 15%
Retailers 60%
Organisational chart
Mark Smith
Managing director
Measurement and FF uses revenue and profit before tax as its main indicators and benchmarks for
review of financial measuring performance
performance
FF conducts monthly financial reviews
CC
CC
Overall conclusion: The entity-level controls at FF are effective and can be relied on to reduce
the RMM at the financial statement level
Principal users of financial Factors that would influence the user’s decision‑making
statements
Bank Profitability, compliance with bank covenants and cash flows to repay
loans
Based on the guidance in AA’s audit manual, and on an assessment of the needs of the likely
users of the financial statements, materiality for planning purposes has been set as follows:
•• Overall materiality – 5% of profit before tax = $125,000.
•• Performance materiality – 75% of overall materiality = $93,750.
CC
Accounts Not Some retailers are going out of business due to the industry
receivable reasonable downturn. The recoverability of accounts receivable could be in
increased 12% doubt
CC
IR × CR × DR = AR
In order to assess both the inherent and control risks, the auditor consolidates all the
information obtained throughout the risk assessment procedures performed – that is, obtaining
an understanding of the entity and its environment, obtaining an understanding of the entity’s
internal controls and performing preliminary analytical procedures.
The following risk factors have been identified at FM appears to have a strong Low
the financial statement level: internal control environment
and effective entity-wide
•• Declining economy as a result of the worldwide
controls
recession
•• Increased competition from overseas Refer to ‘Assessing internal
manufacturers selling at lower prices controls relevant to the audit’
section
•• Some furniture retailers, including a few of FF’s
customers, are going out of business
Refer to ‘Identifying risks through understanding
the entity’ section
CC
The auditor also needs to assess the RMM at the assertion level in order to design appropriate
audit procedures. Assessing the RMM at the assertion level was discussed in the unit on
analysing audit risks, financial statement assertions and initial audit engagements.
CC
CC
Significant factors •• Materiality (overall, individual financial statement areas and performance
materiality)
•• Preliminary assessment of risk at the overall financial statement level and
the impact on the audit
•• Preliminary identification of:
–– Significant and material classes of transactions, account balances at
period end and disclosures
–– Areas where there may be a higher risk of material misstatement
•• How engagement team members are reminded to maintain a questioning
mind and to exercise professional scepticism in gathering and evaluating
audit evidence
•• Relevant results of previous audits, including identified control deficiencies
and action taken by management to address them
•• Discussions with personnel who provided other services to the entity
•• Evidence of management’s attitude towards internal controls and the
importance attached to internal controls generally throughout the entity
•• Volume of transactions, which may determine whether it is more efficient
for the auditor to rely on internal controls
Result of preliminary •• Significant business developments affecting the entity, including changes
engagement activities and in information technology and business processes, changes in key
knowledge gained on other management personnel, and acquisitions and mergers
engagements •• Significant industry developments, such as changes in industry regulations
and new reporting requirements
•• Significant changes in the financial reporting framework, such as changes
in Accounting Standards
•• Other significant relevant developments, such as changes in the legal
environment affecting the entity (e.g. the introduction of a new tax)
Nature, timing and extent of •• The selection of the engagement team (including, where necessary, the
resources necessary engagement quality control reviewer)
•• The assignment of audit work (assign appropriately experienced team
members to areas where the RMM is perceived to be higher)
•• Engagement budgeting, including considering the appropriate amount of
time set aside for areas of higher risk of material misstatement
Adapted from: IFAC Guide, vol. 2, Exhibit 5.2-2, pp. 48 and 49.
The following example illustrates how the auditor uses the individual planning risk assessment
activities and pulls them together to establish the overall audit strategy.
CC
CC
Required reading
ISA 300 paras 7–8, A1, A3–A4, A8–A11, A16 and Appendix.
Example 8 – Determining overall responses to the assessed RMM at the financial statement level
This example follows on from Examples 1–7 and illustrates how the auditor determines audit
procedures to address the assessed RMM at the financial statement level.
Now that Jenny has determined the RMM at the financial statement level, she proceeds to
document her overall responses to address these risks. ‘Overall response’ refers to procedures
that address the broader design and management of the entire audit engagement (as distinct
from further audit procedures, which relate to specific assertions). She documents her findings
in the ‘Overall responses’ section of AA’s audit planning document:
Overall responses
Key factors in The following risk factors have been identified at the financial statement level:
assessing risk
•• Declining economy as a result of the worldwide recession
•• Increased competition from overseas manufacturers selling at lower prices
•• Some furniture retailers, including a few of FF’s customers, are going out of
business
FM appears to have a strong internal control environment and effective entity-wide
controls. RMM at the financial statement level has been assessed as low
Controls over Minimal anti-fraud controls. However, all non-routine journal entries have to be
fraud approved (by signature) and supported by appropriate documentation
CC
Addressing fraud The audit team has been reminded to remain alert for instances of management
override of controls or manipulation, specifically the use of related parties and when
reviewing the reasonableness of estimates and assumptions used (e.g. provision for
doubtful debts). The audit team will also use CAATs to perform journal entry testing.
Composition of The majority of the audit team has worked on last year’s engagement, and is familiar
audit team with the industry and FF’s operations
Given the team’s experience and the nature of the identified fraud risks, no
specialists are required in the audit
The audit team has been briefed on the potential impact of related parties and the
need for professional scepticism at the planning meeting
When responding to risks by designing further audit procedures, the auditor needs to
determine the audit approach – that is, whether to perform tests of control together with
substantive procedures, or substantive procedures alone.
Nature, timing and extent of audit procedures
To ensure sufficient appropriate audit evidence is obtained, the auditor needs to consider the
nature, timing and extent of audit procedures. ISA 330 paras A5–A7 state that:
A5. The nature of an audit procedure refers to its purpose (that is, test of controls or substantive
procedure) and its type (that is, inspection, observation, inquiry, confirmation, recalculation,
reperformance, or analytical procedure). The nature of the audit procedures is of most importance
in responding to the assessed risks.
A6. Timing of an audit procedure refers to when it is performed, or the period or date to which the
audit evidence applies.
A7. Extent of an audit procedure refers to the quantity to be performed, for example, a sample size or
the number of observations of a control activity.
Required reading
ISA 330 paras 5-7, A4–A15 and A19.
CC
There are two main types of audit procedures that auditors use to obtain audit evidence – tests
of controls and substantive procedures. These are illustrated in the following diagram:
Audit procedures
Substantive analytical
Tests of details
procedures
A brief summary of the types of audit procedures and guidance on when to use them is
provided below:
CC
Required reading
ISA 330 paras 4–12, 18 and 20–23.
ISA 520 paras 4–5, A4, A6, A12–A13 and A16.
The following example illustrates the difference between a test of controls and a substantive test
of details:
Purchases Accuracy Select a sample of purchase transactions during the Test of details
financial year in the general ledger, and agree the
amounts of purchases to suppliers’ invoices
This test of details is providing evidence that amounts
recorded in the financial statements are appropriate
CC
CC
Cut-off H •• Select a sample of invoices from the sales ledger and determine
that the invoice was agreed to the customer order and shipping
document by the person approving the invoice. Test some
samples at interim and the remaining samples at year end
Substantive proceedures to be performed at year end
•• Select a sample of sales invoices before and after year end and
agree to related delivery note, ensuring sale was recorded in the
correct period
CC
In addition to performing procedures focused on the account balance and class of transaction
assertions, the auditor must evaluate whether the overall presentation of the financial
statements is in accordance with the reporting framework (ISA 330 para. 24).
Required reading
ISA 330 paras 18, 21, 24, A42–A44 and A53.
Sufficient appropriate audit evidence is further discussed in the unit on responding to assessed
risks – evaluating audit evidence.
Required reading
ISA 500 paras 4–9, A1–A10, A27 and A31.
CC
Learning outcome
3. Assess how the nature, timing and extent of tests of controls and substantive procedures are
impacted by factors discovered in the audit planning process.
ISA 300 para. 10 requires the auditor to ‘update and change the overall audit strategy and the
audit plan as necessary during the course of the audit’. This section discusses how additional
information obtained during the audit process impacts the overall audit strategy and audit plan.
Examples – Matters that would cause the auditor to reassess risks during an audit
The number of errors The auditor may then determine that the controls cannot be relied on and
when testing controls therefore:
may be higher than
•• Increase the assessment of control risk
expected
•• Plan additional substantive audit procedures
CC
Impact of new information on the overall audit strategy and audit plan
On reassessing the RMM at the financial statement and assertion levels, the auditor needs to
determine whether audit procedures determined in the audit plan require amendment; that
is, determine the impact of the new information on the nature, timing and extent of tests of
control and substantive procedures. These would depend on the circumstances in each instance,
including the auditor’s knowledge of other risks relating to the entity being audited. The
auditor could extend audit procedures that have already been planned, if these are suitable, or
might plan different, additional procedures to specifically address the risk.
The following example illustrates how the audit plan may be impacted as a result of new
information obtained during the audit process.
The important point to note is that the auditor must reassess the RMM when appropriate
during the audit, and amend the audit planning and audit responses accordingly.
Required reading
ISA 315 paras 4(b), 30–31, A30, A32, A37, A38, A118–A121, A127–A128, A140–A143 and
Appendix 2.
CC
From her understanding of the business, Jenny notes that this loan is crucial to FF’s ability to
continue its operations, and that FF does not have sufficient cash flow to repay the bank loan
as at 30 June 20X3 in the event that the bank were to call the loan. She also notes that ‘cash and
cash equivalents’ has been assessed as having a low RMM in AA’s audit planning document.
Impact on the assessed RMM at the financial statement level
The fact that FF would not be able to continue business in the event the bank calls the loan
and that it does not have the cash flow to repay the bank loan indicate going concern risks. This
impacts the RMM at the financial statement level, which has been reassessed as high.
Impact on the assessed RMM at the assertion level
In order to comply with the new covenant requirement, FF needs to have at least the same
amount of cash and cash equivalents as its current liabilities at the end of each month.
Management could manipulate its operating cash flow figure by reclassifying amounts that
don’t meet the definition of cash as ‘cash’ – for example, by claiming amounts that it does
not have control over (such as trust accounts) as its own. Alternatively, management could
understate current liabilities by not accounting for them at month end.
This increases the inherent risk of ‘cash and cash equivalents’ and current liabilities as there is
pressure from management to meet the increased covenant requirements. Jenny has revised
the RMM of ‘cash and cash equivalents’ and current liabilities as follows:
RMM at the assertion level
Ratings: High (H), Moderate (M), Low (L).
Completeness L L L
Valuation and H H H
allocation
Completeness H H H
Valuation and M M M
allocation
Note: Only the amended section of the ‘Overall audit strategy’ has been included in this example.
Jenny now needs to design appropriate audit procedures to address the new RMM assessment.
She updates the ‘Overall audit strategy’ section of AA’s audit planning document (shown in
underline) to reflect the changes in the RMM at the financial statement level:
CC
Jenny then updates the ‘Further audit procedures’ section of AA’s audit planning document to
reflect the changes in the RMM at the assertion level.
The audit team needs to assess management’s use of the going concern assumption, including
consideration of any mitigating factors, and to evaluate whether there is significant doubt
about FF’s ability to continue as a going concern
Completeness H
Valuation and M
allocation
CC
Required reading
ISA 300 paras 10, 12, A2, A13 and A18.
Worked example 8.1: Evaluating the impact on the audit plan of information obtained
during audit planning
[Available online in myLearning]
Worked example 8.2: Developing the audit plan for accounts receivable
[Available online in myLearning]
Quiz
[Available online in myLearning]
Readings
Required reading
ISA 300 Planning an Audit of ASA 300 Planning an Audit of a ISA (NZ) 300 Planning an Audit of
Financial Statements Financial Report Financial Statements
ISA 315 (Revised) Identifying ASA 315 Identifying and Assessing ISA (NZ) 315 (Revised) Identifying
and Assessing the Risks of the Risks of Material Misstatement and Assessing the Risks of
Material Misstatement through through Understanding the Entity Material Misstatement through
Understanding the Entity and Its and Its Environment Understanding the Entity and Its
Environment Environment
•• Paragraphs 11, 32, A58 and •• Paragraphs 11, 32, A58 and •• Paragraphs 11, 32, A58 and
A144–A147 A144–A147 A144–A147
ISA 320 Materiality in Planning ASA 320 Materiality in Planning ISA (NZ) 320 Materiality in
and Performing an Audit and Performing an Audit Planning and Performing an Audit
•• Paragraphs 10–11 •• Paragraphs 10–11 •• Paragraphs 10–11
ISA 330 The Auditor’s Responses to ASA 330 The Auditor’s Responses ISA (NZ) 330 The Auditor’s
Assessed Risks to Assessed Risks Responses to Assessed Risks
•• Paragraphs 4–12, 18, 20–24, •• Paragraphs 4–12, 18, 20–24, •• Paragraphs 4–12, 18, 20–24,
A1–A15, A19, A42–A44 and A1–A15, A19, A42–A44 and A1–A15, A19, A42–A44 and
A53 A53 A53
ISA 500 Audit Evidence ASA 500 Audit Evidence ISA (NZ) 500 Audit Evidence
•• Paragraphs 4–9, A1–A10, A27 •• Paragraphs 4–9, A1–A10, A27 •• Paragraphs 4–9, A1–A10, A27
and A31 and A31 and A31
ISA 520 Analytical Procedures ASA 520 Analytical Procedures ISA (NZ) 520 Analytical
Procedures
•• Paragraphs 4–5, A1–A2, A4, •• Paragraphs 4–5, A1–A2, A4, •• Paragraphs 4–5, A1–A2, A4,
A6, A12–A13 and A16 A6, A12–A13 and A16 A6, A12–A13 and A16
Further reading
There are no further readings for this unit.
References
Ideas for this unit were sourced from the following reference:
•• IFAC 2011, Guide to using ISAs in the audits of small- and medium-sized entities, 3rd edn,
vols 1 and 2 (IFAC Guide), Exhibit 5.2-2 on pp. 48 and 49.
ACT
Activity 8.1
Outlining the nature and timing of audit
procedures
Introduction
During the audit planning process, the auditor must identify and assess risks of material
misstatement and their potential impact on the financial statements. The information obtained
during this risk assessment is used to establish an overall audit strategy and develop an audit
plan.
This activity links to learning outcomes:
•• Explain how to develop an overall audit plan to ensure an effective and efficient audit.
•• Assess how the nature, timing and extent of tests of controls and substantive procedures are
impacted by factors discovered in the audit planning process.
At the end of this activity, you will be able to design appropriate audit procedures, in
accordance with:
•• ISA 200 Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance
with International Standards on Auditing (ISA 200).
•• ISA 300 Planning an Audit of Financial Statements (ISA 300).
•• ISA 315 (Revised) Identifying and Assessing the Risks of Material Misstatement through
Understanding the Entity and Its Environment (ISA 315 (Revised)).
•• ISA 330 The Auditor’s Responses to Assessed Risks (ISA 330).
Scenario
You are a senior auditor at Crank & Turn Chartered Accountants (CT). One of CT’s major clients
is Triple Y, a wholesaler of electronic consumer goods and a listed company.
Triple Y has a financial year end of 31 December. All procedures regarding ethics and auditor
independence for the 31 December 20X3 audit were completed in September 20X3, and an
engagement letter has been issued and signed by all parties.
It is now October 20X3, and the audit manager has already established the overall audit
strategy. You are performing the interim audit, including audit planning activities, at Triple Y’s
office.
During the visit, you obtain the following information:
•• Triple Y performs regular cyclical inventory stocktakes. You attend one of these stocktakes
and, during your inspection of the warehouse, note that Triple Y’s inventory includes a large
number of notebook computers from a well-known brand. Having recently purchased the
same notebook, you are aware that the model held by Triple Y was superseded by a more
recent model some time ago.
•• When you raise this issue with management, you are informed that there are no controls in
place to identify superseded models or their impact on potential sales values.
ACT
•• Triple Y uses a high number of casual employees in the warehouse and for administration,
particularly during peak seasonal periods. Demand for casual staff varies considerably and
can be unpredictable. Casual staff are paid on an hourly basis.
•• Controls over payroll in general are reasonably strong. In addition, you have identified
specific weekly controls over the authorisation of casual employees’ hours worked.
CT’s audit manual provides guidance on sample sizes for tests of controls:
Daily 40
Weekly 10
Monthly 2–4
Quarterly 2
Yearly 1
Task
For this activity, for both inventory and payroll expenses, you are required to:
•• Identify the key assertion at risk.
•• Assess the risk of material misstatement.
•• Outline the nature and timing of audit procedures to obtain sufficient appropriate audit
evidence.
•• Outline the extent of any tests of controls.
You are not required to determine the extent of any substantive procedures, as appropriate
sample sizes can only be finalised at year end.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 8.2
Updating the audit strategy and audit plan
Introduction
Audit planning is a continual and iterative process. As an audit progresses, additional
information may come to light that impacts on the nature, timing and extent of the audit
procedures. The auditor has a responsibility to update and change the overall audit strategy
and the audit plan as necessary throughout the course of the audit.
This activity links to learning outcome:
•• Assess how the nature, timing and extent of tests of controls and substantive procedures are
impacted by factors discovered in the audit planning process.
At the end of this activity, you will be able to design appropriate audit procedures in response
to additional information obtained during the audit process, in accordance with:
•• ISA 200 Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance
with International Standards on Auditing (ISA 200).
•• ISA 300 Planning an Audit of Financial Statements (ISA 300).
•• ISA 315 (Revised) Identifying and Assessing the Risks of Material Misstatement through
Understanding the Entity and Its Environment (ISA 315 (Revised)).
•• ISA 330 The Auditor’s Responses to Assessed Risks (ISA 330).
•• ISA 500 Audit Evidence (ISA 500).
Scenario
You are a senior auditor at AAA Chartered Accountants (AAA), an Australian professional
accounting firm that has affiliate offices in every major country around the world. One
of AAA’s major clients is Pretty Clothing (PC), an Australian company that specialises in
manufacturing and distributing general apparel.
PC has a financial year end of 31 December. All procedures regarding ethics and auditor
independence for the 31 December 20X3 audit were completed in September 20X3, and an
engagement letter has been issued and signed by all parties.
It is now October 20X3, and you are performing the interim audit at PC’s office in accordance
with the initial overall audit strategy and the audit plan developed by the audit manager.
While performing your preliminary analytical procedures, you noted that the property, plant
and equipment (PPE) balance as at 30 September 20X3 was $2 million, which is an increase
of $500,000 (rounded) compared to the PPE balance at 31 December 20X2. When you query
PC’s financial controller, Frank, about the significant increase in PPE, he informs you that
PC purchased land in rural China on 30 July 20X3, with a view to building a factory that
will manufacture goods at a cheaper cost. He also mentions that PC has not yet commenced
construction of the factory. It only intends to begin construction in two years’ time, as it
currently does not have the required cash flow for the construction.
When you ask for evidence of the acquisition of the land in China, Frank shows you a document
written in Chinese, which neither you nor any of the audit team members can understand.
Frank tells you that this is the only evidence PC has of the acquisition of the land. He also
ACT
adds that the purchase was settled in American dollars (USD) for an amount equivalent to
$500,000 Australian dollars (AUD). The purchase price is the value that PC intends to recognise
in the 31 December 20X3 financial statements, as its management believes this price is a
good indication of the land’s fair value. In future years, on the completion of the factory’s
construction, PC will engage a property valuer to obtain independent valuations of the land and
factory.
In a recent newspaper article, you also noted that the Chinese Government has tightened its
monetary policy, which has adversely impacted on the property market in China.
You review the risk of material misstatement (RMM) assessment and planned audit procedures
for PPE, as well as the overall audit strategy that was completed by the audit manager prior to
AAA finding out about PC’s acquisition of the land. The relevant extracts of the audit planning
document are tabled as follows:
Reporting objectives As discussed with Frank, the board of directors wants to Engagement
finalise the financial statements on 20 March 20X4. AAA’s letter
audit team should aim to complete all audit work by
10 March 20X4
The following needs to be discussed at the team planning
meeting to be held on 25 October 20X3:
•• Organising audit staff to attend the year-end inventory
counts
Nature, timing and •• Aim to use the same audit staff as per the prior year
extent of resources audit
necessary •• Audit team will commence TOCs and some substantive
testing procedures in the October 20X3 interim audit
ACT
ACT
Task
For this activity, you are required to update the audit strategy and the audit plan. Outline the
required update to the overall audit strategy, RMM at the assertion level, and the nature and
timing of additional audit procedures to obtain sufficient appropriate audit evidence relating to
PC’s PPE.
[Solutions to activities are available online. Please access myLearning to view]
CC
Core content
Unit 9: Responding to assessed risks –
controls testing
Learning outcomes
At the end of this unit you will be able to:
1. Design, perform and evaluate the results of controls testing.
2. Design, implement and evaluate tests of controls, using computer-assisted audit
techniques (CAATs).
3. Apply audit sampling during controls testing in order to provide a reasonable basis for the
auditor to draw conclusions.
4. Explain the importance of evaluating controls and continually evaluating the results of
testing work throughout an audit.
Introduction
Understanding an entity’s internal controls allows the auditor to assess where material
misstatements are likely to occur. This makes consideration of controls an important part of the
audit, and forms part of the risk assessment phase. The unit on understanding the entity and its
environment discussed an entity’s system of internal controls and its importance to the auditor.
In the risk response phase, the auditor performs audit procedures to provide reasonable
assurance that the financial statements are not materially misstated. These procedures include
tests of control and substantive tests. This unit considers tests of controls.
aaa11609_csg
CC
The following diagram illustrates the steps in the risk assessment process and how the auditor
designs procedures to respond to the identified risks (and includes the relevant International
Standards on Auditing (ISAs) that cover the two phases):
CC
Controls testing
Learning outcome
1. Design, perform and evaluate the results of controls testing.
2. Design, implement and evaluate tests of controls, using computer-assisted audit techniques
(CAATs).
Controls
Correct errors
Examples – Controls
The following examples illustrate controls that either detect and correct or prevent errors:
•• A bank reconciliation is performed monthly and checked and approved by a manager
(detect and correct).
•• All purchase orders of $10,000 or more must be approved by two senior managers
(prevent).
•• The computer system restricts access to the general ledger journals function to specific
staff members (prevent).
Types of controls
As discussed in the unit on understanding the entity and its environment, controls can operate
on an entity-wide level or they can be specific to a particular process where they relate to
the initiation, processing or recording of a particular transaction. The focus of this unit is on
the transactional controls. These controls can be manual or automated. The different types of
controls are often interrelated. That is:
•• Manual controls often rely on automated controls – for example, a review of payroll
exception reports is reliant on automated controls (both general and application controls) to
process payroll data and generate the exception reports.
CC
•• IT application controls (ITACs) rely on general IT controls (GITCs) – for example, if GITCs
fail to prevent unauthorised programming changes, the application controls could be
changed or disabled.
Manual controls
Manual controls operate over the manual elements of the accounting system. Manual controls
may be independent of IT, use information produced by IT, or be limited to monitoring the
effective functioning of IT and automated controls. Manual controls often involve handling
exceptions.
Examples of manual controls include:
•• A signature providing evidence of the authorisation of purchase orders.
•• Review of payroll exception reports.
•• Preparation of monthly bank reconciliations.
System access System permissions are Only authorised payroll staff have access to the
controls configured to prevent payroll system. Only the payroll manager has the
unauthorised access to ability to change pay rates
data or a particular system
Assigning different staff members the ability to
authorise and process transactions (segregation of
duties)
Exception reports Reports are automatically Reports showing rejected sales transactions
generated to show
Reports showing unbalanced journal entries
transactions that fall
outside a set of parameters Note: Follow up of an exception report is a manual
control that relies on an automated control (the
report)
Interface/conversion Ensure transactions are Sales information is transferred daily from electronic
controls transferred from one point of sale (EPOS) to financial accounting
system to another timely application
and accurately
System Include input, edit and Pre-set unit sales prices are automatically applied to
configuration validation controls sales invoices
controls
Only valid customer references can be entered
when creating sales invoices
Automated three-way match control for purchases
that includes automated comparison of the supplier
invoice, purchase order and goods received note
Required reading
ISA 315 (Revised) paras A105 and A124.
CC
Walk-through tests
ISA 315 (Revised) para. A74 recommends that the following procedures be performed to assess
the design and implementation of controls:
•• Make enquiries of entity personnel (note, however, that enquiry alone is not sufficient).
•• Observe or reperform the application of specific controls.
•• Inspect documents and reports.
•• Trace one or two transactions through the information system that is relevant to financial
reporting.
Together, the above procedures are often referred to as a ‘walk-through test’, as the auditor
follows, step by step, the design and operation of a control.
The walk-through test determines that a control:
•• Is effective in the prevention, or detection and correction, of material misstatements.
•• Has been implemented at a given point in time.
Required reading
ISA 315 (Revised) paras 12−13 and A74.
CC
Indirect controls
Before testing controls, the auditor must consider whether the controls to be tested are
dependent on the effective operation of other controls − that is, indirect controls. If so, it
may be necessary to obtain evidence of the operating effectiveness of those indirect controls.
(e.g. GITCs). GITCs were discussed in the unit on understanding the entity and its environment.
Required reading
ISA 330 paras 10 and A30−A31.
Having effective controls in place that are tested by the auditor will reduce control risk. Lower
control risk means a lower risk of material misstatement and, consequently, a reduction in the
required reliance on substantive procedures.
Required reading
ISA 330 para 8.
Nature of controls
Typically, a test of controls includes the selection of a representative sample of transactions or
supporting documentation to:
•• Observe the operation of an internal control procedure being performed.
•• Inspect evidence that the control procedure was performed.
•• Enquire of relevant personnel about how and when the control procedure was performed.
•• Reperform the control procedure (e.g. within an IT system).
As the types of audit procedures used to obtain an understanding of controls are also used
to test their operating effectiveness, the auditor may decide it is efficient and effective to
test the operating effectiveness of controls at the same time as evaluating their design and
implementation.
Enquiry alone is not sufficient to test the operating effectiveness of controls − the auditor must
perform other procedures in conjunction with enquiry. Enquiry performed together with either
reperformance or inspection provides greater assurance than enquiry together with observation.
This is because observations are only relevant at the point in time at which they occur. Another
reason why observation provides less assurance than reperformance or inspection is because
when a person performing a control activity knows they are being observed, they are less likely
to bypass certain activities or cut corners.
CC
The design of a test of controls is further influenced by the nature of the control being
tested. If the control (e.g. a reconciliation) produces documentary evidence of its operating
effectiveness, the auditor is likely to choose enquiry combined with inspection of the
documentation to gather evidence that supports the effective operation of the control. However,
documentary evidence of a control’s operating effectiveness may not always exist, which can
often be the case with automated controls. In these situations, evidence of a control’s operating
effectiveness may be obtained through a combination of enquiry and observation, or the use of
CAATs. Where controls are automated within an entity’s IT finance application, it is generally
appropriate to run a CAAT to test the operating effectiveness of IT application controls.
For example, if exception reports are automatically generated by the finance application, it may
be appropriate to use a CAAT to reperform transactions that should appear on the exception
report through the finance application (in a test environment using an up-to-date version of the
client’s software).
CAATs can also provide an effective and efficient way to perform tests of controls when the
auditor decides to increase the extent of tests of controls (ISA 330 para. A16).
Examples − Automated controls that do not generally provide documentary evidence of their operation
The following examples illustrate automated controls that do not necessarily produce
documentary evidence of their operation:
•• Authorisation controls whereby the finance application only allows transactions to be
entered or authorised by particular users – for example, where accounts payable/receivable
staff are not able to approve purchase orders.
•• Input controls that are designed to ensure the completeness and accuracy of transactions
being entered – for example, a field sign test that only allows positive numbers to be
entered in a quantity field in a sales order.
•• Validity tests – for example, where the finance system automatically checks that a vendor’s
name entered on a new purchase order also exists in the approved vendor master file.
•• Duplicate tests – for example, when entering a new sales transaction with an existing
customer, the system checks the data file associated with that customer to ensure the
customer’s purchase order number is not already recorded in the customer’s transaction
history.
There are various CAATs that can be performed on an entity’s finance IT application, or the data
contained in that application. The table below identifies typical methods that are used as part of
audit procedures performed using CAATs, and that could form part of a test of controls:
Match data across files (i.e. trace transactions through the accounting system)
Test authorisation controls (e.g. only accounts payable staff have access to accounts payable finance
module)
Select sample transactions from electronic files that match predetermined parameters or criteria
Stratify, summarise and age information (e.g. accounts receivable ageing report)
CC
CC
•• In this situation, the control is a combination of an ITAC (creation of exception report) and
a manual control (appropriate investigation arising from the exception report). To test
the effective operation of both these controls, the auditor may use a CAAT to compare
the bank account numbers both in and between the employee and vendor master files.
For duplicates created throughout the year, the auditor may select a sample and obtain
documentary evidence that indicates whether the control is operating effectively (e.g.
obtain copies of duly authorised exception reports that contain annotations as to the
validity of the duplicate bank accounts).
Required reading
ISA 330 paras A16, A24 and A27.
Required reading
ISA 330 paras 10, A21, A26−27.
CC
As discussed in previous units, these objectives regarding transactions and account balances are
assertions (refer to ISA 315 (Revised) para. A124).
Auditors design tests of controls to gain reasonable assurance that the controls designed and
implemented by management are effective in addressing specific assertions.
Examples of how controls address specific risks and assertions, and tests of controls to provide
reasonable assurance of each control’s effectiveness
Fixed assets Property, Existence – assets A periodic count Attend fixed asset
are overstated Plant and recorded exist of fixed assets count to observe the
or understated Equipment is performed, count procedure and
Completeness – all
with subsequent obtain evidence of
assets that exist have
reconciliation to the reconciliation of the
been recorded
fixed asset register asset count sheets to the
fixed asset register
Required reading
ISA 315 (Revised) para. A124.
ISA 330 para. 8.
CC
Example – Test of controls where a significant risk of material misstatement has been identified
The following example illustrates a test of controls where a significant risk of material
misstatement has been identified.
The auditor has determined that it is a significant risk that goods are sold to customers who
cannot or will not pay.
The specific assertion at risk is the valuation and allocation of trade receivables. However,
management has designed and implemented a control to mitigate this risk: credit is authorised
before a credit sale is approved.
If the auditor decided to rely on this control and tested the operating effectiveness of this
control during the previous year’s audit, the control still must be tested during the current
year’s audit because the auditor intends to rely on it to mitigate a significant risk.
Required reading
ISA 330 paras 11–15 and A32.
CC
Documentation
Under ISA 330, the auditor must document their responses to assessed risks of material
misstatements at the financial statement level. This must include the nature, timing and extent
of further audit procedures performed; the linking of those procedures with the assessed risks
at the assertion level; and the results of the audit procedures.
Below is a list of items that would normally be documented regarding controls testing.
It enables another experienced auditor to understand and replicate the work done, and reach
the same conclusions simply by following the documented information:
•• The relevant control activities, their purpose and associated assertions.
•• The period covered by the test of controls.
•• The population(s), subject to the control activities tested.
•• The size of the sample tested, including the judgements applied or procedures performed
in determining the sample size.
•• The method used in selecting samples.
•• A description of the test of controls performed.
•• The results, including the evidence obtained and result of investigations into any deviations.
•• Conclusions arising from the test of controls.
•• Names of personnel who performed the test of controls and when it was completed.
•• Names of personnel who reviewed the audit work relating to the test of controls, the extent
of that review and when it was completed.
Required reading
ISA 230 paras 8−9.
ISA 330 para. 28.
CC
Audit sampling
Learning outcome
3. Apply audit sampling during controls testing in order to provide a reasonable basis for the
auditor to draw conclusions.
Method Explanation
Select a sample of items This is appropriate for reaching a conclusion about an entire set of data
from a population (audit (population) by selecting and examining a representative sample of items in the
sampling) population
Sampling enables the auditor to obtain and evaluate audit evidence about
specified characteristics. The determination of the sample size may be made
using either statistical or non-statistical methods
When choosing the most appropriate way to select items for testing, it is important to consider
the type of conclusion that the auditor intends to draw. When all items within the population
are tested, or audit sampling is applied, the auditor may be able to draw conclusions about the
entire population.
When specific items within a population are selected (e.g. high-value or key items), the results
of the test cannot be applied to the entire population. This is because when selecting items
judgementally, the population is divided into items that meet certain criteria and items that do
not. As a result, items that meet the criteria do not provide evidence regarding those items that
do not.
Required reading
ISA 500 paras 10 and A52−A55.
CC
ISA 530 establishes the requirements and provides guidance for situations where the auditor
uses audit sampling in performing audit procedures (the third testing method in the table
above).
This unit discusses how the auditor applies audit sampling during tests of controls. The
application of audit sampling for tests of details is discussed in the unit on responding to
assessed risks – substantive testing.
Required reading
ISA 530 paras 1−5.
CC
Sampling risk
Whenever the auditor intends to draw a conclusion about a population by testing less than the
entire population, sampling risk is created. Sampling risk is the risk that the conclusion reached
on the operating effectiveness of internal controls implemented by management by testing a
sample is not the same as the conclusion that the auditor would reach if the entire population
was tested (ISA 530 para. 5(c)).
The auditor could conclude that the controls are less effective than they actually are. This would
create audit inefficiency as unnecessary additional audit procedures would then need to be
performed.
Alternatively, the auditor may conclude that the controls are more effective than they
actually are across the entire population. This reduces the effectiveness of the audit and could
potentially lead to an inappropriate audit opinion being issued. This second form of sampling
risk is of much more concern to the auditor, who, as a result, is required to determine a sample
size sufficient to reduce the sampling risk to an acceptably low level (ISA 530 para. 7). The
factors that the auditor considers in determining the sample size are considered below.
When designing the test of controls, it is important that the auditor considers the nature of
the audit evidence that they are seeking, and, in the context of the specific test, what would
constitute an error or deviation.
CC
Required reading
ISA 530 paras 5, 6, 8, A4, A7, A9 and A12.
An increase in the extent Increase The greater the reliance the auditor places on the operating
to which the auditor’s risk effectiveness of controls, the greater the extent of the auditor’s
assessment takes into tests of controls and, therefore, the sample size
account relevant controls
An increased sample size provides greater evidence by lowering
the sampling risk, as the auditor is using a larger subset of the
population in order to draw a conclusion over the population
An increase in the Increase The higher the expected rate of deviation in the population,
expected rate of deviation the larger the sample size needs to be, so that the auditor is
of the population to be in a position to make a reasonable estimate of the actual rate
tested of deviation. This is because as the expected rate of deviation
increases and approaches the tolerable rate of deviation, the
auditor cannot tolerate the same levels of sampling risk
Factors relevant to the auditor’s consideration of the expected rate
of deviation include the auditor’s understanding of the business,
changes in personnel or internal control, and the results of audit
procedures applied in previous periods as well as other audit
procedures
CC
An increase in the desired Increase The larger the sample size, the greater the level of assurance the
level of assurance that the auditor receives that results of the sample are, in fact, indicative of
actual rate of deviation the population. This means that if the auditor desires an increased
in the population is not level of assurance, the sample size will need to be increased
more than the tolerable
rate of deviation
An increase in the Decrease Assuming there is no change to the auditor’s expected rate of
tolerable rate of deviation deviation in the population, where the auditor is willing to tolerate
a higher rate of deviation, less evidence is required from the sample
in order to reach a conclusion
By contrast, the lower the tolerable rate of deviation, the larger the
sample size needs to be
An increase in the number Negligible For large populations, the actual size of the population has little,
of items in the population effect if any, effect on sample size. For small populations, however, audit
sampling may not be as efficient as alternative means of obtaining
sufficient appropriate audit evidence
ISA 530 does not prescribe the sampling items or units to be drawn from a population regarding
tests of controls. The actual sample sizes used should always be based on professional
judgement. When testing a control that operates on less than a daily basis, the IFAC Guide
provides the following guideline:
Control operates Suggested minimum sample Coverage percentage of test
Weekly 10 19%
Quarterly 2 50%
Yearly 1 100%
Example – Sample size for tests of controls performed less than daily
This example illustrates the application of IFAC’s sampling guideline.
Bank reconciliations are an important control over cash balances in terms of the valuation and
allocation assertion, and the completeness assertion in respect of transactions affecting cash
balances. The frequency of performing bank reconciliations varies from entity to entity – for a
medium-sized entity, it would be common for bank reconciliations to be performed weekly.
You are auditing a medium-sized entity with three trading bank accounts, one term deposit
account and one surplus cash account. The trading accounts reconciliations are performed
weekly, the term deposit account is reconciled quarterly and the surplus cash account is
reconciled monthly.
Applying the approach recommended by IFAC Guide, you would draw the following samples:
•• 10 copies of the reconciliations performed for each of the trading accounts (i.e. 30 sample
items in total).
•• Between two and four copies of the reconciliations for the surplus cash account.
•• Two copies of the reconciliations performed on the term deposit account.
Required reading
ISA 530 paras 7–8, A10–A11 and Appendix 2.
CC
Sampling approaches
An audit sample can be selected using one of the following two approaches to audit sampling
(ISA 530 para. A4):
•• Statistical sampling.
•• Non-statistical sampling (often referred to as judgemental sampling).
(ii) The use of probability theory to evaluate sample results, including measurement of sampling risk.
Non-statistical sampling is a sampling approach that does not have the characteristics of
statistical sampling.
For example, a statistical sample is commonly obtained using audit sampling software, through
which the auditor determines an estimate of the level of deviation in the population as well as
the tolerable rate of deviation. The audit software will use the characteristics of the population
to determine the appropriate sample size, and also select the sample using random selection
(discussed below). Once the auditor has performed the testing, and identified the level of
deviation in the sample, audit software can then be used to apply those sample results to the
population, producing an expected (but unknown) level of deviation in the population and,
based on probability distributions, determine how high the error rate in the population may be.
This helps the auditor to control the level of sampling risk in the population.
A non-statistical sample may be selected haphazardly, rather than randomly, even if the sample
is then evaluated statistically, or the sample size is determined judgementally. For example, a
sample size of 10 items is determined using audit software, and judgmentally increased by two
items by the auditor, as the sample size is below that recommended by the audit firm’s internal
guidance. In relation to a non-statistical sample, the assessment of sampling risk will require
professional judgement.
The choice between statistical and non-statistical sampling is driven by the auditor’s
professional judgement based on the purpose of the audit procedure and the characteristics of
the population from which the sample is taken (ISA 530 paras 6 and A9).
Since the purpose of audit sampling is to provide a reasonable basis on which the auditor can
draw conclusions about the population from which the sample is selected, it is important that
the auditor selects ‘items for the sample in such a way that each sampling unit in the population
has a chance of selection’ (ISA 530 para. 8). To avoid bias, the auditor selects a representative
sample by choosing items that have characteristics typical of the population (ISA 530 para. A12).
Audit sampling, therefore, requires the auditor to exercise professional judgement in designing
and performing the sampling procedure, and evaluating the results of the sample. Judgement
is particularly important when choosing items using a non-statistical sampling method. When
applying statistical sampling, the use of professional judgement is limited in terms of sample
selection, as items are selected in such a way that each sampling unit has a known probability of
being selected (ISA 530 para. A12).
CC
The auditor needs to determine a starting point for selecting the first item within the first
60 items. A random number generator gives the auditor with a starting point of 25.
The auditor selects the following items in the population for the audit sample:
25th, 85th, 145th, 205th, 265th, 325th, 385th, 445th … 2,365th.
•• Haphazard selection – a non-statistical sampling method that does not use a structured
technique to select items. Although the auditor should avoid bias, there is a risk of
unconscious bias when using haphazard selection. For example, the auditor’s selection may
be unconsciously biased towards selecting higher value items, or easily located items. This
method can, however, be useful when the population is not stored in a systematic manner.
ISA 530 Appendix 4 describes these and other methods of selecting samples.
Required reading
ISA 530 paras 8 and A12–A13, and Appendix 4.
CC
Required reading
ISA 530 paras 9–11 and A14.
CC
Learning outcome
4. Explain the importance of evaluating controls and continually evaluating the results of testing
work throughout an audit.
When evaluating the results of tests of controls, the auditor must determine whether the
tests performed provide a reasonable basis for reliance on those controls. The auditor must
investigate the nature and cause of any deviations found, and evaluate their effect on the test
or other areas of the audit. Considering the consequences of a control deviation requires the
auditor to use professional judgement.
When evaluating the results of a sample relating to testing controls, it is important to note that
materiality does not apply. For each sampling unit selected, the control has operated effectively
or it has not. However, this does not mean that the detection of a control breakdown or deviation
automatically results in the control being ineffective.
Where no deviation from the designed control has occurred, the auditor can conclude that the
control is operating effectively.
On the other hand, where the testing discovers a deviation, the control has not operated
effectively for the item sampled. Similarly, if an auditor is unable to apply the designed
procedure to the selected item (or a replacement item) and is unable to perform an alternative
procedure, this would be a deviation.
ISA 330 para. A41 recognises that deviations in controls can occur due to a variety of factors,
such as changes in key personnel, significant seasonal fluctuations in volume of transactions
and human error.
ISA 530 para. 13 recognises that only rarely is a deviation from a prescribed control in audit
sampling considered an anomaly. In these cases, the auditor may conclude that the sampling
unit is not representative of the population, and, therefore, exclude the result of that sampling
unit from the overall assessment of the effectiveness of the control. However, in order to
conclude that the sampling unit is an anomaly, the auditor must perform additional procedures
to obtain a high degree of certainty that the sampling unit is not representative of the
population. Where the auditor concludes that a deviation is an anomaly, they would normally
extend the sample by selecting a replacement item (ISA 530 para. 10).
The process for evaluating deviations is summarised below:
1. Identify deviations Place each sample item into one of two classifications: ‘deviation’
or ‘no deviation’
2. Consider the nature and cause Carefully consider the nature and cause of each deviation. For
of each deviation example, is there an indication of management override of
controls or possible fraud or was the problem simply a result of
the person responsible being on vacation?
3. Consider sampling risk If deviations have been found, consider if reliance on control
effectiveness should be reduced, the sample size extended or
alternative procedures performed
CC
Where a statistical sample has been tested, the auditor may also perform a statistical evaluation
of the sample to quantify both the sampling risk and projected population deviation rate. It is
important to note that the auditor also uses professional judgement when evaluating the sample
results, even when a statistical evaluation has been obtained, and will assess and respond to the
nature and cause of the deviations identified as part of the overall evaluation of the test.
When deviations are detected, is it often more effective to perform alternative substantive
procedures instead. However, in some circumstances (especially where the volume of
transactions in the particular population is high), it may be more efficient to extend the sample
or select an alternative control to test.
Regardless of the deviation rate, for deviations detected in controls that the auditor intends to
rely on, ISA 330 para. 17 requires the auditor to understand why the deviation(s) occurred, and
then to decide whether:
•• the evidence obtained supports reliance on the controls,
•• additional tests of controls are required, or
•• a substantive approach is required to address the potential risks of misstatement.
Required reading
ISA 330 para. 17.
ISA 530 paras 9–13, 15, A14, A15 and A23.
Required reading
ISA 330 para 16 and A40..
CC
ISA 265 requires the auditor to ‘communicate in writing significant deficiencies in internal
control identified during the audit to those charged with governance on a timely basis’
(ISA 265 para. 9).
The auditor is also required to communicate to management significant deficiencies and other
deficiciencies in internal control that have been identified during the audit. The auditor uses
professional judgement to determine which other deficiencies in internal control should be
communicated to management. Communicating deficiencies in internal control is discussed in
detail in the unit on reviewing the financial statements and audit results.
Required reading
ISA 265 paras 9–10 and A5-A7.
Quiz
[Available online in myLearning]
Readings
Required reading
ISA 265 Communicating ASA 265 Communicating ISA (NZ) 265 Communicating
Deficiencies in Internal Control to Deficiencies in Internal Control to Deficiencies in Internal Control to
Those Charged with Governance Those Charged with Governance Those Charged with Governance
and Management and Management and Management
• Paragraphs 9–10 and A5- • Paragraphs 9–10 and A5- • Paragraphs 9–10 and A5-
A7. A7. A7.
ISA 315 (Revised) Identifying ASA 315 Identifying and Assessing ISA (NZ) 315 (Revised) Identifying
and Assessing the Risks of the Risks of Material Misstatement and Assessing the Risks of
Material Misstatement through through Understanding the Entity Material Misstatement through
Understanding the Entity and Its and Its Environment Understanding the Entity and Its
Environment Environment
•• Paragraphs 11–24, 31, A60–A66, •• Paragraphs 11–24, 31, A60–A66, •• Paragraphs 11–24, 31, A60–A66,
A73–A75, A103–A105, A124 and A73–A75, A103–A105, A124 and A73–A75, A103–A105, A124 and
A143 A143 A143
ISA 230 Audit Documentation ASA 230 Audit Documentation ISA (NZ) 230 Audit Documentation
•• Paragraphs 8–9 •• Paragraphs 8–9 •• Paragraphs 8–9
ISA 330 The Auditor’s Responses to ASA 330 The Auditor’s Responses to ISA (NZ) 330 The Auditor’s Responses
Assessed Risks Assessed Risks to Assessed Risks
•• Paragraphs 3, 4(b), 8–17, 25–28, •• Paragraphs 3, 4(b), 8–17, 25–28, •• Paragraphs 3, 4(b), 8–17, 25–28,
A16, A20–A27, A31–A32, A40–A41 A16, A20–A27, A31–A32, A40– A16, A20–A27, A31–A32, A40–A41
and A60–A62 A41 and A60–A62 and A60–A62
ISA 500 Audit Evidence ASA 500 Audit Evidence ISA (NZ) 500 Audit Evidence
•• Paragraphs 1 0 , A52–A55 •• Paragraphs 1 0 , A52–A55 •• Paragraphs 1 0 , A52–A55
ISA 530 Audit Sampling ASA 530 Audit Sampling ISA (NZ) 530 Audit Sampling
•• Paragraphs 1–13, 15, A4, A7, •• Paragraphs 1–13, 15, A4, A7, •• Paragraphs 1–13, 15, A4, A7,
A9–A15 and A23 A9–A15 and A23 A9–A15 and A23
•• Appendices 2 and 4 •• Appendices 2 and 4 •• Appendices 2 and 4
Further reading
There is no further reading for this unit
References
IFAC 2011, Guide to using ISAs in the audits of small and medium-sized entities, 3rd edn
(IFAC Guide), vols 1 and 2, Exhibit 10.5-4, p. 138; Exhibit 17.1, pp 222-3; Exhibit 17.5-6, p. 240.
Chartered Accountants Australia and New Zealand 2015, Australian audit manual and toolkit 2015
for small and medium sized entities, Thomson Reuters, Australia.
ACT
Activity 9.1
Identifying risks, controls and appropriate
tests of controls
Introduction
Auditors are interested in the controls that an entity’s management designs and implements
to prevent or detect material misstatements in the financial statements. Where the auditor
plans to adopt a controls-based approach to the audit, they must identify the risks of material
misstatements and related controls that are relevant to the audit client. Once identified, the
auditor must then design appropriate tests of controls to obtain evidence as to the effective
operation of the client’s controls.
This activity links to learning outcome:
•• Design, perform and evaluate the results of controls testing.
At the end of this activity, you will be able to identify risks and related controls, and design tests
of controls, in accordance with ISA 315 (Revised) Identifying and Assessing the Risks of Material
Misstatement through Understanding the Entity and Its Environment (ISA 315 Revised) and ISA 330
The Auditor’s Responses to Assessed Risks (ISA 330).
It will take you approximately 40 minutes to complete.
Scenario
You are a senior auditor working for Eastern Partners. One of your clients is SunToy Limited
(SunToy), a listed company that has been operating for a number of years as a producer of
Australian-themed toys. SunToy’s clients are local and international wholesalers. SunToy’s
audit partner, Charles Yondi, has assigned you the task of understanding both the revenue and
employee benefits cycles during the 30 June 20X3 audit.
In reading through the previous year’s audit work papers, which are relevant to understanding
the business, you identify the following information about SunToy.
Revenue cycle
SunToy’s customers only accept liability for goods they order from SunToy when the goods
are physically delivered to their warehouses. For some international customers, shipments of
SunToy’s products to their warehouses can take up to six weeks to be delivered.
The transaction flow for revenue and cost of goods sold (COGS) recognition is as follows:
1. On receipt of a customer order, goods are dispatched from SunToy’s warehouse to the
customer via various shipping companies. Shipments are accompanied by sequentially
numbered delivery dockets. The delivery dockets are duplicated, with one form being
retained by the warehouse manager and the other going to the customer along with the
goods dispatched. At the time of dispatch, the accounting department is sent a dispatch
notice (also sequentially numbered) that identifies the goods shipped, the sale price per unit
and the associated delivery docket number. Based on this dispatch notice, the accounting
department credits the finished goods account and debits the goods in transit account.
ACT
2. When goods arrive at a customer’s warehouse, its receiving clerk signs the delivery docket.
The shipping company sends this customer-signed copy of the delivery docket back to
SunToy’s accounting department.
3. Once the signed delivery docket is received, SunToy’s accounting department raises an
invoice and sends it to the customer. The transactions processed in the finance system at this
point are:
Account description Dr Cr
$ $
COGS XX
Goods in transit XX
Recognition of sale
Account description Dr Cr
$ $
Accounts receivable XX
Sales XX
SunToy’s dispatch notice, the signed delivery docket returned by the customer and a copy of
SunToy’s customer invoice are filed alphabetically by customer name in SunToy’s manual filing
system.
Bernie Tonka, SunToy’s financial controller, maintains that all dispatch notices are processed by
the accounting department within 24 hours of receipt. They are filed numerically in an ‘invoice
pending’ file. This file is checked once a week for all notices that are older than six weeks, which
are then investigated by contacting both the shipping company and customer to check if the
relevant shipments have arrived. Pending an outcome of this investigation, the dispatch notices
and accompanying notes of inquiry are either retained in the ‘invoice pending’ file, or removed
and used to support shrinkage expenses (i.e. if goods in transit are lost and their delivery cannot
be confirmed by either the customer or the shipping company, the relevant goods are then
written off to shrinkage expense).
Each employee’s immediate supervisor is required to sign a hard copy of the roster on a daily
basis as evidence that the rostered hours were worked. Any adjustments (e.g. additional
or reduced hours worked) are noted daily on the roster and recorded in detail on a payroll
adjustment form (PAF) that must be signed by both the supervisor and employee. The hard
copy of the roster plus any PAFs are forwarded to the payroll officer each Friday and used as
the basis for the employee’s casual and part-time wages for that week.
ACT
Charles Yondi has decided that it is appropriate to test controls over the relevant transactions
for both the revenue and employee benefits cycles. The planned audit approach is to rely on
controls over the revenue and employee benefits cycles regarding the assertions identified.
Tasks
For this activity, in relation to the revenue and employer benefits cycles, you are required to:
1. Identify and explain key accounts at risk of material misstatement.
2. Identify key assertions at risk of material misstatement for each key account.
3. Identify a related control that SunToy has in place to address each assertion at risk.
4. Design a test of control to test the control activity identified above.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 9.2
Evaluating results of tests of controls
Introduction
When an auditor plans to rely on identified controls that are appropriately designed and
implemented to address assessed risks, the auditor must obtain sufficient appropriate audit
evidence regarding the effective operation of those controls. Often the volume of transactions is
so high that it is more efficient to test the controls using computer-assisted audit techniques.
This activity links to learning outcomes:
•• Design, perform and evaluate the results of controls testing.
•• Design, implement and evaluate tests of controls, using computer-assisted audit techniques
(CAATs).
•• Apply audit sampling during controls testing in order to provide a reasonable basis for the
auditor to draw conclusions.
At the end of this activity, you will be able to evaluate the sufficiency and appropriateness
of audit evidence documented, as well as the effects of deviations from control activities, in
accordance with ISA 330 The Auditor’s Responses to Assessed Risks (ISA 330) and ISA 530 Audit
Sampling (ISA 530).
It will take you approximately 30 minutes to complete.
Scenario
You are a senior auditor working for Green Tick, an accounting firm, on the audit of BlueWave
Limited (BlueWave), for the financial year ended 30 June 20X3 (FY 20X3). You are reviewing
documentation prepared by a junior auditor, Vincent Bower, relating to tests of controls work
that was performed on BlueWave’s purchasing system.
The following work paper, developed by Vincent, is the subject of your review.
ACT
The clerk then enters the GRN details (GRN number and date, quantities received etc.) into
BlueWave’s purchasing system, which creates a transaction to update both the inventory
and accounts payable records. The date the GRN is entered into the system by the accounts
department is the posting date for the transaction. At the end of each work day, the clerk
checks with the warehouse to confirm the range of GRNs that have been created that day, and
that they have all been recorded in the purchasing system on the same day as the goods have
been physically received.
Mick Ghatas, BlueWave’s financial controller, provided evidence by way of copies of supplier
contracts indicating that BlueWave becomes liable for goods ordered on receipt of the goods,
not on the date the invoices are received.
Key control to be tested in the purchasing process
The control to be tested is the check to ensure the GRN date and date of entry into the
purchasing system is the same for every transaction on a given day. The performance of this
control can be assessed electronically by comparing the GRN date in the system with the
posting date of the accounting entry. This control is to ensure the completeness of the accounts
payable balance as well as the cut-off of purchases. The sample of GRNs is to be tested around
year end using CAATs due to the higher level of transactions at this time and to give extra
comfort over the year-end balance.
Design and implementation of control
Design assessment
The date that the GRN is entered into the purchasing system by the accounts payable
department is the posting date for the transaction. Based on information received from Mick
Ghatas, the GRN date, being the date goods are received, is the date that BlueWave becomes
liable for the goods received. Therefore, entering the GRN on the date of receipt and creating
a transaction in both inventory and accounts payable ensures transactions are recorded in the
correct period.
Implementation assessment
One GRN, recorded in the purchasing system, was selected and compared to the transaction
recorded in the accounts payable subsidiary ledger, as follows:
Conclusion
Control appears to be appropriately designed and implemented. VB 12.04.X3
Tests of controls performed
Date: 15 August 20X3
Prepared by Vincent Bower
Audit work steps performed:
1. With the assistance of Green Tick’s IT audit team, the firm’s generalised audit software
program was used to run a CAAT on a copy of BlueWave’s purchasing system software,
including the transaction data recorded throughout the period under audit. The CAAT was
designed to produce an exception report where recorded GRN and transaction dates do
not match.
2. From a population of 300 GRN transactions raised between 1 July 20X2 and 15 August 20X3,
60 transactions on either side of the 30 June 20X3 year end were selected. A tolerable
deviation rate of 5% was established.
ACT
Results
Five deviations were identified:
Note A: BlueWave’s purchasing manager, Simon Shade, advised that these GRNs had been
cancelled and replaced, so they are not valid deviations.
Conclusion
Three valid deviations were noted from a sample of 60. The deviation rate is 5% and the
tolerable deviation rate is 5%; therefore, this is acceptable.
The controls around GRN transactions are reliable. VB 15.08.20X3
Task
For this activity, as Vincent’s senior auditor, you must evaluate the evidence he has obtained to
assess if the tests of controls performed are sufficient and appropriate, as well as the effects of
deviations from control activities. You will need to raise appropriate review notes on the work
performed and highlight any deficiencies in the documentation provided, with reference to the
appropriate requirements under the Standards. Discussion points to explain your review notes
must also be documented.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 9.3
Evaluating the sufficiency and
appropriateness of tests of controls
Introduction
An entity designs and implements internal controls in order to help it achieve its business
and operational objectives. Such controls often relate to operations, financial reporting, or
compliance with laws and regulations. Auditors are primarily interested in those controls that
prevent and detect and correct material misstatements in the financial statements.
When auditors perform tests of controls, they are seeking to obtain reasonable assurance over
the operating effectiveness of controls to be able to draw the conclusion that they are able to rely
on the controls tested. A conclusion that enables reliance on particular controls for a relevant
assertion allows the auditor to perform less substantive procedures relating to that assertion.
Reducing the amount of substantive testing promotes an efficient and effective audit.
This activity links to learning outcome:
•• Explain the importance of evaluating controls and continually evaluating the results of
testing work throughout an audit.
At the end of this activity, you will be able to evaluate the sufficiency and appropriateness of
control activities identified and tested, in accordance with ISA 315 (Revised) Identifying and
Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment
(ISA 315 (Revised)), ISA 330 The Auditor’s Responses to Assessed Risks (ISA 330) and ISA 500 Audit
Evidence (ISA 500).
It will take you approximately 30 minutes to complete.
Scenario
You are a senior auditor working for the accounting firm Granger & Beatty Australia. As a result
of another senior auditor, Betty Jones, breaking her leg on a weekend skiing trip, you have been
reassigned to work on the audit engagement of a custom book printer, ABKO Pty Ltd (ABKO),
for the financial year ended 30 June 20X3.
Your manager, Diego Dante, has asked you to finish the audit work related to ABKO’s revenue
cycle, which Betty had started. It is 15 July 20X3, and the audit team (including you) has just
arrived at the client’s offices to complete audit testing for the financial year ended 30 June 20X3.
You begin by reviewing the work Betty has already done to determine what is outstanding.
ABKO has four types of clients: small publishers, self-publishers, educational institutions
and traditional publishing houses (collectively described as ‘publishers’). You note that at the
interim audit visit during April 20X3, Betty identified and documented ABKO’s sales process:
•• Publishers email their book files to ABKO in PDF format. ABKO stores the books on its
servers, ready for each new print run that the publishers order.
•• ABKO sets up a username and password for new publishers when they send their first
book order through the printer’s online ordering system. In order to activate its account,
a publisher must log in to ordering system and reset the password. At initial login, the
publisher must specify its billing and shipping addresses and accept ABKO’s terms of trade,
which includes ABKO’s right to perform a credit check through a credit rating agency.
ACT
•• Publishers use the online ordering system to order print runs. The ordering system requires
the publisher to specify quantity, book size, paperback or hardcover format, and paper type
and colour.
•• The online ordering system is integrated with the accounting system. The accounting
system automatically stops orders being made by any publishers who have exceeded their
credit terms and limits.
•• ABKO has set the following credit limits based on their customer profiles:
– Small publishers $10,000
– Self-publishers $10,000
– Educational institutions $100,000
– Publishing houses $200,000
•• When printing is finished, the accounts receivable department issues an invoice and the
books are shipped to the publisher’s nominated delivery address.
•• All sales are payable 30 days from the date of the invoice.
Based on this information, Betty identified and documented the following control activities,
tests of controls, and results of tests of controls:
1. New publishers must log in to In a test environment (copy of the Performed test on 16/04/20X3.
ABKO’s online ordering system accounting system), create four Observed that dummy publisher
and complete mandatory dummy publisher accounts (one for accounts were added to the
detail fields for invoicing. They each credit limit profile) by filling customer master file within the
must also reset their password out the required fields to create a accounting system. Credit limits
and accept the terms of trade, new customer were established in accordance
including the fact that a credit with profiles of each customer
Leave mandatory fields blank in
check may be carried out on group, but not activated for usage
some of the dummy publisher
them by ABKO on acceptance of by customers
online application forms
the terms of trade
Where mandatory fields were left
Accounts are not activated until blank, the online system did not let
credit checks are completed the application proceed
Conclusion: Control appears to be
operating as expected
BJ 18.04.20X3
2. For new publishers, ABKO Test 1: Using the customer creation For each month from July 20X2 to
performs a credit check through date field in the customer master April 20X3, the audit team:
a credit rating agency and sets file, select one customer added
•• Selected one publisher added
the appropriate credit limit for each month and trace it to the
to the customer master file
credit report received from the
and traced it to a credit report
credit rating agency
received from Credit 2 U credit
Test 2: Using the sample selected agency
for Test 1, assess whether the credit •• Assessed the credit limit applied
limits were appropriately applied based on the profile of the
customer
Conclusion: No exceptions noted.
Control appears to be operating as
expected
BJ 18.04.20X3
ACT
3. The online ordering system is In a copy of ABKO’s accounting ABKO’s chief financial officer
integrated with the accounting system’s testing environment: has requested that the tests be
system. The accounting system performed only once, due to the
•• Test 1 – select a number of
automatically stops orders made disruption caused by audit staff to
customers with a predetermined
by any publishers who have the IT staff in establishing the test
credit limit. Process a dummy
exceeded their credit terms and environment. In addition, she has
order for an amount that will
limits requested that the tests of controls
result in credit limits being
be performed only during July
exceeded. Observe whether
20X3, as this is traditionally the
the transaction is permitted to
quietest time of the year for ABKO
continue
•• Test 2 – select a customer who BJ 31.04.20X3
has exceeded their payment
terms (i.e. whose balance is
overdue). Process a dummy
order for any amount. Observe
whether the transaction is
permitted to continue
Tasks
For this activity, you are required to:
1. Identify what remains outstanding in relation to the tests of controls documented.
2. Assuming no further deviations in controls are detected, evaluate whether the control
activities can be relied on.
3. For each of the control activities, identify the key assertions relating to revenue transactions
and associated account balances at period end that have been addressed through tests of
controls. Justify your response.
4. Identify the assertions relating to revenue transactions and associated account balances
at period end that have not been addressed by the controls activities and testing noted in
Betty’s documentation. Justify your response.
[Solutions to activities are available online. Please access myLearning to view]
CC
Core content
Unit 10: Responding to assessed risks
– substantive testing
Learning outcomes
At the end of this unit you will be able to:
1. Apply audit sampling during substantive testing in order to provide a reasonable basis for
the auditor to draw conclusions.
2. Design, perform and evaluate the results of substantive testing.
3. Design, implement and evaluate substantive testing using computer-assisted audit
techniques (CAATs).
Introduction
In the risk response phase, the auditor performs audit procedures to provide reasonable
assurance that the financial statements are not materially misstated. Substantive procedures, as
addressed in ISA 330 The Auditors Responses to Assessed Risks (ISA 330), are part of the auditor’s
response to risk. They provide direct evidence about amounts in the financial statements by
testing the underlying data.
The following diagram illustrates the stages of the audit that relate to risk assessment and
responses to assessed risks, and identifies the Standards that apply to those stages:
CC
These are illustrated in the following diagram:
Audit procedures
Substantive analytical
Tests of details
procedures
This unit focuses on substantive procedures and considers the requirements of the following
International Standards on Auditing (ISAs) that relate to substantive testing:
•• ISA 330 The Auditor’s Responses to Assessed Risks (ISA 330).
•• ISA 500 Audit Evidence (ISA 500).
•• ISA 501 Audit Evidence – Specific Considerations for Selected Items (ISA 501).
•• ISA 505 External Confirmations (ISA 505).
•• ISA 520 Analytical Procedures (ISA 520).
•• ISA 530 Audit Sampling (ISA 530).
This unit covers how to apply audit sampling during substantive testing and how to design,
perform and evaluate substantive procedures, including how to use Computer-assisted audit
techniques (CAATs) in performing those substantive procedures.
CC
Learning outcome
1. Apply audit sampling during substantive testing in order to provide a reasonable basis for the
auditor to draw conclusions.
3. Advertising 110,000
Total 244,000
CC
Sampling involves applying audit procedures to a sample of items from the defined population.
Therefore, sampling is applicable to tests of details, which examine the items that comprise
amounts in the financial statements.
Sampling is not suitable for substantive analytical procedures (SAPs) because these procedures
do not directly examine items that comprise amounts in the financial statements.
Many of the basic concepts relating to audit sampling were discussed in the unit on responding
to assessed risks – controls testing. Most of these concepts are the same when applied to audit
sampling for tests of details. The main differences relate to how the results of audit sampling
are evaluated:
•• When evaluating sampling results for tests of details, the auditor projects misstatements in
the sample to the population to give a best estimate of the misstatement in the population
(ISA 530 para. 14).
•• When evaluating sampling results for tests of controls, the auditor compares deviations
in the sample to a tolerable rate of deviation, and can obtain a best estimate of the rate of
deviation in the population (ISA 530 para. 5(j)).
This section will examine audit sampling through the following phases in a test of details:
Required reading
ISA 530 paras 1–5, 14 and A1–A3.
ISA 500 paras 10 and A52–56
CC
It is often the occurrence and existence assertions that are tested, as applicable. This is because
audit sampling is often applied to a population of recorded items, which are then verified
against evidence to confirm that the transactions occurred during the period, or that the account
balances existed at period end. This concept will be discussed further below.
Different auditing firms use different sample sizes and sampling methodology.
However, sample size, when performing tests of detail, is impacted by factors set out in
ISA 530 Appendix 3. These factors are summarised in the following table:
Increased use of other Decrease If the auditor performs other substantive procedures on the
substantive procedures same amounts and assertions, this reduces the sample size.
The other substantive procedures could be SAPs
Increase in desired level of Increase The larger the sample size, the more assurance there is that
assurance that misstatement in the results of the sample are indicative of the misstatement
the population is not more than in the population. Increased sample sizes will result in
tolerable misstatement increasingly precise results
CC
Increase in expected Increase If the auditor expects a greater misstatement, then the
misstatement sample size must be increased, to provide more results on
which to base the auditor’s estimate of the misstatement
Stratification of the population Decrease Auditors often stratify (i.e. divide) populations into
subpopulations with different characteristics (e.g. monetary
size), and then sample each subpopulation separately. Doing
this will reduce the overall sample size
Number of items in the Negligible This makes sampling an efficient tool when examining large
population effect populations
Required reading
ISA 530 paras 5(c), 5(i), 6–7, A1–A11, Appendix 1 and Appendix 3.
In addition, another method, monetary unit sampling, is often used when designing tests of
details:
•• Monetary unit sampling (MUS) – this method replaces the number of items in the
population and sample with their monetary values. MUS is used to increase the chances of
high-value items being selected for testing, as the individual monetary units (i.e. individual
dollars) are selected, meaning that higher value items have more individual monetary units
available for selection. Therefore, MUS is commonly used when testing for overstatement.
CC
Required reading
ISA 530 paras 8, A12–A13 and Appendix 4.
Required reading
ISA 530 paras 9–11 and A14–A16.
CC
Whereas:
•• The results of a sample for a test of details are projected to the population in order to
calculate a monetary misstatement amount (where applicable).
When assessing the results of testing a sample, the objectives are to evaluate:
•• The results of the sample (ISA 530 para.15(a)).
•• Whether the sample provides a reasonable basis for concluding on the population
(ISA 530 para. 15(b)).
CC
Determining whether the sample provides a reasonable basis for concluding on the
population
If the projected misstatement, and any misstatements from anomalies, exceeds the auditor’s
tolerable misstatement, the sample does not provide a reasonable basis for conclusions about
the population (ISA 530 para. A22). In this event, the auditor needs to:
•• request that management investigates the identified misstatements and makes any
necessary adjustments, or
•• obtain evidence using other audit procedures.
Required reading
ISA 530 paras 12–15, A17–A19 and A21–A23.
Required reading
ISA 230 para. 9.
ISA 450 para. 15.
Worked example 10.1: Evaluating the results of audit sampling for a test of details
[Available online in myLearning]
CC
It may be possible to obtain a reciprocal population (e.g. a population of payments after year
end, when testing for completeness of the accounts payable balance); however, it is important
to note that sampling is generally less effective when testing completeness, and professional
judgement is required to plan test and interpret results.
Required reading
ISA 530 para. 5(a).
ISA 500 paras 10 and A52–A56.
CC
Substantive testing
Learning outcome
2. Design, perform and evaluate the results of substantive testing.
3. Design, implement and evaluate substantive testing using computer-assisted audit
techniques (CAATs).
This section covers how to design substantive procedures that address the residual risk after
any tests of controls have been performed. The following diagram illustrates how the auditor’s
response to risks fits in with the audit risk model, which was introduced in the unit on
understanding the entity and its environment:
Required reading
ISA 330 paras 1–5, 18–21, A1–A3, A42–A43 and A52–A53.
CC
Purpose: Type:
TODs or Inspection
SAPs Nature Observation
Inquiry
Confirmation
Recalculation
Reperformance
Analytical procedures
Procedure
Timing Extent
Each of these elements is important in meeting the auditor’s overall objective to ‘obtain
sufficient appropriate audit evidence’. For example, the auditor can obtain more assurance
by either increasing the sample size for a particular test of details, or by changing the type of
procedure in order to obtain more reliable or appropriate audit evidence.
Required reading
ISA 330 paras A4–A8 and A59.
ISA 500 paras A14–A25.
CC
This unit discusses SAPs that are used at the response to assessed risk stage of the audit, to
obtain audit evidence. When using SAPs as a substantive procedure, the auditor develops an
expectation of the recorded amounts or ratios, evaluates the reliability of the data from which
the expectation is developed and determines an acceptable difference. This is different to SAPs
used as planning and final analytical procedures.
Despite the generalisation that SAPs provide less assurance than tests of details, there are
circumstances when they can be particularly effective, as well as efficient. For example, when
conducting an audit on a property company that manages multiple properties, it may be
possible to perform a SAP with a high degree of accuracy because the number of properties and
rentals may be highly predictable.
SAPs are most suited to:
•• Large volumes of transactions that are predictable over time (ISA 520 para. A6).
•• Analyses that can be performed with a high degree of accuracy (ISA 520 para. A7).
It is also possible to design more effective SAPs by basing them on more disaggregated data –
for example, by analysing revenue by month, division, and product group.
Example – SAPs and tests of details that address the same assertion
To address the risk that the accounts receivable balance is overstated (existence assertion), the
auditor of Brown Co. plans the following substantive procedures:
SAP:
Calculate debtor days and compare to expectations developed from terms of trade, industry
averages, prior years’ reported amounts, and Brown Co.’s forecasts.
Test of details:
Verify a sample of customer balances by tracing to sales invoices prior to period end and
external shipping documents and cash receipts subsequent to the period end.
CC
Required reading
ISA 520 paras 1–5(b), A1–A10 and A11–A14.
ISA 330 para. A44.
CC
Questions to address
Adapted from: Australian audit manual and toolkit 2015 for small and medium sized entities, pp. 133–134
When designing a SAP, it is necessary that the auditor determines the size of variances from
expectations that they are willing to accept. This is influenced by materiality and the level of
assurance planned (ISA 520 para. A16). The auditor also needs to consider how precise the SAP
is expected to be.
Required reading
ISA 520 paras 5(c) and A15.
Required reading
ISA 520 paras 5(d), 7, A16 and A20–A21.
CC
Tests of details
Tests of details involve obtaining direct evidence on items that comprise amounts in the
financial statements. Often the auditor will perform tests of details on sample of items as
discussed above in the section on audit sampling.
The assurance provided by a test of details therefore depends on the:
•• Relevance and reliability of the audit evidence obtained.
•• Quantity of audit evidence obtained.
These factors are relevant when designing any type of audit procedure – test of controls or
substantive procedure.
Many audit firms use audit software or audit program templates that include lists of most
common audit procedures. When using these lists of audit procedures, it is important to
customise the procedure to address the specific risk and explain the evidence obtained,
including source documentation required and details checked.
CC
As the assessed risk increases, so does the quality and quantity of evidence that is required. For
example, the auditor may place more emphasis on obtaining third party evidence which is more
reliable, or by obtaining corroborative evidence from a number of independent sources.
Required reading
ISA 330 paras 6–7 A9–A19 and A44–A47.
ISA 500 paras 4, 6, A1–A3, A6 , A12–A13 and A27.
Relevant assertion
When determining the relevant assertion, the auditor considers the risk, that is, which aspect
of the account ‘could go wrong’ and therefore which assertion is the most at risk of being
misstated.
The substantive procedure needs to be designed to address the assertion being examined
(ISA 330 para. 6). This means obtaining audit evidence that is relevant, or linked, to that
assertion (ISA 500 para. A27). This can often relate to the ‘direction’ of the procedure, or starting
point for the procedure.
When testing the existence or occurrence assertions, the auditor is interested in whether
items that are recorded in the financial statements actually did occur during the period or do
exist at period end (i.e. risk of overstatement). Therefore, a test of details will select a sample
of recorded items and then seek to obtain evidence to verify them.
CC
When testing the completeness assertion, the auditor is concerned with whether transactions
or balances that should have been recorded have been missed (i.e. risk of understatement).
Therefore, a test of details will start by examining evidence of items that should be recorded,
and then investigate whether these items are included in the relevant account balance.
Sufficiency Appropriateness
CC
Required reading
ISA 500 paras 1–5, 7–10 and A1–A56.
Required reading
ISA 330 paras 22–23, A6, A11–A14 and A54–A58.
CC
Required reading
ISA 330 paras A7 and A15.
ISA 500 para. A8.
External confirmations
ISA 330 para. 19 requires the auditor to ‘consider whether external confirmation procedures
are to be performed as substantive audit procedures’. The requirements for how to perform
external confirmations are contained in ISA 505, which is discussed later in the unit on
responding to assessed risk – using the work of others, external confirmations and written
representations. However, for the purposes of this unit, it is important to understand when
external confirmations can be used by the auditor in designing substantive procedures.
Since they come from external parties, external confirmations can provide highly reliable
evidence. The nature of external confirmations means that the evidence is particularly relevant
for testing the existence and occurrence assertions. Confirmations are commonly used to
confirm (ISA 330 para. A48):
•• Bank balances.
•• Trade receivables.
•• Borrowings.
•• Property ownership.
•• Inventories held by third parties.
•• Investments.
Required reading
ISA 330 paras 19 and A48–A51.
ISA 505 paras 1–6, 12–14 and A18–A22.
CC
There are a number of differences between the international, Australian and New Zealand
Standards that cover these areas, listed in the following table:
International, Australian and New Zealand Standards that apply to specified substantive procedures
on selected items
International Standards on Auditing (ISAs) and International Standards on Auditing (New Zealand) (ISAs (NZ))
cover all specific considerations for inventory, segment reporting, and litigation and claims, in a single
respective Standard, ISA 501 Audit Evidence – Specific Considerations for Selected Items
Australian Standards
However, in Australia, litigation and claims is covered by a separate Standard. The relevant Standards are:
•• ASA 501 Audit Evidence – Specific Considerations for Inventory and Segment Information (ASA 501).
•• ASA 502 Audit Evidence – Specific Considerations for Litigation and Claims (ASA 502).
ASA 502 contains some additional Australian-specific requirements and guidance, including a requirement to
make enquiries of management regarding litigation and claims that arise after the initial external enquiry
Here we will briefly discuss the requirements relating to inventories and litigation and claims.
Inventory
The main requirement in ISA 501 is that, if inventory is material to the financial statements, the
auditor must attend a physical inventory count. ISA 501 para. 4(a) requires this attendance, at a
minimum, to include:
•• Evaluating management’s stocktake instructions.
•• Observing inventory counts.
•• Inspecting inventory.
•• Performing test counts.
The final inventory records must then be tested to ensure they reflect the counts
(ISA 501 para. 4(b)).
ISA 501 also contains requirements that apply when the auditor does not attend the physical
inventory count. If this non-attendance is due to unforeseen circumstances, the auditor
must organise an alternative time to observe or make counts (ISA 501 para. 6). In the rare
circumstances where it is not practical for the auditor to attend a count at any time, alternative
procedures are required (ISA 501 para. 7).
CC
Required reading
ISA 501 paras 1–12 and A1–A25.
It is important to remember that evidence obtained from substantive procedures at any stage of
an audit may require the auditor to revise the initial risk assessment or materiality.
Evaluating the results of audit procedures requires the auditor to determine whether sufficient
appropriate audit evidence has been obtained. This is discussed in the unit on responding to
assessed risks – evaluating audit evidence.
Activity 10.3: Evaluating the impact of the results of tests of controls on substantive
procedures
[Located at the end of this unit]
Worked example 10.3: Using computer-assisted audit techniques (CAATs) to perform tests
of details
[Available online in myLearning]
Quiz
[Available online in myLearning]
Readings
Required reading
ISA 330 The Auditor’s Responses ASA 330 The Auditor’s Responses ISA (NZ) 330 The Auditor’s Responses
to Assessed Risks to Assessed Risks to Assessed Risks
•• Paragraphs 1–7, 18–24, A1–A19 •• Paragraphs 1–7, 18–24, A1–A19 •• Paragraphs 1–7, 18–24, A1–A19
and A42–A59 and A42–A59 and A42–A59
ISA 500 Audit Evidence ASA 500 Audit Evidence ISA (NZ) 500 Audit Evidence
•• Paragraphs 1–10 and A1–A56 •• Paragraphs 1–10 and A1–A56 •• Paragraphs 1–10 and A1–A56
ISA 501 Audit Evidence – Specific ASA 501 Audit Evidence – Specific ISA (NZ) 501 Audit Evidence –
Considerations for Selected Items Considerations for Inventory and Specific Considerations for Selected
Segment Information Items
•• Paragraphs 1–12 and A1–A25 •• Paragraphs 1–8 and A1–A16 •• Paragraphs 1–12 and A1–A25
ISA 505 External Confirmations ASA 505 External Confirmations ISA (NZ) 505 External Confirmations
•• Paragraphs 1–6, 12–14 and •• Paragraphs 1–6, 12–14 and •• Paragraphs 1–6, 12–14 and
A18–A22 A18–A22 A18–A22
ISA 520 Analytical Procedures ASA 520 Analytical Procedures ISA (NZ) 520 Analytical Procedures
•• Paragraphs 1–5, 7, A1–A10, •• Paragraphs 1–5, 7, A1–A10, •• Paragraphs 1–5, 7, A1–A10,
A12–A16 and A20–A21 A12–A16 and A20–A21 A12–A16 and A20–A21
ISA 530 Audit Sampling ASA 530 Audit Sampling ISA (NZ) 530 Audit Sampling
•• Paragraphs 1–15, A1–A19, •• Paragraphs 1–15, A1–A19, •• Paragraphs 1–15, A1–A19,
A21–A23 and Appendices 1, 3–4 A21–A23 and Appendices 1, 3–4 A21–A23 and Appendices 1, 3–4
ISA 230 Audit Documentation ASA 230 Audit Documentation ISA (NZ) 230 Audit Documentation
•• Paragraph 9 •• Paragraph 9 •• Paragraph 9
ISA 450 Evaluation of Misstatements ASA 450 Evaluation of Misstatements ISA (NZ) 450 Evaluation of
Identified During the Audit Identified during the Audit Misstatements Identified During the
Audit
•• Paragraph 15 •• Paragraph 15 •• Paragraph 15
Further reading
References
Chartered Accountants Australia and New Zealand 2015, Australian audit manual and toolkit 2015
for small and medium sized entities, 5th edn, Thomson Reuters (Professional) Australia Limited
(Australian audit manual and toolkit 2015).
ACT
Activity 10.1
Designing substantive analytical procedures
Introduction
Substantive analytical procedures (SAPs) are types of substantive procedure that use plausible
relationships between financial and non-financial data to obtain audit evidence. Chartered
Accountants performing audits should be able to design SAPs that are appropriate to the
assessed risks of material misstatement and understand how they are used as part of an audit
strategy.
This activity links to the following learning outcome:
•• Design, perform and evaluate the results of substantive testing.
At the end of this activity, you will be able to respond to assessed risks of material
misstatement, in accordance with:
•• ISA 520 Analytical Procedures (ISA 520).
•• ISA 330 The Auditor’s Responses to Assessed Risks (ISA 330).
•• ISA 500 Audit Evidence (ISA 500).
Scenario
Levart Pty Ltd (Levart) is an Australian travel agency that specialises in package holidays
abroad for families and couples. Accurate Auditors Australia (AAA) has been the external
auditor of Levart for a number of years and was appointed auditor for the 30 June 20X5 year
end. Christopher Briggs (Chris) is the audit senior in charge of the upcoming Levart audit and
Daniel Footer (Dan) is the audit manager.
With the diminishing value of the Australian dollar, lavish and expensive holidays abroad are
becoming less popular for Australians, with domestic travel becoming the norm. In recent years,
Levart has had relatively static operating costs, with payroll costs continuing to be the largest
expense item in the profit and loss.
In prior audit engagements, AAA performed SAPs over Levart’s payroll costs. With minimal
employee turnover, static salaries and wage increments for the Consumer Price Index only,
setting a reliable expectation was straightforward for Chris and Dan. Also, there has been no
history of material misstatements as a result of this procedure. Tests of controls have also been
performed across the payroll process with no exceptions or issues arising.
Reflective of the continuing downturn in the Australian dollar and the subsequent decrease in
demand for holidays abroad, the 20X5 financial year has been challenging for Levart and has
resulted in significant changes in its headcount and overall payroll expense.
During the 20X5 audit, Chris held a meeting with Levart’s payroll manager to gain an
understanding of the headcount and payroll expense changes, and took the following notes:
1. Levart continues to operate seven outlets – its headquarters in Sydney and six outlets
nationwide.
2. Levart employs no part-time workers.
ACT
3. No bonus payments were paid during the year.
4. A number of employees were made redundant from 1 January 20X5 across Levart’s outlets.
5. Consumer Price Index increases of 3% were incorporated in all salaries at Levart at the
beginning of the 20X5 financial year.
6. Salaries are paid monthly to all Levart employees.
7. Redundancy costs are disclosed separately on the face of the profit and loss and do not form
part of the payroll expense.
Following on from this meeting, Chris obtained the following information from the payroll clerk:
Sydney HQ 14 11 120,000
Melbourne 10 8 75,000
Adelaide 8 7 72,500
Perth 9 7 78,500
Canberra 6 6 76,000
Brisbane 8 6 78,500
Total 62 51
In determining the size of the variance that is acceptable, Chris took into consideration
materiality, the level of planned assurance (ISA 520 para. A16) and how precise the SAP was.
Taking this into account, and due to a history of no misstatements and effective controls across
the payroll process, Chris proposed an acceptable variance at performance materiality of
$325,000. This variance was approved by the audit partner.
In the draft financial statements and trial balance for Levart, total payroll costs for 20X5 was
$4,843,093.
Task
Dan has asked Chris to design and perform SAPs for the audit of payroll costs, and to document
his workings and conclusions.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 10.2
Designing tests of details
Introduction
A key feature of an audit is the design of substantive procedures that are responsive to the risks
of material misstatements. Many audit firms use audit software or audit program templates
that include common audit procedures. Chartered Accountants performing audits must use
their professional judgement when selecting and customising procedures to design substantive
procedures suitable for the assessed risks and assertions to obtain sufficient appropriate audit
evidence.
This activity links to learning outcome:
•• Design, perform and evaluate the results of substantive testing.
At the end of this activity, you will be able to design tests of details that are appropriate to the
assessed risks of material misstatement in accordance with:
•• ISA 330 The Auditor’s Responses to Assessed Risks (ISA 330).
•• ISA 500 Audit Evidence (ISA 500).
It will take you approximately 30 minutes to complete.
Scenario
You are an audit senior working for Redtik Chartered Accountants (Redtik). Redtik is the
auditor of Darper Electronics (DE), a listed company that operates and owns 160 electronics
stores across Australia and New Zealand. Each store is designed and operated to a standardised
format, with some minor variations.
You are assigned to the team performing the audit of DE for the year ending 30 June 20X3.
The audit team has determined the following in respect of store refurbishments.
Store refurbishments
Stores undergo periodic refurbishments under a program approved annually by the board
of directors. It can be difficult to distinguish between capital improvements and maintenance
expenditure, and, in previous audits, Redtik has found instances where maintenance expenses
have been incorrectly capitalised against an existing asset.
Redtik has also noted instances where existing plant and equipment has not been appropriately
written off when new refurbishments occurred that replaced those existing items.
Based on the matters above, Redtik has identified the following risks of material misstatement:
Plant and equipment – Valuation There is a risk that store maintenance costs are incorrectly capitalised
and allocation against an existing asset
Plant and equipment – Existence There is a risk that plant and equipment is not appropriately written off
when replaced by refurbishments
ACT
Redtik has obtained from DE schedules of plant and equipment incorporating additions,
disposals, accumulated depreciation and amortisation.
Redtick uses audit software that includes the below procedures for property, plant and
equipment (PPE):
Inspect material items of property, plant and equipment and other non-current assets.
Review repairs accounts to determine whether any item should be reclassified as property,
plant and equipment.
Check movements and depreciation to the minute book or other appropriate sources,
confirming transactions are authorised and reasonable.
Determine whether the depreciation rates used are appropriate and consistent with prior
periods.
Enquire whether any items have been scrapped or destroyed and confirm appropriate records
have been kept.
Confirm that the carrying values of assets are, in respect of corporate entities, in accordance
with the applicable Accounting Standards. Review the bases of valuation and discuss current
realisation expectations with the client. Consider the effects of IFRS on carrying values,
particularly IAS 16 Property, Plant and Equipment and IAS 36 Impairment of Assets.
Assess the impact of any impairment indicators that may indicate impairment.
Cross reference additions, disposals and revaluations to the tax working papers where
relevant.
Confirm that property, plant and equipment are grouped appropriately in the financial
statements, and that additions, disposals and other movements during the period are
disclosed in accordance with the requirements of applicable Accounting Standards.
Review ledger accounts, note unusual items, and agree to property, plant and equipment
schedules.
Review the accounting for deferred expenses for compliance with IFRS.
Task
For this activity, you are required to design tests of details to address the specific risks identified
in the table of assessed risks.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 10.3
Evaluating the impact of the results of tests
of controls on substantive procedures
Introduction
The auditor’s assessment of the risks of material misstatement affects the nature, timing and
extent of substantive procedures. Where the auditor’s assessment of risk includes an expectation
that controls are operating effectively, the results of tests of controls will affect substantive
procedures.
This activity links to learning outcome:
•• Design, perform and evaluate the results of substantive testing.
At the end of this activity, you will be able to evaluate the impact of the results of tests
of controls on substantive procedures, in accordance with:
•• ISA 330 The Auditor’s Responses to Assessed Risks (ISA 330).
•• ISA 500 Audit Evidence (ISA 500).
•• ISA 530 Auditing Sampling (ISA 530).
Scenario
AquaFun is a listed company that operates three theme parks on the Australian east coast.
White & Barrie Chartered Accountants (WB) has been AquaFun’s auditor for the past three
years. You are an audit senior at WB assigned to the audit of AquaFun for the year ending
30 June 20X3. WB’s audit manager assigned to the AquaFun audit is James Green.
WB has obtained the following information from the audit planning, including reviews of audit
working papers for previous financial years.
Theme parks are a highly seasonal business, with the busiest months being December to March.
During these busy times, AquaFun employs casual staff to assist at all three theme parks.
All parks close during August as this is the quietest period of the year. In total, there are 107
full‑time staff (paid fortnightly), 38 part-time staff (paid fortnightly) and 42 casual employees
(paid on the Friday of their allocated working week) across the three theme parks.
Full-time staff are paid an annual salary and are not entitled to overtime, but are entitled to
four weeks’ annual leave with 17% leave loading paid when they take that leave. AquaFun’s
policy is that all full-time staff must take their four weeks’ leave during the August shutdown
period. Leave outside August can only be taken with the written approval of the CEO. During
the shutdown period, it is company policy to employ only part-time employees to perform
the various necessary tasks to ensure that the park can reopen in time for the start of school
holidays in September.
Part-time staff are paid on an hourly basis, and are entitled to overtime and accumulated annual
leave (without leave loading) on a pro rata basis. All part-time staff rates are set out in their
individual employment agreements with AquaFun.
ACT
Casual staff are paid on an hourly basis and receive no leave entitlements. Rates are as per the
relevant statutory award rate. Casual staff positions are mostly filled by school and university
students.
As part of the audit planning process, WB evaluated the design of control activities around
payroll and assessed that they were capable of effectively preventing, detecting and correcting
material misstatements (i.e. controls exist and AquaFun was using these controls).
These control activities include controls over the following risks:
1. Part-time staff are paid at incorrect rates (accuracy assertion).
2. Casual staff are incorrectly paid during the August shutdown period (occurrence assertion).
3. Full-time staff are incorrectly paid holiday leave loading outside the August shutdown
period (occurrence assertion).
As a result of this evaluation, WB intended to rely on the operating effectiveness of controls
around payroll by performing relevant tests of controls, supported by substantive analytical
procedures (SAPs) and tests of details.
WB established a tolerable deviation rate for testing controls over each risk and noted the
following exceptions from the tests of controls:
Task
For this activity, you are required to respond to James’s request to evaluate how the results of
the tests of controls will impact on the nature, timing and extent of substantive procedures.
He also asks you to design a test of details to obtain reasonable assurance in respect of each
assessed risk of material misstatement listed above. He suggests you present your findings in
the following table, and tells you to assume that the sample sizes for the tests of controls will
not be increased.
1.
CC
Core content
Unit 11: Responding to assessed risks
– evaluating audit evidence
Learning outcomes
At the end of this unit you will be able to:
1. Apply the auditor’s requirements if there is inconsistency in, or doubts over, the reliability
of audit evidence.
2. Determine whether sufficient appropriate audit evidence has been obtained on which to
base conclusions and auditor’s reports.
3. Evaluate the effect of identified misstatements on the audit, and of uncorrected
misstatements on the financial statements.
Introduction
Up to this point in the Audit & Assurance (AAA) module, units have examined the audit process,
from the pre-engagement stage through to designing further audit procedures that respond to
risks the auditor has identified and assessed. This unit discusses how the auditor evaluates the
audit evidence obtained from audit procedures.
The following diagram is an illustrative summary of the audit process stages covered so far in
the module:
Pre-engagement activities
CC
Many reviews by audit regulators have highlighted the need for auditors to maintain a
heightened level of professional scepticism, particularly in areas that involve significant
estimation or judgement by management. Professional scepticism, together with evaluating
audit evidence and responding to misstatements, will be discussed in this unit.
The following International Standards on Auditing (ISAs) are covered in this unit:
•• ISA 200 Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance
with International Standards on Auditing (ISA 200).
•• ISA 230 Audit Documentation (ISA 230).
•• ISA 330 The Auditor’s Responses to Assessed Risks (ISA 330).
•• ISA 450 Evaluation of Misstatements Identified during the Audit (ISA 450).
•• ISA 500 Audit Evidence (ISA 500).
CC
Learning outcomes
1. Apply the auditor’s requirements if there is inconsistency in, or doubts over, the reliability of
audit evidence.
2. Determine whether sufficient appropriate audit evidence has been obtained on which to base
conclusions and auditor’s reports.
Having responded to assessed risks by performing further audit procedures, the auditor needs
to evaluate the results of audit procedures. The audit evidence comprises the results of audit
procedures. Under ISA 200 para. 17, the auditor is required to obtain reasonable assurance,
by obtaining ‘sufficient appropriate audit evidence to reduce audit risk to an acceptably low
level’. This enables the auditor to ‘draw reasonable conclusions on which to base the auditor’s
opinion’.
The requirement to evaluate audit evidence is contained in ISA 330 and what constitutes
sufficient, appropriate audit evidence is explained in ISA 500. It is important to apply the
following key auditing concepts when evaluating audit evidence:
•• Professional scepticism, which must be applied to critically evaluate the audit evidence.
•• Professional judgement, which must be exercised to recognise that only reasonable, not
absolute, assurance is provided, and that audit evidence is often persuasive rather than
conclusive.
The importance of professional scepticism and professional judgement have been discussed
throughout the audit and assurance module.
Sufficiency Appropriateness
Sufficiency, relevance and reliability of audit evidence is further explained in the table below.
Relevance and reliability are considered together, because appropriate evidence must be both
relevant and reliable. For example, discussions with management may provide evidence that is
highly relevant to the matter being examined, but oral evidence is not particularly reliable.
On the other hand, obtaining highly reliable evidence, such as confirmation of the existence of
investments from external parties, will not provide evidence that is relevant to examining the
valuations of those investments.
CC
Consider the general statements below about the reliability of audit evidence:
General statements about the reliability of audit evidence (ISA 500 para. A31)
Generalisation Example
Reliability is increased when evidence is Confirmation of bank balances obtained directly from the bank
obtained from independent external sources
Reliability is increased when controls over the Effective controls relating to the preparation of aged accounts
preparation of evidence are effective receivable reports, which the auditor then uses when
examining the recoverability of accounts receivable balances
Evidence obtained directly by the auditor Physical inspection of an item of plant and equipment is more
is more reliable than evidence obtained reliable than an enquiry regarding the item’s condition or
indirectly or by inference existence
Documentary evidence is more reliable than Approved and signed minutes of a meeting are more reliable
oral evidence than an oral representation of the matters discussed at that
meeting
Original documents are more reliable than Written confirmations of accounts receivable balances from
photocopies or facsimiles customers that are received by facsimile present a risk that the
confirmation has been altered or not sent by the correct party
Note: Care needs to be taken in making generalisations about the reliability of different types of audit evidence because
specific circumstances can greatly affect reliability.
CC
Example
This example illustrates how an auditor may test the completeness and accuracy of a system-
generated aged receivables report
An auditor has identified management’s review of aged receivables report as one of the
controls they intend to rely on. To test the completeness of data included in the aged
receivables report, the auditor agrees the total of the amounts in the report to the trial balance.
To test the accuracy of the report, the auditor recalculates the totals in each of the categories to
ensure the amounts in the report add up correctly.
CC
Risk of
material
misstatement
Again, professional judgement is needed to determine the required balance between quality
and quantity. By increasing the quality of evidence, the auditor will often be able to reduce
the quantity. However, if the quality is poor, increasing the quantity will not necessarily
compensate for this (ISA 500 para. A4).
Required reading
ISA 500 paras 5–7, A1–A33 and A49–51.
CC
Perform further
NO audit procedures
YES NO
YES
Continue through
audit process Attempt to obtain further
audit evidence
Required reading
ISA 330 paras 25–27 and A60–A62.
CC
ISA 330 expands on the ISA 230 requirements as they relate to documentation specific to the
auditor’s responses to assessed risks. This documentation must include (ISA 330 para. 28):
(a) The overall responses to address the assessed risks of material misstatement at the financial
statement level, and the nature, timing and extent of the further audit procedures performed;
(b) The linkage of those procedures with the assessed risks at the assertion level; and
(c) The results of the audit procedures, including the conclusions where these are not otherwise clear.
The auditor is also required to document that the financial statements reconcile to the
underlying records (ISA 330 para. 30).
To ensure that these requirements are met, auditors will often include standard items in their
working papers, such as:
•• Headings – for example, client, financial period and working paper subject.
•• Objectives and results of audit procedures, including references to assertions.
•• Conclusions for each audit procedure.
•• Names and initials of preparers and reviewers.
•• Dates of completion and reviews.
•• Working paper references.
•• Cross-references to other working papers.
In order to ‘enable an experienced auditor, having no previous connection with the audit, to
understand’ the matters above (ISA 230 para. 8), it is important that the documentation includes
sufficient details of the audit procedures performed. Typically, audit working papers include
details of the individual items tested, and the audit evidence obtained.
Required reading
ISA 230 paras 8–11 and A2–A17.
ISA 330 paras 28–30 and A63.
Professional scepticism
Professional scepticism, introduced earlier in the AAA module in the unit on assurance purpose
and framework, is applicable to all phases of an audit. It is particularly important when
evaluating audit evidence.
ISA 200 para. 13(l) defines professional scepticism as:
… an attitude that includes a questioning mind, being alert to conditions which may indicate possible
misstatement due to error or fraud, and a critical assessment of audit evidence.
CC
Applying professional scepticism requires the auditor to take an objective view when
evaluating audit evidence, and not assume that the evidence will support, or contradict,
management’s assertions.
CC
Required reading
ISA 200 paras 13(l), 15, 17, A18–A22 and A28–A52.
CC
As regards requirement (2), the auditor needs to consider whether concerns about the reliability
of audit evidence will affect other areas of the audit. As the reliability of evidence is linked to
its source, concerns about its reliability will lead the auditor to consider whether other evidence
from the same source needs to be re-evaluated.
CC
Required reading
ISA 500 paras 11 and A57.
ISA 230 para. 11.
Worked example 11.1: Determining if sufficient appropriate audit evidence has been
obtained
[Available online in myLearning]
Activity 11.2: Determining whether sufficient appropriate audit evidence has been obtained
[Located at the end of this unit]
CC
Evaluating misstatements
Learning outcome
3. Evaluate the effect of identified misstatements on the audit, and of uncorrected
misstatements on the financial statements.
A key element of the overall objective of auditing financial statements is to ‘obtain reasonable
assurance about whether the financial statements as a whole are free from material
misstatement’ (ISA 200 para. 11(a)).
Therefore, an important part of evaluating the results of audit procedures and audit
evidence is the identification and evaluation of misstatements. Where the auditor discovers
misstatements and these are not subsequently corrected, the auditor will need to consider these
uncorrected misstatements when forming the audit opinion. Misstatements can also have other
implications for the audit as discussed later in this section. The relevant Standard for evaluating
misstatements is ISA 450.
Definition of ‘misstatement’
‘Misstatement’ is defined in ISA 450 para. 4 as:
… a difference between the amount, classification, presentation, or disclosure of a reported financial
statement item and the amount, classification, presentation, or disclosure that is required for the item to
be in accordance with the applicable financial reporting framework. Misstatements can arise from error
or fraud.
It is important to understand that misstatements do not just arise when an amount is recorded
inaccurately. Misstatements can also relate to:
•• Omitted amounts or disclosures.
•• Incorrect estimates, or estimates that are based on unreasonable assumptions.
•• Treatments that do not follow the accounting policy or Accounting Standard.
•• Judgements made by management on how amounts are presented in the financial
statements.
Examples – Misstatements
Example 1 – Amount recorded in the wrong period
The amount invoiced for a service performed at the start of the 20X4 financial year is recorded
as revenue close to the end of the 20X3 financial year.
Example 2 – Incorrect estimates
The depreciation of items of plant and equipment is based on excessive estimates of each
asset’s useful life.
Example 3 – Treatment that does not follow the Accounting Standard
Research costs are treated as an intangible asset instead of being recognised as an expense, in
contravention of International Accounting Standard IAS 38 Intangible Assets.
Required reading
ISA 200 para. 11(a).
ISA 450 paras 4 and A1.
CC
Audit objectives
Where the auditor identifies misstatements, they must consider the potential impact of these
on the audit. If management does not correct any identified misstatements, the auditor will
also need to evaluate the effect of the uncorrected misstatements on the financial statements
(ISA 450 para. 3).
The following diagram illustrates the decisions the auditor needs to make:
Identify misstatements
NO YES
Required reading
ISA 450 paras 1–3.
Accumulation of misstatements
Auditors track (i.e. document) all misstatements identified throughout the audit process, with
the exception of those that are ‘clearly trivial’ (ISA 450 para. 5). The auditor generally sets an
amount for what constitutes a ‘clearly trivial’ misstatement. Misstatements below this amount
are not recorded.
This record of accumulated misstatements in a single document facilitates both the auditor’s
communications with management and evaluation of the impact of the misstatements on the
financial statements.
The record of accumulated misstatements is known by a number of common names, including
‘summary of misstatements’, ‘potential audit journal entries’ and ‘potential audit adjustments’.
The following is an example:
Description of misstatement W/P Dr Cr Profit or Current Non-current Current Non-current Equity Corrected
ref. loss assets assets liabilities liabilities Yes/No
$ $ Dr/(Cr) $ Dr/(Cr) $ Dr/(Cr) $ Dr/(Cr) $ Dr/(Cr) $ Dr/(Cr) $ Dr/(Cr) $
Page 11-15
Audit & Assurance
Audit & Assurance Chartered Accountants Program
CC
It is important for the auditor to record all misstatements because, ultimately, all uncorrected
misstatements must be evaluated, both individually and in aggregate.
Types of misstatements
ISA 450 suggests that it may be useful to consider misstatements in the following categories,
for the purposes of both evaluating their impact and communicating them to management
(ISA 450 para. A3):
•• Factual misstatements – misstatements about which there is no doubt.
•• Judgemental misstatements – misstatements that arise from subjective decisions made by
management regarding accounting estimates that the auditor considers unreasonable, or the
selection or application of accounting policies that the auditor considers inappropriate.
•• Projected misstatements – the auditor’s best estimate of misstatements in given populations
based on the projection of misstatements from audit samples.
Required reading
ISA 450 paras 5 and A2–A3.
CC
Evaluating the effect of misstatements on the audit is also required by the following Standards:
•• ISA 240 The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
(ISA 240), requires the auditor to evaluate whether each misstatement is indicative of fraud
(ISA 240 para. 35).
•• ISA 315 (Revised) Identifying and Assessing the Risks of Material Misstatement through
Understanding the Entity and Its Environment (ISA 315 (Revised)), requires the
auditor to revise the initial risk assessment as additional audit evidence is obtained
(ISA 315 (Revised) para. 31). For example, frequent misstatements may cause the auditor
to revise the assessed level of risk.
Required reading
ISA 450 paras 3(a), 6–7 and A4–A6.
ISA 240 para. 35.
ISA 315 para. 31.
Communicating misstatements
Misstatements are communicated on two levels, and at two different points in an audit:
1. To management during the audit. Misstatements that are identified by the auditor should
be communicated to the appropriate level of management on a timely basis during the
audit, unless prohibited by law or regulation (ISA 450 para. 8). Timely communication
of misstatements provides management with the opportunity to consider whether the
issues are actually misstatements, and to conduct its own investigations and obtain further
evidence.
2. To those charged with governance during the final stage of the audit. The auditor will
also communicate with those charged with governance (typically, the board of directors)
towards the conclusion of the audit. This communication contains the uncorrected
misstatements – that is, those misstatements that have not been corrected by management
during the audit – and also indicates the effect these uncorrected misstatements may have
on the auditor’s opinion (ISA 450 para. 12).
In both these communications, the auditor must request that the uncorrected misstatements are
corrected in the financial statements.
Required reading
ISA 450 paras 8–9, 12–13, A7–A10 and A21–A23.
CC
Size of a misstatement
In evaluating the size of misstatements, the auditor considers the impact on each class of
transaction, account balance and disclosure, as well as on the financial statements as a whole
(ISA 450 para. 11(a)). This is because misstatements may be material to one item, but not
to another. For example, a misstatement that is not material to the profit before tax may be
material to the disclosure of key management personnel remuneration.
The auditor will use the record of accumulated misstatements to assist with this evaluation.
Refer to the example of a summary misstatements working paper under ‘Accumulation of
misstatements’, above, and see how each misstatement and the aggregate misstatements in the
example have been allocated between the statement of profit or loss, and between the main
components of the statement of financial position. In practice, the auditor will also consider
the impact of misstatements on the amounts and disclosures that make up each of these
components.
Using this approach enables the auditor to consider the effect of misstatements on multiple
elements of the financial statements.
Nature of a misstatement
The auditor should also consider the nature of the uncorrected misstatements and the particular
circumstances of their occurrence (ISA 450 para. 11(a)). In some instances, misstatements can
be material to the financial statements, even if the amount of the misstatement is less than the
amount that has been set for materiality.
This means the auditor will consider matters such as whether a misstatement affects key
financial ratios, contractual covenants or other amounts that users of the financial statements
are likely to focus on. ISA 450 para. A16 lists a number of circumstances that the auditor would
consider when evaluating whether misstatements are material.
Required reading
ISA 450 paras 10–11 and A11–A20.
CC
Example – Previous period misstatements that affect the current financial period
The auditor of Big Toys identified a misstatement in the financial year ended 30 June 20X2. Big
Toys had not recorded an accrued liability for occupancy expenses. The journal required to
correct the misstatement, which was not posted, was:
Dr Cr
$ $
Without recognising this adjustment, both the profit for the 30 June 20X2 financial year and net
assets as at 30 June 20X2 were overstated by $100,000.
The auditor is now completing Big Toys’ audit for the year ended 30 June 20X3. As Big Toys
would have incorrectly recognised the occupancy expense in 30 June 20X3 financial year
instead of 30 June 20X2, occupancy expense in 20X3 is overstated by $100,000. As the profit for
the 30 June 20X2 financial year was overstated, the opening retained earnings for the 30 June
20X3 financial year is also overstated by $100,000.
The following journal would be required to correct the effect of the above misstatement on the
30 June 20X3 financial statements:
Dr Cr
$ $
Required reading
ISA 450 paras 11(b) and A18.
CC
Documentation
As set out in ISA 450 para. 15, the auditor must document:
•• The amount set for ‘clearly trivial’ misstatements.
•• All misstatements found during the audit and whether they have been corrected.
•• The auditor’s conclusion, and the basis for that conclusion, as to whether uncorrected
misstatements are material individually or in aggregate.
Written representations
Considering misstatements involves the auditor interacting with the entity’s management and
those charged with governance. Therefore, in accordance with ISA 450 para. 14, the auditor is
required to:
… request a written representation from management and, where appropriate, those charged with
governance whether they believe the effects of uncorrected misstatements are immaterial, individually
and in aggregate, to the financial statements as a whole.
Required reading
ISA 450 paras 14–15 and A24–A25.
Worked example 11.2: Determining whether sufficient appropriate audit evidence has been
obtained and identifying misstatements
[Available online in myLearning]
Quiz
[Available online in myLearning]
Readings
Required reading
ISA 200 Overall Objectives of the ASA 200 Overall Objectives of ISA (NZ) 200 Overall Objectives of
Independent Auditor and the the Independent Auditor and the the Independent Auditor and the
Conduct of an Audit in Accordance Conduct of an Audit in Accordance Conduct of an Audit in Accordance
with International Standards on with Australian Auditing Standards with International Standards on
Auditing Auditing (New Zealand)
•• Paragraphs 11(a), 13(j)–13(l), 15, •• Paragraphs 11(a), 13(j)–13(l), 15, •• Paragraphs 11(a), 13(j)–13(l), 15,
17, A18–A22 and A28–A52 17, A18–A22 and A28–A52 17, A18–A22 and A28–A52
ISA 230 Audit Documentation ASA 230 Audit Documentation ISA (NZ) 230 Audit Documentation
•• Paragraphs 8–11 and A2–A17 Paragraphs 8–11 and A2–A17 •• Paragraphs 8–11 and A2–A17
ISA 240 The Auditor’s Responsibilities ASA 240 The Auditor’s ISA (NZ) 240 The Auditor’s
Relating to Fraud in an Audit of Responsibilities Relating to Fraud in Responsibilities Relating to Fraud in
Financial Statements an Audit of a Financial Report an Audit of Financial Statements
•• Paragraph 35 •• Paragraph 35 •• Paragraph 35
ISA 315 (Revised) Identifying ASA 315 Identifying and Assessing ISA (NZ) 315 (Revised) Identifying
and Assessing the Risks of the Risks of Material Misstatement and Assessing the Risks of
Material Misstatement Through through Understanding the Entity Material Misstatement Through
Understanding the Entity and Its and Its Environment Understanding the Entity and Its
Environment Environment
•• Paragraph 31 •• Paragraph 31 •• Paragraph 31
ISA 330 The Auditor’s Responses to ASA 330 The Auditor’s Responses to ISA (NZ) 330 The Auditor’s Responses
Assessed Risks Assessed Risks to Assessed Risks
•• Paragraphs 25–30 and A60–A63 •• Paragraphs 25–30 and A60–A63 •• Paragraphs 25–30 and A60–A63
ISA 450 Evaluation of Misstatements ASA 450 Evaluation of ISA (NZ) 450 Evaluation of
Identified During the Audit Misstatements Identified during the Misstatements Identified During the
Audit Audit
ISA 500 Audit Evidence ASA 500 Audit Evidence ISA (NZ) 500 Audit Evidence
•• Paragraphs 4–7, 11, A1–A33 and •• Paragraphs 4–7, 11, A1–A33 and •• Paragraphs 4–7, 11, A1–A33 and
A57 A57 A57
Further reading
ACT
Activity 11.1
Professional scepticism
Introduction
The quality of an audit is important in maintaining market confidence in financial statements.
Professional scepticism is a state of mind that is critical to the performance of quality audits.
This activity will assist candidates to understand the concept of professional scepticism.
This activity links to learning outcomes:
•• Apply the auditor’s requirements if there is inconsistency in, or doubts over, the reliability
of audit evidence.
•• Determine whether sufficient appropriate audit evidence has been obtained on which to
base conclusions and auditor’s reports.
At the end of this activity, you will be able to understand how professional scepticism is
addressed in the International Standards on Auditing (ISAs), and the importance of professional
scepticism in particular circumstances.
It will take you approximately 30 minutes to complete.
Scenario
You are an audit junior at Smith & Smith Chartered Accountants. Your audit manager, Jenny
Chexem, wants to discuss the importance of professional scepticism when performing an audit.
She suggests that you consider this in the context of the audit procedures you would perform
when obtaining evidence to support the key assumptions around cash flows, growth rates and
discount rates that management would use in a discount cash flow model, supporting the fair
value of an asset.
Task
Outline how you would provide evidence that professional scepticism has been appropriately
exercised whilst performing audit procedures on a discounted cash flow forecast to measure the
fair value of an asset.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 11.2
Determining whether sufficient appropriate
audit evidence has been obtained
Introduction
Understanding what constitutes sufficient appropriate audit evidence and using professional
judgement to evaluate audit evidence are both critical to performing audits. Chartered
Accountants should be able to determine whether audit evidence is sufficient and appropriate
to particular circumstances.
This activity links to learning outcomes:
•• Apply the auditor’s requirements if there is inconsistency in, or doubts over, the reliability
of audit evidence.
•• Determine whether sufficient appropriate audit evidence has been obtained on which to
base conclusions and auditor’s reports.
At the end of this activity, you will be able to determine whether sufficient appropriate audit
evidence has been obtained in particular scenarios, whether further evidence is required, and
identify the impact of audit findings on the initial risk assessment, in accordance with ISA 330
The Auditor’s Responses to Assessed Risks (ISA 330) and ISA 500 Audit Evidence (ISA 500).
It will take you approximately 40 minutes to complete.
Scenario
Louiseton Enterprises (LE) is a large private company that designs and builds exhibition display
stands. Tingle & Tangle Chartered Accountants (T&T) has been LE’s auditor for the past three
years. You are an audit senior assigned to the audit of LE’s financial statements for the year
ended 30 June 20X3. The manager assigned to the LE audit is Gaye Blazit. As the audit senior,
one of your responsibilities is to review the working papers of an audit junior, Susan Shoman.
It is September 20X3 and T&T’s audit team is at LE’s offices undertaking the final audit. You
have obtained the following information from discussions with Susan and from reviewing the
audit working papers prepared by her.
ACT
Discussing this procedure, Susan tells you that she examined the cash journal for the months
of July to September 20X3 and noted any receipts from customers in her sample. She expected
accounts to have been settled by September, because LE’s terms of trade are 60 days from
the invoice date. She then listed the receipts in date order until the total receipts equalled or
exceeded the balance at 30 June 20X3. Susan was unable to fully test some of the balances
because they had not all been settled in full at the time she completed the test. She did no
further work.
A169 135,000 190,000 55,000 Discussed with LE’s financial controller. Cheque for
$55,000 was sent on 30.06.X3, and was not recorded by
supplier until 05.07.X3
C112 255,000 295,000 40,000 Discussed with LE’s financial controller. Supplier used
the wrong price on a June delivery of goods and has
agreed that LE will be credited for the difference
ACT
Tasks
Task 1
Gaye asks you to review the audit procedures performed by Susan and evaluate whether
sufficient appropriate audit evidence has been obtained. Where it has not, you have been asked
to identify what further audit evidence should be obtained.
Task 2
Gaye also requests that you determine whether the results of these audit procedures will
increase the risk of material misstatement (RMM), assuming the further audit evidence obtained
confirms the evidence in the working papers to date. Where the RMM is increased, you should
identify the key assertions at risk and outline the impact on the audit, including additional
audit procedures (or increases in extent).
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 11.3
Evaluating the impact of uncorrected
misstatements
Introduction
Where misstatements identified during the audit are not corrected, the auditor must determine
whether these uncorrected misstatements are material to the financial statements. Chartered
Accountants working on audits will be involved in evaluating misstatements as part of forming
the audit opinion.
This activity links to learning outcome:
•• Evaluate the effect of identified misstatements on the audit, and of uncorrected
misstatements on the financial statements.
At the end of this activity, you will be able to determine whether uncorrected misstatements are
material, individually or in aggregate, in accordance with ISA 450 Evaluation of Misstatements
Identified during the Audit (ISA 450).
It will take you approximately 30 minutes to complete.
Scenario
You are an audit senior at Bean and Sons Chartered Accountants (Bean) currently working on
the audit of Lanvale Fashion (LF) for the year ended 30 June 20X3.
LF is a listed company involved in the manufacture and sale of licensed fashion goods in
Australia and New Zealand. LF has outsourced its manufacturing to suppliers in China. When
LF’s suppliers load the manufactured goods on the ship, the risks and rewards related to the
goods transfer to LF. The suppliers ship the fashion goods from the port of Shangdong to LF’s
warehouse and distribution centre in Sydney. Shipping times are typically six weeks. Once the
goods are received in Sydney, inspected by LF’s quality control department and checked into the
warehousing stock control system, approval is given to accounts payable to pay the supplier’s
invoice in full, provided the quantities and quality are as per the invoice and the purchase order.
LF orders its inventory for each season on the basis that the stock needs to be in its distribution
warehouse two weeks prior to going on sale at its 250 retail stores. As a fashion company, LF’s
inventory is seasonal, manufacturing for two seasons a year – summer and winter. Stock for
each season is refreshed with new styles twice a season.
Matter 1
On 30 June 20X3, you attended the stocktake of LF at its Sydney distribution centre. During the
stocktake, you observed that there were 4,400 items of stock with an ageing in excess of 365 days
and carried at a cost of $204,540. In addition, there were a further 940 items of stock with an
ageing of 180 to 364 days at a cost of $68,000. The warehouse manager confirmed that stock in
excess of 365 days is unlikely to be sold and stock in excess of 180 days will be sold at half of its
cost price. Bean has performed audit procedures to check LF’s management’s assessment of the
net realisable value of these slow-moving items and agrees with the warehouse manager’s view.
However, in the year-end financial statements, management has not written down the aged
stock to its net realisable value.
ACT
Matter 2
On 1 January 20X3, an office insurance premium of $248,082 was paid for the 12 months ending
31 December 20X3. You note that this full amount still appears in prepayments at 30 June 20X3
and therefore represents a misstatement.
Matter 3
Your testing of depreciation expense for the financial year shows that the depreciation expense
relating to plant and equipment is understated by $195,000.
Further audit procedures have confirmed that the above matters are the misstatements arising
and did not identify any additional misstatements.
LF’s management has not changed the financial statements to reflect the above matters. Selected
line items from LF’s statement of profit or loss and statement of financial position are shown
below:
Cash 2,658,567
Inventory 11,000,000
Prepayments 7,000,940
ACT
Task
For this activity, you are required to determine whether the misstatements are material,
individually or in aggregate, from a quantitative perspective by completing a summary of
misstatements (SOM) for the year ended 30 June 20X3.
In completing the above task, you are required to comply with Bean’s audit manual guidelines
in relation to evaluating whether misstatements are material from a quantitative perspective, as
follows:
CC
Core content
Unit 12: Responding to assessed risk – using
the work of others, external confirmations
and written representations
Learning outcomes
At the end of this unit you will be able to:
1. Demonstrate an understanding of the auditor’s use of external confirmation procedures to
obtain relevant and reliable audit evidence.
2. Demonstrate an understanding of the purpose of written representations and the
objectives of an auditor in obtaining written representations from management.
3. Explain the special considerations that apply to group audits, in particular those that
involve component auditors.
4. Demonstrate the steps involved in determining whether and to what extent an external
auditor can use the work of internal auditors.
5. Explain the auditor’s responsibilities relating to using the work of an expert.
Introduction
The first part of this unit describes two important sources of audit evidence:
•• External confirmations, which are generally considered to be reliable audit evidence, being
obtained from independent sources outside the entity.
•• Written representations, which are particularly important when considered in conjunction
with other audit evidence. Management is required to provide written representations as
part of every audit engagement.
The second part of this unit describes the audit procedures to be carried out when using the
work of others, namely another auditor, an internal auditor or an expert. Regardless of whether
the work of these other auditors or experts is used or not, the principal auditor retains sole
responsibility for the auditor’s opinion expressed.
This unit addresses the requirements of the following International Standards on Auditing
(ISAs):
•• ISA 505 External Confirmations (ISA 505).
•• ISA 580 Written Representations (ISA 580).
aaa11612_csg
CC
•• ISA 600 Special Considerations – Audits of Group Financial Statements (Including the Work of
Component Auditors) (ISA 600).
•• ISA 610 (Revised 2013) Using the Work of Internal Auditors (ISA 610 (Revised)).
•• ISA 620 Using the Work of an Auditor’s Expert (ISA 620).
External confirmations
Learning outcome
1. Demonstrate an understanding of the auditor’s use of external confirmation procedures to
obtain relevant and reliable audit evidence.
An effective audit plan is based on an appropriate mix of tests of controls and substantive
procedures that collectively reduce audit risk to an acceptably low level. There are a number of
substantive audit procedures that can be undertaken to address audit risk at the assertion level.
This section addresses the use of external confirmations as a substantive procedure to obtain
relevant and reliable audit evidence, as described in ISA 505.
The reliability of audit evidence is influenced by both its source and its nature. Under
ISA 505 para. 2, audit evidence is considered to be more reliable when it is:
•• Obtained from independent sources outside the entity.
•• Obtained directly by the auditor, rather than indirectly.
•• In documentary form, whether paper, electronic or other medium.
Accordingly, external confirmations, being ‘audit evidence obtained as a direct written response
to the auditor from a third party (the confirming party), in paper form, or by electronic or other
medium’ (ISA 505 para. 6(a)), may be more reliable than evidence that is generated internally by
the entity.
An example of a positive confirmation is a bank confirmation request, where the auditor asks
the bank to confirm the audited entity’s account balances that are held by the bank at year end.
The auditor may also request confirmation of other information, such as securities and leases
held, accounts opened and/or closed during the year, lists of authorised signatories, as well as
unused limits/facilities and breaches of those facilities.
CC
(b) The population of items subject to negative confirmation procedures comprises a large number of
small, homogeneous account balances, transactions or conditions;
(d) The auditor is not aware of circumstances or conditions that would cause recipients of negative
confirmation requests to disregard such requests.
Required reading
ISA 505 paras 1–6, 15 and A23.
(c) Designing the confirmation requests, including determining that requests are properly addressed
and contain return information for responses to be sent directly to the auditor; and
(d) Sending the requests, including follow-up requests when applicable, to the confirming party.
External confirmation procedures are commonly used to provide relevant audit evidence of:
•• Bank balances and other information relevant to banking relationships.
•• Accounts payable and receivable balances and terms.
•• Inventories held by third parties or on consignment.
•• Property title deeds held by the entity’s lawyers or financiers for safe custody or as security.
•• Investments held for safekeeping by third parties.
•• Amounts owed to lenders, including the relevant terms of repayment and any restrictive
covenants.
CC
Australia-specific
The AUASB has issued a Guidance Statement, GS 016 ‘Bank Confirmation Requests’ (GS 016),
which provides guidance to ‘auditors on the enquiry and confirmation methods for obtaining
audit evidence regarding an entity’s bank accounts and transactions’.
Major Australian banks, such as Westpac and National Australia Bank, are using the online
audit confirmation service Confirmation.com to provide customers and their auditors with an
efficient and secure solution for obtaining audit confirmations. Confirmation.com is the world’s
leading provider of online audit confirmations and is widely used by the international banking
and audit industry. More information can be found on the Confirmation.com website at www.
confirmation.com.
Account Dr (Cr)
$
Inventories 317,000
Land 66,000
Borrowings (350,000)
Sales (3,130,000)
CC
Cash at bank Existence, All banks and Account balances at year end (including current
completeness, other financial accounts, interest-bearing deposits, foreign
valuation and institutions currency accounts and money market deposits)
allocation used by the
Accounts opened and closed by the entity
entity
during the period
Authorised signatories to the accounts
Used and unused facilities
In this example, the auditor would not send out external confirmation requests for information
on the following:
Inventories There is no inventory consignment as at year end – that is, all inventory is
held by the entity. Therefore, there is no external party that can confirm the
inventory balances
Land The key assertions at risk for land, buildings, and plant and equipment
would be existence and valuation and allocation. For significant balances
Buildings generally the entity obtains an independent valuation, and the auditor
Plant and equipment will evaluate this valuation. The auditor could engage an expert valuer to
provide an independent valuation of these assets, but would not request
external confirmation
CC
Are responses reliable? If factors give rise to doubts about the reliability of a response:
•• Obtain further audit evidence to resolve or confirm these doubts
•• Consider fraud and other issues that impact on assessed risks; and
•• Investigate exceptions to determine if these are indicative of misstatements
When no response is Perform alternative audit procedures (if possible) to obtain relevant and reliable
received audit evidence
Evaluate overall results Did the external confirmation procedures provide the relevant and reliable
audit evidence required? If the confirming party disagrees with the balance
then alternative audit procedures will be required to determine what the correct
balance is
Adapted from: Australian audit manual and toolkit 2015 for small and medium sized entities, Exhibit 8.3–2, pp. 130–1.
If the auditor determines that a positive confirmation request is necessary to obtain sufficient
appropriate audit evidence, and alternative audit procedures will not provide the required
audit evidence, the auditor needs to determine the implications this will have for the audit and
the auditor’s opinion if this confirmation is not received (ISA 505 para. 13).
Required reading
ISA 505 paras 7–14, 16, A1–A22 and A24–A25.
CC
If the auditor concludes that management’s refusal is unreasonable, or they cannot obtain
relevant and reliable audit evidence from other audit procedures, the auditor must
communicate this to those charged with governance, pursuant to ISA 260 Communication with
Those Charged with Governance (ISA 505 para. 9).
Required reading
ISA 505 paras 8–9 and A8–A10.
Written representations
Learning outcome
2. Demonstrate an understanding of the purpose of written representations and the objectives
of an auditor in obtaining written representations from management.
Management and the auditor agree on the terms of the audit engagement prior to the
commencement of an audit. These terms include management’s responsibilities, as set out in
ISA 210 Agreeing the Terms of Audit Engagements (ISA 210). One of these responsibilities is to
provide written representations to the auditor in respect of the audit.
A written representation is a ‘written statement by management provided to the auditor to
confirm certain matters or to support other audit evidence’ (ISA 580 para. 7). The written
representation usually takes the form of a letter addressed to the auditor (ISA 580 para. 15).
This section addresses the auditor’s responsibility to obtain such written representations from
management as audit evidence. It should be noted that while written representations provide
‘necessary audit evidence’, they ‘do not provide sufficient appropriate audit evidence on their
own’ (ISA 580 para. 4). They should therefore be considered in combination with other evidence
obtained.
The auditor requests written confirmations from management which state that management
‘believe that they have fulfilled their responsibility for the preparation of the financial
statements and for the completeness of the information provided to the auditor’ and ‘to support
other audit evidence’ (when considered necessary by the auditor or as required by other ISAs)
(ISA 580 paras 6(a) and (b)).
The auditor must ‘respond appropriately’ to written representations that are provided by
management, or when management does not provide the requested written representations
(ISA 580 para. 6(c)).
CC
The written representation letter should be obtained ‘as near as practicable to, but not after,
the date of the auditor’s report on the financial statements’. It should cover all the financial
statements and period(s) that are referred to in the auditor’s report (ISA 580 para. 14).
Written management representations are audit evidence, but cannot be used as:
•• A substitute for performing other audit procedures.
•• The sole source of evidence on significant audit matters.
Required reading
ISA 580 paras 1–9, 14–15, A1–A6, A15–A21 and Appendix 2.
In Australia, the Corporations Act 2001 (Cth) (Corporations Act) requires management to provide
all requested information, explanations and assistance to auditors for the purpose of financial
statements audit (Corporations Act s. 312).
The auditor must ask those in management who are responsible for the preparation and
presentation of the financial statements and have knowledge of the matters involved, to provide
written representations (ISA 580 para. 9). Usually, this will be the entity’s chief executive
officer and the chief financial officer, or others with an equivalent level of responsibility
(ISA 580 para. A2), such as the owner-manager.
In New Zealand, the auditor must request written representations from those charged with
governance with appropriate responsibilities for the financial statements and knowledge of the
matters concerned (ISA (NZ) 580 para 9.1).
Required reading
ISA 580 paras 9–12, A2, A7–A9, A14 and A22.
CC
written representations to support ‘other audit evidence’ that is pertinent to the financial
statements, or to specific assertion(s) in the financial statements (ISA 580 para. 13).
These other written representations include those required:
•• under ISAs other than ISA 580, and
•• to support other audit evidence.
ISA Specific
paragraphs
ISA 540 Auditing Accounting Estimates, Including Fair Value Accounting Estimates, and Related 22
Disclosures
•• Communication to the auditor of all the entity’s reasons for choosing a particular course of
action.
•• Management’s plans or intentions in relation to specific matters regarding the financial
statements.
Required reading
ISA 580 paras 13, A10–A13, A22 and Appendix 1.
CC
The following table outlines the appropriate responses required of the auditor in respect of
management’s written representations:
Management Evaluate the integrity of the written representations by: Paras 16, 18 and
provides the 20(a)
•• Considering whether the person making the representation is
requested
expected to be objective and knowledgeable on the subject matter
written
representations •• Assessing whether the representation is reasonable in light of the
auditor’s understanding of the entity and its environment, and other
evidence obtained
•• Considering whether further audit procedures are required to
corroborate the representations (e.g. to corroborate management’s
intent and consider sources of evidence, such as minutes of directors’
meetings, minutes of investment committees, legal documents or
internal correspondence and emails)
•• In the event that the auditor determines that management is
incompetent or lacking integrity or ethical values, the auditor should:
–– Determine the effect that such concerns may have on the reliability
of representations (oral or written) and audit evidence in general
–– Disclaim an opinion on the financial statements where they
conclude that ‘there is sufficient doubt about the integrity of
management’ to show that the required written representations
cannot be relied on
Management •• Perform additional audit procedures to attempt to resolve the matter Para. 17
representations •• If the matter remains unresolved, reconsider the assessment of the
are inconsistent competence, integrity, ethical values or diligence of management,
or contradict or of management’s commitment to or enforcement of these,
other audit and determine the effect that this may have on the reliability of
evidence representations (oral or written) and the audit evidence in general
obtained
•• Determine whether there is reason to doubt management’s integrity.
If so, discuss the matter with those charged with governance and
consider the impact on the risk assessment as well as the need for
further audit procedures
•• Consider whether continued reliance on any other management
representations is appropriate
Adapted from: Australian audit manual and toolkit 2015 for small and medium sized entities, pp. 588–93.
Required reading
ISA 580 paras 16–20 and A23–A27.
CC
Group audits
Learning outcome
3. Explain the special considerations that apply to group audits, in particular those that involve
component auditors.
In engagements where the audited entity comprises of one or more divisions, branches or
subsidiaries (components), the group engagement team may need the audit work to be
undertaken by several different auditors. ISA 600 provides requirements for when an auditor
decides to use the work of another auditor in the audit of group financial statements.
Required reading
ISA 600 paras 1–16 and A1–A22.
Group audit procedures for significant components will differ from those used for components
that are not identified as significant.
CC
Materiality
Materiality in a group audit will be set for the whole group and for particular classes of
transactions, account balances or disclosures – just as it would in any audit of financial
statements. In addition, the group auditor will set ‘component materiality’, which is the
materiality level that component auditors will use in performing an audit or review of the
component’s financial information for the purposes of a group audit (this may be a different
figure to the one they might use when performing an audit under local reporting requirements).
The component materiality will be less than the materiality set for the group. The group auditor
will also advise the materiality level above which misstatements could not be regarded to be
clearly trivial (ISA 600 para. 21).
Procedures
The auditor is required to design procedures to address the risks of material misstatement
identified in the financial statements. In a group engagement, it is the group auditor who
determines the work that will be performed by the component auditors.
For a significant component, under ISA 600 para. 27 this could involve:
•• An audit of the financial information of the component using component materiality.
•• An audit of specified account balances at period end, classes of transactions or disclosures.
•• Specified audit procedures.
This differs from audit work that may need to be performed to meet any statutory or reporting
obligations of the component.
When an audit of the financial information of a component is performed, the group auditor
would be involved in the risk assessment to understand its potential implications for the group
financial statements (ISA 600 para. 30).
For components that are not significant, the group engagement team should perform, at a
minimum, analytical procedures at a group level, although it may still be necessary to perform
further procedures depending on the requirements for evidence on which to base the group
audit opinion (ISA 600 paras 28 and 29).
When significant risks of material misstatement are identified in a component, it is the group
auditor who determines the appropriateness of further audit procedures (ISA 600 para. 31).
Both the group auditor and the component auditor shall perform procedures to identify
subsequent events that might require adjustment of, or disclosure in, the group financial
statements (ISA 600 paras 38 and 39).
(c) Whether the group engagement team will be able to be involved in the work of the component
auditor to the extent necessary to obtain sufficient appropriate audit evidence.
(d) Whether the component auditor operates in a regulatory environment that actively oversees
auditors.
If the group auditor has any concerns about the component auditor’s ethics, competence or
independence, they shall not request the component auditor to perform work (ISA 600 para. 20).
CC
In order to rely on a component auditor’s work, the group auditor should review the main
conclusions drawn in the component auditor’s working papers and discuss the significant
matters they have identified. The group auditor’s review should focus on areas relative to the
significant risks of material misstatement in the group financial statements.
If the group auditor is concerned that a component auditor has not been able to gather sufficient
appropriate audit evidence, the group auditor shall determine what additional procedures are
to be performed and whether they shall be performed by the component auditor or the group
engagement team (ISA 600 para. 43).
It is the group engagement partner’s responsibility to evaluate the effect on the group audit
opinion of any uncorrected misstatements, and of any instances in which sufficient appropriate
audit evidence has not been obtained (ISA 600 para. 45).
The group engagement team is required to document its interactions with the component
auditors. Information that should be documented includes the analysis of whether a component
is significant, the type of work required on the component financial information and written
communications about the group engagement team’s involvement (ISA 600 para. 50).
Required reading
ISA 600 paras 17–31, 38–50, A23–A55 and A57–A66.
CC
Consolidation process
The auditor is required to identify and assess risks of material misstatement. In order to achieve
this in a group audit, the auditor must consider the consolidation process in addition to the
audit of each component.
In this regard, the auditor is required to understand, and consider the impact on the audit
procedures of, the following:
•• The consolidation process, including group management’s instructions issued to the
components (ISA 600 para. 17(b)).
•• Group-wide controls and their impact on the audit plan (ISA 600 paras 17(a) and 32).
•• Whether all components have been included in the consolidation process (ISA 600 para. 33).
•• Consolidation adjustments and reclassifications (ISA 600 para. 34).
•• The consistency of accounting policies across the group (ISA 600 para. 35).
•• The impact of a component that has a different reporting period end to the group
(ISA 600 para. 37).
Required reading
ISA 600 paras 17, 32–37 and A56.
Required reading
ISA 600 paras 46–49 and A64–A66.
Activity 12.3: Using the work of component auditors in audits of group financial statements
[Located at the end of this unit]
CC
Learning outcome
4. Demonstrate the steps involved in determining whether and to what extent an external
auditor can use the work of internal auditors.
In larger entities, an internal audit department is often established to monitor the effectiveness
of various aspects of their operations. Some of the work performed by this internal audit
function may be relevant to an entity’s external auditor. This may mean that the external
auditor could modify the nature and timing of their own audit procedures, or reduce the extent
of the audit procedures that they plan to perform, and instead rely on the work of the internal
audit function. ISA 610 (Revised) outlines when it is permissible to utilise the work of internal
auditors and, if so, to what extent.
Even when using the work of internal audit, the external auditor remains solely responsible for
the audit opinion that is expressed in the auditor’s report on the financial statements.
Required reading
ISA 610 (Revised) paras 1–14 and A1–A4.
Assessing whether and to what extent an external auditor can use the work of
internal audit
Before any specific review of detailed work performed by internal audit, the external auditor
has to determine ‘whether the work of the internal audit function can be used, and if so, in
which areas and to what extent’ (ISA 610 (Revised) para. 13(a)).
Objectivity of the •• The status of the internal audit function within the entity, and the effect this status
internal audit function has on the ability of the internal auditors to be free from bias, conflict of interest or
undue influence of others
(ISA 610 (Revised)
para. A7) •• Whether the internal audit function reports to those charged with governance or
an officer with appropriate authority, or to management, and whether it has direct
access to those charged with governance
•• Whether internal audit is free of any conflicting responsibilities
•• Whether those charged with governance have oversight of employment decisions
that are related to the internal audit function
•• Whether management or those charged with governance place any constraints or
restrictions on the internal audit function
•• Whether the internal auditors are members of relevant professional bodies that
oblige them to comply with relevant professional standards relating to objectivity
CC
Use of a systematic •• Whether there are documented procedures which address risk assessments, work
and disciplined programs, documentation and reporting, which are appropriate to the size and
approach (including circumstances of the entity
quality control) •• Whether there are appropriate quality control policies and procedures
(ISA 610 (Revised)
para. A11)
The auditor should not use the work of the internal audit function if it has concerns about any
of these factors.
Required reading
ISA 610 (Revised) paras 15–16 and A5–A14.
Determining the nature and extent of the work that can be used
After assessing the internal audit function, the external auditor then needs to assess the
nature and scope of the work it performs and consider how that relates to the audit plan. As
the external and internal audit functions work to different objectives, the work performed by
internal audit may not provide the evidence that is required by the external auditor.
The external auditor is required to make all significant judgements during the audit
engagement, and would need to adjust their level of reliance on the work of internal audit if:
•• there is an increased risk of material misstatement at the assertion level
•• a significant judgement is involved in planning or performing audit procedures, or in
evaluating the evidence obtained, or
•• there is the potential for either the objectivity or competency of the internal audit team to be
compromised (ISA 610 (Revised) para. 18).
ISA 610 para. A16 provides examples of work performed by the internal audit function that
could be used by the external auditor. These include:
•• Testing the operating effectiveness of the entity’s controls.
•• Conducting substantive procedures that involve the application of limited judgement.
•• Observing inventory counts.
•• Tracing transactions that are relevant to the entity’s financial reporting through its
information system.
•• Testing the entity’s compliance with statutory and regulatory requirements.
Required reading
ISA 610 (Revised) paras 17–20 and A15–A23.
CC
The level of work the external auditor would perform requires professional judgement and
should reflect the assessed risk of material misstatement, and their assessment of the objectivity
and competency of the internal audit function.
The diagram below summarises the key requirements of ISA 610 (Revised), and illustrates the
audit procedures required by the external auditor in considering using the work of internal
audit.
NO
Adapted from: Australian audit manual and toolkit 2015 for small and medium sized entities, Exhibit 13.8–1, p. 224.
Required reading
ISA 610 (Revised) paras 21–25, 36 and A24–A30.
Activity 12.4: Assessing the adequacy of internal audit work for use in the financial
statements audit
[Located at the end of this unit]
CC
Direct assistance
In some jurisdictions where it is not prohibited by law or regulation, an external auditor may
obtain ‘direct assistance from internal auditors’. Direct assistance is defined as ‘the use of
internal auditors to perform audit procedures under the direction, supervision and review of
the external auditor’ (ISA 610 para. 14(b)). ISA 610 paras 27–35 and 37 provide specific guidance
on the use of internal auditors to provide direct assistance.
Note that the Australian Auditing Standards prohibit the use of internal auditors to provide
direct assistance in an audit or review of financial statements. The New Zealand Auditing
Standards allow the use of internal auditors to provide direct assistance in line with the
international Standard.
Required reading
ISA 610 paras 14(b) and 26.
CC
Learning outcome
5. Explain the auditor’s responsibilities relating to using the work of an expert.
For certain engagements, an auditor may require expertise outside of accounting or auditing,
in order to obtain sufficient appropriate audit evidence. This may involve using the work of an
auditor’s expert, who would provide audit evidence in the form of reports, opinions, valuations
and/or statements.
It is important to note that even when the work of an expert is used, the auditor retains sole
responsibility for the audit opinion expressed.
ISA 620 outlines the process the auditor must follow when considering using the work of an
expert as audit evidence.
Reporting
Adapted from: Australian audit manual and toolkit 2015 for small and medium sized entities, Exhibit 13.9–1, p. 229.
Examples of areas in which the auditor may need to consider using the work of an expert
include:
•• Valuations of assets, such as land and buildings, plant and machinery, works of art, precious
stones, inventory and complex financial instruments.
•• Determination of quantities or the physical condition of assets, such as stockpiles of stored
minerals, underground mineral and petroleum reserves, and the remaining useful life of
different pieces of plant and machinery.
CC
•• Determination of amounts using specialised techniques or methods, such as actuarial
valuation.
•• Analysis of complex or unusual tax compliance issues.
•• Measurement of work completed, and to be completed, on contracts in progress.
•• Specialised inventory counters.
•• Legal opinions concerning interpretations of agreements, statutes and regulations.
Required reading
ISA 620 paras 1–6 and A1–A3.
Engaging an expert
Audit considerations regarding engaging an auditor’s expert are summarised in the flow chart
and table below:
Is an expert needed to
YES
obtain audit evidence?
NO
Does the auditor understand
the expert’s field of expertise? YES
NO
Agree on the terms
of the engagement
NO
Adapted from: Australian audit manual and toolkit 2015 for small and medium sized entities, Exhibit 13.9–4, p. 232.
Is an expert needed The auditor should consider the need for an expert in relation to:
to obtain audit
•• Obtaining an understanding of the entity, including its internal control(s)
evidence?
•• Identifying/assessing the risks of material misstatement
(ISA 620 paras 7 and
•• Determining/implementing overall responses to assessed risks at the financial
A4–A9)
statement level
•• Designing/performing further audit procedures to respond to assessed risks at the
assertion level
•• Evaluating the sufficiency/appropriateness of audit evidence obtained in order to
form an opinion
CC
Is the chosen expert The auditor should consider the following issues in relation to the expert:
competent, capable,
•• Competence, which relates to the nature and level of expertise of the auditor’s
and objective?
expert
(ISA 620 paras 9 and •• Capability, which relates to the ability of the auditor’s expert to exercise that
A14–A20) competence in the circumstances of the engagement (e.g. the expert’s geographic
location, and the availability of time and resources)
•• Objectivity, which relates to the possible effect that bias, conflict of interest, or the
influence of others may have on the professional or business judgement of the
auditor’s expert
Other factors to consider include:
•• The auditor’s personal experience with previous work by the expert
•• Discussions with the expert
•• Discussions with others that are familiar with the expert’s work
•• Knowledge of the expert’s qualifications, membership of a professional body or
industry association, licence to practice, or other forms of external recognition of
the expert
•• Published papers or books by the expert
•• The audit firm’s quality control policies and procedures
Does the auditor The auditor must consider whether they have sufficient understanding of the expert’s
understand the field of work to:
expert’s field of
•• Plan the audit
expertise?
•• Review the results of work performed
(ISA 620 paras 10 and
A21–A22)
Agree on the terms of In establishing the terms of the engagement, the auditor must consider factors such
the engagement as:
(ISA 620 paras 11 and •• Access of the expert to sensitive or confidential entity information
A23–A31) •• The respective roles or responsibilities of the auditor and the auditor’s expert
•• Any multi-jurisdictional legal or regulatory requirements
•• The complexity of the work involved
•• The expert’s previous experience(s) with the entity
•• The extent of the expert’s work, and its significance in the context of the audit
The written agreement should address the:
•• Nature, scope, and objectives of the expert’s work
•• Respective roles and responsibilities
•• Nature, timing, and extent of communication, including the report format
•• Need for confidentiality
•• Appendix to ISA 620, which sets out matters that the auditor may consider for
inclusion in any written agreement with an auditor’s external expert
Adapted from: Australian audit manual and toolkit 2015 for small and medium sized entities, Exhibit 13.9–4, pp. 232–4.
Required reading
ISA 620 paras 7–11 and A4–A31.
CC
If the results of the expert’s work are unsatisfactory or inconsistent with other audit evidence,
the auditor can resolve the matter through one or more of the following courses of action, as
appropriate:
•• Having discussions with the entity and the expert.
•• Performing additional audit procedures.
•• Engaging another expert.
•• Modifying the auditor’s report.
Required reading
ISA 620 paras 12–13 and A32–A40.
Reporting considerations
ISA 620 para. 14 specifies that an auditor’s report containing an unmodified opinion should not
refer to the work of an expert.
However, if the auditor decides to issue a modified auditor’s opinion, it may be appropriate to
refer to, or describe the work of, the expert in order to explain the nature of the modification.
In these circumstances, the auditor would obtain the permission of the expert before making
such a reference. If permission is refused and the auditor believes a reference is necessary, the
auditor may need to seek legal advice (ISA 620 paras 15 and A42).
Required reading
ISA 620 paras 14–15 and A41–A42.
Quiz
[Available online in myLearning]
Readings
Required reading
ISA 505 External Confirmations ASA 505 External Confirmations ISA (NZ) 505 External Confirmations
ISA 580 Written Representations ASA 580 Written Representations ISA (NZ) 580 Written Representations
ISA 600 Special Considerations— ASA 600 Special Considerations— ISA (NZ) 600 Special Considerations –
Audits of Group Financial Audits of a Group Financial Report Audits of Group Financial Statements
Statements (Including the Work of (Including the Work of Component (Including the Work of Component
Component Auditors) Auditors) Auditors)
•• Paragraphs 1–50 and A1–A66 •• Paragraphs 1–50 and A1–A66 •• Paragraphs 1–50 and A1–A66
ISA 610 (Revised 2013) Using the ASA 610 Using the Work of ISA (NZ) 610 (revised 2013) Using the
Work of Internal Auditors Internal Auditors Work of Internal Auditors
•• Paragraphs 1–26, 36 and •• Paragraphs 1–26, 36 and •• Paragraphs 1–26, 36 and A1–A30
A1–A30 A1–A30
ISA 620 Using the Work of an ASA 620 Using the Work of an ISA (NZ) 620 Using the Work of an
Auditor’s Expert Auditor’s Expert Auditor’s Expert
•• Paragraphs 1–15 and A1–A42 •• Paragraphs 1–15 and A1–A42 •• Paragraphs 1–15 and A1–A42
Further reading
References
The following sources were referred to in the preparation of content for this unit:
•• Chartered Accountants Australia and New Zealand 2015, Australian audit manual and
toolkit 2015 for small and medium sized entities, (5th Edition) Thomson Reuters (Professional)
Australia.
•• GS 016 ‘Bank Confirmation Requests’.
•• Corporations Act 2001 (Cth).
ACT
Activity 12.1
Obtaining audit evidence using external
confirmations
Introduction
The role of the auditor includes obtaining sufficient appropriate audit evidence in order to draw
conclusions on which to base their auditor’s opinion. External confirmations generally provide
evidence which is more reliable than internally generated evidence, as they are obtained from
independent sources directly by the auditor.
This activity links to learning outcome:
•• D
emonstrate an understanding of the auditor’s use of external confirmation procedures to
obtain relevant and reliable audit evidence.
At the end of this activity, you will be able to design confirmation requests, assess the
results of external confirmation procedures, evaluate the evidence obtained and respond to
management’s refusal to send requests, in accordance with ISA 505 External Confirmations
(ISA 505).
It will take you approximately 45 minutes to complete.
Scenario
You are an audit senior at Anston & West (A&W), currently working on the 30 June 20X3
financial statements audit of Kanon Bros Limited (Kanon), an abattoir. As one of the largest
cattle abattoirs in the country, Kanon supplies meat to both the major supermarket chains as
well as a large number of butcher shops.
Kanon buys the majority of the cattle it requires and sends them directly to the abattoir for
slaughter. However, it also maintains its own livestock for breeding. The livestock is held on
two third-party owned and managed breeding farms, where the calves are grass-fed for a
period of 45–60 days before being transferred to the abattoir.
Trading conditions for Kanon have been challenging, with weather conditions such as drought
and flood impacting on the price of beef. Purchasing cattle has become very expensive and this
cost is being reflected in the retail selling price of beef products. As a result, consumers have
been substituting beef with other, more affordable meat products. Kanon management receives
bonuses based on the achievement of sales and profit targets for the year.
Your audit manager, Chuck Danson, has provided you with the audit plan which indicates that
accounts receivable and inventory – livestock are material balances. A&W plans to use external
confirmation procedures to obtain audit evidence for both these accounts.
ACT
You have discussed the confirmation process for the two account balances with Kanon’s
financial controller, Tim Kang. Tim has indicated that:
•• For accounts receivable – it would be a ‘waste of time’ sending confirmation requests to
the major supermarkets as they will not respond, but he is happy to organise confirmation
requests to be sent out to a number of butcher shops. He has warned you that not all of the
butcher shop owners will respond, and that for those who do, some confirmations will not
match Kanon’s records. Tim believes that this is because they are small business owners
who do not have the resources to maintain up-to-date accounting records.
•• For inventory – livestock – he does not want to send a confirmation request to one of the
property owners as they are under significant pressure due to a drought affecting their
property. Tim has already arranged for a confirmation from the other property, and he has
provided a copy of the confirmation to you.
Tasks
For this activity, you are required to:
1. Determine whether sending external confirmation requests provides sufficient appropriate
audit evidence that the accounts receivable and inventory – livestock balances are not
materially misstated at 30 June 20X3.
2. For the account receivable – external confirmation requests, outline the information that
should be included.
3. Discuss how you would respond to Tim’s comments on the livestock confirmations.
4. Describe any other audit procedures you believe will be required for accounts receivable.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 12.2
Requesting written representations from
management
Introduction
Auditors are required to request written representations from management as part of their
gathering of audit evidence. The written representations from management may cover many
aspects of the preparation of the financial statements, internal control or specific assertions. This
activity deals with the requirements of these written representations.
This activity links to learning outcome:
•• Demonstrate an understanding of the purpose of written representations and the objectives
of an auditor in obtaining written representations from management.
At the end of this activity, you will be able to outline the written representations that the auditor
should request from management or those charged with governance, in accordance with
ISA 580 Written Representations (ISA 580).
It will take you approximately 20 minutes to complete.
Scenario
You are an audit senior at Beecham Accountants (Beecham) and currently finalising the audit
for the year ended 30 June 20X3 of TWB Limited (TWB), a manufacturer and distributor of
bathroom and kitchen fittings. Under instructions from your audit manager, you requested
from TWB’s management a written representation that it has fulfilled its responsibilities in
regard to preparing the financial statements and that it has provided Beecham with access to
information as was agreed in the terms of the engagement.
TWB’s chief financial officer (CFO), Toby Smith, drafted a representation letter which includes
the following details:
Management has fulfilled its responsibilities, as set out in the terms of the audit engagement
letter dated 28 February 20X3, for the preparation of the financial statements in accordance
with International Financial Reporting Standards. In particular, the financial statements are
fairly presented in accordance therewith.
All transactions have been recorded in the accounting records and are reflected in the
financial statements.
We have disclosed to you all information in relation to fraud or suspected fraud that we are
aware of and that affects the entity and involves:
•• Management;
•• Employees who have significant roles in internal control; or
•• Others where the fraud could have a material effect on the financial statements.
Toby joined TWB part-way through the period to which the financial statements relate and has
indicated that he can only make representations for the period subsequent to his appointment.
He is the only member of TWB’s management who is required to sign the representation letter,
and will only provide the letter to you once you have provided the auditor’s report for the year
ended 30 June 20X3.
ACT
Task
For this activity, you are required to review Toby Smith’s proposed inclusions in the draft
management representation letter.
Outline any amendments to the letter and other factors that need to be addressed under
guidance from ISA 580. Cite references to support your answer.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 12.3
Using the work of component auditors in
audits of group financial statements
Introduction
Many entities prepare financial statements on a group, rather than an individual, basis
(e.g. a head company with one or more subsidiaries and/or associates). The group auditor
(or group audit engagement team) is responsible for obtaining sufficient appropriate audit
evidence regarding the components (e.g. the subsidiaries) of the group financial statements
as well as the consolidation process. They will often use component auditors to do this,
particularly if the components are in different geographical locations. The use of component
auditors requires the group auditor to communicate clearly with the component auditors about
the timing and scope of their work, as well as their findings.
This activity links to learning outcome:
•• Explain the special considerations that apply to group audits, in particular those that
involve component auditors.
At the end of this activity, you will be able to outline the key requirements of the group audit
engagement team in respect of a group financial statements audit, in accordance with ISA 600
Special Considerations – Audits of Group Financial Statements (Including the Work of Component
Auditors) (ISA 600).
It will take you approximately 45 minutes to complete.
Scenario
You are a senior auditor at The Audit Group (TAG), an Australian professional accounting
firm with affiliate offices across the world. TAG is the group auditor of Multi Software Limited
(MSL), a multinational software development company.
MSL’s main operation and head office is in Australia, and TAG has been the group auditor of
the MSL group for the past three years. The MSL group consists of MSL’s Australian operation
and all of its overseas operations. MSL has operations in Singapore, the United Kingdom (UK)
and Hong Kong. TAG engages its affiliate offices overseas to assist in auditing MSL’s
international operations.
MSL’s Singapore operation has been growing rapidly, and this is the first year that the
Singapore operation has been considered material for the MSL group audit. Local audit
procedures performed by TAG’s Singapore affiliate office last year (for the purpose of Singapore
local statutory reporting and filing), noted that revenue recognition was incorrect. This was a
significant matter to the Singapore operation, and MSL’s Singapore management processed the
audit adjustments proposed by last year’s audit team.
Sally, an audit partner at TAG, is the group engagement partner responsible for the direction,
supervision and performance of the 30 June 20X3 MSL group financial statements audit
engagement. She has determined that MSL’s Singapore and UK operations are significant to
the MSL group audit and has engaged TAG’s Singapore and UK affiliate offices as component
auditors to audit these operations. MSL’s Hong Kong operation is a small office and not
material to the group.
ACT
Sally’s team needs to draft group audit instructions for all audit teams undertaking work on the
MSL group audit. You have been assigned to this year’s MSL group financial statements audit
team.
Tasks
For this activity, you are required to:
1. Discuss the key responsibilities of the group audit engagement team.
2. Outline information that TAG would request from the component auditors for the MSL
group financial statements audit.
3. Outline the audit approach that should be taken to address the revenue recognition issue in
MSL’s Singapore operation.
4. Summarise the audit approach for MSL’s Hong Kong operation.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 12.4
Assessing the adequacy of internal audit
work for use in the financial statements audit
Introduction
Where an entity has an internal audit function, the external auditor may seek to use the work of
internal auditors to modify the nature and timing, or reduce the extent of the audit procedures
performed directly by the external auditor. However, the external auditor remains solely
responsible for the auditor’s opinion expressed in the financial statements.
This activity links to learning outcome:
•• Demonstrate the steps involved in determining whether and to what extent an external
auditor can use the work of internal auditors.
At the end of this activity, you will be able to identify when and to what extent the external
auditor can use the work of internal auditors and what procedures are necessary to obtain
sufficient appropriate evidence that the work of the internal audit function is adequate for the
purposes of the financial statements audit, in accordance with ISA 610 (Revised 2013) Using the
Work of Internal Auditors (ISA 610 (Revised)).
It will take you approximately 30 minutes to complete.
Scenario
You are the audit senior at OneAcc Chartered Accountants (OneAcc). You are currently working
on the 31 December 20X3 financial statements audit of Reed Books Limited (Reed Books), a
large book publisher and the local subsidiary of a US publishing house.
Reed Books has been one of OneAcc’s audit clients for a number of years and is considered to
have strong internal controls, and an effective internal audit function.
OneAcc expects to use the work of Reed Books’ internal audit team to reduce the extent of audit
procedures to be performed directly by them. OneAcc has assessed the status, policies and
procedures, competency and approach of Reed Books’ internal audit team and has determined
that their work can be relied on.
OneAcc would like to use the following work performed by Reed Books’ internal audit
function:
ACT
Task
For this activity, you are required to assess whether work performed by Reed Books’ internal
auditors is adequate for the purpose of the 31 December 20X3 financial statements audit. If so,
outline the procedures OneAcc should perform, if any.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 12.5
Using the work of an expert
Introduction
Expressing an opinion on a financial statements audit it is solely the auditor’s responsibility.
There are circumstances during an audit where the auditor may use the conclusions of an
expert in a particular field as appropriate audit evidence; however, the use of an expert does not
diminish the auditor’s responsibility for the opinion expressed.
This activity links to learning outcome:
•• Explain the auditor’s responsibilities relating to using the work of an expert.
At the end of this activity, you will be able to determine when to use the work of an expert and
to assess whether their work is adequate for the financial statements audit, in accordance with
ISA 620 Using the Work of an Auditor’s Expert (ISA 620).
It will take you approximately 30 minutes to complete.
Scenario
Colstone Limited (Colstone) buys uncut coloured gemstones from miners, then cuts and
polishes them and on-sells them to jewellery manufacturers. Colstone is considered a market
leader, renowned particularly for the quality of its rubies.
You are a senior accountant at ABC Chartered Accountants (ABC), a professional accounting
firm. You are working on the 30 June 20X3 financial statements audit of Colstone. ABC has been
Colstone’s auditor for the past two years.
Inventory as at 30 June 20X3 has been identified as a material account balance. It comprises both
cut and uncut gemstones, with rubies being 75% of the inventory balance. The value of a ruby is
primarily determined by its colour – the more intense the red, the higher the price. Cut, clarity
and carats (size) also impact on the price. When viewing Colstone’s inventories, you note that
uncut gemstones look very much like ordinary rocks.
Colstone’s managing director, Paul, advises you that the inventory account balance in the
30 June 20X3 financial statements was determined by Colstone’s employees, who are registered
gemstone valuers.
Paul then provides you with the contact details of an expert gemstone valuer who could be
engaged to report on the value of Colstone’s inventories, and with whom he has a long-standing
relationship. The expert is a registered valuer with many years experience, qualifications in
gemology, and certificates in grading and valuations. He also has access to laboratory testing
equipment if required.
Task
For this activity, you are required to determine whether to engage an expert gemstone valuer
for the 30 June 20X3 financial statements audit.
If an expert is engaged, outline how you would assess their competency, capability and
objectivity. Specifically address whether the expert would be the one recommended by Paul in
your response.
[Solutions to activities are available online. Please access myLearning to view]
CC
Core content
Unit 13: Subsequent events and going
concern
Learning outcomes
At the end of this unit you will be able to:
1. Apply the ‘Events after the Reporting Period’ Accounting Standard in relation to subsequent
events audit requirements.
2. Discuss and explain the auditor’s responsibilities relating to subsequent events.
3. Explain the going concern assumption.
4. Demonstrate the auditor’s responsibilities relating to management’s use of the going
concern assumption.
5. Determine the implications for the auditor’s report in the context of going concern
considerations.
Introduction
The auditor’s responsibilities with respect to the audit of an entity’s financial statements
extend beyond the period that the financial statements relate to. Accordingly, the auditor has
an obligation to perform procedures to ensure that all material subsequent events have been
identified and appropriately reflected within the financial statements before the auditor’s report
is signed.
Additionally, the auditor has responsibility, until the date the auditor’s report is signed, to
determine whether a material uncertainty exists in relation to events or conditions that may cast
significant doubt on an entity’s ability to continue as a going concern.
With reference to International Accounting Standards (IAS) and International Standards on
Auditing (ISAs), this unit discusses the:
•• Recognition and disclosure requirements of subsequent events under IAS 10 Events after the
Reporting Period (IAS 10).
•• Auditor’s responsibilities relating to subsequent events under ISA 560 Subsequent Events
(ISA 560).
•• Going concern requirements under IAS 1 Presentation of Financial Statements (IAS 1).
•• Auditor’s responsibilities relating to going concern under ISA 570 Going Concern (ISA 570).
aaa11613_csg
CC
Learning outcome
1. Apply the ‘Events after the Reporting Period’ Accounting Standard in relation to subsequent
events audit requirements.
Timing of events
Inevitably, there is a ‘gap’ between the end of the accounting (reporting) period and completion
of the financial statements. Events that occur during this period may need to be reflected in the
financial statements for the period just ended.
IAS 10 provides guidance as to when such events should be reflected in the financial statements
and how to treat them. IAS 10 applies to events that occur after the reporting date and before
the date the financial statements are authorised for issue (IAS 10 para. 3).
OR
•• Non-adjusting events.
Events occurring
after reporting date
CC
The difference between an ‘adjusting event’ and a ‘non-adjusting event’ is key to applying
IAS 10, and is discussed below.
Adjusting events
An adjusting event confirms the existence of a condition that existed at the end of the reporting
period, or provides more evidence about such a condition (IAS 10 para. 3(a)). Therefore, the
amounts recognised in the financial statements are adjusted to reflect adjusting events after the
reporting period (IAS 10 para. 8).
Common examples of adjusting events are:
•• Legal disputes and court cases that are settled after the reporting date, but which confirm
the existence of a present obligation (‘a condition’) at the reporting date.
•• Information received after the end of the reporting period that indicates an asset was
impaired at the reporting date – for example, an entity finds out that a customer with a
trade receivables balance at the reporting date went bankrupt after the reporting date
usually confirms that a loss existed at the end of the reporting period.
•• Bonuses or profit shares that were determined after the reporting date, but for which a legal
or constructive obligation existed at the reporting date.
Non-adjusting events
Non-adjusting events are indicative of conditions that arose after the end of the reporting period
and therefore do not relate to a condition that existed at the reporting date (IAS 10 para. 3(b)).
The amounts recognised in the financial statements are therefore not adjusted to reflect these
events (IAS 10 para. 10).
However, material non-adjusting events could influence users of the financial statements.
Therefore, as stated in IAS 10 para. 21, the following relevant information should be disclosed:
(a) Nature of the event.
(b) Estimate of the financial effect, or a statement that such an estimate cannot be made.
CC
Example 2
Company X has an investment of shares in a listed company. The fair value of the shares at 30
June 20X3, based on the listed market price at that time, was $2,500. By 30 August 20X3, the
listed market price of the shares fell significantly and the fair value of the investment is $1,700.
This is a non-adjusting event. The shares trade publicly, so the fall in value is assumed to relate
to circumstances that have arisen after the reporting date. This event would only require
disclosure if it is considered to be material.
Example 3
Company Z received a complaint from one of its customers regarding the performance of a
contract on 2 October 20X2, together with a claim for damages of $1,500,000. As at 30 June
20X3, Company Z had received legal advice that indicated it had a strong defence against this
claim, and estimated that it would cost $500,000 in damages and $100,000 in legal fees to settle
the matter out of court.
On 29 August 20X3, a court rules against Company Z and orders damages of $1,200,000 be paid
to the customer, plus costs of $300,000. Company Z’s own legal costs are $400,000.
This is an adjusting event. Company Z had a present obligation at 30 June 20X3, by way of the
contract with the customer. The court ruling provided information regarding the amount of the
obligation. Therefore, the liability to be recognised at 30 June 20X3 is $1,900,000.
Required reading
IAS 10 paras 3, 8, 10 and 12.
Disclosures
The disclosure requirements of IAS 10 are detailed in paras 17–22.
Required reading
IAS 10 paras 17–22.
Worked example 13.1: Accounting for events after the reporting date
[Available online in myLearning]
CC
Learning outcome
2. Discuss and explain the auditor’s responsibilities relating to subsequent events.
Note: In this example, the financial statements have been approved on the same date that the
auditor’s report has been issued. Most audit firms sign the auditor’s report on the same date
that the financial statements are authorised by the entity’s directors.
CC
The table below outlines the auditor’s responsibilities at various points along this timeline:
Time period ISA 560 Audit procedures and potential impact on the auditor’s report
in which requirements
subsequent
event occurs/
facts become
known to
auditor
Time period 1 The auditor Examples of procedures that can be performed during this period are
Between the must perform provided in ISA 560 paras 7 and A8, including:
reporting date procedures
•• Obtaining an understanding of procedures that management has in
and the date the designed to place to identify subsequent events
auditor’s report is obtain sufficient •• Asking management about the occurrence of any subsequent events
signed appropriate
audit evidence •• Reading minutes of directors’ or management meetings held after
that all events the reporting date (if any)
during this •• Reading the latest available interim financial statements
time period (e.g. management accounts)
that require
•• Reading the latest budgets, cash flow forecasts and management
adjustment of,
reports for periods after the reporting date
or disclosures
in, the financial •• Making enquiries of the entity’s legal counsel concerning any
statements have litigation or claims
been identified When the auditor becomes aware of any subsequent events that
(ISA 560 para. 6) materially impact on the financial statements, they need to consider
whether these have been appropriately reflected (i.e. properly
accounted for, adjusted or adequately disclosed) in the financial
statements (ISA 560 para. 8)
Where management does not amend the financial statements, the
auditor would issue a modified auditor’s opinion
CC
Time period ISA 560 Audit procedures and potential impact on the auditor’s report
in which requirements
subsequent
event occurs/
facts become
known to
auditor
Time period 2 The auditor has As per ISA 560 para. 10:
After the date no obligation
[If ] … a fact becomes known to the auditor that, had it been
of the auditor’s to perform
any audit known to the auditor at the date of the auditor’s report, may have
report but before caused the auditor to amend the auditor’s report, the auditor shall:
the date that procedures
the financial regarding (a) Discuss the matter with management and, where
statements are the financial appropriate, those charged with governance;
issued statements
after the date (b) Determine whether the financial statements need
of the auditor’s amendment and, if so,
report (ISA 560
para. 10). It is (c) Enquire how management intends to address the matter in
management’s the financial statements
responsibility to When the financial statements are amended by management
identify these as a result of such events, the auditor shall carry out the audit
subsequent procedures that are necessary to obtain sufficient appropriate
events and audit evidence (ISA 560 para. 11(a)). Audit procedures in relation to
inform the subsequent events should be extended up to the revised date of the
auditor (ISA 560 auditor’s report (ISA 560 para. 11(b))
para. A11)
If facts become Impact on the auditor’s report
known to the Under ISA 560 para. 13(b), if the auditor’s report has been provided
auditor in this to the entity, the auditor shall notify management not to issue the
time period then financial statements to third parties before all ‘necessary amendments’
the auditor’s have been made
requirements
If the entity fails to amend the financial statements and makes them
are outlined in
available to third parties, the auditor has to take appropriate action to
ISA 560 para. 10
seek to ‘prevent reliance on the auditor’s report’. This course of action
by the auditor depends on the auditor’s legal rights and obligations
in the relevant jurisdiction – in such circumstances, the auditor would
normally seek legal advice (ISA 560 para. A16)
CC
Time period ISA 560 Audit procedures and potential impact on the auditor’s report
in which requirements
subsequent
event occurs/
facts become
known to
auditor
Required reading
ISA 560 paras 1–17 and A6–A18.
CC
Going concern
Learning outcome
3. Explain the going concern assumption.
Required reading
IAS 1 paras 25–26.
ISA 570 paras 2 and 13.
CC
Learning outcome
4. Demonstrate the auditor’s responsibilities relating to management’s use of the going concern
assumption.
ISA 570 outlines the auditor’s responsibilities relating to management’s use of the going concern
assumption, which includes:
•• Obtaining sufficient appropriate audit evidence regarding the appropriateness of
management’s use of the going concern assumption (ISA 570 para. 9(a)).
•• Concluding, based on the audit evidence obtained, whether a material uncertainty exists
that may cast significant doubt on the entity’s ability to continue as a going concern
(ISA 570 para. 9(b)).
•• Determining the implications for the auditor’s report (ISA 570 para. 9(c)).
An auditor needs to assess the entity’s ability to continue as a going concern throughout the
three phases of the audit process (risk assessment, risk response and reporting). The procedures
the auditor should undertake in the risk assessment and risk evaluation phases are discussed
below. The auditor’s responsibilities in the reporting phase are discussed in the next section of
this unit.
Required reading
ISA 570 paras 1, 6 and 9.
CC
Assessing the going concern assumption during the risk assessment phase
When performing risk assessment procedures (as discussed in the unit on analysing audit risks,
financial statement assertions and initial audit engagements), the auditor should consider the
entity’s ability to continue as a going concern. The procedures undertaken by the auditor will
vary depending on whether management has already performed a preliminary assessment of
the appropriateness of the going concern assumption, as outlined in the diagram below (see
ISA 570 para. 10):
NO
Source: Australian audit manual and toolkit 2015 for small and medium sized entities, Exhibit 12.2-1, p. 183.
Note: The auditor’s obligation to assess the going concern assumption is not limited to the risk
assessment phase. The auditors have an obligation throughout the audit to remain vigilant to
the possibility of conditions or events that could ‘cast significant doubt on the entity’s ability to
continue as a going concern’ (ISA 570 para. 11).
Required reading
ISA 570 paras 10–15.
CC
Required reading
ISA 570 paras A2–A6.
Assessing the going concern assumption during the risk response phase
If events/conditions that ‘cast significant doubt’ over the entity’s ability to continue as a going
concern have been identified during the audit, the auditor must obtain sufficient appropriate
audit evidence to determine whether or not a material uncertainty does exist (ISA 570 para. 16).
Events or conditions that may cast doubt on the going concern assumption can often
be mitigated by other factors. For example, the effect of an entity being unable to make its
normal debt repayments may be counterbalanced by management’s plan to maintain adequate
cash flows by disposing of assets, obtaining additional capital or rescheduling loan repayments.
CC
When the auditor identifies going concern events/conditions, the next steps are to:
•• Ask management about its assessment of the entity’s ability to continue as a going concern
(ISA 570 para. 16(a)).
•• Evaluate management’s plans for ‘future actions’ relating to the going concern assessment
and assess ‘whether the outcome of these plans is likely to improve the situation’ and the
plans are ‘feasible in the circumstances’ (mitigating factors) (ISA 570 para. 16(b)).
• Analyzing and discussing the entity’s latest available interim financial statements.
• Reading the terms of debentures and loan agreements and determining whether any have been
breached.
• Reading minutes of the meetings of shareholders, those charged with governance and relevant
committees for reference to financing difficulties.
• Inquiring of the entity’s legal counsel regarding the existence of litigation and claims and the
reasonableness of management’s assessments of their outcome and the estimate of their financial
implications.
Required reading
ISA 570 paras 16 and A15–A18.
CC
Learning outcome
5. Determine the implications for the auditor’s report in the context of going concern
considerations.
Based on the audit evidence obtained in the risk assessment and risk response phases, the
auditor should consider whether:
•• In the auditor’s judgement, a material uncertainty exists ‘that may cast significant doubt on
the entity’s ability to continue as a going concern’ (ISA 570 para. 17).
•• Management’s use of the going concern assumption is appropriate.
•• The financial statements fully describe any going concern events/conditions and disclose
any material uncertainty.
The auditor must consider not just whether management’s use of the going concern assumption
is appropriate but also whether a material uncertainty regarding the entity’s ability to continue
as a going concern exists and has been appropriately disclosed to the users of the financial
statements.
A material uncertainty exists when non-disclosure of the:
•• magnitude of an event or condition’s potential impact, and the
•• likelihood of the event or condition occurring
will lead to financial statements being misleading or impair their fair presentation (ISA 570
para. 17).
If the auditor concludes that management’s use of the going concern assumption is appropriate
and no material uncertainty exists, they would then express an unmodified opinion. However,
if a material uncertainty exists, the appropriateness and adequacy of its disclosure in the
financial statements has implications for the auditor’s report (ISA 570 paras 19 and 20).
The following table illustrates the implications for the auditor’s report of the auditor’s
assessment of management’s use of the going concern assumption and material uncertainty:
CC
The following diagram shows the relationship between going concern considerations and types
of audit opinions and other implications on the auditor’s report:
YES NO
Qualified or
Disclaimer of
Can the auditor obtain, through Is the lack of sufficient Opinion (Limitation
additional audit procedures appropriate audit YES of Scope)
(including considerations of evidence due to
(ISA 570 para. A27)
mitigating factors), sufficient management
appropriate audit evidence to NO unwilling to make, or
determine whether a material extend, their going Refer ISA 705 to
uncertainty exists? concern assessment? determine
NO
(ISA 570 para. 16) (ISA 570 para. 22) implications
(ISA 705 para. 13)
YES
YES
NO
Unmodified opinion
with Emphasis of
Matter paragraph
Is there adequate YES
disclosure in the (ISA 570 para. A26)
YES financial statements
of the alternative Refer ISA 705
NO
basis? to determine
implications
Unmodified opinion
with Emphasis of
Matter paragraph
Is there adequate disclosure of YES (ISA 570 para. 19)
the material uncertainty in the
financial statements?
(ISA 570 para. 18) NO Qualified or Adverse
opinion (inadequate
disclosure)
(ISA 570 para. 20)
CC
Required reading
ISA 570 paras 17–22, A19–A20 and A25–A27.
Worked example 13.3: Assessing material uncertainty in relation to going concern and audit
reports
[Available online in myLearning]
Activity 13.2: Assessing going concern and its impact on the auditor’s report
[Located at the end of this unit]
Quiz
[Available online in myLearning]
Readings
Required reading
IAS 10 Events after the Reporting AASB 110 Events after the Reporting NZ IAS 10 Events after the Reporting
Period Period Period
•• Paragraphs 3, 8, 10, 12 and •• Paragraphs 3, 8, 10, 12 and •• Paragraphs 3, 8, 10, 12 and
17–22 17–22 17–22
ISA 560 Subsequent Events ASA 560 Subsequent Events ISA (NZ) 560 Subsequent Events
•• Paragraphs 1–17 and A6–A18 •• Paragraphs 1–17 and A6–A18 •• Paragraphs 1–17 and A6–A18
ISA 570 Going Concern ASA 570 Going Concern ISA (NZ) 570 Going Concern
•• Paragraphs 1–2, 6, 9–22, A2–A6, •• Paragraphs 1–2, 6, 9–22, A2–A6, •• Paragraphs 1–2, 6, 9–22, A2–A6,
A15–A20 and A25–A27 A15–A20 and A25–A27 A15–A20 and A25–A27
IAS 1 Presentation of Financial AASB 101 Presentation of Financial NZ IAS 1 Presentation of Financial
Statements Statements Statements
•• Paragraphs 25–26 •• Paragraphs 25–26 •• Paragraphs 25–26
Further reading
References
Chartered Accountants Australia and New Zealand 2015, Australian audit manual and toolkit 2015
for small and medium sized entities, 5th edn, Thomson Reuters (Professional) Australia Limited,
Sydney.
ACT
Activity 13.1
Understanding auditor’s responsibilities
relating to subsequent events
Introduction
This activity demonstrates the process that an auditor would follow in assessing subsequent
events and whether the financial statements need amendment as a result of those events.
This activity links to learning outcomes:
•• Apply the ‘Events after the Reporting Period’ Accounting Standard in relation to subsequent
events audit requirements.
•• Discuss and explain the auditor’s responsibilities relating to subsequent events.
At the end of this activity, you will be able to identify subsequent events and determine the
impact of those events on the financial statements, in accordance with IAS 10 Events after the
Reporting Period (IAS 10) and ISA 560 Subsequent Events (ISA 560).
It will take you approximately 30 minutes to complete.
Scenario
You are the audit senior at AMPT, the external auditor of Nirvana Mining (Nirvana), an entity
involved in iron ore supply. Nirvana enters into ongoing contracts to purchase iron ore with
mineral dealers ensuring a sufficient supply of materials to sustain production. The cost of
these contracts is recognised at the point of shipment and is based on the percentage of mineral
content in the ore. For example, a 60% mineral content will cost $600 per kilogram, and 70% will
cost $700 per kilogram.
Nirvana has a 30 June 20X3 reporting date. You are aware of the following independent and
material events that have occurred in relation to Nirvana:
Event Description
1 On 10 June 20X3, Nirvana entered into a contract with Rough Diamond, a mineral dealer. The
minerals were shipped on 28 June 20X3. At the time of the shipment, the mineral content of the ore
was estimated to be 70%, and the liability calculated accordingly
However, when the shipment was received on 15 July 20X3, the mineral content was found to be
80%, resulting in the liability being understated
2 On 17 July 20X3, a plant owned by Nirvana was damaged by fire, resulting in a 20% cut to its
production for the next three months until the damaged plant can be replaced
3 On 28 July 20X3, Nirvana received notice that one of its customers was taking legal action in relation
to a warranty claim involving the quality of goods purchased in May 20X3. Nirvana informed AMPT of
significant problems with the goods on 26 June 20X3, when AMPT was undertaking some initial audit
procedures in respect of the 30 June 20X3 audit
4 On 7 August 20X3, Nirvana informed you that the government had imposed a tax on all iron ore
transactions. The tax is effective from 1 September 20X3
ACT
Tasks
For this activity, you are required to:
•• Assess how each of the four events would impact Nirvana’s 30 June 20X3 financial
statements, if at all.
•• Outline the auditor’s role in communicating any amendments required in the financial
statements.
•• Design appropriate audit procedures for each event which would provide you with
sufficient appropriate audit evidence to ensure that any required amendments to Nirvana’s
financial statements are in accordance with the financial reporting framework.
ACT
Activity 13.2
Assessing going concern assumption and its
impact on the auditor’s report
Introduction
As part of the audit process, under ISA 570 Going Concern (ISA 570) the auditor needs to obtain
sufficient appropriate audit evidence regarding the appropriateness of management’s use of the
going concern assumption in the preparation and presentation of the financial statements, and
to conclude whether there is a material uncertainty about the entity’s ability to continue as a
going concern.
This activity links to learning outcomes:
•• Demonstrate the auditor’s responsibilities relating to management’s use of the going
concern assumption.
•• Determine the implications for the auditor’s report in the context of going concern
considerations.
At the end of this activity, you will be able to assess management’s use of the going concern
assumption in the preparation of the financial statements and understand its impact on the
audit opinion, in accordance with ISA 570.
It will take you approximately 20 minutes to complete.
Scenario
You are a senior accountant at ABC Accounting (ABC) and are currently working on the 30 June
20X3 audits of two different clients, Frenetic and Stonecraft. Consider each of the following
independent and material situations that have occurred within the two businesses.
Frenetic
Frenetic is an events management company that has incurred significant losses over the past
four years. As at 30 June 20X3, the company’s financial statements showed a net current liability
position. ABC is very concerned about the financial position of Frenetic; however, Frenetic’s
directors have provided ABC with updated forecasts and projections showing a return to
profitability and a positive net asset position in the year to 30 June 20X4.
ABC is not convinced that the forecasted positive financial position is achievable, and believes
that Frenetic’s future viability is dependent on the continued financial support of its parent
company. At the date of signing the auditor’s report, the parent company has provided Frenetic
with a written guarantee of its continued financial support, and this has been disclosed by the
directors of Frenetic in a note to the 30 June 20X3 financial statements.
ACT
Stonecraft
Stonecraft is an importer of high-quality natural stone, which is used to manufacture custom-
made stone benchtops for use in domestic kitchens and bathrooms. Over the past 12 months,
Stonecraft has been experiencing a gradual decline in profitability.
Your investigations after the year end reveal the existence of a key local competitor that
is substantially underpricing Stonecraft in order to gain a larger market share. Further
investigations reveal that, on 1 July 20X3, the government passed legislation imposing severely
restrictive import quotas on the amount of natural stone allowed into the country. As a result,
Stonecraft’s current inventories of natural stone are insufficient to cover existing orders.
Stonecraft’s management believes that the depressed economy is the sole reason for the current
poor results, and that the quality of its products will be sufficient to maintain demand in the
future. The directors of Stonecraft have not adequately disclosed their difficulties described
above in the 30 June 20X3 financial statements, and have prepared the financial statements on a
going concern basis. ABC believes that Stonecraft will have to liquidate the business within the
next financial year.
Tasks
For this activity, you are required to:
1. Discuss whether there are conditions that may cast significant doubt on Frenetic and
Stonecraft’s ability to continue as a going concern.
2. Identify any mitigating factors.
3. Assess the use of the going concern assumption by the management of both Frenetic and
Stonecraft and determine the implications for the auditor’s report for the 30 June 20X3
financial statements, if any.
[Solutions to activities are available online. Please access myLearning to view]
CC
Core content
Unit 14: Reviewing the financial statements
and audit results
Learning outcomes
At the end of this unit you will be able to:
1. Demonstrate the use of final analytical procedures in the audit of financial statements.
2. Explain and demonstrate how an auditor obtains an understanding of related party
relationships and transactions.
3. Demonstrate how to obtain sufficient appropriate audit evidence about comparative
information included in the financial statements.
4. Explain the auditor’s responsibilities in relation to other information in documents
containing audited financial statements.
5. Describe and apply the steps involved in communicating appropriately to those charged
with governance and management.
Introduction
The final stage of the audit process is the reporting stage, where the auditor evaluates the
evidence obtained and prepares the auditor’s report. This unit discusses the responsibilities
of the auditor in the final stages of gathering and evaluating evidence, prior to preparing the
auditor’s report. Some of these responsibilities were discussed in the previous units of the Audit
& Assurance module, including the unit on appropriateness of the going concern assumption.
This unit focuses on some of the other specific responsibilities of the auditor in the final stage of
the audit process, as outlined in the following Auditing Standards:
•• ISA 520 Analytical Procedures (ISA 520).
•• ISA 550 Related Parties (ISA 550).
CC
The unit concludes with a discussion regarding the auditor’s responsibilities in communicating
the results of audit procedures, including any deficiencies in internal controls and
misstatements identified.
Learning outcome
1. Demonstrate the use of final analytical procedures in the audit of financial statements.
At the final stage of an audit, before the auditor’s report is issued, the auditor needs to review
the financial statements in order to ensure they are consistent with the auditor’s understanding
of the entity. Using analytical procedures to do this is an efficient way to identify any
inconsistencies when forming the overall conclusion.
CC
Required reading
ISA 520.
Learning outcome
2. Explain and demonstrate how an auditor obtains an understanding of related party
relationships and transactions.
Related party relationships, by nature, are not independent relationships. This means that
there is potentially more risk of material misstatement in related party transactions than in
transactions involving unrelated parties. Accordingly, the International Accounting Standards
Board (IASB) has issued specific requirements for related party transactions, which are
contained in IAS 24.
Throughout the audit process, the auditor has a responsibility to consider related party
relationships, as well as transactions between related parties. ISA 550 addresses these
responsibilities at the various stages of the audit process.
In the risk assessment phase of the audit process (as discussed in the unit on analysing audit
risks – fraud), the auditor is required to undertake procedures to understand the entity’s related
party relationships and transactions when evaluating fraud risk factors, as fraud is more easily
committed through related parties. Additionally, during the risk response and reporting phases,
the auditor is required to identify related parties or significant related party transactions that
management has not previously identified or disclosed to the auditor (ISA 550 para. 21).
This unit focuses on the auditor’s specific responsibility for identifying, assessing and
responding to the risks of material misstatement arising from an entity’s failure to properly
account for or disclose related party relationships, transactions or balances in accordance with
the accounting framework (ISA 550 para. 3).
(a) A person or a close member of that person’s family is related to a reporting entity if that person:
(iii) is a member of the key management personnel of the reporting entity or of a parent of the
reporting entity.
(b) An entity is related to a reporting entity if any of the following conditions applies:
(i) The entity and the reporting entity are members of the same group (which means that each
parent, subsidiary and fellow subsidiary is related to the others).
(ii) One entity is an associate or joint venture of the other entity (or an associate or joint venture of
a member of a group of which the other entity is a member).
CC
(iii) Both entities are joint ventures of the same third party.
(iv) One entity is a joint venture of a third entity and the other entity is an associate of the third
entity.
(v) The entity is a post-employment benefit plan for the benefit of employees of either the
reporting entity or an entity related to the reporting entity. If the reporting entity is itself such
a plan, the sponsoring employers are also related to the reporting entity.
(vii) A person identified in (a)(i) has significant influence over the entity or is a member of the key
management personnel of the entity (or of a parent of the entity).
The following are other definitions in IAS 24 para. 9 that are needed to identify related parties:
Close members of the family of a person are those family members who may be expected to influence,
or be influenced by, that person in their dealings with the entity and include:
and
Key management personnel are those persons having authority and responsibility for planning,
directing and controlling the activities of the entity, directly or indirectly, including any director
(whether executive or otherwise) of that entity.
It is important to note that it is the substance of the relationships between parties that
determines whether they are related, and not merely the legal form (IAS 24 para. 10). A party
that is related to an entity can be either an individual or another entity.
Throughout the audit, the auditor must remain alert for related party information.
Required reading
ISA 550 paras 2–10 and 20–21.
IAS 24 paras 9–10.
CC
4. Perform substantive audit procedures, as appropriate, on the newly identified related
parties and transactions (ISA 550 para. 22(c)). This may include (ISA 550 para. A36):
•• Making enquiries regarding the nature of the relationship with the related party.
•• Reviewing accounting records for transactions with the related party.
•• Verifying the terms and conditions of the related party transactions.
5. Assess the risk that there may be further unidentified or undisclosed related parties or
transactions, and perform additional audit procedures as necessary (ISA 550 para. 22(d)).
6. Consider the possibility that the non-disclosure was intentional and evaluate any
implications for the audit (ISA 550 para. 22(e)).
Required reading
ISA 550 paras 21–22 and A35–A37.
Required reading
ISA 550 paras 23 and A38–A41.
Evaluating the accounting for and disclosure of related party relationships and
transactions
The auditor’s obligations regarding the presentation of related party relationships and
transactions in the financial statements are set out in ISA 550 paras 24–28. These obligations
include:
•• Where management discloses a particular related party transaction as an ‘arm’s length’
transaction, the auditor is required to obtain evidence to assess that assertion (ISA 550
para. 24).
•• When forming an opinion on the financial statements, the auditor must assess whether:
–– The identified related party relationships and transactions have been properly
accounted for and disclosed in accordance with the requirements of IAS 24.
–– The related party relationships and transactions prevent the financial statements from
‘achieving fair presentation’ or cause them to be misleading (ISA 550 para. 25).
In making this assessment, the auditor evaluates whether a misstatement is material. In the case
of related parties, the auditor must consider both the size and the nature of the misstatement,
and the particular circumstances of its occurrence, due to the interest in, and specific
requirements that can relate to, the related party transactions.
A written representation from management and, where appropriate, those charged
with governance, stating that they have disclosed and accounted for all the related party
relationships and transactions, as required by IAS 24, is also required as part of finalising the
audit (ISA 550 para. 26).
The auditor has the responsibility to communicate to those charged with governance any
significant matter in connection with related parties that have arisen over the course of the audit
(ISA 550 para. 27).
CC
Required reading
ISA 550 paras 24–27 and A42–A50.
Activity 14.1: Responding to risks of material misstatement associated with related party
relationships and transactions
[Located at the end of this unit]
CC
Comparative information
Learning outcome
3. Demonstrate how to obtain sufficient appropriate audit evidence about comparative
information included in the financial statements.
The provision of comparative information relating to one or more prior periods is a common
financial reporting requirement, although the nature of the comparative information presented
in an entity’s financial statements depends on the requirements of the applicable financial
reporting framework. The main requirement to include comparative information in a set of
financial statements is included in IAS 1, which states:
Except when IFRSs permit or require otherwise, an entity shall present comparative information in
respect of the preceding period for all amounts reported in the current period’s financial statements. An
entity shall include comparative information for narrative and descriptive information if it is relevant to
understanding the current period’s financial statements. (IAS 1 para. 38)
An entity shall present, as a minimum, two statements of financial position, two statements of profit
or loss and other comprehensive income, two separate statements of profit or loss (if presented), two
statements of cash flows and two statements of changes in equity, and related notes. (IAS 1 para. 38A)
An entity shall present a third statement of financial position as at the beginning of the preceding
period in addition to the minimum comparative financial statements required in paragraph 38A if:
(a) it applies an accounting policy retrospectively, makes a retrospective restatement of items in its
financial statements or reclassifies items in its financial statements; and
(b) the retrospective application, retrospective restatement or the reclassification has a material effect
on the information in the statement of financial position at the beginning of the preceding period.
CC
The audit procedures relating to comparative information are summarised as follows:
Task/situation Procedures
When the auditor •• Perform ‘additional audit procedures as are necessary in the circumstances … to
becomes aware determine whether a material misstatement exists’ (ISA 710 para. 8)
of a potential •• Where the prior period financial statements are amended, confirm that the
misstatement in comparative information agrees with the amended financial statements (ISA 710
the comparative para. 8)
information during the
current audit
Obtain written Request written representations for all periods referred to in the auditor’s opinion.
representations This would include ‘specific written representation regarding any restatement made
to correct a material misstatement’ in the prior period financial statements (ISA 710
para. 9)
Approach Explanation
Corresponding Amounts and other disclosures for the prior period are included as an integral part of the
figures current period’s financial statements, and are intended to be read only in relation to the
current period (ISA 710 para. 6(b))
The auditor’s opinion refers only to the current period, except in the circumstances described
in ISA 710 paras 11, 12 and 14 (ISA 710 para. 10)
As stated in ISA 710 para. A2:
The auditor’s opinion does not refer to the corresponding figures because the
auditor’s opinion is on the current period financial statements as a whole, including
the corresponding figures.
Comparative Amounts and other disclosures for the prior period are included for comparison with the
financial financial statements of the current period but, if audited, are referred to separately in the
statements auditor’s opinion. The level of information included in the comparative financial statements is
comparable with that of the current period (ISA 710 para. 6(c))
The auditor’s opinion refers to each period for which financial statements are presented
(ISA 710 para. 15)
CC
Corresponding figures
As the prior period amounts and other disclosures for the prior period are included as an
integral part of the current period financial statements, the auditor’s opinion refers to the
current period only, except in the specific circumstances noted below (ISA 710 para. 10):
The prior period auditor’s report includes a qualified Modify the auditor’s opinion on the current period’s
opinion, a disclaimer of opinion or an adverse opinion, financial statements (ISA 710 para. 11)
and the matter that gave rise to the modification is
unresolved
The auditor identifies a material misstatement Express a qualified or adverse opinion on the
in the prior period financial statements on which an current period financial statements regarding the
unmodified auditor’s opinion has been issued, and corresponding figures (ISA 710 para. 12)
the corresponding figures have not been properly
restated, or appropriate disclosures have not yet been
made
Prior period financial statements are not audited In an Other Matter (OM) paragraph in the auditor’s
report, state that the corresponding figures are
unaudited
Obtain ‘sufficient appropriate audit evidence that
the opening balances do not contain misstatements
that materially affect the current period’s financial
statements’, in accordance with ISA 510 (ISA 710
para. 14)
Where the prior period figures were audited by another firm, and the auditor is not prohibited
by law or regulation from referring to the predecessor’s auditor’s report and decides to make
such a reference, the auditor would state the following in an OM paragraph in the auditor’s
report (ISA 710 paras 13 and A7):
•• That the financial statements of the prior period were audited by the predecessor auditor.
•• The type of opinion expressed by the predecessor auditor and, if the opinion was modified,
the reasons it was modified.
•• The date of that auditor’s report.
Required reading
ISA 710 paras 1–19 and A1–A11.
IAS 1 paras 38-40D.
IAS 8 paras 19–23 and 42–44.
CC
Learning outcome
4. Explain the auditor’s responsibilities in relation to other information in documents containing
audited financial statements.
When an entity publishes additional information within documents containing the audited
financial statements (e.g. narrative reports from directors or analysts, or charts, graphs and
tables included in an annual report to shareholders), this places additional responsibilities on
the auditor of those financial statements. Generally, unless there is a specific requirement in an
audit engagement, the audit opinion does not cover such other information and the auditor has
no specific responsibility for determining whether it is fairly stated (ISA 720 para. 1). However,
the auditor does have an obligation to read the other information in order to identify any
information that would undermine the credibility of the financial statements and the auditor’s
report. ISA 720 outlines how the auditor should respond in such circumstances.
Australian considerations
In Australia, s. 295 Corporations Act 2001 (Cth) (Corporations Act) states that audited financial
statements (report) should include:
•• Financial statements for the year.
•• Notes to the financial statements (including notes required by Accounting Standards and
other information necessary to give a true and fair view).
•• The directors’ declaration about the statements and notes.
Other information may include information required by law, regulation or custom (ISA 720
para. 5(a)). Examples include:
•• Annual reports.
•• Prospectuses.
•• Financial summaries or highlights.
•• Financial ratios.
•• Names of officers and directors.
CC
The definition of ‘other information’ in the context of ISA 720, which the auditor is required to
read, does not include press releases, information contained in analyst briefings or information
contained on an entity’s website (ISA 720 paras A3–A4).
Required reading
ISA 720 paras 1–5(a), 6–7 and A1–A5.
Inconsistencies
One of the purposes of the requirement for the auditor to read the other information is so that
they can identify any material inconsistencies with the audited financial statements (ISA 720
para. 6).
An ‘inconsistency’ is where the other information contradicts the information contained in
the audited financial statements. A material inconsistency may raise concerns about the audit
conclusions drawn and, potentially, the basis on which the audit opinion is formed (ISA 720
para. 5(b)).
An example may be a graph that appears in an annual report that indicates increasing revenue,
whereas the figures presented in the audited financial statements show a decline in revenue.
Where a material inconsistency is identified, the auditor first needs to determine whether it is
the financial statements or the other information that requires revision (ISA 720 para. 8).
Required reading
ISA 720 paras 5(b), 8–13 and A6–A9.
CC
Misstatements of fact
When the auditor’s review of other information identifies information that is incorrectly stated
or presented, and such information is not included in the audited financial statements, this is
regarded as a ‘misstatement of fact’. Under ISA 720 para. 5(c), ‘[a] material misstatement of fact
may undermine the credibility of the document containing the audited financial statements’.
An example may be a comment in an annual report of a mining entity indicating that a
particular mine site has been assessed by engineers as being a viable drill site, when in fact no
such assessment has been made.
When the auditor identifies an apparent material misstatement of fact, they should discuss this
with management and, based on these discussions, then determine an appropriate course of
action, which may include discussing the matter with those charged with governance (ISA 720
paras 14–16).
CC
Learning outcome
5. Describe and apply the steps involved in communicating appropriately to those charged with
governance and management.
As part of the audit process, the auditor has an obligation to communicate their findings
to those charged with governance. This communication can assist management to fulfil its
obligations, assist those charged with governance to fulfil their oversight obligations, and allow
the opportunity for the financial statements to be adjusted prior to being finalised.
Communication between the auditor and the entity occurs throughout the audit process –
when assessing risks, performing procedures and gathering evidence, and when finalising the
auditor’s report. This section of the unit focuses on the communication between the auditor
and their audit client during the reporting period. As discussed in the unit on pre-engagement
activities, ISA 260 Communication with Those Charged with Governance (ISA 260) provides the
overarching framework for this communication.
The auditor’s obligations for communicating related party matters arising during the audit
have already been discussed earlier in the unit. This section discusses the auditor’s obligations
to communicate the following with either management, or those charged with governance,
or both:
•• Deficiencies in internal control identified during the audit, under ISA 265 Communicating
Deficiencies in Internal Control to Those Charged with Governance and Management (ISA 265).
•• Misstatements identified during the audit in accordance with ISA 450 Evaluation
of Misstatements Identified during the Audit (ISA 450).
CC
(b) Other deficiencies in internal control identified during the audit that have not been communicated
to management by other parties and that, in the auditor’s professional judgment, are of sufficient
importance to merit management’s attention. (Ref: Para. A22–A26) (ISA 265 para. 10).
YES NO
Required reading
ISA 265.
CC
Correction of misstatements
Communicating all misstatements identified during the audit in a timely manner to the
appropriate level of management (ISA 450 para. 8) allows management to determine whether
it agrees with the auditor’s assessment and to correct the financial statements as deemed to be
appropriate (ISA 450 para. A7).
Management may refuse to correct some or all of the misstatements communicated. In such
cases, it is important for the auditor to understand management’s reasons for not making the
correction so that the auditor can take this into account when forming their overall evaluation of
whether the financial statements are free from material misstatement (ISA 450 para. 9).
CC
Quiz
[Available online in myLearning]
Readings
Required reading
Relevant International Standards on Auditing and International Accounting Standards and national
equivalents
ISA 520 Analytical Procedures ASA 520 Analytical Procedures ISA (NZ) 520 Analytical Procedures
ISA 550 Related Parties ASA 550 Related Parties ISA (NZ) 550 Related Parties
•• Paragraphs 2–10, 20–27 and •• Paragraphs 2–10, 20–27 and •• Paragraphs 2–10, 20–27 and
A35–A50 A35–A50 A35–A50
ISA 710 Comparative Information ASA 710 Comparative Information ISA (NZ) 710 Comparative
— Corresponding Figures and — Corresponding Figures and Information — Corresponding
Comparative Financial Statements Comparative Financial Reports Figures and Comparative Financial
Statements
•• Paragraphs 1–19 and A1–A11 •• Paragraphs 1–19 and A1–A11 •• Paragraphs 1–19 and A1–A11
ISA 720 The Auditor’s Responsibilities ASA 720 The Auditor’s ISA (NZ) 720 The Auditor’s
Relating to Other Information in Responsibilities Relating to Responsibilities Relating to
Documents Containing Audited Other Information in Documents Other Information in Documents
Financial Statements Containing an Audited Financial Containing Audited Financial
Report Statements
ISA 265 Communicating Deficiencies ASA 265 Communicating ISA (NZ) 265 Communicating
in Internal Control to Those Charged Deficiencies in Internal Control to Deficiencies in Internal Control to
with Governance and Management Those Charged with Governance and Those Charged with Governance and
Management Management
ISA 450 Evaluation of Misstatements ASA 450 Evaluation of ASA 450 Evaluation of
Identified during the Audit Misstatements Identified during the Misstatements Identified during the
Audit Audit
•• Paragraphs 5–9, 12–14, •• Paragraphs 5–9, 12–14, •• Paragraphs 5–9, 12–14,
A4–A10 and A21–A24 A4–A10 and A21–A24 A4–A10 and A21–A24
IAS 1 Presentation of Financial AASB 101 Presentation of Financial NZ IAS 1 Presentation of Financial
Statements Statements Statements
•• Paragraphs 38–40D •• Paragraphs 38–40D •• Paragraphs 38–40D
IAS 8 Accounting Policies, Changes in AASB 108 Accounting Policies, NZ IAS 8 Accounting Policies,
Accounting Estimates and Errors Changes in Accounting Estimates Changes in Accounting Estimates
and Errors and Errors
•• Paragraphs 19–23 and 42–44 •• Paragraphs 19–23 and 42–44 •• Paragraphs 19–23 and 42–44
Relevant International Standards on Auditing and International Accounting Standards and national
equivalents
IAS 24 Related Party Disclosures AASB 124 Related Party Disclosures NZ IAS 24 Related Party Disclosures
•• Paragraphs 9–10 •• Paragraphs 9–10 •• Paragraphs 9–10
Further reading
References
IFAC 2011, Guide to using ISAs in the audits of small- and medium-sized entities, 3rd edn, vol. 2,
accessed 11 April 2015, www.ifac.org → Publications & Resources → ISA guide.
ACT
Activity 14.1
Responding to risks of material misstatement
associated with related party relationships
and transactions
Introduction
The auditor has a responsibility to obtain an understanding of an entity’s related party
relationships and transactions in order to conclude whether they have been presented
appropriately in the financial statements. In the risk response and reporting phase of the audit,
the auditor develops audit procedures to obtain sufficient appropriate evidence regarding
related party relationships and transactions.
This activity links to learning outcome:
•• Explain and demonstrate how an auditor obtains an understanding of related party
relationships and transactions.
At the end of this activity, you will be able to identify related party relationships and
transactions, and the appropriate audit procedures required under ISA 550 Related Parties
(ISA 550).
It will take you approximately 30 minutes to complete.
Scenario
You are an audit senior at Wilburys Chartered Accountants (Wilburys). You are auditing the
30 June 20X3 financial statements of ABKO Engineering Limited (ABKO).
From your review of
the audit work performed thus far, you have noted that:
•• The minutes of directors’ meetings state that ABKO has entered into a contract with Gese
Limited (Gese) for management consulting services during the year. Gese is owned and
controlled by Greg, a director of ABKO. Greg has signed a ‘conflict of interest declaration’
stating that all transactions with Gese are on standard commercial terms.
•• Greg is not involved in the management or day-to-day operations of Gese.
•• Gese was not included in the list of related parties that ABKO’s management provided at
the planning stage of the audit.
•• Expenses incurred for management consulting services have been recognised in ABKO’s
30 June 20X3 financial statements; however, the fact that this transaction is with Gese, an
entity that is controlled by an ABKO director, has not been disclosed.
Task
For this activity, you are required to plan the audit work required under ISA 550.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 14.2
Responding to inconsistencies in other
information in documents containing the
auditor’s report
Introduction
Some entities will publish an annual report or attach additional information to their audited
financial statements. In these instances, the auditor has a responsibility to read the other
information to assess whether the information could undermine the credibility of the financial
statements and the auditor’s report.
This activity links to learning outcome:
•• Explain the auditor’s responsibilities in relation to other information in documents
containing audited financial statements.
At the end of this activity, you will be able to determine the appropriate response when an
inconsistency is identified between the audited financial statements and other information
attached to the audited financial statements, in accordance with ISA 720 The Auditor’s
Responsibilities Relating to Other Information in Documents Containing Audited Financial Statements
(ISA 720).
It will take you approximately 30 minutes to complete.
Scenario
You are the senior auditor on the 30 June 20X3 financial statements audit of Chamarel Limited
(Chamarel). Chamarel is a company listed on a local stock exchange that specialises in the
manufacture and distribution of confectionery products. The audit has been substantially
completed, and the audit manager has asked you to review the final printers’ proof of
Chamarel’s annual report, prior to it being finalised and the issuing of the auditor’s report.
The annual report includes the following sections:
•• Chairman’s report.
•• CEO’s report.
•• Financial highlights.
•• Review of operations.
•• Outlook.
•• Board of directors.
•• Corporate governance statement.
•• Directors’ report.
•• Financial statements (including the auditor’s report).
•• Sustainability report.
ACT
You have read the annual report and have noted the following:
1. Directors’ information
The directors’ report included in the annual report lists the directors of Chamarel during the
year as being:
•• Pierre Martin (chairman).
•• Amel Dubois (managing director).
•• Gigi L’Amoroso.
•• Lara Leroy.
•• Henri Moreau (appointed June 20X2).
The financial statements contain a disclosure note regarding the directors of Chamarel;
however, Lara Leroy is not disclosed in that note to the financial statements. The audit
working papers confirm that Lara Leroy was not a director at any point during the year
ended 30 June 20X3.
The shareholders’ meeting minutes show that the directors’ information is an area that
shareholders continue to query.
2. Proportion of revenue invested in R&D activities
The financial highlights section of the annual report includes a graph that shows research
and development (R&D) expenditure as a percentage of revenue for each of the past five
years, including the most recent year ended 30 June 20X3.
The graph indicates that Chamarel spent 10% of revenue on R&D in the year ended 30 June
20X3; however, the financial statements show that this was only 1%. A review of the audit
files confirms that 1% of revenue was spent on R&D.
R&D has been identified as a material account balance.
In your initial discussion with Chamarel’s management regarding these matters, it has indicated
that it would be reluctant to make any amendments, given the costs involved in revising the
annual report at this late stage.
Task
For this activity, you are required to outline the appropriate response for each of the two
anomalies between the annual report and the financial statements.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 14.3
Communicating internal control deficiencies
Introduction
The auditor has an obligation to communicate certain matters to management and those
charged with governance, including internal control deficiencies warranting their respective
attention and identified as part of the audit process. While this requires the auditor’s
professional judgement, ISA 265 Communicating Deficiencies in Internal Control to Those Charged
with Governance and Management (ISA 265) provides the auditor with guidance as to which
identified deficiencies must be communicated, to whom and in what manner.
This activity links to learning outcome:
•• Describe and apply the steps involved in communicating appropriately to those charged
with governance and management.
At the end of this activity, you will be able to identify control deficiencies that must be reported
to management and those that must be reported to those charged with governance, the form the
communication should take and the content of the communication.
It will take you approximately 30 minutes to complete.
Scenario
You are an audit senior at BJ Dove Accountants (BJ Dove), and have been part of the
engagement team on the audit of Smithfield Confectionery Limited (Smithfield). Smithfield,
a manufacturer and wholesaler of liquorice and chocolate products, has been an audit client
of BJ Dove for three years.
You are currently completing the audit of the 30 June 20X3 financial statements and your audit
manager asked you to collate a list of the internal control deficiencies identified during the
audit.
You reviewed the audit files and noted the following internal control deficiencies:
1. Lack of review of balance sheet reconciliations
As part of internal controls testing, a sample of balance sheet reconciliations was selected
to verify that the reconciliations had been completed by the finance staff and then reviewed
and approved by Smithfield’s financial controller. Of the initial four months selected, one
month had two reconciliations that had no evidence of a review by the financial controller.
This was over the period that there was a personnel change in the role of financial
controller. Further samples were selected and there was evidence of review by the financial
controller.
2. Lack of segregation of duties in accounts payable
As part of the review of accounts payable controls, it was noted that the creation of a vendor
file does not require authorisation within the system. This means that an accounts payable
clerk can create a new vendor, enter bank account details, and input invoices for payment.
ACT
3. Lack of approval in payroll
While testing the payroll function, it was identified that when employees’ weekly
timesheets are entered into the payroll system, there is no check in place to ensure that the
hours entered match those recorded on the timesheet. As a result, a number of employees
were overpaid during the period. The overpayments were identified as part of the audit
procedures.
4. Weak access controls in IT system
The IT system used by Smithfield requires users to log on with a unique ID and password.
However, the system does not require users to change their passwords on a regular basis,
and, as a result, most users had never changed their passwords since being granted access
to the system. This was noted in last year’s audit of the 20X2 financial statements and was
communicated to Smithfield. No changes to the password requirements were made in the
20X3 year.
Task
For this activity, you are required to prepare a communication plan for the control deficiencies
identified. This plan should specify which control deficiencies need to be communicated
to Smithfield, to whom they should be communicated (management or those charged
with governance), the form of the communication (written or oral) and the content of the
communication.
Assume that there is no local legislative requirement to express an opinion on the effectiveness
of the internal control in conjunction with the audit of the financial statements.
[Solutions to activities are available online. Please access myLearning to view]
CC
Core content
Unit 15: Forming an opinion and issuing an
auditor’s report
Learning outcomes
At the end of this unit you will be able to:
1. Identify and explain the auditor’s responsibility to form an opinion and provide an auditor’s
report.
2. Describe and explain the different types of auditor’s reports that an auditor may issue.
3. Identify and justify the choice of the appropriate auditor’s report for an entity based on the
results of audit work conducted for that entity.
Introduction
All the audit work has been completed and the auditor now needs to determine the appropriate
content for the auditor’s report, including the auditor’s opinion.
For users of financial statements, the auditor’s report is the most important part of the audit.
It is the only part of the audit they see and is used to gauge the reliability of the financial
statements. The consequences of the auditor issuing an inappropriate auditor’s report can be
significant.
This unit focuses on the following:
•• Forming an opinion on the financial statements that have been audited.
•• Issuing an auditor’s report (containing the auditor’s opinion) on the financial statements.
CC
Learning outcome
1. Identify and explain the auditor’s responsibility to form an opinion and provide an auditor’s
report.
CC
or the New Zealand Financial Reporting Act 1993, give ‘a true and fair view’ of) the financial
position and financial performance of the entity. Note that the revision of legislation in New
Zealand has taken out the legislative requirement for a ‘true and fair’ view in legislation.
Instead, the requirement within Accounting Standards (e.g. IAS 1 Presentation of Financial
Statements (IAS 1)) will apply.
Fair presentation frameworks permit disclosures in addition to those specified or, in rare
circumstances, departures from the framework to achieve a ‘fair presentation’.
Under this kind of framework, management may decide to include additional information
beyond that which is required by the relevant Accounting Standards, so that the financial
statements more fairly present the entity’s financial position and performance. The auditor
will need to conclude whether the picture presented by the financial information as a whole
(including the additional information) is consistent with their knowledge of the entity’s
business, and is a fair presentation.
When expressing an unmodified opinion on financial statements prepared in accordance with a
fair presentation framework, that opinion must use one of two phrases (unless law or regulation
requires otherwise):
(a) ‘The financial statements present fairly, in all material respects, ... in accordance with [the
applicable financial reporting framework]’; or
(b) ‘The financial statements give a true and fair view of ... in accordance with [the applicable financial
reporting framework]’(ISA 700 para. 35).
Australia-specific
In Australia, the Corporations Act (ss 295(3)(c) and 297) and the Australian Accounting
Standards both require financial reports to be prepared based on a fair presentation framework
(AASB 101 Presentation of Financial Statements para. 15). It is therefore likely that most, if
not all, financial statements you will review in your work will be based on a fair presentation
framework.
New Zealand-specific
In New Zealand, the Financial Reporting Act 1993 (ss 11 and 14) requires that the financial
statements of a reporting entity or group give a ‘true and fair view’. Similarly, state sector
bodies and local authorities are required to prepare statements that ‘fairly reflect’ their financial
position and financial and non-financial performance. Under the Financial Markets Conduct
Act 2013 (FMCA) the legislative requirement for a true and fair view has been removed from
legislation. Instead, the requirement is that financial statements are prepared under generally
accepted accounting practice (GAAP) which means that the requirements within Accounting
Standards (e.g. IAS 1) will apply. IAS 1 requires that financial statements shall present fairly the
financial position, financial performance and cash flows of an entity.
Compliance framework
Under a compliance framework, the auditor forms an opinion as to whether the financial
statements are prepared in accordance with the framework. Compliance frameworks are
more common where, for example, an auditor might need to express an opinion on whether
the financial statements have been prepared in accordance with a specific accounting method
stipulated.
A compliance framework does not provide scope for additional disclosures or departures from
the requirements of the framework.
When expressing an unmodified opinion on financial statements prepared in accordance with
a compliance framework, alternative wording is required so that the auditor’s opinion shall
be that the ‘financial statements are prepared, in all material respects, in accordance with [the
applicable financial reporting framework]’ (ISA 700 para. 36).
CC
Required reading
International
ISA 700 paras 1–10, 34–37, 43(a)–(i) and A42.
Australia
AASB 101 para. 15.
Corporations Act ss 295(3)(c) and 297.
New Zealand
NZ IAS 1 Presentation of Financial Statements paras 5 and 7.
Alternatives to reporting
In general, an auditor is required to provide a written report containing their conclusions
on an audit. However, under certain circumstances, the ISAs provide for the withdrawal of
the auditor from the engagement where this is possible under local jurisdictional laws or
regulations (ISA 200 Overall Objectives of the Independent Auditor and the Conduct of an Audit in
Accordance with International Standards on Auditing (ISA 200) para. 12).
Required reading
ISA 200 para. 12.
CC
Required reading
ISA 700 paras A5–A10.
Accounting frameworks
The financial reporting framework applied in preparing the financial statements both prescribes
the presentation of the financial statements and provides the auditor with the appropriate
criteria to use.
ISA 700 para. 10 states:
The auditor shall form an opinion on whether the financial statements are prepared, in all material
respects, in accordance with the applicable financial reporting framework.
… designed to meet the common financial information needs of a wide range of users …
Reporting for special purpose financial statements is discussed in the unit on other assurance
engagements and agreed-upon procedures engagements.
CC
The diagram below provides a visual representation of the questions that need to be considered
when determining the type of auditor’s reporting required, and therefore the applicable
Auditing Standards:
These sections, together with the information required in each, are set out in the following table:
Component Description
Title The title of the auditor’s report must clearly indicate that it is the report of an
independent auditor
(ISA 700 para. 21)
Addressee(s) The auditor’s report shall be addressed as required by the circumstances of the audit
engagement. Most commonly, for general purpose financial statements, this is the
(ISA 700 para. 22)
shareholders. However, it may also be the directors, the members, or even a funding
body
CC
Component Description
Management’s This section of the auditor’s report describes management’s responsibility for the
Responsibility for the preparation of the financial statements. This includes management responsibility
Financial Statements for preparing the financial statements in accordance with the applicable financial
reporting framework, and for such internal control as management determines
(ISA 700 paras 24–27)
is necessary to enable the preparation of financial statements that are free from
material misstatement (whether due to fraud or error)
Specific wording may be required in the description above for financial statements
prepared in accordance with a fair presentation framework
Note: This section need not refer to management, but may use terms appropriate in
the context of the particular jurisdiction responsible for the preparation of financial
statements (e.g. ‘the committee’ or ‘the trustees’)
Auditor’s Responsibility The auditor’s report must include a section with the heading ‘Auditor’s responsibility’,
stating that it is the responsibility of the auditor to express an opinion on the
(ISA 700 paras 28–33)
financial statements based on the audit
It must also state that the audit was conducted in accordance with ISAs (or local
equivalents); that those Standards require the auditor to comply with ethical
requirements; that the auditor plan and perform the audit to obtain reasonable
assurance about whether the financial statements are free from material
misstatement, and whether the auditor believes that the audit evidence obtained is
sufficient and appropriate to provide a basis for the auditor’s opinion
This section also provides a description of the audit, and includes statements that:
•• An audit involves performing procedures to obtain evidence about the amounts
and disclosures in the financial statements
•• The procedures selected depend on the auditor’s judgement
•• While internal control may have been considered in selecting those procedures,
the auditor is not expressing an opinion on the effectiveness of the entity’s
internal control (this statement is omitted if the auditor does have the
responsibility to express an opinion on the effectiveness of internal control)
•• The audit also includes an evaluation of the appropriateness of the accounting
policies used, the reasonableness of accounting estimates made by management,
and the overall presentation of the financial statements
Specific wording may be required in the description above for financial statements
prepared in accordance with a fair presentation framework
Auditor’s Opinion The auditor’s report must include an ‘Opinion’ section, containing the Opinion
paragraph
(ISA 700 paras 34–37)
When expressing an unmodified opinion on financial statements that have been
prepared in accordance with a fair presentation framework, the report must use one
of two specific phrases (unless law or regulation requires otherwise) stated in ISA 700
para. 35
When expressing an opinion on financial statements prepared in accordance with a
compliance framework, alternative wording is required
If the applicable reporting framework is not an IFRS (or local equivalent) framework,
the opinion must identify the original jurisdiction of the framework
CC
Component Description
Other Reporting Where an auditor addresses other reporting responsibilities in addition to the
Responsibilities financial statements, those other responsibilities are addressed in a separate section
of the report subtitled ‘Report on Other Legal and Regulatory Requirements’ (or
(ISA 700 paras 38–39)
otherwise, as appropriate to the content)
If such a section is added, the requirements of paras 24–37 discussed above are
contained in a section subtitled ‘Report on the Financial Statements’, which should be
included before ‘Report on Other Legal and Regulatory Requirements’
Signature of the Auditor The auditor’s report must be signed (certain jurisdictions may have requirements
relating to the auditor’s signature)
(ISA 700 para. 40)
Date of the Auditor’s The auditor’s report must be dated no earlier than the date on which the auditor has
Report obtained sufficient appropriate evidence on which to base their opinion. This must
include evidence that those with recognised authority have asserted they have taken
(ISA 700 para. 41)
responsibility for the financial statements
Other requirements may exist in certain jurisdictions
Auditor’s Address The auditor’s address must state the location in the jurisdiction where the auditor
practises
(ISA 700 para. 42)
This is generally understood not to be an exact address, but the name of the city
where the auditor’s primary office is located (e.g. Auckland, Sydney, Wellington or
Perth)
In practice, most audit firms insist on signing the auditor’s report on the same date that the
financial statements are authorised by the entity’s directors. This is due to additional audit
procedures that may be required should the auditor sign the auditor’s report at a later date.
Auditor’s opinion
An auditor forms an auditor’s opinion on financial statements following completion and
evaluation of audit work. As seen in the table above, the auditor’s opinion is a component of the
auditor’s report.
Auditor’s report
An auditor issues an auditor’s report on financial statements that have been audited. The
auditor’s report contains a number of components, as outlined in the table above, including the
auditor’s opinion.
Required reading
ISA 700 paras 7(b), 10, 20–47 and A13–A44.
ISA 800 para. 6(b).
CC
Auditor’s report – additional auditor’s report sections under ISA 705 and ISA 706
Component Description
Basis for Modification When an auditor modifies their opinion on the financial statements, the
auditor’s report must include a paragraph that provides a description of the
(ISA 705 para. 16)
matter giving rise to the modification
The paragraph must be placed immediately before the section containing the
Opinion paragraph and be titled as appropriate for the type of modification; for
example, ‘Basis for Qualified Opinion’
Details of matters to be included in the paragraph and the impact on the
Opinion paragraph will be covered in more detail later in this unit
Other Matter paragraph If an auditor considers it necessary to include an Other Matter paragraph,
it must be included immediately after the section containing the Opinion
(ISA 706 para. 8)
paragraph and any Emphasis of Matter paragraph, or elsewhere if the content is
relevant to the Other Reporting Responsibilities section
Required reading
ISA 705 para. 16.
ISA 706 paras 6–8.
CC
Auditor’s opinions
Learning outcomes
2. Describe and explain the different types of auditor’s reports that an auditor may issue.
3. Identify and justify the choice of the appropriate auditor’s report for an entity based on the
results of audit work conducted for that entity.
Types of auditor’s
opinions
Unmodified opinions
An auditor expresses an unmodified opinion when they conclude that the financial statements
are prepared, in all material respects, in accordance with the applicable financial reporting
framework (ISA 700 para. 16).
In other words, where an auditor concludes that the financial statements fairly present the
entity’s financial position and results of operations, they can then issue an unmodified opinion
on the financial statements using the standard format described in ISA 700.
CC
Modified opinions
As per ISA 705 para. 6, an auditor expresses a modified opinion when:
•• The auditor determines, on the basis of the sufficient appropriate audit evidence gathered
and analysed during the audit, that there are material misstatements in the financial
statements.
•• The auditor is unable to obtain sufficient appropriate audit evidence to conclude that the
financial statements are free from material misstatement.
The following table summarises the circumstances under which a modified opinion is issued:
Nature of the matter giving rise to the Auditor’s judgement about the pervasiveness of the effects or
modification possible effects on the financial statements
CC
An inability to obtain sufficient appropriate audit evidence could either have a possible
‘material but not pervasive’ effect on the financial statements, or a possible ‘material and
pervasive’ effect. The fact that the effect on the financial statements is uncertain (a possible
effect), increases the degree of judgement to be applied by the auditor regarding their
determination as to whether the material impact is either ‘only’ material, or material and
pervasive.
Generally, a misstatement or possible misstatement that is undetected due to inability to
obtain sufficient appropriate audit evidence is considered to be ‘material’ if it could reasonably
be expected to influence the economic decisions of users of the financial statements whose
decisions are affected by the size or the nature of the misstatement.
The term ‘pervasive’ is referred to in ISA 705 para. 5(a) and is used to describe the effects on the
financial statements that:
(i) Are not confined to specific elements, accounts or items of the financial statements;
(ii) If so confined, represent or could represent a substantial proportion of the financial statements; or
(iii) In relation to disclosures, are fundamental to users’ understanding of the financial statements.
The example auditor’s reports set out in the ISA 705 Appendix show the key differences
between the three modified audit opinions. They can be summarised as follows:
Qualified opinion resulting from material In our opinion, except for the effects of the matter described in the
misstatement Basis for Qualified Opinion paragraph, the financial statements
present fairly, in all material respects (or give a true and fair
(ISA 705 Appendix Illustration 1,
view of ) … in accordance with International Financial Reporting
ISA 705 para. 23)
Standards
Qualified opinion resulting from the In our opinion, except for the possible effects of the matter
inability to obtain sufficient appropriate described in the Basis for Qualified Opinion paragraph, the
audit evidence financial statements present fairly, in all material respects, (or
give a true and fair view of ) … in accordance with International
(ISA 705 Appendix Illustration 3,
Financial Reporting Standards
ISA 705 para. 23)
Adverse opinion In our opinion, because of the significance of the matter discussed
in the Basis for Adverse Opinion paragraph, the consolidated
(ISA 705 Appendix Illustration 2,
financial statements do not present fairly (or do not give a true
ISA 705 para. 24)
and fair view of ) … in accordance with International Financial
Reporting Standards
Disclaimer of opinion Because of the significance of the matters described in the Basis for
Disclaimer of Opinion paragraph, we have not been able to obtain
(ISA 705 Appendix Illustrations 4 and 5,
sufficient appropriate audit evidence to provide a basis for an
ISA 705 para. 25)
audit opinion. Accordingly, we do not express an opinion on the
financial statements
CC
Required reading
ISA 700 paras 16–19 and A11–A12.
ISA 705 paras 1–15, 22–28, A1–A16, A21–A25 and Appendix.
Material misstatement that relates A description and quantification of the material misstatement. If it is
to specific amounts or quantitative not practicable to do so, the auditor must state this
disclosures in the financial statements
Material misstatement that relates An explanation of how the narrative disclosure is misstated
to a narrative (i.e. non-numeric)
disclosure
Material misstatement that relates A description of the nature of the omitted information, after the
to the non-disclosure of information auditor has discussed this with those charged with governance.
that is required to be disclosed Unless prohibited by law or regulation, or impracticable to do so (if
the disclosures are not readily available to the auditor or if they are too
voluminous in relation to the auditor’s report), the auditor includes the
omitted disclosure, but only if sufficient appropriate audit evidence
about the omitted disclosure has been obtained
Inability to obtain sufficient A reason for the inability to obtain sufficient appropriate audit
appropriate audit evidence evidence
Required reading
ISA 705 paras 5(a), 16–21, A8 and A17–A20.
CC
Learning outcomes
2. Describe and explain the different types of auditor’s reports that an auditor may issue.
3. Identify and justify the choice of the appropriate auditor’s report for an entity based on the
results of audit work conducted for that entity.
Emphasis of Matter and Other Matter paragraphs, and the matters they relate to, are not
‘modified’ auditor’s opinions. They are used by the auditor to draw users’ attention to
particular matters, but do not affect whether the auditor’s opinion is unmodified or modified.
CC
it necessary to include such a paragraph to explain their inability to withdraw from the
engagement (ISA 706 para. A5).
•• Where the entity has prepared two sets of financial statements, each in accordance with
an appropriate financial reporting framework, and the auditor issues an auditor’s report
on each of these financial statements, the auditor may include an Other Matter paragraph
referring to this fact (ISA 706 para. A8).
•• Where there is a restriction on the distribution or use of the auditor’s report. This could be
the case if financial statements are prepared for specific purposes (but still in accordance
with a general purpose framework ‘because the intended users have determined that
such general purpose financial statements meet their financial information needs’). The
auditor may consider it necessary to include a paragraph to state that the auditor’s report
‘is intended solely for the intended users, and should not be distributed to or used by other
parties’ (ISA 706 para. A9).
It is important to note that (as per ISA 706 para. A10) in an Other Matter paragraph the auditor
is not allowed to include:
•• Information that the auditor is prohibited from providing by law, regulation or other
professional Standards – for example, ethical Standards relating to confidentiality of
information.
•• Information that management is required to provide.
The Other Matter paragraph should have the heading ‘Other Matter’ or another appropriate
heading. It should be placed immediately after the Opinion paragraph or any Emphasis of
Matter paragraph, or elsewhere in the report if the content of the Other Matter paragraph is
relevant to the ‘Other Reporting Responsibilities’ section (ISA 706 para. 8).
For example, if it is a matter relating to ‘Other Reporting Responsibilities’ addressed in
the auditor’s report, the paragraph should be included in the ‘Report on Other Legal and
Regulatory Requirements’ section. If it is a matter relating to an auditor’s responsibilities or an
auditor’s report, the paragraph should be included in the ‘Other Matter’ section that follows
the ‘Report on the Financial Statements’ and the ‘Report on Other Legal and Regulatory
Requirements’ (ISA 706 para. A11).
Required reading
ISA 706.
The financial statements contain a note describing Emphasis of Matter: Drawing users’ attention to
a material uncertainty that relates to the entity’s the material uncertainty that relates to the going
ability to continue as a going concern concern assumption
The financial statements contain a note describing Emphasis of Matter: Drawing users’ attention
an uncertainty regarding the future outcome of to the uncertainty regarding the exceptional
exceptional litigation that is fundamental to users’ litigation
understanding of the financial statements
The entity was not audited in the previous financial Other Matter: Drawing users’ attention to the
period fact that the corresponding figures in the
financial statements are unaudited
CC
The following flow chart may provide assistance in determining whether an additional
paragraph to the auditor’s report is required, and the type of additional paragraph (whether
Emphasis of Matter or Other Matter), if any, under International Standards on Auditing.
YES NO
If a matter is
presented or YES NO
disclosed in the
financial statements
but not appropriately
(i.e. is not in Is the matter Is the matter relevant to
accordance with appropriately presented users’ understanding of
NO
relevant Accounting or disclosed in the the audit, the auditor’s
Standards), it should financial statements? responsibilities or the
be dealt with in the auditor’s report?
auditor’s opinion, not
in an additional
paragraph to the YES
auditor’s report
NO YES
Is the matter of such importance
that it is fundamental to users’
understanding of the financial
statements?
YES NO
CC
Worked example 15.1: Determining the impact of misstatements on the auditor’s report
[Available online in myLearning]
Activity 15.2: Audit reporting – misstatements and inconsistencies between the financial
statements and documents containing the financial statements
[Located at the end of this unit]
Required reading
ISA 260 Appendix 2.
ISA 330 para. 26.
ISA 450 para. 11.
ISA 540 para. 21.
ISA 700 paras 10–15, A1–A4, A45–A51 and Appendix.
CC
The new and revised auditor reporting Standards include a number of key enhancements
that are relevant to all entities. The content of the auditor’s report is reordered, with the audit
opinion now required to go first. The description of the responsibilities of management and
the auditor have been revised, and enhanced auditor reporting on going concern is being
introduced.
A key enhancement is the inclusion of a new section to communicate ‘key audit matters’.
This section will be mandatory for listed entities and voluntary for other entities. Key audit
matters are areas that the auditor views as most significant, and will be required to include an
explanation of how they were addressed in the audit.
In a January 2015 edition of its publication At a Glance, the IAASB summarises the changes to
the Standards, highlighting key aspects of the new and revised Standards.
The Standards can be early adopted. Downer EDI and its auditor, KPMG, was the first of the
ASX-listed companies to report under the new and revised auditor reporting Standards.
Required reading
IAASB 2015, At a Glance: New and revised auditor reporting standards and related conforming
amendments, 15 January, accessed 2 December 2015, www.ifac.org → About IFAC → Publications
and Resources, search for ‘At a glance’.
CC
Activity 15.3: Determining auditor’s reporting implications – subsequent events and going
concern
[Located at the end of this unit]
Activity 15.4: Issuing an auditor’s report when financial statements are not in accordance
with the applicable financial reporting framework
[Located at the end of this unit]
Quiz
[Available online in myLearning]
Readings
Required reading
Relevant International Standards on Auditing and national equivalents and other relevant national
pronouncements
ISA 200 Overall Objectives of the ASA 200 Overall Objectives of ISA (NZ) 200 Overall Objectives of
Independent Auditor and the the Independent Auditor and the the Independent Auditor and the
Conduct of an Audit in Accordance Conduct of an Audit in Accordance Conduct of an Audit in Accordance
with International Standards on with Australian Auditing Standards with International Standards on
Auditing Auditing (New Zealand)
•• Paragraph 12 •• Paragraph 12 •• Paragraph 12
ISA 260 Communication with Those ASA 260 Communication with Those ISA (NZ) 260 Communication
Charged with Governance Charged with Governance with Those Charged with Governance
•• Appendix 2 •• Appendix 2 •• Appendix 2
ISA 330 The Auditor’s Responses to ASA 330 The Auditor’s Responses to ISA (NZ) 330 The Auditor’s Responses
Assessed Risks Assessed Risks to Assessed Risks
•• Paragraph 26 •• Paragraph 26 •• Paragraph 26
ISA 450 Evaluation of Misstatements ASA 450 Evaluation of ISA (NZ) 450 Evaluation of
Identified during the Audit Misstatements Identified during the Misstatements Identified during the
Audit Audit
•• Paragraph 11 •• Paragraph 11 •• Paragraph 11
ISA 540 Auditing Accounting ASA 540 Auditing Accounting ISA (NZ) 540 Auditing Accounting
Estimates, Including Fair Value Estimates, Including Fair Value Estimates, Including Fair Value
Accounting Estimates, and Related Accounting Estimates, and Related Accounting Estimates, and Related
Disclosures Disclosures Disclosures
•• Paragraph 21 •• Paragraph 21 •• Paragraph 21
ISA 700 Forming an Opinion and ASA 700 Forming an Opinion and ISA (NZ) 700 Forming an Opinion
Reporting on Financial Statements Reporting on a Financial Report and Reporting on Financial
Statements
ISA 705 Modifications to the Opinion ASA 705 Modifications to the ISA (NZ) 705 Modifications to the
in the Independent Auditor’s Report Opinion in the Independent Auditor’s Opinion in the Independent Auditor’s
Report Report
Relevant International Standards on Auditing and national equivalents and other relevant national
pronouncements
ISA 706 Emphasis of Matter ASA 706 Emphasis of Matter ISA (NZ) 706 Emphasis of Matter
Paragraphs and Other Matter Paragraphs and Other Matter Paragraphs and Other Matter
Paragraphs in the Independent Paragraphs in the Independent Paragraphs in the Independent
Auditor’s Report Auditor’s Report Auditor’s Report
ISA 800 Special Considerations ASA 800 Special Considerations – ISA (NZ) 800 Special Considerations
– Audits of Financial Statements Audits of Financial Reports Prepared – Audits of Financial Statements
Prepared in Accordance with Special in Accordance with Special Purpose Prepared in Accordance with Special
Purpose Frameworks Frameworks Purpose Frameworks
•• Paragraph 6(b) •• Paragraph 6(b) •• Paragraph 6(b)
Further reading
ACT
Activity 15.1
Determining the appropriate auditor’s
opinion
Introduction
The auditor’s report is issued as the final step in the audit process. The auditor’s opinion is a
major component of the auditor’s report. A number of different types of auditor’s opinions can
be included in the auditor’s report, and the auditor needs to ensure that the correct opinion is
included, based on the results of the audit work performed.
This activity links to learning outcome:
•• Identify and justify the choice of the appropriate auditor’s report for an entity based on the
results of audit work conducted for that entity.
At the end of this activity, you will be able to determine the appropriate opinion to be included
in an auditor’s report.
It will take you approximately 40 minutes to complete.
Scenario
You are a senior auditor working for BLT Chartered Accountants (BLT), a firm of 10 partners.
Reece Kingston, your manager, has developed a training module on determining the
appropriate auditor’s opinion for auditors undertaking the Chartered Accountants Program.
He has developed four fictitious but realistic case studies for the candidates to use.
The case studies are:
ACT
Task
For this activity, you are required to determine the most appropriate auditor’s opinion to be
included in the auditor’s report for each case study, and to justify your decisions.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 15.2
Audit reporting – misstatements and
inconsistencies between the financial
statements and documents containing the
financial statements
Introduction
The auditor’s report can include a description of matters relating to the auditor’s opinion or
other matters that, in the opinion of the auditor, should be brought to the attention of users of
the financial statements.
This activity links to learning outcomes:
•• Describe and explain the different types of auditor’s reports that an auditor may issue.
•• Identify and justify the choice of the appropriate auditor’s report for an entity based on the
results of audit work conducted for that entity.
This activity demonstrates how to determine the appropriate form of auditor’s opinion where
financial statements contain material misstatements. It also demonstrates the impact on the
auditor’s report of inconsistencies between the financial statements and documents that contain
those financial statements, in accordance with:
•• ISA 700 Forming an Opinion and Reporting on Financial Statements (ISA 700).
•• ISA 705 Modifications to the Opinion in the Independent Auditor’s Report (ISA 705).
•• ISA 706 Emphasis of Matter Paragraphs and Other Matter Paragraphs in the Independent Auditor’s
Report (ISA 706).
•• ISA 720 The Auditor’s Responsibilities Relating to Other Information in Documents Containing
Audited Financial Statements (ISA 720).
Scenario
You are an audit senior with Hope & Tait Chartered Accountants (HT). Fluffit is a listed food
manufacturer specialising in bottled condiments, bake-at-home cakes and sandwich spreads.
HT has been the auditor of Fluffit for the last five years. You are a member of the HT team
performing the audit of Fluffit for the year ended 30 June 20X3.
The audit team is currently finalising the audit working papers in preparation for the audit
partner’s review. The audit manager has been reviewing the audit working papers and your
responsibility has been to ensure the working papers are complete, that you have reviewed the
work of junior auditors, and that sufficient appropriate audit evidence has been obtained for all
material amounts and disclosures.
ACT
You conclude that sufficient appropriate audit evidence has been obtained for all material
amounts and disclosures. However, you note the following:
Inventory
You attended the inventory stocktake on 30 June 20X3. During your attendance you inspected
the shelf life of stock items and noticed that some items had ‘best before’ dates that were
either past the date or had only a few weeks to go. When you raised the matter, management
responded that products can legally be sold after the ‘best before’ dates so long as the product is
not damaged, deteriorated or perished.
During the audit, you find that Fluffit’s customers will not accept goods with ‘best before’ dates
that expire within three months, and that such items have minimal sales value. Your audit work
has evaluated that inventory with a carrying value of $400,000 falls into this category, which
is material to Fluffit’s financial statements. Management has declined to adjust the financial
statements on the basis that the products are not legally expired.
Financial statements
Fluffit is required to prepare its financial statements in accordance with International Financial
Reporting Standards (IFRS). You have reviewed the draft financial statements and concluded
they have been materially prepared in accordance with IFRS, with the exception of the item
discussed above.
Annual report
HT has been provided with a draft of all other documents that will go into Fluffit’s annual
report, along with the audited financial statements. One of these documents, the chief
executive officer’s (CEO’s) report, contains a summary of financial performance together with
commentary. You have reviewed all the other documents, including the CEO’s report, and have
discovered that a chart presenting revenue and cost of sales is inconsistent with the revenue
and cost of sales amounts reported in the audited financial statements. The CEO’s commentary
discusses this chart, and presents a view that is inconsistent with Fluffit’s actual performance.
The audit manager has evaluated the inconsistencies as material and has concluded that the
CEO’s report should be amended. He has discussed this with the CEO, who responded that
the chart reflects adjustments to ‘normalise’ the results and is not the concern of the auditors;
therefore, Fluffit would decline to adjust inventory balance in the financial statements or the
CEO’s report.
Legislation requires HT to provide a written auditor’s report and does not permit withdrawal
from the audit.
Task
For this activity, the audit manager has asked you to assist her in preparing a memorandum of
significant audit issues for the audit partner to review. One section of the memorandum will
consider the audit reporting implications. For this activity you are required to:
•• Determine the appropriate auditor’s opinion.
•• Determine whether an Emphasis of Matter (EOM) or Other Matter (OM) paragraph
is required.
ACT
Activity 15.3
Determining auditor’s reporting implications
– subsequent events and going concern
Introduction
This activity demonstrates how events occurring subsequent to the reporting date can impact
the auditor’s opinion and the impact on the auditor’s report of uncertainties regarding going
concern, in accordance with:
•• ISA 560 Subsequent Events (ISA 560).
•• ISA 570 Going Concern (ISA 570).
•• ISA 700 Forming an Opinion and Reporting on Financial Statements (ISA 700).
•• ISA 705 Modifications to the Opinion in the Independent Auditor’s Report (ISA 705).
•• ISA 706 Emphasis of Matter Paragraphs and Other Matter Paragraphs in the Independent Auditor’s
Report (ISA 706).
In order to complete this activity, you will also need to understand the basic principles of
International Accounting Standard IAS 10 Events after the Reporting Period (IAS 10).
This activity links to learning outcomes:
•• Describe and explain the different types of auditor’s reports that an auditor may issue.
•• Identify and justify the choice of the appropriate auditor’s report for an entity based on the
results of audit work conducted for that entity.
Scenario
You are an audit senior working at AAA Chartered Accountants (AAA). BookBooks (BB) is
a listed company. BB is a book wholesaler distributing books to customers in Australia and
New Zealand. You are part of the audit team performing the audit of BB for the year ended
30 June 20X3. BB is required to prepare general purpose financial statements in accordance with
International Financial Reporting Standards (IFRS).
It is 20 August 20X3 and you are working with the audit manager, Christine O’Malley, finalising
the audit. Aside from the matters discussed below, no other matters have been identified as a
result of the audit work.
1. Customer bankruptcy
On 20 July 20X3, BB received a letter from the administrators of a major customer. The letter
indicated that the customer was likely to go into liquidation and, as a result, BB is unlikely to
receive anything significant out of an amount of $1 million owed by the customer at 30 June
20X3.
ACT
2. Going concern
BB’s business has experienced poor trading conditions in recent years, which has put pressure
on the company’s cash flows. The company has a $20 million line of credit facility that is due
for renewal in early December 20X3, which it is hoping to increase to help meet working
capital requirements. There is some doubt whether the existing lender will renew or increase
the facility, and negotiations are in their early stages. If the negotiations are unsuccessful, the
directors believe there could be other lenders, but they have not yet identified a specific source
of alternative funds.
Management has prepared an assessment of the company’s ability to continue as a going
concern, including profit and cash flow forecasts for the period to October 20X4. Management’s
assessment indicates that the company would be unlikely to be able to continue trading beyond
January 20X4 if the company is not able to renegotiate the loan or find alternative funding. The
directors have therefore concluded that there is significant uncertainty regarding BB’s ability to
continue as a going concern.
4. AAA’s audit
AAA has reviewed management’s assessment of going concern, obtaining sufficient appropriate
evidence in respect of the profit and cash flow forecasts and the underlying assumptions. AAA
agrees with the directors’ assessment of a material uncertainty regarding going concern and
with the related disclosures in the financial statements.
AAA has obtained sufficient appropriate audit evidence in respect of all other material
transaction streams, account balances and financial statements disclosures, and has concluded
that the financial statements have otherwise been appropriately prepared in accordance with
IFRS.
Task
For this activity, Christine has asked you to determine the impact of the customer bankruptcy
and the material uncertainty regarding the going concern assumption on the auditor’s report on
BB’s 30 June 20X3 financial statements.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 15.4
Issuing an auditor’s report when financial
statements are not in accordance with the
applicable financial reporting framework
Introduction
The auditor’s report provides information about the auditor’s responsibilities, management’s
responsibilities, the scope of the auditor’s work, and the auditor’s opinion on the financial
statements. It can also include a description of matters that give rise to any modifications of the
auditor’s opinion, and any other matters that, in the auditor’s opinion, should be drawn to the
attention of users of the financial statements.
This activity links to learning outcomes:
•• Describe and explain the different types of auditor’s reports that an auditor may issue.
•• Identify and justify the choice of the appropriate auditor’s report for an entity based on the
results of audit work conducted for that entity.
At the end of this activity, you will be able to understand how the auditor forms an auditor’s
opinion, and the impact on the auditor’s report of financial statements not prepared in
accordance with the applicable financial reporting framework, in accordance with the following
Auditing Standards:
•• ISA 700 Forming an Opinion and Reporting on Financial Statements (ISA 700).
•• ISA 705 Modifications to the Opinion in the Independent Auditor’s Report (ISA 705).
•• ISA 706 Emphasis of Matter Paragraphs and Other Matter Paragraphs in the Independent Auditor’s
Report (ISA 706).
Scenario
You are an audit senior working at Goodadds Chartered Accountants (Goodadds). Goodadds is
the auditor of Grafle, a listed company that manufactures components for specialist agricultural
machinery, and reports its consolidated financial statements under International Financial
Reporting Standards (IFRS). In March 20X3, Grafle acquired 100% of an agriculture machinery
manufacturer, Farmers’ Tools, to which it supplies a large portion of its products.
It is 20 September 20X3, and you are part of the Goodadds team finalising the audit of Grafle for
the year ended 30 June 20X3. During the audit you discovered the following:
•• The new Farmers’ Tools subsidiary has not been consolidated but has instead been
accounted for at cost in the financial statements of Grafle.
•• If the Farmers’ Tools subsidiary was to be consolidated under IFRS then it would have a
material effect on a number of the elements in the financial statements of Grafle.
Goodadds has obtained sufficient appropriate audit evidence and is satisfied that the financial
statements have been prepared in all material respects in accordance with IFRS, and present a
true and fair view, with the exception of the non-consolidation of Farmers’ Tools.
ACT
Task
For this activity, you are required to determine the impact of the non-consolidation of Farmers’
Tools on the auditor’s report on Grafle’s 30 June 20X3 financial statements.
[Solutions to activities are available online. Please access myLearning to view]
CC
Core content
Unit 16: Review engagements
Learning outcomes
At the end of this unit you will be able to:
1. Identify the key differences between an audit and a review engagement.
2. Determine which Standards apply and the assurance practitioner’s responsibilities with
respect to various types of review engagements.
Introduction
There are many different types of assurance engagements that a Chartered Accountant may
be asked to undertake. The primary focus of the Audit & Assurance (AAA) module up to this
point has been on the audit of general purpose financial statements (GPFSs) that are completed
in accordance with the International Standards on Auditing (ISAs). This unit focuses on:
•• review engagements, and
•• how to distinguish between a limited assurance engagement (a review) and a reasonable
assurance engagement (an audit).
As well as addressing the difference between review and audit engagements, this unit
covers the:
•• Concept of assurance as it applies to different types of engagements.
•• Process of identifying specific engagements and the applicable Standards.
•• Assurance practitioner’s key responsibilities with regard to review engagements where
the subject matter is historical financial information.
CC
Learning outcome
1. Identify the key differences between an audit and a review engagement.
Key differences between an audit and a review engagements are summarised in the table below:
Engagement quality control review Listed entities and as required by As required by assurance firm
assurance firm policy policy
Obtaining an understanding of the Sufficient to identify and assess the Sufficient to identify areas in the
entity risk of material misstatement at financial statements where material
the financial statement level and misstatements are likely to arise
assertion levels
CC
Required procedures Plan and perform sufficient Address all material items in the
procedures to reduce the risk financial statements, including
of material misstatement in disclosures. Focus on financial
the financial statements to an statement areas where material
appropriately low level misstatements are likely to arise
Uncorrected misstatements Accumulate, evaluate and request Evaluate and request correction by
correction by management management
The extent of work performed in a review engagement is usually considerably less than that
performed in an audit. If a matter comes to the assurance practitioner’s attention that causes
them to believe that the financial information may be materially misstated, they may extend
the procedures employed in order to draw the appropriate conclusions on the financial
information.
Key differences in evidence-gathering procedures and assurance report conclusions can be
found in the International Framework for Assurance Engagements (International Framework)
paras 77–78 and 85 for reasonable assurance engagements (audits), and paras 79–80 and 86 for
limited assurance engagements (reviews).
Activity 16.1: Determining the difference between review and audit engagements within
the International Framework
[Located at the end of this unit]
Required reading
International Framework paras 2–21, 77–80 and 85–86.
ISRE 2400 (Revised ) Appendix 2.
CC
Learning outcome
2. Determine which Standards apply and the assurance practitioner’s responsibilities with
respect to various types of review engagements.
Where limited assurance is required, the practitioner will apply the International Standards on
Review Engagements (ISREs).
Having concluded that the ISREs apply, the assurance practitioner must then choose the correct
Standard from the ISRE suite of Standards to apply to the particular engagement.
In a review engagement on historical financial information, the key driver that determines
which Standard should be applied is whether the assurance provider is also the auditor of the
entity’s annual financial statements:
•• If the assurance practitioner is the auditor of the entity’s annual financial statements, the
assurance practitioner must apply ISRE 2410.
•• If the assurance practitioner is not the auditor of the entity’s annual financial statements, the
assurance practitioner must apply ISRE 2400 (Revised).
CC
YES
YES
International Standards
Is the engagement
AUDIT on Auditing
an audit or review?
(ISAs)
REVIEW
International Standards on
Review Engagements
(ISREs)
Assurance practitioner
Auditor of the entity who is not the auditor
of the entity
Required reading
ISRE 2400 (Revised) paras 1–2.
ISRE 2410 paras 1–3a.
CC
Australia-specific
Determining whether international or Australian Standards apply
A practitioner in Australia would apply the IAASB’s framework of ISAs, ISREs and ISAEs when
undertaking an engagement for an entity that operates under this international framework –
for example, when the parent entity of a group is based overseas.
If the entity is an Australian company based in Australia, then engagements are normally
performed under the Australian framework (i.e. Australian Auditing and Assurance Standards:
Australian Auditing Standards (ASAs), Australian Standards on Review Engagements (ASREs)
and Australian Standards on Assurance Engagements (ASAEs)).
The Australian Standards for review engagements (ASREs 2400, 2405, 2410 and 2415) are
broadly aligned to the international Standards for review engagements . The international
Standards have been adopted, with modifications, in Australia. These modifications have
arisen primarily as a result of inconsistencies between the Australian legislation regarding the
assurance practitioner’s responsibilities and the requirements of the international Standards.
The Australian and international Standards for review engagements are similar in that the
driver that determines which review Standard applies is whether the assurance practitioner is
the auditor of the entity’s annual financial statements
ASRE 2405 Review of Historical Financial Information Other than a Financial Report
ASRE 2400 and ASRE 2410 are restricted to historical financial information that comprises
financial statements. This restriction has not been placed on their international equivalent
Standards. To deal with this restriction, an additional Standard, ASRE 2405, has been developed
for Australia.
Note: ASRE 2405 is closely aligned to the review principles of ISRE 2400 (Revised) but is not
directly comparable to it.
ASRE 2415 Review of a Financial Report: Company Limited by Guarantee or an Entity Reporting under the
ACNC Act or Other Applicable Legislation or Regulation
An additional Australian-specific review Standard, ASRE 2415, has been developed as a result of
legislative changes regarding companies limited by guarantee and entities required to report
under the Australian Charities and Not-for-Profits Commission Act 2012 (Cth) (ACNC Act) .
Required reading
ASRE 2400 para. 1.
ASRE 2405 para. 1.
ASRE 2410 para. 1.
ASRE 2415 para. 1.
CC
Assurance practitioner
Auditor of the entity who is not the auditor
of the entity
Subject matter − Subject matter − Subject matter − Entity is limited by Entity is limited by
financial report other historical financial report guarantee and guarantee and
financial meets exemption meets exemption
information criteria of criteria of
Corporations Act or Corporations Act or
required to report required to report
under
underthe
theACNC
ACNCAct.
Act under the ACNC Act
Other differences between the Australian and international Standards that apply to review
engagements are also discussed in this unit.
New Zealand-specific
Determining the applicable Standards in New Zealand
XRB Au1 Application of Auditing and Assurance Standards (XRB Au1) sets out the applicable
Standards to be applied by assurance practitioners when conducting different types of
engagements in New Zealand. There are two Standards applicable to review engagements:
•• Review of Historical Financial Statements Performed by an Assurance Practitioner Who is Not
the Auditor of the Entity (ISRE (NZ) 2400).
•• Review of Financial Statements Performed by the Independent Auditor of the Entity
(NZ SRE 2410).
CC
Required reading
XRB Au1.
ISRE (NZ) 2400 paras 1–3 and 14.
NZ SRE 2410 paras 1–5.
Learning outcome
2. Determine which Standards apply and the assurance practitioner’s responsibilities with
respect to various types of review engagements.
The application of ISRE 2400 (Revised) is directed towards the review of financial statements
that comprise historical financial information, by an assurance practitioner who is not the
auditor of the entity. ISRE 2400 (Revised)’s requirements and guidance effectively cover similar
requirements in ISA 200–ISA 706 that are applicable to audits of financial statements, and
are designed to ensure that the assurance practitioner – who initially lacks the same level of
knowledge of the entity as that possessed by the auditor of the entity – undertakes procedures
to ensure they have a knowledge of the entity and its operations that is sufficient to meet the
objectives of the review engagement.
The objective of the practitioner in a review of financial statements (ISRE 2400 (Revised)
para. 14(a)) is to:
… obtain limited assurance, primarily by performing inquiry and analytical procedures, about
whether the financial statements as a whole are free from material misstatement, thereby enabling the
practitioner to express a conclusion on whether anything has come to the practitioner’s attention that
causes the practitioner to believe the financial statements are not prepared, in all material respects, in
accordance with an applicable financial reporting framework.
CC
A review of financial statements differs significantly from an audit of financial statements,
which is conducted in accordance with Auditing Standards.
The discussion below centres on the following two key aspects of those identified above:
(b) To focus on addressing areas in the financial statements where material misstatements are likely to
arise.
CC
The auditor’s responsibilities with regard to enquiry, analytical and other review procedures
are as follows:
•• Enquiries
ISRE 2400 (Revised) para. 48 requires the practitioner to make enquiries of management and
others within the entity, to obtain specific information, including:
–– How management makes significant accounting estimates.
–– Related parties and related party transactions.
–– Significant, unusual or complex transactions, events or matters that have affected or
may affect the entity’s financial statements.
–– Significant changes in business activities, or to terms of contract that materially affect
the entity’s financial statements, including finance and debt contracts or covenants.
–– Significant journal entries or adjustments and significant transactions occurring or
recognised near the end of the reporting period.
–– Existence of any actual, suspected or alleged fraud or illegal acts affecting the entity and
non-compliance with the provisions of laws and regulations.
–– Whether management has identified and addressed subsequent events.
–– The basis of management’s assessment of the entity’s ability to continue as a going
concern and whether there are events or conditions that appear to cast doubt on the
entity’s ability to continue as a going concern.
–– Material commitments, contractual obligations or contingencies.
–– Material non-monetary transactions.
•• Analytical procedures
ISRE 2400 (Revised) para. 49 requires the practitioner to consider whether the data from the
entity’s accounting system is adequate for the purpose of analytical procedures.
Performing analytical procedures can assist the practitioner to:
–– Identify areas where material misstatements are likely to arise in the financial
statements.
–– Identify inconsistencies or variances from expected trends, values or norms in the
financial statements.
–– Corroborate evidence in relation to other enquiry or analytical procedures already
performed (ISRE 2400 (Revised) para. A89).
CC
Unmodified conclusion
An unmodified conclusion is expressed when the practitioner states in the practitioner’s report
(under the heading ‘Conclusion’) that (ISRE 2400 (Revised) para. 74):
(a) “Based on our review, nothing has come to our attention that causes us to believe that the financial
statements do not present fairly, in all material respects (or do not give a true and fair view), … in
accordance with the applicable financial reporting framework,” (for financial statements prepared
using a fair presentation framework); or
(b) “Based on our review, nothing has come to our attention that causes us to believe that the financial
statements are not prepared, in all material respects, in accordance with the applicable financial
reporting framework,” (for financial statements prepared using a compliance framework).
Modified conclusion
If, based on the review procedures performed, the practitioner believes the financial statements
are materially misstated, or is unable to obtain sufficient appropriate evidence in relation to one
or more items in the financial statements that are material to the financial statements as a whole,
the practitioner would express a modified conclusion (ISRE 2400 (Revised) para. 75).
There are three types of modified conclusion:
•• Qualified conclusion.
•• Adverse conclusion.
•• Disclaimer of conclusion.
The following table summarises the circumstances under which a modified conclusion is issued:
Nature of the matter giving rise Practitioner’s judgement about the pervasiveness of the effects
to the modification or possible effects on the financial statements
To recap, ISRE 2400 (Revised) applies to a review of historical information that is not conducted
by the entity’s auditor. Further, ISRE 2400 (Revised) assumes that an assurance practitioner who
is not the entity’s auditor initially does not have the same level of knowledge of the entity as the
auditor.
CC
A summary of the key aspects of ISRE 2400 is tabled below:
Topic Summary
Required reading
ISRE 2400 (Revised) paras 1–23, 30, 36–37, 42–96 and A89.
ISRE 2410 Review of Interim Financial Information Performed by the Independent Auditor
of the Entity
ISRE 2410 was originally introduced to provide a Standard for the performance of a review
of an entity’s interim financial information by an auditor who is also the auditor of the entity.
Interim financial information is financial information that is prepared in accordance with an
applicable financial reporting framework for a period that is shorter than the entity’s financial
year. Examples of interim financial information include half‑yearly financial statements that
are prepared by a publicly listed entity for lodgement with its respective stock exchange, such
as the Australian Securities Exchange (ASX) in Australia, or the New Zealand Exchange (NZX)
in New Zealand.
ISRE 2410 was subsequently amended to include the review of historical financial information
other than interim financial information of an audit client. Such a review is within the scope of
ISRE 2400 (Revised), which is applicable to an assurance practitioner who is not the auditor of
the entity. This means that ISRE 2410 can be applied to the review of financial information for
a financial year as well as a period shorter than a financial year, and includes a single financial
statement (or specific components of a financial statement), other information derived from
financial records, condensed financial statements and a complete set of financial statements
(ISRE 2410 para. 3a).
When conducting a review under ISRE 2410, the assurance practitioner does not provide
reasonable assurance that the historical financial information is free from material misstatement
as they would if conducting an audit of the GPFSs. A review in the context of ISRE 2410 is
similar to that of ISRE 2400 (Revised) (discussed earlier), and consists of making enquiries,
primarily of the persons responsible for financial and accounting matters at an entity, and
applying analytical and other review procedures.
CC
The auditor does not provide ‘an opinion whether the financial information gives a true and
fair view’ or is fairly presented (ISRE 2410 para. 8), because the extent of procedures in a review
engagement does not facilitate the provision of such opinion.
As the auditor is conducting a review, the auditor would not normally test the control
environment. However, the auditor may perform audit procedures on significant or
unusual transactions that have occurred during the period, such as business combinations,
restructurings or significant revenue transactions (ISRE 2410 para. 29).
CC
ISRE 2410 also requires the auditor to include a statement:
•• ‘that the review was conducted in accordance with [ISRE 2410]’ and ‘that such a review
consists of making inquiries, primarily of persons responsible for financial and accounting
matters, and applying analytical and other review procedures’ (ISRE 2410 para. 43(g)), and
•• ‘that a review is substantially less in scope than an audit conducted in accordance with
[ISAs] and consequently does not enable the auditor to obtain assurance that the auditor
would become aware of all significant matters that might be identified in an audit and
accordingly no audit opinion is expressed’ (ISRE 2410 para. 43(h)).
If the auditor believes the historical financial statements are materially misstated, they can
express either a qualified conclusion or an adverse conclusion.
A summary of the key aspects of ISRE 2410 is tabled below:
Topic Summary
Special reporting Follows the set format of the auditor’s conclusion in ISRE 2410 to comply with the
considerations Standard
Required reading
ISRE 2410 paras 1–9, 12–33, 36–64 and Appendix 2.
Worked example 16.1: The assurance practitioner’s responsibilities in the review of financial
statements
[Available online in myLearning]
CC
Australia-specific
Australian review engagement Standards
The Australian suite of review engagements Standards comprises ASRE 2405, ASRE 2400,
ASRE 2410, and ASRE 2415.
ASRE 2400 and ASRE 2410 are broadly consistent with their equivalent ISREs. However, there
are some significant differences between the Australian and international Standards, notably:
•• the application of ASRE 2400 and ASRE 2410 is limited to a full set of financial statements
only, thus resulting in the need for ASRE 2405, for which there is no international
equivalent, and which applies to individual elements of historical financial information.
The ‘Conformity with International Standards on Review Engagements’ section of both ASRE
2400 and ASRE 2410 summarises the additional mandatory requirements, which apply to a
review of a financial report comprising historical financial information.
Required reading
ASRE 2400 paras Aus0.1, 1–3, Aus 3.1 and 14.
ASRE 2410 paras 1–4.
ASRE 2405 Review of Historical Financial Information Other than a Financial Report
Often an assurance practitioner is requested to review historical financial information other
than a financial report. ASRE 2405 was developed by the AUASB to review:
•• Specific components, elements, accounts or items of a financial report, for example:
–– Single financial statement, such as a statement of financial performance or statement
of financial position.
–– Single item, such as accounts receivable and inventory.
–– Asset grouping for impairment or valuation purposes.
•• Other information derived from financial records, for example:
–– Pension scheme’s schedule of externally managed assets and income.
–– Schedule of net tangible assets.
–– Property disbursements schedule for leased property.
–– Schedule of profit participation or employee bonuses.
•• Financial statements prepared in accordance with a financial reporting framework that is
not designed to achieve fair presentation – for example, condensed financial statements
or an entity’s internal management accounts.
The following discussion addresses the key elements of ASRE 2405.
Objective of a review
The practitioner’s objectives in a review of historical financial information other than a
complete set of financial statements are set out in ASRE 2405 para. 16. For an engagement
performed under ASRE 2405, the practitioner is required ‘to express a conclusion whether …
anything has come to [their] attention that causes [them] to believe that the historical financial
information … is not prepared, or prepared fairly, in all material respects’, in accordance with
the applicable reporting criteria.
Planning a review
Under ASRE 2405 para. 25, the practitioner needs to ‘plan the review so that an effective
engagement will be performed’. This will require the practitioner to obtain knowledge,
or update their knowledge, of the business, including its organisation, accounting systems,
operating characteristics and the nature of its assets, liabilities, revenues and expenses.
(See ASRE 2405 paras 25–27.)
CC
If the practitioner believes the historical financial information is materially misstated, they can
express either a qualified conclusion or an adverse conclusion.
How ASRE 2405 conforms with the International Standards on Review Engagements (ISREs)
In drafting ASRE 2405, the AUASB noted that ISRE 2400 (Revised) is applied to engagements
to review other historical financial information, and adapted as necessary in the circumstances.
In addition to ASRE 2400 and ASRE 2410, however, the AUASB decided that the nature of other
historical financial information warranted a separate Standard (i.e. ASRE 2405) to deal more
comprehensively with reviews of other historical financial information.
Therefore, ASRE 2405 is not intended to replicate ISRE 2400 (Revised), but is intended to conform
(with some exceptions) to ISRE 2400 (Revised) to the extent that it addresses reviews of historical
financial information other than a complete set of financial statements (ASRE 2405 para. 67).
The following table summarises the key aspects of ASRE 2405:
Required reading
ASRE 2405 paras 3, 5, 16, 19–20, 24–27, 29–38, 58–64, 67 and Appendix 4.
CC
ASRE 2415 Review of a Financial Report: Company Limited by Guarantee or an Entity Reporting under the
ACNC Act or Other Applicable Legislation or Regulation
The Corporations Act 2001 (Cth) (Corporations Act) was amended in June 2010 to enable certain
companies to have their financial report for a financial year reviewed instead of audited. The
primary reason for the amendments was to reduce costs for companies limited by guarantee,
and certain not-for-profit entities.
Another key legislative change was that the review need not be undertaken by a registered
company auditor; however, the reviewer must hold a practising certificate.
As a result of the changes to the Corporations Act, a number of state governments also
amended their Incorporated Association Acts to allow an incorporated association to be
reviewed by an independent assurance provider, thus removing the obligation for such
associations to be audited.
To give effect to the legislative amendments and provide guidance to practitioners, the AUASB
issued ASRE 2415, which clarifies the appropriate review Standards that practitioners should
apply in particular situations.
ASRE 2415 para. 9 states:
When a company limited by guarantee, or an entity reporting under the ACNC Act, or an entity reporting
under other applicable legislation or regulation, elects to have its financial report reviewed instead of
audited, an auditor who has conducted an audit of the previous financial report of the company or entity in
accordance with the Australian Auditing Standards, shall, in the first financial reporting period under revised
legislation, conduct the review in accordance with ASRE 2410 Review of a Financial Report Performed by the
Independent Auditor of the Entity…
When a company limited by guarantee or an entity reporting under the Australian Charities
and Not-for-Profits Commission Act 2012 (Cth), or an entity reporting under other applicable
legislation or regulation, elects to have its financial statements reviewed instead of audited,
and the review is conducted by a practitioner who was not the auditor of the previous financial
statements, the practitioner must apply ASRE 2400 (ASRE 2415 para. 10).
The following table summarises the key aspects of ASRE 2415:
Topic Summary
Engagement Entity must satisfy the Corporations Act and conditions of an incorporated
acceptance association to be eligible for a review
considerations
The reviewer must hold a practising certificate
Special application If the practitioner was the auditor of the previous period financial statements,
considerations they must apply ASRE 2410 to the current engagement
If the practitioner was not the auditor of the previous period financial
statements, they must apply ASRE 2400 to the current engagement
Required reading
ASRE 2415 paras 9–10.
CC
Quiz
[Available online in myLearning]
Readings
Required reading
ISRE 2400 (Revised) Engagements ASRE 2400 Review of a Financial ISRE (NZ) 2400 Review of Historical
to Review Historical Financial Report Performed by an Assurance Financial Statements Performed by
Statements Practitioner Who is Not the Auditor an Assurance Practitioner Who is Not
of the Entity the Auditor of the Entity
•• Paragraphs 1–23, 30, 36–37, •• Paragraphs AUS 0.1, 1–3, •• Paragraphs 1–23, 30, 36–37,
42–96, A89 and Appendix 2 AUS 3.1, 4–23, 30, 36–37, 42–96, 42–96, A89 and Appendix 2
A89 and Appendix 2
ISRE 2410 Review of Interim ASRE 2410 Review of a Financial NZ SRE 2410 Review of Financial
Financial Information Performed by Report Performed by the Statements Performed by the
the Independent Auditor of the Entity Independent Auditor of the Entity Independent Auditor of the Entity
•• Paragraphs 1–9, 12–33, 36–64 •• Paragraphs 1–10, 13–22, 25–44, •• Paragraphs 1–11, 14–23, 26–45,
and Appendix 2 A4, A11, A20 and Appendix 2 A4, A11, A20 and Appendix 2
Further reading
There is no further reading for this unit.
ACT
Activity 16.1
Determining the difference between
review and audit engagements within the
International Framework
Introduction
Assurance practitioners are requested to perform different services for clients for a variety
of reasons. When considering client requests, practitioners must consider the wishes of the
client with reference to the International Framework for Assurance Engagements (International
Framework).
This activity links to learning outcome:
•• Identify the key differences between an audit and a review engagement.
At the end of this activity, you will be able to distinguish between review and audit
engagements, in accordance with the International Framework.
It will take you approximately 20 minutes to complete.
Scenario
You are a senior auditor working for Finch Dawson and Associates (FDA), a national accounting
firm. One of your largest clients, Magic Mick’s Electronics Limited (MME), has recently
embarked on a growth by acquisition program.
In 20X3, the board of MME decided to investigate the purchase of two separate entities:
•• Precision Chips Inc., a silicon chip manufacturer based in the United States (US).
•• New Technology Inc., an electronic research and development company, also based in
the US.
The directors of MME are anxious to ensure that they pay the lowest possible price for their
investment in these companies, and have asked FDA to help them conduct a ‘due diligence’
investigation of the entities.
MME intends to keep the entities running as separate concerns, it is therefore looking for some
assurance that the entities’ financial statements as at 31 March 20X3 have been prepared, in all
material respects, in accordance with the applicable financial reporting framework.
The engagement partner, Matt Graham, has agreed with MME’s board to perform a review
of the financial statements of Precision Chips Inc. and New Technology Inc. for the period
ending 31 March 20X3.
Matt has told you that this is an important engagement, which will involve flying the team to
the US to perform the two review engagements. The team members who are available to travel
to the US have only worked on audit engagements before; however, they are familiar with US
generally accepted accounting principles (US GAAP), due to their work with other clients who
are subsidiaries of US parent entities.
Matt has advised that these engagements are to be performed applying the International
Standards on Review Engagements (ISREs).
ACT
Task
For this activity, you are required, for the purposes of the initial team briefing, to summarise the
key differences between a review engagement and an audit.
Explain how this applies to the two review engagements that FDA is to perform for MME.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 16.2
Reviewing financial statements
Introduction
Companies are required to prepare half-yearly financial statements for a variety of reasons.
Depending on jurisdictional legislation, or requirements of the users, half-yearly financial
statements may be reviewed by the auditor of the entity’s full-year financial statements.
This activity links to learning outcome:
•• Determine which Standards apply and the assurance practitioner’s responsibilities with
respect to various types of review engagements.
At the end of this activity, you will be able to determine the assurance practitioner’s
responsibilities with respect to review engagements, in accordance with the following relevant
Standards:
Scenario
You are a senior accountant working for AAA Chartered Accountants (AAA), a successful
national accounting firm.
One of your clients is AquaFun, a privately owned business that operates one of the country’s
largest theme parks, Wild Water World (WWW). AquaFun engaged AAA for the first time for
the audit of its financial statements for the year ended 30 June 20X3. AAA completed the audit
in August 20X3.
It is now December 20X3, and AquaFun’s bank has requested that AquaFun supply its interim
general purpose financial statements for the six months ended 31 December 20X3, accompanied
by an assurance report from its auditor (i.e. AAA). The bank has requested that this information
be provided by the end of January 20X4.
AquaFun’s chief financial officer (CFO) is concerned about the cost of AAA providing assurance
on the 31 December 20X3 financial statements, and about the short time frame in which
AquaFun must attend to the bank’s request. The CFO has suggested to AAA that it won’t need
to perform any procedures on the comparative data, since it audited the financial report for the
year ended 30 June 20X3. He has also requested a discounted fee on the same grounds.
Task
For this activity, you are required to outline how AAA should respond to the concerns
of AquaFun’s CFO, as well as his suggestion regarding procedures relative to providing
assurance on the financial statements.
CC
Core content
Unit 17: Other assurance engagements and
agreed-upon procedures engagements
Learning outcomes
At the end of this unit you will be able to:
1. Determine which Standards apply to other assurance engagements.
2. Identify and explain the assurance practitioner’s responsibilities with respect to other
assurance engagements.
3. Outline the principles of an agreed-upon procedures engagement.
Introduction
There are many different types of other assurance engagements that a Chartered Accountant
may be asked to undertake. These engagements were briefly outlined in the unit on assurance
purpose and framework. The primary focus of the Audit & Assurance (AAA) module up to
this point has been on the most common engagements – that is, the audit of general purpose
financial statements (GPFS), which are completed under International Standards on Auditing
(ISAs), and review engagements, which were discussed in the previous unit.
In this unit, the scope of engagements is broadened to encompass other types of assurance
engagements that may be performed under ISAs or applicable national Standards, as well as
engagements that do not provide any level of assurance.
This unit addresses:
•• The concept of assurance as it applies to different types of engagements.
•• The process of identifying specific engagements and the Standards that apply to them.
•• An assurance practitioner’s key responsibilities with regard to different engagements.
The discussion will focus broadly on what an assurance practitioner can and cannot do under
the Standards covered in this unit.
aaa11617_csg
CC
Learning outcomes
1. Determine which Standards apply to other assurance engagements.
2. Identify and explain the assurance practitioner’s responsibilities with respect to other
assurance engagements.
In the unit on assurance purpose and framework, the elements and objectives of an assurance
engagement were introduced. This unit expands on the material covered in earlier units by
specifically identifying the Standards that apply to other assurance engagements and outlining
the assurance practitioner’s responsibilities under each Standard.
Levels of assurance
According to the International Framework for Assurance Engagements (International Framework),
and as discussed in previous units, practitioners can provide two levels of assurance. These are:
•• Reasonable assurance.
•• Limited assurance.
The difference between a reasonable assurance engagement and limited assurance engagement
is reflected in the nature of the work that is performed, level of engagement risk, and type of
conclusion each engagement provides. Put simply, limited assurance conveys less confidence
than reasonable assurance. It is not possible for the auditor to provide absolute assurance.
Further, outside of the International Framework, pronouncements issued by the International
Auditing and Assurance Standards Board (IAASB) also include engagements of an audit nature
that do not provide any assurance.
These engagements are referred to as related services. An example of this type of engagement
is an agreed-upon procedures engagement, where an assurance practitioner performs selected
procedures as agreed with the client and then issues a report of factual findings outlining the
results of the work performed. Agreed-upon procedures engagements are discussed in the final
section of this unit.
CC
CC
In addition to international Standards, the following flow chart includes Australian and New
Zealand Standards that are discussed in this unit:
CC
Australia-specific
CC
New Zealand-specific
ISA 800 addresses specific additional requirements that the auditor needs to fulfil for audits
of SPFS. However, all of the concepts covered in earlier units, such forming an opinion and
issuing an auditor’s report, also apply to an engagement under ISA 800, even though they were
discussed in the context of GPFS.
Australia-specific
In Australia, compliance with ASA 800 Special Considerations – Audits of Financial Reports
Prepared in Accordance with Special Purpose Frameworks (ASA 800) enables compliance with
ISA 800. However, please note that ASA 800 contains additional requirements that outline the
applicable framework for ‘non-reporting’ entities under the Corporations Act 2001 (Cth).
CC
The audit engagements for GPFS and SPFS are similar in many ways. However, additional
responsibilities apply to auditors performing audits of SPFS engagements, which are outlined in
the table below:
Topic Summary
Engagement Before accepting an engagement under ISA 800, para. 8 of the Standard requires the
acceptance auditor to determine the acceptability of the special purpose framework that has been
considerations applied to the preparation of the SPFS
This includes obtaining an understanding of the:
•• Purpose for which the financial statements have been prepared
•• Intended users and their information needs
•• Steps taken by management to determine that the framework is acceptable
Special reporting The auditor’s report on the SPFS must always include an Emphasis of Matter (EOM)
considerations paragraph alerting users that the financial statements have been prepared in
accordance with a special purpose framework and that, as a result, the SPFS may not
be suitable for another purpose (ISA 800 para. 14)
Required reading
ISA 800 paras 6–14, A5–A6 and A14 –A15.
CC
For auditors who perform audits of single financial statements or components of financial
statements, the key responsibilities outlined in the table below apply:
Topic Summary
Engagement Before accepting an engagement under ISA 805, para. 8 of the Standard requires the
acceptance auditor to consider whether the financial reporting framework applied will provide
considerations adequate disclosure to enable the intended users to understand the information
conveyed, and the effect of material transactions and events on that information
In addition, while ISA 805 does not preclude an auditor who did not audit the entity’s
financial statements from conducting the audit of a single financial statement
or component of the financial statements, the auditor must determine whether
conducting the audit in accordance with Auditing Standards is practicable
Special reporting ISA 805 contains specific requirements that relate to the impact on the opinion
considerations for this type of engagement if the auditor’s report on the complete set of financial
statements is modified or the report includes an Emphasis of Matter (EOM) or Other
Matters (OM) paragraph (ISA 805 paras 14–17)
For instance, if an adverse opinion or disclaimer of opinion is formed on the complete
set of financial statements, it is not permitted to express an unmodified opinion on a
single financial statement forming part of those complete financial statements
Required reading
ISA 805 paras 6–17.
CC
Because SFS are derived from complete financial statements that have been audited, only the
auditors of those financial statements may undertake this type of engagement (ISA 810 para. 5).
This impacts on the auditor’s responsibilities in undertaking SFS, as outlined in the table below:
Topic Summary
Engagement acceptance An engagement to audit SFS under ISA 810 may only be accepted where the
considerations auditor is also engaged to perform the audit of the financial statements (in
accordance with ISAs) from which the SFS are derived (ISA 810 para. 5)
In addition, the auditor must:
•• Determine whether the applied criteria are acceptable
•• Obtain management’s agreement that it acknowledges and understands its
responsibilities, and agree on the form of opinion to be expressed
Specific engagement ISA 810 para. 8 outlines a list of procedures that the auditor must perform in
procedures or issues addition to any other procedures they consider necessary (details of which are
outside the scope of this unit)
Special reporting The report on the SFS may be dated later than the report on the audited
considerations financial statements. Where this is the case, the auditor’s report must state that
the SFS (and audited financial statements, if applicable) do not reflect events
subsequent to the date of the audited financial statements
In addition, ISA 810 para. 14(c) also requires that the auditor’s report include an
introductory paragraph disclosing information that is specific to the SFS or the
audit to which they relate
If the SFS are not consistent with, or not a fair summary of, the audited financial
statements, the auditor will express an adverse opinion ( ISA 810 para. 19)
Required reading
ISA 810 paras 4–8, 12–19, A1 and A4–A5.
CC
(b) Completeness: Criteria are complete when subject matter information prepared in accordance
with them does not omit relevant factors that could reasonably be expected to affect decisions of
the intended users made on the basis of that subject matter information. Complete criteria include,
where relevant, benchmarks for presentation and disclosure.
(c) Reliability: Reliable criteria allow reasonably consistent measurement or evaluation of the
underlying subject matter including, where relevant, presentation and disclosure, when used in
similar circumstances by different practitioners.
(d) Neutrality: Neutral criteria result in subject matter information that is free from bias as appropriate
in the engagement circumstances.
(e) Understandability: Understandable criteria result in subject matter information that can be
understood by the intended users.
ISAE 3000 (Revised) discusses, in general, a number of concepts for an assurance practitioner
to consider or follow when applying specific ISAEs to a given engagement. These concepts
include:
•• Ethical requirements.
•• Engagement acceptance and continuance.
•• Quality control.
•• Application of professional scepticism, professional judgement and assurance skills and
techniques.
•• Planning.
•• Performing the engagement.
CC
•• Forming the assurance conclusion and preparing the assurance report.
•• Documentation.
The most important of these concepts are outlined in the table below:
Topic Summary
Engagement ISAE 3000 (Revised) para. 22 details a number of considerations that the practitioner needs
acceptance to consider before accepting an engagement. These include:
considerations
•• Meeting the ethical and independence requirements
•• Being satisfied that the persons performing the engagement collectively have the
appropriate competence and capabilities
•• Having an agreement on the basis on which the engagement is to be performed.
This includes establishing that preconditions for the engagement have been met and
the practitioner and the engaging party have agreed the terms of engagement and
reporting responsibilities. Preconditions for the engagement are listed in ISAE 3000
(Revised) para. 24 .
Planning The practitioner plans an assurance engagement so that it will performed in an effective
considerations manner, including setting the scope, timing and direction of the engagement, and
determining the nature, timing and extent of planned procedures
The practitioner sets materiality for planning and performing the engagement, and
to evaluate whether the subject matter is free from material misstatement (ISAE 3000
para. 44)
Engagement The practitioner obtains an understanding of the subject matter, identifies risks and
performance responds to those risks. The nature of procedures depends on the level of assurance
considerations provided
ISAE 3000 paras 46L–49L provide specific guidance for limited assurance engagements,
whereas paras 46R–48R include guidance for reasonable assurance engagements
Special reporting The output of an assurance engagement is a written report available to third parties
considerations
ISAE 3000 (Revised) para. 69 identifies basic elements to be included in the assurance
report. These include:
•• A title and an addressee
•• Level of assurance provided
•• Identification or description of the subject matter information
•• Identification of the applicable criteria
•• A statement that the engagement was performed under ISAE 3000 or a subject matter-
specific ISAE
•• A statement of compliance with ethical and quality control requirements
•• Summary of work performed
•• The practitioner’s conclusion (the form of which depends on the level of assurance
being provided)
Required reading
ISAE 3000 (Revised) paras 1–6, 12, 14, 20–22, 24, 32–33, 37–51, 64–77, A40 and A45.
CC
Prospective financial information takes many forms, but is commonly seen in documents such
as prospectuses, cash flow forecasts and information provided to stock exchanges by listed
entities, such as revenue or profit forecasts.
The following example illustrates prospective financial information in the form of a graph,
presenting XYZ Limited (XYZ)’s past and future annual revenue, which might be included in its
prospectus:
Annual
Historical Prospective
revenue
financial information financial information
$’000
Information derived
4,000 from XYZ’s past
economic events
3,000
Forecast Projection
20X0 20X1 20X2 20X3 20X4 20X5 20X6 20X7 20X8 20X9
Year
CC
Topic Summary
Level of assurance •• Provides moderate* assurance that the financial information is properly based on
the assumptions and:
– When based on best estimate assumptions, that the assumptions are not
unreasonable
– When based on hypothetical assumptions, that the assumptions are consistent
with the purpose of the information
•• No opinion is expressed on whether the results shown in the prospective financial
information will be achieved
* Moderate assurance as referred to in this Standard has the same meaning as limited assurance in
the Auditing Standards
Engagement While the Standards detail a number of items that the practitioner would consider
acceptance before accepting an engagement, the overriding principle, in both the international
considerations and national Standards, is that an engagement should not be accepted ‘when the
assumptions are clearly unrealistic or the practitioner believes that the prospective
financial information will be inappropriate for its intended use’ (ISAE 3400 para. 11)
Specific engagement At a high level, the type of procedures that would be conducted include:
procedures or issues
•• Obtaining a sufficient level of knowledge of the business to evaluate the
assumptions, including knowledge obtained in any previous engagements
•• Assessing the extent to which reliance on the entity’s historical financial information
is justified
•• Considering the period of time covered by the prospective financial information
•• Assessing management’s competence with regard to the preparation of prospective
financial information, and the extent to which the information is affected by
management’s judgement
•• Considering the adequacy and reliability of the underlying data
Required reading
ISAE 3400 paras 1–5, 8–9, 11, 13–17 and 26–29.
CC
Australia-specific
In Australia, ASAE 3450 Assurance Engagements involving Corporate Fundraisings and/or
Prospective Financial Information (ASAE 3450) deals with engagements that involve corporate
fundraisings and/or prospective financial information.
Despite apparent similarities in the topic titles in ASAE 3450 and ISAE 3400, ASAE 3450 is much
broader in scope than ISAE 3400. It also contains mandatory requirements for the assurance
practitioner that ISAE 3400 does not. Accordingly, ASAE 3450 states that there is no equivalent
ISAE issued by the IAASB.
Some of the significant differences between the two Standards are noted below:
•• Scope – ASAE 3450 deals with engagements that involve corporate fundraisings and/or
prospective financial information. ASAE 3450 includes engagements involving historical
financial information, pro forma historical financial information, projection and pro forma
forecast, as well as engagements that involve prospective financial information. ISAE 3400,
however, only deals with engagements involving prospective financial information.
•• Level of assurance – under ASAE 3450 para. 8, an assurance practitioner can provide the
following types of assurance on the different types of financial information:
–– Historical financial information – limited or reasonable assurance.
–– Pro forma historical financial information – limited or reasonable assurance.
–– Prospective financial information assumptions – limited assurance.
–– Prospective financial information basis of preparation – limited or reasonable
assurance.
–– Prospective financial information (overall) – limited assurance.
•• Examples of an assurance practitioner’s report – examples of an assurance practitioner’s
report on an examination of prospective financial information, or extracts of such reports,
can be found in ASAE 3450 Appendix 3.
Required reading
ASAE 3450 paras 1, 3, 5–9, 12–16, 49, 95, 104, 106, 118, 127, 136 and A85.
New Zealand-specific
New Zealand does not have a national equivalent of ISAE 3400.
Assurance engagements on prospective financial information are conducted in accordance
with ISAE (NZ) 3000 (Revised).
CC
Compliance engagements
Many entities have obligations to comply with externally or internally imposed requirements
that relate to their operations. A compliance engagement reports on whether an entity has met
those requirements.
These obligations are often regulatory or legal – for example, the obligations of certain entities
under corporations regulations, or charities under fundraising legislation. Alternatively,
compliance engagements may be completed on internally imposed requirements – for example,
when a company board requests an engagement to ascertain whether management has
complied with policies that the board has set, such as a risk management framework.
Therefore, the subject matter of a compliance engagement may be quite broad. The subject
matter must be identifiable and can be subject to procedures for gathering sufficient appropriate
evidence. There is no specific International Standard on Assurance Engagements (ISAE) on
compliance engagements, therefore ISAE 3000 (Revised), if applying international Standards, is
the most appropriate.
Topic Summary
Specific The relevant Standards provide guidance on what may be appropriate subject
engagement matter and suitable criteria used in a compliance engagement (which include
procedures or internally and externally imposed criteria). Where criteria are prescribed by
issues legislation or regulation, they are deemed suitable if they meet the definition
(including examples) under ASAE 3100 paras 11(m) and 38/SAE 3100 paras A3 and A9
If any compliance breach is identified, the assurance practitioner, under ASAE 3100
paras 49–50/SAE 3100 paras A43–A44, must:
•• Assess whether the breach is material in the context of the criteria used
•• Consider any materiality specified in the terms of engagement
•• Consider relevant legislative, regulatory or other requirements that may apply
•• Consider the interests of intended users
Special reporting ASAE 3100 para. 80/SAE 3100 para. 58 identifies the basic elements of the
considerations compliance report, many of which are consistent with other assurance reports
Key elements that are specific to compliance reports include the:
•• Identification and description of the requirements
•• Identification of the suitable criteria
•• Level of assurance being provided under ASAE 3100
•• Summary of the work performed
•• Assurance practitioner’s conclusion (the form of which depends on the level of
assurance being provided)
In addition to the compliance report, ASAE 3100 para. 68/SAE 3100 para. 48 requires
the assurance practitioner ‘as soon as practicable’ to inform the responsible party of
any ‘material deficiencies and/or compliance breaches’
CC
Australia-specific
Required reading
ASAE 3100 paras 1–12, 17–19, 33, 36–38, 49–50, 64, 68 and 80.
New Zealand-specific
This example illustrates a compliance engagement in New Zealand.
Required reading
SAE 3100 paras 1–14, 17–18, 26–28, 47–49, 58, A7–A9, A43–A44 and A53.
CC
Performance engagements
In a performance engagement, an assurance practitioner reports on or more of the economy,
efficiency and effectiveness of the activities or a particular entity against identifiable criteria.
There is no specific ISAE on compliance engagements, therefore ISAE 3000 (Revised), if
applying international Standards, is the most appropriate.
Performance engagements are common in the public sector and will be discussed in more detail
in the following unit on internal audit and public sector auditing.
Australia-specific
Topic Summary
Specific engagement The two key requirements for practitioners in a performance engagement are
procedures or issues the:
•• Need for the assurance practitioner to assess the appropriateness of the
activity
•• Suitability of the criteria being used to evaluate or measure the activity
Evaluation of any deficiencies or variations identified may require the exercise
of significant professional judgement
Special reporting ASAE 3500 para. 83 identifies the basic key elements of the assurance report,
considerations many of which are consistent with other assurance reports.
Key elements specific to performance engagements include the:
•• Identification and description of the activity (including whether the
economy, efficiency or effectiveness of the activity is the subject matter of
the engagement)
•• Identification of the suitable criteria
•• Level of assurance being provided under ASAE 3500
•• Summary of the work undertaken
•• Assurance practitioner’s conclusion (the form of which will depend on the
level of assurance being provided)
CC
Required reading
ASAE 3500 paras 1–10, 12, 15, 17–18, 28, 36–37, 40, 44–48 and 83.
New Zealand-specific
There is no international Standard or ISAE (NZ) that relates to performance engagements in
the private sector. The concepts of ISAE (NZ) 3000 would prevail. Performance engagements
performed in the public sector by the Auditor-General are performed under AG-5 Performance
audits, other auditing services and other work carried out by or on behalf of the Auditor-General.
CC
Key responsibilities of the service auditor in an engagement reporting on control procedures at
a service organisation are outlined in the table below:
Topic Summary
Level of Reasonable
assurance
Specific The engagement may also cover one or both of the following aspects (ISAE 3402 para. 8):
engagement
•• Evaluating whether the service organisation’s description of its system ‘fairly presents the
procedures or
system as designed and implemented throughout the specified period’, and evaluating
issues
the design effectiveness of the control procedures
•• Testing the operating effectiveness of the control procedures
Where the engagement covers operating effectiveness over a period of time, the tests
need to be performed over a period of time that is sufficient to determine whether the
procedures were operating effectively throughout the given period
Special reporting Under ISAE 3402, two types of reports can be issued (ISAE 3402 paras 9(j) and 9(k)):
considerations
•• Type 1 report – a report about whether the service organisation’s description of its
system ‘fairly presents the system as designed and implemented’ at the specified date,
and the suitability of the design at the specified date
•• Type 2 report – a report about whether the service organisation’s description of
its system ‘fairly presents the system as designed and implemented throughout
the specified period’, and the suitability of the design and the system’s operating
effectiveness throughout the specified period
Note that these are the same Type 1 and Type 2 reports referred to in ISA 402, and which
were discussed in the unit on understanding the entity and its environment
ISAE 3402 paras 53–54 outlines the required elements of a report on the effectiveness of
control procedures, which include:
•• Identification of the service organisation’s description of its system and the assertion by
the service organisation regarding its system
•• Identification of those parts of the service organisation’s description of its system, if any,
that are not covered by the practitioner’s opinion
•• Identification of the criteria and the party specifying the control objectives
•• A statement of the limitations of the controls and, in the case of Type 2 reports, of the
risk of projecting into future periods any evaluation of the operating effectiveness of the
controls
Required reading
ISAE 3402 paras 1–5, 8–9, 15, 23–24 and 53–56.
CC
Topic Summary
Specific In performing engagements over entity’s controls, the assurance practitioner first
engagement concludes whether the controls are suitably designed. In order to evaluate the design
procedures or of controls, the control objectives need to be developed or identified. If applicable,
issues the practitioner may report on fair presentation of the description of the system,
implementation of the controls as designed and/or that controls are operating as
designed
Assurance engagements on controls may include, for example:
CC
Topic Summary
Special The assurance practitioner forms a conclusion and prepares the assurance report in
reporting accordance with ASAE 3000. In addition, ASAE 3150 para. 89 includes a number of
considerations elements that must be included in the assurance report
Required reading
ASAE 3150 / SAE 3150 paras 1–9 ,15, 18–25, 37, 39, 45–61, 63, 84, 88–89.
Australia-specific
In Australia, ASAE 3420 Assurance Engagements to Report on the Compilation of Pro Forma
Historical Financial Information Included in a Prospectus or other Document (ASAE 3420) was
reissued and is operative for reporting periods commencing on or after 1 January 2015.
Early adoption of this Standard is permitted only in conjunction with the early adoption of
ASAE 3000 (Revised).
For a practitioner in Australia conducting such an engagement, ASAE 3420 enables compliance
with ISAE 3420 to the extent that the engagement is conducted as a reasonable assurance
engagement.
It is important to note when ASAE 3420 or ASAE 3450 applies. ASAE 3420 applies when an
assurance practitioner’s sole responsibility is to report on whether the pro forma financial
information has been compiled, ‘in all material respects, by the responsible party on the basis of
the applicable criteria’ (ASAE 3420 para. 2). ASAE 3450, however, deals with the responsibilities
of an assurance practitioner undertaking an engagement to report on the preparation of
financial information related to corporate fundraising, or, in the case of prospective financial
information, prepared for another purpose
CC
A practitioner’s key responsibilities when reporting on the process of compilation of pro forma
financial information included in a prospectus under ISAE 3420 are outlined in the table below:
Practitioner’s responsibilities – reporting on the compilation of pro forma financial information included
in a prospectus
Topic Summary
Engagement acceptance To accept an engagement to report on the compilation of pro forma financial
considerations information that is included in a prospectus, the practitioner, among other
things, must (ISAE 3420 para. 13):
•• Determine that the practitioner has the appropriate capabilities and
competence within the team to perform the engagement
•• Determine the suitability of the applicable criteria being used, and that it is
unlikely that the pro forma financial information will be misleading for its
intended purpose.
•• Consider ‘whether or not the relevant law or regulation permits the use of, or
reference in the practitioner’s report to, the modified audit opinion or review
conclusion, or the report’ that contains the EOM paragraph, with respect to
the source from which the unadjusted financial information is extracted
•• Obtain the agreement of the responsible party that it acknowledges and
understands its responsibility in respect of specified matters (ISAE 3420
para. 13(g))
Specific engagement ISAE 3420 contains a number of specific procedures that must be performed
procedures or issues depending on the scope of the engagement (details of which are outside the
scope of this unit)
Special reporting The assurance report must include, among others, the following main elements:
considerations
•• A title that clearly indicates the report is an independent assurance report
(ISAE 3420 para. 35(a))
•• Introductory paragraphs that identify (ISAE 3420 para. 35(c)):
(i) The pro forma financial information;
(ii) The source from which the unadjusted financial information has
been extracted, and whether or not an audit or review report on
such a source has been published;
(iii) The period covered by, or the date of, the pro forma financial
information; and
(iv) A reference to the applicable criteria on the basis of which the
responsible party has performed the compilation of the pro forma
financial information, and the source of the criteria;
•• An EOM paragraph, if required (ISAE 3420 para. 34)
Required reading
ISAE 3420 paras 1–7, 10–15, 17–22 and 29–35.
CC
A greenhouse gas (GHG) statement quantifies an entity’s GHG emissions for a period along
with providing explanatory material. Entities may prepare a GHG statement voluntarily, or,
more often, to comply with a regulatory regime.
Engagements to provide assurance over GHG statements are conducted under ISAE 3410
Assurance Engagements on Greenhouse Gas Statements (ISAE 3410). The equivalent national
Standards are ASAE 3410 in Australia and ISAE (NZ) 3410 in New Zealand. These Standards
are outside the scope of AAA module.
Activity 17.4: Identifying the most appropriate assurance engagement and performing the
engagement
[Located at the end of this unit]
CC
Learning outcome
3. Outline the principles of an agreed-upon procedures engagement.
In some circumstances, an entity may not necessarily require a report that provides assurance
on a given subject matter but still want a third party to carry out certain procedures on the
subject matter. In such a case, the entity can request an agreed-upon procedures engagement.
Level of assurance
In an agreed-upon procedures engagement, an assurance practitioner carries out procedures of
an audit nature as agreed with the engaging party, but does not provide or imply a conclusion
or assurance.
Instead, the practitioner completes only those procedures that are outlined in the engagement
letter, and reports only the factual findings of those procedures. Users of the engagement report
must then assess the procedures and findings for themselves and draw their own conclusions.
CC
The practitioner’s responsibilities in an agreed-upon procedures engagement are outlined in the
table below:
Topic Summary
Specific engagement In performing the engagement, the practitioner must carry out only those
procedures or issues procedures agreed on, and use the results to provide a report of factual findings
Special reporting The report on the agreed-upon procedures engagement describes both the
considerations purpose and agreed-upon procedures of the engagement ‘in sufficient detail
to enable the user to understand the nature and extent of the work performed’
(ISRS 4400 para. 17)
ISRS 4400 para. 18 outlines the elements that a report should contain to achieve
this. The most significant of these elements are:
•• A statement that the procedures performed were those agreed upon with’
the engaging party
•• Identification of the purpose for which the agreed-upon procedures were
performed’
•• A list ‘of the specific procedures that were performed’
•• A description of the practitioner’s factual findings, including sufficient details
of any errors and exceptions that they found
•• A statement that the procedures performed ‘do not constitute either an audit
or a review, and, as such, no assurance is expressed’
Required reading
ISRS 4400 paras 2, 4–6 and 15–18.
Australia-specific
In Australia, compliance with ASRS 4400 Agreed-Upon Procedures Engagements to Report Factual
Findings (ASRS 4400) enables compliance with ISRS 4400.
CC
Required reading
ASRS 4400 paras 4–6, 11, 21, 23, 28–30 and A15.
New Zealand-specific
In New Zealand, the following NZICA statement and guideline apply in relation to agreed-upon
procedures engagements:
•• APS-1 Statement of Agreed-Upon Procedures Engagement Standards (APS-1).
•• APG-1 Guideline on Performance of an Agreed-Upon Procedures Engagement (APG-1).
Required reading
APS-1 paras 4–8 and 8.1–8.3.
APG-1 paras 1–3, 5, 8 and 11.
CC
Form and content of report: Factual findings, no conclusion or Conclusion providing assurance
assurance provided
Reporting of procedures Details of the exact nature, timing Summary of work performed
performed: and extent of all procedures
performed are reported
Required reading
ASRS 4400 Appendix 1.
CC
Other services
Assurance practitioners can apply assurance skills and techniques to wide range of services.
These can include engagements or services that are not of an audit nature – such as advisory,
accounting or taxation services.
Some of these other services are discussed below.
Quiz
[Available online in myLearning]
Readings
Required reading
Relevant International Standards on Auditing and assurance pronouncements and national equivalents
and guidance
International Australia New Zealand
ISA 800 Special Considerations ASA 800 Special Considerations – ISA (NZ) 800 Special Considerations
– Audits of Financial Statements Audits of Financial Reports Prepared – Audits of Financial Statements
Prepared in Accordance with Special in Accordance with Special Purpose Prepared in Accordance with Special
Purpose Frameworks Frameworks Purpose Frameworks
•• Paragraphs 6–14, A5–A6 and •• Paragraphs 6–14, A5–A6 and •• Paragraphs 6–14, A5–A6 and
A14–A15 A14–A15 A14–A15
ISA 805 Special Considerations – ASA 805 Special Considerations – ISA (NZ) 805 Special
Audits of Single Financial Statements Audits of Single Financial Statements Considerations – Audits of Single
and Specific Elements, Accounts or and Specific Elements, Accounts or Financial Statements and Specific
Items of a Financial Statement Items of a Financial Statement Elements, Accounts or Items of a
Financial Statement
•• Paragraphs 6–17 •• Paragraphs 6–17 •• Paragraphs 6–17
ISA 810 Engagements to Report on ASA 810 Engagements to Report on ISA (NZ) 810 Engagements to Report
Summary Financial Statements Summary Financial Statement on Summary Financial Statements
•• Paragraphs 4–8, 12–19, A1 and •• Paragraphs 4–8, 12–19, A1 and •• Paragraphs 4–8, 12–19, A1 and
A4–A5 A4–A5 A4–A5
ISAE 3000 (Revised) Assurance ASAE 3000 (Revised) Assurance ISAE (NZ) 3000 (Revised) Assurance
Engagements Other than Audits Engagements Other than Audits Engagements Other than Audits
or Reviews of Historical Financial or Reviews of Historical Financial or Reviews of Historical Financial
Information Information Information
•• Paragraphs 1–6,12, 20–22, 24, •• Paragraphs 1–6, 12, 20–22, 24, •• Paragraphs 1–6, 12, 20–22, 24,
32–33, 37–51, 64–77 and A45 32–33, 37–39, 64–77 and A45 32–33, 37–39, 64–77 and A45
N/A - refer to ISAE 3000 (Revised) ASAE 3100 Compliance SAE 3100 Compliance Engagements
Engagements
•• Paragraphs 1–12, 17–19, 33, •• Paragraphs 1–14, 17–18, 26–28,
36–38, 49–50, 64, 68 and 80 47–49, 58, A7–A9, A43–A44
and A53
N/A - refer to ISAE 3000 (Revised) ASAE 3150 Assurance engagements SAE 3150 Assurance engagements
on Controls on Controls
•• Paragraphs 1–9 ,15, 18-25, 37, •• Paragraphs 1–9 ,15, 18-25, 37,
39, 45-61, 63, 84 and 88–89 39, 45-61, 63, 84 and 88–89
Relevant International Standards on Auditing and assurance pronouncements and national equivalents
and guidance
International Australia New Zealand
ISAE 3400 The Examination of ASAE 3450 Assurance Engagements N/A
Prospective Financial Information involving Corporate Fundraisings
and/or Prospective Financial
Information
•• Paragraphs 1, 3, 5–9, 12–16,
•• Paragraphs 1–5, 8–9, 11, 13–17
49, 95, 104, 106, 118, 127, 136
and 28–29
and A85
ISAE 3402 Assurance Reports on ASAE 3402 Assurance Reports on ISAE (NZ) 3402 Assurance Reports on
Controls at a Service Organization Controls at a Service Organisation Controls at a Service Organisation
•• Paragraphs 1–5, 8–9, 15, 23–24 •• Paragraphs 1–5, 8–9, 15, 23–24 •• Paragraphs 1–5, 8–9, 15, 23–24
and 53–56 and 53–56 and 53–56
ISAE 3410 Assurance Engagements ASAE 3410 Assurance Engagements ISAE (NZ) 3410 Assurance
on Greenhouse Gas Statements on Greenhouse Gas Statements Engagements on Greenhouse Gas
Statements
•• Paragraphs 1–5, 9, 13, 15–17, •• Paragraphs 1–5, 9, 13, 15–17, •• Paragraphs 1–5, 9, 13, 15–17,
72–77 and A18 72–77 and A18 72–77 and A18
ISAE 3420 Assurance Engagements ASAE 3420 Assurance Engagements ISAE (NZ) 3420 Assurance
to Report on the Compilation of To Report on the Compilation of Engagements to Report on the
Pro Forma Financial Information Pro Forma Historical Financial Compilation of Pro Forma Financial
Included in a Prospectus Information included in a Prospectus Information Included in a Prospectus
or other Document
•• Paragraphs 1–7, 10–15, 17–22 •• Paragraphs 1–7, 10–15, 17–22 •• Paragraphs 1–7, 10–15, 17–22
and 29–35 and 29–35 and 29–35
ISRS 4400 Engagements to Perform ASRS 4400 Agreed-Upon Procedures APS-1 Statement of Agreed-Upon
Agreed-Upon Procedures Regarding Engagements to Report Factual Procedures Engagement Standards
Financial Information Findings
•• Paragraphs 2, 4–6 and 15–18 •• Paragraphs 4–6, 11, 21, 23, •• Paragraphs 4–8 and 8.1–8.3
28–30, A15 and Appendix 1
APG-1 Guideline on Performance
of an Agreed-Upon Procedures
Engagement
•• Paragraphs 1–3, 5, 8 and 11
Further reading
ACT
Activity 17.1
Identifying the assurance practitioner’s
responsibilities in a compliance engagement
Introduction
Chartered Accountants may be asked to undertake a wide variety of other assurance
engagements. Some of these engagements may involve circumstances that are not permitted
under International Standards on Auditing and Assurance, and it is therefore vital that
Chartered Accountants understand their responsibilities in relation to accepting, performing
and reporting on these engagements.
This activity links to learning outcome:
•• Identify and explain the assurance practitioner’s responsibilities with respect to other
assurance engagements.
At the end of this activity, you will be able to determine the impact on a compliance
engagement of any exceptions the auditor identifies, in accordance with the following relevant
Standards:
Scenario
You are a senior accountant at a successful accounting firm, ABC Chartered Accountants (ABC),
which has a wide range of clients.
During the 20X2 year, ABC succeeded in obtaining a new audit client, OnCare Health Group
(OnCare), a listed entity. OnCare wholly owns Cancer Care Limited (Cancer Care), a private
oncology clinic specialising in the treatment of cancer.
In addition to providing treatment, Cancer Care also operates nursing home facilities for
terminally ill cancer patients. On entry to a Cancer Care nursing home, all patients pay a $900
deposit that is used to meet the incidental costs incurred during their stay. Under nursing
homes legislation, Cancer Care must maintain a separate trust account for these monies.
Specifically:
•• All funds received from patients must be banked in a separate bank account that is tied to
the trust account.
•• The balance of the bank account must equal the balance of the trust account at all times.
Each financial year, Cancer Care must provide a statement to the Department of Ageing
confirming that it has adhered to the provisions of the legislation regarding the trust account.
Cancer Care requested ABC to provide reasonable assurance on its statement to the Department
of Ageing. During its compliance testing, ABC’s engagement team identified several exceptions
ACT
to Cancer Care’s adherence to the provisions of the legislation and informed those charged with
governance at Cancer Care of its findings.
One member of the ABC engagement team has suggested that it may be easier if ABC provides
limited assurance instead of reasonable assurance as a way of dealing with the exceptions.
Task
For this activity, you are required to:
•• Determine any implications for the engagement of the exceptions identified.
Outline any implications of the proposed changes to the level of assurance provided.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 17.2
Identifying other assurance engagements
Introduction
Appropriate identification of the type and limitations of an engagement that an assurance
practitioner is being asked to undertake is an important step in ensuring compliance with the
relevant International Standards on Auditing (ISAs) and/or local Standards.
This activity links to learning outcomes:
•• Determine which Standards apply to other assurance engagements.
•• Identify and explain the assurance practitioner’s responsibilities with respect to other
assurance engagements.
At the end of this activity, you will be able to identify the type of engagement and the applicable
Standards, and determine the level of assurance that can be provided.
It will take you approximately 20 minutes to complete.
Scenario
Power Limited (Power) is a large coal-fired electricity generator. You are a manager at
Assurance Advantage (AA), Power’s external auditor.
Power is required to prepare, and have audited, general purpose financial statements (GPFS).
The company is currently in the process of renewing its electricity generation licence with the
energy regulator (the regulator).
Included in the proposed new licence are four conditions relating to information to be provided
to the regulator each year.
The licence conditions are as follows:
Condition Details
1 Provide a schedule of electricity derivative assets and liabilities as at each reporting date. The
schedule must be certified as correct by Power’s external auditor
2 Provide high level of assurance on a list of the entity’s electricity generation infrastructure assets,
a description of each asset, the replacement value of each asset, and the remaining life of the
asset as at each reporting date
3 Provide a review report on the operating effectiveness of controls in the electricity trading unit
of Power for each financial year
Power does not want to agree to the proposed licensing conditions before finding out whether
AA can provide the reports or opinions requested.
ACT
Tasks
For this activity, you are required to treat each licence condition as a separate engagement and:
1. With reference to Auditing and Assurance Standards, identify the appropriate type of
assurance engagement that AA should undertake for each licence condition. Justify your
response with reference to the scenario.
2. Determine the level of assurance that AA will provide for each engagement. Where this
differs from the level of assurance requested by the client (implicitly or explicitly), outline
the course of action that AA should take.
ACT
Activity 17.3
Accepting other assurance engagements
Introduction
Chartered Accountants may be asked to undertake a wide variety of other assurance
engagements. Some of these engagements may involve circumstances that are not permitted
under International Standards on Auditing (ISAs), and it is therefore vital that Chartered
Accountants understand their responsibilities relating to accepting or performing these
engagements.
This activity links to learning outcome:
•• Identify and explain the assurance practitioner’s responsibilities with respect to other
assurance engagements.
At the end of this activity, you will be able to determine whether an other assurance
engagement can be accepted or performed based on the assurance practitioner’s responsibilities
in the context of the proposed engagement.
It will take you approximately 30 minutes to complete.
Scenario
This activity is based on the scenario from Activity 17.2 on Power Limited (Power), a large coal-
fired electricity generator.
You are a manager at Assurance Advantage (AA), a mid-tier Chartered Accounting firm and
Power’s external auditor.
Power is required to prepare, and have audited, general purpose financial statements (GPFS).
Power is currently in the process of renewing its electricity generation licence with the energy
regulator (the regulator).
Included in the proposed new licence are four conditions relating to the provision of
information to the regulator each year. Following the feedback you provided to Power,
Condition 1 in the proposed licence has been amended:
Regulator conditions
Licence Details
conditions
1 Provide a schedule of electricity derivative assets and liabilities at each reporting date. The
schedule must be audited by Power’s external auditor
3 Provide a review report on the operational effectiveness of controls in the electricity trading unit
of Power for each financial year
ACT
Power does not want to agree to the proposed licensing conditions before finding out whether
AA can provide the reports or opinions requested.
Power’s chief financial officer (CFO) suggests that because AA looks at the electricity trading
unit’s controls as part of its audit of the GPFS, it will not need to perform any further
procedures in order to issue its review report on the operating effectiveness of internal controls.
A junior auditor, Ben, has prepared an engagement letter, which includes a draft of the
auditor’s report to be issued on the financial statements prepared for condition 4 of the licence
requirements. The example auditor’s report assumes that there were no material misstatements
identified during the audit. Ben has therefore included AA’s standard auditor’s report, based
on ISA 700 Forming an Opinion and Reporting on Financial Statements (ISA 700) in the engagement
letter; however, he is not sure he has drafted the report correctly.
Tasks
For this activity, for each engagement associated with a licence condition, you are required to:
• Identify whether AA can undertake the engagement under the current circumstances, and
justify your answer.
• Where AA cannot undertake the engagement, determine what actions would enable AA to
undertake the engagement.
With regard to licence condition 4, describe any issues that may arise with Ben’s draft report.
ACT
Activity 17.4
Identifying the most appropriate assurance
engagement and performing the
engagement
Introduction
As a Chartered Accountant, it is important to be able to identify the most appropriate
engagement and the relevant Standard under which the engagement should be performed, and
to be able to explain the practitioner’s responsibilities in respect to performing the engagement.
This activity links to learning outcomes:
•• Determine which Standards apply to other assurance engagements.
•• Identify and explain the assurance practitioner’s responsibilities with respect to other
assurance engagements.
At the end of this activity, you will be able to identify the most appropriate assurance
engagement to be performed, the Standard that applies to a particular engagement, and explain
the assurance practitioner’s responsibilities in respect to performing the engagement.
It will take you approximately 20 minutes to complete.
Scenario
AltiAir Limited (AltiAir) is a large, unlisted public company operating a trans-Tasman airline
based in Sydney, Australia. Its licence to operate as an airline was issued by the Civil Aviation
Safety Authority (CASA). Baritone Chartered Accountants (Baritone) is AltiAir’s auditor for its
general purpose financial statements (GPFS).
Increased competition in the airline industry, together with increasing operating costs, has put
considerable pressure on AltiAir’s financial viability. The company generated total revenue of
$460 million in the year end 30 June 20X3, but made a loss of $20 million.
Consider the two situations below:
Situation 1
AltiAir’s licence requires it to submit to CASA a summarised list of in-flight incidents each
quarter (every three months). CASA defines an in-flight incident as ‘anything that did, or could
have if the incident was not prevented, caused injury or death to a passenger or crew member
during an aircraft’s flight’.
The list must include the following details of each incident: date, time, flight number, category
of incident, number of passengers involved and number of crew members involved. The
summarised list must be certified by an independent assurance practitioner to ensure it is
accurate and complete. The licence specifically states the assurance engagement must be
performed in accordance with Auditing and Assurance Standards.
AltiAir has requested Baritone perform these engagements, and the company is preparing for
the assurance engagement for the quarter ending 30 September 20X4.
ACT
Situation 2
AltiAir’s loan agreement with its bank requires it to submit the following abbreviated financial
information to the bank one month after the general purpose financial report has been audited:
1. Abbreviated statement of profit or loss and other comprehensive income.
2. Abbreviated statement of financial position.
3. Abbreviated statement of cash flows.
4. Summary of significant accounting policies.
The bank requires assurance that the abbreviated financial information is consistent with
AltiAir’s GPFS.
Following the audit of AltiAir’s 30 June 20X4 GPFS, Baritone issued an unmodified auditor’s
report.
Two weeks after Baritone issued its auditor’s report on AltiAir’s 30 June 20X4 GPFS, two of
AltiAir’s aircraft crashed near Brisbane Airport. AltiAir’s management confirms that the two
aircraft have to be written off, which will significantly impact on the company’s ability to
generate revenue.
Baritone concluded that AltiAir’s abbreviated financial information was materially consistent
with its general purpose financial statements.
Task
For this activity, for each of the two situations, you are required to:
1. With reference to Auditing and Assurance Standards, identify the type of assurance
engagement and the level of assurance provided. Justify your answer.
2. With regard to Situation 1 only:
•• Design one relevant and practical control that AltiAir should have implemented to
ensure all in-flight incidents were reported and included in the list submitted to CASA.
•• Design one (1) relevant and practical substantive test that Baritone could perform to test
that the list submitted to CASA was accurate and complete.
3. With regard to Situation 2 only:
•• Explain Baritone’s obligations to consider the events following the aircraft crash when
undertaking the engagement. Justify your response.
•• Identify the appropriate opinion Baritone should express.
[Solutions to activities are available online. Please access myLearning to view]
CC
Core content
Unit 18: Internal audit and public sector
auditing
Learning outcomes
At the end of this unit you will be able to:
1. Compare and contrast the role of internal audit and external audit.
2. Explain the features of the public sector accountability environment and how it differs from
the private sector.
3. Discuss the role and the importance of non-financial reporting in the public sector.
4. Apply the appropriate assurance process to public sector engagements.
Introduction
During the course of their career, a Chartered Accountant may choose to work in an internal
audit role or on a public sector audit engagement, either directly for an Auditor-General or
through an outsourced public sector engagement.
This unit will:
•• Explore the role of internal audit in organisations.
•• Examine the ways in which the internal audit function can contribute to good corporate
governance.
•• Compare internal audit’s role to that of external audit.
This unit also considers the public sector accountability environment, and the key differences
between the public and private sectors. Concepts that have been covered in the earlier units of
Audit & Assurance (AAA) module are explored in the context of applying the assurance process
to public sector engagements.
aaa11618_csg
CC
Learning outcome
1. Compare and contrast the role of internal audit and external audit.
Internal audit plays a crucial role in many organisations. The Institute of Internal Auditors (IIA)
defines the internal audit activity (or function) as:
…[An] independent, objective assurance and consulting activity designed to add value and improve
an organization’s operations. The internal audit activity helps an organization accomplish its objectives
by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk
management, control, and governance processes.
The objective of the internal audit function is to provide assurance to those charged with
governance that the following processes are operating effectively and as intended:
•• Corporate governance process.
•• Risk management process.
•• Internal controls.
Ethical considerations
While the IESBA Code applies to external auditors, the IIA’s Code of Ethics (IIA Code) is
specifically designed to promote an ethical culture in the profession of internal auditing.
Both the IESBA Code and IIA Code share common fundamental principles such as integrity,
objectivity, confidentiality, professional competence and due care. The key distinction between
them is that the IESBA Code extensively explores the concept of independence for assurance
engagements.
The concept of independence for internal auditors is different from that for external auditors,
as internal auditors are usually employed directly by the organisation. Many of the safeguards
and specific independence requirements explored in the unit on pre-engagement activities are
not logical when applied to the internal audit function. While the IIA Code is not mandatory
for internal auditors who are not members of the IIA, those who are members of Chartered
Accountants Australia and New Zealand are required to comply with the relevant ethical
Standards.
The IIA’s International Standards for the Professional Practice of Internal Auditing (IIA Standards)
provide guidance to internal auditors on maintaining their independence. A key element of
independence for internal auditors is an appropriate reporting line. The IIA Standards (s. 1100)
state:
… To achieve the degree of independence necessary to effectively carry out the responsibilities of the
internal audit activity, the chief audit executive has direct and unrestricted access to senior management
and the board. This can be achieved through a dual-reporting relationship …
CC
Having an appropriate functional reporting line to the board enhances the independence of the
internal audit function and should be ingrained in the organisation’s internal audit charter.
Required reading
IESBA Code paras 300.1–300.15.
Australia-specific
The Australian Securities Exchange (ASX)’s Corporate Governance Principles and
Recommendations (ASX principles) defines corporate governance as ‘the framework of rules,
relationships, systems and processes within and by which authority is exercised and controlled
in corporations’ (3rd edn, p. 3).
Corporate governance influences how a company sets and achieves its goals, monitors and
assesses risk and optimises performance. Good governance encourages companies to create
value, provide accountability and provide control systems that are appropriate for the level of
risk involved.
While the ASX principles directly apply to listed corporations, they are widely seen as best
practice for all entities.
CC
New Zealand-specific
The Financial Markets Authority (FMA)’s Corporate Governance in New Zealand – Principles and
Guidelines (the Principles) (revised and published in December 2014) sets out nine principles for
establishing and maintaining high standards of corporate governance.
Corporate governance influences how a company sets and achieves goals, monitors and
assesses risk, and optimises performance. Good governance encourages companies to create
value, provide accountability, and establish control systems that are appropriate for the level of
risk involved.
The Principles apply most directly to FMA-reporting entities. However, they are written in a
way that allows them to be applied across a range of organisations, and the FMA encourages
all entities to look at reporting in accordance with the Principles. Listed entities are required,
pursuant to the New Zealand Exchange (NZX)’s NZAX Listing Rules (Listing Rules) s. 10.5.5(i),
to state how their corporate governance processes differ materially from the NZX’s Corporate
Governance Best Practice Code.
The IIA Standards s. 2110 states that an organisation’s internal audit function ‘must assess and
make appropriate recommendations for improving the governance process’ by achieving the
following objectives:
• Promoting appropriate ethics and values within the organization;
• Communicating risk and control information to appropriate areas of the organization; and
• Coordinating the activities of and communicating information among the board, external and
internal auditors, and management.
Regardless of its precise roles and objectives, internal audit plays an important role in the
corporate governance framework of an entity.
CC
The IIA Standards s. 2120 states that the internal audit function must evaluate the effectiveness
of risk management processes and contribute to their improvement. In doing so, the function
must examine whether:
• Organizational objectives support and align with the organization’s mission;
• Appropriate risk responses are selected that align risks with the organization’s risk appetite; and
Internal controls
As discussed in earlier units, ISA 315 para. 4(c) defines internal control as:
… the process designed, implemented and maintained by those charged with governance, management
and other personnel to provide reasonable assurance about the achievement of an entity’s objectives
with regard to reliability of financial reporting, effectiveness and efficiency of operations, and
compliance with applicable laws and regulations.
The process of establishing internal controls starts with those charged with governance and
typically follows the sequence outlined below:
1. Those charged with governance (generally the board of directors) establish the criteria
for the design of the internal controls that they consider appropriate both to manage the
risks facing the organisation and to ensure compliance with regulatory and legislative
requirements.
2. Those charged with governance employ a senior management team to run the organisation
and establish internal control systems. Senior management does not directly manage the
internal controls, but rather oversees them.
3. Operational management runs the organisation. Operational management:
•• Undertakes day-to-day supervision of the risk control framework
•• Monitor operations, including the results of key performance indicators (KPIs).
•• Ensure adherence to policies about structure, segregation of duties, and roles.
•• Utilise specialised resources in relation to the risk management framework
(e.g. compliance, tax and HR training).
4. Those charged with governance establish the internal audit function by developing
an internal audit charter that formally establishes the position of internal audit in the
organisation’s governance framework. The charter outlines internal audit’s role,
responsibilities, authority, the standards it must adhere to, and to whom it is accountable.
5. The internal audit function performs audit procedures that assess the design and
effectiveness of the organisation’s internal controls, and provides assurance to the board of
directors that the entity is complying with established internal controls.
External audit plays a somewhat limited role in auditing the design, implementation and
maintenance of internal controls. ISA 315 para. 12 states that the external auditor only needs
to understand the internal controls that are relevant to the audit, since the focus of external
audit is on how internal controls affect the reliability of financial reporting. The other aspects
of an organisation that are affected by internal controls (i.e. the effectiveness and efficiency
of operations, and compliance with applicable laws and regulation) are examined only in the
context of how these aspects impact on the reliability of financial reporting.
CC
Internal audit’s focus is much broader than external audit. IIA Standards para. 2120.A1 states
that the internal audit function:
… must evaluate risk exposures relating to the organization’s governance, operations, and information
systems regarding the:
CC
Primary objective The purpose of external audit is According to the definition of ‘internal audit
to enhance the degree of confidence activity’ provided by the Glossary in the IIA
in the financial statements. This is Standards, the objective of the internal audit
achieved by the expression of an function is to provide:
opinion by the auditor on whether
… independent,objective assurance and
the financial statements have been
consulting services designed to add value
prepared, in all material respects,
and improve an organization’s operations.
in accordance with the applicable
The internal audit activity helps an
financial reporting framework.
organization accomplish its objectives
In the case of most general purpose
by bringing a systematic, disciplined
reporting frameworks, that opinion
approach to evaluate and improve
is on whether the financial statements
the effectiveness of governance, risk
are presented fairly, in all material
management and control processes
respects, or give a true and fair view in
accordance with the framework
Reporting line Independent auditor’s report to the Audit reports, including conclusions, findings
organisation’s members/owners and recommendations, are issued to those
charged with governance (chair of the board,
Reporting of other matters (not
or chair of the audit and risk committee)
leading to a modification to the
independent auditor’s report) directly
to those charged with governance
Australia: Breaches of the
Corporations Act 2001 (Cth)
(Corporations Act) reported to the
Australian Securities and Investments
Commission (ASIC)
Reporting format Independent auditor’s report is issued Reports vary in format and content
in the form of a written report which depending on the nature of the engagement
contains elements specified in ISA 700 and the needs of the business (see IIA
Forming an Opinion and Reporting on Standards para. 2410.C1)
Financial Statements or uses a layout
Reports are tabled at board meetings, or at
and wording required by law or
audit and risk committee meetings
regulations of a specific jurisdiction
Reports are communicated to senior
management for information, and to allow
the implementation of agreed actions
CC
Terms of audit Agreed upfront with management or Contained in the internal audit charter and in
engagement those charged with governance and the annual audit plan, which is determined by
recorded in an engagement letter the board of directors
or other suitable form of written
agreement, in accordance with
ISA 210 Agreeing the Terms of Audit
Engagements (ISA 210)
Scope of audit Agreed on by the external auditor and The scope of an internal audit engagement
engagement those charged with governance can cover both financial and operational
areas
Normally limited to performing
procedures to obtain audit evidence The head of internal audit determines the
on the amounts and disclosures in the scope of individual audits, ensuring these are
financial statements consistent with the board-approved internal
audit plan and internal audit charter
Australia: The minimum scope of an
external audit is set out in Australian
Auditing Standards and, where
applicable, the requirements of the
Corporations Act
New Zealand: The minimum scope
of an external audit is set out in New
Zealand Auditing Standards and as
required by the Financial Markets
Conduct Act 2013 (s. 461F) or Financial
Reporting Act 1993 (FRA93)
Audit evidence and According to: According to IIA Standards, which require
documentation work papers documenting relevant
•• ISA 230 Audit Documentation
information to support the engagement’s
•• ISA 500 Audit Evidence conclusions and results
Employment and The organisation engages and Internal audit staffing depends on which
remuneration of remunerates an external audit firm, resource model the entity uses:
auditor which employs the members of the
•• In-house – internal audit staff is employed
audit team
and remunerated by the organisation
Members of the external audit team •• Outsourced staff of a professional services
are not employees of the organisation firm – professional services fees are paid to
an external firm, which then remunerates
the internal audit staff
•• Combination of in-house/outsourced
internal audit staff and staff of a
professional services firm – all in-house
internal audit staff is employed and
remunerated by the organisation, while
outsourced staff is remunerated by
the external professional services firm.
The organisation pays the external
professional services firm
CC
Learning outcome
2. Explain the features of the public sector accountability environment and how it differs from
the private sector.
There are many differences between auditing in the private sector and auditing in the public
sector. One factor that differentiates planning, performing and reporting on audits in the
public sector is that Auditors-General act as a constitutional safeguard by giving assurance to
parliament and taxpayers that public sector resources are being appropriately managed and
accounted for in accordance with applicable laws. The breadth and scope of the public sector
audit can be wider relative to a private sector audit.
The size and complexity of the government sector means that the application of certain standard
audit procedures needs to be reviewed when planning an audit or assurance engagement. Take,
for example, the consideration of an appropriate materiality level for an audit engagement.
Applying the concept of materiality to the audit of some government entities might suggest
that misstatements of less than several billion dollars would be considered immaterial. Clearly,
such a misstatement would be regarded as material to the general public. Qualitative factors,
including the public’s interest in the figures, would influence the auditor’s determination of
materiality for the audit of the whole of the government.
To obtain more information about the government finances in Australia and New Zealand,
navigate to www.budget.com.au (Australia) and www.treasury.govt.nz (New Zealand).
Accountability environment
Parliament and the executive government:
•• provide authority for the acquisition and use of public financial resources
•• set the overall policy direction, and
•• are responsible for overseeing management’s administration of those resources.
There is a greater separation of owners and managers in the public sector than in the
private sector. The ‘owners’ are the taxpayers or people in the government’s jurisdiction, as
represented by parliament, and the ‘managers’ are the ministers and public servants. To oversee
accountability in the administration of resources, most parliaments have established standing
committees to monitor what are referred to as the ‘public accounts’.
Government functions are administered through various entities. These include government
departments, government businesses and public trading enterprises, statutory bodies and
companies. In addition, some public bodies established by parliament operate independently
and are not subject to close ministerial control. These bodies may include educational
institutions (e.g. universities), public bodies that manage financial resources of the public
(e.g. government insurance offices), and bodies that operate as agents (e.g. tourism marketing
board). In the absence of an explicit provision to the contrary, such bodies are still considered to
be accountable to the relevant parliament.
Role of Auditors-General
In the public sector, Auditors-General undertake the audit activity. Under the Westminster
system of government, the parliament appoints Auditors-General to monitor the accountability
of their respective government. The role of Auditors-General is vitally important, as they are in
a position to question how the government administers public finances.
CC
Auditors-General cannot generally question the merits of government policy, which is regarded
as the collective will of the people. Enacting government policy is the province of government.
An Auditor-General questioning government policy would be equivalent to a private sector
auditor questioning a company’s business strategies or whether it is appropriate for a business
to have a goal of making a profit.
Auditors-General can, however, conduct audits to identify inefficiency, waste, ineffectiveness, lack
of financial prudence or non-compliance with policies and directives in public sector agencies.
The reports of Auditors-General are tabled in parliament. Once tabled, these reports are public
documents and may be subject to parliamentary or media scrutiny.
Auditors-General are supported by audit offices in carrying out audit engagements and
fulfilling their reporting obligations to parliament. These audit offices employ professional staff
that includes Chartered Accountants.
A public sector audit office is very similar to a private sector accounting practice except that it
does not have a profit motive. Its operations are often like those of the assurance division of a
large accounting firm.
Auditors-General are able to contract private sector auditors to perform some of the
audit‑related services on public sector audit engagements that Auditors-General are required
to provide. In such cases, the responsibility to form an opinion and report on the results of the
audit usually still rests with the Auditor‑General.
An Auditor-General’s mandate is determined by the enabling legislation under which they
operate. The following table lists the relevant legislation by jurisdiction:
Jurisdiction Legislation
Australia
CC
Australia-specific
Government entities exist for a different purpose, and each of the different types of entities may
have a slightly different governance structure. However, under the government’s accounting
policies and governance rules, the management of each entity is required to report under the
applicable Australian Accounting Standards.
Local government reporting and audit requirements vary across Australia pursuant to the
different legislation in each jurisdiction. In some jurisdictions, local government is audited
by the state or territory Auditor-General. In others, the Auditor-General has no role in
local government audits. In others still, private sector auditors conduct the audits of local
government entities while the Auditor-General has an oversight role.
In a number of Australian jurisdictions, the Auditor-General can be requested by various
parties – such as the Legislative Assembly, the Treasurer or another minister – to conduct audits
on specific topics or to undertake audit-related activities. The nature of these audits or activities
will vary according to the request and the legislation operating in that jurisdiction.
In addition, Auditors-General often have the authority to provide other audit services
to government agencies; for example, providing auditor’s reports for the dispersal of
Commonwealth Government grants (for state or territory agencies), or oversight of lottery draws.
New Zealand-specific
The Auditor-General audits all public sector entities (termed ‘public entities’) in New Zealand,
which total approximately 4,000. This includes state-owned enterprises (SOEs), government
ministries and departments, hospitals and schools.
Each of these public entities exists for a different purpose and each of the different types
of government entities has a slightly different governance structure. However, under the
government’s accounting policies and governance rules, the governing body of each entity
is required to report under the applicable New Zealand Financial Reporting Standards.
In New Zealand, in addition to auditing the financial statements and other information that
public entities require to be audited, the Auditor-General has further extensive powers. These
powers include the Auditor-General’s prerogative to examine:
• The efficiency and effectiveness of a public entity’s activities.
• Whether a public entity is complying with its statutory obligations.
• That waste is not occurring as a consequence of an action or inaction by a public entity.
• Whether a public entity has exercised appropriate probity and financial prudence.
‘Probity’ is defined in the NZ Auditor-General’s Auditing Standards ‘Glossary of terms’ and which
means:
... Parliament’s and the public’s expectations of an appropriate standard of behaviour.
The Auditor-General also has the authority to conduct enquiries on any matter concerning
a public entity’s use of its resources. The Auditor-General can, with the agreement of a public
entity, also carry out any other work that is reasonable for an auditor to perform.
Overseeing the Local Authorities (Members’ Interests) Act 1968 also falls to the Auditor‑General.
This requires the Auditor-General to oversee local government members to ensure their
judgement is not influenced by their own personal, financial or beneficial interests when
making decisions.
CC
Australia-specific
Auditors-General must adhere to the professional requirements regarding independence
and, as such, in Australia they are bound by APES 110. However, APES 110 provides that in the
event of a conflict between APES 110 and Auditor-General legislation, the legislation takes
precedence. In addition, some public sector audit engagements are performed under the
Corporations Act. Therefore, for Auditors-General, these engagements must adhere to the
independence requirements of that Act.
As it is for auditors in the private sector, Auditors-General can be subject to the threats
to independence outlined in APES 110. The independence of Auditors-General is often
strengthened by legislation.
The independence of Auditors-General can be protected in the following ways:
•• The Auditor-General may be appointed for a fixed term, which enables them to report
adverse findings without fear of having their position terminated.
•• The Auditor-General may be prohibited from working in the public service of their
jurisdiction after the expiry of their fixed-term appointment. This eliminates any perception
of their being ‘looked after’ (i.e. being offered a favourable appointment by the government
after serving their term as Auditor-General).
•• The Auditor-General may only be removed by a resolution of Parliament, and not just
by the executive government (i.e. both the government and the opposition must agree
to remove the Auditor-General). If the Auditor-General could be removed solely by the
government of the day, this would make it difficult for the Audit-General to report without
fear or favour.
•• Legislation may be enacted that provides that the Auditor-General is the auditor of public
sector agencies and that limits the provision of non-audit services. This ensures that the
Auditor-General and their offices are not compromised in their role by the possibility
of losing clients or income. By narrowly defining the functions of the Auditor-General,
the legislation will help to restrict conflicts of interest that may arise from the provision
of non‑audit services.
•• A parliamentary committee, rather than the executive government, may appoint the
Auditor-General. This reduces the potential for conflicts of interest by ensuring that the
Auditor-General is not selected on party-political grounds.
•• The Auditor-General’s independence may be set out in legislation. Defining the
independence of the Auditor-General will create clear barriers to them performing actions
that may compromise their independence.
•• Subject to any particular requirements of their legislation, Auditors-General have complete
discretion in the performance or exercise of their functions or powers (for example, see s. 8
Auditor-General Act 1997 (Cth)).
•• The Auditor-General may be nominated an ‘Officer of the Parliament’, a title that denotes
that the Auditor-General’s role is to serve Parliament rather than the government of the day
(i.e. broadly, to serve the people).
•• Funding for the Auditor-General and their audit office may be automatically appropriated.
By having an automatic and guaranteed source of funding for the Auditor-General’s
activities, there is no incentive for the Auditor-General or their office to shape their findings
in certain ways in order to receive funding.
In the private sector, when threats to an auditor’s independence are so great that no safeguard
could reduce them to an acceptable level, the auditor must decline the audit engagement.
In contrast, an Auditor-General’s independence and the requirement to audit government
entities is established and protected by legislation.
CC
New Zealand-specific
The Auditor-General has elected to adhere to the professional requirements on independence.
As such, they are bound by PES 1 Code of Ethics for Assurance Practitioners (Revised), and by the
Auditor-General’s own AG PES 1 (Revised) Code of Ethics for Assurance Practitioners.
As in the private sector, the Auditor-General can be subject to threats to independence.
The independence of the office is protected in the following ways:
•• The Auditor-General is appointed for a fixed term, which enables them to report adverse
findings without fear of having their position terminated.
•• The Auditor-General reports directly to the House of Representatives (and has the power
to report to anyone else). The power to report directly and to anyone strengthens the
Auditor‑General’s independence.
•• The Auditor-General is not entitled to be a Member of Parliament or a member of a local
authority. In addition, they must not take up any other government office unless the
Speaker of the New Zealand Parliament authorises the appointment in writing. This
mitigates the risk that the Auditor-General is subject to conflicts of interest.
•• The Auditor-General is prohibited from working in the public service after the expiry of
their fixed-term appointment. This eliminates any perception of their being ‘looked after’
(i.e. being offered a favourable appointment by the government after serving their term
as Auditor‑General).
CC
Government reporting
Learning outcome
3. Discuss the role and the importance of non-financial reporting in the public sector.
The aim of government as a whole is not to make a profit, even though it can control profit-
making entities. Its aim is broader and less clearly defined. Nonetheless, the government raises
revenue through taxes which it uses to provide services for the good of the community, such as
health, education, roads and other infrastructure.
Government reporting often supplements traditional financial statements with other
information, such as key performance indicators (KPIs) and service performance
outcomes. For example, when a government department is given $800 million to provide
financial assistance to local government councils in areas affected by a natural disaster, the
public is more concerned that all eligible local government councils received financial assistance
– not whether the entire $800 million was spent.
Due to the public sector accountability environment, governments often report, and auditors
are often required to provide assurance, on a broad range of matters in addition to the general
purpose financial statements (GPFS), such as KPIs. In addition, an Auditor‑General can carry
out discretionary work on:
•• Compliance with legislation, regulations, policies or contracts.
•• Internal controls.
•• Budgets and appropriations.
•• Reporting on the efficiency and effectiveness of a government agency’s performance
(by conducting performance audits).
The types of engagements listed above are generally performed as assurance engagements
separate to the audit of agencies’ financial statements. The nature and extent of these additional
engagements will depend on the Auditor-General’s specific legislative mandate. These
additional engagements are often not performed by the Auditor-General, but instead by private
audit firms engaged by the agencies.
The nature and extent of the additional information required in a public sector entity’s GPFS
depends on the jurisdiction and, often, on the type of public sector entity it is.
CC
Learning outcome
4. Apply the appropriate assurance process to public sector engagements.
As for assurance engagements that are conducted in the private sector, the fundamental
processes for public sector assurance engagements are:
•• Agree on the terms of the engagement.
•• Plan the engagement.
•• Conduct planned engagement procedures.
•• Based on evidence obtained from the engagement procedures, reassess the planning
assumptions, and, if necessary, perform additional procedures.
•• Communicate with those charged with governance.
•• Form a conclusion or opinion.
•• Prepare a report.
These processes have been discussed in detail in previous units in the AAA module. However,
there are additional considerations that apply to an Auditor-General in executing these
processes, which are discussed in this section.
Note: In most jurisdictions, the Auditor-General is permitted by legislation to outsource
some of their engagements to private sector assurance providers. Nonetheless, when this
occurs, the Auditor-General usually retains the responsibility for issuing the auditor’s report.
Therefore, in this section, the auditor of a public sector entity (or agency) is referred to as the
Auditor‑General.
Australia-specific
Each Auditor-General in Australia operates under different jurisdictional legislation, which
outlines their powers and responsibilities, and the scope of their audit engagements.
For example, the Commonwealth Auditor‑General’s functions and powers are largely set out
in Part 4 Auditor-General Act 1997 (Cth).
New Zealand-specific
In New Zealand, the Auditor-General’s powers and responsibilities are mandated by the Public
Audit Act 2001 (PAA). Section 14 PAA states that the Auditor-General is the ‘auditor of every
public entity’ in New Zealand.
The PAA grants wide powers to the Auditor-General to conduct audits other than those
of financial statements, and other information that public entities require to be audited.
For example, the Auditor-General is empowered to conduct performance audits (s.16 PAA),
auditing work that is appropriate and reasonable for an auditor to perform, as well as enquiries,
either at the request of a public entity or on the Auditor-General’s own initiative, into any
matter involving the use of a public entity’s resources (ss 17 and 18 PAA).
Auditor-General’s Auditing Standard 5 Performance Audits, Other Auditing Services and Other
Work Carried Out by or on behalf of the Auditor-General (AG-5), Auditor-General’s Auditing
Standard 6 Inquiries Carried Out by or on behalf of the Auditor-General (AG-6) and other relevant
assurance engagement Standards apply to all engagements (other than annual audit of
financial statements) for the terms of the engagement. The Auditor-General must also ensure
that engagement terms are within the mandate of the relevant legislation.
CC
CC
(b) whether additional explanation in the auditor’s report can mitigate possible misunderstanding.
If the auditor concludes that additional explanation in the auditor’s report cannot prevent
possible misunderstanding, the auditor shall not accept the audit engagement unless required
by law or regulation to do so. However, the option to decline an audit engagement is generally
not available to Auditors-General.
An option to resolve the conflict between legislative requirements and the abilities of the
Auditor-General under Assurance Standards may be for the Auditor-General to discuss
alternative reporting (which complies with the IAASB’s International Framework for
Assurance Engagements) with the administrator of the legislation. The administrator may
have the legislative power to alter the form and content of the reporting and assurance
requirements. Should this not be an option, the Auditor-General will then be unable to include
any reference within the assurance report to the engagement having been conducted in
accordance with ISAs.
Required reading
ISA 210 para. 21.
CC
CC
Report on compliance with key Public sector entities face a large International
legislation/central government number of requirements that ISAE 3000 (Revised)
pronouncements direct the way they undertake their
Australia
activities. These can be financial
ASAE 3100
and non-financial in nature.
For example, entities may only be New Zealand
permitted to borrow funds from SAE 3100
a certain financing corporation. AG-5
A report on whether an entity AG ISA (250)
has complied with particular key
legislation or central government
pronouncements provides
stakeholders with assurance that
government-wide requirements are
being met
CC
Note: The abbreviated Standards referred to in the table above that have not been previously mentioned in this unit’s
core content are listed below:
International
•• ISA 800 Special Considerations – Audits of Financial Statements Prepared in Accordance with Special Purpose Frameworks
(ISA 800).
•• ISA 805 Special Considerations – Audits of Single Financial Statements and Specific Elements, Accounts or Items of a
Financial Statement (ISA 805).
•• ISA 810 Engagements to Report on Summary Financial Statements (ISA 810).
•• ISRE 2400 Engagements to Review Historical Financial Statements (ISRE 2400).
•• ISAE 3000 (Revised) Assurance Engagements Other than Audits or Reviews of Historical Financial Information (ISAE 3000
(Revised)).
•• ISAE 3420 Assurance Engagements to Report on the Compilation of Pro Forma Financial Information Included
in a Prospectus (ISAE 3420).
•• ISRS 4400 Engagements to Perform Agreed-Upon Procedures Regarding Financial Information (ISRS 4400).
Australia
•• ASA 800 Special Considerations – Audits of Financial Reports Prepared in Accordance with Special Purpose Frameworks
(ASA 800).
•• ASA 805 Special Considerations – Audits of Single Financial Statements and Specific Elements, Accounts or Items of a
Financial Statement (ASA 805).
•• ASA 810 Engagements to Report on Summary Financial Statements (ASA 810).
•• ASAE 3000 (Revised) Assurance Engagements Other than Audits or Reviews of Historical Financial Information
(ASAE 3000).
•• ASAE 3100 Compliance Engagements (ASAE 3100).
•• ASAE 3150 Assurance Engagements on Controls (ASAE 3150).
•• ASAE 3450 Assurance Engagements involving Corporate Fundraisings and/or Prospective Financial Information
(ASAE 3450).
•• ASAE 3500 Performance Engagements (ASAE 3500).
•• ASRS 4400 Agreed-Upon Procedures Engagements to Report Factual Findings (ASRS 4400).
•• ASRE 2400 Review of a Financial Report Performed by an Assurance Practitioner Who is Not the Auditor of the Entity
(ASRE 2400).
•• ASRE 2405 Review of Historical Financial Information Other than a Financial Report (ASRE 2405).
CC
New Zealand
•• AG-2 The Appropriation Audit and the Controller Function (AG-2).
•• AG-4 (Revised) The Audit of Service Performance Reports.
•• AG ISA (NZ) 250 The Auditor-General’s Statement on Consideration of Laws and Regulations (AG ISA (NZ) 250).
•• ISAE (NZ) 3000 (Revised) Assurance Engagements Other than Audits or Reviews of Historical Financial Information (ISAE (NZ)
3000).
•• SAE 3100 Compliance Engagements (SAE 3100).
•• SAE 3150 Assurance Engagements on Controls (SAE 3150)
While some of the Standards identified in the right-hand column above have been introduced
in the unit on other assurance engagements and agreed-upon procedures, the discussion that
follows examines the application of these Standards in the context of public sector engagements.
While these stages are still relevant to public sector engagements, how each step is performed is
likely to vary.
ISAE 3000 (Revised) also addresses the requirements of an assurance engagement to assess the:
• Appropriateness of the subject matter.
• Suitability of the criteria to evaluate or measure the subject matter.
Required reading
ISAE 3000 paras 1–4.
CC
the engagement) against suitable criteria. The subject matter of a compliance engagement must
be identifiable, and can be subject to procedures for gathering sufficient appropriate evidence.
The purpose of ASAE 3100 Compliance Engagements (ASAE 3100) in Australia, and SAE 3100
Compliance Engagements (ASAE 3100) in New Zealand is to establish mandatory requirements
and provide explanatory guidance for performing and reporting on compliance engagements
other than audits or reviews of historical financial information. There is no corresponding ISAE.
In the public sector, compliance engagements involve commonly assessing subject matter for
compliance with:
•• Procurement guidelines mandated by a central agency.
•• Recruitment guidelines mandated by a central agency.
•• Asset management planning guidelines mandated by a central agency.
Determining whether an entity has complied, in all material respects, with certain requirements
is a matter of professional judgement. Determining whether instances of non-compliance are
material requires considering qualitative factors (i.e. the nature of non-compliance) and, to a
lesser extent, quantitative factors. ASAE 3100 para. 50/SAE 3100 para. A43 suggests this would
include considering:
(a) the size, complexity and nature of the entity’s activities;
(c) evidence of a robust compliance system and related controls to detect, rectify and report
compliance breaches;
(f) the impact on the decisions of the intended users and stakeholders of the entity; and
Australia-specific
As noted above, the applicable Standard in Australia is ASAE 3100.
Required reading
ASAE 3100 paras 1–4, 19, 28, 31, 33–34, 36–38, 40–42, 49–60, 64–80 and 85.
New Zealand-specific
As noted above, the applicable Standard in New Zealand is SAE 3100.
In determining whether an entity has complied, in all material respects, with certain
requirements, the Auditor-General may also apply their own Standards to add to the scope
of a compliance audit. For example, where a party is the subject of proposed criticism in the
compliance engagement report, under AG-5 paras 22–23, the Auditor-General will provide that
party with the opportunity to review the material and provide comment to ensure the report is
accurate and balanced.
Required reading
SAE 3100 paras 1–3, 14–20, 23–24, 29–31, 37, 45, 47–57, 61, A4–A9, A30–A35, A40–A41 and
A43–A53.
AG-5 paras 22–23.
CC
Australia-specific
In Australia, performance engagements are performed under ASAE 3500, with reference (and
as an adjunct Standard) to the overarching Standard, ASAE 3000, discussed above. The purpose
of ASAE 3500 is to establish mandatory requirements and provide explanatory guidance for
undertaking and reporting on performance engagements.
Under ASAE 3500 para. 17(h), performance audits (or reviews) involve assessing the ‘economy,
efficiency or effectiveness’ of ‘all or part of the activities of an entity or entities’. According to
ASAE 3500 para. 17(h), performance (audit or review) engagements are directed to assess:
(i) the adequacy of an internal control structure or specific internal controls, in particular those intended to
safeguard assets and to ensure due regard for economy, efficiency or effectiveness;
(ii) the extent to which resources have been managed economically or efficiently; and
(iii) the extent to which activities have been effective.
CC
• Measures aimed at deriving economies of scale, such as centralised resource acquisition, sharing
common resources across a number of business units.
• Measures aimed at improving economy, efficiency or effectiveness.
• Appropriateness of the assignment of responsibilities, and accountability.
• Measures to monitor outcomes against predetermined objectives and performance benchmarks.
(a) being identifiable, and its performance capable of consistent assessment against identified criteria; and
(b) ensuring the information about it is capable of being subjected to procedures for gathering sufficient
appropriate evidence to support a reasonable assurance or limited assurance conclusion, as appropriate.
Suitable criteria
According to ASAE 3500 para. 17(d), suitable criteria in relation to a performance engagement
demonstrate the following characteristics:
(i) relevance: relevant criteria contribute to conclusions that assist decision-making by the intended users.
(ii) completeness: criteria are sufficiently complete when relevant factors that could affect the conclusions in
the context of the performance engagement circumstances are not omitted.
(iii) reliability: reliable criteria allow reasonably consistent evaluation or measurement of the activity.
(iv) neutrality: neutral criteria contribute to conclusions that are free from bias.
(v) understandability: understandable criteria contribute to conclusions that are clear, comprehensive, and
not subject to significantly different interpretations.
Depending on the subject matter, the criteria will range from the general to the very
specific. General criteria are broad statements of acceptable and reasonable performance.
Specific criteria are derived from general criteria and are more closely related to an entity’s
enabling legislation or mandate, objectives, programs, systems and controls.
Examples of general criteria could include the following:
•• Has the agency introduced practical programs that are effective in contributing to the
government’s environment protection policy?
•• Has the agency introduced policies that are effective in contributing to the government’s
carbon footprint reduction plan?
CC
CC
The following table lists examples of subject matter that are assessed by Auditors-General
through performance engagements:
Required reading
ASAE 3500 paras 1–10, 12, 15–19, 23, 27–28, 32, 36–38, 40–48, 53–54, 61–63, 66–71, 74–76,
79–83 and 89–91.
CC
New Zealand-specific
While the Auditor-General will be mindful of Auditing Standards that are applicable to other
audit practitioners, it is important to remember that such Standards – for example, those issued
by the External Reporting Board (XRB) – do not always take full account of the requirements of
public entity audits. These requirements will often be established by legislation, and frequently
relate to the performance of a public entity in carrying out its statutory function.
Performance audit engagements performed by the Auditor-General are performed under
AG-5. Performance audit engagements (whether audits or reviews) may involve assessing the
efficiency or effectiveness of all or a part of the activities of an entity or entities (AG-5 para. 6).
The Auditor-General’s power to undertake performance audits is derived from the PAA (s. 16 –
see the definition of ‘performance audit’ in the Auditor-General’s Auditing Standards ‘Glossary
of terms’ p. 3-103 and the scope of AG-5 para. 1). In conducting a performance audit or other
engagement pursuant to AG-5, the Auditor-General may have regard to the ‘effectiveness and
efficiency’ (AG-5 para. 6) of the entity that is the subject of the engagement.
‘Effectiveness’ and ‘efficiency’ are defined in the Auditor-General’s Auditing Standards ‘Glossary
of terms’ p. 3-102:
Effectiveness ‘means the extent to which objectives are achieved, and relates to the actual
effect of an activity against the intended effect’.
Efficiency ‘means that minimum resources are used to achieve a given quantity and quality
of output, or a maximum output is gained with a given quantity and quality of resources
and relates to resources being used to produce outputs or objectives’.
It is important to note that effectiveness and efficiency in the context of a public sector
performance audit are not audit assertions as commonly used in financial audits, but reflect
the Auditor-General’s audit mandates, on which the Auditor-General will measure the
performance of an activity or entity.
The Auditor-General may also undertake performance audits regarding compliance with:
•• Statutory obligations.
•• Use of public resources.
•• Probity (i.e. the high standard of ethical behaviour that is expected of staff, management
and governing bodies of public sector entities).
•• Financial prudence (i.e. being careful with money).
The Auditor-General may consider the effectiveness and efficiency audit mandates in a separate
performance audit engagement, or in the context of their audit of the relevant public entity’s
financial report.
The Office of the Auditor-General, like all organisations, does not have unlimited resources.
Accordingly, the Auditor-General is required to determine which activities or entities will be
subject to performance audits. AG-5 para. 12 sets out these criteria. The decision on which
performance audits will be carried out is made through the process for developing the Auditor-
General’s work program required under the PAA. The proposed performance audits are set
out in the Auditor-General’s annual audit plan; however, the Auditor-General may choose to
undertake performance audits that arise on an unplanned basis.
AG-5, like other Auditing Standards, requires the Auditor-General to:
•• Formulate the work.
•• Undertake appropriate planning.
•• Obtain relevant evidence.
•• Keep sufficient documentation as evidence that the engagement was conducted
in accordance with the appropriate Standards and thus support the findings,
recommendations and, if appropriate, the conclusions reached by the Auditor-General.
CC
When reporting their findings, recommendations and conclusions, the Auditor-General may, if
appropriate, include criticism of the Department and members of its staff. Pursuant to AG‑5, it is
necessary for the Auditor-General to provide the parties subject to the criticism with sufficient
information for them to comment on the factual accuracy, completeness, fairness and balance
of the findings, recommendations and, if appropriate, the Auditor-General’s conclusions. The
Auditor-General must consider any response from the parties and determine what, if any,
modifications to the report are necessary.
Required reading
AG-5.
Quiz
[Available online in myLearning]
Readings
Required reading
Relevant International Auditing and Assurance pronouncements and national equivalents and guidance
International Australia New Zealand
Code of Ethics for Professional APES 110 Code of Ethics for NZICA Code of Ethics
Accountants (IESBA Code) (2015) Professional Accountants
•• Paragraphs 300.1– 300.15 •• Paragraphs 300.1–300.15 •• Paragraphs 300.1–300.15
ISA 210 Agreeing the Terms of ASA 210 Agreeing the Terms of ISA (NZ) 210 Agreeing the Terms of Audit
Audit Engagements Audit Engagements Engagements
•• Paragraph 21 •• Paragraph 21 •• Paragraph 21
ISA 315 (Revised) Identifying ASA 315 Identifying and Assessing ISA (NZ) 315 (Revised) Identifying
and Assessing the Risks of the Risks of Material Misstatement and Assessing the Risks of Material
Material Misstatement through through Understanding the Entity Misstatement through Understanding the
Understanding the Entity and Its and Its Environment Entity and Its Environment
Environment
•• Paragraphs 4(c) and 12 •• Paragraphs 4(c) and 12 •• Paragraphs 4(c) and 12
ISAE 3000 (Revised) Assurance ASAE 3000 Assurance ISAE (NZ) 3000 Assurance Engagements
Engagements Other than Audits Engagements Other than Audits Other than Audits or Reviews of Historical
or Reviews of Historical Financial or Reviews of Historical Financial Financial Information
Information Information
•• Paragraphs 1-8, 10-12, 14, •• Paragraphs 1–9, 12–26, 28–30, •• Paragraphs 1–4, 6–12, 14–15, 18–19,
20-22, 24, 31-33, 37-51, 64-77 33–37, 40, 43, 56–57, 64–65, 22, 33, 38, 41–42, 45–46, 49 and
and A45 68–70, 73–75, 78 and 82–84 51–52
N/A – ISAE 3000 (Revised) ASAE 3100 Compliance SAE 3100 Compliance Engagements
applies Engagements
•• Paragraphs 1–4, 19, 28, 31, •• Paragraphs 1–3, 14–20, 23–24, 29–31,
33–34, 36–38, 40–42, 49–60, 37, 45, 47–57, 61, A4–A9, A30–A35,
64–80 and 85 A40–A41 and A43–A53
N/A – ISAE 3000 (Revised) ASAE 3500 Performance AG-5 Auditor-General’s Auditing
applies Engagements Standard 5 Performance Audits, Other
Auditing Services and Other Work Carried
Paragraphs 1–10, 12, 15–19, 23, Out by or on behalf of the Auditor-General
27–28, 32, 36–38, 40–48, 53–54,
61–63, 66–71, 74–76, 79–83 and
89–91
N/A N/A AG-4 (Revised) Auditor-General’s
Auditing Standard 4 The Audit of Service
Performance Reports
•• Paragraph 4
Relevant International Auditing and Assurance pronouncements and national equivalents and guidance
International Australia New Zealand
N/A N/A Public Audit Act 2001
•• Sections 5, 14, 16–18, 20–22,
Schedule 3 Item 4
www.ifac.org www.auasb.gov.au www.xrb.govt.nz
www.oag.govt.nz
Further reading
ACT
Activity 18.1
Assessing results of compliance engagements
Introduction
Compliance engagements can be performed in both the private and public sectors. However,
these types of engagements are regularly performed by auditors in the public sector. Some
Auditors-General build in a compliance engagement with their audit of annual financial
statements.
This activity links to learning outcome:
•• Apply the appropriate assurance process to public sector engagements.
At the end of this activity, you will be able to evaluate the results of a compliance engagement,
in accordance with:
Scenario
You are an audit manager working for the Auditor-General. You have taken over from another
audit manager who is on long service leave. The engagement you are currently completing
is an investigation into whether the Department of Information (DI) is complying with the
government-wide recruitment policy established by the Department of Human Capital.
The following is an extract of key requirements of the policy:
Policy Requirement
paragraph
reference
12 The head of a government agency must advertise all vacancies on the government recruitment
website and in at least one major newspaper, as determined by the department head for that
agency
14 A selection committee shall be established to assess the merit of all applicants for appointment
to a vacant position
18 Appointments to vacant positions are to be made by the department head for that agency
The department head is not required to appoint the applicant recommended by the selection
committee; however, they may only fill the vacant position from the pool of applicants
ACT
Policy Requirement
paragraph
reference
74 For appointments made by the department head through exercise of the para. 18 exemption:
•• The department head must provide a written report to the selection committee prior to the
applicant’s appointment
•• The written report must outline the reasons for the department head’s decision to appoint
an applicant not recommended by the selection committee
•• The department head must receive acknowledgement from the selection committee
members prior to making the appointment
The engagement team has already completed the field testing work regarding the DI’s
compliance with the recruitment policy.
From a sample of 15 appointments made throughout the period, the audit engagement team
found only one very senior appointment where the DI had failed to advertise the position in a
major newspaper, but had advertised the position on the government recruitment website. All
other aspects of the recruitment policy had been complied with for all 15 appointments selected.
Task
For this activity, you are required to outline what work is required to complete the
DI compliance engagement and assess the impact of any compliance breaches.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Activity 18.2
Performance engagement criteria
Introduction
Planning is the key to a well-organised performance engagement. Part of the planning process
is to clearly identify the subject matter and the suitable criteria by which the subject matter is
evaluated.
This activity links to learning outcome:
•• Apply the appropriate assurance process to public sector engagements.
At the end of this activity, you will be able to evaluate the suitability of criteria, identify relevant
assertions, and determine appropriate engagement procedures in a performance engagement,
in accordance with:
Scenario
You are an audit manager working for the Auditor-General. The role of the Department of
Industrial Development (DID) is to distribute government grants to eligible businesses. All
agricultural and manufacturing businesses that donate products to the country’s prisons,
hospitals and orphanages free of charge are eligible to apply for government grants, as the
government wants to support these businesses so that they can continue to support the
underprivileged.
Not all applicants will be allocated grants due to limited government funding. Grants will
be allocated based on applicants’ support of the underprivileged. The government has
budgeted $10 million to DID’s grant program for the 30 June 20X3 financial year. Your team is
undertaking an audit engagement on DID’s performance for the year ended 30 June 20X3.
During planning for the engagement, the audit team sets the following questions to assess
DID’s performance:
1. Is the grant program aligned to government priorities?
2. Are grants allocated appropriately?
3. Have grants achieved results?
The audit team then formulates the following performance engagement criteria:
1. Alignment of grant program to government priorities
1.1 Is the grant program aligned to the government’s core business?
1.2 Has DID developed reasonable guidelines and criteria for the grant program?
ACT
2. Appropriate allocation of grants
2.1 Are grants allocated based on the support of the underprivileged regardless of political
and regional characteristics?
2.2 Has DID considered the applicant’s forecast output available for donation in granting
funds?
3. Achievement of results
3.1 Does DID ensure funds are used for good purposes?
3.2 Does DID evaluate its grant program?
The Auditor-General is interested in your team’s work and would like to know the results.
Task
For this activity, you are required to:
•• Assess the suitability of the six audit criteria against the relevant Assurance Standard.
•• Identify and explain which performance-based assertion each of the six audit criteria is
aimed at testing.
•• Design appropriate assurance procedures to test the relevant assertion for audit criteria
2.1 and 2.2.
CC
Core content
Unit 19: Case study, and current and future
trends
Learning outcomes
At the end of this unit you will be able to:
1. Apply the ethical requirements and the audit process to a financial statements audit
engagement.
2. Describe current and future trends that are relevant and important to the practice of
auditing and assurance in all jurisdictions.
3. Explain where to go to keep up to date with assurance Standards and guidance, and
regulatory requirements.
Introduction
All earlier units of the Audit & Assurance (AAA) module have addressed the obligations that an
auditor has under the Auditing and Assurance Standards, and what the auditor is required to
do to meet those obligations. Completion of this unit requires an integrated knowledge of many
of the concepts covered so far in the AAA module. Therefore, completion of all previous units is
recommended before attempting to work through the unit.
This unit also looks at some contemporary audit and assurance issues and explains where to
find current assurance Standards and guidance, and regulatory requirements.
CC
Auditor’s objective
Learning outcome
1. Apply the ethical requirements and the audit process to a financial statements audit
engagement.
As well as these stage-specific activities, continuous audit activities must also be performed
throughout the audit process. These include addressing going concern, documenting audit
evidence, and reviewing and revising the audit plan, strategy and materiality levels.
CC
The diagram below provides an overview of these stages:
AUDIT PROCESS
CC
As the aim of the auditor is to obtain sufficient appropriate audit evidence to reduce audit risk
to an acceptably low level (in order to obtain reasonable assurance on the RMM in the financial
statements), the auditor must design audit procedures in accordance with the risk assessment.
The first step in the planning stage is, therefore, performing risk assessment procedures.
Fraud risk
As the auditor’s main objective is to express an opinion about whether the financial statements
are free from material misstatement, whether due to fraud or error, the auditor must therefore
consider fraud risk in their audit planning.
In particular, the auditor needs to assess whether there are any indicators of fraud risk arising
from related party relationships and transactions, due to the inherent risk associated with
related parties.
Audit requirements regarding fraud risk are discussed in the unit on analysing audit risks –
fraud.
CC
CC
Tests of controls
The purpose of tests of controls is to obtain evidence relating to the operating effectiveness
of the internal controls designed and implemented by management to prevent, or detect and
correct, material misstatements at the assertion level (ISA 330 para. 4(b)).
Tests of controls are discussed in detail in the unit on responding to assessed risks – controls
testing.
Substantive procedures
The purpose of substantive procedures is to detect material misstatements in financial statement
items (i.e. at the assertion level – ISA 330 para. 4(a)). Substantive procedures include tests of
details and substantive analytical procedures (SAPs). Substantive procedures are discussed in
detail in the unit on responding to assessed risks – substantive testing.
Note that an audit cannot be completed solely by performing tests of controls. Substantive
procedures are required to be performed ‘for each material class of transactions, account
balance [at period end], and disclosure’ (ISA 330 para. 18). ISA 330 and ISA 520 both include
specific guidance on when to use substantive procedures.
Evaluating audit evidence
Having responded to assessed risks by performing further audit procedures, the auditor
needs to evaluate the results of those audit procedures – that is, to evaluate the audit evidence,
and in doing so, exercise their professional judgement to determine the sufficiency and
appropriateness of the audit evidence.
Where the auditor determines that sufficient appropriate audit evidence has not been obtained
by performing the audit procedures originally designed in the audit plan, they are required to
design additional procedures to ensure sufficient appropriate audit evidence is obtained, and
update the audit plan accordingly.
This is discussed in the unit on responding to assessed risks – evaluating audit evidence.
Activity 19.4: Evaluating audit evidence and determining further audit procedures
[Located at the end of this unit]
CC
It is important to note, when using the work of others, that the auditor (being the engagement
partner) retains sole responsibility for the audit opinion expressed.
Using the work of others, external confirmations and written representations are all discussed
in detail in the unit on responding to assessed risk – using the work of others, external
confirmations and written representations.
External confirmations
In performing audit procedures and evaluating the results, it is important that the auditor
considers the reliability of audit evidence that has been obtained.
Audit evidence is considered to be more reliable when it is obtained:
•• From independent sources outside the entity that is being audited.
•• Directly by the auditor.
•• In documentary form.
In light of this, auditors often send external confirmation requests to obtain audit evidence.
External confirmations are considered more reliable than evidence that is provided by the entity
itself.
Written representations
The entity’s management has a responsibility to provide written representations to the auditor
in respect of the audit. Specifically, management needs to provide a written statement to the
auditor that management and ‘those charged with governance … believe that they have fulfilled
their responsibility for the preparation of the financial statements and for the completeness
of the information provided to the auditor’, as well as provide other statements considered
‘necessary by the auditor or as required by other ISAs’ to ‘support other audit evidence’
(ISA 580 paras 6(a) and (b)).
It is important to note that although written representations provide ‘necessary audit evidence’,
they ‘do not provide sufficient appropriate audit evidence on their own’ (ISA 580 para. 4). They
should, therefore, always be considered in combination with the other evidence obtained.
CC
Additionally, the auditor has a responsibility to assess the issue of going concern throughout
the audit process, and, based on their professional judgement, to:
•• Evaluate whether management’s use of the going concern assumption is appropriate.
•• Conclude whether a material uncertainty exists in relation to the entity’s ability to continue
as a going concern.
This topic is discussed in detail in the unit on subsequent events and going concern.
These topics are discussed in more detail in the unit on reviewing the financial statements and
audit results.
CC
CC
Learning outcomes
2. Describe current and future trends that are relevant and important to the practice of auditing
and assurance in all jurisdictions.
3. Explain where to go to keep up to date with assurance Standards and guidance, and
regulatory requirements.
International developments
A number of important developments have occurred at an international level. The most
prominent current development, which will be effective for audits of financial statements for
periods ending on or after 15 December 2016, is the implementation of new and revised ISAs
relating to auditor reporting. These developments are discussed in the unit on forming an
opinion and issuing an auditor’s report. The implementation of these Standards will represent a
significant change in practice.
Other current developments that will also be effective for periods ending on or after
15 December 2016 relate to the work of the International Auditing and Assurance Standards
Board (IAASB), and affect the following audit areas:
•• The auditor’s responsibilities relating to other information. These developments are
discussed in the unit on reviewing the financial statements and audit results.
•• Going concern. ISA 570 (Revised) Going Concern will include revisions to the work that
auditors will be required to perform in this regard, with greater emphasis being placed
on going concern disclosures. There will also be changes in how auditors report on going
concern issues. The reporting changes are discussed in the unit on forming an opinion and
issuing an auditor’s report.
•• Communications. ISA 260 (Revised) Communication with Those Charged with Governance will
include guidance on the communication of matters to be included in the auditor’s report,
which is currently located in other Auditing Standards. The revised Standard will also
include guidance relating to communicating key audit matters under the new Auditing
Standard ISA 701 Communicating Key Audit Matters in the Independent Auditor’s Report.
CC
Information on the scope and intent of all the IASB’s current and future projects can be found
on its website (www.ifac.org → Independent Standard-setting Boards → IAASB® Auditing &
Assurance → Projects).
Many contemporary auditing and assurance developments are linked to developments in
reporting on financial and other information. Some of these are discussed below.
Disclosures
In July 2015, the IAASB issued a final pronouncement Addressing Disclosures in the Audit
of Financial Statements – Revised ISAs and Related Conforming Amendments. The focus of the
disclosure project was to ‘enhance the requirements in various ISAs to drive changes in the
auditor’s approach’ to disclosures (Basis for Conclusions, Addressing Disclosures in the Audit of
Financial Statement and Related Conforming Amendments, July 2015 para. 12(b)).
One of these changes in approach will include the integration of assertions for presentation and
disclosure with assertions relating to account balances, classes of transactions and events. The
change has been made to encourage auditors to address the related disclosures at the same time
that they are performing other audit procedures.
The IAABS’s disclosure project was part of a wider project that looked at the complexity
of financial reports and initiatives for the purpose of reducing and simplifying disclosures.
Current discussions on the topic suggest that there is scope for entities to improve the clarity of
financial reports under existing disclosure requirements by highlighting key information, re-
ordering content into logical sections and removing unnecessary disclosures.
Sustainability reporting
The Global Reporting Initiative (GRI) is an independent international organisation that
promotes the use of sustainability reporting as a way for entities to become more sustainable
and contribute to sustainable development. Sustainability issues include issues such as climate
change, human rights and corruption.
The GRI framework includes reporting guidelines, sector guidance and other resources.
The GRI is supportive of integrated reporting as it is an important and necessary innovation of
corporate reporting.
Assurance practitioners can be engaged to provide assurance over sustainability reporting.
Fundamental assurance skills and knowledge are applicable to the broader sets of information
that are presented in sustainability reports. ISAE 3000 Assurance Engagements Other Than Audits
or Reviews of Historical Financial Information (ISAE 3000) is the relevant Standard for this type of
work.
CC
Integrated reporting
The International Integrated Reporting Council (IIRC) is a ‘global coalition of regulators,
investors, companies, standard setters, the accounting profession and [non-government
organisations]’ (see www.integratedreporting.org).
While many companies prepare traditional financial reports and separate sustainability
reports, integrated reports attempt to serve as the reporting ‘centrepiece’ of integrated thinking
within an organisation. They extend the traditional view of capital beyond financial capital, to
incorporate manufactured capital, human capital, social and relationship capital, intellectual
capital and natural capital.
An integrated approach argues that the interrelationships between all forms of capital act to
create short-, medium- and long-term value, and that examining the integrated whole and
embedding this practice in an entity’s decision-making processes is key to understanding the
entity’s value creation over time.
Assurance practitioners have a role in strengthening the credibility of integrated reports.
CC
Australia-specific
CC
New Zealand-specific
Oversight of audit and assurance providers is undertaken by the Financial Markets Authority
(FMA). The FMA has responsibility for the oversight of engagements involving the audit of
financial statements. Its audit oversight activities are intended to help maintain and raise the
standard of conduct in the auditing profession. Information on the FMA’s regulatory work and
guidance on auditor requirements can be found on the FMA’s website (www.fma.govt.nz).
The latest FMA Audit Quality Review Report for the 12 months ended June 2014 can be found
on the FMA website. The report confirms that the majority of the profession in New Zealand
is meeting minimum compliance standards. The report highlights the following key areas
needing attention by audit firms:
•• Monitoring of audit quality.
•• Auditor independence.
•• Professional scepticism.
•• Going concern statements.
•• Use of management or audit experts.
•• Auditing of revenue.
•• Audit sampling.
•• Analytical procedures.
•• Level of audit evidence for audit opinion.
Readings
Required reading
There are no required readings for this unit.
All Accounting and Auditing and Assurance Standards and guidance, and regulatory
requirements referred to in this unit are discussed in detail in Units 1–18.
Further reading
CS
[At the end of this case study, there are several activities]
Case study
Monty Travel Limited (MT)
Background
Monty Travel Limited (MT), a travel company, was established in 20W2 by Monty Swanson and
his wife, Millie. MT has been listed on the Australian Securities Exchange (ASX) since 20W8.
Marshall Barney Chartered Accountants (MBCA) is conducting the audit of MT’s 31 December
20X3 financial statements. MBCA has been MT’s auditor for the past five years.
Key personnel at MBCA working on the MT audit are:
•• Daniel Jones, audit partner in charge.
•• Sheena Soames, audit manager – she has been the manager of the MT audit engagements
for the past three years.
MT’s draft accounts for the year ended 31 December 20X3 are at the end of this case study.
Overall materiality has been calculated at 1% of revenue from operations, or $651,450.
Note: All monetary sums are denominated in Australian dollars (AUD) unless otherwise stated.
Company information
Branches
MT’s head office and management are located in Perth, Western Australia, and it has branches
throughout Australia, New Zealand and Asia. MT owns the head office premises and a number
of the company’s original branch offices, but the majority of branch offices are leased.
Directors
The directors of MT are:
•• Monty Swanson – chief executive officer (CEO).
•• Lily Swanson, Monty’s daughter – chief financial officer (CFO) and a Chartered Accountant
(CA).
•• Three other executive directors.
•• Millie Swanson – non-executive director.
These directors make up the current MT board of directors (the board), and have travel industry
experience. The CEO and CFO enjoy a substantial sales-related bonus provided they also meet
their specific objectives within the business.
Packaged holidays
Initially, MT provided packaged holidays in Australia and New Zealand. It carried on this
business for many years, but has recently expanded into packaged holidays in Asia and Europe.
MT offers three categories of holiday products: ‘Family’, ‘Explorer’ and ‘Couples’ holiday
packages.
CS
Family packages
Family packages are packaged holidays that are attractive to families. These provide either all-
inclusive hotel accommodation (including some meals and drinks) or self-catered apartments
(no meals provided).
Explorer packages
Explorer packages are aimed at people aged between 18 and 30, and are relatively cheap
adventure holidays centred on activities such as sailing, trekking, climbing and cycling.
Couples packages
Couples packages are expensive luxury holidays, which are mainly attractive to honeymooners
and older couples. These prestige products are often customised holidays, and include only the
more upmarket hotel chains and resorts.
MT only sells its own packaged products and does not act as an agent for any other travel
companies. It uses instead the services of other travel industry providers, such as airlines and
hotels, which it pays directly on behalf of its customers. All packaged holidays offered by MT
include accommodation, flights and transfers between airports and hotels.
Marketing
MT procures business through brochures made available at its branches or online through its
website. Both sources include the prices of MT’s holiday packages. Prices are generally not
negotiable, and discounts are not routinely offered. MT does occasionally run last-minute
promotions of discounted packages, particularly in the family packages category, but this is
unusual.
Despite MT’s investment in the online facility, Monty has found that customers prefer to
tailor their own holidays online by booking flights, transfers and accommodation directly
themselves, and bypassing travel agents completely. This trend has had a negative impact on
the performance of all three MT product ranges on offer, but especially on the Explorer range.
The target customer for this range prefers to travel unconstrained by a packaged offering.
CS
Booking procedures
Customers pay a deposit at the time of booking, and are issued with a booking reference
number. They are required to make the final payment eight weeks before the holiday’s
commencement. MT’s cash management is vital due to the seasonal nature of the holidays.
Holiday sales are transacted in AUD, but some hotels require payment in their local currency,
while airlines request payment in US dollars (USD).
Revenue recognition
MT’s revenue recognition policy is that revenue and direct expenses that relate to sold holidays
are recognised in the statement of profit or loss on customers’ departure. Payments received
from customers in advance of departure are recorded as deferred income. Amounts disclosed
as revenue are net of returns, trade allowances and rebates. This revenue policy is in accordance
with IAS 18 Revenue.
ERP system
In order to improve the quality of management information, MT implemented a new enterprise
resource planning (ERP) system in September 20X3, which fully integrates MT’s financial and
operational data. Implementation of this system was carried out by external consultants, and
although it was the first time they had installed such a large system, the project was completed
very quickly but on time.
The new ERP system is made up of separate components, which deal with:
•• General ledger.
•• Accounts receivable.
•• Accounts payable.
•• Purchasing.
•• Payroll.
•• Property, plant and equipment (PPE) register.
•• Management reporting.
These components are fully integrated, so that data only needs to be inputted once and all
relevant components are updated simultaneously. All MT’s branches use the ERP system and
are linked to the head office servers in real time. Bookings made over the internet are also
updated in real time.
CS
Purchasing process
MT’s purchasing department is managed by Vince Chow. Although he is not a director of
the company, he is eligible for profit-related bonus payments. Apart from overseeing the
purchasing department, Vince is also responsible for MT’s negotiations with hotels, including
sourcing new hotels. He takes great pride in this area of responsibility, and insists on
undertaking all negotiations personally.
Details of new suppliers of any type of purchase made by MT must be entered into MT’s
approved supplier list before transactions can be processed. All purchases over $2,000 must
be made through the purchasing department. Local branch managers have the authority to
make purchases below this amount to cover sundry expenses and refunds. Invoices received
are matched to purchase orders, and then sent to the relevant branch or head office manager
for approval. Invoices from hotels and airlines are approved for payment by Vince due to the
amounts involved.
Vince has been with MT since its early days and is a well-respected employee. Monty trusts
Vince and considers him part of the family – as such, Vince’s work is not reviewed by anyone
and he is only required to report to Monty. Monty does not require regular reports from Vince
outside of these discussions.
Internal audit
During 20X1, it was decided that an in-house internal audit department should be established
at MT. Lily Swanson contacted a respected ex-colleague of hers, Joe James, an audit partner
at Murphy Rochester (MR), the international accountancy firm where she trained, to see if
he would be interested in taking up the role of MT’s head of internal audit. He accepted the
position, and also brought over two of the brightest young members of his audit team at MR.
These appointments were all approved at an MT board meeting.
MT’s internal audit department was thus established in August 20X1, and comprises:
•• Joe James – head of internal audit and a CA, previously an assurance partner at an
international accountancy firm.
•• Emma White – an auditor and recently qualified CA with three years’ audit experience.
•• Sam Alexander – an auditor and currently undertaking the Chartered Accountants Program.
Joe reports directly to the board and on a daily basis to Lily Swanson, the CFO.
The internal audit department has unrestricted access to all parts of MT’s business and to all its
employees. It does not perform managerial or operational duties outside of its internal audit
function; however, Lily reserves the right to instruct Joe to undertake assignments that require
immediate attention.
The internal audit department is responsible for documenting all MT’s systems, and making
recommendations to the board on the adequacy of the company’s internal controls or any
improvements that could be made to these controls. Joe is authorised to discuss internal audit
matters arising at any time with Monty and the board of directors.
Joe has set up audit manuals, which include policies and procedures for objectivity and quality
controls, and work programs. Joe is responsible for planning and supervising the internal audit
department, and for reviewing Emma’s and Sam’s work. All work performed by the internal
auditors is documented. Joe conducts quarterly training to ensure Emma and Sam have the
required level of competence to perform their roles. This includes training on MT’s financial
reporting framework.
The introduction of the internal audit department initially met with some resistance from some
members of management at MT, who complained that their time would be wasted by having to
CS
deal with the internal audit team. Following these complaints, Lily issued a general instruction
to all branch and head office managers to cooperate fully with the internal audit team.
In addition to its regular activities, the internal audit team were recently asked by Lily to
undertake an audit of MT’s internet sales activity, given that this is a relatively new activity
for the business. While no significant issues were noted from this exercise, Joe did make some
recommendations in his report to the board, which were accepted and implemented.
CS
Supplier statements are reconciled each month and reviewed by Vince to ensure the processed
invoices have been paid. Lily Swanson checks that the weekly payments listing agrees with
the bank statements, and reviews any unusual payments on the listing. She also reviews the
purchase ledger control account for unusual items.
At the year end, an accruals list of invoices and credit notes received after year end that relate to
transactions that occurred before year end is prepared by Lily. This ensures that purchases are
recognised in the correct accounting period and that there are no unrecorded liabilities.
The finance department is required to retain and reconcile all supplier statements for the
purposes of the year-end audit.
Payroll process
All head office staff are paid salaries. Branch employees earn a basic salary plus commission on
holiday sales, and are also paid for any approved overtime. Commission often accounts for up
to 40% of branch employees’ remuneration.
Recruitment process
1. When a branch manager needs to recruit staff, they must first obtain written authorisation
from the human resources (HR) manager, Jilly Wong, at head office to do so.
2. Once the branch manager has recruited locally, they send the employee’s contract, personal
details and photo identification to the HR department at head office, along with a copy of
their authorisation to recruit.
3. Gurpreet Singh, the HR supervisor, then accesses the payroll system and adds the new
employee details to the employee data file (which is password-protected and can only be
accessed by HR staff.) The payroll system allocates the new employee a unique employee
number. Hardcopy documentation of the employee’s details is then filed in the HR
department.
4. Each month, the system generates a ‘New employees’ report for Jilly, who confirms the
employee’s details are consistent with those in the employee’s file.
CS
The payment system provides the following computer-generated information:
•• Payslips for each employee.
•• A payroll summary, which analyses each employee’s payments. Payments are broken down
into gross pay, net pay, commission and overtime, and deductions.
•• An exception report recording the number of employees on the payroll files for which no
pay was calculated.
•• An exception report recording which employees have been paid for more than 170 hours in
the month.
•• An electronic funds transfer report recording the transfer of net pay amounts into
employees’ bank accounts.
Lu checks the reported exceptions to ascertain if the payroll record needs to be corrected.
Lily reviews the payroll summary, agrees the total amount provided in the electronic funds
transfer report to that of the payment system, and signs her authorisation for the payment to
proceed. Once the electronic funds transfer has been processed by the bank, Lily checks that the
electronic funds transfer report’s total is the same as that on the bank statement.
CS
BOARD OF DIRECTORS
CFO
Lily Swanson
Purchasing
manager
Vince Chow
Auditor HR
Emma supervisor
White Gurpreet Singh
Auditor
Sam
Alexander
CS
Financial information
CS
Current assets
Non-current assets
Current liabilities
Non-current liabilities
Equity
CS
3 Retained earnings
ACT
[All activities are related to the case study. Solutions to activities are available online.
Please access myLearning to view]
Introduction
In deciding whether to accept or continue an engagement, the auditor needs to identify and
evaluate threats to independence and ensure that the audit team is able to comply with relevant
ethical requirements.
This activity links to learning outcomes:
•• Apply the ethical requirements and the audit process to a financial statements audit
engagement.
•• Apply the code of ethics and relevant guidance, statements and legislation regarding
auditor independence (from the unit on pre-engagement activities).
At the end of this activity, you will be able to apply the International Ethics Standards Board
for Accountants Code of Ethics for Professional Accountants (IESBA Code) to identify and evaluate
threats to independence, and identify relevant safeguards to eliminate or reduce the identified
threats.
It will take you approximately 30 minutes to complete.
Scenario
You are a senior auditor at Marshall Barney Chartered Accountants (MBCA). You have been
assigned to work on MT’s 31 December 20X3 financial statements audit engagement.
Sheena Soames, the audit manager, has informed you that she intends to allocate six other
auditors to work on this engagement, including Bradley Spades, a first-year auditor, and Ruth
Rivers, another senior auditor who has been involved in the two previous audits of MT. Ruth
will be taking the lead role in this year’s audit team on site.
When talking to Bradley, he tells you that he is quite excited at the prospect of working on the
audit engagement as he has inherited some shares in MT. He is looking forward to seeing ‘behind
the scenes’ of a company he part owns.
Ruth is a good friend of yours, as you have worked on many audit engagements together. She
has confided to you that she is concerned about potential independence issues if she takes
the lead role in the audit engagement. This is due to her brother’s impending wedding to Lily
Swanson, the CFO of MT, to which she has been invited. The news came as a surprise to her as
she is close to her brother but didn’t know that he was in a relationship with Lily; however, it
appears that, after a whirlwind romance, they are set to marry.
ACT
Task
For this activity, you are required to identify and explain, in accordance with the IESBA Code:
•• key threats to independence
•• key fundamental principles that could be compromised, and
•• the most appropriate safeguard to eliminate the threats to independence, or reduce them to
an acceptable level.
with regard to the MT audit engagement, in relation to the new information you have obtained
about Bradley and Ruth.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Introduction
The auditor must identify and assess the risks of material misstatement, whether due to fraud
or error, at both the financial statement level and the assertion level.
This activity links to learning outcomes:
•• Apply the ethical requirements and the audit process to a financial statements audit
engagement.
•• Discuss and demonstrate the auditor’s responsibility to identify and assess the risks of
material misstatement in financial statement (from the unit on understanding the entity and
its environment).
•• Explain and apply the use of assertions in assessing the risks of material misstatement at the
financial statement level and at the assertion level (from the unit on analysing audit risks,
financial statement assertions and initial audit engagements).
•• Explain and identify the characteristics of fraud in the context of an audit (from the unit on
analysing audit risks – fraud).
•• Explain the going concern assumption (from the unit on subsequent events and going
concern).
At the end of this activity, you will be able to identify risk factors and explain how they impact
on the financial statements, in accordance with ISA 315 (Revised) Identifying and Assessing the
Risks of Material Misstatement through Understanding the Entity and Its Environment (ISA 315) and
ISA 570 Going Concern (ISA 570). You will also be able to identify and explain fraud risk factors
specifically, in accordance with ISA 240 The Auditor’s Responsibilities Relating to Fraud in an Audit
of Financial Statements (ISA 240).
It will take you approximately 60 minutes to complete.
Scenario
You are a senior auditor at Marshall Barney Chartered Accountants (MBCA). You have been
assigned to work on MT’s 31 December 20X3 financial statements audit engagement.
It is January 20X4 and the MT audit is at the planning stage. Sheena, the audit manager, has
asked you to identify the key risks to which MT is exposed.
ACT
Tasks
For this activity, you are required to:
•• Identify key risk factors to which MT is exposed.
•• For financial statement level risks, explain the impact on the financial statements.
•• For assertion level risks, identify the key accounts and assertions at risk of material
misstatement whether due to fraud or error.
ACT
Introduction
Testing the operating effectiveness of controls can reduce the amount of substantive testing
required, which leads to an efficient and effective audit.
This activity links to learning outcomes:
•• Apply the ethical requirements and the audit process to a financial statements audit
engagement.
•• Design, perform and evaluate the results of controls testing (from the unit on responding to
assessed risks – controls testing).
•• Design, implement and evaluate tests of controls, using computer-assisted audit techniques
(CAATs) – (from the unit on responding to assessed risks – controls testing).
At the end of this activity, you will be able to identify risks and controls and design tests of
controls to test the operating effectiveness of internal controls, in accordance with ISA 315
(Revised) Identifying and Assessing the Risks of Material Misstatement through Understanding
the Entity and Its Environment (ISA 315) and ISA 330 The Auditor’s Responses to Assessed Risks
(ISA 330).
It will take you approximately 60 minutes to complete.
Scenario
You are a senior auditor at Marshall Barney Chartered Accountants (MBCA), and have been
assigned to work on MT’s 31 December 20X3 financial statements audit engagement.
When performing risk assessment procedures, you obtain an understanding of MT’s internal
controls around its payroll process designed to prevent or detect and correct material
misstatements regarding the occurrence and accuracy of payroll expenses and the existence,
completeness, and valuation and allocation of payroll liabilities.
Having evaluated the design and implementation of identified controls, you have an
expectation that they have been effectively designed and implemented, and you are now
planning to test the operating effectiveness of these controls. Your team has also tested the
IT general controls and have concluded they are effective.
MBCA’s audit manual provides the following guidelines on selecting sample sizes for tests of
controls:
Daily 25
Weekly 10
Monthly 2–4
Quarterly 2
ACT
MBCA’s audit software includes the following tests of controls for payroll:
Input dummy employees without a valid number to ensure the pay run cannot be processed.
Select exception reports for payroll. Inspect for evidence of review. Through discussion with
the reviewer, determine that appropriate actions are taken by the reviewer with respect of the
exceptions.
Attempt to access the payroll employee data file and the payroll software to confirm access to
systems is appropriately restricted.
For a sample of pay runs, extract pay rates from the employee data file and have the system
recalculate the gross pay and confirm it matches the figure in the pay run.
Select a sample of electronic funds transfer reports and the corresponding bank statements.
Inspect the electronic funds transfer reports for evidence of authorisation.
Tasks
For this activity, you are required to:
1. Identify and explain the risks and relevant controls in MT’s payroll process, including
internal controls in the recruitment, pay run and employee termination processes.
2. Categorise the identified internal controls into manual controls and IT application controls
(ITAC).
3. From the list of possible tests of controls suggested by MBCA’s audit software, select tests of
controls that appropriately address the risks you have identified.
4. Customise the tests to MT’s circumstances in sufficient detail to enable a junior auditor to
perform them.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Introduction
The auditor needs to analyse the results of the audit procedures performed and determine the
impact of the nature, timing and extent of further audit procedures required in order to obtain
sufficient appropriate audit evidence.
This activity links to learning outcomes:
•• Apply the ethical requirements and the audit process to a financial statements audit
engagement.
•• Apply audit sampling during controls testing in order to provide a reasonable basis for
the auditor to draw conclusions (from the unit on responding to assessed risks – controls
testing).
•• Explain the importance of evaluating controls and continually evaluating the results of
testing work throughout an audit (from the unit on responding to assessed risks – controls
testing).
•• Design, perform and evaluate the results of substantive testing (from the unit on responding
to assessed risks – substantive testing).
•• Determine whether sufficient appropriate audit evidence has been obtained on which to
base conclusions and auditor’s reports (from the unit on responding to assessed risks –
evaluating audit evidence).
At the end of this activity, you will be able to evaluate audit evidence and determine the nature,
timing and extent of further audit procedures required in order to obtain sufficient appropriate
audit evidence, in accordance with:
•• ISA 330 The Auditor’s Responses to Assessed Risks (ISA 330).
•• ISA 450 Evaluation of Misstatements Identified during the Audit (ISA 450).
•• ISA 500 Audit Evidence (ISA 500).
Scenario
You are a senior auditor at Marshall Barney Chartered Accountants (MBCA) and have been
assigned to work on MT’s 31 December 20X3 financial statements audit engagement. Sheena
Soames is the audit manager.
Based on the information gathered by the audit team in the planning stage of the audit, Sheena
intends to adopt a combined audit approach. Her expectation is that all controls at MT are
operating effectively and, therefore, she intends to place a high reliance on these internal
controls. In accordance with MBCA’s audit manual, she has set the tolerable rate of deviation at
5% for her controls testing.
ACT
As per the audit plan that Sheena prepared, the audit team performed the following two tests
for the existence, completeness, and valuation and allocation of trade payables:
Test 1:
Test of controls – Valuation and allocation, completeness, and existence of trade payables
Select a random sample of 25 Of the 25 invoices selected, 23 were tested without deviation. The following
invoices exceptions were noted:
Match each invoice to a
Invoice Result Comments
purchase order
number and
Confirm that each invoice has amount
been initialled as evidence
that the invoice details Inv124663 The invoice had not The client had no explanation
have been confirmed to the been initialled as for this. However, the financial
$63.97
purchase order by the finance evidence that the accountant commented that since
department invoice details had the amount was small, he did not
been checked against think it mattered
Check that each purchase the purchase order
order agrees to a related
purchase requisition and Inv128242 There was evidence This was discussed with the
delivery docket and confirm that the invoice agreed financial accountant. The invoice
$2,503.56
that the delivery docket was to the purchase order related to emergency plumbing
authorised by the appropriate and was authorised by work in one of the branches
departmental manager as the branch manager; following a flood. The financial
confirmation that the goods or however, the branch accountant was able to show
service have been received manager does not an email sent to him from the
have authority to branch manager the day after the
Ensure that the supplier’s approve for amounts emergency apologising for not
name on the purchase order is over $2,000 following the normal procedures
on the approved supplier list and explaining the circumstances
Test 2:
Test of details – Existence, completeness, and valuation and allocation of trade payables
Select cash payments All selected subsequent cash payments were agreed to the trade payable balances
subsequent to 31.12.X3 where appropriate, except for the following:
greater than $2,000
and determine: Supplier Cash Trade Reason for difference
payment payable
Whether the payment
$ $
refers to a good
received or service
performed prior to 1. Cross 10,076.49 8,852.98 Goods delivered but uninvoiced
year end and therefore Stationery at year end
correctly recorded
as a trade payable at 2. Hooper 25,368.55 20,459.55 Services performed 14.12.X3 –
31.12.X3. Hotels invoice awaiting authorisation at
year end
ACT
Tasks
For this activity, you are required to evaluate the results of the two tests.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Introduction
The external auditor may seek to use the work of an audit client’s internal auditors to modify
the nature and timing, or reduce the extent of, the audit procedures. However, the external
auditor needs to evaluate whether the work of internal auditors is adequate for the financial
statements audit.
This activity links to learning outcomes:
•• Apply the ethical requirements and the audit process to a financial statements audit
engagement.
•• Demonstrate the steps involved in determining whether and to what extent an external
auditor can use the work of internal auditors (from the unit on responding to assessed risk –
using the work of others, external confirmations and written representations).
At the end of this activity, you will be able to evaluate whether the work of internal auditors can
be relied on by external auditors for the purpose of a financial statements audit, in accordance
with ISA 610 (Revised 2013) Using the Work of Internal Auditors (ISA 610).
It will take you approximately 20 minutes to complete.
Scenario
You are a senior auditor at Marshall Barney Chartered Accountants (MBCA). You have been
assigned to work on MT’s 31 December 20X3 financial statements audit engagement.
MT’s CEO, Monty Swanson, has recently emailed the audit partner, Daniel Jones, to express his
concern at the level of the audit fee quoted by MBCA for the 31 December 20X3 audit. His email
said:
Now our internal audit department is properly established, I assume that you will be able to rely on the
work the department does for your own purposes, so I expect that your fee for this year can be reduced
accordingly.
Task
For this activity, you are required to assess MT’s internal audit department and determine
whether its work can be relied on.
[Solutions to activities are available online. Please access myLearning to view]
ACT
Introduction
The identification and, where applicable, recognition and disclosure of subsequent events form
part of the auditor’s assessment of whether the financial statements are materially misstated.
This activity links to learning outcomes:
•• Apply the ethical requirements and the audit process to a financial statement audit
engagement.
•• Apply the ‘Events after the Reporting Period’ Accounting Standard in relation to subsequent
events audit requirements (from the unit on subsequent events and going concern).
At the end of this activity, you will be able to identify the impact of subsequent events
on financial statements, in accordance with ISA 560 Subsequent Events (ISA 560) and
IAS 10 Events after the Reporting Period (IAS 10).
It will take you approximately 20 minutes to complete.
Scenario
You are a senior auditor at Marshall Barney Chartered Accountants (MBCA) and have been
assigned to work on MT’s 31 December 20X3 financial statements audit engagement. Sheena
Soames is the audit manager.
The auditor’s report is due to be signed on 19 March 20X4. On 9 March 20X4, while finalising
the audit, the following additional information came to Sheena’s attention through the
application of audit procedures under ISA 560:
ACT
Task
For this activity, you are required to identify and explain the impact, if any, of each event on
MT’s 31 December 20X3 financial statements, in accordance with ISA 560 and IAS 10.
[Solutions to activities are available online. Please access myLearning to view]