1/13
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Compliance Reporting
Reporting on compliance occurs when an auditor reports on contractual or regulatory compliance during a financial statement audit, performs an attestation engagement on compliance or internal control over compliance, or reports on compliance/internal control in a single audit for federal assistance recipients.
Negative Assurance
In a compliance report connected to audited financial statements, negative assurance states nothing came to light indicating noncompliance, provided no noncompliance was identified, an unmodified/qualified opinion was issued, and covenants were audited.
Report on Compliance
A written report provided as a separate document or embedded within the financial statement audit report that details compliance, including descriptions of any identified instances of noncompliance.
Attestation Standards: Compliance Attestation
Cover SSAE engagements regarding compliance with specified requirements or internal control over compliance, allowing examinations and agreed-upon procedures, but strictly prohibiting reviews.
Agreed-Upon Procedures Engagements
Engagements where a practitioner performs specific procedures agreed upon by users to assist in evaluating compliance or internal control over compliance without providing assurance.
Examination Engagements
Engagements providing reasonable assurance where a practitioner accumulates sufficient evidence to express an opinion on whether an entity complied with specified requirements in all material respects.
Materiality
In a compliance examination, materiality is influenced by the monetary or non-monetary nature of compliance requirements, frequency of identified noncompliance, sampling risk, and qualitative user expectations.
Overall Requirements for Compliance Examination
Practitioners must assess risk, design responses, determine supplementary audit requirements, obtain management written representations, prepare reports, and document findings.
Required Documentation
Documentation must include assessed risks of material noncompliance, internal control documentation, risk assessment responses, tests of compliance/controls, rationale for materiality levels, and supplemental requirement compliance.
Representation Letter
A mandatory written statement from management acknowledging responsibility for compliance and internal controls, performance of evaluations, disclosure of known/subsequent noncompliance, and provision of relevant records.
Attestation Risk of Noncompliance
The risk that a practitioner unknowingly fails to modify an opinion on noncompliance, equal to the risk of material noncompliance multiplied by detection risk.
Risk of Material Noncompliance
The combination of inherent risk of noncompliance (susceptibility to material noncompliance without controls) and control risk of noncompliance (risk that controls fail to prevent or detect material noncompliance).
Detection Risk of Noncompliance
The risk that practitioner procedures will fail to detect existing material noncompliance, which the auditor directly controls by adjusting the nature, timing, and extent of procedures.
Internal Control over compliance
Refers to an entity's internal processes designed to provide reasonable assurance regarding compliance with specified laws, regulations, rules, contracts, or grants. In compliance attestation engagements under SSAE standards, practitioners may perform agreed-upon procedures or examination engagements to evaluate the effectiveness of these internal controls, but reviews are strictly prohibited. Management must explicitly accept responsibility for establishing, maintaining, and evaluating the effectiveness of internal control over compliance.