1/117
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Why is the auditor required to perform risk assessment procedures, starting with obtaining an understanding of the entity and its environment?
To assess the risk of material misstatement and to make informed judgments about other matters, such as:
- Materiality and tolerable misstatement
- The entity's selection and application of accounting procedures
- Areas that require audit consideration
- Design and performance of further audit procedures
What risk assessment procedures should the auditor use to obtain an understanding of the entity and its environment?
- Inquiry (not enough alone)
- Analytical procedures
- Risk assessment discussion
- Audit data analytics
- Other procedures when applicable (such as reviewing external information)
What factors should be examined when obtaining an understanding of the entity and environment?
- Industry, regulatory, and other external factors
- Applicable financial reporting framework
- Technological factors
- Supply chain and economic factors
- The nature of the entity
- Objectives, strategies, and business risks
- the entity's financial performance
- The company's selection and application of accounting principles
What are the basic technological components of IT infrastructure?
- Hardware
- Software
- Networks
- Operating system
- Data storage/databases
List government policies and actions that an auditor may consider.
- Government spending
- Government taxation
- Interest rates
- Political stability
- Requirements for licenses and permits
What is the definition of a business cycle?
the rise and fall of economic activity relative to its long-term growth trend.
they consist of economic fluctuations that vary in duration and severity. Some cycles are quite mild; others are characterized by large increases in unemployment and/or inflation.
List and define the phases of a typical business cycle.
(1) an expansionary phase characterized by rising growth in economic activity (real GDP)
(2) a peak, or high point of economic activity
(3) a contractionary phase charaacterized by declining growth in economic activity;
(4) a trough, or low point of economic activity
(5) a recovery phase, during which economic activity starts to increase and return to its long-term growth trend.
Differentiate the three economic indicators: leading, lagging, and coincident.
Leading indicators predict economic activity and tend to change before the economy follows that trend (e.g., orders for goods).
Lagging indicators follow economic activity and change after an economic trend has already begun (e.g., prime rate charged by banks).
Coincident indicators change at about the same time as the economic trend (e.g., industrial production).
How are reconciliations used in business processes?
detective controls that review changes in account balances due to business process activities.
How are process narratives used to understand business processes?
written documents that tell the story of a process.
Identify some inherent limitations that may exist even with an effective internal control system.
- Human error or faulty/biased judgment used in decision-making.
- Issues pertaining to the suitability of the entity's objectives
- External events beyond the control of the entity
- Management override of controls
- Deliberate circumvention of controls through collusion
What is a significant risk?
Requires special audit consideration.
-Nonroutine, unusual, or complex transactions.
- Improper revenue recognition
-Fraud risk.
-Significant related party transactions.
-Accounting estimates or other subjective measurements of financial information.
-Accounting principles that are subject to different interpretations.
- Noncompliance with laws and regulations
What are the documentation requirements surrounding the auditor's assessment of risk?
- Discussion among the audit team.
- Understanding of the entity and its environment, including its internal control.
- Assessment of the risks of material misstatement.
- Basis for the risk assessment.
- Identified risks and related controls evaluated.
What are the three ways in which an auditor should respond to assessed risk?
- An overall response, to address risk at the FS level.
- A response at the relevant assertion level.
- A response to significant risks.
assertion level risks
specific transaction / account balances; Inherent and control assess separately
Substantive approach - Only substantive tests are used, either because there are no effective controls or because it would not be efficient to test the operating effectiveness of controls.
Combined approach - Tests of the operating effectiveness of control and tests of substantive procedures are both used.
test of controls may be required
When are tests of controls performed in a financial statement audit?
When the auditor's risk assessment is based on the assumption that controls are operating effectively;
Or:
When substantive procedures alone are insufficient, such as when there is a significant amount of electronic processing or when audit evidence is obtained in electronic form.
What steps should the auditor perform in assessing and responding to risk?
1. Obtain an understanding of the entity and its environment, including its internal control.
2. Assess the risk of material misstatement.
3. Respond to the assessed level of risk by designing further audit procedures based on this assessment.
4. Test internal controls to evaluate their operating effectiveness.
5. Perform substantive tests.
6. Evaluate the sufficiency and appropriateness of audit evidence obtained.
What procedures might an auditor use to evaluate an estimate?
- Reviewing and testing management's procedures.
- Developing an independent estimate or range for comparative purposes.
- Reviewing subsequent events and transactions that corroborate the estimate value.
What are the auditor's responsibilities when concluding on the reasonableness of an accounting estimate?
The auditor must confirm that:
- The assessed risk of material misstatement for the estimate remains appropriate.
- management's recognition, measurement, presentation, and disclosure are in accordance with the applicable financial reporting framework.
- Sufficient appropriate audit evidence has been obtained.
The auditor considers both corroborative and contradictory information when concluding on the reasonableness of an estimate.
Define related parties.
Related parties may include the reporting entity's affiliates, principal owners, and management, as well as any members of their immediate families.
What is the auditor's primary concern with respect to related party transactions?
The auditor is primarily concerned with the proper disclosure of related party transactions in accordance with GAAP.
How can the auditor determine whether related parties exist?
- Evaluating the company's procedures for identifying and accounting for related party transactions.
- Asking management.
- Reviewing the reporting entity's filings with the SEC.
- Reviewing prior year's audit documentation or inquiring of the predecessor auditor.
- Performing procedures over balances with affiliated entities as of concurrent dates.
What are some common audit procedures related to contingencies, including pending litigation or possible future litigation?
- Obtaining and reviewing the response from a letter of inquiry to the client's attorneys.
- Inquiring of management.
- Reviewing minutes of meetings of stockholders, board of directors, and other executive committees.
- Reviewing correspondence and invoices from lawyers.
- Reviewing contracts, loan agreements, loan guarantees, leases, and correspondence from taxing authorities.
What is the effect on the auditor's opinion if a client refuses to permit inquiry of its attorney, or if the attorney refuses to respond?
If a client does not permit inquiry of its attorney - Disclaimer or Withdrawal from engagement.
If a lawyer has devoted substantial attention to litigation, but refuses to respond to the auditor's letter of inquiry - Qualified opinion or Disclaimer of opinion (depends on materiality).
attorney does respond —> substantial attention limitation - limit response to only matters they have given alot of attention; confidentiality limitation
management is still the primary source of information for contingencies
What is the going concern period for financial statements where the applicable financial reporting framework is under the guidance of the following standard-setting bodies?
- FASB
- GASB
FASB: One year after the date the financial statements are issued (or available to be issued, as applicable)
GASB: One year beyond the date of the financial statements. GASB further requires that, if a governmental entity currently knows information that may raise substantial doubt shortly thereafter, such information should also be considered.
What conditions and events may indicate substantial doubt about an entity's ability to continue as a going concern?
FINE
F - Financial difficulties
I - Internal matters, such as labor difficulties, substantial dependence on a particular project, etc.
- Negative trends
- External matters, such as legal proceedings, new legislation, loss of a principal customer, natural disasters, etc.
What influences the auditor's decision regarding the sufficiency of audit evidence?
- RMM
- The quality of audit evidence
What factors should be considered when evaluating the reliability of audit evidence?
1. source of information (internal vs. external, direct knowledge vs. indirect)
2. Key attributes of evidence - accuracy, completeness, authenticity, susceptibility to bias
3. Internal controls in place related to evidence gathered
4. Form of evidence (oral vs. documentary)
5. Consistency of evidence
best - auditors direct knowlege, then external evidence, then internal, then oral
How is the relevance of evidence determined?
To be relevant, evidence must relate to the financial statement assertions under consideration.
PCAOB standards state that the relevance of audit evidence depends on the design and timing of the audit procedure.
What factors are relevant to the conclusion that sufficient appropriate evidence has been obtained?
- The significance of uncorrected misstatements and the likelihood of their having a material effect on the financial statements
- The results of audit procedures performed and the achievement of audit objectives
- the auditor's risk assessment
- Effectiveness of management's response and internal controls to address risk
- Experience gained during previous audits
- An understanding of the entity and its environment, the applicable financial reporting framework, and the entity's system of internal control
What are the documentation requirements surrounding the auditor's response to assessed risk?
- Overall response addressing assessed risk at the FS level.
- Nature, extent, and timing of further audit procedures.
- Linkage of further audit procedures with assessed risk at the relevant assertion level.
- Results of audit procedures.
- Conclusions reached regarding the use of prior period evidence.
- Basis for not using external confirmation procedures for accounts receivable with a material balance.
- the agreement or reconciliation of the information in the financial statement to the underlying accounting records.
List some of the standard auditing procedures used in most audits.
C the FIVE CARROT WARS
C - Confirmation
F - Footing (adding down), cross-footing (adding across), and recalculation
I - Inquiry
V - Vouching (existence / occurence)
E - Examination/Inspection (documentation)
C - Cutoff review
A - Analytical procedures (scanning)
R - Reperformance
R - Reconciliation
O - Observation
T - Tracing (completeness)
W - Walk-through (combo inquiry, observation, inspection, recalculation, repreformance)
A - Auditing related accounts simultaneously
R - Representation letter (required from mgmt)
S - Subsequent events review
What are analytical procedures?
Evaluations of financial information made by a study of plausible relationships among both financial and non-financial data (e.g., ratio analysis).
Note: Analytical procedures are required in the planning and final review stages of an audit. They may be used (but are not required) in substantive testing.
What steps are involved when using analytical procedures for substantive testing?
1. Determine that analytical procedures are suitable for testing the assertion(s).
2. Evaluate the reliability of data from which the auditor's expectation is to be developed.
3. Develop an expectation of the recorded amount.
4. Perform the analytical procedures and compare the results of the analytical procedures with the expectations.
5. Investigate any significant differences.
What is the purpose of applying analytical procedures during the overall review stage of the audit?
To evaluate the overall financial statement presentation, to assess the conclusions reached, and to assist in forming an opinion on whether the financial statements are free of material misstatement. This evaluation is typically performed by the manager or partner.
What is the difference between nonstatistical and statistical sampling?
Statistical sampling:
- uses laws of probability for selection and evaluation of a sample.
- allows for quantification of audit risk and sufficiency of audit evidence.
Nonstatistical sampling:
- does not utilize statistical models in calculations.
- Auditors use their judgment to determine sample sizes, and sample results are evaluated using auditor judgment.
What is the relationship between sampling risk and reliability (confidence level)?
Sampling + Confidence level = 100%
What is attribute sampling?
a statistical sampling method used to estimate a rate of occurrence in a sample.
It is used in tests of controls.
yes and no questions
table use
calc sample size = tolerable rate and expected deviation rate to find sample size
evaluation of sample results = sample size and actual # of deviations found
What factors affect sample size for an attribute sampling application?
- Risk of assessing control risk too low (inverse relationship)
- Tolerable deviation rate (inverse relationship)
- Expected deviation rate (direct relationship)
- Population size (not an issue if the population is large)
conclusion about an attribute sampling application
upper deviation rate > tolerable deviation rate = do not rely on the control
upper deviation rate < tolerable deviation rate = rely on the control
if sample is representative of the population usually the correct decision is made, if its not then the decision is usually incorrect
discovery sampling
a type of attribute sampling used when the expected deviation rate is near zero.
It is used when the auditor is looking for a very critical characteristic (e.g., fraud).
Describe variables sampling.
a statistical sampling method used to estimate the numerical measurement of a population.
used primarily in substantive testing.
What is stratification, and why would an auditor stratify a population?
separates the sample into relatively homogenous groups. Each group is treated as a separate population.
typically used we a population has highly variable amounts.
Stratification usually results in a smaller sample size.
What are the sampling plans commonly used for variables estimation?
- Mean-per-unit estimation: the sample mean x # of items in population
stratifys population , sensitive to variablity
- Ratio estimation: The ratio between book value and audited value (from a sample); used when proportional to BV
smaller sample size
- Difference estimation: The difference between book value and audited value (from a sample); used when not proportional to BV
smaller sample size
all used to estimate the population
What factors affect sample size for a variables sampling application?
- Standard deviation or population variability (direct relationship)
- tolerable misstatement (inverse relationship)
- Acceptable level of risk (inverse relationship)
- Expected size and frequency of misstatements (direct relationship)
- Assessed level of risk (direct relationship)
What amounts are compared in drawing a conclusion about a variables sampling application?
client's book value to the calculated range in a variables sampling application.
If the recorded book value is within the acceptable range, the book value is considered fairly stated. (The calculated range is the point estimate, as determined from the sample, plus/minus an allowance for sampling risk.)
probability-proportional-to-size (PPS) sampling.
a hybrid sampling technique that uses attribute sampling theory to express a conclusion in dollar amounts rather than as a rate of occurrence. The sampling unit is defined as an individual dollar in a population, which creates the effect of stratified sampling (the unit's chance of being selected increases as its amount increases).
higher values are more likely to be sampled
used in substantive testing (like variable sampling)
What are the advantages and disadvantages of using PPS sampling?
Advantages: Automatic stratification and Efficient (smaller sample)
Disadvantages: May require special considerations for negative, zero, and understated balances
How is the sampling interval determined in a PPS sampling application?
Sampling interval = Tolerable misstatement/Reliability factor
(The reliability factor comes from a table and is based on the risk of incorrect acceptance.)
How is the sample size determined in a PPS sampling application?
Sample size = Recorded amount of the population/Sampling interval
Define audit data analytics (ADAs).
data analytic techniques that enable auditors to analyze and review both financial and nonfinancial data to discover patterns, relationships, and anomalies during an audit.
What are the steps an auditor should use when applying audit data analytics?
- Plan the ADA.
- Access and obtain the data.
- Review and analyze the relevance and reliability of the sourced data.
- Perform the ADA using the selected tools and techniques.
- Evaluate outcomes to ensure the objective was achieved.
Describe the three components of the ETL process.
extract, transform, and load
- Data extraction involves the identification and obtaining of source data
- Transforming data entails taking unstructured data, cleaning it, and validating it to ensure it is accurate and ready for analysis
- Loading the data into a software program for analysis or into a data storage location is the final step of the ETL process
What are the four broad categories of data analytics that can be applied as audit data analytics?
- Descriptive analytics
- Diagnostic analytics
- Predictive analytics
- Prescriptive analytics
Define descriptive data analytics.
Explain what happened or what is happening now and help to gain a high-level understanding of the location of central tendency, spread, shape, and other descriptive values of the data being analyzed.
Define diagnostic data analytics.
work to uncover correlations, patterns, and relationships among data to explain outcomes.
utilized when an organization wants to understand the underlying cause of results; essentially, why something happened with the data.
Define predictive data analytics.
use historical data to make predictions, estimates, and assertions about future events
regression analysis
forecasting
time-series modeling
classification
sentiment analysis (feelings towards things)
Define prescriptive data analytics.
build on predictive analytics and shift the focus from addressing what will happen to how to make something happen. Examples include what-if analysis and decision support and automation.
what if analysis
decision support and automation
machine learning
natural language
How can audit data analytics be applied to tests of details?
ADAs can perform sequence checks, test entire populations, compare transactions against external data, and evaluate source data to identify missing data.
How can audit data analytics be applied to analytical procedures?
- Compare current year data to preceding year data.
- Compare industry trends to those at the audited entity.
- Develop expectations for transaction or balance amounts.
- Perform drill-down analyses of differences found between expected and actual amounts.
How does a relational database work?
allows data to be stored in different tables, and the tables can be linked through relationships using key values.
What different methods can be used to obtain audit data analytics data?
- Utilizing built-in reporting provided by information systems
- Custom queries of information systems
- Data mining
- Data-pulls
- Walk-throughs and interviews of clients
- Research and external sites
How are data visualizations used in audit data analytics?
Used to turn complex content into easy-to-read graphs or charts to provide the auditor with insights to make decisions.
List some techniques that can be used to interpret audit data analytics results.
regression analysis, variance analysis, period-over-period analysis, classification, and trend analysis.
what is the purpose of analytical procedues used in audit planning phase
to understand the clients business and to identify unusual transactions and events, amounts, ratios, or trends that might represent specific risks relevant to the audit
IT environment
multiple layers of supporting IT infrastructure. ( hardware, software, network, operating systems, and data storage)
how are flowcharts used to understand business processes
visual represntation of how information flows through a process
what should be inculded in each step of an audit
Nature, extent, timing
what phrases must be included in a separate going concern section (nonissue) or explanatory paragraph (issuer)?
“sustainable doubt”
“going concern”’
don’t include comparative f/s if there was a going concern in previous yrs but is gone now
types of audit procedures and why they are used
risk assessment procedure -to obtain an understanding of the entity and its environment (internal controls)
test of controls - to evaluate the operating effectiveness of internal control in preventing or detecting material misstatements
substantive procedures - to detect material misstatements in the financial statements
when is audit evidence gathered during an audit
risk assessment procedures
test of controls
substantive procedures
other audit procedures
what should the direction of testing be if the auditor is concerned about the existence or occurence assertion?
vouching backward from the accounting record (f/s,je) to source documents
make sure everything that is recorded actually happened
what should the direction of testing be if the audiotr is concerned about the completeness assertion?
tracing forward from source documents to the accounting records
make sure everything that happened is recorded
when is professional judgement necessary in the use of statistical or non statistical sampling by an auditor
define population and sampling unit
select the appropriate sampling method
evaluate whether the audit evidence is appropriate
evaluate the nature of deviation or errors
consider sampling risk
evaluate sample results and project to the population
sampling risk
the risk that the auditors conclusion based on a sample is different from the conclusion that would have been reached if the tests had been applied to all items in the population
2 aspects of sampling risk that the audior would be concerned with when performing substantive testing
risk of incorrect acceptance - deciding from the sample that the balance is correct when it is really materially misstated
affects audit effectiveness
risk of incorrect rejection - deciding from the sample that the balance is materially misstated when it is really correct
affects the audit efficiency
2 aspects of sampling risk for test of controls
risk of assessing control risk too low - assessed level of CR is less than the true risk, thinking a control is more effective and reliable than it actually is
affects audit effectiveness
risk of assessing control risk too high - assessed risk is greater than the true risk, thinking a control is more reliable and effective than you think
affects audit efficiency , do more testing than you need to
tolerable deviation rate (attribute sampling)
the maximum rate (%) of deviation from a control procedure that the auditor is willing to accept while still relying on the control
tolerable misstatement (variables sampling)
the largest amount of misstatement the auditor believes can exist in a balance or class of transactions without causing the F/S to be materially misstated
list some benefits of audit data analytics
better understanding of clients + their operations
advanced assessment of risk
expanded audit coverage through testing of entire populations
increased efficiency of applied procedures
enhance fraud detection
insights gained from evaluating metadata and relationships among data
improved communication through data visualizations and other reports
risk assessment
auditor needs to gather evidence that is NOT bias towards corroborative evidence rather than contradictory
fraud v risk assessment
fraud = material misstatement from fraud
risk = risk of material misstatement overall
inherent risk
susceptibility of MM without before considering internal controls
understand the buisness industry, regulatory, nature, objectives, and financial performance
factors are usually closely related
applicable internal control framework
picked by management (coso or another)
auditor - tests design and implementation of controls
preventative v detective controls
preventative = reasonable assurance only valid transactions are recognized, approved, and submitted. Before the processing activity occurs
prevent errors
detective = reasonable assurance that errors or irregularities are discovered and corrected on a timely basis. after processing has been completed
find errors
auditor uses judgement to determine what controls should be assessed during the audit
manual v automated controls
manual = performed by people, better when judgement and discretion is required
large unusual transactions, changes in circumstances, potential misstatment is difficult to define or predict
also used to monitor automated controls
automated = using IT
high volume, reoccurring transactions, adequately designed and automated
controls for changes in the IT environment
change - management process
segregation of duties
system development, acquisition, implementation
controls related to managing IT operations
job scheduling and monitoring
backup and recovery
intrustion detection
dual purpose test
test of controls + test of details on the same transaction
test operating effectiveness of control
support relevant assertions or detect MM
only used when there is a low level of risk
substantative procedures v test of controls
weak or no contols - no control test, maximum sub testing
some controls - some control tests, some sub tests
strong internal controls - control test, minimum sub tests
never fully eliminate substantive procedures
test controls when risk assessment is based on controls operating effectively or when substantive procedures are insufficient
operating effectiveness
auditor is not required to evaluated operating effectiveness as a part of understanding the design /implementation of controls
timing of substanative procedures
interem , period end, after period end
noncompliance
act of omission, unintentional or intentional
mangement is responsible to comply, auditors are to obtain reasonable assurance f/s are free from MM due to noncompliance w laws and regulations
direct effect on f/s
indirect effect on f/s - inquiry of mgmt and inspect correspondence with licensing + regulatory authorities
material effect on f/s - qualified/adverse
insufficient evidence - qualified/disclaimer
client response - withdrawl
auditors bias
availability bias - more weight on more recent, available evidence
confirmation bias - information that corroborates rather than contradicts
overconfidence bias - overestimate ones ability to make accurate judgements
anchoring bias - use initial info/understanding as anchor against subsequent events
automation bias - favor info generated from automated systems
groupthink - make decision as a group not as an individual
types of audit evidence
accounting records - need additional support not enough for evidence alone
initial entries and any supporting records (checks, electronic funds, invoices, contracts, ledgers, JE)
corroborating evidence - provides additional support
minutes of meetings, confirmations, industry reports, evidence from outside sources
substantive procedures
direct mm at the assertion level
testing dollar value amounts
test of details —> transactions, balances disclosures
substantive analytical procedures —> analysis relationship of data
methods to develop auditors expectations for analytical procdures
trend analysis - low level of assertion ; compare prior and current periods
ratio analysis - low level of assertion ; compare prior ratios and current
non statistical analysis - very high level of assertion ; uses predictive model
regression analysis - very high level of assertion ; statistical techniques that uses prior period data
provides explicit mathematically objective and precise methods
allows inclusion of large number independent variables
provides direct and quantitative measures of the precision of expectation
differences do not necessarily indicate errors or fraud, just need for further investigation
confirmation
external - must be written ; auditor designs, sends them, and receives them. client does not do anything with confirmations
auditor can engage a 3ed party to help with the process but they must be evaluated
must maintain professional skepticism
send follow ups if no response or oral response
positive - response for agreement or disagreement
sent with all applicable info just respond yes or no - higher response rate because its easy
sent blank, they fill out info - more reliable audit evidence but lower repsonse rate
negative - only respond if you disagree
provides significantly less audit evidence
account balances (b/s) assertions
existence
completness
valuation, allocation, accuracy
classification
rights and obligations
transactions, events, related disclosures (I/S)
ocurence
completness
accuracy
cutoff
classifciation