1/63
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Information Risk
risk that the information disseminated by a company will be materially false or misleading
Business Risk
risk that an entity will fail to meet its stated business objectives
Attestation Engagement
a CPA evaluates information that someone else is responsible for and then reports whether that information is reliable
Assurance Services
independent professional services that improve the quality of information, or its context, for decision makers
Examples of Financial Attestation Engagements
-Financial forecasts and projections
-examination of Management's Discussion and Analysis
-Pro Forma Financial Information
Examples of Non-Financial Attestation Engagements
-Effectiveness of internal control systems
-compliance with environmental regulations
-sustainability reporting engagements.
What are management's financial statement assertions?
(PCAOB)
-Existence/Occurrence: It happened and exists.
-Rights & Obligations: The company owns it or owes it.
-Completeness: Nothing is missing.
-Valuation/Allocation: Recorded at the correct amount.
-Presentation & Disclosure: Properly classified and disclosed
Professional Judgement
the application of relevant training, knowledge, and experience in making informed decisions during audit
Why is auditor independence important?
-makes audit credible and unbiased
-helps users trust F/S and reduce information risk
Examples of independence Issues faced by audit team members
-ownership of stock by auditor/their close family
-having close family working for client's finance/acct dept
-performing bookkeeping services for audit client while auditing the related F/S
-negotiating job opportunity with client (must wait yr)
Staff responsibilities
low risk accounts (AR, cash, PPE, Inv., internal control testing)
Senior responsibilities
Reviewing staff work papers, audit complicated accounts (rev, equity, etc.), manage budgets, deal with clients
Manager responsibilites
Reviewing work of seniors/staff, selling services to clients
Partner responsibilities
review big picture issues, sign off on audit opinion, sell services to clients
Types of Audits and Auditors: Financial (External Auditors/CPAs)
ensure that F/S are reliable
Types of Audits and Auditors: Operational (Internal and Governmental Auditors/CIAs)
improve operational effectiveness and efficiency
Types of Audits and Auditors: Compliance (Internal and Governmental Auditors)
Ensure compliance with company and/or governmental rules and regulations
Types of Audits and Auditors: Forensic (Fraud auditors/CFEs)
Designed to investigate a crime and will often involve gathering evidence designed to convict a fraudster
AICPA (American Institute of Certified Public Accountants)
oversees standard setting for private company audits
PCAOB (Public Company Accounting Oversight Board)
-Created by SOX (2002)
-Sets auditing standards for public company audits
-Inspects CPA firms for compliance
-Can ban firms from auditing public companies
10 Generally Accepted Auditing Standards
-Adequate Training & Proficiency: must be properly trained.
-Independence: remain unbiased.
-Due Professional Care: use reasonable care and professional judgment
-Planning & Supervision: plan the audit and supervise assistants.
-Understand Internal Control: understanding of internal controls to plan the audit.
-Sufficient Appropriate Evidence: Gather enough reliable evidence to support the opinion
-GAAP: State whether the financial statements follow GAAP.
-Consistency: Report any lack of consistency with prior years.
-Adequate Disclosures: State if disclosures are inadequate.
-Opinion: Express an opinion or explain why one cannot be given.
Professional Skepticism
-Refers to an auditor's questioning mindset towards representations made by management and evidential matter gathered
-Must be skeptical because a potential conflict of interest always exists between the auditor and the client
CPA firms' quality control practices
-layered review of audit work papers within audit team
-concurring audit review
-peer CPA firm review
-PCAOB inspections
Unmodified/Unqualified Audit Opinion
- F/S are in conformity with GAAP
- May include explanatory language that addresses going concern issue or notable event that warrants f/s user's attention
Qualified Audit Opinion
Except for a specific materially misstated account, F/S are in conformity with GAAP
Adverse Audit Opinion
- F/S are not in conformity with GAAP
- Financial statement user should not rely upon the financial statements
Disclaimer Audit Opinion
auditors do not express an opinion
Major Items in Auditor's Report
-Auditor's and management responsibility in financial reporting process
-Audit conducted in accordance with PCAOB standards
-Opinion on financial statements
-Opinion on internal control over financial reporting
Critical Audit Matters
Issues that were especially difficult, subjective, or complex during the audit.
Purpose of the auditor's report over the internal controls over financial reporting
to express an opinion on whether a company's internal controls are effective in preventing or detecting material misstatements in the financial statements
Issues an auditor would have to discuss with client's former auditor before beginning an engagement with new client
-any concerns about management's honesty
-any disputes over accounting/audit procedures
-fraud/illegal acts/internal controls (issues previously communicated to client)
-reason for auditor change
Engagement Letters
-When a new client is accepted or when an audit engagement continues from year to year, an engagement letter should be prepared
-contract between auditor and client
-Should include: Objectives of the engagement, Management's responsibilities, Auditors' responsibilities, Any limitations of the engagement
Internal v External Auditors
Internal: help with audit
External: make final decisions, responsible for audit
Audit Specialist
persons skilled in fields other than accounting and auditing—actuaries, appraisers, attorneys, environmental engineers, and geologists— who are not members of the audit team.
IT Auditors
-Specialized skills are often needed to evaluate the effect of computerized processing on the audit, to understand the flow of transactions, or to design and perform audit procedures
-IT auditors are members of the audit team and arecalled in when the need for their skills arises
Vouching (downstream)
-starts with something recorded in the company's accounting records and works backward to the original supporting documents to make sure the transaction actually happened
-books --> source documents
-Did this actually happen?
-To detect overstatements
Tracing (upstream)
-starts with original source documents and follows them forward into the accounting records to make sure the transaction was recorded
-source documents --> books
-Was this recorded?
-To detect understatements
Analytical Procedures
-when an auditor compares the expectation to a recorded balance
-Two categories: Auditor's expected values of account balances & Variation analyses
Purposes of Audit Documentation
-good audits have good workpapers (without good workpapers --> audit failure, even if your conclusion is correct)
-Nature, timing and extent of work performed
-Evidence of due care
-Professional judgments (question to ask: "is it fairly stated?")
-facilitates planning, performance, and supervision
-Basis for conclusions (evidence)
-Provides basis for review
Permanent Files
-info of continuing audit significance
-Ex: key contracts, bylaws, organization chart, royalty & bond agreements
Current Files
-entire engagement administration file for the year under audit
-all documentation that is sufficient to support all conclusions on the audit
Control Risk
the likelihood that the client's internal control policies and procedures fail to prevent or detect a material misstatement
Detection Risk
the likelihood that the auditors' substantive procedures will fail to detect a material misstatement that exists within an account balance or class of transactions
Inherent Risk
The likelihood that an error or fraud will enter the accounting information system
Audit Risk Model Equation
AR = IR x CR x DR
Audit Risk
the risk that an auditor expresses an inappropriate audit opinion when the financial statements are materially misstated
If inherent risk and control risk are low, what happens?
increased detection risk = less substantive testing = smaller sample size = higher scope
How do actual and tolerable deviation rates affect control risk?
actual dev < tolerable dev = controls are effective/low control risk
actual dev > tolerable dev = controls are not effective/high control risk
Relationship between scope and sample size?
-higher scope cutoff = smaller sample
-lower scope cutoff = larger sample
Audit Plan
A comprehensive list of the specific audit procedures that the audit team needs to perform to gather sufficient appropriate evidence on which to base their opinion on the financial statements
Staffing the audit engagement
Teams usually consist of: Audit engagement partner, Audit manager, IT audit specialist, Tax specialist, Quality assurance partner, Audit staff
Interim Audit Work
procedures performed several weeks or months before the balance sheet date
Year-End Audit Work
procedures performed shortly before and after the balance sheet date
Time Reports
-Everyone who works on the audit engagement is required to report the time taken to perform procedures for each phase of the audit
-These time reports are recorded by budget categories for the purposes of: Evaluating the efficiency of the audit team members, Compiling a record for billing the client, Compiling a record for planning the next audit
3 purposes of audit procedures
-Risk assessment: Understand the client and identify risks.
-Tests of controls: Test if internal controls are working.
-Substantive procedures: Test if the financial statements are correct.
Substantive audit plan
A list of audit procedures used to gather evidence that management's assertions about significant financial statement accounts and disclosures are correct
2 ways to conduct substantive tests
1. Substantive analytical procedures
2. Tests of details
4 major stages of audit
1. Planning
2. Preliminary Fieldwork
3. Year-End Substantive Testing (Fieldwork)
4. Reporting
What occurs during planning stage
-Decide whether to accept the client
- Sign engagement letter
- Contact predecessor auditor (new clients)
- Determine staffing & request client documents
- Understand client's business and industry
- Brainstorm fraud risks
- Perform analytical procedures
- Assess inherent risk and preliminary control risk
- Determine materiality
- Design the audit program
What occurs during preliminary fieldwork?
- Update analytical procedures
- Test the operating effectiveness of internal controls
- Sample transactions
- Compare actual deviation rate to acceptable deviation rate
- If controls are weak, increase control risk and perform more substantive testing
What occurs during year-end substantive testing?
-Update analytical procedures
-Perform substantive testing of account balances and transactions
-Obtain and examine supporting documentation
- Determine sample sizes and test samples
-Evaluate evidence for material misstatements
-Propose adjusting journal entries
-Communicate with legal counsel if needed
-Present audited financial statements to the audit committee
What occurs during the reporting stage?
-Consider subsequent events
- Document management representations
- Issue the audit report
- Ensure GAAS reporting standards are met
-Communicate recommendations to management
Information Sources
-General business sources (magazines, journals)
-Company sources (bylaws, contracts, minutes of meetings)
-Information from client acceptance or continuance evaluation, audit planning, past audits, and other engagements
Risk of Material Misstatement
-likelihood that material misstatements may have entered the accounting system and not been detected and corrected by the client's internal control
-inherent risk and control risk