1/43
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Audit risk model
Audit Risk = Inherent Risk x Control Risk x Detection Risk (ISA 200.13(n))
Audit risk (definition)
The risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated
Risk of material misstatement
Inherent Risk x Control Risk combined - the risk that the financial statements are materially misstated, before any audit work
Inherent risk (definition)
The susceptibility of an assertion to misstatement, possibly material, before consideration of any related internal controls
Inherent risk - who controls it
The business/entity - the auditor has no control over inherent risk
Inherent risk - 3 broad categories
Fraud, Error, Going concern
Inherent risk - fraud drivers
Pressure, Opportunity, Incentive
Inherent risk - error examples
Complex calculations, incorrect estimates, processing mistakes
Inherent risk - going concern key question
Could financial distress affect the recognition, measurement, presentation or disclosure in the financial statements?
Control risk (definition)
The risk that a misstatement, which could be material, will not be prevented or detected and corrected on a timely basis by the entity's internal control
Control risk - who controls it
The business/entity - the auditor has no control over control risk, only evaluates it
Control risk - default assumption
Control risk is assessed as high, unless controls exist and have been tested (e.g. via walkthrough) and shown to be working
Control risk - can it ever be nil
No - control risk can never be nil, since controls can never be completely fool-proof
Detection risk (definition)
The risk that the auditor does not detect a material misstatement that exists
Detection risk - who controls it
The auditor - this is the only element of audit risk the auditor can control
Detection risk - can it ever be zero
No - due to inherent limitations of an audit (not testing 100% of transactions, subjective judgement in analysing results)
Detection risk - what drives it
Adequate planning, proper assignment of personnel, application of professional scepticism, supervision and review
Detection risk formula
DR = Audit risk / (IR x CR) - the balancing factor
Audit risk model - target
Audit risk must always be kept LOW - since IR and CR aren't controllable, DR is adjusted (the balancing figure) to keep AR low
IR and CR both high - effect on DR and procedures
Detection risk must be set low, achieved via a substantive approach with extensive substantive procedures performed at or after year-end
IR or CR evaluated as low - effect on DR
A higher detection risk can be accepted, meaning less extensive substantive procedures are needed
Systems-based audit approach
Relies on testing and placing reliance on the client's internal controls (tests of controls) - used when control risk is assessed as low/effective
Substantive approach
No reliance placed on internal controls - extensive substantive procedures (tests of detail and analytical procedures) are performed instead
When is a substantive approach followed
When control risk is provisionally evaluated as high, meaning no reliance can be placed on the system of internal control
Two levels at which risk is evaluated
At financial statement level (affects the statements as a whole) and at account balance/class of transaction level (for each assertion or account balance)
Materiality - Step 1
Determine which financial information to use (current year actual vs budget vs prior year - choose the most accurate reflection of current operations)
Materiality - Step 2
Identify the possible bases and percentage ranges given by the firm (e.g. % of revenue, gross profit, profit before tax, total assets, equity)
Materiality - Step 3
Decide which base to use, considering: users of the financial statements, nature of the business, and stability of the base
Materiality - Step 3 users to consider
Shareholders (interested in profit/dividends), credit providers (interested in liquidity/ability to service debt), and what each is most focused on in the financial statements
Materiality - Step 4
Calculate the materiality range using the chosen base and percentage range
Materiality - Step 5
Decide on the final planning materiality figure within the range, based on the assessed level of detection risk (e.g. a figure closer to the lower end if detection risk is low, midway if medium)
Management assertions - the main categories
Existence, Occurrence, Completeness, Accuracy, Cut-off, Classification, Valuation, Rights and obligations, Presentation
Assertion - Occurrence
Transactions and events that have been recorded actually took place and relate to the entity
Assertion - Completeness
All transactions, events, assets, liabilities and equity interests that should have been recorded have been recorded
Assertion - Accuracy
Amounts and other data relating to recorded transactions/events have been recorded appropriately
Assertion - Cut-off
Transactions and events have been recorded in the correct accounting period
Assertion - Classification
Transactions and events have been recorded in the proper accounts
Assertion - Existence
Assets, liabilities, and equity interests exist
Assertion - Valuation
Assets, liabilities, and equity interests are included in the financial statements at appropriate amounts
Assertion - Rights and obligations
The entity holds/controls the rights to assets, and liabilities are the obligations of the entity
Exam technique - "discuss/evaluate" risk question
Identify factors and their impact(s), including BOTH factors that increase AND decrease risk, then draw a conclusion per component of audit risk
Exam technique - "identify/describe" risk question
Only identify and describe factors that increase risk (not decrease)
Exam technique - risk factor answer structure
Must state the risk factor AND the motivation/reason (impact) - both parts are needed to get the mark, one sentence is not enough alone