1/111
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What are the auditor requirements for performing an integrated audit?
Plan and perform the audit to achieve objectives of both engagements
Use the same control criteria as management
Designed to provide sufficient appropriate audit evidence
What are auditors of issuers required to perform under PCAOB standards?
An integrated audit, auditing both the financial statements and management’s assessment of the effectiveness of ICFR
Are integrated audits required for nonissuers?
They’re optional if the client wants to engage the auditor to do so
What is the objective in an ICFR audit?
To express an opinion on the effectiveness of the entity’s ICFR
What should the date in management’s assessment of the effectiveness of ICFR be the same as?
The balance sheet date
Can an entity’s internal control be effective if even ≥1 material weakness exists?
No
How are the audits of financial statements and the audits of ICFR planned and performed?
Together
What must management do in an integrated audit?
Accept responsibility for the effectiveness of ICFR
Evaluate the effectiveness of the ICFR
Provide a written assessment about the effectiveness of the entity’s ICFR in a report that accompanies the auditor’s report
What should the written representation letter from management contain?
Acknowledge responsibility for internal control
States management’s assessment as of a specific date and criteria used
Affirms that management didn’t rely on audit’s procedures as their basis
States all deficiencies disclosed
Describe fraud resulting in material weaknesses or involving management/important people
Significant changes after report date
How should the auditor’s fraud risk assessment be performed in an integrated audit?
It should be integrated into the audit of ICFR
What are the high areas of risk in an audit of ICFR?
Management fraud and management override of controls
What should the auditor consider when developing an overall strategy for an integrated audit? (mnemonic)
F - Financial reporting practices of the industry
E - Economic conditions
L - Laws and regulations
T - Technological changes
What is the top-down approach?
It’s used in selecting controls to test
How does the top-down approach evaluate risks?
Financial statement level
Entity Level
Inherent risk factors to identify significant classes of transaction, account balances, and disclosures
What do controls at the entity level include?
Control environment
Management override
Risk assessment procedures
Monitoring results
Period-end financial reporting
What should the auditor evaluate when testing controls?
The design effectiveness of the controls and test and evaluate the operating effectiveness of the controls (and if it’s implemented)
What procedures are performed to test the design of controls?
Inquirt, observation, inspection
How should tests of controls be designed?
To provide sufficient appropriate evidence to support both the opinion on ICFR and the control risk assessment needed for the financial statement audit
Does an individual control have to operate without any deviations to be considered effective?
No
What should the auditor determine when evaluating control deficiencies?
Whether they represent significant deficiencies or material weaknesses (either alone or in combination)
What should the auditor’s opinion on the effectiveness of ICFR be based on?
All available evidence, including evidence obtained from the financial statement audit
What do we need to disclose in ICFR?
If there any any discrepancies between management’s report and ours
What do we do if management’s report is incomplete/improper?
We’ll modify ours
What do we do if management doesn’t supply a report?
Withdraw
What is the purpose of an audit on the effectiveness of an entity’s ICFR (nonissuers)?
To express an opinion about whether the entity maintained, in all material respects, effective control as of a point in time based on the control criteria
What is the purpose of an auditor’s consideration of ICFR in an audit of financial statements? (nonissuers)
To enable the auditor to plan the audit and determine the nature, extent, and timing of tests to be performed
For nonissuers, how should deficiencies in internal control be communicated in an integrated audit?
Significant deficiencies and material weaknesses should be communicated, in writing, to management and those charged with governance by the report release date
Control deficiencies should be communicated to management, in writing, no later than 60 days following the report release date
Should the auditor issue a report stating that no material weakness, or no deficiencies less severe than a material weakness, were identified in an integrated audit of a nonissuer?
No
If a control deficiency is previously communicated but still not fixed, what should we do?
Point it out again
Are you required to search for control deficiencies?
No, but those identified must be communicated
For issuers, how should deficiencies in internal control be communicated in an integrated audit?
All control deficiencies should be communicated to management, in writing
Significant deficiencies and material weaknesses should be communicated, in writing, to management and the audit committee
All deficiencies should be communicated prior to the issuance of the auditor’s report
When reporting on internal control for nonissuers and issuers, what can the auditor do in terms of reporting?
They can combine the opinion on ICFR with the opinion on the financial statements, or they may issue two separate reports
What is included in the report on internal control?
Description of the inherent limitations of ICFR
Warning the reader not to project the evaluation into the future
If issuing a separate report on internal control, what do you need to do?
Reference the other report in it
What does the presence of a material weakness in identified controls result in?
An adverse opinion on ICFR
What must be included in the auditor’s report if theres’ the presence of a material weakness in identified controls?
Definition of a material weakness
Statement that a material weakness has been identified
Identification of the material weakness described in management’s assessment
What does the auditor do if management fails to report a material weakness in identified controls?
State the issues
Describe the omitted weakness
Tell those charged with governance
What should the auditor do if engaged to report on whether a previously reported material weakness continues to exist?
This is voluntary. We can accept if we have the knowledge and management accepts responsibility in a written report.
What is an attestation engagement?
When a CPA is engaged to issue:
An independent examination
A review
An agreed-upon procedures report on a subject matter or on an assertion about the subject matter that is the responsibility of a party other than the practitioner (typically management)
What are the various types of attestation services?
Agreed-upon procedures
Financial forecasts and projections
Pro forma financial statements
Compliance attestations
Management’s discussion and analysis
Reporting on controls at a service organization
What is the report type for agreed-upon procedures?
Agreed-upon procedures
What is the report type for financial forecasts and projections?
Assertion-based examination
Agreed-upon procedures
What is the report type for pro forma financial statements?
Assertion-based examination
Review
What is the report type for compliance attestations?
Assertion-based examination
Agreed-upon procedures
What is the report type for management’s discussion and analysis?
Assertion-based examination
Review
What is the report type for reporting on controls at a service organization?
Assertion-based examination
How are attestation standards different than GAAS?
They’re a natural extension of GAAS, but differ because there’s no reference made to historical financial statements
What level of assurance do examinations provide?
Positive/Reasonable assurance
Results in an opinion
What level of assurance do reviews provide?
Negative/Limited assurance
Results in a conclusion
What level of assurance do agreed-upon procedures provide?
No assurance
BUT procedure findings are listing
When is a written assertion generally obtained?
In an assertion-based examination, review, or agreed-upon procedures engagement
What is included in a report for examination and review engagements?
Title: Independent Accountant’s Report
Intro
Scope (AICPA)
Independence Requirements
Inherent Limitations (opt)
Emphasis of matter (opt)
Conclusion/opinion
What conditions must exist for an auditor to accept an agreed-upon procedures engagement? (menmonic)
I - Independence of the practitioner.
A - Agreement of the parties on what procedures are to be applied, the criteria to be used, etc.
M - The subject matter must be capable of consistent Measurement.
S - The engaging party (client) takes responsibility for the Sufficiency of the designated procedures.
U - Use of the report can be general or restricted to specified parties.
R - The client (or in some cases a third party) is Responsible for the subject matter.
E - Engagements to perform agreed-upon procedures on prospective financial statements must include a summary of significant assumptions used for the prospective financial statements.
What reporting elements are required in the accountant’s report for agreed-upon procedures?
Description of procedures performed and the related findings
A statement that the engaging party has agreed that the procedures performed are appropriate for the intended purpose of the engagement
A disclaimer of opinion
A statement that the report may not be suitable for any other purpose and that the user is responsible for determining the suitability for his or her needs
Identification of engaging party
Subject matter
Nature and purpose
Subject matter is the responsibility of the responsible party
Is independence required for agreed-upon procedures?
Yes
What is included in prospective financial statements?
Financial forecast
Financial projection
What is a Financial Forecast?
Reflects, to the best of the responsible party’s knowledge, the expected financial results of a future period based on expected conditions and expected courses of action by the entity
General use OR Limited use
What is a Financial Projection?
Entity’s financial position and results of operation are based on hypothetical assumptions using a “what-if” type of scenario
Limited use
What types of engagements can the auditor perform with regard to prospective financial statements?
Preparation Engagement
Compilation Engagement
Examination Engagement
Agreed-Upon Procedures
What are the details of a preparation engagement for prospective financial statements?
Statement on each page that says, “no assurance is provided”
Falls under SSARS
What are the details of a compilation engagement for prospective financial statements?
Does not express an opinion or assurance
Includes a caution about achievability
States that the accountant has no responsibility to update
Falls under SSARS
What are the details of an examination engagement for prospective financial statements?
There are two parts to the opinion: financial statements presented in conformity with guidelines and assumptions providing a reasonable basis for financial statements
Caution about achievability
Accountant has no responsibility to update
What are the details of an agreed-upon procedures for prospective financial statements?
Caution about achievability
Accountant has no responsibility to update
Is a review of prospective F/S allowed?
No
What are Partial presenations of prospective information?
Exclude certain essential elements, such as sales, GP, COGS, and are not appropriate for general use
What are Pro Forma Financial Statements?
Show the effect that a hypothetical transaction would have had on past financial statements (these are NOT prospective)
What should be referenced in a pro forma financial statement?
The financial statements from which the historical financial information was derived
When are a service organization’s services considered part of the user entity’s information system?
When those services affect the initiation, execution, processing, or reporting of the user company’s transactions
What are the objectives of the service auditor?
To obtain reasonable assurance about whether:
Management’s description of the service organization system’s design and implementation is fairly presented
The controls related to the control objectives were suitably designed
The controls operated effectively when included in the scope of the engagement
What is a SOC 1 engagement?
Used by a user entity/auditor to evaluate the impact of service org controls on the financial statement of the user entity (restricted use)
What is a SOC 2 engagement?
Includes trust services (security, confidentiality, etc). Also, restricted use.
What is a Type 1 report prepared by the service auditor?
Report on management description, design/implementation of controls, but NOT on operating effectiveness of controls
What is a Type 2 report prepared by the service auditor?
Report on management description, design/implementation of controls, AND on operating effectiveness of controls
What should the user auditor obtain an understanding of?
The nature and significance of the services provided by the service organization and the effect on the user entity’s system of internal control
Can the user auditor use the service auditor’s report in the assessment of the user entity’s system of internal control?
Yes, but Type 1 only allows user auditor to obtain an understanding of controls, it doesn’t provide a basis for reducing assessment of control risk
What should the user auditor be satisfied with in terms of the service auditor?
Service auditor competence and independence
Adequacy of standards
Appropriateness of period covered
Adequacy of period covered by tests of controls
Relevance of tests for us
What are the difference types of reporting on compliance?
Compliance with contractual agreements or regulatory requirements in connection with a FS audit
Compliance with requirements of specific laws and regulations or on internal control over compliance
Compliance and controls over compliance as part of a single audit engagement
What assurance is provided in a situation where an auditor is asked to issue a report on a client’s compliance with contractual agreements or regulatory requirements in connection with a FS audit?
Negative assurance
What is required when an auditor is asked to issue a report on a client’s compliance with contractual agreements or regulatory requirements in connection with a FS audit?
Must have audited client’s FS
Restriction on use applies to entire report (If separate report, restriction only applies to report on compliance)
What is the risk assessment model of audit risk of noncompliance?
Audit Risk of Noncompliance (should be low) = Risk of Material Noncompliance (assessed by the auditor) x Detection Risk (controlled by the auditor)
What is the Risk of Material Noncompliance comprised of?
Inherent Risk of Noncompliance
Control Risk of Noncompliance
How does GAGAS define “unconditional requirements”?
With which the auditor MUST comply
How does GAGAS define “presumptively mandatory requirements”?
With which the auditor SHOULD comply, but reason for departure must be documented
What are the three types of government engagements?
Financial audits
Attestation engagements
Performance audits (compliance, controls, prospective analysis, and effectiveness, economy, efficiency)
In a financial statement audit, what does GAGAs require?
A reprot on ICFR
What do audits in accordance with GAGAS require additional attention to?
Fraud, noncompliance, abuse
What should an auditor do when reporting confidential information under GAGS?
Disclose the exclusion by reporting that information has been omitted and why
What do you need to make sure of in terms of documentation?
That is supports findings, conclusions, recommendations, and that departures/findings are included
What are the 4 considerations for developing a finding?
Criteria
Condition
Cause
Effect
What is GAGAS also called?
The Yellow Book
What does GAGAS include?
All GAAS standards by reference and expand requirements with additional standards that focus on audits of governments and governmental financial assistance
What do single audits represent?
Supplementary audit requirements that relate to federal financial assistance
How does GAGAS describe the nature of audits of government entities?
Those that often focus on compliance with laws and regulations that may have a direct and material effect on the determination of financial assistance revenue amounts displayed in the financial statements
Why is compliance important under GAGAS?
Helps determine whether government assistance was properly earned or whether it is owed back to the grantor
What is management responsible for in government audits under GAGAS?
Identifying the appropriate laws and regulations
Establishing internal controls that provide reasonable assurance that the entity complies with applicable laws and regulations
Preparing supplemental financial reports
Obtaining an audit that satisfies the appropriate legal, regulatory, or contractual requirements
What are auditors responsible for in government audits under GAGAS?
Obtaining reasonable assurance that the financial statements are free of material misstatements resulting from violations of laws and regulations that have a direct and material effect on the determination of financial statement amounts
Determining whether management has properly identified laws and regulations, for understanding the implications of noncompliance on the financial statements
Ensuring that the scope of the audit addresses the appropriate requirements.
What should the auditor report for government audits under GAGAS?
All instances that involve fraud or illegal acts unless they are inconsequential
What is the purpose of a GAGAS Report on IC over Compliance (Yellow Book)?
Not to express and opinion, but to report on what we did in terms of tests and results
What type of assurance is needed for GAGAS Report on IC over Compliance (Yellow Book)?
Broader assurance
What type of letter is needed for GAGAS Report on IC over Compliance (Yellow Book)?
Management representation letter