A5 - Integrated Audits, Attestation Engagements, Compliance, and Government Audits

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/111

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:01 PM on 6/26/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

112 Terms

1
New cards

What are the auditor requirements for performing an integrated audit?

  1. Plan and perform the audit to achieve objectives of both engagements

  2. Use the same control criteria as management

  3. Designed to provide sufficient appropriate audit evidence


2
New cards

What are auditors of issuers required to perform under PCAOB standards?

An integrated audit, auditing both the financial statements and management’s assessment of the effectiveness of ICFR

3
New cards

Are integrated audits required for nonissuers?

They’re optional if the client wants to engage the auditor to do so

4
New cards

What is the objective in an ICFR audit?

To express an opinion on the effectiveness of the entity’s ICFR

5
New cards

What should the date in management’s assessment of the effectiveness of ICFR be the same as?

The balance sheet date

6
New cards

Can an entity’s internal control be effective if even ≥1 material weakness exists?

No

7
New cards

How are the audits of financial statements and the audits of ICFR planned and performed?

Together

8
New cards

What must management do in an integrated audit?

  • Accept responsibility for the effectiveness of ICFR

  • Evaluate the effectiveness of the ICFR

  • Provide a written assessment about the effectiveness of the entity’s ICFR in a report that accompanies the auditor’s report


9
New cards

What should the written representation letter from management contain?

  1. Acknowledge responsibility for internal control

  2. States management’s assessment as of a specific date and criteria used

  3. Affirms that management didn’t rely on audit’s procedures as their basis

  4. States all deficiencies disclosed

  5. Describe fraud resulting in material weaknesses or involving management/important people

  6. Significant changes after report date


10
New cards

How should the auditor’s fraud risk assessment be performed in an integrated audit?

It should be integrated into the audit of ICFR

11
New cards

What are the high areas of risk in an audit of ICFR?

Management fraud and management override of controls

12
New cards

What should the auditor consider when developing an overall strategy for an integrated audit? (mnemonic)

F - Financial reporting practices of the industry

E - Economic conditions

L - Laws and regulations

T - Technological changes

13
New cards

What is the top-down approach?

It’s used in selecting controls to test

14
New cards

How does the top-down approach evaluate risks?

  1. Financial statement level

  2. Entity Level

  3. Inherent risk factors to identify significant classes of transaction, account balances, and disclosures


15
New cards

What do controls at the entity level include?

  • Control environment

  • Management override

  • Risk assessment procedures

  • Monitoring results

  • Period-end financial reporting


16
New cards

What should the auditor evaluate when testing controls?

The design effectiveness of the controls and test and evaluate the operating effectiveness of the controls (and if it’s implemented)

17
New cards

What procedures are performed to test the design of controls?

Inquirt, observation, inspection

18
New cards

How should tests of controls be designed?

To provide sufficient appropriate evidence to support both the opinion on ICFR and the control risk assessment needed for the financial statement audit

19
New cards

Does an individual control have to operate without any deviations to be considered effective?

No

20
New cards

What should the auditor determine when evaluating control deficiencies?

Whether they represent significant deficiencies or material weaknesses (either alone or in combination)

21
New cards

What should the auditor’s opinion on the effectiveness of ICFR be based on?

All available evidence, including evidence obtained from the financial statement audit

22
New cards

What do we need to disclose in ICFR?

If there any any discrepancies between management’s report and ours

23
New cards

What do we do if management’s report is incomplete/improper?

We’ll modify ours

24
New cards

What do we do if management doesn’t supply a report?

Withdraw

25
New cards

What is the purpose of an audit on the effectiveness of an entity’s ICFR (nonissuers)?

  • To express an opinion about whether the entity maintained, in all material respects, effective control as of a point in time based on the control criteria


26
New cards

What is the purpose of an auditor’s consideration of ICFR in an audit of financial statements? (nonissuers)

To enable the auditor to plan the audit and determine the nature, extent, and timing of tests to be performed

27
New cards

For nonissuers, how should deficiencies in internal control be communicated in an integrated audit?

  • Significant deficiencies and material weaknesses should be communicated, in writing, to management and those charged with governance by the report release date

  • Control deficiencies should be communicated to management, in writing, no later than 60 days following the report release date


28
New cards

Should the auditor issue a report stating that no material weakness, or no deficiencies less severe than a material weakness, were identified in an integrated audit of a nonissuer?

No

29
New cards

If a control deficiency is previously communicated but still not fixed, what should we do?

Point it out again

30
New cards

Are you required to search for control deficiencies?

No, but those identified must be communicated

31
New cards

For issuers, how should deficiencies in internal control be communicated in an integrated audit?

  • All control deficiencies should be communicated to management, in writing

  • Significant deficiencies and material weaknesses should be communicated, in writing, to management and the audit committee

  • All deficiencies should be communicated prior to the issuance of the auditor’s report


32
New cards

When reporting on internal control for nonissuers and issuers, what can the auditor do in terms of reporting?

They can combine the opinion on ICFR with the opinion on the financial statements, or they may issue two separate reports

33
New cards

What is included in the report on internal control?

  • Description of the inherent limitations of ICFR

  • Warning the reader not to project the evaluation into the future


34
New cards

If issuing a separate report on internal control, what do you need to do?

Reference the other report in it

35
New cards

What does the presence of a material weakness in identified controls result in?

An adverse opinion on ICFR

36
New cards

What must be included in the auditor’s report if theres’ the presence of a material weakness in identified controls?

  • Definition of a material weakness

  • Statement that a material weakness has been identified

  • Identification of the material weakness described in management’s assessment


37
New cards

What does the auditor do if management fails to report a material weakness in identified controls?

  • State the issues

  • Describe the omitted weakness

  • Tell those charged with governance


38
New cards

What should the auditor do if engaged to report on whether a previously reported material weakness continues to exist?

This is voluntary. We can accept if we have the knowledge and management accepts responsibility in a written report.

39
New cards

What is an attestation engagement?

When a CPA is engaged to issue:

  • An independent examination

  • A review

  • An agreed-upon procedures report on a subject matter or on an assertion about the subject matter that is the responsibility of a party other than the practitioner (typically management)


40
New cards

What are the various types of attestation services?

  • Agreed-upon procedures

  • Financial forecasts and projections

  • Pro forma financial statements

  • Compliance attestations

  • Management’s discussion and analysis

  • Reporting on controls at a service organization


41
New cards

What is the report type for agreed-upon procedures?

Agreed-upon procedures

42
New cards

What is the report type for financial forecasts and projections?

  • Assertion-based examination

  • Agreed-upon procedures


43
New cards

What is the report type for pro forma financial statements?

  • Assertion-based examination

  • Review


44
New cards

What is the report type for compliance attestations?

  • Assertion-based examination

  • Agreed-upon procedures


45
New cards

What is the report type for management’s discussion and analysis?

  • Assertion-based examination

  • Review


46
New cards

What is the report type for reporting on controls at a service organization?

Assertion-based examination

47
New cards

How are attestation standards different than GAAS?

They’re a natural extension of GAAS, but differ because there’s no reference made to historical financial statements

48
New cards

What level of assurance do examinations provide?

  • Positive/Reasonable assurance

  • Results in an opinion


49
New cards

What level of assurance do reviews provide?

  • Negative/Limited assurance

  • Results in a conclusion


50
New cards

What level of assurance do agreed-upon procedures provide?

  • No assurance

  • BUT procedure findings are listing


51
New cards

When is a written assertion generally obtained?

In an assertion-based examination, review, or agreed-upon procedures engagement

52
New cards

What is included in a report for examination and review engagements?

  • Title: Independent Accountant’s Report

  • Intro

  • Scope (AICPA)

  • Independence Requirements

  • Inherent Limitations (opt)

  • Emphasis of matter (opt)

  • Conclusion/opinion


53
New cards

What conditions must exist for an auditor to accept an agreed-upon procedures engagement? (menmonic)

I - Independence of the practitioner.

A - Agreement of the parties on what procedures are to be applied, the criteria to be used, etc.

M - The subject matter must be capable of consistent Measurement.

S - The engaging party (client) takes responsibility for the Sufficiency of the designated procedures.

U - Use of the report can be general or restricted to specified parties.

R - The client (or in some cases a third party) is Responsible for the subject matter.

E - Engagements to perform agreed-upon procedures on prospective financial statements must include a summary of significant assumptions used for the prospective financial statements.

54
New cards

What reporting elements are required in the accountant’s report for agreed-upon procedures?

  • Description of procedures performed and the related findings

  • A statement that the engaging party has agreed that the procedures performed are appropriate for the intended purpose of the engagement

  • A disclaimer of opinion

  • A statement that the report may not be suitable for any other purpose and that the user is responsible for determining the suitability for his or her needs

  • Identification of engaging party

  • Subject matter

  • Nature and purpose

  • Subject matter is the responsibility of the responsible party


55
New cards

Is independence required for agreed-upon procedures?

Yes

56
New cards

What is included in prospective financial statements?

  • Financial forecast

  • Financial projection


57
New cards

What is a Financial Forecast?

  • Reflects, to the best of the responsible party’s knowledge, the expected financial results of a future period based on expected conditions and expected courses of action by the entity

  • General use OR Limited use


58
New cards

What is a Financial Projection?

  • Entity’s financial position and results of operation are based on hypothetical assumptions using a “what-if” type of scenario

  • Limited use


59
New cards

What types of engagements can the auditor perform with regard to prospective financial statements?

  • Preparation Engagement

  • Compilation Engagement

  • Examination Engagement

  • Agreed-Upon Procedures


60
New cards

What are the details of a preparation engagement for prospective financial statements?

  • Statement on each page that says, “no assurance is provided”

  • Falls under SSARS


61
New cards

What are the details of a compilation engagement for prospective financial statements?

  • Does not express an opinion or assurance

  • Includes a caution about achievability

  • States that the accountant has no responsibility to update

  • Falls under SSARS


62
New cards

What are the details of an examination engagement for prospective financial statements?

  • There are two parts to the opinion: financial statements presented in conformity with guidelines and assumptions providing a reasonable basis for financial statements

  • Caution about achievability

  • Accountant has no responsibility to update


63
New cards

What are the details of an agreed-upon procedures for prospective financial statements?

  • Caution about achievability

  • Accountant has no responsibility to update


64
New cards

Is a review of prospective F/S allowed?

No

65
New cards

What are Partial presenations of prospective information?

Exclude certain essential elements, such as sales, GP, COGS, and are not appropriate for general use

66
New cards

What are Pro Forma Financial Statements?

Show the effect that a hypothetical transaction would have had on past financial statements (these are NOT prospective)

67
New cards

What should be referenced in a pro forma financial statement?

The financial statements from which the historical financial information was derived

68
New cards

When are a service organization’s services considered part of the user entity’s information system?

When those services affect the initiation, execution, processing, or reporting of the user company’s transactions

69
New cards

What are the objectives of the service auditor?

To obtain reasonable assurance about whether:

  • Management’s description of the service organization system’s design and implementation is fairly presented

  • The controls related to the control objectives were suitably designed

  • The controls operated effectively when included in the scope of the engagement


70
New cards

What is a SOC 1 engagement?

Used by a user entity/auditor to evaluate the impact of service org controls on the financial statement of the user entity (restricted use)

71
New cards

What is a SOC 2 engagement?

Includes trust services (security, confidentiality, etc). Also, restricted use.

72
New cards

What is a Type 1 report prepared by the service auditor?

Report on management description, design/implementation of controls, but NOT on operating effectiveness of controls

73
New cards

What is a Type 2 report prepared by the service auditor?

Report on management description, design/implementation of controls, AND on operating effectiveness of controls

74
New cards

What should the user auditor obtain an understanding of?

The nature and significance of the services provided by the service organization and the effect on the user entity’s system of internal control

75
New cards

Can the user auditor use the service auditor’s report in the assessment of the user entity’s system of internal control?

Yes, but Type 1 only allows user auditor to obtain an understanding of controls, it doesn’t provide a basis for reducing assessment of control risk

76
New cards

What should the user auditor be satisfied with in terms of the service auditor?

  • Service auditor competence and independence

  • Adequacy of standards

  • Appropriateness of period covered

  • Adequacy of period covered by tests of controls

  • Relevance of tests for us


77
New cards

What are the difference types of reporting on compliance?

  • Compliance with contractual agreements or regulatory requirements in connection with a FS audit

  • Compliance with requirements of specific laws and regulations or on internal control over compliance

  • Compliance and controls over compliance as part of a single audit engagement


78
New cards

What assurance is provided in a situation where an auditor is asked to issue a report on a client’s compliance with contractual agreements or regulatory requirements in connection with a FS audit?

Negative assurance

79
New cards

What is required when an auditor is asked to issue a report on a client’s compliance with contractual agreements or regulatory requirements in connection with a FS audit?

  • Must have audited client’s FS

  • Restriction on use applies to entire report (If separate report, restriction only applies to report on compliance)


80
New cards

What is the risk assessment model of audit risk of noncompliance?

Audit Risk of Noncompliance (should be low) = Risk of Material Noncompliance (assessed by the auditor) x Detection Risk (controlled by the auditor)

81
New cards

What is the Risk of Material Noncompliance comprised of?

  • Inherent Risk of Noncompliance

  • Control Risk of Noncompliance


82
New cards

How does GAGAS define “unconditional requirements”?

With which the auditor MUST comply

83
New cards

How does GAGAS define “presumptively mandatory requirements”?

With which the auditor SHOULD comply, but reason for departure must be documented

84
New cards

What are the three types of government engagements?

  1. Financial audits

  2. Attestation engagements

  3. Performance audits (compliance, controls, prospective analysis, and effectiveness, economy, efficiency)


85
New cards

In a financial statement audit, what does GAGAs require?

A reprot on ICFR

86
New cards

What do audits in accordance with GAGAS require additional attention to?

Fraud, noncompliance, abuse

87
New cards

What should an auditor do when reporting confidential information under GAGS?

Disclose the exclusion by reporting that information has been omitted and why

88
New cards

What do you need to make sure of in terms of documentation?

That is supports findings, conclusions, recommendations, and that departures/findings are included

89
New cards

What are the 4 considerations for developing a finding?

  • Criteria

  • Condition

  • Cause

  • Effect


90
New cards

What is GAGAS also called?

The Yellow Book

91
New cards

What does GAGAS include?

All GAAS standards by reference and expand requirements with additional standards that focus on audits of governments and governmental financial assistance

92
New cards

What do single audits represent?

Supplementary audit requirements that relate to federal financial assistance

93
New cards

How does GAGAS describe the nature of audits of government entities?

Those that often focus on compliance with laws and regulations that may have a direct and material effect on the determination of financial assistance revenue amounts displayed in the financial statements

94
New cards

Why is compliance important under GAGAS?

Helps determine whether government assistance was properly earned or whether it is owed back to the grantor

95
New cards

What is management responsible for in government audits under GAGAS?

  • Identifying the appropriate laws and regulations

  • Establishing internal controls that provide reasonable assurance that the entity complies with applicable laws and regulations

  • Preparing supplemental financial reports

  • Obtaining an audit that satisfies the appropriate legal, regulatory, or contractual requirements


96
New cards

What are auditors responsible for in government audits under GAGAS?

  • Obtaining reasonable assurance that the financial statements are free of material misstatements resulting from violations of laws and regulations that have a direct and material effect on the determination of financial statement amounts

  • Determining whether management has properly identified laws and regulations, for understanding the implications of noncompliance on the financial statements

  • Ensuring that the scope of the audit addresses the appropriate requirements.


97
New cards

What should the auditor report for government audits under GAGAS?

All instances that involve fraud or illegal acts unless they are inconsequential

98
New cards

What is the purpose of a GAGAS Report on IC over Compliance (Yellow Book)?

Not to express and opinion, but to report on what we did in terms of tests and results

99
New cards

What type of assurance is needed for GAGAS Report on IC over Compliance (Yellow Book)?

Broader assurance

100
New cards

What type of letter is needed for GAGAS Report on IC over Compliance (Yellow Book)?

Management representation letter