1/87
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Chapter 1: Intro to Assurance and Auditing
Financial Statement Audit Overview
Public companies need to put out an annual report (10K) with financial statements
Management prepares financial statements
Auditor has to be independent
Audit committee hires the external auditor
Auditors make risk assessments about complex transactions, weak controls, and issues in the industry to plan the audit
Auditors collect evdience to support their opinion with reasonable assurance whether the financial statements as a whole are free of material misstatement due to error or fraud
The audit opinion is included with the company’s annual report to the public and filed with the SEC
Investors, creditors, and other stakeholders care about the audit report
Demands for auditing
Audits are required by Securities Exchange Acts of 1933 and 1934 for publicly traded companies in the U.S.
Prior to 1933, 82% of companies already had independent audits
Other demands for auditing
To raise capital (stocks, bonds, etc)
To fufill a stewardship function (managing the corporation’s assets)
Important role in the principal-agent relationship
Principal agent relationship

Assurance Services
Auditing is the highest level of assurance

What is auditing?
Systematic process (follows GAAS and uses a risk-based approach)
Objectivity collecting and evaluation evidence (independently and unbiasedly getting evidence on a test-basis)
Assertions are made by management (everything in the financial statements and footnotes
Assertions should conforn to specified rules (GAAP)
Results are reported to others (users are investors and creditors)
Management assertions balance sheet

Overview of the Financial Statement Audit Process

Major Audit Concept - Materiality
The magnitude of an omission or misstatement of accounting info that in light of surrounding cirumstances. makes it probable that the judgement of a reasonable person would have been changed or influence by the omission or misstatement
- Quantitiative and qualitiative considerations
Major Audit Concept - Audit Risk
Risk that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated
- Audit provides reasonable assurance that the FS do not contain material misstatements
The Audit Process
Client acceptance/continuance = deciding whether to accept new clients and retain current clients
New clients, the auditor req to confer w the predecessor and do background checks on top management
Prelim engagement act = determine audit team req, ensure independence of audit firm and team, understand services to be performed and terms of engagement —- understanding entity and environment
Planning = determine materiality, assessment of clients business risk, final plan sets the nature, timing, extent of the audit procedures to be performed
Consider entity and audit internal controls
Audit business processes and related accounts = most of the time on a f/s audit or audit of internal control, for public companies, these are done tg
Complete the audit = addresses issues like the possibility of undisclosed contingent liabilities, lawsuits, searches, etc
Evaluate results and issue audit opinion

What is an unqualified report?
Means the financial statement is free of material misstatements, clean
It’s common for auditors to find misstatements but clients will fix
Audit report includes opinion on the financial statements, basis for opinion, and critical audit matters

Chapter 2: Financial Statement Auditing Environment
What did the Sarbanes-Oxley Act of 2002 (SOX) do?
Created the Public Company Accounting Oversight Board (PCAOB) to regulate public accounting firms
accounting firms must register with PCAOB
Set auditing standards
Conduct inspections on accounting firms
annually for large accounting firms (>100 public clients)
Triennially for small accounting firms (<100 public clients)
Under new independence rules, non-audit services were severely limited
No consulting or management functions for audit clients (bookkeeping, financial info systems design and implementation, valuation services, actuarial services, internal audit services, HR functions, legal or investment services)
Tax services are okay
A second partner review and approval for all audits
Lead audit partner and review partner rotate off every 5 years
Client’s CEO and CFO certify the financial statements and disclosures
Penalties up to $5 million and 20 yrs of prison
One year cooliing off period - CEO, CFO, controller, anyone in financial reporting management cannot have been employed by the company’s audit firm within one year proceeding their audit
Management must assess and report on the effectiveness of internal controls over financial reporting (ICFR)
Required audit and audit opinion on effectiveness of ICFR
Audit committee must be independent; with at least one financial expert
What is Corporate Governance?
To form a business, principals decide on the organizational form (corp, partnership) and hire managers to manage resources
System of corporate governance oversees management
It consists of all the people, processes, and activities in place to help ensure proper stewardship over an entity’s assets
Good corporate governance ensures that those managing an entity properly use their time, talents, and entity’s resources in the best interest of the absentee ownners, and that they faithfully report the economic condition and performance of the enterprise
Model of a Business
Management, with guidance from the Board of Directors set objectives with strategies to achieve those objectives
Management then establish business processes to implement these strategies
Bus. Processes include financing, purchasing, HR management, inventory management, and revenue processes
Business processes involve transactions
The enterprise designs and implements accounting information systems to capture the details of these transactions
Design and implement system of internal control to ensure transactions are handled and recorded appropriately and resources are protected
Audit Committee Characteristics
Required for all publically traded companies
3-6 members
independent outside directors
can’t accept any consulting, advisory, or other compensating fee from the company
can not be an affiliated person of the company or any of its subsidiaries
Contain at least 1 member with financial expertise
based on education & work experience
understanding GAAP and FS
Experience with GAAP financial statements and internal controls
understanding of audit committee functions
typcial candidates = retired audit partners, financial officers, principal accounting officers
If an audit committee lacks financial expertise, must disclose to SEC the reason why
Audit Committee Responsibilities
Overseeing the financial reporting and disclosure process
monitoring choice of accounting policies and principles
oveseeing hiring, performance, and independence of the external auditors
oversight of regulatory compliance, ethics, and whisteblower hotlines
monitoring the internal control process
overseeing the performance of internal audit
discussing risk management policies and practices with management
Firms that have good governance…
are less likely to engage in “financial engineering” and less risky to audit
have a code of conduct reinforced by actions of top management and independent board members
take the requirements of good internal control over financial reporting seriously
make a commitment to financial competencies needed
Organizations that Affect Financial Statement Audits in the United States

PCAOB
Established by SOX
Quasi-gov regulatory agency overseen by SEC
Consists of 5 board members with no more than 2 being CPAs
Funded by over 1,850 audit firms that perform public company audits
responsibilites
audit standard authority
inspections of registed audit firms (1 or 3 yrs)
Disciplinary authority over registered audit firms
Principles Underlying an Audit (in accordance with GAAS)
Purpose and premise of an audit
Responsibilites of the auditor
Performance of the Audit
Reporting
Purpose and premise of an audit
Purpose is an opinion on the FS, in all material aspects, in accordance with GAAP
Audit in accordance with GAAS (management is responsible for financial statements)
Responsibilites of the auditor
having competence and capabilities to perform the audit
complying with ethical requirements, including integrity & independence
maintaining professional skepticism and exercising due professional care in professional judgement
Performance of the audit
obtain reasonable assurance about whether the financial statements are free of material misstatements, whether due to error or fraud
plan the work and properly supervise assistants
determines and applies appropriate materiality levels throughout the audit
identifies and assesses risks of material misstatements based on understanding the entity and environment, including the entity’s internal controls
obtain sufficient appropriate audit evidence
inherent limitations prohibit absolute assurance
Reporting
Express an opinion about whether the FS are presented fairly, in all material aspects, in accordance with GAAP
Chapter 19 - Professional Conduct and Independence
AICPA’s Principles of Professional Conduct
Starts with preface that is applicable to all CPAs
Preface consists with preamble and principles, described below
Starts at a conceptual level with principles → general rules → detailed interpretations
3 parts
Part 1 applies to CPAs in public practice, who provide assurance to audits which 3rd party stakeholders will rely
Part 2 applies to CPAs who are working in business but not as auditors, doesn’t require independence
Part 3 applies to CPAs who are neither 1 or 2 (such as professors)
Preamble - Principles of Professional Conduct
Principles guide members in the performance of their professional responsibilities and express the basic tenets of ethical and professional conduct. The principles call for an unwavering commitment to honorable behavior, even at the sacrifice of personal advantage.
Principles - Principles of Professional Conduct
Responsibilities: In carrying out their responsibilities as professionals, members should exercise sensitive professional and moral judgement in all their activities
The public interest: Members should accept the obligation to act in a way that will serve the public interest, honor the public trust, and demonstrate commitment to professionalism
Integrity: To maintain and broaden public confidence, members should perform all professional responsibilities with the highest sense of integrity.
Objectivity and independence: A member should maintain objectivity and be free of conflicts of interest in discharging professional responsibilities. A member in public practice should be independent in fact and appearance when providing auditing and other attestation services.
Due care: A member should observe professions’s technical and ethical standards, strive continually to improve competence and quality of services, and discharge professional responsibility to the best of the member’s ability.
Scope and nature of services: Member in public practice should observe the principles of the code of professional conduct in determining the scope and nature of services to be provided.
When is independence in mind/fact?
An auditor is independent in fact when they are objective and unbiased in their actions and decisions
Threat to author’s professional judgements (actual bias)
When is independence in appearance?
An auditor is independent in appearance when they are perceived by knowledgeable users as independent
Threat to auditor’s credibility and reputation
Ex. working on a engagement team where your best friend’s wife is in a position at the client that affects its financial statements may be independent in fact, but not in appearance.
When does independence matter?
For all attestation services
Financial statement audits and reviews
All covered members must be independent
Who is a covered member?
Any individual who is…
on the attest engagement team
in a position to influence the attest engagement
a partner or manager who provides more than 10 hrs of nonattest services to the attest entity
Designation as a covered member ends on the later of the date the firm signs the report on the f/s for the fiscal year during which those services were provided or the date they no longer expect to provide 10 or more hours of nonattest services to the attest client on a recurring basis
a partner in the office in which the lead attest engagement partner primarily practices in connection with the attest engagement
the firm, including employees benefit plan
an entity whose operating, financial, or accounting policies can be controlled by any of the individuals or entities described above or by two or more such individuals or entities if they act together
Independence - Prohibited Financial Relationships
Direct financial interest: a financial interest that is owned directly by an individual or entity or is under the control of an individual or entity
Financial interest that is owned thru an intermediary (trust or estate) is also considered a direct financial interest
Ex. owning shares of the client’s stock
Can’t borrow, own, invest not even a cent
Indirect financial interest: when a covered member has a financial interest in an entity that is associated with an attest entity
Ex. owning shares of a mutual fund that owns the client’s stock
impairs independence if your indirect interest is material (<5% net worth)
can’t own stock in an entity with a material relation with the client or one of a client’s related parties
Independence - prohibited business relationships
Independence is impaired if CPA performs a managerial or other significant role for an entity’s org during the time period covered by an attest engagement
Non-attest services for attest clients
A firm’s independence will be considered to be impaired with respect to an entity if a partner or professional employee leaves the firm and is subsequently employed by or associated with that entity in a key position unless a number of conditions are met
The one year cooling off period for oversight roles
Independence - Effect of family relationships
A covered member’s immediate family (spouse or equivlent or dependent) is subject to rule 101 and its interpretations and rulings
100% of independence rules apply to immediate family
A covered members close relatives can impair independence if
Close relatives = nondependent children, brothers, sisters, parents, grandparents, parents in law and their respective spouses
member’s close relative could influence signficiant influence over the financial or accounting policies of the entity (FR oversight role in client)
member’s close relative has a material financial interest in the entity
Independence - Effect of litigation
Independence is impaired when
Management sues the auditor, claiming the auditor did poor audit work.
Management clearly says it intends to bring that kind of lawsuit.
The auditor sues management, claiming management committed fraud or deceit.
Independence - Provision of Nonattest services
AICPA Code of Professional Conduct restricts the types of nonaudit services that can be provided to attest clients. Examples include
authorizing, executing or consummating a transaction on behalf of an entity
Preparing source documents evidencing the occurrence of a transaction
having custody of entity assets
supervising the entity’s employees
determining which recommendations of the member should be implemented
establishing for maintaining internal controls
The SEC (mandated by SOX) has even more restrictive independence rules for audits for public companies
providing nonattest services is only okay if allowed, approved by audit committee, and disclosed
Independence - SEC and PCAOB Independence requirements for audits of public companies
SEc rules are predicated by 3 basic principles of auditor objectivity and independence
An auditor should not audit his own work
An auditor should not function in the role of management
An auditor should not serve in an advocacy role for the tntity and should not have a mutual or conflicting interest with an audit client
Ex: bookkeeping, financial info system design and implementation, appraisal or valuation services, actuarial services, internal audit outsourcing services, management functions or human resources, broker or dealer, investment advisor, or investment banking services, legal or expert services
Disciplinary actions
AICPA can discipline members for violating the code of professional conduct
membership in AICPA can be suspended or terminated
CPA license can be suspended or revoked
PCAOB inspects all registered firms for compliance
Chapter 3: Audit planning, types of tests and materiality
Client Acceptance and Continuance
Auditors have to make decisions about:
accepting new clients
is the firm capable? (consider firm personnel, specialists, if able to complete by reporting deadline, independent)
does the firm comply with legal and ethical requirements?
how is the client’s integrity?
Inquiries of the predecessor auditor, inquire other firm personnel or third parties (bankers, legal counsel, industry peers), background searches of relevant databases
(SIM - skills, independence, management risk/integrity)
Continuing with existing clients
Evaluate client relations periodically
What should successor auditor ask predecessor auditor (Required communications)
Information that might bear on the integrity of management.
Information regarding identified or suspected fraud and matters involving noncompliance with laws and regulations.
Disagreements with management about accounting policies, auditing procedures, or other similarly significant matters.
Communications to audit committees or others with equivalent authority and responsibility regarding fraud, illegal acts by clients (i.e., noncompliance with laws and regulations), and internal-control-related matters.
The reasons for the change of auditors.
Any significant related parties or unusual transactions
Continuing with Existing Clients
Evaluate client retention periodically
Near audit completion
After a significant event (conflicts over accounting or audit issues, dispute over audit fees)
All public companies must disclose auditor changes in SEC 8-K filing, including reason for change
What are reasons for audit firm to dissociate from client?
Disagreement between client/auditor
Auditor not willing to accept audit risk or business risk
Auditor/client misalignment (company grows or shrinks and needs a larger/smaller auditor)
Preliminary Engagement Activities
Determine audit team requirements
- look at size, complexity, level of risk, any special expertise, availability, timing of work
Assess compliance with ethical and independence requirements
Ensure independence is maintained!
many firms have policy of not completing current audit until all of prior year fees have been paid
Establish an understanding of the entity
Engagement letter
using work of internal auditors
role of the audit committee
What is the engagement letter?
a contract oulining the responsibilities of both parties and preventing misunderstandings between the two parties
addressed to the chair of the audit committee
What does the engagement letter include?
services to be performed and related reports
auditor’s responsibilities and limitations
objective of the audits
summary of the audit procedures to be performed and evidence that will be obtained
limitations of the audit
management responsibilities
expectations regarding f/s prep and responsibility for ICFR
expectations for making evidence available on a timely basis
expectations about management representation letter (written represenations about the f/s)
Timing and fees
establish timeline for audit work performance
details on an estimate of audit fees (breakdown by level of auditor)
agreed upon assistance from the company personnel (specialists or internal auditors)
Using the work of internal audit function
auditor can use the work of internal audit as evidence and request IA to provide direct assistence in the external audit
obtain an understanding of IA
objectivity
competence
systematic and disciplined approach (do they adequately document their IA produres or guidance covering areas like risk assessments, work programs, documentation, quality control)
If IA is reliable, audit can use IA work to reduce audit work
if auditors rely on IA, then they must supervise, review, evaluate, and test IA work
Planning the audit
Develop audit strategy and plan (nature, extent, timing of testing)
assess business risks (understand entity & environment)
establish materiality
consider multi-locations or business units (which locations are audited and what to audit at each location or bus unit)
assess the need for specialists (specialists in finance, valuation, legal, etc)
consider violations of laws and regulations (securities acts, enviornmental protection, price-fixing, etc)
identify related parties (RP = affiliates, investments under equity method, trusts for benefit of employees, pension, principal owners and their immediate families)
consider additional value-added services
doc the overall audit strategy, plan, and prepare audit programs
Identify Related Parties
Auditor must evaluate the entity’s identification of, accounting for, and disclosure of transactions with related parties
identify if transactions are “at arms length”
examples of “related parties”
affiliates of the entity
entities using equity method to account for investment
trusts for benefit of employees
principal owners of entity
managment
immediate families of principal owners and management
other parties that can have significant influence
How do auditors identify related parties and related party transactions?
Inquire if management and other about names of related parties, reasons for transactions with the RP
minutes of the board of director meetings
conflict-of-interest statements from management and others
financial and reporting info provided to creditors, investors, and regulators
contracts or other agreements (including side agreements that may not be formally documented between customers and vendors, and management)
contracts and other agreements representing significant unusual transactions
Example of RP is a partnership composed of management who owns a building leased by the entity, auditor would examine lease agreement
Type of audit tests
risk assesment procedures
tests of controls
substantive procedures
dual purpose tests
Risk assessment procedures
Used to obtain an understanding of the entity and its environment, including its internal control
includes inquiries of management and others, preliminary analytical procedures, observation, and inspection
Tests of controls
Test the operating effectiveness of controls in preventing or detecting & correcting material misstatements to the f/s
Inquiries of appropriate management, supervisory, and staff personnel.
Inspection of documents, reports, and electronic files.
Observation of the application of specific controls.
Walkthroughs, which involve tracing a transaction from its origination to its inclusion in the financial statements through a combination of audit procedures, including inquiry, observation, and inspection.
Reperformance of the application of the control by the auditor.
Substantive procedures
Tests to detect material misstatements (monetary errors) in transactions, account balance, or disclosure in f/s
Includes
test of details
substantive tests of transactions to detect errors or fraud in individual transactions
test of details of account balances and disclosures
substantive analytical procedures
Evaluations of financial info thru analysis of plausible relationships among both financial and nonfiancial data (examination of trends and errors)
Dual Purpose tests
tests of controls and substantive tests simulatieously on the same document
Materiality
Matter of professional judgement
misstatements, including omissions, are material if theres a high likelihood that individually or in aggregate, they would influence the judgement made by a reasonable user of financial statements
affected by size or nature of a misstatement or both (quantitative & qualitiative)
Steps in applying materiality on an audit
determine overall materiality (Planning materiality PM)
Determine tolerable misstatement (TM): allocation of materiality to individual account/class of transactions level)
Evaluate auditing findings: near the end of the audit, examine individual and aggregate misstatements)
Detemine overall materiality (PM)
Auditing standards require auditors to establish materiality threshold for financial statements as a whole
PCAOB guidence: auditor should consider company’s earnings and other relevant factors
ASB: provides additional guidance on fiancial statement balances to consider
PM is the maximum amount by which the auditor feels that the fianncial statements can be misstated and not affect the decisions of users.
Considerations for PM
Quantitiative basis
Based off a range of pretax income by default, total sales/rev, total equity, total assets, or net assets
Qualitiative considerations for quantitiative basis of materiality
use the low end range of quantitative materiality for factors such as
material misstatements detected during prior year
high risk of fraud
potential loan convenant violations or going concern issues
high market pressures
volatile business environment
higher than normal risk of bankruptcy
High end of the range quantitiatve materiality is rare and needs very convincing documentation
Determine Tolerable Misstatement (TM)
TM: amt or amts that reduce to an appropriately level the probability that the total of uncorrected and undetected misstatements would result in a material misstatement of the financial statements
Typically 50-75% of PM depending on risk
Purpose of TM
establish a scope for the audit procedures over individual account balances
audit all account balances over the threshold
assumption is errors in any account below threshold wouldn’t generate misstatements that would result in a material misstatement
serves as a safety net
Evaluate audit findings
occurs near end of audit
aggregate misstatements from each amount or disclosure for all misstatements over the de minimum threshold (2% of PM)
When evaluating aggregate misstatements, include the current year effect of misstatements not adjusted in the prior year that were immaterial
if aggregate misstatements at account level > TM = adjust financial statements and consider qualitiative factors
If remaining total aggregate misstatement for all PM = adjust f/s and consider qualitiative factors
considerations from misstatements that are estimates
Chapter 4: Audit Risk Assessments
Audit Risk
The risk that auditor will issue on unqualified opinion on materially misstated financial statements
Two components
risk that account balances and disclosures contain material misstatements (inherent & control risk)
risk that the auditor will not detect such misstatements (detection risk)

Audit risk model
(is adapative to the account)
RMM is inversely related to AR
DR directly related to AR
IR and CR are inversely related to DR

Inherent risk (IR)
Risks related to entity and its environment (beyond auditor’s control)
Control risk (CR)
(unrelated to inherent risk)
Function of the effectiveness of the design and operation of intenral control
Detection risk (DR)
Risk that the procedures performed by an auditor to reduce audit risk to an acceptably low level will not detected a misstatement that exists and that could be material
determined by effectiveness of the auditor
DR is caused by:
What is detection risk caused by?
inappropriate audit procedures
improper or incomplete use of appropriate audit procedures
mistinterpretation of results from an audit procedure
How to reduce detection risk?
adequate planning, supervision, review, PS, etc
the lower the detection risk, the more substantive testing required
controlled by the auditor in planning
How to use the audit risk model
set a planned level of audit risk (AR)
determined based on risk of client (engagement/business risk)
set at low or very low level
assess the risk of material misstatement (RMM)
range from very low to very high
solve for appropriate level of detection risk (DR)
Use DR to design audit procedures that will reduce AR to an acceptably low level (the nature, extent, and timing of testing)
When setting audit risk (AR), consider…
RMM
The auditor’s risk
The risk that the auditor is exposed to financial loss or damage to his or her professional reputation from litigation, adverse publicity, or other events arising in connections with f/s audited and reported on
Global factors that impact engagement risk
num of users of f/s
integrity of management
financial health of the company
company’s industry charactersitics
Auditor’s assessment of client’s business risk
Risks resulting from signficiant conditions, events, circumstances, and actions or inactions that could adversely affect management’s ability to execute its strategies and to achieve its objectives, or through the settting of inappropriate objetives or strategies
Most business risks have the potential to affect f/s
auditors have to identify potential business risks and understand the potential material misstatements that may result
Examples of business risks (IR and CR)
Nature of entity
org structure, management personnel, sources of funding - including capital structure, noncapital funding, and other debt instruments, investments, size and complexity, relative profitability of key products and services, key supplier and customer relationships
Industry, regulatory, external factors
industry conditions - market & competition, cyclical or seasonal activity
reglatory environment - accounting principles such as industry specific practices, regulatory framework for a regulated industry, taxation, government policies, environmenal reqs
Other external factors = general level of economic activity, interest rates, inflation
Objectives, strategies, and related business risks
industry developments, new products and services, expansion, use of IT, effects of implementing a strategy
Entity Performance measures
Budgets, variance analysis, performance reports, comparison to industry peers, analyst expectations, credit ratings, profitability and liquidity ratios
Internal control effectiveness
active and qualified board of directors, independent audit committee members, effective risk assessment process, competent and objective internal audit function, controls related to proper authoriztion of transactions, ensuring assets exist, monitoring of controls
types and causes of misstatements - RMM
Errors (unintentional acts)
Fraud (intentional acts)
m/s from fraudulent financial reporting
m/s from misappropriation of assets
Misstatements due to errors or fraud include
inaccuracy in gathering or processing data from which financial statements are prepared
omission of an amount or disclosure
a f/s disclosure that is not presented in accordance with GAAP
An incorrect accounting estimate arising from overlooking or clear misinterpretation of facts
judgements of management concerning accounting estimates that the auditor considers reasonable or the selection or application of accounting policies that the auditor considers inappropriate
Two types of fraud

Fraud risk assessment process
During planning, auditors are required to assess the risk of material misstatement due to fraud
Fraud brainstorming session - discussion among the audit team members about the risks and opportunities for fraud at the company this year
inquire of management and others abt their views on the risks of fraud and how it is addressed
managment, audit committee, internal audit function
Consider any unusal or unexpected relationships that have been identified in performing analytical procedures in planning the audit
understand the client’s period-end closing process and investigate unexpected period-end adjustments
The fraud triangle
3 conditions are generally present when material misstatements due to fraud occur
incentive/pressure: motivation or reason to commit the fraud
opportunity: circumstances exist that allow the opportunity to commit the fraud
rationalization/attitude: one is able to justify commiting the fraud, or some individuals possess an attitude, character, or set of ethical values that allow them to commit dishonest acts
Even honest individuals can commit fraud in an environment where sufficient pressure exists, and the greater the pressure the easier it is to rationalize
Fraud can only take place when there is an opportunity!!

Incentives/Pressures for fraudulent reporting
financial distress due to economic, industry, or entity operating conditions
ex. recurring operating losses or negative cf
execssive pressure for management to meet requirements or expectations
analyst expectations, earnings growth, positive earnings, exec compensation tied to performance targets, meeting debt covenet restrictions, adverse financial results impact significant pending transactions
management’s personal situation threatened by entity’s financial performance (getting fired)
Opportunities for fraudulent reporting
weak internal controls
signficiant related party transactions
signficicant subjective accounting estimates and/or uncertainty
unsual or highly complex transactions
ineffective monitoring of management by BOD or AC (weak corporate governance)
single person dominates management
complex or unstable organziational structure
(difficult to detect when management overrides controls, and if collusion occurs)
Attitudes/rationalization for fraudulent reporting
ineffective communication, support, or enforcement of values/ethics
tone at the top, lack of code of conduct
history of violations of securities laws or other regulations
excessive interest by management in maintaining or increasing the stock price or earnings trends
a practice of management committing to aggressive or unrealisitic forecasts
recurring attempts by managemnt to justify marginal or inappropriate accounting on the basis of materilaity
Fraud risk factors for misappropriation of assets
incentives/pressures
employees with personal financial obligations/troubles
adverse relationships between entity and its employees (expected layoffs, not being promoted or rewarded as expected)
opportunities
circumstances that make assets suscpetible to theft (large amts of cash on hand)
inadequate internal controls (lack of segregation of duties, lack of physical controls, lack of system access controls)
attitudes/rationalizations
disregard for the need for monitoring and maintaining effective controls
changes in behavior or lifestyles that indicate assets have been misappropriated
Auditor’s response to pervasive risks
Pervasive risks affect the entire financial statement as a whole
Ask: Could this cause errors in many places, or just one place?
If it is a pervasive risk, then need to
emphasize the need for professional skepticism in gathering and evaluating evidence
assign more experienced staff or use specialists
provide more supervision
incorporate more unpredicatability in selection of testing
Auditor’s response to specific risks
At the mangement assertion level
Perform tests of controls and substantive tests that directly respond to the specific risks
If the misstatement is or may be the result of fraud, and the effect could be material, the auditor should…
attempt to obtain audit evidence to determine whether, in fact, material fraud has occured, and its effect
consider implications for other aspects of the audit
discuss the matter and approach to further investigate with appropriate level of management that is at least 1 level above those involved in committing the fraud
suggest the approporiate level of management consult with legal counsel
communicate with the audit committee
consider withdrawing from the engagement