Financial Statement Auditing, Assurance, Ethics, and Risk Assessment Vocabulary
Introduction to Financial Statement Auditing and Assurance
- Distinction Between Auditing and Other Accounting Courses:
- Other Accounting Courses: Focus on rules, techniques, and computations required to prepare and analyze financial information.
- Auditing Course: Focuses on analytical and logical skills, conceptual frameworks, and evaluating whether financial information is presented fairly.

- Principals, Agents, and Agency Theory:
- Principal (Absentee Owner): Provides capital and hires an agent to manage organizational resources.
- Agent (Manager): Accountable to the principal; manages resources and provides periodic financial reports.
- Information Asymmetry and Conflicts of Interest: The manager has more information about the entity's true financial state than the absentee owner. Conflicts of interest arise because managers may act in their own self-interest rather than the owner's best interest. This dynamic creates information risk for the principal.
- Role of the Auditor: The manager hires an independent auditor to report on the fairness of financial reports and pays the auditor to reduce the principal's information risk. The auditor gathers evidence, evaluates fairness, and issues an audit opinion to accompany the financial reports, adding credibility.

The Demand for Auditing:
- Audits lend credibility to financial statements by reducing information risk (the risk that financial statement information is materially misstated).
- Causes of Financial Statement Misstatements:
- Accidental errors
- Lack of knowledge regarding accounting principles
- Unintentional bias
- Deliberate falsification (fraud)
- Business Risk vs. Information Risk: Audits do not directly address business risk—the risk that a company will be unable to meet its financial obligations due to adverse economic conditions, poor management decisions, or competitive pressures.
Key Players in an Audit:
- Client Management (e.g., CEO, CFO): Primary responsibility for preparing the Financial Statements (F/S) and establishing/maintaining effective Internal Control over Financial Reporting (ICFR).
- Audit Committee: A specialized committee of independent members of the board of directors; responsible for appointing, compensating, and overseeing the independent auditor, as well as resolving accounting disputes.
- Independent Auditor: Responsible for expressing an opinion on whether the financial statements comply with Generally Accepted Accounting Principles (GAAP). The auditor is not responsible for preparing the financial statements. Full auditor responsibilities are outlined by PCAOB standard .
Relationships Among Auditing, Attest, and Assurance Services:
- Auditing Definition: A systematic process of objectively obtaining and evaluating evidence regarding assertions about economic actions and events to ascertain the degree of correspondence between those assertions and established criteria, and communicating the results to interested users.
- Relationship Spectrum:
- Assurance Services: The broadest category; professional services that improve the quality or context of information for decision-makers.
- Attest Services: A sub-category of assurance services where a practitioner issues a written report on subject matter or an assertion about subject matter that is the responsibility of another party.
- Auditing: A specialized form of attest service focused primarily on historical financial statements.


- Overview of the Financial Statement Auditing Process:
- Management Actions: Implements internal controls Conducts transactions Accumulates transactions into account balances Prepares financial statements Issues financial statements to users.
- Auditor Actions: Establishes terms of engagement Obtains evidence regarding management assertions Tests assertions against criteria (GAAP) Determines overall fairness Issues audit report to accompany financial statements.

Fundamental Audit Concepts:
- Materiality: The magnitude of an omission or misstatement of accounting information that makes it probable that the judgment of a reasonable person relying on the information would be changed or influenced. Lower materiality thresholds require auditors to gather greater amounts of audit evidence.
- Audit Risk: The risk that the auditor mistakenly expresses an unqualified (clean) audit opinion when the financial statements are materially misstated. Auditing standards dictate that an audit provides reasonable assurance, not absolute assurance.
- Evidence: Underlying accounting data and corroborating information available from internal or external sources. Must be sufficient (quantity) and appropriate (quality).
- Relevance: Whether evidence relates to the specific assertion being tested.
- Reliability: Whether evidence can be trusted to signal the true state of the assertion.
- Sampling and Data Analytics: Due to cost and time constraints, auditors examine subsets of transactions using sampling. Modern data analytics increasingly allow auditors to test entire populations.
Major Phases of an Audit:
- Client acceptance/continuance
- Preliminary engagement activities
- Plan the audit
- Consider and audit internal control
- Audit business processes and related accounts (e.g., revenue generation)
- Complete the audit
- Evaluate results and issue audit report

Management Assertions
- Overview: Management implicit or explicit assertions regarding classes of transactions, account balances, and related disclosures.

Assertions About Classes of Transactions and Events (and Related Disclosures) for the Period Under Audit:
- Occurrence: Recorded or disclosed transactions and events actually occurred and pertain to the entity.
- Completeness: All transactions, events, and related disclosures that should have been recorded have been included.
- Authorization: All transactions and events have been properly authorized. (Note: International and AICPA auditing standards consider Authorization a subset of Occurrence, but it is listed separately for instructional clarity).
- Accuracy: Amounts and other data relating to recorded transactions and events have been recorded appropriately, and related disclosures have been properly measured and described.
- Cutoff: Transactions and events have been recorded in the correct accounting period.
- Classification: Transactions and events have been recorded in the proper accounts.
- Presentation: Transactions and events are appropriately aggregated or disaggregated and clearly described, with relevant and understandable disclosures under the applicable financial reporting framework.
Assertions About Account Balances (and Related Disclosures) at Period End:
- Existence: Assets, liabilities, and equity interests exist.
- Rights and Obligations: The entity holds or controls the rights to assets, and liabilities represent obligations of the entity.
- Completeness: All assets, liabilities, and equity interests that should have been recorded have been included, along with all required disclosures.
- Accuracy, Valuation, and Allocation: Assets, liabilities, and equity interests are included at appropriate amounts, with any resulting valuation or allocation adjustments properly recorded.
- Classification: Assets, liabilities, and equity interests have been recorded in the proper accounts.
- Presentation: Assets, liabilities, and equity interests are appropriately aggregated or disaggregated and clearly described.
Application Example - Vouching Test:
- An auditor performs a vouching test on accounts receivable by inspecting the general ledger, selecting sample account balances, and tracing back to original supporting documentation.
- Tested Assertion: Existence (verifying that the recorded balance actually exists as an asset).
Audit Reporting, Opinions, and Emerging Technologies
- Structure of the Audit Report for Public Companies:
- Title: Must include the word "Independent" (e.g., "Report of Independent Registered Public Accounting Firm").
- Addressee: Addressed to stockholders and the Board of Directors of the client company.
- Core Sections:
- Opinion on the Financial Statements: Explicit statement of the audit scope, financial statements audited, years covered, and opinion on conformity with U.S. GAAP.
- Explanatory Paragraph (if separate ICFR report): References the auditor's separate opinion on Internal Control Over Financial Reporting.
- Basis for Opinion: States management's responsibility, auditor's responsibility, PCAOB registration/independence requirements, compliance with PCAOB standards, and that audit evidence provides a reasonable basis for the opinion.
- Critical Audit Matters (CAMs): Matters arising from the audit that were communicated (or required to be communicated) to the audit committee, relate to accounts or disclosures material to the financial statements, and involved especially challenging, subjective, or complex judgments.
- Sign-off Elements: Firm signature, tenure year (year service began), City and State of issuance, and Report Date.


Apple Inc. FY 2020 Audit Report Details (Ernst & Young LLP):
- Audited consolidated balance sheets as of September 26, 2020 and September 28, 2019, and related consolidated statements of operations, comprehensive income, shareholders' equity, and cash flows for three years.
- Issued an unqualified opinion on financial statements and ICFR (dated October 29, 2020).
- CAM Identified: Uncertain Tax Positions ( gross unrecognized tax benefits, with affecting the effective tax rate if recognized).
- Auditor Tenure: Served as Apple Inc.'s auditor since 2009; Issued from San Jose, California on October 29, 2020.
Types of Audit Reports:
- Unqualified (Clean) Opinion: The standard report issued when financial statements are presented fairly, in all material respects, in conformity with GAAP.
- Qualified Opinion: Issued when financial statements are fairly presented except for the effect of a material misstatement or scope limitation that is not pervasive.
- Adverse Opinion: Issued when misstatements are so material and pervasive that the financial statements are not presented fairly and should not be relied upon.
- Disclaimer of Opinion: Issued when a severe scope limitation prevents the auditor from obtaining sufficient evidence to form an opinion on the financial statements as a whole.
Knowledge Assessment - Unqualified Opinion Interpretation:
- An investor reading an unqualified audit report may conclude that any disputes over significant accounting issues between management and the auditor have been resolved to the auditor's satisfaction.
Audit Data Analytics (ADA) and Emerging Technologies:
- ADA involves analyzing data, building models, and visualizing information to identify patterns, anomalies, and risk areas.
- Key emerging technologies transforming financial statement audits:
- Robotic Process Automation (RPA): Automates routine, repetitive audit tasks.
- Distributed Blockchain Databases: Provides immutable transaction ledgers for verification.
- Artificial Intelligence (AI): Facilitates predictive analysis and complex text/data extraction.
The Financial Statement Auditing Environment and Governance
Types of Auditors:
- External Auditors: Independent CPAs auditing public and private entities.
- Internal Auditors: Employees of an entity providing operational and compliance reviews.
- Government Auditors: Conduct audits for federal, state, or local agencies (e.g., GAO, IRS).
- Fraud Auditors / Forensic Accountants: Specialized in investigating fraud, financial crimes, and white-collar offenses.
Classification of Professional Services:
- Assurance Services: Broad quality-improving information services.
- Attest Services: Professional services that result in a written report improving information quality.
- Audit Services: Financial statement audits, Internal Control Audits, Compliance Audits, Operational Audits, Fraud Audits.
- Non-Audit Services: Tax Preparation and Planning, Management Advisory Services, Compilation and Review Services.
Public Accounting Firm Hierarchy and Selected Duties:

Partner: Reaches agreement with auditee on engagement scope; ensures proper planning and GAAS compliance; assembles qualified team; supervises team and reviews workpapers; concludes on evidence adequacy and signs audit report.
Manager: Plans audit and schedules team members; supervises preparation of and approves audit program; reviews workpapers, financial statements, and audit report; recommends key judgments to partner; oversees seniors and staff; handles client billing and fee collections; informs partner of problems.
Senior / In-Charge: Assists in audit plan development; prepares time budgets; assigns tasks to staff and directs day-to-day audit execution; performs complex procedures, gathers and evaluates evidence; supervises and reviews staff work; informs manager of accounting/auditing issues.
Staff / Associate: Performs assigned audit procedures; prepares complete and accurate documentation of completed work; informs senior of any problems encountered.
Public Accounting Firm Categories: Big 4 (Deloitte, EY, PwC, KPMG), Mid-Tier (Grant Thornton, BDO, RSM), Regional, and Local firms.
History and Government Regulation:
Late 1990s / Early 2000s Boom: Accounting firms aggressively marketed high-margin non-audit consulting services to audit clients, leading to severe conflicts of interest.
Corporate Scandals: Enron, WorldCom, Tyco, Lehman Brothers.
Sarbanes-Oxley (SOX) Act of 2002: Enacted by Congress to regulate the audit profession. Created the Public Company Accounting Oversight Board (PCAOB), established strict independence rules, and mandated integrated audits (financial statements and internal controls) for large public companies.
Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010: Granted PCAOB authority to inspect foreign audit firms practicing in the U.S. and exempted smaller public companies from ICFR audits.
- Societal Expectations and Auditor Responsibilities:
Auditor Responsibility: Provide reasonable assurance that financial statements are free of material misstatement due to error, fraud, or illegal acts.
Due Professional Care: Requires professional skepticism—an attitude that includes a questioning mind and critical assessment of audit evidence. Failure can lead to civil or criminal liability.
Management Responsibility: Primary responsibility for maintaining effective internal controls and preparing fair financial statements.
- Overview of Business and Corporate Governance:

Corporate governance provides oversight and supervision of managers to protect stakeholder value.
5 Basic Business Processes:
- Revenue Process: Handling customer orders, sales, billing, and cash receipts.
- Financing Process: Raising capital via debt/equity and managing investments.
- Purchasing Process: Acquiring inventory, goods, services, and processing disbursements.
- Human Resource Management Process: Hiring, payroll, employee benefits, and termination.
- Inventory Management Process: Accumulating and allocating manufacturing/inventory costs.
- Organizations Regulating the Audit Profession in the U.S.:

Securities and Exchange Commission (SEC): Federal agency overseeing public market standard-setting.
Public Company Accounting Oversight Board (PCAOB): Establishes Auditing Standards () for public company audits.
Financial Accounting Standards Board (FASB): Establishes accounting principles (U.S. GAAP).
American Institute of Certified Public Accountants (AICPA): Private association; its Auditing Standards Board (ASB) issues Statements on Auditing Standards () for nonpublic company audits.
International Auditing and Assurance Standards Board (IAASB): Issues International Standards on Auditing () used in over 110 international jurisdictions.
- Principles Underlying GAAS (ASB Preface):
Purpose and Premise: Purpose is to express an opinion on financial statements. Conducted on the premise that management is responsible for financial statement preparation, ICFR design/maintenance, and providing unrestricted access and information to the auditor.

- Responsibilities: Auditors must possess appropriate competence/capabilities, comply with ethical standards, and maintain professional skepticism and exercise professional judgment.

- Performance: Express opinion by obtaining reasonable assurance; plan and supervise work; establish materiality; identify/assess risks of material misstatement; obtain sufficient appropriate evidence. Inherent limitations arise from the nature of financial reporting, nature of audit procedures, and cost-benefit/timeliness tradeoffs.

- Reporting: Express an opinion in a written report based on evidence evaluation or state that an opinion cannot be expressed.

Audit Planning, Client Engagement, and Audit Procedures
- Phases of Audit Planning:

Prospective Client Acceptance Considerations:
- Firm Capabilities: Ensure proper technical skills, industry expertise, personnel capacity, availability of specialists, and ability to meet reporting deadlines.
- Legal and Ethical Compliance: Ensure independence, adherence to regulatory agency rules, and compliance with the AICPA Code of Professional Conduct.
- Client Integrity: Evaluate reputation of owners/management/governance, nature of operations, commitment to internal control, scope limitation indicators, and criminal activity/money laundering risks.
Communication Between Predecessor and Successor Auditors ():
- The successor auditor must initiate communication with the predecessor auditor prior to client acceptance.
- Key Discussion Topics: Integrity of client management, disagreements over accounting/auditing principles, communications regarding fraud or illegal acts, internal control deficiencies, workpaper access, and reasons for changing auditors.
Continuing Client Retention:
- Periodically evaluate client retention near audit completion or following significant events.
- Discontinue relationships in cases of severe conflicts over accounting issues or fee disputes.
Preliminary Engagement Activities:
- Determine audit engagement team requirements.
- Assess compliance with ethical and independence requirements.
- Establish understanding of engagement terms with the entity.
Establishing an Understanding with the Entity:
- Engagement Letter: Formal service contract between auditor and client detailing engagement objectives, management's responsibilities, auditor's responsibilities, limitations, and fee structure.
- Example: EarthWear Clothiers engagement letter addressed to Mr. Chad Simon, Chair of Audit Committee, signed by Willis & Adams, P.C. (Boise, Idaho; April 1, 2018).


Using the Internal Audit Function (): Evaluate the Internal Audit Function based on Objectivity, Competence, and use of a Systematic and Disciplined Approach.
Audit Committee Requirements (SOX Section 301):
Independent board members.
Directly responsible for hiring, compensating, and overseeing the external auditor.
Must preapprove all audit and non-audit services.
Must establish whistleblower procedures for accounting/control complaints.
Must have authority to engage independent counsel.
Detailed Audit Planning Activities ():
Assess Business Risks: Understand entity and environment to identify risks leading to material misstatement.

- Consider Multi-Locations: Correlate audit procedures with risk levels at individual units.
- Assess Need for Specialists: Determine IT or technical specialist requirements early.
- Consider Illegal Acts:
- Direct and Material Effect: Direct impact on financial statements (e.g., tax/pension laws). Auditor responsibility is identical to errors/fraud.
- Indirect and Material Effect: Compliance laws (e.g., environmental protections, equal employment). Auditor must remain aware and investigate if brought to attention.

- Identify Related Parties: Inquire of management regarding related party names, relationship nature, transaction types, and underlying business purpose (e.g., Andy Fastow/Enron SPE transactions).

- Document Audit Strategy and Plan: Explicitly link entity business risks and internal controls to planned audit procedures (nature, timing, extent).

- Types of Audit Tests:
- Risk Assessment Procedures: Used to obtain an understanding of the entity and its environment, including internal controls.
- Tests of Controls: Evaluate the design and operating effectiveness of internal controls (inquiry, inspection, walkthrough, reperformance, observation).
- Substantive Procedures: Detect material misstatements in financial statement components.
- Substantive Analytical Procedures: Evaluations of financial information through plausible relationships among financial and non-financial data.
- Tests of Details: Direct testing of individual transactions, account balances, and disclosures for errors or fraud.
- Dual-Purpose Tests: Audit procedures designed to simultaneously test control effectiveness and detect transaction-level misstatements on the same document.
Materiality Determination and Evaluation
Materiality Process Overview:
- Step 1: Determine overall materiality (planning materiality).
- Step 2: Determine tolerable misstatement (allocation to individual accounts/classes of transactions).
- Step 3: Evaluate audit findings near audit completion.
Step 1 - Overall Materiality:
- Common Quantitative Benchmarks: Income before taxes (IBT), Total assets, Total revenues, Net assets, Total equity.
- Qualitative Factors for Adjusting Thresholds Lower: Prior year misstatements, high fraud risk, potential loan covenant violations, small misstatements causing missed earnings targets, volatile business environment.
Step 2 - Tolerable Misstatement:
- The portion of overall materiality allocated to a specific account balance or transaction class.
- Combined tolerable misstatement across all accounts usually exceeds overall planning materiality because errors rarely hit maximum limits simultaneously across all accounts, and overall materiality acts as a aggregate safety net.
Step 3 - Evaluate Audit Findings:
- Aggregate misstatements (known + likely) from all accounts.
- Include unadjusted prior period misstatements.
- Compare aggregate misstatements to overall materiality. If aggregate misstatements exceed overall materiality, management must adjust financial statements or auditor issues a modified opinion.
Worked Numerical Examples & Practice Problems:
- Problem 3-32 (Quarterly Projection Calculation):
- Reported IBT: Q1 = , Q2 = .
- Q3 Projection: decline from Q2 .
- Q4 Projection: increase over Q3 .
- Projected Annual IBT: .
- Overall Materiality ( benchmark): .
- Problem 3-33 / Scenario 1 (Murphy & Johnson Audit Evaluation):
- Client Background: Privately owned small motor manufacturer. Financial statement components: Income before taxes = , Total assets = , Total revenues = .
- Part a: Overall Materiality ( of IBT): .
- Tolerable Misstatement ( of overall materiality): .
- Part b: Audit Findings Evaluation: Detected aggregate income overstatement = .
- Evaluation: Since (overall materiality), the financial statements are materially misstated. Management must adjust financial statements; otherwise, the CPA firm must express a qualified or adverse audit opinion.
Professional Conduct, Ethics, and Independence
Definitions:
- Ethics: System or code of conduct based on moral duties indicating how an individual should interact with society.
- Professionalism: Conduct, aims, or qualities characterizing a profession or professional person.
AICPA Code of Professional Conduct Framework:

Principles: Broad, aspirational frameworks for professional conduct; ideal attitudes/behaviors (not specifically enforceable).
Rules of Conduct: Minimally acceptable standards of professional conduct (specifically enforceable).
Interpretations: Detailed interpretations explaining specific rules of conduct (departures must be justified).
- Six Principles of Professional Conduct (AICPA):

- Responsibilities: Exercise sensitive professional and moral judgments in all activities.
- Public Interest: Serve the public interest, honor public trust, and demonstrate commitment to professionalism.
- Integrity: Perform all professional responsibilities with the highest sense of integrity.
- Objectivity and Independence: Maintain objectivity and be free of conflicts of interest. Independent in fact and appearance during attestation services.
- Due Care: Observe technical/ethical standards, continuously improve competence, and discharge responsibility to the best of ability.
- Scope and Nature of Services: Observe Code principles when determining scope and nature of services provided.
Key AICPA Rules of Conduct:
- Integrity and Objectivity Rule (1.100.001): Maintain objectivity/integrity, free of conflicts of interest, and do not knowingly misrepresent facts or subordinate judgment.
- Independence Rule (1.200.001): Be independent in performance of professional services as required by designated standards.
- General Standards (1.300.001): Comply with Professional Competence, Due Professional Care, Planning and Supervision, and Sufficient Relevant Data.
- Accounting Principles Rule (1.320.001): Shall not state financial statements conform to GAAP if they contain uncorrected material departures.
- Acts Discreditable Rule (1.400.001): Shall not commit acts discreditable to the profession (e.g., employment discrimination/harassment, disclosing CPA exam questions, failing to file tax returns, negligence in statement preparation, failing to fulfill records requests).
- Contingent Fees Rule (1.510.001): Prohibits contingent fee arrangements for audit/review engagements, prospective financial exams, or tax return preparation.
- Commissions and Referral Fees Rule (1.520.001): Prohibits accepting/paying commissions for clients receiving audit/review services; mandatory disclosure of permitted referral fees.
- Confidential Client Information Rule (1.700.001): Prohibits disclosing confidential client information without consent. 5 Permitted Exceptions:
- To comply with GAAP/GAAS disclosure requirements.
- To comply with a valid subpoena or court order.
- As part of an authorized peer review.
- As part of an official investigative or disciplinary proceeding.
- Reviewing practice in connection with a sale, merger, or purchase.
Independence Provisions and Rules:
- Covered Members Definition: Individuals on attest engagement team; individuals in a position to influence engagement; partners/managers providing >10 hours nonattest services to client annually; partners in lead engagement partner's primary office; the firm/benefit plans; controlled entities.
- Financial Relationships:
- Direct Financial Interest: Ownership or control of entity stock/debt (prohibited for covered members regardless of materiality).
- Material Indirect Interest: Ownership in mutual fund holding client stock (prohibited if material to covered member).
- Unpaid Fees: Unpaid audit fees outstanding for >1 year act as a debt/loan, impairing independence.
- Family Relationships:
- Immediate Family: Spouse, spousal equivalent, dependent (subject to full Independence Rule).
- Close Relatives: Nondependent children, siblings, parents, grandparents, in-laws. Impairs independence if relative holds key/significant position at client or material financial interest known to auditor.
- Actual or Threatened Litigation: Impairs independence if management sues auditor (or vice versa) alleging audit deficiencies or fraud.
SEC and PCAOB Public Company Independence Rules:
- 4 Core Objectivity Principles: Auditor cannot audit own work, function in management role, act as client advocate, or share mutual/conflicting interests.
- 9 Prohibited Non-Audit Services: Bookkeeping; Financial Information Systems Design/Implementation; Appraisal/Valuation/Actuarial; Internal Audit Outsourcing; Management/HR functions; Broker/Dealer/Investment Advisor; Legal Services; Expert Services.
- Partner Rotation: Lead and engagement review partners must rotate off every 5 consecutive years.
- Cooling-Off Period: 1-year cooling-off period required before audit team members can accept key financial reporting roles at client.
Quality Management Standards: Statement on Quality Management Standards (SQMS) No. 1 requires accounting firms to operate risk-based quality management systems ensuring GAAS compliance.
Audit Risk Model and Risk Assessment Process
Audit Risk Model Equations:
- Where .
Definitions of Risk Components:
- Inherent Risk (IR): Susceptibility of an assertion to material misstatement before considering internal controls.
- Control Risk (CR): Risk that an internal control will fail to prevent, or detect and correct, material misstatements on a timely basis.
- Detection Risk (DR): Risk that auditor's procedures will fail to detect existing material misstatements. Divided into Sampling Risk and Nonsampling Risk (inappropriate audit procedures, misinterpreting evidence, failing to recognize misstatements).
- Engagement Risk: Auditor's exposure to financial loss and reputational damage from litigation, adverse publicity, or client business failure.
Inverse Relationship Between RMM and DR:
- High assessed RMM Low planned DR Increased audit procedures and evidence required.
- Low assessed RMM High planned DR Reduced audit procedures and evidence required.
Auditor Risk Assessment Model Combinations:
- Scenario 1: Acceptable AR = Very Low, Assessed RMM = High Planned DR = Low.
- Scenario 2: Acceptable AR = Low, Assessed RMM = Moderate Planned DR = Moderate.
- Scenario 3: Acceptable AR = Low, Assessed RMM = Low Planned DR = High.
Auditor's Risk Assessment Process:

- Risk Assessment Procedures: Management/employee inquiries, analytical procedures, observation, and inspection.
- Understanding Entity & Environment:
- Nature of Entity: Operations, ownership/governance, investment activities, financing structure, financial reporting practices.
- Industry, Regulatory, & External Factors: Market competition, technology shifts, taxation, regulations, interest rates, inflation.

* **Objectives, Strategies, & Related Business Risks:** Identify entity goals and strategy-driven business risks.
* **Entity Performance Measures:** Internal/external key performance indicators (KPIs).
* **Internal Control:** Understand design and operation of internal controls.
- Fraud Risk Assessment and Fraud Triangle:
- Error: Unintentional misstatements.
- Fraud: Intentional misstatements.
- Fraudulent Financial Reporting: Manipulation, falsification, alteration of records, or intentional GAAP misapplication.
- Misappropriation of Assets: Asset theft, embezzling receipts, or paying for unreceived goods/services.
- Fraud Risk Triangle Conditions:
- Incentive / Pressure: Personal financial obligations, aggressive earnings forecasts, threatened financial stability.
- Opportunity: Weak internal controls, ineffective monitoring, complex organizational structure, large cash holdings.
- Attitude / Rationalization: Disregard for controls, unethical tone at the top, overriding controls, lifestyle changes.

- Auditor Response to Assessed Risks:

Financial Statement Level Risks: Pervasive risks Develop overall response (assign experienced staff, increase unpredictability, heighten skepticism).
Assertion Level Risks: Specific account/disclosure risks Design targeted audit procedures.
- Documentation and Communication:
Document: Team discussions, risk identification procedures, identified fraud risks, audit responses, and results.
Communication: Report minor fraud to management level above perpetrators. Report fraud involving senior management or material misstatement directly to the Audit Committee.