Auditing

Section 1: Introduction to Auditing

  1. Purpose of Auditing and Regulatory Agencies
  • AICPA Professional Standards
    • Provide financials statement users with an opinion by auditor on whether the financial statements are presented fairly, in all material respects, in accordance with GAAP, enhance the degree of confidence intended users can place in financial statements
  • Securities and Exchange Commission (SEC)
    • US government agency, 1933, to administer laws and regulations relating to the exchange of securities and the publication of financial information by US businesses.
    • Function of SEC is to protect investors and the public by requiring full disclosure of financial information by companies offering securities for sale to the public
    1. Securities Act of 1933

a. S-1 Registration Statement : company going public (IPO) initial public offering

    1. Securities Exchange Act of 1934

a. 10K : annual report (audit 3 years of income statement & 2 years of balance sheet)

b. 10Q : quarterly report (reviewed by CPA firm)

c. 8K : report companies must file with SEC to announce major events shareholders should know

Acquisition bankruptcy, change of auditor, conflict of interest

    1. Sarbanes - Oxley Act of 2002

a. PCAOB – Public Company Accounting Oversight Board

To oversee the audits of public companies in order to protect the interest of investors and public interest in the preparation of informative, accurate, and independent audit reports

b. Section 404 – requires to test internal controls

    1. Database of SEC filings

a. EDGAR – Electronic Data Gathering, Analysis, and Retrieval system

      • SEC filings: 10K, 10Q, 8K
  1. Types of Audits and Auditors
  2. Type of Audits
  • Financial statement audit : express opinion in accordance with GAAP
    • Audit of financial statement of objectively obtaining and evaluating evidence of an entity
    • Determine whether or not financial statements are fairly stated in accordance with GAAP
    • Independent Auditor’s Report on GAAP Financial Statements
  • Compliance audit : complying with special agreement / requirements
    • Concerned with determining whether or not certain requirements have been met
      • Loan covenants, tax law, contractual agreements
    • Special Report – no standard format for this report (depends on type of audit)
  • Operational audit : if entity is operating efficiency, effectively, economically
    • Determine whether or not a business enterprise is functioning optimally
    • No standard format for this report, depends on type of operational audit
  • Integrated audit : test internal controls & financial statements in accordance of SOX
    • Sarbanes Oxley Act of 2002, a public company must have integrated audit
    • Independent Auditor's Report on GAAP Financial Statements
    • Independent Auditor's Report on Internal Controls Financial Reporting
  1. Type of Auditors
  • Independent Auditors – Certified Public Accountants
    • No financial interest in company audited to evaluate evidence from unbiased perspective
  • Internal Auditors
    • Works for the company benign audited – not independent but still be objective
    • Can help perform audit for third party audit but can't express an opinion
  • Government Auditors
    • Government Accountability Office – investigative arm of congress watchdog
      • Audits other government agencies (DMV, Post Office)
      • Reports directly to congress on the efficiency, effectiveness and compliance of government agencies projects and functions
      • Supports congress in meeting constitutional responsibilities, help improve performance, ensure accountability of federal government for the American people
      • Established by Budget and Accounting Act of 1921 as General Accounting Office
      • Human Capital Reform Act 2004, changed to Governmental Accountability Office
    • Internal Revenue Service
      • IRS is a division of the federal government's Treasury Department and enforces compliance with Internal Revenue Code

Financial Statement Audit & Integrated Audit

Compliance Audit

Operation Aduit

Independent Auditor: CPA firm

Primary

Secondary

Secondary

Internal Auditor

Can assist independent auditor

Primary or Secondary

Primary or Secondary

Governmental Auditor

(GAO or IRS)

Government Auditor:

IRS

Governmental Auditor: GAO

  1. CPA Firm Services & Auditing Standards
  2. CPA Firm Services
  • Attestation Services – to provide assurance as fairness and dependability (must be independent)
  1. Audits
  2. Reviews
  3. Other attestation services
  • Tax Services
  • Consulting Services
  • Accounting and Bookkeeping Services
  1. Auditing Standards –applies to public & nonpublic companies, until 2002 SOX divided responsibility
  • Auditing Standards Board (AICPA – non public companies)
    • AICPA to issue auditing, attesting, quality control statements, standards, guidance to CPAs
    • Statements on Auditing Standards (SAS) – no testing internal control + non public
      • Original SAS number, which is organized by date of issuance
      • An AU number, which is organized by topic
    • Statements on Auditing Standards (GAAS) – audit (GAAP)
    • Statements on Standards for Accounting and Review Services compilation & review
    • Statements on Standards for Attestation Engagements – other attestation engagements
    • Statements on Standard for Tax Services – tax
    • Statements on Standard for Consulting Services – consulting
  • International Auditing Standards – established by the International Auditing and Assurance Standards Board (IAASB) of the International Federation of Accountants (IFAC)
  • Public Company Accounting Oversight Board (PCAOB – public companies)
    • SOX 2002 changed hierarchy of generally accepted auditing standards
    • PCAOB and SEC have final authority over auditing regulation and public auditors professional practices standards for audits of public companies “issuers”
    • Public accountants and firms who audit public companies are required to register with PCAOB and follow all standards, principles, rules to audit, attestation, and quality control
    • Auditing Standards (AS) SOX 2002 created integrated audit for public companies
      • Test and express opinion on internal controls and financial statements
      • Management needs to express and test their own controls
    • Standards for audits, equality control, independence, ethical behavior
    • September 17, 2015 – Securities and Exchange Commission approved the Proposed Rules:
      • General Auditing Standards (AS 1000s) – standards on broad auditing principles, concepts, activities, and communications
      • Audit Procedures (AS 2000s) – standards for planning and performing audit procedures and for obtaining audit evidence
      • Auditor Reporting (AS 3000s) – standards for auditor’s reports
      • Matters Related to Filings under Federal Securities Laws (AS 4000s) – standards on certain auditor responsibilities relating to U.S. Securities and Exchange Commission filings for securities offerings and reviews of interim financial information
      • Other Matters Associated with Audits (AS 6000s) – standards for other work performed in conjunction with an audit of an issuer or of a broker or dealer
  1. Generally Accepted Auditing Standards (GAAS)
  • General standards: personal in nature, concerned with qualification of auditor & quality of work
    • Training and proficiency – audit is to be performed by a person with adequate technical training and proficiency as an auditor
    • Independence – no direct financial interest and no material indirect financial interest
    • Professional care – due diligence of planning and performing audit and preparing report
  • Standards of field work
    • Planning and supervision – plan work before taking action & must be properly supervised
    • Internal controls (ARCCS) – understand internal controls to plan the audit and determine the nature, timings and extent of tests to be performed for order and to prevent fraud
    • Appropriate (competent) evidence – obtained through inspection, observation, injuries, and confirmations to have reasonable basis for an opinion regarding financial statements
      • Section 404: must audit internal controls and test to rely for public companies
  • Standards of reporting
    • Accounting principles in accordance with GAAP – report shall state whether financial statements are presented in accordance with accounting principles
    • No new principles, consistency – report shall identify circumstances in which principles have not been consistently observed in current period in relation to the preceding period
    • Omitted Disclosures, None – informative disclosures in financial statements are to be regarded as reasonably adequate unless otherwise states in the report
    • Express an opinion – expression of opinion regarding financial statements

Steps in Performing An Audit

  • Step 1 – determine that the three general standards have been met
  • Step 2 – understand client’s operation or business and decide whether to enter engagement
  • Step 3 – plan the audit in accordance with the first standard of field work
  • Step 4 – consider the client's internal control in accordance with the second standard of field work
  • Step 5 – perform substantive tests, get competent evidence accordance with standard of field work
  • Step 6 – report on results, issuing an audit report in accordance with the four standards of reporting
  1. Codification of Statements on Auditing Standards, Principles Underlying an Audit Conducted
  • Auditing Standards Board has developed the principles to provide a framework that is helpful in understanding and explaining an audit
  • Principles organized to provide a structure for Codification of Statements on Auditing Standards
  • This structure addresses the:
    • Purpose of an audit (purpose)
    • Personal responsibilities of the auditor (responsibilities)
    • Auditors actions in performing the audit (performance)
    • Reporting (reporting)

Purpose of an Audit and Premise Upon Which an Audit is Conducted

  1. Purpose of an audit is to provide financial statement users with an opinion by the auditor on whether the financial statements are presented fairly in accordance with GAAS
  2. Conducted on the premise that management have responsibility:
  3. For the preparation and fair presentation of the financial statements
      • Design, implementation, maintenance of internal controls and fair presentation of financial statements free from material misstatement (fraud / error)
  4. To provide the auditor with
      • All information: records, documentations, etc relevant to preparation and fair presentation of financial statements
      • Additional information that the auditor may request from management
      • Unrestricted access to those within the entity to obtain audit evidence

Responsibilities

  1. Auditors are responsible for having appropriate competence and capabilities to perform the audit, complying with relevant ethical requirements, and maintain professional skepticism and exercising professional judgment

Performance

  1. Auditor obtains reasonable assurance about whether the financial statements as a whole are free from material misstatements (fraud / error)
    • Plans the work and properly supervises
    • Determines and applies appropriate materiality level through the audit
    • Identified and assessed risk of material misstatement, whether due to fraud or error, based on an understanding of the entity and its environment, including entity’s internal control
    • Obtains sufficient appropriate audit evidence about whether material misstatements exists, through designing and implementing appropriate responses to the assessed risk
  2. Auditor is unable to obtain absolute assurance that the financial statements are free from material misstatement due to inherent limitations
    • Nature of financial reporting
    • Nature of audit procedures
    • Need for audit to be conducted within reasonable period of time

Reporting

  1. Auditor expresses, in the form of a written report, an opinion in accordance with the auditors findings or states that an opinion cannot be expressed
  2. Types of Reports
  • Standard Unmodified / Unqualified Opinion
    • AICPA uses “Unmodified”
    • PCAOB uses “Unqualified”
  • Standard Unmodified / Unqualified Opinion with Emphasis of Matter
    • AICPA uses “Unmodified”
    • PCAOB uses “Unqualified”

For AICPA and PCAOB reports, the following reports opinions are called modified opinions:

  • Qualified Opinion – clean except for the effects of the matter
  • Adverse Opinion – financial statement does not present fairly of financial position
  • Disclaimer of Opinion – unable to gather sufficient competent evidence (fire/flood/management)
  1. AICPA Code of Professional Conduct

Provide guidance and rules to all members in public practice, in industry, in government, in education

Code of Professional Conduct of the American Institute of Certified Public Accountants consist of:

  1. The Principles (framework for the rules)
    1. Responsibilities – professional and moral judgements
    2. The public interest – commitment to professionalism
    3. Integrity – highest sense of integrity
    4. Objectivity and independence – objectivity and be free of conflicts of interest
    5. Due care – profession’s technical and ethical standards
    6. Scope and nature of services – principles of the code of professional conduct
  2. The Rules
    1. 100 Integrity and Objectivity – maintain objectivity and integrity
    2. 200 Independence – shall be independent in the performance of professional services
      1. Covered member: on attest engagement team, position to influence, partner, firm
        1. Had or committed to acquire direct or material indirect financial interest
        2. Was a trustee of any trust or executor or administrator of any estate, acquire more than 10% of the clients outstanding equity securities
        3. Had a joint closely held investment
        4. Had any loan to or from the client
          1. Permitted loans:

Automobile loans and leases collateralized by automobile

Loans fully collateralized by the cash surrender value of an insurance policy

Loans fully collateralized by cash deposits at the same financial institution (passbook loan)

Aggregate outstanding balances from credit cards reduces to $10,000 or less on a current basis

      1. A partner or professional employee of the firm, their immediate family owned more than 5% of clients outstanding equity securities
      2. During the period covered by the financial statements or during the period of the professional engagement, a firm or partner or professional employee of the firm was simultaneously associated with the client as a(n)
        1. Director, officer, employee
        2. Promoter, underwriter, voting trustee
        3. Trustee for any pension or profit sharing trust of the client

Who is required to be Independent ?

Work on the audit

Work in the same office

Work in a different office

Partners

Yes

Yes

Unless in a position to influence

Managers

Yes

Unless in a position to influence

Unless in a position to influence

Non-Managers

(Seniors & Staff)

Yes

Unless in a position to influence

Unless in a position to influence

  1. Independence of mind
    1. State of mind that permits the performance of an attest service without being affected by influences that compromise professional judgment, allowing individual to act with integrity and exercise objectivity and professional skepticism
  2. Independence in appearance
    1. Avoidance of circumstances that would cause a reasonable and informed third party having knowledge of all relevant information of a firm or a member of the attest engagement team has been compromised

Threats to independence are circumstance that could impair independence

  • Adverse interest threat – commence litigation
  • Advocacy threat – initial public offering or witness services
  • Familiarity threat – partner or equivalent of the firm as member of attest engagement for too long
  • Management participation threat – member serves as officer or director of the attest client
  • Self interest threat – member could benefit financial or otherwise, from an interest in client
  • Self review threat – member will not appropriately evaluate results of previous judgments made
  • Undue influence threat – subordinate judgment to individual associated with an attest client due to one's reputation or expertise, aggressive or dominant personality or attempts to coerce or exercise excessive influence over the member
    1. 300 General Standards
      1. Professional competence (training & proficiency)
      2. Due professional care (professional care)
      3. Planning and supervision (planning & supervision)
      4. Sufficient relevant data (competent evidence)
    2. 310 Compliance with Standards – various services shall comply with its own standards
    3. 320 Accounting Principles
      1. (1) member shall not express an opinion or state that statements or data are presented in conformity with generally accepted accounting principles
      2. (2) State that they are not aware of any material modification that should be made to statements or data in order for them to be in conformity with generally accepted accounting principles
    4. 400 Acts Discreditable – acts discreditable to the professional (civil actions)
    5. 500 Fees and Other Types of Remuneration
      1. Contingent fees – fee for outcome of duties and opinion
        1. Perform for a contingent fee any professional services (audit or review)
        2. Prepare an original or amended tax return or claim for a tax refund for a contingent fee for any client
      2. Commissions and referral fees – cannot perform duties for commission $$
        1. An audit or review of a financial statement
        2. A compilation of a financial statement
        3. An examination of prospective financial information
    6. 600 Advertising and Other Forms of Solicitation
      1. Shall not seek clients by advertising or solicitation (coercion, overreaching, harassing) in a manner that is false, misleading, or deceptive
    7. 700 Confidential Client Information – no discussion of info without consent unless:
      1. To relieve a member of their professional obligations of the “compliance with standards rule” or the “accounting principles rule”
      2. To affect members obligation to comply with subpoena or summons
      3. To prohibit review of members professional practice under AICPA or CPA society
      4. To preclude a member from their duty of constituted investigation
    8. 800 Form of Organization and Name – cannot be misleading
      1. Names of one + past owners may be included in firm name of successor
      2. Jones & Jones : 2 people working (dad dies); 2 years name cannot be misleading
  1. Quality Control

Set of policies and procedures established by a CPA firm to ensure conformity with professionals standards. Quality control standards apply to the firm overall – everything the CPA firm does

Policies and Procedures:

  1. Leadership responsibilities for quality within the firm (tone at the top)
    1. Establish policies and procedures to promote an internal culture based on recognition that quality is esstain in performing engagements
  2. Relevant ethical requirements
    1. Personnel should maintain independence, in fact and appearance, firm should establish policies and procedures to ensure that the firm and its personnel maintain independence
  3. Acceptance and continuance of client relationship and specific engagements
    1. Selective engagements, a client whose management lacks integrity is minimized
    2. Firm should be competent to perform engagement and have capabilities (time & resources)
  4. Human resources
    1. Encompasses hiring, assigning personnel to engagements, professional development, advancement activities. Quality of firm’s work depends on the integrity, objectivity, intelligence, competence, experience, motivation of personnel who perform, supervise and review the work
  5. Engagement performance
    1. Encompasses planning, supervising, reviewing, documenting, and communicating the results of each engagement to meet professional standards, regulatory requirements, and firm’s quality.
  6. Monitoring
    1. Evaluate whether elements of quality control of designed and being applied effectively

Section 2: Step One

  1. General standards
  2. Training and proficiency – audit is to be performed by a person with adequate technical training and proficiency as an auditor
  3. Independence – no direct financial interest and no material indirect financial interest
    1. Independence: both in fact and in appearance; act with integrity
  4. Professional care – due diligence and responsibilities of planning and performing audit and preparation of the report
    1. Clarified Statements on Auditing Standards AU-C 200, professional care is replaced by:
      1. Professional judgment: application of relevant training, knowledge, experience
      2. Professional skepticism: an attitude with a questioning mind
    2. GAAS require that the auditor exercise professional judgment and maintain professional skepticism throughout the planning and performance of the audit
      1. Identify and assess risks of material misstatement
      2. Obtain sufficient appropriate audit evidence
      3. Form an opinion on the financial statements

Section 3: Step Two

  1. Obtain an understanding of the clients operations and business and industry
  2. Consideration of Financial Statements: auditor should obtain and review financial information
  3. Communication with Third Parties: auditor should inquire attorneys/creditors of client and mgmt
  4. Communication with Predecessor Auditor
    1. Predecessor auditor: auditor who has resigned
    2. Successor auditor: auditor who has accepted / invited to an engagement
      1. Disagreements the predecessor had with management as to auditing
      2. Understanding as to the reason for the change of auditors
      3. Integrity of management
  5. Consideration of Managements Integrity: should not associate with clients that lack integrity
  6. Decide whether to enter into the engagement with the client
  7. Evaluate Information Obtained to Understand the Client
    1. Determine whether or not auditor is willing to perform the audit
    2. If auditor decides to accept engagement, they must communicate with the audit committee
  8. Communication with Audit Committee
    1. Audit committee: sub-committee of the Board of Directors with duties of:
      1. Hiring the independent auditor
      2. Reviewing the plan for the audit
      3. Reviewing audit results and financial statements
      4. Overseeing the adequacy of the internal control system
    2. Communication with the Audit Committee Before the Audit
      1. To establish timing, fees, responsibilities of both parties and overall audit plan
      2. Once agreed upon, an engagement letter is prepared
    3. Communication with the Audit Committee During and After the Audit
      1. Communication concerning the audit:
        1. Significant accounting policies or their application
        2. Sensitive accounting estimates
        3. Significant audit adjustment
        4. Disagreements with management
      2. Communication concerning errors, fraud, and illegal acts:
        1. Significant errors, irregularities, illegal acts
      3. Communication concerning internal controls:
        1. Significant deficiencies in the design or operation of the internal controls
          1. Storonger audit committee & more involved post SOX (active role)
  9. Engagement Letter
    1. Clear understanding with client regarding the nature of the services to be performed in auditing the financial statements and the responsibilities assumed include:
      1. Auditor’s responsibilities
        1. Perform the audit
        2. Express an opinion
      2. Management responsibilities
        1. Preparation and fair presentation of the financial statements
        2. Implementation and maintenance of internal controls
        3. Provide auditor with access to all information (records & documentation)
    2. Contents of the engagement may also include fees and other work

Section 4: Step Three

First Standard of Field Work: Auditor must adequately plan the work and must properly supervise any assistants

  1. Considerations in Planning the Audit
  • Matters relating to the entities business and the industry in which it operates
  • The entity’s accounting policies, procedures, methods used to process accounting information
  • Planned assessed level of control risk
  • Preliminary judgment about materiality levels
  • Financial statement items likely to require adjustments
  • Nature of reports expected to be issues
  1. Planning Procedures
  • Reviewing files, prior years workpapers, permanent files, financial statements, reports
  • Discussing matters that affect auditor with firm personnel responsibilities for non-audit services
  • Inquiring about current business developments affecting the entity
  • Reading the current year's interim financial statements
  • Discussing the type, scope, and timing of the audit with management, board of directors, committee
  • Considering the effects of applicable accounting and auditing pronouncement, especially new ones
  • Coordinating the assistance of entity personnel in data preparation
  • Determining the extent involvement of consultants, specialists and the client's internal auditor
  • Establishing the timing of the audit work and coordinating staffing requirements
  1. Materiality and Audit Risk in Conducting the Audit
  • Audit risk and materiality affect the application of generally accepted auditing standards, especially in the standards of fieldwork and reporting
    • Consider when planning the audit and designing auditing procedures
    • Consider when evaluating whether the financial statements taken as a whole are presented fairly, in all material respects, in conformity with GAAP
  • Both materiality and suit risk are reflected in the auditor’s report
    • Auditor’s “reasonable assurance” financial statements are free of material misstatement
    • “Present fairly, in all material respects” belief financial statements not materially misstated
  1. Materiality
  • Considered material if it impacts decision maker’s economic decision based on financial statements
  • Previous AICPA Guidelines:
    • 5 - 10% of Pretax Net Income
    • 0.5 - 1.5% of the larger of Total Assets or Total Revenues
  • Current AICPA Guidelines: based on auditors judgment
  1. Audit Risk
  • Risk auditor express inappropriate audit opinion when financial statements are materially misstated
  • Risk of material misstatement: risk that the financial statements are materially misstated prior to the audit, is comprised on inherent risk and control risk
    • Inherent risk: innate risk of the industry (some clients are more risky than others)
    • Control risk: based by the entity’s internal control structure policies or procedures
    • Detection risk: based on the procedures performed by the auditor to reduce audit risk
  1. Auditor's Responsibility to Detect and Report Errors, Fraud & Illegal Acts
  2. Definition of Errors, Fraud, & Illegal Acts
    1. Errors: unintentional misstatements of amounts or disclosures in financial statement
      1. Mistake in gathering or processing accounting data from f/s prepared
      2. Incorrect accounting estimates arising from oversight or misinterpretation of facts
      3. Mistakes in the application of accounting principles relating to amount, classification, manner of presentation or disclosure
    2. Fraud: intentional misstatements of amounts or disclosures in financial statement
      1. Fraudulent financial reporting: deceiving financial statement users through intentional misstatements/omissions of amounts or disclosures
        1. Manipulation, falsification, alteration of accounting records and documents
        2. Misrepresentation of transaction or significant information
        3. Intentional misapplication of accounting principles relating to amounts
      2. Misappropriation of assets: involve theft where the effect causes financial statements to be materially misstated or false and misleading records or documents
        1. Embezzlement
        2. Stealing
        3. Causing payment for goods or services not rendered
  3. Fraud Risk Factors
    1. Incentive / pressure: a reason to commit fraud
    2. Opportunity: e.g., ineffective controls, override of controls
    3. Attitude / rationalization: ability to justify the fraud to oneself
  4. Example of Fraud Risk Factors
    1. Misstatements Arising from Fraudulent Financial Reporting
      1. Incentive / pressure
        1. Threaten financial stability or profitability
        2. Excessive pressure on management to meet required expectations
        3. Management or directors’ financial situation threatened
        4. Excessive pressure to meet financial target by directors or management
      2. Opportunity
        1. Industry provides opportunities
        2. Ineffective monitoring of management
        3. Complex or unstable organizational structure
        4. Internal control deficient
      3. Attitude / rationalization
        1. Relating to board members, management or employees
    2. Misstatements Arising from Misappropriation of Assets
      1. Incentive / pressure
        1. Employees with personal financial obligations
        2. Adverse relationship between company and employee
      2. Opportunity
        1. Characteristics of assets
        2. Inadequate internal control
      3. Attitude / rationalization
        1. Attitude of those with access to assets susceptible to misappropriation
  5. Auditor's Responsibility to Detect and Report Illegal Acts
    1. Refers to violations of laws or government regulations
      1. Direct Effect Illegal Acts: auditor's responsibility to detect and report illegal acts with a direct and material effect on the determination of financial statement
        1. tax laws affect accruals and amount recognized as expense in period
      2. Indirect Effect Illegal Acts: related to the safety and health, environmental protection and antitrust violation with an indirect effect
    2. Audit procedures in response to possible illegal acts
      1. Auditor obtain understanding of acts nature to evaluate effect on f/s
    3. Effect on the auditor report
      1. If the auditor concludes that an illegal act has material effect on the financial statements, auditor should express a qualified opinion or an adverse opinion
    4. Auditor responsibility
      1. Auditor should design the audit to provide reasonable assurance of detecting errors and fraud that are material to the financial statements

Assurance Provided by Auditor

Immaterial

Material

Errors

No assurance

Reasonable assurance

Fraud

No assurance

Reasonable assurance

Illegal acts (direct)

No assurance

Reasonable assurance

Illegal acts (indirect)

No assurance

No assurance

  1. Other Planning Considerations
  2. Reasonable Assurance: is a high, but not absolute, level of assurance
  3. Professional Skepticism: questioning mind, be alert to conditions of fraud/error, critically assess
  4. Auditor Judgement: application of relevant training, knowledge, and experience provided by auditing, accounting, and ethical standards to make informed decisions about the course of action
  5. Audit documentation (working papers)
    1. Purpose of documentation
      1. Auditor should prepare and maintain audit documentation
      2. Constitutes the principal record of the working that auditor has done and the conclusions reached concerning significant matters
        1. Sufficient and appropriate record of the abscess for the auditor report
        2. Evidence that the audit was planned and performed in accordance with GAAS and applicable legal and regulatory requirements
    2. Audit files
      1. Permanent file (> 1 year): articles of incorporation, lease, loan, pension, minutes
      2. Current file (< 1 year): inventory country, bank reconciliation, etc
    3. Audit documentation and retention
      1. Audit documentation should be finalized in 60 days after release of the report
      2. Audit documentation should be retained for no less than 5 years
  6. Timing of the Audit: federal securities laws require publicly traded companies to disclose information on an ongoing basis (larger companies have shorter filing periods)
  7. Strategic Plan: Contents of Strategic Plan
    1. Introduction
    2. Contractual understanding
      1. Objective (audit to express an opinion)
      2. Product expected
    3. Current year development
      1. Change in business
      2. Any new contracts
      3. Sale or purchase of a subsidiary
    4. Accounting policies and procedures
      1. Inventory
      2. Fixed assets – depreciation
      3. Foreign currency transitions
      4. Leases – capital or operating pension costs
      5. Deferred taxes
      6. New FASB’s – when they intend to comply
    5. Business and inherent risk
      1. Discuss natural of industry and relative risk
      2. Stability of the industry
      3. Market size, growth potential, competition
      4. Stability of the client with respect to the industry
    6. Control risk
      1. Control activities
      2. Risk assessment
      3. Information and communication monitoring
      4. Control environment
    7. Analytical review
      1. Establish and justify a materiality for analysis ($ & % change)
      2. Discuss reasons for fluctuations from prior year numbers (difference of current to prior)
    8. Other planning consideration
      1. Key audit dates
      2. Involvement of auditor’s tax and other departments
      3. Scope and materiality
      4. Budget
    9. Other issues
      1. Pending litigation
      2. Other items

Section 5: Step Four

Second Standard of Field Work: Auditor must obtain a sufficient understanding of the entity and its environment, including its internal control, to access the risk of material misstatement of the financial statements whether due to error or fraud, and to design the nature, timing and extent of further audit procedures

  1. Committee of Sponsoring Organizations of the Treadway Commission (COSO)
  • US private sector initiative, formed in 1985
  • Committee of Internal Controls
    • American Institute of Certified Public Accountants (AICPA)
    • American Accounting Association (AAA)
    • Financial Executives Institute (FEI)
    • The Institute of Internal Auditors (IIA)
    • The Institute of Management Accountants (IMA)
  • Major objective – to identify factors that cause fraudulent financial reporting and to make recommendations to reduce its incidence
  • In 1992, COSO published internal control – integrated framework
  • In May 2013, COSO issued the updated internal control – integrated framework to make it more relevant in the current business environment
  • Objectives on Internal Controls (ASAP)
  1. To ensure accurate, reliable financial statements (GAAP)
  2. To safeguard assets
  3. To ensure that management and the company adhere to laws and regulations
  4. To promote operational efficiency
  5. COSO Framework: Internal Control Components (CRIME ~ PIPS ~ ARCCS)
  • Control Activities (PIPS): to have good strong internal controls
    • Performance Reviews
    • Information Processing
    • Physical controls / safeguarding of assets
    • Segregation of duties (ARCCS)
      • Authorization
      • Recording
      • Custody / Safeguarding
      • Comparison
  • Risk Assessment: assess and mitigate risk (increase assess risk to decrease risk)
    • Properly training when hiring new employees & new computer systems
  • Information and Communication: understand and evaluate internal control
    • Evaluate clients computer system (beginner to advanced)
    • Understand how systems are implemented for accounting software
    • Communications with who has access to the system (payroll, etc)
  • Monitoring: monitoring rules with organization
    • Can not simply trust employee: need to verify & monitor employees
  • Control Environment: tone at the top (top management internal controls)
    • Ethical & moral behavior at the company
    • Monitoring the internal controls
  1. Steps to Understanding Internal Controls

Step 1: Obtain an understanding of the design of internal controls (talk to mgmt – CRIME & ask questions)

Step 2: Document your understanding

  • Memorandum / Narrative
  • Flow Chart
  • Internal Control Questionnaire (ICQ) – yes or no (strengths and weaknesses)

Step 3: Assess Control Risk

  • Inherent risk – No one
  • Control risk – management (internal controls: errors, fraud, illegal acts)
  • Detection risk – auditor (testing & evidence)

Step 4: Perform tests of controls (RIIO) – can we rely on internal controls?

  • Reperform
  • Inspect
  • Inquire
  • Observe

Step 5: [Reassess Control Risk] & Set Detection Risk

  • If internal controls are reliable, skip reassessment
    • SOX 404 (public company) must test & express opinion on internal controls (6 steps)
  • If rely on internal controls, must justify and test

Step 6: Document Conclusions

  1. Approaches to performing an Audit
  • Reliance approach
    • Auditor test controls & determine that they can rely on internal controls
    • As a result, auditor will do less substantive testing
  • Substantive approach
    • Auditor are not relying on internal controls
    • As a result, auditor will do more substantive testing

Three Different Possibilities (non publicly traded company)

Approach

Management's description of internal controls

ASSESS control risk

Results of internal control tests

SET detection risk

Substantive tests

Reliance

strong

low

strong

high

less

Substantive

weak

high

Don't test I/C

low

more

Hybrid

strong

low

weak

Reassess control risk → high

Set detection risk → low

more

Auditor’s Documentation and Procedure Requirements

Reliance Approach

assess control risk below max level

Substantive Approach

assess control risk at max level

Document understanding of entity’s internal control

Required

Required

Document basis for conclusion concerning control risk

Required

“If you rely, you must justify”

Not required

Perform test of controls to determine effectiveness of policies and procedures

Yes

No

Substantive Testing

Yes, but limited if determine auditor can rely on internal control

Yes

  • SOX 404: financial statements are impacted by internal controls
    • Have to test internal controls to find weakness linked to financial statements
  1. Limitations to Internal Controls
    1. Human error
    2. Management override
    3. Collusion: two or more people working together to perpetrate fraud
    4. Cost / Benefit Tradeoff: if internal controls are too strong & impact the ability to perform work
  2. Significant Deficiencies and Material Weaknesses
  • Deficiency in Internal Control: exists when the design or operation of a control to prevent or detect and correct misstatements on a timely basis
    • Deficiency in design: when (a) a control is missing (b) not properly designed
    • Deficiency in operation: does not operate as designed
  • Significant Deficiency: less severe than material weakness yet important enough to bring attention
  • Material Weakness: a reasonable possibility that a material misstatement of the entity's financial statements will not be prevented or detected and corrected on a timely basis
  1. Sarbanes Oxley Act of 2002 – Section 404
  • Using a Top-Down Approach (largest risk / asset)
    • Auditor should use a top-down approach to the audit of internal control
    • Beings at the financial statement level and with the auditor's understanding of the overall risks to internal control over financial reporting
    • Reasonable possibility of martial misstatement to the financial statements
  • Identifying Entity-Level Controls
    • Auditor must test those entity-level controls that are important to auditors conclusion about whether the company has effective internal control over financial reporting
  • Identifying Significant Accounts and Disclosures and Their Relevant Assertions
    • Auditor should identify significant accounts and disclosures and their relevant assertions (financial statement assertions have a reasonable possibility of containing a misstatement)
  • Understanding Likely Sources of Misstatement
    • Understand the flow of transaction related to relevant assertions
      • How transactions are initiated, authorized, processed, and recorded
    • Identify points of company’s processes where misstatement could arise would be material
    • Identify controls that management has implements to address potential misstatements
    • Identify controls that management has implemented to prevent or timely detection unauthorized acquisition, use or disposition of company's assets that could result in material misstatement
  • Selecting Controls to Test
    • Auditor should test controls that are important to conclusion about whether the company’s controls sufficiently address the assessed risk of misstatement to each relevant assertion
  • Testing and Evaluating the Effectiveness of the Design of Controls
  • Testing Operating Effectiveness
  • Evaluating the Results of Testing
    • Significant deficiency should be classified as material weakness if, by itself or in combination with other control deficiencies, result in more than a remote likelihood of material misstatement
  • Forming an opinion and Reporting
    • Combined report: containing both an opinion on the financial statement and an opinion on internal controls over financial reporting
    • Separate report on financial statement and internal controls over financial reporting
  • No Disclosure of Significant Deficiencies
    • Section 404 require management’s assessment to disclose only material weakness, not significant deficiencies
  • Material Weakness Result in Adverse Opinion on Internal Control
  1. The Accounting Cycle

Business Transaction →

Business Document

Journal Entry →

  1. Sales
  2. Cash Receipts
  3. Purchases
  4. Cash Disbursements
  5. General

Ledgers

  1. General
  2. Accounts Receivable Subledger
  3. Accounts Payable Subledger

Trial Balance →

Adjustments

Adjusted Trial Balance →

Financial Statements

  1. Income Statement
  2. Statement of Owner's Equity
  3. Balance Sheet
  4. Statement of Cash Flow
  5. Notes
  1. The Five Internal Control Cycles
  2. Revenue Cycle
    1. Authorizing sales on account and authorizing credits to accounts receivable
    2. Authorizing sales, recording accounts receivable and having custody of inventory
    3. Cashier, cash receipts, and preparing bank reconciliation should be separate
    4. Authorizing sales and bad debt write offs
  3. Purchases and Spending Cycle
    1. Authorizing purchases, receiving goods and recording the purchase
    2. Authorizing new vendors and authorizing purchases
    3. Cash functions of authorizing payments, recording payments, access to checks and reconciliation of the bank account
    4. Individuals who approve vouchers for payments should not have access to unused purchased orders
  4. Personnel and Payroll Cycle
    1. Function of authorizing the hiring of personnel, payroll processing (recording) and distributing payroll checks (custody)
    2. Function of authorizing payroll rate changes and payroll processing (recording)
    3. Payroll checks should be prepared by the payroll department and signed by the treasurer, segregating recording and custody
  5. Conversion Cycle
  6. Investing & Financial Cycle

Key Controls

  1. Authorization
  2. Record
  3. Custody
  4. Comparison
  5. Segregation of Duties

Key Documents

  1. Pre-printed, pre-numbered, numerically numbered?
  2. Who (internally & externally) obtain or retain a copy of doc?
  3. What information should be in the document?