Understanding Audit Risk Assessment Objectives of

Published  . 0 views
↓ Download
Understanding Audit Risk Assessment Objectives of
1 / 1
Understanding Audit Risk Assessment Objectives of - slide 1 of 61 Understanding Audit Risk Assessment Objectives of - slide 2 of 61 Understanding Audit Risk Assessment Objectives of - slide 3 of 61 Understanding Audit Risk Assessment Objectives of - slide 4 of 61 Understanding Audit Risk Assessment Objectives of - slide 5 of 61 Understanding Audit Risk Assessment Objectives of - slide 6 of 61 Understanding Audit Risk Assessment Objectives of - slide 7 of 61 Understanding Audit Risk Assessment Objectives of - slide 8 of 61 Understanding Audit Risk Assessment Objectives of - slide 9 of 61 Understanding Audit Risk Assessment Objectives of - slide 10 of 61 Understanding Audit Risk Assessment Objectives of - slide 11 of 61 Understanding Audit Risk Assessment Objectives of - slide 12 of 61 Understanding Audit Risk Assessment Objectives of - slide 13 of 61 Understanding Audit Risk Assessment Objectives of - slide 14 of 61 Understanding Audit Risk Assessment Objectives of - slide 15 of 61 Understanding Audit Risk Assessment Objectives of - slide 16 of 61 Understanding Audit Risk Assessment Objectives of - slide 17 of 61 Understanding Audit Risk Assessment Objectives of - slide 18 of 61 Understanding Audit Risk Assessment Objectives of - slide 19 of 61 Understanding Audit Risk Assessment Objectives of - slide 20 of 61 Understanding Audit Risk Assessment Objectives of - slide 21 of 61 Understanding Audit Risk Assessment Objectives of - slide 22 of 61 Understanding Audit Risk Assessment Objectives of - slide 23 of 61 Understanding Audit Risk Assessment Objectives of - slide 24 of 61 Understanding Audit Risk Assessment Objectives of - slide 25 of 61 Understanding Audit Risk Assessment Objectives of - slide 26 of 61 Understanding Audit Risk Assessment Objectives of - slide 27 of 61 Understanding Audit Risk Assessment Objectives of - slide 28 of 61 Understanding Audit Risk Assessment Objectives of - slide 29 of 61 Understanding Audit Risk Assessment Objectives of - slide 30 of 61 Understanding Audit Risk Assessment Objectives of - slide 31 of 61 Understanding Audit Risk Assessment Objectives of - slide 32 of 61 Understanding Audit Risk Assessment Objectives of - slide 33 of 61 Understanding Audit Risk Assessment Objectives of - slide 34 of 61 Understanding Audit Risk Assessment Objectives of - slide 35 of 61 Understanding Audit Risk Assessment Objectives of - slide 36 of 61 Understanding Audit Risk Assessment Objectives of - slide 37 of 61 Understanding Audit Risk Assessment Objectives of - slide 38 of 61 Understanding Audit Risk Assessment Objectives of - slide 39 of 61 Understanding Audit Risk Assessment Objectives of - slide 40 of 61 Understanding Audit Risk Assessment Objectives of - slide 41 of 61 Understanding Audit Risk Assessment Objectives of - slide 42 of 61 Understanding Audit Risk Assessment Objectives of - slide 43 of 61 Understanding Audit Risk Assessment Objectives of - slide 44 of 61 Understanding Audit Risk Assessment Objectives of - slide 45 of 61 Understanding Audit Risk Assessment Objectives of - slide 46 of 61 Understanding Audit Risk Assessment Objectives of - slide 47 of 61 Understanding Audit Risk Assessment Objectives of - slide 48 of 61 Understanding Audit Risk Assessment Objectives of - slide 49 of 61 Understanding Audit Risk Assessment Objectives of - slide 50 of 61 Understanding Audit Risk Assessment Objectives of - slide 51 of 61 Understanding Audit Risk Assessment Objectives of - slide 52 of 61 Understanding Audit Risk Assessment Objectives of - slide 53 of 61 Understanding Audit Risk Assessment Objectives of - slide 54 of 61 Understanding Audit Risk Assessment Objectives of - slide 55 of 61 Understanding Audit Risk Assessment Objectives of - slide 56 of 61 Understanding Audit Risk Assessment Objectives of - slide 57 of 61 Understanding Audit Risk Assessment Objectives of - slide 58 of 61 Understanding Audit Risk Assessment Objectives of - slide 59 of 61 Understanding Audit Risk Assessment Objectives of - slide 60 of 61 Understanding Audit Risk Assessment Objectives of - slide 61 of 61
Description: Understanding Audit Risk Assessment Objectives of This Course: Outline the PPC audit risk assessment process Understand how to use PPC practice aids to perform and document risk assessment What is Risk Assessment? Risk Assessment Obtain an

Related Topics

Download Presentation

"Understanding Audit Risk Assessment Objectives of" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Understanding Audit Risk Assessment<br>
slide2. Objectives of This Course: Outline the PPC audit risk assessment process
Understand how to use PPC practice aids to perform and document risk assessment<br>
slide3. What is Risk Assessment? Risk Assessment
Obtain an understanding of the client, including internal control
Identify and assess risks of material misstatement of the financial statements, whether due to error or fraud
Evaluate both overall risks and risks that affect only specific assertions Linkage Audit Procedures

Concentrate audit effort in high risk areas
Inherent risk
Control risk
Perform less extensive procedures in low risk areas<br>
slide4. PPC Audit Approach<br>
slide5. Preliminary Engagement Activities<br>
slide6. Client Acceptance/Continuance Consider: Nature and purpose of engagement
Preconditions for an audit
Client’s reputation, integrity, and competence
Communication with predecessor
Compliance with ethical requirements, including independence
Adequacy of accounting records
Firm resources and competence
Engagement economics
Other risk concerns Document CX-1.1: “Engagement Acceptance and Continuance Form”
CX-1.2: “Engagement Independence Compliance and Nonattest Services Documentation Form”
CX-7.1: “Risk Assessment Summary Form” (if risks are identified)<br>
slide7. Establish an Understanding with the Client Establish an understanding about:
Objectives of the engagement
Auditor’s services to be performed, including nonattest services
Management’s responsibilities
Auditor’s responsibilities
Limitations of the engagement
Communicate the understanding in a written engagement letter
CL-1.1: “Audit Engagement Letter”<br>
slide8. Planning and Risk Assessment Procedures<br>
slide9. Engagement Team Discussion Susceptibility of the financial statements to material misstatement, including material misstatement due to fraud or error that could result from the related party relationships
Application of GAAP to the entity’s facts and circumstances in light of its accounting policies
Fraud-related matters
Include:
Critical issues and areas of significant audit risk
Areas susceptible to management override of controls
Unusual accounting practices
Important control systems
Significant IT applications and how IT may affect the audit
Materiality considerations
Need to exercise professional skepticism
Business risks<br>
slide10. Engagement Team Discussion (cont.) Attendance:
Engagement partner
Key members of engagement team
Document:
How and when the discussion occurred, who participated, and decisions about planned responses
CX-3.2: “Engagement Team Discussion”
CX-7.1: “Risk Assessment Summary Form” (if risks are identified)<br>
slide11. Materiality Materiality for the financial statements as a whole
Materiality for particular items of lesser amounts
Performance materiality
Component materiality (group audits only)<br>
slide12. Materiality (cont.) Apply professional judgment
Consider decisions that users make
Use appropriate benchmarks, such as % of assets or revenue
Re-evaluate materiality as the audit progresses. If lower, reconsider:
Level of performance materiality
Adequacy of procedures<br>
slide13. Materiality (cont…) Document:
Materiality at the financial statement level
If applicable, materiality level(s) for particular transaction classes, account balances, or disclosures
Performance materiality
Factors considered in their determination
Any revisions made during the audit
The amount below which misstatements would be considered clearly trivial
CX-2: “Financial Statement Materiality Worksheet for Planning Purposes”
CX-3.5: “Analysis of Group Components and Determination of Component Materiality”<br>
slide14. Risk Assessment Two categories of audit procedures:
Risk assessment procedures
Further audit procedures Both Provide Audit Evidence Risk Assessment Procedures Further
Audit Procedures<br>
slide15. Risk Assessment Procedures Diagram<br>
slide16. Risk Assessment Procedures (cont…) Performed to obtain an understanding of the entity and its environment, including internal control, for the purpose of assessing risks
All of the procedures should be performed
Inquiry alone is not sufficient to understand internal control
Provide audit evidence<br>
slide17. Inquiries Management
Internal audit (if such a function exists)
Other employees
External parties (maybe)<br>
slide18. Required Inquiries Inquire about:
Entity and its environment
Fraud-related matters
Related parties
Accounting estimates
Compliance with laws and regulations
Service organizations
Document the inquiries:
CX-3.3, “Fraud Risk Inquiries Form”
CX-7.1, “Risk Assessment Summary Form” (if risks are identified)<br>
slide19. Observation and Inspection Inspect documents and records
Read management and internal reports and minutes
Read external information
Visit premises and plant facilities
Trace transactions through the system (walkthroughs)<br>
slide20. Analytical Procedures Preliminary analytical procedures
Analytical procedures related to revenue required by AU-C 240
To enhance understanding of the business and identify potential risk areas
Documented by completing a step on AP-1: “Audit Program for General Planning Procedures”
Add risks to CX-7.1: “Risk Assessment Summary Form”<br>
slide21. Risk Assessment Procedures Document the procedures performed
AU-C 230 provides guidance on documenting procedures
For inquiries, document the date, name, and title of individual, inquiry, and response
For observation, document what was observed, where, when, and entity personnel involved
For inspection, document the identifying characteristics, for example, document name or number and date<br>
slide22. Understanding the Entity and Its Environment Perform risk assessment procedures (inquiry, analytics, observation, and inspection) to gather information about:
Industry, regulatory, and other external factors
Nature of the entity
Objectives, strategies, and related business risks
Measurement and review of the entity’s financial performance
Selection and application of accounting policies
Internal control<br>
slide23. Understanding the Entity and Its Environment (cont) Obtain an understanding of the client’s selection and application of accounting policies
Are accounting policies appropriate for the entity and consistent with the industry?
Are there any changes in accounting policies? 23<br>
slide24. Understanding the Entity and Its Environment (cont.) Consider the presence of fraud risk factors
Update information obtained in prior years by performing risk assessment procedures to determine if the information has changed<br>
slide25. Using the PPC Approach CX-3.1: “Understanding the Entity and Identifying Risks”
Key elements of the understanding
The consideration of fraud risk factors
Sources of information
Risk assessment procedures performed
CX-7.1: “Risk Assessment Summary Form”
CX-6.1: “Entity Risk Factors” and CX-6.2: “Fraud Risk Factors” (memory joggers) 25<br>
slide26. Understanding Internal Control Diagram 26<br>
slide27. Understanding Internal Control Understand design and implementation
Perform inquiry, observation, and inspection
Inquiry alone is not sufficient to understand the design and implementation of controls 27<br>
slide28. Understanding Internal Control (cont.) Evaluate the design and implementation of controls—
Related to significant risks
Related to risks that cannot be tested effectively using substantive procedures alone
Understand—
How the incorrect processing of transactions is resolved
How detail is reconciled to the general ledger for material accounts 28<br>
slide29. Understanding Internal Control (cont) Document the following:
Understanding of internal control components
Sources of information
Procedures performed
Controls evaluated related to significant risks and risks for which substantive procedures alone are not effective<br>
slide30. The PPC Approach Entity-level controls
Control environment
Risk assessment
Information and communication
Monitoring
Activity-level controls
Financial reporting system
Control activities
IT environment and general IT controls<br>
slide31. Using the PPC Approach (cont) CX-4.1: “Understanding the Design and Implementation of Internal Control”
Evaluate entity-level controls
Identify significant transaction classes
CX-4.2.1: “Financial Reporting System Documentation Form—Significant Transaction Classes”
Document the processing of transactions for each significant transaction class
Document the financial close and reporting process<br>
slide32. Using the PPC Approach (cont…) CX-4.2.2: “Financial Reporting System Documentation Form—IT Environment and General IT Controls”
Understand the effect of IT
CX-4.3.1: “Walkthrough Documentation Memo” or CX-4.3.2: “Walkthrough Documentation Table”
For each walkthrough
CX-5: “Activity and Entity-level Control Forms” (optional)<br>
slide33. Identifying Significant Transaction Classes Transaction classes that present a reasonable possibility of material misstatement of the financial statements or disclosures based on:
Volume of activity
Size and composition of accounts
Types of transactions
Presence of fraud risks or other significant risks
Changes from the prior period<br>
slide34. Understanding Significant Transaction Classes How are transactions initiated and authorized?
How are transactions recorded, processed, and corrected?
How are transactions transferred to the general ledger and reconciled?
What reports are generated and how are they used?<br>
slide35. Understanding Significant Transaction Classes (cont) Consider control objectives:
Completeness: All transactions are recorded
Occurrence: All recorded transactions occurred and pertain to the entity
Accuracy: Transactions are recorded in the proper amount
Classification: Transactions are recorded in the proper account
Cutoff: Transactions are recorded in the proper period<br>
slide36. Documenting Significant Transaction Classes Narrative description
Focus on key controls and control objectives related to identified risks
How are control objectives achieved?
What controls are in place to address significant or fraud risks?
Are controls properly designed and implemented?<br>
slide37. Performing Walkthroughs Select one or a few transactions
Trace from initial creation of the source document to final posting in the general ledger
Inspect documents and records used in processing, make inquiries, and observe procedures being performed<br>
slide38. Retrospective Review of Accounting Estimates Performed to evaluate:
Effectiveness of management’s estimation process
Information relevant to current year estimates
The need for disclosure
The existence of possible management bias
AP-1: “Audit Program for General Planning Procedures”<br>
slide39. Assessing Risks and Developing Responses<br>
slide40. Assess Risks at the Financial Statement Level Identify risks that are pervasive to the financial statements and potentially affect many assertions
Assess the risk of material misstatement at the financial statement level
Develop overall responses
Document the risk assessment and the responses
CX-7.1: “Risk Assessment Summary Form” (Part I) 40<br>
slide41. Develop the Overall Audit Strategy Characteristics of the engagement that define its scope
Reporting objectives of the engagement
Important factors that determine audit focus
Resources needed to perform the audit 41<br>
slide42. Factors That Determine Audit Focus Materiality levels
Assessed risk of material misstatement at financial statement level
Preliminary identification of high risk audit areas
Whether you plan to test controls
Level of client assistance 42<br>
slide43. Assess Risks at the Relevant Assertion Level Identify risks of material misstatement (due to error or fraud) for specific—
Account balances
Transaction classes
Disclosures
Consider what can go wrong at the relevant assertion level 43<br>
slide44. Assess Risks at the Relevant Assertion Level Diagram 44<br>
slide45. Assess Risks at the Relevant Assertion Level (cont) Assessing risks at the assertion level
Are the risks of a magnitude that could result in material misstatement?
What is the likelihood that the risks could result in material misstatement?
Likelihood is a function of:
Inherent risk
Control risk
Need a basis for the assessment 45<br>
slide46. Assess Risks at the Relevant Assertion Level (cont..) Identify significant risks that require special audit consideration
Fraud risks
Other significant risks
Significant risks often relate to:
Significant economic, accounting, or other developments
Complex, nonroutine, or judgmental matters
Transactions with related parties 46<br>
slide47. Assess Risks at the Relevant Assertion Level (cont…) Identify risks for which substantive procedures alone are not adequate
Revise the risk assessment and reconsider planned audit procedures if audit evidence contradicts the original risk assessment<br>
slide48. Assess Risks Document the following:
Risk assessment at the relevant assertion level
Basis for the assessment
Significant risks
Risks for which substantive procedures alone are not adequate
CX-7.1: “Risk Assessment Summary Form” (Part II) 48<br>
slide49. The Detailed Audit Plan The nature, timing, and extent of further audit procedures to respond to the risk assessment (i.e., the audit program)
Provides linkage between the risk assessment and the responses at the assertion level 49<br>
slide50. Tailoring the PPC Audit Programs<br>
slide51. Performing Further Audit Procedures 51<br>
slide52. Tests of Controls Perform tests of controls if:
Relying on them to reduce the risk assessment
Substantive tests alone are not adequate
Inquiry alone is not sufficient for testing controls 52<br>
slide53. Tests of Controls (cont) Rotational tests of controls are permitted:
Obtain evidence about whether the controls have changed using inquiry, observation, and inspection
If controls have changed, rotation is not appropriate
Test a control at least once every three years
If several controls are rotationally tested, test some controls each year
If relying on controls for significant risks, controls must be tested in the current year
CX-10.1: “Test of Controls Form” 53<br>
slide54. Substantive Procedures Test all relevant assertions for material account balances, transaction classes, and disclosures
Perform procedures specifically to address significant risks
Substantive analytical procedures alone are not sufficient for significant risks 54<br>
slide55. Substantive Procedures (cont) Perform the following substantive procedures in all audits:
Agree or reconcile the financial statements and notes to the accounting records
Examine material journal entries and other adjustments made when preparing the financial statements
Procedures required by AU-C 240 to address the risk of management override of controls
Required procedures are on AP-2, “Audit Program for General Auditing and Completion Procedures” 55<br>
slide56. Documenting Further Audit Procedures Document the following:
Nature, timing, and extent
Linkage
Results, including results of procedures to address management override
Conclusion about relying on tests of controls performed in a prior audit 56<br>
slide57. Summary Completed risk assessment consists of:
AP-1: “Audit Program for General Planning Procedures”
CX-1.1: “Engagement Acceptance and Continuance Form”
CX-1.2: “Engagement Independence Compliance and Nonattest Services Documentation Form
CX-2: “Financial Statement Materiality Worksheet for Planning Purposes”
CX-3.1: “Understanding the Entity and Identifying Risks”
CX-3.2: “Engagement Team Discussion”
CX-3.3: “Fraud Risk Inquiries Form”<br>
slide58. Summary (cont) Completed risk assessment (cont.)
CX-4.1: “Understanding the Design and Implementation of Internal Control”
CX-4.2.1: “Financial Reporting System Documentation Form—Significant Transaction Classes” (for each significant transaction class and financial close and reporting)
CX-4.2.2: “Financial Reporting System Documentation Form—IT Environment and General IT Controls”
CX-4.3: “Walkthrough Documentation Table” (for each walkthrough)
CX-7.1: “Risk Assessment Summary Form”<br>
slide59. Summary (cont…) Other PPC practice aids related to risk assessment
CX-5: “Activity and Entity-level Control Forms” (optional)
CX-6.1: “Entity Risk Factors” (memory jogger)
CX-6.2: “Fraud Risk Factors” (memory jogger)
CX-10.1: “Test of Controls Form” (if controls are tested)
CX-12.2: “Audit Difference Evaluation Form”
AP-2: “Audit Program for General Auditing and Completion Procedures”
Tailored audit programs for individual audit areas<br>
slide60. SAS No. 145 Highlights Enhances and clarifies aspects of assessing the risks of material misstatement
Introduces or revises key definitions, such as significant risk and spectrum of inherent risk
Requires separate assessment of inherent risk and control risk
Revises requirements related to understanding the entity’s system of internal control and the evaluation of the design of certain controls
Implements a new stand-back requirement
Effective for audits of financial statements for periods ending on or after December 15, 2023<br>
slide61. Questions?<br>