8 Audit Procedures Evidence Gathering and Evaluation Flashcards
(102 cards)
What does audit evidence need to be?
Sufficient, relevant and reliable, for the purposes of the audit opinion
What are the 5 ESSENTIAL criteria audit evidence must support
To achieve this aim and be relevant to the audit objectives, there must be sufficient and reliable audit evidence about all of the following:
1. Existence (assets and liabilities at y/e) and occurrence (transactions throughout the year). Genuine or not?
2. Completeness (includes accuracy of recording and correct cut-off)
3. Rights and obligations (per conceptual framework definitions of assets and liabilities)
4. Valuation and/or measurement (in accordance with relevant IAS / FRS)
5. Presentation or disclosure (in accordance with relevant IAS / FRS and/or Companies Act)
What is occurance
Transactions and events that have been recorded have occurred and pertain to the entity – i.e. they are genuine
What is completeness
- All transactions and events that should have been recorded have been recorded
- “Completeness” includes:
o Accuracy and reliability of data recording and processing throughout the year – amounts and other data relating to transactions and events have been classified and recorded appropriately so that y/e transaction totals and balances are not over/under recorded
o Correct cut-off – transactions and events have been recorded in the correct accounting periods
What is presentation and disclosure
Financial information is appropriately presented and described, and disclosures are clearly expressed in accordance with International Accounting Standards, the Companies Act, and LSX listing rules
What is the correct cut off
- Sales and purchases recorded in the correct month
- Accidental cut of errors are fairly common, but management can apply deliberate cut-off ‘errors’ as a means of window-dressing. See topic 4 re Thomas Gerard legal case
- Easy place for management to apply fraudulent accounting as errors here are common and therefore if they are caught they can pass it off as just a mistake
- General rule sale is considered to be the point of dispatch
What is existence
Assets, liabilities, and equity interests exist (they are genuine) (reliable)
What is completeness
All assets, liabilities and equity interests that should have been recorded have been recorded, and y/e cut-off is correct for debtors, creditors and inventory (reliable)
What is rights and obligations
The entity holds or controls the rights to assets, and liabilities are the obligations of the entity (they meet the ASB definitions of assets and liabilities) (reliable and relevant)
What is valuation and measurement
Assets, liabilities, and equity interests are included in the financial statements at appropriate amounts in accordance with International Accounting Standards, to show a ‘true and fair view.’ (reliable)
What is presentation and disclosure
Financial information is appropriately presented and described, and disclosures are clearly expressed in accordance with International Accounting Standards, the Companies Act, and LSX listing rules. (understandable, relevant, consistent).
What are internal controls
- Internal control is ‘all embracing’ and includes absolutely everything which is designed/intended to help an organization achieve any of the above objectives.
- All internal controls are ultimately the responsibility of the directors
What are the objectives of internal controls
Internal controls within accounting systems typically have one or more of the following specific objectives:
* Ensuring complete and reliable data processing (accounting records)
* Ensuring proper authorization, and preventing unauthorized transactions
* Safeguarding assets
* Detecting/preventing/correcting errors
* Deterring fraud (by making fraud more difficult and/or increasing the chance of detection)
* Facilitating management supervision and review (includes internal checks and reconciliations, and internal audit)
* Maintaining an audit trail
What are the limitations of internal controls
- All systems of internal control are designed, operated and supervised by human beings.
o Some are more careful and honest - Therefore, they will never be perfect. CR will never be zero
o Therefore AR can never be zero
Why is the segregation of responsibilities important when considering internal controls
- This is a very important feature of internal control, and auditors will always look for this. It involves the division of functional responsibilities between different people, together with regular ‘internal checks’ and/or reconciliation by different members of staff and/or supervisors.
- This can greatly reduce the risks of undetected errors, unauthorized transactions.
How does strong internal controls make fraud harder
- Fraud would require collusion, in a well designed system
- Fraud by nature is devious and by nature carefully concealed
- If good segregation then need lots of people to come together to create a successful fraud
How does strong internal controls reduce audit work
- Strong segregation will allow auditors to place more reliance on compliance testing and do less substantive testing
o Lower control risk and reliable internal control and records
o Also accidental errors are far more likely to be detected
What are the 4 main functions of controls that need separating (CARR)
Custody
* Maintains safe custody of particular assets/money/data. Can only accept/release assets after authorization (see below). Should deliver information to the record keeping function (see below).
Authorisation
* Authorises activities and takes decisions (of transactions/events relating to those assets).
Recording
* Records all the activities/events taking place (complete and reliable accounting records).
Reconciliation
* Independently checks and reconciles assets against authorisations and accounting records.
What are the components of internal controls
- Control environment
- Entity’s risk assessment processes
- Information systems
- Control activities
- Monitoring of controls
What is the control environment
- This is important and pervasive.
- It sets the overall tone for the entire organisation and influences the consciousness of its people.
o Leadership comes from to top directors must set a good example for all lower members of staff - It is the foundation for all other components of the internal control structure.
- It Includes corporate governance (based on the UK C.G. Code, see Gray & Manson Chapter 5), integrity, ethical values and management attitudes to internal controls
o UK companies either have to comply with the corporate governance code of explain why not. It is not law so cant force companies
What are the elements of the control environment
- Communication and enforcement of integrity and ethical values
- Commitment to competence
- Management’s philosophy and operating style
- Organizational structure
- Assignment/delegation of authority and responsibility
- Human resource policies and practices
o If any of the above are unsatisfactory, it is likely that ‘inherent risk’ and ‘control risk’ will BOTH be higher
What should a risk assessment cover
- This involves detailed analysis by the PLC of its strategic, operational and market risks.
- Some of these may be highly unpredictable
- Public companies should consider the possibilities of various business risks crystallizing and the significance of the consequent financial impacts on the business. These are part of ‘inherent risk’, because they can have very serious impacts on profitability and asset values, and even ‘going concern’. Therefore, they impact the financial statements.
- When this has been done, suitable internal controls should be introduced to monitor and reduce risks to acceptable levels, to the extent that this is possible.
How can information systems support the 5 criteria
- Relevant and timely information about internal activities and external factors are essential if a company is to be successful. We live in the ‘information age’.
- Successful managers need timely, relevant and reliable information e.g. ‘management accounts’.
What is an accounting system
- It comprises all of the methods and records established to identify, assemble, analyse, classify, record and report transactions and accounting events, and maintain accountability for all assets and liabilities.
- It must also provide a complete audit trail for ALL transactions.