Chapter 6: Professional Responsibilities, Audit Documentation, IT Audit, and Government Auditing Flashcards
(42 cards)
what are six principles of the AICPA code of professional conduct?
The 6 principles (articles) of the Code of Conduct are:
- Responsibilities
- Public interest
- Integrity
- Objectivity and independence
- Due care
- Scope and nature of services
Under the AICPA Code of Professional Conduct, Rule 101, independence is impaired:
- if a member has a DIRECT financial interest with attestation clients without regard to materiality
- if a member has a material INDIRECT financial interest in the client
- if a member or a member’s immediate family member has a loan to or from the client
- if a members accepts more than a token gift
- if a member is an employee of or makes management decisions on behalf of the client
- if the client is overdue more than one year in the payment of professional fees to the member
- if there is actual or threatened litigation between the member and the client
According to AICPA Code of Professional Conduct, Rule 203, a departure from GAAP may be justified under what circumstance?
a departure from GAAP may be justified only if compliance with GAAP would cause the financial statements to be misleading
Under Rule 301, in what circumstances must a CPA disclose confidential client information without the consent of the client?
A CPA must disclose confidential information without client consent under the following circumstances:
- It is necessary to comply with a valid subpoena or summons
- As part of a quality review of the CPA’s professional practices authorized by the AICPA
- in response to any inquiry made by the ethics division or the trial board of the AICPA, or by a duly-constituted investigative body of a state CPA society
When are contingent fees prohibited under Rule 302?
Contingent fees are prohibited for:
- audits of financial statements
- reviews of FS
- examination of prospective financial information
what is an “issuer” and what group establishes standards for audit reports of issuers?
an issuer is an entity subject to the rules of the SEC (this would include primarily public companies) The PCAOB (Public Company Accounting Oversight Board) establishes standards for audit reports of issuers.
Title I of the Sarbanes-Oxley Act of 2002 (SOX) requires that registered firms must adhere to what auditing standards?
- Audit workpapers must be maintained for seven years
- A concurring or second partner review is required for each audit report
- the audit report must describe the scope of the testing of the issuer’s internal controls
Under SOX Title II, what services must be preapproved by the auditor committee and what services may not be provided to an audit client?
all auditing services and permitted non-audit services (including tax services) must be pre-approved by the audit committee.
Prohibited services include: bookkeeping financial information systems design and implementation appraisal and valuation services actuarial services management functions and HR functions internal audit outsourcing services investment-related services Legal services expert services unrelated to the audit (SEC Regulation S-X contains same rules)
what are the audit partner rotation rules under SOX Title II and SEC Regulation S-X?
- both SOX and Regulation S-X require the lead and concurring partner to rotate off the audit every five years
- regulation S-X further requires other partners to rotate off every seven years. Lead and concurring partners are subject to a five-year “time out” and other partners are subject to a two-year “time out”
what must be reported by the auditor to the audit committee under SOX Title II and SEC Regulation S-X?
- critical accounting policies and procedures used
- alternative accounting treatments discussed with management, the ramifications of alternatives, and the treatment preferred by the auditor
- material written communications between the auditor and management
what is the required cooling-off period under SOX Title II and SEC Regulation S-X?
the audit firm cannot have employed an issuer’s CEO, CFO, controller, CAO, or other employee in a financial reporting oversight role during the one year preceding the audit
what is the required content of management’s internal control report under SOX Title IV?
- management’s responsibility for establishing an adequate internal control structure for financial reporting
- an assessment of the effectiveness of the current year’s control structure
what are the PCAOB’s tax-related independence rules?
- registered firms may not provide confidential or aggressive tax transactions to audit clients
- registered firms may not provide tax service to corporate officers of audit clients or their immediate family members
- audit committee must pre-approve tax services and related fees
under the SEC’s principles of independence, a client relationship or a service provided to an audit client would create independence issues if it:
- creates a mutual or conflicting interest between the auditor and client
- results in the auditor acting as management or an employee of the audit client
- places the auditor in a position of auditing his or her own work
- makes the auditor an advocate for the audit client
Explain the conceptual framework approach under IFAC’s Code of Ethics and identify threats to compliance with its fundamental principles
IFAC’s Code is based on a conceptual framework (versus a set of rules) that requires entities to identify, evaluate, and address threats to compliance with its fundamental principles. These threats include:
- Self-interest threat
- self-review threat
- advocacy threat
- familiarity threat
- intimidation threat
How long must audit documentation be retained for issuers and nonissuers?
PCAOB rules require that auditors retain audit documentation of public companies (issuers) for 7 years from the report release date
SAS rules require that auditors keep audit documentation for nonissuers for at least 5 years from the report release date
the report release date is the date on which the auditor gives the client permission to use the report (often the date the report is delivered to client)
What are the advantages and disadvantages of auditing with a computer?
Disadvantages:
- audit documentation may not contain readily-observable details of calculations
Advantages:
- less math errors due to automatic performance of math on all documents
- automatic cross-referencing of amounts by linking each lead schedule to the working trial balance and financial statements
- automatic preparation of financial statements, tax return schedules, and consolidating schedules
- reduction in required supervisory review time
- automatic performance of certain analytical review procedures
- enhanced client service
- Improved morale and productivity for audit team
Describe “auditing around the computer” and identify when it is appropriate and not appropriate
when auditing around the computer, the auditor does not directly test the application program, but instead tests the input data, processes the data independently, and then compares the independent results to the program results
This method is appropriate for simple batch systems that have a good audit trail. Auditing around the computer is not appropriate when there is insufficient paper-based evidence
List and briefly define the types of computer assisted audit techniques (CAATs) that may be used
- Transaction tagging - electronically marks specific transactions
- Embedded audit modules - sections of program code collect data for the auditor
- Test data - use of the client’s system to process the auditor’s data off-line
- Integrated test facility - use the client’s system to process auditor’s data, online
- Parallel simulation - use of the auditor’s system to reprocess client data
in conducting an audit of an organization receiving federal financial assistance, what additional audit procedures must be performed in addition to the general requirements of GAAS and GAGAS?
Those procedures performed under GAAS and GAGAS plus:
- the auditor should obtain and document an understanding of internal control established to ensure compliance with the laws and regulations applicable to the federal financial assistance
- in some instances, tests of controls are mandated to evaluate the effectiveness of such controls.
audits of governmental entities may draw on up to 3 sets of standards or supplementary requirements. What are they and what are the circumstances that surround their application?
Generally Accepted Auditing Standards (all audits)
Generally Accepted Government Auditing Standards (Yellow Book audits): auditee is a government, or receives financial assistance from the government
OMB Circular A-133 (Single Audits of Federal Financial Assistance): an entity expending more than $500K in federal financial assistance annually
Identify the additional auditor responsibilities associated with government audits under GAGAS
- Obtaining an understanding of how laws, rules, and regulations relate to financial statement amounts
- assessing the degree to which management has identified laws, rules, and regulations that have a material impact on financial statement amounts
- obtaining reasonable assurance that financial statements are free from material misstatements resulting from violations of laws, rules, and regulations associated with the determination of financial statement amounts
- communication to management, as appropriate, that GAAS procedures alone will not fulfill additional audit requirements related to an audit of a government or of governmental assistance.
identify the 3 types of governmental audits/engagement normally undertaken by CPAs
- Financial audits: engagements primarily designed to determine the fair presentation of financial statements in conformity with GAAP or an OCBOA. Financial audits also include audits of specified elements of the financial statements
- Attestation engagements: examinations, reviews, and agreed upon procedures, etc.
- Performance audits: effectiveness, economy and efficiency audits, internal control and compliance audits
in concluding an audit of an organization under GAGAS, what audit documentation, in addition to that required by GAAS, must also be included?
Internal control documentation must include:
- Consideration of procedures that ensure the auditee’s compliance with laws, rules, and regulations
- written representations from management with regard to management’s identification of material laws, rules, and regulations; management’s responsibility for ensuring compliance with laws, rules, and regulations; and management’s knowledge of any violations that should be disclosed or recorded