In: Accounting
1 a) What is acceptable audit risk, and how may this risk affect the scope of the auditors’ work?
B) What is an engagement letter? Is there any similarity between the engagement letter and the standard unmodified audit report? Please explain.
C) When may an auditor seek the help of an outside specialist, and what responsibility the auditor maintains if he/she uses such help?
D )Please write out the Audit Risk model equation for planning and explain it.
E) The COSO Framework described five components of internal control that management designs and implements to provide reasonable assurance that its control objectives will be met. Please list and explain these.
F)What are tests of controls, and what are the procedures for test of controls?
What is an AUDIT PROGRAM? What is the main purpose of using an audit program in auditing?
A. Acceptable Audit Risk:
As the name suggests, acceptable risk is that percentage of misstatement in the financial statements or any documents under audit, that the auditor is ready to accept. In other words, it is the measure at which the auditor is willing to accept that the financial statements or the subject matter of audit may be materially misstated during or after the audit is completed.
Affect on scope of audit:
The higher the risk of acceptance, the lower is the certainty of misstatement of financial statements, and vice-versa. In other words, when the auditors acceptance of risk level is low, he will be more certain that the financial statements are free from misstatements, as more misstatements will not be accepted by the auditor.
B. Engagement Letter and standard unmodified audit report:
Engagement letter is a kind of agreement between the auditor and the client, which includes the terms & conditions of the audit. It is an arrangement that an auditor has with a client to performan audit of client's books of accounts and the financial statements. It includes, the objective and scope of audit, the reponsibilities of the auditor and the management (client), etc.
Unmodified audit report is a kind of audit report where the auditor expresses an unmodified opinion stating that the financial statements are prepared, in all material respects, in accordance with the financial reporting framework.
There are no such similarities between an engagement letter and unmodified audit report. Engagement letter is an agreement done before start of audit, and the audit report is given after the audit is completed. Engagement letter is an agreement between the auditor and the client, whereas audit report is the report that an auditor gives on the basis of his audit of financial statements. However, both engagement letter and audit report, do state the responsibilities of auditor and the management, and the Independence to be maintained by the auditor while performing the audit.
C. Seeking the help of an outside specialist:
Auditor is not expected to be an expertise in all fields or subjects. He is a specialist in Auditing, Taxation and accounting matters. However, there will be situations where the auditor might have to look into different fields or subjects in order to obtain sufficient audit evidence. In such situation, where in expertise in a different subject or field other than in which the auditor is an expert is necessary, he / she shall determine seeking the help of specialist in such subject or field.
Responsibilities of the auditor in such a situation:
D. Audit Risk Model:
Audit risk is the risk that the auditor will express an inappropriate audit opinion on financial statements that contain material misstatements.
The formula for determining the level of risk associated with a given audit is as follows:
Detection Risk = Audit Risk / (Inherent Risk x Control Risk)
DR = AR / (IR x CR)
In other words, AR = IR x CR x DR (audit risk is the product of Inherent Risk, Control Risk and Detection Risk)
Detection risk is the risk that the auditor will not detect a material misstatement during the course of audit.
Inherent risk (IR) is the susceptibility of having a material misstatement, assuming there were no Internal Controls.
Control risk (CR) is the risk that the material misstatement will not be prevented or detected and corrected on a timely basis by the internal control system.
E. Five components of Internal control as described by COSO framework:
The five components described by COSO Framework are control environment, risk assessment, information and communication, monitoring activities, and existing control activities (CRIME). They are explained as follows:
F. Test of Controls:
A test of controls is an audit procedure to test the effectiveness of a control used by a client entity, to prevent or detect material misstatements. Depending on the results of this test, auditors may choose to rely upon a client's system of controls as part of their audit. However, if the test reveals that controls are weak, the auditors will enhance their use of substantive testing, which usually increases the cost of an audit.
The procedures vary from auditor to auditor depending on the control that they want to review. The following are general procedures of tests of controls:
F. Audit Program:
An audit program is a detailed plan of work, prepared by the auditor for carrying out the audit. It is comprised of a set of techniques and procedures, which the auditor plans to apply in the given audit for forming an opinion about the client's statement of accounts. It provides a basis for the supervision and control of the audit work. It may also contain the audit objectives for each audit step.
The main purpose of the audit program is to serve in detail the set of instructions to the audit team, the pattern and flow of audit work, and to complete the audit in a smooth and planned manner. It helps the auditor to devote appropriate attention to important areas of the audit, identify and resolve potential problems on a timely basis. A well organised and programmed audit is always more effective and efficient than unplanned / unprogrammed audits.