Intermediate Single Audit Issues: Planning, Performing and Reporting NASACT Audio Conference April 2, 2008 Presented by Frank Crawford, CPA Crawford &

Slides:



Advertisements
Similar presentations
Arizona’s First Year SAS 112 Experience from the Audit Side
Advertisements

SAS 112 Post-implementation Review NSAA/NASACT Middle Management Conference April 14, 2008 Presented by: Cindy Simon Wisconsin Legislative Audit Bureau.
AICPA SAS 112: Case studies and Intermediate Reporting Issues Presented by Frank Crawford, CPA Crawford & Associates, P.C.
Single Audit Fundamentals: A Refresher Presented by Frank Crawford, CPA Crawford & Associates, P.C.
Presentation Title on MasterPage 1 Single Audit Changes – Recovery Act Compliance Supplement Appendix VII devoted to ARRA CFDA numbers Clarification of.
Implementing SAS 112 Thomas H. McTavish, C.P.A. Auditor General State of Michigan.
1 AICPA Statement on Auditing Standards No. 112, Communicating Internal Control Matters Identified in an Audit NASACT Audio Conference October 19, 2006.
OMB Circular A133 Audits of States, Local Governments, and Non-Profit Organizations 1 Departmental Research Administrators Training Track.
Internal Control and Control Risk
Presented by YOUR NAME THE DATE
G L O B A L S E R V I C E / I N D U S T R Y A U D I T / T A X / A D V I S O R Y / L I N E O F B U S I N E S S SAS 112 Presentation California State University.
OMB Circular A-133 (Single Audit) Heather Perry, CPA Amy Ring,
Preparing for your Agency Audit under OMB CIRCULAR A 133 “What will auditors be testing?" 1.
Internal Control.
Michael Moreland & Kathryn Beseau Partners Moreland & Associates, Inc.
OMB Circular A-123 – Management’s Responsibility for Internal Control Policy Applicability Sources of Information Assessment, Documentation and Reporting.
SAS 112 – The Year After Presented by Chris Ray Partner - KPMG LLP KPMG LLP.
The Super Circular – Will It Be A Game Changer? April 14, 2015 Beth A. Wood, CPA, State Auditor 1 NASACT Middle Management Conference.
Review of Introduction to Auditing
SAS 112 Update Chapter 9 Presented by Chris Ray, Partner KPMG LLP KPMG LLP.
Auditing A Risk-Based Approach To Conducting A Quality Audit
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
UCSD Office of the Controller1 SAS112 Implementation UCSD Status Update.
Prepared and Presented By: Frank Crawford, CPA.
Statement on Auditing Standards (SAS) 112 Communicating Internal Control Related Matters Identified in an Audit.
Implications of SAS 112 NCURA Regional Meeting Park City, Utah April 22-27, 2006.
Impact of the New Clarity Standards on Governmental Audits Presented by Beila Sherman, CPA and Enrique Llerena, CPA.
Auditing Internal Control over Financial Reporting
An Accountant’s Look at the Changing Horizons within SOX 404 Presented to Colorado Bar Association’s Securities Law Group Presented by Bill Evert Hein.
PwC Internal Control Reports: Facts, Myths and Best Practices FIRMA National Risk Management Training Conference – San Francisco, CA Wednesday March 31,
Auditing Internal Control over Financial Reporting
1 Improving Single Audits to Protect Taxpayers 2008 Federal Financial Management Conference Mary M. Foelster, CPA American Institute of CPAs March 11,
AICPA SAS 112 on Internal Controls: Implications and Impacts on State Agencies and Auditors Presented by Frank Crawford, CPA Crawford & Associates, P.C.
New Auditing Standards Laurie Ball, CPA Swenson Advisors, LLP (Murrieta) Audit Director Accounting Day May 12, 2008.
Connecting Great Ideas and Great People Finance and Business Operations Symposium Gelman, Rosenberg & Freedman, CPAs Ms. Terri McKnight, CPA, Director.
Considering Internal Control
Port of Redwood City Presentation to The Board of Commissioners Port of Redwood City Presentation to The Board of Commissioners December 12, 2012 Presented.
UT-Arlington Accounting CPE Day August 13, 2014 SEFA Preparation and Subrecipient Monitoring.
1 Application of SAS 112 in a Single Audit GAQC Member Conference Call January 15, 2008 Presented by Mandy Nelson, CPA George Rippey, CPA.
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
NO FRAUD LEFT BEHIND The Effect of New Risk Assessment Auditing Standards on Schools Runyon Kersteen Ouellette.
Audit Risk. "Audit risk" means the risk that the auditor gives an inappropriate audit opinion when the financial statements are materially misstated Audit.
1 The Impact of SAS 112 on Governmental Financial Statement Audits GAQC Member Conference Call January 4, 2007 Presented by Chuck Landes, CPA.
Appendix E – Checklist for Review of Performance Audits Presented by: Ashton Coleman Department of Defense Office of the Inspector General August 16, 2012.
________________________________________________________________________________ Members AICPA Division of Firms  Center for Public Company Audit Firms.
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Webinar for FY 2011 i3 Grantees February 9, 2012 Fiscal Oversight of i3 Grants Erin McHughJames Evans, CPA, CGFM, CGMA Office of Innovation and Improvement.
Audit and Audit Resolution Presented by Wendy Spivey ADECA Audit Manager.
Auditing Standards Update 2006 VAGFOA Conference Rob Churchman, CPA June 5, 2006.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
Learning Objectives LO5 Document an accounting system to identify key controls and weaknesses in order to assess control risk. LO6 Write key control tests.
Internal Control Systems
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control Risk Chapter.
Page 1 Portfolio Committee on Water and Environmental Affairs 14 July 2009.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Federal Schedule Webinar Presented in Conjunction with ODJFS January 11, 2012 Rhonda Kline, CPA Accounting & Auditing Division.
Audit Findings.
Obtain and document understanding of internal control
Update on the Latest Developments in Government Auditing Standards
PLANNING, MATERIALITY AND ASSESSING THE RISK OF MISSTATEMENT
Uniform Guidance Discussion
Application of SAS 112 in a Single Audit
Update on the Developments in Government Auditing Standards
How to Prepare for an Audit
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Resolving Audit Findings: Guidance for the Non-CPA
Presentation transcript:

Intermediate Single Audit Issues: Planning, Performing and Reporting NASACT Audio Conference April 2, 2008 Presented by Frank Crawford, CPA Crawford & Associates, P.C.

Objectives High level overview of national single audit stat sample results Highlight and overview intermediate single audit issues identified Highlight and overview of advanced single audit issues identified Review SAS 112 impact Review initiatives to improve audit quality Take your questions

Single Audit Stat Sample Results Most prevalent deficiencies found –Not documenting the understanding of internal controls over compliance requirements (56.5%) –Not documenting the testing of internal controls of at least some compliance requirements (61%) –Not documenting compliance testing of at least some compliance requirements (59.6%)

Single Audit Stat Sample Results Not prevalent, but one of the most consequential deficiencies –Misreporting coverage of major federal programs, or in other words, one or more federal programs were identified as major programs when in reality they were not major programs Consequential because users may get a false sense of reliance by using opinions issued on major programs that were not actually audited as major –Sampling issues Insufficient sample sizes Lack of documentation of how the samples were selected and the population

Intermediate Single Audit Issues Identified Planning –Defining the reporting entity –Cognizant/Oversight Agency Identification and Considerations –Engagement Letter Considerations –Unique Considerations of Fraud and Abuse –Low-Risk Auditee Determinations –Identifying Federal Programs and Clusters

Intermediate Single Audit Issues Identified Planning Issues, cont. –Determination of Major Programs –Determination of Material Audit Requirements (part 2 of the Compliance Supplement) –Using Parts 3, 4, 5 and 7 of the Compliance Supplement to Create Audit Programs –Using Part 6 of the Compliance Supplement for Internal Control Documentation Designing, Performing, and Testing –Risk Assessment and Sample Size Determinations –Planning and Performing Dual Purpose Tests

Intermediate Single Audit Issues Identified Fieldwork –Auditing the Schedule of Expenditures of Federal Awards (SEFA) –Testing the Summary Schedule of Prior Audit Findings –Testing Information Technology (IT) Systems –Analysis of Audit Test Results and Exceptions –Determining Questioned Costs and Likely Questioned Costs –Testing Unique Requirements

Intermediate Single Audit Issues Identified Reporting –Qualitative Determination and Content of a Finding –Evaluating Findings and Determining Compliance Opinion(s) –Evaluating and Reporting on Internal Control –Modifications to Single Audit Reports –Preparation of the Schedule of Findings and Questioned Costs –Relationship of GAS Reports to Circular A-133 Reports and Schedules –Data Collection Form –Representation Letters for Federal Programs –Use of the GAS/A-133 Guide Illustrative Auditor Reports

Advanced Single Audit Issues Identified Planning, Fieldwork and Reporting –Accountability and Risk Management in a Single Audit –Key Considerations in Reviewing Single Audits –Preparing for and Responding to Quality Control Reviews (QCRs) –Firm-Specific Policies and Tools –Program-Specific Audit Considerations – Planning and Reporting –How to Recall and Reissue Single Audit Reporting Packages

Other intermediate and advanced single audit issues identified Stay current each year by reviewing –Changes to GAS/A133 Guide –AICPA Annual GAS/A133 ARA –Federal Agency Communications/Reports on Audit Deficiencies –Changes to Circular A-133 –Significant Changes to OMB Cost and Administrative Circulars –Updates to the OMB Compliance Supplement –Changes to the Data Collection Form

SAS 112 Impact Federal Register Notice, June 26 th, 2007, Volume 72, Issue 122 is the notice of the incorporation of SAS 112s requirements into the single audit process…

Pocket Guide to SAS 112 for Single Audit (A-133): What is the Likelihood of actual or potential noncompliance with a type of compliance requirement of a federal program, and what is the Magnitude of the actual or potential noncompliance? REMOTE S REMOTE M REMOTE L MORE THAN REMOTE S CONTROL DEFICIENCY SIGNIFICANT DEFICIENCY MATERIAL WEAKNESS MORE THAN REMOTE M MORE THAN REMOTE L Communicate in Writing

Footnotes to Pocket Guide Likelihood (two types) –Remote - the chance that the internal control deficiency would cause noncompliance with a type of compliance requirement of a federal program is slight –More than Remote – the chance that the internal control deficiency would cause noncompliance with a type of compliance requirement of a federal program is at least reasonable possible

Footnotes to Pocket Guide Magnitude defined as –S = Small (standards use term Inconsequential) –M = Medium (standards use the term More than Inconsequential) –L = Large (standards use the term Material) (can you tell that I worked in mens clothing store when I was a younger?)

Factors that may affect likelihood and magnitude Likelihood –The nature of the type of compliance requirement involved. For example, a specific special test or provision may involve greater risk because it is unique to the program and may require unique controls. –The susceptibility of the program and related types of compliance requirements to fraud. –The subjectivity and complexity involved in meeting the compliance requirement, and the extent of judgment allowed. –The cause and frequency of any known or detected exceptions related to the operating effectiveness of a control. –The interaction or relationship of the control with other controls. –The interaction of the control deficiency with other control deficiencies. –The possible future consequences of the deficiency

Factors that may affect likelihood and magnitude Magnitude –The program amounts or total of transactions exposed to the deficiency, in relation to the type of compliance requirement. –The volume of activity related to the compliance requirement exposed to the deficiency in the current period or expected in future periods. –Adverse publicity or other qualitative factors

Other factors to consider Combination of control deficiencies Evaluating the effect of compensating controls Deviations in the operating effectiveness of controls Prudent official test

Examples of typical significant deficiencies Policies and procedures that are incomplete, inadequate, or outdated for the activities subject to a type of compliance requirement Inadequate segregation of duties over a type of compliance requirement Controls over complex types of compliance requirements IT controls relating to the activity subject to the type of compliance requirement

Examples of typical material weaknesses Lack of operating policies and procedures for the activities subject to a type of compliance requirement Ineffective oversight of a major federal program by those charged with governance for compliance with those program requirements the activity subject to the type of compliance requirement, e.g., lack of adequate review of federal financial reports prior to submission to the grantor Identification by the auditor of material noncompliance for the period under audit that was not initially identified by the entitys internal control. (This is a strong indicator of a material weakness even if management subsequently corrects the noncompliance.)

Examples of typical material weaknesses, cont. An ineffective internal audit function or risk assessment function for a major program for which such functions are important to the monitoring or risk assessment component of internal control for a type of compliance requirement Identification of fraud in the program of any magnitude on the part of senior program management. For the purposes of evaluating and communicating deficiencies in internal control, the auditor should evaluate fraud of any magnitudeincluding fraud resulting in immaterial noncomplianceon the part of senior program management, of which he or she is aware Failure by management or those charged with governance to assess the effect of a significant deficiency previously communicated to them and either correct it or conclude that it will not be corrected An ineffective control environment. Control deficiencies in various other components of internal control could lead the auditor to conclude that a significant deficiency or material weakness exists in the control environment over compliance with major program requirements

Initiatives to improve audit quality Better and more effective training courses to be offered AICPA audit quality center task forces More clear and understandable language from the standard-setters Making a commitment

Questions???