BA 427 – Assurance and Attestation Services Lecture 21 Tests of Controls.

Slides:



Advertisements
Similar presentations
Internal Control and Control Risk
Advertisements

Auditing Concepts.
1. Management Income Statement Balance Sheet Stmt of CF Management Prepares 1 Users Basic Mistrust 2 Auditors Independent Auditor 3 Lends Credibility.
Discussion on SA-500 – AUDIT EVIDENCE
Review of Introduction to Auditing
Chapter 9 The Study of Internal Control and Assessment of Control Risk
Auditing A Risk-Based Approach To Conducting A Quality Audit
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Internal Control in a Financial Statement Audit
Section 404 Audits of Internal Control and Control Risk
Nature of an Integrated Audit
INTERNAL CONTROL OVER FINANCIAL REPORTING
Financial Audit Autonomous Bodies Internal Control and Risk Assessment Session Internal Control and Risk Assessment.
Audit Evidence and Documentation Chapter 5. McGraw-Hill/Irwin © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. 5-2 Management Assertions Existence.
1 Designing Substantive Procedures The auditor “must plan and perform the audit to reduce the audit risk to an acceptably low level that is consistent.
INTERNAL CONTROL OVER FINANCIAL REPORTING
Chapter 5 Internal Control over Financial Reporting
Considering Internal Control
Internal Control in a Financial Statement Audit
Understanding Audit Risk Assessment
Internal Control in a Financial Statement Audit
9 - 1 ©2003 Prentice Hall Business Publishing, Essentials of Auditing 1/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 9.
©2003 Prentice Hall Business Publishing, Auditing and Assurance Services 9/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Chapter 05 Audit Evidence and Documentation McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 8.1 Control Risk,
Evaluation of Internal Control System
Auditing the Revenue Process
Evaluation of Internal Control System. Learning Objective 1 Contrast management’s need for internal control with the auditor’s need to consider internal.
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Chapter 6 Internal Control in a Financial Statement Audit Copyright © 2014 McGraw-Hill Education. All rights reserved. No reproduction or distribution.
CHAPTER 5 INTERNAL CONTROL OVER FINANCIAL REPORTING.
Chapter 12 Inventories and Cost of Goods Sold McGraw-Hill/Irwin
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 6-1 Chapter Six Internal Control in a Financial Statement Audit.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
©2003 Prentice Hall Business Publishing, Auditing and Assurance Services 9/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control.
Learning Objectives LO5 Document an accounting system to identify key controls and weaknesses in order to assess control risk. LO6 Write key control tests.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
Chapter 06 Audit Planning, Understanding the Client, Assessing Risks, and Responding McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc.
OVERVIEW THE AUDIT PROCESS Overview of the Audit Process.
Chapter 5 Evidence and Documentation McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Copyright © 2007 Pearson Education Canada 1 Chapter 11: Overall Audit Plan and Audit Program.
Lecture 9 Audit Evidence
Chapter 3 The Audit Process. Overview of Audit Process Developing an Understanding with the Client Financial statement engagements Audits Compilations.
©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control Risk Chapter.
1 chapter 13 Overall Audit Strategy and Audit Program.
1 Overview of PCAOB Auditing Standard No. 5 An Audit of Internal Control Over Financial Reporting that is Integrated with an Audit of Financial Statements.
18-1 Copyright © 2016 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
 Planning an audit of cost statements, records and other related documents is considered necessary to ensure achievement of audit objectives with available.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Auditing Concepts.
Obtain and document understanding of internal control
Internal Control Evaluation: Assessing Control Risk
Types of tests Risk Assessment Procedures – Auditors use the results of risk assessment procedures to determine the type and amount of further audit.
Developing the Overall Audit Plan and Audit Program
Internal Control in a Financial Statement Audit
Audit Evidence and Documentation
LATIHAN MID SEMINAR AUDIT hiday.
Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8th Edition William C. Boynton California Polytechnic State University at.
Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8th Edition William C. Boynton California Polytechnic State University at.
Defining Internal Control
INTERNAL CONTROLS AND THE ASSESSMENT OF CONTROL RISK
AUDIT TESTS.
Overall Audit Strategy and Audit Program
Presentation transcript:

BA 427 – Assurance and Attestation Services Lecture 21 Tests of Controls

Lecture 21 – Tests of Controls  Management’s assertions: Existence or occurrence. Completeness. Rights and obligations. Valuation or allocation. Presentation and disclosure.

Lecture 21 – Tests of Controls  Audit risk: Inherent Risk Control Risk Detection Risk

Lecture 21 – Tests of Controls  Audit risk: Inherent Risk:  The susceptibility of an assertion to a material misstatement assuming no related controls exist. Control Risk Detection Risk

Lecture 21 – Tests of Controls  Audit risk: Inherent Risk Control Risk:  The risk that a material misstatement that could occur in an assertion will not be prevented or detected on a timely basis by the entity’s internal control system. Detection Risk

Lecture 21 – Tests of Controls  Audit risk: Inherent Risk Control Risk Detection Risk:  The risk that the external auditor will not detect a material misstatement that exists in an assertion.  Can be broken down into TD x AP: TD = the risk for tests of details AP = the risk for analytical procedures and other procedures

Lecture 21 – Tests of Controls The audit risk model: AR = Audit Risk AR = IR x CR x DR The auditor establishes AR as an overall goal, assesses IR, and then plans the audit to achieve levels of CR and DR that results in the targeted AR.

Lecture 21 – Tests of Controls  Control risk: An evaluation of the effectiveness of internal controls in preventing or detecting material misstatements.  Control risk is stated in terms of the financial statement assertions: Existence or occurrence. Completeness. Rights and obligations. Valuation or allocation. Presentation and disclosure.

Lecture 21 – Tests of Controls  Reasons to set control risk at 100% (primarily pertains to nonpublic companies): Controls are unlikely to pertain to an assertion. Controls are unlikely to be effective. Evaluating effectiveness would be inefficient.

Lecture 21 – Tests of Controls  Procedures necessary to set control risk below 100%: Identify specific controls relevant to specific assertions.  Some controls have pervasive effects, whereas other controls affect only a specific assertion. Test controls. Reach a conclusion on the assessed level of control risk.

Lecture 21 – Tests of Controls  Test controls There are procedures to evaluate the effectiveness of a control’s design, which are concerned with whether the control is suitably designed to prevent or detect material misstatements. There are procedures to evaluate the operating effectiveness of controls. In some cases, the same procedure can serve either or both purposes.

Lecture 21 – Tests of Controls  Test controls In general, sample sizes will be larger when testing the operating effectiveness of controls than when obtaining evidence about the design of controls. Also, tests of the operating effectiveness of controls need to cover an adequate time period. Tests of the design of controls can be drawn from a single point in time.

Lecture 21 – Tests of Controls  Test controls The following procedures can be used to evaluate the design of controls:  Inquiry of entity personnel  Inspection of documents and reports  Observation of the application of the control  Narratives  Internal control questionnaires  Flowcharts

Lecture 21 – Tests of Controls  Test controls The following procedures can be used to test the operating effectiveness of controls:  Inquiry of entity personnel  Inspection of documents and reports  Observation of the application of the control  Reperformance by the auditor

Lecture 21 – Tests of Controls  Inquiry of entity personnel  This procedure is legitimate, although it provides relatively weak evidence that the control is operating as described.

Lecture 21 – Tests of Controls  Inspection of documents and reports This procedure provides strong evidence that the control is operating. Requires that the control leaves an audit trail.

Lecture 21 – Tests of Controls  Observation of the application of the control: Particularly helpful if there is an identified control that does not leave an audit trail. Example: segregation of duties.

Lecture 21 – Tests of Controls  Reperformance by the auditor: Particularly helpful if there is an identified control that does not leave an audit trail. Example: Trace sales prices to an authorized price list.

Lecture 21 – Tests of Controls  Walkthroughs The auditor  selects one or a few documents for the initiation of a transaction type.  traces the documents through the entire accounting process.  makes inquiries and observes current activities at each stage of the processing of the transaction.  examines completed documentation for the transactions.

Lecture 21 – Tests of Controls  Walkthroughs PCAOB Auditing Standard No. 2 requires walkthroughs for each major class of transactions.

Lecture 21 – Tests of Controls  Sarbanes-Oxley Section 404 There is an obvious and close connection between tests of controls in support of the auditor’s assessment of control risk in the Audit Risk Model, and tests of controls in connection with the auditor’s reporting requirements under Section 404.

Nonpublic CompanyPublic Company Obtain an understanding of internal control: design and operation Sufficient to audit financial statements Sufficient to audit internal control over financial reporting

Nonpublic CompanyPublic Company Obtain an understanding of internal control: design and operation Sufficient to audit financial statements Sufficient to audit internal control over financial reporting Decide on control risk for each transaction type Low, medium or high Select “low”

Nonpublic CompanyPublic Company Obtain an understanding of internal control: design and operation Sufficient to audit financial statements Sufficient to audit internal control over financial reporting Decide on control risk for each transaction type Low, medium or high Select “low” Plan and perform tests of controls and evaluate results Extensive tests for all objectives Extent of testing depends on cost-benefit analysis

Nonpublic CompanyPublic Company Plan and perform tests of controls and evaluate results Extensive tests for all objectives Extent of testing depends on cost-benefit analysis Revise assessed control risk, if necessary

Nonpublic CompanyPublic Company Plan and perform tests of controls and evaluate results Extensive tests for all objectives Extent of testing depends on cost-benefit analysis Revise assessed control risk, if necessary Plan detection risk and perform substantive tests in accordance with the A.R.M. Likely to be less substantive testing Likely to be more substantive testing, depending on control risk

Nonpublic CompanyPublic Company Issue internal control report or letter Must issue a report on internal control over financial reporting and issue a written communication to the audit committee describing significant deficiencies and material weaknesses. Must communicate, preferably in writing, to the audit committee or its equivalent, describing significant deficiencies and material weaknesses.