Audit Strategy, Plan, Approach Flashcards
Nature - Necessity
(1) “Unable to gather sufficient and appropriate audit evidence on substantive procedures alone, due to:
• High volume of transactions
• Complex system
• Tight audit deadline (cost/benefit of testing controls)
• Auditor needs to place reliance on controls in order to test
• System generated/no audit trail/ computer generated transactions
• Bring in any scope issues that shows that we not enough time to do substantives only e.g. multiple locations/expansion
(2) If there are areas of significant risk, the auditor needs to review design and implementation of the controls as per ISA 315.
Significant risks:
• List examples e.g. manufacturer
• ….
(3) ISA 240 states that the auditor must assess management’s design of controls over fraud risks:
• List examples of fraud risks e.g. incentive to manipulate
• ….
(4) There is a high reliance on IT controls in the company, which may mean we must rely of test of controls. The following controls are highly relied by the client and are automated and manual dependent:
• List examples of controls relied on by the client e.g. reconciliation performed by computer
Nature - Desirability
Testing controls will provide a cost-benefit to the audit firm (usually the case).
Testing controls will provide an opportunity to give value-added advice to clients.
Testing controls will provide an opportunity to train staff.
The client has specifically requested the auditor to test control or there is an expectation that they
will do so.
Specific control weaknesses were identified in the previous audit and the client has undertaken to
amend them.
The auditor needs to audit the corporate governance statement on the effectiveness of internal
controls.
The auditor can rely on previous years’ tests of control (and hence benefit from efficiencies in future
years). This is only possible if:
o The control system and personnel have not changed since the last test; o The controls were last tested within the previous three years;
o The controls do not address a significant risk; and
o Controls were found to be effective during the previous year’s test.
Nature - Possibility (Are there controls to Test?)
• There seems to be a good/bad control environment in place
o There are controls to test (List 3 examples of controls)
o Internal audit function
o Management’s attitude
• The client relies on IT controls
o Need to test ITGC before application controls
o If ITGC not in place can still test manual independent
- Managements Integrity – if risk of override is high, cannot place reliance on controls
- Do we have the resources to test? CAATs, IT experts?