Unit 4 - Audit Risk Strategy in a Professional Engagement Flashcards
Define Audit Risk.
The risk (probability) that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated.
Which of the following audit risk components may be assessed in nonquantitative terms?
Control Risk
Detection Risk
Inherent Risk
Control Risk - Yes
Detection Risk - Yes
Inherent Risk - Yes
What do professional standards identify as the two types of F/S related fraud?
Fraudulent financial reporting
Misappropriation of assets
What are the 3 categories of risk factors in the “fraud triangle?”
Opportunities
Incentives/Pressures
Attitudes/Rationalizations
What are fraud risks categorized as Incentives/Pressures?
Financial stability/profitability is threatened by economic conditions
Excessive pressure to meet the expectation of outsiders
What are fraud risks categorized as Opportunities?
Major financial statement elements that involve significant estimates by management that are difficult to corroborate
Ineffective monitoring of management (e.g., domination of management by a single person or small group without compensation controls; ineffective board of directors or audit committee oversight
Complex or unstable organizational structure
Internal controls are deficient
What are fraud risks categorized as Attitudes/Rationalizations?
Lack of commitment to establishing and enforcing ethical standards
Previous violations of securities laws or other regulations
Excessive focus by management on the entity’s stock price
What are incentives/pressures to commit misappropriation of assets?
Employees who have access to cash or other assets have personal financial problems
Employees have adverse relationships with the entity under audit, including anticipated future layoffs or recent changes to benefits or compensation levels
What are opportunities to commit misappropriation of assets?
When assets are inherently vulnerable to theft
Inadequate internal control over assets
What are attitudes/rationalizations to commit misappropriation of assets?
Auditors may not be in a position to assess these.
Employee’s behavior indicates dissatisfaction with the entity under audit
Changes in employee’s behavior or lifestyle is suspicious
Employee exhibits disregard for internal control related to assets by overriding existing controls or failing to correct known deficiencies
What are red flags from fieldwork that may affect the risk assessment?
Discrepancies in the accounting records - lack of support or suspicious errors
Conflicting or missing evidence - missing documents (or only available as copies)
Problematic relationship between the auditor and client personnel - undue time pressures or lack of access to records, etc.
What are two elements that make up a firm’s quality control system?
Acceptance & continuance of clients and engagements. - Important for firm to have policies and procedures to do risk assessment and decide when to accept a new engagement opportunity as well as when to continue an existing client relationship
Relevant ethical requirements (with emphasis on independence). - Firm must have policies and procedures to establish that all personnel associated with the engagement meet AICPA ethics requirements.
What are 5 matters that must be addressed (written or oral) with a predecessor auditor?
- Information bearing on the integrity of management
- Disagreements with management about accounting or auditing issues
- Communications to those charged with governance about fraud and/or noncompliance with laws or regulations
- Communications to management or those charged with governance about significant deficiencies in I/C
- Predecessor’s understanding about reason for the change in auditors
What are the 3 main phases of an audit?
Risk Assessment Phase - involves gaining an understanding of the client, identifying factors that may impact the risk of a material misstatement occurring in the financial statements, performing a risk and materiality assessment, and developing an audit strategy
Risk Response Phase - involves performing detailed tests of controls and substantive tests of transactions and accounts.
Reporting Phase - involving evaluating results of the detailed testing in light of the auditor’s understanding of the client, and forming an opinion as to the fair presentation of the client’s financial statements.
What are three main areas involved in the Risk Response phase of an audit?
-Perform detailed tests of controls
-Perform substantive tests of transactions and accounts and make decisions about the extent and timing of detailed testing of account balances and transactions
-Determine whether they plan to rely on the client’s system of internal controls