The Stages of an Audit – After Appointment
1 Overview
All audits start by:
Planning
Understanding.
After these stages, the auditor can assess the risk of material misstatement and respond to that risk. We will see later how the risk of material misstatement can be broken down into several causes, but if you are dealing with a relatively new company with inexperienced staff, and which has high value, portable inventory and many cash transactions, you will probably see that the risk of material misstatement is relatively high. Audit work must then be planned to reduce the risk of material misstatement finding its way into the financial statements.
The audit approach, in the overview above, then divides:
Left hand branch. Here, the auditor has reason to expect that there are effective internal controls operating. For example, authorisation of transactions, employees checking another's work, monthly reconciliations (e.g. of bank and suppliers' statements), etc. If there is good internal control the chances of errors getting through into the financial statements are significantly reduced. Therefore rather than examine a high volume of transactions and balances, auditors tend to test the effectiveness of controls. If satisfactory, the examination of the details of transactions and balances themselves can be reduced.
Right hand branch. If the auditor does not expect there to be effective internal controls, the only way to obtain assurance that the financial statements are free from material misstatement will be to carry out substantive procedures.
Definition: Substantive procedure - an audit procedure designed to detect material misstatements at the assertion level. This will mean examining a higher volume of transactions and balances.
Of course, if the auditor expects to rely on effective controls but then discovers, after testing begins, that they are not operating satisfactorily, all audit evidence must be obtained from substantive procedures.
Management will be written to with an outline of why the controls are ineffective or are operating unsatisfactorily. Hopefully management will take action so that in the following year the problems are less.
Note that the same approach is not necessarily taken to ALL areas of the audit. For example, the auditor may plan to rely on controls over purchases (and hence the recording of liabilities also) but adopt a substantive approach to revenue (and receivables).
After all the audit procedures (either the 'combined approach' of tests of controls and substantive procedures or 'substantive approach'), there is an overall review of the financial statements. Think of this as sitting back and looking at the financial statements as a whole: taken as a whole, do the financial statements present fairly, in all material respects, the company's financial position and performance? Finally the auditor’s report can be issued.
2 Audit planning
Audit planning is very important and the auditors state in the auditor’s report that they planned and performed their audit. ISA 300 Planning an Audit of Financial Statements is written in the context of recurring audits.
2.1 Reasons why planning is important
If you don’t plan it, you won’t carry out the audit effectively. You would not know something as obvious as when the year end is, or how many branches or factories a company has, or how many staff members you may need to conduct the audit, or whether the company has a lot of valuable inventory.
You have to think both of a general strategy in a detailed approach. For example, in some very large companies auditors do not visit all the branches every year. They may visit only a quarter of the branches one year, another quarter the next year and so on. They have to decide whether or not to attend a physical inventory count. They may have to decide whether or not opinions from other experts are required (e.g. if management revalues property during the year).
2.2 Objectives of adequate planning
To give appropriate attention to important areas. Is there a high inventory? Is there a high volume of cash transactions? Are trade receivables particularly significant?
To identify potential problems. For example, if the company has recently changed its computerised accounting system there may well have been problems at the switch-over time, and staff may still be inexperienced.
To carry out the work expeditiously. That really means reasonably quickly and efficiently.
To ensure that the right numbers of staff are in the audit team with the right skills. They have to be timetabled so that the work for this client and other clients can be accommodated.
To coordinate, if necessary, with other parties. For example, the internal audit department of the company.
To facilitate the direction and supervision of the audit team and the review of their work; this is a component of quality management at the engagement level (see Chapter 24). The work performed in an audit is subjected to many reviews. The audit senior will review working papers prepared by audit trainees, then the audit manager will review them, and finally the engagement partner will review them. All of this has to be timetabled and time must also be left to clear the review points, for example, if additional work is required.
2.3 Planning documentation
The overall audit strategy sets the scope, timing and direction of the audit, and guides the development of the more detailed audit plan. It includes matters such as:
The allocation of resources to specific audit areas (e.g. the number of team members to observe the inventory count – see Chapter 20);
The resources required for specific audit areas (e.g. the need for an expert – see Chapter 23);
When resources are to be deployed (e.g. at an interim audit stage, year end or final audit) ; and
How resources are managed, directed and supervised (e.g. the timing of team meetings and reviews).
The audit plan includes a description of the nature, timing and extent of planned risk assessment procedures (see s.3.2) and further audit procedures (i.e. the auditor’s responses to assessed risks).
The overall audit strategy and the audit plan must be documented and should be updated as necessary during the course of the audit.
See Chapter 24 for further aspects of audit documentation (“working papers”).
3 Understanding the entity
In order to identify and assess the risks of material misstatement, the auditor must obtain an understanding of:
the entity;
its environment;
the applicable financial reporting framework; and
system of internal control.
3.1 Required understanding
The entity and its environment. The complexity of its organisational structure, its ownership and governance and IT environment. Also the entity's business model and business risks that may increase the risk of misstatement in the financial statements (e.g. management incentives may result in bias to overstate profits).
Industry factors. Banks, insurance companies, and many other operations in the financial sector are subject to regulation and sometimes the auditor has to ensure that these regulations have been adhered to.
Financial performance measures. Measures can put pressure on management to achieve targets that may result in management bias or even fraud (see Chapter 25).
Applicable financial reporting framework. The auditor should consider the entity's financial reporting practices and accounting policies (e.g. for revenue recognition) and changes thereto (e.g. new IFRS Standards).
System of internal controls. The auditor has to gain an understanding of the entity’s internal controls. Whether they exist and to what extent they are expected to operate. We will see in Chapter 12 that this has a profound effect on how the audit is likely to be conducted.
The control environment. This refers to the context in which the internal controls relevant to the preparation of the financial statements operate. The effectiveness of the control environment has a significant bearing on audit procedures, as we will see in Chapter 12.
3.2 Risk assessment procedures
Risk assessment procedures (i.e. audit procedures designed and performed to identify and assess risks of material misstatement – ‘RoMM’) must include:
Enquiries of management and others (e.g. internal audit) who may have information that is likely to assist in identifying RoMM.
Analytical procedures which may help identify unusual transactions/events and ratios or trends that have audit implications.
Observation (e.g. of processes) and inspection (e.g. of assets and documents) to support the enquiries and provide information.
Prior year information obtained can be used as long as it remains relevant and reliable as audit evidence for the current audit. Information obtained during client acceptance procedures may also be relevant.
RoMM exists when there is a reasonable possibility of:
A misstatement occurring (i.e. likelihood); and
It being material if it were to occur (i.e. magnitude).
Risks must be assessed at two levels to provide a basis for designing further audit procedures:
The financial statement level (i.e. relating to the financial statements as a whole, for example, the risk of management override of internal control).
The assertion level (i.e. relating to classes of transactions, account balances and disclosures).
RoMM is explained in more detail in Chapter 9.
4 Audit timing
An auditor’s response must change the nature, timing or extent of audit work. A management action such as recruiting staff, improving a control or correcting an accounting policy is not an audit response. State what the audit team will do and what evidence it will obtain.
Now we are going to look in more detail at the conduct of an audit. Here is a typical timetable.
The first thing that has to happen is a planning visit, or if not a visit at least a telephone call. There would certainly be a visit before the first audit of a new client commenced.
Contact is necessary because, at the very least, you have to agree with the client when the audit staff will visit. Also at this planning stage, enquiry should be made about what changes may have taken place at the client since the previous audit. For example, they may have a new accounting system, or there maybe changes in staff, or they might have expanded so instead of having one shop they maybe have two, and that will have implications for inventory counts.
The next stage is what’s known as the interim audit. The interim audit would typically happen perhaps in July or August of the year to 31 December. The auditor will carry out tests of controls, to ensure that the system of internal control as they understand it and as specified by the client is actually working in practice.
There will usually be some audit procedures that have to be carried out at the reporting date. For example, where the value of inventory included in the financial statements will be based on physical quantities, the auditor will plan to attend the physical count. (This is covered later in Chapter 20.)
After the year end, the auditors will return and carry out a final audit. At this point the client should have prepared the financial statements and the auditor will be concentrating on obtaining sufficient appropriate audit evidence to express a conclusion on the financial statements.
Remember this is only a typical timetable, sometimes it has to change. For example, if it is a very tight reporting deadline early in January, a lot of the final audit might actually be done on the November financial statements and then, in early January, a review is performed to make sure that the full year’s results appeared to be consistent with what was audited in more detail for 11 months. Occasionally there might be more than one interim audit particularly if the organisation is rather dispersed and the auditors have to visit a number of different locations.
Usually after the interim audit, the auditor will send a 'management letter' to the client. This will report any weaknesses or deficiencies in internal control identified during the audit. (This is covered later in Chapter 12.)
The stages of an audit (after appointment)
10 questionsAnswer the questions one at a time. Your progress is saved so you can leave and come back.
Open chapter practice

