Skip to content

Ask the Tutor ACCA AAA

assuming management responsibility

Former userFormer user4y ago

[Content removed at user request]

KimKimTutor4y ago#1
"Management threat" is not a separate category (see page 24 of the notes) - nor is it a term used in the Code. There is a general prohibition in the Code that an audit firm should not assume a management responsibility for an audit client. This is a para from the Code re the provision of internal audit services: "605.4 A1 Paragraph R600.7 precludes a firm or a network firm from assuming a management responsibility. Performing a significant part of the client’s internal audit activities increases the possibility that firm or network firm personnel providing internal audit services will assume a management responsibility." 605.4 A2 Examples of internal audit services that involve assuming management responsibilities include: ?? Setting internal audit policies or the strategic direction of internal audit activities. ?? Directing and taking responsibility for the actions of the entity’s internal audit employees. ?? Deciding which recommendations resulting from internal audit activities to implement. ?? Reporting the results of the internal audit activities to those charged with governance on behalf of management. ?? Performing procedures that form part of the internal control, such as reviewing and approving changes to employee data access privileges. ?? Taking responsibility for designing, implementing, monitoring and maintaining internal control. ?? Performing outsourced internal audit services, comprising all or a substantial portion of the internal audit function, where the firm or network firm is responsible for determining the scope of the internal audit work; and might have responsibility for one or more of the matters noted above.
KimKimTutor4y ago#2
Assuming management responsibilities is one of the few things that is a "no no". The relevant section (R600.7) has the heading "Prohibition on Assuming Management Responsibilities" and applies to ALL audit clients. What you suggest are not safeguards as defined in the Code (they are not actions taken by the AUDITOR) - they are means to avoid assuming management responsibilities.
Sign into reply to this topic.