EXPLORING A NEW AUDIT RISK FACTOR THE CIRCUMVENTION ASPECT

Size: px
Start display at page:

Download "EXPLORING A NEW AUDIT RISK FACTOR THE CIRCUMVENTION ASPECT"

Transcription

1 EXPLORING A NEW AUDIT RISK FACTOR THE CIRCUMVENTION ASPECT Stanley X. Lewis, Jr., Troy University J. Scott Magruder, The University of Southern Mississippi Eddy J. Burks, Troy University Carl Smolinski, LSU-Shreveport ABSTRACT The accounting profession considers various risk factors during an audit of financial statements inherent, control and detection to aid in planning and thereby minimizing applied procedures when auditing financial statements produced by a client s financial reporting system. The Sarbanes-Oxley Act (2002) and efforts by COSO (2007) allude to but do not update these risk factors as the profession made efforts to address the changed business environment. However, currently more than 90% of all records maintained in an electronic format and an estimated 70% or more are never converted to hard copy and result in a need for these risk factors to be updated. The research being conducted by the authors explore one aspect of the impact of technology - circumvention. INTRODUCTION The accounting profession considers several types of risk when working with client organizations which are periodically revisited as the business community evolves and changes due to changes in the global marketplace. However, risk as a factor continues to be viewed from primarily from the two traditional perspectives: 1) internal to the organization (client) and 2) external (non-client) risk issues. The traditional perspectives are limited in that they attempt to evaluate risk using descriptive methods without including adequately significant changes in business. More than 90% of all business records are maintained in many electronic formats and it is estimated that 70% or more are not ever converted to hard copy; thus, traditional descriptive efforts to evaluate (and thus manage) risk are showing signs of aging (Montague, 2007). The research being conducted by the authors explore one aspect of a new risk category - the impact of technology on risk. RISK FACTORS The traditional perspective within the accounting profession when considering the risk associated with the audit of a set of financial statements is viewed from two points-of-view: (1) an internal view by a client and (2) the external auditor s view of risk related to the audit. Internal Risk The risk that is internal to a corporation is the risk that internal corporate or management efforts will not result in an effective and efficiency system of internal control and that internal monitoring will not detect weaknesses and problems in a timely manner to assist the board of directors and management in achieving its financial reporting objective.

2 These efforts are commonly referred to as risk management and it has evolved through the years as business failures have been made public resulting in regulatory actions and often with the passage of statutory laws designed to strengthen the financial reporting process vital to investors, employees and other stakeholder groups (COSO, 2004). The National Commission on Fraudulent Financial Reporting established what became known as the Tread way Commission to address several issues including the IR issue as the accounting professional and the greater business community undertook efforts to address weaknesses in the financial reporting efforts. In 1992 the Tread way Commission released Internal Control Integrated Framework as a guide to the business community and thus the accounting profession as an effort to provide a structure for corporations to use in efforts to improve the existing financial reporting systems used. This guide defined internal control as a process, effected by an entity s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in three categories: Effectiveness and efficiency of operations. Reliability of financial reporting. Compliance with applicable laws and regulations The Commission stated success or failure of the internal control process is based upon a judgment of its effectiveness by the company s board of directors and management efforts in achieving reasonable assurance that: They understand the extent to which the entity s operations objectives are being achieved. Reliably published financial statements are being prepared. They are in compliance with applicable laws and regulations (AICPA Basics, 2005) A subsequent or follow up to the 1992 Treadway Commission effort was undertaken and completed by the Committee of Sponsoring Organizations (COSO), subunit of the Treadway Commission, in 2001 led to the issuance an updated guide or framework known as Enterprise Risk Management Integrated Framework (2004) incorporating evolving issues since 1992 and several highly public financial reporting and business failures. Congressional action resulted in the enactment of the Sarbanes-Oxley Act of 2002 (COSO, 2004). The updated framework was completed and circulated in 2004 and provided an updated structure for corporate management and board of directors in their efforts to evaluate and improve what was then being labeled Enterprise Risk Management (ERM) after a series of high-profile business failures (and the corresponding audit failures by the accounting profession) that had led to investors, employees and other stakeholders suffering significant losses The goal of COSO was

3 to provide an improved and more complete framework that incorporated changes in how business was conducted and was one of several attempts by the accounting profession to respond to the perceived failures of public accounting firms in the series of business failures and the enacted Sarbanes-Oxley Act of In the 2004 guide Enterprise Risk Management (ERM) was defined as follows: Enterprise risk management is a process, effected by an entity s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and management risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives. (COSO, 2004) These efforts have been integrated into changes in professional standards within the accounting profession as it relates to audit engagements. The current professional standards promulgated by the American Institute of Certified Public Accountants (AICPA, 2007 ) described internal risk in terms of two identifiable components: (1) inherent risk (IR) the susceptibility that an account or class of transactions contained within the financial statements or underlying records could be materially misstated, either individually or when aggregated with other misstatements, and (2) control risk (CR) the susceptibility that an inherent risk misstatement could occur and not be prevented or detected by the internal control system (policies and procedures) established by the corporation. (AICPA, 2007) These two components when considered together form what may be labeled Risk of Material Misstatement (RMM) the professional assessment of both inherent and control risk when determining the planning, completion and conclusion of an audit engagement. However, RMM is only one aspect of the issues involved when professionals are associated with services that involve risk and describes the risks from the perspective of the corporation and not the accounting professional. The CPA is not able to directly manage IR and thereby control it since it is a function of the inherent nature of an account (such as cash) and/or classes of transactions (such as Internet-based sales). Equally important is that the CPA is not able to manage (and thereby control) CR since it is the result of decisions, policies, procedures and the resulting environment in which events and activities are recorded in the general ledger system and are the underlying documentation for summarized data in the financial statements created by the board of directors and management. However, the CPA should be able to evaluate the adequacy of the client s efforts to create a reasonable internal control environment that will address adequately the IR in their financial reporting system (AICPA, 2007). External Risk The certified public accountants (CPAs) engaged to audit financial statements prepared by a client s financial reporting systems are required to assess the RMM describing a client s internal risk (both IR and CR). However, two other areas of risk

4 to be considered in order for the professional to develop a complete understanding and consideration of the entire spectrum of risk in an audit environment - detection risk and audit risk. Detection Risk (DR) the failure by the auditor to detect and assess correctly the internal (to the corporation) risk factors and thereby not correctly assessing risk and thus being associated with misleading financial statements and an incorrect audit report. Auditors attempt to manage this risk by considering to areas of risk: (1) tests of details risk (TD) or the risk that audit procedures did not detect material weaknesses in the client s internal control system that underlies its financial reporting system, and (2) substantive analytical procedures risk (AP) or the risk that audit procedures applied beyond those test of details procedures did not detect material weaknesses in the financial statements produced by the client s financial reporting system. Audit Risk (AR) the cumulative risk that an auditor is associated with materially misstated financial statements by incorrectly assessing the various components of risk during an audit and is a cumulative perspective of all risk factors (inherent, control and detection). The AICPA describes a general model for understanding the general relationship of audit risk and the other risk components described above and thereby control overall risk of releasing a report associated with a set of financial statements by the use of numerical calculations. AR = RMM x DR RMM = Inherent Risk (IR) x Control Risk (CR) DR = Detection Risk The external auditor can manage (and thus control) DR during audit planning and the subsequent application of audit procedures (TD and AP) and are found in common audit practice guides used within the profession. (AICPA, 2007 and AICPA, Internal Control, 2005) The rationale is simple, the auditors wish to reduce or restrict their legal exposure or liability to investors, employees and other stakeholder groups. Evidence gathered by CPAs during the conduct of an audit of financial statements prepared (and thus subsequently published or distributed) in a client s financial reporting system should also be examined from two other perspectives: (1) the detection of fraud, and (2) the impact of technology on the financial reporting system and the related internal control system. Fraud Detection The importance of fraud is viewed in the context of negligence. Two degrees of negligence are important in understanding of it in relation to audit risk and fraud: ordinary negligence or the lack of reasonable care when performing services, and gross negligence or a lack of even minimum care when performing services. The

5 profession view is found in AICPA (2007) where fraud is defined and described as an: intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage. Two types of misstatements resulting from fraud are relevant to the auditor s consideration in a financial statement audit: misstatements arising from fraudulent financial reporting and misstatements arising from misappropriation of assets. In the AICPA (2007) the responsibility to be assumed by the auditor: Although the auditor has no responsibility to plan and perform the audit to detect immaterial misstatements, there is a distinction in the auditor s response to detected misstatements depending on whether those misstatements are caused by error or fraud. When the auditor encounters evidence of potential fraud, regardless of its materiality, the auditor should consider the implications for the integrity of management or employees and the possible effect on other aspects of the audit. The accounting profession attempts to use these definitions when assessing audit risk, determining DR (TD and AP) and determining the implications (effectiveness) of a client s internal control system (IR and CR) which should designed to provide reasonable assurance regarding the achievement of objectives as described by COSO in its 2004 framework: (1) effectiveness and efficiency of operations, (2) reliability of financial reporting, and (3) compliance with applicable laws and regulations (COSO, 2007). Auditing Computer-based Information Systems With in the accounting professional is minimal guidance as to how auditors should gather evidence to form the basis for their report which will be issued with a client s audited financial statements. Three common approaches utilized by CPAs and learned from experience by some of the researchers are: (1) auditing around the easiest and more common approach used within the profession is to compare known inputs with outputs generated by a client s information system, (2) auditing through the more difficult approach for CPAs to use since it requires a level of indepth knowledge about information systems and technology that most CPAs do not possess nor do they have the technical expertise to obtain the level of understanding of technical (electronic) control procedures in place by the information system, and (3) auditing with computer aided tools or the practice of using computer technology to automate and/or simplify the audit process (Wikipedia, 2007). The implications for the accounting profession to continue to select the more traditional approach

6 (auditing around the computer) raises the question as to whether or not CPAs are adequately evaluating their audit risk (AR) and the detection risk (DR) component correctly during planning for a financial statement audit, and, thereby, actually increasing their exposure to claims of gross negligence and fraud. Circumvention & Fraud Risk In general there it is assumed that in today s environment a business will use technology. In fact, the level of usage is described by Montague (2007) as 90% of all records are now maintained in electronic format and 70% of those are never printed out in hard copy. Current research focused on one aspect of evidence gathering by the CPA during a financial statement audit the circumvention of the board of directors and managements internal control system policies and procedures. This circumvention is of interest since the corporate environment of today includes a networked information technology (IT) professional unit that utilizes virus scanning tools, firewalls, network operating system features to manage the access to the company s system. Most of the attention is focused on the use of well-known tools or procedures such as matching user names to passwords and the use of firewalls to reduce the intrusions by hackers. Equally important to the internal efforts under COSO business guidelines is the ability of auditors to know how to prevent and when necessary to detect errors or irregularities. Thus, in today s network environment an auditor must have a greater level of an understanding of intrusion tools which could be used for fraudulent activities and ways to detect the misuse of such tools. These tools that can be easily be used to circumvent existing security procedures in a computerbased information system and enable unauthorized access to individuals that may wish to obtain company information-data and/or cause malicious harm to the networked system. An understanding of the potential existence of such tools and their usage is important to financial statement auditors and specialized auditors such as fraud examiners and forensic accountants who are engaged to determine the nature, level and implications of activities which are suspicious of being fraudulent including the inappropriate use of company assets-resources including company information-data and use of its information system for questionable activities. Several intrusion techniques (or tools) could be identified as tools for circumvention efforts. The current research focused on only one of these Port Knocking Individuals assigned the responsibility to complete tests of details and apply substantive tests need at a minimum an awareness of intrusion tools such as port knocking when assessing a computer system to determine if it will prevent and/or detect efforts that are considered fraudulent. If an auditor is to be effective in managing audit risk (AR) and provide legal defenses against claims of gross negligence or fraud greater knowledge of such activities is crucial. Pork Knocking serves as the basis for an illustration of a circumvention scenario that could be non-

7 readily detected but could have significant consequences to the client and other relying upon the CPA to detect fraudulent during an audit of financial statements. Port Knocking The circumvention method of Port Knocking was described in by Krzywinski as a process for a remote user to connect to a server when the port (service) is closed and a firewall is in place. The remote user sends a sequence of requests to the server. All of the ports are closed and attempts are logged by the firewall system that also contains software to monitors the firewall's logs. However, the software will open a given port when a correct sequence of port attempts is detected. When this happens the remote user can then access the requested port. This is a form of "a stealthy method of authentication and information transfer to a networked machine that has no open ports" (Krzywinski, 2003). The transmission of any type encoded information is the link to where fraudulent activities can become a consideration to an auditor. A Simple Scenario of Port Knocking In simple terms port knocking refers to the electronic interactions between two computers as one attempts to open a closed port and thus pass through the second s firewall. The IT unit as part of its responsibility manages the networked system including the firewall (good) and the ability of individuals to use of port knocking to pass messages between computers (individuals) in a manner that bypasses or circumvents the normal network security features (bad). How can port knocking work? Consider a simple scenario - suppose that an underpaid employee agrees to be involved in a scheme to provide internally developed calculations used in the standard cost system when the business is developing competitive bids. These bids will form the basis for a significant portion of annual revenue when the contract is awarded. The costs are considered sensitive and are carefully guarded from release to the industry association and news media due to the highly volatile industry. The knowledge of these costs by competitors could result in successful competitive bids by others and result in loss revenue for the business. The use of a computer backdoor which had not been closed by the IT staff to introduce a surrogate virus program allowing someone to insert into the system a program that permits the altering of system access logs to conceal activities from the obvious detection by system auditors (Magruder, 1992). By accessing the system via the firm s Intranet (for example, the shipping/receiving department), a transparent communication operation using port knocking could be established allowing a person in cost accounting (underpaid employee) to transmit coded data to another in the shipping/receiving unit (co-conspirator) who in turn can transfer the coded data to the external person. The two employees are able to pass coded

8 information between their locations internally. Generally, the businesses firewall would not be effective since both the sender and receiver are both internal in the system (e.g., on the same side of the firewall used by the system). External transmissions from the shipping/receiving department are numerous and routine and the firewall is structured to permit more ready transmission from this location to external computers resulting in the firewall not easily detecting transmissions from this location. In addition, the transmission out is not monitored as extensively as the in-coming transmission which was designated a higher priority for internal control purposes. In essence, the conspirators would be able to transmit sensitive data to others outside the corporate system in a manner that is not easily detected. The potential impact of circumvention tools, such as Port Knocking, are not being considered in the auditor s current approach to determining and managing audit risk as established by the accounting profession. The impact of technology is a factor that is not adequately included in audit risk decisions. Circumvention - Can This Be Done? Can this be done? The answer is yes. It can be done easily by anyone with minimal programming knowledge such as a part-time student and full-time employee in shipping/receiving department of the hypothetical company. Most companies use a client-server environment and, thus, those internal to the company (cost accounting and shipping/receiving clerks) simply need ta simple software module (program) written in a language such as perl instructing the network server to take the message, map the characters to predefined ports and send the message to the receiver computer client. Both clerks and the external coconspirator would install and use the same module and thus have the same port mapping information and decoding features for messages. One very important aspect is this process is meant to be as "invisible" as possible, so the information is not sent all at once but rather sent over (perhaps) an extended period of time to minimize monitoring software detecting a pattern of unusual behavior. At most, a stray packet here and there may be detected if the network utilizes a sniffer program; however, typically an internal sniffer program seldom is used since efforts are directed toward the detection of outside intrusions attempting to enter the firm s system. Sending out coded data becomes easy. An indepth discussion of the programming for port knocking was described by Magruder (2005). Early the messages could only be sent during working hours since messages sent after working hours may more easily be detected by the system. CONCLUSIONS Several types of risk are considered by the auditor from the two traditional perspectives of internal and external to a client organization. However, these risk factors are changing due to changes in the global marketplace. One concern is the auditor s use of descriptive methods which do not adequately consider significant changes in business technology usage. A significant portion of all business records

9 being maintained electronically as well as most are not converted to hard copy results in these traditional descriptive efforts have the opposite effect of what is intended. Rather, than improving the profession s management of audit risk the adherence to the traditional views of audit risk actually have the potential to increase the profession s risk during audits of financial statement. The current research explored one aspect of the audit risk issue - the potential impact of technology on the risk to the auditor of failing to detect fraudulent activities within a client s internal control system. REFERENCES AICPA Audit Committee Toolkit, Internal Control: A Tool for the Audit Committee, AICPA, The AICPA Audit Committee Toolkit, 2005, Basics of Internal Control, page 1. AICPA, Professional Standards, Vol. I (July 7, 2007), AU 312, pages Committee of Sponsoring Organizations of the Treadway Commission, Enterprise Risk Management Executive Summary, September 2004, pages v - 2. Committee of Sponsoring Organizations of the Treadway Commission, Internal Control Integrated Framework - guidance on Monitoring Internal Control Systems, Discussion Document, September 2007, page 3. In Wikipedia, Computer Aided Audit Tools, Krzywinski, M., Port Knocking Network Authentication Across Closed Ports, SysAdmin Magazine, 2003, 12: Magruder, J. Scott; and Lewis, Stanley X., Jr.; "Espionage Via Viruses," COMPUTER FRAUD & SECURITY BULLETIN, (January 1992), pp Magruder, Scott; Lewis, Stanley X. Jr.; and Chen, Kuo Lane; Sending Messages Via Port Knocking; 2005 Information Resources Management Association International Conference Proceedings; San Diego, California; May 15-18, 2005; pages Montague, Brian A., Report from Counsel Comments on Recent Legal Developments and Trends from Law Offices of Brian A. Montague, PLLC, Navigating Electronic Discovery Rules, Fall 2007, page 4. Treadway Commission, Internal Control Integrated Framework, 1992.

CPA REVIEW SCHOOL OF THE PHILIPPINES M a n i l a. AUDITING THEORY Risk Assessment and Response to Assessed Risks

CPA REVIEW SCHOOL OF THE PHILIPPINES M a n i l a. AUDITING THEORY Risk Assessment and Response to Assessed Risks Page 1 of 7 CPA REVIEW SCHOOL OF THE PHILIPPINES M a n i l a Related PSAs: PSA 400, 315 and 330 AUDITING THEORY Risk Assessment and Response to Assessed Risks 1. Which of the following is correct statement?

More information

Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8 th Edition

Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8 th Edition Modern Auditing: Assurance Services and the Integrity of Financial Reporting, 8 th Edition William C. Boynton California Polytechnic State University at San Luis Obispo Raymond N. Johnson Portland State

More information

EFFICIENT USE OF AUDIT COMMITTEES

EFFICIENT USE OF AUDIT COMMITTEES AGENDA EFFICIENT USE OF AUDIT COMMITTEES BRENT YOUNG, CPA JERRY GAITHER, CPA Best practices related to: Audit Committee Process Internal Audit Risk Management 2 AUDIT COMMITTEE PROCESS AND PROCEDURES Audit

More information

Presentation by: CPA Zachary Muthui

Presentation by: CPA Zachary Muthui Audit Planning and Risk Assessment Presentation by: CPA Zachary Muthui Uphold public interest Audit planning Objectives of audit planning To ensure that the audit is performed in a smooth and effective

More information

AUDIT RESPONSIBILITIES AND OBJECTIVES

AUDIT RESPONSIBILITIES AND OBJECTIVES AUDIT RESPONSIBILITIES AND OBJECTIVES CHAPTER 6 Copyright 2017 Pearson Education, Ltd. 6-1 CHAPTER 1 LEARNING OBJECTIVES 6-1 Explain the objective of conducting an audit of financial statements and an

More information

WATCH WORDS FROM THE PEER REVIEW PROCESS

WATCH WORDS FROM THE PEER REVIEW PROCESS WATCH WORDS FROM THE PEER REVIEW PROCESS Peer Review 3 NOT DOCUMENTED = NOT PERFORMED Vendor-obtained practice aids, checklists and forms are NOT audit evidence Sources of audit evidence Books, records,

More information

An Audit of Internal Control Over Financial Reporting Performed in Conjunction with An Audit of Financial Statements

An Audit of Internal Control Over Financial Reporting Performed in Conjunction with An Audit of Financial Statements Page A 1 Standard Appendix Auditing Standard No. 2 AUDITING AND RELATED PROFESSIONAL PRACTICE STANDARDS Auditing Standard No. 2 An Audit of Internal Control Over Financial Reporting Performed in Conjunction

More information

An Audit of Internal Control Over Financial Reporting Performed in Conjunction with An Audit of Financial Statements

An Audit of Internal Control Over Financial Reporting Performed in Conjunction with An Audit of Financial Statements AUDITING STANDARD No. 2 An Audit of Internal Control Over Financial Reporting Performed in Conjunction with An Audit of Financial Statements March 9, 2004 AUDITING AND RELATED PROFESSIONAL PRACTICE STANDARDS

More information

Chapter 2. The CPA Profession

Chapter 2. The CPA Profession Chapter 2 The CPA Profession Review Questions 2-1 The four major services that CPAs provide are: 1. Audit and assurance services Assurance services are independent professional services that improve the

More information

13-A. Fraud Phase II Issues Paper

13-A. Fraud Phase II Issues Paper IAASB Main Agenda Page 2002 855 Agenda Item 13-A Convergence with US Fraud Standard 1. In March 2001, the IAPC approved revisions to ISA 240 The Auditor s Responsibility to Consider Fraud and Error in

More information

2-2 The major characteristics of CPA firms that permit them to fulfill their social function competently and independently are:

2-2 The major characteristics of CPA firms that permit them to fulfill their social function competently and independently are: Link full download Solution Manual : http://testbankair.com/download/solution-manual-forauditing-and-assurance-services-16th-edition-by-arens-elder-beasley-and-hogan Link full download test bank: http://testbankair.com/download/test-bank-for-auditing-andassurance-services-16th-edition-by-arens-elder-beasley-and-hogan/

More information

Accounting 408 Exam 2, Chapters 3, 4, 5, 6, E, F

Accounting 408 Exam 2, Chapters 3, 4, 5, 6, E, F Accounting 408 Exam 2, Chapters 3, 4, 5, 6, E, F Summer 2017 Name Row Multiple Choice Questions. (2 points each, 100 points total) Read each question carefully and indicate the one best answer to each

More information

Chapter 8. Planning and Testing Operating Effectiveness of Internal Control over Financial Reporting. Prepared by Richard J.

Chapter 8. Planning and Testing Operating Effectiveness of Internal Control over Financial Reporting. Prepared by Richard J. Chapter 8 Planning and Testing Operating Effectiveness of Internal Control over Financial Reporting Prepared by Richard J. Campbell Copyright 2011, Wiley and Sons Learning Objectives 1. Learn the relationships

More information

McGraw-Hill/Irwin. Copyright 2013 by The McGraw-Hill Companies, Inc. All rights reserved.

McGraw-Hill/Irwin. Copyright 2013 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin Copyright 2013 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 04 Management Fraud and Audit Risk Learning Objectives 1. Define business risk and understand how management

More information

Audrey A. Gramling Kennesaw State University. Larry E. Rittenberg. University of Wisconsin Madison. Karla M. Johnstone

Audrey A. Gramling Kennesaw State University. Larry E. Rittenberg. University of Wisconsin Madison. Karla M. Johnstone Auditin Audrey A. Gramling Kennesaw State University Larry E. Rittenberg University of Wisconsin Madison Karla M. Johnstone University of Wisconsin Madison /% SOUTH-WESTERN *% CENGAGE Learning- Australia

More information

Implementation Tool for Auditors

Implementation Tool for Auditors Implementation Tool for Auditors CANADIAN AUDITING STANDARDS (CAS) DECEMBER 2017 STANDARD DISCUSSED CAS 315, Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity

More information

UNCOVERING THE TRUTH WITH FORENSIC ACCOUNTING

UNCOVERING THE TRUTH WITH FORENSIC ACCOUNTING UNCOVERING THE TRUTH WITH FORENSIC ACCOUNTING Contributed by : CA Nirav DharodVishesh Sangoi (a member of the association) he can be reached at dharodnirav99@gmail.com Competing in a rapidly changing world,

More information

S12 - Guidelines for Planning an IS Audit Christopher Chung

S12 - Guidelines for Planning an IS Audit Christopher Chung S12 - Guidelines for Planning an IS Audit Christopher Chung IS Auditing Guidelines for Planning an IS Audit Session Objectives Agenda Information Systems Audit Planning and Scoping o Understanding Business

More information

Don t Leave Home Without Your SOX!

Don t Leave Home Without Your SOX! Don t Leave Home Without Your SOX! Using Function Points to identify and document your company s application controls for the Sarbanes-Oxley Act of 2002, Section 404 Presented by Tammy Preuss CFPS, PMP,

More information

Auditing and Attestation (AUD) - Content Outline Effective January 2014

Auditing and Attestation (AUD) - Content Outline Effective January 2014 Auditing and Attestation (AUD) - Content Outline Effective January 2014 The Auditing and Attestation section tests knowledge and understanding of the following professional standards: Auditing standards

More information

Consideration of Fraud in a Financial Statement Audit (Redrafted) *

Consideration of Fraud in a Financial Statement Audit (Redrafted) * STATEMENT ON AUDITING STANDARDS Consideration of Fraud in a Financial Statement Audit (Redrafted) * Statement on Auditing Standards (SAS) Consideration of Fraud in a Financial Statement Audit (Redrafted)

More information

Evaluating Internal Controls

Evaluating Internal Controls A SSURANCE AND A DVISORY BUSINESS S ERVICES Fourth in the Series!@# Evaluating Internal Controls Evaluating Overall Effectiveness, Identifying Matters for Improvement, and Ongoing Assessment of Controls

More information

1. A series of business and related auditing failures led to the passage of the Sarbanes-Oxley Act (2002).

1. A series of business and related auditing failures led to the passage of the Sarbanes-Oxley Act (2002). Chapter 02 The Financial Statement Auditing Environment True / False Questions 1. A series of business and related auditing failures led to the passage of the Sarbanes-Oxley Act (2002). True False 2. The

More information

Chapter 18. Integrated Audits of Public Companies. McGraw-Hill/Irwin. Copyright 2012 by The McGraw-Hill Companies, Inc. All rights reserved.

Chapter 18. Integrated Audits of Public Companies. McGraw-Hill/Irwin. Copyright 2012 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 18 Integrated Audits of Public Companies McGraw-Hill/Irwin Copyright 2012 by The McGraw-Hill Companies, Inc. All rights reserved. Nature of an Integrated Audit Auditors of public companies should

More information

After completing this Session, you should be able to answer the following questions:

After completing this Session, you should be able to answer the following questions: About this Course Welcome to CMA Auditing Course, Part II. Below, you will find a short summary of the modules. Upon registration, further introductory resources will tell you: How the course is organized

More information

VERSION #1 WRITE ON YOUR SCANTRON!!!

VERSION #1 WRITE ON YOUR SCANTRON!!! ECON 132A WINTER 2009 MIDTERM #2 Name: Date: ANSWER ALL MULTIPLE CHOICE QUESTIONS ON GREEN SCANTRON ANSWER QUESTIONS 29 & 30 IN THE SPACE PROVIDED ANSWER THE SIMULATION ASSIGNMENT IN YOUR BLUE-BOOK, PUT

More information

[RELEASE NOS ; ; FR-77; File No. S ]

[RELEASE NOS ; ; FR-77; File No. S ] SECURITIES AND EXCHANGE COMMISSION 17 CFR PART 241 [RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06] Commission Guidance Regarding Management s Report on Internal Control Over Financial Reporting

More information

SAS Teleconference

SAS Teleconference SAS 104-111 Teleconference Jan. 15, 2009 Craig Funkhouser, Crowe Horwath LLP craig.funkhouser@crowehorwath.com Ken Goldmann, J.H. Cohn kgoldmann@jhcohn.com 1 Today s Program Historical Background, Review

More information

Audit Risk. Exposure Draft. IFAC International Auditing and Assurance Standards Board. October Response Due Date March 31, 2003

Audit Risk. Exposure Draft. IFAC International Auditing and Assurance Standards Board. October Response Due Date March 31, 2003 IFAC International Auditing and Assurance Standards Board October 2002 Exposure Draft Response Due Date March 31, 2003 Audit Risk Proposed International Standards on Auditing and Proposed Amendment to

More information

Diving into the 2013 COSO Framework. Presented by: Ronald A. Conrad

Diving into the 2013 COSO Framework. Presented by: Ronald A. Conrad Diving into the 2013 COSO Framework Presented by: Ronald A. Conrad 2 Objectives Obtain an understanding of why the COSO Framework has been updated Understand how the framework has changed Identify the

More information

By CPA Alfred Lagat Tullon Audit Consulting Ltd 11 th August 2015

By CPA Alfred Lagat Tullon Audit Consulting Ltd 11 th August 2015 By CPA Alfred Lagat Tullon Audit Consulting Ltd 11 th August 2015 Common deficiencies Steps you can take to avoid them Practical cases and implications So there is potentially an appetite for auditors

More information

PART 6 - INTERNAL CONTROL

PART 6 - INTERNAL CONTROL PART 6 - INTERNAL CONTROL INTRODUCTION The A-102 Common Rule and OMB Circular A-110 (2 CFR part 215) require that non-federal entities receiving Federal awards (i.e., auditee management) establish and

More information

AUDIT RISK ASSESSMENT AND RESPONSES TO ASSESSED RISK BY Geoffrey Byamugisha Partner, Ernst & Young. Lessons on Audit Risk. Responding to fraud risk

AUDIT RISK ASSESSMENT AND RESPONSES TO ASSESSED RISK BY Geoffrey Byamugisha Partner, Ernst & Young. Lessons on Audit Risk. Responding to fraud risk AUDIT RISK ASSESSMENT AND RESPONSES TO ASSESSED RISK BY Geoffrey Byamugisha Partner, Ernst & Young ICPAU Page 1 COURSE CONTENT Lessons on Audit Risk Identification of audit risk and audit risk assessment

More information

Chapter 06. Audit Planning, Understanding the Client, Assessing Risks, and Responding. McGraw-Hill/Irwin

Chapter 06. Audit Planning, Understanding the Client, Assessing Risks, and Responding. McGraw-Hill/Irwin Chapter 06 Audit Planning, Understanding the Client, Assessing Risks, and Responding McGraw-Hill/Irwin Copyright 2012 by The McGraw-Hill Companies, Inc. All rights reserved. Obtaining Clients Submit a

More information

Enterprise Risk Management Integrated with Strategy & Performance

Enterprise Risk Management Integrated with Strategy & Performance Implementing the updated COSO ERM framework Enterprise Risk Management Integrated with Strategy & Performance Frank Balabyeki February 2, 2018 What is the Updated COSO ERM Framework? Key Changes to the

More information

WATCH WORDS FROM THE PEER REVIEW PROCESS

WATCH WORDS FROM THE PEER REVIEW PROCESS WATCH WORDS FROM THE PEER REVIEW PROCESS Peer Review 3 NOT DOCUMENTED = NOT PERFORMED Vendor-obtained practice aids, checklists and forms are NOT audit evidence Sources of audit evidence Books, records,

More information

Chapter 2. The CPA Profession

Chapter 2. The CPA Profession Chapter 2 The CPA Profession Review Questions 2-1 The four major services that CPAs provide are: 1. Audit and assurance services Assurance services are independent professional services that improve the

More information

Professional scepticism: its implications on audits of financial statements

Professional scepticism: its implications on audits of financial statements Professional scepticism: its implications on audits of financial statements Professional scepticism, which should never be a new term to any accounting student, is often perceived as the cornerstone of

More information

Auditing Standards and Practices Council

Auditing Standards and Practices Council Auditing Standards and Practices Council PHILIPPINE STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT PHILIPPINE STANDARD ON AUDITING

More information

FRAUD RISK FACTORS CHECKLIST (Source: New AU Section 240, Appendix A)

FRAUD RISK FACTORS CHECKLIST (Source: New AU Section 240, Appendix A) Page 136 of 174 FRAUD RISK FACTORS CHECKLIST (Source: New AU Section 240, Appendix A) RECOGNIZING RISK FACTORS THAT SHOULD GET YOUR ATTENTION How to use the checklist: 1. Review this checklist towards

More information

INTERNATIONAL STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT CONTENTS

INTERNATIONAL STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT CONTENTS INTERNATIONAL STANDARD ON AUDITING 315 UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT (Effective for audits of financial statements for periods beginning

More information

In 1992, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) issued a

In 1992, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) issued a Checkpoint Contents Accounting, Audit & Corporate Finance Library Editorial Materials Audit and Attest Internal Control Communications Chapter 1 INTRODUCTION AND OVERVIEW 100 Background 100 Background

More information

Auditing Standard 16

Auditing Standard 16 Certified Sarbanes-Oxley Expert Official Prep Course Part K Sarbanes Oxley Compliance Professionals Association (SOXCPA) The largest association of Sarbanes Oxley Professionals in the world Auditing Standard

More information

Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement

Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement Issued December 2007 International Standard on Auditing Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement The Malaysian Institute of Certified Public Accountants

More information

IAASB Main Agenda (March 2005) Page Agenda Item 12-C

IAASB Main Agenda (March 2005) Page Agenda Item 12-C IAASB Main Agenda (March 2005) Page 2005 429 Agenda Item 12-C [ISA AND IAPS SPLIT] PROPOSED INTERNATIONAL AUDITING PRACTICE STATEMENT XXX THE APPLICATION OF INTERNATIONAL STANDARDS ON AUDITING IN AN AUDIT

More information

IAASB Main Agenda (March 2016) Agenda Item. Initial Discussion on the IAASB s Future Project Related to ISA 315 (Revised) 1

IAASB Main Agenda (March 2016) Agenda Item. Initial Discussion on the IAASB s Future Project Related to ISA 315 (Revised) 1 Agenda Item 3-A Initial Discussion on the IAASB s Future Project Related to ISA 315 (Revised) 1 Objectives of the IAASB Discussion The objective of this agenda item are to: (a) Present initial background

More information

Risk management. Risk management system

Risk management. Risk management system Report on the main characteristics of the internal control and risk management system with respect to the accounting process according to Sec. 289 para. 4 of the German Commercial Code As an enterprise

More information

Question No: 1 FINALTERM EXAMINATION Fall 2008 ACC311- Fundamentals of Auditing (Session - 1) When the cash sales should be recorded by the companies in order to achieve control objectives? Record the

More information

CPA REVIEW SCHOOL OF THE PHILIPPINES M a n i l a AUDITING THEORY PROFESSIONAL AND LEGAL RESPONSIBILITIES

CPA REVIEW SCHOOL OF THE PHILIPPINES M a n i l a AUDITING THEORY PROFESSIONAL AND LEGAL RESPONSIBILITIES Page 1 of 10 CPA REVIEW SCHOOL OF THE PHILIPPINES M a n i l a Related PSAs : PSA 240rev, 250 and 260 AUDITING THEORY PROFESSIONAL AND LEGAL RESPONSIBILITIES PSA 240(rev) The Auditor s Responsibility to

More information

Practical Approach to Internal Controls for Pre & Post IPOs in Hong Kong & China

Practical Approach to Internal Controls for Pre & Post IPOs in Hong Kong & China Compliance Services: Accounting, Operations, and IT Processes 3394 Holly Oak Lane, Escondido, California 92027 Tel: 760.550.2160 Fax: 760.839.2160 Practical Approach to Internal Controls for Pre & Post

More information

STANDING ADVISORY GROUP MEETING

STANDING ADVISORY GROUP MEETING 1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STANDING ADVISORY GROUP MEETING CONSIDERATION OF OUTREACH AND RESEARCH REGARDING THE AUDITOR'S

More information

Speech by SEC Staff: Remarks before the 2007 AICPA National Conference on Current SEC and PCAOB Developments

Speech by SEC Staff: Remarks before the 2007 AICPA National Conference on Current SEC and PCAOB Developments Home Previous Page Speech by SEC Staff: Remarks before the 2007 AICPA National Conference on Current SEC and PCAOB Developments by Josh Jones Professional Accounting Fellow, Office of the Chief Accountant

More information

What Are Your Auditors Doing? Presented by Carrie Kennedy, Partner Travis Smith, Partner Moss Adams LLP

What Are Your Auditors Doing? Presented by Carrie Kennedy, Partner Travis Smith, Partner Moss Adams LLP What Are Your Auditors Doing? Presented by Carrie Kennedy, Partner Travis Smith, Partner Moss Adams LLP 1 MOSS ADAMS AT A GLANCE Full service national CPA firm providing assurance, tax, and consulting

More information

Internal Financial Control (IFC)& Internal Financial Controls over Financial Reporting (IFCoFR)

Internal Financial Control (IFC)& Internal Financial Controls over Financial Reporting (IFCoFR) Internal Financial Control (IFC)& Internal Financial Controls over Financial Reporting (IFCoFR) Origin of IFC The first significant focus on internal control certification related to financial reporting

More information

FOUNDATIONS IN ACCOUNTANCY Paper FAU (UK) Foundations in Audit (United Kingdom)

FOUNDATIONS IN ACCOUNTANCY Paper FAU (UK) Foundations in Audit (United Kingdom) Answers FOUNDATIONS IN ACCOUNTANCY Paper FAU (UK) Foundations in Audit (United Kingdom) June 2012 Answers Section A QUESTIONS 1 10 MULTIPLE CHOICE Question Answer See Note Below 1 A 1 2 D 2 3 C 3 4 B 4

More information

Case #1.1 Waste Management: The Matching Principle

Case #1.1 Waste Management: The Matching Principle Case #1.1 Waste Management: The Matching Principle I. Technical Guidance To maximize the knowledge acquired by students, this book has been designed to be read in conjunction with the post-sarbanes-oxley

More information

Alternative Operating Structures, Governance Best Practices and Fraud Risk Management

Alternative Operating Structures, Governance Best Practices and Fraud Risk Management THE UNIVERSITY OF TEXAS SCHOOL OF LAW Presented: 2015 Nonprofit Organizations Institute January 15-16, 2015 Austin, Texas Alternative Operating Structures, Governance Best Practices and Fraud Risk Management

More information

Post-Conference Auditing and Investigating Fraud Seminar

Post-Conference Auditing and Investigating Fraud Seminar Post-Conference Auditing and Investigating Fraud Seminar Auditing Track Auditors Fraud Responsibilities 1 of 18 Introduction Differing roles one goal External auditor Internal auditor Fraud examiner 2

More information

STAFF QUESTIONS AND ANSWERS

STAFF QUESTIONS AND ANSWERS 1666 K Street, N.W. Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STAFF QUESTIONS AND ANSWERS AUDITING INTERNAL CONTROL OVER FINANCIAL REPORTING Summary: Staff

More information

VERSION #1 PLEASE WRITE ON YOUR SCANTRON

VERSION #1 PLEASE WRITE ON YOUR SCANTRON VERSION #1 PLEASE WRITE ON YOUR SCANTRON ECON 132A MIDTERM #1 ANDERSON PLEASE answer multiple choice questions on green scantron and the rest in your blue book. When you are done put your scantron inside

More information

Internal Controls and Sampling Tests

Internal Controls and Sampling Tests Question 1: What important concepts should management consider in the design and implementation of internal controls? The two concepts that are important for management to consider in the design and implementation

More information

LeiningerCPA, Ltd. INTERNAL CONTROL PROCEDURE STATEMENT

LeiningerCPA, Ltd. INTERNAL CONTROL PROCEDURE STATEMENT LeiningerCPA, Ltd. INTERNAL CONTROL PROCEDURE STATEMENT Effective internal control is a foundation for safe and sound operations. Management and the Board of Directors are committed to providing sufficient

More information

AUDITING. Auditing PAGE 1

AUDITING. Auditing PAGE 1 AUDITING Auditing 1. Professionalism The International Professional Practices Framework (IPPF) is the conceptual framework that organizes authoritative guidance promulgated by The Institute of Internal

More information

International Standard on Auditing (Ireland) 402 Audit Considerations Relating to an Entity using a Service Organisation

International Standard on Auditing (Ireland) 402 Audit Considerations Relating to an Entity using a Service Organisation International Standard on Auditing (Ireland) 402 Audit Considerations Relating to an Entity using a Service Organisation MISSION To contribute to Ireland having a strong regulatory environment in which

More information

) ) ) ) ) ) ) ) ) ) ) ) PROPOSED AUDITING STANDARDS RELATED TO THE AUDITOR'S ASSESSMENT OF AND RESPONSE TO RISK

) ) ) ) ) ) ) ) ) ) ) ) PROPOSED AUDITING STANDARDS RELATED TO THE AUDITOR'S ASSESSMENT OF AND RESPONSE TO RISK 1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org PROPOSED AUDITING STANDARDS RELATED TO THE AUDITOR'S ASSESSMENT OF AND RESPONSE TO RISK AND

More information

Heads Up. When Small Looms Large SEC Staff Issues Materiality Guidance

Heads Up. When Small Looms Large SEC Staff Issues Materiality Guidance Heads Up Accounting, Tax, and Regulatory Developments Affecting Capital Markets Instruments and Strategies August 16, 1999; Volume 6; Issue 8 When Small Looms Large SEC Staff Issues Materiality Guidance

More information

REPORT 2016/033 INTERNAL AUDIT DIVISION

REPORT 2016/033 INTERNAL AUDIT DIVISION INTERNAL AUDIT DIVISION REPORT 2016/033 Advisory engagement on the Statement on Internal Control project at the United Nations Joint Staff Pension Fund 25 April 2016 Assignment No. VS2015/800/01 CONTENTS

More information

INTERNATIONAL STANDARD ON AUDITING 500 AUDIT EVIDENCE CONTENTS

INTERNATIONAL STANDARD ON AUDITING 500 AUDIT EVIDENCE CONTENTS INTERNATIONAL STANDARD ON 500 AUDIT EVIDENCE (Effective for audits of financial statements for periods beginning on or after December 15, 2004) CONTENTS Paragraph Introduction... 1-2 Concept of Audit Evidence...

More information

FDICIA Reporting for Financial Institutions. Reporting Changes Under Part 363 and SAS 130

FDICIA Reporting for Financial Institutions. Reporting Changes Under Part 363 and SAS 130 FDICIA Reporting for Financial Institutions Reporting Changes Under Part 363 and SAS 130 CONTENTS 02 INTRODUCTION REQUIREMENTS BY TIER 03 03 Management Assessment 04 05 03 Independent Auditors FILING DEADLINES

More information

Community Bankers Conference

Community Bankers Conference 3rd Annual Regional and Community Bankers Conference The Federal Reserve Bank of Boston Disclaimer NEVER WRONG DON T COMPLETELY RELY UPON Recent Developments in Audit Practice SOX, FDICIA 112, Other Robert

More information

CPA REVIEW SCHOOL OF THE PHILIPPINES M a n i l a AUDITING THEORY AUDIT PLANNING

CPA REVIEW SCHOOL OF THE PHILIPPINES M a n i l a AUDITING THEORY AUDIT PLANNING CPA REVIEW SCHOOL OF THE PHILIPPINES M a n i l a Related PSAs: PSA 300, 310, 320, 520 and 570 Appointment of the Independent Auditor AUDITING THEORY AUDIT PLANNING Page 1 of 9 Early appointment of the

More information

Mapping of Original ISA 315 to New ISA 315 s Standards and Application Material (AM) Agenda Item 2-C

Mapping of Original ISA 315 to New ISA 315 s Standards and Application Material (AM) Agenda Item 2-C Mapping of to 315 s and Application Material (AM) Agenda Item 2-C AM 1. The purpose of this International Standard on Auditing (ISA) is to establish standards and to provide guidance on obtaining an understanding

More information

IAASB CAG Public Session (March 2016) Agenda Item. Initial Discussion on the IAASB s Future Project Related to ISA 315 (Revised) 1

IAASB CAG Public Session (March 2016) Agenda Item. Initial Discussion on the IAASB s Future Project Related to ISA 315 (Revised) 1 Agenda Item C.1 Initial Discussion on the IAASB s Future Project Related to ISA 315 (Revised) 1 Objectives of the IAASB CAG Discussion The objective of this agenda item are to: (a) Present initial background

More information

AN AUDIT OF INTERNAL CONTROL THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS: GUIDANCE FOR AUDITORS OF SMALLER PUBLIC COMPANIES

AN AUDIT OF INTERNAL CONTROL THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS: GUIDANCE FOR AUDITORS OF SMALLER PUBLIC COMPANIES 1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org PRELIMINARY STAFF VIEWS AN AUDIT OF INTERNAL CONTROL THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL

More information

Auditors Moving from Guidance to Requirements: Arriving at the Risk Assessment Standards

Auditors Moving from Guidance to Requirements: Arriving at the Risk Assessment Standards Journal of Forensic & Investigative Accounting Vol. 2, Issue 2 Auditors Moving from Guidance to Requirements: Arriving at the Risk Assessment Standards Brian Patrick Green Alan Reinstein * The Auditing

More information

Background. Required Communications of Other Internal Control Deficiencies

Background. Required Communications of Other Internal Control Deficiencies Checkpoint Contents Accounting, Audit & Corporate Finance Library Editorial Materials Audit and Attest Management Letter Comments: Operations and Controls Chapter 1 Communication of Management Comments

More information

PLEASE complete #1-25 on your green scantron and the rest of them in your blue book.

PLEASE complete #1-25 on your green scantron and the rest of them in your blue book. Name: Date: You can keep this exam. PLEASE complete #1-25 on your green scantron and the rest of them in your blue book. 1. To qualify as "principal auditor" and render an opinion on the financial statements

More information

County of Sutter. Management Letter. June 30, 2012

County of Sutter. Management Letter. June 30, 2012 County of Sutter Management Letter June 30, 2012 County of Sutter Index Page Management Letter 3 Management Report Schedule of Current Year s 4 Schedule of Prior Auditor Comments 9 Prior Year Information

More information

29 th Regional Conference of WIRC

29 th Regional Conference of WIRC 29 th Regional Conference of WIRC Internal Financial Control - Auditors responsibility The Lalit International, Mumbai 6 December 2014 Contents 1 Provisions of Companies Act, 2013 2 Auditors responsibility

More information

ACTION Agenda Item I ANNUAL AUDIT REPORT December 6, 2002

ACTION Agenda Item I ANNUAL AUDIT REPORT December 6, 2002 ACTION Agenda Item I-2 2001-02 ANNUAL AUDIT REPORT December 6, 2002 Recommendation That the KCTCS Board of Regents receive the financial audit results for the 2001-02 fiscal year. Rationale The resolution

More information

Auditing Accounting Estimates, Including Fair Value Accounting Estimates, and Related Disclosures

Auditing Accounting Estimates, Including Fair Value Accounting Estimates, and Related Disclosures Auditing Accounting Estimates 511 AU-C Section 540 Auditing Accounting Estimates, Including Fair Value Accounting Estimates, and Related Disclosures Source: SAS No. 122. Effective for audits of financial

More information

A Discussion About Internal Controls February 2016

A Discussion About Internal Controls February 2016 A Discussion About Internal Controls February 2016 What we will cover today 001 Introductions 002 Defining Internal Controls 003 COSO Internal Controls Integrated Framework 004 Approach to Designing Internal

More information

2013 New COSO 2013 Framework and Current Trends in Risk Management

2013 New COSO 2013 Framework and Current Trends in Risk Management 2013 New COSO 2013 Framework and Current Trends in Risk Management Session 105 IASA 86 TH ANNUAL EDUCATIONAL CONFERENCE & BUSINESS SHOW Agenda COSO 2013 framework Overview Why the update? What has been

More information

STATEMENT OF AUDITING STANDARDS 500 AUDIT EVIDENCE

STATEMENT OF AUDITING STANDARDS 500 AUDIT EVIDENCE STATEMENT OF AUDITING STANDARDS 500 AUDIT EVIDENCE (Issued January 2004) Contents Paragraphs Introduction 1-2 Concept of Audit Evidence 3-6 Sufficient Appropriate Audit Evidence 7-14 The Use of Assertions

More information

COSO What s New, What s Changed, Why Does it Matter and Other Frequently Asked Questions

COSO What s New, What s Changed, Why Does it Matter and Other Frequently Asked Questions COSO 2013 What s New, What s Changed, Why Does it Matter and Other Frequently Asked Questions Today s Presenter Jonathan Reiss is a Director in Protiviti s New York office in the Internal Audit Practice.

More information

Comparison of the PCAOB s Auditing Standards No. 5 and No. 2 (Certain key differences are highlighted by underlining)

Comparison of the PCAOB s Auditing Standards No. 5 and No. 2 (Certain key differences are highlighted by underlining) Comparison of the PCAOB s Auditing Standards No. 5 and No. 2 (Certain key differences are highlighted by underlining) Topic AS No. 5 AS No. 2 Objective of ICFR Audit Planning the ICFR Audit Integration

More information

Special Considerations Audits of Group Financial Statements (Including the Work of Component Auditors)

Special Considerations Audits of Group Financial Statements (Including the Work of Component Auditors) Special Considerations---Audits of Group Financial Statements 665 AU-C Section 600 Special Considerations Audits of Group Financial Statements (Including the Work of Component Auditors) Source: SAS No.

More information

PCAOB PROPOSED INTERNAL CONTROL AUDIT STANDARD

PCAOB PROPOSED INTERNAL CONTROL AUDIT STANDARD PCAOB PROPOSED INTERNAL CONTROL AUDIT STANDARD Lorraine Magrath, Troy University Troy Campus Eddy J. Burks, Troy University Troy Campus ABSTRACT Two complete annual financial reporting cycles have been

More information

Chapter 4. Risk Assessment. Copyright 2012 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin

Chapter 4. Risk Assessment. Copyright 2012 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin Chapter 4 Risk Assessment McGraw-Hill/Irwin Copyright 2012 by The McGraw-Hill Companies, Inc. All rights reserved. LO# 1 Audit Risk The risk that an auditor expresses an unqualified opinion on materially

More information

Acceleron Pharma Inc. Code of Business Conduct and Ethics

Acceleron Pharma Inc. Code of Business Conduct and Ethics I. INTRODUCTION Acceleron Pharma Inc. Code of Business Conduct and Ethics (Amended & Restated as of March 1, 2018) This Code of Business Conduct and Ethics ( Code ) provides a general statement of the

More information

Navigating the PCAOB s and SEC s internal control expectations A discussion. June 2015

Navigating the PCAOB s and SEC s internal control expectations A discussion. June 2015 Navigating the PCAOB s and SEC s internal control expectations A discussion June 2015 Setting the scene ICFR guidance: PCAOB Auditing Standard No. 5 (May 2007) PCAOB staff views: An Audit of Internal Control

More information

SRI LANKA AUDITING STANDARD 315 (REVISED)

SRI LANKA AUDITING STANDARD 315 (REVISED) SRI LANKA AUDITING STANDARD 315 (REVISED) IDENTIFYING AND ASSESSING THE RISKS OF MATERIAL MISSTATEMENT THROUGH UNDERSTANDING THE ENTITY AND ITS ENVIRONMENT (Effective for audits of financial statements

More information

Audit Evidence. ISA 500 Issued December International Standard on Auditing

Audit Evidence. ISA 500 Issued December International Standard on Auditing Issued December 2007 International Standard on Auditing Audit Evidence The Malaysian Institute of Certified Public Accountants (Institut Akauntan Awam Bertauliah Malaysia) INTERNATIONAL STANDARD ON AUDITING

More information

BUSINESS CPA EXAM REVIEW V 3.0. For Exams Scheduled After March 31, 2017

BUSINESS CPA EXAM REVIEW V 3.0. For Exams Scheduled After March 31, 2017 For Exams Scheduled After March 31, 2017 CPA EXAM REVIEW BUSINESS UPDATES AND ACADEMIC HELP Click on Community and Support at www.becker.com/cpa CUSTOMER SERVICE AND TECHNICAL SUPPORT Call 1-877-CPA-EXAM

More information

Audit & Risk Committee Charter

Audit & Risk Committee Charter Audit & Risk Committee Charter Status: Approved Custodian: Executive Office Date approved: 2014-03-14 Implementation date: 2014-03-17 Decision number: SAQA 04103/14 Due for review: 2015-03-13 File Number:

More information

Stephen M. Eells State Auditor. Department of the Treasury Division of Revenue and Enterprise Services Information Technology Systems

Stephen M. Eells State Auditor. Department of the Treasury Division of Revenue and Enterprise Services Information Technology Systems Department of the Treasury Division of Revenue and Enterprise Services Information Technology Systems February 6, 2017 to June 20, 2018 Stephen M. Eells State Auditor Table of Contents Scope... 1 Objective...

More information

MODULE 2: Engagement Planning (11% 17%)

MODULE 2: Engagement Planning (11% 17%) AU2 Advanced External Auditing MODULE 2: Engagement Planning (11% 17%) Lecturer: Glen B. Carlson, B. Comm.(Honours), C.G.A. Module 2 engagement planning Module 2 covers the planning of an audit engagement,

More information

IAASB Main Agenda (December 2006) Page Agenda Item

IAASB Main Agenda (December 2006) Page Agenda Item IAASB Main Agenda (December 2006) Page 2006 3035 Agenda Item 6-C PROPOSED REVISED INTERNATIONAL STANDARD ON AUDITING 540 (COMBINED ISA 540-545) (Mark-up from Close-off ISA 540) AUDITING ACCOUNTING ESTIMATES,

More information

Name: Chapter 12 Revenue- and Inventory-Related Financial Statement Frauds MULTIPLE CHOICE

Name: Chapter 12 Revenue- and Inventory-Related Financial Statement Frauds MULTIPLE CHOICE Name: Chapter 12 Revenue- and Inventory-Related Financial Statement Frauds Instructions: There are 46 multiple choice questions on this quiz. You may choose any 25 (but only 25) questions to answer. Please

More information

International Standard on Auditing (Ireland) 315

International Standard on Auditing (Ireland) 315 International Standard on Auditing (Ireland) 315 Identifying and Assessing the Risks of Material Misstatement Through Understanding the Entity and its Environment MISSION To contribute to Ireland having

More information