Audit Standards 6/23/2017. Outline. Let s Refresh. Changes to the IIA Standards

Similar documents
The Red (Book) Rocks The Latest and Greatest Audit Standards

Lake County School District. Quality Assurance & Improvement Program. Internal Self-Assessment for. The Internal Audit Department

International Standards for the Professional Practice of Internal Auditing (Standards)

International Standards for the Professional Practice of Internal Auditing

Report. Quality Assessment of Internal Audit at <Organisation> Draft Report / Final Report

International Standards for the Professional Practice of Internal Auditing (Standards)

INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS)

GoldSRD Audit 101 Table of Contents & Resource Listing

Internal Audit Quality Analysis Evaluation against the Standards International Standards for the Professional Practice of Internal Auditing (2017)

Changes To the Public Sector Internal Audit Standards April 2017

CONNECTING THE INTERNAL AUDIT DOTS AN OVERVIEW OF INTERNAL AUDIT S ROLE, SCOPE, STANDARDS AND ENGAGEMENT APPROACH

Quality Assurance and Improvement Program (QAIP)

How to Pass an ALGA Yellow Book Peer Review Training by the Association of Local Government Auditors (ALGA) Tampa, Florida September 20, 2013

Practice Advisory : Quality Assurance and Improvement Program

Changes to The IIA Standards: What Board Members and Executive Management Need to Know

INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING

What We Will Cover Today

U. S. GAO Government Auditing Standards Update The New Yellow Book

Quality Assessment Review. Agenda. The Law Says 11/16/2015. Internal Audit Management November 19-20, 2015

Kentucky State University Office of Internal Audit

10/5/2016. Quality Assessment Review. Agenda. What s the purpose of a QAR? Internal Audit Manager Training October 3-4, 2016

Group Internal Audit Charter

Format and organization of GAGAS Auditor preparation of financials is a significant threat to independence 3 party arrangements in government State

Internal Audit Charter

Implementation Guide 1312

Practice Advisory : Internal Audit Charter

Guidance Note: Corporate Governance - Audit Committee. March Ce document est aussi disponible en français.

External Quality Assessment Are You Ready? Institute of Internal Auditors

Guidance Note: Corporate Governance - Audit Committee. January Ce document est aussi disponible en français.

Chapter 6 Field Work Standards for Performance Audits

The IPPF in How changes to The IIA s guidance framework can benefit internal auditors and SAIs

Internal Audit Quality Policy

Government Auditing Standards

2012 IIA Standards Update

Implementation Guide 1300

STANDARDS: QUALITY ASSURANCE

Internal Audit Charter

Community Bankers Conference

Periodic internal quality assessment Questions for discussion

SIAAB Guidance #05. Conforming with FCIAA and Standards in Small Audit Functions in the State of Illinois. Adopted December 8, 2015

Implementation Guide 1200

Internal Audit Charter

External Quality Assessment Review of University of Florida s Office of Internal Audit

City of Edmonton EXTERNAL QUALITY ASSESSMENT OF THE OFFICE OF THE CITY AUDITOR. September 11, 2015

Internal Audit Policy and Procedures Internal Audit Charter

AUDITING. Auditing PAGE 1

External Quality Assessment of the Internal Audit Activity at the World Food Programme

Performance Auditing: What It Is, and Why It Is Important Presented by: Harriet Richardson, CPA, CIA, CGAP Audit Manager, City of Berkeley

OFFICE OF INTERNAL AUDITS APPALACHIAN STATE UNIVERSITY AUDIT MANUAL

Independent Validation of the Internal Auditing Self-Assessment

FLORIDA STATE UNIVERSITY Office of Inspector General Services Report #17-06

INTERNAL AUDIT CHARTER SECURE TRUST BANK PLC

Internal Audit Charter

External Quality Assessment of the Internal Audit Activity at. County of Orange. April County of Orange Final Report: June 13,

Implementation Guide 2060

OPERATIONAL DIRECTIVE REF. OD.ED INTERNAL AUDIT AND INVESTIGATIONS CHARTER

Audit and Risk Committee Charter

1. Definition & Mission

Quality Assurance in Internal Audit. Standard on Internal Audit (SIA) 7

This Internal Audit Charter is intended to define the role, responsibility and accountability of the Society s Internal Audit function.

COPYRIGHTED MATERIAL AUDIT SCHEDULING. Focus on: Conduct Engagements (25 35%) 1

August 14, Dear Ms. Gula:

Internal Audit Charter

GROUP INTERNAL AUDIT. Internal Audit Charter 24 February 2016

An Examination of an Entity s Internal Control Over Financial Reporting That Is Integrated With an Audit of Its Financial Statements

Implementation Guide 2340

Quality Assessments what you need to know

Self Assessment Workbook

CATERPILLAR INC. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS (adopted by the Board of Directors on February 11, 2015)

United Nations Development Programme Office of Audit and Investigations CHARTER OF THE OFFICE OF AUDIT AND INVESTIGATIONS.

Internal Audit Annual Assertion on Internal Auditing. for Financial Year

Practice Guide. Developing the Internal Audit Strategic Plan

In 1992, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) issued a

CLIENT ALERT: INTERNAL CONTROL OVER FINANCIAL REPORTING

Guidance Note: Corporate Governance - Board of Directors. January Ce document est aussi disponible en français.

AUDIT COMMITTEE REPORTING: TRENDS & BEST PRACTICES Timothy Etoori Head of Internal Audit UGAFODE Microfinance

Internal Audit Standards Board Disposition on the 2010 Standards Exposure Results/Comments. Introduction

Canada. Internal Audit Charter 1+1. Canadian Nuclear Safety Commission. Office of Audit and Ethics. April 18, 2011

Internal Audit Mandate

VIRGINIA POLYTECHNIC INSTITUTE AND STATE UNIVERSITY COMPLIANCE, AUDIT, AND RISK COMMITTEE OF THE BOARD OF VISITORS COMPLIANCE, AUDIT, AND RISK CHARTER

Statement on February 2014 Auditing Standards 128. Using the Work of Internal Auditors

AUDIT COMMITTEE OF THE BOARD OF DIRECTORS

3.6.2 Internal Audit Charter Adopted by the Board: November 12, 2013

Policy and Procedures Date: November 5, 2017

CABOT OIL & GAS CORPORATION AUDIT COMMITTEE CHARTER

INTERNAL AUDIT DEPARTMENT CHARTER

Control Environment Toolkit: Internal Audit Function

Caribbean Association of Audit Committee Members Inc. Independent Quality Assurance Assessment of the Internal Audit function

INTERNAL AUDIT CHARTER

Agreeing the Terms of Audit Engagements

SA 210 (REVISED) AGREEING THE TERMS OF AUDIT ENGAGEMENTS (EFFECTIVE FOR ALL AUDITS RELATING TO ACCOUNTING PERIODS BEGINNING ON OR AFTER APRIL 1, 2010)

Bank of Botswana Internal Audit Charter March 18, 2013 INTERNAL AUDIT CHARTER BANK OF BOTSWANA

CGIAR System Management Board Audit and Risk Committee Terms of Reference

May 3, To the Jail Board Members and Management Western Tidewater Regional Jail Authority 2402 Godwin Blvd Suffolk, Virginia 23434

RREGULATION ON INTERNAL CONTROLS AND INTERNAL AUDIT FUNCTION IN MICROFINANCE INSTITUTIONS. Article 1 Scope and Purpose

Dena Jansen, CPA Partner Maxwell Locke & Ritter LLP

INTERNAL AUDIT CHARTER

Internal controls over Financial Reporting Key concepts. Presentation by Jayesh Gandhi at WIRC

Dexia Group Audit Charter

Transcription:

Audit Standards Let s Refresh Outline Changes in the Standards Changes in the Yellowbook Standards Attribute/General Standards Performance/Fieldwork Standards Reporting Standards Key Differences Changes to the Standards 1

Introduced a Mission Statement July 2015 Introduced the new and improved International Professional Practices Framework (IPPF) Added the Core Principles for Internal Auditing Practice Transitioned Practice Advisories to Implementation Guidance Merged Practice Guides and Global Technology Audit Guides (GTAGS) into Supplemental Guidance January 1, 2017 New Standards are effective! Two new standards, pertaining to: CAEs taking on roles in risk management, compliance, or other roles beyond internal auditing Assurance engagement after previously consulting in that area Alignment of the Standards to the Core Principles: Aligns with the strategies, objectives, and risks of the organization, Is insightful, proactive, and future-focused. Updates to existing Standards: Communications QAIP (AKA Peer reviews) Changes to the Yellowbook 2

Changes to its format and structure, April 5, 2017 - July 6, 2017 Exposure Draft Comment Period Updates on the following topics: Independence Competence and Continuing Professional Education Quality Control and Peer Review Financial Audits Attestation Engagements and Reviews of Financial Statements Performance Audits Stay tuned Next Year! vs Differences 3

Applicability Auditors of Government entities Auditors of entities that receive government awards Entities performing Audits IPPF Internal Auditors worldwide All Industries Differences Between Attribute/General Standards Attribute/General Standards Independence Professional Judgement Competence Quality Control & Assurance Purpose, Authority, Responsibility Independence & Objectivity Proficiency & Due Professional Care Quality Assurance & Improvement Program 4

Purpose, Authority & Responsibility Defined Engagement by Engagement Financial Audits Attestations Engagements Performance Audits Non-audit Services Charter Defined nature of assurance services Nature of consulting services Independence & Objectivity 3.02 In all matters relating to the audit work, the audit organization and the individual auditor, whether government or public, must be independent. Mind Appearance Organizational 3.02 3.32 (>22 pages!) 1100 Independence and Objectivity The internal audit activity must be independent, and internal auditors must be objective in performing their work. Organization Independent Auditors Objective Independence & Objectivity INTERNAL AUDITORS Orange encouraged Head charged with governance Results reported Organizationally outside line management Access to those charged with Governance Sufficiently removed from political pressures Level within the organization without interference Direct interaction with the board Safeguards for roles outside of Internal Auditing Individual Objectivity Disclosure of impairments 5

Knowledge, Skills, and Abilities Competence Collectively possess adequate professional competence Knowledge of General knowledge of environment Skills to communicate clearly and effectively Skills appropriate for the work being performed (i.e. sampling, IT, engineering) Specialize Knowledge as appropriate (GAAP, SAS, SSAE) Proficiency & Due Professional Care Must possess the knowledge and skills Collectively within work group Evaluate risk of fraud Knowledge of key information technology risks Decline engagements/consult out if lacking knowledge and skills Exercise Due Professional Care Continuing Professional Education Every two year 24 Hours Government Auditing Government Environment Specific or Unique Environment Planning, directing or reporting 56 Additional Hours At least 20 hours/year Must enhance: Knowledge Skill Other Competencies Meet Certification Requirements CIA - 40 hours a year Auditing or Accounting Management & Communication Computer Science, Math, Econ, Law Specific business topics/industry Quality Assurance and Control System of Quality Control Encompass leadership, quality work, policies and procedures Documented On-going, periodic assessments External Peer Review Every 3 years Rules Report Requirements Must develop a program to ensure conformance Cover all aspects of the activity Internal Assessments On-going (day to day sup) Periodic External Assessments (QAIP) Every 5 years Independent qualified team 6

Differences Between Fieldwork/Performance Standards Fieldwork/Performance Standards Reasonable Assurance Significance Audit Risk Planning Supervision Evidence Audit Documentation Managing the Internal Audit Activity Nature of the work Engagement Planning Performing the engagement Communicating Results Monitoring Progress Resolution of Senior Management s Acceptance of Risk Managing the Internal Audit Activity 2000 - The chief audit executive must effectively manage the internal audit activity to ensure it adds value to the organization. Effectively managed when: Achieves its purpose identified in the charter Conforms with the standards Each auditor conforms to the Code of Ethics It considers trends and emerging issues Enhances governance, risk management and control processe Adds Value if it considers: Strategies Objectives Risk 7

Annual Audit Plan 2010 Planning The chief audit executive must establish a risk-based plan to determine the priorities of the internal audit activity, consistent with the organization s goals. Documented risk assessment Annually Consider expectation of senior management Senior Management Approval Resource constrained Reasonable Assurance 6.03 - In performance audits that comply with, auditors obtain reasonable assurance that evidence is sufficient and appropriate to support the auditors findings and conclusions in relation to the audit objectives. Depends on the engagement Evaluate whether evidence Sufficient Appropriate Significance & Risk/ Nature of the audit Significance (AKA Material) Relative importance Context Qualitative Quantitative Audit Risk Findings, conclusions, recommendations or assurances Improper or incomplete Nature Contribute to the improvement Governance Risk Management Control Processes Systematic Disciplined Risk Based 8

Planning Planned to reduce audit risk Should assess audit risk & significance and apply to the audit objectives and the scope/methodology Must consider Organization s strategies Organization s Objectives Risk relevant to the engagement Planning Considerations Should assess nature and profile of program considering the potential users Within in context of audit objectives Internal Controls Information systems controls Laws, regulations, contracts, grant agreements Potential fraud and abuse Ongoing investigations Results of previous audits/attestations Must consider Strategies and objectives of the activity Significant risks to the objectives, resources and operations Adequacy and effectiveness of governance, risk management and control Opportunities for making significant improvements to governance, risk management and control processes Audit Plan Prepare a written plan May include Strategy Audit program Project plan Audit planning paper Key decisions Audit objectives Scope and methodology Work Program Engagement Objectives Scope Resource allocation Procedures for identifying, analyzing, evaluating and documenting information 9

Supervision Must supervise staff Providing sufficient guidance Staying informed on problems encountered Reviewing work Provide OJT Nature and Extent depending on Size of audit Significance of work Experience of staff Properly supervise Depend on proficiency and experience of internal auditors Evidence Sufficient Persuade a knowledgeable person Appropriate Relevant Valid Reliable Sufficient Reliable Relevant Useful To achieve objectives Provide a reasonable basis for conclusion Elements of Finding Criteria Condition Cause Effect or Potential Effect 5 C s Criteria Condition Consequence Cause Corrective Action 10

Documentation 6.79 Auditors should prepare audit documentation in sufficient detail to enable an experienced auditor, having no previous connection to the audit, to understand from the audit documentation the nature, timing, extent, and results of audit procedures performed, the audit evidence obtained and its source and the conclusions reached, including evidence that supports the auditors significant judgments and conclusions. 2330 Must document sufficient, reliable, relevant and useful information to support the engagement results and conclusions. 2310 (Interpretation) Sufficient information is factual, adequate, and convincing so that a prudent, informed person would reach the same conclusions as the auditor. Differences Between Reporting Standards Reporting Standards Reporting Report Contents Distributing Reports (Performance Standards) Managing the Internal Audit Activity Nature of the work Engagement Planning Performing the engagement Communicating Results Monitoring Progress Resolution of Senior Management s Acceptance of Risk 11

Reporting Auditors must issue audit reports communicating the results of each completed performance audit. (7.03) Internal auditors must communicate the results of engagements. (2400) Appropriate form Purpose Communicate results Reduce misunderstandings Make available to public Facilitate follow-up Report Content Audit Objectives Scope and Methodology Support Findings Report Limitations Perspective (of findings) Background Information Deficiencies in Internal Control, instances of fraud, and non-compliance Conclusions Recommendations Engagement s objectives Scope Results Applicable conclusions Where appropriate, opinion Must be accurate, objective, clear, concise, constructive, complete and timely Report Content (cont) Conformance Views of Responsible Officials Conducted in conformance with the International Standards for the Professional Practice of Internal Auditing Satisfactory Performance Outside parties limitations for distribution 12

Distribution of Report Government Auditors Those charged with governance Copies to others with legal oversight Internal Auditors Parties who give results due consideration Mandated by statute/regulations Public Accounting Firms In accordance with the engagement agreement Appropriate Parties Due Consideration Additional follow-up Must have a system to monitor the disposition of results Must communicate when management has accepted unacceptable levels of risk Key Differences Differences 3 Categories of Standards Independent & Objective Non-Audit Services Focus Audit Risk & Significance Written Report Experienced auditor, having no previous connection to the audit, to understand 2 Categories of Standards Objective & Organizationally Independent Consulting Activities Focus Organization s strategies, objectives and risk & Adding Value Must Communicate Prudent, informed person would reach the same conclusions as the auditor 13

Questions Audit Standards Let s Refresh 14