Guide to Using International Standards on Auditing in - IFAC

Guide to Using International Standards on Auditing in - IFAC Guide to Using International Standards on Auditing in - IFAC

17.03.2014 Views

58 ong>Guideong> ong>toong> ong>Usingong> ong>Internationalong> ong>Standardsong> on Auditing in the Audits of Small- and Medium-Sized Entities Volume 1—Core Concepts Control Element The Key Question Possible Controls Participation by Those Charged With Governance (TCWG) (Other than Where Management is TCWG) Management’s Philosophy and Operating Style Organizational Structure Assignment of Authority and Responsibility How effective is the governance (if any) being provided over entity operations? What are management's attitudes and actions ong>toong>ward financial reporting? Has a relevant organizational structure been established? Have key areas of authority and responsibility been appropriately assigned? • A majority of TCWG are independent of management. • TCWG have the appropriate experience, stature, and financial expertise. • Significant issues and financial results are communicated ong>toong> TCWG in a timely manner. • TCWG provide effective oversight over management’s activities. This includes raising difficult questions and pursuing answers. • TCWG meet on a regular basis, and minutes of meetings are circulated in a timely basis. • Management demonstrates positive attitudes and actions ong>toong>ward: – Sound internal control over financial reporting (including management override and other fraud), – Appropriate selection/application of accounting policies, – Information-processing controls, and – The treatment of accounting personnel. • Management has established procedures ong>toong> prevent unauthorized access ong>toong> or destruction of assets, documents, and records. • Management analyzes business risks and takes appropriate action. • The organizational structure is appropriate ong>toong> facilitate achievement of entity objectives, operating functions, and regulaong>toong>ry requirements. • Management clearly understands its responsibility and authority for business activities, and possesses the requisite experience and levels of knowledge ong>toong> properly execute its positions. • The entity structure facilitates the flow of reliable and timely information ong>toong> the appropriate people for planning and controlling activities. • Incompatible duties are segregated ong>toong> the extent possible. • There are policies and procedures for authorization and approval of transactions. • Appropriate lines of reporting and accountability exist (appropriate ong>toong> the entity’s size and the nature of its activities). • Job descriptions include control-related responsibilities.

59 ong>Guideong> ong>toong> ong>Usingong> ong>Internationalong> ong>Standardsong> on Auditing in the Audits of Small- and Medium-Sized Entities Volume 1—Core Concepts Control Element The Key Question Possible Controls Human Resources Policies and Practices What standards are in place ong>toong> ensure: Recruitment of the most competent and trustworthy people? Training is provided ong>toong> ensure people can perform their jobs? Promotions are driven by performance appraisals? • Management establishes/enforces standards for hiring the most qualified individuals. • Recruiting practices include employment interviews, background checks, and communication of values, expected behaviors, and management’s operating style. • Job performance is periodically evaluated, the results reviewed with each employee, and appropriate action taken. • Training policies address prospective roles and responsibilities, expected levels of performance, and evolving needs. 5.4 Risk Assessment Paragraph # Relevant Extracts from ISAs 315.15 The audiong>toong>r shall obtain an understanding of whether the entity has a process for: (a) Identifying business risks relevant ong>toong> financial reporting objectives; (b) Estimating the significance of the risks; (c) Assessing the likelihood of their occurrence; and (d) Deciding about actions ong>toong> address those risks. (Ref: Para. A79) 315.16 If the entity has established such a process (referred ong>toong> hereafter as the “entity’s risk assessment process”), the audiong>toong>r shall obtain an understanding of it, and the results thereof. If the audiong>toong>r identifies risks of material misstatement that management failed ong>toong> identify, the audiong>toong>r shall evaluate whether there was an underlying risk of a kind that the audiong>toong>r expects would have been identified by the entity’s risk assessment process. If there is such a risk, the audiong>toong>r shall obtain an understanding of why that process failed ong>toong> identify it, and evaluate whether the process is appropriate ong>toong> its circumstances or determine if there is a significant deficiency in internal control with regard ong>toong> the entity’s risk assessment process. 315.17 If the entity has not established such a process or has an ad hoc process, the audiong>toong>r shall discuss with management whether business risks relevant ong>toong> financial reporting objectives have been identified and how they have been addressed. The audiong>toong>r shall evaluate whether the absence of a documented risk assessment process is appropriate in the circumstances, or determine whether it represents a significant deficiency in internal control. (Ref: Para. A80)

59<br />

<str<strong>on</strong>g>Guide</str<strong>on</strong>g> <str<strong>on</strong>g>to</str<strong>on</strong>g> <str<strong>on</strong>g>Us<strong>in</strong>g</str<strong>on</strong>g> <str<strong>on</strong>g>Internati<strong>on</strong>al</str<strong>on</strong>g> <str<strong>on</strong>g>Standards</str<strong>on</strong>g> <strong>on</strong> <strong>Audit<strong>in</strong>g</strong> <strong>in</strong> the Audits of Small- and Medium-Sized Entities Volume 1—Core C<strong>on</strong>cepts<br />

C<strong>on</strong>trol Element The Key Questi<strong>on</strong> Possible C<strong>on</strong>trols<br />

Human Resources<br />

Policies and<br />

Practices<br />

What standards are<br />

<strong>in</strong> place <str<strong>on</strong>g>to</str<strong>on</strong>g> ensure:<br />

Recruitment of the<br />

most competent<br />

and trustworthy<br />

people?<br />

Tra<strong>in</strong><strong>in</strong>g is provided<br />

<str<strong>on</strong>g>to</str<strong>on</strong>g> ensure people<br />

can perform their<br />

jobs?<br />

Promoti<strong>on</strong>s<br />

are driven by<br />

performance<br />

appraisals?<br />

• Management establishes/enforces standards for hir<strong>in</strong>g<br />

the most qualified <strong>in</strong>dividuals.<br />

• Recruit<strong>in</strong>g practices <strong>in</strong>clude employment <strong>in</strong>terviews,<br />

background checks, and communicati<strong>on</strong> of values,<br />

expected behaviors, and management’s operat<strong>in</strong>g style.<br />

• Job performance is periodically evaluated, the results<br />

reviewed with each employee, and appropriate acti<strong>on</strong><br />

taken.<br />

• Tra<strong>in</strong><strong>in</strong>g policies address prospective roles and<br />

resp<strong>on</strong>sibilities, expected levels of performance, and<br />

evolv<strong>in</strong>g needs.<br />

5.4 Risk Assessment<br />

Paragraph #<br />

Relevant Extracts from ISAs<br />

315.15 The audi<str<strong>on</strong>g>to</str<strong>on</strong>g>r shall obta<strong>in</strong> an understand<strong>in</strong>g of whether the entity has a process for:<br />

(a) Identify<strong>in</strong>g bus<strong>in</strong>ess risks relevant <str<strong>on</strong>g>to</str<strong>on</strong>g> f<strong>in</strong>ancial report<strong>in</strong>g objectives;<br />

(b) Estimat<strong>in</strong>g the significance of the risks;<br />

(c) Assess<strong>in</strong>g the likelihood of their occurrence; and<br />

(d) Decid<strong>in</strong>g about acti<strong>on</strong>s <str<strong>on</strong>g>to</str<strong>on</strong>g> address those risks. (Ref: Para. A79)<br />

315.16 If the entity has established such a process (referred <str<strong>on</strong>g>to</str<strong>on</strong>g> hereafter as the “entity’s risk<br />

assessment process”), the audi<str<strong>on</strong>g>to</str<strong>on</strong>g>r shall obta<strong>in</strong> an understand<strong>in</strong>g of it, and the results thereof.<br />

If the audi<str<strong>on</strong>g>to</str<strong>on</strong>g>r identifies risks of material misstatement that management failed <str<strong>on</strong>g>to</str<strong>on</strong>g> identify, the<br />

audi<str<strong>on</strong>g>to</str<strong>on</strong>g>r shall evaluate whether there was an underly<strong>in</strong>g risk of a k<strong>in</strong>d that the audi<str<strong>on</strong>g>to</str<strong>on</strong>g>r expects<br />

would have been identified by the entity’s risk assessment process. If there is such a risk, the<br />

audi<str<strong>on</strong>g>to</str<strong>on</strong>g>r shall obta<strong>in</strong> an understand<strong>in</strong>g of why that process failed <str<strong>on</strong>g>to</str<strong>on</strong>g> identify it, and evaluate<br />

whether the process is appropriate <str<strong>on</strong>g>to</str<strong>on</strong>g> its circumstances or determ<strong>in</strong>e if there is a significant<br />

deficiency <strong>in</strong> <strong>in</strong>ternal c<strong>on</strong>trol with regard <str<strong>on</strong>g>to</str<strong>on</strong>g> the entity’s risk assessment process.<br />

315.17 If the entity has not established such a process or has an ad hoc process, the audi<str<strong>on</strong>g>to</str<strong>on</strong>g>r shall<br />

discuss with management whether bus<strong>in</strong>ess risks relevant <str<strong>on</strong>g>to</str<strong>on</strong>g> f<strong>in</strong>ancial report<strong>in</strong>g objectives<br />

have been identified and how they have been addressed. The audi<str<strong>on</strong>g>to</str<strong>on</strong>g>r shall evaluate whether<br />

the absence of a documented risk assessment process is appropriate <strong>in</strong> the circumstances, or<br />

determ<strong>in</strong>e whether it represents a significant deficiency <strong>in</strong> <strong>in</strong>ternal c<strong>on</strong>trol. (Ref: Para. A80)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!