Public Company Accounting Oversight Board; Notice of Filing of Proposed Rules on Auditing Standards Related to the Auditor's Assessment of and Response to Risk and Related Amendments to PCAOB Standards

Federal RegisterSep 27, 2010

Ask Donna

What actually matters in this document.

Text

SECURITIES AND EXCHANGE COMMISSION

[Release No. 34-62919; File No. PCAOB-2010-01]

Public Company Accounting Oversight Board; Notice of Filing of Proposed Rules on Auditing Standards Related to the Auditor's Assessment of and Response to Risk and Related Amendments to PCAOB Standards

September 15, 2010.

Pursuant to Section 107(b) of the Sarbanes-Oxley Act of 2002 (the “Act”), notice is hereby given that on September 15, 2010, the Public Company Accounting Oversight Board (the “Board” or the “PCAOB”) filed with the Securities and Exchange Commission (the “Commission”) the proposed rules described in Items I and II below, which items have been prepared by the Board. The Commission is publishing this notice to solicit comments on the proposed rules from interested persons.

I. Board's Statement of the Terms of Substance of the Proposed Rules

On August 5, 2010, the Board adopted the following eight auditing standards:

• Auditing Standard No. 8,

Audit Risk

• Auditing Standard No. 9,

Audit Planning

• Auditing Standard No. 10,

Supervision of the Audit Engagement

• Auditing Standard No. 11,

Consideration of Materiality in Planning and Performing an Audit

• Auditing Standard No. 12,

Identifying and Assessing Risks of Material Misstatement

• Auditing Standard No. 13,

The Auditor's Responses to the Risks of Material Misstatement

• Auditing Standard No. 14,

Evaluating Audit Results

• Auditing Standard No. 15,

Audit Evidence

(collectively referred to as the “Risk Assessment Standards”); and amendment to the Board's interim auditing standards (collectively, “the proposed rules ”). The text of the Risk Assessment Standards and amendments to the Board's interim auditing standards are set out below.

Auditing Standard No. 8

Audit Risk

Introduction

1. This standard discusses the auditor's consideration of audit risk in an audit of financial statements as part of an integrated audit

1

or an audit of financial statements only.

1

When the auditor is performing an integrated audit of financial statements and internal control over financial reporting, the requirements in Auditing Standard No. 5,

An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements,

also apply. However, the risks of material misstatement of the financial statements are the same for both the audit of financial statements and the audit of internal control over financial reporting.

Objective

2. The objective of the auditor is to conduct the audit of financial statements in a manner that reduces audit risk to an appropriately low level.

Audit Risk

3. To form an appropriate basis for expressing an opinion on the financial statements, the auditor must plan and perform the audit to obtain reasonable assurance about whether the financial statements are free of material misstatement

2

due to error or fraud. Reasonable assurance

3

is obtained by reducing audit risk to an appropriately low level through applying due professional care, including obtaining sufficient appropriate audit evidence.

2

Misstatement is defined in Appendix A of Auditing Standard No. 14,

Evaluating Audit Results.

3

See

AU sec. 110,

Responsibilities and Functions of the Independent Auditor,

and paragraph .10 of AU sec. 230,

Due Professional Care in the Performance of Work,

for a further discussion of reasonable assurance.

4. In an audit of financial statements, audit risk is the risk that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated, i.e., the financial statements are not presented fairly in conformity with the applicable financial reporting framework. Audit risk is a function of the risk of material misstatement and detection risk.

Note: The auditor should look to the requirements of the Securities and Exchange Commission for the company under audit with respect to the accounting principles applicable to that company.

Risk of Material Misstatement

5. The risk of material misstatement refers to the risk that the financial statements are materially misstated. Auditing Standard No. 12,

Identifying and Assessing Risks of Material Misstatement,

indicates that the auditor should assess the risks of material misstatement at two levels: (1) At the financial statement level and (2) at the assertion

4

level.

5

4

See

Auditing Standard No. 15,

Audit Evidence,

for a description of financial statement assertions.

5

Paragraph 59 of Auditing Standard No. 12.

6. Risks of material misstatement at the financial statement level relate pervasively to the financial statements as a whole and potentially affect many assertions. Risks of material misstatement at the financial statement level may be especially relevant to the auditor's consideration of the risk of material misstatement due to fraud. For example, an ineffective control environment, a lack of sufficient capital to continue operations, and declining conditions affecting the company's industry might create pressures or opportunities for management to manipulate the financial statements, leading to higher risk of material misstatement.

7. Risk of material misstatement at the assertion level consists of the following components:

a.

Inherent risk,

which refers to the susceptibility of an assertion to a misstatement, due to error or fraud, that could be material, individually or in combination with other misstatements, before consideration of any related controls.

b.

Control risk,

which is the risk that a misstatement due to error or fraud that could occur in an assertion and that could be material, individually or in combination with other misstatements, will not be prevented or detected on a timely basis by the company's internal control. Control risk is a function of the effectiveness of the design and operation of internal control.

8. Inherent risk and control risk are related to the company, its environment, and its internal control, and the auditor assesses those risks based on evidence he or she obtains. The auditor assesses inherent risk using information obtained from performing risk assessment procedures and considering the characteristics of the accounts and disclosures in the financial statements.

6

The auditor assesses control risk using evidence obtained from tests of controls (if the auditor plans to rely on those controls to assess control risk at less than maximum) and from other sources.

7

6

Paragraph 59.a. of Auditing Standard No. 12.

7

Paragraphs 32-34 of Auditing Standard No. 13,

The Auditor's Responses to the Risks of Material Misstatement.

Detection Risk

9. In an audit of financial statements, detection risk is the risk that the procedures performed by the auditor will not detect a misstatement that exists and that could be material, individually or in combination with other misstatements. Detection risk is affected by (1) the effectiveness of the

substantive procedures and (2) their application by the auditor, i.e., whether the procedures were performed with due professional care.

10. The auditor uses the assessed risk of material misstatement to determine the appropriate level of detection risk for a financial statement assertion. The higher the risk of material misstatement, the lower the level of detection risk needs to be in order to reduce audit risk to an appropriately low level.

11. The auditor reduces the level of detection risk through the nature, timing, and extent of the substantive procedures performed. As the appropriate level of detection risk decreases, the evidence from substantive procedures that the auditor should obtain increases.

8

8

Paragraph 37 of Auditing Standard No. 13.

Auditing Standard No. 9

Audit Planning

Introduction

1. This standard establishes requirements regarding planning an audit.

Objective

2. The objective of the auditor is to plan the audit so that the audit is conducted effectively.

Responsibility of the Engagement Partner for Planning

3. The

engagement partner

9

is responsible for the engagement and its performance. Accordingly, the engagement partner is responsible for planning the audit and may seek assistance from appropriate engagement team members in fulfilling this responsibility. Engagement team members who assist the engagement partner with audit planning also should comply with the relevant requirements in this standard.

9

Terms defined in Appendix A,

Definitions,

are set in boldface type the first time they appear.

Planning an Audit

4. The auditor should properly plan the audit. This standard describes the auditor's responsibilities for properly planning the audit.

10

10

The term, “auditor,” as used in this standard, encompasses both the engagement partner and the engagement team members who assist the engagement partner in planning the audit.

5. Planning the audit includes establishing the overall audit strategy for the engagement and developing an audit plan, which includes, in particular, planned risk assessment procedures and planned responses to the risks of material misstatement. Planning is not a discrete phase of an audit but, rather, a continual and iterative process that might begin shortly after (or in connection with) the completion of the previous audit and continues until the completion of the current audit.

Preliminary Engagement Activities

6. The auditor should perform the following activities at the beginning of the audit:

a. Perform procedures regarding the continuance of the client relationship and the specific audit engagement,

11

11

Paragraphs .14-.16 of QC sec. 20,

System of Quality Control for a CPA Firm's Accounting and Auditing Practice.

AU sec. 161,

The Relationship of Generally Accepted Auditing Standards to Quality Control Standards,

explains how the quality control standards relate to the conduct of audits.

b. Determine compliance with independence and ethics requirements, and

Note: The determination of compliance with independence and ethics requirements is not limited to preliminary engagement activities and should be reevaluated with changes in circumstances.

c. Establish an understanding with the client regarding the services to be performed on the engagement.

12

12

AU sec. 310,

Appointment of the Independent Auditor.

Planning Activities

7. The nature and extent of planning activities that are necessary depend on the size and complexity of the company, the auditor's previous experience with the company, and changes in circumstances that occur during the audit. When developing the audit strategy and audit plan, as discussed in paragraphs 8-10, the auditor should evaluate whether the following matters are important to the company's financial statements and internal control over financial reporting and, if so, how they will affect the auditor's procedures:

• Knowledge of the company's internal control over financial reporting obtained during other engagements performed by the auditor;

• Matters affecting the industry in which the company operates, such as financial reporting practices, economic conditions, laws and regulations, and technological changes;

• Matters relating to the company's business, including its organization, operating characteristics, and capital structure;

• The extent of recent changes, if any, in the company, its operations, or its internal control over financial reporting;

• The auditor's preliminary judgments about materiality,

13

risk, and, in integrated audits, other factors relating to the determination of material weaknesses;

13

Auditing Standard No. 11,

Consideration of Materiality in Planning and Performing an Audit.

• Control deficiencies previously communicated to the audit committee

14

or management;

14

If no audit committee exists, all references to the audit committee in this standard apply to the entire board of directors of the company.

See

15 U.S.C. §§ 78c(a)58 and 7201(a)(3).

• Legal or regulatory matters of which the company is aware;

• The type and extent of available evidence related to the effectiveness of the company's internal control over financial reporting;

• Preliminary judgments about the effectiveness of internal control over financial reporting;

• Public information about the company relevant to the evaluation of the likelihood of material financial statement misstatements and the effectiveness of the company's internal control over financial reporting;

• Knowledge about risks related to the company evaluated as part of the auditor's client acceptance and retention evaluation; and

• The relative complexity of the company's operations.

Note: Many smaller companies have less complex operations. Additionally, some larger, complex companies may have less complex units or processes. Factors that might indicate less complex operations include: fewer business lines; less complex business processes and financial reporting systems; more centralized accounting functions; extensive involvement by senior management in the day-to-day activities of the business; and fewer levels of management, each with a wide span of control.

Audit Strategy

8. The auditor should establish an overall audit strategy that sets the scope, timing, and direction of the audit and guides the development of the audit plan.

9. In establishing the overall audit strategy, the auditor should take into account:

a. The reporting objectives of the engagement and the nature of the communications required by PCAOB standards,

15

15

See, e.g.,

AU sec. 310 and AU sec. 380,

Communication With Audit Committees.

Also, various laws or regulations require other matters to be communicated. (

See, e.g.,

Rule 2-07 of Regulation S-X, 17 CFR 210.2-07; and Rule 10A-3 under the Securities Exchange Act of 1934, 17 CFR 240.10A-3.) The requirements of this standard do not modify communications required by those other laws or regulations.

b. The factors that are significant in directing the activities of the engagement team,

16

16

See, e.g.,

paragraph 6 of Auditing Standard No. 10,

Supervision of the Audit Engagement.

c. The results of preliminary engagement activities

17

and the auditor's evaluation of the important matters in accordance with paragraph 7 of this standard, and

17

Paragraph 6 of this standard.

d. The nature, timing, and extent of resources necessary to perform the engagement.

18

18

See, e.g.,

paragraph .06 of AU sec. 230,

Due Professional Care in the Performance of Work,

paragraph 16 of this standard, and paragraph 5.a. of Auditing Standard No. 13,

The Auditor's Responses to the Risks of Material Misstatement.

Audit Plan

10. The auditor should develop and document an audit plan that includes a description of:

a. The planned nature, timing, and extent of the risk assessment procedures;

19

19

Auditing Standard No. 12,

Identifying and Assessing Risks of Material Misstatement.

b. The planned nature, timing, and extent of tests of controls and substantive procedures;

20

and

20

Auditing Standard No. 13 and Auditing Standard No. 5,

An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements.

c. Other planned audit procedures required to be performed so that the engagement complies with PCAOB standards.

Multi-Location Engagements

11. In an audit of the financial statements of a company with operations in multiple locations or business units,

21

the auditor should determine the extent to which audit procedures should be performed at selected locations or business units to obtain sufficient appropriate evidence to obtain reasonable assurance about whether the consolidated financial statements are free of material misstatement. This includes determining the locations or business units at which to perform audit procedures, as well as the nature, timing, and extent of the procedures to be performed at those individual locations or business units. The auditor should assess the risks of material misstatement to the consolidated financial statements associated with the location or business unit and correlate the amount of audit attention devoted to the location or business unit with the degree of risk of material misstatement associated with that location or business unit.

21

The term “business units” includes subsidiaries, divisions, branches, components, or investments.

12. Factors that are relevant to the assessment of the risks of material misstatement associated with a particular location or business unit and the determination of the necessary audit procedures include:

a. The nature and amount of assets, liabilities, and transactions executed at the location or business unit, including, e.g., significant transactions executed at the location or business unit that are outside the normal course of business for the company, or that otherwise appear to be unusual given the auditor's understanding of the company and its environment;

22

22

Paragraph .66 of AU sec. 316,

Consideration of Fraud in a Financial Statement Audit.

b. The materiality of the location or business unit;

23

23

Paragraph 10 of Auditing Standard No. 11 describes the consideration of materiality in planning and performing audit procedures at an individual location or business unit.

c. The specific risks associated with the location or business unit that present a reasonable possibility

24

of material misstatement to the company's consolidated financial statements;

24

There is a reasonable possibility of an event, as used in this standard, when the likelihood of the event is either “reasonably possible” or “probable,” as those terms are used in the FASB Accounting Standards Codification, Contingencies Topic, paragraph 450-20-25-1.

d. Whether the risks of material misstatement associated with the location or business unit apply to other locations or business units such that, in combination, they present a reasonable possibility of material misstatement to the company's consolidated financial statements;

e. The degree of centralization of records or information processing;

f. The effectiveness of the control environment, particularly with respect to management's control over the exercise of authority delegated to others and its ability to effectively supervise activities at the location or business unit; and

g. The frequency, timing, and scope of monitoring activities by the company or others at the location or business unit.

Note: When performing an audit of internal control over financial reporting, refer to Appendix B, Special Topics, of Auditing Standard No. 5

25

for considerations when a company has multiple locations or business units.

25

Paragraphs B10-B16 of Auditing Standard No. 5.

13. In determining the locations or business units at which to perform audit procedures, the auditor may take into account relevant activities performed by internal audit, as described in AU sec. 322,

The Auditor's Consideration of the Internal Audit Function in an Audit of Financial Statements,

or others, as described in Auditing Standard No. 5. AU sec. 322 and Auditing Standard No. 5 establish requirements regarding using the work of internal audit and others, respectively.

14. AU sec. 543,

Part of Audit Performed by Other Independent Auditors,

describes the auditor's responsibilities regarding using the work and reports of other independent auditors who audit the financial statements of one or more of the locations or business units that are included in the consolidated financial statements.

26

In those situations, the auditor should perform the procedures in paragraphs 11-13 of this standard to determine the locations or business units at which audit procedures should be performed.

26

For integrated audits,

see also

paragraphs C8-C11 of Auditing Standard No. 5.

Changes During the Course of the Audit

15. The auditor should modify the overall audit strategy and the audit plan as necessary if circumstances change significantly during the course of the audit, including changes due to a revised assessment of the risks of material misstatement or the discovery of a previously unidentified risk of material misstatement.

Persons With Specialized Skill or Knowledge

16. The auditor should determine whether specialized skill or knowledge is needed to perform appropriate risk assessments, plan or perform audit procedures, or evaluate audit results.

17. If a person with specialized skill or knowledge employed or engaged by the auditor participates in the audit, the auditor should have sufficient knowledge of the subject matter to be addressed by such a person to enable the auditor to:

a. Communicate the objectives of that person's work;

b. Determine whether that person's procedures meet the auditor's objectives; and

c. Evaluate the results of that person's procedures as they relate to the nature, timing, and extent of other planned audit procedures and the effects on the auditor's report.

Additional Considerations in Initial Audits

18. The auditor should undertake the following activities before starting an initial audit:

a. Perform procedures regarding the acceptance of the client relationship and the specific audit engagement; and

b. Communicate with the predecessor auditor in situations in which there has been a change of auditors in accordance with AU sec. 315,

Communications Between Predecessor and Successor Auditors.

19. The purpose and objective of planning the audit are the same for an initial audit or a recurring audit engagement. However, for an initial audit, the auditor should determine the additional planning activities necessary to establish an appropriate audit strategy and audit plan, including determining the audit procedures necessary to obtain sufficient appropriate audit evidence regarding the opening balances.

27

27

See also

paragraph 3 of Auditing Standard No. 6,

Evaluating Consistency of Financial Statements.

Appendix A—Definition

A1. For purposes of this standard, the term listed below is defined as follows:

A2. Engagement partner—The member of the engagement team with primary responsibility for the audit.

Auditing Standard No. 10

Supervision of the Audit Engagement

Introduction

1. This standard establishes requirements regarding supervision of the audit engagement, including supervising the work of engagement team members.

Objective

2. The objective of the auditor is to supervise the audit engagement, including supervising the work of engagement team members so that the work is performed as directed and supports the conclusions reached.

Responsibility of the Engagement Partner for Supervision

3. The

engagement partner

28

is responsible for the engagement and its performance. Accordingly, the engagement partner is responsible for proper supervision of the work of engagement team members and for compliance with PCAOB standards, including standards regarding using the work of specialists,

29

other auditors,

30

internal auditors,

31

and others who are involved in testing controls.

32

Paragraphs 5-6 of this standard describe the nature and extent of supervisory activities necessary for proper supervision of engagement team members.

33

28

Terms defined in Appendix A,

Definitions,

are set in boldface type the first time they appear.

29

AU sec. 336,

Using the Work of a Specialist.

30

AU sec. 543,

Part of Audit Performed by Other Independent Auditors.

31

AU sec. 322,

The Auditor's Consideration of the Internal Audit Function in an Audit of Financial Statements.

32

Paragraphs 16-19 of Auditing Standard No. 5,

An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements.

33

See also

paragraph .06 of AU sec. 230,

Due Professional Care in the Performance of Work.

4. The engagement partner may seek assistance from appropriate engagement team members in fulfilling his or her responsibilities pursuant to this standard. Engagement team members who assist the engagement partner with supervision of the work of other engagement team members also should comply with the requirements in this standard with respect to the supervisory responsibilities assigned to them.

Supervision of Engagement Team Members

5. The engagement partner and, as applicable, other engagement team members performing supervisory activities, should:

a. Inform engagement team members of their responsibilities,

34

including:

34

AU sec. 230.06 and paragraph 5 of Auditing Standard No. 13,

The Auditor's Responses to the Risks of Material Misstatement,

establish requirements regarding the appropriate assignment of engagement team members.

(1) The objectives of the procedures that they are to perform;

(2) The nature, timing, and extent of procedures they are to perform; and

(3) Matters that could affect the procedures to be performed or the evaluation of the results of those procedures, including relevant aspects of the company, its environment, and its internal control over financial reporting,

35

and possible accounting and auditing issues;

35

Auditing Standard No. 12,

Identifying and Assessing Risks of Material Misstatement,

describes the auditor's responsibilities for obtaining an understanding of the company, its environment, and its internal control over financial reporting.

b. Direct engagement team members to bring significant accounting and auditing issues arising during the audit to the attention of the engagement partner or other engagement team members performing supervisory activities so they can evaluate those issues and determine that appropriate actions are taken in accordance with PCAOB standards;

36

36

See, e.g.,

paragraph 15 of Auditing Standard No. 9,

Audit Planning,

paragraph 74 of Auditing Standard No. 12, and paragraphs 20-23 and 35-36 of Auditing Standard No. 14,

Evaluating Audit Results.

Note: In applying due professional care in accordance with AU sec. 230, each engagement team member has a responsibility to bring to the attention of appropriate persons, disagreements or concerns the engagement team member might have with respect to accounting and auditing issues that he or she believes are of significance to the financial statements or the auditor's report regardless of how those disagreements or concerns may have arisen.

c. Review the work of engagement team members to evaluate whether:

(1) The work was performed and documented;

(2) The objectives of the procedures were achieved; and

(3) The results of the work support the conclusions reached.

37

37

Auditing Standard No. 14 describes the auditor's responsibilities for evaluating the results of the audit, and Auditing Standard No. 3,

Audit Documentation,

establishes requirements regarding audit documentation.

6. To determine the extent of supervision necessary for engagement team members to perform their work as directed and form appropriate conclusions, the engagement partner and other engagement team members performing supervisory activities should take into account:

a. The nature of the company, including its size and complexity;

38

38

Paragraph 10 of Auditing Standard No. 12.

b. The nature of the assigned work for each engagement team member, including:

(1) The procedures to be performed, and

(2) The controls or accounts and disclosures to be tested;

c. The risks of material misstatement; and

d. The knowledge, skill, and ability of each engagement team member.

39

39

See also

paragraph 5.a. of Auditing Standard No. 13 and AU sec. 230.06.

Note: In accordance with the requirements of paragraph 5 of Auditing Standard No. 13,

The Auditor's Responses to the Risks of Material Misstatement,

the extent of supervision of engagement team members should be commensurate with the risks of material misstatement.

40

40

Paragraph 5.b. of Auditing Standard No. 13 indicates that the extent of supervision of engagement team members is part of the auditor's overall responses to the risks of material misstatement.

Appendix A—Definition

A1. For purposes of this standard, the term listed below is defined as follows:

A2. Engagement partner—The member of the engagement team with primary responsibility for the audit.

Auditing Standard No. 11

Consideration of Materiality in Planning and Performing an Audit

Introduction

1. This standard establishes requirements regarding the auditor's consideration of materiality in planning and performing an audit.

41

41

Auditing Standard No. 14 establishes requirements regarding the auditor's consideration of materiality in evaluating audit results.

Materiality in the Context of an Audit

2. In interpreting the federal securities laws, the Supreme Court of the United States has held that a fact is material if there is “a substantial likelihood that the * * * fact would have been viewed by the reasonable investor as having significantly altered the `total mix' of information made available.”

42

As the Supreme Court has noted, determinations of materiality require “delicate assessments of the inferences a `reasonable shareholder' would draw from a given set of facts and the significance of those inferences to him * * *.”

43

42

TSC Industries

v.

Northway, Inc.,

426 U.S. 438, 449 (1976).

See also Basic, Inc.

v.

Levinson,

485 U.S. 224 (1988).

43

TSC Industries,

426 U.S. at 450.

3. To obtain reasonable assurance about whether the financial statements are free of material misstatement, the auditor should plan and perform audit procedures to detect misstatements that, individually or in combination with other misstatements, would result in material misstatement of the financial statements. This includes being alert while planning and performing audit procedures for misstatements that could be material due to quantitative or qualitative factors. Also, the evaluation of uncorrected misstatements in accordance with Auditing Standard No. 14,

Evaluating Audit Results,

requires consideration of both qualitative and quantitative factors.

44

However, it ordinarily is not practical to design audit procedures to detect misstatements that are material based solely on qualitative factors.

44

Appendix B of Auditing Standard No. 14.

4. For integrated audits, Auditing Standard No. 5,

An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements,

states, “In planning the audit of internal control over financial reporting, the auditor should use the same materiality considerations he or she would use in planning the audit of the company's annual financial statements.”

45

45

Paragraph 20 of Auditing Standard No. 5.

Objective

5. The objective of the auditor is to apply the concept of materiality appropriately in planning and performing audit procedures.

Considering Materiality in Planning and Performing an Audit

Establishing a Materiality Level for the Financial Statements as a Whole

6. To plan the nature, timing, and extent of audit procedures, the auditor should establish a materiality level for the financial statements as a whole that is appropriate in light of the particular circumstances. This includes consideration of the company's earnings and other relevant factors. To determine the nature, timing, and extent of audit procedures, the materiality level for the financial statements as a whole needs to be expressed as a specified amount.

Note: If financial statements for the audit period are not available, the auditor may establish an initial materiality level based on estimated or preliminary financial statement amounts. In those situations, the auditor should take into account the effects of known or expected changes in the company's financial statements, including significant transactions or adjustments that are expected to be reflected in the financial statements at the end of the period.

Establishing Materiality Levels for Particular Accounts or Disclosures

7. The auditor should evaluate whether, in light of the particular circumstances, there are certain accounts or disclosures for which there is a substantial likelihood that misstatements of lesser amounts than the materiality level established for the financial statements as a whole would influence the judgment of a reasonable investor. If so, the auditor should establish separate materiality levels for those accounts or disclosures to plan the nature, timing, and extent of audit procedures for those accounts or disclosures.

Note: Lesser amounts of misstatements could influence the judgment of a reasonable investor because of qualitative factors, e.g., because of the sensitivity of circumstances surrounding misstatements, such as conflicts of interest in related party transactions.

Determining Tolerable Misstatement

8. The auditor should determine the amount or amounts of tolerable misstatement for purposes of assessing risks of material misstatement and planning and performing audit procedures at the account or disclosure level. The auditor should determine tolerable misstatement at an amount or amounts that reduce to an appropriately low level the probability that the total of uncorrected and undetected misstatements would result in material misstatement of the financial statements. Accordingly, tolerable misstatement should be less than the materiality level for the financial statements as a whole and, if applicable, the materiality level or levels for particular accounts or disclosures.

9. In determining tolerable misstatement and planning and performing audit procedures, the auditor should take into account the nature, cause (if known), and amount of misstatements that were accumulated in audits of the financial statements of prior periods.

Considerations for Multi-Location Engagements

10. For purposes of the audit of the consolidated financial statements of a company with multiple locations or business units, the auditor should determine tolerable misstatement for the individual locations or business units at an amount that reduces to an appropriately low level the probability that the total of uncorrected and undetected misstatements would result in material misstatement of the consolidated financial statements. Accordingly, tolerable misstatement at an individual location should be less than the materiality level for the financial statements as a whole.

Considerations as the Audit Progresses

11. The auditor should reevaluate the established materiality level or levels and tolerable misstatement when, because of changes in the particular circumstances or additional information that comes to the auditor's attention, there is a substantial likelihood that misstatements of amounts that differ significantly from the materiality level or levels that were established initially would influence the judgment of a reasonable investor. Situations in which changes in circumstances or additional information that comes to the auditor's attention would require such reevaluation include:

a. The materiality level or levels and tolerable misstatement were established initially based on estimated or preliminary financial statement amounts that differ significantly from actual amounts.

b. Events or changes in conditions occurring after the materiality level or levels and tolerable misstatement were established initially are likely to affect

investors' perceptions about the company's financial position, results of operations, or cash flows.

Note: Examples of such events or changes in conditions include (1) changes in laws, regulations, or the applicable financial reporting framework that affect investors' expectations about the measurement or disclosure of certain items and (2) significant new contractual arrangements that draw attention to a particular aspect of a company's business that is separately disclosed in the financial statements.

12. If the auditor's reevaluation results in a lower amount for the materiality level or levels or tolerable misstatement than initially established by the auditor, the auditor should (1) evaluate the effect, if any, of the lower amount or amounts on his or her risk assessments and audit procedures and (2) modify the nature, timing, and extent of audit procedures as necessary to obtain sufficient appropriate audit evidence.

Note: The reevaluation of the materiality level or levels and tolerable misstatement is also relevant to the auditor's evaluation of uncorrected misstatements in accordance with Auditing Standard No. 14.

46

46

Paragraph 17 of Auditing Standard No. 14.

Auditing Standard No. 12

Identifying and Assessing Risks of Material Misstatement

Introduction

1. This standard establishes requirements regarding the process of identifying and assessing risks of material misstatement

47

of the financial statements.

47

Paragraphs 5-8 of Auditing Standard No. 8,

Audit Risk.

2. Paragraphs 4-58 of this standard discuss the auditor's responsibilities for performing

risk assessment procedures

.

48

Paragraphs 59-73 of this standard discuss identifying and assessing the risks of material misstatement using information obtained from performing risk assessment procedures.

48

Terms defined in Appendix A,

Definitions,

are set in boldface type the first time they appear.

Objective

3. The objective of the auditor is to identify and appropriately assess the risks of material misstatement, thereby providing a basis for designing and implementing responses to the risks of material misstatement.

Performing Risk Assessment Procedures

4. The auditor should perform risk assessment procedures that are sufficient to provide a reasonable basis for identifying and assessing the risks of material misstatement, whether due to error or fraud,

49

and designing further audit procedures.

50

49

AU sec. 316,

Consideration of Fraud in a Financial Statement Audit,

discusses fraud, its characteristics, and the types of misstatements due to fraud that are relevant to the audit, i.e., misstatements arising from fraudulent financial reporting and misstatements arising from asset misappropriation.

50

Auditing Standard No. 15,

Audit Evidence,

describes further audit procedures as consisting of tests of controls and substantive procedures.

5. Risks of material misstatement can arise from a variety of sources, including external factors, such as conditions in the company's industry and environment, and company-specific factors, such as the nature of the company, its activities, and internal control over financial reporting. For example, external or company-specific factors can affect the judgments involved in determining accounting estimates or create pressures to manipulate the financial statements to achieve certain financial targets. Also, risks of material misstatement may relate to, e.g., personnel who lack the necessary financial reporting competencies, information systems that fail to accurately capture business transactions, or financial reporting processes that are not adequately aligned with the requirements in the applicable financial reporting framework. Thus, the audit procedures that are necessary to identify and appropriately assess the risks of material misstatement include consideration of both external factors and company-specific factors. This standard discusses the following risk assessment procedures:

a. Obtaining an understanding of the company and its environment (paragraphs 7-17);

b. Obtaining an understanding of internal control over financial reporting (paragraphs 18-40);

c. Considering information from the client acceptance and retention evaluation, audit planning activities, past audits, and other engagements performed for the company (paragraphs 41-45);

d. Performing analytical procedures (paragraphs 46-48);

e. Conducting a discussion among engagement team members regarding the risks of material misstatement (paragraphs 49-53); and

f. Inquiring of the audit committee, management, and others within the company about the risks of material misstatement (paragraphs 54-58).

Note: This standard describes an approach to identifying and assessing risks of material misstatement that begins at the financial statement level and with the auditor's overall understanding of the company and its environment and works down to the significant accounts and disclosures and their relevant assertions.

51

51

Paragraph 11 of Auditing Standard No. 15 discusses financial statement assertions.

6. In an integrated audit, the risks of material misstatement of the financial statements are the same for both the audit of internal control over financial reporting and the audit of financial statements. The auditor's risk assessment procedures should apply to both the audit of internal control over financial reporting and the audit of financial statements.

Obtaining an Understanding of the Company and Its Environment

7. The auditor should obtain an understanding of the company and its environment (“understanding of the company”) to understand the events, conditions, and company activities that might reasonably be expected to have a significant effect on the risks of material misstatement. Obtaining an understanding of the company includes understanding:

a. Relevant industry, regulatory, and other external factors;

b. The nature of the company;

c. The company's selection and application of accounting principles, including related disclosures;

d. The

company's objectives and strategies

and those related

business risks

that might reasonably be expected to result in risks of material misstatement; and

e. The company's measurement and analysis of its financial performance.

8. In obtaining an understanding of the company, the auditor should evaluate whether significant changes in the company from prior periods, including changes in its internal control over financial reporting, affect the risks of material misstatement.

Industry, Regulatory, and Other External Factors

9. Obtaining an understanding of relevant industry, regulatory, and other external factors encompasses industry factors, including the competitive environment and technological developments; the regulatory environment, including the applicable

financial reporting framework

52

and the legal and political environment;

53

and external factors, including general economic conditions.

52

The auditor should look to the requirements of the Securities and Exchange Commission for the company under audit with respect to the accounting principles applicable to that company.

53

AU sec. 317,

Illegal Acts by Clients,

discusses the auditor's consideration of laws and regulations relevant to the audit.

Nature of the Company

10. Obtaining an understanding of the nature of the company includes understanding:

• The company's organizational structure and management personnel;

• The sources of funding of the company's operations and investment activities, including the company's capital structure, noncapital funding (e.g., subordinated debt or dependencies on supplier financing), and other debt instruments;

• The company's significant investments, including equity method investments, joint ventures, and variable interest entities;

• The company's operating characteristics, including its size and complexity;

Note: The size and complexity of a company might affect the risks of misstatement and how the company addresses those risks.

• The sources of the company's earnings, including the relative profitability of key products and services; and

• Key supplier and customer relationships.

Note: The auditor should take into account the information gathered while obtaining an understanding of the nature of the company when determining the existence of related parties in accordance with AU sec. 334,

Related Parties.

11. As part of obtaining an understanding of the company as required by paragraph 7, the auditor should consider performing the following procedures and the extent to which the procedures should be performed:

• Reading public information about the company relevant to the evaluation of the likelihood of material financial statement misstatements and, in an integrated audit, the effectiveness of the company's internal control over financial reporting, e.g., company-issued press releases, company-prepared presentation materials for analysts or investor groups, and analyst reports;

• Observing or reading transcripts of earnings calls and, to the extent publicly available, other meetings with investors or rating agencies;

• Obtaining an understanding of compensation arrangements with senior management, including incentive compensation arrangements, changes or adjustments to those arrangements, and special bonuses; and

• Obtaining information about trading activity in the company's securities and holdings in the company's securities by significant holders to identify potentially significant unusual developments (e.g., from Forms 3, 4, 5, 13D, and 13G).

Selection and Application of Accounting Principles, Including Related Disclosures

12. As part of obtaining an understanding of the company's selection and application of accounting principles, including related disclosures, the auditor should evaluate whether the company's selection and application of accounting principles are appropriate for its business and consistent with the applicable financial reporting framework and accounting principles used in the relevant industry. Also, to identify and assess risks of material misstatement related to omitted, incomplete, or inaccurate disclosures, the auditor should develop expectations about the disclosures that are necessary for the company's financial statements to be presented fairly in conformity with the applicable financial reporting framework.

13. The following matters, if present, are relevant to the necessary understanding of the company's selection and application of accounting principles, including related disclosures:

• Significant changes in the company's accounting principles, financial reporting policies, or disclosures and the reasons for such changes;

• The financial reporting competencies of personnel involved in selecting and applying significant new or complex accounting principles;

• The accounts or disclosures for which judgment is used in the application of significant accounting principles, especially in determining management's estimates and assumptions;

• The effect of significant accounting principles in controversial or emerging areas for which there is a lack of authoritative guidance or consensus;

• The methods the company uses to account for significant and unusual transactions; and

• Financial reporting standards and laws and regulations that are new to the company, including when and how the company will adopt such requirements.

Company Objectives, Strategies, and Related Business Risks

14. The purpose of obtaining an understanding of the company's objectives, strategies, and related business risks is to identify business risks that could reasonably be expected to result in material misstatement of the financial statements.

Note: Some relevant business risks might be identified through other risk assessment procedures, such as obtaining an understanding of the nature of the company and understanding industry, regulatory, and other external factors.

15. The following are examples of situations in which business risks might result in material misstatement of the financial statements:

• Industry developments (a potential related business risk might be, e.g., that the company does not have the personnel or expertise to deal with the changes in the industry.)

• New products and services (a potential related business risk might be, e.g., that the new product or service will not be successful.)

• Use of information technology (“IT”) (a potential related business risk might be, e.g., that systems and processes are incompatible.)

• New accounting requirements (a potential related business risk might be, e.g., incomplete or improper implementation of a new accounting requirement.)

• Expansion of the business (a potential related business risk might be, e.g., that the demand for the company's products or services has not been accurately estimated.)

• The effects of implementing a strategy, particularly any effects that will lead to new accounting requirements (a potential related business risk might be, e.g., incomplete or improper implementation of the strategy.)

• Current and prospective financing requirements (a potential related business risk might be, e.g., the loss of financing due to the company's inability to meet financing requirements.)

• Regulatory requirements (a potential related business risk might be, e.g., that there is increased legal exposure.)

Note: Business risks could affect risks of material misstatement at the financial statement level, which would affect many accounts and disclosures in the financial statements. For example, a company's loss of financing or declining conditions affecting the company's

industry could affect its ability to settle its obligations when due. This, in turn, could affect the risks of material misstatement related to, e.g., the classification of long-term liabilities or valuation of long-term assets, or it could result in substantial doubt about the company's ability to continue as a going concern. Other business risks could affect the risks of material misstatement for particular accounts, disclosures, or assertions. For example, an unsuccessful new product or service or failed business expansion might affect the risks of material misstatement related to the valuation of inventory and other related assets.

Company Performance Measures

16. The purpose of obtaining an understanding of the company's performance measures is to identify performance measures, whether external or internal, that affect the risks of material misstatement.

17. The following are examples of performance measures that might affect the risks of material misstatement:

• Measures that form the basis for contractual commitments or incentive compensation arrangements;

• Measures used by external parties, such as analysts and rating agencies, to review the company's performance; and

• Measures the company uses to monitor its operations that highlight unexpected results or trends that prompt management to investigate their cause and take corrective action, including correction of misstatements.

Note: The first two examples represent performance measures that can affect the risks of material misstatement by creating incentives or pressures for management of the company to manipulate certain accounts or disclosures to achieve certain performance targets (or conceal a failure to achieve those targets). The third example represents performance measures that management might use to monitor risks affecting the financial statements.

Note: Smaller companies might have less formal processes to measure and review financial performance. In such cases, the auditor might identify relevant performance measures by considering the information that the company uses to manage the business.

Obtaining an Understanding of Internal Control Over Financial Reporting

18. The auditor should obtain a sufficient understanding of each component

54

of internal control over financial reporting (“understanding of internal control”) to (a) identify the types of potential misstatements, (b) assess the factors that affect the risks of material misstatement, and (c) design further audit procedures.

54

Paragraphs 21-22 of this standard discuss components of internal control over financial reporting.

19. The nature, timing, and extent of procedures that are necessary to obtain an understanding of internal control depend on the size and complexity of the company;

55

the auditor's existing knowledge of the company's internal control over financial reporting; the nature of the company's controls, including the company's use of IT; the nature and extent of changes in systems and operations; and the nature of the company's documentation of its internal control over financial reporting.

55

Paragraph 13 of Auditing Standard No. 5,

An Audit of Internal Control Over Financial Reporting That is Integrated with An Audit of Financial Statements,

states, “The size and complexity of the company, its business processes, and business units, may affect the way in which the company achieves many of its control objectives. The size and complexity of the company also might affect the risks of misstatement and the controls necessary to address those risks.”

Note: The auditor also might obtain an understanding of certain controls that are not part of internal control over financial reporting, e.g., controls over the completeness and accuracy of operating or other nonfinancial information used as audit evidence.

56

56

Paragraph 10 of Auditing Standard No. 15.

20. Obtaining an understanding of internal control includes evaluating the design of controls that are relevant to the audit and determining whether the controls have been implemented.

Note: Procedures the auditor performs to obtain evidence about design effectiveness include inquiry of appropriate personnel, observation of the company's operations, and inspection of relevant documentation. Walkthroughs, as described in paragraphs 37-38, that include these procedures ordinarily are sufficient to evaluate design effectiveness.

Note: Determining whether a control has been implemented means determining whether the control exists and whether the company is using it. The procedures to determine whether a control has been implemented may be performed in connection with the evaluation of its design. Procedures performed to determine whether a control has been implemented include inquiry of appropriate personnel, in combination with observation of the application of controls or inspection of documentation. Walkthroughs, as described in paragraphs 37-38, that include these procedures ordinarily are sufficient to determine whether a control has been implemented.

21. Internal control over financial reporting can be described as consisting of the following components:

57

57

Different internal control frameworks use different terms and approaches to describe the components of internal control over financial reporting.

• The control environment,

• The company's risk assessment process,

• Information and communication,

• Control activities, and

• Monitoring of controls.

22. Management might use an internal control framework with components that differ from the components identified in the preceding paragraph when establishing and maintaining the company's internal control over financial reporting. In evaluating the design of controls and determining whether they have been implemented in an audit of financial statements only, the auditor may use the framework used by management or another suitable, recognized framework.

58

For integrated audits, Auditing Standard No. 5, states, “The auditor should use the same suitable, recognized control framework to perform his or her audit of internal control over financial reporting as management uses for its annual evaluation of the effectiveness of the company's internal control over financial reporting.”

59

If the auditor uses a suitable, recognized internal control framework with components that differ from those listed in the preceding paragraph, the auditor should adapt the requirements in paragraphs 23-36 of this standard to conform to the components in the framework used.

58

See

Securities Exchange Act Release No. 34-47986 (June 5, 2003) for a description of the characteristics of a suitable, recognized framework.

59

Paragraph 5 of Auditing Standard No. 5.

Control Environment

23. The auditor should obtain an understanding of the company's control environment, including the policies and actions of management, the board, and the audit committee concerning the company's control environment.

24. Obtaining an understanding of the control environment includes assessing:

• Whether management's philosophy and operating style promote effective internal control over financial reporting;

• Whether sound integrity and ethical values, particularly of top management, are developed and understood; and

• Whether the board or audit committee understands and exercises oversight responsibility over financial reporting and internal control.

Note: In an audit of financial statements only, this assessment may be based on the evidence obtained in

understanding the control environment, in accordance with paragraph 23, and the other relevant knowledge possessed by the auditor. In an integrated audit of financial statements and internal control over financial reporting, Auditing Standard No. 5

60

describes the auditor's responsibility for evaluating the control environment.

60

Paragraph 25 of Auditing Standard No. 5.

25. If the auditor identifies a control deficiency

61

in the company's control environment, the auditor should evaluate the extent to which this control deficiency is indicative of a fraud risk factor, as discussed in paragraphs 65-66 of this standard.

61

Paragraph A3 of Auditing Standard No. 5.

The Company's Risk Assessment Process

26. The auditor should obtain an understanding of management's process for:

a. Identifying risks relevant to financial reporting objectives, including risks of material misstatement due to fraud (“fraud risks”);

b. Assessing the likelihood and significance of misstatements resulting from those risks; and

c. Deciding about actions to address those risks.

27. Obtaining an understanding of the company's risk assessment process includes obtaining an understanding of the risks of material misstatement identified and assessed by management and the actions taken to address those risks.

Information and Communication

28.

Information System Relevant to Financial Reporting.

The auditor should obtain an understanding of the information system, including the related business processes, relevant to financial reporting, including:

a. The classes of transactions in the company's operations that are significant to the financial statements;

b. The procedures, within both automated and manual systems, by which those transactions are initiated, authorized, processed, recorded, and reported;

c. The related accounting records, supporting information, and specific accounts in the financial statements that are used to initiate, authorize, process, and record transactions;

d. How the information system captures events and conditions, other than transactions,

62

that are significant to the financial statements; and

62

Examples of such events and conditions include depreciation and amortization and conditions affecting the recoverability of assets.

e. The period-end financial reporting process.

Note: Appendix B discusses additional considerations regarding manual and automated systems and controls.

29. The auditor also should obtain an understanding of how IT affects the company's flow of transactions. (See Appendix B.)

Note: The identification of risks and controls within IT is not a separate evaluation. Instead, it is an integral part of the approach used to identify significant accounts and disclosures and their relevant assertions and, when applicable, to select the controls to test, as well as to assess risk and allocate audit effort.

30. A company's business processes are the activities designed to:

a. Develop, purchase, produce, sell and distribute a company's products or services;

b. Record information, including accounting and financial reporting information; and

c. Ensure compliance with laws and regulations relevant to the financial statements.

31. Obtaining an understanding of the company's business processes assists the auditor in obtaining an understanding of how transactions are initiated, authorized, processed, and recorded.

32. A company's period-end financial reporting process, as referred to in paragraph 28.e., includes the following:

• Procedures used to enter transaction totals into the general ledger;

• Procedures related to the selection and application of accounting principles;

63

63

Paragraphs 12-13 of this standard.

• Procedures used to initiate, authorize, record, and process journal entries in the general ledger;

• Procedures used to record recurring and nonrecurring adjustments to the annual financial statements (and quarterly financial statements, if applicable); and

• Procedures for preparing annual financial statements and related disclosures (and quarterly financial statements, if applicable).

33.

Communication.

The auditor should obtain an understanding of how the company communicates financial reporting roles and responsibilities and significant matters relating to financial reporting to relevant company personnel and others, including:

• Communications between management, the audit committee, and the board of directors; and

• Communications to external parties, including regulatory authorities and shareholders.

Control Activities

34. The auditor should obtain an understanding of control activities that is sufficient to assess the factors that affect the risks of material misstatement and to design further audit procedures, as described in paragraph 18 of this standard.

64

As the auditor obtains an understanding of the other components of internal control over financial reporting, he or she is also likely to obtain knowledge about some control activities. The auditor should use his or her knowledge about the presence or absence of control activities obtained from the understanding of the other components of internal control over financial reporting in determining the extent to which it is necessary to devote additional attention to obtaining an understanding of control activities to assess the factors that affect the risks of material misstatement and to design further audit procedures.

64

Also see

paragraph B5 of Appendix B of this standard.

Note: A broader understanding of control activities is needed for relevant assertions for which the auditor plans to rely on controls. Also, in the audit of internal control over financial reporting, the auditor's understanding of control activities encompasses a broader range of accounts and disclosures than what is normally obtained in a financial statement audit.

Monitoring of Controls

35. The auditor should obtain an understanding of the major types of activities that the company uses to monitor the effectiveness of its internal control over financial reporting and how the company initiates corrective actions related to its controls.

65

65

In some companies, internal auditors or others performing an equivalent function contribute to the monitoring of controls. AU sec. 322,

The Auditor's Consideration of the Internal Audit Function in an Audit of Financial Statements,

establishes requirements regarding the auditor's consideration and use of the work of the internal audit function.

36. An understanding of the company's monitoring activities includes understanding the source of the information used in the monitoring activities.

Performing Walkthroughs

37. As discussed in paragraph 20, the auditor may perform walkthroughs as part of obtaining an understanding of internal control over financial reporting. For example, the auditor may perform walkthroughs in connection with understanding the flow of transactions

in the information system relevant to financial reporting, evaluating the design of controls relevant to the audit, and determining whether those controls have been implemented. In performing a walkthrough, the auditor follows a transaction from origination through the company's processes, including information systems, until it is reflected in the company's financial records, using the same documents and IT that company personnel use. Walkthrough procedures usually include a combination of inquiry, observation, inspection of relevant documentation, and re-performance of controls.

Note: For integrated audits, Auditing Standard No. 5 establishes certain objectives that the auditor should achieve to further understand likely sources of potential misstatements and as part of selecting the controls to test. Auditing Standard No. 5 states that performing walkthroughs will frequently be the most effective way of achieving those objectives.

66

66

See

paragraphs 34-38 of Auditing Standard No. 5.

38. In performing a walkthrough, at the points at which important processing procedures occur, the auditor questions the company's personnel about their understanding of what is required by the company's prescribed procedures and controls. These probing questions, combined with the other walkthrough procedures, allow the auditor to gain a sufficient understanding of the process and to be able to identify important points at which a necessary control is missing or not designed effectively. Additionally, probing questions that go beyond a narrow focus on the single transaction used as the basis for the walkthrough allow the auditor to gain an understanding of the different types of significant transactions handled by the process.

Relationship of Understanding of Internal Control to Tests of Controls

39. The objective of obtaining an understanding of internal control, as discussed in paragraph 18 of this standard, is different from testing controls for the purpose of assessing control risk

67

or for the purpose of expressing an opinion on internal control over financial reporting in the audit of internal control over financial reporting.

68

The auditor may obtain an understanding of internal control concurrently with performing tests of controls if he or she obtains sufficient appropriate evidence to achieve the objectives of both procedures. Also, the auditor should take into account the evidence obtained from understanding internal control when assessing control risk and, in the audit of internal control over financial reporting, forming an opinion about the effectiveness of internal control over financial reporting.

67

Paragraphs 16-35 of Auditing Standard No. 13,

The Auditor's Responses to the Risks of Material Misstatement.

68

Paragraph B1 of Auditing Standard No. 5.

40.

Relationship of Understanding of Internal Control to Evaluating Entity-Level Controls in an Audit of Internal Control Over Financial Reporting.

Auditing Standard No. 5 states, “The auditor must test those entity-level controls that are important to the auditor's conclusion about whether the company has effective internal control over financial reporting.”

69

The procedures performed to obtain an understanding of certain components of internal control in accordance with this standard, e.g., the control environment, the company's risk assessment process, information and communication, and monitoring of controls, might provide evidence that is relevant to the auditor's evaluation of entity-level controls.

70

The auditor should take into account the evidence obtained from understanding internal control when determining the nature, timing, and extent of procedures necessary to support the auditor's conclusions about the effectiveness of entity-level controls in the audit of internal control over financial reporting.

69

Paragraph 22 of Auditing Standard No. 5.

70

The entity-level controls included in paragraph 24 of Auditing Standard No. 5 include controls related to the control environment; the company's risk assessment process; centralized processing and controls; controls over the period-end financial reporting process; and controls to monitor other controls.

Considering Information From the Client Acceptance and Retention Evaluation, Audit Planning Activities, Past Audits, and Other Engagements

41.

Client Acceptance and Retention and Audit Planning Activities.

The auditor should evaluate whether information obtained from the client acceptance and retention evaluation process or audit planning activities is relevant to identifying risks of material misstatement. Risks of material misstatement identified during those activities should be assessed as discussed beginning in paragraph 59 of this standard.

42.

Past Audits.

In subsequent years, the auditor should incorporate knowledge obtained during past audits into the auditor's process for identifying risks of material misstatement, including when identifying significant ongoing matters that affect the risks of material misstatement or determining how changes in the company or its environment affect the risks of material misstatement, as discussed in paragraph 8 of this standard.

43. If the auditor plans to limit the nature, timing, or extent of his or her risk assessment procedures by relying on information from past audits, the auditor should evaluate whether the prior years' information remains relevant and reliable.

44.

Other Engagements.

When the auditor has performed a review of interim financial information in accordance with AU sec. 722,

Interim Financial Information,

the auditor should evaluate whether information obtained during the review is relevant to identifying risks of material misstatement in the year-end audit.

45. The auditor should obtain an understanding of the nature of the services that have been performed for the company by the auditor or affiliates of the firm

71

and should take into account relevant information obtained from those engagements in identifying risks of material misstatement.

72

71

See

PCAOB Rule 3501(a)(i), which defines “affiliate of the accounting firm.”

72

Paragraph 7 of Auditing Standard No. 9,

Audit Planning.

Performing Analytical Procedures

46. The auditor should perform analytical procedures that are designed to:

a. Enhance the auditor's understanding of the client's business and the significant transactions and events that have occurred since the prior year end; and

b. Identify areas that might represent specific risks relevant to the audit, including the existence of unusual transactions and events, and amounts, ratios, and trends that warrant investigation.

47. In applying analytical procedures as risk assessment procedures, the auditor should perform analytical procedures relating to revenue with the objective of identifying unusual or unexpected relationships involving revenue accounts that might indicate a material misstatement, including material misstatement due to fraud. Also, when the auditor has performed a review of interim financial information in accordance with AU sec. 722, he or she should take into account the analytical procedures applied in that review when designing and applying analytical procedures as risk assessment procedures.

48. When performing an analytical procedure, the auditor should use his or

her understanding of the company to develop expectations about plausible relationships among the data to be used in the procedure.

73

When comparison of those expectations with relationships derived from recorded amounts yields unusual or unexpected results, the auditor should take into account those results in identifying the risks of material misstatement.

73

Analytical procedures consist of evaluations of financial information made by a study of plausible relationships among both financial and nonfinancial data.

Note: Analytical procedures performed as risk assessment procedures often use data that is preliminary or data that is aggregated at a high level, and, in those instances, such analytical procedures are not designed with the level of precision necessary for substantive analytical procedures.

Conducting a Discussion Among Engagement Team Members Regarding Risks of Material Misstatement

49. The key engagement team members should discuss (1) the company's selection and application of accounting principles, including related disclosure requirements, and (2) the susceptibility of the company's financial statements to material misstatement due to error or fraud.

Note: The key engagement team members should discuss the potential for material misstatement due to fraud either as part of the discussion regarding risks of material misstatement or in a separate discussion.

74

74

Paragraphs 52-53 of this standard.

Note: As discussed in paragraph 67, the financial statements might be susceptible to misstatement through omission of required disclosures or presentation of inaccurate or incomplete disclosures.

50. Key engagement team members include all engagement team members who have significant engagement responsibilities, including the engagement partner. The manner in which the discussion is conducted depends on the individuals involved and the circumstances of the engagement. For example, if the audit involves more than one location, there could be multiple discussions with team members in differing locations. The engagement partner or other key engagement team members should communicate the important matters from the discussion to engagement team members who are not involved in the discussion.

Note: If the audit is performed entirely by the engagement partner, that engagement partner, having personally conducted the planning of the audit, is responsible for evaluating the susceptibility of the company's financial statements to material misstatement.

51. Communication among the engagement team members about significant matters affecting the risks of material misstatement should continue throughout the audit, including when conditions change.

75

75

See also

paragraph 29 of Auditing Standard No. 14,

Evaluating Audit Results.

Discussion of the Potential for Material Misstatement Due to Fraud

52. The discussion among the key engagement team members about the potential for material misstatement due to fraud should occur with an attitude that includes a questioning mind, and the key engagement team members should set aside any prior beliefs they might have that management is honest and has integrity. The discussion among the key engagement team members should include:

• An exchange of ideas, or “brainstorming,” among the key engagement team members, including the engagement partner, about how and where they believe the company's financial statements might be susceptible to material misstatement due to fraud, how management could perpetrate and conceal fraudulent financial reporting, and how assets of the company could be misappropriated, including (a) the susceptibility of the financial statements to material misstatement through related party transactions and (b) how fraud might be perpetrated or concealed by omitting or presenting incomplete or inaccurate disclosures;

• A consideration of the known external and internal factors affecting the company that might (a) create incentives or pressures for management and others to commit fraud, (b) provide the opportunity for fraud to be perpetrated, and (c) indicate a culture or environment that enables management to rationalize committing fraud;

• A consideration of the risk of management override; and

• A consideration of the potential audit responses to the susceptibility of the company's financial statements to material misstatement due to fraud.

53. The auditor should emphasize the following matters to all engagement team members:

• The need to maintain a questioning mind throughout the audit and to exercise professional skepticism in gathering and evaluating evidence, as described in AU sec. 316;

76

76

AU sec. 316.13.

• The need to be alert for information or other conditions (such as those matters presented in Appendix C of Auditing Standard No. 14) that might affect the assessment of fraud risks; and

• If information or other conditions indicate that a material misstatement due to fraud might have occurred, the need to probe the issues, acquire additional evidence as necessary, and consult with other team members and, if appropriate, others in the firm including specialists.

77

77

Paragraphs 20-23 of Auditing Standard No. 14 establish further requirements for evaluating whether misstatements might be indicative of fraud and determining the necessary procedures to be performed in those situations.

Inquiring of the Audit Committee, Management, and Others Within the Company About the Risks of Material Misstatement

54. The auditor should inquire of the audit committee, or equivalent (or its chair), management, the internal audit function, and others within the company who might reasonably be expected to have information that is important to the identification and assessment of risks of material misstatement.

Note: The auditor's inquiries about risks of material misstatement should include inquiries regarding fraud risks.

55. The auditor should use his or her knowledge of the company and its environment, as well as information from other risk assessment procedures, to determine the nature of the inquiries about risks of material misstatement.

Inquiries Regarding Fraud Risks

56. The auditor's inquiries regarding fraud risks should include the following:

a. Inquiries of management regarding:

(1) Whether management has knowledge of fraud, alleged fraud, or suspected fraud affecting the company;

(2) Management's process for identifying and responding to fraud risks in the company, including any specific fraud risks the company has identified or account balances or disclosures for which a fraud risk is likely to exist, and the nature, extent, and frequency of management's fraud risk assessment process;

(3) Controls that the company has established to address fraud risks the company has identified, or that otherwise help to prevent and detect fraud, including how management monitors those controls;

(4) For a company with multiple locations (a) the nature and extent of monitoring of operating locations or business segments and (b) whether there

are particular operating locations or business segments for which a fraud risk might be more likely to exist;

(5) Whether and how management communicates to employees its views on business practices and ethical behavior;

(6) Whether management has received tips or complaints regarding the company's financial reporting (including those received through the audit committee's internal whistleblower program, if such program exists) and, if so, management's responses to such tips and complaints; and

(7) Whether management has reported to the audit committee on how the company's internal control serves to prevent and detect material misstatements due to fraud.

b. Inquiries of the audit committee, or equivalent, or its chair regarding:

(1) The audit committee's views about fraud risks in the company;

(2) Whether the audit committee has knowledge of fraud, alleged fraud, or suspected fraud affecting the company;

(3) Whether the audit committee is aware of tips or complaints regarding the company's financial reporting (including those received through the audit committee's internal whistleblower program, if such program exists) and, if so, the audit committee's responses to such tips and complaints; and

(4) How the audit committee exercises oversight of the company's assessment of fraud risks and the establishment of controls to address fraud risks.

c. If the company has an internal audit function, inquiries of appropriate internal audit personnel regarding:

(1) The internal auditors' views about fraud risks in the company;

(2) Whether the internal auditors have knowledge of fraud, alleged fraud, or suspected fraud affecting the company;

(3) Whether internal auditors have performed procedures to identify or detect fraud during the year, and whether management has satisfactorily responded to the findings resulting from those procedures; and

(4) Whether internal auditors are aware of instances of management override of controls and the nature and circumstances of such overrides.

57. In addition to the inquiries outlined in the preceding paragraph, the auditor should inquire of others within the company about their views regarding fraud risks, including, in particular, whether they have knowledge of fraud, alleged fraud, or suspected fraud. The auditor should identify other individuals within the company to whom inquiries should be directed and determine the extent of such inquiries by considering whether others in the company might have additional knowledge about fraud, alleged fraud, or suspected fraud or might be able to corroborate fraud risks identified in discussions with management or the audit committee. Examples of other individuals within the company to whom inquiries might be directed include:

• Employees with varying levels of authority within the company, including, e.g., company personnel with whom the auditor comes into contact during the course of the audit (a) in obtaining an understanding of internal control, (b) in observing inventory or performing cutoff procedures, or (c) in obtaining explanations for significant differences identified when performing analytical procedures;

• Operating personnel not directly involved in the financial reporting process;

• Employees involved in initiating, recording, or processing complex or unusual transactions, e.g., a sales transaction with multiple elements or a significant related party transaction; and

• In-house legal counsel.

58. When evaluating management's responses to inquiries about fraud risks and determining when it is necessary to corroborate management's responses, the auditor should take into account the fact that management is often in the best position to commit fraud. Also, the auditor should obtain evidence to address inconsistencies in responses to the inquiries.

Identifying and Assessing the Risks of Material Misstatement

59. The auditor should identify and assess the risks of material misstatement at the financial statement level and the assertion level. In identifying and assessing risks of material misstatement, the auditor should:

a. Identify risks of misstatement using information obtained from performing risk assessment procedures (as discussed in paragraphs 4-58) and considering the characteristics of the accounts and disclosures in the financial statements.

Note: Factors relevant to identifying fraud risks are discussed in paragraphs 65-69 of this standard.

b. Evaluate whether the identified risks relate pervasively to the financial statements as a whole and potentially affect many assertions.

c. Evaluate the types of potential misstatements that could result from the identified risks and the accounts, disclosures, and assertions that could be affected.

Note: In identifying and assessing risks at the assertion level, the auditor should evaluate how risks at the financial statement level could affect risks of misstatement at the assertion level.

d. Assess the likelihood of misstatement, including the possibility of multiple misstatements, and the magnitude of potential misstatement to assess the possibility that the risk could result in material misstatement of the financial statements.

Note: In assessing the likelihood and magnitude of potential misstatement, the auditor may take into account the planned degree of reliance on controls selected to test.

78

78

Paragraphs 16-35 of Auditing Standard No. 13.

e. Identify significant accounts and disclosures

79

and their relevant assertions

80

(paragraphs 60-64 of this standard).

79

Paragraph A10 of Auditing Standard No. 5 states:

An account or disclosure is a significant account or disclosure if there is a reasonable possibility that the account or disclosure could contain a misstatement that, individually or when aggregated with others, has a material effect on the financial statements, considering the risks of both overstatement and understatement. The determination of whether an account or disclosure is significant is based on inherent risk, without regard to the effect of controls.

80

Paragraph A9 of Auditing Standard No. 5 states:

A relevant assertion is a financial statement assertion that has a reasonable possibility of containing a misstatement or misstatements that would cause the financial statements to be materially misstated. The determination of whether an assertion is a relevant assertion is based on inherent risk, without regard to the effect of controls.

Note: The determination of whether an account or disclosure is significant or whether an assertion is a relevant assertion is based on inherent risk, without regard to the effect of controls.

f. Determine whether any of the identified and assessed risks of material misstatement are

significant risks

(paragraphs 70-71 of this standard).

Identifying Significant Accounts and Disclosures and Their Relevant Assertions

60. To identify significant accounts and disclosures and their relevant assertions in accordance with paragraph 59.e., the auditor should evaluate the qualitative and quantitative risk factors related to the financial statement line items and disclosures. Risk factors relevant to the identification of significant accounts and disclosures and their relevant assertions include:

• Size and composition of the account;

• Susceptibility to misstatement due to error or fraud;

• Volume of activity, complexity, and homogeneity of the individual transactions processed through the account or reflected in the disclosure;

• Nature of the account or disclosure;

• Accounting and reporting complexities associated with the account or disclosure;

• Exposure to losses in the account;

• Possibility of significant contingent liabilities arising from the activities reflected in the account or disclosure;

• Existence of related party transactions in the account; and

• Changes from the prior period in account and disclosure characteristics.

61. As part of identifying significant accounts and disclosures and their relevant assertions, the auditor also should determine the likely sources of potential misstatements that would cause the financial statements to be materially misstated. The auditor might determine the likely sources of potential misstatements by asking himself or herself “what could go wrong?” within a given significant account or disclosure.

62. The risk factors that the auditor should evaluate in the identification of significant accounts and disclosures and their relevant assertions are the same in the audit of internal control over financial reporting as in the audit of the financial statements; accordingly, significant accounts and disclosures and their relevant assertions are the same for both audits.

Note: In the financial statement audit, the auditor might perform substantive auditing procedures on financial statement accounts, disclosures, and assertions that are not determined to be significant accounts and disclosures and relevant assertions.

81

81

The auditor might perform substantive auditing procedures because his or her assessment of the risk that undetected misstatement would cause the financial statements to be materially misstated is unacceptably high or as a means of introducing unpredictability in the procedures performed.

See

paragraphs 11, 14, and 25 of Auditing Standard No. 14, for further discussion about undetected misstatement.

See

paragraph 61 of Auditing Standard No. 5 and paragraph 5.c. of Auditing Standard No. 13, for further discussion about the unpredictability of auditing procedures.

63. The components of a potential significant account or disclosure might be subject to significantly differing risks.

64. When a company has multiple locations or business units, the auditor should identify significant accounts and disclosures and their relevant assertions based on the consolidated financial statements.

Factors Relevant to Identifying Fraud Risks

65. The auditor should evaluate whether the information gathered from the risk assessment procedures indicates that one or more fraud risk factors are present and should be taken into account in identifying and assessing fraud risks. Fraud risk factors are events or conditions that indicate (1) an incentive or pressure to perpetrate fraud, (2) an opportunity to carry out the fraud, or (3) an attitude or rationalization that justifies the fraudulent action. Fraud risk factors do not necessarily indicate the existence of fraud; however, they often are present in circumstances in which fraud exists. Examples of fraud risk factors related to fraudulent financial reporting and misappropriation of assets are listed in AU sec. 316.85. These illustrative risk factors are classified based on the three conditions discussed in this paragraph, which generally are present when fraud exists.

Note: The factors listed in AU sec. 316.85 cover a broad range of situations and are only examples. Accordingly, the auditor might identify additional or different fraud risk factors.

66. All three conditions discussed in the preceding paragraph are not required to be observed or evident to conclude that a fraud risk exists. The auditor might conclude that a fraud risk exists even when only one of these three conditions is present.

67.

Consideration of the Risk of Omitted, Incomplete, or Inaccurate Disclosures.

The auditor's evaluation of fraud risk factors in accordance with paragraph 65 should include evaluation of how fraud could be perpetrated or concealed by presenting incomplete or inaccurate disclosures or by omitting disclosures that are necessary for the financial statements to be presented fairly in conformity with the applicable financial reporting framework.

68.

Presumption of Fraud Risk Involving Improper Revenue Recognition.

The auditor should presume that there is a fraud risk involving improper revenue recognition and evaluate which types of revenue, revenue transactions, or assertions may give rise to such risks.

69.

Consideration of the Risk of Management Override of Controls.

The auditor's identification of fraud risks should include the risk of management override of controls.

Note: Controls over management override are important to effective internal control over financial reporting for all companies, and may be particularly important at smaller companies because of the increased involvement of senior management in performing controls and in the period-end financial reporting process. For smaller companies, the controls that address the risk of management override might be different from those at a larger company. For example, a smaller company might rely on more detailed oversight by the audit committee that focuses on the risk of management override.

Factors Relevant To Identifying Significant Risks

70. To determine whether an identified and assessed risk is a significant risk, the auditor should evaluate whether the risk requires special audit consideration because of the nature of the risk or the likelihood and potential magnitude of misstatement related to the risk.

Note: The determination of whether a risk of material misstatement is a significant risk is based on inherent risk, without regard to the effect of controls.

71. Factors that should be evaluated in determining which risks are significant risks include:

a. The effect of the quantitative and qualitative risk factors discussed in paragraph 60 on the likelihood and potential magnitude of misstatements;

b. Whether the risk is a fraud risk;

Note: A fraud risk is a significant risk.

c. Whether the risk is related to recent significant economic, accounting, or other developments;

d. The complexity of transactions;

e. Whether the risk involves significant transactions with related parties;

f. The degree of complexity or judgment in the recognition or measurement of financial information related to the risk, especially those measurements involving a wide range of measurement uncertainty; and

g. Whether the risk involves significant transactions that are outside the normal course of business for the company or that otherwise appear to be unusual due to their timing, size, or nature.

Further Consideration of Controls

72. When the auditor has determined that a significant risk, including a fraud risk, exists, the auditor should evaluate the design of the company's controls that are intended to address fraud risks and other significant risks and determine whether those controls have been implemented, if the auditor has not already done so when obtaining an understanding of internal control, as described in paragraphs 18-40 of this standard.

82

82

Auditing Standard No. 13 discusses the auditor's response to fraud risks and other significant risks.

73. Controls that address fraud risks include (a) specific controls designed to

mitigate specific risks of fraud, e.g., controls to address risks of intentional misstatement of specific accounts and (b) controls designed to prevent, deter, and detect fraud, e.g., controls to promote a culture of honesty and ethical behavior.

83

Such controls also include those that address the risk of management override of other controls.

83

AU sec. 316.88 and paragraph 14 of Auditing Standard No. 5 present examples of controls that address fraud risks.

Revision of Risk Assessment

74. The auditor's assessment of the risks of material misstatement, including fraud risks, should continue throughout the audit. When the auditor obtains audit evidence during the course of the audit that contradicts the audit evidence on which the auditor originally based his or her risk assessment, the auditor should revise the risk assessment and modify planned audit procedures or perform additional procedures in response to the revised risk assessments.

84

84

See also

paragraph 46 of Auditing Standard No. 13.

APPENDIX A—Definitions

A1. For purposes of this standard, the terms listed below are defined as follows:

A2. Business risks—Risks that result from significant conditions, events, circumstances, actions, or inactions that could adversely affect a company's ability to achieve its objectives and execute its strategies. Business risks also might result from setting inappropriate objectives and strategies or from changes or complexity in the company's operations or management.

A3. Company's objectives and strategies—The overall plans for the company as established by management or the board of directors. Strategies are the approaches by which management intends to achieve its objectives.

A4. Risk assessment procedures—The procedures performed by the auditor to obtain information for identifying and assessing the risks of material misstatement in the financial statements whether due to error or fraud.

Note: Risk assessment procedures by themselves do not provide sufficient appropriate evidence on which to base an audit opinion.

A5. Significant risk—A risk of material misstatement that requires special audit consideration.

APPENDIX B—Consideration of Manual and Automated Systems and Controls

B1. While obtaining an understanding of the company's information system related to financial reporting, the auditor should obtain an understanding of how the company uses information technology (“IT”) and how IT affects the financial statements.

85

The auditor also should obtain an understanding of the extent of manual controls and automated controls used by the company, including the IT general controls that are important to the effective operation of the automated controls. That information should be taken into account in assessing the risks of material misstatement.

86

85

See also

AU sec. 324,

Service Organizations,

if the company uses a service organization for services that are part of the company's internal control over financial reporting.

86

See also

paragraphs 16-17 of Auditing Standard No. 9,

Audit Planning.

B2. Controls in a manual system might include procedures such as approvals and reviews of transactions, and reconciliations and follow-up of reconciling items.

B3. Alternatively, a company might use automated procedures to initiate, record, process, and report transactions, in which case records in electronic format would replace paper documents. When IT is used to initiate, record, process, and report transactions, the IT systems and programs may include controls related to the relevant assertions of significant accounts and disclosures or may be critical to the effective functioning of manual controls that depend on IT.

B4. The auditor should obtain an understanding of specific risks to a company's internal control over financial reporting resulting from IT. Examples of such risks include:

• Reliance on systems or programs that are inaccurately processing data, processing inaccurate data, or both;

• Unauthorized access to data that might result in destruction of data or improper changes to data, including the recording of unauthorized or non-existent transactions or inaccurate recording of transactions (particular risks might arise when multiple users access a common database);

• The possibility of IT personnel gaining access privileges beyond those necessary to perform their assigned duties, thereby breaking down segregation of duties;

• Unauthorized changes to data in master files;

• Unauthorized changes to systems or programs;

• Failure to make necessary changes to systems or programs;

• Inappropriate manual intervention; and

• Potential loss of data or inability to access data as required.

B5. In obtaining an understanding of the company's control activities, the auditor should obtain an understanding of how the company has responded to risks arising from IT.

B6. When a company uses manual elements in internal control systems and the auditor plans to rely on, and therefore test, those manual controls, the auditor should design procedures to test the consistency in the application of those manual controls.

Auditing Standard No. 13

The Auditor's Responses to the Risks of Material Misstatement

Introduction

1. This standard establishes requirements regarding designing and implementing appropriate responses to the risks of material misstatement.

Objective

2. The objective of the auditor is to address the risks of material misstatement through appropriate overall audit responses and audit procedures.

Responding to the Risks of Material Misstatement

3. To meet the objective in the preceding paragraph, the auditor must design and implement audit responses that address the risks of material misstatement that are identified and assessed in accordance with Auditing Standard No. 12,

Identifying and Assessing Risks of Material Misstatement

.

4. This standard discusses the following types of audit responses:

a. Responses that have an overall effect on how the audit is conducted (“overall responses”), as described in paragraphs 5-7; and

b. Responses involving the nature, timing, and extent of the audit procedures to be performed, as described in paragraphs 8-46.

Overall Responses

5. The auditor should design and implement overall responses to address the assessed risks of material misstatement as follows:

a.

Making appropriate assignments of significant engagement responsibilities.

The knowledge, skill, and ability of engagement team members with significant engagement responsibilities should be commensurate with the assessed risks of material misstatement.

87

87

See also

paragraph .06 of AU sec. 230,

Due Professional Care in the Performance of Work.

b.

Providing the extent of supervision that is appropriate for the circumstances, including, in particular, the assessed risks of material misstatement.

(See paragraphs 5-6 of Auditing Standard No. 10,

Supervision of the Audit Engagement.

)

c.

Incorporating elements of unpredictability in the selection of audit procedures to be performed.

As part of the auditor's response to the assessed risks of material misstatement, including the assessed risks of material misstatement due to fraud (“fraud risks”), the auditor should incorporate an element of unpredictability in the selection of auditing procedures to be performed from year to year. Examples of ways to incorporate an element of unpredictability include:

(1) Performing audit procedures related to accounts, disclosures, and assertions that would not otherwise be tested based on their amount or the auditor's assessment of risk;

(2) Varying the timing of the audit procedures;

(3) Selecting items for testing that have lower amounts or are otherwise outside customary selection parameters;

(4) Performing audit procedures on an unannounced basis; and

(5) In multi-location audits, varying the location or the nature, timing, and extent of audit procedures at related locations or business units from year to year.

88

88

For integrated audits, paragraphs 61 and B13 of Auditing Standard No. 5,

An audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements,

establish requirements for introducing unpredictability in testing of controls from year to year and in multi-location audits.

d.

Evaluating the company's selection and application of significant accounting principles.

The auditor should evaluate whether the company's selection and application of significant accounting principles, particularly those related to subjective measurements and complex transactions,

89

are indicative of bias that could lead to material misstatement of the financial statements.

89

Paragraphs 12-13 of Auditing Standard No. 12 discuss the auditor's responsibilities regarding obtaining an understanding of the company's selection and application of accounting principles.

See also

paragraphs .66-.67 of AU sec. 316,

Consideration of Fraud in a Financial Statement Audit,

and paragraphs .04 and .06 of AU sec. 411,

The Meaning of Present Fairly in Conformity With Generally Accepted Accounting Principles.

Note: Paragraph .11 of AU sec. 380,

Communication With Audit Committees,

discusses the auditor's judgments about the quality of a company's accounting principles.

6. The auditor also should determine whether it is necessary to make pervasive changes to the nature, timing, or extent of audit procedures to adequately address the assessed risks of material misstatement. Examples of such pervasive changes include modifying the audit strategy to:

a. Increase the substantive testing of the valuation of numerous significant accounts at year end because of significantly deteriorating market conditions, and

b. Obtain more persuasive audit evidence from substantive procedures due to the identification of pervasive weaknesses in the company's control environment.

7. Due professional care requires the auditor to exercise professional skepticism.

90

Professional skepticism is an attitude that includes a questioning mind and a critical assessment of the appropriateness and sufficiency of audit evidence. The auditor's responses to the assessed risks of material misstatement, particularly fraud risks, should involve the application of professional skepticism in gathering and evaluating audit evidence.

91

Examples of the application of professional skepticism in response to the assessed fraud risks are (a) modifying the planned audit procedures to obtain more reliable evidence regarding relevant assertions and (b) obtaining sufficient appropriate evidence to corroborate management's explanations or representations concerning important matters, such as through third-party confirmation, use of a specialist engaged or employed by the auditor, or examination of documentation from independent sources.

90

AU secs. 230.07-.09.

91

AU sec. 316.13.

Responses Involving the Nature, Timing, and Extent of Audit Procedures

8. The auditor should design and perform audit procedures in a manner that addresses the assessed risks of material misstatement for each relevant assertion of each significant account and disclosure.

9. In designing the audit procedures to be performed, the auditor should:

a. Obtain more persuasive audit evidence the higher the auditor's assessment of risk;

b. Take into account the types of potential misstatements that could result from the identified risks and the likelihood and magnitude of potential misstatement;

92

92

For example, potential misstatements regarding disclosures include omission of required disclosures or presentation of inaccurate or incomplete disclosures.

c. In an integrated audit, design the testing of controls to accomplish the objectives of both audits simultaneously:

(1) To obtain sufficient evidence to support the auditor's control risk

93

assessments for purposes of the audit of financial statements;

94

and

93

See

paragraph 7.b. of Auditing Standard No. 8,

Audit Risk,

for a definition of control risk.

94

For purposes of this standard, the term “audit of financial statements” refers to the financial statement portion of the integrated audit and to the audit of financial statements only.

(2) To obtain sufficient evidence to support the auditor's opinion on internal control over financial reporting as of year-end.

Note: Auditing Standard No. 5 establishes requirements for tests of controls in the audit of internal control over financial reporting.

10. The audit procedures performed in response to the assessed risks of material misstatement can be classified into two categories: (1) tests of controls and (2) substantive procedures.

95

Paragraphs 16-35 of this standard discuss tests of controls, and paragraphs 36-46 discuss substantive procedures.

95

Substantive procedures consist of (a) tests of details of accounts and disclosures and (b) substantive analytical procedures.

Note: Paragraphs 16-17 of this standard discuss when tests of controls are necessary in a financial statement audit. Ordinarily, tests of controls are performed for relevant assertions for which the auditor chooses to rely on controls to modify his or her substantive procedures.

Responses to Significant Risks

11. For significant risks, the auditor should perform substantive procedures, including tests of details, that are specifically responsive to the assessed risks.

Note: Auditing Standard No. 12 discusses identification of significant risks

96

and states that fraud risks are significant risks.

96

See

paragraph 71 of Auditing Standard No. 12 for factors that the auditor should evaluate in determining which risks are significant risks.

Responses to Fraud Risks

12. The audit procedures that are necessary to address the assessed fraud risks depend upon the types of risks and the relevant assertions that might be affected.

Note: If the auditor identifies deficiencies in controls that are intended to address assessed fraud risks, the auditor should take into account those deficiencies when designing his or her response to those fraud risks.

Note: Auditing Standard No. 5 establishes requirements for addressing assessed fraud risks in the audit of internal control over financial reporting.

97

97

Paragraphs 14-15 of Auditing Standard No. 5.

13.

Addressing Fraud Risks in the Audit of Financial Statements.

In the audit of financial statements, the auditor should perform substantive procedures, including tests of details, that are specifically responsive to the assessed fraud risks. If the auditor selects certain controls intended to address the assessed fraud risks for testing in accordance with paragraphs 16-17 of this standard, the auditor should perform tests of those controls.

14. The following are examples of ways in which planned audit procedures may be modified to address assessed fraud risks:

a. Changing the

nature

of audit procedures to obtain evidence that is more reliable or to obtain additional corroborative information;

b. Changing the

timing

of audit procedures to be closer to the end of the period or to the points during the period in which fraudulent transactions are more likely to occur; and

c. Changing the

extent

of the procedures applied to obtain more evidence, e.g., by increasing sample sizes or applying computer-assisted audit techniques to all of the items in an account.

Note: AU secs. 316.54-.67 provide additional examples of responses to assessed fraud risks relating to fraudulent financial reporting (e.g., revenue recognition, inventory quantities, and management estimates) and misappropriation of assets in the audit of financial statements.

15. Also, AU sec. 316 indicates that the auditor should perform audit procedures to specifically address the risk of management override of controls including:

a. Examining journal entries and other adjustments for evidence of possible material misstatement due to fraud (AU secs. 316.58-.62);

b. Reviewing accounting estimates for biases that could result in material misstatement due to fraud (AU secs. 316.63-.65); and

c. Evaluating the business rationale for significant unusual transactions (AU secs. 316.66-.67).

Testing Controls

Testing Controls in an Audit of Financial Statements

16.

Controls to be Tested.

If the auditor plans to assess control risk at less than the maximum by relying on controls,

98

and the nature, timing, and extent of planned substantive procedures are based on that lower assessment, the auditor must obtain evidence that the controls selected for testing are designed effectively and operated effectively during the entire

period of reliance

.

99

However, the auditor is not required to assess control risk at less than the maximum for

all

relevant assertions and, for a variety of reasons, the auditor may choose not to do so.

98

Reliance on controls that is supported by sufficient and appropriate audit evidence allows the auditor to assess control risk at less than the maximum, which results in a lower assessed risk of material misstatement. In turn, this allows the auditor to modify the nature, timing, and extent of planned substantive procedures.

99

Terms defined in Appendix A,

Definitions,

are set in

boldface type

the first time they appear.

17. Also, tests of controls must be performed in the audit of financial statements for each relevant assertion for which substantive procedures alone cannot provide sufficient appropriate audit evidence and when necessary to support the auditor's reliance on the accuracy and completeness of financial information used in performing other audit procedures.

100

100

Paragraph 10 of Auditing Standard No. 15,

Audit Evidence,

and paragraph .16 of AU sec. 329,

Substantive Analytical Procedures.

Note: When a significant amount of information supporting one or more relevant assertions is electronically initiated, recorded, processed, or reported, it might be impossible to design effective substantive tests that, by themselves, would provide sufficient appropriate evidence regarding the assertions. For such assertions, significant audit evidence may be available only in electronic form. In such cases, the sufficiency and appropriateness of the audit evidence usually depend on the effectiveness of controls over their accuracy and completeness. Furthermore, the potential for improper initiation or alteration of information to occur and not be detected may be greater if information is initiated, recorded, processed, or reported only in electronic form and appropriate controls are not operating effectively.

18.

Evidence about the Effectiveness of Controls in the Audit of Financial Statements.

In designing and performing tests of controls for the audit of financial statements, the evidence necessary to support the auditor's control risk assessment depends on the degree of reliance the auditor plans to place on the effectiveness of a control. The auditor should obtain more persuasive audit evidence from tests of controls the greater the reliance the auditor places on the effectiveness of a control. The auditor also should obtain more persuasive evidence about the effectiveness of controls for each relevant assertion for which the audit approach consists primarily of tests of controls, including situations in which substantive procedures alone cannot provide sufficient appropriate audit evidence.

Testing Design Effectiveness

19. The auditor should test the design effectiveness of the controls selected for testing by determining whether the company's controls, if they are operated as prescribed by persons possessing the necessary authority and competence to perform the control effectively, satisfy the company's control objectives and can effectively prevent or detect error or fraud that could result in material misstatements in the financial statements.

Note: A smaller, less complex company might achieve its control objectives in a different manner from a larger, more complex organization. For example, a smaller, less complex company might have fewer employees in the accounting function, limiting opportunities to segregate duties and leading the company to implement alternative controls to achieve its control objectives. In such circumstances, the auditor should evaluate whether those alternative controls are effective.

20. Procedures the auditor performs to test design effectiveness include a mix of inquiry of appropriate personnel, observation of the company's operations, and inspection of relevant documentation. Walkthroughs that include these procedures ordinarily are sufficient to evaluate design effectiveness.

101

101

Paragraphs 37-38 of Auditing Standard No. 12 discuss performing a walkthrough.

Testing Operating Effectiveness

21. The auditor should test the operating effectiveness of a control selected for testing by determining whether the control is operating as designed and whether the person performing the control possesses the necessary authority and competence to perform the control effectively.

22. Procedures the auditor performs to test operating effectiveness include a

mix of inquiry of appropriate personnel, observation of the company's operations, inspection of relevant documentation, and re-performance of the control.

Obtaining Evidence From Tests of Controls

23. The evidence provided by the auditor's tests of the effectiveness of controls depends upon the mix of the nature, timing, and extent of the auditor's procedures. Further, for an individual control, different combinations of the nature, timing, and extent of testing might provide sufficient evidence in relation to the degree of reliance in an audit of financial statements.

Note: To obtain evidence about whether a control is effective, the control must be tested directly; the effectiveness of a control cannot be inferred from the absence of misstatements detected by substantive procedures.

Nature of Tests of Controls

24. Some types of tests, by their nature, produce greater evidence of the effectiveness of controls than other tests. The following tests that the auditor might perform are presented in the order of the evidence that they ordinarily would produce, from least to most: inquiry, observation, inspection of relevant documentation, and re-performance of a control.

Note: Inquiry alone does not provide sufficient evidence to support a conclusion about the effectiveness of a control.

25. The nature of the tests of controls that will provide appropriate evidence depends, to a large degree, on the nature of the control to be tested, including whether the operation of the control results in documentary evidence of its operation. Documentary evidence of the operation of some controls, such as management's philosophy and operating style, might not exist.

Note: A smaller, less complex company or unit might have less formal documentation regarding the operation of its controls. In those situations, testing controls through inquiry combined with other procedures, such as observation of activities, inspection of less formal documentation, or re-performance of certain controls, might provide sufficient evidence about whether the control is effective.

Extent of Tests of Controls

26. The more extensively a control is tested, the greater the evidence obtained from that test.

27. Matters that could affect the necessary extent of testing of a control in relation to the degree of reliance on a control include the following:

• The frequency of the performance of the control by the company during the audit period;

• The length of time during the audit period that the auditor is relying on the operating effectiveness of the control;

• The expected rate of deviation from a control;

• The relevance and reliability of the audit evidence to be obtained regarding the operating effectiveness of the control;

• The extent to which audit evidence is obtained from tests of other controls related to the assertion;

• The nature of the control, including, in particular, whether it is a manual control or an automated control; and

• For an automated control, the effectiveness of relevant information technology general controls.

Note: AU sec. 350,

Audit Sampling,

establishes requirements regarding the use of sampling in tests of controls.

Timing of Tests of Controls

28. The timing of tests of controls relates to when the evidence about the operating effectiveness of the controls is obtained and the period of time to which it applies. Paragraph 16 of this standard indicates that the auditor must obtain evidence that the controls selected for testing are designed effectively and operated effectively during the entire period of reliance.

29.

Using Audit Evidence Obtained during an Interim Period.

When the auditor obtains evidence about the operating effectiveness of controls as of or through an interim date, he or she should determine what additional evidence is necessary concerning the operation of the controls for the remaining period of reliance.

30. The additional evidence that is necessary to update the results of testing from an interim date through the remaining period of reliance depends on the following factors:

• The possibility that there have been any significant changes in internal control over financial reporting subsequent to the interim date;

Note: If there have been significant changes to the control since the interim date, the auditor should obtain evidence about the effectiveness of the new or modified control;

• The inherent risk associated with the related account(s) or assertion(s);

• The specific control tested prior to year end, including the nature of the control and the risk that the control is no longer effective during the remaining period, and the results of the tests of the control;

• The planned degree of reliance on the control;

• The sufficiency of the evidence of effectiveness obtained at an interim date; and

• The length of the remaining period.

31.

Using Audit Evidence Obtained in Past Audits.

For audits of financial statements, the auditor should obtain evidence during the current year audit about the design and operating effectiveness of controls upon which the auditor relies. When controls on which the auditor plans to rely have been tested in past audits and the auditor plans to use evidence about the effectiveness of those controls that was obtained in prior years, the auditor should take into account the following factors to determine the evidence needed during the current year audit to support the auditor's control risk assessments:

• The nature and materiality of misstatements that the control is intended to prevent or detect;

• The inherent risk associated with the related account(s) or assertion(s);

• Whether there have been changes in the volume or nature of transactions that might adversely affect control design or operating effectiveness;

• Whether the account has a history of errors;

• The effectiveness of entity-level controls that the auditor has tested, especially controls that monitor other controls;

• The nature of the controls and the frequency with which they operate;

• The degree to which the control relies on the effectiveness of other controls (e.g., the control environment or information technology general controls);

• The competence of the personnel who perform the control or monitor its performance and whether there have been changes in key personnel who perform the control or monitor its performance;

• Whether the control relies on performance by an individual or is automated (i.e., an automated control would generally be expected to be lower risk if relevant information technology general controls are effective);

102

102

The auditor also may use a benchmarking strategy, when appropriate, for automated application controls in subsequent years' audits. Benchmarking is described further beginning at paragraph B28 of Auditing Standard No. 5.

• The complexity of the control and the significance of the judgments that must be made in connection with its operation;

• The planned degree of reliance on the control;

• The nature, timing, and extent of procedures performed in past audits;

• The results of the previous years' testing of the control;

• Whether there have been changes in the control or the process in which it operates since the previous audit; and

• For integrated audits, the evidence regarding the effectiveness of the controls obtained during the audit of internal control.

Assessing Control Risk

32. The auditor should assess control risk for relevant assertions by evaluating the evidence obtained from all sources, including the auditor's testing of controls for the audit of internal control and the audit of financial statements, misstatements detected during the financial statement audit, and any identified control deficiencies.

33. Control risk should be assessed at the maximum level for relevant assertions (1) for which controls necessary to sufficiently address the assessed risk of material misstatement in those assertions are missing or ineffective or (2) when the auditor has not obtained sufficient appropriate evidence to support a control risk assessment below the maximum level.

34. When deficiencies affecting the controls on which the auditor intends to rely are detected, the auditor should evaluate the severity of the deficiencies and the effect on the auditor's control risk assessments. If the auditor plans to rely on controls relating to an assertion but the controls that the auditor tests are ineffective because of control deficiencies, the auditor should:

a. Perform tests of other controls related to the same assertion as the ineffective controls, or

b. Revise the control risk assessment and modify the planned substantive procedures as necessary in light of the increased assessment of risk.

Note: Auditing Standard No. 5 establishes requirements for evaluating the severity of a control deficiency and communicating identified control deficiencies to management and the audit committee in an integrated audit. AU sec. 325,

Communications About Control Deficiencies in an Audit of Financial Statements,

establishes requirements for communicating significant deficiencies and material weaknesses in an audit of financial statements only.

Testing Controls in an Audit of Internal Control

35. Auditing Standard No. 5 states that the objective of the tests of controls in an audit of internal control is to obtain evidence about the effectiveness of controls to support the auditor's opinion on the company's internal control over financial reporting. The auditor's opinion relates to the effectiveness of the company's internal control over financial reporting as of a point in time and taken as a whole.

103

Auditing Standard No. 5 establishes requirements regarding the selection of controls to be tested and the necessary nature, timing, and extent of tests of controls in an audit of internal control over financial reporting.

103

Paragraph B1 of Auditing Standard No. 5.

Substantive Procedures

36. The auditor should perform substantive procedures for each relevant assertion of each significant account and disclosure, regardless of the assessed level of control risk.

37. As the assessed risk of material misstatement increases, the evidence from substantive procedures that the auditor should obtain also increases. The evidence provided by the auditor's substantive procedures depends upon the mix of the nature, timing, and extent of those procedures. Further, for an individual assertion, different combinations of the nature, timing, and extent of testing might provide sufficient appropriate evidence to respond to the assessed risk of material misstatement.

38. Internal control over financial reporting has inherent limitations,

104

which, in turn, can affect the evidence that is needed from substantive procedures. For example, more evidence from substantive procedures ordinarily is needed for relevant assertions that have a higher susceptibility to management override or to lapses in judgment or breakdowns resulting from human failures.

105

104

Paragraph A5 of Auditing Standard No. 5.

105

See, e.g.,

paragraph .14 of AU sec. 328,

Auditing Fair Value Measurements and Disclosures.

Nature of Substantive Procedures

39. Substantive procedures generally provide persuasive evidence when they are designed and performed to obtain evidence that is relevant and reliable. Also, some types of substantive procedures, by their nature, produce more persuasive evidence than others. Inquiry alone does not provide sufficient appropriate evidence to support a conclusion about a relevant assertion.

Note: Auditing Standard No. 15 discusses certain types of substantive procedures and the relevance and reliability of audit evidence.

40. Taking into account the types of potential misstatements in the relevant assertions that could result from identified risks, as required by paragraph 9.b., can help the auditor determine the types and combination of substantive audit procedures that are necessary to detect material misstatements in the respective assertions.

41.

Substantive Procedures Related to the Period-end Financial Reporting Process.

The auditor's substantive procedures must include the following audit procedures related to the period-end financial reporting process:

a. Reconciling the financial statements with the underlying accounting records; and

b. Examining material adjustments made during the course of preparing the financial statements.

Note: AU secs. 316.58-.62 establish requirements for examining journal entries and other adjustments for evidence of possible material misstatement due to fraud.

Extent of Substantive Procedures

42. The more extensively a substantive procedure is performed, the greater the evidence obtained from the procedure. The necessary extent of a substantive audit procedure depends on the materiality of the account or disclosure, the assessed risk of material misstatement, and the necessary degree of assurance from the procedure. However, increasing the extent of an audit procedure cannot adequately address an assessed risk of material misstatement unless the evidence to be obtained from the procedure is reliable and relevant.

Timing of Substantive Procedures

43. Performing certain substantive procedures at interim dates may permit early consideration of matters affecting the year-end financial statements, e.g., testing material transactions involving higher risks of misstatement. However, performing substantive procedures at an interim date without performing procedures at a later date increases the risk that a material misstatement could exist in the year-end financial statements that would not be detected by the auditor. This risk increases as the period between the interim date and year end increases.

44. In determining whether it is appropriate to perform substantive procedures at an interim date, the auditor should take into account the following:

a. The assessed risk of material misstatement, including:

(1) The auditor's assessment of control risk, as discussed in paragraphs 32-34;

(2) The existence of conditions or circumstances, if any, that create incentives or pressures on management to misstate the financial statements between the interim test date and the end of the period covered by the financial statements;

(3) The effects of known or expected changes in the company, its environment, or its internal control over financial reporting during the remaining period;

b. The nature of the substantive procedures;

c. The nature of the account or disclosure and relevant assertion; and

d. The ability of the auditor to perform the necessary audit procedures to cover the remaining period.

45. When substantive procedures are performed at an interim date, the auditor should cover the remaining period by performing substantive procedures, or substantive procedures combined with tests of controls, that provide a reasonable basis for extending the audit conclusions from the interim date to the period end. Such procedures should include (a) comparing relevant information about the account balance at the interim date with comparable information at the end of the period to identify amounts that appear unusual and investigating such amounts and (b) performing audit procedures to test the remaining period.

46. If the auditor obtains evidence that contradicts the evidence on which the original risk assessments were based, including evidence of misstatements that he or she did not expect, the auditor should revise the related risk assessments and modify the planned nature, timing, or extent of substantive procedures covering the remaining period as necessary. Examples of such modifications include extending or repeating at the period end the procedures performed at the interim date.

Dual-Purpose Tests

47. In some situations, the auditor might perform a substantive test of a transaction concurrently with a test of a control relevant to that transaction (a “

dual-purpose test

”). In those situations, the auditor should design the dual-purpose test to achieve the objectives of both the test of the control and the substantive test. Also, when performing a dual-purpose test, the auditor should evaluate the results of the test in forming conclusions about both the assertion and the effectiveness of the control being tested.

106

106

Paragraph .44 of AU sec. 350 discusses applying audit sampling in dual-purpose tests.

APPENDIX A—Definitions

A1. For purposes of this standard, the terms listed below are defined as follows:

A2. Dual-purpose test—Substantive test of a transaction and a test of a control relevant to that transaction that are performed concurrently, e.g., a substantive test of sales transactions performed concurrently with a test of controls over those transactions.

A3. Period of reliance—The period being covered by the company's financial statements, or the portion of that period, for which the auditor plans to rely on controls in order to modify the nature, timing, and extent of planned substantive procedures.

Auditing Standard No. 14

Evaluating Audit Results

Introduction

1. This standard establishes requirements regarding the auditor's evaluation of audit results and determination of whether he or she has obtained sufficient appropriate audit evidence.

Objective

2. The objective of the auditor is to evaluate the results of the audit to determine whether the audit evidence obtained is sufficient and appropriate to support the opinion to be expressed in the auditor's report.

Evaluating the Results of the Audit of Financial Statements

3. In forming an opinion on whether the financial statements are presented fairly, in all material respects, in conformity with the applicable financial reporting framework, the auditor should take into account all relevant audit evidence, regardless of whether it appears to corroborate or to contradict the assertions in the financial statements.

4. In the audit of financial statements,

107

the auditor's evaluation of audit results should include evaluation of the following:

107

For purposes of this standard, the term “audit of financial statements” refers to the financial statement portion of the integrated audit and to the audit of financial statements only.

a. The results of analytical procedures performed in the overall review of the financial statements (“overall review”);

b.

Misstatements

accumulated during the audit, including, in particular,

uncorrected misstatements;

108

108

Terms defined in Appendix A,

Definitions,

are set in

boldface type

the first time they appear.

c. The qualitative aspects of the company's accounting practices;

d. Conditions identified during the audit that relate to the assessment of the risk of material misstatement due to fraud (“fraud risk”);

e. The presentation of the financial statements, including the disclosures; and

f. The sufficiency and appropriateness of the audit evidence obtained.

Performing Analytical Procedures in the Overall Review

5. In the overall review, the auditor should read the financial statements and disclosures and perform analytical procedures to (a) evaluate the auditor's conclusions formed regarding significant accounts and disclosures and (b) assist in forming an opinion on whether the financial statements as a whole are free of material misstatement.

6. As part of the overall review, the auditor should evaluate whether:

a. The evidence gathered in response to unusual or unexpected transactions, events, amounts, or relationships previously identified during the audit is sufficient; and

b. Unusual or unexpected transactions, events, amounts, or relationships

109

indicate risks of material misstatement that were not identified previously, including, in particular, fraud risks.

109

Paragraphs 46-48 of Auditing Standard No. 12,

Identifying and Assessing Risks of Material Misstatement

and paragraph .03 of AU sec. 329,

Substantive Analytical Procedures.

Note: If the auditor discovers a previously unidentified risk of material misstatement or concludes that the evidence gathered is not adequate, he or she should modify his or her audit procedures or perform additional procedures as necessary in accordance with paragraph 36 of this standard.

7. The nature and extent of the analytical procedures performed during the overall review may be similar to the analytical procedures performed as risk assessment procedures. The auditor should perform analytical procedures relating to revenue through the end of the reporting period.

110

110

Paragraph 47 of Auditing Standard No. 12 contains a requirement to perform analytical procedures relating to revenue as part of the risk assessment procedures.

8. The auditor should obtain corroboration for management's explanations regarding significant unusual or unexpected transactions,

events, amounts, or relationships. If management's responses to the auditor's inquiries appear to be implausible, inconsistent with other audit evidence, imprecise, or not at a sufficient level of detail to be useful, the auditor should perform procedures to address the matter.

9.

Evaluating Whether Analytical Procedures Indicate a Previously Unrecognized Fraud Risk.

Whether an unusual or unexpected transaction, event, amount, or relationship indicates a fraud risk, as discussed in paragraph 6.b., depends on the relevant facts and circumstances, including the nature of the account or relationship among the data used in the analytical procedures. For example, certain unusual or unexpected transactions, events, amounts, or relationships could indicate a fraud risk if a component of the relationship involves accounts and disclosures that management has incentives or pressures to manipulate, e.g., significant unusual or unexpected relationships involving revenue and income.

Accumulating and Evaluating Identified Misstatements

10.

Accumulating Identified Misstatements.

The auditor should accumulate misstatements identified during the audit, other than those that are clearly trivial.

Note: “Clearly trivial” is not another expression for “not material.” Matters that are clearly trivial will be of a smaller order of magnitude than the materiality level established in accordance with Auditing Standard No. 11,

Consideration of Materiality in Planning and Performing an Audit,

and will be inconsequential, whether taken individually or in aggregate and whether judged by any criteria of size, nature, or circumstances. When there is any uncertainty about whether one or more items is clearly trivial, the matter is not considered trivial.

11. The auditor may designate an amount below which misstatements are clearly trivial and do not need to be accumulated. In such cases, the amount should be set so that any misstatements below that amount would not be material to the financial statements, individually or in combination with other misstatements, considering the possibility of undetected misstatement.

12. The auditor's accumulation of misstatements should include the auditor's best estimate of the total misstatement in the accounts and disclosures that he or she has tested, not just the amount of misstatements specifically identified. This includes misstatements related to accounting estimates, as determined in accordance with paragraph 13 of this standard, and projected misstatements from substantive procedures that involve audit sampling, as determined in accordance with AU sec. 350,

Audit Sampling.

111

111

AU sec. 350.26.

13.

Misstatements Relating to Accounting Estimates.

If the auditor concludes that the amount of an accounting estimate included in the financial statements is unreasonable or was not determined in conformity with the relevant requirements of the applicable financial reporting framework, he or she should treat the difference between that estimate and a reasonable estimate determined in conformity with the applicable accounting principles as a misstatement. If a range of reasonable estimates is supported by sufficient appropriate audit evidence and the recorded estimate is outside of the range of reasonable estimates, the auditor should treat the difference between the recorded accounting estimate and the closest reasonable estimate as a misstatement.

Note: If an accounting estimate is determined in conformity with the relevant requirements of the applicable financial reporting framework and the amount of the estimate is reasonable, a difference between an estimated amount best supported by the audit evidence and the recorded amount of the accounting estimate ordinarily would not be considered to be a misstatement. Paragraph 27 discusses evaluating accounting estimates for bias.

14.

Considerations as the Audit Progresses.

The auditor should determine whether the overall audit strategy and audit plan need to be modified if:

a. The nature of accumulated misstatements and the circumstances of their occurrence indicate that other misstatements might exist that, in combination with accumulated misstatements, could be material; or

b. The aggregate of misstatements accumulated during the audit approaches the materiality level or levels used in planning and performing the audit.

112

112

Auditing Standard No. 11.

Note: When the aggregate of accumulated misstatements approaches the materiality level or levels used in planning and performing the audit, there likely will be greater than an appropriately low level of risk that possible undetected misstatements, when combined with the aggregate of misstatements accumulated during the audit that remain uncorrected, could be material to the financial statements. If the auditor's assessment of this risk is unacceptably high, he or she should perform additional audit procedures or determine that management has adjusted the financial statements so that the risk that the financial statements are materially misstated has been reduced to an appropriately low level.

15. The auditor should communicate accumulated misstatements to management on a timely basis to provide management with an opportunity to correct them.

16. If management has examined an account or a disclosure in response to misstatements detected by the auditor and has made corrections to the account or disclosure, the auditor should evaluate management's work to determine whether the corrections have been recorded properly and whether uncorrected misstatements remain.

17.

Evaluation of the Effect of Uncorrected Misstatements.

The auditor should evaluate whether uncorrected misstatements are material, individually or in combination with other misstatements. In making this evaluation, the auditor should evaluate the misstatements in relation to the specific accounts and disclosures involved and to the financial statements as a whole, taking into account relevant quantitative and qualitative factors.

113

(See Appendix B.)

113

If the financial statements contain material misstatements, AU sec. 508,

Reports on Audited Financial Statements,

indicates that the auditor should issue a qualified or an adverse opinion on the financial statements. AU sec. 508.35 discusses situations in which the financial statements are materially affected by a departure from the applicable financial reporting framework.

Note: In interpreting the federal securities laws, the Supreme Court of the United States has held that a fact is material if there is “a substantial likelihood that the * * * fact would have been viewed by the reasonable investor as having significantly altered the ‘total mix' of information made available.”

114

As the Supreme Court has noted, determinations of materiality require “delicate assessments of the inferences a ‘reasonable shareholder' would draw from a given set of facts and the significance of those inferences to him * * *.”

115

114

TSC Industries

v.

Northway, Inc.,

426 U.S. 438, 449 (1976).

See also

Basic, Inc.

v.

Levinson,

485 U.S. 224 (1988).

115

TSC Industries,

426 U.S. at 450.

Note: As a result of the interaction of quantitative and qualitative considerations in materiality judgments, uncorrected misstatements of relatively small amounts could have a material effect on the financial statements. For

example, an illegal payment of an otherwise immaterial amount could be material if there is a reasonable possibility

116

that it could lead to a material contingent liability or a material loss of revenue.

117

Also, a misstatement made intentionally could be material for qualitative reasons, even if relatively small in amount.

116

There is a reasonable possibility of an event, as used in this standard, when the likelihood of the event is either “reasonably possible” or “probable,” as those terms are used in the FASB Accounting Standards Codification, Contingencies Topic, paragraph 450-20-25-1.

117

AU sec. 317,

Illegal Acts by Clients.

Note: If the reevaluation of the established materiality level or levels, as set forth in Auditing Standard No. 11,

118

results in a lower amount for the materiality level or levels, the auditor should take into account that lower materiality level or levels in the evaluation of uncorrected misstatements.

118

Paragraphs 11-12 of Auditing Standard No. 11.

18. The auditor's evaluation of uncorrected misstatements, as described in paragraph 17 of this standard, should include evaluation of the effects of uncorrected misstatements detected in prior years and misstatements detected in the current year that relate to prior years.

19. The auditor cannot assume that an instance of error or fraud is an isolated occurrence. Therefore, the auditor should evaluate the nature and effects of the individual misstatements accumulated during the audit on the assessed risks of material misstatement. This evaluation is important in determining whether the risk assessments remain appropriate, as discussed in paragraph 36 of this standard.

20.

Evaluating Whether Misstatements Might Be Indicative of Fraud.

The auditor should evaluate whether identified misstatements

119

might be indicative of fraud and, in turn, how they affect the auditor's evaluation of materiality and the related audit responses. As indicated in AU sec. 316,

Consideration of Fraud in a Financial Statement Audit,

fraud is an intentional act that results in material misstatement of the financial statements.

120

119

Misstatements include omission and presentation of inaccurate or incomplete disclosures.

120

AU sec. 316.05.

21. If the auditor believes that a misstatement is or might be intentional, and if the effect on the financial statements could be material or cannot be readily determined, the auditor should perform procedures to obtain additional audit evidence to determine whether fraud has occurred or is likely to have occurred and, if so, its effect on the financial statements and the auditor's report thereon.

22. For misstatements that the auditor believes are or might be intentional, the auditor should evaluate the implications on the integrity of management or employees and the possible effect on other aspects of the audit. If the misstatement involves higher-level management, it might be indicative of a more pervasive problem, such as an issue with the integrity of management, even if the amount of the misstatement is small. In such circumstances, the auditor should reevaluate the assessment of fraud risk and the effect of that assessment on (a) the nature, timing, and extent of the necessary tests of accounts or disclosures and (b) the assessment of the effectiveness of controls. The auditor also should evaluate whether the circumstances or conditions indicate possible collusion involving employees, management, or external parties and, if so, the effect of the collusion on the reliability of evidence obtained.

23. If the auditor becomes aware of information indicating that fraud or another illegal act has occurred or might have occurred, he or she also must determine his or her responsibilities under AU secs. 316.79-.82A, AU sec. 317, and Section 10A of the Securities Exchange Act of 1934, 15 U.S.C. § 78j-1.

Evaluating the Qualitative Aspects of the Company's Accounting Practices

24. When evaluating whether the financial statements as a whole are free of material misstatement, the auditor should evaluate the qualitative aspects of the company's accounting practices, including potential bias in management's judgments about the amounts and disclosures in the financial statements.

25. The following are examples of forms of management bias:

a. The selective correction of misstatements brought to management's attention during the audit (e.g., correcting misstatements that have the effect of increasing reported earnings but not correcting misstatements that have the effect of decreasing reported earnings).

Note: To evaluate the potential effect of selective correction of misstatements, the auditor should obtain an understanding of the reasons that management decided not to correct misstatements communicated by the auditor in accordance with paragraph 15.

b. The identification by management of additional adjusting entries that offset misstatements accumulated by the auditor. If such adjusting entries are identified, the auditor should perform procedures to determine why the underlying misstatements were not identified previously and evaluate the implications on the integrity of management and the auditor's risk assessments, including fraud risk assessments. The auditor also should perform additional procedures as necessary to address the risk of further undetected misstatement.

c. Bias in the selection and application of accounting principles.

121

121

Paragraph 5.d. of Auditing Standard No. 13,

The Auditor's Responses to the Risks of Material Misstatement.

d. Bias in accounting estimates.

122

122

Paragraph 27 of this standard.

26. If the auditor identifies bias in management's judgments about the amounts and disclosures in the financial statements, the auditor should evaluate whether the effect of that bias, together with the effect of uncorrected misstatements, results in material misstatement of the financial statements. Also, the auditor should evaluate whether the auditor's risk assessments, including, in particular, the assessment of fraud risks, and the related audit responses remain appropriate.

27.

Evaluating Bias in Accounting Estimates.

The auditor should evaluate whether the difference between estimates best supported by the audit evidence and estimates included in the financial statements, which are individually reasonable, indicate a possible bias on the part of the company's management. If each accounting estimate included in the financial statements was individually reasonable but the effect of the difference between each estimate and the estimate best supported by the audit evidence was to increase earnings or loss, the auditor should evaluate whether these circumstances indicate potential management bias in the estimates. Bias also can result from the cumulative effect of changes in multiple accounting estimates. If the estimates in the financial statements are grouped at one end of the range of reasonable estimates in the prior year and are grouped at the other end of the range of reasonable estimates in the current year, the auditor should evaluate whether management is using swings in estimates to achieve an expected or desired outcome, e.g., to offset higher or lower than expected earnings.

Note: AU secs. 316.64-.65 establish requirements regarding performing a retrospective review of accounting estimates and evaluating the potential for fraud risks.

Evaluating Conditions Relating to the Assessment of Fraud Risks

28. When evaluating the results of the audit, the auditor should evaluate whether the accumulated results of auditing procedures

123

and other observations affect the assessment of the fraud risks made throughout the audit and whether the audit procedures need to be modified to respond to those risks. (See Appendix C.)

123

Such auditing procedures include, but are not limited to, procedures in the overall review (paragraph 9 of this standard), the evaluation of identified misstatements (paragraphs 20-23 of this standard), and the evaluation of the qualitative aspects of the company's accounting practices (paragraphs 24-27 of this standard).

29. As part of this evaluation, the engagement partner should determine whether there has been appropriate communication with the other engagement team members throughout the audit regarding information or conditions that are indicative of fraud risks.

Note: To accomplish this communication, the engagement partner might arrange another discussion among the engagement team members about fraud risks. (See paragraphs 49-51 of Auditing Standard No. 12.)

Evaluating the Presentation of the Financial Statements, Including the Disclosures

30. The auditor must evaluate whether the financial statements are presented fairly, in all material respects, in conformity with the applicable financial reporting framework.

Note: AU sec. 411,

The Meaning of Present Fairly in Conformity With Generally Accepted Accounting Principles,

establishes requirements for evaluating the presentation of the financial statements. Auditing Standard No. 6,

Evaluating Consistency of Financial Statements,

establishes requirements regarding evaluating the consistency of the accounting principles used in financial statements.

Note: The auditor should look to the requirements of the Securities and Exchange Commission for the company under audit with respect to the accounting principles applicable to that company.

31. As part of the evaluation of the presentation of the financial statements, the auditor should evaluate whether the financial statements contain the information essential for a fair presentation of the financial statements in conformity with the applicable financial reporting framework. Evaluation of the information disclosed in the financial statements includes consideration of the form, arrangement, and content of the financial statements (including the accompanying notes), encompassing matters such as the terminology used, the amount of detail given, the classification of items in the statements, and the bases of amounts set forth.

Note: According to AU sec. 508, if the financial statements, including the accompanying notes, fail to disclose information that is required by the applicable financial reporting framework, the auditor should express a qualified or adverse opinion and should provide the information in the report, if practicable, unless its omission from the report is recognized as appropriate by a specific auditing standard.

124

124

AU secs. 508.41-.44.

Evaluating the Sufficiency and Appropriateness of Audit Evidence

32. Auditing Standard No. 8,

Audit Risk,

states:

To form an appropriate basis for expressing an opinion on the financial statements, the auditor must plan and perform the audit to obtain reasonable assurance about whether the financial statements are free of material misstatement due to error or fraud. Reasonable assurance is obtained by reducing audit risk to an appropriately low level through applying due professional care, including obtaining sufficient appropriate audit evidence.

125

125

Paragraph 3 of Auditing Standard No. 8.

33. As part of evaluating audit results, the auditor must conclude on whether sufficient appropriate audit evidence has been obtained to support his or her opinion on the financial statements.

34. Factors that are relevant to the conclusion on whether sufficient appropriate audit evidence has been obtained include the following:

a. The significance of uncorrected misstatements and the likelihood of their having a material effect, individually or in combination, on the financial statements, considering the possibility of further undetected misstatement (paragraphs 14 and 17-19 of this standard).

b. The results of audit procedures performed in the audit of financial statements, including whether the evidence obtained supports or contradicts management's assertions and whether such audit procedures identified specific instances of fraud (paragraphs 20-23 and 28-29 of this standard).

c. The auditor's risk assessments (paragraph 36 of this standard).

d. The results of audit procedures performed in the audit of internal control over financial reporting, if the audit is an integrated audit.

e. The appropriateness (i.e., the relevance and reliability) of the audit evidence obtained.

126

126

Paragraphs 7-9 of Auditing Standard No. 15,

Audit Evidence,

discuss the relevance and reliability of audit evidence.

35. If the auditor has not obtained sufficient appropriate audit evidence about a relevant assertion or has substantial doubt about a relevant assertion, the auditor should perform procedures to obtain further audit evidence to address the matter. If the auditor is unable to obtain sufficient appropriate audit evidence to have a reasonable basis to conclude about whether the financial statements as a whole are free of material misstatement, AU sec. 508 indicates that the auditor should express a qualified opinion or a disclaimer of opinion.

127

127

AU sec. 508.22-.34 contains requirements regarding audit scope limitations.

36.

Evaluating the Appropriateness of Risk Assessments.

As part of the evaluation of whether sufficient appropriate audit evidence has been obtained, the auditor should evaluate whether the assessments of the risks of material misstatement at the assertion level remain appropriate and whether the audit procedures need to be modified or additional procedures need to be performed as a result of any changes in the risk assessments. For example, the re-evaluation of the auditor's risk assessments could result in the identification of relevant assertions or significant risks that were not identified previously and for which the auditor should perform additional audit procedures.

Note: Auditing Standard No. 12 establishes requirements on revising the auditor's risk assessment.

128

Auditing Standard No. 13 discusses the auditor's responsibilities regarding the assessment of control risk and evaluation of control deficiencies in an audit of financial statements.

129

128

Paragraph 74 of Auditing Standard No. 12.

129

Paragraphs 32-34 of Auditing Standard No. 13.

Evaluating the Results of the Audit of Internal Control Over Financial Reporting

37. Auditing Standard No. 5,

An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements,

indicates

that the auditor should form an opinion on the effectiveness of internal control over financial reporting by evaluating evidence obtained from all sources, including the auditor's testing of controls, misstatements detected during the financial statement audit, and any identified control deficiencies. Auditing Standard No. 5 describes the auditor's responsibilities regarding evaluating the results of the audit, including evaluating the identified control deficiencies.

130

130

Paragraphs 62-70 of Auditing Standard No. 5 discuss evaluating identified control deficiencies, and paragraphs 71-73 of Auditing Standard No. 5 discuss forming an opinion on the effectiveness of internal control over financial reporting.

APPENDIX A—Definitions

A1. For purposes of this standard, the terms listed be

This text is long and has been trimmed here. Open the source document for the complete record.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.