Auditing: A Risk Based Approach to Conducting a Quality Audit, 10e
Solutions for Chapter 5
True/False Questions
5-1 T
5-2 F
5-4 T
5-6 T
5-8 T
5-10 T
5-12 T
5-14 T
5-16 T
5-18 F
5-20 F
5-22 T
5-24 F
Multiple-Choice Questions
5-25 E
5-26 A
5-28 B
5-30 B
5-32 A
5-34 D
5-36 A
5-2
5-37 D
5-39 A
5-41 A
5-43 A
5-45 A
5-47 B
5-48 B
Review and Short Case Questions
5-49
a. The American Institute of CPAs (AICPA) develops auditing standards that are used by
auditors for their non-public clients. The standards of the AICPA are very similar to the
standards of the IAASB.
5-50
a. On the “pro” side, having the same standards makes audits more comparable for the
public and the auditors. Nobody has to go through the trouble of reconciling differences
in audits. Further, having the same standards would allow audit firms the opportunity to
5-3
5-51
The Ten Standards
Holmes’ Failure to Comply with “The Ten
Standards”
General Standards:
Technical Training and proficiency
as an auditor
The college students did not have the proper training
and proficiency and were not properly supervised.
Independence
Holmes lacked independence because of the financial
interest in whether the bank loan is granted to Ray.
Due professional care
Holmes failed to follow the fieldwork and reporting
standards as a reasonably prudent auditor would have
done. He did not critically review the work done or the
judgments of the assistants.
Holmes accepted the engagement without first
considering the availability of qualified staff. He also
failed to supervise the assistants and plan the work
adequately.
Understanding internal control
Holmes and the assistants did not obtain an
understanding of the client’s internal controls.
Sufficient appropriate evidence
Holmes gathered no evidence to corroborate the
information in the financial statements. The work
performed was more an accounting service than an
audit service.
Reporting standards:
Adherence to applicable financial
The report made no reference to GAAP. Because
Holmes did not do a proper audit, no opinion should
which such principles have not
been consistently observed
Holmes was not in a position to determine whether the
accounting principles had been consistently observed
due to the lack of evidence.
significant accounting policies should be described.
report did not mention this.
5-4
The Ten Standards
Holmes’ Failure to Comply with “The Ten
Standards”
Opinion
Even though an opinion was expressed, it is not based
5-52
The ten standards used by the PCAOB have historically provided the foundation for the financial
statement audit. These standards are stated as unconditional requirements. The AICPA’s
5-53
An important implication of Exhibit 5.2 is that the quality of internal control, which is the
responsibility of the client, affects the reliability of the client’s financial statement data. The
client is responsible the organization’s internal controls and for the preparation of the financial
5-54
PHASE OF THE AUDIT OPINION
FORMULATION PROCESS
ACTIVITIES WITHIN THE PHASE
Phase I Making Client Acceptance and
Continuance Decisions
Assess whether management uses an
acceptable financial reporting
framework
Respond to identified risks of material
misstatement
issue
5-55
a. The primary activities that affect the revenue cycle include:
Order taking, shipment, and billing of goods
Sales returns and allowances
Warranty claims
Collection of receivables
5-56
Revenue: accounts include sales, sales returns and allowances, sales discounts, account
receivable, allowance for uncollectible accounts, warranty liabilities and expenses, bad
debt expense, sales commission expense, cash
5-6
5-57
Existence: Assertions about existence address whether assets and liabilities exist. For
accounts receivable, management asserts that the recorded accounts receivable exist at the
balance sheet date and relate to valid sales.
Completeness: Assertions about completeness address whether all transactions and accounts
that should be included in the financial statements are included. For accounts receivable,
5-58
Audit programs list the audit procedures that the auditor performs in an audit. The standards
5-59
An audit program details the audit procedures to be completed before providing the audit
opinion(s). The information that the auditor needs prior to developing the audit program is
information obtained during Phases I and II of the audit opinion formulation process and would
include:
The client’s business and the industry within which it operates
Business risks the company faces and determining how those risks might affect the
5-7
The quality of the design of the client’s internal controls over financial reporting
Management’s approach to assessing internal control over financial reporting and
whether management has sufficient documentation of the design and operation of internal
5-60
Audit documentation is the record of audit procedures performed, relevant audit evidence
obtained, and conclusions the auditor reached (terms such as working papers or workpapers are
also sometimes used).
Examples of audit documentation include:
Audit programs
5-61
Management’s use of an acceptable financial reporting framework. Without an acceptable
financial reporting framework, management does not have an appropriate basis for the
5-8
5-62
Exhibit 5.7 illustrates examples of sources of risk of material misstatement that the auditor may
5-63
The PCAOB has identified the following as controls related to fraud risk:
Controls over significant, unusual transactions, particularly those that result in late or
unusual journal entries;
Controls over journal entries and adjustments made in the period-end financial reporting
process;
5-64
The auditor’s documentation should clearly identify each important internal control and the
5-65
Based on obtaining an understanding through risk assessment procedures, the auditor assesses
control risk ranging from high (weak controls) to low (strong controls). Assessing control risk as
5-9
5-66
Once the risk of material misstatement has been assessed, the auditor needs to determine how to
respond to the identified risks. Accounts, disclosures, and assertions that have a higher level of
identified risk of material misstatement would require larger boxes of evidence. Consider the
three boxes in Panel A of Exhibit 5.8. An assertion with a low risk of material misstatement
5-67
(a) Risk
(b) Controls to
Mitigate the Risk
(c ) Evidence that
Control is
Operating
Effectively (Test of
Control)
(1) Individual could
take cash and could
cover up the cash
(1) Management
could perform period
reviews of accounts
(1) The auditor could
review management
analyses of accounts
5-10
(a) Risk
(b) Controls to
Mitigate the Risk
(c ) Evidence that
Control is
Operating
Effectively (Test of
Control)
(2) The individual
could also take cash,
but record it, and
(2) There are no
compensating
controls for this.
was getting accurate
reports of the write-
offs.
or bad debt expense.
(1) Individual bills
the customer and
takes the cash
This is difficult to
control because
management would
No tests because the
potential mitigating
control is not
There is no unusual
risk here.
Controls are
sufficient.
No additional tests of
controls.
This is not an
unusual situation for
Management review
of all significant
The auditor could test
to determine if there
5-11
(a) Risk
(b) Controls to
Mitigate the Risk
(c ) Evidence that
Control is
Operating
Effectively (Test of
Control)
entries or accounting
estimates may be
made without
economic substance,
or may be in error.
review. However,
management is not
always aware of the
closing entries, nor
reviews it in detail.
The risk is that this
person does
everything and there
is no segregation of
duties.
detracts from
management
However, as noted in
the previous column
Management review
all the transactions
and acts as an
additional control.
The problem with
this control is that it
The auditor could
examine evidence
that management
thoroughly reviews
all transactions,
reperforms bank
reconciliations, etc.
The individual could
change the software
to have inventory
sent to him, or to
Software controls
that would not allow
access to changing
the software.
Auditor would have
to have evidence that
the software could
not be changed.
(a) Risk
(b) Controls to
Mitigate the Risk
(c ) Evidence that
Control is
Operating
Effectively (Test of
Control)
5-68
The auditor selects controls that are most important to the organization’s ability to adequately
address the risk of material misstatement. The controls need to be well designed and
implemented. The auditor selects both entity-wide and transaction controls for testing. The
5-69
The answer to the question depends on the specific controls that a client has in place. The
solution is based on what might be considered controls that are typically found in the sales cycle.
Examples include:
Preauthorized sales prices are entered into the computer pricing table by authorized
individuals.
management, internal audit, or other parties performing control analysis.
5-70
The auditor seeks information on the organization’s control environment because the control
environment is pervasive. The attitude of those at the top, and their approaches to creating an
environment that facilitates overall control, provides the framework in which all the other
5-13
5-71
a. Testing the operating effectiveness of controls is accomplished through tests of controls.
This typically requires the auditor to take a sample of transactions to determine if
evidence exists that the control is operating as it is designed to operate – and thus is
effective in mitigating the risk of material misstatement.
5-72
The auditor can test commitment to integrity and ethical values (COSO Principle 1) through
first-hand knowledge of the client’s attitude toward “pushing the accounting boundaries.”
Additional approaches the auditor might utilize include:
Read and analyze the code of ethics for completeness and tone.
Inquire as to the process to report violations of the code (whistleblower function) and
whether there are demonstrated activities to follow up on reported violations by the audit
5-14
5-73
On integrated audits the auditor will test and report on the effectiveness of internal controls over
financial reporting as of the client’s year end. When the auditor is issuing an opinion on internal
control, the PCAOB has mandated that the external auditor must test operating effectiveness of
5-74
On all audits, auditors must gain an understanding of the design of internal controls in order to
plan the audit. Requirements for testing the operating effectiveness of the controls vary
depending on whether the client is a larger public company or other type or organization.
a.
Larger publicly held companies:
Auditors of larger public companies must attest to the effectiveness of the client’s internal
controls over financial reporting as of the client’s year end. In performing an audit of internal
control, the auditor will:
Assess the design effectiveness and implementation of controls
Review the client’s testing of the operating effectiveness of controls as a basis for
b.
5-75
If the authorization control is not working effectively, there could be (a) unauthorized purchases
of goods that were never delivered to the company, i.e., fictitious purchases, (b) goods could be
of inferior quality, or (c) goods could be acquired at a higher than usual (or market) price. These
could all result in an overstatement of inventory.
In this setting the auditor will not be able to rely on controls and should expand the substantive
audit procedures related to inventory through:
5-76
a. If control deficiencies are identified, assess those deficiencies to determine whether the
preliminary control risk assessment should be modified (should control risk be increased
from low to high?) and document the implications for substantive procedures (should the
substantive procedures be modified?).
5-16
5-77
Control
a. Test of Control
b. Modification of Substantive Audit
Procedures if Control Not Effective
(1) Credit
Approval
(a) Randomly select new orders and determine if credit
process is working as described.
(b) Obtain a computer print-out of all accounts with a past
Accounts receivable valuation is likely to
be affected since sales would be made to
customers that do not meet the client’s
credit standards. The auditor would expand
(2) Pre-
numbered
(a) Review procedures utilized by client to account for pre-
numbered receiving slips. Test their process for accuracy.
There will be concern that all receipts
were properly recorded. The auditor
5-17
Control
a. Test of Control
b. Modification of Substantive Audit
Procedures if Control Not Effective
Document.
documents or initials of the person performing the matching).
inventory.
(3) Payments
Require
(a) Take a sample of vendor payments to determine that all
such payments are accompanied by a receiving slip, purchase
The auditor would be concerned with
the payment for fictitious goods and
Allowed by
Bookkeeper.
adjustment, and so forth). Determine that the accounts
support exists for credit memos issued.
(4) Credit
Memos Not
Take a sample of credit memos and examine for existence of
proper support (receipt of returned goods, customer
The auditor would expand the credit
memo test to determine that proper
(5) Cash
Receipts and
Select a sample of day’s remittances and reconcile deposit
slip with remittance advices sent to accounts receivable.
Expand sample of remittances to ensure
that all remittances are recorded on a
File.
personnel department.
personnel department records.
(6) Adding
Generate a listing of employees added to the master file.
Expand payroll tests to examine for the
(7) Password
Protection of
Review policies for adding/deleting or changing passwords
with the data processing function responsible for password
Review print-outs of changes made to
payroll file and trace to authorization.
5-18
Control
a. Test of Control
b. Modification of Substantive Audit
Procedures if Control Not Effective
Attempt to access the files using common passwords.
Interview payroll personnel regarding password protection.
(8) Edit Limit
Tests.
hours or more than 3 jobs.
Submit data to the computer application to determine if the
edit tests would reject the items submitted if the items are
beyond the limits.
Review edit reports generated by computer application to
determine disposition of employees working more than 53
Expand payroll tests as per above.
(9) Issuance of
Examine credit memos for proper approval noting attachment
Expand credit memo testing to
more than 6%
of customer
purchases.
Review all credit memos in excess of a specific dollar limit to
determine if divisional management approval is required, and
if so, whether it was obtained.
adjustments affects the validity of
recorded sales or receivables.
(10) Approval
of price
Discuss with divisional manager the process for implementing
the control.
Review for large adjustments to
customers for possible kick-backs to