SlideShare uma empresa Scribd logo
1 de 17
Atta-ur-Rahman Arif
Audit Risk Model
• AR = IR x CR x DR
• AR = Audit risk
– Also referred to as Residual Risk
– The risk that the auditor will incorrectly issue an
unqualified opinion
• IR = Inherent risk
– The risk of material misstatements absent any
internal controls or testing
Audit Risk Model
• CR = Control risk
– The risk that internal controls will fail to prevent
or detect material misstatement
• DR = Detection risk
– The risk that audit tests will fail to detect material
misstatement
• Therefore, audit risk is a function of inherent
risk, unchecked by controls and not detected
by the auditor
Risk Components
• Inherent risk
– Higher in complex transactions
– Higher where items are more naturally prone to
fraud
– Based in part on prior experience
– Industry and management pressures
• Inherent risk cannot be changed by the
auditor
Control Risk
• Part of Audit Risk Model
• Depends on the design and execution of controls
• Audit Risk = risk that internal controls will FAIL to prevent or
detect misstatement
– High CR means high risk controls will fail
– Low CR means low risk controls will fail
• If CR is high, auditor will not rely much on controls
• If CR is low, auditor can rely on ICS and reduce other types of
testing
Is Risk Quantifiable?
• Yes and No
• Often assessed in percentage terms
• Requires judgment because no number is out
there to be measured
• Detection risk needs to be quantified for
statistical testing
Interrelationship of Risks
• IF IR and CR are high,
then
• If IR is high and CR is
low
• If IR is low and CR is low
• If IR is low but CR is
high
• DR should be low (lots
of testing)
• DR can be higher,
because controls offset
high IR
• DR can be high
• Somewhat indicative of
fraud. DR should be
very low
What is Acceptable Audit Risk?
Risk the auditor is willing to take of being wrong
Generally considered in terms of unqualified
where there are misstatements, but not in
reverse
Depends on engagement risk
› Financial stability
› Industry factors
› Management integrity
Degree of reliance on audited statements
Keep Things Open
• Control risk assessment must be backed up by
control testing results
• If tests show weaker controls, CR is higher,
thus DR needs to be lower
Internal Control Objectives
• Reliability of financial statements
• Efficiency and effectiveness of operations
• Compliance with laws and regulations
• Safeguarding of assets
Underlying Limitations
• Reasonable assurance
• Cost-benefit
• Inherent limitations
– collusion
Design of ICS
• Preventing material misstatements
• Detecting material misstatements
• Preventing misappropriation
• Detecting misappropriation
• SarbOx: Management must assess and report
on design
– How are transaction initiated, authorized,
recorded, processed, and reported?
– Are there any weaknesses?
Management’s Report on ICS
• Must describe design
• Must make assertions about effectiveness
• Must report material weaknesses
• A single weakness prevents claim that ICS is
operating effectively
• Must be able to document basis for report
• Auditor will provide an opinion on the report
• Any weaknesses mean that auditor’s report will
be adverse.
Risk Assessment
• Management’s identification of risks
– Economic
– Industry
– Regulatory
– Operating risks
• Analysis and management of risks
• Examples
– Oil companies in the Gulf of Mexico
– Smith Corona
Control Activities
• Policies and procedures to address risks
• Pertains to all four other areas
• Separation of duties
• Proper authorization
• Adequate documents and records
• Physical control over assets and records
• Independent checks
Information and
Communication
• Initiates, records, processes, and reports
• Transaction cycles
• Subsidiaries and controls
• Think of PERCV
Monitoring
• Need to ensure controls are working
• Monitoring now more pressing because of
SarbOx
• Control needs change
• Personnel change
• Organizational structure changes

Mais conteúdo relacionado

Mais procurados

audit sampling notes
audit sampling notesaudit sampling notes
audit sampling notes
student
 
Chapter audit report
Chapter audit reportChapter audit report
Chapter audit report
EasyStudy3
 
Financial Reporting
Financial ReportingFinancial Reporting
Financial Reporting
Qasim Raza
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management Framework
Treasury Consulting LLP
 

Mais procurados (20)

Internal controls
Internal controlsInternal controls
Internal controls
 
AUDIT REPORT [ AUDITING ]
AUDIT REPORT [ AUDITING ]AUDIT REPORT [ AUDITING ]
AUDIT REPORT [ AUDITING ]
 
Audit procedures
Audit proceduresAudit procedures
Audit procedures
 
audit sampling notes
audit sampling notesaudit sampling notes
audit sampling notes
 
Audit
AuditAudit
Audit
 
Audit Risk Assessment Chapter 9
Audit Risk Assessment Chapter 9Audit Risk Assessment Chapter 9
Audit Risk Assessment Chapter 9
 
Chapter audit report
Chapter audit reportChapter audit report
Chapter audit report
 
Financial Reporting
Financial ReportingFinancial Reporting
Financial Reporting
 
Audit risk model
Audit risk modelAudit risk model
Audit risk model
 
Ch 02. Obtaining an Engagement
Ch 02. Obtaining an Engagement Ch 02. Obtaining an Engagement
Ch 02. Obtaining an Engagement
 
International Auditing Standards (ISA)
International Auditing Standards (ISA)International Auditing Standards (ISA)
International Auditing Standards (ISA)
 
STANDARDS ON AUDITING
STANDARDS ON AUDITINGSTANDARDS ON AUDITING
STANDARDS ON AUDITING
 
Standards of Internal Audit
Standards of Internal AuditStandards of Internal Audit
Standards of Internal Audit
 
Chapter 6
Chapter 6Chapter 6
Chapter 6
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management Framework
 
Conceptual Framework in Accounting
Conceptual Framework in AccountingConceptual Framework in Accounting
Conceptual Framework in Accounting
 
INTERNATIONAL AUDITING STANDARDS -PPT.pptx
INTERNATIONAL AUDITING STANDARDS -PPT.pptxINTERNATIONAL AUDITING STANDARDS -PPT.pptx
INTERNATIONAL AUDITING STANDARDS -PPT.pptx
 
AUDIT EVIDENCE-PPT.pptx
AUDIT EVIDENCE-PPT.pptxAUDIT EVIDENCE-PPT.pptx
AUDIT EVIDENCE-PPT.pptx
 
Auditing In Computer Environment Presentation
Auditing In Computer Environment PresentationAuditing In Computer Environment Presentation
Auditing In Computer Environment Presentation
 
Unit 1 Introduction to Audit
Unit 1   Introduction to AuditUnit 1   Introduction to Audit
Unit 1 Introduction to Audit
 

Destaque

Audit planning and risk assessment
Audit planning and risk assessmentAudit planning and risk assessment
Audit planning and risk assessment
casahiljain1992
 
Case 3_pp_final_v2 gr3
Case  3_pp_final_v2 gr3Case  3_pp_final_v2 gr3
Case 3_pp_final_v2 gr3
malenacharur
 
Arens12e 09
Arens12e 09Arens12e 09
Arens12e 09
John Sy
 
For model i 4a - 11 - risk assessment in the internal audit department
For model  i   4a - 11 - risk assessment in the internal audit departmentFor model  i   4a - 11 - risk assessment in the internal audit department
For model i 4a - 11 - risk assessment in the internal audit department
Rajeswaran Muthu Venkatachalam
 
Proposal risk based internal audit 2013
Proposal risk based internal audit 2013Proposal risk based internal audit 2013
Proposal risk based internal audit 2013
Nidhi Gupta
 
Risk Assessment For Internal Auditors
Risk Assessment For Internal AuditorsRisk Assessment For Internal Auditors
Risk Assessment For Internal Auditors
minkhollow
 

Destaque (20)

DPA 3043(AUDITING)-CHAPTER 6:Materiality and Risk
DPA 3043(AUDITING)-CHAPTER 6:Materiality and RiskDPA 3043(AUDITING)-CHAPTER 6:Materiality and Risk
DPA 3043(AUDITING)-CHAPTER 6:Materiality and Risk
 
Audit Chapter 7
Audit Chapter 7Audit Chapter 7
Audit Chapter 7
 
Audit planning and risk assessment
Audit planning and risk assessmentAudit planning and risk assessment
Audit planning and risk assessment
 
Audit Materiality & business risks p7
Audit Materiality & business risks p7Audit Materiality & business risks p7
Audit Materiality & business risks p7
 
Case 3_pp_final_v2 gr3
Case  3_pp_final_v2 gr3Case  3_pp_final_v2 gr3
Case 3_pp_final_v2 gr3
 
Arens12e 09
Arens12e 09Arens12e 09
Arens12e 09
 
Risk assessment and internal controls - Internal Audit
Risk assessment and internal controls - Internal AuditRisk assessment and internal controls - Internal Audit
Risk assessment and internal controls - Internal Audit
 
Audit Risk Analysis of the Coca-Cola Company
Audit Risk Analysis of the Coca-Cola CompanyAudit Risk Analysis of the Coca-Cola Company
Audit Risk Analysis of the Coca-Cola Company
 
9. audit evidence
9. audit evidence9. audit evidence
9. audit evidence
 
Audit risk model
Audit risk modelAudit risk model
Audit risk model
 
For model i 4a - 11 - risk assessment in the internal audit department
For model  i   4a - 11 - risk assessment in the internal audit departmentFor model  i   4a - 11 - risk assessment in the internal audit department
For model i 4a - 11 - risk assessment in the internal audit department
 
Proposal risk based internal audit 2013
Proposal risk based internal audit 2013Proposal risk based internal audit 2013
Proposal risk based internal audit 2013
 
Audit Documentation Presentation
Audit Documentation PresentationAudit Documentation Presentation
Audit Documentation Presentation
 
Risk Based Audit Approach
Risk Based Audit ApproachRisk Based Audit Approach
Risk Based Audit Approach
 
Risk Assessment For Internal Auditors
Risk Assessment For Internal AuditorsRisk Assessment For Internal Auditors
Risk Assessment For Internal Auditors
 
Audit Sampling
Audit SamplingAudit Sampling
Audit Sampling
 
Financial audit
Financial auditFinancial audit
Financial audit
 
Practical approach to Risk Based Internal Audit
Practical approach to Risk Based Internal AuditPractical approach to Risk Based Internal Audit
Practical approach to Risk Based Internal Audit
 
Coca cola brand audit
Coca cola brand auditCoca cola brand audit
Coca cola brand audit
 
Coca-Cola Financial Analysis
Coca-Cola Financial AnalysisCoca-Cola Financial Analysis
Coca-Cola Financial Analysis
 

Semelhante a 11. materiality and audit risk

0210-RISK-BASED-AUDIT-APPROACH-new-20211020142926.ppt
0210-RISK-BASED-AUDIT-APPROACH-new-20211020142926.ppt0210-RISK-BASED-AUDIT-APPROACH-new-20211020142926.ppt
0210-RISK-BASED-AUDIT-APPROACH-new-20211020142926.ppt
Siraj332397
 
Chapter 2. audit planning procedures & documentation
Chapter 2. audit planning procedures & documentationChapter 2. audit planning procedures & documentation
Chapter 2. audit planning procedures & documentation
Thane
 
Financial transaction control process of suzlon
Financial transaction control process of suzlonFinancial transaction control process of suzlon
Financial transaction control process of suzlon
Pratima Patir
 

Semelhante a 11. materiality and audit risk (20)

Audit Risk and Fraud
Audit Risk and FraudAudit Risk and Fraud
Audit Risk and Fraud
 
0210-RISK-BASED-AUDIT-APPROACH-new-20211020142926.ppt
0210-RISK-BASED-AUDIT-APPROACH-new-20211020142926.ppt0210-RISK-BASED-AUDIT-APPROACH-new-20211020142926.ppt
0210-RISK-BASED-AUDIT-APPROACH-new-20211020142926.ppt
 
CNIT 160 Ch 4b: Security Program Management
CNIT 160 Ch 4b: Security Program ManagementCNIT 160 Ch 4b: Security Program Management
CNIT 160 Ch 4b: Security Program Management
 
CNIT 160 Ch 4b: Security Program Management
CNIT 160 Ch 4b: Security Program ManagementCNIT 160 Ch 4b: Security Program Management
CNIT 160 Ch 4b: Security Program Management
 
Risk Based Approach to Auditing Financial Statements.pptx
Risk Based Approach to Auditing Financial Statements.pptxRisk Based Approach to Auditing Financial Statements.pptx
Risk Based Approach to Auditing Financial Statements.pptx
 
Audit Risk Presentation.pptx
Audit Risk Presentation.pptxAudit Risk Presentation.pptx
Audit Risk Presentation.pptx
 
CNIT 160 4b: Security Program Management (Part 2)
CNIT 160 4b: Security Program Management (Part 2)CNIT 160 4b: Security Program Management (Part 2)
CNIT 160 4b: Security Program Management (Part 2)
 
McKonly & Asbury Webinar - Fraud Prevention and Detection: Surprise Fraudster...
McKonly & Asbury Webinar - Fraud Prevention and Detection: Surprise Fraudster...McKonly & Asbury Webinar - Fraud Prevention and Detection: Surprise Fraudster...
McKonly & Asbury Webinar - Fraud Prevention and Detection: Surprise Fraudster...
 
Internal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsInternal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality Audits
 
Chapter 2. audit planning procedures & documentation
Chapter 2. audit planning procedures & documentationChapter 2. audit planning procedures & documentation
Chapter 2. audit planning procedures & documentation
 
CISA Training - Chapter 1 - 2016
CISA Training - Chapter 1 - 2016CISA Training - Chapter 1 - 2016
CISA Training - Chapter 1 - 2016
 
Auditing principles and practices, chapter 2
Auditing principles and practices, chapter 2Auditing principles and practices, chapter 2
Auditing principles and practices, chapter 2
 
Risk-Assessment-.pptx
Risk-Assessment-.pptxRisk-Assessment-.pptx
Risk-Assessment-.pptx
 
Risk-Assessment-.pptx
Risk-Assessment-.pptxRisk-Assessment-.pptx
Risk-Assessment-.pptx
 
Financial transaction control process of suzlon
Financial transaction control process of suzlonFinancial transaction control process of suzlon
Financial transaction control process of suzlon
 
Effective Concurrent Audit-2020.pptx
Effective Concurrent Audit-2020.pptxEffective Concurrent Audit-2020.pptx
Effective Concurrent Audit-2020.pptx
 
chapter2-190516054412.pdf
chapter2-190516054412.pdfchapter2-190516054412.pdf
chapter2-190516054412.pdf
 
Conducting an Information Systems Audit
Conducting an Information Systems Audit Conducting an Information Systems Audit
Conducting an Information Systems Audit
 
Understanding and Managing Risks in Management Systems Auditing
Understanding and Managing Risks in Management Systems AuditingUnderstanding and Managing Risks in Management Systems Auditing
Understanding and Managing Risks in Management Systems Auditing
 
summary_of_isa_for_f8-converted-converted.pdf
summary_of_isa_for_f8-converted-converted.pdfsummary_of_isa_for_f8-converted-converted.pdf
summary_of_isa_for_f8-converted-converted.pdf
 

Mais de Syed Osama Rizvi

The nature of experimentation
The nature of experimentationThe nature of experimentation
The nature of experimentation
Syed Osama Rizvi
 

Mais de Syed Osama Rizvi (20)

Project management-130717112230-phpapp02
Project management-130717112230-phpapp02Project management-130717112230-phpapp02
Project management-130717112230-phpapp02
 
15. auditor of limited co.
15. auditor of limited co.15. auditor of limited co.
15. auditor of limited co.
 
14. professional ethics october 2011
14. professional ethics october 201114. professional ethics october 2011
14. professional ethics october 2011
 
13. report
13. report13. report
13. report
 
12. audit completion
12. audit completion12. audit completion
12. audit completion
 
10. verification
10. verification10. verification
10. verification
 
8. internal control new
8. internal control new8. internal control new
8. internal control new
 
7. quality control policies
7. quality control policies7. quality control policies
7. quality control policies
 
7. programme
7. programme7. programme
7. programme
 
6. vouching
6. vouching6. vouching
6. vouching
 
6. audit techniques
6. audit techniques6. audit techniques
6. audit techniques
 
5. documentation sep 2013
5. documentation sep 20135. documentation sep 2013
5. documentation sep 2013
 
4. cotrolloing
4. cotrolloing4. cotrolloing
4. cotrolloing
 
3. planning intro
3. planning intro3. planning intro
3. planning intro
 
3. planning feb 2014
3. planning feb 20143. planning feb 2014
3. planning feb 2014
 
2. engagement letter
2. engagement letter2. engagement letter
2. engagement letter
 
1. introduction
1. introduction1. introduction
1. introduction
 
1. history of audit jan 14
1. history of audit jan 141. history of audit jan 14
1. history of audit jan 14
 
The nature of experimentation
The nature of experimentationThe nature of experimentation
The nature of experimentation
 
Session 1
Session 1Session 1
Session 1
 

Último

The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
heathfieldcps1
 

Último (20)

The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
 
Single or Multiple melodic lines structure
Single or Multiple melodic lines structureSingle or Multiple melodic lines structure
Single or Multiple melodic lines structure
 
Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POS
 
Kodo Millet PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
Kodo Millet  PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...Kodo Millet  PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
Kodo Millet PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
 
How to Add New Custom Addons Path in Odoo 17
How to Add New Custom Addons Path in Odoo 17How to Add New Custom Addons Path in Odoo 17
How to Add New Custom Addons Path in Odoo 17
 
Graduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - EnglishGraduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - English
 
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
 
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdfUGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
 
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
 
Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)
 
Micro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdfMicro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdf
 
Plant propagation: Sexual and Asexual propapagation.pptx
Plant propagation: Sexual and Asexual propapagation.pptxPlant propagation: Sexual and Asexual propapagation.pptx
Plant propagation: Sexual and Asexual propapagation.pptx
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdf
 
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdfUnit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptx
 
General Principles of Intellectual Property: Concepts of Intellectual Proper...
General Principles of Intellectual Property: Concepts of Intellectual  Proper...General Principles of Intellectual Property: Concepts of Intellectual  Proper...
General Principles of Intellectual Property: Concepts of Intellectual Proper...
 
COMMUNICATING NEGATIVE NEWS - APPROACHES .pptx
COMMUNICATING NEGATIVE NEWS - APPROACHES .pptxCOMMUNICATING NEGATIVE NEWS - APPROACHES .pptx
COMMUNICATING NEGATIVE NEWS - APPROACHES .pptx
 
Google Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptxGoogle Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptx
 
Application orientated numerical on hev.ppt
Application orientated numerical on hev.pptApplication orientated numerical on hev.ppt
Application orientated numerical on hev.ppt
 

11. materiality and audit risk

  • 2. Audit Risk Model • AR = IR x CR x DR • AR = Audit risk – Also referred to as Residual Risk – The risk that the auditor will incorrectly issue an unqualified opinion • IR = Inherent risk – The risk of material misstatements absent any internal controls or testing
  • 3. Audit Risk Model • CR = Control risk – The risk that internal controls will fail to prevent or detect material misstatement • DR = Detection risk – The risk that audit tests will fail to detect material misstatement • Therefore, audit risk is a function of inherent risk, unchecked by controls and not detected by the auditor
  • 4. Risk Components • Inherent risk – Higher in complex transactions – Higher where items are more naturally prone to fraud – Based in part on prior experience – Industry and management pressures • Inherent risk cannot be changed by the auditor
  • 5. Control Risk • Part of Audit Risk Model • Depends on the design and execution of controls • Audit Risk = risk that internal controls will FAIL to prevent or detect misstatement – High CR means high risk controls will fail – Low CR means low risk controls will fail • If CR is high, auditor will not rely much on controls • If CR is low, auditor can rely on ICS and reduce other types of testing
  • 6. Is Risk Quantifiable? • Yes and No • Often assessed in percentage terms • Requires judgment because no number is out there to be measured • Detection risk needs to be quantified for statistical testing
  • 7. Interrelationship of Risks • IF IR and CR are high, then • If IR is high and CR is low • If IR is low and CR is low • If IR is low but CR is high • DR should be low (lots of testing) • DR can be higher, because controls offset high IR • DR can be high • Somewhat indicative of fraud. DR should be very low
  • 8. What is Acceptable Audit Risk? Risk the auditor is willing to take of being wrong Generally considered in terms of unqualified where there are misstatements, but not in reverse Depends on engagement risk › Financial stability › Industry factors › Management integrity Degree of reliance on audited statements
  • 9. Keep Things Open • Control risk assessment must be backed up by control testing results • If tests show weaker controls, CR is higher, thus DR needs to be lower
  • 10. Internal Control Objectives • Reliability of financial statements • Efficiency and effectiveness of operations • Compliance with laws and regulations • Safeguarding of assets
  • 11. Underlying Limitations • Reasonable assurance • Cost-benefit • Inherent limitations – collusion
  • 12. Design of ICS • Preventing material misstatements • Detecting material misstatements • Preventing misappropriation • Detecting misappropriation • SarbOx: Management must assess and report on design – How are transaction initiated, authorized, recorded, processed, and reported? – Are there any weaknesses?
  • 13. Management’s Report on ICS • Must describe design • Must make assertions about effectiveness • Must report material weaknesses • A single weakness prevents claim that ICS is operating effectively • Must be able to document basis for report • Auditor will provide an opinion on the report • Any weaknesses mean that auditor’s report will be adverse.
  • 14. Risk Assessment • Management’s identification of risks – Economic – Industry – Regulatory – Operating risks • Analysis and management of risks • Examples – Oil companies in the Gulf of Mexico – Smith Corona
  • 15. Control Activities • Policies and procedures to address risks • Pertains to all four other areas • Separation of duties • Proper authorization • Adequate documents and records • Physical control over assets and records • Independent checks
  • 16. Information and Communication • Initiates, records, processes, and reports • Transaction cycles • Subsidiaries and controls • Think of PERCV
  • 17. Monitoring • Need to ensure controls are working • Monitoring now more pressing because of SarbOx • Control needs change • Personnel change • Organizational structure changes