CA Intermediate · Auditing and Ethics
Risk Assessment and Internal Control: formula sheet
Key formulas
- Overall audit strategy
- Overall audit strategy = scope + timing + direction of the audit
- It sets the framework and guides the detailed audit plan. It is generally established first, but the two are closely inter-related.
- Audit plan
- Audit plan = risk assessment procedures + further audit procedures + other procedures required by SAs
- For each, state nature, timing and extent. Plan is more detailed than strategy.
- Strategy contents (SA 300, para 8)
- (a) Characteristics of the engagement that define its scope; (b) reporting objectives, timing of the audit and nature of communications; (c) significant factors that determine the direction of the team's efforts, including, as applicable, determining appropriate materiality and preliminary identification of areas of higher risk of material misstatement, preliminary activities and knowledge gained on other engagements; (d) nature, timing and extent of resources
- Use these four heads from SA 300 para 8 to organise any 'contents of overall audit strategy' answer.
- Documentation under SA 300
- Document: overall audit strategy, audit plan, significant changes made during the audit and reasons
- Missing this point loses easy marks.
- Nature of planning
- Planning = continual and iterative process
- It is not a discrete phase after the engagement is accepted.
- Audit risk model
- Audit Risk = Risk of Material Misstatement × Detection Risk
- This is a conceptual relationship, not a calculation tool. RMM is made up of inherent risk and control risk.
- Components of RMM
- RMM = Inherent Risk and Control Risk
- SA 315 (Revised 2019) requires separate assessment of inherent risk and control risk at the assertion level.
- Risk assessment procedures
- Inquiries + Analytical procedures + Observation and inspection
- Remember all three. Inquiry alone is not enough. These procedures do not by themselves give sufficient evidence for the opinion.
- Relationship of risk to detection risk
- Higher RMM → Lower acceptable detection risk → More extensive substantive work
- Detection risk is inversely related to assessed RMM.
- Audit risk model
- Audit risk = Risk of material misstatement × Detection risk
- RMM = Inherent risk × Control risk. It is a conceptual relationship, not a precise calculation in the exam.
- Risk of material misstatement
- RMM = Inherent risk × Control risk
- Both exist independently of the audit. The auditor assesses them but cannot change them.
- Detection risk relationship
- Higher RMM ⇒ lower acceptable detection risk
- Lower detection risk means more or better substantive procedures.
- Benchmark-based materiality
- Materiality = Benchmark × Chosen percentage
- Percentage is a matter of judgment. SA 320 does not fix a percentage.
- Performance materiality
- Performance materiality < Materiality for the financial statements as a whole
- Set to cover aggregation of uncorrected and undetected misstatements.
- Revision of materiality
- Revise if new information arises during the audit
- If the revised level is lower, reconsider performance materiality and the nature, timing and extent of further procedures.
- Five components of internal control (SA 315)
- Control environment + Entity's risk assessment process + Process to monitor the system of internal control + Information system and communication + Control activities
- Write all five by name, in the order SA 315 (Revised 2019) gives them.
- Objectives of internal control
- Reliable financial reporting + Effective and efficient operations + Compliance with laws and regulations
- Safeguarding of assets is usually discussed under operations.
- Level of assurance
- Internal control gives reasonable assurance, not absolute assurance
- Reason: inherent limitations such as human error, collusion, management override and cost-benefit.
- Responsibility
- Design, implementation and maintenance of internal control = management and those charged with governance; understanding and evaluating it for audit = auditor
- Use this line to answer questions on who is responsible.
- Auditor's duty on IFC
- Section 143(3)(i): report whether adequate IFC with reference to financial statements exist AND whether they operate effectively
- Both limbs must appear in your answer: adequacy and operating effectiveness. The duty applies to all companies, subject to exemptions. The report is given in a separate Annexure to the auditor's report.
- Directors' responsibility
- Section 134(5)(e): directors of a listed company lay down IFC and ensure they are adequate and operating effectively. Section 134(3)(q) read with Rule 8(5)(viii) of the Companies (Accounts) Rules, 2014: the Board's report of every company states the adequacy of IFC
- Responsibility for IFC is management's. The auditor only reports.
- Tests of controls vs substantive procedures
- Tests of controls → whether controls operated effectively. Substantive procedures → whether amounts and disclosures are misstated (tests of details + substantive analytical procedures)
- Results of tests of controls decide how much substantive testing you need.
- Walkthrough
- Walkthrough = trace one transaction end to end using inquiry, observation and inspection
- Confirms understanding and design. It does not alone prove operating effectiveness.
- ICQ versus ICE
- ICQ = questions asking whether specific controls exist (Yes/No/N/A); ICE = questions asking whether control objectives are met, i.e. whether an error or fraud could occur and go undetected given the controls in place
- Tell them apart by the type of question: ICQ asks "Is there a control?", ICE asks "Could this error or fraud happen undetected?". ICQ is often answered by client staff and reviewed by the auditor, but do not treat this as a rule.
- Reading an ICQ
- Yes = control present; No = possible weakness; N/A = question not relevant
- Every "No" should be followed up and its effect on audit procedures considered.
- Purpose of a flowchart
- Flowchart = graphic record of the flow of documents and activities in a process
- It helps spot gaps, duplication and missing checks.
- SA 230 objective
- Documentation must let an experienced auditor with no previous connection understand the work done, the evidence and the conclusions
- This is the test of sufficiency of documentation.
- Matters SA 230 expects to be recorded
- Nature, timing and extent of procedures + who performed and when + who reviewed and when + results and conclusions
- Also record significant matters, judgments and discussions with management.
Quick revision
- The overall audit strategy sets scope, timing and direction; the audit plan details the procedures to carry out.
- Planning is a continuous process and not a single early step. Revise the plan when circumstances change.
- Risk assessment procedures include inquiries, analytical procedures, and observation and inspection.
- Audit risk = risk of material misstatement × detection risk, and risk of material misstatement combines inherent risk and control risk.
- The auditor cannot influence the entity's inherent and control risk, only assess them, and then sets detection risk through the nature, timing and extent of procedures.
- Higher assessed risk means more extensive and more reliable substantive procedures.
- Materiality is a matter of professional judgment and depends on both size and nature of the item.
- Performance materiality is set below overall materiality to reduce the chance that uncorrected errors add up to a material amount.
- Internal control has five components: control environment, entity's risk assessment process, information system and communication, control activities, and monitoring of controls.
- Internal control has inherent limitations, such as human error, collusion, management override and cost-benefit considerations.
- A walkthrough test follows one transaction from start to finish through the process to confirm understanding of the controls.
- Section 143(3)(i) of the Companies Act, 2013 requires the auditor's report to state whether the company has an adequate internal financial controls system with reference to financial statements and whether it operates effectively. Certain private companies (one-person companies, small companies, and specified low-turnover, low-borrowing private companies) are exempt from this reporting by MCA notification.
- Documentation should be enough for an experienced auditor with no prior link to the audit to understand the work done and the conclusions reached.
Common mistakes
- Treating overall audit strategy and audit plan as the same thing. Fix: Say strategy sets scope, timing and direction. Say plan details the nature, timing and extent of procedures. Keep them in separate paragraphs.
- Saying planning is done only at the start of the audit. Fix: Write that planning is continual and iterative, and the strategy and plan are updated as the audit proceeds.
- Saying inquiry is enough to understand the entity. Fix: Always list all three: inquiries, analytical procedures, observation and inspection. Add that inquiry alone is not sufficient.
- Treating detection risk as a risk of the entity. Fix: Inherent and control risk exist independently of the audit. Detection risk depends on the auditor's procedures and can be changed by the auditor.
- Saying the auditor can reduce inherent or control risk. Fix: Remember that inherent and control risk exist in the entity. The auditor only assesses them and responds through detection risk.
- Treating audit risk and materiality as the same thing. Fix: Materiality is the size threshold. Audit risk is the chance of giving a wrong opinion. Say this in one line when asked for the difference.
- Using the component names from the earlier version of SA 315 in an answer written under SA 315 (Revised 2019). Fix: The earlier version used names such as 'information system, including related business processes, relevant to financial reporting, and communication', 'control activities relevant to the audit' and 'monitoring of controls'. The revised SA 315 uses 'information system and communication', 'control activities' and 'process to monitor the system of internal control'. The entity's risk assessment process kept the same name in both versions. Write the revised names.
- Saying internal control gives absolute assurance or prevents all fraud. Fix: Always write reasonable assurance and add that inherent limitations stop it from being absolute.
- Saying the auditor is responsible for designing and maintaining IFC. Fix: Write: directors of a listed company lay down and maintain IFC (Section 134(5)(e)), and the Board's report of every company covers the adequacy of IFC (Rule 8(5)(viii)); the auditor evaluates and reports under Section 143(3)(i).
- Writing only about adequacy and forgetting operating effectiveness. Fix: Always give both limbs, and explain the difference with a one-line example.
Exam tips
- Short notes on SA 300 are common. Open with the objective, then give contents under heads, then close with documentation.
- For difference questions, give at least four clear points and keep both sides parallel.
- In case-based questions, name the fact from the scenario and say whether it affects strategy, plan or both.
- In MCQs, treat words like 'only', 'never' or 'one-time' about planning with caution. Check the option against SA 300 (planning is continual and iterative) instead of rejecting it automatically.
- Link planning to risk in every answer, because it shows you understand why the auditor plans.
- Write the three procedures by name every time. Examiners look for the list.
- In case-based questions, split the risk into inherent and control risk, then link it to the response. This structure earns step marks.
- Be sure of who owns each risk: detection risk is the auditor's. MCQs often test this.