Skip to content

CA Final · Advanced Auditing, Assurance and Professional Ethics · Digital Auditing & Assurance

A CA firm audits a listed company and also offers a cyber-security consulting service. The firm is asked by the audit client to design and implement the client's new financial-reporting IT system, including its internal controls, and later to audit the financial statements produced by it. Considering the Companies Act, 2013 and the Code of Ethics, what is the correct conclusion?

This is not permitted. The Companies Act, 2013 prohibits an auditor from designing and implementing financial information systems for the audited company, and the Code of Ethics recognises a self-review threat. Using separate partners or comparing fees does not remove a statutory prohibition.

  1. APermitted, provided separate partners handle the design work and the audit
  2. BPermitted, since the design of IT systems is an advisory service that never affects independence
  3. CPermitted only if the fee for design work is lower than the audit fee
  4. DNot permitted, because designing and implementing financial information technology systems for the audit client is a prohibited service for the auditor and creates a self-review threat that safeguards cannot reduce acceptablyCorrect

Explanation

Section 144 of the Companies Act, 2013 bars an auditor from providing services such as design and implementation of financial information systems to the company it audits. The Code of Ethics also identifies a self-review threat. Option A is wrong as separate partners do not cure a statutory prohibition.

Did you get it right without looking?

One question tells you little. A timed set on Digital Auditing & Assurance shows your real accuracy, how long you take and where you lose marks.

More Digital Auditing & Assurance questions