Skip to content

CA Final · Advanced Auditing, Assurance and Professional Ethics · Digital Auditing & Assurance

While auditing Himalaya Pharma Ltd, the auditor uses data analytics to test the entire population of journal entries. The software flags 1,200 entries posted on Sundays and after midnight by a user whose access rights were recently changed. The management says these are routine month-end closings. What should the auditor do under SA 240 and SA 330?

The auditor should treat the flagged entries as higher risk, corroborate management's explanation through inquiry and supporting documents, and evaluate possible management override. Journal entry testing is mandatory under SA 240 for every audit, and uncorroborated management explanations are not sufficient evidence.

  1. AAccept management's explanation as sufficient audit evidence since the entries are system generated
  2. BDrop the analysis because journal entry testing is required only for listed companies
  3. CReport immediately to the Central Government under section 143(12) without further inquiry
  4. DTreat the flagged entries as a higher-risk population, corroborate management's explanation with supporting documents and inquiries, and evaluate whether the entries indicate possible management override of controlsCorrect

Explanation

SA 240 requires journal entry testing for all audits as a response to management override risk. Unusual timing and user access changes are risk indicators needing corroboration. Accepting an explanation alone is insufficient evidence, and reporting under 143(12) is premature before determining whether fraud is suspected.

Did you get it right without looking?

One question tells you little. A timed set on Digital Auditing & Assurance shows your real accuracy, how long you take and where you lose marks.

More Digital Auditing & Assurance questions