Skip to content

CA Final · Advanced Auditing, Assurance and Professional Ethics · Digital Auditing & Assurance

While auditing Kaveri Pharma Ltd, CA Rohit uses data analytics to test 100% of journal entries. The tool flags entries posted on Sundays by a user with a generic login 'ADMIN' with round-rupee amounts near the quarter-end. Under SA 240 and SA 330, what is the most appropriate next step?

The auditor should investigate the flagged entries by inquiring of management and checking supporting documents, and consider the fraud risk and control implications of the generic login. Flags are indicators, not proof, so neither ignoring them nor jumping to an adverse opinion is appropriate.

  1. ADisregard the flags since the software generated them and not management
  2. BEvaluate the flagged entries by inquiring of management and examining supporting documents, and consider the implications for fraud risk and the reliability of the dataCorrect
  3. CConclude that a material misstatement exists due to fraud and issue an adverse opinion immediately
  4. DReduce the sample for other tests because analytics covered the entire population

Explanation

Journal entry testing is a required response to the risk of management override. Flagged items must be investigated through inquiry and corroboration with documents, and the auditor should consider whether the generic login points to a control deficiency. Flags alone are not conclusive evidence of fraud, so an immediate adverse opinion is premature.

Did you get it right without looking?

One question tells you little. A timed set on Digital Auditing & Assurance shows your real accuracy, how long you take and where you lose marks.

More Digital Auditing & Assurance questions