Audit planning: points to note
This is the second of two articles (the first one relating to audit completion) that considers the area of audit planning. Audit planning is probably one of the most crucial aspects of an audit because without undertaking a sufficient programme of planning, the auditor runs the risk of going in blind which in turn increases audit risk (audit risk being the risk that the auditor forms an incorrect opinion on the financial statements). UK and Ireland ISAs which are related to planning (those in the 300 series: ISAs (UK and Ireland) 300, 315, 320 and 330) are vast, hence this article cannot go into every matter that an auditor must consider. The intention is to flag up some of the more important issues that are related to audit planning and practitioners are advised to consult the UK and Ireland ISAs in the 300 series to address any concerns or problematic issues they encounter.
According to ISA (UK and Ireland) 300, the objective of audit planning is to plan the audit so that it will be performed in an effective manner. ISA (UK and Ireland) 300 says that planning an audit involves establishing the overall audit strategy, which then helps to develop the audit plan. ISA (UK and Ireland) 300 recognises that adequate audit planning will benefit the auditor in a number of ways, specifically paragraph 2 to ISA (UK and Ireland) 300 says the benefits are as follows:
- Helping the auditor to devote appropriate attention to important areas of the audit.
- Helping the auditor identify and resolve potential problems on a timely basis.
- Helping the auditor properly organise and manage the audit engagement so that it is performed in an effective and efficient manner.
- Assisting in the selection of engagement team members with appropriate levels of capabilities and competence to respond to anticipated risks, and the proper assignment of work to them.
- Facilitating the direction and supervision of engagement team members and the review of their work.
- Assisting, where applicable, in coordination of work done by auditors of components and experts.
Preliminary engagement activities
ISA (UK and Ireland) 300 requires the auditor to perform ‘preliminary engagement activities’ at the start of an audit assignment. These preliminary engagement activities are undertaken in order that the auditor can identify and evaluate events or circumstances that may adversely affect the auditor’s ability to plan and perform the audit engagement. Paragraph 6 to ISA (UK and Ireland) 300 requires the auditor to perform the following activities at the start of an audit engagement:
- Perform procedures required by ISA (UK and Ireland) 220 Quality control for an audit of financial statements regarding the continuance of the client relationship and the specific audit engagement.
- Evaluate compliance with relevant ethical requirements, including independence, in accordance with ISA (UK and Ireland) 220.
- Establish an understanding of the engagement terms, as required under ISA (UK and Ireland) 210, Agreeing the terms of audit engagements.
The Application and Other Explanatory Material within ISA 300 at paragraph A6 gives examples of why the above three activities should be performed, such as:
- Ensuring the auditor maintains necessary independence and ability to perform the engagement.
- Ensuring there are no issues with management’s integrity that may affect the auditor’s willingness to continue the engagement.
- Ensuring there is clear understanding with the audit client as to the terms of the engagement.
Audit strategy and audit plan
Establishing the audit strategy will help the auditor to determine various issues that will be required throughout the audit (subject to the auditor’s risk assessment). When establishing the audit strategy, the auditor will consider the resources that will be needed in certain audit areas, for example high risk areas and the level of skill and experience that will need to be devoted to such areas, including the use of experts where it is deemed necessary. The auditor will also need to consider the amount of the resources to be assigned to specific audit areas, when these resources are needed and how these resources will be managed, directed and supervised.
Once these issues have been addressed by the auditor, the detailed audit plan can then be developed. The audit plan will include the nature, timing and extent of audit procedures to be performed which are all risk-based – in other words the auditor will undertake risk assessment procedures early on in the audit process and will plan the nature, timing and extent of specific further audit procedures depending on the outcome of the auditor’s risk assessment procedures.
What is important to appreciate is that while audit planning naturally occurs at the start of the audit process, it is not completed once planning is complete. The UK and Ireland ISAs recognise that planning is a ‘continuous and iterative’ process and that changes to the original audit plan may well be needed as a result of unexpected events, changes in conditions, or as a result of audit evidence gathered during the detailed audit work (such as when audit evidence reveals matters that differ significantly from the information that was available to the auditor during the original planning).
Direction, supervision and review
Many auditors ask the question “how much review work am I expected to complete?” The answer to this is that it will depend on many factors. Of course, this is not what many auditors wish to receive as a reply, but ISA (UK and Ireland) 300 acknowledges four factors that the auditor will need to consider to determine the nature, timing and extent of the direction and supervision of team members deployed on an audit, including:
- The size and complexity of the entity.
- The area of the audit.
- The assessed risks of material misstatement.
- The capabilities and competence of the individual team members performing the audit work.
Identifying the risks of material misstatement
To be able to identify the risks of material misstatement, the auditor has to have a clear understanding of the audit client. ISA (UK and Ireland) 315 says that the objective of the auditor is to identify and assess the risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels, through understanding the entity and its environment, including the entity’s internal control, thereby providing a basis for designing and implementing responses to the assessed risks of material misstatement which are dealt with in ISA (UK and Ireland) 330.
An article of this nature cannot cover every possible issue that may be covered when obtaining an understanding of an entity, but a few points that really should be documented are as follows:
- What the entity does and how it conducts its operations.
- The industry sector in which the entity operates.
- External factors that affect the entity.
- How it is financed.
- Group structure (where applicable), including subsidiaries, associates, joint ventures etc.
- Objectives and strategies of the entity.
- The effectiveness of its internal control.
- How management identify and analysis the risks facing the business and how they respond to those risks.
- Significant financial reporting issues and accounting estimates.
A final point to note with regards to the client’s control environment is that in addition to the auditor having to gain an understanding of the client’s control environment, the auditor must also evaluate whether management, with the oversight of those charged with governance, has created and maintained a culture of honesty and ethical behaviour as well as whether the strengths in the control environment elements collectively provide an appropriate foundation for the other components of internal control, and whether those other components are not undermined by deficiencies in the control environment. This is an issue that appears to be missed out and is on the ‘hotspot’ list of some file reviewers as this requirement is specifically covered in ISA (UK and Ireland) 315 at paragraph 14 (a) and (b).
Risk assessment
ISA (UK and Ireland) 315 requires the auditor to obtain an understanding as to whether the audit client has processes in place to:
- Identify business risks.
- Estimate the significance of the risks.
- Assess the likelihood of their occurrence.
- Decide about actions to address those risks.
Some clients may not have an established process in place, or they may just have ad-hoc processes. Where this is the case the auditor must discuss with management whether business risks which are relevant to the objectives of financial reporting have been identified and how they have been addressed. The auditor must then consider whether the absence of a documented risk assessment process is appropriate in the circumstances, or determine whether it goes to represent a significant deficiency in internal control.
Once risk has been assessed, the auditor must implement appropriate responses to those risks. ISA (UK and Ireland) 330, The auditor’s responses to assessed risks requires the auditor to design and implement overall responses to address the assessed risks of material misstatement at the financial statement level. How the auditor designs these responses will be influenced by a couple of considerations which are covered in ISA (UK and Ireland) 330 at paragraph 7 which says the auditor shall:
- Consider the reasons for the assessment given to the risk of material misstatement at the assertion level for each class of transactions, account balance, and disclosure including:
- the likelihood of material misstatement due to the particular characteristics of the relevant class of transactions, account balance, or disclosure (that is, the inherent risk); and
- whether the risk assessment takes account of relevant controls (that is, the control risk), thereby requiring the auditor to obtain audit evidence to determine whether the controls are operating effectively (that is, the auditor intends to rely on the operating effectiveness of controls in determining the nature, timing and extent of substantive procedures); and
- Obtain more persuasive audit evidence the higher the auditor’s assessment of risk.
ISA (UK and Ireland) 330 requires the auditor to perform tests of controls if the auditor’s assessment of risk of material misstatement at the assertion level includes an expectation that the controls are operating effectively or where substantive procedures alone will not be able to provide sufficient appropriate audit evidence at the assertion level. However, care must be taken when placing reliance on internal controls and where the auditor places greater reliance on the effectiveness of a control, the auditor must obtain more persuasive audit evidence.
Relying on tests of control from the previous audit
It is permissible to use audit evidence from previous audits concerning the operating effectiveness of specific controls, but in doing so the auditor must make sure that they establish the continuing relevance of that evidence by obtaining audit evidence concerning whether any significant changes in those controls have occurred since the previous audit. Where there have been significant changes that affect the continuing relevance of the audit evidence obtained from the previous audit, the auditor must test the controls in the current audit. However, if there have not been such changes the auditor will be required to test the controls at least once in every third audit. This does not mean that every control will be tested at least once in every third audit, because paragraph 14(b) to ISA (UK and Ireland) 330 requires the auditor to test some controls each audit so as to avoid the possibility of testing all the controls on which the auditor intends to rely in a single audit period with no testing of controls in the next two audit periods.
Where substantive tests are concerned, ISA (UK and Ireland) 330 requires substantive testing to be carried out for each material class of transaction, account balance and disclosure regardless of the assessed risks of material misstatement as well as considering whether external confirmation procedures should be performed as substantive audit procedures, so there is no getting away from the detailed ‘ticking and bashing’ procedures.
The auditor must also ensure that paragraph 20 to ISA (UK and Ireland) 330 is complied with which says that the auditor must include the following audit procedures related to the financial statement closing process:
- Agreeing or reconciling the financial statements with the underlying accounting records; and
- Examining material journal entries and other adjustments made during the course of preparing the financial statements.
Conclusion
Audit planning is a crucial aspect of the audit process and there are many areas in audit planning that lend themselves to misunderstanding and misinterpretation. In some cases audit firms have been criticised for the sheer lack of planning documentation on file and from which inspectors can only conclude that the amount of planning documentation on file is representative of the actual amount of planning work that has been done. Many modern auditing software programmes will provide a comprehensive planning memorandum and outline the information that should be included in the planning section of the current audit file, but the most crucial point to bear in mind is to make sure the crucial planning points are fully documented.
Category: Audit





