The Overall Audit Approach
Chapter Twenty-One
Syllabus topic 1, "Audit Planning – Meaning, Objectives, Factors to be considered, Sources of obtaining information, Discussion with Client, Overall Audit Approach"
Pages 56 to 57 of 98
In one line
The overall audit approach is the decision how far to rely on the entity's internal control and how much to test the figures directly.
The two kinds of procedure
| Compliance procedures | Substantive procedures | |
|---|---|---|
| What they test | Whether the internal controls exist and operate | Whether the figures in the accounts are correct |
| What they answer | Can I rely on this system? | Is this balance right? |
| Example | Examining a sample of purchase invoices for the authorising signature | Circularising debtors to confirm the balances they owe |
| Failure means | The control cannot be relied on, so more substantive work is needed | The figure may be misstated |
Substantive procedures divide again.
| Tests of details | Vouching transactions, verifying balances, confirming with third parties, attending the stock count |
| Analytical procedures | Comparing the figure with an expectation formed from ratios, trends, budgets and knowledge of the business |
The approach is a mix, and the control decides it
| Internal control assessed as | Compliance procedures | Substantive procedures | Called |
|---|---|---|---|
| Strong, and tested to be operating | Extensive | Reduced | A systems-based approach |
| Weak or unreliable | Few or none | Extensive | A substantive approach |
| Absent, or the entity is very small | None | On everything material | A wholly substantive approach |
Notice the trade. Compliance testing is cheaper than substantive testing on a large volume of transactions, which is why a strong control system reduces the cost of an audit as well as its risk. It never reduces it to nothing: some substantive work is done whatever the control, because of management override.
Why some substantive work is always done
Because the one risk internal control cannot address is the risk of management overriding it. The controls are operated by people who report to management, and management can set them aside.
So the auditor always:
- tests journal entries, especially those made near the year end and those with unusual descriptions;
- reviews accounting estimates for bias; and
- examines significant transactions outside the normal course of business.
Those three are done however strong the controls are, and naming them is the answer to "why can the auditor never rely wholly on internal control".
The steps in fixing the approach
| Step | |
|---|---|
| 1 | Understand the accounting system and the control environment |
| 2 | Make a preliminary assessment of control risk |
| 3 | Where the preliminary assessment is that controls can be relied on, test them by compliance procedures |
| 4 | Confirm or revise the assessment on the results of that testing |
| 5 | Fix the nature, timing and extent of the substantive procedures accordingly |
| 6 | Revise during the work if anything found contradicts the assessment |
Step four is where audits go wrong. A preliminary assessment that controls are strong, not tested, and then relied on, is an assumption presented as a conclusion.
The rest of this chapter
Module one is free. The rest of this chapter comes with the B.Com. (Accountancy) Semester 3 notes.
You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does the syllabus.
Notes: ₹499 Already bought it? Sign in
Free either way: the syllabus, and module one of every subject.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.