Notes Chapter 5 AUD
Notes Chapter 5 AUD
http://www.cpa-cfa.org
Audit Sampling (statistic sampling)
Sampling risk – reach the wrong conclusion based on the sample
Although statistical sampling aids the auditor in quantitative ways, it is not a substitute for professional
judgement. Professional judgement is still needed/required to set parameters and evaluate the results.
Audit risk – risk of getting the opinion wrong due to uncertainty in applying audit procedures (sampling and
other)
Risk of assessing control risk too low – risk that the assessed level of control risk based on the sample is less
than the true risk based on the actual operating effectiveness of the control (i.e. sample results indicate a lower
deviation rate than actually exists in the population)
Risk of assessing control risk too high – risk that the assessed level of control risk based on the sample is
greater than the true risk based on the actual operating effectiveness of the control. sample results indicate a
greater deviation rate than actually exists in the population
There are two sorts of mistakes an auditor can make with sampling:
1. The auditor may fail to identify an existing problem (incorrect acceptance and assessing control risk too low)
2. The auditor may falsely identify a problem where none exist (incorrect rejection and assessing control risk
too high)
The risk of incorrect acceptance and the risk of assessing control risk too low relate to the effectiveness of an
audit in (possibly not) detecting an existing material misstatement. Auditors usually accept a risk of 5% (or
10%). Inverse to the risk is the confidence level (also called reliability). The auditor is 95% confident that the
sample is representative of the population.
The risk of incorrect rejection and the risk of assessing control risk too high relate to the efficiency of the audit
(the auditor does more audit work than is necessary)
Attribute Sampling
Planning considerations
• Relationship between the sample to the objective of the test of controls
• Tolerable deviation rate – maximum rate of deviation from a prescribed procedure the auditor will tolerate
without modifying planned reliance (or changing control risk assessment) on internal control. Rate set by
the auditor
• Auditors allowable risk of assessing control risk too low
• Characteristics of the population
Deviation rate – auditors best estimate of the deviation rate in the population from which the sample was
selected. There is a direct relationship to sample size: the fewer the deviations expected, the smaller the sample
size would be needed.
Population of 1000 and sample 100 items and 7 deviations identified within the sample
7% sample deviation rate
Estimate 70 deviations in the population (7% sample deviation rate)
1
AUD - Notes Chapter 5
http://www.cpa-cfa.org
If the estimated deviation rate for the entire population is less than the tolerable rate for the population, the
auditor should consider the risk that such a result might be obtained even though the true deviation rate for the
population exceeds the tolerable rate for the population. For example assume the tolerable rate for a population
is 5% and the sample consists of 60 items:
• If no deviations are found in the sample of 60, the auditor may conclude that there is an acceptably low
sampling risk that the true deviation rate in the population exceeds the tolerable rate of 5% (this is because
the sample deviation rate is much less than the tolerable rate)
• If the sample includes two or more deviations (2 in 60 = 3.33%), the auditor may conclude that there is an
unacceptably high sampling risk that the rate of deviations in the population exceeds the tolerable rate of
5% (this is because the sample deviation rate is close to the tolerable rate)
• The auditor applies professional judgement in making such evaluations
Sample deviation rate + allowance for sampling risk = Upper deviation rate
Allowance for sampling risk = what we found in the sample isn’t representative of the population
If the upper deviation rate is less than or equal to the auditors tolerable deviation rate, the auditor may rely on
the control (assuming results of other audit tests do not contradict such results)
If the upper deviation rate exceeds the auditors tolerable deviation rate, the auditor would not rely on the
control. Instead the auditor would either:
• Select and test compliance with some other internal accounting control, or
• Modify the nature, extent, or timing of related substantive tests to reflect the reduced reliance
The auditor projects the misstatements found in the sample to the population using one of several methods
(MPU, ratio, difference, etc). The projected misstatement is applied to the recorded balance to obtain a “point
estimate” of the true balance.
The auditor must then add an allowance for the sampling risk (sometimes called a precision interval) to this
estimate
2
AUD - Notes Chapter 5
http://www.cpa-cfa.org
In deciding whether to accept the clients book value, the auditor determines whether the recorded book value
falls within the acceptable range (i.e. point estimate +/- the allowance for sampling risk). If so, the book value
is fairly stated
Advantages
• Emphasizes larger items by stratifying the sample. The chance of an item being selected is proportionate to
its dollar amount
• If no errors are expected, PPS sampling generally requires a smaller sample than other methods
Disadvantages
• Items with zero, negative or understated balances require special design considerations
Tolerable misstatement - the maximum dollar error that may exist in the account without causing the F/S to be
materially misstated
Reliability factors correspond to the risk of incorrect acceptance and are generally obtained from a table
Integrated test facility (ITF) – similar to test data approach except that the test data is commingled with live
data (the clients system is used to process the auditors data, on-line)
• Test data must be separated from the live data before the reports are created. This is usually accomplished
by processing the test data to dummy accounts (fictitious customer, branch, vendor)
• Client personnel are not informed that the test is being run
Parallel simulation (reperformance test) – auditor re-processes some or all the clients live data (using auditor
software) and then compares the results with the clients files (the auditors system is used to process client data)
Generalized audit software packages (GASPs) – allows the auditor to have little technical knowledge of the
clients system (computerized environment)
Previously communicated significant deficiencies and material weaknesses that have not been corrected should
be communicated again
The CPA may report on mgmt’s assertion or may report directly on the effectiveness of the entity’s internal
control
Obtain from mgmt a written assertion about the effectiveness of the entity’s internal control. The assertion may
be presented in two ways:
1. a separate report that will accompany the accountants report
2. a representation letter to the accounts
When a material weakness exists, the CPA should express an opinion directly on the effectiveness of internal
control, and not on mgmt’s assertion
In a F/S audit, use of the report on the internal control is restricted, while
In a separate examination of internal control, use of the report is generally not restricted
The auditors report must disclose material weaknesses in internal control, but is not required to disclose
significant deficiencies that are not material weakness (different than the attestation standards)
If an auditor conducts the audit (of a nonissuer) in accordance with both GAAS and PCAOB, the auditor may
indicate in the auditors report that the audit was conducted in accordance with both standards
Government Auditing
Auditors responsibilities
• Obtaining reasonable assurance that the F/S are free of material misstatements resulting from violations of
laws and regulations that have direct and material effect on the F/S
• Obtaining an understanding of the possible effects on F/S of laws and regulations
• Assessing whether mgmt has identified laws and regulations that have direct and material effect
• Communicating to mgmt and the audit committee that an audit in accordance with GAAP may not be
sufficient if, during the audit, the auditor becomes aware that the entity is subject to additional audit
requirements that may not be encompassed in the terms of the engagement
Attestation engagements performed in conformity with Generally Accepted Government Auditing Standards
(GAGAS) (the yellow book) incorporate the AICPA’s standards for examinations, reviews, and agreed upon
procedures by reference and include expanded requirements
Mgmt is responsible for the entity’s compliance with laws and regulations
Mgmt has identified and disclosed in writing to the auditor all the laws and regulations that have a direct and
material effect on its F/S
Audit reports should be distributed to the appropriate officials of the entity requiring or arranging for the audit
(including external funding sources)
GAGAS requires a written report on the auditors understanding of internal control and the assessment of
control risk in all audits. This is different from GAAS, which requires written communication only when
significant deficiencies are noted
Auditor communication requirements increase in government settings. Auditors often have the responsibility of
reporting significant deficiencies to specific regulatory bodies or grantor agencies
Management Representations
Obtained from mgmt at the conclusion of fieldwork and should address all F/S covered by the report even if
current mgmt was not present during all such periods
Purpose:
1. To confirm representations explicitly or implicitly given to auditor
2. To indicate and document the continuing appropriateness of such representations
3. To reduce the possibility of misunderstanding concerning matter that are the subject of the
representations
5
AUD - Notes Chapter 5
http://www.cpa-cfa.org