Product Image

Auditor's Risk Assessment Process: Tackling the New Risk Assessment SASs

Author/Moderator: Richard H. Gesseck, CPA
Publisher: AICPA
Availability: In Stock
See Below To Add To Cart
View Online Catalog
Add This Page

Description

Ideal for self-study or on-site training!

Learn the requirements that significantly enhance the quality and depth of the understanding of the entity and its environment, including its internal control system. Gain an understanding of how the new standards differ from existing standards and what you will have to do differently now — both during the interim and final field work phases. Learn what procedures are now required to respond to assessed risks. Also learn how the documentation standards in SAS No. 103 and the required communication of internal control related matters in SAS Nos. 112 and 115 fit into the typical audit process.

Objectives: 
  • Recognize how the new risk assessment standards differ from existing standards and how these differences will significantly affect your audit practice
  • Develop a more in-depth understanding of the entity and its environment, including its system of internal control
  • Identify the risks of material misstatement in the financial statements and what the entity is doing to mitigate them
  • Provide a more rigorous assessment of the risks of material misstatement
  • Improve the linkage between the assessed risks and the nature, timing and extent of audit procedures performed in response to those risks

Prerequisite: Basic understanding of accounting and auditing principles

Videocourse Details

View the video clip

In this video, Richard H. Gesseck, CPA, Audit Partner at UHY LLP in New Haven, CT, discusses the new SASs with William I. Eskin, CPA, President at WIE, Inc. in Baltimore, MD, and an instructor for this course; Elizabeth S. Gantnier, CPA, Director of Quality Control at Stegman & Company in Baltimore, MD, and an instructor for this course; and Lawrence J. Gramling, Ph.D., CPA, Professor of Accounting at the University of Connecticut in Storrs, CT.

*(188-min. video) The DVD disk contains the video presentation and a viewable copy of the Manual.
**The Additional Manual is for group study training only. Unlike other formats, it has no exam answer sheet and cannot be used to earn self-study credit.

Table of Contents

  • Chapter 1 - Overview
    • Learning Objectives
    • Introduction
    • The Audit Process
    • Phase I – Audit Planning
      • Client Continuance and Independence Matters
      • Understand the Business and Its Risks
      • Perform Preliminary Analytical Review Procedures
      • Set Planning Materiality and Tolerable Misstatement
      • Identify Significant Accounts and Processes
      • Conduct Audit Team Brainstorming Meeting
      • Assess Risk of Material Misstatement at the Entity Level
      • Agree on Timing and Deliverables
      • Develop an Overall Audit Strategy
      • Establish an Understanding with the Client Regarding the Services to be Performed
      • Issue Audit Planning Document
    • Phase II – Internal Control Documentation
      • Gather or Update Documentation for Significant Processes
      • Perform Walk-Throughs
      • Ask "What Could Go Wrong" Questions
      • Identify Controls
      • Evaluate Design Effectiveness
      • Decide Whether to Rely On and therefore Test Controls
    • Phase III – Assessing Risks and Designing Procedures to Detect Material Misstatements
    • Phase IV – Interim and Year-End Testing
      • Perform Tests of Controls and Details
      • Evaluate Quality and Sufficiency of Evidence Obtained
      • Evaluate Misstatements
    • Phase V – Wrap-Up
    • Final Overall Analytical Review
    • Communicating Deficiencies
    • Conduct Closing Meeting
    • Assemble Audit Documentation
  • Chapter 2 - Audit Planning
    • Learning Objectives
    • Introduction
    • Overall Impact of the Risk Assessment Standards on Audit Planning
      • SAS No. 104, Amendment to Statement on Auditing Standards No. 1, Codification of Auditing Standards and Procedures ("Due Professional Care in the Performance of Work")
      • SAS No. 105, Amendment to SAS No. 95, Generally Accepted Auditing Standards
      • SAS No. 106, Audit Evidence
      • SAS No. 107, Audit Risk and Materiality in Conducting an Audit
      • SAS No. 108, Planning and Supervision
      • SAS No. 109, Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement
      • SAS No. 111, Amendment to SAS No. 39, Audit Sampling
    • Prior to the Audit
      • Appointment
      • Client Continuance or Acceptance
    • Gaining an Understanding of the Entity and Its Environment
      • Understanding the Entity and Its Environment
    • Performing Preliminary Analytical Review Procedures
    • Estimate Planning Materiality and Tolerable Misstatement
      • Planning Materiality
      • Tolerable Misstatement
      • Documenting Planning Materiality
    • Identifying Significant Accounts
    • Conducting a Risk Assessment/Fraud Specific Audit Team Meeting
    • Assessing the Risk of Material Misstatement Arising from Error or Fraud at the Entity Level
    • Agreeing on Timing and Deliverables
    • Developing an Overall Audit Strategy
      • Specialized Skills
    • Establishing an Understanding with the Client
    • Issuing an Audit Planning Document
    • Summary
    • Questions
  • Chapter 3 - Internal Control Documentation
    • Learning Objectives
    • Introduction
    • Overall Impact of the Risk Assessment Standards on Internal Control Documentation
      • SAS No. 105, Amendment to SAS No. 95, Generally Accepted Auditing Standards
      • SAS No. 106, Audit Evidence
      • SAS No. 109, Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement
      • SAS No. 110, Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained
    • Steps in the Documentation Process
      • Identify Entity Level Controls
      • Anti-fraud Programs and Controls
      • Identify Significant Accounts, Groups of Accounts, and Classes of Transactions
    • Identifying Significant Underlying Processes
      • Routine Processes
      • Non-Routine and Estimation Processes
      • Information Technology (IT) Processes
    • Obtaining Documentation of Processes
      • Perform a Walk-Through of Each Significant Process
    • Ask 'What Could Go Wrong' Questions
    • Identify Preventive or Detective Controls
    • Evaluate the Design of Internal Controls
      • Determining Whether to Test Controls
      • TIS 8200.05
      • Financial Statement Closing Process
    • Summary
    • Questions
  • Chapter 4 - Assessing Risks and Designing Procedures to Detect Material Misstatements . 4-1 Learning Objectives
    • Introduction
    • Overall Impact of Risk Assessment SASs on Assessing Risks and Designing Procedures
      • SAS No. 105, Amendment to SAS No. 95, Generally Accepted Auditing Standards
      • SAS No. 106, Audit Evidence
      • SAS No. 109, Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement
      • SAS No. 110, Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained
    • Risk Assessment
      • Audit Risk
      • Assessing Inherent Risk
      • Assessing Control Risk
      • Combined Risk Assessment
      • Significant Risks That Require Special Audit Consideration
      • Required Testing of Controls
      • TIS 8200.05
      • Responding to Risk
      • Revising Risk Assessment
      • Documentation of Risk Assessment Related Matters
      • Overall Response
      • Response to Risk at the Assertion Level
    • Financial Statement Assertions
    • Audit Procedures
      • Designing Further Audit Procedures
      • Linking Assessed Risks to the Design of Further Audit Procedures
    • Summary
    • Questions
  • Chapter 5 - Interim and Year-End Testing
    • Learning Objectives
    • Introduction
    • Overall Impact of Risk Assessment SASs on Interim and Year-End Testing
      • SAS No. 105, Amendment to SAS No. 95, Generally Accepted Auditing Standards
      • SAS No. 106, Audit Evidence
      • SAS No. 107, Audit Risk and Materiality in Conducting an Audit
    • Applying the Standards and Concepts in Practice
      • Updating Interim Tests
      • Selecting Procedures
      • Testing Details of Classes of Transactions, Testing Controls, and Dual-Purpose Tests
      • Testing the Financial Statement Closing Process
    • Evaluating Quality and Sufficiency of Audit Evidence
    • Evaluating Misstatements
      • Impact of Misstatements
      • Known vs. Likely Misstatements
      • Differences in Accounting Estimates
      • Consideration of Prior Year Uncorrected Misstatements
      • Qualitative Factors
      • Uncorrected Misstatements
      • Communicating Misstatements
      • Documentation
    • Summary
    • Questions
  • Chapter 6 - Audit Wrap-Up
    • Learning Objectives
    • Introduction
    • Final Overall Analytical Review
    • Communicating Significant Deficiencies and Material Weaknesses to Management and Those Charged with Governance
      • Control Deficiency
      • Evaluating Control Deficiencies
      • Exceptions Identified in Tests of Operating Effectiveness
      • Evaluating Exceptions in the Design or Operating Effectiveness of Controls
      • Severity
      • Significant Deficiency
      • Inconsequential Misstatement
      • Material Weakness
      • Prudent Official Test
      • Form of Communication
    • Conducting Closing Meeting(s)
    • Issuing the Auditor's Opinion
    • Assembling the Audit Documentation for Filing
    • Summary
    • Questions
  • Chapter 7 - Latest Developments
  • Value Aid
  • Statements on Auditing Standards 104-111

732993

Excerpts

Chapter 1 - Overview

Learning Objectives

After completing this chapter you should be able to describe the key activities in the typical process for auditing an entity's financial statements in accordance with generally accepted auditing standards. This knowledge should, in turn, enable you to recognize changes in activities resulting from the issuance of the Risk Assessment Standards.

Introduction

To further enhance audit quality, the AICPA Auditing Standards Board issued a set of eight Statements on Auditing Standards (SASs) – collectively known as the Risk Assessment Standards. These Standards are effective for audits of financial statements for periods beginning on or after December 15, 2006.

This course begins with an overview of the typical audit process and then examines how the Risk Assessment Standards will affect it. The Risk Assessment Standards reflected in this course include the following:

• SAS No. 104, Amendment to Statement on Auditing Standards No. 1, Codification of Auditing Standards and Procedures ("Due Professional Care in the Performance of Work")
• SAS No. 105, Amendment to Statement on Auditing Standards No. 95, Generally Accepted Auditing Standards
• SAS No. 106, Audit Evidence
• SAS No. 107, Audit Risk and Materiality in Conducting an Audit
• SAS No. 108, Planning and Supervision
• SAS No. 109, Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement
• SAS No. 110, Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained
• SAS No. 111, Amendment to Statement on Auditing Standards No. 39, Audit Sampling

The Auditing Standards Board (ASB) believes that the requirements and guidance provided in the Risk Assessment Standards will result in a substantial change in audit practice and in more effective audits. Overall the new SASs change the audit process to

Expand the quality and depth of the auditor's required understanding of the entity and its environment, including its internal control – The standards require the auditor to obtain an understanding of a significantly expanded set of information about specific elements of the entity and its environment. The purpose of the required understanding of this broadened set of information about the entity and its environment is to enhance the auditor's ability to identify and assess risks that may lead to material misstatements in the financial statements. The auditor is required to perform risk assessment procedures in all audits to obtain an understanding of the entity and its control environment, including its internal control. Risk assessment procedures include updating information obtained in prior audits that the auditor intends to use in the current audit. The expanded understanding about the entity and its environment should also be helpful to the auditor throughout the audit when making judgments about materiality and when critically evaluating audit evidence.

Require the auditor to assess the risks of material misstatements at the financial statement level and at the assertion level on all audits based on the understanding obtained – The new SASs note that assessing risks of material misstatements encompasses a combined assessment of inherent risk and control risk. The new SASs eliminate the auditor's ability to assess "risk at the maximum" without support for that assessment. Thus, auditors will be required to support all risk assessments at whatever level, including risks at the maximum, based on their understanding of the entity and its environment. In addition, the new SASs require the auditor to identify "significant risks" (defined later in this chapter) that require special audit consideration, and risks for which substantive procedures alone will not reduce audit risk to an appropriate level.

Eliminate the "default to maximum" for control risk, which should encourage testing of controls – Auditors will no longer be able to assess control risk "at the maximum" without support for that assessment. Thus, that kind of audit approach can no longer be used as a default audit strategy. Instead, auditors should document the basis for a control risk at maximum assessment. The ASB believes this will encourage the testing of controls in all audits. In addition, the new SASs expand the auditor's requirement to understand internal controls in every audit by also requiring the auditor to evaluate the design of controls, including relevant control procedures over "significant risks," and to determine whether those control procedures have been implemented.

Emphasize importance of the entity's risk assessment process – The new SASs emphasize that when the auditor identifies potential risks of material misstatements in the financial statements, it is important for the auditor to consider the entity's risk assessment process. To assist the auditor with this consideration, the new SASs discuss how the entity's risk assessment process fits in with the entity's process of setting objectives and strategies and assessing related business risks. When the auditor identifies risks of material misstatements that the entity's risk assessment processes failed to detect, the new SASs require the auditor to consider why the process failed and whether the process is appropriate in the circumstance.

Strengthen the linkage between assessed risks and the auditor's responses to those risks – Because auditors frequently struggle with designing an appropriate audit response to risks identified, the new SASs contain expanded guidance designed to significantly improve the auditor's ability to effectively address the identified risks. Auditors are required to determine both an overall response to address the risks of material misstatements at the financial statement level and a response to assess risks of material misstatements at the assertion level. The new guidance emphasizes the importance of the nature of the audit procedures in responding to assessed risks. The new SASs also require the auditor to perform substantive procedures for "significant risks." These substantive procedures consist of tests of details alone or tests of details combined with substantive analytical procedures that are specifically responsive to the identified risks. If the auditor plans to rely on the operating effectiveness of controls to mitigate a significant risk, the auditor is required to obtain all evidence about the operating effectiveness of those controls from tests of controls performed in the current period. The auditor cannot conclude that controls are operating effectively based on tests of controls performed in prior audits even when the auditor also determined that the controls did not change since that testing.

Clarify the auditor's ability to rely on audit evidence gathered in prior audits – Except for controls related to significant risks, the auditor who plans to rely on controls that have not changed since they were last tested should perform tests of the operating effectiveness of those controls at least every third year in an annual audit. As noted above, the auditor should test controls designed to address significant risks in the current audit.

Strengthen guidance for testing disclosures – The new SASs include expanded guidance to specifically address the importance of considering the "completeness" of disclosures and their understandability. The assertions related to presentation and disclosure have been significantly revised to provide this emphasis.

Clarify and expand guidance on evaluating audit findings – When evaluating audit findings, auditors should consider the effect of uncorrected misstatements related to prior periods on the current-period financial statements.

Expand documentation requirements – Because the ASB believes that documentation requirements can drive behavior, the new SASs require the auditor to document, among other things, the following items:

– Results of the risk assessments both at the financial statement level and the assertion level;

– The nature, timing, and extent of audit procedures performed;

– The linkage of auditor responses with the assessed risks at the assertion level; and

– Results of the audit procedures.

The Audit Process

The typical audit process may proceed as depicted below. And although it is presented as an iterative process, procedures and phases often overlap and activities may even take place in a different sequence. The Risk Assessment Standards, which are effective for audits of financial statements for periods beginning on or after December 15, 2006, affect almost all of the phases presented. The phases and activities have been numbered and named merely for reference purposes during the remainder of this course. A summary of the typical audit process and the key activities within each phase follows:

• Phase I (Audit Planning) – Chapter 2

– Perform client continuance procedures and consider independence matters.

– Understand the entity and its risks.

– Perform preliminary analytical review procedures.

– Estimate planning materiality and tolerable misstatement.

– Identify significant accounts and processes.

– Conduct an audit team "brainstorming" meeting. This meeting addresses the risks of material misstatement arising from error or fraud.

– Assess the risk of material misstatement arising from error or fraud at the entity level.

– Agree on timing and deliverables.

– Develop overall audit strategy.

– Establish an understanding with the client regarding the services to be performed.

– Issue an audit planning report.

• Phase II (Internal Control Documentation) – Chapter 3

– Gather or update documentation for significant processes.

– Perform a walk-through of each significant process.

– Ask "what could go wrong" questions.

– Identify preventive vs. detective controls.

732993

Videocourse Details

NASBA Field of Study: Auditing
Level: Basic
Recommended CPE Credit: Text — 12; DVD/Manual — 15
Yellow Book Hours: Text -12; DVD/Manual -15
Auditor's Risk Assessment Process: Tackling the New Risk Assessment SASs
Text ,
Product# 732993
Availability: In Stock
Regular:$198.75
AICPA Member:$159.00
Your Price:$198.75
Auditor's Risk Assessment Process: Tackling the New Risk Assessment SASs
DVD/Manual ,
Product# 182995
Availability: In Stock
Regular:$261.25
AICPA Member:$209.00
Your Price:$261.25
Auditor's Risk Assessment Process: Tackling the New Risk Assessment SASs
Addl Manual for DVD
Product# 352993
Availability: In Stock
Regular:$73.75
AICPA Member:$59.00
Your Price:$73.75
To receive your AICPA member discount, Sign In now, or Register using your AICPA membership number.
Choose the Standing Order Option and get these discounts on your initial purchase:

Publications--10% discount
CPE Self-Study--20% discount

Each new future annual edition will then be automatically shipped to you at a 10% discount.