ISL458U-AUDITING
Chapter 4: Audit Planning
Introduction
After the audit engagement letter is signed, the auditor will plan the audit work, which will take approximately one year. The auditor should determine the strategy, that is, the approach to be applied, before planning the work. The scope of the audit, the time schedule, and other important factors related to the audit should be taken into account when setting up the audit.
The auditor will prepare the audit plan in accordance with the audit strategy. A detailed plan should be prepared by experienced auditors in the audit team for the success of the audit. The first task in the audit plan should be to understand the client’s business and its industry. The auditor will then assess the audit risk.
The Stages of the Audit Process
During the audit process, the activities of the auditor can be gathered in four stages. These are as follows:
• Accepting the engagement and arrangement • Audit planning • Performing audit procedures • Reporting of findings.
In the past, auditors were spending most of their time on work towards the accuracy of their account items. Today, more time is devoted to client acceptance, audit planning, understanding, and assessment of internal controls, and corruption investigations. The auditor should make adequate audit planning according to the generally accepted field audit standard related to the field work. Planning will help the auditor gather sufficient and appropriate evidence to form an opinion, perform the audit at an affordable cost, and avoid misunderstandings about the business. Planning is a continuous and repetitive process rather than being a one-time job. It starts shortly after the completion of the previous audit work and continues until the end of current audit work.
Client Acceptance and Audit Engagement
In Turkey, according to the Turkish Commercial Code (TCC), an auditor/audit firm should be chosen in the company’s general assembly. The auditor must be determined for each operating cycle and before the operating cycle ends. If the auditor is not appointed until the 4th month of the operating cycle by the company’s general assembly, the appointment of the auditor is made by the court upon the application of the relevant persons.
Proposal Evaluation
The process of evaluating the proposal from the client includes the assessments to be made about the client’s business and the assessments that should be considered with its ethical dimension.
a. Evaluation of the Client’s Business: In practice, the audit firms determine the risk level of their clients (such as low risk, medium risk, high risk)
with the tests they developed and decide whether to accept and continue the audit accordingly. b. Ethical Evaluations: The audit firm should consider its own business risk when accepting the proposal. The business risk (for audit firms or auditors): Possibility of loss of professional reputation of the audit firm or auditor due to acceptance of the audit engagement.
Audit Engagement with Client
According to the International Standards of Auditing (ISA), an audit engagement letter must be created between the audit firm and the client to solidify the audit arrangement. The engagement letter must be signed by the authorities of both parties. The requirements by the Public Oversight Authority for arrangements should be taken into account.
Audit Plan and Audit Strategy
Within the scope of planning, an audit strategy and an audit plan need to be devised. The audit strategy is a general approach to the audit engagement, which is the specification of the detailed audit plan, the scope and performance of the audit. The audit plan regulates specific audit procedures such as risk assessment and details of the structure, scope and timing of the work that will help the auditor to form an opinion.
Preparing the Audit Plan
The auditor creates the audit plan in accordance with the audit strategy. The plan includes risk assessment procedures, structure, time, and scope of further audit procedures. Adequate audit plans help the auditor in the following matters.
• To draw attention to important areas in auditing, • Solving the problem of time pressure, • Management and organization of the audit in accordance with the audit engagement, • To determine the audit team appropriately, • Supervision and direction of team members and to be able to observe their work, • Coordination of communication with people to be contacted in the client business and external experts.
Audit Risk Assessment
When assessing the audit’s risk, the auditor tries to balance the cost of issuing an inappropriate audit opinion to the cost of applying additional audit procedures to reduce the audit risk. Audit risk components, or in other words, the audit risk model includes three different types of risks. These are a) Inherent Risk (IR), b) Control Risk (CR) and c) Detection Risk (DR). Audit risk is found by multiplying these three types of risk probabilities.
Internal Control Components
In the COSO report, internal control consists of five parts:
• Control environment • Risk assessment • Control activities • Information and communication • Monitoring activities.
Assessing Control Risk
Familiarization with ICS and CR (control risk) assessment may differ from business to business. However, the most common approach used by the auditor is as follows:
a. To discover the control environment, risk assessment procedures, accounting information and communication system, monitoring methods as detailed as possible, b. To get familiarized with the specific controls that reduce CR and c. To test the effectiveness of the controls.
The auditor can only conclude that the client entity “has low CR” after the third stage. The auditor documents the collected information in three ways. These are as follows:
• Story-Taking (Note-Taking) • Flow Chart • Internal Control Survey Form
The most preferred approach in audits is to use all three certification methods together.
Test of Controls
The procedures performed to support the low-valued CR level and test the effectiveness of the controls are called “Test of Controls (TC)”. Especially, the auditor needs to determine whether controls are being used effectively. If TC results support controls as expected, the auditor will continue to use the same level. However, if the auditor finds out that the controls were not implemented effectively, CR level should be reevaluated.
If the auditor trusts the effectiveness of the controls due to the audit work carried out in the previous year, it may reduce the scope of the control tests. The auditor uses the control tests and the results of the CR valuation process to identify the risk of findings and related supportive tests. For example, the auditor observed that an effective internal control was designed for cash register entries. Therefore, in supportive tests, it will be sufficient to investigate whether cash receipts are recorded correctly in accounting ledger records.
Internal Control Applications in Companies
In Turkey, the number of companies with an effective internal control system and the number of companies with an internal audit unit (which monitors the internal control system) is increasing with a widespread understanding of institutionalization. Enterprises in the financial sector, such as banks and brokerage firms, must establish an effective ICS and internal audit unit due to legal obligations. In real sector companies, these structures are
found in companies with foreign partners, in public companies and holding companies that have reached a certain size.
For SMEs in Turkey, an advanced ICS is not yet able to be implemented. The main encountered shortcomings are:
• Institutionalization • Risk management • Written policies and procedures (Business processes) • Performance measurement (predominantly financial criteria) • Principle of segregation of duties and authorization • IFRS competence • Periodic control activities (such as regular inventory count) • Information security • Internal audit function • Some deficiencies in the reporting and budgeting system, • Deficiencies in information system.
In Turkey, SMEs began to be subject to audit at the beginning of 2013.
In conclusion, the auditor, who formed the audit strategy and audit plan, will then guide the studies (collection of evidence) of the audit procedures (supportive tests) that will enable them to respond to the risks according to the evaluated audit risks.