内部控制与审计风险(英).docx

上传人:修**** 文档编号:13010016 上传时间:2022-04-27 格式:DOCX 页数:17 大小:12.73KB
返回 下载 相关 举报
内部控制与审计风险(英).docx_第1页
第1页 / 共17页
内部控制与审计风险(英).docx_第2页
第2页 / 共17页
点击查看更多>>
资源描述

《内部控制与审计风险(英).docx》由会员分享,可在线阅读,更多相关《内部控制与审计风险(英).docx(17页珍藏版)》请在taowenge.com淘文阁网|工程机械CAD图纸|机械工程制图|CAD装配图下载|SolidWorks_CaTia_CAD_UG_PROE_设计图分享下载上搜索。

1、内部控制与审计风险(英)Chapter 1 General provisionsArticle 1This standard is prepared in accordance with the General Independent Auditing Standard to establish standards for Certified Public Accountants (“CPAs”) on the study and evaluation of an entitys internal controls in the audit of financial statements, t

2、o assess audit risk, to improve audit efficiency and to ensure a high standard of professional work.Article 2The term “internal controls” in this standard refers to the policies and procedures formulated and implemented by an entity with a view to ensuring the efficient conduct of the business activ

3、ities, safeguarding assets, preventing, detecting and correcting error and fraud, and ensuring the truthfulness, legitimacy and completeness of accounting information.Internal controls include the control environment, accounting systems and control procedures.Article 3The term “audit risk” in this s

4、tandard refers to the possibility of the CPA expressing an inappropriate audit opinion after performing an audit, when the financial statements contain material misstatements or omissions. Audit risk includes inherent risk, control risk and detection risk.Article 4Unless otherwise specified, CPAs sh

5、ould refer to this standard in performing audit work other than the audit of financial statements.Chapter 2 General principlesArticle 5When preparing the audit plan, the CPA should study and evaluate the entitys internal controls.Article 6The CPA should perform compliance tests on any internal contr

6、ols, which are intended to be relied upon, to determine the impact on the nature, timing and extent of the substantive tests.Article 7The CPA should maintain professional scepticism, apply professional judgement reasonably to assess the audit risk and to design and perform relevant audit procedures

7、in order to reduce the audit risk to an acceptable level.Article 8The CPA should document the work carried out and the results of the study and evaluation of the internal controls and the assessment of the audit risk in the audit working papers.Chapter 3 Internal controlsArticle 9It is the accountin

8、g responsibility of the entitys management to establish sound internal controls. The relevant internal controls should generally:(1) ensure that business activities are conducted in accordance with appropriate authorization;(2) ensure that all transactions and events are promptly recorded at the cor

9、rect amount, in the appropriate accounts and in the proper accounting period, to enable preparation of financial statements in accordance with the relevant requirements of the accounting standards;(3) ensure that access to and handling of assets and records are permitted only in accordance with appr

10、opriate authorization; and(4) ensure that assets recorded are reconciled with the physical assets at regular intervals.Article 10When determining the reliability of internal controls, the CPA should maintain professional scepticism and pay adequate attention to the following inherent limitations of

11、internal controls:(1) The design and implementation of internal controls are restricted by the principle of cost and benefit;(2) Internal controls tend to be directed at routine business activities;(3) Even perfectly designed internal controls may not operate effectively due to human carelessness, d

12、istraction, mis-judgement and the misunderstanding of instructions;(4) Internal controls may be circumvented through the collusion by relevant persons with parties inside or outside the entity;(5) Internal controls may be circumvented when a person responsible for exercising an internal control abus

13、es that responsibility or submits to external pressure; and(6) Internal controls may deteriorate or become ineffective due to changes in the operating environment and the nature of the business.Article 11When preparing the audit plan, the CPA should understand the design and operating conditions of

14、the entitys internal controls.When determining the nature, timing and extent of the audit procedures which should be performed to understand the internal controls, the CPA should mainly consider the following factors:(1) the size and business complexity of the entity;(2) the type and complexity of t

15、he entitys data processing system;(3) audit materiality;(4) the type of relevant internal controls;(5) the documentation of relevant internal controls; and(6) the result of the assessment of inherent risk.Article 12In understanding the internal controls, the CPA should make reasonable use of previou

16、s audit experience. With regard to significant internal controls, generally the CPA may also perform the following procedures:(1) make enquiries of the entitys relevant persons and inspect the relevant internal control documentation;(2) inspect the documents and records generated by the internal con

17、trols;(3) observe the entitys business activities and the operating conditions of the internal controls; and(4) choose certain typical transactions and events and perform walkthrough tests on them.Article 13The CPA should obtain and understanding of the control environment sufficient to assess the a

18、ttitudes, awareness and actions of the entitys management regarding internal controls and their importance.Major factors affecting the control environment include:(1) philosophy, methods and style of management;(2) organisational structure and methods of assigning authority and responsibility; and(3

19、) the control system.Article 14The CPA should obtain an understanding of the accounting system sufficient to identify and understand:(1) the major classes of transactions and activities of the entity;(2) how major classes of transactions and activities are initiated;(3) significant supporting docume

20、nts, accounting records and items in the financial statements; and(4) the accounting and financial reporting process for significant transactions and events.Article 15The CPA should obtain an understanding of the following major control procedures sufficient to determine the relevant audit procedure

21、s reasonably:(1) the authorisation of transactions;(2) the assignment of responsibility;(3) the control of supporting documents and records;(4) access to assets and use of records; and(5) any independent checking.Article 16Internal audit is an important component of the entitys control system. The C

22、PA should consider the following factors when studying and evaluating the quality of the internal audit work to determine whether to rely on the results of the internal audit work:(1) the independence of the internal auditors;(2) the experience and competence of the internal auditors;(3) the nature,

23、 timing and extent of the internal audit procedures;(4) the sufficiency and appropriateness of the audit evidence obtained by the internal auditors; and(5) the merit placed on the internal audit work by the management.Article 17The CPA may use various methods such as narrative descriptions, question

24、naires, check lists, flow charts etc. to understand and evaluate internal controls and should include them in the audit working papers.Article 18The CPA should inform the entitys management of material internal control weaknesses identified during the audit. If necessary, a management letter may be

25、issued.Chapter 4 Audit riskArticle 19In developing the overall audit plan, the CPA should assess inherent risk at the financial statement level. Inherent risk refers to the susceptibility of an account balance, or class of transactions, to material misstatements or omissions, either individually or

26、when aggregated with misstatements or omissions in other account balances or classes of transactions, assuming that there were no relevant internal controls.Article 20In developing the detailed audit plan, the CPA should consider the impact of the assessment of inherent risk on the material account

27、balances or classes of transactions at the assertion level, or directly assume that inherent risk is high for the assertion.Article 21The CPA should exercise professional judgement reasonably and consider the following factors when assessing inherent risk:(1) the integrity and competence of manageme

28、nt;(2) any changes in management, especially the financial staff;(3) any unusual pressures on management;(4) the nature of business;(5) the circumstances and factors affecting the industry in which the entity operates;(6) financial statement items likely to be susceptible to misstatements;(7) the co

29、mplexity of important transactions and events which might require using the work of an expert;(8) the degree of estimation and judgement involved in determining account balances;(9) the susceptibility of assets to loss or misappropriation;(10) the occurrence of unusual or complex transactions during

30、 the accounting period, particularly near the accounting period end; and(11) the susceptibility of transactions and events to omissions in the routine accounting process.Article 22After understanding the internal controls and assessing inherent risk, the CPA should make a preliminary assessment of c

31、ontrol risk, at the assertion level, for each material account balance or class of transactions. Control risk refers to the possibility that a misstatement or omission that could occur in an account balance or class of transactions, either individually or when aggregated with misstatements or omissi

32、ons in other account balances or classes of transactions, will not be prevented, detected or corrected by the internal controls.Article 23The CPA should assess the control risk of material account balances or classes of transactions at a high level, for some or all assertions, when one or more of th

33、e following situations occurs:(1) the entitys internal controls are not effective;(2) it is difficult for the CPA to assess the effectiveness of internal controls; or(3) the CPA does not plan to perform compliance tests.Article 24When making a preliminary assessment of control risk for a financial s

34、tatement assertion, the CPA should not assess the control risk at a high level when:(1) relevant internal controls are likely to prevent, detect or correct material misstatements or omissions; and(2) the CPA plans to perform compliance tests.Article 25if the CPA plans to rely on the internal control

35、s, he should perform compliance procedures to assess the control risk. The lower the preliminary assessment of control risk, the more evidence the CPA should obtain to show that internal controls are suitably designed and operating effectively.Article 26The CPA may perform the following compliance p

36、rocedures:(1) inspection of documents supporting transactions and events;(2) enquiries about, and observation of, internal control operations which leave no audit trail; and(3) reperformance of relevant internal control procedures.Article 27When one or more of the following situations occurs, the CP

37、A may directly perform substantive procedures without performing compliance tests:(1) the relevant internal controls do not exist;(2) even though the relevant internal controls exist, the CPA, through preliminary study, discovers that the internal controls do not operate effectively; or(3) complianc

38、e tests require more work than the reduction of substantive tests that would have been achieved by performing compliance tests.Article 28Based on the results of the compliance tests, the CPA should assess whether the design and operation of the internal controls are in line with the conclusion drawn

39、 from the preliminary assessment of control risk. If there are discrepancies, the assessed level of control risk should be revised and the nature, timing and extent of substantive procedures should be modified accordingly.Article 29In a continuing engagement, the CPA may make use of the information

40、relating to the study and evaluation of internal controls obtained in prior periods, but will need to update it.Article 30The CPA should understand whether the internal controls were applied consistently throughout the accounting period being audited. If there were obvious changes, the CPA should co

41、nsider testing them separately.Article 31If compliance tests have been performed in the interim audit, the CPA, before deciding to rely entirely on their results, should consider the following factors to obtain further audit evidence for the period between interim period end and final period end:(1)

42、 the conclusion drawn from the compliance tests in the interim audit;(2) the length of the remaining period after the interim audit;(3) any changes in internal controls after the interim audit;(4) the nature and amount of the transactions and activities which occurred after the interim audit; and(5)

43、 the substantive procedures to be performed.Article 32Before concluding the audit, the CPA should, based on the results of substantive tests and other audit evidence, make a final assessment of the control risk and check whether it is in line with the conclusion drawn from the preliminary assessment

44、 of the risk. If not, the CPA should consider whether additional relevant audit procedures should be performed.Article 33As control risk and inherent risk are related, the CPA should make an overall assessment of inherent risk and control risk, and use the result as the basis for the assessment of d

45、etection risk.Detection risk refers to the possibility that substantive tests will not detect a misstatement or omission that exists in an account balance or class of transactions that could be material, either individually or when aggregated with misstatements or omissions in other account balances

46、 or classes of transactions.The assessment of inherent risk and control risk has a direct impact on the assessment of detection risk. For higher levels of inherent risk and control risk, the CPA should perform more detailed substantive procedures and should also consider their nature, timing and ext

47、ent to reduce the detection risk to an acceptable level.Article 34Regardless of the result of the assessment of inherent risk and control risk, the CPA should perform substantive tests on all material account balances or classes of transactions.Article 35If, after performing relevant audit procedure

48、s, the CPA still believes that detection risk regarding an assertion for a material account balance or class of transactions cannot be reduced to an acceptable level, the CPA should express a qualified opinion or a disclaimer of opinion.Article 36The internal controls in small businesses are usually weaker,

展开阅读全文
相关资源
相关搜索

当前位置:首页 > 管理文献 > 企业管理

本站为文档C TO C交易模式,本站只提供存储空间、用户上传的文档直接被用户下载,本站只是中间服务平台,本站所有文档下载所得的收益归上传人(含作者)所有。本站仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。若文档所含内容侵犯了您的版权或隐私,请立即通知淘文阁网,我们立即给予删除!客服QQ:136780468 微信:18945177775 电话:18904686070

工信部备案号:黑ICP备15003705号© 2020-2023 www.taowenge.com 淘文阁