Most disputes between an organisation and its auditor arise from confusing the roles. Clarity here saves a long argument at year end.
1 Who is responsible for what?
| Party | Responsibility |
|---|---|
| Management | Preparing the statements under the applicable framework · designing and operating internal control · preventing and detecting fraud · providing the auditor with information |
| Those charged with governance (the board / audit committee) | Overseeing the financial reporting process · monitoring the auditor’s independence · discussing their findings and observations |
| The external auditor | Obtaining reasonable assurance and expressing an opinion · communicating with those charged with governance · complying with the standards and the code of ethics |
| Internal audit | Evaluating the effectiveness of governance, risk and controls internally — a function separate from the external auditor |
A common confusion
Asking the auditor to prepare the journal entries or draft the statements and then audit them. That destroys their independence, because they would be auditing their own work — and the law and the professional code of ethics may prohibit it.
2 The auditor’s independence
Independence has two sides: independence in fact — genuine impartiality of mind — and independence in appearance: that nothing exists that would lead a reasonable party to doubt that impartiality.
Self-interest
Large fees from a single client
Self-review
Auditing work the firm itself prepared
Advocacy
Arguing the client’s case
Familiarity
A long relationship or a family tie
Intimidation
A threat to terminate the engagement
Five threats to independence — assessed and mitigated, or the engagement is declined
- Usual safeguards: rotating the engagement partner, an independent quality review, limits on non-assurance services, and a clear acceptance policy.
- Typical prohibitions: a financial interest in the client, a loan from them, or a relative employed in a position that influences the statements.
- Fees: must not create a dependency that impairs impartiality, and must not be contingent on the outcome of the opinion.
3 The auditor and fraud
Responsibility for preventing and detecting fraud rests with management and those charged with governance. The auditor is responsible for obtaining reasonable assurance that the statements are free of material misstatement whether arising from fraud or error. They must:
- Maintain professional scepticism throughout the audit, however favourable past impressions have been.
- Presume a fraud risk in revenue recognition and address it, unless it is rebutted with justification.
- Test unusual manual journal entries and the possibility of management override of controls.
- Report: inform the appropriate level of management and those charged with governance, and comply with any statutory requirement to report irregularities.
Fraud usually occurs when three elements come together:
| Element | Meaning | Example |
|---|---|---|
| Incentive or pressure | A financial need, or a target that must be met | A bonus tied to the year’s profit |
| Opportunity | A weak control that allows the act and its concealment | One employee both approves and executes |
| Rationalisation | Convincing oneself the act is acceptable | “I’ll put it back later” · “They owe me this” |
An organisation usually cannot control the incentive or the rationalisation, but it can close off the opportunity — and that is where controls and segregation of duties earn their keep.
4 Working with internal audit
The external auditor may use the work of internal audit if they evaluate its objectivity, competence and methodology and find them appropriate. But that transfers no responsibility: the opinion remains the auditor’s alone.
Chapter 1 summary
- Management prepares the statements and prevents fraud, those charged with governance oversee, and the auditor expresses the opinion.
- Independence in fact and in appearance, with five threats addressed through safeguards.
- An auditor may not audit work they prepared themselves.
- The auditor seeks reasonable assurance that the statements are free of material misstatement from fraud or error.
- Opportunity is the side of the fraud triangle the organisation can close off with controls.
5 Test your understanding
Three quick questions
Pick the answer you believe is correct and you will see the result immediately.
1. An organisation asked its auditor to prepare the closing entries and then audit the statements. What is the threat?
They would be auditing work they prepared themselves, so they cannot be impartial in evaluating it.
2. Who bears primary responsibility for preventing fraud in an organisation?
Prevention and detection are internal responsibilities; the auditor seeks reasonable assurance about material misstatement.
3. The auditor relied on the work of internal audit. Who bears responsibility for the opinion?
Using the work of others transfers no responsibility; the opinion remains the auditor’s in full.