Welcome to Planning and Risk Assessment!

Hello! Welcome to one of the most critical areas of the Advanced Audit and Assurance (AAA) syllabus. If you have ever felt overwhelmed by the sheer volume of information in an audit case study, you are not alone. Planning is where we make sense of that information. Think of this chapter as the "GPS" of the audit—without it, we’d be driving aimlessly. By the end of these notes, you will understand how to set the direction of the audit and identify exactly where the "danger zones" (risks) are.

1. The Big Picture: Audit Strategy vs. Audit Plan

Before we dive into the numbers, we need a roadmap. In AAA, you must distinguish between the Audit Strategy and the Audit Plan. These are often confused, but they serve different purposes.

The Audit Strategy (The "What")

The Strategy sets the scope, timing, and direction of the audit. It’s like planning a massive road trip across the country. You decide which cities to visit, your total budget, and how many drivers you need.

Key things decided here:
Scope: Which locations or subsidiaries are we auditing?
Timing: When are the deadlines? When is the final audit?
Direction: What are the high-level risks we already know about?

The Audit Plan (The "How")

The Plan is much more detailed. It’s the turn-by-turn directions on your GPS. It describes the nature, timing, and extent of the specific audit procedures the team will perform.

Quick Tip: The Strategy is created first, and the Plan is developed based on that strategy. They are "living documents," meaning they can change if we find something unexpected during the audit!

Key Takeaway: Strategy = Big Picture (Scope/Timing). Plan = Detailed Instructions (Procedures).

2. Materiality: When Does an Error Matter?

In auditing, we don't look for every single penny. We look for "material" errors. Materiality is the threshold above which an error or omission would change the mind of someone reading the financial statements.

How do we calculate it?

Materiality is a matter of professional judgment, but we usually use these common benchmarks as a starting point:

Profit before tax: 5% – 10%
Total assets: 1% – 2%
Revenue: 0.5% – 1%

Types of Materiality

1. Overall Materiality: This is for the financial statements as a whole.
2. Performance Materiality: This is a lower amount (e.g., 75% of overall materiality). We use this to plan our work so that the total of all small, undetected errors doesn't accidentally add up to a huge material error.
3. Specific Materiality: Sometimes, a small amount is material because of its nature. For example, a $1 error in director’s bonuses is usually material because it’s a legal requirement to show it correctly.

\n\n

Analogy: Imagine you are buying a car for $20,000. If the seller forgot to tell you about a $5 scratch, you probably wouldn't care (Immaterial). But if they forgot to tell you the engine is missing (Material), you definitely wouldn't buy it!

Key Takeaway: Materiality isn't just about size; it's about whether the information matters to the person using the accounts.

3. Assessing the Risk of Material Misstatement (ROMM)

This is the "meat" of the AAA exam. You will often be asked to "evaluate the risks of material misstatement." To do this, you need to understand the Audit Risk Model.

The Audit Risk Formula

\( Audit Risk = Risk of Material Misstatement (ROMM) \times Detection Risk \)

Where:
\( ROMM = Inherent Risk \times Control Risk \)

Breaking it Down:

1. Inherent Risk: The risk that an account balance is wrong just because of its nature.
Example: A jewelry shop has high inherent risk for "Inventory" because diamonds are easy to steal and hard to value.

2. Control Risk: The risk that the company’s internal systems (like passwords or security guards) fail to prevent or catch an error.
Example: If the jewelry shop doesn't have a safe or a security camera, control risk is high.

3. Detection Risk: This is the risk that WE (the auditors) fail to find the error. This is the only part of the risk model the auditor can actually change. If ROMM is high, we must decrease Detection Risk by doing more work!

Mnemonic - "ICE":
Inherent (Nature of the business)
Control (Internal systems)
Errors we missed (Detection)

Common Mistake to Avoid: Don't confuse Business Risk with Audit Risk. Business risk is the risk the company goes bankrupt (e.g., a competitor launches a better product). Audit risk is the risk we give the wrong opinion on the financial statements.

Key Takeaway: If the client is risky (Inherent/Control), we must work harder (lower Detection risk) to keep the overall Audit Risk low.

4. Using Analytical Procedures at the Planning Stage

Analytical procedures involve looking at the relationships between numbers. At the planning stage, we use them to spot "red flags" that might indicate a risk of misstatement.

Common Ratios to Know:

Gross Profit Margin: \( (Gross Profit / Revenue) \times 100 \)
Current Ratio: \( Current Assets / Current Liabilities \)
Inventory Days: \( (Inventory / Cost of Sales) \times 365 \)

How to use them in an exam:
Don't just calculate the number. Tell the examiner why it matters.
Bad Answer: "The gross profit margin went from 20% to 25%."
Good Answer: "The gross profit margin increased from 20% to 25%. This is unexpected as the industry is in a recession. This suggests a risk that revenue is overstated or costs are understated."

Key Takeaway: Numbers tell a story. If the story doesn't make sense, there is a high risk of material misstatement.

5. Quick Review Checklist

Before you move on, make sure you can answer these:
1. Can I explain the difference between Strategy and Plan?
2. Do I know the three benchmarks for calculating materiality?
3. Can I identify Inherent vs. Control risks in a case study?
4. Do I remember that Detection Risk is the only one the auditor controls?

Don't worry if this seems tricky at first! Risk assessment is a skill that gets better with practice. The more case studies you read, the faster you will be at spotting those "red flags." You've got this!