Welcome to the Blueprint: Designing the Audit Approach!
Hello there! Welcome to one of the most critical chapters in your auditing journey. Think of designing an audit approach as creating a customized roadmap for a treasure hunt. If you don't plan your route carefully, you might miss the treasure (or in our case, the financial errors!) or spend way too much time looking in the wrong places.
In this chapter, we will learn how auditors decide what to test, when to test it, and how much testing is enough. Don't worry if this seems a bit abstract at first—we'll break it down into simple steps that make perfect sense.
1. The Big Picture: Strategy vs. Plan
Before we start digging into the details, we need to understand the difference between the Audit Strategy and the Audit Plan. They sound similar, but they serve different purposes.
The Overall Audit Strategy: This is the "Wide Lens" view. It sets the scope, timing, and direction of the audit. It’s like deciding you want to go on a vacation to Japan in the Spring and setting a budget.
- Key focus: What resources do we need? Which high-level areas are risky?
The Detailed Audit Plan: This is the "Zoomed In" view. It’s much more specific than the strategy. It lists the exact procedures (the "how-to") that the audit team will follow. This is like your day-to-day itinerary in Japan, listing exactly which trains to take and which temples to visit.
- Key focus: The Nature, Extent, and Timing (N.E.T.) of audit procedures.
Key Takeaway: The Strategy comes first and guides the Plan. You can't have a detailed plan without a general strategy!
2. The Concept of Materiality (The "Does it Matter?" Filter)
Auditors don't check every single cent. Why? Because it would take forever and cost too much! Instead, we use Materiality.
What is Materiality? Information is material if omitting it or misstating it could influence the economic decisions of the users of the financial statements. In simple terms: Would this error make a bank change its mind about giving the company a loan? If yes, it's material.
How do we set it?
1. Overall Materiality: Based on a benchmark (e.g., 5% of Profit Before Tax or 1% of Total Assets).
2. Performance Materiality: This is a lower amount than overall materiality. We set this "buffer" to reduce the risk that the total of many small, uncorrected errors exceeds the overall materiality.
3. Specific Materiality: Sometimes, even a tiny error matters (e.g., related party transactions or director's pay). We set lower limits for these sensitive areas.
Quick Review:
- High Risk = Lower Materiality (we need to be more careful).
- Low Risk = Higher Materiality (we can afford to be a bit more relaxed).
3. The Audit Risk Model
This is the heart of audit planning. To design the right approach, we must understand the Audit Risk Model:
\( Audit Risk = Inherent Risk \times Control Risk \times Detection Risk \)
1. Inherent Risk (IR): The risk that an account balance is wrong just because of the nature of the business, before considering any controls.
Example: A jewelry store has high IR for inventory because diamonds are small and easy to steal.
2. Control Risk (CR): The risk that the company's own internal "safety nets" (controls) fail to catch an error.
Example: If the jewelry store doesn't have a security guard or CCTV, the Control Risk is high.
Note: IR and CR together are called the Risk of Material Misstatement (RMM). These are the client's risks. The auditor cannot change them; we can only assess them.
3. Detection Risk (DR): This is the risk that the auditor fails to find a mistake. This is the only part of the equation the auditor can control!
- If RMM is High, the auditor must make DR Low (by doing more work).
- If RMM is Low, the auditor can accept a Higher DR (by doing less work).
Did you know? There is an inverse relationship between RMM and Detection Risk. When one goes up, the other must go down to keep the total Audit Risk at an acceptably low level.
4. Choosing the Approach: Substantive vs. Combined
Once we know the risks, we choose our "battle strategy." There are two main approaches:
A. The Substantive Approach
In this approach, the auditor does not rely on the company's internal controls. Instead, they check the numbers and transactions directly.
- When to use: When controls are weak, non-existent, or it’s just faster to check the numbers than to test the controls.
- What it looks like: Checking 100 bank statements or counting every piece of equipment physically.
B. The Combined Approach
Here, the auditor tests the company's controls first. If the controls work well, the auditor can do less substantive testing.
- When to use: When the company has strong internal controls or a very high volume of transactions (where checking every number is impossible).
- Steps:
1. Test of Controls (ToC) to see if the "safety net" works.
2. If ToC is successful, do reduced Substantive Procedures.
Common Mistake to Avoid: Many students think that if controls are great, we don't need to do any substantive testing. Wrong! ISA 330 requires auditors to perform some substantive procedures for all material items, regardless of how good the controls are.
5. The N.E.T. of Audit Procedures
When you are designing the specific steps in your audit plan, always think of N.E.T.:
Nature: What kind of test? (e.g., Are we observing a stock take? Are we recalculating interest? Are we asking management questions?)
Extent: How much testing? (e.g., Are we checking 10 invoices or 100? Larger sample sizes are needed when risk is high.)
Timing: When do we do it? (e.g., Do we test at the year-end or do some "interim" work 3 months before the year-end?")
Memory Aid: Think of a fishing NET. If you want to catch more fish (errors), you need a bigger Nature (better tests), a wider Extent (more samples), and the right Timing (when the fish are biting!).
6. Responding to Significant Risks
Some risks are "special" and need extra attention. These are called Significant Risks.
Examples: Complex transactions, high degree of subjectivity (like estimating future lawsuits), or transactions with a high risk of fraud.
Key Approach: For significant risks, you cannot rely solely on analytical procedures (comparing last year to this year). You must perform specific substantive procedures that directly address that risk.
Summary and Quick Checklist
Before you move on, make sure you can answer these questions:
1. Do I understand that Strategy is the "Big Picture" and the Plan is the "Details"?
2. Can I explain why we use Materiality to save time and focus on what matters?
3. Do I remember the Audit Risk formula and the inverse relationship between RMM and Detection Risk?
4. Do I know when to use a Substantive vs. Combined approach?
5. Can I define N.E.T.?
Final Encouragement: Audit planning is all about logic. If you identify a specific risk (e.g., the company's computers were stolen), your audit approach should logically respond to it (e.g., go and physically count the remaining computers). You've got this!