Welcome to Reporting on Compliance!
In the world of auditing, we spend a lot of time looking at numbers to make sure they are "fairly presented." But sometimes, users of the audit report (like banks or the government) care about more than just the numbers—they want to know if the company is following the rules. Whether it’s a bank loan agreement or a government grant, "compliance" is all about staying within the lines. In this chapter, we will learn how auditors report on whether an entity is obeying those rules. Don't worry if this seems a bit technical at first; we will break it down into simple pieces!
1. Compliance in a Financial Statement Audit (AU-C 806)
Imagine you are auditing a company's financial statements. While you are doing your work, the company asks you to also provide a report on whether they followed certain rules in a contractual agreement (like a loan covenant) or a regulatory requirement. This is very common!
How it Works
To report on compliance in this way, you must be the auditor of the company's financial statements. You cannot just swoop in and only do the compliance part under this specific standard. Think of it as a "sidecar" to the main audit motorcycle.
Negative Assurance
This is a key term! For this type of report, the auditor usually provides Negative Assurance. This doesn't mean something bad! It means the auditor says: "Nothing came to our attention that caused us to believe the entity failed to comply."
Important Note: You can only give this negative assurance if:
1. You expressed an unmodified or qualified opinion on the financial statements.
2. No instances of noncompliance were identified.
What if you gave an Adverse Opinion or Disclaimer?
If the main audit report was an Adverse Opinion (the books are a mess) or a Disclaimer (you couldn't finish the audit), you cannot provide negative assurance on compliance. It wouldn't make sense to trust the compliance report if you can't even trust the numbers!
Quick Review:
- Context: Financial Statement Audit.
- Assurance Type: Negative Assurance ("Nothing came to our attention").
- Restriction: The report is usually restricted to the specific parties involved (like the company and the bank).
2. Attestation Engagements for Compliance (AT-C 315)
Sometimes, a client needs a more "heavy-duty" report on compliance that isn't tied directly to the financial statement audit. This falls under Attestation Standards (SSAE). There are two main types of engagements here:
A. Compliance Examination
An examination is the highest level of assurance (like an audit). The auditor’s goal is to express an opinion on whether the entity complied with requirements in all material respects.
- Analogy: This is like a full home inspection. The inspector looks everywhere to give a definitive "thumbs up" or "thumbs down."
- Requirement: Management must provide a written assertion (a statement saying "we complied with the rules").
B. Agreed-Upon Procedures (AUP)
In an AUP, the auditor and the client agree on specific steps the auditor will take. The auditor doesn't give an opinion or a conclusion; they just list the procedures performed and the findings.
- Analogy: This is like a grocery list. You go to the store, check off the items, and tell the client exactly what you found for each item. You don't say if the whole meal was good; you just report on the ingredients.
Common Mistake: Students often confuse these two. Remember: Examination = Opinion; Agreed-Upon Procedures = Findings.
3. Government Auditing Standards (The "Yellow Book")
When an entity receives government money, they often fall under GAGAS (Generally Accepted Government Auditing Standards), also known as the Yellow Book. This is "regular auditing" but with a few extra layers of protection for the taxpayers.
Reporting Requirements
Under the Yellow Book, the auditor’s report must include:
1. A statement on whether the financial statements are fair (Standard Audit).
2. A report on Internal Control over Financial Reporting.
3. A report on Compliance with laws, regulations, and provisions of contracts or grant agreements.
Did you know? Unlike a private audit, Yellow Book reports require the auditor to describe the scope of their testing of internal controls and compliance, even if they didn't find any problems!
4. The Single Audit Act (Uniform Guidance)
This is the "Big Boss" of compliance audits. It applies to entities (like non-profits or local governments) that spend \( \$750,000 \) or more in federal financial assistance in a single year.
\n\nThe Two Main Objectives
\n1. Audit of the financial statements.\n
2. Audit of Compliance for "Major Programs."
How to Pick "Major Programs"
\nThe auditor doesn't have to check every single dollar. They use a risk-based approach to pick which federal programs to test. They look at:\n
- The amount of money spent.\n
- How complex the program is.\n
- Whether the program has had problems in the past.
What gets reported?
\nThe auditor must report "Questioned Costs." These are costs that the auditor thinks might not follow the rules. In a Single Audit, any questioned cost over \( \$25,000 \) must be specifically identified in the report.
Memory Aid: Think of the Single Audit as a "Two-for-One" deal. You get an audit of the Financials and an audit of the Federal Rules at the same time.
Summary and Key Takeaways
Compliance reporting can feel like an alphabet soup (SSAE, GAGAS, OMB), but here are the "Must-Know" points for the CPA exam:
1. Financial Statement Sidecar (AU-C 806): Provides negative assurance. Only allowed if the main audit was clean (unmodified/qualified).
2. Attestation (SSAE): Can be an Examination (Opinion) or Agreed-Upon Procedures (Findings).
3. Yellow Book (GAGAS): Requires reporting on Internal Control and Compliance, regardless of whether problems were found.
4. Single Audit: Triggered at \( \$750,000 \) in federal spending. Focuses on Major Programs and reporting Questioned Costs over \( \$25,000 \).
Keep pushing forward! Auditing compliance is all about understanding which set of rules you are playing by. Once you identify the "standard" (SAS, SSAE, or Yellow Book), the reporting requirements fall right into place.