Essence of Audit and Assurance
The purpose of this blog post is to explain the essence of assurance at a high level and in terms a lay person can understand. Primarily, I want to explain the key aspects of an audit; but to do that, it helps to understand the other two forms of assurance. For certified public accountants (CPAs) and chartered accountants (CAs) as they are called in the United States, Canada, and in many other jurisdictions; there tend to be three standard levels of assurance provided over general purpose financial statements:
- Compilation or No Assurance: The CPA/CA assembles financial information into the form of a financial statements but does not verify information. A compilation is essentially financial statement preparation with disclosure that no assurance is provided.
- Review or Limited Assurance: The CPA/CA performs very limited inquiries and analytical procedures to conclude whether anything appears materially misstated. This provides moderate or limited assurance.
- Audit or Reasonable Assurance: The CPA/CA, who must be independent of the reporting economic entity, creates a systematic plan, must follow audit standards, performs detailed substantive testing, evaluates and tests internal controls, gathers evidence all per that systematic plan, uses auditor judgment to reach a conclusion, and issues an opinion on whether the financial statements are fairly stated. This provides relatively high level or "reasonable assurance"; the strongest level available.
An audit is an independent verification of the information provided in a general purpose financial statement to determine whether that information has been fairly presented. In essence, an auditor is a neutral third party who examines the reporting entity’s records, processes, and supporting documentation to assess whether the financial statements provide can be relied upon to provide an accurate and trustworthy picture of the entity’s financial position and financial performance per some published financial reporting framework.
To do this, auditors systematically evaluate several key elements using prescribed professional standards. They begin by identifying the risks which are areas where unintentional errors or fraud could occur. Next, auditors examine the entity’s internal controls, the rules and safeguards designed to prevent those problems. Internal controls mitigate or are countermeasures to those risks. Auditors then review the control activities that put those controls into practice and gather evidence such as documents, approvals, reconciliations, analysis, and system logs. Finally, the auditor test that evidence, verify claims, ask questions, and then form an opinion on whether the financial statements are fairly presented in all material respects. Once their work is complete, the auditor issues an opinion communicating their conclusion about the reliability of the financial statements.
That is a high level overview of what happens in an audit. Let me now dig into a few important areas where more detail would be helpful.
Audit and assurance professional standards are published by the American Institute of Certified Public Accountants (AICPA), International Auditing and Assurance Standards Board (IAASB), Public Company Accounting and Oversite Board (PCAOB), and other such audit standards setters.
Governance, risk, and compliance (GRC) frameworks like COSO, ISACA (COBIT), ISO, NIST, the IIA, and OCEG all provide GRC frameworks that help enterprises design, operate, and improve the governance, risk, and regulatory compliance reporting and control environments that professional audit standards require and that audit professionals must rely on.
But OCEG is somewhat unique because it integrates all GRC disciplines into one holistic, coherent model, rather than focusing on just one area.
Open Compliance and Ethics Group (OCEG) is a global nonprofit thinktank that pioneered GRC. OCEG enhances culture and integrates governance, risk, and compliance to help organizations drive principled performance. OCEG is the only one offering a fully integrated, interdisciplinary GRC framework. OCEG provides integrated frameworks for compliance, governance, and risk management that helps enterprises design, operate, and improve the governance, risk, and control environment that professional audit standards require and audit professionals rely on.
OCEG provides an XBRL taxonomy which covers key areas of audit and assurance: risk, control, and control activities. But OCEG does this from the perspective of the enterprise; not from the perspective of the auditor. For example, the XBRL taxonomy provides nothing related to audit evidence.
Risk
Risk relates to the possibility of error, harm, or misstatement that threatens objectives. In terms of audit and assurance, this includes three areas of risk:
- Inherent risk: is the risk that is specific to the nature of a process or a type of business event
- Control risk: is the risk that a control implemented to mitigate or act as a countermeasure to that risk fails
- Detection risk: is the risk the auditor misses the problem
Risk is the driver. Everything downstream exists because a risk exists.
Control
A control is a designed safeguard intended to reduce, mitigate, or act as a countermeasure to potential risk. Controls are policy-level ideas, they are abstract, they are stable, controls are part of an organizations designed processes and workflows.
Examples of a control are, "All journal entries must be independently reviewed." or "Access must be restricted to authorized users."
Control Activity
The control activity is the actual behavior of the employees of an enterprise that makes the control real. Control activities are concrete, observable, performed by people or systems, variable across time. Examples of control activities are a manager approving a journal entry, the IT department removing inactive users from a system in compliance with company policy, the HR department reviewing payroll changes per company policy.
Evidence
Evidence is the artifacts produced by control activities. Evidence includes things like workflow approvals, system logs, reconciliations, reports, timestamps, audit trails, and other documentation. Evidence is the bridge between operations and assurance.
Audit Step or Audit Test
An audit step is the evaluation of evidence to determine whether controls and control activities are in fact effective and being operated consistent with policy. An audit step or audit test includes things like design effectiveness of an internal control, operating effectiveness of a control activity, substantive accuracy. Audit steps/tests reduce detection risk by validating whether controls actually do exist, whether control activities actually do occur, and therefore whether evidence is reliable and a control can or cannot be relied upon.
Updated Risk
Updated risk is the new understanding of risk after the audit evidence is collected via the audit steps/tests which are part of the systematic audit plan. Updated risk reflects residual risk, new risks discovered, weaknesses in controls, failures in activities, gaps in evidence, changes in the environment. This updated risk feeds back into new controls, modified controls, new control activities, enhanced monitoring, improved or otherwise enhanced/adjusted audit procedures.
Auditor Judgement
Auditor judgment is the step where the auditor evaluates the sufficiency and appropriateness of evidence, considers whether risks have been adequately addressed, determines whether misstatements might exist, decides whether possible mistakes/misstatements are potentially material, forms a professional opinion on fair presentation of a financial statement taken as a whole.
This is the moment where the auditor’s expertise, skepticism, and reasoning come together. Auditor judgment is not mechanical, it is not an algorithm. Auditor judgment is a professional judgment based on evidence, standards, and risk; but also the training, skills, and experience of the certified public accountant or chartered accountant.
Audit Evidence Graph; Preservation of Record of Auditor Judgement
Today's audit bundles tend to be sets of documents that humans are supposed to read. Tomorrow's "audit bundles" will be machine interpretable graphs with related models that (a) are preserving a record of the auditor judgment and (b) it makes audit computable, traceable, improvable, and partially automatable.
Human judgement is still very much at the center. But you also have a computable audit logic engine.
Right now, audit is a human‑driven reasoning process. But once you build an appropriate model which is machine interpretable and structure information per that model; each step is represented as a graph node with strongly typed relationships, you can:
- automatically trace how a risk connects to controls
- automatically trace how controls connect to control activities
- automatically trace how control activities generate evidence
- automatically trace how evidence supports audit steps/audit tests
- automatically trace how audit steps/audit tests inform auditor judgment
- automatically trace how auditor judgment updates risk
This turns the audit from a narrative into a computable chain of causality. Further, the record of auditor judgment is preserved. That preserved record of auditor judgement; if global open industry standards are used; can be queried and analyzed across different audit engagements and new insights and wisdom can be gleaned to better understand and improve that chain of causality, that closed loop. A virtuous cycle is created
* * *
What I have covered above relates to an audit of a general purpose financial statement by an independent third party auditor because that is what I understand and know about. But these same ideas apply to special purpose financial statements, supplemental information, internal audits, compilations and reviews created by bookkeepers and other non CPAs/CAs, and other financial accounting use cases. These ideas can also be applied to management accounting, cost accounting, tax accounting, other comprehensive basis of accounting (OCBOA); governmental accounting, not-for-profit accounting and other such use cases.
This combines five things (isolated silos) together into one "platform" or "ecosystem" (not sure what to call it). Those five things are:
- the closing book used to prepare a financial statement (replaces the 800 fragmented electronic spreadsheets used by the average Fortune 1000 company)
- the actual general purpose financial statement itself
- the financial reporting framework used to specify what the general purpose financial statement must look like
- the audit bundle used to collect and document audit evidence and summarize auditor judgement in the form of what amounts to a book
- financial analysis models used to create period comparisons for things like variance analysis, entity comparisons for things like benchmarking or financial analysis, and Dupont analysis and unlevered discounted cash flows analysis used for analyzing investments
Additional Information:
- Accounting & Audit by Design (A&AD) Framework
- Auditology: The Science of Audit Improvement
- International Organization of Supreme Audit Institutions (INTOSAI)
- Committee of Sponsoring Organizations (COSO)
- Statements on Auditing Standards (United States)
- Generally Accepted Auditing Standards (GAAS)
- Audit
- Semantics of Accountability
Comments
Post a Comment