内部控制和审计风险(英文版)_第1页
内部控制和审计风险(英文版)_第2页
内部控制和审计风险(英文版)_第3页
内部控制和审计风险(英文版)_第4页
内部控制和审计风险(英文版)_第5页
已阅读5页,还剩14页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

n更多企业学院: 中小企业管理全能版183套讲座+89700份资料总经理、高层管理49套讲座+16388份资料中层管理学院46套讲座+6020份资料国学智慧、易经46套讲座人力资源学院56套讲座+27123份资料各阶段员工培训学院77套讲座+ 324份资料员工管理企业学院67套讲座+ 8720份资料工厂生产管理学院52套讲座+ 13920份资料财务管理学院53套讲座+ 17945份资料销售经理学院56套讲座+ 14350份资料销售人员培训学院72套讲座+ 4879份资料内部控制与审计风险(英)Chapter 1 General provisionsArticle 1This standard is prepared in accordance with the General Independent Auditing Standard to establish standards for Certified Public Accountants (“CPAs”) on the study and evaluation of an entitys internal controls in the audit of financial statements, to assess audit risk, to improve audit efficiency and to ensure a high standard of professional work.Article 2The term “internal controls” in this standard refers to the policies and procedures formulated and implemented by an entity with a view to ensuring the efficient conduct of the business activities, safeguarding assets, preventing, detecting and correcting error and fraud, and ensuring the truthfulness, legitimacy and completeness of accounting information.Internal controls include the control environment, accounting systems and control procedures.Article 3The term “audit risk” in this standard refers to the possibility of the CPA expressing an inappropriate audit opinion after performing an audit, when the financial statements contain material misstatements or omissions. Audit risk includes inherent risk, control risk and detection risk.Article 4Unless otherwise specified, CPAs should refer to this standard in performing audit work other than the audit of financial statements.Chapter 2 General principlesArticle 5When preparing the audit plan, the CPA should study and evaluate the entitys internal controls.Article 6The CPA should perform compliance tests on any internal controls, which are intended to be relied upon, to determine the impact on the nature, timing and extent of the substantive tests.Article 7The CPA should maintain professional scepticism, apply professional judgement reasonably to assess the audit risk and to design and perform relevant audit procedures in order to reduce the audit risk to an acceptable level.Article 8The CPA should document the work carried out and the results of the study and evaluation of the internal controls and the assessment of the audit risk in the audit working papers.Chapter 3 Internal controlsArticle 9It is the accounting responsibility of the entitys management to establish sound internal controls. The relevant internal controls should generally:(1) ensure that business activities are conducted in accordance with appropriate authorization;(2) ensure that all transactions and events are promptly recorded at the correct amount, in the appropriate accounts and in the proper accounting period, to enable preparation of financial statements in accordance with the relevant requirements of the accounting standards;(3) ensure that access to and handling of assets and records are permitted only in accordance with appropriate authorization; and(4) ensure that assets recorded are reconciled with the physical assets at regular intervals.Article 10When determining the reliability of internal controls, the CPA should maintain professional scepticism and pay adequate attention to the following inherent limitations of internal controls:(1) The design and implementation of internal controls are restricted by the principle of cost and benefit;(2) Internal controls tend to be directed at routine business activities;(3) Even perfectly designed internal controls may not operate effectively due to human carelessness, distraction, mis-judgement and the misunderstanding of instructions;(4) Internal controls may be circumvented through the collusion by relevant persons with parties inside or outside the entity;(5) Internal controls may be circumvented when a person responsible for exercising an internal control abuses that responsibility or submits to external pressure; and(6) Internal controls may deteriorate or become ineffective due to changes in the operating environment and the nature of the business.Article 11When preparing the audit plan, the CPA should understand the design and operating conditions of the entitys internal controls.When determining the nature, timing and extent of the audit procedures which should be performed to understand the internal controls, the CPA should mainly consider the following factors:(1) the size and business complexity of the entity;(2) the type and complexity of the entitys data processing system;(3) audit materiality;(4) the type of relevant internal controls;(5) the documentation of relevant internal controls; and(6) the result of the assessment of inherent risk.Article 12In understanding the internal controls, the CPA should make reasonable use of previous audit experience. With regard to significant internal controls, generally the CPA may also perform the following procedures:(1) make enquiries of the entitys relevant persons and inspect the relevant internal control documentation;(2) inspect the documents and records generated by the internal controls;(3) observe the entitys business activities and the operating conditions of the internal controls; and(4) choose certain typical transactions and events and perform walkthrough tests on them.Article 13The CPA should obtain and understanding of the control environment sufficient to assess the attitudes, awareness and actions of the entitys management regarding internal controls and their importance.Major factors affecting the control environment include:(1) philosophy, methods and style of management;(2) organisational structure and methods of assigning authority and responsibility; and(3) the control system.Article 14The CPA should obtain an understanding of the accounting system sufficient to identify and understand:(1) the major classes of transactions and activities of the entity;(2) how major classes of transactions and activities are initiated;(3) significant supporting documents, accounting records and items in the financial statements; and(4) the accounting and financial reporting process for significant transactions and events.Article 15The CPA should obtain an understanding of the following major control procedures sufficient to determine the relevant audit procedures reasonably:(1) the authorisation of transactions;(2) the assignment of responsibility;(3) the control of supporting documents and records;(4) access to assets and use of records; and(5) any independent checking.Article 16Internal audit is an important component of the entitys control system. The CPA should consider the following factors when studying and evaluating the quality of the internal audit work to determine whether to rely on the results of the internal audit work:(1) the independence of the internal auditors;(2) the experience and competence of the internal auditors;(3) the nature, timing and extent of the internal audit procedures;(4) the sufficiency and appropriateness of the audit evidence obtained by the internal auditors; and(5) the merit placed on the internal audit work by the management.Article 17The CPA may use various methods such as narrative descriptions, questionnaires, check lists, flow charts etc. to understand and evaluate internal controls and should include them in the audit working papers.Article 18The CPA should inform the entitys management of material internal control weaknesses identified during the audit. If necessary, a management letter may be issued.Chapter 4 Audit riskArticle 19In developing the overall audit plan, the CPA should assess inherent risk at the financial statement level. Inherent risk refers to the susceptibility of an account balance, or class of transactions, to material misstatements or omissions, either individually or when aggregated with misstatements or omissions in other account balances or classes of transactions, assuming that there were no relevant internal controls.Article 20In developing the detailed audit plan, the CPA should consider the impact of the assessment of inherent risk on the material account balances or classes of transactions at the assertion level, or directly assume that inherent risk is high for the assertion.Article 21The CPA should exercise professional judgement reasonably and consider the following factors when assessing inherent risk:(1) the integrity and competence of management;(2) any changes in management, especially the financial staff;(3) any unusual pressures on management;(4) the nature of business;(5) the circumstances and factors affecting the industry in which the entity operates;(6) financial statement items likely to be susceptible to misstatements;(7) the complexity of important transactions and events which might require using the work of an expert;(8) the degree of estimation and judgement involved in determining account balances;(9) the susceptibility of assets to loss or misappropriation;(10) the occurrence of unusual or complex transactions during the accounting period, particularly near the accounting period end; and(11) the susceptibility of transactions and events to omissions in the routine accounting process.Article 22After understanding the internal controls and assessing inherent risk, the CPA should make a preliminary assessment of control risk, at the assertion level, for each material account balance or class of transactions. Control risk refers to the possibility that a misstatement or omission that could occur in an account balance or class of transactions, either individually or when aggregated with misstatements or omissions in other account balances or classes of transactions, will not be prevented, detected or corrected by the internal controls.Article 23The CPA should assess the control risk of material account balances or classes of transactions at a high level, for some or all assertions, when one or more of the following situations occurs:(1) the entitys internal controls are not effective;(2) it is difficult for the CPA to assess the effectiveness of internal controls; or(3) the CPA does not plan to perform compliance tests.Article 24When making a preliminary assessment of control risk for a financial statement assertion, the CPA should not assess the control risk at a high level when:(1) relevant internal controls are likely to prevent, detect or correct material misstatements or omissions; and(2) the CPA plans to perform compliance tests.Article 25if the CPA plans to rely on the internal controls, he should perform compliance procedures to assess the control risk. The lower the preliminary assessment of control risk, the more evidence the CPA should obtain to show that internal controls are suitably designed and operating effectively.Article 26The CPA may perform the following compliance procedures:(1) inspection of documents supporting transactions and events;(2) enquiries about, and observation of, internal control operations which leave no audit trail; and(3) reperformance of relevant internal control procedures.Article 27When one or more of the following situations occurs, the CPA may directly perform substantive procedures without performing compliance tests:(1) the relevant internal controls do not exist;(2) even though the relevant internal controls exist, the CPA, through preliminary study, discovers that the internal controls do not operate effectively; or(3) compliance tests require more work than the reduction of substantive tests that would have been achieved by performing compliance tests.Article 28Based on the results of the compliance tests, the CPA should assess whether the design and operation of the internal controls are in line with the conclusion drawn from the preliminary assessment of control risk. If there are discrepancies, the assessed level of control risk should be revised and the nature, timing and extent of substantive procedures should be modified accordingly.Article 29In a continuing engagement, the CPA may make use of the information relating to the study and evaluation of internal controls obtained in prior periods, but will need to update it.Article 30The CPA should understand whether the internal controls were applied consistently throughout the accounting period being audited. If there were obvious changes, the CPA should consider testing them separately.Article 31If compliance tests have been performed in the interim audit, the CPA, before deciding to rely entirely on their results, should consider the following factors to obtain further audit evidence for the period between interim period end and final period end:(1) the conclusion drawn from the compliance tests in the interim audit;(2) the length of the remaining period after the interim audit;(3) any changes in internal controls after the interim audit;(4) the nature and amount of the transactions and activities which occurred after the interim audit; and(5) the substantive procedures to be performed.Article 32Before concluding the audit, the CPA should, based on the results of substantive tests and other audit evidence, make a final assessment of the control risk and check whether it is in line with the conclusion drawn from the preliminary assessment of the risk. If not, the CPA should consider whether additional relevant audit procedures should be performed.Article 33As control risk and inherent risk are related, the CPA should make an overall assessment of inherent risk and control risk, and use the result as the basis for the assessment of detection risk.Detection risk refers to the possibility that substantive tests will not detect a misstatement or omission that exists in an account balance or

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论