SAS 117: The New Auditing Standard on Compliance May 11, 2010 Eric Formberg, Plante & Moran, PLLC Randy Roberts, AZ Auditor General Office 1.

Slides:



Advertisements
Similar presentations
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin.
Advertisements

Assurance Services Independent professional services that “improve the quality of information, or its context, for decision makers” Assurance service encompass.
Obtaining Clients Submit a proposal
Internal Control in a Financial Statement Audit
1 AUDIT AND AUDIT RESOLUTION Peg Rosenberry, Director of Grants Management Claire Moreno, Audit Liaison, Office of Grants Management 9/18/2009 AMERICORPS.
2 Session Objectives Increase participant understanding of effective financial monitoring based upon risk assessments of sub-grantees Increase participant.
AICPA SAS 112: Case studies and Intermediate Reporting Issues Presented by Frank Crawford, CPA Crawford & Associates, P.C.
Intermediate Single Audit Issues: Planning, Performing and Reporting NASACT Audio Conference April 2, 2008 Presented by Frank Crawford, CPA Crawford &
The Managing Authority –Keystone of the Control System
Using Internal Control to Manage Risk Mary C. Braun, CPA, CGFM Management Concepts, Incorporated.
Vision: A strong and capable civil society, cooperating and responsive to Cambodias development challenges 1.
Chapter 13 Overall Audit Plan and Audit Program
Human Capital Investment Programme Disability Activation Project (DACT) WELCOME Support Workshop Thursday 7 th February
Additional Assurance Services: Other Information
Audit Reports Chapter 3.
Internal Control–Integrated Framework
LACPA ISA Presentation
OMB Circular A133 Audits of States, Local Governments, and Non-Profit Organizations 1 Departmental Research Administrators Training Track.
Section 404 Audits of Internal Control and Control Risk
Internal Control and Control Risk
©2003 Prentice Hall Business Publishing, Auditing and Assurance Services 9/e, Arens/Elder/Beasley Audit of the Capital Acquisition and Repayment.
Overall Audit Plan and Audit Program
Chapter 14 Fraud Risk Assessment.
Review of Introduction to Auditing
Auditing A Risk-Based Approach To Conducting A Quality Audit
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Internal Control in a Financial Statement Audit
Section 404 Audits of Internal Control and Control Risk
SAS 112: The New Auditing Standard Jim Corkill Controller Accounting Services & Controls.
Auditing Standards IFTA\IRP Audit Guidance Government Auditing Standards (GAO) Generally Accepted Auditing Standards (GAAS) International Standards on.
Impact of the New Clarity Standards on Governmental Audits Presented by Beila Sherman, CPA and Enrique Llerena, CPA.
Reports on Audited Financial Statements
Auditing Internal Control over Financial Reporting
Audit and Fiscal Oversight Responsibilities VAVRINEK, TRINE, DAY & CO., LLP December 15,2010.
The CPA Profession Chapter 2 By Arens et. al. Learning Objective 1 Describe the nature of CPA firms, what they do, and their structure.
New Auditing Standards Laurie Ball, CPA Swenson Advisors, LLP (Murrieta) Audit Director Accounting Day May 12, 2008.
INTERNAL CONTROL OVER FINANCIAL REPORTING
Chapter 5 Internal Control over Financial Reporting
Internal Control in a Financial Statement Audit
NO FRAUD LEFT BEHIND The Effect of New Risk Assessment Auditing Standards on Schools Runyon Kersteen Ouellette.
Internal Control in a Financial Statement Audit
SAS Update GFOA Western Pa – January 2008 Presented by Rob Lent, CPA, CGFM.
1 The Impact of SAS 112 on Governmental Financial Statement Audits GAQC Member Conference Call January 4, 2007 Presented by Chuck Landes, CPA.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 8.1 Control Risk,
Chapter 8: Client Risk Profile and Documentation
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Audit Planning and Types of Audit Tests Chapter Five.
Chapter 6 Internal Control in a Financial Statement Audit Copyright © 2014 McGraw-Hill Education. All rights reserved. No reproduction or distribution.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
Chapter 06 Audit Planning, Understanding the Client, Assessing Risks, and Responding McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc.
Copyright © 2007 Pearson Education Canada 1 Chapter 11: Overall Audit Plan and Audit Program.
©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control Risk Chapter.
1 Overview of PCAOB Auditing Standard No. 5 An Audit of Internal Control Over Financial Reporting that is Integrated with an Audit of Financial Statements.
Audit Reports Chapter 3. Audit Reports What is an audit report? Different reporting guidelines exist depending on the type of company upon which the auditor.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Improving Compliance with ISAs Presenters: Al Johnson & Pat Hayle.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
 Planning an audit of cost statements, records and other related documents is considered necessary to ensure achievement of audit objectives with available.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Presented by Frank Crawford, CPA Chris Pembrook, CPA, MBA, CGAP, Cr.FA Crawford & Associates, PC, Oklahoma City, OK
Internal Control in a Financial Statement Audit
Internal Control Evaluation: Assessing Control Risk
Meeting Audit Requirements
Update on the Latest Developments in Government Auditing Standards
PLANNING, MATERIALITY AND ASSESSING THE RISK OF MISSTATEMENT
Reports on Audited Financial Statements
Internal and Governmental Financial Auditing and Operational Auditing
Internal control - the IA perspective
Update on the Developments in Government Auditing Standards
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
Presentation transcript:

SAS 117: The New Auditing Standard on Compliance May 11, 2010 Eric Formberg, Plante & Moran, PLLC Randy Roberts, AZ Auditor General Office 1

What This Session Will Cover What the new Compliance Audit SAS will require How a compliance audit differs from the financial statement portion of an audit Insight on how to implement the compliance audit requirements Questions 2

What the New Standard Will Do Supersedes AU section 801, Compliance Auditing Considerations... (SAS 74) Uses new clarity format Effective for audits of periods ending June 15, 2010 and later 3

What the New Standard Will Do Address some of the recommendations in the PCIEs study on single audit quality Clarify its applicability Update for changes in the compliance audit environment Clarify that, and which, generally accepted auditing standards apply to the compliance portion of an audit Identify auditor requirements and provide guidance that are unique to a compliance audit Update the elements to be included in an auditors report on compliance for current standards 4

New Compliance SAS – Content Intro and Applicability Objectives Definitions Requirements and Guidance 5

This new SAS applies when all of the following are required: Generally accepted auditing standards (GAAS) Financial audit standards for Government Auditing Standards A governmental audit requirement that requires the auditor to express an opinion on compliance Applicability 6

Applicability Examples Requirement Single Audit (A-133) HUD Guide audit State Grant State law to determine that gas tax monies spent for road purposes Bond monies spent per debt covenants Type of engagement Compliance audit (AU801) Compliance attestation (AT601) Agreed-upon procedure (AT101) In connection with (AU c) 7

Objectives Obtain sufficient appropriate audit evidence to form an opinion and report at the level specified by the government audit requirement on whether the entity complied in all material respects with the applicable compliance requirements Identify audit and reporting requirements specified in the governmental audit requirement that are supplementary to GAAS and GAGAS, if any, and perform procedures to address those requirements. 8

Definitions Terms Unique to Compliance Audit Environment Applicable Compliance Requirements Governmental Audit Requirement Compliance Audit Terms Adapted for Compliance Audit Environment from Financial Audit Standards Audit Risk of Noncompliance Risk of Material Noncompliance Significant Deficiency in Internal Control over Compliance Material Weakness in Internal Control over Compliance 9

Definitions – Examples Applicable compliance requirements Risk of material noncompliance All laws and regulations a govt. follows Laws and regulations related to a program to be audited Laws and regulations that could have a material effect on compliance with a program Compliance = F/S = materially accurate 10

Requirements Adapt and apply AU sections to compliance objectives Appendix has the laundry list, but whatre the key ones? Materiality Risk assessment process Gotta do the tests – internal controls, tests of compliance, analytical procedures – sufficient to give an opinion Reporting Documentation 11

Materiality Materiality set based on governmental audit requirement, GAAS and GAGAS supplement how Different levels of materiality Different nature Unique qualitative & quantitative factors Opinion on program Compliance Require- ments Findings 12

Risk Assessment Procedures Gaining an understanding First, which programs, which requirements? Inquiries, past experience, federal regulations What are the risk factors? Newness, complexity, knowledge, nature of services, level of oversight, past external and internal reports, management's corrective actions What are the internal controls? Five elements of COSO for compliance objectives 13

Risk of Material Noncompliance Factors relative to the applicable compliance requirements when assessing this risk: Complexity Susceptibility to noncompliance Length of time the entity has been following them The auditors observations about the entitys compliance in prior years The potential effect on the entity of noncompliance The degree of judgment involved to adhere to them The auditors assessment of the risks of material misstatement in the financial statement audit Design and implementation of relevant internal controls 14

Matching Controls with Related Risks Controls over compliance – Controls with a purpose! Value of control dependent on compliance risk it offsets Risk assessment process Identify compliance risk Identify control(s) that reduce risk Determine if risk is reduced sufficiently (a relatively low level) Do deficiencies exist? Impact on compliance tests? DOCUMENT YOUR THINKING! Are tests of control effectiveness necessary? Governmental audit requirement (A-133) Reduce overall audit effort to issue an opinion 15

Match Game ControlCompliance Susie approves the reimbursement request The grant department budget is approved annually by the Board Cash needs projections for grants are updated monthly by the business office Harry checks the suspended and debarred website for each contract The grants director obtains certified payrolls every 2 weeks from the contractor Fixed assets are tagged Pete keeps a calendar showing due dates for grant reports 16

Performing Further Procedures Pervasive risks – how its different than a F/S audit Compliance: Trip across what affects multiple programs/ requirements; Respond to overall risk F/S: Look at both overall and assertion level; Respond to risks at both Examples: Centralized recordkeeping with poor internal controls Tone at the Top suggests lack of concern for compliance Overall grants management centered on one individual Decentralized operation with no monitoring 17

Performing Further Procedures Tests of compliance Tests of details, tests of transactions Tests of internal control, if: Risk assessment is based on expectation that controls are operating effectively Substantive procedures alone wont provide sufficient appropriate audit evidence, or Required by governmental audit requirement Portions of AU 318 related to evidence of operating effectiveness obtained in prior audits are not applicable to compliance audits 18

Performing Further Procedures New chapter about sampling in Government Auditing Standards and A-133 Audit Guide Perform any supplementary audit requirements e.g., specific procedures to identify major programs e.g., assess reasonableness of summary schedule of prior audit findings Where analytical procedures fit in For planning As tests of compliance Other evidence 19

How Does Fraud Fit In? It does!.. Focus - Impact of Fraud Risks on noncompliance Fraud Triangle in a compliance environment Example Areas of Concern Funding pressure Maximizing reimbursement Job security Program or Participant Utilization Compliance world often a separate part of the entity Power of the journal entry! SAS 99 documentation requirements apply Hot Topic………ARRA concerns 20

Forming an Opinion Do you have enough relevant evidence to determine whether an entity materially complied? Consider: The frequency of the noncompliance The nature of the noncompliance The adequacy of the entitys system for monitoring compliance Whether any identified noncompliance resulted in likely questioned costs that are material to the government program 21

Forming an Opinion Making the decision about material noncompliance Is it big enough (per the governmental audit requirement [GAR]) to be: A finding? Material to the requirement? Material to the program? Look to the GAR – could be noncompliance, internal control deficiencies, questioned costs $ or % for monetary transactions (e.g., cost principles, cash management); # or % for nonmonetary (e.g., eligibility, reporting) Significance of requirement to program; degree to which requirement was not complied with 22

Subsequent events Financial statement audits versus compliance audit Financial statement audit Focus on event affecting F/S Procedures looking after period for signs of F/S misstatement or future events to disclose in current F/S Procedures applied to transactions of subsequent period Procedures include looking for significant events Compliance audit Focus on events affecting noncompliance Procedures looking after period for signs of noncompliance during the period No procedures applied to compliance in subsequent period Procedures focused on inquiries and info reported in subsequent period Explanatory paragraph in auditors report for subsequent period whoppers 23

Reporting and Reports Reporting Opinion on compliance Other required reporting per the governmental audit requirement (e.g., instances of noncompliance, internal control deficiencies, questioned costs) Reports Report on compliance Report on internal controls Can be combined 24

Documentation All of AU section 339 applies Key areas: Risk assessment procedures Response to risk of material noncompliance Materiality levels used and the basis on which they were determined Can there be more than one? How should it be applied to specific requirements? Compliance with supplemental audit requirements No expectation to document how the auditor adapted and applied every applicable AU section 25

Reissuing a Compliance Report Hopefully, this never happens to you! Explanatory paragraph describing reason for reissuance or report and changes made Dating Update if all programs affected Dual date if not all programs affected A need to reissue auditor-prepared documents referred to in the compliance report is considered to be a reissuance of the report itself 26

AICPA Audit Resources Auditing & Accounting Guides will continue to be important for meeting standards for Single Audits Government Auditing Standards and Circular A- 133 State & Local Governments 27

Questions ????? 28