Download presentation
1
ISSAI 400 Compliance Audit Subcommittee
Fundamental Principles of Compliance Audit Compliance Audit Subcommittee Vilnius, Lithuania 19th-20th of September 2012 Mona Paulsrud, CAS harmonization team
2
ISSAI 400 presentation The approach of the CAS harmonization team to ISSAI 400 Structure and contents of ISSAI 400
3
CAS’ contribution to the developmentof public sector auditing
4
The purpose and authority of ISSAI 400
ISSAI 400 Principles of Compliance Audit ISSAI 4000 Compliance Audit Guidelines Objective of principles compared to standards. Framework: audit theory of high level adjusted to the public sector context of the SAI. The coherent story of Compliance Audit – adjusted to both ISSAI 4100 and ISSAI 4200.
5
The dual approach – a Compliance Audit document of similar level
6
AIM OF ISSAI 400 To provide a coherent, high level framework of Compliance Audit in the public sector, covering both ISSAI 4100 and ISSAI 4200.
7
CAS’ approach in developing ISSAI 400
Financial audit – the cradle of the audit profession and audit theory Defines basic concepts and terminology of auditing
8
Compliance Audit – The extended perspective
How far should we strech?
9
CAS’ strategy in developing ISSAI 400
Build upon existing contents and terminology of the ISSAI 4000 series Create a coherent story of Compliance Audit High, generic level of concepts and principles Dual approach – updated IFAC terminology How far should we strech?
10
ISSAI 400 – Basic structure
Introduction Purpose and authority of ISSAI 400 The nature of Compliance Audit } Story of CA Elements of Compliance Audit } Audit theory Principles of Compliance Audit } Requirements Making reference to the ISSAIs Same structure as ISSAI 100 – long discussions in the project of structure and sequence.
11
The nature of Compliance Audit
The independent asessment of whether a particular subject matter is in compliance with established criteria.
12
The nature of Compliance Audit
Origins of cash flow in the public sector are the decisions and premises of the legislature.
13
Public sector context of the SAI
THE LEGISTALURE THE EXECUTIVE THE ENTITY AUTHORITIES AUTHORITIES This is what it looks like in Norway – you can each draw one for your country. Is how the SAI relates its practice to its public sector context and identifies the elements of the audit. AUTHORITIES Compliance Audit
14
The elements of Compliance Audit
Authorities Subject matter The three parties To be defined by the SAI at an institutional level in order to connect their audits to the public sector context and choose wich standard to follow. SAI ISSAI 4100 or ISSAI 4200?
15
Authorities and criteria
Structure and contents of authorities – premises of what can be measured. Authorities = the sources of audit criteria Regularity and propriety.
16
SUBJECT MATTER Underlying subject matter Subject matter information
Shift in terminology in ISAE 3000 – what the ISAE 3000 gives us.
17
The three parties of Compliance Audit
THE LEGISLATURE INTENDED USER PRACTITIONER ELEMENTS OF AN AUDIT RESPONSIBLE PARTY The reason why this needs to be defined: The definition and use of each audit term depends on this. Example: ”materiality” depends om who is the user. The executive THE GOVERNMENT THE SAI
18
Assurance in Compliance Audit
Attest engagements Direct reporting audits Forms of assurance Reasonable assurance Limited assurance Levels of assurance
19
Forms of reporting Long form reporting Short form reporting Findings
Opinions & various forms of conclusions
20
Variations of Compliance Audit
SUBJECT MATTER ASSURANCE APPROACH FORMS OF REPORTING AUDIT EVIDENCE
21
The elements of Compliance Audit
Authorities Subject matter The three parties To be defined by the SAI at an institutional level in order to connect their audits to the public sector context and choose wich standard to follow. SAI ISSAI 4100 or ISSAI 4200?
22
Principles of Compliance Audit
Principles: at the level of an individual audit Planning Gathering evidence Concluding and reporting Explain the workload coming up for CAS.
23
Principles of Compliance Audit
Principles = «should statments» Able to fit all variations of Compliance Audit. To be translated into «shall statements» when level 4 is to be used as authoritative standards. Explain the workload coming up for CAS.
24
PRINCIPLES TO BE APPLIED IN CONDUCTING A COMPLIANCE AUDIT
General principles: to be considered prior to comencement and at more than one point throughout the audit process 2. Principles related to the audit process: related to steps in the audit process itself
25
General principles Legal basis Ethics and independence Quality control
Audit team management and skills Audit risk Materiality Professional judgment and skeptisim Documentation Communication The legal basis – is the specific principle of Compliance Audit distinguishing this from other audit types. The other concepts – coming from the cradle – some given an extended contents, i.e. relationship to ISSAI 100.
26
Audit team management and skills
… includes an understanding of and practical experience of the type of audit being undertaken; an understanding of the applicable standards and authorities; an understanding of the entity’s legal basis and operations; and the ability and experience to exercise professional judgement. ISSAI 400 para. 54
27
inherent risk - control risk - detection risk
Audit risk Audit risk in Compliance Audit covers both attestation and direct engagements. inherent risk - control risk - detection risk The degree to which these components are relevant to the audit is affected by the nature of the subject matter, whether the audit is performed as a reasonable assurance or limited assurance audit and whether it is a direct or an attestation engagement. ISSAI 400 para. 56 Not well adjusted in existing ISSAI 4100/4200 – split audit risk and risk assessment in ISSAI 400
28
Materiality Value Context Nature
29
Materiality Materiality in Compliance Audit consists of both quantitative and qualitative factors. … An essential part of determining materiality is to consider the importance of compliance for the intended users and the consequences of potential or identified instances of non-compliance. ISSAI 400 para. 58 Explains why the definition of users in the elements is essential.
30
Principles related to the audit process
1. Planning and designing a compliance audit Subject matter and criteria Audit scope Understanding the entity Risk assessment Understaning internal control and control environment Risk of fraud Audit strategy and audit plan 2. Gathering audit evidence 3. Evaluating audit evidence, concluding and reporting Evaluating audit evidence and forming conclusions Reporting Follow up
31
Planning and designing a compliance audit
2. Audit scope 3. Understanding the entity 4. Risk assessment 5. Internal control and control environment 6. Risk of fraud 7. Audit strategy and plan 1. Subject matter and criteria Why designing is important
32
Gathering audit evidence
Sufficient and appropriate audit evidence.
33
Evaluating audit evidence, concluding and reporting
Evaluating audit evidence and forming conclusions Reporting Follow up
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.