Skip to content
SmartStudy

Internal Audit and Other Assurance Engagements

Other Engagements

Internal Audit and Other Assurance Engagements

Syllabus tag: KASNEB CPA | Intermediate Level | CA24 Auditing and Assurance | Topic 10 Internal Audit and Other Assurance Engagements

Lesson objectives

By the end of this topic, you will be able to:

  • Distinguish internal audit from external audit
  • Explain what safeguards internal audit independence
  • State when an external auditor may use the work of internal audit
  • Describe the main types of internal audit assignment
  • Distinguish audit, review, agreed-upon procedures and compilation

Why this matters

The two audit functions are constantly confused. They differ in who appoints them, who they report to, what they examine and what they conclude — and an examiner will test each of those.

Internal and external audit compared

Internal auditExternal audit
Appointed byThe company — audit committee or boardThe shareholders
Reports toManagement and the audit committeeThe shareholders
ObjectiveEvaluate and improve risk management, control and governanceExpress an opinion on the financial statements
ScopeSet by management; as wide as they wishSet by statute and ISAs
Required?Voluntary for most entitiesStatutory
IndependenceOf the activities reviewedOf the company entirely

The essential distinction: internal audit is independent of the operations it reviews but not of the company; external audit is independent of the company itself. That single sentence answers most exam questions comparing the two.

Safeguarding internal audit independence

An internal auditor is an employee, so independence has to be constructed:

  • Reporting to the audit committee, not to the finance director
  • The audit committee approving appointment, removal and remuneration
  • Internal auditors not auditing work they previously performed
  • Unrestricted access to records, assets and personnel
  • No operational responsibility for the areas reviewed

Where internal audit reports to the finance director, its ability to report adversely on the finance function is compromised. That reporting line is the first thing to examine.

Types of internal audit assignment

  • Operational audits — economy, efficiency and effectiveness: the three Es
  • Compliance audits — adherence to laws, regulations and policies
  • Financial audits — reliability of internal financial information
  • IT audits — controls over systems and data
  • Value for money audits — common in the public sector
  • Fraud investigations
  • Risk management reviews

Value for money is examined through the three Es: economy (obtaining resources at least cost), efficiency (output per unit of input) and effectiveness (achieving the intended objectives). Note that a body can be economical and efficient while failing entirely on effectiveness, by doing the wrong thing cheaply and quickly.

Using the work of internal audit

The external auditor may use internal audit's work, but remains solely responsible for the opinion. That responsibility is never shared or reduced.

Before relying on the work, evaluate:

  • The objectivity of the function — its reporting line and status
  • The competence of its staff — qualifications, training, experience
  • Whether a systematic and disciplined approach is applied, including quality control
  • The level of risk in the area concerned

The greater the risk and the more judgement involved, the less reliance is appropriate. Work on significant risks and matters of judgement should be performed by the external auditor.

Direct assistance — using internal auditors to perform procedures under the external auditor's direction — is permitted in some jurisdictions and prohibited in others, and where allowed requires evaluation of threats and prohibits use on significant risks.

The external auditor must re-perform some of the work relied upon. Reading the internal audit report is not evaluation.

:::checkpoint An external auditor proposes to rely on internal audit's testing of revenue recognition, which the team has identified as a significant risk. Explain why this is inappropriate even where the internal audit function is objective and competent. :::

Levels of assurance engagement

EngagementWork performedConclusionAssurance
AuditTests of control and substantive proceduresPositive opinionReasonable
ReviewMainly enquiry and analytical proceduresNegative conclusionLimited
Agreed-upon proceduresOnly the procedures specified by the clientFactual findings onlyNone
CompilationAssembling information from client dataNo conclusionNone

Two of these provide no assurance at all, and saying so plainly is the examinable point.

Agreed-upon procedures report what was found, not what it means. The practitioner states the findings and expressly gives no opinion, because the client chose the procedures and only the client can judge whether they were sufficient. The report is restricted to the parties who agreed them.

Compilation uses the accountant's expertise to assemble information, not to verify it. The report states clearly that no assurance is expressed.

Other engagements

Prospective financial information — forecasts and projections. The practitioner can never give reasonable assurance about the future. The conclusion covers whether the assumptions are a reasonable basis and whether the information is properly prepared on those assumptions.

Due diligence for an acquisition, and forensic engagements for litigation or fraud, are investigations rather than assurance engagements, and their scope is set by the terms of engagement rather than by ISAs.

:::checkpoint A client asks your firm to perform agreed-upon procedures on its inventory count and wants the resulting report sent to its bank as evidence the inventory figure is reliable. Explain why this is a problem. :::