Internal Audit and Other Assurance Engagements
Other Engagements
Internal Audit and Other Assurance Engagements
Syllabus tag: KASNEB CPA | Intermediate Level | CA24 Auditing and Assurance | Topic 10 Internal Audit and Other Assurance Engagements
Lesson objectives
By the end of this topic, you will be able to:
- Distinguish internal audit from external audit
- Explain what safeguards internal audit independence
- State when an external auditor may use the work of internal audit
- Describe the main types of internal audit assignment
- Distinguish audit, review, agreed-upon procedures and compilation
Why this matters
The two audit functions are constantly confused. They differ in who appoints them, who they report to, what they examine and what they conclude — and an examiner will test each of those.
Internal and external audit compared
| Internal audit | External audit | |
|---|---|---|
| Appointed by | The company — audit committee or board | The shareholders |
| Reports to | Management and the audit committee | The shareholders |
| Objective | Evaluate and improve risk management, control and governance | Express an opinion on the financial statements |
| Scope | Set by management; as wide as they wish | Set by statute and ISAs |
| Required? | Voluntary for most entities | Statutory |
| Independence | Of the activities reviewed | Of the company entirely |
The essential distinction: internal audit is independent of the operations it reviews but not of the company; external audit is independent of the company itself. That single sentence answers most exam questions comparing the two.
Safeguarding internal audit independence
An internal auditor is an employee, so independence has to be constructed:
- Reporting to the audit committee, not to the finance director
- The audit committee approving appointment, removal and remuneration
- Internal auditors not auditing work they previously performed
- Unrestricted access to records, assets and personnel
- No operational responsibility for the areas reviewed
Where internal audit reports to the finance director, its ability to report adversely on the finance function is compromised. That reporting line is the first thing to examine.
Types of internal audit assignment
- Operational audits — economy, efficiency and effectiveness: the three Es
- Compliance audits — adherence to laws, regulations and policies
- Financial audits — reliability of internal financial information
- IT audits — controls over systems and data
- Value for money audits — common in the public sector
- Fraud investigations
- Risk management reviews
Value for money is examined through the three Es: economy (obtaining resources at least cost), efficiency (output per unit of input) and effectiveness (achieving the intended objectives). Note that a body can be economical and efficient while failing entirely on effectiveness, by doing the wrong thing cheaply and quickly.
Using the work of internal audit
The external auditor may use internal audit's work, but remains solely responsible for the opinion. That responsibility is never shared or reduced.
Before relying on the work, evaluate:
- The objectivity of the function — its reporting line and status
- The competence of its staff — qualifications, training, experience
- Whether a systematic and disciplined approach is applied, including quality control
- The level of risk in the area concerned
The greater the risk and the more judgement involved, the less reliance is appropriate. Work on significant risks and matters of judgement should be performed by the external auditor.
Direct assistance — using internal auditors to perform procedures under the external auditor's direction — is permitted in some jurisdictions and prohibited in others, and where allowed requires evaluation of threats and prohibits use on significant risks.
The external auditor must re-perform some of the work relied upon. Reading the internal audit report is not evaluation.
:::checkpoint An external auditor proposes to rely on internal audit's testing of revenue recognition, which the team has identified as a significant risk. Explain why this is inappropriate even where the internal audit function is objective and competent. :::
Levels of assurance engagement
| Engagement | Work performed | Conclusion | Assurance |
|---|---|---|---|
| Audit | Tests of control and substantive procedures | Positive opinion | Reasonable |
| Review | Mainly enquiry and analytical procedures | Negative conclusion | Limited |
| Agreed-upon procedures | Only the procedures specified by the client | Factual findings only | None |
| Compilation | Assembling information from client data | No conclusion | None |
Two of these provide no assurance at all, and saying so plainly is the examinable point.
Agreed-upon procedures report what was found, not what it means. The practitioner states the findings and expressly gives no opinion, because the client chose the procedures and only the client can judge whether they were sufficient. The report is restricted to the parties who agreed them.
Compilation uses the accountant's expertise to assemble information, not to verify it. The report states clearly that no assurance is expressed.
Other engagements
Prospective financial information — forecasts and projections. The practitioner can never give reasonable assurance about the future. The conclusion covers whether the assumptions are a reasonable basis and whether the information is properly prepared on those assumptions.
Due diligence for an acquisition, and forensic engagements for litigation or fraud, are investigations rather than assurance engagements, and their scope is set by the terms of engagement rather than by ISAs.
:::checkpoint A client asks your firm to perform agreed-upon procedures on its inventory count and wants the resulting report sent to its bank as evidence the inventory figure is reliable. Explain why this is a problem. :::