Thursday, 29 December 2011

Topic 11: Prepare Engagement Work Program

Engagement work program is a document that lists the procedures to be followed during an engagement, designed to achieve the engagement plan.

For assurance engagement - work programs must include the procedures for identifying, analyzing, evaluating and documenting information during the engagement. The work program must be approved prior to its implementation and any adjustments approved promptly.

For consulting engagement - work programs may vary in form and content depending upon the nature of the engagement.

Engagement work plan should be approved in writing by the CAE or designee prior to the commencement of engagement work, where practicable.

Topic 10: Establish Adequate Planning and Supervision of the Engagement

The extent of supervision required will depend on the proficiency and experience of internal auditors and the complexity of the engagement. The CAE has over responsibility for supervising the engagement, whether performed by or for the internal audit activity, but may designate appropriately experienced members of the internal audit activity to perform the review. Appropriate evidence of supervision is documented and retained.

Supervision is a process that begins with planning and continues throughout the engagement. The process includes:

  • Ensuring designated auditors collectively possess the required knowledge, skills, and other competencies to perform the engagement.
  • Providing appropriate instructions during the planning of the engagement and approving the engagement program.
  • Ensuring the approved engagement program is completed unless changes are justified and authorized.
  • Determining engagement working papers adequately support engagement observations, conclusions and recommendations.
  • Ensuring engagement communications are accurate, objective, clear, concise, constructive and timely.
  • Ensuring engagement objectives are met
  • Providing opportunities for developing internal auditors' knowledge skills and other competencies. 
On tactical level, planning and supervision also involves:
  • Deadlines
  • Travel arrangements
  • On-site logistics
  • Assignments
  • Team communication and supervision
  • Team development

Topic 9: Determine the Level of Staff and Resources for the Engagement

Internal auditors must determine appropriate and sufficient resource to achieve engagement objectives based on an evaluation of the nature and complexity of each engagement, time constraints and availability of resources.

The success of an engagement is often judged by:

  • Achievement to the level of standards
  • Fulfillment of engagement objectives
  • Completion within budget

Topic 8: Determine Engagement Procedures

Engagement procedures are drafted to ensure successful attainment of engagement objectives, Engagement procedures must be relevant to the selected objectives. A procedure may be applicable to the internal audit as a whole, but if it is erroneously applied to an objective, the result will be irrelevant.

Audit evidence refers to facts used to support audit opinions, conclusions and recommendations which can be physical (pictures), documentary (letters, memo), representational (testimonials) or analytical (graph comparison).

Types of legal evidence includes:

  • Best evidence - also referred as primary evidence and is generally documentary
  • Secondary evidence - is inferior primary evidence. Oral testimony and written summaries. 
  • Direct evidence - a fact without requiring presumptions or interference. E.g eyewitness
  • Conclusive evidence - leads to only one conclusions.
  • Circumstantial evidence - proves an intermediate fact from which a primary fact can be logically inferred. 
  • Corroborative evidence - supplements evidence already given and tends to support it.
The internal auditor should always bear in mind the mandatory injunction in the Code of Ethics honor the confidentiality requirements of the owner of audited data. 


Topic 7: Consider the Potential for Fraud When Planning an Engagement

Internal auditors must have sufficient knowledge to evaluate the risk of fraud and the manner in which it is managed by the organization, but are not expected to have the expertise of a person whose primary responsibility is detecting and investigating fraud.

The fraud triangle consist of the following elements:

  • Motive - The reason why an individual acts or reacts
  • Opportunity - The favorable circumstance that allows the individual to commit fraud
  • Rationalization - How the individual justifies the fraudulent action
Fraud indicator denotes signs that indicate both the inadequacy of controls in place to deter fraud and the possibility that some perpetrator has already overcome these weak or absent controls to commit fraud. This can also be referred as red flags.

Risk assessment is the identification and measurement of risk and the process of prioritizing risk.

The following actions is considered as effective fraud risk assessment:
  • Performed on a systematic and recurring basis
  • Considers possible fraud schemes and scenarios, including consideration of internal and external factors. 
  • Assesses risk at a company-wide, significant business unit and significant account level. 
  • Evaluates the likelihood, significant and pervasiveness of each risk. 
  • Assesses exposure arising from each category of fraud risk by identifying mitigating control activities and considering effectiveness of those control activities. 
  • Is performed with the involvement of appropriate personnel
  • Considers management override of controls
  • Is updated when special circumstances arise
The final determination of whether or not the risk of fraud warrants special consideration when conducting the engagement involves the internal auditor's judgement skills. This mental attitude or judgment is a combination of the internal auditor's analytical skills and all information related to the organization to determine if internal control weaknesses exist and signal the potential for fraud activity. 

Topic 6: Identify or Develop Criteria for Assurance Engagements

Criteria should be consistent with audit engagement objectives and ultimately yield useful information to the client. The lack of suitable criteria may result in the internal auditor drawing inappropriate conclusions. 

Examples of generally accepted suitable criteria for assurance engagements includes:
  • Acts and regulations
  • Policies and procedures
  • Standards or guidelines
  • Risk management
  • Control frameworks
  • Performance information
  • Client management roles and responsibilities
  • Industry best practices
  • Guidance provided by recognized bodies of experts
  • Benchmark evidence
When there are no generally accepted criteria consistent with the audit engagement objectives, the lead internal auditor will need to discuss with client management and identify the criteria suitable for the engagement. 

Topic 5: Establish/Refine Engagement Objectives and Identify/Finalize the Scope of Engagement

Internal auditors establish engagement objectives to address the risks associated with the activity under review.

For planned engagements, the objectives proceed from which the annual audit plan is derived. For unplanned engagements, the objectives are established prior to the start of the engagement and are designed to address the specific issue that prompted the engagement.

Engagement objectives are different than management's operational objectives. Operational objectives specify what the client hopes to accomplish while engagement objectives deal with what the internal auditor hopes to accomplish.

Broad categories of engagement objectives includes:

  • Effectiveness and efficiency of operations
  • Reliability of reporting
  • Compliance
The scope of engagement must include consideration of relevant systems, records, personnel and physical properties including those under the control of third parties. 

If significant consulting opportunities arise during an assurance engagement, a specific written understanding as to the objectives, scope, respective responsibilities and other expectations should be reached and the results of the consulting engagement communicated in accordance with consulting standards.

In performing consulting engagements, internal auditors must ensure that the scope of the management is sufficient to address the agreed upon objectives. If internal auditors develop reservations about the scope during the engagement, these reservations must be discussed with the client to determine whether to continue with the engagement. 

Any restriction placed on the internal audit activity that thwarts it from fulfilling the intended scope should be communicated, preferably in writing to the board, audit committee or other appropriate governing authority.