UNIVERSITY OF ECONOMICS AND LAW FACULTY OF ACCOUNTING AND AUDITING GRADUATION THESIS AUDIT PROCEDURES OF RISK ASSESSMENT AT PLANNING PHASE AT EY VIETNAM LIMITED COMPANY ADVISOR: HOÀNG THỊ MAI KHÁNH AUTHOR: NGUYỄN THANH TRÚC STUDENT ID: K174050625 HO CHI MINH CITY, MAY 2021 UNIVERSITY OF ECONOMICS AND LAW FACULTY OF ACCOUNTING AND AUDITING GRADUATION THESIS AUDIT PROCEDURES OF RISK ASSESSMENT AT PLANNING PHASE AT EY VIETNAM LIMITED COMPANY ADVISOR: HOÀNG THỊ MAI KHÁNH AUTHOR: NGUYỄN THANH TRÚC STUDENT ID: K174050625 HO CHI MINH CITY, MAY 2021 i COMMENTS OF ADVISOR …………………………………………….…………………………………… ii THANK YOU STATEMENT First of all, I would like to thank the teachers of the University of Economics and Law especially the teachers in Accounting and Auditing Faculty, who always accompany me, teach and convey knowledge, extremely valuable to me throughout final this year. That knowledge will definitely help you a lot on your career path in the future. I would like to send my deep thanks to my advisor – Ms. Hoang Thi Mai Khanh.
She is a person who always helps and supports me a lot but over the past time, she has always taught me a lot of things about the field that I have chosen. Through her support, all of them helped me a lot in completing the thesis and helped me receive the necessary technical knowledge to apply in work and in life. Thank you very much. I also would like to send my deep thanks to the Board of Directors and my colleagues at EY.
The time I practiced at Ernst & Young Co. gave me the opportunity to gain practical knowledge. Practice, imparting to me skills, experience and especially helping me a lot so that I can complete this essay. During the internship, as well as in the process of completing this graduation thesis, there are still many limitations, it is inevitable that unnecessary mistakes are unavoidable.
I look forward to receiving the comments of teachers. Those things will help me a lot in learning skills, experience and overcoming mistakes. I sincerely thank you! Ho Chi Minh City, April 19th 2021 Student name iii LIST OF ABBREVIATIONS TERM MEANING FSs Financial statements BOD Board of Directors EY GAM Ernst & Young Global Audit Methodology ROMM Risk of material misstatements UTB Understanding The Business ELC Entity Level Controls ISA International Standard on Auditing VSA Vietnamese Standard on Auditing iv LIST OF TABLES Table 1. Matrix of detection risk Table 2.Summary of Walk-through Test Results Table 2.
CRA for material items Table 2. Relationship between associated risk and substantive testing performance LIST OF DIAGRAMS Diagram 1.1 - Relationship between components in audit risk Diagram 2. EY’s organizational structure of management v Table of Contents INTRODUCTION. 1 Reasons to choose the topic.
1 Objectives of the study. 2 Methodology of the study. 2 Scope and limitations of the study. 3 CHAPTER 1: THEORITICAL BACKGROUND OF AUDIT RISKS AND AUDIT RISK ASSESSMENT.
What are audit risks? Differentiate from other types of risk. Differentiate from business risk. Audit risks model components. The relationship between risk types (audit risk model).
Relationship between audit risks with materiality. Risk assessment process. Risk assessment in each stage of the financial statements audit. Risk assessment in planning stage of the financial statements audit.
14 CHAPTER 2: AUDIT PROCESS OF RISK ASSESSMENT AT EY – ILLUSTRATION AT CLIENT ABC. Introduction to EY. Mission, Vision & Values. Audit process of FSs at Ernst & Young Vietnam (EY GAM).
Risk assessment process at Ernst & Young Vietnam – Illustrate at ABC Company .1 Pre-planning phase .4 Assessment of internal control system. Combined risk (CRA) with substantive test. 62 CHAPTER 3: COMMENTS AND RECOMMENDATIONS. Comment on the audit risk assessment process during the planning phase at Ernst & Young Co.
75 APPENDIX I - AUDITOR PROCEDURES TO BE FOLLOWED WHEN UNDERSTANDING INTERNAL CONTROL SYSTEMS. 75 APPENDIX II - UNDERSTAND THE BUSINESS - COMPANY ABC. 78 APPENDIX III - LAWS AND REGULATIONS FORM – ABC COMPANY. 87 APPENDIX IV – ENTITY LEVEL CONTROLS COMPANY A.
92 APPENDIX V – CRA FOR MATERIAL ITEMS AT CLIENT ABC. 106 1 INTRODUCTION Reasons to choose the topic Nowadays, along with the development and diversification of IT, integration and cooperation with the countries around the world as participating in many free trade agreements such as opposition agreements Trans-Pacific (TPP), ASEAN Economic Community (ACE),. This has contributed to make Vietnam's economy more and more developed, parallel to the advantages in multi-modal import, businesses in Vietnam also face with the formula and fierce competition in capital mobilization and market expansion. To meet these difficulties in economic integration, the FSs have been audited to contribute an important part in creating reputation and reliability for businesses.
The audit of financial statements not only needed for the supervision of companies trading on the stock market, but also used as a mechanism for fraud detection and financial liability. In order to solve the problem above, companies FSs need to be audited to provide audited reports to stakeholder’s confidence on the information they are provided. As one of the professional services, auditors are becoming the essential workforce in the society. With independence and technical knowledge, auditors can give the confidence to the shareholders on the subject matter as financial statements and help them make decision on whether they should invest their money in the company.
One of the audit procedures in the planning phase will help the auditors is, “Risk Assessment at the planning stage of an audit". Risk assessment in the planning phase is extremely important, helping the auditor have a basis for content design, schedule, and scope of subsequent audit procedures. Besides, risk assessment also helps auditors identify high-risk areas, then focus resources to ensure not passing material misstatements. Furthermore, the risk 2 assessment also helps the auditors save time, thereby bringing the balance between benefits and costs and auditors' efforts but still ensure the quality of the audit.
Among all procedures in conducting an audit, risk assessment is the fundamental procedures. Today, an audit is still conducted on a risk-based approach to give a reasonable assurance on the FSs. The auditors cannot and do not arrange to check all transactions but just the material and risky areas. Understanding the essence of this procedure, the author decided to combine the theory and the practical experience gaining from the internship at Ernst and Young Vietnam Limited Company, then choose the topic “Audit procedures of risk assessment at planning phase at EY Vietnam Limited Company”.
Objectives of the study The study aims to: - Review the theoritical background of risk assessment procedures in the planning stage of an audit. - Describe and analyze the practice of risk assessment at EY Vietnam Limited Company. Figure out the different between the guideline from books and on the practical use of methods to assess the risk of Ernst & Young Vietnam Limited Company. - Give comments on pros and cons as well as recommendations for the implementation of the regulation risk assessment at EY.
Methodology of the study - Collect documents and published standards related to ROMM assessment, theoretical from the Auditing course - Researching on the audit program of EY (EY Global Audit Methodology - EY GAM). - Collecting data from the entity audit file combined with the interview with EY audit team leaders to learn about ROMM assessment procedures at EY Vietnam Co. 3 Scope and limitations of the study The procedure for assessing the risks of material misstatement during the audit planning stage is an important process and is regulated by international accounting standards and Vietnam, so the auditing companies apply the submitted to this in all audits. And obviously, EY has also been applying the above process in the company's audit program, the risk assessment is a continuous process and is always updated and adjusted in time so that auditors have the coping with risks, and this is usually a job by senior auditors such as audit team leaders, owners,.
Those are auditors who have a lot of experience, knowledge and professional judgment to make practical and effective reviews. The topic focuses only on risk assessment, does not focus on other procedures and illustrates only 1 client, so it is not general for all cases at EY. At the same time, the writer is not directly involved in the discussion, discussion and assessment of audit risks during the audit preparation phase, but only has the opportunity to learn the actual documents, to record the Client records about the content related to the risk assessment procedures of the units in which the writer is participating in the audit in EY's Canvas audit program. 4 CHAPTER 1: THEORITICAL BACKGROUND OF AUDIT RISKS AND AUDIT RISK ASSESSMENT 1.
What are audit risks? Differentiate from other types of risk 1. Audit risk Auditing standards require the auditor to obtain an understanding of the entity and its environment, including its internal control, to assess the ROMM in the client’s financial statements. Auditors can increase the number of audit procedures in order to reduce the level of audit risk. Reducing audit risk to a modest level is a key part of the audit function, since the users of financial statements are relying upon the assurances of auditors when they read the financial statements of an organization.
According to paragraph 13 VSA 200 defines: “Audit risk is the risk stated by the auditor knowledge is not appropriate when the audited financial statements contain material misstatements. Audit risk is the result of risks of material misstatement (including inherent risks, audit risks control) and risk detection. ” In addition, paragraph A33 VSA 200 states: “Auditing risk” does not include the risk that the auditor may state that the financial statements contain material misstatement but in fact the financial statements do not contain such misstatements. The auditor can give an opinion that there are material misstatements in the financial statements, but in reality, the financial statements do not have misstatements like that.
This risk is usually not serious. It only affects the effectiveness results of the audit because the auditor has performed more procedures to prove the financial statements there are no material flaws. Additionally, audit risk is a related technical term to the audit process, does not imply the risks that auditors encounter in business such as losing the lawsuit, 5 disclosing information, not collecting audit fees, etc…or events arising in relation to the audit of financial statements” There are many reasons why auditors give inappropriate opinions while the audited financial statements still contain material misstatements, including: - The audit of the financial statements only provides a reasonable level of assurance (a high level of assurance possible acceptable but not absolute). - Unable to detect all misstatements at the unit due to the existence of fraudulent acts noncompliance or collusion among employees at the client is audited.
- Limited in terms of time as well as audit fees. The audit was performed out the balance between time and audit fees. Auditors performed the audit for a reasonable fee also guarantees the quality of the service be provided. - Limited professional capacity of auditors and capacity in the field of operation client action.
- Limitations in audit procedures that lead to the inability to detect all misstatements key at the client. - Due to the nature of financial statement preparation: accounting estimates, provisions, etc… - The risk in sampling technique leads to the sample being selected not being representative of the population. Differentiate from business risk Business risks are defined as “a risk resulting from significant conditions, events, circumstances, actions or inactions that could adversely affect an entity’s ability to achieve its objectives and execute its strategies, or from the setting of inappropriate objectives and strategies”.