Responsibilities of Auditors in Changing Scenario
CA. Arun Kumar Srivastava
The author is a member of the Institute. He can be reached at arunkumar.srivastava818@gmail.com and eboard@icai.in.
“ICAI has issued various Auditing standards and Guidance notes relating to Internal control system, Reporting on frauds, Risk assessment, External confirmations, Related party transactions etc. Besides, in the companies act 2013, various reporting requirements through CARO 2020 have been introduced regarding end use of Funds, Diversion of funds, Related party transactions and Loans& Investment in subsidiaries, joint ventures and Associates, etc. An attempt has been made in this Article to consolidate/summarize the desired Auditing practices to be adopted by the Auditors considering the guidelines/regulations prescribed in Auditing standards / Guidance notes issued by ICAI and COMPANIES ACT 2013 so that the Expectation of society/Regulatory authorities may be fulfilled. Read on…”
During recent times many corporates including NBFC’S Frauds have taken place, which have awakened a need for introspection among professional fraternity to review the Audit strategies and practices. Reserve Bank of India has recently reported that number of frauds have increased from 2251 cases in 2014-15 amounting Rs.17122 crores. to 3606 cases amounting Rs.64548 cr. in 2018-19 and 2438 cases amounting to Rs.110419 crores in H1 financial year 2020. RBI has advised lenders to decide whether loan accounts that have been red flagged as suspicious six months ago are fraudulent or not. Since, it is being alleged by the Regulators that more professional skepticism needs to be adopted by the Auditors as well as adoption of Standards on Auditing in its true spirit. The risk factors and deficiency in the internal control system as reported has revealed following:
- No proper due diligence was exercised while granting loans and advances by the NBFCs.
- End use of the funds was not ensured and funds were diverted to Group companies.
- Short term borrowings were utilized for long gestation projects through Group companies which resulted in default of repayment to the lenders and bondholders, etc.
- Terms & conditions of loans including interest rates on loans were found prejudicial to the interest of the company.
- Ever greening of loans had taken place i.e. additional credit facilities have been granted to the defaulting borrowers to adjust their overdue outstanding so that classification of loans as non-performing assets may be avoided. This has also resulted in overstating of profit through generation of fresh interest income.
- Fresh loans were given to the companies where account was written off in the books of NBFCs.
- Loans were given to Promoter related entities without proper due diligence. For instance, net worth of the Borrowing entity was not sufficient and full loan was disbursed without monitoring the physical progress as suggested by National Housing Bank.
- Sales were inflated by raising fictitious invoices resulting into overstating of profit and consequential increase in share prices of the companies.
- Debtors and Bank deposits were overstated through deficiency in the internal control system.
- Payments against service contracts were released without taking into account the physical progress of the work / completion of services.
Auditing Strategies
Considering above and expectations of various regulatory authorities including MCA, SEBI, RBI and NFRA, now there is a need to exercise more professional skepticism while conducting the audit and adopt the auditing strategies religiously and in true spirit as prescribed in various Standards on Auditing (SAs) particularly following standards and Guidance Notes:
SA 240 – The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
As per this standard, An Auditor is responsible for obtaining reasonable assurance that financial statements taken as a whole are free from material misstatement whether caused by fraud or error. To ensure it, Auditor has to maintain Professional skepticism i.e. questioning mind throughout the audit. Auditor also needs to perform necessary procedures e.g. risk assessment procedures which include inquiries of the management, evaluation of fraud risk factors, evaluation of audit evidence, obtaining management representations, communication to Management and with those charged with the governance and communication to enforcement and regulatory authorities.
SA 315 – Identifying and Assessing the Risk of Material Misstatement through Understanding the Entity and Its Environment
As per this Standard, Auditor has to assess the risk of material misstatement, whether ,due to fraud or error in the financial statements/ assertions(representations by the management as included in the financial statements). For that purpose ,Auditor has to study the nature of industry to which entity pertains, the nature of entity and its operations, its regulatory environment to which it is exposed and its internal control which will help the auditor in adopting appropriate auditing strategies to reduce the risk level of material misstatement. To achieve this objective, auditor has to enquire appropriate officials including internal audit team, adopt analytical procedures like Ratio/trend analysis and conduct observation and inspections like comparison of Budgets with Actuals, review of minutes of Audit committee and Board of directors and review of internal control/ audit manual etc. Auditor has to examine controls embedded in the IT system, authorization for changes in programs/ data files and overriding of Edit checks etc. Auditor has also to review manual control system like delegation of powers for granting various financial sanctions, rotations of job, segregation of duties, preparation of bank and other reconciliations and generation of various MIS reports etc. For example, in Banks, integration of SWIFT with CBS to be examined so that all Letters of credit/guarantees issued may be recorded, similarly generation of various exception reports in the banks also to be reviewed by the auditor. Selection of accounting policies should be in consistent with the relevant accounting standard/accounting practices adopted in industry so that Revenue and other transactions may be properly recognised, measured, classified and disclosed.
SA 450 – Evaluation of Misstatements Identified during the Audit
As per this Standards, Auditor has to evaluate the impact of identified accumulated material misstatements on the financial statements. Misstatements may pertain to classification, presentation and disclosure of a reported financial item. Auditor has to evaluate the misstatements considering the aspect of materiality determined as per SA 320.He has to convey the same along with its impact on financial statements to those charged with the governance and request them to correct it. If not corrected , the impact of uncorrected misstatements ,which are material individually or in aggregate, the impact of same on auditors opinion may be communicated to those charged with governance and if, necessary, a written representation may be obtained from them regarding not treating the misstatements to be material.After receipt of representation, auditor has to exercise his professional judgement for inclusion of uncorrected misstatements in the audit report suitably.
SA 550 – Related Parties
As per this standard, Auditor has to understand related party relationships and transactions to recognise fraud risk factors if any, arising out of those relationships and transactions so that identification and assessment of risk of material misstatement due to fraud may be made. Auditor has to obtain sufficient appropriate audit evidence about identification of related party relationships and transactions, their proper accounting and disclosures in the financial statements in accordance with the applicable financial reporting framework.
Guidance Note on Audit of Internal Financial Controls over Financial Reporting
Companies Act 2013 requires the Auditor to report on adequacy of internal financial controls with reference to financial statements of the company and the operating effectiveness of such controls. To ensure that, auditor has to understand flow of transactions, risk of material misstatements, identification of applications and associated IT environment, design and implementation of controls and assess audit impact/plan operative effectiveness testing. For detailed guidance on this aspect, reference may be made to the Guidance Note on Audit of Internal Financial Controls over Financial Reporting issued by ICAI.
SA 505 – External Confirmations
As per this standard, direct confirmations are obtained from third parties regarding account balances, other elements and terms of contracts etc.
Guidance Note on Reporting on Fraud under Section 143(12) of the Companies Act, 2013
Detailed reporting requirement under companies act has been given in the guidance note during audit/attest functions by the auditor if, he has reason to believe in performance of duties that an offence of fraud involving individually an amount of Rs. one crore or above has been/is being committed against the company by the officers/employees, auditor shall report the matter to the Central Government.
Key Focus Areas for Auditors
Besides above, auditors have to pay special attention to the following areas of an organisation:
- a) Verification of sales with GST returns: Verification of sales with GST returns and GSTR 9c and scrutinize unbilled Revenue. Review of IT system for ensuring that Raising of invoices are linked with delivery of goods / E –way bills etc. and sales are recognized as per principles envisaged in AS9.ie Revenue recognition / IND AS 115 i.e. Revenue from Customer.
- b) Minutes of Committee & Board Meetings: Minutes of Audit Committee , Board Meetings and shareholders meetings to ascertain approval/Arms -length of related party transactions , show cause notices issued by Regulatory /Tax authorities, if any and other important matters relating to Misstatements/ frauds in the financial statements, if any.
- c) IT Risk Assessment & Access Controls: Risk assessment of the Organization particularly information Technology system including segregation of duties ,sharing of passwords, concept of maker, checker and approver etc. and delegation of power issued by the Board of Directors.
- d) Whistle Blower Policy: Whistle blower policy of the company and detail of complaints if any, after going through the minutes of Audit committee and Board of Directors.
- e) Vigilance and C&AG Observations: Vigilance department /C&AG observations on propriety cum efficiency audit in case of public sector undertakings.
- f) Contingent Liabilities & Tax Demands: Contingent liabilities with reference to demands raised by Tax authorities, letter of credits /counter guarantees issued to Bankers / financial institutions so that cases of Tax evasion, issue of in-genuine Letter of credits and Guarantees including its development/ involvement may be ascertained.
-
g) RBI Inspection & Early Warning Signals: Review of reports of RBI, Internal inspection audits and concurrent audits in case of Banks/NBFCs so that fraudulent/suspicious transactions may be ascertained. RBI has issued master directions no. RBI/DBS/2016-17/28 dated 1st July 2016(updated as on 3rd July 2017) on Frauds- classification and reporting by commercial banks and select FIs. Few early warning signals highlighted in the master directions are given below:
- Critical issues highlighted in stock audit report
- Liabilities appearing in ROC search report, not reported by borrower in the Annual report
- Floating front/associate companies by investing borrowed money
- Not routing of sales proceeds through consortium /member bank/lenders to the company
- Heavy cash withdrawal in Loan accounts.
- h) Internal and Forensic Audit Reports: Review of Internal audit and forensic audit reports, if any, to ascertain the risk factors, weakness in internal control system and material misstatement in the financial statements.
- i) Compliance with Sections 179, 180, 185, 186 & 187: Compliance of sections 179,180,185,186 and 187 of the Companies Act 2013 relating to Powers of Board, Restrictions on loans & advances to Directors and companies/firms in which Directors are interested as well as relating to investment of funds which is presently limited to 60% of paid-up capital, free reserves and securities premium account or 100% of free reserves and securities premium account whichever is higher except with prior approval of General body meeting by way of special resolution.
- j) Accounting and Auditing Manual: Accounting and Auditing manual prepared by the organization which contains detailed guidelines relating to internal control system and recording of transactions.
Regulatory Provisions under Companies Act, 2013
Salient regulatory provisions under Companies Act, 2013 related to responsibilities of an auditor for inquiring /reporting on utilisation of funds/review of internal control system/ misstatements in the financial statements are briefly discussed below:
- Section 143(1)(a): mentions “whether loans and advances made by the company on the basis of security have been properly secured and whether the terms on which they have been made are prejudicial to the interests of the company or its members” i.e. proper security covering loan amount has been obtained and rate of interest is in conformity with the prevailing market rates (not less than prevailing yield on Govt. securities).
- Section 143(1)(b): mentions “whether transactions of the company which are represented merely by book entries are prejudicial to the interests of the company” (same refers to transactions like in the nature of circular trading which implies that multiple transactions have taken place among various entities without physical movement of goods and raising fabricated invoices. This may also result into fraudulent claim of input tax credit under GST law).
- Section 143(3)(i): requires Auditor to report whether the company has adequate internal financial controls with reference to financial statements in place and the operating effectiveness of such controls.
-
Section 143(12) read with Rule 13 of Companies (Audit and Auditors Rules, 2014): if the Auditor of a company in the course of performance of his duties as statutory auditor, has reason to believe that an offence of fraud which involves or is expected to involve individually an amount of Rs. one crore or above, is being or has been committed against the company by its officers or employees, the Auditor shall report the matter to the Central Government.
Provided that in case of fraud involving lesser than the specified amount, the auditor shall report the matter to the Audit committee constituted under section 177 or to the Board in other cases within such time and such manner as may be prescribed and in such cases companies shall also disclose the details of such frauds in the Board report.
Enhanced Reporting Requirements under CARO 2020
Besides above, CARO 2020 has also inserted various reporting requirements by the auditors considering the issues of diversion/end use/siphoning of funds, which are briefly described below:
- Agreement of Quarterly Returns with Books (Working Capital > Rs. 5 Crore): Agreement of quarterly returns/statements filed by the company with the banks/financial institutions with the books of Account, in case sanction of working capital limits more than Rs. 5 crore during the year on basis of security of current assets: Auditor has to ensure that stock / book debt statements are in conformity with books of account/ stock records of the company.
- Terms of Loans, Investments and Guarantees: Whether the investments made, guarantees provided, security given and the terms and conditions of grant of loans and advances in nature of loans and guarantees provided are not prejudicial to the interest of the company: Auditor has to examine sources of funds of the company for such investment, rate of interest as per prevailing market rate, repayment period and other covenants of the loan. Financial standing and credit rating of the investee company needs to be examined.
- Regularity of Repayment Schedules: Whether schedule of repayment of principal and payment of interest in respect of loans & advances in the nature of loans has been stipulated and whether the same are regular: Auditor has to examine loan agreements and whether repayments including interest as per stipulations are regular or not.
- Recovery of Overdues Exceeding 90 Days: Whether reasonable steps have been taken in respect of recovery of principal and interest in respect of overdue amount more than ninety days.
- Evergreening of Loans: Reporting in case of loans or advances in the nature of loan which has fallen due during the year and has been renewed or extended or fresh loan granted to settle the overdues of existing loans given to the same parties: Auditor has to examine the terms of renewal/ extension and granting of fresh loan to settle the old loan considering the Ever greening aspect as mentioned in the preceding paragraphs.
- Loans to Promoters / Related Parties Payable on Demand: Reporting the aggregate amount of loans granted to promoters under section 2(69), related parties as defined in section 2(76) of companies act 2013 in case of loans either payable on demand or without specifying the terms or repayment period: Auditor has to examine above aspect considering the loan agreements and requirements of SA 550, Related Parties and report accordingly.
- Compliance with Section 185 and Section 186: Compliance of Section 185 and section 186 of Companies Act 2013 relating to Loans, Investments, Guarantees and security to Directors etc. and other Body corporate: Section 185 relates to restrictions on loans and providing guarantees/security to directors of the company / its holding company, their relatives , partners and the firm in which director and relatives are partner. However, for granting such loans and provision for security/ guarantee to the private companies/ body corporate (excluding wholly owned subsidiaries) in which directors are interested, approval of General meeting by way of special resolution is required. Section 186 relates to restriction on inter-company loans/ investments for which threshold limit is defined as mentioned in preceding paragraphs, rate of interest to be levied not less than applicable rate on government securities as per applicable tenor and prior approval of public financial institutions are to be obtained in case where any term loan is subsisting.
- Defaults in Repayment of Borrowings: Reporting about period and amount of default in repayment of loans or other borrowings or in the payment of interest to the lender: Auditor has to obtain schedule of repayments including interest and ascertain default position, if any, for reporting.
- Willful Defaulter Declaration: Whether the company has been declared willful defaulter by any Bank or financial institution or other lender: RBI vide master circular no RBI/2014-15/73 dated July 1st 2014 has defined willful defaulter as those borrower who have defaulted in repayment obligations inspite of having capacity to honour the said obligations/diverted the funds for other purposes/ disposed off the property without knowledge of the lender. The list of willful defaulter may be ascertained from the credit information companies like CIBIL, EQUIFAX etc. who are registered with RBI.
- End Use and Diversion of Term Loans: Reporting about end use of the term loans and its diversion, if any: Auditor has to examine specific end use of the fund borrowed or its diversion as defined in RBI master direction dated 1st July 2014 as mentioned above which includes diversion of funds to group companies/routing of funds through other bank other than lender/ consortium banks/ utilising short term fund for long term purposes etc.
- Short-Term Funds Utilised for Long-Term Purposes: Reporting of utilisation of funds raised on short term basis for long term purposes: Auditor has to review sources and Application of funds and current ratio to examine and report above aspect.
- Funds Raised to Meet Obligations of Subsidiaries/JVs/Associates: In case of funds raised by company from any entity or person on account or to meet the obligations of its subsidiaries, joint ventures or associates, then reporting about details of such transactions: Auditor has to examine above aspect by obtaining a list of subsidiaries, associates and joint venture companies, schedule of borrowings and review the cash flows of the company to ascertain the utilization of borrowed funds for group companies. Confirmations from the auditors of group companies as per SA 600, Using the Work of another auditor to be taken and disclosures required by SA 550 and AS 18 /Ind AS 24 to be checked.
- Loans Raised on Pledge of Securities in Subsidiaries/JVs: Reporting about loans raised during the year along with default, if any, on the pledge of securities held in its subsidiaries, joint ventures or associates companies: Auditor has to obtain schedule of loans raised during the year against the pledge of securities of subsidiaries, joint ventures and associate companies, examine the loan agreements and details of charges/modifications filed with the ROC and report the defaults taken place, if any, as per terms of the agreement.
- Frauds Noticed or Reported: Reporting about nature and amount of any fraud by the company or any fraud on the company noticed or reported during the year: Auditor has to review internal audit reports, minutes of meetings of audit committee and Board, show-cause notices issued by regulatory authorities, etc. to ascertain the details of fraud by/ on the company and also obtain management representations for disclosure of all frauds.
-
Whistle Blower Complaints & Vigil Mechanism: Whether the auditor has considered whistle blower complaints if any, received during the year by the company: As per section 177(9) of the Companies Act, 2013, following class of companies are required to establish a vigil mechanism for their directors and employees to report their genuine concerns or grievances:
- Every listed company
- Companies which accept deposit from the public
- Companies which have borrowed money from banks and public financial institutions in excess of Rs. fifty crore
- Related Party Compliance (Sections 177 & 188): Compliance of Sections 177 and 188 of the companies act 2013 for related parties transactions and disclosure thereof in the financial statements as per applicable accounting standards: Auditor has to examine minutes of meetings of Shareholders and Board of directors /Audit committee for approval of related party transactions considering its Arm’s-Length position particularly those outside ordinary business transactions like services rendered to sister concerns without considerations, Major sales discounts and circular transactions etc. Compliance of SA 550 and AS 18/Ind AS 24 to be also checked.
- Undisclosed Income Surrendered in Tax Assessments: Reporting on recording of transactions surrendered/ disclosed as income during the year in the tax assessment under Income tax act 1961 which was not accounted for earlier: Auditor has to assess whether company had intentionally not accounted for that income in previous years which may be an indication of fraudulent financial reporting.