The Chartered Accountant • Journal of ICAI December 2020 • Vol. 69 • No. 6 • pp. 24–28 (Journal pp. 684–688)
Resilience & Auditing Standards

Role of ‘Auditor’ and ‘Standards on Auditing’, in Building Resilience

CA. Deepa Agarwal The author is a member of the Institute. She can be reached at deepa2580@gmail.com and eboard@icai.in.

Building the resiliency of the economy is a collective responsibility of companies, regulators, stakeholders and industry associations. Within each organisation, operational resilience calls for stakeholders to promote a culture of resiliency through training and awareness, constant oversight, timely communications and board reporting. The key components of business resilience, which include defining and understanding critical business needs, going concern and impairment assessment, risk assessment, internal control deficiencies are essential guideposts on the road to resiliency.

This article is an attempt to highlight the role of audit and underlying Standards on Auditing issued by the ICAI in developing a more resilient organization by providing assurance on financial information and valuable insights in various areas to the stakeholders and regulators. Read on…

Recently, there has been manifold increase in the usage of the term resilience. The British Standards Institution published a guidance Standard, BS 65000 – Organisational Resilience, which has attempted to define the term and the principles and attributes associated with it. In essence, this standard calls for much closer integration and alignment of risk management, disaster recovery, crisis management and security. It enables senior management to describe a strategy for the organizational resilience which identifies benefits, behaviours of resilient organizations. Being able to continue critical business functions while responding to a major disaster, and then to return to normal operations efficiently and cohesively afterward, is a critical success factor for all organizations.

What is happening around us now due to COVID 19 has proved beyond any doubt that we live in an uncertain, volatile and complex world. Businesses around the world are facing challenges on handling disruption of such a high magnitude. This disruption has warranted a change in technology, information security norms, the work environment, people management, process engineering, risk management and so on. Auditors have used technology and their creativity while exercising their professional skepticism to maintain high quality in audits and issuing an opinion that is relied upon by stakeholders and regulators. Auditors have also shared knowledge and experiences with audit committees facing new and complex accounting issues, all while investing time and resources in businesses hit hard by the pandemic.

Auditors play a vital role in assessing various components of Business and providing assurance to stakeholders that financial statements provide a true and fair view of the state of affairs of the entity. Auditors contribute to business in varied ways, for example, through timely communication of issues which requires urgent attention of the board of directors/audit committee and reporting to point out the deficiencies and weaknesses in internal control systems. While conventional auditing based on sampling techniques is followed, it is imperative that auditors provide value beyond audit by use of technology and data analytics. Investors and other stakeholders are looking for more and different information because traditional book value can be an incomplete measure of corporate value in today’s economy. With data analytics, auditors can test complete sets of data, rather than just testing samples to meet increasing expectations of stakeholders and regulators. The auditing profession has the capabilities to bring its expertise, building trust and confidence in information into new areas to enhance the reliability of information for stakeholders through the assurance services they provide. Investors, lenders, and other users of audited financial statements can more confidently use this information because auditors have provided an independent perspective. This assessment, in other words, builds trust and confidence.

The key areas wherein audit, and auditors play a significant role in times of disruption and developing resilience in organisations are discussed below:

1. Evaluation of Going Concern

The Board and management need assurance regarding the future viability of their business, assessment of the financial position and health of the company, and an assurance that disaster will not impact the continuity of the business. SA 570, Going Concern requires an auditor to make an assessment and conclude on the appropriateness of management’s use of the going concern basis of accounting.

Robust going concern analysis by the auditor will highlight the sensitive areas for board to focus on and to assess whether the business can continue as a going concern for the next 12 months. Section 134(5) of the Companies Act, 2013 requires directors to affirm that annual accounts have been prepared on a going concern basis, i.e., whether the Board has a reasonable expectation that the company will be able to continue in operation and meet its liabilities as they fall due over the period of its assessment. As part of a going concern assessment, management can assess what impact the current events and conditions have on the entity’s operations and forecasted cash flows, with a focus on whether the entity will have sufficient liquidity to continue to meet its obligations as they fall due. The businesses can be prepared to deal with the liquidity and operational issues by evaluating various options of restructuring of debt arrangements, capital expenditure reduction etc.

“While conventional auditing based on sampling techniques is followed, it is imperative that auditors provide value beyond audit by use of technology and data analytics.”

2. Assessing Level of Preparedness to Deal with Uncertainties

The key principles of resilience is the ability to anticipate & assess, plan & prepare, protect & control, and respond & recover in the situation of major disruptive or catastrophic risk, whether they are internal or external, known or unknown, in addition to the ability to adapt & reform in the light of long term strategic risk such as climate change, pandemics or changing markets. SA 260, Communication to Those Charged With Governance requires auditor to communicate with board of directors/audit committees about significant findings, difficulties in conducting audit and matters, arising from the audit that, in the auditor’s professional judgment, are significant to the oversight of the financial reporting process.

Audit committee members are the proper channel for communicating audit findings, as well as the right filter for choosing which information goes to investors and taking corrective actions. Unexpected events like COVID 19 can disrupt or slow down business activity significantly. Historically, audit rely upon traditional auditing strategies, working within the same parameters and procedures. Using technology and analytics to drive the risk assessment, performing audit procedures (sampling, estimation, electronic confirmations) can help auditors to be more proactive and help businesses in taking proactive measures to deal with disruptions.

3. Use of Technology and Data Analytics

Auditors as well as the companies have extensively used technology, particularly in recent years, to facilitate a smooth transition to a remote working environment. During the pandemic, auditors have really leveraged the technology that they have already been implementing. Cloud-based audit platforms and videoconferencing technology have been particularly valuable during the pandemic both for the auditors and the companies.

Better decisions make better businesses and having the right data at the right time is critical for management to be able to address the changing demands of their key stakeholders. Auditing standards are written on the assumption that it is rarely possible to test 100% of the transactions entered by any entity. This is no longer true with the use of data analytics. By integrating this innovative approach into audit — identifying and capturing the right data, analysing, interpreting and presenting it in a more meaningful way, auditors can provide a valuable independent perspective that will support not only the integrity of the financial statements, but also management and audit committees to become proactive. This will enable them to address issues important to the business and its stakeholders with fact-based answers.

Data analytics enables the organisations to experience an audit that moves beyond the “traditional” approach, addressing the increasing role of IT systems and mass data, and delivering even more relevance, assurance and quality. New age auditors are leveraging data analytics to provide new approaches to enhance risk identification, obtain better quality audit evidence more effectively, highlight internal control deficiencies, or identify opportunities for improvement. Auditors by virtue of their audit experience and with use of analytics can provide useful information for comparisons with prior years and (potentially) other businesses, predict market trends, help in internal benchmarking and better focus on risk.

SA 315, Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment, requires the auditor to consider the implication of such events when obtaining an understanding of the entity and its environment, in light of its objectives, strategies and other business risks.

4. Risk Assessment

Risk assessment is critical for every organisation. Management could benefit by taking a clue from auditor’s strategy in assessing risks from such events. For example, adhering to sound internal controls principles and practices, employing robust systems of quality control, and embedding a culture of ethics and integrity can go a long way to helping an organization to remain resilient in times of crisis. The outbreak of COVID-19 can have a number of potential issues for entities, particularly entities that operate in geographies that are significantly exposed to the outbreak. In addition, there could also be impact on those entities whose vendors/ bankers/ suppliers/ service providers are in geographies that are exposed.

SA 315, Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity and Its Environment, requires the auditor to consider the implication of such events when obtaining an understanding of the entity and its environment, in light of its objectives, strategies and other business risks. Auditor is required to discuss with those charged with governance and management whether the impact of the COVID 19 has been incorporated into their risk assessment processes and how they have identified and assessed the significance of the emerging business risks.

5. Fraud Prevention and Detection

The professional skepticism of the auditor acts as an early warning signal for the audit committees/board of directors in various areas like ratio analysis, fraud prevention and detection, liquidity and solvency issues faced by the companies. Audit serves an important role for companies in fraud prevention and detection. Recurring analysis of a company’s operations and maintaining rigorous systems of internal controls can prevent and detect various forms of fraud and other accounting irregularities.

SA 240, — The Auditor’s Responsibilities Relating to Fraud in an audit of financial statements provides that an auditor conducting an audit in accordance with SAs is responsible for obtaining reasonable assurance that the financial statements taken are free from material misstatement, whether caused by fraud or error. Auditors are also expected to inquire more closely into reasons behind such matters as, for example, errors in accounting estimates, unusual transactions that appear to lack business rationale, and a reluctance to correct immaterial errors discovered by the audit.

If the auditor has identified a fraud or has obtained information that indicates that a fraud may exist, the auditor shall communicate these matters on a timely basis to the appropriate level of management in order to inform those with primary responsibility for the prevention and detection of fraud of matters relevant to their responsibilities. An important part of prevention can be deterrence, and if a company is known to have an active and diligent audit system in place, by reputation alone it may prevent an employee or vendor from attempting a scheme to defraud the company.

SA 240, — The Auditor’s Responsibilities Relating to Fraud in an audit of financial statements provides that an auditor conducting an audit in accordance with SAs is responsible for obtaining reasonable assurance that the financial statements taken are free from material misstatement, whether caused by fraud or error.

6. Internal Control Considerations

An audit does not only examine whether a company’s financial statements gives a true and fair view, but it also tests that the company’s systems are operating as part of testing of internal controls. The systems an auditor examines include the company’s internal controls, or the measures taken to reduce or eliminate accounting errors or fraud. Based on the results of an audit, the auditors recommend changes the company should make to its processes or systems to eliminate problems and reduce future errors. Companies can improve their financial processes and controls, remedying issues before they become major financial concerns.

The auditor needs to reassess the risk, evaluate the design and operating effectiveness of key processes and controls and support remediation. Companies may need to implement new internal controls or modify existing internal controls over financial reporting. SA 265, Communicating Deficiencies in Internal Control to those charged with governance and management requires the auditor to communicate appropriately to those charged with governance and management deficiencies in internal control that the auditor has identified during the audit and that, in the auditor’s professional judgment, are of sufficient importance to merit their respective attentions.

Without a system of internal controls or an audit system, a company would not be able to create reliable financial reports for internal or external purposes. Thus, it would not be able to determine how to allocate its resources and would be unable to know which of its segments or product lines are profitable and which are not. The deficiencies identified in control environment and fraud risk assessments will enable management to be cautious as changes in operational management needs to be implemented to deal with the situation.

SA 265, Communicating Deficiencies in Internal Control to those charged with governance and management requires the auditor to communicate appropriately to those charged with governance and management deficiencies in internal control that the auditor has identified during the audit and that, in the auditor’s professional judgment, are of sufficient importance to merit their respective attentions.

7. Use the Work of Internal Auditor

SA 610, Using the work of internal auditors permit the external auditor to use the work of internal auditor. Internal audit expertise will help the organisation to become resilient in coming out from the COVID 19 impact or any business disruptions. It will not only help to monitor the ongoing practices of the company and reporting the same to the senior management but shall also strive to provide invaluable recommendations in such times. As described in SA 315, the entity’s internal audit function is likely to be relevant to the audit if the nature of the internal audit function’s responsibilities and activities are related to the entity’s financial reporting, and the auditor expects to use the work of the internal auditors to modify the nature or timing, or reduce the extent, of audit procedures to be performed.

Internal audits of the Business Continuing Programmes and Disaster Recovery programs are highly recommended. The audit committees and the Board need assurance regarding the effectiveness of these programmes since it helps to minimize the impact of disruption. Plans should be practiced and focused on recovering what is most important to the business. Internal audits can explore the alignment between capability and the organization’s recovery requirements, the usability of plans and the extent to which critical resource dependencies can be recovered in an incident.

8. Looking Forward

As businesses continue to adjust to the new normal, understanding the long-term effects of the pandemic/disruptions and determining what actions needed is critical. COVID-19 has revealed just how disruptive events can be on “business as usual” and emphasized the need for better future planning. With threats like climate change ramping up there is a lot to be considered and planned for. Further, the pandemic has brought into sharper focus the need for transparent and reliable information beyond historical financial statements.

Doing business has been changed significantly, including how auditors operate. It is clear that the auditing profession has an important role to play in advancing economic recovery. Investor protection is critical to efficient capital formation to fund Innovation and entrepreneurial risk taking. It is the flow of audited information in the marketplace that, when perceived as both reliable and relevant to investment decisions, gives investors the confidence to participate in a market. The auditing profession has steadily developed, systemized, and strengthened this trust and confidence-building role by following professional standards, principles and with robust regulatory oversight.

Reinforcing market confidence through audit reliability, supporting the effectiveness of audit committees, increasing audit transparency — these are real challenges for a profession to stay relevant in this agile environment. ∎∎∎