The Chartered Accountant • Journal of ICAI March 2021 • Vol. 69 • No. 9 • pp. 91–95 (Journal pp. 1115–1119)
BANK AUDIT

Standards on Auditing for Bank Audit

CA. Abhay V Kamat The author is member of the Institute. He can be reached at eboard@icai.in.

“A question sometimes raised by some people is that what are the auditing standards that are applicable in case of audit of banks. I feel the question is not appropriate as all the auditing standards are important and are applicable to the audit of banks. Standards on Auditing (SAs) provide guidance to the members in performing quality audits. If professionals adhere to the SAs, the audit can be conducted effectively and efficiently and achieve its objectives. Recently, quite a few times, audit profession has been put under a lense and accordingly, we should follow SAs. We should understand them, learn them and implement them in right spirit. Read on…”

1. Introduction

The Standards on Auditing (SAs) are formulated in the context of an audit of financial statements by an independent auditor. They are to be adapted to as necessary to the circumstances when applied to audit of other historical financial information. These SAs give guidance to the auditor in conduct of the audit which is consistent in the quality. Further, SAs demonstrate the responsibility which is casted on the independent auditors.

Statutory audit of the banks is an important aspect from the point of view of the banks as well as from the view of the auditors. In case of the bank audit, it becomes a typical exercise because of its strigent timeline, vast scope, repetitive transactions yet variety in transactions. The auditor should not only use one’s professional expertise but also the professional skepticism while carrying out the audit of the bank.

2. Process Of Bank Audit

In case of the public sector banks the statutory audit is carried out in two stages. As all of us are aware the bank operates through branches and there are various controlling offices including the head office. Hence the branches are audited by the statutory branch auditors (SBA). The SBAs carry out the branch audit and report to the controlling office as well as the statutory central auditors (SCA). The observations made by the SBAs are considered. [Where the change/ corrections to be made are made at the controlling offices which are verified by the SCAs]. In addition to this the SCAs carry out the audit of various functions at the Head Office level viz. treasury, secretarial, Risk management department, Recovery and restructure, accounts, etc. On the basis of the reports of the branch auditors and the observations in the audit of various functional departments at the head office, SCAs audit the financial statements and issue the audit report on those financial statements. The financial statements of the bank include various details and disclosures apart from the profit and loss account and Balance Sheet. Thus, audit of bank is a multilayer activity wherein many bank functionaries and number of audit professionals are involved. In order to have consistency in approach the guidance from SAs play an important role.

Sometimes people ask as to what the applicable auditing standards in bank audit are. I feel this may not be a correct question. In fact, all auditing standards are applicable to the audit of banks and the auditor should follow all the auditing standards.

3. Standards on Auditing

The Auditing and Assurance Standard Board (AASB) has issued number of auditing standards. They are classified into various broad areas. Even the numbering of the standards is given on the basis of this classification. This is as follows:

  • SAs 100-199 – Introductory Matters
  • SAs 200-299 – General Principles and Responsibilities
  • SAs 300-499 – Risk Assessment and Response to Assessed Risk
  • SAs 500-599 – Audit Evidence
  • SAs 600-699 – Using Work of Other
  • SAs 700-799 – Audit Conclusions and Reporting

When we consider the applicability of SAs for the bank audit we find that all the SAs will be applicable. However, it would be very difficult to explain each and every standard in this article. Hence the endeavour is to discuss the auditing standards on the basis of various functions involved in the bank audit which could be broadly as follows:

  1. Initial Engagement (SAs 200, 210)
  2. Risk assessment and audit planning (SAs 300, 315, 320, 330, 450, 530)
  3. Conduct of the audit (SAs 220, 240, 250, 500, 501, 505, 510, 520, 540, 550, 560, 570, 580)
  4. Audit documentation (SAs 230)
  5. Using the work of other (SAs 299, 600, 610, 620)
  6. Audit conclusions and reporting (SAs 700, 701, 705, 706, 710, 720)

3.1 Initial Engagement

The auditor should study the appointment letter. When the terms and conditions are acceptable then the acceptance letter should be sent to the appointing authority after obtaining NOC from the previous auditor of the Branch/Bank. The auditor should draft an engagement letter and send it to the person in charge/ appointing authority for its signature and keep a copy of letter duly signed by the auditor and auditee on the record. The broad contents of the engagement letter are given in the standard. Similarly, the Guidance Note on Audit of Banks gives the standard format for the engagement letter for the bank.

3.2 Risk Assessment and Audit Planning

The auditor should prepare a plan for audit. While planning the auditor should form an audit team considering the qualification and experience of a person, availability of the person, size of the audit team. physical infrastructure available at the audit place, time schedule etc. Wherever required the training sessions to the audit teams should be conducted before going to the audit place.

The auditor should understand the over all business of a particular branch, composition of the business, major customers of the bank, etc, which will help to assess the risk. E. g. where the branch is situated at the industrial area, the customers will be from the manufacturing sectors as against the location of the bank at the marketplace will make the branch to entertain the customers from the trading business. This will have impact on the composition of the loan portfolio viz. term loans, cash credit, bill discounting, export finance, etc,

Even the economic recession in a particular industry will impact a branch business which is having majority of the customers from the same industry. Therefore, understanding the environment and the entity to be audited is must before we start the audit.

Having understood the environment and the audit entity, the auditor should assess the risk in the audit. On the basis of the perception of the risk the auditor should plan the audit. The audit program could be designed accordingly and even the audit sampling could also be done considering the initial risk assessment.

Audit Sampling

As I mentioned initially, the transactions in the bank are multiple and repetitive. Hence audit sampling is a must. The sample selected should cover maximum business at the branch and shall cover all variety of transactions, period (in case of certain seasonal aspects), nature of products, etc,

Materiality

Considering the risk and overall volume at the entity level the auditor should fix the materiality of misstatement in the financial statements. As standard suggests, in case of deviation in accounting principles the auditor should report the matter irrespective of the materiality fixed. In other case the reporting of material misstatement will have to be done.

3.3 Conduct of the Audit

Having done the planning properly the auditor should concentrate on the conduct of the audit. While conducting the audit the auditor should ensure the quality in the audit ( SA 220) In order to achieve the quality in audit the auditor should select proper audit team considering the knowledge, experience, availability and the time schedule. The audit team should be headed by the engagement partner who will be guiding the audit team during the audit, reviewing the work its progress and resolve the unsolved issues or the issues of difference of opinion. The audit should have a competent Engagement Quality Reviewer (EQR) who will review the work of Engagement Partner. In case of any suggestions EQR will guide the engagement team including the partner. Thus, the quality in the assignment is maintained.

Initial Audit Engagement – Opening Balances

In case of Bank audit the auditor need not verify the opening balances of each and every account. However, the auditor should see whether the entries for last year’s Memorandum of Changes (MoC) are passed properly during the current year. Usually, the MoCs are passed at the Head Office level while finalising the financial statements and they are intimated to the branches subsequently. The auditor of the subsequent audit period should see whether the entries are passed correct. Sometimes there are chances that the entries may get passed twice at the branch level. The auditor should ensure that such mistakes are not there at the branch level.

Audit Evidence

The auditor should collect the objective audit evidence to satisfy about the transactions recorded at the branch level. The audit evidence may be internal like books, registers, records, vouchers, etc. or the external evidence like third party confirmations, certificates, valuation reports, specific reports, etc. Sometimes the bank makes accounting estimate like provisions, value of security, useful life of fixed assets, contingent liabilities in case of legal disputes, etc. In such cases the auditor should review the basis of the estimate and if required make proper disclosure thereof.

Other Aspects

One of the fundamental accounting assumptions is going Concern. The auditor should see whether there is any threat to the Going concern principle of the bank. Similarly, the transactions with the related parties need to be scrutinised and disclosed. The auditor should obtain the list of related parties and the transactions with them. Though the time from the year end till the signing of audit report is very short, the auditor should see the subsequent events and take appropriate action on it. In most of the cases the related parties and going concern disclosure may not be relevant in case of bank branch audit. However, for SCAs it will be quite relevant.

The auditor should obtain written representation from the management about the assertions made by them during the course of audit.

3.4 Audit Documentation

The auditor should maintain proper audit documentation in its working paper file. The working paper file should include the audit plan, audit program, the terms of engagement, execution of audit work, audit evidence, accounting estimates made, management representations, audit findings and audit conclusions, reporting, etc, The audit documentation is helpful in subsequent reviews, investigations, or any other reference in relation to the audit carried out. The retention of audit working papers is seven years as per SQC-1. The working papers can be maintained electronically on computer system.

3.5 Using the Work of Other

During the course of audit, the auditor has to depend on the work of other professionals. In case of branch audit, the branch auditor depends on the reports given by the concurrent auditors of the branch. The auditor shall go through the reports and note the concerns mentioned therein. The auditor should plan its audit procedure in such a manner that the concerns noted are examined and the audit conclusions are confirmed.

As mentioned earlier the bank audit is carried at two layers branch audit and central office audit. Thus, the CSAs should depend on the work done by the branch auditors. While depending on the work of the branch auditors, the CSA should give the directions to the branch auditors, take a confirmation about the audit procedure used, use audit conclusions of the branch auditors while forming its opinion. However, while using the work of other auditors the auditor should review the reports and ensure that the audit conclusions are drawn properly. The auditor should also consider the materiality while forming its audit opinion.

Using the work of an Expert

While having accounting estimates the management may take report from the expert in different subjects. e.g. In case of the employee benefit liability the management shall appoint the actuary for actuarial calculation of the liability. In such case the auditor shall depend on the actuarial report. However, it is the duty of the auditor to see whether the data given to the actuary is correct. Similarly, the auditor should review the assumptions made by the actuary such as discount rate, salary escalation rate, composition of the salary, retirement age of the employee, etc,

In case of valuation of the security offered against the loan, the bank will take valuation report from the empanelled valuer. In such case the auditor shall consider the same for the security value while making the provision on the NPAs. However, the auditor needs to see the reservations, exclusions, validity of the title of the property, etc, and form the audit opinion.

In short, the auditor should apply professional skepticism while accepting the work of another expert.

Responsibility of Joint auditors

Normally for the banks there are more than one auditor as SCAs. In such case SA 299 gets triggered. In case of the joint auditors the responsibility of individual firm needs to be spelled out clearly. The auditors should sign the work allocation sheet on the basis of the allocation of work agreed. Every individual audit firm is responsible for the area audited by the respective firm. In case an individual audit firm feel that the audit observation needs to be discussed with the other audit firm for taking collective view and conclude on the audit opinion, then it can do so against the principles enunciated in SA 299.

3.6 Audit Conclusions and Reporting

The auditor should finalise its audit finding, discuss them with those charged with the governance. After discussion if he is satisfied with the explanations, then it may be concluded that there are no material misstatements. However, if auditor feels that there is material misstatement, he may deal in the audit report appropriately.

The audit report is the statement of audit opinion given by the auditor. It may be a clean report which is called as the unmodified report. In case of any material misstatement the auditor may suitably give modified report, which may be a qualified report or adverse report or a disclaimer of opinion. There may be certain facts or matters which, in the opinion of the auditor, are material to be known by the reader of the financial statements, however they will not amount to material misstatement. In such case the auditor may give Emphasis of Opinion (EOM) without qualifying the audit opinion. for using appropriate audit opinion, the auditor should look at the SAs and finalise the audit report.

Key Audit Matters (KAM)

Key Audit Matters are those matters that in the auditor’s professional judgement, were of most significance in the audit of the financial statements of the current period. Key audit matters are selected from the matters communicated with those charged with governance. In case auditor notices such matters, they should be mentioned in the audit report.

Other Information

The auditor should verify the corresponding figures related to the previous period in the financial statements (SA 710).

SA 720 deals with the auditor’s responsibilities relating to other information, whether financial or non-financial information (other than financial statements and the auditor’s report thereon) included in the bank’s annual report. The annual report may be a single document or a combination of documents that serve the same purpose. Thus, the auditor should verify that the information given in the annual report is in line with the details given in the financial statements. In case of discrepancy, the fact should be brought to the notice of those charged with governance.

4. Conclusion

Standards on Auditing give a guidance to the members which ultimately lead to good quality in Audit. I am sure that the SAs will definitely come to the help of the auditors to maintain the quality and consistency in the audit. If we follow them properly, the quality in audit will definitely follow. Hence, we should read them, study them and implement them in right spirit.

— CA. Abhay V Kamat