Monday, August 29, 2011

Internal Auditor Independence

Internal Audit Independence

July 29, 2011

I run into more than a few internal auditors who struggle with independence. The people who pay their salaries and keep their team funded and staffed don’t understand what auditors do and therefore set the internal audit shops up for audit failure.

Sometimes I wonder if executives would actually prefer an ineffective, impotent audit function. If internal audit can actually say what is so, these executives might actually have to change their behavior or alter their choices –and who wants that kind of scrutiny and feedback?

Executives and managers commonly put up two hurdles to effective audit shops:

  • Asking internal auditors to report to those who they audit
  • Asking internal auditors to take part in managing the entity

One audit shop I evaluated in the 90’s was required by the executives to do both. I reviewed a retirement system’s compliance with the Texas Internal Audit Act a year after the Act was passed. The internal auditor of this retirement system – we’ll call her Bonnie - reported to the executive director of the retirement system –not to the board. He directed Bonnie’s every move and kept her busy doing special projects.

Because Bonnie wanted to keep her job, she did as he instructed. She came up with an “audit plan” every year – but never completed any of the audits!

This retirement system had $24 billion in investments at the time and employed ONE ineffective internal auditor. The Texas law requires that the retirement system report to the governing board, employ a qualified director, and follow the red book and yellow book simultaneously.

Bonnie lasted in her role as internal auditor for only a few more years because she was/did none of those things. The retirement system eventually changed its ways only because they were forced to do so by state law.

Bonnie did keep her job – but her position was retitled to "executive in charge of special projects"’ and a real internal audit shop was founded. Now the retirement system employs a more appropriate number of auditors - seven.

Independence means you report to those in charge of governance

What are auditors good for? Their objective, independent take on a subject matter. The governing body is supposed to be able to rely on them to uncover and report on risks to the organization. Then the board can make an informed decision on what to do about the risks. The governing board should be able to ask the internal auditor give them a true picture of what is going on inside their entity.

But if the internal auditor is afraid to tell the truth because they are afraid of losing their jobs, what good are they?

How do you keep an internal auditor from being afraid of losing their jobs? You make sure they are structurally independent. A picture is worth a thousand words:

LIKE THIS:

NOT LIKE THIS:

If the internal auditor has to report to the people it is auditing – then these powerful people might squelch the auditors results. In the first diagram, the internal auditor (renamed the Chief Audit Executive or CAE by the Institute of Internal Auditors) reports directly to the board and doesn’t fear reprimand if they say what is so.

This is just one of the many ways an internal auditor can be shielded from political ramifications when they tell the truth. For other ideas, you can check out chapter 3 of the Yellow Book (the GAO’s Government Auditing Standards).

Here is an excerpt from the GAO’s Government Auditing Standards that discusses internal auditor independence:

Organizational Independence for Internal Audit Functions:

3.16 Certain federal, state, or local government entities employ auditors to work for management of the audited entities. These auditors may be subject to administrative direction from persons involved in the entity management process. Such audit organizations are internal audit functions and are encouraged to use the Institute of Internal Auditors (IIA) International Standards for the Professional Practice of Internal Auditing in conjunction with GAGAS. Under GAGAS, a government internal audit function can be presumed to be free from organizational impairments to independence for reporting internally if the head of the audit organization meets all of the following criteria:

a. is accountable to the head or deputy head of the government entity or to those charged with governance;

b. reports the audit results both to the head or deputy head of the government entity and to those charged with governance;

c. is located organizationally outside the staff or line-management function of the unit under audit;

d. has access to those charged with governance; and:

e. is sufficiently removed from political pressures to conduct audits and report findings, opinions, and conclusions objectively without fear of political reprisal.

3.17 The internal audit organization should report regularly to those charged with governance.

Independence means you don’t help create the subject matter of the audit

Do you have kids/dogs/cats? Aren’t they brilliant little geniuses? A gift to the world and everyone who encounters them? Look, I’ve seen your kids/dog/cat, and you have a serious problem with objectivity!

You see, when you make the baby or adopt the pet, you have a hard time calling the baby ugly or badly behaved. This is why internal auditors have to be careful to stay clear of helping management create the subject matter they will later be asked to tell the truth about.

For instance, when the Obama Administration sent billions to the states in order to help stimulate the economy, every state’s leadership was overwhelmed. They knew they had to properly account for the monies and provide performance measures for the programs lickity split! And some of them asked for help setting up proper systems from their state auditors. Wise state auditors (who act as internal auditors for state functions) told the state agencies that they were on their own. No, the state auditor wouldn’t help create policies, procedures, and tracking systems because later they needed to be able to come in and say whether these management structures were working. They needed to be able to call the baby ugly and not feel any personal embarrassment. Who wants to admit that their kid talks back to adults or that their dog steals food off the kitchen counter? No, it isn’t adorable.

The Institute of Internal Auditors and the Government Accountability Office feel differently about this subject. The IIA acknowledges that internal auditors provide two main services – assurance services (telling the truth about the subject matter) and consulting services (making a baby).

Assurance services look like this:

Consulting services look like this:

Internal auditors do know lots of stuff about a broad range of subjects and are very helpful and process oriented. They are a great addition to a management team. But, when they are part of management, they lose their objectivity about the subject matter.

A GAO employee (the GAO authors the yellow book) once told me that internal audit is an oxymoron. No, he wasn’t calling internal auditors morons! He was saying that the terms don’t jive. Internal means you lose your objectivity and can’t audit – in his mind. That because internal auditors are part of management, so giving an completely objective view of the subject matter is impossible.

The GAO has a different term for what the IIA calls consulting services – they call them non-audit services and cautions auditors about taking non-audit services on:

3.20 Audit organizations at times may perform other professional services (nonaudit services) that are not performed in accordance with GAGAS. Audit organizations that provide nonaudit services must evaluate whether providing the services creates an independence impairment either in fact or appearance with respect to entities they audit.[Footnote 27] Based on the facts and circumstances, professional judgment is used in determining whether a nonaudit service would impair an audit organization's independence with respect to entities it audits.

But in case you can’t seem to help yourself in performing non-audit/consulting services, the GAO provides a little more guidance:

3.22 The following two overarching principles apply to auditor independence when assessing the impact of performing a nonaudit service for an audited program or entity: (1) audit organizations must not provide nonaudit services that involve performing management functions or making management decisions and (2) audit organizations must not audit their own work or provide nonaudit services in situations in which the nonaudit services are significant or material to the subject matter of the audits.

3.23 In considering whether audits performed by the audit organization could be significantly or materially affected by the nonaudit service, audit organizations should evaluate (1) ongoing audits; (2) planned audits; (3) requirements and commitments for providing audits, which includes laws, regulations, rules, contracts, and other agreements; and (4) policies placing responsibilities on the audit organization for providing audit services.

3.24 If requested to perform nonaudit services that would impair the audit organization's ability to meet either or both of the overarching independence principles for certain types of audit work, the audit organization should inform the requestor and the audited entity that performing the nonaudit service would impair the auditors' independence with regard to subsequent audit or attestation engagements.

Why am I telling you these things? Because it is time for some internal auditors to have a heart-to-heart with the leaders in their organizations.

Organization leaders shouldn’t push the internal auditor to do work that will ruin their independence and should shield them from political backlash when they tell the truth. That way, the resources that are dedicated to internal auditing will yield the greatest results.


helpful checklists from the AICPA

ever wonder what a peer reviewer is looking for when they review your government engagements? Beat them to the punch, and self review using these checklists:

http://www.aicpa.org/InterestAreas/GovernmentalAuditQuality/Resources/Au...


CPA firms who don't want to write findings re: grants are missing the point

Quite frequently, I hear CPAs in my yellow book and Single Audit classes saying "You don't really write that up do you? We don't write that sort of thing up." That is because their mind is still in commercial audit mode. The owner of a corporation doesn't want you to write up every little finding - it is no one's business but hers. But in the government environment - we aren't serving the auditee - we are serving those who benefit from the grant. When we keep those folks in mind - the elderly, the poor, the CHILDREN! (yes, I get emotional about those the programs are serving) - we do write up findings. We don't care whether the auditee is happy with the results. They aren't our ultimate customer.

Here is an email conversation I had with one of my colleagues. I think my colleague does a nice job of describing why one of his client's won't write findings:


Hi, Leita:
I just finished the session with X&X. It went well,
although there were some disagreements when I talked about what the feds
expected to see in a finding....

My reply:

Hm. Many CPAs avoid writing findings like the plague. Costs too much time and time is MONEY. They miss the big picture of what they are up to – enhancing accountability and transparency in government. Was that what the disagreement was about?
Thanks for keeping me updated.
:)
Leita


Hi Leita: You got it! I used one of their findings that the entity had not kept time records, and was required to. The effect they had was that it had violated the rules, which was the condition again. The real impact was that hundreds of thousands of $ was unsupported. But they couldn't say that -- and keep the client.

One of the senior members insisted that I was expecting them to go beyond their professional responsibilities. I explained that I wasn't a federal rep. I just wanted to let them know what the fed auditors expected, so they would not be surprised if the issue came up. There was a disagreement, but it stayed friendly.

I thought of pointing out that if they were hired by the HUD OIG to do the same audits, using the same engagement letter and the same GAAS and GAGAS standards, they would report the effect if HUD had told them that's what it wanted and expected. So the professional responsibilities would have been the same (engagement letter, audit standards, A-133), but the findings would have been different because of what the client wanted to disclose in the findings. But, I decided to let that one go.

I have to do what ?*#$@ to audit government grants!?!

So you are still hanging in with this idea, eh? Even after I described how granular the audit work can be and who you will be working with in government, you are still game? Good for you. You might be made for this gig.

But before you take on a new client, I want to warn you of a few more things in this last of three articles on the subject. They might not be deal breakers – but I guess that depends on how sensitive you are to regulation.

I regularly teach full day seminars on YellowBook standards (which by the way, you are going to have to follow!) and at about 1 o’clock, the attendees start thinking about getting out of government auditing. At that point, some of them are saturated with bad news. I even had one woman in San Francisco stand up and offer her sole government client to anyone who was interested – she was done. Sort of a live e-bay auction. By the end of the day, she was back to her regular gigs - free of the constraints of government standards.

What is the Yellow Book anyway? It is also known as Generally Accepted Government Auditing Standards or GAGAS. (How is that for an attractive acronym?!?) The Yellow Book is written by the Government Accountability Office, the federal audit agency. And it regularly exceeds the standards set forth by the AICPA in the SASs (Statements on Auditing Standards for Financial Audits). Actually it is an additional governmental specific standard designed to layer on top of the AICPA standards.

Here is how the standards stack up: The Single Audit Act/OMB Circular A-133 requires that Single Audits be conducted in accordance with GAGAS. Inside GAGAS, the Single Audit is classified as a financial audit. Financial auditors must follow the edicts of chapters 1-5 (2007 version) of the Yellow Book plus the AICPA SASs.

So, did you catch that? In order to do the Single Audit, you follow three layers of directions. 1. The Single Audit requirements 2. GAGAS and 3. The AICPA’s SASs. Whew, I am tired just thinking about it!

This wasn’t that big a deal a decade ago. All three standard setting bodies were pretty quiet before the Enron debacle. Since then, the AICPA and GAO standards have been in constant state of flux. It is great for my business, as a teacher. But not so great as a practitioner.

Here are a few things that trigger a “You’ve got to be kidding!?!” response from the participants in my Yellow Book seminars.

1. Specific training. GAGAS requires auditors to get 80 hours of training that enhances their ability to conduct audits every two years. Out of this 80 hours, 24 of it must be in government topics or topics relevant to your audit environment. This means that your tax update classes won’t count! Here is the specific relevant paragraph from GAGAS:

GAGAS 2007 3.46 Auditors performing work under GAGAS, including planning, directing, performing field work, or reporting on an audit or attestation engagement under GAGAS, should maintain their professional competence through continuing professional education (CPE). Therefore, each auditor performing work under GAGAS should complete, every 2 years, at least 24 hours of CPE that directly relates to government auditing, the government environment, or the specific or unique environment in which the audited entity operates. For auditors who are involved in any amount of planning, directing, or reporting on GAGAS assignments and those auditors who are not involved in those activities but charge 20 percent or more of their time annually to GAGAS assignments should also obtain at least an additional 56 hours of CPE (for a total of 80 hours of CPE in every 2-year period) that enhances the auditor's professional proficiency to perform audits or attestation engagements. Auditors required to take the total 80 hours of CPE should complete at least 20 hours of CPE in each year of the 2-year period.

2. Extra nagging regarding independence: As of this writing, GAGAS is in the middle of revision. The 2011 version of the Yellow Book should be out… well hopefully in 2011. The exposure draft continues on a theme that the GAO has always emphasized; while the GAO doesn’t specifically prohibit auditors from creating financial statements for their audit clients, they definitely don’t like it. Here is an excerpt from the 2010 proposed revision:

GAGAS 2010 Proposed 3.44. Bookkeeping is the systematic recording of an entity's transactions. Auditors performing bookkeeping services for an audited entity they audit should determine that the audited entity's management is providing sufficient oversight of those services. Auditors should determine that the audited entity's management
responsible for oversight possesses suitable skill, knowledge, and/or experience to evaluate the adequacy of the bookkeeping services provided, and accepts responsibility for the results of the services.

3.45. Bookkeeping services that would impair an auditor's independence include:

a. determining or changing journal entries, account codings or classifications for transactions, or other accounting records for an entity without obtaining the entity's approval,

b. authorizing or approving transactions,

c. preparing source documents, and,

d. making changes to source documents without client approval.

Preparing Financial Statements:

GAGAS 2010 Proposed 3.46. Management is responsible for the preparation and fair presentation of the financial statements in accordance with the applicable financial reporting framework. Consequently an auditor's acceptance of responsibility for the preparation and fair presentation of financial statements that the auditor will subsequently audit would impair the auditor's independence. Auditors should determine that audited entity management taking responsibility for the preparation and fair presentation of the financial statements possesses suitable skill, knowledge, and/or experience to evaluate the adequacy of any services in this area provided by the auditor.

When I read that, I am discouraged from coming up with journal entries and preparing the financial statements. But it doesn’t expressly prohibit it, does it? Very much like a nagging - but ultimately powerless - parent.

This causes lots of angst during my seminars because auditors believe three things: 1. Their tiny client can’t create the financials or won’t pay for a third party to prepare them 2. The client expects the auditor to do it and 3. The auditor’s life is easier if they create the financials they end up auditing.

Unfortunately, the GAO isn’t exactly sympathetic to any of those views. But just like a nagging but ineffective parent, they are always talking but never putting their foot down or taking the keys to the car. This is something to keep your eye on when the next revision comes out.

3. The GAO isn’t happy just hearing about symptoms – they want a diagnosis of the root cause. In order to enhance transparency and accountability in government, GAGAS asks that auditors don’t stop at simply pointing out flaws in the client’s operations or in compliance. The GAO wants to know why the flaw occurred, whether it is a big deal, and what should be done about it. The GAO asks auditors to describe the elements of a finding (condition, effect, cause, criteria, recommendation) and this makes the auditor perform extra work, because the effect and root cause don’t necessarily present themselves to the auditor on a silver platter. For more on this topic, please see the newsletter archive athttp://www.yellowbook-cpe.com .

4. Additional reportable conditions – under GAGAS auditors have two additional triggers of a finding in addition to those laid out in the SASs. Under the SASs, internal control weaknesses and fraud are reportable.

The GAO adds non-compliance and abuse to the mix. First, government auditors must design their audits to uncover significant non-compliance with grants and contracts. That isn’t that big a deal to most folks, because that is one of the subject matters for the Single Audit anyway.

But the second additional responsibility, abuse, does cause auditors pause:

4.12 Abuse involves behavior that is deficient or improper when compared with behavior that a prudent person would consider reasonable and necessary business practice given the facts and circumstances. Abuse also includes misuse of authority or position for personal financial interests or those of an immediate or close family member or business associate. Abuse does not necessarily involve fraud, violation of laws, regulations, or provisions of a contract or grant agreement.

4.13 If during the course of the audit, auditors become aware of abuse that could be quantitatively or qualitatively material to the financial statements, auditors should apply audit procedures specifically directed to ascertain the potential effect on the financial statements or other financial data significant to the audit objectives. After performing additional work, auditors may discover that the abuse represents potential fraud or illegal acts. Because the determination of abuse is subjective, auditors are not required to provide reasonable assurance of detecting abuse.

Abuse is a criteria-less complaint about bad behavior in government.

An audit is the evaluation of a subject matter against criteria. For non-compliance, the criteria is the law or regulation the subject matter should meet. For internal controls, the criteria is COSO. For fraud, the criteria is the elements of a crime per statute. But who is to say if everyone in the government agency, including the janitor, needs a i-Pad and i-Phone or not? Is that wasteful and abusive? Some would say yes, others might say no. And because there is no objective criteria to go on, they are both right.

What about a tribal council traveling monthly to the Bellagio in Vegas to do research on how to operate a good casino? What if they took friends and family with them and partied down (presumably to replicate the customer experience)? What if other members of the tribe were living in trailers and the sewer system was in serious need of repair? Is that abuse? The tribal council thought that luxury travel was a perk of their job.

The auditor thought otherwise. Because they weren’t breaking any particular law, the auditor and the tribal council fought. The auditor put the abuse in their audit report and was promptly fired. But did he do the right thing? I think so.

Why does the government want us to report waste and abuse? Because we are on the front lines and see this stuff. The feds may never visit. And if we don’t say anything, who will? 60 Minutes only has so many shows a year; they can’t cover every wasteful scandal!

So to sum it all up – auditing in the government environment is trippy, different, sometimes flat out annoying. Most practitioners find it easiest to either embrace government accounting or walk away from it all together. Playing the middle and just dabbling in this environment can be a dangerous headache because of the intense expectations and scrutiny. Don’t say I didn’t tell you.

-----

Leita Hart-Fanta, CPA, CGFM

Resides in Austin, Texas and can be reached at www.auditskills.com.


Sunday, August 28, 2011

Unfunded Obligations Amount to $534K per Household

Did you catch the front page headline in USA Today on June 7?

US owes $62 trillion

http://www.usatoday.com/news/washington/2011-06-06-us-owes-62-trillion-i...

I can't get to the actual paper without a subscription. But if you can get to the paper - and can read the last paragraph...

The government has promised pension and health benefits worth more than $700,000 per retired civil servant. The pension fund's key asset: federal IOU's

Can You Take Low Inherent Risk Compliance Items Off of Your Audit Plate?

I started an online conversation regarding the Single Audit a few weeks ago - and it still isn't completely resolved. Here is the email I sent to my referencial gurus:

Hi Smart People -

Please take a minute to ponder this question and give me your opinion on it.

Last week, I was teaching Single Audit stuff at a CPA firm and argued that SAS 117 gave the auditor the ability to use the risk assessment formula (especially IR!) to get compliance items off their plate. If it the item wasn't inherently risky, then there was no need to worry about controls over the item.

An audit manager agreed that would be great and that would reduce his efforts significantly. But upon further research, he wasn't sure that the standards would let him get away with it. As you guys know, the standards can be vague and contradictory and I am constantly trying to reduce the scope of the audit.

Here is my thinking and find relevant quotes from SAS 117 and OMB Circular A-133 below:

  • You have 14 compliance items per major grant
  • You can take a few off your plate right off the bat, because they aren't relevant to the program
  • Then you assess inherent risk of the remaining requirements

  • If they are inherently risky – moderately or highly risky – then you would determine whether the entity has controls in place to mitigate these risks and test these controls (because of that phrase above in OMB Circular A-133 that says "plan for a low assessed level of control risk")

  • But if the compliance item doesn't generate a very big 'who cares' or inherent risk – then you don't have to evaluate the controls. ? And what if you went one step further and didn't even evaluate compliance? (OK – that might be taking things too far!) But it would be nice to blow off the evaluation of controls.

SAS 117:

The auditor should design and perform further audit procedures in response to the assessed risks of material non-compliance. These procedures should include performing tests of controls over compliance if:

  • The auditor's risk assessment includes an expectation of the operating effectiveness of controls over compliance related to the applicable compliance requirements;
  • Substantive procedures alone do not provide sufficient appropriate audit evidence; or
  • Such tests of controls over compliance are required by government audit requirements

If an of the conditions in this paragraph are met, the auditor should test the operating effectiveness of controls over each applicable compliance requirement to which the conditions apply in each compliance audit.

OMB Circular A-133

(c) Internal control.

(1) In addition to the requirements of GAGAS, the auditor shall perform procedures to obtain an understanding of internal control over Federal programs sufficient to plan the audit to support a low assessed level of control risk for major programs.

(2) Except as provided in paragraph (c)(3) of thissection, the auditor shall:

(i) Plan the testing of internal control over major programs to support a low assessed level of control risk for the assertions relevant to the compliance requirements for each major program; and

(ii) Perform testing of internal control as planned in paragraph (c)(2)(i) of this section.

(3) When internal control over some or all of the compliance requirements for a major program are likely to be ineffective in preventing or detecting noncompliance, the planning and performing of testing described in paragraph (c)(2) of this section are not required for those compliance requirements. However, the auditor shall report a reportable condition (including whether any such condition is a material weakness) in accordance with §___.510, assess the related control risk at the maximum, and consider whether additional compliance tests are required because of ineffective internal control.

(d) Compliance.

(1) In addition to the requirements of GAGAS, the auditor shall determine whether the auditee has complied with laws, regulations, and the provisions of contracts or grant agreements that may have a direct and material effect on each of its major programs.

(2) The principal compliance requirements applicable to most Federal programs and the compliance requirements of the largest Federal programs are included in the compliance supplement.

(3) For the compliance requirements related to Federal programs contained in the compliance supplement, an audit of these compliance requirements will meet the requirements of this part. Where there have beenchanges to the compliance requirements and the changes are not reflected in the compliance supplement, the auditor shall determine the current compliance requirements and modify the audit procedures accordingly. For those Federal programs not covered in the compliance supplement, the auditor should use the types of compliance requirements contained in the compliance supplement as guidance for identifying the types of compliance requirements to test, and determine therequirements governing the Federal program by reviewing the provisions of contracts and grant agreements and the laws and regulations referred to in such contracts and grant agreements.

(4) The compliance testing shall include tests of transactions and such other auditing procedures necessary to provide the auditor sufficient evidence to support an opinion on compliance.

What do you think of that approach?

Thanks mucho!

Leita

And here are their responses:

response #1:

Hi Leita,

Here are my thoughts:

A-133 indicates that the auditor shall perform procedures to obtain an understanding of controls sufficient to plan the audit to support a low assessed level of “control risk” (not a low combined inherent and control risk). In addition, it is my understanding that SAS 117 requires controls over “each applicable compliance requirement” to be understood and tested in planning to support a low assessed control risk (unless deemed ineffective to begin with) when such tests are required by government audit requirements (such as A-133 requires). If my understanding is accurate, it would seem that an “applicable compliance requirement” should not be eliminated from this control understanding and testing merely because it is considered to have a low inherent risk of noncompliance. While it seems logical that low inherent risk of noncompliance should drive the level of control understanding and testing for an applicable compliance requirement, the A-133 audit requirement is unique (and maybe illogical) and differs from a financial statement audit where a low inherent risk can have a direct impact whether controls are tested.

These are my initial thoughts, but I am always open to new ideas.

Response #2:

Your thoughts are good, but they are not quite correct.

First, while there are 14 requirement, they do not all apply to every program.

1. You only have to deal with the ones that do apply to a specific major program.

2. Some of those may not have a direct or material effect on the program and those you can eliminate from audit testing, but YOU MUST EXPLAIN WHY!

3. All the others must be tested:

a. Here is where inherent risk comes into play, the lower the inherent risk the lower the risk of material misstatement and therefore the less testing you have to do.

In summary, every requirement that applies to a major program must either be tested or explained away as not have a direct and material effect.

Response #3:

Leita,
I don't have enough experience with OMB A-133 to be able to answer this with any kind of confidence. I think that is the key. Because if a compliance requirement is material according to OMB A-133 then I think that makes it material to the audit, regardless of whether it meets the "usual" materiality standards. That's because of the section (can't remember the cite) that requires you to include qualitative risks.
A-133, bolded below, says "assertions relevant to the compliance requirements" NOT assertion relevant to the MATERIAL compliance requirements.
I could certainly be wrong, but that's my gut feel at present. What you are saying certainly makes logical and even economic sense though.
Linda
A-133
(i) Plan the testing of internal control over major programs to support a low assessed level of control risk for the assertions relevant to the compliance requirements for each major program
After I sent these to the very smart and thorough auditor at the CPA firm, he responded with the following:

I will be working on setting up our single audit templates soon based on CCH’s practice aids. I was reading up on the AICPA guide for single audits. Here are some interesting paragraphs from the guide that I think supports your methodology and will allow us to remove any low risk areas……

6.25 SAS No. 117 defines applicable compliance requirements as compliance requirements that are subject to a compliance audit. SAS No. 117 also states that some governmental audit requirements provide a framework for the auditor to determine the applicable compliance requirements and cites the OMB Circular A-133 Compliance Supplement (Compliance Supplement) as such a framework in a Circular A-133 compliance audit. Therefore, in a Circular A-133 compliance audit, the applicable compliance requirements are those that may have a direct and material effect on each major program (direct and material compliance requirements). Further, the Compliance Supplement is the primary source for identifying compliance requirements for federal programs, and the auditor, using professional judgment, determines which of the 14 types of compliance requirements may have a direct and material effect on each major program. These direct and material compliance requirements are tested as part of the compliance audit. A program specific audit guide issued by a grantor agency may be another source for identifying applicable compliance requirements. For programs not included in the Compliance Supplement, Part 7 of that document instructs auditors to, among other things, review the federal award document and referenced laws and regulations applicable to the program and the Catalog of Federal Domestic Assistance. Chapter 10 Database 'Research Mgr - MOM Authoring', View '7.a. Content in Process\a. by Team', Document 'Accounting; Auditing'of this guide further discusses the use of the Compliance Supplement to identify direct and material compliance requirements.

6.38 SAS No. 117 Database 'Research Mgr - MOM Authoring', View '7. Main Content Authoring\a. Contents', Document 'Auditing'states that the auditor should assess the risks of material noncompliance whether due to fraud or error for each applicable compliance requirement (PER 6.25 ABOVE, THESE ARE ONLY THE DIRECT AND MATERIAL REQUIREMENTS)14 and should consider whether any of those risks are pervasive to the entity’s compliance.

10.15 In a Circular A-133 compliance audit, the auditor should perform the following, as discussed in paragraphs 10.16–.69:

a. Identify the auditee’s major programs to be tested and reported on for compliance

b. Identify the compliance requirements applicable to each major program

c. Determine which of the compliance requirements identified in step (b) could have a direct and material effect on each major program (ASSESS RISK IR – Eliminate low IR areas)

d. Plan the engagement

e. Consider relevant portions of the entity’s internal control over compliance for each direct and material compliance requirement for each major program

f. Obtain sufficient appropriate audit evidence, which involves testing internal control over compliance and compliance with direct and material compliance requirements for each major program

g. Consider indications of abuse

h. Consider subsequent events

i. Form an opinion about whether the auditee complied with the direct and material compliance requirements

j. Perform follow-up procedures on previously identified findings

10.17 As discussed in this section, the auditor should determine, after identifying the compliance requirements applicable to each major program, the direct and material compliance requirements to be tested and reported on in a Circular A-133 compliance audit. As further described in paragraph 10.19, Part 2 Database 'Research Mgr - MOM Authoring (New)', View '7.a. Content in Process\a. by Team', Document 'Government'of the Compliance Supplement provides a matrix that is useful to the auditor in identifying whether particular types of compliance requirements may apply to federal programs. The auditor then assesses, based on the nature of the program and the transactions for the period under audit, those types of compliance requirements that may have a direct and material effect on each major program. The auditor should use professional judgment in making this determination.

10.19………..In making a determination not to test a type of compliance requirement identified as applicable to a particular program, the auditor should conclude, and document such conclusion, either that the requirement does not apply to the particular auditee or that noncompliance with the requirements could not have a direct and material effect on a major program.

10.33 In planning the audit, the auditor should use knowledge gained in the inherent risk of noncompliance assessment process (as described in chapter 6 of this guide) to (a) identify types of potential noncompliance, (b) to consider other factors that affect the risks of material noncompliance, and (c) to design appropriate tests of compliance to reduce the risk of significant noncompliance to a sufficiently low level.

Thus, it appears that, although this is not the official “risk assessment,” a sifting of the compliance requirements that may have a direct and material effect should occur (your “high likely and magnitude”). By doing this, we eliminate any of the 14 compliance areas that do not have a direct and material effect (which to me, would include those that would be low risk) from even being considered in the overall risk assessment (since they would not be considered “applicable”). Any of these that are eliminated, we would need to document why (which could be accomplished in a similar manner as when we document a low inherent risk).

Thus, I think we are more/less accomplishing the same goal. We should “sift out” our low risk compliance areas and end up only with those high risk areas to further assess and perform substantive/control tests. So, maybe the intent is to only test controls on areas with high inherent risk and NOT test low risk areas (no controls or substantive testing).

What do you think?


Well, I think I want to get stuff of of my audit plate - because every chosen compliance item creates a whole little world of work. It is risky. The federal government would prefer that you cover every little item - but that is not a reasonable expectation.
Now the question is - what do you think? Let me know.