by John McCarthy Consulting Ltd. | Oct 14, 2023 | Blog, News
Continuing from last week’s blog we are looking at the guidance issued in ISA 240 ‘The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements’

I
Continuing the items to be documented by the audit engagement team in their discussion of how fraud might be perpetrated in the audit client. That discussion needs to be structured around these headline items (continued from last week):
- Whether there are economic, industry and operating conditions that give rise to fraud risk factors for particular classes of transactions, account balances and disclosures. (Examples of economic, industry and operating conditions that may give rise to fraud risk factors are included in the examples of incentives/pressures and opportunities in Appendix 1.)
- A consideration of any material frauds of which team members have experience in companies in the same industry and whether there are similar risks – see our blog of 3 October about the Protected Disclosures
- A consideration of management’s involvement in overseeing employees with access to cash or other assets susceptible to misappropriation.
- A consideration of any unusual or unexplained changes in behavior or lifestyle of management or employees which have come to the attention of the engagement
- An emphasis on the importance of maintaining a proper state of mind throughout the audit regarding the potential for material misstatement due to fraud.
- A consideration of the types of circumstances that, if encountered, might indicate the possibility of fraud.
- A consideration of how an element of unpredictability will be incorporated into the nature, timing and extent of the audit procedures to be performed.
- A consideration of the audit procedures that might be selected to respond to the susceptibility of the entity’s financial statement to material misstatement due to fraud and whether certain types of audit procedures are more effective than
- A consideration of any allegations of fraud that have come to the auditor’s
- A consideration of the risk of management override of controls.
- A consideration of the extent of segregation of duties and whether and how that may be overridden.
- A consideration of how those charged with governance and management promote a culture of honesty and integrity; what policies they have to facilitate and encourage reporting of wrongdoing (see the Protected Disclosures regime mentioned above); and how they respond to any such reports.
- A consideration of audit team experience, or other knowledge, of the competencies and attitudes of employees in areas where there are risks of material misstatement.
- Circumstances where it may be beneficial to have further discussion(s) among the engagement team at later stages in the audit may include, for example, when the auditor’s evaluation of audit evidence has provided further insight about the risks of material misstatement due to fraud (see more in ISA 240 paragraph A50) or members of the audit team have identified:
- Fraud risk factors that were not covered in the original discussion.
- Actual or suspected fraud.
Further guidance on these topics is given in Application paragraphs A12 and A12-1 in the standard.
IT Controls Assessment
Auditors are reminded that there are relatively significant changes in the requirements of ISA 315 Identifying and Assessing the Risks of Material Misstatement for accounting periods commencing 15 December 2021, which in practical terms means, accounting periods Ended 31 December 2022 and later.
Auditors dealing with the audits of entities with such accounting periods affected by these change will need, to adopt new audit programmes and, in additional to the normal audit tests, to also assess the entity’s IT controls (no matter what the size of that entity).
This is a significant new development for auditors of SMEs, in particular, and will be a game changer ion the type of audit documentation and evidence of assessment of such IT controls by the auditor on audit files.
For an easy to implement additional (two page) IT Controls Questionnaire to help document the above process, please click on this link to download immediately for only €60 + VAT.
Please also go to our website to see our:
- Anti-Money Laundering Policies Controls & Procedures Manual (March 2022) – View the Table of Contents click here.
- AML webinar (March 2022) available here, which accompanies the AML Manual. It explains the current legal AML reporting position for accountancy firms and includes a quiz. Upon completion, you receive a CPD Certificate of attendance in your inbox.
- letters of engagement and similar templates. Please visit our site here where immediate downloads are available in Word format. A bulk discount is available for orders of five or more items if bought together.
- ISQM TOOLKIT or if you prefer to chat through the different audit risks and potential appropriate responses presented by this new standard, please contact John McCarthy FCA by e-mail at john@jmcc.ie.
We typically tailor ISQM training and brainstorming sessions to suit your firm’s unique requirements. The ISQM TOOLKIT 2022 is available to purchase here.
by John McCarthy Consulting Ltd. | Sep 20, 2023 | Blog, News
The ‘fraud triangle’ (shown below) is a well-known tool for enabling discussions among audit teams about the possible ‘climatic’ factors that may be present in an audit client. Where all three coincide, fraud is much more likely to be present.

ISA 240 ‘The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements’ was re-issued in October 2022 with additional requirements (among other topics) to do with the audit engagement team discussion.
For the purposes of this blog (Part 1 of a 2 part series) we are focusing on the main areas of the audit team discussion.
‘The discussion shall include an exchange of ideas among engagement team members about fraud risk factors, including:
- incentives for management or others within the entity to commit fraud;
- how management could perpetrate and conceal fraudulent financial reporting; and
- how assets of the entity could be misappropriated (ISA 240.16.1)
For a group audit, the discussion among the group engagement team shall include matters to discuss with the component auditor of a significant component about the susceptibility of the component to material misstatement of the financial information of that component due to fraud. (ISA 240.16.2)
If allegations of fraud come to the auditor’s attention, the discussion shall include how to investigate and respond to those allegations. (ISA 240.16.3) see last week’s blog on the expanded Protected Disclosures regime now in force in Ireland and which will have implications for auditors of the affected entities.
The standard allows for the initial engagement team discussion to be later revisited and revised, where necessary, when ‘fraud risk factors that have been identified during the course of the audit and the implications for the audit’ considered (ISA 240.16.4)
Basically the audit engagement team is expected to document a discussion of how fraud might be perpetrated in the audit client. That discussion needs to be structured around the headline items shown below:
The guidance focuses on:
- incentives to manage earnings or key performance indicators derived from the financial statements in order to deceive financial statement users by influencing their perceptions as to the entity’s performance and profitability;
- A consideration of circumstances that might be indicative of earnings management and the practices that might be followed by management to manage earnings that could lead to fraudulent financial reporting.
- A consideration of the risk that management may attempt to present disclosures in a manner that may obscure a proper understanding of the matters disclosed (for example, by including too much immaterial information or by using unclear or ambiguous language).
- A consideration of the known external/internal factors affecting the entity that may create an incentive or pressure for management or others to commit fraud, provide the opportunity for fraud to be perpetrated, and indicate a culture or environment that enables management or others to rationalize committing
Further guidance on these topics is given in Application paragraphs A12 and A12-1 in the standard. We will say more about this topic next week.
IT Controls Assessment
Auditors are reminded that there are relatively significant changes in the requirements of ISA 315 Identifying And Assessing The Risks Of Material Misstatement for accounting periods commencing 15 December 2021, which in practical terms means, accounting periods Ended 31 December 2022 and later.
Auditors dealing with the audits of entities with such accounting periods affected by these change will need, to adopt new audit programmes and, in additional to the normal audit tests, to also assess the entity’s IT controls (no ,matter what the size of that entity).
This is a significant new development for auditors of SMEs, in particular, and will be a game changer ion the type of audit documentation and evidence of assessment of such IT controls by the auditor on audit files.
For an easy to implement additional (two page) IT Controls Questionnaire to help document the above process, please click on this link to download immediately for only €60 + VAT.
Please go to our website to see our:
- letters of engagement and similar templates. Please visit our site here where immediate downloads are available in Word format. A bulk discount is available for orders of five or more items if bought together.
- ISQM TOOLKIT or if you prefer to chat through the different audit risks and potential appropriate responses presented by this new standard, please contact John McCarthy FCA by e-mail at john@jmcc.ie.
We typically tailor ISQM training and brainstorming sessions to suit your firm’s unique requirements. The ISQM TOOLKIT 2022 is available to purchase here.
by John McCarthy Consulting Ltd. | Sep 20, 2023 | Blog, News
The Protected Disclosures (Amendment) Act 2022 (the Act) requires certain entities to have in place procedures to establish internal reporting channels and procedures to enable workers make protected disclosures (defined as a ‘relevant wrongdoing’). From 17 December 2023 its scope will be expanded to employers with over 50 employees.
The Act already applies to certain entities from 1 January 2023 including entities employing over 250 employees and certain financial services (regardless of employee numbers) entities like AIFMs, MiFID firms, Irish UCITS management companies and other Irish financial service providers, as well as Irish domiciled corporate funds.
The 2022 Act expands the scope of the Protected Disclosures Act, 2014 to include areas such as:
- public procurement;
- financial services;
- anti-money laundering (AML);
- product safety and compliance;
- transport safety;
- environmental protection;
- radiation and nuclear safety;
- food and animal health and welfare;
- public health;
- consumer protection; and
- the protection of privacy and personal data.
Its scope is being enhanced from 17 December 2023 when employers with over 50 employees will need to have such a policy in place. The basic steps for employers are:
- the establishment, maintenance and operation of a secure and confidential internal reporting channel for workers who wish to make a protected disclosure, whether in writing, orally or both;
- the designation of an impartial and competent person who may be internal/external; and
- an obligation to provide workers with information on the internal/external protected disclosure reporting process.
The Act also creates a newly established Office of the Protected Disclosures Commissioner (www.opdc.ie) which will forward reports of work-related wrongdoing to the most appropriate body for initial assessment and follow-up.
Employees are given protection from dismissal from employment (among other protections) when they report a ‘relevant wrongdoing’ (defined which are defined to include:
- Where an offence has been or is likely to be committed;
- Non-compliance with a legal obligation – the 2014 Act excludes obligations arising under the worker’s contract of employment;
- A miscarriage of justice;
- Danger to the health and safety of any individual;
- Damage to the environment;
- An unlawful or otherwise improper use of funds or resources of a public body;
- Oppression, gross neglect or gross mismanagement by a public body; and
- Other breaches related to the financial interests of the EU the internal market, EU competition and state aid rules and internal market rules on corporate tax.
The legislation is complex and we cannot cover all its aspects in the space of a blog. We urge our readers to seek independent professional and legal advice where necessary.
IT Controls Assessment
Auditors are reminded that there are relatively significant changes in the requirements of ISA 315 Identifying And Assessing The Risks Of Material Misstatement for accounting periods commencing 15 December 2021, which in practical terms means, accounting periods Ended 21 December 2022 and later.
Auditors dealing with the audits of entities with such accounting periods affected by these change will need, to adopt new audit programmes and, in additional to the normal audit tests, to also assess the entity’s IT controls (no ,matter what the size of that entity).
This is a significant new development for auditors of SMEs, in particular, and will be a game changer ion the type of audit documentation and evidence of assessment of such IT controls by the auditor on audit files.
For an easy to implement additional (two page) IT Controls Questionnaire to help document the above process, please click on this link to download immediately for only €60 + VAT.
Please go to our website to see our:
- letters of engagement and similar templates. Please visit our site here where immediate downloads are available in Word format. A bulk discount is available for orders of five or more items if bought together.
- ISQM TOOLKIT or if you prefer to chat through the different audit risks and potential appropriate responses presented by this new standard, please contact John McCarthy FCA by e-mail at john@jmcc.ie.
We typically tailor ISQM training and brainstorming sessions to suit your firm’s unique requirements. The ISQM TOOLKIT 2022 is available to purchase here.
by John McCarthy Consulting Ltd. | Dec 19, 2022 | Blog, News
As many are already aware, access to the RBO Register has recently been shut down, following an EU Court of Justice ruling.
Access to the Register of Beneficial ownership registry is only now being reopened to registered designated persons, which includes accountants in practice.
In order to gain access to the Register from now on, Designated Persons will need to appoint an authorised administrator register themselves, using a Form BEN3A1 Designated Persons Administration Declaration form (fillable online).
We suggest readers monitor the home page of the RBO for more information which will appear there as soon as it becomes available.
Meanwhile, for those of you still in the process of ISQM 1 implementation, please see our new ISQM TOOLKIT or if you prefer to chat through the different audit risks and potential appropriate responses presented by this new standard, please call or e-mail John McCarthy FCA or e-mail him at john@jmcc.ie.
We typically tailor training and brainstorming sessions to suit your firm’s unique requirements.
Publications and AML webinar
To ensure your letters of engagement and similar templates are up to date visit our site here where immediate downloads are available in Word format. A bulk discount is available for orders of five or more items if bought together.
by John McCarthy Consulting Ltd. | Dec 13, 2022 | Blog, News
The ISQM 2 comes into effect on 15 December 2022. It relates to what used to be called ‘engagement quality control reviews’.
These are now called ‘engagement quality reviews’ also known as Engagement Quality Review (EQR or EQ review). These are also referred to as Hot File Review.
The main changes are as follows:
- The standard require the reviewer to challenge the engagement partners’ judgments much more than in the previous requirements. In the past, reviews have sometimes focused on process more than on assessing the quality of judgments.
- The scope of the standard, at least for small and medium firms with non-PIE or listed audits states that reviews should be required:
-
- for ‘other engagements’ that are required by law or regulation; and
- audits and other engagements that the firm itself determines should be reviewed in response to a specific ‘quality risk’.
These types of audit engagement could include those where there are:
-
- high levels of complexity or judgment;
- un-remediated deficiencies in internal control at the audit firm;
- there are recurring inspection findings on the audit; and
- engagements for new clients where there were disagreements with the previous auditor.
Some firms that didn’t need an EQ review in the past may need one in the future as the scope for avoiding one will probably be narrower. However the implications are not clear. It will ultimately depend on individual firms’ assessment of their quality risks and the types of appropriate responses to such risks which may include an EQ review.
Who can carry out the EQR?
Reviewers will need sufficient seniority/experience, with sufficient time and resources allowed to do the job properly.
With ever-increasing emphasis on quality generally within firms and the adverse consequences associated with quality failings, it seems likely that the role of EQ reviewer will be an even more challenging one in future.
As regards documenting Audit Firms’ statement of Quality Management (SoQM), We typically tailor training and brainstorming sessions to suit your firm’s unique requirements.
For more assistance please see our new ISQM TOOLKIT or if you prefer to chat through the different audit risks and potential appropriate responses presented by this new standard, please call or e-mail John McCarthy FCA or e-mail him at john@jmcc.ie
Publications and AML webinar
To ensure your letters of engagement and similar templates are up to date visit our site here where immediate downloads are available in Word format. A bulk discount is available for orders of five or more items if bought together.
by John McCarthy Consulting Ltd. | Dec 6, 2022 | Blog, News
Root cause analysis (RCA) is a requirement of the new ISQM 1 which comes into effect in less than 10 days. It is one of the eight main components of that standard.
Audit firms will be expected to carry out RCA from 15 December 2022 and have the results and implementation action plan available for inspection by audit monitoring teams in 2023.
RCAs main objective is to examine the more serious audit deficiencies that have occurred during either hot or cold file reviews and involves asking ‘why’ questions, typically five times. The ultimate aim being to prevent them from happening again.
Known as the ‘5 Whys’ technique – it is allegedly attributed to the famously successful Toyota vehicle manufacture process.
In the audit world you might find that the source of a problem is lack of adequate staff training or staff performing audit work with an out of date disclosure checklist – the root problem occurs there.
But what is the root cause of the problem? The answer lies in going deeper by asking why the problem occurred. Asking “Why?” five times requires taking the answer to the first why and then asking why that occurs.
Typically, the process of asking “Why?” leads upstream in the process. It may be a defect that occurs in planning, but the root cause may be in the poor quality of client records, or perhaps a lack of sufficiently critical sceptical thinking on the part of the audit team.
Some typical root cause that we have come across include:
- risk assessment at the planning stage of the audit;
- the extent of audit evidence obtained and the level of documentation; and
- the degree of disclosure within the financial statements.
A common reason for these types of issue is a lack of understanding of the ISAs (Ireland) or accounting standards. Some firms insist on staff reading the ISAs as a basic starting point. What a good idea?
The 2022 book of the ISAs (Ireland) is available from the CAI store here. (We promise we don’t get a commission!). These standards are essential reading for all audit teams, especially with so many modifications to the standards coming into play for accounting periods ending 31 December 2022.
Other reasons that can be root causes include:
- flaws in the design of audit tests and
- inadequate review by senior audit team personnel (i.e. the audit manager or the audit engagement partner) as well as;
- Client familiarity which can play a part in leading to poorer quality audit documentation.
For more assistance please see our new ISQM TOOLKIT or if you prefer to chat through the different audit risks and potential appropriate responses presented by this new standard, please call or e-mail John McCarthy FCA or e-mail him at john@jmcc.ie
Publications and AML webinar
To ensure your letters of engagement and similar templates are up to date visit our site here where immediate downloads are available in Word format. A bulk discount is available for orders of five or more items if bought together.