Education / Flow

FlowAustralian rules

Audits 101: how to navigate them for your clients

When dealing with money, the importance of financial accuracy and reliability cannot be understated. Whether it’s for investors making decisions, creditors assessing creditworthiness, or regulatory authorities ensuring compliance, the trust placed in financial statements is of utmost importance.

This is where audits, usually performed by diligent accountants and bookkeepers, play a vital role.

Below, we will explore the significance of audits and explore their crucial role in ensuring the integrity of financial records. From the importance of audits in enhancing credibility to the key steps involved in the audit process, we will provide a comprehensive understanding of this critical aspect of financial management.

Why are audits important?

As you well know, the purpose of an audit is to provide an independent and objective evaluation of an organisation’s financial records and statements. As a bookkeeper, your client will likely go through audits from various regulatory authorities, such as the Australian Tax Office (ATO).

Audits serve multiple important purposes.

They help ensure accuracy.

First and foremost, audits help ensure the accuracy and reliability of financial information. By thoroughly examining books and records, auditors can verify the completeness and correctness of transactions, ensuring that the financial statements present a true and fair view of the organisation’s financial position.

They build credibility.

Audits enhance the credibility and trustworthiness of financial statements (and, of course, the organisation they belong to).

When financial statements are audited, it adds an additional layer of assurance for stakeholders, such as investors, creditors, and regulatory authorities.

The independent opinion provided by auditors adds credibility to the financial information presented, instilling confidence in users of the statements that they are reliable and free from material misstatements.

Case Study: Where a Failure to Audit Properly… leads to failure

Financial professionals may be familiar with the downfall of FTX, a now-bankrupt cryptocurrency exchange and hedge fund. It was one of the largest crypto currency exchanges in the world, but filed for bankruptcy in 2022.

Reportedly an independent review of FTX’s audited financial statements revealed a “a series of red flag related-party transactions” that should have led to more scrutiny. This included a huge stake in “unlocked FTT” and “FTT collateral”, which was a coin invented by FTX’s owner.

Read more: ‘A Complete Failure of Corporate Controls’: What Investors and Accountants Missed in FTX’s Audits | CoinDesk

When will your clients be audited?

Generally speaking, audits may happen in a range of circumstances. These may include internal audits, audits mandated by law or audits done for a particular purpose.

You or your client will be audited at some stage in. We’ll explain some of the type of audits below.

Mandatory audits

Audits may be a mandated requirement by law or a government agency.

Government bodies and agencies often require organisations to undergo audits to ensure compliance with tax laws, financial reporting regulations or specific industry regulations. For example, the Australian Securities & Investments Commission requires that large proprietary companies must prepare and lodge financial reports and a director’s report for each financial year, and that the accounts must be audited.

Some industries are even more regulated, such as banking, insurance and securities. Regulatory authorities may require audits to assess financial stability, adherence to regulations and protection of stakeholders. For example, the Australian Prudential Regulatory Authority’s Prudential Standard APS 310 requires authorised deposit-taking institutions such as banks to appoint an auditor.

Internal audits

Internal audits are conducted by financial professionals employed within an organisation - such as your in-house bookkeeper or accountant. They focus on evaluating internal controls, risk management and operational efficiency, and often have the benefit of having company-specific knowledge that a third party may not have.

Management and the board of directors of a company, for example, may initiate internal audits to assess the effectiveness of internal controls, identify potential risks and evaluate compliance with policies and procedures.

In larger organisations, an audit committee comprising board members may oversee internal audit activities. They would usually request audits to monitor the organisation’s financial health, internal control environment and compliance with regulatory requirements.

Special purpose audits

Special purpose audits are conducted for specific reasons beyond the scope of regular financial audits. They may be initiated by external parties or internal stakeholders. The entities that request special purpose audits may include:

  • Shareholders and investors: they may request audits to gain an independent evaluation of an organisation’s financial position, assess the accuracy of financial statements or validate the financial health of the company.
  • Potential buyers or lenders: When a company is involved in a merger, acquisition, or financing arrangement, potential buyers or investors may request audits to obtain a clear understanding of the target company’s financial position, risks and opportunities.
  • Granting institutions: Non-profit organizations and research institutions that rely on grants and funding may be required to undergo audits to demonstrate accountability, ensure proper usage of funds and comply with other grantor requirements.

How to prepare for a financial audit

“Fail to plan … plan to fail”. Auditing is no exception.

There is a *lot*to consider when you, or when one of your clients, gets audited. Preparing for one is that critical preliminary step that financial professionals must undertake to ensure a smooth and efficient audit process.

Here are the steps you can take to set your auditing up for success.

1. Get communication with the auditors down pat

To kickstart the audit preparation process, financial professionals should establish a clear line of communication with their (or their clients’) auditors. This involves discussing the audit objectives, timelines and scope.

By understanding the auditors’ requirements and expectations, you can align their preparations accordingly.

2. Gather and organise all financial documentation

One of the essential, and yet strangely overlooked, task in audit preparation is gathering and organising financial documentation.

This includes financial statements, bank statements, invoices, receipts, ledgers, payroll records, tax filings and any other relevant financial records.

You should ensure that these documents are complete, up-to-date and readily accessible for the auditors. Proper organisation saves time during the audit and facilitates easy retrieval of information.

3. Review your and your client’s internal controls (and identify potential weakness)

Before the audit commences, you should review your client’s internal controls. This involves assessing the effectiveness of existing controls, identifying potential weaknesses or deficiencies, and taking necessary steps to strengthen them.

By proactively addressing control issues, you and your client can minimise the risk of errors, fraud, or misstatements, improving the overall reliability of your financial information.

4. Conduct a “mini audit” before the real audit begins

To ensure readiness for the audit, you’ll need to conduct a comprehensive self-assessment of your own financial statements (or your client’s financial statements).

This involves reviewing the statements for accuracy, completeness and adherence to all relevant accounting standards and regulations.

By proactively identifying areas of concern or potential errors, you can rectify any discrepancies and address them before the audit begins.

5. Ensure compliance with all relevant accounting standards and regulations

This is related to the “mini audit” discussed in step four.

Compliance with accounting standards and regulations is a crucial aspect of audit preparation. You should ensure that your client’s financial records and statements are in line with the applicable accounting standards, such as Generally Accepted Accounting Principles (GAAP) or International Financial Reporting Standards (IFRS).

Compliance helps to build trust and confidence in the financial statements and reduces the risk of non-compliance issues arising during the audit.

Key steps in the audit process

The audit process typically involves several key steps, each of which needs to be well understood if you are going to help a client navigate an audit.

Step one: Planning phase

The planning phase is the initial step in the audit process and involves establishing the scope, objectives and approach for the audit. Key activities include:

  • Defining the audit’s scope and objectives- During this stage, the auditors work closely with the client to determine the areas of focus, audit objectives and the timeframe. This ensures that the audit is tailored to the specific needs and risks of the organisation being audited.
  • Assessing risks and understanding the audited entity - Auditors will conduct an initial risk assessment to identify potential areas of material misstatement or fraud risks. This will involve analysing your client’s industry, operations, internal control environment and previous audit findings to gain a comprehensive understanding of the audited entity.
  • Developing an audit plan and timeline- Based on the scope, objectives and risk assessment, auditors develop a detailed audit plan outlining the procedures, resources and timelines for the engagement. This plan serves as a roadmap for the steps to follow.

Step two: Risk assessment and internal control evaluation

In this next phase, auditors evaluate the effectiveness of internal controls and assess the risk of material misstatement in the financial statements.

The typical steps within this part of the process includes:

  • Evaluating the internal control environment - Auditors will then review your client’s internal control systems, policies, and procedures to assess their design and operating effectiveness. They identify significant accounts, processes, and controls relevant to the audit and evaluate the overall control environment.
  • “Stress-testing” the design and operating effectiveness of internal controls - Auditors will stress test your client to verify whether their internal controls are appropriately designed and operating effectively. This may involve inquiries, observation and re-performance of control activities to ensure that they are functioning as intended.

Step three: Substantive testing

Substantive testing is where the ‘real testing’ comes in - where the auditor specifically looks for flaws in financial records. It is where they look for material misstatements or evidence of fraud in your client’s accounting records, so that the financial records can be verified as accurate and complete.

There are broadly two types of “substantive tests”, including:

  • Analytical procedures - This is where financial data sets are meticulously compared with one another. This ensures that the financial statements are free from material misstatements.
  • Testing account balances and transactions - this involves the selection of select samples of individual transactions and balances to test and verify their accuracy and completeness. They may perform procedures such as vouching, tracing and confirmation of balances to obtain corroborating evidence.

Step four: Audit adjustments and management responses

After the substantive testing, auditors will communicate their findings, proposed adjustments and recommendations to the audited entity (in other words, you and your client). This is usually done via the “audit report”.

The audit report is the culmination of the audit process and serves as a formal document that communicates the auditor’s findings and conclusions. It provides an independent and objective assessment of the organisation’s financial statements.

The most critical component of the audit report is the auditor’s opinion on the fairness and reliability of the financial statements. The opinion is expressed as “unqualified” (meaning the financial statements are free from material misstatements), “qualified” (indicating certain limitations or exceptions), “adverse” (when the financial statements are materially misstated), or “disclaimer” (when the auditor cannot form an opinion).

The report will also provide an explanation of the basis for the auditor’s opinion, including the audit procedures performed, the evidence obtained and the evaluation of accounting policies and estimates.

The auditors will then work closely with management to resolve any identified errors, discrepancies or control deficiencies. During this stage, they will provide guidance on implementing corrective actions, improving internal controls and enhancing financial processes.

Important Note: Auditors are not your enemy

It can be easy for us (and our clients) to perceive auditors as being “out to get us”. They are specifically looking for fraud, evidence of wrongdoing and discrepancies within financial records. In other words, they are looking for things that our organisation is doing wrong.

But they are doing that to help us, not to hinder us. By identifying discrepancies or, at worst, fraud, organisations are able to take immediate corrective action to ensure it does not continue or happen again.

Post-audit activities

The completion of the audit marks the beginning of the post-audit activities, which are essential for ensuring that the audit process leads to meaningful outcomes and improvements.

These activities involve addressing management’s responses, evaluating the effectiveness of internal controls, conducting a post-audit review and considering audit recommendations.

1. Addressing management’s responses

Management’s responses to the audit findings and recommendations play a crucial role in driving positive change within the organisation. Post-audit activities focus on working collaboratively with management to address identified errors, discrepancies, control deficiencies or weaknesses. Key aspects of addressing management’s responses include:

  • Reviewing proposed corrective actions

Auditors will carefully evaluate the adequacy and appropriateness of management’s proposed corrective actions. They assess whether the actions effectively address the identified issues and provide reasonable assurance that similar problems will not recur in the future.

  • Collaborative problem solving

Auditors and management collaborate to develop practical solutions to the identified issues. This may involve revising internal control processes, enhancing accounting procedures, or implementing additional training programs for staff.

The aim is to develop sustainable solutions that align with the organisation’s objectives and improve overall financial reporting.

  • Monitoring implementation

Auditors monitor the implementation of management’s responses to ensure that the proposed corrective actions are carried out effectively.

They may request periodic updates from management to track the progress of implementation and provide guidance or support as needed.

  • Revisiting financial statements

If necessary adjustments were proposed during the audit, auditors verify whether these adjustments have been accurately reflected in the financial statements.

They review the revised financial statements to ensure that the reported financial information aligns with the audit findings and addresses any material misstatements.

2. Evaluating the effectiveness of internal controls

Post-audit activities will also involve evaluating the effectiveness of your client’s internal controls. This evaluation helps identify areas for improvement and ensures that the internal control environment provides reasonable assurance over the reliability of financial reporting.

Key aspects of this process include:

  • Assessing control enhancements

Auditors will assess whether the proposed enhancements to internal controls have been successfully implemented and are operating effectively. They will review the updated control processes and procedures to determine their adequacy in addressing identified control deficiencies.

  • Testing control effectiveness

Auditors will perform follow-up testing of selected control activities to verify their operating effectiveness. This may involve re-performing control tests or obtaining updated evidence to confirm that the controls are functioning as intended.

  • Addressing new control risks

Auditors will also consider any new control risks that may have emerged since the previous audit. They will assess whether the internal control framework adequately addresses these risks and will recommend additional control measures, if necessary.

  • Documenting control improvements

It is essential to document any control improvements made as a result of the audit. This documentation serves as a reference for future audits and helps ensure that your client’s internal control system continues to evolve and improve over time.

3. Conducting a post-audit review

A post-audit review allows the organisation to reflect on the audit process, identify lessons learned and implement improvements for future audits. This review will involves assessing the effectiveness of the audit engagement and the overall audit approach.

This will include:

  • Reviewing the audit process

Auditors here will evaluate the effectiveness of the audit procedures, methodology and techniques employed during the audit.

They will assess, for example, whether the audit objectives were achieved, the audit resources were effectively utilised and the audit timeline was reasonable.

  • Identifying strengths and weaknesses

Auditors identify the strengths and weaknesses of the audit process, both from their perspective and from the viewpoint of management. They evaluate the efficiency and effectiveness of the audit engagement and highlight areas that require improvement or further attention.

Ultimately, the post-audit review provides an opportunity to capture lessons learned from the audit experience. Auditors and management reflect on the challenges encountered, successful strategies employed and areas where improvements can be made. These insights help enhance the effectiveness and efficiency of future audits.

  • Updating the audit approach

Based on the findings of the post-audit review, auditors may revise and update their audit approach, methodologies or procedures. This ensures that the audit process remains relevant and aligned with industry best practices, regulatory requirements and emerging risks.

The review also prompts auditors to evaluate the adequacy and completeness of the audit documentation. They may identify areas where additional documentation or clarity is required to improve the overall quality and comprehensiveness of the audit files.

4. Considering audit recommendations

Audit recommendations are valuable insights provided by auditors to help organisations improve their financial processes, internal controls, and overall compliance.

Post-audit activities involve considering and implementing these recommendations to enhance financial management practices. Key aspects of considering audit recommendations include:

  • Prioritising recommendations

An auditor’s report will likely have many recommendations.

Auditors and management collaborate to prioritise these recommendations based on their potential impact and feasibility. They assess the urgency and significance of each recommendation and determine the appropriate timeline for implementation.

Some of the recommendations in the report may be expressed as “urgent”, suggesting that they should be given the first priority.

  • Developing action plans

Management develops action plans to address the audit recommendations. These plans outline the specific steps, responsible parties, timelines and resources required to implement the recommendations effectively.

Collaboration between auditors and management ensures that the action plans are practical and achievable.

  • Monitoring implementation progress

Auditors monitor the progress of implementing the audit recommendations. They review the action plans, request updates and provide guidance to ensure that the recommendations are implemented in a timely and effective manner.

  • Assessing the impact

Once the recommendations have been implemented, the auditors will evaluate their impact on the organisation’s financial processes, internal controls and overall compliance.

This assessment helps determine the effectiveness of the recommendations and highlights any additional areas for improvement.

  • Continuous improvement

The post-audit activities serve as a catalyst for continuous improvement. Management and auditors work together to create a culture of ongoing evaluation, learning and refinement of financial processes and controls to enhance the organisation’s overall financial management practices.

Wrapping it up

Audits are crucial for your client. They can be stressful, difficult and sometimes daunting, but they are an important mechanism that provides credibility and assurance to financial statements - ultimately enhancing trust in the accuracy of financial records.

By adhering to best practices, collaborating with auditors, and embracing the lessons learned from the audit process, you can contribute to the integrity of financial information and instill confidence among your client’s stakeholders.