17.4 Reporting on Compliance: AU-C 806, AT-C 315 & AU-C 935
Key Takeaways
- Under AU-C 806, an auditor may give negative assurance on compliance with covenants that relate to accounting matters, in a separate report or an other-matter paragraph.
- AU-C 806 negative assurance is not given when the auditor has expressed an adverse opinion or disclaimed an opinion on the related financial statements.
- AT-C 315 compliance attestation permits examinations and agreed-upon procedures but not reviews, and material noncompliance leads to a qualified or adverse examination opinion.
- AU-C 935 compliance audits, including single audits, apply materiality to each major program and produce an opinion on compliance plus a report on internal control over compliance.
17.4 Reporting on Compliance: AU-C 806, AT-C 315 & AU-C 935
Blueprint Link: Area IV.D asks you to identify what an auditor considers when reporting on compliance with contractual agreements or regulatory requirements in connection with a financial statement audit, and what a practitioner considers when reporting on an attestation engagement about compliance with laws, regulations, rules, contracts, or grants and related internal control. Government single audits add a third route.
1. Three Routes to a Compliance Report
| Route | Standard | Typical Request | Form of Assurance |
|---|---|---|---|
| Compliance comment attached to a financial statement audit | AU-C 806 | A lender wants comfort on loan covenants tied to accounting matters | Negative assurance |
| Stand-alone compliance attestation | AT-C 315 | A grantor or regulator wants assurance about compliance with specified requirements | Opinion (examination) or findings (agreed-upon procedures) |
| Compliance audit required by a governmental audit requirement | AU-C 935 (with GAGAS and the Uniform Guidance for single audits) | Federal award recipients | Opinion on compliance for each major program |
2. AU-C 806: Compliance Reports in Connection with Audited Financial Statements
Loan agreements, bond indentures, and regulators sometimes ask the auditor to comment on compliance with covenants such as working capital minimums, restrictions on dividends, or debt-to-equity ratios.
Conditions for issuing the report:
- The covenants relate to accounting matters that were subjected to procedures in the audit of the financial statements.
- The auditor has expressed an unmodified or qualified opinion. If the auditor expressed an adverse opinion or disclaimed an opinion, the auditor does not give negative assurance on compliance.
Form: A separate report or an other-matter paragraph in the auditor's report on the financial statements.
Typical content:
- A statement that the audit was conducted in accordance with GAAS, with the date of the auditor's report and a note of any modified opinion.
- Identification of the specific covenants or requirements, and a statement that the assurance relates only to those that concern accounting matters.
- Negative assurance, for example: in connection with the audit, nothing came to the auditor's attention that caused it to believe the entity failed to comply with the identified covenants insofar as they relate to accounting matters.
- A statement that the audit was not directed primarily toward obtaining knowledge of noncompliance.
- A description of significant interpretations of contract terms made by management, when applicable.
- An alert restricting the use of the report to the specified parties (for example, management, the board, and the lender).
If noncompliance is found: The auditor describes the instances of noncompliance in the report rather than giving negative assurance on those items, and also considers the financial statement effects (for example, classification of callable debt as current).
Exam Trap: A covenant requiring the borrower to keep adequate insurance or maintain facilities is not an accounting matter tested in the audit, so it falls outside an AU-C 806 report.
3. AT-C 315: Compliance Attestation Engagements
AT-C 315 applies when a practitioner is engaged to report on an entity's compliance with requirements of specified laws, regulations, rules, contracts, or grants, or on the effectiveness of an entity's internal control over compliance with those requirements.
Permitted engagement types: Examinations and agreed-upon procedures. A review of compliance is not permitted.
Examination steps:
- Obtain an understanding of the specified compliance requirements (these serve as the criteria).
- Plan the engagement and assess the risk of material noncompliance, including fraud risk.
- Obtain an understanding of internal control over compliance relevant to the engagement.
- Obtain sufficient appropriate evidence about compliance with each requirement.
- Consider subsequent events through the report date.
- Request a written assertion and obtain written representations from the responsible party.
Reporting:
| Result | Report |
|---|---|
| Complied in all material respects | Unmodified opinion |
| Material noncompliance (not pervasive) | Qualified opinion, describing the noncompliance |
| Pervasive material noncompliance | Adverse opinion |
| Unable to obtain sufficient evidence | Qualified opinion or disclaimer |
Use of the report is restricted when the criteria (the specified requirements) are available only to specified parties.
Example: A state grant requires a nonprofit to match every $1 of grant funds with $0.50 of private contributions and to spend at least 80% of funds on direct services. The grantor engages the nonprofit's CPA to examine compliance with those two requirements. The practitioner tests the matching calculation and the classification of expenditures and expresses an opinion; if the nonprofit spent only 72% on direct services and that is material, the opinion is qualified or adverse.
4. AU-C 935: Compliance Audits Under Governmental Audit Requirements
AU-C 935 applies when the auditor is engaged or required to perform a compliance audit under GAAS, Government Auditing Standards, and a governmental audit requirement that calls for an opinion on compliance, the most common example being a single audit under the Uniform Guidance.
- Materiality is set for the compliance audit at the level of each major program, based on the governmental audit requirement, rather than only at the financial statement level.
- Risk assessment is performed for each applicable compliance requirement of each major program.
- Internal control over compliance: When the governmental requirement calls for it (as the Uniform Guidance does for major programs), the auditor tests controls over compliance.
- Written representations specific to compliance are required.
- Reports: an opinion on compliance for each major program; a report on internal control over compliance that identifies significant deficiencies and material weaknesses but expresses no opinion on that control; and a schedule of findings and questioned costs (Section 17.5).
5. Summary Comparison
| Feature | AU-C 806 | AT-C 315 | AU-C 935 |
|---|---|---|---|
| Linked to a financial statement audit? | Yes | No (stand-alone attestation) | Performed with the financial statement audit in a single audit |
| Assurance | Negative assurance | Reasonable (examination) or none (AUP) | Reasonable (opinion on compliance) |
| Review permitted? | Not applicable | No | Not applicable |
| Report on internal control over compliance | No | Possible, if engaged to examine it | Yes, without an opinion |
| Restricted use | Yes | When criteria are available only to specified parties | As required by the governmental requirement |
A bank asks a borrower's auditor for a report on the borrower's compliance with the accounting-related covenants of its loan agreement. The auditor has expressed an adverse opinion on the borrower's financial statements. What should the auditor do?
Which statement is appropriate in an auditor's report on compliance with aspects of contractual agreements issued under AU-C 806?
A state agency wants assurance about a nonprofit's compliance with the requirements of a grant. Which engagement may a practitioner NOT perform under AT-C 315?
In a compliance audit under AU-C 935 performed as part of a single audit, how does the auditor apply materiality?