20.1 Nature of Auditing, Assurance, and Information Risk
Key Takeaways
An independent financial statement audit provides a high, but not absolute, level of assurance (reasonable assurance) expressed positively in the audit opinion, because inherent limitations preclude absolute guarantees.
Inherent limitations of an audit arise from the nature of financial reporting (estimates and judgments), the nature of audit procedures (evidence gathering limitations and fraud concealment), and the necessity to balance timeliness and cost through selective testing and sampling.
Information risk stems from four fundamental economic drivers: remoteness of information, conflict of interest (agency theory), voluminous data, and transaction complexity.
Financial statement, compliance, and operational audits differ in purpose and criteria; COA audits government agencies and GOCCs, while internal auditors serve the entity itself.
Nature of Auditing, Assurance, and Information Risk
Auditing in the Philippines gives credibility to financial statements, protects the public interest, and supports stable capital markets. This section covers the definition and objectives of an audit under PSA 200, reasonable assurance and the inherent limitations of an audit, the economic demand for audits (agency theory and information risk), and the types of audits and auditors.
1. Nature, Objective, and Scope of Financial Statement Audits
Formal Definition of Auditing
Auditing in general is defined (American Accounting Association) as a systematic process of objectively obtaining and evaluating evidence regarding assertions about economic actions and events to ascertain the degree of correspondence between these assertions and established criteria, and communicating the results to interested users.
Applied to a statutory audit of financial statements in the Philippines:
- Assertions represent the implicit or explicit representations made by management regarding the recognition, measurement, presentation, and disclosure of transactions and accounts in the financial statements.
- Established Criteria refer to the applicable financial reporting framework, which in the Philippines primarily consists of Philippine Financial Reporting Standards (PFRS), PFRS for Small and Medium-sized Enterprises (PFRS for SMEs), or PFRS for Small Entities.
- Users include existing and potential investors, creditors, financial institutions, employees, regulatory authorities, and the general public.
Primary Objective under PSA 200
Under Philippine Standard on Auditing 200 (PSA 200), Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance with Philippine Standards on Auditing, the overarching objectives of the auditor are:
- To obtain reasonable assurance about whether the financial statements as a whole are free from material misstatement, whether due to fraud or error, thereby enabling the auditor to express an opinion on whether the financial statements are prepared, in all material respects, in accordance with an applicable financial reporting framework; and
- To report on the financial statements, and communicate as required by the PSAs, in accordance with the auditor's findings.
Levels of Assurance: Reasonable vs. Absolute Assurance
The auditor provides a high, but not absolute, level of assurance, termed reasonable assurance. Reasonable assurance represents an accumulation of the audit evidence necessary for the auditor to conclude that there are no material misstatements in the financial statements taken as a whole.
| Assurance Level | Degree of Confidence | Form of Opinion / Conclusion | Typical Engagement |
|---|---|---|---|
| Reasonable Assurance | High, but not absolute | Positive expression ("In our opinion, the financial statements present fairly, in all material respects...") | Independent Financial Statement Audit (PSA 200-700 series) |
| Limited (Negative) Assurance | Moderate | Negative expression ("Nothing has come to our attention that causes us to believe...") | Review of Interim or Annual Financial Statements (PSRE 2400 / 2410) |
| No Assurance | None | Factual findings or compilation report (No assurance expressed) | Agreed-Upon Procedures (PSRS 4400) or Compilation (PSRS 4410) |
An audit is not a guarantee that financial statements are free from all misstatements. The auditor does not provide absolute assurance because an audit is subject to pervasive inherent limitations.
Inherent Limitations of an Audit
PSA 200 identifies three broad categories of inherent limitations that prevent the auditor from providing absolute assurance:
Inherent Limitations of an Audit
│
┌─────────────────────────────────────┼─────────────────────────────────────┐
▼ ▼ ▼
Nature of Financial Reporting Nature of Audit Procedures Timeliness & Cost-Benefit
• Subjective management judgments • Practical & legal constraints • Selective testing / sampling
• Accounting estimates & uncertainty • Intentional concealment & collusion • Persuasive rather than
• Alternative acceptable accounting • Non-possession of search/subpoena conclusive evidence
treatments powers • Reasonable time & expense
1. Nature of Financial Reporting
The preparation of financial statements involves significant management judgment, subjective decisions, and accounting estimates that involve uncertainty (e.g., expected credit loss allowances, fair value measurements of illiquid assets, provision for environmental liabilities, and asset impairment testing). Consequently, many financial statement items cannot be measured with mathematical exactness.
2. Nature of Audit Procedures
Auditors face practical and legal constraints when gathering audit evidence:
- Management and third parties may intentionally or unintentionally fail to provide complete information requested by the auditor.
- Fraud Concealment: Fraud, especially fraud involving management override of controls, forgery, intentional misrepresentation, or collusion between employees and external parties, is deliberately designed to be hidden. Standard audit procedures may be ineffective for discovering sophisticated concealment.
- Lack of Legal Powers: Auditors are not government prosecutors or judicial officers. They do not possess legal powers of search, seizure, or subpoena to compel testimony or confiscate records.
3. Timeliness of Financial Reporting and Balance Between Benefit and Cost
Users expect financial information to be made available within a reasonable period following the reporting date. To provide timely reports at a reasonable economic cost:
- Auditors must rely on selective testing (sampling) rather than examining 100% of the entity's transactions and account balances.
- The matter of difficulty, time, or cost involved is not in itself a valid basis for the auditor to omit an audit procedure for which there is no alternative, but the audit is planned so that audit effort is directed toward areas where risk of material misstatement is highest.
- Audit evidence is predominantly persuasive rather than conclusive in nature.
2. Economic Demand for Auditing & Information Risk
The Agency Problem and Stewardship Theory
Modern corporate enterprise is characterized by the separation of ownership and management. Shareholders (principals) delegate day-to-day operational control and custody of economic resources to professional managers (agents). This structural separation produces an inherent agency problem:
- Asymmetry of Information: Management possesses direct, comprehensive, real-time access to the company's financial and operational data, whereas shareholders and creditors receive only periodic summary reports prepared by that same management.
- Conflict of Interest: Management may have personal incentives (e.g., performance bonuses, stock option values, promotion aspirations, job preservation) to present an overly favorable portrait of financial performance and financial condition, potentially disguising operational failures or capital losses.
The independent audit serves as a vital corporate governance monitoring mechanism. By retaining an independent third party to verify management's representations, principals mitigate agency costs and reduce information asymmetry.
Information Risk: Definition and Drivers
Information risk is the risk that financial information upon which a business, investment, or credit decision is made is inaccurate, incomplete, or materially misleading. In capital markets, an entity's cost of capital reflects three distinct components:
While an auditor cannot alter the risk-free rate and cannot eliminate the client's underlying business risk (e.g., technological obsolescence, economic recessions, competitor actions), an independent audit directly reduces information risk. Lower information risk enables the reporting entity to obtain debt and equity capital at lower financing costs.
Four fundamental economic drivers create information risk:
| Driver of Information Risk | Operational Mechanism | Audit Impact |
|---|---|---|
| Remoteness of Information | Decision-makers (e.g., institutional investors, commercial bank loan officers) are physically and legally separated from the entity's records and daily operations. Firsthand verification is practically impossible. | Independent auditors perform on-site and remote examination of source documents, contracts, and physical assets on behalf of remote users. |
| Biases and Motives of the Provider | When information is prepared by an entity whose goals differ from those of the user, the data may be slanted to favor the preparer (e.g., inflating revenues to meet earnings targets or understating liabilities to avoid violating debt covenants). | Independent auditors maintain professional skepticism and objectivity, verifying assertions against independent external third-party evidence. |
| Voluminous Data | Modern commercial entities execute millions of transactions annually. As transaction volume multiplies, the likelihood of clerical errors, incorrect classifications, processing defects, and system failures increases exponentially. | Auditors evaluate internal control systems and utilize automated audit software and statistical sampling to detect systemic processing errors. |
| Complexity of Transactions | Complex commercial arrangements (e.g., multi-element revenue contracts under PFRS 15, derivative financial instruments under PFRS 9, cross-border corporate combinations, variable interest entities) are inherently difficult to record properly. | Auditors deploy specialized accounting knowledge, technical valuation specialists, and rigorous testing methodologies to verify accounting treatment. |
Mechanisms for Reducing Information Risk
Users of financial statements have three potential approaches to manage information risk:
- User Directly Verifies the Information: The user examines the records directly. This is economically inefficient, impractical for large enterprises, and legally restricted for minority shareholders.
- User Shares Information Risk with Management: The user contracts with management to absorb losses resulting from inaccurate information. However, if the business collapses into insolvency, management cannot make the user whole.
- Independent Audited Financial Statements are Provided: Management hires an independent CPA firm to audit the statements, or users mandate that an independent audit report accompany the financial statements. This is the universal, cost-effective solution supporting modern capital markets.
3. Types of Audits and Auditors
| Type of audit | Purpose | Typical criteria | Example |
|---|---|---|---|
| Financial statement audit | Determine whether the financial statements are fairly presented | Applicable financial reporting framework (PFRS, PFRS for SMEs, PFRS for Small Entities) | Annual audit of a corporation's statements filed with the SEC and BIR |
| Compliance audit | Determine whether the entity follows specific rules, laws, contracts, or policies | Laws, regulations, loan covenants, internal policies | Checking compliance with bond indenture covenants or procurement rules |
| Operational (performance) audit | Evaluate the efficiency and effectiveness of operations and recommend improvements | Criteria set by management or the auditor (less objective) | Review of a hospital's purchasing process |
| Type of auditor | Employer and independence | Main work |
|---|---|---|
| External (independent) auditor | CPA in public practice, independent of the client | Financial statement audits under the PSAs |
| Internal auditor | Employee of the entity, reporting ideally to the audit committee | Evaluation of controls, risk management, and governance; operational and compliance audits |
| Government auditor | Commission on Audit (COA) under the 1987 Constitution | Audit of government agencies, GOCCs, and public funds, including financial, compliance, and performance audits |
| BIR examiner | Revenue officer of the Bureau of Internal Revenue | Tax audits (examination of books to verify tax liabilities) |
Other key distinctions: assurance engagements increase users' confidence in a subject matter against criteria, while related services (agreed-upon procedures and compilations) do not express assurance. An external auditor may rely on the work of internal auditors only after evaluating their objectivity, competence, and systematic approach under PSA 610.
Which of the following factors is an inherent limitation of an audit that prevents the independent auditor from providing absolute assurance on financial statements?
The fact that audit evidence is predominantly persuasive rather than conclusive, requiring the use of selective testing and sampling.
The auditor's professional negligence in failing to verify all supporting supplier invoices during the inventory count.
The auditor's statutory obligation under Republic Act No. 9298 to issue an unmodified opinion within sixty days of the fiscal year-end.
The refusal of the Board of Accountancy to grant subpoena powers over external audit clients.
A commercial enterprise seeking a PHP 100,000,000 credit facility submits financial statements audited by an independent CPA to the lending bank. Which component of the borrowing entity's cost of capital is directly addressed and mitigated by the independent audit?
The risk-free interest rate prevailing on Philippine Treasury bonds
The general business risk associated with competitive obsolescence in the borrower's industry
The information risk that the borrower's financial statements contain material misstatements or fraudulent omissions
The default risk resulting from macroeconomic inflation and monetary tightening by the Bangko Sentral ng Pilipinas
A team evaluates whether a hospital's purchasing department buys medical supplies efficiently and recommends process improvements. What type of audit is this?
Financial statement audit
Compliance audit
Operational audit
Review engagement
Sections you finish are checked off in the contents.