1 / 3100%
THREE PRIMARY TYPES OF AUDITS
CPAs perform three primary types of audits:
1. Operational audit
2. Compliance audit
3. Financial statement audit
Operational audit
An operational audit evaluates the efficiency and effectiveness of any part of an
organization’s operating procedures and methods. At the completion of an operational
audit, management normally expects recommendations for improving operations. For
example, auditors might evaluate the efficiency and accuracy of processing payroll
transactions in a newly installed computer system. Another example, where most
accountants feel less qualified, is evaluating the efficiency, accuracy, and customer
satisfaction in processing the distribution of letters and packages by a company such as
Federal Express.
In operational auditing, the reviews are not limited to accounting. They can include
the evaluation of organizational structure, computer operations, production methods,
marketing, and any other area in which the auditor is qualified. Because of the many
different areas in which operational effectiveness can be evaluated, it is impossible to
characterize the conduct of a typical operational audit. In one organization, the auditor
might evaluate the relevancy and sufficiency of the information used by management in
making decisions to acquire new fixed assets. In a different organization, the auditor
might evaluate the efficiency of the information flow in processing sales.
It is more difficult to objectively evaluate whether the efficiency and effectiveness
of operations meets established criteria than it is for compliance and financial statement
audits. Also, establishing criteria for evaluating the information in an operational audit is
extremely subjective. In this sense, operational auditing is more like management
consulting than what is usually considered auditing.
Compliance audit
A compliance audit is conducted to determine whether the auditee is following
specific procedures, rules, or regulations set by some higher authority. Following are
examples of compliance audits for a private business.
1. Determine whether accounting personnel are following the procedures
prescribed by the company controller
2. Review wage rates for compliance with minimum wage laws
3. Examine contractual agreements with bankers and other lenders to be sure the
company is complying with legal requirements
4. Determine whether a mortgage bank is in compliance with newly-enacted
government regulations
Governmental units, such as school districts, are subject to considerable
compliance auditing because of extensive government regulation. Many private and not-
for-profit organizations have prescribed policies, contractual agreements, and legal
requirements that may require compliance auditing.
Results of compliance audits are typically reported to management, rather than
outside users, because management is the primary group concerned with the extent of
compliance with prescribed procedures and regulations. Therefore, a significant portion
of work of this type is often done by auditors employed by the organizational units. When
an organization such as the IRS wants to determine whether individuals or organizations
are complying with its requirements, the auditor is employed by the organization issuing
the requirements.
Financial statement audit
A financial statement audit is conducted to determine whether the financial
statements (the information being verified) are stated in accordance with specified
criteria. Normally, the criteria are U.S. or international accounting standards, although
auditors may conduct audits of financial statements prepared using the cash basis or
some other basis of accounting appropriate for the organization. In determining whether
financial statements are fairly stated in accordance with accounting standards, the
auditor gathers evidence to determine whether the statements contain material errors or
other misstatements. The primary focus of this book is on financial statement audits.
As businesses increase in complexity, it is no longer sufficient for auditors to focus
only on accounting transactions. An integrated approach to auditing considers both the
risk of misstatements and operating controls intended to prevent misstatements. The
auditor must also have a thorough understanding of the entity and its environment. This
understanding includes knowledge of the client’s industry and its regulatory and
operating environment, including external relationships, such as with suppliers,
customers, and creditors. The auditor also considers the client’s business strategies and
processes and critical success factors related to those strategies. This analysis helps the
auditor identify business risks associated with the client’s strategies that may affect
whether the financial statements are fairly stated.
Students also viewed