Keeping up with standards and regulation is biggest challenge facing SMPs. Insight from IFAC SMP Quick Poll Findings and tips for audit efficiency are discussed in this presentation by Mats Olsson, Member, IFAC Small and Medium Practices Committee, at the KibR Seminar in Warsaw on November 7, 2013.

  • ISAs acknowledge that the appropriate exercise of professional judgment is essential to the proper conduct of an audit. Professional judgment is necessary, in particular, regarding decisions about the nature, timing, and extent of audit procedures used to meet the requirements of the ISAs and gather audit evidence.However, while the auditor of an SME needs to exercise professional judgment, this does not mean that the auditor can decide not to apply a requirement of an ISA except in exceptional circumstances and provided that the auditor performs alternative audit procedures to achieve the aim of the requirement.
  • The auditor need not be concerned with ISAs that are not relevant to the audit. Nevertheless, it is necessary that the auditor understands the scope of each ISA to determine whether it is relevant or not in the circumstances.
  • The auditor’s objectives are the same for audits of entities of different sizes and complexities. This, however, does not mean that every audit will be planned and performed in exactly the same way. The requirements of the ISAs, therefore, focus on matters that the auditor needs to address in an audit and do not ordinarily detail the specific procedures that the auditor should perform.ISA 330 paragraph 8 The Auditor’s Response to Assessed Risk paragraph 8 states that “The auditor shall design and perform tests of controls to obtain sufficient appropriate audit evidence as to the operating effectiveness of relevant controls if the auditor’s assessment of risks of material misstatement at the assertion level includes an expectation that the controls are operating effectively (that is, the auditor intends to rely on the operating effectiveness of controls in determining the nature, timing and extent of substantive procedures)”.ISA 220 paragraphs 19-21 Quality Control for an Audit of Financial Statements paragraphs 19 -21 all relate to an Engagement Quality Control Review, which are required for all audits of financial statements of listed entities.
  • The objective of ISA315 is critical and underpins every audit engagement regardless of size. The requirement in ISA 315 is for the auditor to obtain an understanding of the entity and its environment. While the audit considerations underlying this requirement will be equally relevant for both large and small entities, the typically simpler structure and processes in an SME often mean that the auditor may obtain an understanding of the entity and its environment quite readily and document this in a straightforward manner. This is emphasized several times in the ISAs e.g. “Smaller entities may use less structured means and simpler processes and procedures to achieve their objectives” (ISA 315, paragraph A45).ISAs allow for an effective and efficient audit. The ISAs explain that the appropriate audit approach for designing and performing audit procedures depends on the auditor’s risk assessment. For example, in the context of an SME audit where there are not many control activities in the SME that can be identified by the auditor, the auditor may decide that it is efficient to perform further audit procedures that are primarily substantive procedures (ISA 330, paragraph A18).
  • ISAs also include useful guidance that assists the auditor in understanding or applying specific requirements in the ISAs in the context of an SME audit. Analytical proceduresFor example, because interim or monthly financial information may not be available in an SME for purposes of analytical procedures to identify and assess the risks of material misstatement, the auditor may need to plan to perform analytical procedures when an early draft of the entity’s financial statements becomes available (ISA 315, paragraph A10).DocumentationFor example, “the form, content, and extent of documentation depend on various factors, including the size and complexity of the entity”, and the audit methodology and technology used in the audit (ISA 230, paragraph A2, ISA 315, paragraph A131.“The documentation for the audit of a smaller entity is generally less extensive than that for the audit of a larger entity (ISA 230, paragraph A16). “Documentation may be simple and relatively brief” (ISA 315, paragraph A132).ISAs provide examples of how the documentation in an SME audit can be approached in an efficient and effective manner, e.g. - The documentation of the understanding of the entity may be incorporated in the auditor’s documentation of the overall strategy and audit plan. Similarly, the results of the risk assessment may be documented as part of the auditor’s documentation of further procedures (ISA 315, paragraph A131)
  • The objective of implementing a system of quality control is the same for all firms regardless of their nature or size. However, this does not mean that all firms have to design and implement exactly the same specific policies and procedures, or policies and procedures at the same level of detail, to achieve the objective and requirements of ISQC 1. Smaller firms will find that effective and proportionate implementation may be best achieved by first studying the provisions of ISQC 1 and then, in light of the nature and size of a firm and the services thefirm provides, developing policies and procedures tailored to the firm’s circumstances.The ISQC does not call for compliance with requirements that are not relevant (ISQC 1 paragraph 14).Explains that smaller firms may use more informal methods in the documentation of their systems of quality control such as manual notes, checklists and forms (ISQC 1 paragraph A75).Firms can draw on external resources to meet some of the requirements of ISQC 1. For example, in relation to the requirements of ISQC 1 addressing the need for sufficient personnel with the competence and capabilities to perform engagements in accordance with professional standards, firms may use a suitably qualified external person, for example, when internal technical and training resources are unavailable. Often, this will likely be an effective (and cost effective) way to achieve the aims of the requirements.
  • There are a number of practical steps which could be considered for improving audit efficiencies. AutomationAutomating the audit practice provides an opportunity to improve audit quality at both firm-wide and individual engagement levels. At the firm level, setting up standardized templates helps ensure that all phases have been completed in every audit. Customized checklists can be updated as needed and incorporated into individual engagement files at the beginning of every engagement. It is important that every file is customized for the individual client. The generic firm template is a great place to start, but it is only a start. SoftwareWhen using commercially available software SMPs engagements, you can roll forward last year’s electronic file almost instantly and have ‘mapped’ trial balance codes for efficiency if generating the financial statements. You can also e-mail an engagement letter and list of deliverables required when you visit the client at the beginning of the audit. If you import data from one application program to another, data conversion errors should be eliminated and grouping and arithmetical errors can be minimized.PlanningThe essential component for an efficient audit is proper planning and organisation both from the perspective of the audit firm and the business. It is important that the timeframe is agreed in advance with clearly specified delivery dates. The field work should be scheduled and the board meeting to sign the accounts agreed. A list of client deliverables should be provided by the audit firm. The initial planning meeting should be scheduled in advance. Risk based approachThe audit team should focus on working smarter, not harder. The work should be concentrated on the key risk areas with the level and amount of work tailored accordingly. A thorough analytical review should be undertaken which identifies the key risks and the level of testing that will be performed on these and other areas. This review should include scoping out of balances which are fully understood and would not lead to a material misstatement. When considering the audit approach, sometimes less is more. The audit team should limit procedures on areas considered to be low risk and focus attention and time on significant risks or historical areas known to cause issues. Staff training/ supervisionThe audit firm must ensure that their staff are resourced at the correct level and that more junior team members receive adequate supervision to complete the work to a high standard. Senior reviews of the testing must be scheduled in a timely manner, so any open points are closed when the audit team is onsite and not later at greater cost. CommunicationRegular, effective communication is important for individuals in audit team and the business. A daily tracker with open queries is useful tool to facilitate these conversations. As a result any issues will also be discussed early, so there is less likelihood of last minute changes and late surprises.
    18. 18. Page 18 | Confidential and Proprietary Information References – General  IFAC SMP Committee website:  IFAC SMP Twitter: (please follow us)  IFAC SMP Community: (please join us)  IFAC SMP Quick Poll: Mid-Year 2013: quick-poll-mid-year-2013 (please take the Nov./Dec. 2014 poll)  Resources and tools (all): committee/smp-resources-and-tools  IFAC Translations and Permissions: • Links to implementation of ISAs resources:,Audit • Links to implementation of ISQC 1 resources:,Quality%20Control
    19. 19. Page 19 | Confidential and Proprietary Information References – IAASB • Staff Q&A, Applying ISAs Proportionately with the Size and Complexity of an Entity: proportionately-size-and-complexity-ent • Staff Q&A, Applying ISQC 1 Proportionately with the Nature and Size of a Firm: ortionality_FINAL.pdf • The Clarified ISAs—Findings from the Post-Implementation Review: review
    20. 20. Page 20 | Confidential and Proprietary Information References – Knowledge Sharing - Implementation • Guide to Using International Standards on Auditing in the Audits of Small- and Medium- Sized Entities (Third Edition) (incl. companion manual and slides): audits-small-and-medium-sized-en • Guide to Quality Control for Small- and Medium-Sized Practices (Third Edition) (incl. companion manual and slides): small-and-medium-sized-practices-third-edition-0 • Boosting the Quality and Efficiency of Smaller Entity Audits article: audits • Tips for Cost-Effective ISA Application article: resources/tips-cost-effective-isa-application • Tips for Cost-Effective ISQC 1 Application article: resources/tips-cost-effective-isqc-1-application
