CPA Exam — AUDAssessing Risk and Developing a Planned ResponseHard

A public company client has a complex, decentralized organizational structure with multiple divisions operating autonomously. The company recently acquired a smaller competitor, integrating its financial reporting into one of the existing divisions. The auditor notes that the acquired entity's financial reporting personnel have limited experience with public company accounting standards. When developing the overall audit strategy, what is the most appropriate initial response concerning internal controls over financial reporting (ICFR)?

  1. APresume a high control risk for the acquired entity's financial reporting processes.
  2. BIncrease the scope of substantive analytical procedures for the entire company.
  3. CPlan to rely heavily on the existing division's general IT controls.
  4. DImmediately recommend the client implement a centralized financial reporting system.
Show answer & explanation

Correct answer: A. Presume a high control risk for the acquired entity's financial reporting processes.

The acquired entity's personnel having limited experience with public company accounting standards, combined with its integration into a complex, decentralized structure, strongly suggests that the controls over financial reporting for the acquired operations may be ineffective or non-existent. In such a scenario, the auditor should initially presume a high control risk, which will lead to a more substantive audit approach for those operations.

Why the other options are wrong

  • B. While substantive analytical procedures may be part of the response, presuming high control risk for the specific segment is a more direct and fundamental initial strategy, guiding the nature, timing, and extent of all further procedures, including substantive tests.
  • C. Reliance on general IT controls is only appropriate after they have been evaluated and tested, and it doesn't address the specific personnel experience deficiency in financial reporting.
  • D. Recommending system changes is a management responsibility and is typically done after a thorough assessment, not as an initial audit planning step.

Control Risk Assessment - Acquisitions

When auditing an acquired entity, especially one with inexperienced personnel or integration challenges, auditors should initially assess control risk as high unless evidence suggests otherwise, due to the inherent difficulties in establishing and maintaining effective ICFR in such circumstances.

  • Acquisitions introduce new ICFR challenges.
  • Inexperienced personnel increase control risk.
  • High control risk dictates more substantive approach.

Memory trick: New company, new people? Assume controls are a mess!

More Assessing Risk and Developing a Planned Response questions