There are strong relationships that are automatically setup within an Agile Audit engagement file once we have completed our Risk Assessment.
Completion your risk assessment means you have successfully:
You have identified all risks for the firm you are auditing and have successfully documented these risks in the 2-240 Risk Report.
You have identified all the firm’s internal controls and have documented them in the 2-230 Control Report.
Returning to the 2-240 Risk Report you have now associated all Internal Controls (2-230) with at least one risk (you can apply multiple risks to one or many controls).
A good indicator that this has been setup appropriately is reviewing your 2-250 Risk Assessment Report. If for example we consider Revenue;
These are all the risks assigned to this Financial Statement Area.
Represents the Assertions that are associated with this risk
The Controls designed to mitigate this risk
The Audit Response (the procedures, ASA 330) assigned to the risk
In this report you can see what internal controls have been identified and entered into the Agile Audit engagement. As you can see from the image below, all controls are presented under the appropriate Business Cycle.
Note: You may see the same Control presented twice.
From within this workpaper you are able to:
Collapse all controls to the title, for real estate purposes .
Press the button to edit a control and link it to a risk.