| Guidelines This chapter describes the audit committee’s responsibilities in overseeing the external audit function, and the supervisor´s relationships with external auditors of banks and the audit oversight body. The contents of this chapter are based on:
|
| Related standards |
| Related guidelines |
A bank’s board and management are responsible for ensuring that financial statements are prepared in accordance with the applicable financial reporting framework. They must also ensure that annual financial statements have been audited and include the opinion of an independent external auditor. The audit of the financial statements does not relieve the board or senior management of their responsibilities.
An external auditor conducts the audit of a bank’s financial statements to obtain reasonable assurance about whether the financial statements are free from material misstatement, whether due to fraud or error. This enables the auditor to:
External auditors of banks can play an important role in contributing to financial stability when they deliver quality bank audits which foster market confidence in banks’ financial statements. Quality bank audits are also a valuable input in the supervisory process, as the external auditor has a duty to report/alert directly to the supervisor on matters of material significance.
The following terms are used throughout this chapter and have the meaning given below:
Supervisors have a keen interest in the quality with which external auditors perform bank audits. This chapter aims to enhance the quality of external audits of banks and the effectiveness of prudential supervision by:
This chapter outlines supervisory expectations for the external audit, to help banks' audit committees oversee banks' external auditors. These expectations and recommendations also facilitate supervisors’ engagement with external auditors and the relevant audit oversight bodies. The Committee does not have the authority to set professional standards for external auditors. The recommendations should therefore be read alongside the professional standards, which provide additional guidance for the proper application of the standards to audits of banks, including:
This chapter acknowledges significant differences in national and institutional frameworks, including accounting, auditing and governance standards. Supervisors are encouraged to address legal and institutional obstacles to implementing the guidelines within their authority and, where necessary, advocate for reforms to enhance their ability to fully apply these guidelines.
Principle 1: The audit committee should have a robust process for approving, or recommending for approval, the appointment, reappointment, removal and remuneration of the external auditor.
The audit committee should have the primary responsibility for the appointment, reappointment, removal, and remuneration of the external auditor. In doing so, the audit committee should determine appropriate criteria for selecting the external auditor and regularly assess their knowledge, competence and independence (see Principle 2 below) and the effectiveness of the external audit (see Principle 3 below), having due regard to the supervisory expectations and recommendations in this chapter.
The audit committee should evaluate risks related to the auditor’s potential withdrawal from the engagement and prepare a response plan.
The bank’s annual report should explain the approach the audit committee has taken regarding the recommendation of the appointment or reappointment of the external auditor, and include information on the tenure of the incumbent auditor.
If the board of directors disagrees with the audit committee’s recommendation, the annual report, or any publications by the bank relating to the appointment/reappointment/dismissal of the external auditor, should explain the audit committee’s recommendation and the board’s reasons for taking a different position.
The audit committee should assess the external auditor’s quality, before its first appointment and at least annually thereafter. This includes reviewing the auditor’s quality management procedures and its compliance with all applicable quality management standards, as well as any significant matters of concern arising from these procedures. The audit committee should also consider, where available, the external audit firm’s annual transparency report and any inspection reports from the audit oversight body.
The audit committee should stay informed about:the audit firm’s structure and governance, and the current nature of the audit environment (including in jurisdictions abroad where the bank operates). It should also be aware of:
It should also consider lessons learned from recent audit failures and how the audit firms have dealt with them.
The audit committee should satisfy itself that the level of the audit fees is commensurate with the scope of work undertaken and not compromise audit quality. Fee reductions should not lead to higher materiality thresholds, reduced audit scope, or less attention to significant risks without appropriate reason.
The audit committee should agree on the engagement letter with the external auditor before approval. This letter should be updated for changes in legal requirements or auditing standards.
If the external auditor resigns or communicates an intention to resign, the audit committee should investigate and consider whether further action is needed.
Principle 2: The audit committee should monitor and assess the independence of the external auditor.
The audit committee should monitor and assess the external auditor’s independence at least annually, considering relevant national laws, regulations and professional requirements. This includes reviewing relationships between the bank and the audit firm (including the provision of non-audit services), any inadvertent violations, and any safeguards established by the external auditor to maintain independence. The audit committee should consider whether, as well as complying with the applicable jurisdictional independence standards, the audit firm also complies with the independence standards applicable to public interest entities in internationally accepted ethical standards (see FRD20.106).
The audit committee should balance risks between:
The audit committee should have a policy in place that stipulates the criteria for tendering the external audit contract. The audit committee should periodically consider putting the audit firm contract out for tender, considering the audit firm’s tenure and potential risks to independence.
The audit committee should understand the audit firm’s policy on rotation of members of the audit engagement team and the audit firm’s compliance with any jurisdictional or other local regulatory independence requirements in this regard.
The audit committee should seek assurance that the audit team and firm and, when applicable, the network external auditors have no relationships with the bank which could compromise actual or perceived independence. It should also review at least on an annual basis the audit firm’s policies and processes for maintaining independence.
20.24 The audit committee should develop a policy on non-audit services, specifying the criteria for services the auditor may provide or is prohibited from providing, and when advance approval by the audit committee is required. The policy should be reviewed periodically. IAC10 states that, as a sound practice, banks should not outsource internal audit activities to their own external auditor. Any departure from this best practice should be limited to small banks and should remain within the bounds of the applicable ethical standards for the statutory or external auditor.
Non-audit services provided by the external auditor should not impair the external auditor’s objectivity and independence. The audit committee should monitor these services and ensure safeguards are in place to mitigate any threat to objectivity and independence.
Where the external auditor provides non-audit services to the bank, the bank’s annual report (or other relevant publications) should explain to shareholders the nature of these services, the fee incentives for the non-audit services received, and how auditor independence is safeguarded.
Principles 3: The audit committee should monitor and assess the effectiveness of the external audit.
At the start of each audit, the audit committee should review the audit approach, scope, materiality level(s), areas of focus, and how the auditor proposes to address areas of significant risks.
The audit committee should confirm that the audit team has adequate resources and expertise for its engagement. The audit committee should understand the nature and extent to which the external auditor intends to use audit work performed by network firm personnel and other audit firms.
The audit committee should ensure the audit complies with internationally accepted auditing standards, as well as any applicable laws and regulations.
The audit committee should:
The audit committee should also discuss with the external auditor the statements provided by management in the representation letter to the auditor and ensure they are complete and appropriate.
The audit committee should discuss with the auditor the audit-related reports, including any management letter (or equivalent), which the external auditor has provided to the bank. In particular, the audit committee should discuss with the external auditor any significant deficiencies in internal control over financial reporting.
Upon completion of the audit fieldwork, but before the external auditor issues the audit report, the audit committee should review whether the audit plan has been followed and understand any changes made during the audit, including those resulting from changes in the identified risks of material misstatement and the work undertaken by the external auditor to address those risks.
After the audit, the audit committee should assess its effectiveness, report on the effectiveness of the process to the board of directors and discuss its findings and any recommendations with the board.
The audit committee should seek feedback from the external auditor, where relevant, on the main findings of audit quality reviews of the bank’s audit and the audit firm’s quality control systems by audit oversight bodies.
Principle 4: The audit committee should have effective communication with the external auditor to enable the audit committee to carry out its oversight responsibilities and to enhance the quality of the audit.
Regular, timely open communication between the audit committee and the external auditor is essential. Regular dialogue should be held throughout the reporting cycle of the bank.
While cooperation is important, the audit committee should challenge the external auditor when necessary to ensure robust discussions and stronger and deeper understanding on key issues.
The audit committee should consider inviting the external auditor to attend audit committee meetings, even when no specific audit topics are on the agenda, to discuss relevant matters. To enhance audit quality, the audit committee should consider, if necessary, assisting the external auditor to gain access to any other committee meetings that the external auditor determines to be relevant for the auditor’s work.
The audit committee should have the right and authority to meet with the external auditor without executive management, to discuss any issues that arose during the external audit and their resolution.
The audit committee should discuss with the external auditor any matters arising from the statutory audit that may have an impact on regulatory capital or disclosures.
The audit committee should discuss with the external auditor any significant issues identified in the course of the audit, including upcoming changes in standards and the consequences of material transactions for the financial reporting processes and performance of the bank.
The audit committee should communicate matters that are likely to be of significant relevance to the conduct of the statutory audit to the external auditor, including significant communications with the supervisor.
Principle 5: The audit committee should require the external auditor to report to it on all relevant matters to enable the audit committee to carry out its oversight responsibilities.
In some jurisdictions, auditors must also report on internal controls over financial reporting; this section focusses on reporting to the audit committee in the context of the financial statement audits.
The external auditor should provide those charged with governance with timely observations on significant matters relevant to their oversight responsibility on the financial reporting process, in line with internationally accepted auditing standards.
The audit committee should request reporting on key issues (see ISA 260 for examples of key issues).
The external auditor should also determine whether significant matters need to be communicated to the bank’s governing body.
Written communications of significant findings between the auditor and those charged with governance is recommended to enhance audit quality and to support supervisory work, even if oral communication is also used.
The key objective of these relationships is to improve the supervision of the banking sector and enhance the quality of external audits. An effective relationship allows both parties to fulfil their responsibilities without implying that one is responsible for the other’s statutory duties.
The external auditor can provide the supervisor with valuable insight into a bank’s operations, including management’s application of accounting policies and judgments. Conversely, supervisors can share independent assessments that may help the external auditor to focus attention on key areas of concern. In certain jurisdictions, the supervisor may also request the external auditor to perform specific assignments that go beyond the statutory audit work.
Principle 6: The supervisor and the external auditor should have an effective relationship that includes appropriate communication channels for the exchange of information relevant to carrying out their respective statutory responsibilities.
Supervisors and external auditors should have an open and constructive relationship ensuring that information shared is treated appropriately and confidentially.
For effective communication, both parties should engage knowledgeable individuals, who are authorised toc exchange relevant information.
The supervisor may benefit from the external auditor’s work as they often address similar issues, though with different focuses. The external auditor may also gain useful insights from the supervisor. However, neither party should rely on the other’s work as a substitute for their own and the bank should remain the main source of information for their respective work.
The terms of this relationship can be determined in individual jurisdictions and should be clear to both parties – for example, through guidance issued by the banking supervisor.
The external auditor’s report on financial statements is used for prudential supervisory purposes. During audits, the external auditor communicates significant matters to management or governance bodies, and these communications may also be accessed by the supervisor. In some cases, the external auditor may review the supervisor’s communications to the bank.1
| 1 | The external auditor should review the supervisor’s communications to the bank to help identify instances of non-compliance with laws and regulations that may have a material effect on the financial statements as required by ISA 250. |
The supervisor and the external auditor should consider communicating in writing on matters of potential mutual interest, ensuring these communications are part of the bank’s records and accessible to both parties.
Communication between supervisors and external auditors should include direct written and/or oral communication channels or a combination of both, depending on circumstances.
Written communication channels may include extended audit reports submitted to the supervisor but not made public.2 In some jurisdictions, these reports may be part of the external auditor’s statutory audit work and may also address prudential supervisory requirements.
| 2 | Ordinarily, such reports would be issued for the attention of the board of directors of the audited bank, but should be delivered to the supervisor as well (directly or through the bank). |
Oral communication channels may involve formal or or ad hoc bilateral meetings between the supervisor and the auditor. Trilateral meetings including the audit committee chair (or an independent non-executive director) may also be held. Bilateral and trilateral meetings are examples of sound practice communication channels, particularly for systematically important banks (SIBs).
These communication channels can provide supervisors with information outside the external auditor’s formal duty to report/alert (see Principle 7), such as emerging and thematic issues, sector-wide issues or bank-specific matters. Examples of such matters include:
Where bilateral and trilateral meetings are held, particularly in the case of SIBs, the timing and content of these meetings could be aligned with the external audit’s planning and concluding phases and/or the supervisory assessment of the bank. These meetings should focus on significant risks and findings.
The form, frequency and content of the communication between the supervisor and the external auditor of the bank will vary based on jurisdictional circumstances, the bank’s characteristics, and the supervisory model.
External auditors are bound by ethical standards to treat much of their audit-related information as confidential. Nevertheless, in jurisdictions where a legal provision protects external auditors from disciplinary proceedings, prosecution and liabilities when making disclosures in good faith to the supervisor (safe harbour), external auditors may share information with the supervisor in good faith without breaching their duty of confidentiality.
For matters outside the scope of the duty to report/alert discussed in Principle 7, but which may still be of interest to the supervisor, the external auditor communicates these matters either indirectly through the bank, or directly with the bank’s consent, in cases where safe harbour protections do not exist.3
| 3 | In jurisdictions where one does not exist, supervisors should be encouraged to work towards achieving a safe harbour. |
The supervisor, subject to confidentiality rules, may share bank-specific information with the external auditor if it supports its supervisory work and improves audit quality. Before sharing information, supervisors should assess its sensitivity and relevance to their duties and the auditor’s work.
Principle 7: The supervisor should require the external auditor to report to it directly on matters arising from an audit that are likely to be of material significance to the functions of the supervisor.
Reporting should be conducted directly from the auditor to the supervisor, unless not permitted, in which case reporting should be conducted indirectly through the bank.
When required by the regulatory framework or by formal agreement, the external auditor should promptly communicate matters of material significance to the supervisor (referred to as “duty to report/alert”). In jurisdictions with such a requirement, the disclosure in good faith to the supervisors by an external auditor of matters of material significance does not constitute a breach of the auditor’s duty of confidentiality.4
The external auditor typically discusses significant matters with the bank’s management and/or those charged with governance. However, when required to report directly to the supervisor on such matters, the external auditor should not rely on the bank to notify the supervisor.
Examples of significant matters within the auditor’s duty to report/alert include:
The external auditor should notify the supervisor of their resignation (or intent to resign) or removal by the bank.
Both the supervisor and external audit firms obtain information which, when reviewed entirely, can help identify trends and developments indicative of emerging systemic risk. Audit firms may also identify emerging issues, such as inconsistent or inappropriate application of accounting standards. Addressing these issues early will allow external auditors and supervisors to take timely remedial action at the national level and at affected banks to ensure the fair presentation of their financial statements.
Principle 8: There should be open, timely and regular communication between the banking supervisor, the audit firms, and the accounting profession as a whole, on key risks and systemic issues as well as a regular exchange of views on appropriate accounting techniques and auditing issues.
The banking supervisor and external audit firms should regularly discuss existing and emerging key risks and systemic issues at the national level. Open communication in a constructive environment is important, and ad hoc meetings should be held when urgent matters arise, to enable timely action.
Periodic meetings between the supervisor, audit firms, and professional accountancy bodies should address existing and emerging key risks and systemic issues. Discussions may identify key risks, including:
Such discussions can help identify systemic issues and promote consistent application of appropriate accounting policies. It may be beneficial for banking industry associations to be involved in discussions on these topics.
The audit oversight body’s main role is to monitor the quality of audits in order to protect the interests of investors or further the public interest.
Principle 9: There should be regular and effective dialogue between the banking supervisor and the relevant audit oversight body.
Where an audit oversight body exists, the supervisory authority should maintain regular dialogue with it to address issues related to bank audits.
Dialogue can occur through formal (eg scheduled regular meetings) and informal channels (eg ad hoc discussions, telephone conversations). Communication should be open, constructive, and two-way.
Meetings should occur as frequently as necessary to discuss issues of mutual concern or interest arising from each authority’s duties, subject to relevant legal constraints.
Information exchanges may include topics such as the robustness of audits in areas critical to the supervisor, such as loan loss provisioning, internal controls or risk management. Discussions may also address audit deficiencies identified by the oversight body, its responses and any corrective actions taken by audit firms to improve audit quality.
Where an appropriate framework for information-sharing is in place, the supervisor may also share concerns about audit quality at specific banks, or general issues with audit firms, such as areas where there can be a significant risk of material misstatement.
While identifying audit deficiencies is not the supervisor’s primary focus, it should inform the audit oversight body of any matters requiring its attention.
Discussions should cover not only current issues but also thematic or emerging topics.
Based on these discussions, the supervisor may take action such as:
Information shared between the supervisor and the audit oversight body is likely to be subject to legal confidentiality requirements. The receiving party should handle such information accordingly, and consider:
While the primary focus in this section is on the financial statement audit, the external auditor may identify matters during the audit that are relevant to the supervisor and which should be communicated to them.
In some jurisdictions, as part of the statutory audit, the external auditor may also undertake additional work, such as providing assurance on internal controls or other aspects of a bank’s operations. The supervisory expectations set out in this part of the document provide a relevant reference for such additional work.
Expectation 1: The external auditor of a bank should have banking industry knowledge and competence sufficient to respond appropriately to the risks of material misstatement in the bank’s financial statements and to properly meet any additional regulatory requirements that may be part of the statutory audit.
The external auditor of a bank should have specialised knowledge and competence in auditing banks, appropriate to the size, complexity and diversity of banking activities, and the legal and regulatory framework in which banks operate. The auditor should use experts as appropriate.
Knowledge and competence are critical for exercising professional judgment and carrying out key audit tasks, such as identifying and assessing risks of material misstatement and designing and implementing appropriate responses.
For banking audits, the audit engagement team should have:
Given the complexity of financial reporting requirements, especially for accounting estimates, the external auditor should consider whether to involve experts with specialised skills or knowledge in areas such as loan loss provisions, fair value measurements, and areas with differing interpretation, or newly developing practices.
Audit firms should have a documented policy and procedure that sets minimum competency criteria for the bank audit engagement team, considering the roles and experience of different team members.
Supervisors may have the ability to influence the competency requirements for external auditors. Where specific requirements for bank auditors do not exist, the supervisor may encourage professional and regulatory bodies to introduce training and experience requirements to ensure audit teams for bank audits are sufficiently competent.
In some cases, expertise in a field beyond accounting or auditing may be needed to support the audit engagement team. This may include complex valuations (eg financial instruments, commercial property), regulatory matters or evaluation of complex IT environments, particularly in areas with significant risks of material misstatement.
Internationally accepted auditing standards outline the procedures auditors should follow to determine whether to use the work of an expert and ensure the auditor’s expert’s work is adequate for the audit.
For complex valuation models used in accounting estimates, the external auditor should also consider the following when deciding whether to use an auditor’s expert:5
| 5 | These considerations are additional to those set out in ISA 620. |
Expectation 2: The external auditor of a bank should be objective and independent in both fact and appearance with respect to the bank.
Objectivity is a fundamental ethical principle and a key element of audit quality. It requires that the external auditor’s judgment is not compromised because of bias, conflict of interest or the undue influence of others. As objectivity is a state of mind that in most cases cannot be directly observed by users of financial statements, it is important for the external auditor to be independent in both fact and appearance.
Ethical standards, both jurisdictional and international provide frameworks to help external auditors achieve and maintain independence.
Independence means freedom from situations and influences, facts and circumstances where a reasonably informed third party would conclude that an external auditor’s objectivity is impaired. Independence applies not only to the bank being audited but also to its related entities.
The external auditor of a bank must comply with jurisdictional ethical standards. Whether or not the jurisdictional ethical standards align with internationally accepted ethical standards (eg IESBA), the external auditor of a bank should also comply with the independence standards for public interest entities6 under internationally accepted ethical standards.
| 6 | Public interest entities are defined by IESBA and includes “an entity one of whose main functions is to take deposits from the public”. |
When assessing potential threats to independence, the external auditor should evaluate not only the specific rules, but also the substance of the threat to independence, and how a reasonably informed third party would perceive the situation. Non-assurance services provided by the audit firm or its network firms to the audited bank may create threats to independence and objectivity, which should be carefully evaluated.
The external auditor should be particularly cautious of self-review threats, when advising management on accounting matters. For example, in cases where complex transactions are structured to achieve specific accounting or regulatory outcome, auditors must ensure they do not take on management’s role or responsibility while providing advice.
Expectation 3: The external auditor should exercise professional scepticism when planning and performing the audit of a bank, having due regard to the specific challenges in auditing a bank.
Professional scepticism should manifest itself not only through the auditor obtaining corroborating evidence for management’s assertions, but also challenging management’s assertions, considering whether there are alternative accounting treatments that are preferable to those selected by management, and documenting the auditing approach, the evidence obtained, the rationale applied and the conclusions reached.7 Throughout the audit, the auditor adopts a questioning approach when considering information and in forming conclusions.
| 7 | Professional scepticism is defined by the IAASB as “an attitude that includes a questioning mind, being alert to conditions which may indicate possible misstatement due to error or fraud, and a critical assessment of evidence”. |
Professional scepticism is critical in bank audits due to the significance of accounting estimates and the potential for limited objective evidence supporting those estimates. Professional scepticism is particularly important in areas involving:
Key areas where professional scepticism is essential include impairment calculations, fair value measurements and going concern assessments, including assessments of solvency and liquidity. It is also important for complex transactions that lack substance, or to achieve particular accounting or regulatory outcomes. In such cases, the external auditor should challenge management’s inputs and assumptions, forming independent views and questioning evidence provided by management.
Where a bank consistently uses valuations that show a pattern of optimism or pessimism within a range of acceptable valuations, the external auditor should consider the risk of management bias. This includes reviewing other areas that might be affected by management bias, such as accounting estimates and classification of financial instruments, that are used for regulatory capital measures. The auditor informs those charged with governance, where appropriate, of any indicators of possible management bias.
The extent of professional scepticism exercised should be evident in the audit documentation, which should clearly describe the conclusions reached and how they were achieved. Internationally accepted auditing standards set minimum requirements for audit documentation.
Expectation 4: Audit firms undertaking bank audits should comply with the applicable standards on quality control.
Audit firms should comply with jurisdictional quality management standards. Regardless of jurisdictional standards, audit firms should also comply with the quality management requirements applicable to audits of listed entities under internationally accepted quality management standards.
The audit of a bank should be subject to an engagement quality review (EQR). The EQR reviewer should be involved from the early stages of the audit, not only at the end. The EQR reviewer should have the necessary competence and capabilities, including sufficient time, and appropriate authority, to perform the role and should review how the engagement team has demonstrated professional scepticism. Such considerations should be documented in the audit working papers. The EQR reviewer should also assess how the audit engagement team has addressed accounting and regulatory information.
EQR is part of a firm-level quality management system that emphasises quality, consultation and compliance with auditing, ethical, legal and regulatory standards.
The involvement of the EQR reviewer throughout the audit, and the outcome of the EQR, should be evident in the audit working papers. Robust documentation of the discussions between the EQR reviewer and the audit team on all matters of significant judgment should be included in the working papers. In jurisdictions where the supervisor has access to the external auditor’s working papers, the extent and results of the EQR would also be at the supervisor’s disposal.
Expectation 5: The external auditor of a bank should identify and assess the risks of material misstatement in the bank’s financial statements, considering the complexities of the bank’s activities and the effectiveness of its internal control environment.
In auditing a bank, the external auditor identifies and assesses risks of material misstatements at both the financial statement and assertion levels. The external auditor also gains an understanding of internal controls relevant to the audit, including the bank’s control environment.
To address assessed risks of material misstatement, the external auditor follows an audit strategy combining substantive procedures and control testing. Given the high volume of transactions in banks, the external auditor of a bank is expected to test relevant controls over significant financial reporting processes to determine their reliability.
The external auditor needs to apply the concept of materiality appropriately in planning and performing the audit.
The external auditor exercises professional judgment to determine what is material to the financial statements, focusing on misstatements that could reasonably be expected to influence economic decisions of users taken on the basis of the financial statements.
Certain financial statement items, such as those used in regulatory ratios (eg leverage, liquidity and capital adequacy ratios) are critical to users. The auditor should consider these ratios when setting materiality thresholds for the audit.
Even misstatements below materiality thresholds should be carefully evaluated, as they may indicate broader control deficiencies that could lead to material misstatements.
According to internationally accepted auditing standards, the components of internal controls relevant to financial statement audits are:
A robust internal control environment is critical to the strength of a bank’s governance system and its ability to manage risk. The external auditor should assess, amongst other considerations:
Compensation arrangements can indicate a bank’s culture and risk attitude. The external auditor should pay attention to risks of material misstatement in the financial statements due to fraud, especially where compensation incentivises excessive risk-taking or other inappropriate behaviour.
Understanding control activities relevant to the audit is critical for assessing risks and designing further audit procedures in response to assessed risks. The external auditor should take account of factors such as:
When the external auditor uses the work of internal auditors as evidence for the financial statement audit, internationally accepted auditing standards require that they assess its relevance and adequacy. The external auditor should engage with, the internal auditors. This may provide valuable input into the external auditor’s understanding of the entity and its environment and aid in identifying and assessing risks of material misstatement.
The external auditor should provide written feedback on their interactions with the internal audit function, including, where relevant, its observations on the adequacy of the work of the internal audit function, to those charged with governance. This information is also valuable to the supervisor.
Expectation 6: The external auditor of a bank should respond appropriately to the significant risks of material misstatement in the bank’s financial statements.
After identifying significant risks of material misstatement, whether due to fraud or error, at the financial statement level and the assertion level, the auditor designs and implements appropriate responses, including testing controls in the current period that the auditor plans to rely on and performing substantive procedures specific to that risk.
In addition to the areas set out in FRD20.137 to FRD20.150, certain financial statement items, such as deferred tax assets, investments in unconsolidated entities, pension fund assets and the classification of financial instruments, may be subject to management bias. External auditors should evaluate these items for potential management bias and its impact on regulatory ratios.
Significant risks in banks change over time. Below is a list of audit areas commonly associated with significant risks of material misstatements, but is not exhaustive.
Loan loss provisioning is a key area involving complex judgements about credit risk. The external auditors should consider the following factors in relation to loan loss provisioning and the related allowance for loan losses. This list is not intended to be comprehensive.
Financial instruments measured at fair value may include financial instruments that are subject to an impairment assessment which may be a key area of judgment. Auditors should consider changes in the bank’s portfolio of financial instruments and evaluate the accounting implications.
Accounting standards for financial instruments contain requirements for recognition; initial and subsequent measurement (including impairment); reclassification from fair value to amortised cost; derecognition; presentation; and disclosures. Auditing financial instruments often requires complex procedures to obtain sufficient appropriate audit evidence to obtain reasonable assurance that the financial statements are not materially misstated. The accounting classification of an individual financial instrument may be particularly important for achieving a favourable regulatory outcome.
Auditors should adopt a sceptical approach to management’s assumptions for valuing financial instruments with significant unobservable inputs, following guidance such as IAPN 1000, Special considerations in auditing financial instruments.
Non-compliance with laws, regulations or contracts can lead to litigation, penalties or reputational damage. Such events may require recognition of provisions, contingent liabilities and/or qualitative disclosures in the bank’s financial statements. Further, any adverse impact on the bank’s reputation resulting from this non-compliance could have consequences for the bank’s going concern assessment. Auditors should remain alert to such risks.
Users of financial statements need relevant and extensive qualitative and quantitative disclosures, due to the complexity of transactions and estimates represented in banks’ financial statements. Increased transparency through fairly presented public disclosures enhances market confidence. It is therefore important that the bank provide disclosures that present the bank’s financial condition, identify and describe the risks to which the bank is exposed and how they are managed, and are meaningful and responsive to changes in market conditions and perceived risks.
The external auditor should assess whether the bank’s disclosures fairly present the bank’s financial condition and risks, particularly with regard to:
In some jurisdictions, certain regulatory ratios (eg capital ratios) may be published with banks’ financial statements and are material to a range of users in assessing bank performance. In its audit work, the external auditor should be alert to any indications that the regulatory ratios published with or included in the financial statements are not consistent with the auditor’s understanding of the bank’s risk profile, activities and strategy.
The external auditor is responsible for obtaining sufficient appropriate audit evidence and conclude about the appropriateness of management’s use of the going concern assumption in the preparation of the financial statements and whether there is material uncertainty about the entity’s ability to continue as a going concern. The external auditor should remain alert throughout the audit for evidence of events or conditions that may cast significant doubt on a bank’s ability to continue as a going concern.
Going concern assessments for banks is different from that likely to be performed for a non-bank entity because of features such as maturity mismatches, credit risk, the potential for regulatory intervention, and market sensitivity. Going concern assessments of banks are unique for the following reasons:
Banks are required to meet liquidity requirements and capital ratios set by the supervisor. The external auditor should evaluate the liquidity and solvency of the bank for the period over which the going concern assumption has been assessed:
| 8 | Non-compliance with capital requirements is one of the examples noted in ISA 570, under other events or conditions that may cast significant doubt about the going concern assumption. |
In assessing management’s assertion that a bank is a going concern, the external auditor should consider at least the following factors:
If material uncertainties related to events or conditions that may cast significant doubt exist about the bank’s ability to continue as a going concern, the external auditor should promptly notify supervisors.
Securitisations, including special purpose entities (SPEs), require special consideration by the external auditor and are of interest to the supervisor for the following reasons:
This module describes expectations to combat money laundering and terrorist financing.
This module describes expectations and practices relating to capital adequacy.
This module describes expectations for corporate governance.
This module describes expectations for credit risk and counterparty credit risk management.
This module describes expectations for external audit and sets out references related to public disclosure.
This module describes expectations for banks’ internal audit and compliance functions.
This module describes expectations for liquidity risk management.
This module sets out references related to market risk and interest rate risk.
This module describes expectations for the management of operational risk and operational resilience.
This module describes expectations for the management of problem assets and expected credit losses.
This module describes the application of proportionality in prudential regulation and supervision.
This module describes expectations for risk management.
This module describes the nature and application of prudential supervision.