4 ms·
The difference is one of scale. For example, a Walmart sized company could easily have some fraud going on the scale of a couple million dollars - the financial
by Tyrek 8y ago
The difference is one of scale. For example, a Walmart sized company could easily have some fraud going on the scale of a couple million dollars - the financial statements are considered to be materially correct (i.e. in that investors would not consider numbers off by a couple million to be a big deal), but there would still be fraud going on.
You have to understand that the underlying concept of audit that a small team of auditors is responsible for ensuring that a huge (relatively) company is going about things correctly - there's no way to obtain a 100% assurance with that scale of manpower, and there's no appetite from companies to significantly increase the audit fees to obtain that level of assurance. Instead, a sampling/risk-based approach is taken in order to ensure that there cannot be a large error within the financials.
- UK-Al05 8y agoBut the point is that auditors didn't catch massive amounts of fraud either. Where financial statements did not match reality at all.
- acchow 8y agoOk, I think I understand now. The layers are: reality -> accounting books -> financial statements The auditors don't look at the first mapping "reality -> accounting books" but only at the second one "accounting books -> financial statements"? And even in the second mapping, they check with a sampling-based approach?
- sithadmin 8y ago>The auditors don't look at the first mapping "reality -> accounting books" but only at the second one "accounting books -> financial statements"? That's not entirely correct. A good portion of SOX audit efforts in the US, for instance, is spent on examining configuration of the various systems on which financial reporting is dependent (e.g. examining exactly how segregation of duty controls are implemented in the ERP system). A good portion of time is also spent examining if human-executed processes (e.g. employee on boarding/off boarding, granting permissions to data and financial system capabilities, manual review of backup job reports, etc) are actually being carried out in a manner that complies with the organization's SOX controls.
- Tyrek 8y agoNo, all testing is down all the way down to 'reality'. But testing is statistically scaled to detect large errors. The threshold for 'large' shifts with how large the audited company is. i.e. a couple million dollars is a rounding error at Walmart. Additionally, pretty much 90% of an audit flows through a limited number of client contacts. Audits are not designed to defend against a concerted effort to prevent the auditors from seeing 'reality' (i.e. un-doctored documents), due to the manpower requirements to validate information at that level. Conceptually, it's the difference between 'I-trust-you-but-I-need-to-check-that-you-did-your-homework' and 'Trust no one, everything you see is a lie'.