📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

2020 audit lectures - Module 3, Topic 4 - Deciding on the right audit strategy

AmandaLovesToAudit42:35

Transcription

What's up, audit fans, and welcome to our last topic in module three, which is about planning. And topic four is about deciding on the right audit strategy. And you might be thinking, wow, we spent four topics on planning. That's really, really important because planning is the foundation of our audit, and it helps us make sure that our audit is effective and efficient from the very start. So, let's get into it.

So, what am I going to cover in this topic? Well, we're going to do a little recap first of the previous three topics about our risks of material misstatement. Then we're going to look at the audit risk model. We're going to talk about identifying what the standard calls as significant risks. We're going to look at how we then respond to the risks that we've identified. We've identified these risks, what do we do with them? And then look at planning our audit strategy, linking that back to the audit risk model, and then documenting our work in something called our audit program. And designing those programs is really going to be, and executing them is what is coming up in module number four, which is about gathering evidence.

So, let's start with a context diagram of what we're actually doing in this particular topic of the module. So, we know that the output is our audit report, and in our audit report, our plan is that we're going to give an opinion. And that opinion, so the audit report contains an opinion, and to be able to give that opinion, we need to gather reasonable assurance that the financial statements are going to be free from material misstatements. Now, how do we get that reasonable assurance? How do we make that decision? Well, we know that we're going to need audit evidence. We're going to need evidence that the financial statements, which are down here, thin stats, which is what the audit report is about, we're going to need to get evidence that our financial statements are free from material misstatement. Okay, and we know what materiality is as well. So, we know that feeding into this whole process is an understanding of materiality.

Now, to gather our evidence, we know that we need to gather information about the financial uh statements that they I'm going to do this in a different color because I need to cross over here, that our financial statements meet our assertions. Remember, we've got our assertions for our transactions, and we've got assertions for our balances. And so our assertions help guide the evidence that we need to collect. But what do we need to collect, and in which particular areas? We need to have a plan. So, I'm going to go back to black here. We need to have a strategy to go and collect this evidence, and that strategy comes from using, whoops, arrows the wrong way around there, our audit risk model. So, our audit risk model is this key component which helps us decide on our audit strategy because our strategy and our assertions are sort of going to work together to help us collect our evidence.

So, the planning part that we've been looking at is that we know that the audit risk model needs inherent risks and it needs a control risk assessment to go into the model, and our detection risk will help us generate our audit strategy. But to be able to identify the inherent risk and the control risks, which remember we call our ROMs, these are both ROMs here, we need to understand the client. All right. So, in terms of what we've been doing so far in the planning phase, is we've been looking at what do we need to do to understand the client so that we can generate control risks and inherent risks and an assessment to be able to use the detection risk model to come up with a general audit strategy. And that's what today is going to be about. Today is going to be about figuring out what is this strategy. And you might think, well, you know, we spent three weeks on identifying our inherent risks and our control risks and understanding our client. And this is probably, you know, the reason that we do that is because it's a really difficult topic. It's difficult to understand what the inherent risks are and to be able to look at a process and identify what could go wrong in the internal controls. Our next module, module number four, is going to be spending a couple of weeks looking at this evidence. So, feeding in, how do I collect the evidence to be able to generate the opinion? And then at the very end, we're going to be looking at this process of actually building the opinion and doing some of the other tasks that we do at the end of the audit. So, that's the context for this particular topic. We're all about trying to evaluate exactly what's happening in terms of strategy, what should we do in our approach to go and gather the evidence? And there are two main strategic options I'm going to talk about, and then a mix between both of them.

So, our first real media topic today is the ROMs and where they come from. Remember, ROM stands for Risk of Material Misstatement. Now, remember from our inherent risks, the key is to understand the client, the industry, and the environment. And if you go back into ASA 315, there's plenty of information about what we need to know. And you need to be able to know how to do that research, to do some of the searching, to go into the back of ASA 315 and figure out what do I need to know about an industry, about a client, about their environment. We also need to ask in our current situation, especially in light of COVID-19, are management more likely to understate or overstate? This will help us also get this insight into what do we expect to see in the financials. And we know that we looked at expectations when we did our financial analysis topic. So, I sort of think about, what do I expect to see? What do I see? What is different? What is unexpected? And what could be driving those unexpected movements?

So, for us, we need to think about, let me get my mouse pointer back on, the increased risk of misstatement. So, inherent risks are places that inherently, because of the structure of the firm, what they do, how they do it, something in the nature of the business, there's an increased risk of error or fraud in the accounting information. We're not thinking about problems in processing or internal processes, that's control risk. We're just thinking about what could go wrong. International companies could have more foreign currency translation reserve risk, for example.

Now, to figure out whether we do have a risk or whether we don't have a risk, remember that you need to be able to link that risk to a specific assertion and account. The exception to that rule is going concern. It's the only time in which you might say, oh, this doesn't link to a specific account, but you need to figure out what account is going to be misstated and what assertion is it likely to be understated or overstated.

Now, sometimes students get a bit confused as to what it means by having low, medium, and high inherent risk. This comes from using your professional judgment. But as we're developing that professional judgment, here are some guidelines. So, low risk is that we think there's a low chance of material misstatements in the financials. So, you think that the inherent risks are relatively small and they're unlikely to occur. In medium, we think, oh, you know, there's definitely a few areas. So, we might say some or few areas of increased risk. Okay. And that could be, we're going to talk about magnitude, how big could the error be, and likelihood a little bit later on. So, we take those things into account. Then high. So, high would be lots of areas of risks of material misstatement. So, that'd be a company that is international, uses a lot of estimations. So, you know, if you're thinking about number, there's not really a number here. There's nothing that says low inherent risk is like three risks, and medium is 10, and high is 15. But, you know, this is all relative as well. So, some industries are more risky than others. Airlines are more risky. Mining firms tend to be more risky generally because of their nature. Pharmaceutical companies because of research and development. So, the more that you practice, the more that you imagine yourself, immerse yourself as you're walking and you see a product like, you know, a stylus pen, or you buy bread, or you go to a local bakery, or to your local Japanese sushi place, think about, you know, is there more risk, less risk? Um, generally, in the current environment, we think that there's more risk of material misstatement. And if in doubt, overstate the level of risk. So, if you're worried, no, I'm not sure if it's low or medium, always err on the side of caution. The conservatism principle for us as accountants still applies. Um, and go for higher levels of risk because higher levels of risk means you're going to be more careful on that audit. So, you're always better off going higher than lower.

So, the next thing that we need to talk about is control risk. And remember, control risk comes from that pyramid that we looked at. We looked at flow charting and drawing out the control processes to try and find if there are any weaknesses. So, we need to be able to identify those components, those five components of the systems of internal controls, documenting the control processes or the business process, and then identifying the control activities. What are things that are they're doing to prevent or detect material misstatements? And remember, you can see control activities everywhere and anywhere. You know, I've got my iPad here, and even something as simple as having the uh password to log in could be a control activity. If you work in a retail organization, you might have to type in a code to access a system or swipe a card to be able to use the cash register. Control activities are everywhere. And once you start looking for them, when you go to buy something, sell something on eBay, log on to your internet banking, get a driver's license, open a business, there are controls everywhere. And we need to be able to know how to identify them, but also importantly, we need to be able to identify control weaknesses. Where is something that goes wrong? What could be the issue? Once we've identified the control weakness, the questions we need to be able to ask ourselves are, what is the potential misstatement? All right. And when I mean potential misstatement, I mean we need to be thinking about our account, but also about the assertion. So, typically, we'll be able to say, oh, look, we think that this lack of approval of something is going to affect the occurrence of a particular transaction or the accuracy of a particular transaction. So, we need to be able to identify these weaknesses and then say, what next? So, what? That's a really, really important question.

Now, in terms of control risks and low, medium, or high, it's a little bit easier to make some judgments here. So, low control risks would be, you know, I would say probably one to two weaknesses of a minor nature. Okay. You might have really great controls, but one really whopper weakness, and that is going to overshadow everything in terms of size and issue. But, you know, usually one to two minor weaknesses, you go with low control risk because no company is perfect. So, that means in a medium situation, you're probably going to be looking at sort of, you know, three to five weaknesses. And a high control risk situation would be that six plus or a few smaller ones that are really, really big. Like, imagine that the, um, ATM. So, you're going to get money out, put your card in, and it didn't require a PIN. That's a really huge control. There might be lots of others, but one really massive issue can really overshadow and probably push it into that high control risk area.

So, in topic 4.2, we're going to look at identifying the significant risks. And this isn't a term we've talked about yet. I've only talked about inherent risks and control risks. I'm going to get into significant risks because they're actually mentioned specifically in the standard. So, this comes from ASA 315, and I've asked you to read ASA 315 a few times because it's a really important standard. And it says here, and let me get my mouse so that I can show you, a significant risk, and this is from the glossary of the definitions, is an identified risk of material misstatement. All right. So, we've already identified it as an inherent risk, ROM, okay? So, we say, look, we found this risk, and normally when you're brainstorming, you could have 20 or 30 risks for a client. So, we identify a risk, and then the assessment of that inherent risk is close to the upper end of the spectrum of inherent risk due to the degree to which inherent risk factors affect the likelihood of the misstatement and the magnitude. So, that's the important part to take away here. We're looking at the combination of the likelihood of the misstatement occurring, is it a 60% chance of happening, 100% chance of happening, and then also the magnitude of the potential misstatement, so how big in terms of dollars could the error be? So, the likelihood is like the probability. Well, it's not very easy to read there. Let me change colors. So, the likelihood is the probability. The potential magnitude is the dollar value size. And it says there, once we have, we we map out our risks, then we're going to identify some as significant risks. And then ASA 330 says that what we need to do is, where we have a significant risk, then we need to make sure that we plan for it specifically in an audit because we think there's a greater risk of material misstatement. Remember, an audit is risk-based, and so where we think there's more risk, we're going to pay more attention, we're going to collect more evidence, we're probably going to be a bit more professionally skeptical as well. So, we need to do this quite carefully.

Now, how many significant risks might an audit have? There is no magic number. Um, in talking with Professor Roger Simnet, who's the chair of the Auditing Standards Board, and he was there when they drafted the first standard that talked about significant risks, 315, a number of years ago, they said, you know, we might, these are like showstopper things on the audit. We might have five, six, seven of these really big things. So, you might identify lots of risks, small ones, big ones, but the significant risks that are going to shift, have a seismic shift in our audit planning, those are going to be what we classify as our significant risks. So, that's a definition from, uh, paragraph 11 over here. And then a separate paragraph, paragraph 32, says I have to look at the ROMs and say, are any significant? It's going to be very unlikely that you're going to have an audit that will have no significant risks. It's very much more likely that they might have three, four, five. Really risky firms are going to have a much higher number there.

So, how do we figure out which risks are significant? Now, remember, I told you before that ASA 315 says look at the potential magnitude of misstatement and the likelihood. So, remember the magnitude, I'll do this in green, these are like really big dollar issues, these are small dollar issues. And the likelihood, this is like 0% chance of happening, and this is 100% chance of happening. So, how do you figure out which risks are significant? Well, what you do is you go and you take your ROMs, your inherent risks, especially your ROMs, and you put them on this matrix. So, you might have risks plotted out all around here. All right. And you'll work with your team to figure out, you know, this high magnitude, low likelihood. So, what it's really saying is that you essentially have to take, um, your likelihood and your potential magnitude. And there's no real science to this. All right. We sort of draw, oops, that's not the color pen I wanted there. No eraser, eraser. Yeah. So, I'm dividing my sort of process into quadrants here. And most of the time, we would say, okay, the things that are at the upper end. When the standard says the upper end, what they're referring to is the risks that are here in this quadrant, high likelihood of occurring, high potential dollar value impact. Now, in the current COVID environment, that circle, all these lines might shift. So, we might decide, and I'm going to draw these in a different color, let's go with purple, that in a COVID environment, where there's a greater risk of companies collapsing, where we need to be extra specially careful, we might move our sort of quadrant lines to be down here rather than being exactly quadrants. We might say, in a situation like the current environment, I might actually expand what goes into my significant risk list because if something happens to a company, they collapse, and our audit didn't take into account everything, I'd rather do more work by making more risks significant and then having to deal with the planning and gathering evidence, then do less and then potentially end up with an audit that doesn't meet the Corporations Act requirements in terms of meeting the ASAs. Now, this is not always necessarily equally into four, but it's professional judgment. The key here is that idea of professional judgment. All right. And this is something you develop over time. You don't walk out of uni going, yup, I know how to make these judgments. Instead, it takes years of practice. If you're going to an audit intern job, or a vacation job, or a grad job, you'll ask if you can get involved in this process. And if they say, okay, here are our significant risks, you can say, oh, look, why is this risk on the list? But why did we decide not to include this other one down here? Something that's always interested me is that, you know, you might have something that's very low likelihood but very high magnitude. Do you consider that in this unusual, unprecedented COVID circumstances? You know, I'm sure some companies would have thought about the risk of, you know, a global pandemic outbreak. The likelihood was like tiny, but the magnitude was huge. So, we really need to talk as a team. And this is how you learn these skills in terms of deciding what is going to be significant. For students, I recommend again trying to plot them out and trying to make sure that you can say for yourself, why is this one high magnitude and high likelihood? Do I have anything to back it up? Do I have evidence? Do I have information from other industries? What is my logic? How could I justify this? Because one of the things we're going to talk about a bit later is how we justify our decisions in this area.

Now, if you don't document it, it didn't happen. This is really, really critical. So, ASA 315 says that in paragraph 38, I have to document everything. What discussions did my team have to come to this decision? What are the key elements of my understanding about the client? All right. Um, where did I get that information from? Who did I talk to? What risk assessment procedures did I do? Let me look at the design of the internal controls. Have I documented it? Have I identified the control activities and identified the weaknesses? And then, lucky last, it says, we've identified the risks of material misstatement. Um, we've identified our significant risks and risks for which substantive procedures cannot provide sufficient appropriate evidence. So, that's saying there are some accounts that are going to be so risky that I might not be able to get enough evidence to be able to give my opinion. That's pretty rare. But the key here is we need to document. Which means you need to practice thinking about, why is this a risk? What account does it affect? What assertion does it affect? Why is it important for the auditor to look at it? Another way of thinking about it is, what could go wrong if I don't look at this? If I miss this, and something does occur or there is an issue, how much trouble could I be in?

So, topic 4.3 is, what do we do once we've identified the risks? Yeah, it's great to identify the risks, but we've got to do something about it because remember, our audit is risk-based, which means we need to take the risk and we need to focus our audit effort. So, this whole process in terms of responding is about focusing our audit effort because remember, we have a limited time to do this audit. We have limited people resources. So, we want to make sure that when we deploy our people, we're doing it in a way that is effective, it's gathering the evidence that we need, and is also efficient at the same time. So, we're not wasting audit resources, we're not doing more testing than we need to, we're doing just the right amount. It's a bit like Goldilocks and the three bears, right? How much porridge, what temperature is the porridge that's too hot, and what porridge is too cold, and what temperature is just right? Finding that balance is unique to the audit. It's unique to the audit partner, the individual auditor's experiences. So, again, that professional judgment comes into play.

So, what are we required to do? I'm introducing a new standard here, one that we haven't looked at yet, which is ASA 330, and it's even called our Responses to Risks. So, what we have to do is we have to design and implement responses to address the assessed risk of material misstatement. So, where we think there is a significant risk or a high risk of material misstatement, we need to have a response. And what does it mean by response? Well, response means some plan to check whether that risk did actually result in misstatements or not. That's our response. And our response is going to be some way that we gather evidence to say, yes, there's an error, and it's $200,000, or we say, no, it's all good. All right. So, I, I need to make sure that I go and check this information. I need to gather this evidence to support my audit opinion because, remember, risk-based audit, there's more risk, I'm going to spend more effort looking into the potential misstatements. Just like you're studying for audit topics, you think, I know I need to know more, I don't feel as comfortable, I think there's a greater risk I might fall down on that type of question, then I'm going to spend more time studying. So, risk-based is something, you know, responding based on risk is something we do every single day.

Now, in terms of what our response needs to do, it needs to contain audit procedures. We're going to learn about procedures in our next module. There are methods to go and collect evidence. And we're going to look at the nature, what exactly is the procedure, the timing, when do I need to collect it, and the extent, which is how much evidence. If there is more risk, I might want to collect two sources of evidence. I might want to collect evidence close to the end of the financial year. I might want to get evidence from external sources. I might want to collect more evidence rather than less. So, we'll talk about these sorts of decisions in our next module. But just know that when we have a risk, we are going to have to do something about it. And our response is going to need to reflect what is the risk, how big is it, what's the likelihood, and what's the potential magnitude.

So, how do we know what my audit strategy is? Topic 4.4, we're going to talk about choosing the right strategy based on our ROMs, based on our understanding of the client, and based on the audit risk model because, remember, 330 said you have to make a response to these risks. And our audit strategy is really equal to our response. It's a bad idea there.

So, a reminder of the audit risk model. It's been a few weeks since we've looked at this. But remember, it starts out as AR equals IR * CR * DR. And then we transform that to say DR is Audit Risk divided by Inherent Risk and Control Risk. And we know that these things to here, they move in opposite directions. So, as the level of risk increases, our detection risk decreases. And remember, detection risk is the risk of not detecting the misstatement. So, low detection risk means I'm going to do a lot of work so that the risk of not detecting the misstatement is very small. Okay, that makes sense. That in a situation where inherent and control risks are high, there's a big chance of misstatements, I want to do a lot of work to make sure, like, find everything, which means my detection risk is going to be low. My risk of missing something is going to be small because I'm going to do a lot of work to look into it.

So, what does that mean from a really practical sense? Well, I'm going to draw a little diagram here. And so, I'm going to have, first up, I'll do this in blue, I'm going to have my ROMs. Oops. So, my Risk of Material Misstatement. All right. And so, that's made up of inherent risk and control risk. Okay. So, let's have low control risk down here and high control risk over here on the right. All right. So, so this is low CR, high CR. And it does include inherent risk, but the quality of the internal control system is also going to drive part of our audit strategy, as well as the level of inherent risk. So, let's start with, uh, I'll do controls in green. So, when it comes to understanding internal controls, everybody has to have a base level of information, right? So, I'm going to draw a little box here, and this box represents all the work that we do to understand the systems of internal control. All right. Everybody has to do this volume of work, just here, to understand internal controls. Now, if internal controls are good, they're really solid, there's no weaknesses, that protective layer around my accounting data is like really nice and tight, then I'm going to focus on testing that protective layer. Okay. So, in green here, the volume of control testing I'm going to do is really, really high. All right. I hope everybody's okay.

Now, on the right-hand side, where I have control risk as high, that's my Swiss cheese, leaky bucket example, right? So, there, I've actually gone away and I've gathered my information on the internal controls. Let me just get my laser pointer here. I've gathered my information on my internal controls, and I know that the controls, they're just, they're pretty terrible, right? You might say, look, they're pretty internal controls. So, what I'm going to do, instead of testing them, I'm going to go straight into the accounting data. So, my level of testing in that situation is going to be pretty small. See if I can draw a straight line here. Oh, not too bad. Okay. So, what you can see from my diagram here, if this is volume of testing, I'm going to do more testing of internal controls where controls are good, and I'm going to do less testing of internal controls where controls are pretty shitty. Okay.

Now, the next thing I'm going to talk about is, I'm going to talk about substantive testing. Substantive testing is detailed checking. Okay. Now, I have to always do a basic level of substantive testing. You cannot do an audit that is controls testing alone. That would be really, really not appropriate practice. There's nothing that I guess excludes that in the audit standards, but, you know, we've talked about this amongst audit circles for a long time. Like, if there's really great controls, do I need to still do substantive testing? I always say yes, because doing some substantive testing covers your ass in case things go wrong, and you say, yeah, I did some substantive testing. So, I'm going to draw a little orange box here at the bottom. Oh, this is going to be really terrible. It's not going to be a really straight line. I wish I had a ruler. Okay. All right. So, this base amount is the base amount of substantive testing we're going to do, no matter what. Even if the controls are really great. Down here on this left-hand side, I'm still going to do a little bit of testing. But think about the right-hand side, controls are terrible, leaky bucket. So, instead, I'm going to do lots of checking of individual transactions, detailed looking at stuff, getting paper cuts, checking records. So, my volume of substantive testing is going to be really, really high, right? And then decreases as my level of internal controls improves. So, at the base here, we have a base level of. So, we have a base level of substantive testing. And then on top of that, there's the base level, and then on top of that, we sort of have the rest. I'm trying to color this in, but it's not going to look very pretty. See if I can get it to sort of, you get the idea. I'll try and cover this in. Okay. So, everybody has to do that base level. And then on top of that, depending on, you know, the level of risk, we're going to do more and more substantive testing. So, from the green aspect here, this is volume of tests of controls. Okay.

Now, the thing I haven't included so far is what this second little arrow is. And this is really detection risk, right? So, where there is low controls and low inherent risk, detection risk is high. Then on the right-hand side, I have low detection risk. Okay. So, let me get my mouse pointer back up so that I can show you what I'm talking about. Okay, low control risk, low inherent risk, high detection risk. It doesn't mean that we're collecting any less evidence, but our strategy is going to be one that's focused on testing internal controls and a little bit of substantive testing because we think the controls are really solid. On the right-hand side, we have high control risk, high inherent risk. We're probably not going to do a lot of tests of internal controls, but we're going to do a lot of detailed checking.

Now, what if we're somewhere in the middle? What if we have some good internal controls and some areas of high risk? Well, then we're probably going to do a mix of both. So, that's where detection risk is in that moderate range in the middle. Now, there's nothing that says we're still just on this left-hand axis, you know, this left-hand column, or right smack in the middle, or further over here on the right. An audit could be anywhere along this spectrum with this risk. So, it's really mix and match. And then also, you might have one overall strategy for the entire audit. Overall, we're going to test of controls. But when you evaluate different cycles, the sales and revenue and cash receipt cycle, the purchasing and accounts payable cycle, you might find that those cycles have slightly different profiles. We thought procedures were really great in sales, but they're really crappy in purchasing. Doesn't make sense to do the same audit strategy. It makes sense to shift our strategy depending on what's happening in that individual area. So, that's how we practically apply and we come up with our strategy. So, when I say, tell me what your strategy is, I said, my detection risk is high, I'm taking a strategy that focuses on testing internal controls. Or, oh, yeah, my detection risk is low, I'm going to focus on a strategy that is mostly about substantive testing. Or, well, my detection risk is somewhere in the middle, so I'm going to do some tests of controls where controls are good, but where I know there's a weakness, I'm going to ramp up that substantive testing because I know that there's a greater chance there's going to be an error there.

So, I hope I know that this is quite a long slide to work through, or this long section, but it's really important that we understand this because what we're going to be doing in the next module hinges on knowing how to do this correctly. Now, audit strategies and programs are unique. They're custom designed for the client, the current economic environment, the industry. And strategies and plans can change from year to year. Everybody's audit strategies for COVID-19 are way different than the strategies and the plans that we saw for last year. So, they're always highly customized. It's really important to remember. I'm going to have an extra video that links through to YouTube where I talk about how our audit programs and our strategies are actually like making fried rice. So, if you like cooking and you want a bit more of an analogy, then make sure you check out that video as well.

Now, what about special considerations? I talked about COVID-19. There's a much bigger risk around going concern when it comes to COVID-19. Some businesses that, if you're in the pub industry, or the restaurant industry, or the hospitality and hotel industry, there's going to be much bigger issues around going concern. We've seen a number of companies go into voluntary administration. Virgin Airlines has gone into voluntary administration. Prior to the coronavirus, we saw lots of other retail operations going into voluntary administration. Target is not looking like a very profitable, um, arm of Wesfarmers at the moment. We also need to be aware of debt covenants. We haven't talked about debt covenants yet, but a covenant is when you have a loan, and that loan has conditions attached. And those conditions say things like, oh, you have to have a current asset level or a current asset ratio above a certain amount, or you need to keep so much inventory on hand, or so much cash on hand, or this is what your gross profit margin needs to be like. I raise debt covenants because if a company breaches its debt covenant, often that debt becomes due straight away. So, management, this is one area where management are much more likely to adjust and manipulate and massage the accounts using accrual accounting and accounting policy choice to help them stay above that debt covenant. And that's also going to link through to their going concern. So, that's something in terms of where we think there might be more risk. That's something that's certainly going to come into play. The third one that I've got there is thresholds for receiving government assistance programs. Like JobKeeper, for example, are available to companies that have certain revenue levels and have seen revenue levels drop by a certain amount. So, while companies might normally overstate their revenues, we might actually expect to see some understatement of revenues so that some companies might have a better chance of qualifying for JobKeeper. Especially when it comes to big companies, because for big companies that are more than a billion dollars in turnover, they have to see a very significant drop in revenues. I know that a number of universities are trying to get access to the JobKeeper program. Sydney Uni, La Trobe, and I think one other. And I can imagine that the accountants there are trying to actually figure out how to show the biggest drop in revenue so that they could get the most assistance.

So, what are the major tasks that you should be able to do from module three? Number one, know how to understand the client. Know how to do a little bit of research. What do you need to learn? Where do I find out that list in ASA 315? You need to be able to identify inherent risks and evaluate inherent risk as low, medium, or high. That comes from understanding the client, doing financial analysis, brainstorming. You need to be able to identify the control activities and make a control risk evaluation. So, that's flow charting the process, what are the controls, what are the weaknesses, do we have any issues? And then apply the audit risk model to determine the audit strategy. Are we doing a mostly test of controls approach, or a mostly substantive approach, or a mix of the two? So, those are the things that you need to be able to do from module three. Remember that with our risks, we also need to be able to link them back to specifically, remember I talked about my pen to work here, can you link it back to an account and can you link it back to an assertion? Okay. What is the potential misstatement? Where is the error? What is something that can go wrong?

So, what comes next? Next is module 4, which is about gathering evidence. And this is, how do I get the evidence that supports my opinion of reasonable assurance that the financial statements are free from material misstatement? So, we'll look at how do I implement this audit strategy of testing internal controls or substantive testing. So, we're going to look at that implementation and designing audit programs. And the other thing I forgot to add there is that we're also going to look at executing audit programs. So, what are the sorts of things that we might do to actually gather this audit evidence and give you some hands-on experience? So, that's it for module three. It's a really large one. Of course, if you have any questions, please make sure that you ask them in the channel on Teams. We're always there to answer questions. No question is too silly. And we look forward to seeing you in our workshops.