How audits fail in Significant Accounts
The recurring ways firms fell short. Click any one to read the real inspection findings.
- Little or no substantive testing31
The firm performed little or no substantive testing over the account, disclosure, or assertion.
7 significant risk - Estimate assumptions not evaluated25
The firm didn't sufficiently evaluate the reasonableness of the significant assumptions behind an estimate.
12 significant risk - Accuracy/completeness of client data not tested16
The firm used issuer-prepared schedules, reports, or system data without testing that they were accurate and complete.
4 significant risk - Accounting or disclosure treatment not evaluated13
The firm didn't evaluate whether the accounting or disclosures conformed with GAAP, or didn't identify departures from GAAP or omitted disclosures.
4 significant risk - Reliance on a specialist or pricing service9
The firm relied on a specialist, pricing service, or third party without sufficiently evaluating that work.
5 significant risk - Management review controls not fully evaluated7
The firm tested a management review control but didn't evaluate the specific procedures the reviewer performed, or the control's precision.
2 significant risk - Estimate method, model, or data not evaluated7
The firm didn't evaluate the method, model, or underlying data the issuer used to develop an estimate or fair value.
5 significant risk - Controls not identified or tested6
The firm didn't identify and/or test controls it needed to rely on for the account or assertion.
1 significant risk - Confirmations / alternative procedures5
The firm didn't obtain confirmations, or didn't perform sufficient alternative procedures when confirmations weren't returned.
- Other testing deficiency4
A deficiency that doesn't fall into one of the more specific patterns above.
- Sample too small or unsupported3
The sample the firm tested was too small, or the basis for the sample size didn't support the conclusion.
- IT general controls not tested2
The firm relied on automated or IT-dependent controls but didn't adequately test the underlying IT general controls (e.g. change management).