PCAOB Deficiency Tracker

Explorer

Search and filter 7,142 Part I.A deficiencies.

Clear
62 resultsPage 1 of 2
FirmAreaDeficiencyStandardFlags
BDO China Shu Lun Pan Certified Public Accountants LLP
China · BDO International Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. The firm relied on controls it selected for testing in its approach to testing inventory. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. As a result of the following deficiencies in the firm's testing of IT general controls (ITGCs) over certain of these IT systems the firm's testing of these automated and IT-dependent controls was not sufficient. (AS 2301.18)
Financial statement audit only · full report
AS 2301.18
BDO China Shu Lun Pan Certified Public Accountants LLP
China · BDO International Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. The firm relied on controls it selected for testing in its approach to testing inventory. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. ? The firm selected for testing certain controls over change management and user access but did not perform procedures to test or test any controls over the completeness of the population of items from which it made its selections for testing. (AS 1105.10)
Financial statement audit only · full report
AS 1105.10
BDO China Shu Lun Pan Certified Public Accountants LLP
China · BDO International Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. The firm relied on controls it selected for testing in its approach to testing inventory. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. ? The firm selected for testing a control that consisted of the issuer's periodic review of user access to one of its IT systems. The firm however did not perform procedures to test the design and operating effectiveness of this control. (AS 2301.19 and .21)
Financial statement audit only · full report
AS 2301.19; AS 2301.21
BDO China Shu Lun Pan Certified Public Accountants LLP
China · BDO International Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. The firm relied on controls it selected for testing in its approach to testing inventory. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. ? The firm selected for testing a control over the authorization and restriction of privileged access to one of its systems. The firm did not perform sufficient procedures to test this control because it limited its procedures to testing that one type of privileged access was restricted at a point in time during the year. (AS 2301.16 and .21)
Financial statement audit only · full report
AS 2301.16; AS 2301.21
BDO China Shu Lun Pan Certified Public Accountants LLP
China · BDO International Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. The firm relied on controls it selected for testing in its approach to testing inventory. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. ? For one of its IT systems the firm identified control deficiencies related to (1) developers having inappropriate access to the production environment and (2) the lack of monitoring of user activity. The firm did not evaluate the severity of these deficiencies and the effect on its control risk assessments. (AS 2301.34)
Financial statement audit only · full report
AS 2301.34
BDO USA, P.C.
United States · BDO International Limited
Inventory
IT general controls not tested
The issuer used an IT system to initiate process and record transactions related to revenue and inventory. In its testing of controls over these accounts the firm tested various IT-dependent manual controls that used data and reports generated or maintained by this IT system. The firm did not identify and test controls that addressed whether the level of access provided to users was appropriate. (AS 2201.39)
Both financial statement and ICFR audits · full report
AS 2201.39
BDO USA, P.C.
United States · BDO International Limited
Inventory
IT general controls not tested
The issuer used an IT system to initiate process and record transactions related to revenue and inventory. In its testing of controls over these accounts the firm tested various IT-dependent manual controls that used data and reports generated or maintained by this IT system. As a result of the deficiency in the firm's testing of ITGCs the firm's testing of these IT-dependent manual controls was not sufficient. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
BDO USA, P.C.
United States · BDO International Limited
Inventory
IT general controls not tested
The issuer used a service organization to host and maintain an IT system that the issuer used to initiate process and record transactions related to revenue and inventory. In its testing of controls over these accounts the firm tested certain automated and/or IT-dependent manual controls that used data and reports generated or maintained by this IT system. As a result of the following deficiency in the firm's testing of ITGCs the firm's testing of these automated and IT-dependent manual controls was not sufficient. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
Baker Tilly US, LLP
United States
Inventory
IT general controls not tested
The firm's internal inspection program had inspected this audit reviewed these areas and also identified the deficiencies below. The issuer used multiple information-technology (IT) systems to initiate process and record transactions related to inventory. The firm selected for testing an automated control that used data generated or maintained by these IT systems. As a result of the deficiencies in the firm's testing of IT general controls the firm's testing of this automated control was not sufficient. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
Deloitte Touche Tohmatsu Certified Public Accountants LLP
China · Deloitte Touche Tohmatsu Limited
Inventory
IT general controls not tested
The issuer used multiple IT systems to initiate process and report transactions related to certain revenue and related accounts and inventory. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by certain of these IT systems. As a result of the following deficiencies in the firm's testing of IT general controls (ITGCs) the firm's testing of these automated and IT-dependent manual controls was not sufficient. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
Deloitte Touche Tohmatsu Certified Public Accountants LLP
China · Deloitte Touche Tohmatsu Limited
Inventory
IT general controls not tested
With respect to change management: • The firm selected for testing change management controls that consisted of management's review and approval of requests for access including privileged-level access to application data files and databases. The firm did not however identify and test any controls over the appropriateness of changes made directly to the financial data within such application data files and databases. (AS 2201.39)
Both financial statement and ICFR audits · full report
AS 1105.10; AS 2201.39
Deloitte Touche Tohmatsu Certified Public Accountants LLP
China · Deloitte Touche Tohmatsu Limited
Inventory
IT general controls not tested
With respect to change management: • The firm selected for testing another change management control that consisted of the testing and approval of changes made to the structure of databases and relationships between data prior to their migration into the production environment. The firm did not perform procedures to test or test any controls over the completeness of the population of changes from which it made its selections to test this control. (AS 1105.10)
Both financial statement and ICFR audits · full report
AS 1105.10; AS 2201.39
Deloitte Touche Tohmatsu Certified Public Accountants LLP
China · Deloitte Touche Tohmatsu Limited
Inventory
IT general controls not tested
As a result of the firm's ITGC testing deficiencies discussed above the firm did not perform sufficient substantive procedures as follows: • The sample sizes the firm used in certain of its substantive procedures to test revenue and related accounts were too small to provide sufficient appropriate audit evidence because these procedures were designed based on a level of control reliance that was not supported due to the deficiencies in the firm's control testing discussed above. (AS 2301.16 .18 and .37; AS 2315.19 .23 and .23A)
Both financial statement and ICFR audits · full report
AS 2301.16; AS 2301.18; AS 2301.37; AS 2315.19; AS 2315.23; AS 2315.23A
Deloitte Touche Tohmatsu Certified Public Accountants LLP
China · Deloitte Touche Tohmatsu Limited
Inventory
IT general controls not tested
As a result of the firm's ITGC testing deficiencies discussed above the firm did not perform sufficient substantive procedures as follows: • The firm used certain system-generated data to substantively test revenue and related accounts and inventory but did not test or (as discussed above) sufficiently test controls over the accuracy and completeness of this data. (AS 1105.10)
Both financial statement and ICFR audits · full report
AS 1105.10
Deloitte Touche Tohmatsu Certified Public Accountants LLP
China · Deloitte Touche Tohmatsu Limited
Inventory
IT general controls not tested
As a result of the firm's ITGC testing deficiencies discussed above the firm did not perform sufficient substantive procedures as follows: • The firm performed substantive analytical procedures as part of its testing of certain revenue. The firm used certain system-generated data to develop its expectations but did not test or (as discussed above) sufficiently test controls over the accuracy and completeness of this data. (AS 2305.16)
Both financial statement and ICFR audits · full report
AS 2305.16
Deloitte Touche Tohmatsu Certified Public Accountants LLP
China · Deloitte Touche Tohmatsu Limited
Inventory
IT general controls not tested
The issuer used an IT system to initiate process and record certain inventory and inventory-related transactions and deployed a separate instance of the system at a majority of its warehouses. Changes to this system were first deployed to some warehouses for purposes of pilot testing after which the changes were deployed to the remaining warehouses. The following deficiency was identified: • The firm selected for testing an IT-dependent manual control over inventory that consisted of the performance of periodic cycle counts which used information generated by one of the automated controls discussed above. The accuracy and completeness of this information depended on the effective operation of this automated control. As a result of the deficiency in the firm's testing of this automated control as discussed above the firm's testing of this IT- dependent manual control was not sufficient. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
Deloitte Touche Tohmatsu Certified Public Accountants LLP
China · Deloitte Touche Tohmatsu Limited
Inventory
IT general controls not tested
The issuer used an IT system to initiate process and record certain inventory and inventory-related transactions and deployed a separate instance of the system at a majority of its warehouses. Changes to this system were first deployed to some warehouses for purposes of pilot testing after which the changes were deployed to the remaining warehouses. The following deficiency was identified: • The firm did not obtain sufficient appropriate audit evidence with regard to the issuer's inventory cycle-count procedures over certain inventory. Specifically as a result of the deficiencies in the firm's testing of the automated and IT-dependent manual controls as discussed above the firm did not obtain sufficient appropriate audit evidence that the cycle- count procedures the issuer used for this inventory were sufficiently reliable to produce results substantially the same as those that would have been obtained by a count of all items during the year. (AS 2510.11)
Both financial statement and ICFR audits · full report
AS 2510.11
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. As a result of the following deficiencies in the firm's testing of IT general controls (ITGCs) over certain of these IT systems the firm's testing of these automated and IT-dependent controls was not sufficient. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to change management: The firm selected for testing change management controls over an IT system that consisted of the documentation review testing and approval of changes in the testing/QA environment prior to their migration into production. The firm selected for testing change management controls over another IT system that consisted of the (1) approval of changes after deployment in the production environment by the business users to confirm that they were satisfied with the changes and had tested them (2) periodic review of a list of all manual changes made to the accounting database tables by users with direct database access to verify that all changes agreed to an approved change request and (3) review and approval of all direct changes made to published data. The following deficiency was identified: · For the first control the firm did not perform procedures to test or test any controls over the completeness of the population of changes from which it made its selections for testing. (AS 1105.10)
Both financial statement and ICFR audits · full report
AS 1105.10
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to change management: The firm selected for testing change management controls over an IT system that consisted of the documentation review testing and approval of changes in the testing/QA environment prior to their migration into production. The firm selected for testing change management controls over another IT system that consisted of the (1) approval of changes after deployment in the production environment by the business users to confirm that they were satisfied with the changes and had tested them (2) periodic review of a list of all manual changes made to the accounting database tables by users with direct database access to verify that all changes agreed to an approved change request and (3) review and approval of all direct changes made to published data. The following deficiency was identified: · For the second control the firm did not evaluate the effect of the control owner excluding certain information when performing the control on the control's ability to effectively prevent or detect a material misstatement. (AS 2201.42)
Both financial statement and ICFR audits · full report
AS 2201.42
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to change management: The firm selected for testing change management controls over an IT system that consisted of the documentation review testing and approval of changes in the testing/QA environment prior to their migration into production. The firm selected for testing change management controls over another IT system that consisted of the (1) approval of changes after deployment in the production environment by the business users to confirm that they were satisfied with the changes and had tested them (2) periodic review of a list of all manual changes made to the accounting database tables by users with direct database access to verify that all changes agreed to an approved change request and (3) review and approval of all direct changes made to published data. The following deficiency was identified: · For the third control the firm did not identify and test any controls over the completeness of direct data changes to the system database. (AS 2201.39)
Both financial statement and ICFR audits · full report
AS 2201.39
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · The firm selected for testing controls that consisted of the configuration of an IT system used to test inventory ('inventory testing system') to automatically calculate the assay results of each sample based on a pre-established formula and the issuer's periodic validation of those calculations. The firm used a 'test of one' approach to test these controls but did not evaluate whether the tested configurations were applied to all relevant metals and locations across the inventory testing system and an inventory subledger system to support the use of such an approach. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · The firm selected for testing a control that consisted of the configuration of the inventory subledger system to automatically calculate the metal content of each data entry based on the weight and assay results. The firm did not test all significant processing alternatives of this control for each relevant metal content type used for calculating the value of inventory. (AS 2201.42 and .44)
Both financial statement and ICFR audits · full report
AS 2201.42; AS 2201.44
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · The firm selected for testing controls that consisted of management's review and approval of the assay results in the inventory testing system. For the other control the firm did not test an aspect of the control related to the control owner's assessment of the reasonableness of the assay results for more than half of the assay results selected for testing. (AS 2201.44)
Both financial statement and ICFR audits · full report
AS 2201.44
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · The firm selected for testing a control that consisted of management's verification and approval of the recorded weight of certain inventory. The firm did not evaluate the effect of certain exceptions identified during its substantive audit procedures related to inventory on its conclusions regarding the operating effectiveness of this control. (AS 2201.B8)
Both financial statement and ICFR audits · full report
AS 2201.B8
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The issuer's IT systems had development testing/quality assurance (QA) and production environments. Changes to the IT systems were typically tested in the testing environment prior to their migration to the production environment. Changes could however be made directly in the production environment in certain situations on an emergency basis. The firm performed a review of the security settings in place over certain of the issuer's accounting systems using an unapproved custom software audit tool that included tests of privileged access password settings and client production settings. The firm also selected for testing a control over user access to the production environment of these IT systems that consisted of (1) a security setting in these systems that would not allow any direct changes to be made in the production environment by any user and (2) management's review and approval of a system-generated report that listed any changes made to the system security settings. The following deficiency was identified: · The firm did not perform any procedures to evaluate the reliability of the information produced from the custom software audit tool that was used to test the security settings of these IT systems. (AS 1105.04 and .06)
Both financial statement and ICFR audits · full report
AS 1105.4; AS 1105.6
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · To test the existence of certain inventory the firm observed the physical inventory counts at all locations and performed procedures to test the rollforward of inventory from the dates in which the inventory was physically counted to year-end using system-generated reports provided by the issuer. The firm did not perform sufficient procedures to test the existence of certain inventory. Specifically the firm's observation procedures were not suitable because the firm did not perform any substantive procedures to reconcile the quantities of certain inventory counted as reflected in the stock count records to the issuer's inventory records. Therefore these observations did not provide sufficient evidence of the quantity of inventory at these locations. (AS 2510.09)
Both financial statement and ICFR audits · full report
AS 2510.9
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · To test the existence of certain inventory the firm observed the physical inventory counts at all locations and performed procedures to test the rollforward of inventory from the dates in which the inventory was physically counted to year-end using system-generated reports provided by the issuer. The firm did not perform sufficient procedures to test the existence of certain inventory. The firm did not perform sufficient procedures to evaluate the reliability of a report used to test the rollforward of certain inventory quantities from the dates in which the inventory was physically counted to year-end because it did not evaluate the nature and cause of certain exceptions identified during its substantive audit procedures. (AS 1105.04 and .06)
Both financial statement and ICFR audits · full report
AS 1105.4; AS 1105.6
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · The firm did not perform procedures to extend its conclusions regarding the existence and valuation of inventory assay results from the interim date in which the audit procedures were performed to year-end beyond obtaining and reviewing minutes from certain laboratory quality review meetings and the accompanying presentations. (AS 2301.45)
Both financial statement and ICFR audits · full report
AS 2301.45
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The issuer's IT systems had development testing/quality assurance (QA) and production environments. Changes to the IT systems were typically tested in the testing environment prior to their migration to the production environment. Changes could however be made directly in the production environment in certain situations on an emergency basis. The firm performed a review of the security settings in place over certain of the issuer's accounting systems using an unapproved custom software audit tool that included tests of privileged access password settings and client production settings. The firm also selected for testing a control over user access to the production environment of these IT systems that consisted of (1) a security setting in these systems that would not allow any direct changes to be made in the production environment by any user and (2) management's review and approval of a system-generated report that listed any changes made to the system security settings. The following deficiency was identified: · The firm did not select for testing any instances in which the control over user access to the production environment of these IT systems operated because there were no changes made to the system security settings during the periods that were selected for testing. (AS 2201.42 and .44)
Both financial statement and ICFR audits · full report
AS 2201.42; AS 2201.44
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The issuer's IT systems had development testing/quality assurance (QA) and production environments. Changes to the IT systems were typically tested in the testing environment prior to their migration to the production environment. Changes could however be made directly in the production environment in certain situations on an emergency basis. The issuer managed the provisioning of emergency privileged access rights which allowed users with such rights to make direct changes to the production environments of certain IT systems. The firm selected for testing controls over the assignment of privileged access rights for these systems that consisted of the system administrators' review and approval of privileged access requests. The following deficiency was identified: · For one control the firm did not perform sufficient procedures to test or test any controls over the completeness of the population of privileged access requests from which it made its selection for testing because the firm limited its selection to the population of active accounts of users with privileged access rights. (AS 1105.10)
Both financial statement and ICFR audits · full report
AS 1105.10
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The issuer's IT systems had development testing/quality assurance (QA) and production environments. Changes to the IT systems were typically tested in the testing environment prior to their migration to the production environment. Changes could however be made directly in the production environment in certain situations on an emergency basis. The issuer managed the provisioning of emergency privileged access rights which allowed users with such rights to make direct changes to the production environments of certain IT systems. The firm selected for testing controls over the assignment of privileged access rights for these systems that consisted of the system administrators' review and approval of privileged access requests. The following deficiency was identified: · The number of privileged access requests selected for testing did not provide sufficient appropriate audit evidence because the firm limited its selection to one account for one month and did not perform any procedures to test the effectiveness of the control over the remaining audit period. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The issuer's IT systems had development testing/quality assurance (QA) and production environments. Changes to the IT systems were typically tested in the testing environment prior to their migration to the production environment. Changes could however be made directly in the production environment in certain situations on an emergency basis. Access to another IT system was controlled through the assignment of roles such as 'read-only ' 'edit ' and 'administrator ' to users for access to this system and related database for the accounting tables and modules. The firm selected for testing a control over user access to this system and related database that consisted of management's periodic review of a list of users with administrator roles to determine whether (1) the assignment of such roles was authorized (2) the access profiles were valid and (3) all manual changes made to the tables agreed to an approved change request. The following deficiency was identified: · The firm did not identify and test any controls over the accuracy and completeness of the reports used in the operation of the control. (AS 2201.39)
Both financial statement and ICFR audits · full report
AS 2201.39
Significant risk
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to change management: The firm selected for testing change management controls over an IT system that consisted of the documentation review testing and approval of changes in the testing/QA environment prior to their migration into production. The firm did not obtain evidence that testing was performed and reviewed by the control owners for nearly half of the system changes selected for testing. (AS 2201.42 and .44)
Both financial statement and ICFR audits · full report
AS 2201.42; AS 2201.44
Significant risk
Ernst & Young LLP
United States · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple IT systems to initiate process and record transactions related to this inventory. In its testing of controls over this account the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. The firm did not identify and test any controls that addressed the risk that unauthorized changes were made to the databases that supported certain of these systems. (AS 2201.39)
Both financial statement and ICFR audits · full report
AS 2201.39
Ernst & Young LLP
United States · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used multiple IT systems to initiate process and record transactions related to this inventory. In its testing of controls over this account the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. The firm did not identify and test any controls that addressed the risk that unauthorized changes were made to the databases that supported certain of these systems. As a result of this deficiency in the firm's testing of ITGCs the firm's testing of these automated and IT-dependent manual controls was not sufficient. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
Ernst & Young LLP
United States · Ernst & Young Global Limited
Inventory
IT general controls not tested
The issuer used an information-technology (IT) system to initiate process and record transactions related to certain revenue and inventory. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by this IT system. As a result of the following deficiencies in the firm's testing of IT general controls (ITGCs) the firm's testing of these automated and IT-dependent controls was not sufficient. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
Incorrect opinion
Frost, PLLC
United States
Inventory
IT general controls not tested
The firm selected for testing various IT-dependent manual controls that used data and reports generated by these IT systems. As a result of the deficiencies in the firm's testing of information technology general controls discussed above the firm's testing of these IT-dependent manual controls was not sufficient. (AS 2201.46)
ICFR audit only · full report
AS 2201.46
Grant Thornton LLP
United States · Grant Thornton International Limited
Inventory
IT general controls not tested
With respect to Inventory at one of the issuer's business units: The firm selected for testing a control that included the issuer's annual physical inventory count of this inventory. The following deficiencies were identified: · The firm did not evaluate whether the IT-dependent aspects of this control would be effective given the significant deficiency related to this IT system. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
Marcum LLP
United States
Inventory
IT general controls not tested
The firm's internal inspection program inspected this audit and reviewed the Inventory and Journal Entries areas but did not identify the deficiencies below. For certain business units the issuer used an IT system to initiate process and record transactions related to inventory and revenue. In its testing of controls over these accounts the firm tested various automated controls that used data generated or maintained by this IT system. The firm selected for testing a control over change management for this system but did not evaluate whether this control was designed to address all program changes. As a result of the deficiency in the firm's testing of the ITGC the firm's testing of these automated controls was not sufficient. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
Marcum LLP
United States
Inventory
IT general controls not tested
The firm's internal inspection program inspected this audit and reviewed the Inventory and Journal Entries areas but did not identify the deficiencies below. For certain inventory which was affected by the ITGC testing deficiencies discussed above the following additional deficiencies related to the firm's testing of controls were identified: · The firm selected for testing an automated control over inventory costing. The firm did not sufficiently test the design and operating effectiveness of this control as it limited its testing to only certain scenarios without identifying and evaluating all relevant configurations. (AS 2201.42 and .44)
Both financial statement and ICFR audits · full report
AS 2201.42; AS 2201.44
Marcum LLP
United States
Inventory
IT general controls not tested
The firm's internal inspection program inspected this audit and reviewed the Inventory and Journal Entries areas but did not identify the deficiencies below. For certain inventory which was affected by the ITGC testing deficiencies discussed above the following additional deficiencies related to the firm's testing of controls were identified: · The firm selected for testing an automated control over inventory costing. The firm did not identify that this control was not designed to address whether inventory was valued in accordance with the issuer's policy. (AS 2201.42)
Both financial statement and ICFR audits · full report
AS 2201.42
Marcum LLP
United States
Inventory
IT general controls not tested
The firm's internal inspection program inspected this audit and reviewed the Inventory and Journal Entries areas but did not identify the deficiencies below. For certain inventory which was affected by the ITGC testing deficiencies discussed above the following additional deficiencies related to the firm's testing of controls were identified: · The firm did not identify and test any controls over an input the issuer used in determining the cost of inventory. (AS 2201.39)
Both financial statement and ICFR audits · full report
AS 2201.39
Marcum LLP
United States
Inventory
IT general controls not tested
The firm's internal inspection program inspected this audit and reviewed the Inventory and Journal Entries areas but did not identify the deficiencies below. For certain inventory which was affected by the ITGC testing deficiencies discussed above the following additional deficiencies related to the firm's testing of controls were identified: · The issuer performed cycle counts of inventory and the issuer's cycle-count policy required inventory to be counted at specific frequencies during the year. The firm selected for testing controls that consisted of the issuer's review of cycle-count results. The firm did not test the aspects of one of these controls that addressed whether inventory counts were performed in accordance with the issuer's designated count frequency in its cycle-count policy. (AS 2201.42 and .44)
Both financial statement and ICFR audits · full report
AS 2201.42; AS 2201.44
Marcum LLP
United States
Inventory
IT general controls not tested
The firm's internal inspection program inspected this audit and reviewed the Inventory and Journal Entries areas but did not identify the deficiencies below. For certain inventory which was affected by the ITGC testing deficiencies discussed above the following additional deficiencies related to the firm's testing of controls were identified: · The issuer performed cycle counts of inventory and the issuer's cycle-count policy required inventory to be counted at specific frequencies during the year. The firm selected for testing controls that consisted of the issuer's review of cycle-count results. The firm did not identify and test any controls over the accuracy and completeness of certain information used in the operation of these controls. (AS 2201.39)
Both financial statement and ICFR audits · full report
AS 2201.39
Marcum LLP
United States
Inventory
IT general controls not tested
The firm's internal inspection program inspected this audit and reviewed the Inventory and Journal Entries areas but did not identify the deficiencies below. For certain inventory which was affected by the ITGC testing deficiencies discussed above the following additional deficiencies related to the firm's testing of controls were identified: · The firm identified exceptions in its substantive testing of the existence of inventory but did not evaluate the effect of these exceptions on the effectiveness of the issuer's cycle-count controls. (AS 2201.B8)
Both financial statement and ICFR audits · full report
AS 2201.B8
Marcum LLP
United States
Inventory
IT general controls not tested
The issuer used multiple service organizations to host and/or maintain an information-technology (IT) system that the issuer used to initiate process and record transactions related to revenue and related accounts inventory and long-lived assets at certain business units. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by this IT system. As a result of the deficiencies in the firm's testing of IT general controls (ITGCs) discussed below the firm's testing of these automated and IT-dependent manual controls was not sufficient. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
Marcum LLP
United States
Inventory
IT general controls not tested
For inventory at two business units which was affected by the ITGC audit deficiencies discussed above the following additional deficiencies were identified: · The firm selected for testing controls that consisted of the issuer's performance of physical inventory counts. The firm did not test the aspects of these controls that addressed whether an accurate and complete count had occurred. (AS 2201.42 and .44)
Both financial statement and ICFR audits · full report
AS 2201.42; AS 2201.44
Marcum LLP
United States
Inventory
IT general controls not tested
For inventory at two business units which was affected by the ITGC audit deficiencies discussed above the following additional deficiencies were identified: · The firm did not perform any procedures to evaluate the issuer's classification of certain items as inventory. (AS 2301.08)
Both financial statement and ICFR audits · full report
AS 2301.8
Moss Adams LLP
United States
Inventory
IT general controls not tested
The issuer used an information technology ('IT') application to record revenue and inventory. The firm selected for testing certain automated and IT-dependent manual controls over revenue and inventory that used information generated or maintained by this application. The accuracy and completeness of this information depended on effective IT general controls ('ITGCs'). The firm's testing of ITGCs was not sufficient because it did not identify and test a complete population of operating system changes that could potentially affect change management controls over the application. As a result the firm's testing of the automated and IT-dependent manual controls was not sufficient. (AS 2201.46)
Both financial statement and ICFR audits · full report
AS 2201.46
← PreviousPage 1 of 2Next →