- Inspection year
- 2022
- Report date
- 25-May-2023
- PCAOB release
- 104-2023-078
- Audits reviewed
- 3
- Audits w/ Part I.A deficiencies
- 2
- Part I.A deficiency rate
- 67%
- Part I.A deficiencies
- 7
- Part I.B deficiencies
- 4
- Report
- View PDF ↗
Deficiencies (7)
Grouped by issuer and in the same order as the PCAOB report, so each item ties back directly to the source.
Issuer A6 deficiencies
| # | Area | Deficiency | Standard | Flags |
|---|---|---|---|---|
| 1 | Accruals | The issuer used multiple information technology ('IT') systems and applications to process and record transactions including those related to revenue and certain accruals. In its testing over these accounts at two of the issuer's components the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by the IT systems that depended on effective IT general controls (ITGCs). As a result of deficiencies in the firm's testing of ITGCs at these components the firm's testing of these automated and IT-dependent manual controls was not sufficient. (AS 2201.46) Both financial statement and ICFR audits | AS 2201.46 | |
| 2 | Accruals | The issuer used multiple information technology ('IT') systems and applications to process and record transactions including those related to revenue and certain accruals. In its testing over these accounts at two of the issuer's components the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by the IT systems that depended on effective IT general controls (ITGCs). The firm selected for testing a control over developer access in which changes to certain applications were managed by corresponding change management tools. The firm did not evaluate whether (1) changes to the applications were managed only by each application's respective change management tool and (2) access to a user ID with the ability to migrate changes within the system was given to certain users that were not developers. Further the firm did not test whether other user groups or profiles within one change management tool had the ability to migrate changes within the systems managed by that tool. (AS 2201.42 and .44) Both financial statement and ICFR audits | AS 2201.42; AS 2201.44 | |
| 3 | Accruals | The issuer used multiple information technology ('IT') systems and applications to process and record transactions including those related to revenue and certain accruals. In its testing over these accounts at two of the issuer's components the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by the IT systems that depended on effective IT general controls (ITGCs). The firm selected for testing various change management controls over these IT systems. The firm did not perform sufficient procedures to test the completeness of the population of changes from which it made its selections because the firm's procedures were limited to (1) observing the parameters used to extract data from the ticketing systems and (2) obtaining a usage report of shared user IDs with the ability to migrate changes from a tool without evaluating which applications were managed by the tool. (AS 1105.10) Both financial statement and ICFR audits | AS 1105.10 | |
| 4 | Accruals | The issuer used multiple information technology ('IT') systems and applications to process and record transactions including those related to revenue and certain accruals. In its testing over these accounts at two of the issuer's components the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by the IT systems that depended on effective IT general controls (ITGCs). The issuer identified an incident of unauthorized access to its IT systems and as a result determined that certain of its ITGCs were deficient. The firm did not evaluate the severity of these control deficiencies to determine whether the deficiencies in combination with other deficiencies constituted a material weakness. (AS 2201.62) Both financial statement and ICFR audits | AS 2201.62 | |
| 5 | Accruals | The firm did not perform any substantive procedures to test or sufficiently test controls over the accuracy and completeness of data produced by these IT systems that it used to test certain accruals. (AS 1105.10) Both financial statement and ICFR audits | AS 1105.10 | |
| 6 | Journal Entries | The firm selected for testing manual journal entries meeting certain fraud criteria. The firm did not perform sufficient procedures to test these journal entries because it did not examine the underlying support for the entries. (AS 2401.61) Both financial statement and ICFR audits | AS 2401.61 |
Issuer B1 deficiency
| # | Area | Deficiency | Standard | Flags |
|---|---|---|---|---|
| 1 | Inventory | The firm did not identify and test any controls over the calculation of inventory cost. (AS 2201.39) ICFR audit only | AS 2201.39 |