← Back to Explorer
Ernst & Young Incorporated
South Africa · Ernst & Young Global Limited · Triennially Inspected
- Inspection year
- 2023
- Report date
- 21-Jun-2024
- PCAOB release
- 104-2024-113
- Audits reviewed
- 3
- Audits w/ Part I.A deficiencies
- 3
- Part I.A deficiency rate
- 100%
- Part I.A deficiencies
- 46
- Part I.B deficiencies
- 4
- Report
- View PDF ↗
Deficiencies (46)
Grouped by issuer and in the same order as the PCAOB report, so each item ties back directly to the source.
Issuer A23 deficiencies
| # | Area | Deficiency | Standard | Flags |
|---|---|---|---|---|
| 1 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. As a result of the following deficiencies in the firm's testing of IT general controls (ITGCs) over certain of these IT systems the firm's testing of these automated and IT-dependent controls was not sufficient. (AS 2201.46) Both financial statement and ICFR audits | AS 2201.46 | Significant risk |
| 2 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The issuer's IT systems had development testing/quality assurance (QA) and production environments. Changes to the IT systems were typically tested in the testing environment prior to their migration to the production environment. Changes could however be made directly in the production environment in certain situations on an emergency basis. The firm performed a review of the security settings in place over certain of the issuer's accounting systems using an unapproved custom software audit tool that included tests of privileged access password settings and client production settings. The firm also selected for testing a control over user access to the production environment of these IT systems that consisted of (1) a security setting in these systems that would not allow any direct changes to be made in the production environment by any user and (2) management's review and approval of a system-generated report that listed any changes made to the system security settings. The following deficiency was identified: · The firm did not perform any procedures to evaluate the reliability of the information produced from the custom software audit tool that was used to test the security settings of these IT systems. (AS 1105.04 and .06) Both financial statement and ICFR audits | AS 1105.4; AS 1105.6 | Significant risk |
| 3 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The issuer's IT systems had development testing/quality assurance (QA) and production environments. Changes to the IT systems were typically tested in the testing environment prior to their migration to the production environment. Changes could however be made directly in the production environment in certain situations on an emergency basis. The firm performed a review of the security settings in place over certain of the issuer's accounting systems using an unapproved custom software audit tool that included tests of privileged access password settings and client production settings. The firm also selected for testing a control over user access to the production environment of these IT systems that consisted of (1) a security setting in these systems that would not allow any direct changes to be made in the production environment by any user and (2) management's review and approval of a system-generated report that listed any changes made to the system security settings. The following deficiency was identified: · The firm did not select for testing any instances in which the control over user access to the production environment of these IT systems operated because there were no changes made to the system security settings during the periods that were selected for testing. (AS 2201.42 and .44) Both financial statement and ICFR audits | AS 2201.42; AS 2201.44 | Significant risk |
| 4 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The issuer's IT systems had development testing/quality assurance (QA) and production environments. Changes to the IT systems were typically tested in the testing environment prior to their migration to the production environment. Changes could however be made directly in the production environment in certain situations on an emergency basis. The issuer managed the provisioning of emergency privileged access rights which allowed users with such rights to make direct changes to the production environments of certain IT systems. The firm selected for testing controls over the assignment of privileged access rights for these systems that consisted of the system administrators' review and approval of privileged access requests. The following deficiency was identified: · The firm did not evaluate the specific review procedures that the control owners performed to assess the appropriateness of the provisioning and activity during the privileged access sessions to ensure that only approved activity was executed on these systems. (AS 2201.42 and .44) Both financial statement and ICFR audits | AS 2201.42; AS 2201.44 | Significant risk |
| 5 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The issuer's IT systems had development testing/quality assurance (QA) and production environments. Changes to the IT systems were typically tested in the testing environment prior to their migration to the production environment. Changes could however be made directly in the production environment in certain situations on an emergency basis. The issuer managed the provisioning of emergency privileged access rights which allowed users with such rights to make direct changes to the production environments of certain IT systems. The firm selected for testing controls over the assignment of privileged access rights for these systems that consisted of the system administrators' review and approval of privileged access requests. The following deficiency was identified: · For one control the firm did not perform sufficient procedures to test or test any controls over the completeness of the population of privileged access requests from which it made its selection for testing because the firm limited its selection to the population of active accounts of users with privileged access rights. (AS 1105.10) Both financial statement and ICFR audits | AS 1105.10 | Significant risk |
| 6 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The issuer's IT systems had development testing/quality assurance (QA) and production environments. Changes to the IT systems were typically tested in the testing environment prior to their migration to the production environment. Changes could however be made directly in the production environment in certain situations on an emergency basis. The issuer managed the provisioning of emergency privileged access rights which allowed users with such rights to make direct changes to the production environments of certain IT systems. The firm selected for testing controls over the assignment of privileged access rights for these systems that consisted of the system administrators' review and approval of privileged access requests. The following deficiency was identified: · The number of privileged access requests selected for testing did not provide sufficient appropriate audit evidence because the firm limited its selection to one account for one month and did not perform any procedures to test the effectiveness of the control over the remaining audit period. (AS 2201.46) Both financial statement and ICFR audits | AS 2201.46 | Significant risk |
| 7 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The issuer's IT systems had development testing/quality assurance (QA) and production environments. Changes to the IT systems were typically tested in the testing environment prior to their migration to the production environment. Changes could however be made directly in the production environment in certain situations on an emergency basis. Access to another IT system was controlled through the assignment of roles such as 'read-only ' 'edit ' and 'administrator ' to users for access to this system and related database for the accounting tables and modules. The firm selected for testing a control over user access to this system and related database that consisted of management's periodic review of a list of users with administrator roles to determine whether (1) the assignment of such roles was authorized (2) the access profiles were valid and (3) all manual changes made to the tables agreed to an approved change request. The following deficiency was identified: · The firm did not identify and test any controls over the accuracy and completeness of the reports used in the operation of the control. (AS 2201.39) Both financial statement and ICFR audits | AS 2201.39 | Significant risk |
| 8 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The issuer's IT systems had development testing/quality assurance (QA) and production environments. Changes to the IT systems were typically tested in the testing environment prior to their migration to the production environment. Changes could however be made directly in the production environment in certain situations on an emergency basis. Access to another IT system was controlled through the assignment of roles such as 'read-only ' 'edit ' and 'administrator ' to users for access to this system and related database for the accounting tables and modules. The firm selected for testing a control over user access to this system and related database that consisted of management's periodic review of a list of users with administrator roles to determine whether (1) the assignment of such roles was authorized (2) the access profiles were valid and (3) all manual changes made to the tables agreed to an approved change request. The following deficiency was identified: · The firm did not evaluate the specific review procedures that the control owners performed to determine whether access was appropriate and that the roles were adequately restricted or granted to users to prevent unauthorized and inappropriate access to this system and related database. (AS 2201.42 and .44) Both financial statement and ICFR audits | AS 2201.42; AS 2201.44 | Significant risk |
| 9 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to change management: The firm selected for testing change management controls over an IT system that consisted of the documentation review testing and approval of changes in the testing/QA environment prior to their migration into production. The firm did not obtain evidence that testing was performed and reviewed by the control owners for nearly half of the system changes selected for testing. (AS 2201.42 and .44) Both financial statement and ICFR audits | AS 2201.42; AS 2201.44 | Significant risk |
| 10 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to change management: The firm selected for testing change management controls over an IT system that consisted of the documentation review testing and approval of changes in the testing/QA environment prior to their migration into production. The firm selected for testing change management controls over another IT system that consisted of the (1) approval of changes after deployment in the production environment by the business users to confirm that they were satisfied with the changes and had tested them (2) periodic review of a list of all manual changes made to the accounting database tables by users with direct database access to verify that all changes agreed to an approved change request and (3) review and approval of all direct changes made to published data. The following deficiency was identified: · For the first control the firm did not perform procedures to test or test any controls over the completeness of the population of changes from which it made its selections for testing. (AS 1105.10) Both financial statement and ICFR audits | AS 1105.10 | Significant risk |
| 11 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to change management: The firm selected for testing change management controls over an IT system that consisted of the documentation review testing and approval of changes in the testing/QA environment prior to their migration into production. The firm selected for testing change management controls over another IT system that consisted of the (1) approval of changes after deployment in the production environment by the business users to confirm that they were satisfied with the changes and had tested them (2) periodic review of a list of all manual changes made to the accounting database tables by users with direct database access to verify that all changes agreed to an approved change request and (3) review and approval of all direct changes made to published data. The following deficiency was identified: · For the first control the firm did not evaluate the specific review procedures that the control owner or business users performed to validate and approve the appropriateness of the migrated changes to the production environment. (AS 2201.42 and .44) Both financial statement and ICFR audits | AS 2201.42; AS 2201.44 | Significant risk |
| 12 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to change management: The firm selected for testing change management controls over an IT system that consisted of the documentation review testing and approval of changes in the testing/QA environment prior to their migration into production. The firm selected for testing change management controls over another IT system that consisted of the (1) approval of changes after deployment in the production environment by the business users to confirm that they were satisfied with the changes and had tested them (2) periodic review of a list of all manual changes made to the accounting database tables by users with direct database access to verify that all changes agreed to an approved change request and (3) review and approval of all direct changes made to published data. The following deficiency was identified: · For the second control the firm did not evaluate the effect of the control owner excluding certain information when performing the control on the control's ability to effectively prevent or detect a material misstatement. (AS 2201.42) Both financial statement and ICFR audits | AS 2201.42 | Significant risk |
| 13 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to change management: The firm selected for testing change management controls over an IT system that consisted of the documentation review testing and approval of changes in the testing/QA environment prior to their migration into production. The firm selected for testing change management controls over another IT system that consisted of the (1) approval of changes after deployment in the production environment by the business users to confirm that they were satisfied with the changes and had tested them (2) periodic review of a list of all manual changes made to the accounting database tables by users with direct database access to verify that all changes agreed to an approved change request and (3) review and approval of all direct changes made to published data. The following deficiency was identified: · For the second and third controls the firm did not evaluate the specific review procedures that the control owners performed to validate the appropriateness of direct data changes to the system database. (AS 2201.42 and .44) Both financial statement and ICFR audits | AS 2201.42; AS 2201.44 | Significant risk |
| 14 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to change management: The firm selected for testing change management controls over an IT system that consisted of the documentation review testing and approval of changes in the testing/QA environment prior to their migration into production. The firm selected for testing change management controls over another IT system that consisted of the (1) approval of changes after deployment in the production environment by the business users to confirm that they were satisfied with the changes and had tested them (2) periodic review of a list of all manual changes made to the accounting database tables by users with direct database access to verify that all changes agreed to an approved change request and (3) review and approval of all direct changes made to published data. The following deficiency was identified: · For the third control the firm did not identify and test any controls over the completeness of direct data changes to the system database. (AS 2201.39) Both financial statement and ICFR audits | AS 2201.39 | Significant risk |
| 15 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · The firm selected for testing controls that consisted of the configuration of an IT system used to test inventory ('inventory testing system') to automatically calculate the assay results of each sample based on a pre-established formula and the issuer's periodic validation of those calculations. The firm used a 'test of one' approach to test these controls but did not evaluate whether the tested configurations were applied to all relevant metals and locations across the inventory testing system and an inventory subledger system to support the use of such an approach. (AS 2201.46) Both financial statement and ICFR audits | AS 2201.46 | Significant risk |
| 16 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · The firm selected for testing a control that consisted of the configuration of the inventory subledger system to automatically calculate the metal content of each data entry based on the weight and assay results. The firm did not test all significant processing alternatives of this control for each relevant metal content type used for calculating the value of inventory. (AS 2201.42 and .44) Both financial statement and ICFR audits | AS 2201.42; AS 2201.44 | Significant risk |
| 17 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · The firm selected for testing controls that consisted of management's review and approval of the assay results in the inventory testing system. For one of these controls the firm did not evaluate the specific review procedures that the control owner performed to assess the accuracy of the assay results. (AS 2201.42 and .44) Both financial statement and ICFR audits | AS 2201.42; AS 2201.44 | Significant risk |
| 18 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · The firm selected for testing controls that consisted of management's review and approval of the assay results in the inventory testing system. For the other control the firm did not test an aspect of the control related to the control owner's assessment of the reasonableness of the assay results for more than half of the assay results selected for testing. (AS 2201.44) Both financial statement and ICFR audits | AS 2201.44 | Significant risk |
| 19 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · The firm selected for testing a control that consisted of management's verification and approval of the recorded weight of certain inventory. The firm did not evaluate the effect of certain exceptions identified during its substantive audit procedures related to inventory on its conclusions regarding the operating effectiveness of this control. (AS 2201.B8) Both financial statement and ICFR audits | AS 2201.B8 | Significant risk |
| 20 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · To test the existence of certain inventory the firm observed the physical inventory counts at all locations and performed procedures to test the rollforward of inventory from the dates in which the inventory was physically counted to year-end using system-generated reports provided by the issuer. The firm did not perform sufficient procedures to test the existence of certain inventory. Specifically the firm's observation procedures were not suitable because the firm did not perform any substantive procedures to reconcile the quantities of certain inventory counted as reflected in the stock count records to the issuer's inventory records. Therefore these observations did not provide sufficient evidence of the quantity of inventory at these locations. (AS 2510.09) Both financial statement and ICFR audits | AS 2510.9 | Significant risk |
| 21 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · To test the existence of certain inventory the firm observed the physical inventory counts at all locations and performed procedures to test the rollforward of inventory from the dates in which the inventory was physically counted to year-end using system-generated reports provided by the issuer. The firm did not perform sufficient procedures to test the existence of certain inventory. The firm did not perform sufficient procedures to evaluate the reliability of a report used to test the rollforward of certain inventory quantities from the dates in which the inventory was physically counted to year-end because it did not evaluate the nature and cause of certain exceptions identified during its substantive audit procedures. (AS 1105.04 and .06) Both financial statement and ICFR audits | AS 1105.4; AS 1105.6 | Significant risk |
| 22 | Inventory | The issuer used multiple information-technology (IT) systems to initiate process and record inventory and inventory-related transactions. In its testing of controls over inventory the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to other tests of controls and substantive procedures related to inventory certain of which were affected by the audit deficiencies discussed above related to user access and change management the following additional deficiency was identified: · The firm did not perform procedures to extend its conclusions regarding the existence and valuation of inventory assay results from the interim date in which the audit procedures were performed to year-end beyond obtaining and reviewing minutes from certain laboratory quality review meetings and the accompanying presentations. (AS 2301.45) Both financial statement and ICFR audits | AS 2301.45 | Significant risk |
| 23 | Revenue | The firm's approach for substantively testing revenue consisted primarily of performing a software-assisted analysis to test the relationships among revenue accounts receivable and cash receipts. The reliability of the audit evidence obtained from this analysis was dependent upon the firm's testing of cash receipts data underlying the analysis. To test this data the firm agreed a sample of cash receipts to bank statements customer invoices and other documents such as packing lists delivery notes and transfer requests. The firm identified that certain cash receipts selected for testing did not relate to revenue and a corresponding receivable. The firm did not perform sufficient procedures to evaluate whether the cash receipts data was appropriate for use in the analysis because it did not evaluate the implications of these unrelated cash receipts on the sufficiency and appropriateness of the data. (AS 1105.10) Both financial statement and ICFR audits | AS 1105.10 |
Issuer B17 deficiencies
| # | Area | Deficiency | Standard | Flags |
|---|---|---|---|---|
| 1 | Accounts Receivable | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. As a result of the following deficiencies in the firm's testing of ITGCs over certain of these IT systems the firm's testing of these automated and IT-dependent controls was not sufficient. (AS 2201.46) Both financial statement and ICFR audits | AS 2201.46 | |
| 2 | Accounts Receivable | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The firm performed a review of the security settings in place over the issuer's accounting system using an unapproved custom software audit tool that included tests of privileged access password settings and client production settings. The firm identified certain exceptions involving the segregation of duties of two users who had administrator access to the system which enabled them to migrate changes into production. The firm also identified that the system's production environment had been opened multiple times during the year by these two users. The following deficiency was identified: · The firm did not determine the effect of the exception identified on the operating effectiveness of the user access controls over the system. (AS 2201.48) Both financial statement and ICFR audits | AS 2201.48 | |
| 3 | Accounts Receivable | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The firm performed a review of the security settings in place over the issuer's accounting system using an unapproved custom software audit tool that included tests of privileged access password settings and client production settings. The firm identified certain exceptions involving the segregation of duties of two users who had administrator access to the system which enabled them to migrate changes into production. The firm also identified that the system's production environment had been opened multiple times during the year by these two users. The following deficiency was identified: · The firm did not identify and test any controls over the appropriateness of the activity that the two privileged access users performed when opening the system's production environment. (AS 2201.39) Both financial statement and ICFR audits | AS 2201.39 | |
| 4 | Accounts Receivable | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The firm performed a review of the security settings in place over the issuer's accounting system using an unapproved custom software audit tool that included tests of privileged access password settings and client production settings. The firm identified certain exceptions involving the segregation of duties of two users who had administrator access to the system which enabled them to migrate changes into production. The firm also identified that the system's production environment had been opened multiple times during the year by these two users. The following deficiency was identified: · The firm did not perform any procedures to evaluate the reliability of the information produced from the custom software audit tool that was used to test the security settings of this system. (AS 1105.04 and .06) Both financial statement and ICFR audits | AS 1105.4; AS 1105.6 | |
| 5 | Accounts Receivable | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The firm selected for testing controls over the assignment of privileged access rights to certain other IT systems that consisted of management's review and approval of privileged access requests. The following deficiency was identified: · The firm did not identify and test any controls over the accuracy and completeness of the reports used in the operation of these controls. (AS 2201.39) Both financial statement and ICFR audits | AS 2201.39 | |
| 6 | Accounts Receivable | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to user access: The firm selected for testing controls over the assignment of privileged access rights to certain other IT systems that consisted of management's review and approval of privileged access requests. The following deficiency was identified: · The firm did not evaluate the specific review procedures that the control owners performed to determine whether access was appropriate and that the roles were adequately restricted or granted to users to prevent unauthorized and inappropriate access to these systems. (AS 2201.42 and .44) Both financial statement and ICFR audits | AS 2201.42; AS 2201.44 | |
| 7 | Accounts Receivable | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to change management: The firm selected for testing change management controls over certain IT systems that consisted of (1) the authorization of changes prior to development (2) testing and approval of changes prior to their migration into production and (3) the establishment of segregation of duties and the restriction of users with the ability to develop and migrate changes to production to authorized personnel. The firm did not perform procedures to test or test any controls over the completeness of the population of changes from which it made its selections for testing. (AS 1105.10) Both financial statement and ICFR audits | AS 1105.10 | |
| 8 | Revenue | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to Revenue which was affected by the audit deficiencies related to user access and change management the following additional deficiency was identified: · The firm selected for testing a control that consisted of the issuer's review of price changes made in the accounting system as reflected in a customized system-generated report to determine whether they were properly approved. The firm did not identify and test any controls over the accuracy and completeness of the report used in the operation of the control. (AS 2201.39) Both financial statement and ICFR audits | AS 2201.39 | |
| 9 | Revenue | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to Revenue which was affected by the audit deficiencies related to user access and change management the following additional deficiency was identified: · The firm selected for testing a control that consisted of the issuer's review of price changes made in the accounting system as reflected in a customized system-generated report to determine whether they were properly approved. The firm did not test an aspect of the control related to the issuer's review of certain price changes. (AS 2201.42 and .44) Both financial statement and ICFR audits | AS 2201.42; AS 2201.44 | |
| 10 | Revenue | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to Revenue which was affected by the audit deficiencies related to user access and change management the following additional deficiency was identified: · The firm selected for testing an automated control that consisted of the configuration of the issuer's accounting system to automatically update invoiced sales prices to reflect those within the system's price list and used a 'test of one' approach to test the control. The firm did not perform sufficient procedures to support the use of such an approach because it did not test the configuration or programming of the control during the audit period or perform other procedures that would have provided sufficient appropriate audit evidence that the control was designed and operating effectively. (AS 2201.46) Both financial statement and ICFR audits | AS 2201.46 | |
| 11 | Revenue | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to Revenue which was affected by the audit deficiencies related to user access and change management the following additional deficiency was identified: · The firm selected for testing controls that consisted of management's review and approval of printed sales orders. The firm did not perform procedures to test or test any controls over the completeness of the population of certain sales orders from which it made its selections for testing. (AS 1105.10) Both financial statement and ICFR audits | AS 1105.10 | |
| 12 | Revenue | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to Revenue which was affected by the audit deficiencies related to user access and change management the following additional deficiency was identified: · The firm selected for testing controls that consisted of the reconciliation of revenue and inventory sold and management's review and approval of the reconciliations. The firm did not identify and test any controls over the accuracy and completeness of the reports used in the operation of these controls. (AS 2201.39) Both financial statement and ICFR audits | AS 2201.39 | |
| 13 | Revenue | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to Revenue which was affected by the audit deficiencies related to user access and change management the following additional deficiency was identified: · The firm selected for testing an automated control that consisted of automatic interfaces between the issuer's accounting system and certain of its production and dispatch related systems and used a 'test of one' approach to test the control. The firm did not perform sufficient procedures to support the use of such an approach because it did not test the interface configuration or programming of the control or perform procedures to test the design of the control as it relates to each relevant interface. (AS 2201.46) Both financial statement and ICFR audits | AS 2201.46 | |
| 14 | Revenue | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. The issuer used multiple IT systems to initiate process and record transactions related to revenue accounts receivable and long-lived assets. In its testing of controls over these accounts the firm tested various automated and IT-dependent manual controls that used data and reports generated or maintained by these IT systems. With respect to Revenue which was affected by the audit deficiencies related to user access and change management the following additional deficiency was identified: · The firm's approach for substantively testing revenue consisted primarily of performing a software-assisted analysis to test the relationships among revenue accounts receivable and cash receipts. The reliability of the audit evidence obtained from this analysis was dependent upon the firm's testing of cash receipts data underlying the analysis. To test this data the firm reconciled certain cash activity used in the analysis to the respective cash accounts in the issuer's general ledger and agreed a sample of cash receipts to bank statements and customer remittance advices. The firm did not perform sufficient procedures to evaluate whether the cash receipts data was appropriate for use in the analysis because it (1) did not reconcile all cash activity used in the analysis to the respective cash accounts in the issuer's general ledger (2) made the majority of its cash receipts selections from the population of trade accounts receivable and unallocated receivable journal entries rather than the cash journal entries used in the analysis and (3) did not evaluate whether certain cash receipts selected for testing related to revenue and were appropriately included in the cash data underlying the analysis. (AS 1105.10) Both financial statement and ICFR audits | AS 1105.10 | |
| 15 | Accounts Receivable | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. With respect to Accounts Receivable which was affected by the audit deficiencies related to user access and change management the following additional deficiency was identified: · The firm did not identify and test any controls over the posting of cash receipts to customer accounts and invoices. (AS 2201.39) Both financial statement and ICFR audits | AS 2201.39 | |
| 16 | Accounts Receivable | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. With respect to Accounts Receivable which was affected by the audit deficiencies related to user access and change management the following additional deficiency was identified: · The firm selected for testing a control that consisted of the issuer's review and analysis of accounts receivable as reflected in a customized system-generated accounts receivable aging report. The firm did not evaluate whether the automated aspect of this control which consisted of the system's aging of customer account balances was configurable and programmable and if so perform procedures to test the configuration and programming of the control. (AS 2201.42) Both financial statement and ICFR audits | AS 2201.42 | |
| 17 | Accounts Receivable | The firm's internal inspection program had inspected this audit and reviewed certain of these areas but did not identify certain of the deficiencies below. With respect to Accounts Receivable which was affected by the audit deficiencies related to user access and change management the following additional deficiency was identified: · The firm selected for testing a control that consisted of the issuer's review and analysis of accounts receivable as reflected in a customized system-generated accounts receivable aging report. The firm did not perform procedures to test the accuracy and completeness of the reports and calculations produced by the system to determine whether the automated aspect of the control operated as it was designed. (AS 2201.44) Both financial statement and ICFR audits | AS 2201.44 |
Issuer C6 deficiencies
| # | Area | Deficiency | Standard | Flags |
|---|---|---|---|---|
| 1 | Accounts Receivable | The following deficiency was identified: · The firm selected for testing a control that consisted of the configuration of the issuer's accounting system to automatically apply cash receipts to specific invoices and the manual investigation of outstanding items and unapplied cash receipts in the cash in-transit accounts. The firm did not test the automated aspect of this control related to the automatic application of cash receipts to specific invoices. (AS 2201.42 and .44) ICFR audit only | AS 2201.42; AS 2201.44 | |
| 2 | Accounts Receivable | The following deficiency was identified: · The firm selected for testing an automated control that consisted of the configuration of the issuer's accounting system to automatically record sales transactions based on revenue recognition triggers contained in the sales order and customer master files. The firm did not test whether the system accurately retrieved information from customer master files that was associated with the recorded sales. (AS 2201.42 and .44) ICFR audit only | AS 2201.42; AS 2201.44 | |
| 3 | Accounts Receivable | The following deficiency was identified: · The firm selected for testing a control that consisted of the reconciliation of goods invoiced to goods shipped and delivered. The firm did not perform procedures to test the design and operating effectiveness of this control. (AS 2201.42 and .44) ICFR audit only | AS 2201.42; AS 2201.44 | |
| 4 | Accounts Receivable | The following deficiency was identified: · The firm selected for testing a control that consisted of the issuer's verification of the shipment and delivery dates recorded in the accounting system to determine whether the transfer of title and recognition of revenue was based on accurate information. The firm did not identify and test any controls over the completeness of a customized system-generated report used in the operation of this control. (AS 2201.39) ICFR audit only | AS 2201.39 | |
| 5 | Accounts Receivable | The following deficiency was identified: · The firm selected for testing controls that consisted of the issuer's (1) use of revenue recognition triggers to consistently recognize revenue for each billing type (2) matching of sales invoices to documents supporting proof of delivery and transfer of title and (3) verification of the shipment and delivery dates recorded in the accounting system to determine whether the transfer of title and recognition of revenue was based on accurate information. The firm did not perform procedures to test or test any controls over the completeness of the population of a customized system-generated report from which it made its selections for testing. (AS 1105.10) ICFR audit only | AS 1105.10 | |
| 6 | Long-Lived Assets | The firm selected for testing a control that consisted of the completion of impairment indicator surveys and the issuer's review and approval of impairment calculations and related testing. The firm did not evaluate the specific review procedures that the control owner performed to determine the accuracy and completeness of the consolidated impairment indicator questionnaires. (AS 2201.42 and .44) ICFR audit only | AS 2201.42; AS 2201.44 |