What's changed: Initial version
6.2Reporting to management and the audit opinion
Covers how to choose the reporting destination (management, or a superior who can maintain independence), the problem of reporting directly to the head of the audited department, the difference between the audit opinion of an assurance engagement (a conclusion giving a level of assurance) and the proposals of an advisory engagement (improvement proposals as the main aim), and the principle that an opinion is expressed within the scope of the audit evidence obtained.
An audit report's independence and effectiveness are determined by "to whom" it is reported. A systems auditor must judge how to report results to a position independent of the audit target (management, an audit committee, and so on) and deliver them to a party that can decide on remediation as an organization. Along with this, whether the audit is assurance-type (expressing a level of assurance) or advisory-type (improvement proposals as the main aim) changes whether the report gives an "opinion" or "proposals." And the opinion expressed must not exceed the scope of the audit evidence one was able to obtain—vouching for an area where evidence is insufficient is not audit but irresponsible assurance.
6.2.1Independence of the reporting destination
- The reporting destination is a superior independent of the audit target: results are reported to a position that can direct and decide on remediation as an organization (management, the board, an audit committee, and so on), which ensures the fix is put into action. If reporting is completed only within the audited department, inconvenient findings risk being buried, and the audit loses effectiveness.
- The problem of reporting directly and solely to the head of the audited department: settling for reporting a serious deficiency only to the head of the audited department—who is a party to the deficiency—is problematic for independence and objectivity, because that party has an incentive not to escalate findings unfavorable to their own department. Sharing results with the field for fact-checking is itself appropriate, but secure a path that delivers the final report to independent management or an audit committee.
6.2.2The assurance opinion and advisory proposals
- The opinion of an assurance (assurance-type) audit: a type in which, against certain criteria, the auditor expresses an "opinion (conclusion)" and gives a level of assurance on whether controls are effective. Users (management, external stakeholders) rely on that assurance opinion in their decisions. Therefore the assurance opinion must be backed by sufficient and appropriate audit evidence, and where evidence is lacking, the opinion is qualified or not expressed.
- The proposals of an advisory (consulting-type) audit: a type whose main aim is the improvement proposals themselves, in which the auditor advises on remediation or the direction of enhancement for deficiencies. Expressing an assurance opinion is not its main aim. Even so, the evaluation underlying the advice is fact-based, and one takes care to separate roles so as not to become so deeply involved in the advice as to impair the independence of a later assurance audit (do not assure a mechanism one helped design).
- Express opinions within the scope of the audit evidence: the auditor states an opinion only about the scope they were able to verify. Expressing "no problems" even for areas that could not be verified due to time or constraints is over-assurance not grounded in evidence, and is wrong. Clearly stating the verification scope, premises, and constraints (scope limitations) in the report, thereby clarifying the scope of assurance, prevents user misunderstanding and protects the auditor's scope of responsibility.
Most-tested points: "report to management/an audit committee independent of the audit target (do not stop at the party who is the audited department head)," "assurance-type expresses an opinion (conclusion) giving a level of assurance / advisory-type has improvement proposals as its main aim," "express opinions backed by sufficient and appropriate audit evidence; qualify or withhold for what cannot be verified," and "state the verification scope and premises to clarify the scope of assurance." Questions test the distinction of not assuring beyond the scope of evidence.
6.2.3Judgment in reporting destination and expressing opinion
Suppose a systems auditor conducts an assurance-type audit of the internal controls of an accounting system and finds several serious control deficiencies. Two judgments arise here. First, the reporting destination. The deficiencies found stemmed from the accounting department's operations, but reporting only to the head of the accounting department and calling it done is inappropriate for independence and objectivity—the department head, as a party to it, may have an incentive not to escalate findings unfavorable to their own department, risking the burial of serious deficiencies. Sharing results with the accounting department for fact-checking is itself appropriate, but the final audit opinion secures a path to independent management (and an audit committee) so remediation can be decided as an organization. Second, expressing the opinion. Because this is assurance-type, the auditor is in the position to express an opinion (conclusion) and give a level of assurance on "whether the controls are effective," but that opinion must not exceed the scope of the audit evidence obtained. If, say, time constraints prevented sufficient verification of a certain processing area (e.g., overnight-batch error handling), assuring "no problems" even for that unverified area is over-assurance not grounded in evidence and is wrong. Correctly, after stating an opinion about the verified scope, the verification scope, premises, and constraints (that this area is out of verification scope) are stated in the report, so users do not misunderstand the scope of assurance. Had this audit been advisory-type, the auditor's main aim would not be expressing an assurance opinion but improvement proposals, advising on remediation and the direction of control enhancement—yet even then, roles are separated so as not to become so involved in the advice as to impair the independence of a later assurance audit. Reporting to management independent of the audit target and expressing the opinion within the scope of evidence with a clear scope of assurance is the judgment of reporting to management and expressing an opinion.
| Aspect | Assurance-type | Advisory-type |
|---|---|---|
| Main aim | Express an opinion and give assurance | The improvement proposals themselves |
| Deliverable | Assurance opinion (backed by evidence) | Advice and proposals |
| Independence caution | Express within evidence; qualify/withhold | Do not get too involved in the advice |
Trap: "Even for a serious deficiency, reporting only to the head of the audited department—the party involved—is enough" is wrong—that party has an incentive not to escalate unfavorable findings, and without securing a path to management/an audit committee independent of the audit target, it gets buried. "In assurance-type, one should assure the whole as no-problem, including areas that could not be verified" is also wrong—the opinion must not be expressed beyond the scope of the audit evidence obtained, and vouching for unverified areas is over-assurance. "Even in an advisory audit, the auditor's main aim is expressing an assurance opinion" is wrong too—advisory-type has improvement proposals as its main aim.
6.2.4Section summary
- The reporting destination is management/an audit committee independent of the audit target (do not stop at the party who is the audited department head; prevent burial)
- Assurance-type expresses an opinion (conclusion) and gives assurance / advisory-type has improvement proposals as its main aim—their roles differ
- Express the opinion within the scope of sufficient and appropriate audit evidence; qualify/withhold for unverifiable areas and state the scope and premises to clarify the scope of assurance
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. A systems auditor finds a serious internal-control deficiency stemming from the accounting department's operations. Which reporting destination for the audit results is most appropriate?
Q2. In an assurance-type systems audit, time constraints prevented sufficient verification of part of the processing (overnight-batch error handling). Which way of expressing the audit opinion is most appropriate?
Q3. An audit is commissioned with the main aim not of assuring a conclusion on control effectiveness but of proposing improvements to the business process. Which characterization of this audit is most appropriate?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

