top of page
Search

PCAOB Audit Tradecraft: Why Technical Audit Standards Alone Do Not Make a Great External Auditor

Build the Judgment, Skepticism, Risk Assessment and Audit Skills Needed to Perform High-Quality PCAOB Audits


External auditors spend enormous amounts of time learning auditing standards.


That knowledge is essential—but it is not enough.


A technically knowledgeable auditor can still perform a poor audit.


Why?


Because high-quality auditing requires something beyond knowing what a PCAOB auditing standard says. The auditor must know how to apply that standard when confronted with incomplete information, management judgment, conflicting evidence, time pressure, difficult personalities and ambiguous facts.


That combination of knowledge, judgment and practical skill is audit tradecraft.

Corporate Compliance Seminars developed PCAOB Audit Tradecraft for the External Auditor to help external auditors develop these practical capabilities while strengthening their understanding of PCAOB auditing standards, Sarbanes-Oxley, risk assessment, COSO, Internal Control over Financial Reporting (ICFR), audit documentation and PCAOB inspection issues. The two-day program provides 12 NASBA-approved CPE credits.



What Is Audit Tradecraft?

Think about two auditors who have read exactly the same PCAOB standards.


Both know the requirements.


Both understand the firm's methodology.


Both have access to the same audit software.


Yet one consistently identifies important issues that the other misses.


What makes the difference?


The stronger auditor may be better at:

  • Asking questions

  • Listening

  • Recognizing inconsistencies

  • Following an audit trail

  • Understanding management motivations

  • Challenging assumptions

  • Connecting apparently unrelated information

  • Recognizing unusual transactions

  • Determining when evidence is insufficient

  • Knowing when to keep digging

  • Communicating difficult conclusions


Those abilities constitute much of what we call audit tradecraft.


They are particularly important in PCAOB engagements because the auditor is ultimately responsible for obtaining sufficient appropriate evidence to support the audit opinion. PCAOB AS 1105 makes clear that audit evidence includes information that both supports and contradicts management's assertions.


That means the external auditor's job is not to prove management right.


It is to determine what the evidence demonstrates.


Professional Skepticism Is a Behavior, Not a Slogan

Almost every auditor has heard the phrase professional skepticism.


The harder question is:

What does professional skepticism actually look like at 3:30 in the afternoon during an audit walkthrough?


PCAOB Auditing Standard 1000 describes professional skepticism as including a questioning mind and critical assessment of audit evidence. Among other things, auditors must objectively evaluate corroborating and contradictory information, remain alert to potential misstatements from fraud or error, avoid being satisfied with less-than-persuasive evidence, and consider potential management and auditor bias.


That translates into behaviors.


Management says:

"We always review that report."

The tradecraft question becomes: Show me.


Management says:

"That was an isolated transaction."

The tradecraft question becomes: How do we know?


Management says:

"There aren't any other exceptions."

The tradecraft question becomes: What evidence supports that conclusion?


Management says:

"We've always done it this way."

The tradecraft question becomes: Why does that make the control effective?


The skeptical auditor does not assume management is dishonest.


But the skeptical auditor does not assume management is correct either.


The External Auditor Must Learn to Follow the Evidence

Good auditors develop hypotheses.


Great auditors are willing to abandon them.


Suppose an auditor begins testing expecting a control to operate effectively.


The first five samples support that expectation.


The sixth does not.


A weak auditor may unconsciously look for a reason to dismiss the exception.


A strong auditor asks:


What is this exception trying to tell me?


Perhaps it is:

  • A documentation failure

  • An isolated human error

  • A misunderstanding of the control

  • Evidence the control operates differently than described

  • Evidence the population is incomplete

  • A management override

  • A broader control deficiency

  • A potential fraud indicator


PCAOB auditing standards specifically require additional work when evidence from different sources is inconsistent or when the auditor doubts its reliability.


Audit tradecraft means recognizing that an inconsistency is not an inconvenience.


It may be the most important evidence in the workpaper.


Risk Assessment Is Where Good Audits Begin

Poor audit execution frequently starts with poor planning.


If the auditor misunderstands the business, process, incentives, controls or risks, the resulting audit procedures may be perfectly executed—and still address the wrong risks.


The CCS course therefore devotes substantial attention to audit planning and risk management, including risk assessment from the external auditor's perspective.


The auditor should understand:

  • What could materially go wrong?

  • Why could it go wrong?

  • Where could it occur?

  • Who could cause it?

  • What incentives exist?

  • Which controls should prevent or detect it?

  • Can management override those controls?

  • What evidence would indicate that the control failed?

  • What evidence would contradict management's explanation?


PCAOB Auditing Standard 2301 reinforces the connection between assessed risks and the auditor's response. When circumstances warrant, auditors may need more persuasive evidence, independent corroboration or modified procedures.


The objective is not more auditing.


It is better-targeted auditing.


Understanding the Client's Business Is Tradecraft

Auditors cannot properly assess risk if they do not understand how the organization actually operates.


That requires getting beyond policies and procedure manuals.


The auditor needs to understand:


How does the company make money?


Where does cash enter and leave the organization?


What estimates materially affect financial reporting?


Where does management exercise significant judgment?


What performance targets influence employee behavior?


Where could management override normal controls?


Which systems generate the information used in financial reporting?


Which third parties are important to the process?


A walkthrough should therefore be an investigation into how the process actually works—not a ceremonial confirmation of a process narrative prepared last year.


Learn to Ask Better Questions

External auditors obtain enormous amounts of evidence through conversations.


Yet interviewing is rarely taught with the same intensity as sampling or accounting.


Consider the difference between asking:

"Do you review the monthly reconciliation?"

and:

"Walk me through the last reconciliation you completed."

The first question invites a yes-or-no response.


The second invites evidence.


Then ask:

"What do you look for?"

Then:

"What was the last exception you found?"

Then:

"What did you do with it?"

Then:

"Show me."

That sequence moves the auditor from representation to corroboration.


That is tradecraft.


Audit the Process That Exists—not the Process in the Narrative

A client may have beautiful documentation.


The process may still operate differently.


External auditors should distinguish among:


The designed process — what management says should happen.


The documented process — what the narrative or flowchart says happens.


The actual process — what employees really do.


The controlled process — what can be demonstrated through evidence.


These may not be identical.


The CCS program examines the client's approach to SOX documentation and the auditor's approach to entity-level and process controls.


That distinction is critical to ICFR auditing.


COSO Is More Than Five Boxes

Many auditors can name the five components of the COSO Internal Control—Integrated Framework.


The more difficult challenge is understanding how those components and principles operate together.


The CCS course specifically addresses COSO entity-level controls involving the Control Environment, Risk Assessment and supporting components, as well as how the components and principles integrate.


The auditor should be looking beyond individual transaction controls.


Ask:

  • What tone does management actually establish?

  • How does the organization hold people accountable?

  • How are risks identified?

  • How does information move upward?

  • Are employees willing to report problems?

  • Does the Audit Committee receive complete information?

  • How does management monitor controls?

  • What happens when controls fail?


A perfectly documented transaction control exists inside a larger control environment.


If that environment is weak, the auditor needs to understand the implications.


Management Override Changes Everything

A control may work perfectly for 364 days.


If an executive can override it on the 365th day when the financial consequences matter, the auditor has a different risk.


That is why fraud risk requires particularly strong professional skepticism.


PCAOB Auditing Standard 2401 emphasizes that auditors should maintain a mindset recognizing that material misstatement due to fraud could exist regardless of previous experience with the company or beliefs about management's honesty and integrity.


Tradecraft means asking uncomfortable questions professionally.


Who can override the control?


Who can post unusual journal entries?


Who can change vendor banking information?


Who can modify system permissions?


Who reviews senior management transactions?


What happens when the CEO wants an exception?


The organizational chart tells you who has authority.


The audit should determine how that authority is actually exercised.


Workpapers Must Tell the Audit Story

Audit documentation should not merely prove that somebody completed a checklist.


A strong workpaper should allow an experienced reviewer to understand:

  • The objective

  • The risk

  • The procedure

  • The population

  • The evidence

  • The exceptions

  • The auditor's analysis

  • The judgment applied

  • The conclusion


CCS specifically includes developing audit workpapers capable of supporting PCAOB-compliant audits as part of its tradecraft curriculum.


A reviewer should not have to reconstruct the auditor's thinking.


The workpaper should tell the story.


The Auditor Must Be Willing to Be Wrong

This may be one of the most important characteristics of a great auditor.


Auditors develop expectations.


Those expectations can become biases.


Once we believe:

  • The control works

  • Management is competent

  • The transaction is reasonable

  • The estimate is conservative

  • The exception is isolated

we naturally notice information supporting that belief.


Audit tradecraft requires actively looking for information that could prove our initial conclusion wrong.


PCAOB auditing standards explicitly emphasize evaluating both corroborating and contradictory evidence.


That is professional skepticism in action.


Artificial Intelligence Makes Tradecraft More Important—not Less

AI can now help external auditors:

  • Research industries

  • Summarize regulations

  • Develop planning questions

  • Analyze datasets

  • Compare documents

  • Draft workpapers

  • Generate interview questions

  • Identify unusual patterns

  • Draft reports


Those capabilities are powerful.


They also create a new danger.


An auditor can produce a very sophisticated-looking answer that is wrong.


The future external auditor therefore needs two capabilities:


Technology competence and audit judgment.


AI can identify an anomaly.


The auditor must determine whether it matters.


AI can summarize an interview.


The auditor must determine whether the interviewee was credible.


AI can draft a risk assessment.


The auditor must determine whether the risks are complete.


AI can draft a workpaper.


The auditor remains responsible for the conclusion.


Tradecraft becomes more valuable as automation increases because professional judgment becomes the differentiator.


PCAOB Inspection Readiness Should Begin During Planning

A firm should not start thinking about PCAOB inspection quality after the engagement is completed.


Inspection readiness begins when the audit is planned.


Auditors should continually ask:

If a PCAOB inspector selected this area, would the workpaper demonstrate why we performed these procedures, what evidence we obtained, what contradictory information we considered and why our conclusion was reasonable?

CCS's program directly addresses typical PCAOB inspection issues and the development of audit documentation capable of supporting the auditor's conclusions.


The objective should not be to create more paper.


The objective is to create better evidence of better auditing.


What You Will Study in PCAOB Audit Tradecraft for the External Auditor

The CCS program brings these concepts together through ten major subject areas:

  1. Sarbanes-Oxley and the PCAOB

  2. Current PCAOB Auditing Standards

  3. Audit Planning and Risk Management

  4. COSO Control Environment Entity-Level Controls

  5. COSO Risk Assessment Entity-Level Controls

  6. COSO Supporting Components

  7. The Client's Approach to SOX Documentation

  8. The Auditor's Approach to Risk Assessment and Control Environment Entity-Level Controls

  9. The Auditor's Approach to Process Controls

  10. Auditor Tradecraft Summary


The objective is not simply to memorize standards.


It is to become better at performing the audit.


Who Should Attend?

The program is particularly valuable for external auditors and CPA firm professionals who want to improve both technical PCAOB knowledge and practical execution skills. It is also relevant for compliance professionals who need a stronger understanding of the intersection among SOX, ICFR, COSO, risk assessment and external auditing.


The program is listed at the Basic level with no prerequisites or advance preparation required, making it useful both for developing auditors and professionals who want to reinforce the fundamentals underlying high-quality PCAOB work.


Build Better Auditors—not Better Checklist Completers

The external audit profession does not need auditors who can simply execute another checklist.


It needs professionals who can:

  • Think critically

  • Recognize risk

  • Ask difficult questions

  • Evaluate evidence

  • Challenge assumptions

  • Detect inconsistencies

  • Exercise professional skepticism

  • Document their reasoning

  • Communicate clearly

  • Exercise sound professional judgment


Those capabilities cannot be automated into a checklist.


They have to be developed.


That is the purpose of PCAOB Audit Tradecraft for the External Auditor.


The live, two-day CCS program provides 12 NASBA-approved CPE credits in Auditing and Business Ethics and is scheduled in two six-hour sessions from 9:00 a.m. to 3:00 p.m. Central Time, with a 30-minute lunch break each day. Private programs are also available for groups of two or more.



The PCAOB auditing standards tell an auditor what is required.


Methodology tells an auditor what procedures to perform.


Tradecraft determines how well the auditor actually does the job.


That difference ultimately determines audit quality

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page