audit-assurance · v1.0.0 · 2026-03-04 · sha256 429c6e213655bf2b
audit-assurance v1.0.0A
Immutable. This exact content is served forever at /api/v1/blob/429c6e213655bf2b.
--- name: "audit-assurance" description: 'Industry knowledge for Audit & Assurance advisory. Covers financial audit, internal audit, IT audit, SOC reporting taxonomy, key metrics (audit hours, restatement rate, material weakness), regulatory frameworks (PCAOB, IAASB, SOX, COSO), quality trends, and stakeholder mapping for partner, engagement team, and audit committee interactions.' metadata: author: "AgentX" version: "1.0.0" created: "2026-03-04" updated: "2026-03-04" compatibility: frameworks: ["agentx"] platforms: ["windows", "linux", "macos"] --- # Audit & Assurance Domain Knowledge > Industry taxonomy, metrics, trends, and stakeholder context for consulting and advisory engagements in Audit & Assurance. ## When to Use - Preparing research briefs for audit firms or audit committees - Building presentations on audit quality, methodology, or technology adoption - Creating comparison matrices for audit tools or frameworks - Advising on internal controls, SOC reporting, or assurance standards - Stakeholder engagement with audit partners, internal audit directors, CFOs, or audit committees ## Industry Taxonomy ### Service Lines ``` External / Financial Statement Audit +-- Public Company Audit: PCAOB standards, integrated audit (financial + ICFR) +-- Private Company Audit: AICPA standards, compilations, reviews +-- Non-Profit / Government: Single Audit (Uniform Guidance), Yellow Book (GAGAS) +-- Group / Consolidated Audits: component auditors, ISA 600, PCAOB AS 1206 Internal Audit +-- Operational Audit: process efficiency, risk mitigation, compliance testing +-- Financial Audit: internal controls over financial reporting +-- IT / Cyber Audit: general IT controls (ITGCs), application controls, cybersecurity +-- Compliance Audit: regulatory adherence, policy compliance +-- Forensic / Investigative: fraud examination, dispute advisory IT Audit & Assurance +-- SOC 1 (ICFR): controls at a service organization relevant to user entities' ICFR +-- SOC 2 (Trust Services): security, availability, processing integrity, confidentiality, privacy +-- SOC 3: general-use trust services report +-- HITRUST / HIPAA: healthcare data assurance +-- ISO 27001: information security management certification Specialized Assurance +-- ESG / Sustainability Assurance: ISAE 3000, ISSA 5000, limited/reasonable assurance +-- Agreed-Upon Procedures (AUP): specific scope, specified parties +-- Attestation Engagements: SOC, compliance attestation, prospective financials +-- Royalty & License Audits: contractual compliance verification ``` ### Professional Standards Hierarchy | Standard Setter | Standards | Applies To | |----------------|-----------|------------| | PCAOB | Auditing Standards (AS) | US public company audits (SEC registrants) | | AICPA (ASB) | Statements on Auditing Standards (SAS) | US non-public audits | | IAASB | International Standards on Auditing (ISA) | Global (non-US jurisdictions) | | IIA | International Standards for the Professional Practice of Internal Auditing (IPPF) | Internal audit globally | | AICPA | SSAE (attestation), SSARS (review/compilation) | Attestation and review engagements | | ISAE | ISAE 3000, ISAE 3410 | Non-financial assurance (ESG, sustainability) | ## Key Metrics & KPIs ### Audit Quality Indicators | Metric | Definition | Benchmark | |--------|-----------|-----------| | Restatement Rate | Financial restatements post-audit | Lower = higher quality | | PCAOB Inspection Deficiency Rate | Deficiencies found in PCAOB inspections | < 20% = strong | | Material Weakness (MW) Rate | MW in ICFR identified | Industry-specific context | | Going Concern Accuracy | Correct going concern opinions vs actual outcomes | Higher = better judgment | | Engagement Partner Tenure | Years on same engagement | Max 5 years (rotation) | | Staff-to-Partner Leverage Ratio | Staff hours / partner hours | 8-15x typical | ### Engagement Economics | Metric | Definition | Benchmark | |--------|-----------|-----------| | Realization Rate | Billed revenue / standard hours x rate | > 90% = healthy | | Audit Hours per $M Revenue | Total hours relative to client size | Efficiency benchmark | | Budget vs Actual Hours | Planned hours vs actual | < 10% overrun target | | Fee Growth Rate | Year-over-year audit fee changes | CPI + complexity adjustments | | Write-off / Write-down Rate | Unbilled hours as % of total | < 5% target | | Accounts Receivable Days | Days to collect audit fees | < 60 days | ### Internal Audit Metrics | Metric | Definition | Benchmark | |--------|-----------|-----------| | Audit Plan Completion | % of planned audits completed | > 90% | | Findings per Audit | Average observations per engagement | Context-dependent | | Repeat Findings Rate | Previously identified issues recurring | < 10% = effective remediation | | Time to Close Findings | Days from finding to remediation | < 90 days for high/critical | | Stakeholder Satisfaction Score | Survey-based quality rating | > 4.0/5.0 | | Cost per Audit Hour | Total IA budget / audit hours delivered | Benchmarked by industry | ## Regulatory & Compliance Landscape | Framework | Jurisdiction | Focus | |-----------|-------------|-------| | PCAOB Standards | United States | Public company audit methodology, inspections, enforcement | | Sarbanes-Oxley (SOX) 302/404 | United States | CEO/CFO certification, ICFR assessment | | COSO Internal Control Framework | Global | Internal control design and evaluation (2013 framework) | | COSO ERM Framework | Global | Enterprise risk management (2017 framework) | | AICPA Quality Management Standards | United States | QM 10, QM 20, QM 30 (firm quality systems) | | ISQM 1 / ISQM 2 | Global | Quality management at firm and engagement level | | EU Audit Reform | European Union | Mandatory rotation, non-audit service restrictions | | ISSA 5000 | Global (IAASB) | Sustainability assurance standard | | SEC XBRL / iXBRL | United States | Structured financial data filing | | CSRD | European Union | Corporate sustainability reporting + assurance mandate | ## Current Trends (2024-2026) | Trend | Impact | Relevance | |-------|--------|-----------| | AI-Augmented Audit | Automated journal entry testing, anomaly detection, NLP for contracts | Efficiency, quality | | Continuous Auditing / Monitoring | Near-real-time control testing, automated evidence gathering | Risk reduction, timeliness | | ESG / Sustainability Assurance | Mandatory sustainability reporting assurance (CSRD, SEC) | New service line, skills gap | | Data Analytics in Audit | Full-population testing, pattern analysis, visualization | Audit quality improvement | | Cybersecurity Assurance | SOC for Cybersecurity, NIST assessments, IT audit growth | Demand growth | | Audit Quality Transformation | Firm quality management systems (ISQM 1), root cause analysis | Regulatory expectation | | Remote / Hybrid Audit Delivery | Virtual walkthroughs, cloud evidence, digital confirmations | Operating model | | Audit Committee Expectations | Greater reporting, focus on fraud risk, non-financial metrics | Communication, reporting | | Talent & Workforce Challenges | CPA pipeline decline, competition for data/tech skills | Capacity, pricing | | Crypto / Digital Asset Assurance | New audit considerations for blockchain, digital assets, DeFi | Emerging standards | ## Stakeholder Map | Role | Priorities | Language | |------|-----------|----------| | Audit Partner / Engagement Partner | Audit quality, risk management, client relationship, economics | Standards, risk, commercial | | Audit Committee Chair | Financial reporting integrity, auditor independence, risk oversight | Governance, fiduciary | | CFO / Controller | Clean opinion, timely close, minimal adjustments | Financial, process | | Internal Audit Director / CAE | Risk coverage, stakeholder value, IA effectiveness | Risk, assurance, advisory | | Chief Compliance Officer | Regulatory adherence, policy enforcement, monitoring | Compliance, regulatory | | IT Audit Manager | ITGC effectiveness, SOC readiness, cyber risk coverage | Technical, controls | | External Audit Manager / Senior | Execution, testing, documentation, timeline management | Procedural, detail-driven | | Risk Management / CRO | ERM alignment, risk assessment, emerging risks | Risk framework, scenarios | | Board of Directors | Oversight, tone at the top, reputational risk | Governance, strategic | ## Discovery Questions Use these to scope engagements and understand client context: - What is your current audit methodology and technology platform? - Where are you on the journey to data-driven / AI-augmented auditing? - What were the key findings from your last PCAOB/regulatory inspection? - How do you manage the audit of IT general controls and cybersecurity? - What is your ESG/sustainability assurance strategy and readiness? - How does internal audit coordinate with external audit? - What is your CPA pipeline and talent retention strategy? - How do you measure and report audit quality indicators? - What is the audit committee's top concern for the next reporting cycle? ## Anti-Patterns - **Ignoring independence**: Every recommendation must consider auditor independence (financial, business, personal) - **Standards-agnostic advice**: Always specify which standard framework applies (PCAOB vs ISA vs IIA) - **Technology over methodology**: Tools augment professional judgment -- they do not replace it - **Overlooking materiality**: All audit recommendations must be framed in context of materiality thresholds - **Generic risk language**: Use specific risk categories (inherent, control, detection, fraud risk) - **Confusing assurance levels**: Distinguish clearly between reasonable, limited, and agreed-upon procedures