Audit of Different Types of Entities and Banks
Weightage: Chapter 8 of ICAI's Paper 5 syllabus, roughly 10 marks. Applies every earlier chapter's framework to specific entity types, each with its own governing law and its own particular risk emphasis.
Company audit under the Companies Act, 2013
Appointment, removal, qualification, disqualification of auditors — this material is developed fully in Paper 2's Corporate and Other Laws chapter on accounts and audit, and this chapter builds on it rather than repeating it: the auditor's rights and duties under sections 143–147 (right of access to books and vouchers, right to receive information and explanations, duty to report on specified matters, the auditor's report contents required by the Act itself, over and above SA 700's own requirements).
The company auditor's report under section 143 must additionally state matters including: whether proper books of account have been kept; whether the balance sheet and profit and loss account are in agreement with the books; whether, in the auditor's opinion, the financial statements comply with the applicable Accounting Standards; whether any director is disqualified from being appointed a director; qualifications, reservations or adverse remarks relating to the maintenance of accounts; and, for specified companies, a statement on the adequacy and operating effectiveness of internal financial controls with reference to financial statements — this last item connects directly back to the internal control chapter, now examined specifically as a statutory reporting requirement rather than merely an audit planning input.
CARO (Companies Auditor's Report Order) requires the auditor to include a statement on specified additional matters (fixed asset records, inventory verification, compliance with deposit provisions, and others) for companies falling within its scope, with specified exemptions (for instance, for certain small, private, or specified categories of company) — the exact scope and exemptions are examinable in outline rather than in exhaustive statutory detail at this level.
Audit of non-corporate entities
Where an entity is not a company, there is generally no single, comprehensive statute governing its audit the way the Companies Act governs a company — the auditor's rights and duties instead derive substantially from the terms of the specific engagement, together with whatever specific statute (if any) applies to that entity type. This is the conceptual point examined most: candidates must recognise that the source of an auditor's authority and duty shifts depending on entity type, from a comprehensive statute (company) to an engagement letter plus a narrower, entity-specific law (most others).
Sole proprietorship and partnership — no statutory audit requirement generally exists (subject to tax-law-triggered audit requirements under the Income-tax Act's specified turnover thresholds, developed in Paper 3); where an audit is performed, the auditor's rights and duties are governed entirely by the engagement letter agreed with the proprietor/partners, since no overarching audit statute applies.
Trusts — audited under the terms of the trust deed and applicable specific legislation (for a charitable or religious trust, relevant state Public Trusts Acts, or Income-tax Act provisions where exemption is claimed); the auditor verifies that trust funds have been applied in accordance with the objects of the trust as stated in the trust deed, which is the trust audit's most distinctive emphasis.
Co-operative societies — audited under the relevant Co-operative Societies Act, which prescribes specific matters the auditor must additionally report on, often including verification that the society's transactions are within the scope of its bye-laws and that statutory reserve requirements are met.
Local bodies — audited under specific municipal or local government legislation, generally with a strong emphasis on compliance with budgetary and statutory spending provisions, given the public-fund nature of the entity.
Bank audit
Banks are singled out for a dedicated section precisely because a bank's balance sheet is structured fundamentally differently from an ordinary trading or manufacturing company's, and this drives correspondingly different audit emphasis.
Advances are the largest and most significant asset for most banks (the equivalent of receivables/inventory combined, in terms of audit significance), and their classification is governed by RBI's prudential norms on Income Recognition and Asset Classification (IRAC).
Classification of advances:
Standard assets — advances that do not disclose any problem and do not carry more than normal risk attached to the business.
Non-performing assets (NPAs) — an advance where interest and/or instalment of principal remains overdue for a period of more than 90 days (the specific figure is examinable and precisely tested) — this single threshold is the hinge of the entire bank audit chapter, because everything about income recognition and provisioning for advances follows from whether an account has crossed it.
Within NPAs, further sub-classification: sub-standard assets (an asset that has remained NPA for a period less than or equal to 12 months); doubtful assets (an asset that has remained in the sub-standard category for a period of 12 months); loss assets (an asset where loss has been identified but the amount has not been written off wholly, considered uncollectible).
Income recognition on NPAs — once an account is classified NPA, income (interest) is not recognised on an accrual basis; it is recognised only when actually received — this is the single most consequential audit consequence of the 90-day crossing, since a bank continuing to accrue interest income on an account that has, in substance, stopped performing would overstate both income and the corresponding asset.
Provisioning — banks are required to make specified minimum provisions against advances according to their classification (higher provisioning percentages for doubtful and loss assets than for sub-standard, and progressively higher again the longer an asset has remained doubtful), reflecting the increasing likelihood of ultimate loss the longer non-performance persists.
The auditor's specific bank-audit procedures consequently concentrate heavily on: testing the 90-day ageing of advances to confirm correct classification; verifying that income has not been accrued on accounts that have crossed the NPA threshold; and testing the adequacy of provisions against the classification actually determined, rather than against whatever classification and provisioning the bank's own system may have generated, since a bank's own systems can themselves be a source of error or, in some documented cases historically, of deliberate evergreening (artificially keeping an account classified as standard by disguising non-payment) — connecting directly back to the professional scepticism principle from the opening chapter of this subject.
Other distinctive features of bank audit: branch audit structure (many banks are audited through a combination of a central statutory audit and separate branch-level audits, particularly for larger branches, with the results consolidated); and specific verification of contingent liabilities distinctive to banking (letters of credit, guarantees issued, bills for collection), which for a bank are typically far larger in scale relative to the balance sheet than for an ordinary company.
The unifying lesson
Every entity type in this chapter is approached the same underlying way: identify what makes this entity's financial statements and risk profile distinctive, and adapt the general audit framework (risk assessment, evidence, materiality, all developed in earlier chapters) to that specific distinctiveness — a bank's distinctiveness is its advances and their classification; a trust's is verifying application of funds against its objects; a non-corporate entity's is the absence of a comprehensive governing statute, shifting the source of the auditor's authority to the engagement letter.
