Saturday, June 6, 2026

Audit documentation 002

Here is the complete framework — **56 core audit documents across 7 phases**, fully cross-referenced. Below is a structured summary of the architecture:

---

## Framework Architecture

### Phase 1 — Pre-Engagement (DOC-01 to 06)
Before any work begins. Covers client acceptance, independence, AML screening (MLPA 2012 + BFIU), predecessor communication, and the engagement letter (ISA 210 / Contract Act 1872). All mandatory before signature.

### Phase 2 — Planning (DOC-07 to 13)
Overall audit strategy (ISA 300), materiality computation (ISA 320 — three tiers: overall, performance, specific), entity understanding (ISA 315 Revised 2019 with 6 components of ICFR), preliminary analytics, ITGC planning, group audit instructions (ISA 600 Revised), and team briefing.

### Phase 3 — Risk Assessment (DOC-14 to 20)
The Risk Assessment Matrix (RAM) by assertion is the anchor. Fraud brainstorming (ISA 240), ICQ + walkthroughs, related party mapping (BAS 24 + ISA 550 — critical in BD family-conglomerate structures), going concern initial review (ISA 570), and significant estimates identification (ISA 540 Revised 2019 — includes WPPF provision under Labour Act 2006).

### Phase 4 — Fieldwork (DOC-21 to 34)
14 documents covering: audit programmes (ISA 330), controls testing, sampling (ISA 530), bank confirmations (with BB/EDF-specific variants), debtors circularization (ISA 505), stock observation (ISA 501 — critical for RMG/pharma), revenue cut-off, **deferred tax** (BAS 12 + ITA 2023 — tax holiday SROs, minimum tax s.82C), **WPPF 5%** workpaper (Labour Act 2006 mandatory), loan analysis (BFRS 9 + BRPD circulars), litigation (BAS 37 + VAT Act 2012), query log (ISA 450), and expert evaluation (ISA 620).

### Phase 5 — Completion & Review (DOC-35 to 43)
Summary of audit differences vs. materiality thresholds, final analytical review (ISA 520.6), going concern final conclusion, subsequent events (BAS 10), Management Representation Letter (ISA 580 — signed same date as report), completion checklist, **EQCR documentation** (ISQM 2 — mandatory for all PIEs/listed), BFRS/BAS disclosure checklist, and **KAM documentation** (ISA 701 — mandatory for listed entities per BSEC 2020 notification).

### Phase 6 — Reporting (DOC-44 to 50)
Independent Auditor's Report (ISA 700/701/705/706), Management Letter (ISA 265), TCWG communication (ISA 260 + BSEC CG Code 2018), **Long-Form Audit Report for Bangladesh Bank** (BCD Circular — mandatory for banks), ICFR report (ISAE 3402), **Corporate Governance Compliance Certificate** (BSEC 2018 — filed with DSE/CSE), and tax audit certificate (ITA 2023 + Transfer Pricing Rules).

### Phase 7 — Post-Issuance (DOC-51 to 56)
File assembly within 60 days (ISA 230 + ICAB 7-year retention), hot/cold quality review (ISQM 1), post-report-date subsequent events, regulatory filing confirmations (RJSC + BSEC + BB + IDRA), lessons-learned memo, and independence renewal triggering the **7-year partner rotation** assessment (IESBA + ICAB Code of Ethics 2020).

---

**Key BD-specific items embedded throughout:** WPPF 5%, BSEC CG Code 2018, BRPD circulars, Income Tax Act 2023, NBR SROs, Labour Act 2006, MLPA 2012/BFIU, mouza/khatian land title verification, EDF loan confirmations, and CIC clearance for going concern.

No comments:

Post a Comment