What do you need to know about an audit?

Assuarance services

By: Mart Nõmper

Contents

One of the strengths of Estonia’s business environment is transparency. Companies’ annual reports are publicly available, as are the auditor’s reports included with the annual reports of companies that have undergone an audit or review.

However, while all companies must file their annual report with the Estonian Business Register within six months of the end of their financial year – even if they had no business activity – not every company is required to undergo an audit or review.

So, what should the owner or manager of an Estonian company know about audits? How can you determine whether an audit is mandatory, and how should you prepare for an audit or review?

When is an audit mandatory?

Whether a company needs an audit, a review or neither depends on its size, based on its revenue, total assets and number of employees.

The easiest way to determine whether your company is subject to an audit or review requirement is to use Grant Thornton Baltic’s audit calculator. Enter your company’s revenue, total assets and number of employees to quickly find out whether an audit or review is required.

Audit or review – what is the difference?

An audit and a review are both ways of examining financial statements, but they differ in scope and in the level of assurance provided by the auditor.

An audit is a more thorough examination. The auditor assesses the information presented in the financial statements and determines whether they provide a true and appropriate view of the company’s financial position and performance. The auditor also considers the company’s processes and internal controls and assesses risks that could result in material misstatements in the financial statements.

A review is more limited in scope. It mainly involves enquiries with management and analytical procedures. A review therefore provides a lower level of assurance than an audit, but it can still help identify whether the financial statements may contain material errors or deficiencies.

In both cases, the auditor may provide management with observations and recommendations. An audit or review should therefore not be seen merely as a compliance requirement. It is also an opportunity to receive independent feedback about your company. This is why some companies choose to have an audit or review even when they are not legally required to do so.

Use the audit to improve your business

An independent auditor’s opinion gives company owners, management, investors, banks and business partners additional assurance that the company’s financial reporting is reliable and that material risks have been addressed.

An auditor may also identify opportunities to make processes more efficient and automated. For example, e-invoices and the automation of purchasing and sales processes can reduce data-entry errors, speed up transactions and improve the quality of financial data.

Auditors can also help companies identify weaknesses in processes that may go unnoticed in day-to-day operations. These may include shortcomings in internal controls, data quality or the organisation of work.

How do you find an auditor in Estonia?

When choosing an auditor for your company, consider their qualifications, experience and reliability, as well as whether they have sufficient capacity to serve your company.

There are around 350 certified auditors and more than 100 audit firms operating in Estonia. Their contact details are available on the website of Audiitorkogu, the Estonian Auditors’ Association.

An auditor’s experience and ability to meet agreed deadlines are particularly important. Larger audit firms can draw on the combined experience of dozens or even hundreds of professionals who have dealt with a wide range of situations and solutions.

Larger firms also have more flexibility to adjust work schedules if an employee becomes ill or leaves the company, helping ensure that the work is still completed on time and to the required standard. This additional capacity is one reason why the services of larger audit firms may be somewhat more expensive.

Information about the quality of Estonian audit firms is available from the results of quality inspections conducted by the Auditing Activities Oversight Board. Based on these inspections, audit firms are placed into four categories. Green is the best result and means that the quality of the audit service meets all requirements. Yellow indicates minor deficiencies, while orange and red indicate lower quality levels that require significant improvement. It is advisable to choose an auditor from the green or yellow categories.

You should also check whether the auditor has the required professional indemnity insurance and what level of cover it provides. This insurance covers direct financial losses caused in the provision of audit services. The minimum insurance cover is EUR 64,000. Given that companies may have assets and revenues worth millions of euros, the minimum level of cover may not always be sufficient to compensate for losses resulting from an auditor’s error.

When should you contact an auditor?

Once you have selected a suitable auditor, contact them well in advance. The number of auditors in Estonia has decreased over the years while their workload has continued to grow.

There is another practical consideration. As the financial year of most Estonian organisations ends on 31 December, much of the audit work is concentrated in the first half of the year. This creates a particularly busy period for auditors and can result in longer waiting times.

There is, however, one practical way for some companies to schedule their audit for a less busy period.

Companies with seasonal business activities may want to consider using a financial year that differs from the calendar year. For example, this may be a practical solution for companies in tourism, retail, agriculture and several other sectors. If the financial year ends during a quieter period for the company, both preparing the annual report and carrying out the audit may be easier to manage.

You can read more about changing a company’s financial year in Grant Thornton Baltic’s article on the subject.

What does the audit process look like?

Preparing for an audit starts before the annual report is completed. The auditor familiarises themselves with the company’s activities and financial performance, assesses potential risks and agrees on the audit timetable and arrangements for exchanging information.

For larger or more complex companies, audit work may begin before the financial year has ended. For example, if the financial year ends on 31 December, the auditor can carry out an interim audit in the autumn. They can review transactions and balances for the first nine months and determine the focus of the final audit. After year-end, the auditor can then concentrate mainly on events in the final quarter and year-end balances.

Before the audit begins, the auditor sends the company a list of the documents and data required for the audit. These materials are usually shared through a secure file-sharing environment or audit portal.

Sending confidential documents to the auditor by ordinary email is not secure and should be avoided. If sensitive information needs to be sent by email, it should be encrypted.

Among other things, the auditor assesses the company’s financial reporting, material transactions, asset and liability balances and, where necessary, the operation of internal controls. The scope of the work depends on the company and the auditor’s assessment of the areas that may involve greater risk.

If questions arise or deficiencies are identified during the audit, the auditor communicates with the company and may request additional explanations or documents. This gives the company an opportunity to correct inaccuracies before the audit is completed.

At the end of the audit, the auditor issues their report and, where appropriate, separately presents observations and recommendations for improving the company’s processes or internal controls.

What does the company need to do?

The most important point to understand is that an audit is not solely the auditor’s responsibility. The company’s management and accountant also have an important role to play.

First, the company’s accounting records must be in good order. When preparing the annual report, for example, asset and liability balances should be checked to ensure that they comply with the accounting principles used to prepare the financial statements.

Second, the requested documents and data must be provided to the auditor on time. The better the information is prepared, the more smoothly the audit is likely to proceed.

Third, communicate openly with your auditor. If a question arises about a transaction or an accounting policy, it is better to discuss it immediately rather than wait for the audit. Resolving an issue as it arises usually takes less time than dealing with a problem discovered only when the auditor reviews the financial statements.

How should you prepare for an audit?

Good preparation helps avoid situations where the auditor has to wait for documents or the company has to start correcting errors during the audit itself.

Ideally, preparation should begin before the end of the financial year. Review observations and recommendations from previous audits and check whether the issues identified have been resolved. It is also worth reviewing material balances, transactions and agreements in good time and making sure that all necessary documentation is available.

Pay particular attention to common problem areas in annual reports. Errors can arise, for example, from missing notes relating to material balances, missing or incorrect references and cross-references, failure to disclose material matters such as events after the reporting date, errors in the cash flow statement, or incomplete disclosure of related-party transactions and balances.

The best audit is one the company prepares for throughout the year. Accurate day-to-day accounting, well-organised documentation and open communication with the auditor can reduce both the time spent on the audit and the risk of unpleasant surprises.