13.07.2015 Views

Guidance for AA1000AS (2008) Assurance Providers - AccountAbility

Guidance for AA1000AS (2008) Assurance Providers - AccountAbility

Guidance for AA1000AS (2008) Assurance Providers - AccountAbility

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

A.4 Conducting an <strong>AA1000AS</strong> (<strong>2008</strong>) Engagement4.1 Planning the engagementA best practice assurance plan would contain details of:• the objectives of the engagement including:• scope,• level of assurance,• standards to be used, and• criteria to be used;• the assurance strategy, including risk assessment;• the tasks and activities, including• evidence gathering methods,• resources requirements (human, financial, technological), and• schedule (dates and duration);• the evidence requirements (depth, breadth, type, sources of evidence,sampling protocols);• the resource requirements;• the roles and relationships;• identification of key reporting organisation and assurance provider contacts;and• reference documents, protocols, checklists and other working documents to beused.4.1.1 Engagement riskThe practitioner should reduce assurance engagement risk to an acceptably lowlevel in the circumstances of the engagement. In general, assurance engagementrisk comprises inherent risk, control risk and detection risk. The degree to whichthe assurance provider considers each of these components is affected by theengagement circumstances.The assurance provider needs to obtain an understanding of the subject matter andother engagement circumstances; sufficient to identify and assess the risks of the16 September, 2009

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!