Current through November 30, 2024
Section 1773.32 - Reports on internal control; compliance with provisions of laws, regulations, contracts, and grant agreements; and instances of fraud(a) As required by GAGAS, the auditor must prepare a written report describing the scope of the auditor's testing of internal control over financial reporting and of compliance with provisions of laws, regulations, contracts, and grant agreements, and state whether the tests provided sufficient, appropriate evidence to support opinions on the effectiveness of internal control and on compliance with provisions of laws, regulations, contracts, and grant agreements. This report must include the manual or printed signature of the audit firm and must include the following items as appropriate: (1) Significant deficiencies and material weaknesses in internal control;(2) Identified or suspected instances of noncompliance with provisions of laws, regulations, contracts and grant agreements that have a material effect on the financial statements or other financial data significant to the audit objectives and any other instances that warrant the attention of those charged with governance;(3) Identified or suspected instances of fraud that have a material effect, either quantitatively or qualitatively, to the financial statements or other financial data significant to the audit objectives; and(4) Identified or suspected instances of abuse that have a material effect, either quantitatively or qualitatively, to the financial statements or other financial data significant to the audit objectives.(b) When the auditor detects instances of noncompliance or abuse that have an effect on the financial statements that are less than material but warrant the attention of those charged with governance, they should communicate those findings in writing to those charged with governance in a separate communication. If the auditor has issued a separate communication detailing immaterial instances of noncompliance or abuse, the reports on internal control; compliance with provisions of laws, regulations, contracts, and grant agreements; and instances of fraud must be modified to include a statement such as: "We noted certain immaterial instances of noncompliance [and/or abuse], which we have reported to the management of (auditee's name) in a separate letter dated (month, day, 20XX)."
(c) If the auditor has issued a separate letter to management to communicate other matters involving the design and operation of the internal control over financial reporting, the reports on internal control; compliance with provisions of laws, regulations, contracts, and grant agreements; and instances of fraud must be modified to include a statement such as: "However, we noted other matters involving the internal control over financial reporting that we have reported to the management of (auditee's name) in a separate letter dated (month, day, 20XX)."
83 FR 19907 , May 7, 2018, as amended at 88 FR 7565 , Feb. 6, 2023 83 FR 19907 , 7/6/2018; 88 FR 7565 , 5/8/2023; 89 FR 88635 , 12/9/2024