but the tl;dr is that auditors don't provide "insurance", they provide "assurance", specifically reasonable assurance.... that the accounts are "true and fair"
or to be put it in even simpler terms, they can't guarantee something fishy did or didn't happen, the transaction scope is just too much, they will "try their best" and do enough of a check to say if anything fishy pops put.
> Is it just a top-level glance at the numbers because there isn't enough time/money to scrutinize everything?
yes you hit the nail right on the head. Of course things have changed, govt have put their own requirements in addition to auditing standards, but still that's an adequate summary.
the more through of a check, the more difficult, time consuming and expensive it becomes, and at some point the fraud becomes cheaper than the audit.
but even more importantly is the mentality. There is a phrase we were taught "Auditor is a watchdog and not a bloodhound" that kind of explains what auditors are supposed to do.
----
i left the field but i'll try to answer to the best of my ability
In crypto the auditing process is somewhat more sophisticated. They scan the contract for similarity to known scams and analyze it for possible backdoors. They also do due diligence on the promoter of the contract ("fully doxxed").
In reality of course all this work could have been replaced by def is_fraud():return True
And the accuracy would probably increase. Crypto fraud has the beautiful property that the people being defrauded actively defend the fraudsters. Moreover, in a lot of cases it isn't technically fraud since the contract is upfront about what it does but at the same time it is very exploitative but that doesn't matter to crypto people
how do you technologize intent-detection? maybe chatgpt-x could do it, but that's the crux.
i am NOT haying pattern recognition won't help, search for audit software and you will see each of the big four has specialized software. (here is EY's: https://www.ey.com/en_gl/audit/technology)
the problem is the issue of perverse incentives, IMHO. Audit takes a butt load of time and money, and disrupt business while they do their thing, and pays peanuts frankly... and audit firms earn more from associated services, contracts which they can earn if they don't bother the management too much.
yes, there are a dozen caveats and stuff, but frankly, the issue comes down not to technology but to people. The same network of people are in the few audit firms, and the spin out to join companies sometime later, who hire the same few audit firms, and so on.
https://kfknowledgebank.kaplan.co.uk/audit-and-assurance/aud...
but the tl;dr is that auditors don't provide "insurance", they provide "assurance", specifically reasonable assurance.... that the accounts are "true and fair"
or to be put it in even simpler terms, they can't guarantee something fishy did or didn't happen, the transaction scope is just too much, they will "try their best" and do enough of a check to say if anything fishy pops put.
yes you hit the nail right on the head. Of course things have changed, govt have put their own requirements in addition to auditing standards, but still that's an adequate summary.the more through of a check, the more difficult, time consuming and expensive it becomes, and at some point the fraud becomes cheaper than the audit.
but even more importantly is the mentality. There is a phrase we were taught "Auditor is a watchdog and not a bloodhound" that kind of explains what auditors are supposed to do.
----
i left the field but i'll try to answer to the best of my ability