Skip to content

Audit Risk

VIVA Subject Guide

1 Introduction

YouTube video

Audit risk is a technical term related to the process of auditing. The first thing to appreciate is that audit risk cannot be reduced to zero as an audit cannot provide absolute assurance – only reasonable assurance. This is because an audit has ‘inherent limitations’, for example:

  • Part of the nature of financial reporting is that financial statements should include accounting estimates which necessarily involve judgement.

  • Audit procedures are designed to gather audit evidence, not to detect intentional misstatement that has been deliberately concealed.

  • As an audit needs to be conducted within a reasonable period of time and at a reasonable cost, it is not possible to examine everything exhaustively.

Audit risk is considered throughout the audit, in particular:

  • In understanding the entity – what are the risks? (ISA 315 Identifying and Assessing the Risks of Material Misstatement).

  • In planning the audit – how are risks to be reduced to an acceptably low level? (ISA 330 The Auditor’s Responses to Assessed Risks).

A ‘planning’ question in Section B of the AA exam will typically include the requirement “Describe [a specified number] audit risks and explain the auditor’s response to each risk in planning the audit of [Client Co]”. This Chapter explains the components of audit risk and introduces how the auditor responds to risk.

2 Audit risk

Audit risk is the risk that the auditor gives an inappropriate opinion on the financial statements (i.e. the audit opinion is that the financial statements present fairly, in all material respects, when, in fact, they contain a material misstatement).

Audit risk is a function of two risks:

  • The risk that the draft financial statements actually contain a material misstatement. This is the risk of material misstatement ('ROMM') that was introduced in Chapter 8.

  • The risk that audit procedures fail to detect it, so that the financial statements are published with the misstatement still present. This is detection risk.

ROMM has two components

  • The risk that the error occurs in the first place. This is inherent risk.

  • The risk that the client’s own procedures don’t pick up and correct that error. This is control risk.

Therefore, for an inappropriate opinion to have been expressed:

1The error has to have occurred2The client’s procedures and staff must nothave picked it up and corrected it3The auditor must have failed to detect itThe material error reaches the published financialstatements — and that is audit risk

3 The audit risk model

The 'audit risk model' is an equation which expresses the relationship between components of risk:

ARIRCRDR=××Risk of material misstatementAuditriskInherentriskControlriskDetectionriskSamplingriskNon-samplingrisk

Don’t look at this too mathematically. What it is saying is that auditors will want the audit risk to be low: they don’t want to make an error in their audit opinion. If they want the audit risk to be low then the terms on the right hand side of the equation, or at least some of them, have to be low.

If both inherent risk and control risks are high, then the only way you will get the audit risk low is to be very sure that your detection risk is low. This means more audit work than if RoMM were lower.

If inherent risk and control risks are low themselves, in other words that there is only a small chance the error occurs in the first place and internal controls are operating effectively, you can achieve a relatively low audit risk even with a relatively high detection risk. In other words the amount of audit work will be less than if RoMM were higher.

The auditor assesses inherent and control risk - but cannot change them - they are 'givens' specific to each audit. Control risk is assessed if the auditor plans to test the operating effectiveness of controls. If not, the combined assessment of the RoMM is the same as the assessment of inherent risk.

The auditor must respond to the assessed risks by varying the nature, timing and extent of work which is actually performed to reduce detection risk to an acceptably low level.

For example:

  • obtaining more reliable or corroborative evidence (nature);

  • performing audit procedures on the reporting date rather than during the later final audit (timing);

  • increasing sample sizes (extent).

Detection risk has two components:

  • Sampling risk This risk arises when audit procedures are applied to samples rather than entire populations. The auditor may conclude, based on a sample, that controls are more effective than they actually are or that there is no material misstatement when, in fact, there is. The auditor may then be doing too little work so that actual misstatements go undetected. Sampling risk can be reduced by examining larger samples.

  • Non-sampling risk This risk arises from reasons other than sample size. For example, audit staff were insufficiently experienced, there is a higher risk that they might use inappropriate audit procedures, misinterpret evidence or fail to recognise an error. Non-sampling risk must be minimised through adequate planning, assigning sufficiently skilled staff and the direction, supervision and review of their work.

4 Examples of the types of risk

Build each audit-risk point as a chain: scenario fact, accounting implication, named financial statement area and direction of possible misstatement, then a responsive audit action. ‘Assets may be misstated’ is too vague when the scenario supports a specific balance and direction.

Let’s look at the three main components of the audit risk model in a little bit more detail.

  • Inherent risk is the risk that there is a misstatement that could be material, if there were no related internal controls which could identify and trap that misstatement. Inherent risks can be increased by complex transactions which are difficult to understand, inexperienced staff, a cash-based business (because cash is usually more difficult to record than bank transfers), a pressure to perform (which may mean that some staff members who have optimistic view of sales and costs), and short reporting deadlines.

  • Control risk is the risk that the material misstatement, having occurred, will not be prevented or detected and corrected by the system of internal control. The main factors which affect control risk are the control environment (i.e. the foundation for the other components of the system of internal control), the design of the system of internal control itself, and finally how well and consistently the system of internal control operates. This is covered later in Chapter 12.

  • Detection risk is the failure of the auditor to detect the material misstatement in the financial statements. This will be increased if the auditor was relatively inexperienced, if it was a new client, if there was a lot of time and fee pressure, if planning was poor so the entity was poorly understood, and if the auditor was straying into an industry where they had little previous experience or expertise.

5 Where ROMM can be found

ROMM may exist and must therefore be assessed at two levels:

  1. Financial statement level

  2. Assertion levels.

5.1 Financial statement level

Risks at the financial statement level are those that relate to the financial statements as a whole and potentially affect many assertions. For example, the risks arising from fraud or a deficient control environment or significant doubts about going concern. The auditor's response to such risks may include:

  • Assigning more experienced audit staff

  • Designing audit procedures that are less predictable

  • Exercising greater supervision over audit work.

5.2 Assertion level

At the assertion level, essentially any single figure which appears in the financial statements is making assertions. For example, it is saying something about its accuracy, its measurement, completeness and occurrence (of a transaction) or existence (of an asset or liability).

At the assertion level, the nature, timing and extent of audit procedures must be designed to respond to the assessed risks (ISA 330). For example, if you are worried about receivables valuation you have to do a lot more work verifying that receivables are recoverable. It may be possible to wait for several months after the year end to see which customers actually pay. Assertions are described in more detail in Chapter 10.

5.3 ISA 315 (Revised 2019)

ISA 315 (Revised 2019) introduced new concepts and definitions to assist with the identification and assessment of risks of material misstatement:

  • Inherent risk factors – characteristics of events or conditions that affect the susceptibility of an assertion to misstatement, before consideration of controls.

  • Spectrum of inherent risk – the degree to which inherent risk varies.

  • Relevant assertion – an assertion with an identified risk of material misstatement.

  • Significant class of transactions, account balance or disclosure – one for which there is one or more relevant assertion. *

  • Significant risk – a risk of misstatement which is close to the upper end of the spectrum of inherent risk or treated as significant in accordance with an ISA (e.g. revenue recognition).

1Understand the entity2Identify relevant assertions3Identify significant transactions,balances and disclosure4Determine where on thespectrum of risk each sitsSignificant risks identified

* IMPORTANT note: Substantive procedures must be designed and performed for each material class of transactions, account balance and disclosure (regardless of assessed RoMM).

Assertions are described in more detail in Chapter 10.

Practice questions

Audit risk

10 questions

Answer the questions one at a time. Your progress is saved so you can leave and come back.

Open chapter practice