Skip to content

Risk

VIVA Subject Guide
YouTube video

1 Types of risk

The AAA exam will include a 50-mark case study question, set at the planning stage of an audit. Typically, you will be required to evaluate at least one of the following types of risks for a given assignment:

  • Business risks

  • Audit risks

  • Risks of material misstatement ('ROMM').

It is essential that you can distinguish between these terms.

Business risks result from significant conditions, events, circumstances, actions or inactions that could adversely affect the entity's ability to achieve its objectives and execute its strategies.

There are four main categories of business risk:

  • Strategic risk

  • Financial risk

  • Operational risk

  • Compliance risk

Competition is a common source of strategic risk for businesses planning to expand into new products or markets. Financial risks could arise because of high borrowings and a rise in interest rates. This will put the business under severe pressure and could increase the risk of material misstatement, perhaps with regards to going concern problems. Operational risks arise from day-to-day business activities. For example, if the products are made incorrectly then there might be warranty claims and a loss of reputation. Compliance risks arise from a failure to comply with regulations. This can mean that the business has large penalties or fines to pay or it may result in the loss of an operating licence, so it can no longer trade.

The auditor does not have a responsibility to identify or assess all business risks, but an understanding of business risks that may result in ROMM is essential (ISA 315).

2 Business risk

It is, of course, not the auditor’s duty to manage a business and its risks or even to warn audit clients about business risks. It is the directors’ and management’s responsibility to run the business for the benefit of shareholders. Auditors cannot be expected to have expertise in the huge variety of business risks that are suffered by their many clients. Provided the financial statements properly report on what has happened in the business (eg that inventory of a poorly selling product has been written down appropriately) the audit opinion is not affected: the financial statements are presented fairly, in all material respects.

So why is business risk important to auditors? Well, it is important because business risk will often often influence inherent risk (ie the susceptibility of a financial statement assertion to the risk of material misstatement). If misstatements which are not prevented or detected and corrected by internal controls (control risk) are not detected by the the auditor (detection risk), the auditor will express an inappropriate opinion (audit risk).

The following examples illustrate just some of the possible risks of material misstatement arising from business risk:

Business risk

Possible ROMM

Strategic: out-of date products

Inventory might not sell at above cost and should be written down to net realisable value (risk of overstated inventory/profit)

Strategic: operations in a country where the currency has devalued

Subsidiary's assets and liabilities should be retranslated at the reporting date (risk of overstated net assets and understated exchange losses)

Operational: a batch of products has been poorly manufactured

Sales returned (risk of overstated revenue), goods scrapped (risk of overstated inventory/profit), compensation to be paid (risk of understated liabilities)

Operational: computer virus in the accounting system that deletes customers' records

What are the receivables balances? (risk of misstated receivables)

Financial risk: significant rise in interest rates

Material uncertainty relating to going concern (disclosure risk)

Financial risk: significant bank loans with covenants attached

As well as going concern (above), management bias increases inherent risk at the financial statement level

Compliance risk: improper recruitment of staff that contravenes equality legislation

Actual fines/penalties (risk of understated liabilities) or possible fines/penalties (disclosure risk for contingent liabilities)

Compliance risk: failure to comply with health and safety legislation

Fines/penalties and going concern (as above)

3 Audit risk

Audit risk is the risk that the financial statements contain a material misstatement that the auditors have not discovered so that the auditors give an inappropriate opinion on the published financial statements. (Strictly, it could also refer to the auditors modifying their opinion when the financial statements are fine. However, this is 'scoped out' of the ISAs as this risk is ordinarily insignificant.)

Audit risk has three components whose relationship is described by the audit risk model:

audit risk model


  • Inherent risk = the risk of an error occurring in the first place, without any controls being present.

  • Control risk = the risk that the entity’s control procedures do not prevent, detect and correct the error.

  • Detection risk = the risk that audit procedures do not discover the error.

The assessment of inherent risk considers both likelihood and magnitude of possible misstatement. A significant risk may arise from matters such as:

  • Transactions that involve subjectivity (e.g. because there are acceptable alternative accounting treatments);

  • Accounting estimates with high estimation uncertainty or using complex models;

  • Account balances or quantitative disclosures that involve complex calculations;

  • Changes in the entity’s business that involve changes in accounting (e.g. acquisitions or change in business model).

If there are no controls any errors will find their way into the draft financial statements.

However, an effective system of internal control can help to prevent or detect and correct errors. For example:

  • Senior management of experts review assumptions and other sources of estimation uncertainty.

  • Segregation of duties or independent checks reduce the risk of errors and fraud.

  • Reconciliations check the completeness and accuracy of numerical data.

  • Authorisation and approval lends reliability to transactions.

  • Physical measures safeguard assets.

  • Inspection of assets can detect damaged assets or deliveries not properly made.

Don’t look upon the audit risk model too mathematically. What it is saying is that auditors will want the audit risk to be low: they don’t want to make an error in their audit opinion.

If they want the audit risk to be low then the terms on the right hand side of the equation, or at least some of them, have to be low.

If an error is made in the first place (inherent risk) AND is not identified and corrected by the controls (control risk) then the error will be incorporated into the draft financial statements. There is then only one line of defence to prevent the error from being included in the published financial statements: the audit.

Control risk


If the auditors believe that the inherent risks together with the control risks are unacceptably high, then they must increase the amount of audit work they perform. This reduces the detection risk (the risk that the error is not discovered by the auditors). Risks of undetected material misstatements must be reduced to levels which provide reasonable assurance that material errors are detected.

Neither inherent risk nor control risk can be influenced by auditors in the short term. Inherent risk might be completely impervious to change (for example, a complicated transaction will always be complicated). Control risks might be reduced in the medium term if the audit client takes note of auditors’ letters which set out control weaknesses. However, when it comes time to perform the audit on the draft financial statements, the only risk that the auditors can control is the detection risk. They must do sufficient audit work to manage the overall audit risk.

4 Causes of material misstatements

Material misstatements can occur in two ways:

  1. The amount is materially incorrect

  2. The amount is materially correct but incorrectly classified, presented or disclosed (ie does not comply with the applicable financial reporting framework).

Auditors must therefore obtain audit evidence about the amount and also the treatment of the amount in the financial statements.

Remember, audit evidence is needed to support all the relevant assertions. So for a non-current asset, evidence is needed about existence, ownership (rights and obligations), accuracy valuation and allocation, completeness, classification, presentation. Transactions and events require evidence about occurrence, completeness, accuracy, cut-off, classification and presentation. IFRSs usually specify how amounts should be classified and presented. They can also determine cut-off (eg in revenue recognition), rights and obligations (eg right-of-use assets and lease liabilities) and valuation (eg subsequent measurement of property, plant and equipment).

5 Detection risk

Detection risk has two components:

  • Sampling risk     This arises when audit procedures are applied to samples rather than entire populations. The auditor may conclude, based on a sample, that controls are more effective than they actually are or that there is no material misstatement when, in fact, there is. The auditor may then be doing too little work so that actual misstatements go undetected. Sampling risk can be reduced by examining larger samples.

  • Non-sampling risk     This risk arises from reasons other than sample size. For example, if the audit staff were inappropriately qualified, there is a higher risk that they might use inappropriate audit procedures, misinterpret evidence or fail to recognise an error.

  •   Good quality control procedures should minimise non-sampling risk: adequate planning, assigning sufficiently skilled staff and the direction, supervision and review of their work.

6 Auditor's responses to assess risks

You should recall from earlier studies that ROMM may exist at both the

  • Financial statement level

  • Assertion levels.

See Chapter 9 of our AA notes if you need to revise this.

6.1 Overall responses

Misstatements at the financial statement level are potentially more subtle and require a higher level of skill to detect. The auditor's response may include assigning more experienced staff, providing more supervision and emphasis on professional scepticism. Understanding of the control environment is particularly relevant here and will have a significant effect on audit strategy. For example:

  • If effective, more audit procedures may be performed at an interim date as the auditor has more confidence in internal control and the reliability of audit evidence.

  • If ineffective, more extensive substantive audit procedures should be performed at the year end.

6.2 Assertion level

Assessed risks of material misstatement at the assertion level require the auditor to design and perform further audit procedures, for example:

  • Tests of controls (if intending to rely on their operating effectiveness);

  • Substantive procedures that are specifically responsive to the identified significant risk;

  • Obtaining more persuasive audit evidence the higher the assessment of risk;

  • Considering significant risks when determining key audit matters (see Chapter 23);

  • If significant risks relate to a component in a group audit, greater involvement of the group engagement partner and team (see Chapter 21).

Note that substantive procedures must be designed and performed for each material class of transactions, account balance and disclosure irrespective of the assessed risks of material misstatement.