Skip to contentSkip to search

ACCA AAA · Chapter 11

Risk

Your chapter at a glance. Open any section, or keep the whole map in view.

Business risk and the audit risk model

Trace the risk business event to financial statements

Business risk

  • Threatens the entity’s objectives and strategies
  • Management is responsible for managing it

Risk of material misstatement

  • Possible material misstatement in financial statements
  • Arises at financial statement or assertion level

Audit risk

  • Inappropriate opinion on materially misstated statements

Connection

  • Identify whether a business risk affects amounts/disclosures
  • Not every business risk produces a RoMM

Main categories

  • Strategic: competition or unfamiliar markets
  • Financial: borrowings, interest and covenants
  • Operational: defective goods or disrupted systems
  • Compliance: fines, penalties or loss of licence

Audit relevance

  • Understand risks that may cause RoMM or affect going concern
  • Identify affected transaction, balance or disclosure
  • State the direction and nature of possible misstatement

Illustrations

  • Obsolete stock: overstated inventory and profit
  • Defective goods: returns, scrapping and liabilities
  • Covenant pressure: management bias or going concern disclosure

Inherent risk

  • Susceptibility to misstatement before controls
  • Assess likelihood and magnitude

Control risk

  • Controls fail to prevent or detect and correct misstatement

Detection risk

  • Audit procedures fail to detect a misstatement

Risk pathway

  • Event or condition creates inherent risk
  • Failure of relevant controls leaves misstatement in draft statements
  • Audit procedures seek to detect it before the opinion

Higher inherent risk

  • Subjective transactions and complex estimates
  • Complex calculations or changes to business/accounting
  • Significant risk may lie near upper end of spectrum

Relevant controls

  • Review assumptions and estimation uncertainty
  • Segregate duties and independently check transactions
  • Reconcile data, approve transactions and safeguard assets

Timescale

  • Auditor cannot change inherent risk in the short term
  • Control risk may fall later if entity remedies deficiencies

Misstatements, detection risk and responses

Reduce audit risk specific evidence for each assessed risk

Amounts and omissions

  • Materially incorrect amount
  • Omitted amount or required disclosure

Treatment

  • Correct amount may be wrongly classified or presented
  • Disclosures may fail to meet the reporting framework

Evidence and assertions

  • Obtain evidence for amount and its treatment
  • Assets: existence, rights, completeness and valuation
  • Transactions: occurrence, completeness, accuracy and cut-off
  • Also consider classification and presentation

Sampling risk

  • Sample conclusion differs from whole-population conclusion
  • May overrate controls or miss a material misstatement
  • Improve sample design, selection and size

Non-sampling risk

  • Incorrect conclusion unrelated to sampling
  • Wrong procedure, misread evidence or missed misstatement
  • Reduce through skilled staff, direction, supervision and review

Auditor’s control

  • Change nature, timing and extent of procedures
  • Obtain sufficient appropriate evidence to reduce audit risk

Financial statement level

  • Use experienced staff and closer supervision
  • Increase professional scepticism

Control environment

  • Strong environment may support more interim procedures
  • Deficiencies may require more year-end substantive work

Strategy

  • Respond to pervasive risks across the engagement
  • Communicate significant matters to management/TCWG

Target the assessed RoMM

  • Test controls if relying on their operating effectiveness
  • Design substantive procedures responsive to significant risks
  • Obtain more persuasive evidence as assessed risk rises

Specific response

  • Explain change to nature, timing or extent
  • Link procedure to the affected assertion and misstatement
  • Consider group team involvement for component risks

Always required

  • Substantive procedures for every material class of transactions
  • Also for each material balance and disclosure

Want it on paper? Download the PDF, or print this page.