ACCA AAA · Chapter 11
Risk
Your chapter at a glance. Open any section, or keep the whole map in view.
Business risk and the audit risk model
Trace the risk business event to financial statements
Business risk
- Threatens the entity’s objectives and strategies
- Management is responsible for managing it
Risk of material misstatement
- Possible material misstatement in financial statements
- Arises at financial statement or assertion level
Audit risk
- Inappropriate opinion on materially misstated statements
Connection
- Identify whether a business risk affects amounts/disclosures
- Not every business risk produces a RoMM
Main categories
- Strategic: competition or unfamiliar markets
- Financial: borrowings, interest and covenants
- Operational: defective goods or disrupted systems
- Compliance: fines, penalties or loss of licence
Audit relevance
- Understand risks that may cause RoMM or affect going concern
- Identify affected transaction, balance or disclosure
- State the direction and nature of possible misstatement
Illustrations
- Obsolete stock: overstated inventory and profit
- Defective goods: returns, scrapping and liabilities
- Covenant pressure: management bias or going concern disclosure
Inherent risk
- Susceptibility to misstatement before controls
- Assess likelihood and magnitude
Control risk
- Controls fail to prevent or detect and correct misstatement
Detection risk
- Audit procedures fail to detect a misstatement
Risk pathway
- Event or condition creates inherent risk
- Failure of relevant controls leaves misstatement in draft statements
- Audit procedures seek to detect it before the opinion
Higher inherent risk
- Subjective transactions and complex estimates
- Complex calculations or changes to business/accounting
- Significant risk may lie near upper end of spectrum
Relevant controls
- Review assumptions and estimation uncertainty
- Segregate duties and independently check transactions
- Reconcile data, approve transactions and safeguard assets
Timescale
- Auditor cannot change inherent risk in the short term
- Control risk may fall later if entity remedies deficiencies
Misstatements, detection risk and responses
Reduce audit risk specific evidence for each assessed risk
Amounts and omissions
- Materially incorrect amount
- Omitted amount or required disclosure
Treatment
- Correct amount may be wrongly classified or presented
- Disclosures may fail to meet the reporting framework
Evidence and assertions
- Obtain evidence for amount and its treatment
- Assets: existence, rights, completeness and valuation
- Transactions: occurrence, completeness, accuracy and cut-off
- Also consider classification and presentation
Sampling risk
- Sample conclusion differs from whole-population conclusion
- May overrate controls or miss a material misstatement
- Improve sample design, selection and size
Non-sampling risk
- Incorrect conclusion unrelated to sampling
- Wrong procedure, misread evidence or missed misstatement
- Reduce through skilled staff, direction, supervision and review
Auditor’s control
- Change nature, timing and extent of procedures
- Obtain sufficient appropriate evidence to reduce audit risk
Financial statement level
- Use experienced staff and closer supervision
- Increase professional scepticism
Control environment
- Strong environment may support more interim procedures
- Deficiencies may require more year-end substantive work
Strategy
- Respond to pervasive risks across the engagement
- Communicate significant matters to management/TCWG
Target the assessed RoMM
- Test controls if relying on their operating effectiveness
- Design substantive procedures responsive to significant risks
- Obtain more persuasive evidence as assessed risk rises
Specific response
- Explain change to nature, timing or extent
- Link procedure to the affected assertion and misstatement
- Consider group team involvement for component risks
Always required
- Substantive procedures for every material class of transactions
- Also for each material balance and disclosure
Want it on paper? Download the PDF, or print this page.
