The audit risk model
Audit Risk (AR) = Inherent Risk (IR) × Control Risk (CR) × Detection Risk (DR)
The auditor doesn't control inherent or control risk — those are properties of the client and its environment. What the auditor does control is detection risk, adjusted by varying the nature, timing, and extent of procedures.
| Risk | What it measures | Auditor's response |
|---|---|---|
| Inherent risk | Susceptibility to misstatement absent any controls (e.g., complex estimates, cash-heavy business) | Assess, don't control |
| Control risk | Risk that a client's internal controls fail to prevent/detect a misstatement | Assess (test controls if relying on them) |
| Detection risk | Risk that the auditor's own procedures fail to detect a material misstatement | Control, by adjusting audit procedures |
The inverse relationship
If inherent and control risk (together, the "risk of material misstatement") are assessed as high, the auditor must accept a lower acceptable detection risk — meaning more extensive, more reliable, and more year-end (rather than interim) procedures.
EXAMPLE: A client has weak segregation of duties over cash receipts (high control risk) and operates in a industry prone to revenue-recognition fraud (high inherent risk). To keep overall audit risk at an acceptably low level, the auditor must plan a very low acceptable detection risk — e.g., 100% confirmation of receivables at year-end rather than a sample tested at an interim date.
Assertions
Risk is assessed at the assertion level for classes of transactions, account balances, and disclosures — not just at the financial-statement level. Key assertions: existence/occurrence, completeness, accuracy/valuation, rights and obligations, presentation and disclosure, and cutoff.
EXAM TIP: A question describing a risk factor is usually testing whether you can map it to the correct assertion. "Goods shipped near year-end recorded in the wrong period" → cutoff. "Fictitious sales recorded" → existence/occurrence. "Sales left off the books" → completeness.