Audit Risk & Internal Control

Medium

Find each AUD term hidden in the grid. Selecting a word reveals its definition and a link to study it in depth.

8 terms · Choose how you want to study

New to the CPA Exam (Core Sections) exam? Read our how-to-pass guide →

Study modes

Terms in this set

Audit Risk Model

The framework expressing audit risk as the product of inherent risk, control risk, and detection risk.

AUD loves to hold audit risk constant and move one input: if inherent and control risk rise, the acceptable detection risk falls, forcing more persuasive evidence — more effective procedures, year-end rather than interim timing, and larger sample sizes. The “tell” is any prompt asking how an assessment change affects evidence; the answer almost always hinges on this inverse relationship between detection risk and the risk of material misstatement. Inherent risk and control risk combine into RMM, the assessment that actually drives planning (under SAS 145 you assess the two separately, not as one blended number).

The classic trap is treating all three as auditor-set. The auditor assesses inherent and control risk (they exist in the client and its controls) but only sets detection risk by altering the nature, timing, and extent of substantive testing — don’t confuse assessing with controlling. Another snare: students lower detection risk yet pick “decrease testing,” reversing the logic. Memory hook: detection risk and substantive evidence move in opposite directions — push detection risk down, push evidence up.

Inherent Risk

The susceptibility of an assertion to material misstatement before considering any related controls.

AUD loves to test inherent risk by giving you a scenario and asking which account or assertion carries higher susceptibility. The “tell” is anything complex, subjective, uncertain, or non-routine — fair-value estimates, related-party transactions, year-end pressure (management bias), or liquid, easily-misappropriated assets. SAS 145 made this a separate assessment at the assertion level, plotted on a “spectrum of inherent risk” that combines the likelihood and magnitude of misstatement, so the higher answer is the assertion sitting near the top of both.

The classic trap is conflating risks the auditor only assesses with the one it controls. Inherent risk and control risk are entity-driven and exist regardless of the audit; together they form the risk of material misstatement (IR × CR). The auditor can’t change them — it adjusts only detection risk in the audit risk model to hit acceptably low audit risk. Watch the wording: inherent risk is judged “before considering controls,” while control risk asks whether controls would catch the error. Memory hook: inherent = innate.

Control Risk

The risk that a material misstatement will not be prevented or detected on a timely basis by internal control.

Expect AUD to give a fact pattern and ask what happens to the rest of the model when assessed control risk changes. The “tell”: a clue about controls (well-designed and operating, or weak/overridden), then a question about substantive testing. The answer hinges on the inverse relationship — because acceptable detection risk is set inversely to the assessed risk of material misstatement, a lower control risk permits a higher detection risk, so the auditor can do less substantive work; high control risk forces detection risk down and pushes testing toward year-end, larger samples, and more reliable evidence. To assess control risk below maximum, you must test operating effectiveness of controls — understanding alone never lowers it (no test of controls means control risk stays at maximum).

The classic trap is swapping it with inherent risk: control risk is about whether controls catch a misstatement, inherent risk exists before controls; together they form RMM, which the entity owns (SAS 145 now requires assessing the two separately). Detection risk is the only piece the auditor controls. Memory hook: inherent and control are the client’s risks; detection is yours. Don’t say the auditor “sets” control risk — they assess it.

Detection Risk

The risk that the auditor's procedures fail to detect a material misstatement that exists.

AUD item-writers love a fact pattern where the risk of material misstatement (RMM = inherent risk × control risk) is assessed high, then ask what the auditor does. The answer hinges on the inverse relationship: holding audit risk constant, a higher RMM forces a lower acceptable detection risk, achieved through more persuasive evidence — more effective procedures, substantive work shifted from interim toward year-end, and larger sample sizes. The classic “tell” is a stem listing account characteristics; read them as IR/CR drivers, not detection-risk levers.

The trap is misattributing control. Only detection risk’s acceptable level is the auditor’s direct lever, set through procedures; inherent and control risk are assessed, not set by fiat. The auditor can never reduce inherent risk, and control risk drops below maximum only when controls are tested and found operating effectively (per SAS 145). Students also flip the relationship, wrongly raising detection risk as RMM rises. Memory hook: detection risk is the “do-it-yourself” component you control through your work; inherent and control risk are conditions you only evaluate.

Materiality

The threshold at which there is a substantial likelihood that a misstatement or omission would influence the judgment made by a reasonable user based on the financial statements.

AUD item-writers test the three layers and force you to keep them straight: overall (planning) materiality for the statements as a whole, performance materiality set lower to reduce the chance that the aggregate of uncorrected and undetected misstatements exceeds overall materiality, and the clearly trivial threshold (an AU-C 450 concept, typically a few percent of materiality) below which items need not be accumulated. The classic stem gives a benchmark and asks for a percentage — often ~5% of pretax income, switching to revenue or total assets when earnings are volatile or near break-even. The “tell”: when results swing wildly, the answer abandons income for a more stable benchmark.

Do not confuse materiality with the audit risk model: materiality sizes what matters, while inherent/control/detection risk sizes the chance of missing it — and because detection risk moves inversely to materiality, a lower materiality demands more testing. It also differs from audit evidence, the information gathered, not the threshold that scopes how much you need. The trap students fall for: treating materiality as a fixed number rather than revising it — usually downward — when audit findings or revised expectations warrant.

Internal Control

The processes designed to provide reasonable assurance about reliable reporting, effective operations, and compliance.

AUD items hinge on one rule: obtaining an understanding of internal control is required on every audit, but testing operating effectiveness is optional. When a fact pattern asks what the auditor “must” do, the answer is almost always evaluate the design and determine whether controls are implemented (via inquiry, observation, inspection, and often a walkthrough), not test them. Auditors test controls only when they plan to rely on them, or when substantive procedures alone cannot reduce risk to an acceptably low level (e.g., highly automated, paperless processing). The classic trap: confusing design and implementation (always assessed) with operating effectiveness (tested only on reliance).

Don’t blur internal control with control risk — internal control is the system; control risk is the risk that a material misstatement won’t be prevented, or detected and corrected timely by that system. Controls map to management assertions and the COSO components. COSO mnemonic — CRIME: Control environment, Risk assessment, Information & communication, Monitoring, Existing (control) activities. The control environment is the foundation (“tone at the top”); a weak one taints every other component.

COSO Framework

A widely used internal control framework built on five integrated components.

AUD loves to make you match a control to its component or pick which component a described weakness belongs to. The classic tell: a question describes “tone at the top,” ethical values, or board oversight, and you must label it control environment (the foundation, not a control activity). Reconciliations, approvals, and segregation of duties are control activities; whistleblower hotlines and separate reporting lines are information and communication (Principle 14). The 2013 framework codified 17 principles mapped to the five components, and all five components plus relevant principles must be present and functioning—and operating together in an integrated manner—for internal control to be effective.

The trap is confusing the five components with the three objective categories the COSO cube tracks: operations, reporting, and compliance (the cube’s third face is entity structure). To lock the components, try CRIME—Control environment, Risk assessment, Information and communication, Monitoring, and control Existence (control activities)—or any mnemonic that keeps all five straight, since AUD rewards labeling them cold.

Management Assertions

The implicit or explicit representations management makes in the financial statements, such as existence and completeness.

AUD items almost always make you match a procedure to the assertion it actually tests, and the favorite trap is direction of testing: tracing from source documents forward into the ledger tests completeness (understatement risk), while vouching from the ledger back to support tests existence/occurrence (overstatement risk). The “tell” is which population you start from. Item-writers split assertions into three groups: classes of transactions (occurrence, completeness, accuracy, cutoff, classification), account balances (existence, completeness, valuation/allocation, rights and obligations), and presentation and disclosure (occurrence and rights, completeness, classification/understandability, accuracy/valuation). (SAS 145 now folds disclosures into the other two, but most banks still teach the three buckets.)

Don’t confuse the assertion (what management claims) with the audit evidence that tests it or the internal control that should prevent the misstatement — the procedure links them. Classic error: picking “existence” when the risk is omitted liabilities, which is completeness. Hook: “Existence = is it real? Completeness = is it all there?” Confirming receivables tests existence and rights, not completeness.