You assess inherent risk as high and control risk as high for revenue. Detection risk has to drop, the audit budget you set assuming moderate risk is now wrong, and the entire plan needs to change. The exam will ask you exactly what changes and in what order.
Every planning decision flows from this equation:
AR = IR x CR x DR
Audit risk is the risk that you express an inappropriate opinion when the financial statements are materially misstated. Firms typically set audit risk at a low level, often 5%.
Inherent risk is the susceptibility of an assertion to material misstatement before considering internal controls. Five factors push it up: complexity, subjectivity, change, uncertainty, and susceptibility to management bias. Cash is low IR. Fair-value derivatives are high IR.
Control risk is the risk that internal controls fail to prevent or detect a material misstatement on a timely basis. You assess it based on the design and operating effectiveness of the entity's controls.
Common mistakes
- Confusing inherent risk and control risk. A complex fair-value estimate is an inherent risk factor (susceptibility of the assertion). A missing approval process for journal entries is a control risk factor (weakness in the system). Read for complexity/subjectivity (IR) versus controls failing (CR).
- Treating detection risk as something you assess, not set. You assess IR and CR. You set DR as the consequence. The trap choice "detection risk is high because the entity has weak controls" confuses CR with DR. Weak controls raise CR, which forces DR down, not up.
- Forgetting that management override is always a risk. Even with perfect controls, management can override them. The three required procedures (journal entries, estimate bias, unusual transaction rationale) apply on every audit. Trap: "no further procedures needed because controls operate effectively."
Bottom line
- Audit Risk = Inherent Risk x Control Risk x Detection Risk. Detection risk is the only component the auditor sets, as a consequence of the IR and CR assessments.
- Risk of material misstatement (RMM) = IR x CR. Assess it at both the financial statement level (pervasive) and the assertion level (targeted).
- Higher RMM means lower acceptable DR, which means more evidence, more experienced staff, larger samples, and more year-end (vs interim) testing.
- Significant risks require special audit consideration and cannot be addressed solely by tests of controls. Five categories: fraud risks, significant unusual transactions, related party transactions outside the normal course, revenue recognition, and high-uncertainty estimates.
Exam shortcut
Run the two-step classifier on every risk scenario. Step 1: inherent (complexity, subjectivity, change) or control (weakness in the system)? Step 2: pervasive (financial statement level) or specific (assertion level)? That eliminates half the wrong answers before you read them. For fraud questions, map every fact to the triangle, pressure, opportunity, or rationalization. All three corners present means elevated risk and a significant-risk response on revenue.
The full lesson (about 5,853 words, 39 min read) adds 8 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- II.E1
Browse all free CPA AUD lessons or jump into free CPA AUD practice questions.