Skip to content

CA Intermediate · Auditing and Ethics

Risk Assessment and Internal Control: formula sheet

Full chapter guide

Key formulas

Overall audit strategy
Overall audit strategy = scope + timing + direction of the audit
It sets the framework and guides the detailed audit plan. It is generally established first, but the two are closely inter-related.
Audit plan
Audit plan = risk assessment procedures + further audit procedures + other procedures required by SAs
For each, state nature, timing and extent. Plan is more detailed than strategy.
Strategy contents (SA 300, para 8)
(a) Characteristics of the engagement that define its scope; (b) reporting objectives, timing of the audit and nature of communications; (c) significant factors that determine the direction of the team's efforts, including, as applicable, determining appropriate materiality and preliminary identification of areas of higher risk of material misstatement, preliminary activities and knowledge gained on other engagements; (d) nature, timing and extent of resources
Use these four heads from SA 300 para 8 to organise any 'contents of overall audit strategy' answer.
Documentation under SA 300
Document: overall audit strategy, audit plan, significant changes made during the audit and reasons
Missing this point loses easy marks.
Nature of planning
Planning = continual and iterative process
It is not a discrete phase after the engagement is accepted.
Audit risk model
Audit Risk = Risk of Material Misstatement × Detection Risk
This is a conceptual relationship, not a calculation tool. RMM is made up of inherent risk and control risk.
Components of RMM
RMM = Inherent Risk and Control Risk
SA 315 (Revised 2019) requires separate assessment of inherent risk and control risk at the assertion level.
Risk assessment procedures
Inquiries + Analytical procedures + Observation and inspection
Remember all three. Inquiry alone is not enough. These procedures do not by themselves give sufficient evidence for the opinion.
Relationship of risk to detection risk
Higher RMM → Lower acceptable detection risk → More extensive substantive work
Detection risk is inversely related to assessed RMM.
Audit risk model
Audit risk = Risk of material misstatement × Detection risk
RMM = Inherent risk × Control risk. It is a conceptual relationship, not a precise calculation in the exam.
Risk of material misstatement
RMM = Inherent risk × Control risk
Both exist independently of the audit. The auditor assesses them but cannot change them.
Detection risk relationship
Higher RMM ⇒ lower acceptable detection risk
Lower detection risk means more or better substantive procedures.
Benchmark-based materiality
Materiality = Benchmark × Chosen percentage
Percentage is a matter of judgment. SA 320 does not fix a percentage.
Performance materiality
Performance materiality < Materiality for the financial statements as a whole
Set to cover aggregation of uncorrected and undetected misstatements.
Revision of materiality
Revise if new information arises during the audit
If the revised level is lower, reconsider performance materiality and the nature, timing and extent of further procedures.
Five components of internal control (SA 315)
Control environment + Entity's risk assessment process + Process to monitor the system of internal control + Information system and communication + Control activities
Write all five by name, in the order SA 315 (Revised 2019) gives them.
Objectives of internal control
Reliable financial reporting + Effective and efficient operations + Compliance with laws and regulations
Safeguarding of assets is usually discussed under operations.
Level of assurance
Internal control gives reasonable assurance, not absolute assurance
Reason: inherent limitations such as human error, collusion, management override and cost-benefit.
Responsibility
Design, implementation and maintenance of internal control = management and those charged with governance; understanding and evaluating it for audit = auditor
Use this line to answer questions on who is responsible.
Auditor's duty on IFC
Section 143(3)(i): report whether adequate IFC with reference to financial statements exist AND whether they operate effectively
Both limbs must appear in your answer: adequacy and operating effectiveness. The duty applies to all companies, subject to exemptions. The report is given in a separate Annexure to the auditor's report.
Directors' responsibility
Section 134(5)(e): directors of a listed company lay down IFC and ensure they are adequate and operating effectively. Section 134(3)(q) read with Rule 8(5)(viii) of the Companies (Accounts) Rules, 2014: the Board's report of every company states the adequacy of IFC
Responsibility for IFC is management's. The auditor only reports.
Tests of controls vs substantive procedures
Tests of controls → whether controls operated effectively. Substantive procedures → whether amounts and disclosures are misstated (tests of details + substantive analytical procedures)
Results of tests of controls decide how much substantive testing you need.
Walkthrough
Walkthrough = trace one transaction end to end using inquiry, observation and inspection
Confirms understanding and design. It does not alone prove operating effectiveness.
ICQ versus ICE
ICQ = questions asking whether specific controls exist (Yes/No/N/A); ICE = questions asking whether control objectives are met, i.e. whether an error or fraud could occur and go undetected given the controls in place
Tell them apart by the type of question: ICQ asks "Is there a control?", ICE asks "Could this error or fraud happen undetected?". ICQ is often answered by client staff and reviewed by the auditor, but do not treat this as a rule.
Reading an ICQ
Yes = control present; No = possible weakness; N/A = question not relevant
Every "No" should be followed up and its effect on audit procedures considered.
Purpose of a flowchart
Flowchart = graphic record of the flow of documents and activities in a process
It helps spot gaps, duplication and missing checks.
SA 230 objective
Documentation must let an experienced auditor with no previous connection understand the work done, the evidence and the conclusions
This is the test of sufficiency of documentation.
Matters SA 230 expects to be recorded
Nature, timing and extent of procedures + who performed and when + who reviewed and when + results and conclusions
Also record significant matters, judgments and discussions with management.

Quick revision

  • The overall audit strategy sets scope, timing and direction; the audit plan details the procedures to carry out.
  • Planning is a continuous process and not a single early step. Revise the plan when circumstances change.
  • Risk assessment procedures include inquiries, analytical procedures, and observation and inspection.
  • Audit risk = risk of material misstatement × detection risk, and risk of material misstatement combines inherent risk and control risk.
  • The auditor cannot influence the entity's inherent and control risk, only assess them, and then sets detection risk through the nature, timing and extent of procedures.
  • Higher assessed risk means more extensive and more reliable substantive procedures.
  • Materiality is a matter of professional judgment and depends on both size and nature of the item.
  • Performance materiality is set below overall materiality to reduce the chance that uncorrected errors add up to a material amount.
  • Internal control has five components: control environment, entity's risk assessment process, information system and communication, control activities, and monitoring of controls.
  • Internal control has inherent limitations, such as human error, collusion, management override and cost-benefit considerations.
  • A walkthrough test follows one transaction from start to finish through the process to confirm understanding of the controls.
  • Section 143(3)(i) of the Companies Act, 2013 requires the auditor's report to state whether the company has an adequate internal financial controls system with reference to financial statements and whether it operates effectively. Certain private companies (one-person companies, small companies, and specified low-turnover, low-borrowing private companies) are exempt from this reporting by MCA notification.
  • Documentation should be enough for an experienced auditor with no prior link to the audit to understand the work done and the conclusions reached.

Common mistakes

  • Treating overall audit strategy and audit plan as the same thing. Fix: Say strategy sets scope, timing and direction. Say plan details the nature, timing and extent of procedures. Keep them in separate paragraphs.
  • Saying planning is done only at the start of the audit. Fix: Write that planning is continual and iterative, and the strategy and plan are updated as the audit proceeds.
  • Saying inquiry is enough to understand the entity. Fix: Always list all three: inquiries, analytical procedures, observation and inspection. Add that inquiry alone is not sufficient.
  • Treating detection risk as a risk of the entity. Fix: Inherent and control risk exist independently of the audit. Detection risk depends on the auditor's procedures and can be changed by the auditor.
  • Saying the auditor can reduce inherent or control risk. Fix: Remember that inherent and control risk exist in the entity. The auditor only assesses them and responds through detection risk.
  • Treating audit risk and materiality as the same thing. Fix: Materiality is the size threshold. Audit risk is the chance of giving a wrong opinion. Say this in one line when asked for the difference.
  • Using the component names from the earlier version of SA 315 in an answer written under SA 315 (Revised 2019). Fix: The earlier version used names such as 'information system, including related business processes, relevant to financial reporting, and communication', 'control activities relevant to the audit' and 'monitoring of controls'. The revised SA 315 uses 'information system and communication', 'control activities' and 'process to monitor the system of internal control'. The entity's risk assessment process kept the same name in both versions. Write the revised names.
  • Saying internal control gives absolute assurance or prevents all fraud. Fix: Always write reasonable assurance and add that inherent limitations stop it from being absolute.
  • Saying the auditor is responsible for designing and maintaining IFC. Fix: Write: directors of a listed company lay down and maintain IFC (Section 134(5)(e)), and the Board's report of every company covers the adequacy of IFC (Rule 8(5)(viii)); the auditor evaluates and reports under Section 143(3)(i).
  • Writing only about adequacy and forgetting operating effectiveness. Fix: Always give both limbs, and explain the difference with a one-line example.

Exam tips

  • Short notes on SA 300 are common. Open with the objective, then give contents under heads, then close with documentation.
  • For difference questions, give at least four clear points and keep both sides parallel.
  • In case-based questions, name the fact from the scenario and say whether it affects strategy, plan or both.
  • In MCQs, treat words like 'only', 'never' or 'one-time' about planning with caution. Check the option against SA 300 (planning is continual and iterative) instead of rejecting it automatically.
  • Link planning to risk in every answer, because it shows you understand why the auditor plans.
  • Write the three procedures by name every time. Examiners look for the list.
  • In case-based questions, split the risk into inherent and control risk, then link it to the response. This structure earns step marks.
  • Be sure of who owns each risk: detection risk is the auditor's. MCQs often test this.