Skip to content

CMA Intermediate · Corporate Accounting and Auditing

Audit Risk, Internal Control, Internal Check and Internal Audit: formula sheet

Full chapter guide

Key formulas

Audit risk model
Audit Risk (AR) = Risk of Material Misstatement (RMM) × Detection Risk (DR)
This is the conceptual form. It is a planning aid, not an exact calculation.
Risk of material misstatement
RMM = Inherent Risk (IR) × Control Risk (CR)
So AR = IR × CR × DR. SA 315 (Revised) treats IR and CR as assessed separately for assertions.
Acceptable detection risk
DR = AR ÷ (IR × CR)
Use it with risks as proportions. Higher assessed IR or CR means lower acceptable DR, so more substantive work.
Direction of response
Higher RMM → lower DR → more, stronger substantive procedures
Lower RMM allows a higher DR and less extensive testing.
Materiality rule
Misstatement is material if it could reasonably influence users' economic decisions
Judge by both amount and nature. A small amount can be material if it hides fraud or a covenant breach.
Objectives of internal control
Reliable reporting + Efficient operations + Legal compliance + Safeguarding of assets
Learn this as the answer to any 'objectives' question. Say that assurance is reasonable, not absolute.
COSO components
Control environment → Risk assessment → Control activities → Information and communication → Monitoring
Memory aid: CRCIM. The control environment is the foundation for the other four.
Inherent limitations
Human error + Collusion + Management override + Cost-benefit + Focus on routine items + Changing conditions
These apply even to well-designed controls, so the auditor cannot rely on controls alone.
Auditor's duty under SA 315
Understand relevant controls = Evaluate design + Determine implementation
Understanding is required for every audit. Testing operating effectiveness is a separate step.
Purpose of evaluation
Control evaluation → assess control risk → decide nature, timing and extent of substantive procedures
Stronger controls mean lower control risk and less substantive work; weaker controls mean the opposite.
Audit risk model
Audit risk = Risk of material misstatement × Detection risk
Risk of material misstatement combines inherent risk and control risk. Control evaluation helps assess control risk.
Questionnaire answer rule
Yes = control present; No = possible weakness
Design questions so that Yes is always the good answer. Each No needs follow-up.
Test of controls vs substantive procedure
Tests of controls → operating effectiveness of controls; Substantive procedures → amounts and disclosures
Substantive procedures include tests of details and analytical procedures.
Meaning of internal check
Internal check = division of work so that one employee's work is checked by another in the routine
Write this as the definition. It is part of internal control, not equal to it.
Core principle
No single person should handle a transaction from start to finish
This is the most important rule. Use it in every application answer.
Separation of functions
Authorisation ≠ Custody ≠ Recording
Different people should approve, hold the asset and record the transaction.
Control vs check
Internal control ⊃ Internal check
Internal control is the wider concept; internal check is one part of it.
Section 138 rule
Prescribed class of company → must appoint internal auditor (CA, CMA or other professional; may be an employee)
Classes and thresholds are in the Companies (Accounts) Rules, 2014. Do not quote figures unless you are sure of them.
Who decides scope and who receives the report
Scope, functions, periodicity, methodology → Audit Committee / Board, in consultation with the internal auditor; report → Audit Committee / Board
Internal auditor reports to those charged with governance, not to shareholders.
Internal vs statutory audit: core contrast
Internal: for management and the board, scope set by Audit Committee/Board, may be an employee | Statutory: for members, scope set by law, independent of management
Use this contrast as the skeleton for any difference question.
SA 610 test before using internal audit work
Objectivity + Competence + Systematic and disciplined approach → then use and test the work
The statutory auditor alone is responsible for the opinion; using the work is not a reference to it in the report.
SA 610 direct assistance
Not prohibited by law or regulation + objectivity and competence evaluated + auditor directs, supervises and reviews → direct assistance permitted
Responsibility for the opinion stays solely with the statutory auditor.

Quick revision

  • Audit risk depends on the risk of material misstatement and the risk that the auditor does not detect it.
  • SA 315 has five internal control components.
  • The five components: control environment, entity's risk assessment process, information system and communication, control activities, monitoring of controls.
  • The control environment sets the tone of the organisation and influences the control consciousness of its people.
  • Manual elements suit judgment, such as large, unusual or non-recurring transactions.
  • Whether the entity's risk assessment process is appropriate is a matter of judgment.
  • Internal check is built into routine work so one person's work is checked by another.
  • A questionnaire asks structured questions; a flow chart shows the process visually.
  • Internal audit scope covers governance, risk management and internal control.
  • Internal audit work that may be used includes testing the operating effectiveness of controls and observing inventory counts.
  • Internal audit's objectives, scope and status vary with the entity's size and structure.
  • Control activities are relevant to the audit based on the risk identified and whether testing them will reduce substantive testing.

Common mistakes

  • Saying the auditor can reduce inherent and control risk by doing more testing. Fix: Inherent and control risks belong to the entity. You assess them. Only detection risk is changed by your procedures.
  • Confusing inherent risk with control risk. Fix: Ask: would the error be likely even with good controls? If yes, inherent. Ask: did controls fail to stop it? If yes, control risk.
  • Saying internal control gives absolute assurance or eliminates fraud. Fix: Always use the words 'reasonable assurance' and add at least two limitations.
  • Confusing internal control with internal check or internal audit. Fix: Treat internal control as the whole system. Internal check is a part of it (division of work so one person's work is checked by another). Internal audit is a monitoring function.
  • Treating tests of controls and substantive procedures as the same thing. Fix: Tests of controls check whether a control worked during the period. Substantive procedures check the figures. Write the objective of each in your answer.
  • Saying a flow chart tests controls. Fix: A flow chart only records the system. Operation is confirmed by a walkthrough and tests of controls.
  • Treating internal check and internal control as the same thing Fix: Say internal control is the whole framework and internal check is one part, the division of duties and cross-checking of work.
  • Writing general points without applying them to the area asked Fix: Name specific roles, such as the cashier, the accountant and the wages clerk, and say who checks whom.
  • Saying internal audit is compulsory for every company. Fix: Write that it applies to prescribed classes of companies only, as per the Companies (Accounts) Rules, 2014.
  • Writing that the internal auditor reports to shareholders. Fix: Say the internal auditor reports to the audit committee or board, as agreed in the engagement scope.

Exam tips

  • For MCQs, first spot which of the three risks the sentence describes. Wording about the entity's business points to inherent risk, and wording about controls failing points to control risk.
  • In theory answers, always draw the link between assessed risk and the nature, timing and extent of procedures. This earns the marks examiners look for.
  • Write the model as AR = IR × CR × DR and show decimal conversion in numericals. Step marks depend on it.
  • Mention SA 315 (Revised) for identifying and assessing risks and SA 330 for responses, but only as references. Do not quote paragraph numbers.
  • Add a line on materiality when the question gives amounts. Compare the misstatement with the materiality level and consider its nature.
  • Open every theory answer with 'process' and 'reasonable assurance'. These words show examiners you know the standard definition.
  • For MCQs, watch for options that claim 'absolute assurance', 'eliminates fraud' or 'auditor designs controls'. These are usually wrong.
  • In case-based questions, name the COSO component beside each fact. Naming earns marks even when your explanation is short.