CMA Intermediate · Corporate Accounting and Auditing
Audit Risk, Internal Control, Internal Check and Internal Audit: formula sheet
Key formulas
- Audit risk model
- Audit Risk (AR) = Risk of Material Misstatement (RMM) × Detection Risk (DR)
- This is the conceptual form. It is a planning aid, not an exact calculation.
- Risk of material misstatement
- RMM = Inherent Risk (IR) × Control Risk (CR)
- So AR = IR × CR × DR. SA 315 (Revised) treats IR and CR as assessed separately for assertions.
- Acceptable detection risk
- DR = AR ÷ (IR × CR)
- Use it with risks as proportions. Higher assessed IR or CR means lower acceptable DR, so more substantive work.
- Direction of response
- Higher RMM → lower DR → more, stronger substantive procedures
- Lower RMM allows a higher DR and less extensive testing.
- Materiality rule
- Misstatement is material if it could reasonably influence users' economic decisions
- Judge by both amount and nature. A small amount can be material if it hides fraud or a covenant breach.
- Objectives of internal control
- Reliable reporting + Efficient operations + Legal compliance + Safeguarding of assets
- Learn this as the answer to any 'objectives' question. Say that assurance is reasonable, not absolute.
- COSO components
- Control environment → Risk assessment → Control activities → Information and communication → Monitoring
- Memory aid: CRCIM. The control environment is the foundation for the other four.
- Inherent limitations
- Human error + Collusion + Management override + Cost-benefit + Focus on routine items + Changing conditions
- These apply even to well-designed controls, so the auditor cannot rely on controls alone.
- Auditor's duty under SA 315
- Understand relevant controls = Evaluate design + Determine implementation
- Understanding is required for every audit. Testing operating effectiveness is a separate step.
- Purpose of evaluation
- Control evaluation → assess control risk → decide nature, timing and extent of substantive procedures
- Stronger controls mean lower control risk and less substantive work; weaker controls mean the opposite.
- Audit risk model
- Audit risk = Risk of material misstatement × Detection risk
- Risk of material misstatement combines inherent risk and control risk. Control evaluation helps assess control risk.
- Questionnaire answer rule
- Yes = control present; No = possible weakness
- Design questions so that Yes is always the good answer. Each No needs follow-up.
- Test of controls vs substantive procedure
- Tests of controls → operating effectiveness of controls; Substantive procedures → amounts and disclosures
- Substantive procedures include tests of details and analytical procedures.
- Meaning of internal check
- Internal check = division of work so that one employee's work is checked by another in the routine
- Write this as the definition. It is part of internal control, not equal to it.
- Core principle
- No single person should handle a transaction from start to finish
- This is the most important rule. Use it in every application answer.
- Separation of functions
- Authorisation ≠ Custody ≠ Recording
- Different people should approve, hold the asset and record the transaction.
- Control vs check
- Internal control ⊃ Internal check
- Internal control is the wider concept; internal check is one part of it.
- Section 138 rule
- Prescribed class of company → must appoint internal auditor (CA, CMA or other professional; may be an employee)
- Classes and thresholds are in the Companies (Accounts) Rules, 2014. Do not quote figures unless you are sure of them.
- Who decides scope and who receives the report
- Scope, functions, periodicity, methodology → Audit Committee / Board, in consultation with the internal auditor; report → Audit Committee / Board
- Internal auditor reports to those charged with governance, not to shareholders.
- Internal vs statutory audit: core contrast
- Internal: for management and the board, scope set by Audit Committee/Board, may be an employee | Statutory: for members, scope set by law, independent of management
- Use this contrast as the skeleton for any difference question.
- SA 610 test before using internal audit work
- Objectivity + Competence + Systematic and disciplined approach → then use and test the work
- The statutory auditor alone is responsible for the opinion; using the work is not a reference to it in the report.
- SA 610 direct assistance
- Not prohibited by law or regulation + objectivity and competence evaluated + auditor directs, supervises and reviews → direct assistance permitted
- Responsibility for the opinion stays solely with the statutory auditor.
Quick revision
- Audit risk depends on the risk of material misstatement and the risk that the auditor does not detect it.
- SA 315 has five internal control components.
- The five components: control environment, entity's risk assessment process, information system and communication, control activities, monitoring of controls.
- The control environment sets the tone of the organisation and influences the control consciousness of its people.
- Manual elements suit judgment, such as large, unusual or non-recurring transactions.
- Whether the entity's risk assessment process is appropriate is a matter of judgment.
- Internal check is built into routine work so one person's work is checked by another.
- A questionnaire asks structured questions; a flow chart shows the process visually.
- Internal audit scope covers governance, risk management and internal control.
- Internal audit work that may be used includes testing the operating effectiveness of controls and observing inventory counts.
- Internal audit's objectives, scope and status vary with the entity's size and structure.
- Control activities are relevant to the audit based on the risk identified and whether testing them will reduce substantive testing.
Common mistakes
- Saying the auditor can reduce inherent and control risk by doing more testing. Fix: Inherent and control risks belong to the entity. You assess them. Only detection risk is changed by your procedures.
- Confusing inherent risk with control risk. Fix: Ask: would the error be likely even with good controls? If yes, inherent. Ask: did controls fail to stop it? If yes, control risk.
- Saying internal control gives absolute assurance or eliminates fraud. Fix: Always use the words 'reasonable assurance' and add at least two limitations.
- Confusing internal control with internal check or internal audit. Fix: Treat internal control as the whole system. Internal check is a part of it (division of work so one person's work is checked by another). Internal audit is a monitoring function.
- Treating tests of controls and substantive procedures as the same thing. Fix: Tests of controls check whether a control worked during the period. Substantive procedures check the figures. Write the objective of each in your answer.
- Saying a flow chart tests controls. Fix: A flow chart only records the system. Operation is confirmed by a walkthrough and tests of controls.
- Treating internal check and internal control as the same thing Fix: Say internal control is the whole framework and internal check is one part, the division of duties and cross-checking of work.
- Writing general points without applying them to the area asked Fix: Name specific roles, such as the cashier, the accountant and the wages clerk, and say who checks whom.
- Saying internal audit is compulsory for every company. Fix: Write that it applies to prescribed classes of companies only, as per the Companies (Accounts) Rules, 2014.
- Writing that the internal auditor reports to shareholders. Fix: Say the internal auditor reports to the audit committee or board, as agreed in the engagement scope.
Exam tips
- For MCQs, first spot which of the three risks the sentence describes. Wording about the entity's business points to inherent risk, and wording about controls failing points to control risk.
- In theory answers, always draw the link between assessed risk and the nature, timing and extent of procedures. This earns the marks examiners look for.
- Write the model as AR = IR × CR × DR and show decimal conversion in numericals. Step marks depend on it.
- Mention SA 315 (Revised) for identifying and assessing risks and SA 330 for responses, but only as references. Do not quote paragraph numbers.
- Add a line on materiality when the question gives amounts. Compare the misstatement with the materiality level and consider its nature.
- Open every theory answer with 'process' and 'reasonable assurance'. These words show examiners you know the standard definition.
- For MCQs, watch for options that claim 'absolute assurance', 'eliminates fraud' or 'auditor designs controls'. These are usually wrong.
- In case-based questions, name the COSO component beside each fact. Naming earns marks even when your explanation is short.