Skip to content

Audit and Assurance · Assessing audit risks

Audit Risk Model: Inherent, Control and Detection Risk

Updated 11 October 2026 · Fact-checked

Audit risk is the risk that the auditor gives an inappropriate opinion on financial statements that are materially misstated. It has three components: inherent risk, control risk and detection risk. The first two combine into the risk of material misstatement. The auditor assesses that risk and sets detection risk, and so the amount of testing, to keep audit risk low.

Understand Audit Risk Model

Audit risk is the risk that you express an inappropriate opinion when the financial statements are materially misstated. For example, you give a clean opinion on accounts that contain a material error. You cannot remove this risk. The aim of ISA 200 is to reduce it to an acceptably low level.

Audit risk has three components. The first two, inherent risk and control risk, combine into the risk of material misstatement. Inherent risk is the susceptibility of an item to material misstatement before you consider any controls. Complex estimates, cash, new products and aggressive management targets all raise it. Control risk is the risk that the client's internal controls will not prevent, or detect and correct, a material misstatement on a timely basis. Weak segregation of duties or no review of journals raise it.

Inherent risk and control risk belong to the client. You cannot change them. You assess them together as the risk of material misstatement (RMM). Detection risk is different. It is the risk that your own audit procedures fail to find a material misstatement that exists. You control it through the nature, timing and extent of your work.

The link works like a seesaw. If RMM is high, you must accept a low detection risk. That means more extensive, more reliable, year-end and better-quality evidence, and more experienced staff. If RMM is low, you can accept higher detection risk and do less substantive work. Controls you have tested and found effective support a lower assessed control risk. The client's underlying control risk does not change. The lower assessment allows you to do less substantive testing.

The model is applied at two levels: the financial statements as a whole, and each assertion for each balance or class of transactions. This is why you do not audit every area equally. You focus effort where the risk is highest.

Key rules to remember

Audit risk model
Audit risk = Inherent risk × Control risk × Detection risk
A conceptual model, not a calculation with real figures in most exams. Each component is assessed as high, medium or low.
Risk of material misstatement
RMM = Inherent risk combined with Control risk
ISA 315 (Revised) requires you to assess inherent and control risk separately at assertion level. RMM is the combination of the two. It is a judgement, not an arithmetic product. You carry it into your response.
Link to detection risk
Higher RMM → lower acceptable detection risk → more substantive work
Detection risk is the only component you can change. It is inversely related to RMM.
Controls and risk
Controls tested and effective → support a lower assessed control risk → less substantive testing
Testing does not change the client's actual control risk. It only supports a lower assessment. If controls are weak or not tested, assess control risk as high and rely on substantive procedures.

How to solve Audit Risk Model questions

Use this method for any question on audit risk, whether it asks you to define it, explain it or apply it to a scenario.

  1. 1Read the requirement. Note whether it asks for definitions, risk identification, or the audit response.
  2. 2Define audit risk in one line: giving an inappropriate opinion when the financial statements are materially misstated.
  3. 3Split it into inherent risk, control risk and detection risk. Give a short definition of each.
  4. 4From the scenario, pick out facts that raise inherent risk (complexity, estimates, new systems, pressure) and facts that raise control risk (weak or missing controls).
  5. 5State that inherent and control risk combine into the risk of material misstatement, as a judgement and not a calculation, and say which area or assertion is affected.
  6. 6Explain the effect on detection risk: high RMM means you need low detection risk, so more or better substantive work.
  7. 7Give specific responses: nature (more reliable evidence), timing (at year end), extent (larger samples), and staffing or review.
  8. 8Link each point to the facts given. Do not write generic textbook text.

Quickest way: Fact, risk type, response

When to use it: Use this for Section B scenarios and Section C risk questions when time is short.

  1. Underline each fact in the scenario that signals a problem.
  2. Label it I (inherent) or C (control).
  3. Name the affected balance or assertion, such as inventory existence or revenue occurrence.
  4. Write one response that lowers detection risk: more testing, year-end testing, or senior review.
  5. For objective questions, remember that only detection risk is controlled by the auditor.

Common mistakes in Audit Risk Model

  • Saying the auditor can reduce inherent or control risk.

    Students assume the auditor controls every risk component.

    Fix: Inherent and control risks exist in the client. Only detection risk is changed by your procedures.

  • Mixing up inherent risk and control risk.

    Both describe misstatement and the scenario facts can look alike.

    Fix: Ask whether the problem exists even with perfect controls. If so, it is inherent. If it is about a control failing, it is control risk.

  • Getting the direction of detection risk wrong.

    Students link high risk with high detection risk.

    Fix: High RMM needs low detection risk, which means more testing. Say this in words in your answer.

  • Confusing audit risk with business risk.

    Both words appear in the planning chapter.

    Fix: Business risk is a threat to the client's objectives. Audit risk is about your opinion. Business risks can lead to RMM, but they are not the same.

  • Giving generic responses such as 'do more work'.

    Students run out of time or do not link to the scenario.

    Fix: Specify the nature, timing and extent of the extra work and tie it to the balance affected.

Worked examples

Example 1

Section B style: Rapid Ltd sells electronic goods. It has launched a new accounting system this year, and inventory includes fast-changing models held in six warehouses. Management bonuses depend on profit. Explain which of these facts affect inherent risk and which affect control risk, and the effect on detection risk for inventory.

Show the solution
  1. Inherent risk: fast-changing models raise the risk of obsolescence and overvalued inventory. This exists regardless of controls.
  2. Inherent risk: the profit-based bonus gives management an incentive to overstate inventory and profit.
  3. Control risk: the new accounting system raises the chance that errors are not prevented or detected, because staff are unfamiliar and controls are untested.
  4. Control risk: six warehouses make it harder to apply consistent counting and recording controls.
  5. Combined, the risk of material misstatement for inventory, especially valuation and existence, is high.
  6. Detection risk must therefore be set low, so substantive work must increase.

Answer: Obsolete models and the bonus incentive raise inherent risk. The new system and many warehouses raise control risk. RMM for inventory is high, so detection risk must be low. Respond by attending counts at the main warehouses, testing net realisable value near year end on a larger sample, and using experienced staff with senior review.

Example 2

Explain the audit risk model and how an auditor uses it to plan the audit of a client whose payroll controls are well documented and appear strong, but which holds a complex derivative valuation.

Show the solution
  1. Define audit risk as the risk of an inappropriate opinion when the financial statements are materially misstated. It is made up of inherent, control and detection risk.
  2. Payroll: documented controls that appear strong do not by themselves justify low control risk. You can assess control risk as low only if tests of controls confirm that the controls operate effectively. Payroll is generally not an inherently complex area, so inherent risk is low. RMM is therefore assessed as low only once those tests confirm the controls work.
  3. Once RMM is confirmed as low, detection risk can be higher. Use analytical procedures and limited substantive testing. If the tests of controls fail, assess control risk as high and do more substantive work.
  4. Derivative: a complex valuation involves judgement and estimation, so inherent risk is high. Control risk is also likely high if the client has little expertise.
  5. RMM is high, so detection risk must be low. Use more substantive procedures.
  6. Include responses: use an auditor's expert, test the model inputs to external data, and assign a senior member of the team.
  7. Summarise that effort moves away from payroll towards the derivative.

Answer: Audit risk has three components: inherent, control and detection risk. Payroll RMM is assessed as low only after tests of controls confirm that the controls operate effectively. If they do, less substantive work is needed. The derivative has high inherent risk and likely high control risk, so RMM is high and detection risk must be low. Use an expert, test inputs, and apply senior review. Audit effort is directed to the derivative.

Exam tips

  • Use the exact terms inherent, control and detection risk and define each briefly. Marks are often given for correct definitions.
  • In scenarios, quote the fact and then name the risk type. A fact without a label, or a label without a fact, scores less.
  • Always finish with the effect on audit procedures. Examiners reward responses that are linked to nature, timing and extent.
  • In objective questions, look for the trap: the auditor cannot change inherent or control risk.
  • Do not write about every risk type if the requirement asks for one. Answer the requirement.

Audit Risk Model in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Audit Risk Model: frequently asked questions

What is the difference between inherent risk and control risk?

Inherent risk is the susceptibility of an item to material misstatement before considering controls. Control risk is the risk that the client's controls fail to prevent or detect and correct a misstatement. Complex estimates raise inherent risk. Missing authorisation raises control risk.

Which risk can the auditor control?

Only detection risk. You change it through the nature, timing and extent of your procedures. Inherent and control risk are assessed, not controlled.

Is audit risk a formula I must calculate?

In AA it is a conceptual model. Audit risk = inherent risk × control risk × detection risk. You are not usually asked to multiply numbers. You are asked to explain the relationship and apply it to facts.

How does the audit risk model affect the audit approach?

A higher assessed risk of material misstatement means lower acceptable detection risk, so you do more substantive work, test closer to year end and use more experienced staff. Effective controls let you do less substantive testing.