Skip to content

Audit and Assurance · Audit planning and documentation

Audit Risk and Risk of Material Misstatement Explained for ACCA

Updated 11 October 2026

Audit risk is the risk that the auditor gives an inappropriate opinion when the financial statements are materially misstated. It equals the risk of material misstatement (inherent risk × control risk) combined with detection risk. You assess the risks, then design procedures that respond to them.

Understand Audit Risk and Risk of Material Misstatement

Auditors cannot check everything, so they focus effort where errors are most likely. Audit risk is the risk of expressing an inappropriate opinion on financial statements that are materially misstated. Your job is to keep this risk at an acceptably low level.

Audit risk has two parts. The first is the risk of material misstatement (RMM), which exists before the audit and is the client's risk. The second is detection risk, the risk that your procedures fail to find a material misstatement. You control detection risk. You do not control RMM. The multiplied form of the model is conceptual only. It shows how the parts relate, and you do not calculate it with numbers.

RMM has two components. Inherent risk is the susceptibility of an assertion to material misstatement before considering any controls. It is high for estimates, complex transactions, new or unusual items, and industries with rapid change. Control risk is the risk that the client's internal controls will not prevent, or detect and correct, a material misstatement on a timely basis. Weak segregation of duties or no review of journals raises it. ISA 315 (Revised 2019) requires you to assess the two separately at assertion level.

The link is inverse. If RMM is high, you need detection risk to be low. To lower detection risk you do more work: larger samples, more substantive procedures, more experienced staff, testing nearer year end, and more evidence from external sources.

A significant risk is an identified and assessed RMM that, in your judgement, needs special audit consideration. Fraud risks, revenue recognition (a presumed fraud risk under ISA 240), related party transactions outside normal business, and highly judgemental estimates are typical. For significant risks you must obtain an understanding of the controls relevant to the risk, evaluate their design and determine whether they have been implemented. If your approach relies on those controls, you must test them in the current period (ISA 330). You also need substantive procedures that respond specifically to the risk. These must include tests of details. Substantive analytical procedures alone are not sufficient. Risk assessment under ISA 315 is done at financial statement level and at assertion level, and you revisit it as the audit goes on.

Key rules to remember

Audit risk model
Audit risk = Risk of material misstatement × Detection risk
It is a conceptual model, not a calculation you must perform with numbers. Use it to explain relationships.
Risk of material misstatement
RMM = Inherent risk × Control risk
This is also conceptual, not a calculation. Inherent and control risk exist independently of the audit. ISA 315 (Revised 2019) requires them to be assessed separately at assertion level.
Inverse relationship
Higher RMM → lower acceptable detection risk → more extensive audit procedures
Use this chain when the question asks how the audit approach changes.
Significant risk
Significant risk = assessed RMM needing special audit consideration
Respond by understanding the relevant controls (evaluate their design and determine their implementation). If you plan to rely on those controls, test them in the current period. Also perform substantive procedures that address the specific risk, including tests of details. Substantive analytical procedures alone are not sufficient.

How to solve Audit Risk and Risk of Material Misstatement questions

Use this approach for any scenario asking you to identify, assess or respond to audit risks.

  1. 1Read the scenario and underline facts that suggest risk: new systems, estimates, pressure on management, unusual transactions, weak controls, growth, or change in staff.
  2. 2For each fact, state the risk in one sentence: what could be misstated, in which balance or disclosure, and in which direction (overstated or understated).
  3. 3Classify it: inherent risk (nature of the item or business), control risk (weak or missing controls), or both. Say which one clearly.
  4. 4Judge whether it is significant, for example fraud, revenue, judgemental estimates or unusual transactions. Justify with a reason.
  5. 5Explain the effect on the audit: higher risk means lower detection risk, so more or better evidence.
  6. 6Give a specific response: the procedure, its nature, timing or extent, and which assertion it covers.
  7. 7Check you have linked each risk to the scenario and not given a textbook list. Keep the same order for each risk.

Quickest way: Risk, Why, Response in three lines

When to use it: Use this in Section B or OT case questions when time is short and the question asks for risks and responses.

  1. Write the risk: 'Inventory may be overstated because...' using a scenario fact.
  2. Write the reason in one phrase and tag it as inherent or control.
  3. Write one targeted procedure: 'Attend the count and test cut-off.'
  4. Move on. Marks are awarded for points made. A risk, its explanation and a well-targeted response each tend to earn credit, but there is no fixed mark per point.
  5. For OT questions, match the wording to the model: inherent is about the item, control is about the client's systems, detection is about the auditor's work.

Common mistakes in Audit Risk and Risk of Material Misstatement

  • Saying the auditor can reduce inherent risk or control risk.

    Students mix up risks the auditor influences with those they only assess.

    Fix: The auditor assesses inherent and control risk. Only detection risk is managed by changing procedures.

  • Listing risks without linking them to the scenario.

    Students recite generic risks from memory.

    Fix: Quote or use a specific fact from the scenario in every risk. Generic points earn little.

  • Confusing business risk with risk of material misstatement.

    Both words contain 'risk' and both arise from the client's situation.

    Fix: Business risk is a threat to the entity's objectives. It becomes RMM only when it could cause a material misstatement. State that link.

  • Giving responses that are vague, such as 'perform more audit work'.

    Students run out of time or do not name a procedure.

    Fix: Name the procedure, the item and the assertion, for example 'Inspect post year-end receipts to test the existence and valuation of receivables'.

  • Mixing up inherent and control risk.

    Both come from the client's circumstances.

    Fix: Ask: would the risk exist even with perfect controls? If yes, it is inherent. If the cause is a missing or weak control, it is control risk.

  • Treating every risk as significant.

    Students want to show caution.

    Fix: Reserve significant risk for fraud, revenue, major estimates and unusual transactions, and explain why each is special.

Worked examples

Example 1

Trent Co manufactures electronic goods and sells through its own website. This year it launched a new online order system, and the finance director's bonus depends on reaching a profit target. Inventory includes a large amount of obsolete components. Identify and classify two risks of material misstatement and suggest an audit response to each. (6 marks)

Show the solution
  1. Risk 1: revenue may be overstated, affecting the occurrence and cut-off assertions. This is a significant risk because revenue recognition is a presumed fraud risk. The finance director's bonus depends on profit. This is a fraud risk factor (incentive) that raises inherent risk, because it creates pressure to manipulate results.
  2. Control risk for revenue is separate: the new online system has not been tested over time, so controls over recording orders and cut-off may be weak. This is a control risk and is assessed separately from the inherent risk.
  3. Response to risk 1: obtain an understanding of the controls over online sales, evaluate their design and determine whether they are implemented. Test occurrence by agreeing a sample of recorded sales to customer orders, dispatch records and cash receipts. Test cut-off by tracing a sample of sales around year end to dispatch records, and review post year-end credit notes for returns of goods sold before year end. Also test the interface between the website and the ledger.
  4. Risk 2: inventory may be overstated because obsolete components are held at cost above net realisable value. This is an inherent risk because it needs management judgement over valuation, affecting the valuation assertion.
  5. Response to risk 2: review inventory ageing and usage reports, compare cost with post year-end selling prices, and discuss obsolescence with production staff. Challenge management's write-down estimate.

Answer: Revenue overstatement (occurrence and cut-off) is a significant risk (presumed fraud risk). The bonus is a fraud risk factor (incentive) that raises inherent risk, and the untested new system gives a separate control risk. It is responded to with controls understanding, occurrence and cut-off testing and review of credit notes. Inventory overvaluation (valuation assertion) is an inherent risk from obsolescence, responded to with ageing review and comparison of cost to net realisable value.

Exam tips

  • Always tie risks to scenario facts. Marks are for application, not for naming the model.
  • In OT questions, read each option for who controls the risk. Only the auditor controls detection risk.
  • Say 'overstated' or 'understated' and name the assertion or balance when describing a risk.
  • For significant risks, mention that you must obtain an understanding of the relevant controls, evaluate their design and determine their implementation. Add that controls you plan to rely on must be tested, and that substantive procedures must include tests of details, not only analytical procedures.
  • In Section B, keep a pattern of one risk, one reason, one response, then move on. Marks are awarded for points made, so do not count on a fixed mark per point.

Audit Risk and Risk of Material Misstatement: frequently asked questions

What is the difference between inherent risk and control risk?

Inherent risk is how likely an item is to be misstated before considering controls, because of its nature or the business environment. Control risk is the chance that the client's controls fail to prevent or detect that misstatement. Weak controls raise control risk, while complex estimates raise inherent risk.

Can the auditor change the risk of material misstatement?

No. The auditor assesses it but does not create or remove it. The auditor responds by changing detection risk, through the nature, timing and extent of procedures.

What are examples of significant risks in the AA exam?

Common examples are revenue recognition, management override and fraud, complex or judgemental estimates such as provisions and valuations, and significant related party or unusual transactions. You need to explain why the item needs special consideration in the scenario.

How does ISA 315 affect risk assessment?

ISA 315 requires the auditor to perform risk assessment procedures to identify and assess the risks of material misstatement at financial statement and assertion levels. These procedures include enquiries, analytical procedures and observation or inspection. The assessment forms the basis for designing further audit procedures.