Audit and Assurance · Objective and general principles
ISA 200 Overall Objectives and Audit Risk Explained
Updated 11 October 2026 · Fact-checked
ISA 200 says the auditor's overall objectives are to obtain reasonable assurance that the financial statements are free from material misstatement, and to report on them in line with findings. Audit risk is the risk of giving an inappropriate opinion. It comprises the risk of material misstatement (inherent and control risk) and detection risk.
Understand ISA 200 Overall Objectives and Audit Risk
An audit exists to increase the confidence users place in financial statements. ISA 200 sets out what the auditor is trying to achieve. There are two overall objectives. First, obtain reasonable assurance about whether the financial statements as a whole are free from material misstatement, whether caused by fraud or error. This lets the auditor give an opinion on whether they are prepared, in all material respects, in accordance with the applicable financial reporting framework. Second, report on the financial statements and communicate as ISAs require, in line with the auditor's findings.
Reasonable assurance is a high level of assurance, but not absolute. The auditor cannot guarantee that the statements are correct. This is because of the inherent limitations of an audit. They include: the use of testing and sampling rather than checking everything; limitations of internal control, such as collusion or management override; most evidence being persuasive rather than conclusive; the use of judgement, especially for estimates; and the nature of financial reporting itself. Fraud that is concealed, such as forgery or collusion, is harder to find than error.
Audit risk is the risk that the auditor gives an inappropriate opinion when the financial statements are materially misstated. It has two parts. The risk of material misstatement is the risk that the statements are misstated before the audit starts. It is made up of inherent risk and control risk. Inherent risk is the susceptibility of an assertion to material misstatement before considering any controls. Complex estimates, high-value inventory, or a dominant manager raise it. Control risk is the risk that the entity's internal controls will not prevent, or detect and correct, a misstatement on a timely basis. Weak controls raise it.
Detection risk is the risk that the auditor's procedures will not detect a material misstatement. Unlike the other two, the auditor controls it. Inherent and control risk exist independently of the audit. The auditor responds to them by changing the nature, timing and extent of procedures. If the assessed risk of material misstatement is high, the auditor needs lower detection risk. That means more extensive, more reliable evidence, often gathered nearer the year end and by the audit team rather than from the client.
The auditor must also exercise professional judgement and maintain professional scepticism, and comply with relevant ethical requirements. Scepticism means a questioning mind and being alert to conditions that may indicate misstatement. Expect exam questions to ask you to explain a term, link a scenario fact to a risk type, or explain why an audit cannot give absolute assurance.
Key rules to remember
- Audit risk model
- Audit risk = Risk of material misstatement × Detection risk
- A conceptual model, not a calculation you must perform in AA. Know what each part means.
- Risk of material misstatement
- Risk of material misstatement = Inherent risk × Control risk
- Both exist before and independently of the audit. The auditor assesses them but cannot change them.
- Inverse relationship
- Higher assessed risk of material misstatement → lower acceptable detection risk
- Lower detection risk means more, or more reliable, substantive procedures.
- Overall objectives (ISA 200)
- (1) Obtain reasonable assurance of no material misstatement; (2) report in line with findings
- Reasonable assurance is high but not absolute.
How to solve ISA 200 Overall Objectives and Audit Risk questions
Use this method for any question on ISA 200, audit risk or the limits of an audit.
- 1Read the requirement and identify the task: state the objectives, define a risk component, classify a scenario fact, or explain limitations.
- 2For objectives, give both: reasonable assurance about material misstatement, then reporting in line with findings. Add that the opinion covers the applicable framework.
- 3For risk, decide whether each scenario fact sits before the audit (inherent or control) or in the auditor's procedures (detection).
- 4Classify: nature of the business, transaction or balance gives inherent risk. A weak or absent control gives control risk. Poor sampling or procedures gives detection risk.
- 5Link to the response: higher risk of material misstatement means lower detection risk, so more or better substantive work, more experienced staff and year-end testing.
- 6For limitations, name the cause (testing, controls, evidence, judgement, fraud) and tie it to the scenario, then conclude that only reasonable assurance is possible.
- 7Check you used the mark allocation: one clear point per mark, with a reason or scenario link.
Quickest way: Three-question risk classifier
When to use it: Use it for Section A and Section B objective questions that ask which type of risk a fact describes.
- Ask: does this exist without the auditor doing anything? If no, it is detection risk.
- If yes, ask: is it about the nature of the item, such as complexity, estimates or susceptibility to fraud? That is inherent risk.
- If it is about a control failing or missing, such as no authorisation or no reconciliation, it is control risk.
- Remember the auditor can only change detection risk, and it moves opposite to the other two.
Common mistakes in ISA 200 Overall Objectives and Audit Risk
Saying the auditor gives absolute assurance or guarantees the statements are correct.
Students confuse a high level of assurance with certainty.
Fix: Always write reasonable assurance: high but not absolute, because of inherent limitations.
Saying the auditor can reduce inherent and control risk.
The model looks like all three are adjustable.
Fix: The auditor only assesses inherent and control risk. Only detection risk is changed, by altering the nature, timing and extent of procedures.
Putting a weak control under inherent risk.
Both are risks of misstatement in the entity.
Fix: Controls absent or ineffective means control risk. Inherent risk is about the item itself before controls.
Getting the direction of detection risk wrong.
Students link higher risk with higher everything.
Fix: Higher risk of material misstatement requires lower detection risk, meaning more extensive work.
Listing only one objective, usually the opinion, and leaving out reporting and communication.
Students remember the opinion but forget the second objective.
Fix: State both objectives. Say the second is to report on the statements and communicate as ISAs require, in line with findings.
Stating limitations generally without explaining why they matter.
Students memorise a list.
Fix: For each limitation give the cause and the consequence, for example testing means some misstatements may go unfound.
Worked examples
Example 1
Explain the overall objectives of the auditor under ISA 200 and why an auditor cannot give absolute assurance. (6 marks)
Show the solution
- Objective 1: obtain reasonable assurance about whether the financial statements as a whole are free from material misstatement, due to fraud or error.
- This enables the auditor to express an opinion on whether the statements are prepared, in all material respects, in accordance with the applicable financial reporting framework.
- Objective 2: report on the financial statements, and communicate as ISAs require, in line with the auditor's findings.
- Limitation 1: auditors test samples, not every transaction, so some misstatements may not be found.
- Limitation 2: internal controls have inherent limits, such as collusion and management override.
- Limitation 3: most evidence is persuasive rather than conclusive, and estimates and judgements involve uncertainty. Fraud that is concealed is hard to detect.
Answer: The objectives are reasonable assurance on material misstatement and reporting in line with findings. Absolute assurance is impossible because of sampling, control limitations, persuasive evidence, judgement and concealed fraud.
Example 2
An audit client sells jewellery through many stores. Stores have no regular inventory counts and managers can override the till system. The audit senior has decided to extend year-end testing of inventory. Identify the risk types and explain the senior's response. (5 marks)
Show the solution
- High-value, portable inventory is easy to steal. This is inherent risk.
- No regular inventory counts is a missing control. This is control risk.
- Managers able to override the till system is also a control weakness, so control risk, and it increases fraud risk.
- Both raise the risk of material misstatement, so the auditor needs lower detection risk.
- The response is to extend substantive work, such as attending counts at more stores at the year end, using more experienced staff, and testing more items.
Answer: Inherent risk arises from high-value portable inventory. Control risk arises from no counts and manager override. With a high risk of material misstatement, detection risk must be lowered by more extensive, more reliable year-end substantive procedures.
Exam tips
- In Section A and B, classify the risk before looking at the options. Detection risk is the only one the auditor controls.
- In written answers, tie each risk to a scenario fact. A generic definition alone earns few marks.
- Always write reasonable assurance, never absolute or guarantee. This is a frequent marker complaint.
- For limitations questions, give cause and effect, one point per mark.
- Show the link between assessed risk and the nature, timing and extent of procedures.
ISA 200 Overall Objectives and Audit Risk in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
ISA 200 Overall Objectives and Audit Risk: frequently asked questions
What are the overall objectives of the auditor under ISA 200?
There are two. The auditor obtains reasonable assurance that the financial statements as a whole are free from material misstatement, and reports on them in line with the findings. This supports an opinion on whether they comply with the applicable framework.
What is the difference between inherent risk and control risk?
Inherent risk is how susceptible an item is to misstatement before considering controls, for example a complex estimate. Control risk is the risk that the entity's controls fail to prevent, or detect and correct, a misstatement in time.
Why is detection risk the only risk the auditor controls?
Detection risk depends on the auditor's own procedures. The auditor can change their nature, timing and extent. Inherent and control risk exist in the entity regardless of the audit, so the auditor can only assess them.
What are the inherent limitations of an audit?
They include testing rather than checking everything, limits of internal control, evidence that is persuasive rather than conclusive, the use of judgement in estimates, and the difficulty of finding concealed fraud. These are why the auditor gives reasonable, not absolute, assurance.