Skip to content

Auditing and Ethics · Nature, Objective and Scope of Audit

Audit Risk, Materiality and Reasonable Assurance Explained

Updated 4 October 2026 · Fact-checked

Audit risk is the risk that the auditor gives an inappropriate opinion when the financial statements are materially misstated. It equals the risk of material misstatement (inherent risk × control risk) combined with detection risk. Materiality sets the size of errors that matter. Together they give reasonable assurance, not absolute assurance.

Understand Audit Risk, Materiality and Reasonable Assurance

An auditor cannot check every transaction. So the auditor gives reasonable assurance: a high, but not absolute, level of assurance that the financial statements are free from material misstatement. Absolute assurance is not possible because of inherent limitations such as testing on a sample basis, limits of internal control, the use of judgment, and evidence that is persuasive rather than conclusive.

Audit risk is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated. It is made up of two parts: the risk of material misstatement and detection risk.

The risk of material misstatement has two components at the assertion level. Inherent risk is the susceptibility of an assertion to a material misstatement, before considering any controls. Example: estimates such as provisions, or high-value, easily stolen inventory. Control risk is the risk that the entity's internal control will not prevent, or detect and correct, a material misstatement on time. Both exist independently of the audit. The auditor assesses them, but cannot change them.

SA 315 (Revised) requires the auditor to assess inherent risk and control risk separately. It does not prescribe numerical percentages. The multiplicative model (Audit Risk = Inherent Risk × Control Risk × Detection Risk) is a conceptual illustration, and numerical questions use it only to show how the components relate.

Detection risk is the risk that the procedures performed by the auditor will not detect a material misstatement. This is the one the auditor controls. If the assessed risk of material misstatement is high, the auditor must keep detection risk low by changing the nature, timing (nearer the period end) and extent of procedures, including larger samples. If it is low, the auditor can accept higher detection risk.

Materiality means information is material if omitting or misstating it could reasonably influence the economic decisions of users taken on the basis of the financial statements. It is a matter of professional judgment and depends on both size (quantity) and nature (quality). The auditor sets overall materiality, often using a percentage of a suitable benchmark such as profit before tax or revenue, and performance materiality (lower than overall materiality) to reduce the chance that small errors add up to a material amount. Audit risk and materiality are inversely related: a lower materiality level means more audit work.

Key rules to remember

Audit risk model
Audit Risk = Risk of Material Misstatement × Detection Risk
Risk of material misstatement is the combination of inherent risk and control risk.
Risk of material misstatement
RMM = Inherent Risk × Control Risk
A conceptual illustration for numerical questions. SA 315 (Revised) requires separate assessment of inherent and control risk but does not prescribe numerical percentages. The auditor assesses RMM but does not control it.
Acceptable detection risk
Detection Risk = Audit Risk ÷ (Inherent Risk × Control Risk)
Rearranged from the model. If RMM rises, detection risk must fall.
Relationship rule
Higher assessed RMM → lower acceptable detection risk → more substantive work
Inverse relationship. Detection risk is the only component the auditor can change directly.
Materiality rule
Performance materiality < Overall materiality
Performance materiality is set lower to cover aggregation of uncorrected and undetected misstatements.
Materiality and audit risk
Lower materiality → more audit evidence needed
Materiality is judged by size and nature, and is not a fixed percentage prescribed for all cases.

How to solve Audit Risk, Materiality and Reasonable Assurance questions

Use this order for any question on audit risk, materiality or assurance, whether it is theory, a case study or a short numerical.

  1. 1Identify what is asked: assurance, a risk component, materiality, or the link between them.
  2. 2Define the term in one line in the words of the Standards (SA 200, SA 315, SA 320).
  3. 3Classify the risk in the case. Entity-side and exists before audit work: inherent or control. Caused by the auditor's procedures: detection.
  4. 4Link to the response. High RMM means lower detection risk, more substantive procedures, larger samples, or testing nearer year end.
  5. 5For materiality, consider both size and nature, and state that it is a matter of professional judgment.
  6. 6For numerical questions, write the formula, substitute, and state the conclusion in words.
  7. 7Close by tying back to reasonable assurance: the auditor reduces audit risk to an acceptably low level, not to zero.

Quickest way: Three-question shortcut for risk questions

When to use it: Use this for MCQs and short case-based questions where you must name the type of risk or the auditor's response quickly.

  1. Ask: does this risk exist in the entity even if I did no audit? If yes and it comes from the nature of the item (estimates, complexity, fraud-prone), it is inherent risk.
  2. If the weakness is in the entity's systems (no authorisation, no reconciliation, poor segregation of duties), it is control risk.
  3. If the problem is in the auditor's own tests (small sample, wrong procedure, wrong timing), it is detection risk.
  4. For MCQs, eliminate options that say the auditor can control inherent or control risk, or that give absolute assurance.
  5. For written answers, use the format: definition, application to the facts, auditor's response, conclusion. Each part earns step marks.

Common mistakes in Audit Risk, Materiality and Reasonable Assurance

  • Saying the auditor gives absolute assurance or guarantees accuracy.

    Students confuse an audit with a certificate of exactness.

    Fix: Always write reasonable assurance: high but not absolute, because of inherent limitations such as sampling, judgment and control limitations.

  • Treating detection risk as an entity risk.

    All three names include the word risk, so they blur together.

    Fix: Remember that inherent and control risk belong to the entity. Detection risk belongs to the auditor's procedures.

  • Saying the auditor can reduce inherent risk or control risk by doing more work.

    Students assume more audit work lowers every risk.

    Fix: More work only lowers detection risk. The auditor can only assess inherent and control risk.

  • Getting the inverse link backwards, such as higher RMM allowing higher detection risk.

    Students memorise the formula without thinking about its logic.

    Fix: Think of a see-saw: when risk in the entity is high, the auditor accepts less risk of missing it, so detection risk is set low.

  • Defining materiality only as a percentage of profit or turnover.

    Benchmarks are taught first, so the qualitative side is forgotten.

    Fix: State that materiality depends on size and nature. A small item can be material, for example one that turns a profit into a loss or involves fraud or related parties.

  • Mixing up overall materiality and performance materiality.

    Both are amounts and appear in the same answer.

    Fix: Overall materiality is for the financial statements as a whole. Performance materiality is a lower amount used when designing and performing procedures.

Worked examples

Example 1

An auditor assesses inherent risk at 50% and control risk at 40% for a balance. The auditor wants overall audit risk to be 5%. Compute the acceptable detection risk and explain what it means.

Show the solution
  1. Write the model: Audit Risk = Inherent Risk × Control Risk × Detection Risk.
  2. Compute RMM = 0.50 × 0.40 = 0.20, or 20%.
  3. Rearrange: Detection Risk = Audit Risk ÷ RMM = 0.05 ÷ 0.20 = 0.25.
  4. Convert to a percentage: 25%.
  5. Interpret: the auditor can accept a 25% chance that the procedures miss a material misstatement, and must design tests to achieve this.

Answer: Acceptable detection risk is 25%. The auditor must design procedures so that the chance of missing a material misstatement is no more than 25%. If control risk were assessed higher, this figure would fall and more substantive testing would be needed.

Example 2

Explain with reasons which type of risk is involved in each case: (a) A company values unlisted investments using complex estimates. (b) The company has no reconciliation of bank accounts and no approval of payments. (c) The auditor tests only 10 invoices out of 5,000 and misses a large error.

Show the solution
  1. Case (a): the complexity and estimation make the item prone to misstatement before considering controls. This is inherent risk.
  2. Case (b): the entity's controls would not prevent or detect errors on time. This is control risk.
  3. Case (c): the error escaped because of the auditor's own sample and procedures. This is detection risk.
  4. Response: for (a) and (b), the auditor should treat RMM as high and keep detection risk low through more substantive procedures and larger samples. For (c), the auditor should increase the sample size and improve the design of tests.

Answer: (a) Inherent risk. (b) Control risk. (c) Detection risk. The auditor controls only detection risk, and sets it low where inherent and control risk are high, so as to give reasonable assurance.

Exam tips

  • Write reasonable assurance, never absolute assurance, in every answer. Examiners look for this.
  • In case studies, label the risk type first and then give the auditor's response. Both parts carry marks.
  • For numericals, show the formula, the substitution and a one-line interpretation. Even if the arithmetic slips, steps still earn marks.
  • In materiality answers, mention both quantity and nature, and say it is a matter of professional judgment.
  • Practise the MCQ trap questions: which risk can the auditor control, and what happens when materiality is lowered.

Practice questions from Nature, Objective and Scope of Audit

Audit Risk, Materiality and Reasonable Assurance in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Audit Risk, Materiality and Reasonable Assurance: frequently asked questions

What are the components of audit risk?

Audit risk has two parts: the risk of material misstatement and detection risk. The risk of material misstatement is made up of inherent risk and control risk. So the commonly quoted three components are inherent, control and detection risk.

What is the difference between reasonable assurance and absolute assurance?

Reasonable assurance is a high level of assurance that the financial statements are free from material misstatement. Absolute assurance would be a guarantee of no error at all. An audit cannot give it because of limitations such as sampling, judgment and limits of internal control.

Is materiality a fixed percentage?

No. Auditors often use a percentage of a benchmark such as profit before tax or revenue as a starting point, but the final figure is a matter of professional judgment. Qualitative factors can make a small item material.

Which audit risk can the auditor control?

Only detection risk. The auditor changes it through the nature, timing and extent of procedures. Inherent and control risk exist in the entity, and the auditor can only assess them.