CA Intermediate · Auditing and Ethics
Risk Assessment and Internal Control: CA Intermediate Auditing and Ethics
Risk Assessment and Internal Control covers how an auditor plans the audit, understands the entity, judges audit risk and materiality, and tests internal controls. To solve questions, name the Standard on Auditing, apply it to the facts given, and conclude with the effect on audit procedures.
What this chapter covers
This chapter is the base of the risk-based audit. Before testing anything, the auditor plans the work, learns about the entity and its environment, identifies where the financial statements could be materially wrong, and decides how much testing is needed. The chapter covers audit planning and strategy, risk assessment procedures, audit risk and materiality, the components and limitations of internal control, internal financial controls under the Companies Act, 2013, walkthrough tests, and the tools and documentation used to record the evaluation.
The ideas are linked in a chain. Understanding the entity feeds the risk assessment. The risk assessment decides the audit strategy and plan. Materiality sets the level of testing. Internal control evaluation decides how far you can rely on controls and how much substantive work is left. Each link is a likely exam question.
This chapter connects to the rest of the paper. Later chapters on audit evidence, sampling, the audit of items of financial statements, and the company audit all assume you know why a procedure was chosen. Reporting also depends on it, because materiality and risk shape the opinion. If this chapter is clear, the other chapters become easier to learn.
This chapter is worth your effort because it supplies both kinds of marks. MCQs test definitions, components, limitations and the relationship between risk, materiality and evidence. Descriptive questions give you a short scenario and ask what the auditor should do, so you must apply the Standards on Auditing to facts. The concepts are also reused in almost every other chapter of the paper, so time spent here pays back many times. Students who learn them as a logical chain, not as isolated lists, answer faster and lose fewer marks.
Risk Assessment and Internal Control: topics in the order to study them
- 1Audit Planning and StrategyStart here because it shows the whole flow of an audit and where risk assessment fits, including the difference between the overall strategy and the audit plan.
- 2Risk Assessment Procedures and Understanding the EntityPlanning depends on knowing the entity, so learn the procedures used to gather that knowledge and identify risks of material misstatement.
- 3Audit Risk and MaterialityOnce risks are identified, you need the risk model and materiality to see how they decide the nature, timing and extent of work.
- 4Internal Control: Components and LimitationsControls are the entity's own response to risk, so you learn them after risk and before testing them.
- 5Internal Financial Controls (IFC) and Walkthrough TestsThis applies control concepts to the Companies Act requirements and shows how the auditor confirms their understanding of a process.
- 6Internal Control Evaluation Tools and Audit DocumentationFinish with the tools used to record and evaluate controls and the documentation that proves the work was done.
How to prepare Risk Assessment and Internal Control
Learn this chapter as one connected process, then practise applying it to short facts. Use this plan over a few focused sessions.
- Read the six topics once in the given order and draw a single flow chart from planning to documentation. Keep it as your master sheet.
- For each topic, list the key terms in your own words: for example overall audit strategy, audit plan, risk of material misstatement, inherent risk, control risk, detection risk, performance materiality.
- Learn the audit risk relationship in words first: audit risk is the risk of giving an inappropriate opinion when the statements are materially misstated. Then link each part to what the auditor can or cannot control.
- Memorise the five components of internal control and the inherent limitations. For each, prepare one example from a business, so you can use it in scenario answers.
- Practise scenario questions in a three-part format: the relevant Standard or provision, the facts from the question, and the conclusion on what the auditor should do. This earns step marks.
- Solve MCQs by topic after each session. Eliminate options that overstate, such as those saying the auditor can eliminate risk or that controls guarantee accuracy.
- Revise with your master sheet and quick points two or three days before the exam, and attempt one timed mixed set.
Common mistakes in Risk Assessment and Internal Control
Mixing up the audit strategy and the audit plan.
Fix: Remember that the strategy is the broad approach on scope, timing and direction, and the plan is the detailed set of procedures that follows from it.
Saying the auditor controls inherent and control risk.
Fix: State that these risks belong to the entity and its environment. The auditor only assesses them and then adjusts detection risk through the audit procedures.
Listing internal control components without applying them to the facts.
Fix: Identify which component the facts point to, such as a weak control environment or missing monitoring, and explain the effect on the audit approach.
Treating materiality as a fixed percentage that works for every case.
Fix: Describe materiality as a judgment based on user needs, the benchmark chosen and the nature of the item, and use any figure only when the question gives it.
Confusing a walkthrough test with a test of controls.
Fix: A walkthrough traces one transaction to confirm understanding of the process. Tests of controls check operating effectiveness over the period on a sample.
Claiming that strong internal control guarantees there are no errors.
Fix: Always mention inherent limitations, including collusion and management override, and say controls give reasonable assurance and not absolute assurance.
Last-day revision: Risk Assessment and Internal Control
- The overall audit strategy sets scope, timing and direction; the audit plan details the procedures to carry out.
- Planning is a continuous process and not a single early step. Revise the plan when circumstances change.
- Risk assessment procedures include inquiries, analytical procedures, and observation and inspection.
- Audit risk = risk of material misstatement × detection risk, and risk of material misstatement combines inherent risk and control risk.
- The auditor cannot influence the entity's inherent and control risk, only assess them, and then sets detection risk through the nature, timing and extent of procedures.
- Higher assessed risk means more extensive and more reliable substantive procedures.
- Materiality is a matter of professional judgment and depends on both size and nature of the item.
- Performance materiality is set below overall materiality to reduce the chance that uncorrected errors add up to a material amount.
- Internal control has five components: control environment, entity's risk assessment process, information system and communication, control activities, and monitoring of controls.
- Internal control has inherent limitations, such as human error, collusion, management override and cost-benefit considerations.
- A walkthrough test follows one transaction from start to finish through the process to confirm understanding of the controls.
- Section 143(3)(i) of the Companies Act, 2013 requires the auditor's report to state whether the company has an adequate internal financial controls system with reference to financial statements and whether it operates effectively. Certain private companies (one-person companies, small companies, and specified low-turnover, low-borrowing private companies) are exempt from this reporting by MCA notification.
- Documentation should be enough for an experienced auditor with no prior link to the audit to understand the work done and the conclusions reached.
Risk Assessment and Internal Control practice questions
- During the audit of Bharat Agro Ltd, CA Rohit identifies a significant deficiency in internal control over inventory counting. Under SA 265,…
- Rao & Associates audit Western Cement Ltd, a company with turnover above the prescribed limit. Section 143(3)(i) of the Companies Act, 2013 …
- During the audit of Sundaram Pharma Ltd, the auditor identifies that the company recognises a large portion of its annual revenue through ye…
- While planning the audit of Kaveri Textiles Ltd, the engagement team identifies that the company's revenue recognition is highly complex and…
- Auditor Rohan finds that at Deccan Steels Ltd., the same accounts officer raises purchase orders, receives goods and approves supplier payme…
- During planning of the audit of Narmada Retail Ltd, the engagement team learns that the company recently implemented a new ERP system and th…
- CA Anita is auditing Vistara Retail Ltd. She assesses a risk of material misstatement in revenue recognition and, after considering the natu…
- During the audit of Bharat Steels Pvt Ltd, the auditor learns that the internal auditor reports directly to the finance manager, who is also…
Risk Assessment and Internal Control in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Risk Assessment and Internal Control: frequently asked questions
Which topic in this chapter should I study first?
Start with Audit Planning and Strategy. It shows how the whole audit flows, so the later topics on risk, materiality and controls fit into a clear picture.
How do I answer scenario questions on risk and controls?
Use three steps: state the relevant Standard on Auditing or provision, link it to the facts in the question, and conclude with the action the auditor should take. Keep each step to a sentence or two. This format picks up step marks even if your conclusion is partly off.
What is the difference between internal control and internal financial controls?
Internal control is the broad system management sets up to run the business, protect assets and support reliable reporting. Internal financial controls under the Companies Act, 2013 focus on the controls over financial reporting and related matters, and the auditor reports on them. Learn both and the link between them.
How should I handle MCQs from this chapter?
Read each option for absolute words such as always or guarantee, as these are often wrong in auditing. Match the term to its definition and remember that the auditor gives reasonable assurance. There is no negative marking, so attempt every MCQ.