Skip to content

CMA Intermediate · Corporate Accounting and Auditing

Audit Risk, Internal Control, Internal Check and Internal Audit

This chapter covers how an auditor assesses the risk of material misstatement, how the entity's internal control and internal check reduce that risk, and how internal audit adds assurance. To solve questions, identify the risk, link it to a control, then state the audit response and the reliance you can place.

What this chapter covers

This chapter explains how an auditor decides where errors are most likely and how much testing is needed. Audit risk is the starting point. The auditor assesses the risks of material misstatement by understanding the entity and its environment, including its internal control.

Internal control is the entity's own system for reducing those risks. SA 315 divides it into five components: the control environment, the entity's risk assessment process, the information system (including related business processes relevant to financial reporting, and communication), control activities, and monitoring of controls. Internal check is a narrower part of this, built into daily routines so that one person's work is checked by another. Internal audit is a function that reviews and evaluates controls, risk management and governance.

The chapter connects to the rest of Paper 10 because vouching, verification and the audit report all depend on risk and control. A strong control system means less substantive testing. A weak one means more. If you understand this link, later audit chapters become easier to follow.

This chapter gives you both objective and written marks. Section A MCQs often test definitions, the five components and who does what. Written questions ask you to evaluate a control system, list weaknesses, or explain how an auditor uses internal audit work. The ideas are also reused in nearly every other audit topic, so time spent here pays back across the whole paper.

Audit Risk, Internal Control, Internal Check and Internal Audit: topics in the order to study them

  1. 1Audit Risk and Risk AssessmentStart here because it explains why the auditor cares about controls at all.
  2. 2Internal Control: Meaning, Objectives and ComponentsOnce you know the risk, learn the entity's system that responds to it and the five SA 315 components.
  3. 3Internal Control Evaluation: Questionnaire and Flow ChartThis shows how the auditor records and tests the control system you just studied.
  4. 4Internal Check SystemStudy it after internal control so you see it as one practical part of the larger system.
  5. 5Internal Audit: Scope, Functions and ReportingFinish with internal audit, since the external auditor's use of its work builds on everything before.

How to prepare Audit Risk, Internal Control, Internal Check and Internal Audit

Study this chapter as one chain: risk, control, evaluation, check, internal audit. Always ask how each idea changes the audit work.

  1. Read the risk topic first and write the link in one line: higher risk of material misstatement means more audit work.
  2. Learn the five components of internal control in order, and write two examples of each from a company you know.
  3. For the control environment, memorise the seven elements: integrity and ethical values, commitment to competence, participation by those charged with governance, management's philosophy and operating style, organisational structure, assignment of authority and responsibility, and human resource policies.
  4. Practise drawing a simple flow chart and writing five questionnaire items for purchases or payroll.
  5. Compare internal control, internal check and internal audit in a small table in your notes, with purpose and who performs each.
  6. Learn the internal audit scope: governance, risk management, internal control, financial and operating information, operating activities and compliance. Note examples of work an external auditor may use, such as testing operating effectiveness of controls.
  7. Solve past MCQs, then write two full answers in a clear format with a heading, points and a short conclusion.

Common mistakes in Audit Risk, Internal Control, Internal Check and Internal Audit

  • Mixing up internal control, internal check and internal audit.

    Fix: Remember that internal control is the whole system, internal check is routine cross-checking within it, and internal audit is a separate review function.

  • Listing the five components in the wrong order or with wrong names.

    Fix: Use the SA 315 wording exactly and rehearse the list until you can write it without prompts.

  • Writing only definitions in written answers.

    Fix: Tie each point to the scenario: name the weakness, the risk it creates and the audit response.

  • Treating internal audit as a replacement for the external auditor.

    Fix: State that the external auditor remains responsible for the opinion and only uses internal audit work as evidence where suitable.

  • Ignoring the control environment in case studies.

    Fix: Check each case for tone at the top, governance involvement, competence and authority, and mention the relevant element.

  • Skipping MCQ practice because the chapter is mostly theory.

    Fix: Attempt MCQs on terms, components and examples, since Section A is compulsory and has no negative marking.

Last-day revision: Audit Risk, Internal Control, Internal Check and Internal Audit

  • Audit risk depends on the risk of material misstatement and the risk that the auditor does not detect it.
  • SA 315 has five internal control components.
  • The five components: control environment, entity's risk assessment process, information system and communication, control activities, monitoring of controls.
  • The control environment sets the tone of the organisation and influences the control consciousness of its people.
  • Manual elements suit judgment, such as large, unusual or non-recurring transactions.
  • Whether the entity's risk assessment process is appropriate is a matter of judgment.
  • Internal check is built into routine work so one person's work is checked by another.
  • A questionnaire asks structured questions; a flow chart shows the process visually.
  • Internal audit scope covers governance, risk management and internal control.
  • Internal audit work that may be used includes testing the operating effectiveness of controls and observing inventory counts.
  • Internal audit's objectives, scope and status vary with the entity's size and structure.
  • Control activities are relevant to the audit based on the risk identified and whether testing them will reduce substantive testing.

Audit Risk, Internal Control, Internal Check and Internal Audit practice questions

Audit Risk, Internal Control, Internal Check and Internal Audit in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Audit Risk, Internal Control, Internal Check and Internal Audit: frequently asked questions

What are the five components of internal control?

They are the control environment, the entity's risk assessment process, the information system and communication, control activities, and monitoring of controls. SA 315 uses this division as a framework, though auditors may use other terminology if all components are covered.

What is the difference between internal check and internal control?

Internal control is the entity's overall system for managing risks and safeguarding reliable reporting. Internal check is a part of it, built into daily routines so that one employee's work is verified by another.

Can an external auditor use the work of internal auditors?

Yes, in suitable cases. SA 610 (Revised) gives examples such as testing the operating effectiveness of controls, observing inventory counts and testing compliance with regulatory requirements. The external auditor still decides how much to rely on it.

How should I prepare this chapter for the exam?

Learn the definitions and component lists for MCQs. Then practise short written answers that link a control weakness to a risk and an audit response, using clear points.