Corporate Accounting and Auditing · Audit Risk, Internal Control, Internal Check and Internal Audit
Audit Risk and Risk Assessment: Inherent, Control and Detection Risk
Updated 10 October 2026 · Fact-checked
Audit risk is the risk that the auditor gives an inappropriate opinion when the financial statements are materially misstated. It has two parts: the risk of material misstatement (inherent risk and control risk) and detection risk. You assess the first, then set audit procedures so that detection risk stays low enough.
Understand Audit Risk and Risk Assessment
Audit risk is the chance that you express a clean opinion on financial statements that are materially wrong. You cannot remove this risk fully. Your job is to bring it down to an acceptably low level.
Audit risk has two main parts. The first is the risk of material misstatement (RMM). This exists in the entity before you start work. It has two components: inherent risk and control risk. The second is detection risk, the risk that your own audit procedures fail to find a material misstatement that exists.
Inherent risk is how likely an assertion is to be misstated, assuming there are no related controls. Complex estimates, cash, fast-moving inventory, and unusual transactions carry high inherent risk. Control risk is the risk that the entity's internal control will not prevent, or detect and correct, a misstatement on time. Both exist independently of the audit. You can only assess them, not change them.
Detection risk is the one you control. If you assess RMM as high, you must accept a lower detection risk. You do this with more extensive tests, more reliable evidence, larger samples, and procedures near the year end. If RMM is low, you can accept a higher detection risk.
Materiality sets the size of misstatement that matters. A misstatement is material if it could reasonably influence the economic decisions of users. It is a matter of judgement, using amount and nature. Auditors often fix an overall materiality using a benchmark such as profit before tax, revenue or total assets. Performance materiality is set lower, to cover the chance that small uncorrected errors add up. SA 315 (Revised) requires you to identify and assess RMM at the financial statement level and the assertion level by understanding the entity, its environment and its internal control. SA 330 requires you to design responses to those assessed risks.
Key rules to remember
- Audit risk model
- Audit Risk (AR) = Risk of Material Misstatement (RMM) × Detection Risk (DR)
- This is the conceptual form. It is a planning aid, not an exact calculation.
- Risk of material misstatement
- RMM = Inherent Risk (IR) × Control Risk (CR)
- So AR = IR × CR × DR. SA 315 (Revised) treats IR and CR as assessed separately for assertions.
- Acceptable detection risk
- DR = AR ÷ (IR × CR)
- Use it with risks as proportions. Higher assessed IR or CR means lower acceptable DR, so more substantive work.
- Direction of response
- Higher RMM → lower DR → more, stronger substantive procedures
- Lower RMM allows a higher DR and less extensive testing.
- Materiality rule
- Misstatement is material if it could reasonably influence users' economic decisions
- Judge by both amount and nature. A small amount can be material if it hides fraud or a covenant breach.
How to solve Audit Risk and Risk Assessment questions
Use this method for any question on audit risk, whether theory, a scenario or a numerical on the risk model.
- 1Define audit risk in one line and name its two parts: risk of material misstatement and detection risk.
- 2Split RMM into inherent risk and control risk. Define each in the entity's context.
- 3Read the scenario and classify each fact. Nature of the business, complex estimates or cash points to inherent risk. Weak supervision, no reconciliations or override of controls points to control risk.
- 4Link the assessed RMM to detection risk. Higher RMM means lower acceptable detection risk.
- 5State the response: nature, timing and extent of procedures, such as larger samples, year-end testing and more substantive tests.
- 6Comment on materiality where relevant, covering the benchmark, the effect of nature and the need to document.
- 7For numericals, use AR = IR × CR × DR, convert percentages to decimals, solve for the missing term and interpret the result.
Quickest way: Three-line risk answer
When to use it: Use when time is short, such as a 2-mark MCQ or a short note worth a few marks.
- Write: Audit risk = RMM × Detection risk, and RMM = Inherent × Control.
- Say which risk the facts describe. Entity-level nature of business is inherent. Failure of controls is control. Auditor's procedures missing an error is detection.
- Finish with the link: higher RMM means lower detection risk, so more substantive testing.
- In a numerical, divide AR by the product of the other two risks.
Common mistakes in Audit Risk and Risk Assessment
Saying the auditor can reduce inherent and control risk by doing more testing.
Students think all risks sit with the auditor.
Fix: Inherent and control risks belong to the entity. You assess them. Only detection risk is changed by your procedures.
Confusing inherent risk with control risk.
Both describe misstatement risk, and scenarios mix the two.
Fix: Ask: would the error be likely even with good controls? If yes, inherent. Ask: did controls fail to stop it? If yes, control risk.
Reversing the link between RMM and detection risk.
Students assume high risk means accepting higher risk.
Fix: Remember the see-saw. High RMM forces low detection risk, which means more audit work.
Treating materiality as a fixed percentage that is always correct.
Benchmarks are taught as quick rules.
Fix: Call a benchmark a starting point. Add that nature, such as fraud or related party items, can make smaller amounts material.
Making errors in the numerical by mixing percentages and decimals.
Rushing under time pressure.
Fix: Convert to decimals first, for example 40% = 0.40, solve, then convert back to a percentage.
Writing that audit risk can be reduced to zero.
Students confuse 'low' with 'nil'.
Fix: Say it is reduced to an acceptably low level. Inherent limitations of an audit always remain.
Worked examples
Example 1
An auditor wants overall audit risk of 5%. Inherent risk is assessed at 50% and control risk at 40%. Calculate the detection risk the auditor can accept, and state what happens if control risk is reassessed at 100%.
Show the solution
- Use AR = IR × CR × DR, so DR = AR ÷ (IR × CR).
- Convert to decimals: AR = 0.05, IR = 0.50, CR = 0.40.
- IR × CR = 0.50 × 0.40 = 0.20.
- DR = 0.05 ÷ 0.20 = 0.25, which is 25%.
- If CR becomes 100% (1.00), IR × CR = 0.50 × 1.00 = 0.50.
- New DR = 0.05 ÷ 0.50 = 0.10, which is 10%.
Answer: Acceptable detection risk is 25%. If control risk rises to 100%, it falls to 10%, so the auditor must do more extensive substantive procedures.
Example 2
Sunrise Textiles Ltd has a large inventory of fabrics held at many godowns. Stock records are updated manually, no one reconciles godown records to the ledger, and the accountant also approves purchases. Identify the risks and state the auditor's response.
Show the solution
- Inherent risk: large inventory in many locations, with valuation and existence issues, so inherent risk is high.
- Control risk: manual records, no reconciliation and no segregation of duties since the accountant approves purchases. Controls are unlikely to prevent or detect errors, so control risk is high.
- So RMM for inventory assertions of existence and valuation is high.
- Therefore acceptable detection risk must be low.
- Response on nature: rely on substantive procedures, such as attending the physical count at key godowns and testing valuation against cost and net realisable value.
- Response on timing: perform procedures at or near the year end.
- Response on extent: use larger samples and cover more locations.
- Document the assessment, the materiality used and the reasons for the response.
Answer: Both inherent and control risk are high, so RMM is high. The auditor must keep detection risk low through extensive year-end substantive testing of inventory, including physical verification and valuation checks.
Exam tips
- For MCQs, first spot which of the three risks the sentence describes. Wording about the entity's business points to inherent risk, and wording about controls failing points to control risk.
- In theory answers, always draw the link between assessed risk and the nature, timing and extent of procedures. This earns the marks examiners look for.
- Write the model as AR = IR × CR × DR and show decimal conversion in numericals. Step marks depend on it.
- Mention SA 315 (Revised) for identifying and assessing risks and SA 330 for responses, but only as references. Do not quote paragraph numbers.
- Add a line on materiality when the question gives amounts. Compare the misstatement with the materiality level and consider its nature.
Practice questions from Audit Risk, Internal Control, Internal Check and Internal Audit
- Under the internal control questionnaire method of evaluating a client's control system, the auditor typically obtains the information by:
- A CMA firm auditing Kaveri Textiles Ltd prepares a flow chart of the purchase cycle. Which advantage is most directly associated with a flow…
- An auditor of a manufacturing company is evaluating IT in the control system. Which one of the following is NOT stated by SA 315 as a genera…
- Considering SA 315, why can the auditor NOT assume that a manual control will be applied consistently?
- According to SA 315, control activities are best described as:
Audit Risk and Risk Assessment in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Audit Risk and Risk Assessment: frequently asked questions
What is the difference between inherent risk and control risk?
Inherent risk is the susceptibility of an assertion to material misstatement before considering any controls. Control risk is the risk that the entity's internal controls fail to prevent or detect and correct such a misstatement. Both belong to the entity, not the auditor.
Can the auditor control detection risk?
Yes. Detection risk depends on the auditor's procedures. You lower it by using more reliable evidence, larger samples and tests closer to the year end, and you can accept a higher level when assessed RMM is low.
What is the risk of material misstatement?
It is the combination of inherent risk and control risk. It is the risk that the financial statements are materially misstated before the audit. SA 315 (Revised) requires you to assess it at the financial statement level and at the assertion level.
Is the audit risk model a precise formula?
No. It is a conceptual tool for planning. In the exam you may use it for numericals, but in practice auditors assess risks with judgement, often as high, medium or low.
What is materiality in an audit?
A misstatement is material if it could reasonably influence the economic decisions of users of the financial statements. It is judged by both amount and nature, and the auditor sets it during planning.