,

Audit Risk Explained: Inherent, Control, and Detection Risk

Every internal auditor uses the phrase “audit risk” and most use it to mean two different things in the same sentence. Sometimes it means the risks in the area being audited, the things that could go wrong in route cash or payroll or vendor onboarding. Sometimes it means the risk that the audit itself gets the answer wrong: that the report says the controls work when they do not, or, less discussed but just as expensive, that it says they fail when they do not. Only the second meaning is audit risk in the technical sense, and it is the one that decides how big a sample to pull, which procedures to run, how much to rely on a control, and how confident the conclusion can be. A function that has never separated the two ends up sizing every test the same way regardless of what is at stake, which is the single most common methodological weakness an external quality assessor finds.

This guide explains audit risk as the external auditing standards define it, translates each component into the vocabulary and procedures of an internal audit engagement under the Global Internal Audit Standards, and shows how the model drives real decisions. It includes the audit risk model with a table of combinations, a translation table from external-audit terms to internal-audit practice, an inherent risk factor scoring table, a control-risk-to-testing decision table, a detection-risk table mapping procedure mix and sample size to assurance, a worked example at MidState Beverage across two engagements, a table separating audit risk from business risk and engagement risk, and the common failures. It was rewritten in September 2026 to reflect the Global Internal Audit Standards and current audit sampling practice. It assumes you have read, or will read alongside it, the site’s guides to the internal audit risk assessment and to audit sample sizes, which cover the two ends of the process this guide connects.

In this guide

What audit risk is, and what it is not

Audit risk is the risk that the auditor reaches and reports the wrong conclusion. In the external audit standards, where the term was defined, it is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated; ISA 200 and PCAOB AS 1101 both frame it that way, and both decompose it into the risk that a material misstatement exists and the risk that the auditor’s procedures fail to detect it. Internal audit borrowed the concept and broadened it, because internal audit engagements conclude on many things besides financial statements: whether a process’s controls are designed and operating effectively, whether a regulation is being complied with, whether an operation is efficient. In each case the auditor is exposed to the same two failures. The controls may be worse than the report says, which is the failure the profession worries about, because a clean report on a broken process is the one that ends up in front of an audit committee after the loss. And the controls may be better than the report says, which wastes management’s remediation effort and, over time, teaches auditees that findings are noise.

Audit risk is not the risk in the area under review. The chance that a MidState Beverage driver skims cash from a route is a business risk, and the engagement exists to assess how well it is controlled; the chance that the engagement concludes settlement controls are effective when a driver is skimming is audit risk. Nor is it the risk to the audit function of doing the engagement at all, which the Standards treat under planning and resourcing as the risk of the plan failing to cover what matters. The three are related, and the section below on keeping them apart shows how, but the discipline of the model depends on holding the middle one steady: the question is always whether this engagement, with these procedures and this sample, could reach a conclusion the facts do not support, and how likely that is. Under the Global Internal Audit Standards the concept lives in Standard 13.2, which requires an engagement risk assessment as the basis for objectives, scope, and the work program, and in Standard 14.1’s requirement that conclusions rest on sufficient, reliable, relevant, and useful information; the GIAS Domain V guide traces both through an engagement.

The audit risk model: inherent, control, and detection risk

The model expresses audit risk as the product of three components. Inherent risk is the susceptibility of the area to a material error or failure before considering controls: cash is inherently riskier than fixed assets, estimates riskier than invoices, new systems riskier than stable ones. Control risk is the risk that the controls in place fail to prevent or detect that error on a timely basis; it is high where controls are missing or poorly designed and low where they are well designed and have been shown to operate. Detection risk is the risk that the auditor’s own procedures fail to find an error that the controls let through; it is the only component the auditor controls, and it is controlled by choosing procedures, sample sizes, and timing. In the standard notation, audit risk equals inherent risk multiplied by control risk multiplied by detection risk, and the first two together are the risk of material misstatement, or in internal audit terms the residual risk that the area carries into the audit.

The auditor sets audit risk at the level acceptable for the engagement, assesses inherent and control risk from the risk assessment and the walkthrough, and solves for detection risk: the higher the residual risk, the lower the detection risk the auditor can tolerate, and the more testing it takes to get there. The table shows the logic with illustrative percentages. The numbers are not to be believed literally, which is the model’s most important caveat and is dealt with below; they are there to make the direction and the scale of the relationships visible.

ScenarioInherent riskControl riskResidual risk (IR x CR)Acceptable audit riskDetection risk the auditor can accept (AR / residual)What it means for the work
Route cash at a beverage distributor, after an Unsatisfactory prior reportHigh (0.9)High (0.8)0.725%About 7%Extensive testing: full-population analytics plus large samples; little reliance on controls; site visits
Vendor master maintenance with a strong, recently tested workflow controlModerate (0.6)Low (0.3)0.185%About 28%Rely on the control: test its operation with a 25-item sample; limited substantive work
Fixed asset additions, stable process, few transactionsLow (0.3)Moderate (0.5)0.155%About 33%Small sample or full review of the population if it is small; analytics on additions
Revenue recognition with manual pricing overrides at year endHigh (0.9)Moderate (0.5)0.455%About 11%Substantive testing of overrides in full; sample of standard transactions; cutoff work
Payroll at a company with a mature outsourced provider and a clean SOC 1Moderate (0.5)Low (0.2)0.105%About 50%Rely on the provider’s report and the user-entity controls; test the reconciliation and access

Three caveats keep the model honest. It is not literally multiplicative: inherent and control risk are not independent (weak controls tend to grow where risk is high and management attention is low), and the percentages are ordinal judgments dressed as probabilities. Detection risk is never zero, because sampling, human error, and management’s ability to conceal things all persist however much testing is done, and the model is sometimes used to justify testing to a spurious precision. And the acceptable audit risk is a policy decision the function should make once, in its methodology, not a dial an auditor turns to make a budget fit; a function that quietly accepts 20 percent audit risk on a high-residual-risk engagement because the hours ran out has made a decision the audit committee would want to know about. Used for what it is, a structured way to reason from the risk in the area to the work the conclusion requires, the model is the best planning tool the profession has.

Translating the model into an internal audit engagement

Internal auditors rarely write “IR x CR x DR” in a planning memo, but every well-planned engagement performs the calculation in words. The translation below maps each term of the external model to the artifact in an internal audit engagement where the same judgment is made and recorded, under the Standards that require it. The value of the mapping is that it exposes the engagements where a judgment was skipped: a work program with 25-item samples on every control, regardless of the risk assessment score, has set detection risk without ever assessing residual risk.

External audit termInternal audit equivalentWhere it is assessed and recordedStandard
MaterialitySignificance: the threshold at which an error, loss, or control failure would change a rating or matter to the board; often set as a dollar amount, a count, or a regulatory consequenceEngagement planning memo; the function’s rating criteria13.3 objectives and scope; 13.4 evaluation criteria
Inherent riskThe risk scores from the annual risk assessment, refined at engagement level for each process or objectiveRisk assessment workbook; engagement risk assessment; the risk column of the RCM9.4 audit plan; 13.2 engagement risk assessment
Control riskThe design evaluation from the walkthrough (can the control prevent or detect the risk?) and the prior operating-effectiveness historyWalkthrough documentation; RCM control and design conclusion columns; prior reports and issue log13.2; 14.1
Risk of material misstatementResidual risk carried into testing: the risk after the controls as designed, before the auditor has tested anythingThe RCM’s residual risk rating or the planning memo’s risk table13.2
Detection riskThe choice of procedures (inquiry, observation, inspection, re-performance, analytics), sample sizes, population coverage, and timingWork program and sampling memo13.6 work program; 14.1
Audit riskThe risk that the engagement’s conclusion or rating is wrong; the acceptable level is a methodology decisionMethodology manual; sampling policy (confidence levels); the conclusion in the report9.1 methodologies; 15.1 final communication
Tests of controlsOperating-effectiveness testing sized to control frequencyWork program; test sheets13.6; 14.1
Substantive proceduresDirect testing of transactions, balances, or outcomes where controls cannot be relied on, plus full-population analyticsWork program; analytics scripts13.6; 14.1

The mapping also explains a pattern reviewers see in weak files: a design conclusion that a control is not effective, followed by a 25-item operating-effectiveness test of the same control. In model terms, the auditor has assessed control risk as high and then run a procedure that only makes sense when control risk is low. The correct response to a failed design conclusion is to stop testing the control, treat control risk as maximum for that risk, and move the hours to substantive work, which is exactly what the test of design versus operating effectiveness guide sets out from the other direction.

Assessing inherent risk: the factors and a scoring table

The revised ISA 315 gave the profession a useful vocabulary for inherent risk: five factors that raise it, namely complexity, subjectivity, change, uncertainty, and susceptibility to misstatement through management bias or fraud, and the idea of a spectrum of inherent risk rather than a binary high or low. Internal audit adds factors the external auditor weights less, because internal audit’s objectives extend beyond the financial statements: transaction volume and velocity, the degree of manual handling, the maturity of the system, staff turnover and vacancy in the process, prior audit history, and the regulatory exposure. The table scores MidState Beverage’s route cash handling and its fixed asset additions process on the same factors, which is what an engagement-level inherent risk assessment should look like: the same scale applied to different areas so that the difference in the result is a difference in the area, not in the assessor.

Inherent risk factorWhat raises itRoute cash handling (12 depots, 300 routes, $31M a year)Fixed asset additions (about 140 a year, capitalized centrally)
ComplexityMany steps, hand-offs, systems, or entitiesHigh: handheld to depot spreadsheet to route-accounting module to bank, across twelve locations and two acquired distributors on their own systems (3)Low: one approval path, one system, one accounting team (1)
SubjectivityEstimates, judgments, discretion in processingModerate: variance tolerances and override decisions at depot level (2)Moderate: capitalize-versus-expense judgments and useful lives (2)
ChangeNew systems, reorganization, acquisitions, new peopleHigh: two acquisitions not yet integrated; depot manager turnover at three sites in FY26 (3)Low: unchanged policy and team for four years (1)
UncertaintyDependence on forecasts or external conditionsLow: transactions are observable events (1)Low (1)
Susceptibility to fraud or biasCash, liquid assets, incentives, override capabilityHigh: cash and checks handled by 300 drivers; FY26 Dayton diversion of $18,400; self-approved overrides (3)Low: no cash; assets are physical and tagged (1)
Volume and velocityTransaction count and speedHigh: 37,400 settlements a year, daily (3)Low: 140 additions a year (1)
Manual handlingRe-keying, spreadsheets, paperHigh: deposit listings re-keyed at seven depots (3)Moderate: capitalization forms are manual, posting is systemic (2)
Prior audit historyOpen findings, repeat findings, no prior coverageHigh: FY27-01 rated Unsatisfactory with two High findings (3)Low: last audited FY24, Satisfactory, no open actions (1)
Regulatory exposureReporting, licensing, or legal consequences of failureModerate: sales tax and excise reporting depends on settlement accuracy (2)Low (1)
Total (maximum 27)23: high inherent risk11: low inherent risk

The scale is deliberately simple, three points per factor, because the purpose is to rank and to justify, not to measure. What matters is that the factors are written down, that the evidence for each score is a fact (“depot manager turnover at three sites”) rather than an adjective, and that the same table is used across engagements so that a score of 23 means the same thing in route cash as it would in payroll. Functions that inherit inherent risk scores from the annual risk assessment should still re-score at engagement level, because the annual assessment was done months earlier at a higher level of aggregation, and the engagement risk assessment under Standard 13.2 is where the scores are made specific enough to drive a work program; the site’s planning memo template has the table in the form most functions use.

Assessing control risk: the reliance decision

Control risk is assessed in two stages, and the model’s discipline is that the second stage is only worth performing if the first is passed. Design: from the walkthrough, can the control as it exists, performed as prescribed by someone with the authority and competence to perform it, prevent or detect the risk it is mapped to, at the precision the risk requires? Operation: has it done so consistently across the period, which is a sampling question? A control that fails design carries maximum control risk for that risk and is not tested for operation. A control that passes design is a candidate for reliance, and the decision to rely is a decision to accept a higher detection risk on the substantive side in exchange for the assurance the control test provides. The table turns the assessment into the testing consequence.

Control assessment from the walkthrough and historyControl riskReliance decisionTesting consequence
Well-designed, automated or key manual control; operated effectively in the prior period; no relevant changesLowRelyOperating-effectiveness sample at the standard size for the control’s frequency (25 for daily, 40 for high risk or multiple per day, 60 for very high volume or where reliance is critical); minimal substantive testing
Well-designed control, not previously tested or changed since last testedModerate until testedRely if the test passesFull operating-effectiveness sample; hold substantive procedures in reserve; if the sample shows a deviation, control risk reverts to high and the reserve procedures run
Control exists but precision is insufficient for the risk (tolerance too wide, review too high-level, evidence of review absent)HighDo not relySubstantive testing and analytics on the population; report the design gap
Control missing for an identified riskMaximumNot applicableSubstantive procedures sized for the residual risk; a design finding regardless of what the substantive work shows
Compensating control identified by management after the gap is raisedHigh until evidencedRely only if it operated in the period and is evidencedWalk and test the compensating control before reducing the substantive work; unevidenced compensating controls do not reduce control risk
Control operated by a third party covered by a SOC 1 Type 2 reportLow to moderate, depending on the report’s period, exceptions, and the complementary user-entity controlsRely on the report for the provider’s controls; test the user-entity controls yourselfBridge letter for the gap period; test the reconciliations and access controls on your side

Two points about reliance that the model makes explicit. Reliance is a bet on the sample: relying on a control tested with 25 items accepts, at the confidence levels most functions use, a real chance that the control fails more often than the sample shows, which is why high-residual-risk areas use larger samples or do not rely at all. And reliance decays: a control tested in FY26 tells you less about FY27 with every change in people, systems, and volume, and the FY26 result is an input to control risk, not a substitute for testing. The control deficiency evaluation guide covers what to do with the gaps this stage finds.

Managing detection risk: procedures, samples, and analytics

Detection risk is where the auditor spends the budget, and there are three levers. The first is the procedure mix: inquiry alone leaves detection risk near its maximum, because it tests what people say; inspection of documents and re-performance of the control pull it down; observation of the control operating pulls it further for the moment observed. The second is coverage: a sample tests a slice and leaves sampling risk, while full-population analytics tests every transaction for the specific conditions coded and leaves only the risk that the conditions were the wrong ones. The third is sample size, which for attribute testing is set by the confidence level the function’s methodology requires and the deviation rate it can tolerate; the common sizes of 25, 40, and 60 correspond, roughly, to increasing confidence that a control with a low true failure rate would have shown a deviation. The table shows how the levers combine, with the acceptable detection risk from the model as the target.

Acceptable detection risk (from the model)Procedure mixCoverage and sampleTimingTypical hours on a mid-sized process
Very low (under 10%): high residual risk, low tolerance for a wrong conclusionRe-performance and inspection as the primary procedures; observation of custody steps on site; inquiry only to direct the other workFull-population analytics for every risk that can be expressed as a rule, plus samples of 40 to 60 for controls that survive design; substantive tests of the highest-risk transactions in fullAcross the whole period, including a period-end cutoff test; unannounced where cash or inventory is involved200 to 350
Low (10% to 20%)Inspection and re-performance for key controls; analytics on the main populationSamples of 25 to 40 on key controls; analytics for duplicates, approvals, and timing on the full population; targeted substantive tests where analytics flagInterim testing with a roll-forward to period end120 to 200
Moderate (20% to 35%)Inspection of control evidence; analytics where cheapSamples of 25 on key controls relied upon; limited substantive workOne point in the period with a change inquiry for the remainder60 to 120
Higher (over 35%): low residual risk areaInquiry with corroborating inspection of a few items; analytics if the data is already availableSmall samples (10 to 15) or a full review where the population is small; reliance on prior-year results if unchangedOne point in the period30 to 60

Analytics deserve a specific word because they changed the arithmetic. A test that reads every one of MidState’s 37,400 settlements for self-approved overrides has no sampling risk for that condition; the detection risk that remains is that the rule missed a form of the problem (an override approved by a colleague who owed the driver a favor, say) and that the data extract was incomplete, which is why the completeness of the population and the reliability of the report it came from are tested first, as the IPE testing guide describes. Where analytics can express the risk, they should carry the detection-risk load and samples should be reserved for what analytics cannot see: the quality of a judgment, the existence of a document, the independence of a reviewer. The audit evidence guide ranks the procedures by the reliability of what they produce, and the sampling guide gives the sizes and the deviation rules.

Worked example: two engagements at MidState Beverage

MidState Beverage is a three-state drinks distributor with twelve depots and 300 delivery routes, where about 4,200 smaller customers pay drivers in cash and checks, roughly $31 million a year. Its FY27 plan opened with route cash handling, after a Dayton driver diverted $18,400 over five months in FY26, and later in the year ran a small fixed asset additions review at the request of the CFO. The two engagements sit at opposite ends of the model, and the table shows how the same reasoning produced work programs of very different shape and cost. The route cash engagement ended as report FY27-01, rated Unsatisfactory, with five findings; the fixed asset review issued two Low observations.

Model stepRoute cash handling (FY27-01)Fixed asset additions
Significance thresholdAny undetected diversion; settlement variances above $500 per route-day; any depot with no independent reconciliationMisclassified additions above $25,000 in aggregate; any untagged asset above $5,000
Inherent riskHigh (23 of 27): cash, twelve sites, manual re-keying, acquisitions, prior finding, fraud historyLow (11 of 27): few transactions, one system, stable team
Control risk from the walkthroughsHigh: at nine depots the depot manager prepared and approved the settlement reconciliation; override review not performed against the $25 per route-day tolerance; sync exception report unread; deposit listings re-keyed at seven depotsLow: capitalization approval by the controller against a written policy, asset tagging by facilities with a reconciliation to the register quarterly, both evidenced for the prior four quarters
Residual risk carried into testingVery highLow
Acceptable detection riskVery low: the conclusion had to be able to say whether diversion was occurring, not only whether controls were designedModerate to high: a wrong conclusion would misstate an immaterial balance
Procedures chosenFull-population analytics on all 37,400 settlements (variance patterns, self-approved overrides, deposits lagging settlements, customers with no statement); re-performance of settlement reconciliations for 60 route-days across all twelve depots, selected by the auditors; observation of cash counts at four depots, two unannounced; customer confirmations for 90 accounts with recurring short-pays; inspection of bank deposit records against depot listings for three months at the seven re-keying depotsInspection of the capitalization approval and policy test for a sample of 25 additions; analytics on the full population of 140 for additions below the capitalization threshold and for duplicated descriptions; physical verification of 15 assets; one-quarter re-performance of the register reconciliation
Reliance on controlsNone for the settlement reconciliation and override review; limited reliance on the bank reconciliation performed by corporate finance, which was testedFull reliance on approval and tagging controls after the 25-item test passed
Hours520 planned; 548 actual45 planned; 42 actual
ResultUnsatisfactory: 1,412 self-approved overrides in 37,400 settlements; reconciliations not independent at 9 of 12 depots; 1,130 of 4,200 customers receiving no statement; 38 route-days at exactly the tolerance referred for investigationSatisfactory: two Low observations on documentation of useful-life judgments
Residual audit risk after the workLow: the analytics covered the population for the conditions that matter, the re-performance covered every depot, and the conclusion states the limits (customer confirmations were a sample; unrecorded sales cannot be detected from settlement data alone)Moderate and accepted: the conclusion says the controls operated and the population analytics found no exceptions; a misclassification below the threshold could exist

The route cash engagement ran 28 hours over budget and nobody objected, because the planning memo had said in advance that the acceptable detection risk was very low and why, and the audit committee had approved a plan that priced it accordingly. The fixed asset review took less than a week and the CFO got a clean answer that was as reliable as it needed to be. Both are the model working. The failure mode the model prevents is the one where both engagements get 25-item samples of whatever controls the process owner listed, take about 120 hours each, and produce two Satisfactory reports, one of which is wrong.

Audit risk, business risk, and engagement risk: keeping them apart

Three risks share the word and are managed by three different people with three different tools. Business risk belongs to management and is what the audit assesses. Audit risk belongs to the auditor on the engagement and is what the model manages. Engagement risk, in the sense the Standards use when they require the chief audit executive to plan and resource the function, belongs to the head of audit and covers whether the plan, the people, and the hours are adequate to the mandate: the risk that the function audits the wrong things, or the right things badly, across the year. Conflating them produces recognizable errors. A planning memo that lists the business risks of route cash and calls them “audit risks” has described what to audit but not how hard; a report that says “the audit risk in this area is high” when it means the process is risky misleads a reader who knows the term; and a function that reports “engagement risk” to its committee as the sum of the business risks in its plan has told the committee nothing about whether the function can deliver.

RiskDefinitionOwnerManaged throughMidState exampleWhere it is recorded
Business riskThe risk that an event or condition prevents the organization or process from achieving its objectivesManagement; the board for appetiteControls, risk management, insurance, strategyA driver diverts route cash; a depot fails to deposit; a customer is never billedRisk register; RCM risk column; the engagement’s objectives
Audit riskThe risk that the engagement’s conclusion is wrong given the factsThe engagement lead and reviewerThe model: assess inherent and control risk, set detection risk through procedures and samplesConcluding that settlement controls are effective when nine depots have no independent reconciliationPlanning memo; sampling memo; the stated limitations in the report
Engagement and plan risk (function level)The risk that the function’s plan, resources, and methodology do not deliver the assurance the board expectsThe chief audit executive; the audit committeeRisk-based planning, resourcing, methodology, quality program, reporting of coverage gapsAuditing route cash at four depots because the budget would not stretch to twelve, and not telling the committeeAnnual plan and its uncovered-areas section; committee reporting; QAIP results

The three connect in one direction. Business risk, scored in the annual assessment, sets inherent risk for the engagement; the function-level decision about how much assurance the board wants on that business risk sets the acceptable audit risk; and the engagement’s procedures are then what the model says they must be. A committee that wants high assurance on route cash and approves a plan that funds 120 hours has created a function-level risk the chief audit executive must report, because the engagement cannot reach the audit risk the committee’s expectation implies. The site’s guides to the risk appetite statement and to the internal audit plan cover the two ends of that chain.

Documenting the assessment so a reviewer can follow it

An audit risk assessment that lives in the engagement lead’s head fails the Standards’ documentation requirements and, more practically, fails the reviewer who has to sign the report. The minimum record is short. In the planning memo: the significance threshold and its basis; the inherent risk score per risk or process area with the factual evidence for each factor; the control risk assessment per key control from the walkthrough, with the design conclusion; the resulting residual risk; and the acceptable audit risk the methodology sets for an engagement of this rating. In the work program: for each risk, the procedures chosen and the sentence that links them to the residual risk (“residual risk very high; no reliance on the reconciliation control; full-population analytics plus 60 re-performances across all depots”). In the report: the conclusion, and the limitations that describe the detection risk that remains (“customer confirmations were performed on a sample; unrecorded sales cannot be detected from settlement data”). That last item is the one most reports omit, and it is the one that protects the function when a loss surfaces later in an area the engagement covered, because it shows the committee was told what the conclusion did and did not establish.

Reviewers should be able to trace each sample size in the file back to a residual risk rating and each residual risk rating back to a design conclusion and an inherent risk score. Where the trace breaks, the sample size was inherited from habit, and the file cannot show why 25 was enough. The audit work program guide shows the linkage column in the program, and the workpaper example shows how the sampling memo records the decision; the free RCM Workbench carries the risk, control, design conclusion, and residual risk columns the model needs in one place.

Common mistakes with audit risk

FailureWhat it looks likeWhy it mattersFix
Calling business risk “audit risk”The planning memo lists what could go wrong in the process under the heading “audit risks”The memo never states how much assurance the conclusion needs, so the work program is sized by habitSeparate headings: risks in the area; residual risk; acceptable audit risk; procedures
One sample size for everythingTwenty-five items on every control regardless of the risk scoreOver-testing low-risk areas and under-testing high-risk ones; the high-risk conclusion is the one that failsSample size follows residual risk and control frequency; the methodology says how
Testing operation after design failedA control rated “not effectively designed” is then tested with 25 samplesHours spent proving a non-control operated; control risk is already maximumStop at the design conclusion; move the hours to substantive procedures
Reliance on unevidenced compensating controlsManagement describes a review that “always happens” and the sample is reducedControl risk was lowered on inquiry evidence aloneWalk and test the compensating control before relying on it
Treating the model’s percentages as measurementsA memo computing detection risk to two decimal places and defending a sample of 23False precision; the components are ordinal judgmentsUse the model for direction and scale; use the methodology’s confidence levels for sizes
Letting the budget set audit riskHours run out, the sample is cut, the conclusion is unchangedThe function has silently accepted a higher audit risk than its methodology allowsCut scope explicitly and report the uncovered area; never cut assurance silently
Ignoring detection risk in analytics“We tested 100 percent” with no test of population completeness or of the rule’s coverageA complete-looking test with an untested extract can miss everythingTest the IPE first; state what the rule cannot see
No limitations in the reportA conclusion with no statement of what the procedures did and did not coverWhen a loss surfaces, the committee believes it was told the area was cleanA limitations paragraph in every report, written from the detection risk that remains
Prior-year reliance without change analysis“Controls tested effective in FY26” carried forward as low control riskPeople, systems, and volumes changed; the prior result is an input, not a conclusionChange inquiry with the performers; re-test where anything material changed
Auditor’s own judgment excluded from the modelA rating changed at the closing meeting without revisiting the risk assessmentThe file shows a conclusion the assessed risk does not supportIf the rating changes, the risk assessment and the work that supports it are updated first

The model is thirty years older than most of the people using it, and it survives because it forces one question at every stage of an engagement: given what could go wrong here and how well it is controlled, how much work does the conclusion I am about to sign actually require? Functions that can answer that question in their files produce reports the committee can rely on and budgets the committee can understand. The walkthrough guide covers the stage where control risk is assessed, and the substantive testing guide covers the procedures that carry the load when controls cannot be relied on.

Related guides

Comments

One response to “Audit Risk Explained: Inherent, Control, and Detection Risk”

  1. […] forging rapport is crucial, internal audit must keep a professional boundary. Overly chummy relationships can create perceptions of partiality. Instead, aim for a […]

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading