is-auditing10 min read

Audit Risk Assessment: Inherent, Control, and Detection Risk

Master the audit risk model and its three components. Learn how inherent, control, and detection risk affect IS audit planning for the CISA exam.

CISAPractice|

The Audit Risk Model

Audit risk is the risk that an auditor issues an incorrect opinion or conclusion. Understanding the audit risk model is fundamental to IS audit planning and is a core CISA exam topic. The model breaks audit risk into three components that auditors must assess and manage.

Components of Audit Risk

Inherent Risk

Inherent risk is the susceptibility of an area to material error or misstatement, assuming no internal controls are in place. It represents the natural risk associated with a process, system, or transaction type before considering any mitigating controls.

Factors that increase inherent risk include:

  • Complexity: Complex systems, transactions, or processes are more prone to errors.
  • Volume: High transaction volumes increase the opportunity for errors.
  • Sensitivity: Systems handling sensitive data (financial, personal, health) carry higher inherent risk.
  • Change: New systems, significant upgrades, or organizational changes introduce uncertainty.
  • Manual processes: Manual procedures are more susceptible to human error than automated controls.
  • External factors: Regulatory requirements, industry threats, and economic conditions affect inherent risk.

Control Risk

Control risk is the risk that internal controls fail to prevent, detect, or correct material errors or misstatements. It reflects the effectiveness of the organization's control environment.

Factors that increase control risk include:

  • Weak control design: Controls that are not properly designed to address identified risks.
  • Poor implementation: Controls that exist on paper but are not consistently executed.
  • Lack of segregation of duties: Concentrated responsibilities that bypass normal checks.
  • Inadequate monitoring: Failure to review control effectiveness regularly.
  • Override capability: The ability of management or privileged users to bypass controls.

Detection Risk

Detection risk is the risk that audit procedures fail to detect material errors or misstatements that exist. This is the only component of audit risk that the auditor directly controls through the nature, timing, and extent of audit procedures.

Factors that increase detection risk include:

  • Inadequate audit procedures: Using the wrong tests or techniques for the area being audited.
  • Insufficient sample size: Testing too few items to reliably detect errors.
  • Poor timing: Performing procedures at the wrong time or covering the wrong period.
  • Auditor inexperience: Lack of knowledge or skills relevant to the area being audited.

The Audit Risk Formula

The relationship between these components is expressed as:

Audit Risk = Inherent Risk x Control Risk x Detection Risk

Auditors manage overall audit risk by adjusting detection risk. When inherent risk and control risk are high, the auditor must reduce detection risk by performing more extensive audit procedures. Conversely, when inherent and control risks are low, the auditor can accept higher detection risk, requiring fewer procedures.

Practical Application

During audit planning, the auditor assesses inherent and control risk to determine the appropriate level of detection risk. A system with high complexity (high inherent risk) and weak controls (high control risk) demands thorough audit procedures (low detection risk) to keep overall audit risk acceptable.

CISA Exam Tips

Remember that inherent risk and control risk exist independently of the audit; the auditor assesses them but cannot change them. Detection risk is the only component the auditor can control. The exam may present scenarios requiring you to determine how to adjust audit procedures based on the risk assessment of an area.

Related Tags

IS AuditingCISA ExamRisk AssessmentAudit RiskAudit Planning

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free