Overall Audit Risk
Risk Indicator Risk Component Description of Risk
1. Client & Engagement Factors Inherent Risk Client & Engagement Factors
• New audit client • New audit client
• First-time audit engagement → Opening balances may be misstated as the
• Lack of prior audit knowledge auditor has no prior year knowledge.
(opening balances risk) • First-time audit engagement
• Frequent change of auditors → Risk that accounting policies are not
• Resistance to auditor involvement consistently applied.
• Scope limitations imposed by client • Lack of prior audit knowledge
• Low audit fees (commercial → Auditor may not identify unusual trends or
pressure) misstatements.
• Frequent change of auditors
→ May indicate management attempting to
avoid scrutiny.
• Resistance to auditor involvement
→ Management may be hiding errors or fraud.
• Scope limitations imposed
→ Auditor unable to obtain sufficient
appropriate evidence.
• Low audit fees
→ Risk that insufficient audit work is performed
due to resource constraints.
2. Industry & Environment Inherent Risk Industry & Environment
• Highly regulated industry • Highly regulated industry
• Complex legal/compliance → Risk of non-compliance with laws leading to
environment fines or misstatements.
• Rapidly changing industry (e.g. • Complex legal environment
tech, pharma) → Financial statements may omit required
• High competition disclosures.
• Economic pressure / downturn • Rapidly changing industry
• Exposure to foreign markets / FX → Risk that accounting treatments are
risk outdated or incorrect.
• High competition
→ Pressure to overstate profits to remain
competitive.
• Economic downturn
→ Increased risk of going concern issues and
asset impairment.
• Foreign exposure (FX risk)
→ Incorrect translation of foreign transactions.
3. Nature of Business Operations Inherent Risk Nature of Business Operations
• Complex manufacturing processes • Complex manufacturing processes
• Use of estimates/judgement (e.g. → Inventory valuation may be incorrect due to
provisions, valuations) costing complexities.
• High-volume transactions • Use of estimates/judgement
• Non-routine / unusual transactions → Management bias may lead to
• Decentralised operations over/understatement (e.g. provisions).
• Use of specialists (e.g. scientists, • High-volume transactions
engineers) → Errors may occur and go undetected.
• Non-routine transactions
→ Incorrect accounting treatment due to lack
of familiarity.
• Decentralised operations
→ Inconsistent application of controls across
locations.
• Use of specialists
→ Reliance on experts may lead to incorrect
assumptions.
4. Financial & Going Concern Risks Inherent Risk Financial & Going Concern Risks
• Liquidity issues • Liquidity issues
• Cash flow constraints → Entity may not meet short-term obligations.
• Going concern uncertainty • Cash flow constraints
• High debt levels → Pressure to manipulate financial results.
• Pressure to meet targets / • Going concern uncertainty
covenants → Financial statements may be prepared on
• Declining profitability incorrect basis.
• Cost cutting (e.g. reduced quality • High debt levels
control) → Risk of covenant breaches and manipulation
of ratios.
• Pressure to meet targets
→ Incentive to overstate revenue or understate
expenses.
• Declining profitability
→ Increased fraud risk or aggressive
accounting.
• Cost cutting (e.g. quality control)
→ Operational failures impacting financial
reporting.
5. Management & Governance Risks Inherent Risk Management & Governance Risks
• Questionable integrity of • Questionable integrity
management → Increased likelihood of fraud or
• Aggressive profit targets misrepresentation.
• Pressure on auditors
• Bias in estimates • Aggressive profit targets
• History of errors/fraud → Bias in revenue recognition or estimates.
• Dominant CEO / override culture • Pressure on auditors
→ Risk of inappropriate audit opinion.
• Bias in estimates
→ Overstated assets or understated liabilities.
• History of fraud/errors
→ Higher likelihood of recurrence.
• Dominant CEO
→ Risk of management override of controls.
6. Human Resources / Competence Inherent Risk Human Resources / Competence
• Inexperienced staff • Inexperienced staff
• High staff turnover → Errors in processing transactions.
• Lack of industry expertise • High staff turnover
• Over-reliance on trainees → Lack of continuity → incomplete records.
• Inadequate training • Lack of industry expertise
→ Incorrect accounting treatments.
• Over-reliance on trainees
→ Poor judgement in complex areas.
• Inadequate training
→ Misapplication of accounting standards.
7. Time & Audit Constraints Inherent Risk Time & Audit Constraints
• Tight audit deadlines • Tight deadlines
• Multiple engagements at same time → Incomplete or rushed financial reporting.
• Insufficient time for procedures • Multiple engagements
• Limited review of subsequent → Reduced audit attention.
events • Insufficient audit time
→ Failure to detect misstatements.
• Limited review of subsequent events
→ Material events not disclosed.
8. IT & Systems Risks (often IMPLIED) Inherent Risk IT & Systems Risks
• New IT systems • New systems
• System changes or migrations → Data migration errors.
• Poor system integration • System changes
• Manual overrides → Loss or corruption of data.
• Lack of audit trail • Poor integration
→ Incomplete or duplicated transactions.
• Manual overrides
→ Increased fraud risk.
• No audit trail
→ Inability to trace transactions.
9. Segregation of Duties (BIG EXAM Control Risk Segregation of Duties
AREA) • One person performs multiple roles
• One person performs multiple → Fraud can occur without detection.
roles: • No independent review
o Authorization → Errors not identified or corrected.
o Recording
o Custody
• No independent review
10. Authorization Weaknesses Control Risk Authorization Weaknesses
• Transactions not approved • Transactions not approved
• No approval hierarchy → Invalid or fraudulent transactions
• Unauthorized payments or hiring processed.
• No approval hierarchy
→ Lack of accountability.
• Unauthorized payments/hiring
→ Financial loss to the entity.
11. Documentation & Record Keeping Control Risk Documentation & Record Keeping
• Missing supporting documents • Missing documents
• Poor record keeping → Transactions cannot be verified.
• No audit trail • Poor record keeping
• Incomplete payroll records → Incomplete financial records.
• No audit trail
→ Difficult to trace errors or fraud.
• Incomplete payroll records
→ Incorrect salary payments.
12. Payroll & HR Controls Control Risk Payroll & HR Controls
• One person handles payroll • One person handles payroll
• No employee verification → Risk of ghost employees.
• Ghost employees possible • No employee verification
• No background checks → Payments made to non-existent staff.
• No ID verification • No background checks
• Employees collecting others’ wages → Hiring of dishonest employees.
• Weak hiring processes • No ID verification
→ Payments made to wrong individuals.
• Employees collecting others’ wages
→ Theft risk.
• Weak hiring processes
→ Increased fraud risk.
13. Cash Handling Controls Control Risk Cash Handling Controls
• No segregation in cash handling • No segregation in cash handling
• No supervision during payments → Theft may occur undetected.
• No reconciliation of cash • No supervision
• Lack of physical controls over cash → Increased fraud risk.
• No reconciliations
→ Errors or theft not identified.
• No physical controls
→ Cash easily misappropriated.
14. Monitoring & Review Controls Control Risk Monitoring & Review Controls
• No independent checks • No independent checks
• No reconciliations → Errors remain undetected.
• No internal audit function • No reconciliations
• Lack of supervision → Misstatements not corrected.
• No management review • No internal audit function
→ Weak oversight.
• Lack of supervision
→ Poor control enforcement.
• No management review
→ Financial misstatements not identified.
15. Control Environment Weaknesses Control Risk Control Environment Weaknesses
• Weak tone at the top • Weak tone at the top
• Lack of ethical culture → Employees may engage in unethical
• Poor governance structures behaviour.
• Lack of policies and procedures • Lack of ethical culture
→ Increased fraud risk.
• Poor governance
→ Ineffective oversight.
• No policies/procedures
→ Inconsistent processes.
16. IT Control Weaknesses Control Risk IT Control Weaknesses
• No access controls • No access controls
• Shared passwords → Unauthorized system access.
• No system backups • Shared passwords
• No change controls → No accountability.
• Weak cybersecurity • No backups
→ Loss of financial data.
• No change controls
→ Unauthorized system changes.
• Weak cybersecurity
→ Risk of data breaches.
17. Processing & Operational Controls Control Risk Processing & Operational Controls
• Errors not detected • Errors not detected
• No exception reports → Financial statements misstated.
• No review of outputs • No exception reports
• Lack of reconciliations → Irregular transactions not flagged.
• No review of outputs
→ Incorrect reports used.
• No reconciliations
→ Differences not identified.
MIXED RISKS (HIGH-LEVEL EXAM INSIGHT)
These are powerful because examiners LOVE them:
• Management integrity issues
• Weak control environment
• Incompetent staff
• Tight deadlines
• Low audit fees
• Lack of oversight