AUDIT RISK
Audit risk is defined as: The risk of that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated. (Typically, stating that the financial statements are true and fair, when in fact they are not). Audit risk is further defined by way of a formula: AUDIT RISK = INHERENT RISK X CONTROL RISK X DETECTION RISK Inherent risk The risk of errors or misstatements due to the nature of the company and its transactions. ISA 200 requires the audit team to have a good knowledge of how the clients activities are likely to affect its financial statements, and the audit team should discuss these matters in a planning meeting before deciding on the detailed approach and audit work to be used. Such a meeting is compulsory under ISA 315 and must be documented. Control risk Control risk is the risk of errors or misstatements because the companys internal controls are not strong enough to prevent, detect and correct them. Control risk increases due to the lack of suitable procedures implemented by the client. The implementation of such procedures will have a cost, e.g.: the installation of new equipment the employment of extra staff the time taken by additional administrative procedures. The client therefore needs to make a judgement about whether the benefits of the control outweigh the costs of implementing it. Detection risk This is the risk that the auditors procedures do not pick up material misstatements. Detection risk is a function of the effectiveness of an audit procedure and of its application by the auditor. Detection risk cannot be reduced to zero because the auditor usually does not examine all of a class of transactions, account balance, or disclosure and because of other factors. Such other factors include the possibility that an auditor might select an inappropriate audit procedure, misapply an appropriate audit procedure, or misinterpret the audit results. These other factors ordinarily can be addressed through adequate planning, proper assignment of personnel to the engagement team, the application of professional scepticism, and supervision and review of the audit work performed. Detection risk includes sampling risk. It is the risk that the sample may not be representative. Inherent risk and control risk cannot be directly influenced by the auditor, as they relate to the nature of the entity and its systems. (Together these two risks are known as the Entity risk.) The only risk that the auditor can change is detection risk. Therefore, once inherent and control risk have been assessed, and with a maximum overall audit risk score in mind, detection risk becomes the balancing figure. Detection risk will be a major variable in determining the extent of audit procedures, e.g. sample sizes for audit tests.
[Link]@[Link]