CHAPTER 8: OVERVIEW OF RISK-
BASED AUDIT PROCESS
AAP
Risk-Based Audit Approach
Risk-Based Audit Approach – is an audit approach that begins with an
assessment of the types and likelihood of misstatements in account balance
and then adjusts the amount and type of audit work, to the likelihood of
material misstatements occurring in account balances.
FACTORS TO CONSIDER IN
IMPLEMENTING THE AUDIT
RISK MODEL
1 High-risk activities
Existence of large non-routine
2 transactions
Matters requiring judgement or
3 management intervention.
4 Potential for fraud.
LIMITATION OF THE AUDIT RISK MODEL
Inherent risk is difficult to formally assess.
LIMITATION OF THE AUDIT RISK MODEL
The model treats each risk component as separate and independent
when in fact the components are not independent.
LIMITATION OF THE AUDIT RISK MODEL
Audit risk is judgmentally determined.
LIMITATION OF THE AUDIT RISK MODEL
Audit technology is not so fully developed that each
component of the model can be accurately assessed.
Risk-based audit vs. Account-based audit
Risk-Based Audit Account-Based
Audit
Risk-Based
Audit
In risk-based audit, the audit team views all activities in the organization first in terms of
risks to strategies and objectives and then in terms of management’s plans and processes
to mitigate risk. The auditors obtain an understanding of the client’s objectives. Then
risks are identified and the auditors determine how management plans to mitigate the
risk and whether those plans are in place and operating effectively.
Account-Based Audit
In account-based auditing, auditors first obtain an understanding of
control and assess control risk for particular types of error and frauds
in specific accounts and cycle.
The Risk-Based Audit
Process
Phase I Risk Assessment
Phase II Risk Response
Phase III Reporting
REASONABLE ASSURANCE
intended to inform the users that Auditors do not
guarantee or insure the fair presentation of the financial
statements.
FREE OF MATERIAL MISSTATEMENT
intended to inform the users that the auditor’s responsibility is limited to
material financial information. Materiality is important because it is impractical
for auditors to provide assurance on immaterial amounts.
Nature of
Risk
Risk is a concept used to express uncertainty about events
and/or their outcomes that could have a materia l effect on
the organization.
CRITICAL COMPONENTS
OF RISK
Audit Risk
The risk that an Auditor may give an unqualified
opinion on financial statements that are materially
misstated.
Engagement Risk
The economic risk that a CPA Firm is exposed to simply because it is
associated with a particular client including loss of reputation, inability of
the client to pay the auditor, or financial loss because management is not
honest and inhibits the Audit process. Engagement risk is controlled by
careful selection and retention of client.
Financial Reporting
Risk
Those risks that relate directly to the recording of
transactions and the presentation of financial data in an
organization’s financial statements.
Business Risk
Those risks that affect the operations and
potential outcomes of organizational activities.
WAYS TO CONTROL
AUDIT RISK
Avoid audit risk by not accepting
certain companies as client, i.e.
reduce engagement risk to zero
Set audit risk at a level that the
auditor believes will mitigate the
likelihood that the auditor will fail to
identify material misstatements.