AUDIT RISKS
FAKI, FAKI
fakifaki1977@[Link]
+255773144446
2024 Faki,Faki
Meaning of Audit Risk
Audit risk refers to the possibility that the auditor may
issue an incorrect opinion on the financial
statements.
The main concern is that the auditor may say the
financials are free from material misstatement when
they are not.
It involves a failure to detect errors or fraud that
could mislead users of the financial statements.
Source: ISA 200 – Overall Objectives of the
Independent Auditor and the Conduct of an Audit in
Accordance with International Standards on Auditing.
2024 Faki,Faki
Nature of Audit Risk
Audit risk arises because:
1. Audits are based on sampling and do not test 100%
of transactions.
2. Judgment is involved in interpreting accounting
standards and assessing controls.
3. Estimates and assumptions are used by
management, which may be wrong or biased.
4. Fraud risk – some frauds are difficult to detect,
especially those involving collusion.
Hence, auditors only provide "reasonable assurance",
not an absolute guarantee.
2024 Faki,Faki
Components of Audit Risk
1. Inherent Risk (IR)
This is the natural likelihood of a misstatement before
considering controls.
Factors increasing IR:
o Complex accounting
o High-value or judgmental transactions (e.g., goodwill
impairment)
o Industry risk (e.g., construction or financial services)
2. Control Risk (CR)
The chance that internal controls fail to detect or
correct misstatements.
If a company has poor segregation of duties or weak
supervision, CR increases.
2024 Faki,Faki
3. Detection Risk (DR)
The chance that auditors fail to detect a
misstatement despite performing procedures.
DR is within the auditor’s control and is inversely
related to IR and CR.
o High IR/CR → Low DR must be accepted
o This means more rigorous testing
2024 Faki,Faki
Identifying and Assessing Risks Through
Understanding the Entity – ISA 315
ISA 315 Objective:
To identify and assess the risks of material
misstatement (RMM) through gaining knowledge
about:
The entity
Its internal controls
Its environment (industry, regulations,
competition)
2024 Faki,Faki
Key Elements to Understand:
1. Nature of the Entity
o Type of business
o Revenue sources and cost structure
o Ownership structure
2. Industry, Regulatory, and External Factors
o Economic conditions
o Laws and regulations
o Technological changes
3. Objectives and Strategies
o Business goals and related risks
o Risk of not meeting targets → pressure to manipulate
results
4. Internal Control
o How the entity identifies and responds to business
risks
o Whether proper financial controls are in place
5. Financial Reporting Framework
2024
o E.g., IFRS, GAAP Faki,Faki
Detailed Testing
Detailed testing is a substantive audit
procedure that involves examining a
comprehensive set of transactions, records, or
activities, either in full or through sampling, to
verify compliance with established policies,
procedures, or controls.
This process is fundamental for gathering
evidence to assess the accuracy, reliability, and
effectiveness of the organization’s operations
and controls.
2024 Faki,Faki
Purposes of Detailed Testing
The primary objectives of detailed testing are:
Verifying Accuracy and Completeness:
Ensuring that data, transactions, or records are
accurately and completely recorded according to
established criteria, such as financial standards,
internal procedures, or regulatory requirements.
Assessing Operating Effectiveness of Controls:
Evaluating whether internal controls are operating
as designed and effectively preventing or detecting
issues like errors, fraud, or non-compliance.
Detecting Errors, Non-Compliance, or Fraud:
Identifying discrepancies, weaknesses, or instances
of fraud by thoroughly reviewing records, activities,
or transactions.
2024 Faki,Faki
Examples of Detailed Testing
Detailed testing may include various procedures
depending on the nature of the audit and the area
being examined.
Common examples are:
Invoice and Payment Reviews:
Auditors may examine invoices and payments to
ensure they are appropriately approved, reconciled
with purchase orders, and comply with company
policies and procedures.
Recalculation of Financial or Operational Data:
Auditors may perform recalculations to verify the
accuracy of amounts recorded in financial statements,
such as rechecking interest calculations or
recalculating depreciation on assets.
Physical Inventory Verification:
Auditors may compare physical inventory records with
actual stock on hand to assess the accuracy of
2024 inventory data and ensure
Faki,Fakiproper inventory controls
Risk Assessment
Risk assessment is the process of identifying,
analyzing, and evaluating the risks of material
misstatement (RMM) in the financial statements at
both the financial statement level and the assertion
level.
Audit risk assessment is one of the most critical
phases in the audit process.
It helps auditors identify areas where material
misstatements are likely to occur and to design
appropriate audit procedures to respond to those
risks.
During this phase, auditors identify and prioritize
potential risks that may impact the activity under
review.
2024 Faki,Faki
This includes considering risks related to fraud and
evaluating the significance of each risk.
The key objectives are to:
Gain an understanding of the entity and its
environment.
Identify and assess RMM due to error or fraud.
Design audit procedures that appropriately respond to
those risks.
Plan the audit efficiently and allocate audit resources
effectively.
2024 Faki,Faki
TYPE OF RISK IN RISK ASSESSMENT
Type of Risk Definition Level
Risks that affect
financial
Financial statements as a
Statement whole (e.g., Broad
Level Risk management
override of
controls)
Risks that relate to
specific
Assertion transactions or
Detailed
Level Risk balances (e.g.,
revenue
recognition)
2024 Faki,Faki
Risk Assessment Factors and Procedures
Risk Assessment Factors
Factors that may increase risk:
Transactions that are unusual or non-routine (e.g.,
one-time large asset sales)
Management bias in estimates (e.g., provisions,
impairment)
Related-party transactions (often used for fraud)
Lack of proper documentation or controls
External pressures like loan covenants or stock
exchange requirements
2024 Faki,Faki
Procedures for Risk Assessment
Auditors use several risk assessment procedures to
gather information:
1. Inquiries
o Ask management and staff about processes, risks, and
controls.
2. Analytical Procedures
o Analyze trends and ratios. Unusual movements may
indicate issues.
o E.g., Sudden revenue growth but flat cash flows →
possible fake sales
3. Observation and Inspection
o Look at operations and documents to assess controls
and environment.
o E.g., Watch how inventory is counted.
4. Team Discussion
o Brainstorming about how fraud could occur.
o Helps in identifying areas like revenue fraud or
inventory manipulation.
2024 Faki,Faki
Procedure Description Purpose
Interviews with
Identify known or
Inquiries management and
suspected risks
staff
Analytical Ratio/trend Spot unusual
Procedures analysis patterns
Watching
Evaluate internal
Observation processes (e.g.,
controls
inventory count)
Reviewing Understand
Inspection documents/contra processes and
cts risks
Identify fraud and
Brainstorming by
Team Discussion misstatement
audit team
areas
2024 Faki,Faki
Impact of Risk Assessment on the Audit
Audit Strategy and Planning
The findings from risk assessment directly impact
how the auditor plans the audit:
High-risk areas → More substantive
procedures, detailed testing
Low-risk areas → May use more analytical
procedures or rely on controls
Materiality and Sampling
Risk assessment helps set materiality
thresholds
It determines sample sizes and testing
approaches
Audit Documentation
Risks identified must be clearly documented.
Includes how the auditor plans to address those
risks
2024 Faki,Faki
Example: High-Risk Revenue Recognition
If a company recognizes revenue upfront on long-
term contracts:
Risk identified: Revenue may be overstated
Auditor response:
o Test revenue cut-offs
o Confirm contracts with customers
o Evaluate management estimates for
completion
2024 Faki,Faki
Impact on Audit Opinion
If the auditor finds risks that aren't addressed
adequately by management:
They may issue a modified opinion (qualified,
adverse, or disclaimer)
2024 Faki,Faki
END OF
LECTURE ONE
ANY QUESTIONS?
ANY COMMENTS?
23/05/2025 Faki,Faki