3.3 The Audit Risk Model: Inherent, Control & Detection Risk

Key Takeaways

  • Audit risk is the risk of an inappropriate opinion when financial statements are materially misstated; the auditor reduces it to an acceptably low level to obtain reasonable assurance.

  • Inherent risk and control risk combine as the risk of material misstatement (RMM); detection risk is the risk that audit procedures do not detect an existing material misstatement.

  • The expression AR = RMM × DR explains an inverse planning relationship but does not require literal probability scores or a universal 5% audit-risk target.

  • Higher assessed RMM calls for more persuasive responsive evidence through the nature, timing and extent of procedures.

  • When the auditor does not plan to rely on controls, the audit response takes no assurance from their operating effectiveness, but controls may still be examined for understanding or reporting.

Last updated: October 2026

3.3 The Audit Risk Model: Inherent, Control & Detection Risk

An audit provides reasonable, not absolute, assurance. Under ISA 200, audit risk is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated. The auditor designs and performs the engagement to reduce that risk to an acceptably low level.

The model and its limits

The familiar expression is:

AR=IR×CR×DRAR = IR \times CR \times DR

Inherent risk and control risk together form the risk of material misstatement:

RMM=IR×CRRMM = IR \times CR

So the planning relationship can be written as:

AR=RMM×DRAR = RMM \times DR

The expression is conceptual. ISA 200 does not prescribe a universal 5% audit-risk target, require control risk to be entered as 1.0, or turn professional judgments into objectively measured probabilities. Firms and public audit institutions may use qualitative categories or internal scales, but the documented assessment and response must comply with the standards.

Components

Inherent risk is the susceptibility of an assertion to a material misstatement before considering related controls. ISA 315’s inherent-risk factors include complexity, subjectivity, change, uncertainty and susceptibility to management bias or other fraud risk factors. A novel financial instrument or judgmental estimate may be high on the spectrum even in a well-controlled entity.

Control risk is the risk that the entity’s controls do not prevent, or detect and correct, a material misstatement on a timely basis. The auditor understands relevant controls and evaluates design and implementation as required. Operating effectiveness is tested when the planned approach relies on controls or when substantive procedures alone cannot provide sufficient appropriate evidence.

Detection risk is the risk that the auditor’s procedures fail to detect an existing material misstatement. It includes:

  • sampling risk, where a sample-based conclusion differs from the conclusion that would arise from applying the procedure to the whole population; and
  • non-sampling risk, such as choosing an unsuitable procedure, misapplying it or misinterpreting evidence.

The auditor influences detection risk through sound design, execution, supervision and review. It can be reduced but not eliminated.

The inverse planning relationship

For a given acceptable level of audit risk, higher assessed RMM means lower acceptable detection risk. The auditor responds under ISA 330 through:

  • nature — choosing more effective or persuasive procedures, such as direct confirmation, reperformance or detailed inspection;
  • timing — performing work nearer year-end or adding procedures over the roll-forward period; and
  • extent — increasing coverage or sample size where that improves the evidence.

This is not a mechanical recipe. Larger samples do not repair an irrelevant procedure. External evidence is not automatically reliable. Year-end work is not always superior when a control operates continuously and can be tested effectively over time. The response must match the assertion, population and reason for the assessed risk.

Control reliance and substantive work

If the auditor does not plan to rely on a control, testing its operating effectiveness merely to claim reliance is unnecessary. The substantive response still must be sufficient and appropriate. The auditor may nevertheless examine controls to understand the system, satisfy a reporting objective, investigate an exception or determine whether substantive procedures alone are possible.

Conversely, effective controls do not eliminate substantive procedures for material classes of transactions, balances and disclosures. ISA 330 requires a substantive response, and significant risks require procedures specifically responsive to the risk. If the response to a significant risk consists only of substantive procedures, those procedures include tests of details.

Constructed audit response

Assume a grant programme has complex eligibility rules, rapid staff turnover and a verification backlog. The auditor identifies high inherent susceptibility and finds no basis for planned reliance on affected controls. A responsive plan might combine transaction testing, direct or physical evidence, targeted data analysis and work near period end. The extent depends on materiality, population characteristics, procedure effectiveness and sampling risk—not on an automatic requirement to examine every transaction.

The working papers should connect each assessed risk to the assertion, explain the intended evidence, record results and show how exceptions changed the plan. That traceable logic is more important than a decorative numerical risk score.

Reassessment continues throughout the engagement. New contradictory evidence, control failures or unexpected error patterns can move a risk higher and require additional procedures. Conversely, a planned response may change when reliable evidence resolves an uncertainty. Every change should preserve the link between risk, assertion, procedure, result and conclusion.

Loading diagram...
Risk Assessment to Audit Response
Test Your Knowledge

If assessed RMM is high, what happens to acceptable detection risk for a given acceptably low level of audit risk?

A

It increases automatically

B

It decreases, requiring a more persuasive audit response

C

It becomes identical to control risk

D

It no longer matters

Test Your Knowledge

Which component is most directly influenced by the auditor’s procedure design and execution?

A

Inherent risk

B

Control risk

C

Detection risk

D

Business risk

Test Your Knowledge

Which is an example of non-sampling risk?

A

A representative sample happens to understate the population error rate

B

A random start selects no high-value items

C

A confidence interval is wider than planned

D

The auditor uses an unsuitable procedure or misinterprets the evidence

Test Your Knowledge

What is the appropriate response when the auditor does not plan to rely on controls in a high-risk area?

A

Design substantive procedures responsive to the assessed risk and obtain sufficient appropriate evidence without claiming unsupported control reliance

B

Set control risk mechanically to zero

C

Examine every transaction automatically

D

Omit the control environment from the entity understanding

Sections you finish are checked off in the contents.