8.5 The Audit Risk Model: Inherent, Control & Detection Risk
Key Takeaways
- Audit risk is the risk that an auditor issues an inappropriate conclusion — typically certifying a system that does not in fact conform — and it decomposes into inherent risk, control risk, and detection risk.
- Inherent risk is the susceptibility of a process to nonconformity before controls are considered; in OH&S it rises with hazard energy, task variability, contractor use, and shift work.
- Control risk is the risk that the auditee's own controls fail to prevent or detect a nonconformity, and it is assessed from the design and operating effectiveness of those controls, not from management's assurances.
- Detection risk is the only component the auditor directly controls, and it is reduced by increasing sample size, using more reliable procedures, and assigning more competent auditors.
- The risk-based approach in ISO 19011:2018 requires audit effort to be concentrated where inherent and control risk are highest, which is why uniform sampling across all processes is a planning defect.
8.5 The Audit Risk Model: Inherent, Control & Detection Risk
The risk-based approach is the seventh principle of ISO 19011:2018 and, unlike the other six, it is operational rather than ethical: it tells you where to spend your hours. PECB examines the auditor's ability to apply that approach through the classical audit risk model and to distinguish the different types of risks related to audit activities.
Note the vocabulary trap that catches many candidates: this section is about risk to the audit, not about the OH&S risks of the auditee. The two are related but distinct, and the exam deliberately tests whether you can tell them apart.
1. Audit Risk Defined
Audit risk is the risk that the auditor expresses an inappropriate audit conclusion — most consequentially, recommending certification for a management system that does not conform, or that is incapable of achieving its intended outcomes.
The model decomposes it into three components:
Audit Risk = Inherent Risk × Control Risk × Detection Risk
The first two exist in the auditee's world and the auditor can only assess them. The third exists in the auditor's world and can be managed. That asymmetry is the whole practical point of the model.
| Component | Whose risk? | Auditor's power | Driven by |
|---|---|---|---|
| Inherent risk (IR) | Auditee | Assess only | Nature of the activity |
| Control risk (CR) | Auditee | Assess only | Design and operation of controls |
| Detection risk (DR) | Auditor | Control directly | Nature, timing and extent of procedures |
2. Inherent Risk
Inherent risk is the susceptibility of a process, activity, or clause area to nonconformity assuming no controls are in place. It is a property of the work itself.
Drivers that raise inherent risk in an OH&S context:
- Hazard energy — work at height, confined space entry, hot work, high-voltage electrical work, molten metal, hazardous substances, mobile plant.
- Task variability — non-routine, one-off, or emergency work where no rehearsed procedure exists.
- Organizational churn — high turnover, heavy agency or contractor use, recent mergers, rapid headcount growth.
- Complexity — multi-employer sites, outsourced processes, multi-jurisdiction legal obligations.
- Temporal exposure — night shifts, weekend working, and shutdown/turnaround periods where supervision thins.
- History — prior incidents, prior nonconformities, regulatory enforcement action.
A stationery store has low inherent risk. A refinery turnaround with 400 contractors has very high inherent risk. Nothing the organization does changes that baseline; controls act on top of it.
3. Control Risk
Control risk is the risk that a nonconformity will not be prevented, or detected and corrected, by the auditee's own control system.
Assessing it requires evaluating two separate things:
- Design effectiveness — would the control, if operated as intended, actually prevent or detect the failure? A permit-to-work system with no independent gas-test verification is defective by design.
- Operating effectiveness — is the control actually performed, consistently, by competent people? A well-designed permit system signed retrospectively at end of shift is operating ineffectively.
Indicators of high control risk:
- Internal audit programme is superficial, overdue, or performed by staff auditing their own work (a Clause 9.2 impartiality breach).
- Management review is a formality with no documented outputs or decisions.
- Monitoring under 9.1.1 measures only lagging indicators.
- Compliance evaluation under 9.1.2 has not been performed or is undocumented.
- No management of change process (8.1.3), so system controls decay silently after modifications.
- Worker consultation (5.4) is nominal, so failures are never reported upward.
Critical exam point: control risk is assessed from evidence, not from management representations. An auditee stating "our permit system is robust" is an assertion to be tested, not a basis for lowering assessed control risk. Where the auditor lacks evidence about a control, control risk is assessed as high by default.
4. Detection Risk
Detection risk is the risk that the auditor's own procedures fail to detect a nonconformity that exists. This is the only lever the auditor holds, and the model is used in reverse:
Assess IR and CR → set the acceptable overall audit risk → solve for the detection risk you can afford → design procedures to achieve it.
Where IR and CR are high, allowable detection risk is low, which forces the auditor to:
- Increase sample size — examine 25 permits instead of 5.
- Improve procedure quality — direct observation of the task being performed, rather than reading records about it.
- Shift timing — audit the night shift, attend a live confined-space entry, visit during a turnaround rather than a quiet week.
- Raise team competence — assign a technical expert for specialist processes.
- Triangulate — corroborate documentary evidence with interview and physical observation.
Conversely, where inherent and control risk are genuinely low, a higher detection risk is acceptable and a smaller sample suffices. This is what makes an audit plan risk-based rather than mechanically uniform.
Sampling vs non-sampling risk
Detection risk splits into two sources, and the exam tests the distinction:
| Type | Cause | Mitigation |
|---|---|---|
| Sampling risk | The sample examined is not representative of the population, purely as an artefact of selection | Larger samples; stratified or random selection; avoid letting the auditee choose the sample |
| Non-sampling risk | Auditor error: insufficient competence, a flawed checklist, misinterpreting the criteria, accepting weak evidence, bias | Competence assessment; team briefing; peer/quality review; professional scepticism |
Non-sampling risk cannot be reduced by examining more records — a competence or judgement failure repeated across a larger sample simply produces more wrong conclusions.
5. Applying the Model in Audit Planning
The risk assessment produces the allocation of audit days, which is the visible output examiners test.
Worked example. A certification body plans a Stage 2 audit of a construction contractor with 5 audit days available.
| Process | Inherent risk | Control risk | Allowable detection risk | Audit effort |
|---|---|---|---|---|
| Work at height | High (fatality potential) | High (2 prior falls; MOC absent) | Very low | 1.5 days; observe live tasks on two sites; sample 30 permits |
| Subcontractor management | High (8.1.4; 60% of workforce) | Medium | Low | 1 day; sample 12 subcontractor competence files |
| Plant & equipment | Medium | Low (strong maintenance records, verified) | Medium | 0.75 day; sample 10 inspection records |
| Legal register (6.1.3) | Medium | Medium | Medium | 0.75 day |
| Office ergonomics | Low | Low | High | 0.25 day; walkthrough only |
| Management review / internal audit | Medium | High (overdue) | Low | 0.75 day |
An audit plan that instead allocated 0.7 days uniformly to every process would violate the risk-based approach: it over-audits office ergonomics and under-audits the process most likely to kill someone.
On-site revision. Risk assessment is provisional. If the auditor discovers on day 2 that maintenance records have been back-dated, assessed control risk for plant and equipment jumps, allowable detection risk collapses, and the sample must be extended — reallocating time from lower-risk areas and, if necessary, formally revising the audit plan with the audit client.
A lead auditor reviews an audit plan allocating exactly half a day to each of ten processes, including both confined-space entry and office ergonomics. What is the principal deficiency?
An auditor uses a poorly constructed checklist that omits Clause 8.1.3 entirely, and consequently fails to detect that the organization has no management of change process. Which risk has materialised, and would a larger sample have prevented it?
An auditee's OH&S manager assures the audit team that the permit-to-work system is rigorously applied, and asks the auditor to reduce the permit sample accordingly. How should the auditor treat this assurance when assessing control risk?