8.5 The Audit Risk Model: Inherent, Control & Detection Risk

Key Takeaways

  • Audit risk is the risk that an auditor issues an inappropriate conclusion — typically certifying a system that does not in fact conform — and it decomposes into inherent risk, control risk, and detection risk.
  • Inherent risk is the susceptibility of a process to nonconformity before controls are considered; in OH&S it rises with hazard energy, task variability, contractor use, and shift work.
  • Control risk is the risk that the auditee's own controls fail to prevent or detect a nonconformity, and it is assessed from the design and operating effectiveness of those controls, not from management's assurances.
  • Detection risk is the only component the auditor directly controls, and it is reduced by increasing sample size, using more reliable procedures, and assigning more competent auditors.
  • The risk-based approach in ISO 19011:2018 requires audit effort to be concentrated where inherent and control risk are highest, which is why uniform sampling across all processes is a planning defect.
Last updated: September 2026

8.5 The Audit Risk Model: Inherent, Control & Detection Risk

The risk-based approach is the seventh principle of ISO 19011:2018 and, unlike the other six, it is operational rather than ethical: it tells you where to spend your hours. PECB examines the auditor's ability to apply that approach through the classical audit risk model and to distinguish the different types of risks related to audit activities.

Note the vocabulary trap that catches many candidates: this section is about risk to the audit, not about the OH&S risks of the auditee. The two are related but distinct, and the exam deliberately tests whether you can tell them apart.


1. Audit Risk Defined

Audit risk is the risk that the auditor expresses an inappropriate audit conclusion — most consequentially, recommending certification for a management system that does not conform, or that is incapable of achieving its intended outcomes.

The model decomposes it into three components:

Audit Risk = Inherent Risk × Control Risk × Detection Risk

The first two exist in the auditee's world and the auditor can only assess them. The third exists in the auditor's world and can be managed. That asymmetry is the whole practical point of the model.

ComponentWhose risk?Auditor's powerDriven by
Inherent risk (IR)AuditeeAssess onlyNature of the activity
Control risk (CR)AuditeeAssess onlyDesign and operation of controls
Detection risk (DR)AuditorControl directlyNature, timing and extent of procedures

2. Inherent Risk

Inherent risk is the susceptibility of a process, activity, or clause area to nonconformity assuming no controls are in place. It is a property of the work itself.

Drivers that raise inherent risk in an OH&S context:

  • Hazard energy — work at height, confined space entry, hot work, high-voltage electrical work, molten metal, hazardous substances, mobile plant.
  • Task variability — non-routine, one-off, or emergency work where no rehearsed procedure exists.
  • Organizational churn — high turnover, heavy agency or contractor use, recent mergers, rapid headcount growth.
  • Complexity — multi-employer sites, outsourced processes, multi-jurisdiction legal obligations.
  • Temporal exposure — night shifts, weekend working, and shutdown/turnaround periods where supervision thins.
  • History — prior incidents, prior nonconformities, regulatory enforcement action.

A stationery store has low inherent risk. A refinery turnaround with 400 contractors has very high inherent risk. Nothing the organization does changes that baseline; controls act on top of it.


3. Control Risk

Control risk is the risk that a nonconformity will not be prevented, or detected and corrected, by the auditee's own control system.

Assessing it requires evaluating two separate things:

  1. Design effectiveness — would the control, if operated as intended, actually prevent or detect the failure? A permit-to-work system with no independent gas-test verification is defective by design.
  2. Operating effectiveness — is the control actually performed, consistently, by competent people? A well-designed permit system signed retrospectively at end of shift is operating ineffectively.

Indicators of high control risk:

  • Internal audit programme is superficial, overdue, or performed by staff auditing their own work (a Clause 9.2 impartiality breach).
  • Management review is a formality with no documented outputs or decisions.
  • Monitoring under 9.1.1 measures only lagging indicators.
  • Compliance evaluation under 9.1.2 has not been performed or is undocumented.
  • No management of change process (8.1.3), so system controls decay silently after modifications.
  • Worker consultation (5.4) is nominal, so failures are never reported upward.

Critical exam point: control risk is assessed from evidence, not from management representations. An auditee stating "our permit system is robust" is an assertion to be tested, not a basis for lowering assessed control risk. Where the auditor lacks evidence about a control, control risk is assessed as high by default.


4. Detection Risk

Detection risk is the risk that the auditor's own procedures fail to detect a nonconformity that exists. This is the only lever the auditor holds, and the model is used in reverse:

Assess IR and CR → set the acceptable overall audit risk → solve for the detection risk you can afford → design procedures to achieve it.

Where IR and CR are high, allowable detection risk is low, which forces the auditor to:

  • Increase sample size — examine 25 permits instead of 5.
  • Improve procedure quality — direct observation of the task being performed, rather than reading records about it.
  • Shift timing — audit the night shift, attend a live confined-space entry, visit during a turnaround rather than a quiet week.
  • Raise team competence — assign a technical expert for specialist processes.
  • Triangulate — corroborate documentary evidence with interview and physical observation.

Conversely, where inherent and control risk are genuinely low, a higher detection risk is acceptable and a smaller sample suffices. This is what makes an audit plan risk-based rather than mechanically uniform.

Sampling vs non-sampling risk

Detection risk splits into two sources, and the exam tests the distinction:

TypeCauseMitigation
Sampling riskThe sample examined is not representative of the population, purely as an artefact of selectionLarger samples; stratified or random selection; avoid letting the auditee choose the sample
Non-sampling riskAuditor error: insufficient competence, a flawed checklist, misinterpreting the criteria, accepting weak evidence, biasCompetence assessment; team briefing; peer/quality review; professional scepticism

Non-sampling risk cannot be reduced by examining more records — a competence or judgement failure repeated across a larger sample simply produces more wrong conclusions.


5. Applying the Model in Audit Planning

The risk assessment produces the allocation of audit days, which is the visible output examiners test.

Worked example. A certification body plans a Stage 2 audit of a construction contractor with 5 audit days available.

ProcessInherent riskControl riskAllowable detection riskAudit effort
Work at heightHigh (fatality potential)High (2 prior falls; MOC absent)Very low1.5 days; observe live tasks on two sites; sample 30 permits
Subcontractor managementHigh (8.1.4; 60% of workforce)MediumLow1 day; sample 12 subcontractor competence files
Plant & equipmentMediumLow (strong maintenance records, verified)Medium0.75 day; sample 10 inspection records
Legal register (6.1.3)MediumMediumMedium0.75 day
Office ergonomicsLowLowHigh0.25 day; walkthrough only
Management review / internal auditMediumHigh (overdue)Low0.75 day

An audit plan that instead allocated 0.7 days uniformly to every process would violate the risk-based approach: it over-audits office ergonomics and under-audits the process most likely to kill someone.

On-site revision. Risk assessment is provisional. If the auditor discovers on day 2 that maintenance records have been back-dated, assessed control risk for plant and equipment jumps, allowable detection risk collapses, and the sample must be extended — reallocating time from lower-risk areas and, if necessary, formally revising the audit plan with the audit client.

Loading diagram...
Solving the Audit Risk Model for Audit Effort
Test Your Knowledge

A lead auditor reviews an audit plan allocating exactly half a day to each of ten processes, including both confined-space entry and office ergonomics. What is the principal deficiency?

A
B
C
D
Test Your Knowledge

An auditor uses a poorly constructed checklist that omits Clause 8.1.3 entirely, and consequently fails to detect that the organization has no management of change process. Which risk has materialised, and would a larger sample have prevented it?

A
B
C
D
Test Your Knowledge

An auditee's OH&S manager assures the audit team that the permit-to-work system is rigorously applied, and asks the auditor to reduce the permit sample accordingly. How should the auditor treat this assurance when assessing control risk?

A
B
C
D