22.1 Audit Risk Model and Fraud Risk

Key Takeaways

  • The Audit Risk Model expresses Audit Risk as the mathematical product of Inherent Risk, Control Risk, and Detection Risk: AR=IR×CR×DRAR = IR \times CR \times DR, where the Risk of Material Misstatement (RMM=IR×CRRMM = IR \times CR) exists independently of the audit.

  • Acceptable Detection Risk bears an inverse relationship to the assessed Risk of Material Misstatement (DR=ARRMMDR = \frac{AR}{RMM}); when RMM is assessed as high, the auditor must set a lower acceptable Detection Risk and gather more persuasive, year-end substantive evidence.

  • Under PSA 240, fraud is distinguished from error by intentionality, and professional standards mandate two non-rebuttable or presumed fraud risks: the risk of management override of controls (present on all audits) and the presumed risk of fraud in revenue recognition.

Last updated: September 2026

Audit Risk Model and Fraud Risk

Because an audit provides reasonable rather than absolute assurance, the auditor designs procedures that keep audit risk acceptably low. This section covers the audit risk model under PSA 200 and PSA 315 (Revised 2019), the components of the risk of material misstatement and detection risk, and the auditor's responsibilities for fraud under PSA 240, including the presumed fraud risk in revenue recognition and management override of controls.


1. The Audit Risk Model: Mathematical & Conceptual Framework

Audit Risk (AR) is the risk that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated. For example, issuing an unmodified (clean) opinion on financial statements that contain a material misstatement due to overstated revenue constitutes an audit failure driven by unmanaged audit risk.

                                    The Audit Risk Model
                                              │
                                      Audit Risk (AR)
                   (Target: Acceptably Low Level, e.g., 5% or 1%)
                                              │
                    ┌─────────────────────────┴─────────────────────────┐
                    ▼                                                   ▼
       Risk of Material Misstatement (RMM)                     Detection Risk (DR)
     (Entity's Inherent & Internal Controls)                 (Auditor's Procedures)
                    │                                                   │
         ┌──────────┴──────────┐                               ┌────────┴────────┐
         ▼                     ▼                               ▼                 ▼
   Inherent Risk         Control Risk                   Substantive Tests    Substantive
       (IR)                  (CR)                          of Details         Analytics

The Mathematical Formulation

Pursuant to PSA 200, Audit Risk is modeled as a joint probability function:

Audit Risk (AR)=Inherent Risk (IR)×Control Risk (CR)×Detection Risk (DR)\text{Audit Risk } (AR) = \text{Inherent Risk } (IR) \times \text{Control Risk } (CR) \times \text{Detection Risk } (DR)

Where:

  • Risk of Material Misstatement (RMM): The combination of Inherent Risk and Control Risk (RMM=IR×CRRMM = IR \times CR). RMM represents the likelihood that financial statements contain a material misstatement prior to the audit. RMM is the entity's risk and exists independently of the audit. The auditor cannot change RMM; the auditor can only assess it through risk assessment procedures.
  • Detection Risk (DR): The risk that the procedures performed by the auditor to reduce audit risk to an acceptably low level will not detect a misstatement that exists and that could be material. Detection risk is the auditor's risk. It is the only component of the model that the auditor directly manages and controls through the nature, timing, and extent of substantive audit procedures.

Solving for Acceptable Detection Risk

In planning the audit, the auditor establishes a target acceptable Audit Risk (e.g., AR=0.05AR = 0.05 or 5%) and assesses Inherent Risk and Control Risk based on understanding the client. The auditor then solves for the acceptable level of Detection Risk (DRDR):

DR=ARIR×CR=ARRMMDR = \frac{AR}{IR \times CR} = \frac{AR}{RMM}

The Fundamental Inverse Relationship

The relationship between assessed RMM and acceptable Detection Risk is strictly inverse:

   Assessed RMM (IR x CR) is HIGH   ════►   Acceptable Detection Risk (DR) must be LOW
                                            Auditor must perform MORE PERSUASIVE,
                                            EXTENSIVE, and YEAR-END substantive tests.

   Assessed RMM (IR x CR) is LOW    ════►   Acceptable Detection Risk (DR) can be HIGH
                                            Auditor may perform LESS EXTENSIVE tests,
                                            use INTERIM testing, and rely on analytics.
Assessed RMM LevelAcceptable Detection RiskNature of Substantive ProceduresTiming of Substantive ProceduresExtent of Substantive Procedures
High RMM (Weak controls, complex transactions)Low DRMore reliable, direct external evidence (e.g., physical inspection, external confirmation, recomputation).Performed at year-end or after the balance sheet date.Larger sample sizes, lower testing thresholds.
Moderate RMMModerate DRBalanced mix of internal documentation, inquiry, and external confirmations.Mix of interim testing and year-end roll-forward testing.Standard sample sizes based on audit tables.
Low RMM (Strong controls, routine transactions)High DRLess persuasive evidence acceptable; heavy use of substantive analytical procedures.Performed at interim dates with minimal year-end review.Smaller sample sizes, higher testing thresholds.

Important Board Exam Rule: Detection Risk can never be reduced to zero because of the inherent limitations of an audit, including the use of testing/sampling, human fallibility in evaluating evidence, and the reality that audit evidence is persuasive rather than conclusive.


2. Detailed Components of the Risk Model

A. Inherent Risk (IR)

Inherent Risk is the susceptibility of an assertion about a class of transactions, account balance, or disclosure to a misstatement that could be material, either individually or when aggregated with other misstatements, before consideration of any related controls.

Under PSA 315 (Revised 2019), the auditor assesses Inherent Risk along a spectrum of inherent risk by evaluating Inherent Risk Factors:

  1. Complexity: Intricate accounting calculations (e.g., valuation of embedded derivative financial instruments, stock option pricing models under PFRS 2, or deferred tax asset recoverability under PAS 12).
  2. Subjectivity: Transactions requiring substantial management estimation and judgment (e.g., allowance for expected credit losses under PFRS 9, fair value of non-quoted investment property under PAS 40).
  3. Change: Volatility in market conditions, rapid technological obsolescence of inventory, or newly enacted tax/regulatory frameworks.
  4. Uncertainty: Cash flow forecast ambiguity, outcome of pending patent litigation, or environmental remediation liabilities under PAS 37.
  5. Susceptibility to Misstatement Due to Management Bias or Fraud: Highly compensated executive bonuses tied to EBITDA targets, aggressive revenue growth models, or imminent debt covenant default thresholds.

B. Control Risk (CR)

Control Risk is the risk that a misstatement that could occur in an assertion about a class of transactions, account balance, or disclosure and that could be material, individually or when aggregated with other misstatements, will not be prevented, or detected and corrected, on a timely basis by the entity's internal control.

  • Control Risk is a function of the effectiveness of the design, implementation, and maintenance of internal control by management and those charged with governance.
  • Inherent Limitations of Internal Control: Control Risk can never be zero (CR>0CR > 0) because internal controls are subject to inherent limitations:
    • Human error, misunderstanding of instructions, and fatigue.
    • Faulty human judgment in decision making.
    • Collusion between two or more employees to circumvent established segregation of duties.
    • Management override of controls (executives bypassing controls using administrative authority).
    • Cost-benefit trade-offs (management consciously choosing not to implement an expensive control for a minor financial risk).

If the auditor chooses not to test internal controls (because controls are believed to be ineffective, or because testing them is operationally inefficient), Control Risk is assessed at the maximum (100% or 1.0).

C. Two Levels of Material Misstatement Risk

Pursuant to PSA 315, the auditor must assess RMM at two distinct levels:

  1. Financial Statement Level: Pervasive risks that affect the financial statements as a whole and potentially affect many individual assertions (e.g., lack of management integrity, deficient general IT control environment, going concern distress).
  2. Assertion Level: Risks related to specific classes of transactions (occurrence, completeness, accuracy, cutoff, classification), account balances (existence, rights and obligations, completeness, accuracy/valuation/allocation), and presentation/disclosure.

3. Fraud Considerations under PSA 240

Pursuant to PSA 240, misstatements in financial statements can arise from either fraud or error. The critical distinguishing factor is intentionality:

  • Error: An unintentional misstatement in financial statements, including mathematical mistakes, oversights, or misinterpretation of facts.
  • Fraud: An intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage.
                                  The Fraud Triangle
                                          │
                      ┌───────────────────┼───────────────────┐
                      ▼                   ▼                   ▼
             Incentive / Pressure    Opportunity        Rationalization
            - Meeting earnings      - Deficient         - "Just borrowing"
              targets                 internal controls - "Company underpays"
            - Bonus thresholds      - Complex structure - "Everybody cheats
            - Debt covenant ratios  - Dominant CEO        on taxes"

The Fraud Triangle

PSA 240 classifies fraud risk factors into three conditions typically present when fraud occurs (the Fraud Triangle):

  1. Incentive / Pressure: Management or employees have an incentive or are under pressure to commit fraud (e.g., declining financial performance, excessive debt maturity pressures, market expectations for unrealistic revenue growth, personal gambling debts).
  2. Opportunity: Circumstances exist that allow fraud to be perpetrated (e.g., absence of physical controls over inventory, ineffective board oversight, significant transactions with related parties not in the ordinary course of business, high employee turnover in accounting).
  3. Attitude / Rationalization: Individuals possess an ethical character or attitude that allows them knowingly and intentionally to commit a dishonest act, or they rationalize the crime (e.g., "the company owes me because I was passed over for promotion," "this is merely a temporary loan before quarter-end," "minimizing taxes benefits our employees").

Types of Fraud Relevant to the Auditor

  1. Fraudulent Financial Reporting ("Cooking the Books"): Intentional misstatements or omissions of amounts or disclosures designed to deceive financial statement users (e.g., recording fictitious sales, altering inventory counts, prematurely recognizing revenue before delivery, failing to record material liabilities).
  2. Misappropriation of Assets ("Theft / Defalcation"): Theft of an entity's assets (e.g., embezzling cash receipts, stealing inventory or scrap metals, causing the entity to pay for goods not received via fictitious vendors, using company assets for personal benefit).

Mandatory Presumptions under PSA 240

Board examinations heavily test the two mandatory presumptions required of auditors under PSA 240:

                          Mandatory Fraud Presumptions (PSA 240)
                                            │
               ┌────────────────────────────┴────────────────────────────┐
               ▼                                                         ▼
     Presumption 1: Fraud Risk                                Presumption 2: Management
       in Revenue Recognition                                   Override of Controls
  ├─ Presumed present in all audits                        ├─ Pervasive risk across all entities
  ├─ Can be rebutted ONLY in rare cases                    ├─ CANNOT BE REBUTTED under any circumstance
  └─ Example: simple single-unit real estate rental         └─ Mandatory procedures required:
     (If rebutted, must document reasons in workpapers)        1. Test journal entries & adjustments
                                                               2. Review accounting estimates for bias
                                                               3. Evaluate significant unusual transactions
  1. Presumption of Fraud Risk in Revenue Recognition: The auditor shall, based on a presumption that there are risks of fraud in revenue recognition, evaluate which types of revenue, revenue transactions, or assertions give rise to such risks (e.g., improper cutoff, fictitious invoicing, side agreements granting return rights). Rebuttal Rule: If the auditor concludes that the presumption is not applicable to the engagement (e.g., a simple investment holding company with single-source predictable rental revenue), the auditor must explicitly document the justification in the audit working papers.
  2. Risk of Management Override of Controls: Management is in a unique position to perpetrate fraud because of management's ability to manipulate accounting records and prepare fraudulent financial statements by overriding controls that otherwise appear to be operating effectively. This risk cannot be rebutted. The auditor must perform mandatory audit procedures to address management override:
    • Testing the appropriateness of journal entries recorded in the general ledger and other adjustments made in the preparation of the financial statements (especially entries made at period-end, posted by senior managers, or lacking supporting documents).
    • Reviewing accounting estimates for biases that represent a risk of material misstatement due to fraud (e.g., retrospectively comparing prior year subjective estimates to actual historical outcomes).
    • Evaluating the business rationale for significant unusual transactions outside the normal course of business.
Test Your Knowledge

In planning the audit of a commercial client's inventory account, the engagement team establishes an overall target Audit Risk of 5% (0.05). Based on preliminary risk assessment procedures, the auditor assesses Inherent Risk at 80% (0.80) due to complex valuation models and market volatility, and assesses Control Risk at 50% (0.50) after identifying moderate control deficiencies. What is the acceptable level of Detection Risk that the auditor must plan for when designing substantive procedures for inventory?

A

25.0%

B

10.0%

C

40.0%

D

12.5%

Test Your Knowledge

Under PSA 240 (The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements), which statement accurately describes the professional requirements regarding fraud risk assessments and management override of controls?

A

The auditor may rebut the risk of management override of controls if the client has an active, independent audit committee and clean internal control reports.

B

The auditor is required to assume that fraud risks always exist in inventory valuation, but may never assume fraud risks in revenue recognition.

C

Fraudulent financial reporting and misappropriation of assets can only be committed by non-managerial staff, while management is restricted to clerical errors.

D

The auditor must presume there are risks of fraud in revenue recognition (which requires documented reasons if rebutted), and must treat the risk of management override of controls as an unpredictable, pervasive risk that can never be rebutted.

Test Your Knowledge

Which condition is an example of an opportunity in the fraud triangle?

A

Management bonuses depend heavily on meeting earnings targets

B

The cashier who receives collections also posts the accounts receivable ledger

C

An employee believes the company owes them for unpaid overtime

D

Analysts expect the company's earnings to grow 20% this year

Sections you finish are checked off in the contents.