Auditing & Assurance Services - Chapter 4: The Audit Risk Model and Inherent Risk Assessment
Chapter 4: The Audit Risk Model and Inherent Risk Assessment
Overview of Audit Risk
Audit Risk (AR): The risk that an auditor will express an inappropriate audit opinion (e.g., a "clean" opinion) when the financial statements are materially misstated.
Audit risk is comprised of three key components:
Inherent Risk (IR): The likelihood that a material misstatement will occur in the first place.
Control Risk (CR): The likelihood that an existing material misstatement would not be prevented or detected by the client's internal controls.
Detection Risk (DR): The likelihood that the auditor's own substantive procedures will fail to detect a material misstatement that exists.
Understanding the Components of Audit Risk
Inherent Risk (IR)
Definition: The probability that, in the absence of internal controls, material errors or fraud could occur.
Factors Affecting Inherent Risk:
The nature of the client’s business and its strategy for competitive advantage.
The major types of transactions the client engages in.
The effectiveness and integrity of the client's managers and accountants.
Control Risk (CR)
Definition: The likelihood that the client’s internal control policies and procedures will fail to prevent or detect a material misstatement.
Factors Affecting Control Risk:
The overall control environment in which the company operates.
The existence (or lack thereof) and effectiveness of specific control activities.
Monitoring activities by oversight bodies (e.g., audit committee, internal audit function).
Detection Risk (DR)
Definition: The likelihood that the auditors’ substantive procedures will fail to detect a material misstatement that exists within an account balance or class of transactions.
Factors Affecting Detection Risk:
Nature, Timing, and Extent of Audit Procedures: The specific types of tests, when they are performed, and how many items are tested.
Sampling Risk: The risk of choosing an unrepresentative sample from the population.
Non-Sampling Risk: The risk that the auditor may reach inappropriate conclusions based upon the available audit evidence, even if the sample is representative (e.g., human error, misinterpretation).
The Audit Risk Model (ARM)
Formula:
Audit Risk (AR): Set by the auditor to a low or very low acceptable level.
Inherent Risk (IR): Assessed by the auditor, indicating a HIGH likelihood if a material misstatement is likely to enter the accounting information system.
Control Risk (CR): Assessed by the auditor, indicating a HIGH likelihood if a material misstatement is not likely to be detected by the client's internal controls.
Detection Risk (DR): Calculated by the auditor, representing the acceptable level of detection risk. A HIGH detection risk means auditors can afford less effective testing, while a LOW detection risk requires more effective testing.
Impact of Detection Risk on Audit Procedures
Lower Detection Risk Allowed (meaning more rigorous testing is needed):
Nature: More effective substantive tests.
Timing: Testing performed closer to or at year-end.
Extent: More numerous and extensive tests.
Higher Detection Risk Allowed (meaning less rigorous testing is sufficient):
Nature: Less effective substantive tests.
Timing: Testing performed at interim periods (before year-end).
Extent: Fewer tests.
Matrix Approach to Detection Risk Determination
This matrix illustrates the inverse relationship between the assessed levels of Inherent Risk (IR) and Control Risk (CR) and the acceptable level of Detection Risk (DR).
Inherent Risk (IR) \ Control Risk (CR) | Low | Moderate | High |
|---|---|---|---|
Low | DR-High | DR-Moderate to High | DR-Moderate |
Moderate | DR-Moderate to High | DR-Moderate | DR-Low to Moderate |
High | DR-Moderate | DR-Low to Moderate | DR-Low |
Fraud and Fraud Risk
Fraud: The act of knowingly making material misrepresentations of fact with the intent of inducing someone to believe the falsehood and act on it, thereby suffering a loss or damage.
Key Difference from Error: The presence of intent differentiates misstatements caused by fraud from those caused by error.
Fraud Risk: A specific instance of the risk of material misstatement related to situations where management intends to mislead the marketplace through fraudulent financial statements.
Categories of Fraud Risk Factors
Factors that might indicate an increased risk of fraudulent financial reporting fall into three categories:
Management’s characteristics and influence.
Industry conditions.
Operating characteristics and financial stability.
Specific Fraud Risk Factors
Management's Characteristics and Influence:
Management has motivation (e.g., bonuses, stock options) for fraudulent reporting.
Management decisions are dominated by a single individual or a small group.
Management fails to demonstrate an appropriate attitude toward internal control and financial reporting.
Managers are overly aggressive in financial reporting.
Managers place excessive emphasis on earnings projections.
Management participates excessively in selecting accounting principles or determining estimates.
High turnover of senior management.
Company has a known history of violations.
Evasive responses by managers and employees to auditor inquiries.
Frequent disputes between managers and auditors.
Industry Conditions:
Company profits lag behind industry averages.
New regulatory requirements could impair stability or profitability.
The company's market is saturated due to fierce competition.
The company's industry is declining or undergoing rapid changes.
Operating Characteristics and Financial Stability:
A weak internal control environment prevails.
The company cannot generate sufficient cash flows to ensure it is a going concern.
Pressure exists to obtain capital.
The company operates in a tax haven jurisdiction.
Many difficult accounting measurement and presentation issues.
Significant transactions or balances contain estimates that are difficult to audit.
Significant and unusual related-party transactions.
Accounting personnel are lax or inexperienced.
Types of Fraud
Fraudulent Financial Reporting: Intentional misstatements or omissions of amounts or disclosures intended to deceive financial statement users.
Misappropriation of Assets: Theft of assets from the entity. This encompasses various forms of employee fraud, including:
Employee Fraud: Use of fraudulent means to misappropriate funds or other property from an employer.
Embezzlement: A type of fraud where employees or nonemployees wrongfully misappropriate funds or property entrusted to their care, custody, and control, often involving false accounting entries and deception.
Larceny: Simple theft, where an employee or nonemployee misappropriates funds or property not initially entrusted to their custody (e.g., stealing cash from a register).
Defalcation: A broad term often used interchangeably with employee fraud, embezzlement, and larceny.
Overview of Fraud Targets and Methods (Examples)
Stockholders/Creditors: Fraudulent Financial Statements, Securities Fraud.
Competitors: Theft of Trade Secrets.
Owners/Managers: Insider Trading, Related-Party Transactions, Employee Bribery.
Customers: False Advertising, Short Shipments, Defective Products, Price Fixing, Shoplifting, False Refunds, False Credit Cards, Hot Checks.
Vendors/Suppliers/Consultants: Short Shipment, Double Billing, False Invoices, Employee Bribery.
Employees: Expense Account Padding, Embezzlement, Theft of Cash and Property, Kickbacks, False Benefits Claims, Padded Payroll.
Insurers: False Loss Claims.
Government: Tax Evasion, Contract Cost Padding, False Benefit Claims.
Inherent Risk Assessment
Principle: Risk assessment is foundational to the entire audit process.
Definition: Inherent risk refers to the exposure or susceptibility of an assertion within an entity’s financial statements to a material misstatement, irrespective of the system of internal controls.
Misstatements by Assertion
Auditors assess inherent risk at the assertion level. Misstatements are categorized by the assertion violated:
Occurrence: Invalid transactions are recorded (e.g., fictitious sales).
Completeness: Valid transactions or disclosures are omitted from the financial statements (e.g., unrecorded liabilities).
Accuracy: Transaction or disclosure amounts are inaccurate.
Classification: Transactions are classified in the wrong accounts.
Presentation: Transactions are inappropriately aggregated or disaggregated and are not clearly described.
Cutoff: Transactions are recorded in the wrong accounting period.
Inherent Risks of Accounts
Factors making accounts susceptible to misstatement or fraud include:
Dollar size of the account.
Liquidity (how easily an asset can be converted to cash).
Volume of transactions.
Complexity of transactions.
Subjective estimates involved in the account balance.
Understanding the Client’s Business and Its Environment
Auditing standards mandate that auditors obtain a thorough understanding of the business to properly plan and perform the audit.
This understanding includes:
Industry, regulatory, and other external factors affecting the client.
The nature of the company and its related parties.
The effect of the client’s computerized processing on financial reporting.
The accounting principles and related disclosures used by the client.
The client's objectives, strategies, and related business risks.
The client's company performance measures and analysis.
Information Sources for Understanding the Client
General Business Sources:
Trade magazines and journals specific to the client's industry.
General business magazines and newspapers.
Company Sources:
Corporate charter and bylaws or partnership agreement.
Contracts, agreements, and details of legal proceedings.
Minutes of meetings of directors and committees of the board of directors.
Information gathered from client acceptance or continuance evaluation, prior audit planning, past audits, and other engagements with the client.
Preliminary Analytical Procedures
Purpose:
Help identify potential problem areas for the audit.
Provide a standard starting point for examining financial statements.
Familiarize the auditor with the client’s business and help identify areas of risk.
Requirement: Analytical procedures are required by professional standards during the preliminary (planning) stage of the audit.
Steps for Performing Analytical Procedures
Develop an expectation: Formulate an expectation of recorded amounts or ratios.
Define a significant difference: Establish a threshold for what constitutes a significant difference from the expectation.
Compare expectation with the recorded amount: Perform the comparison.
Investigate significant differences: If a significant difference exists, investigate the cause (e.g., inquiry of management, examining supporting documents).
Document each of the preceding steps.
Note: Analytical procedures can also be used for substantive testing (though not required), and they are required at the end of the audit in the overall review stage.
Audit Team Brainstorming Discussions
Requirement: A required procedure for the audit team.
Objectives:
Gain an understanding of previous experiences with the client.
Discuss how a fraud might be perpetrated and concealed within the entity.
Discuss procedures that might effectively detect fraud.
Set the proper tone of professional skepticism and diligence for the engagement.
Timing: Discussions should be ongoing throughout the engagement.
Inquiries
Auditors should make inquiries of various client personnel and groups to gather information relevant to risk assessment:
Management
Internal Auditors
Directors (including independent directors)
Audit Committee
Other Employees who may have insights into potential risks or issues.
Overall Assessment and Documentation of Inherent Risk
Assessment Scope: Inherent risk must be assessed for each significant financial statement account and disclosure.
Evaluation Factors: Auditors should evaluate both quantitative (e.g., dollar size) and qualitative (e.g., complexity, subjectivity) risk factors.
Identifying Relevant Assertions: After identifying significant accounts and disclosures, the auditor must identify the relevant financial statement assertions.
An assertion is considered relevant if it has a “reasonable possibility of containing a misstatement that would cause the financial statements to be materially misstated.”