What Is Audit Risk?
Audit risk is the risk that the auditor gives an inappropriate opinion when the financial statements are materially misstated. Here's the model and what each component means.
Audit risk is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated. In plain terms, it's the chance the auditor signs off accounts that are actually wrong. Managing it down to an acceptable level is the whole point of planning and performing an audit.
The audit risk model
Audit risk is usually broken into components, often expressed as: audit risk = inherent risk × control risk × detection risk.
- Inherent risk — the susceptibility of a balance or transaction to material misstatement before considering controls (for example, complex estimates or judgemental areas).
- Control risk — the risk that the client's internal controls fail to prevent or detect a misstatement.
- Detection risk — the risk that the auditor's own procedures fail to detect a misstatement that exists.
How auditors respond to risk
Inherent and control risk are properties of the client — the auditor assesses but cannot change them. Detection risk is the one the auditor controls: if inherent and control risk are high, the auditor lowers detection risk by doing more work, better-targeted procedures, or using more experienced staff.
Audit risk in ACCA AA and AAA
Risk questions are a staple of AA and AAA. The marks come from identifying a specific risk in the scenario, explaining why it's a risk, and describing a relevant auditor response — not from listing generic risks. Practising these and marking them against the official ACCA scheme with The 50% Club shows you exactly how to turn a scenario into scoring points.