By the end of this chapter you'll be able to…

  • 1State the audit risk model and its components: inherent risk, control risk and detection risk
  • 2Explain why detection risk is the only component the auditor directly controls
  • 3Apply the inverse relationship between assessed risk and detection risk to determine the nature, timing and extent of procedures
  • 4State what SA 315 requires the auditor to understand about the entity and its environment
  • 5List the risk assessment procedures used to obtain that understanding
  • 6Identify a significant risk and the factors that make a risk significant
  • 7State the five components of internal control under the COSO framework
  • 8Explain segregation of duties and why it matters
  • 9State the inherent limitations of internal control
  • 10Distinguish tests of controls from substantive procedures and explain why substantive procedures are always required
💡
Why this chapter matters in CA Intermediate
The audit risk model is what ties the whole of this paper together: risk of material misstatement exists independently of the audit, a function of the entity itself, while detection risk is the only component the auditor directly controls through the nature, timing and extent of procedures. Understanding this inverse relationship — higher assessed risk demands lower detection risk, meaning more extensive and more reliable procedures — is what makes every later chapter's discussion of evidence, sampling and specific audit procedures make sense as a response to something rather than an arbitrary checklist. The five components of internal control under COSO, and segregation of duties in particular, are the vocabulary every later discussion of controls testing depends on.

Risk Assessment and Internal Control

Weightage: Chapter 3 of ICAI's Paper 5 syllabus, roughly 12 marks. This is the "understand the entity and assess the risk" stage of the audit sequence, and it is what the audit plan in the previous chapter is actually a response to.

The audit risk model

Audit risk is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated. It is a function of two components:

Risk of Material Misstatement (RMM) exists independently of the audit — it is a function of the entity and its environment, and consists of two sub-components:

Inherent risk — the susceptibility of an assertion about a class of transaction, account balance or disclosure to a misstatement that could be material, either individually or in aggregate, before consideration of any related controls. Some balances are inherently riskier than others regardless of how good the client's controls are — cash is inherently more susceptible to misappropriation than, say, land; a complex, judgement-heavy estimate is inherently more susceptible to misstatement than a simple, mechanically computed figure.

Control risk — the risk that a misstatement that could occur in an assertion and that could be material will not be prevented, or detected and corrected, on a timely basis by the entity's internal control.

Detection risk — the risk that the procedures performed by the auditor to reduce audit risk to an acceptably low level will not detect a misstatement that exists and that could be material. Detection risk is the only component of audit risk the auditor directly controls, through the nature, timing and extent of audit procedures — RMM exists regardless of what the auditor does; detection risk is a function of how the auditor responds to it.

The inverse relationship examined constantly: the higher the assessed RMM, the lower detection risk must be set to keep overall audit risk at an acceptably low level, which in practice means more extensive, more reliable procedures (more persuasive evidence, testing closer to year end rather than at an interim date, larger samples). Where RMM is assessed as low, the auditor can accept a correspondingly higher detection risk and still hold audit risk at an acceptable level, performing fewer or less extensive procedures.

Understanding the entity and its environment — SA 315

Before any risk can be assessed, the auditor must first understand the entity. SA 315 requires the auditor to obtain an understanding of: the entity's organisational structure, ownership and governance, and its business model; industry, regulatory and other external factors, including the applicable financial reporting framework; the entity's selection and application of accounting policies; the entity's objectives, strategies and related business risks that may result in risk of material misstatement; the measurement and review of the entity's financial performance; and the entity's internal control (developed as its own separate topic below).

Risk assessment procedures used to obtain this understanding include: inquiries of management and others within the entity; analytical procedures; observation and inspection; and, where the entity has an internal audit function, inquiries of appropriate individuals within it.

Significant risks are risks of material misstatement that, in the auditor's judgement, require special audit consideration — the auditor determines whether identified risks are significant by evaluating factors including whether the risk is a risk of fraud, whether it is related to significant recent economic, accounting or other developments, the complexity of transactions, whether it involves significant transactions with related parties, the degree of subjectivity in the measurement of financial information, and whether it involves significant transactions outside the normal course of business.

Internal control — the five components (COSO framework)

Internal control is the process designed, implemented and maintained by those charged with governance, management and other personnel to provide reasonable assurance about the achievement of an entity's objectives with regard to reliability of financial reporting, effectiveness and efficiency of operations, and compliance with applicable laws and regulations.

The control environment — the set of standards, processes and structures providing the basis for carrying out internal control across the organisation, including the entity's ethical values, management's commitment to competence, participation by those charged with governance, and the assignment of authority and responsibility. A strong control environment does not, by itself, prevent misstatement, but it is the foundation on which the effectiveness of the other four components depends.

The entity's risk assessment process — the entity's own process for identifying and responding to business risks relevant to financial reporting objectives, distinct from the auditor's own risk assessment (the auditor evaluates whether the entity's process is suitably designed for its circumstances).

The information system relevant to financial reporting, including the related business processes, and communication — how transactions are initiated, recorded, processed and reported, and how the entity communicates financial reporting roles, responsibilities and significant matters relating to financial reporting.

Control activities — the policies and procedures that help ensure management directives are carried out, including authorisation, performance reviews, information processing controls, physical controls, and segregation of duties. Segregation of duties is examined specifically and repeatedly: separating the functions of authorisation, custody of assets, and record-keeping among different individuals, so that no single person can both perpetrate and conceal an error or fraud.

Monitoring of controls — a process to assess the effectiveness of internal control performance over time, including ongoing evaluations and separate evaluations, and taking necessary remedial actions.

Inherent limitations of internal control

Internal control, however well designed, can provide only reasonable, not absolute, assurance that the entity's objectives will be achieved (the same reasonable-versus-absolute distinction from SA 200, applied here to controls rather than to the audit itself), because of inherent limitations: the possibility of human error or mistakes in judgement or through simple carelessness; the possibility of controls being circumvented by collusion between two or more people, or by management override of controls; and the fact that controls are generally designed to respond to routine, not unusual, transactions.

The auditor's response to assessed risk

Having assessed RMM at both the financial statement level (pervasive risks affecting the financial statements as a whole) and the assertion level (risks specific to particular classes of transactions, balances or disclosures), the auditor designs and performs further audit procedures whose nature, timing and extent are responsive to the assessed risks — this is what makes risk assessment the hinge of the whole audit: it is not a compliance exercise performed and then set aside, but the direct input that determines everything the audit does next.

Tests of controls are performed where the auditor's approach includes an expectation that controls are operating effectively, or where substantive procedures alone would not provide sufficient appropriate evidence. Substantive procedures — tests of details and substantive analytical procedures — are always performed for each material class of transactions, balance and disclosure, regardless of the assessed level of control risk, because control risk assessment alone can never be reduced to zero and substantive evidence is always required to some extent.

Key formulas & results

Everything to memorise for the exam hall, in one card. Screenshot this for revision.

Audit Risk = Risk of Material Misstatement x Detection Risk
Risk of Material Misstatement = Inherent Risk x Control Risk, existing independently of the audit
Detection risk is the only component the auditor directly controls, through nature/timing/extent of procedures
Higher assessed RMM requires LOWER detection risk — more extensive, more reliable, more year-end-focused procedures
Five COSO components: control environment, entity's risk assessment process, information system and communication, control activities, monitoring
Segregation of duties: separate authorisation, custody of assets, and record-keeping among different individuals
Substantive procedures are always performed for each material class of transaction/balance/disclosure regardless of assessed control risk
⚠️

Traps CA Intermediate sets — and how to dodge them

These are the exact option-traps and misreads that cost marks under negative marking.

WATCH OUT
Treating audit risk, inherent risk, control risk and detection risk as interchangeable rather than as a specific multiplicative model with distinct components
WATCH OUT
Believing the auditor can directly control inherent risk or control risk, when only detection risk is directly within the auditor's control
WATCH OUT
Getting the direction of the inverse relationship backwards — assuming higher assessed risk permits fewer procedures
WATCH OUT
Skipping the SA 315 understanding-the-entity step and moving straight to procedures without first building the required understanding
WATCH OUT
Assuming any unusual transaction automatically qualifies as a significant risk without checking it against the specific evaluation factors
WATCH OUT
Confusing the entity's own risk assessment process (one of the five COSO components) with the auditor's risk assessment
WATCH OUT
Believing a strong control environment alone guarantees effective internal control, when it is only the foundation the other components depend on
WATCH OUT
Assuming internal control, however well designed, can eliminate the risk of misstatement entirely, ignoring its inherent limitations
WATCH OUT
Omitting substantive procedures because control risk was assessed as very low, when some substantive evidence is always required

Exam-pattern practice

PYQ-style questions with full solutions. Work through them as a readiness check — mark yourself honestly and get your gap report at the end.

Readiness check

Are you exam-ready for Risk Assessment and Internal Control?

15 problems from this chapter. Try each one, reveal the worked solution, mark yourself honestly — get your gap report at the end.

15 questions~11 min

5-minute revision

The whole chapter, distilled. Read this the night before the exam.

  • Audit Risk = RMM x Detection Risk; RMM = Inherent Risk x Control Risk
  • RMM exists independently of the audit; detection risk is the only component the auditor directly controls
  • Higher assessed RMM demands LOWER detection risk — more extensive, more reliable, more year-end-focused procedures
  • SA 315: understand organisational structure/governance, industry/regulatory factors, accounting policies, objectives/strategies/business risks, performance measurement, and internal control
  • Risk assessment procedures: inquiry, analytical procedures, observation and inspection, plus internal audit inquiries where applicable
  • Significant risks need special consideration: check fraud risk, recent developments, complexity, related parties, subjectivity of measurement, unusual transactions
  • Five COSO components: control environment (the foundation), the entity's own risk assessment process, information system and communication, control activities, monitoring
  • Segregation of duties separates authorisation, custody, and record-keeping among different people
  • Internal control gives reasonable, never absolute, assurance — limited by human error, collusion, management override, and its focus on routine transactions
  • Tests of controls are optional (used where relied on or where substantive alone is insufficient); substantive procedures are always required regardless of assessed control risk

CA Intermediate question blueprint

How this topic is asked, tier by tier — so you can prep to the pattern.

Typical weightage: 12

Exam-hall strategy

Battle-tested tips from mentors and toppers for this topic under the sectional clock.

  1. State the audit risk model explicitly and identify which component a fact pattern is describing before answering
  2. Always connect an assessed risk level to its consequence for detection risk and therefore for the nature, timing and extent of procedures
  3. Cite SA 315 explicitly whenever discussing understanding the entity or risk assessment procedures
  4. For significant risk questions, run through the specific evaluation factors rather than asserting a conclusion
  5. Name all five COSO components when the question calls for internal control generally, not just the one most obviously relevant
  6. State segregation of duties' three separated functions explicitly: authorisation, custody, record-keeping
  7. Always note that substantive procedures are required regardless of how favourably control risk is assessed

Beyond the exam

Where this skill shows up in the job you're competing for — and in life.

The audit risk model is the conceptual backbone of every …

The audit risk model is the conceptual backbone of every risk-based audit methodology used by every major audit firm worldwide

SA 315's understanding-the-entity requirement is performe…

SA 315's understanding-the-entity requirement is performed at the start of every real audit engagement, typically through a formal, documented planning meeting with client management

Segregation of duties reviews are a standard first step i…

Segregation of duties reviews are a standard first step in any internal control assessment or fraud risk evaluation, in both audit and internal consulting contexts

The distinction between tests of controls and substantive…

The distinction between tests of controls and substantive procedures directly shapes audit fee negotiations, since a client with strong, well-tested controls can genuinely reduce the extent, and therefore cost, of substantive audit work

Where else this topic is tested

Prepare once, score in every exam that asks it.

CA Final Paper 3 — Advanced Auditing, Assurance and Professional Ethics, where risk assessment is extended to group audits and complex entities
CS Executive — Secretarial Audit, Compliance Management and Due Diligence
CMA Intermediate — Cost and Management Audit
ACCA Audit and Assurance, where ISA 315 and the COSO framework are examined in near-identical terms

Questions aspirants ask

Pulled from the Q&A community and mentor sessions.

Because assessing inherent and control risk is precisely what tells the auditor how low to set detection risk, which is the only lever available to manage overall audit risk. Without assessing the risk of material misstatement, the auditor would have no principled basis for deciding how extensive, or how reliable, the audit procedures need to be for any given area; assessing RMM is the diagnostic step, and calibrating detection risk through the design of procedures is the responsive step, and the two only work together — a candidate cannot skip the diagnosis and still expect a sensible response.

Inherent risk is a neutral, descriptive fact about the nature of a balance or transaction class, not a judgement about the client's honesty or competence; cash is inherently risky because of what it is, easily moved, easily concealed, universally desired, regardless of how honest or careful a particular client's staff happen to be. High inherent risk simply means the auditor needs to plan more robust procedures for that specific area, exactly as high control risk does, and neither on its own implies wrongdoing; it is the auditor's overall risk assessment, combining inherent risk, control risk and any specific red flags observed, that determines how much scrutiny an area genuinely warrants.

Yes, control risk can be assessed at the maximum, meaning the auditor concludes that controls are unlikely to prevent or detect a material misstatement, often because controls are absent, poorly designed, or known to be ineffective, exactly the persistent cash weakness scenario in this chapter's problems illustrates. Where control risk is assessed at maximum, the auditor plans to rely entirely on substantive procedures for that area, without performing tests of controls at all, since there would be no controls whose effectiveness is worth confirming, and detection risk must then be set very low, meaning correspondingly extensive and reliable substantive procedures, to compensate for the absence of any control-based assurance.
Header Logo