Risk Assessment and Internal Control
Weightage: Chapter 3 of ICAI's Paper 5 syllabus, roughly 12 marks. This is the "understand the entity and assess the risk" stage of the audit sequence, and it is what the audit plan in the previous chapter is actually a response to.
The audit risk model
Audit risk is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated. It is a function of two components:
Risk of Material Misstatement (RMM) exists independently of the audit — it is a function of the entity and its environment, and consists of two sub-components:
Inherent risk — the susceptibility of an assertion about a class of transaction, account balance or disclosure to a misstatement that could be material, either individually or in aggregate, before consideration of any related controls. Some balances are inherently riskier than others regardless of how good the client's controls are — cash is inherently more susceptible to misappropriation than, say, land; a complex, judgement-heavy estimate is inherently more susceptible to misstatement than a simple, mechanically computed figure.
Control risk — the risk that a misstatement that could occur in an assertion and that could be material will not be prevented, or detected and corrected, on a timely basis by the entity's internal control.
Detection risk — the risk that the procedures performed by the auditor to reduce audit risk to an acceptably low level will not detect a misstatement that exists and that could be material. Detection risk is the only component of audit risk the auditor directly controls, through the nature, timing and extent of audit procedures — RMM exists regardless of what the auditor does; detection risk is a function of how the auditor responds to it.
The inverse relationship examined constantly: the higher the assessed RMM, the lower detection risk must be set to keep overall audit risk at an acceptably low level, which in practice means more extensive, more reliable procedures (more persuasive evidence, testing closer to year end rather than at an interim date, larger samples). Where RMM is assessed as low, the auditor can accept a correspondingly higher detection risk and still hold audit risk at an acceptable level, performing fewer or less extensive procedures.
Understanding the entity and its environment — SA 315
Before any risk can be assessed, the auditor must first understand the entity. SA 315 requires the auditor to obtain an understanding of: the entity's organisational structure, ownership and governance, and its business model; industry, regulatory and other external factors, including the applicable financial reporting framework; the entity's selection and application of accounting policies; the entity's objectives, strategies and related business risks that may result in risk of material misstatement; the measurement and review of the entity's financial performance; and the entity's internal control (developed as its own separate topic below).
Risk assessment procedures used to obtain this understanding include: inquiries of management and others within the entity; analytical procedures; observation and inspection; and, where the entity has an internal audit function, inquiries of appropriate individuals within it.
Significant risks are risks of material misstatement that, in the auditor's judgement, require special audit consideration — the auditor determines whether identified risks are significant by evaluating factors including whether the risk is a risk of fraud, whether it is related to significant recent economic, accounting or other developments, the complexity of transactions, whether it involves significant transactions with related parties, the degree of subjectivity in the measurement of financial information, and whether it involves significant transactions outside the normal course of business.
Internal control — the five components (COSO framework)
Internal control is the process designed, implemented and maintained by those charged with governance, management and other personnel to provide reasonable assurance about the achievement of an entity's objectives with regard to reliability of financial reporting, effectiveness and efficiency of operations, and compliance with applicable laws and regulations.
The control environment — the set of standards, processes and structures providing the basis for carrying out internal control across the organisation, including the entity's ethical values, management's commitment to competence, participation by those charged with governance, and the assignment of authority and responsibility. A strong control environment does not, by itself, prevent misstatement, but it is the foundation on which the effectiveness of the other four components depends.
The entity's risk assessment process — the entity's own process for identifying and responding to business risks relevant to financial reporting objectives, distinct from the auditor's own risk assessment (the auditor evaluates whether the entity's process is suitably designed for its circumstances).
The information system relevant to financial reporting, including the related business processes, and communication — how transactions are initiated, recorded, processed and reported, and how the entity communicates financial reporting roles, responsibilities and significant matters relating to financial reporting.
Control activities — the policies and procedures that help ensure management directives are carried out, including authorisation, performance reviews, information processing controls, physical controls, and segregation of duties. Segregation of duties is examined specifically and repeatedly: separating the functions of authorisation, custody of assets, and record-keeping among different individuals, so that no single person can both perpetrate and conceal an error or fraud.
Monitoring of controls — a process to assess the effectiveness of internal control performance over time, including ongoing evaluations and separate evaluations, and taking necessary remedial actions.
Inherent limitations of internal control
Internal control, however well designed, can provide only reasonable, not absolute, assurance that the entity's objectives will be achieved (the same reasonable-versus-absolute distinction from SA 200, applied here to controls rather than to the audit itself), because of inherent limitations: the possibility of human error or mistakes in judgement or through simple carelessness; the possibility of controls being circumvented by collusion between two or more people, or by management override of controls; and the fact that controls are generally designed to respond to routine, not unusual, transactions.
The auditor's response to assessed risk
Having assessed RMM at both the financial statement level (pervasive risks affecting the financial statements as a whole) and the assertion level (risks specific to particular classes of transactions, balances or disclosures), the auditor designs and performs further audit procedures whose nature, timing and extent are responsive to the assessed risks — this is what makes risk assessment the hinge of the whole audit: it is not a compliance exercise performed and then set aside, but the direct input that determines everything the audit does next.
Tests of controls are performed where the auditor's approach includes an expectation that controls are operating effectively, or where substantive procedures alone would not provide sufficient appropriate evidence. Substantive procedures — tests of details and substantive analytical procedures — are always performed for each material class of transactions, balance and disclosure, regardless of the assessed level of control risk, because control risk assessment alone can never be reduced to zero and substantive evidence is always required to some extent.
