Auditing & Assurance

Audit Risk & Materiality

18 question(s)

What is the audit risk model?

Beginner
The audit risk model expresses audit risk as the product of inherent risk, control risk, and detection risk: AR = IR x CR x DR. Audit risk is the risk the auditor gives an inappropriate opinion when the statements are materially misstated. The auditor assesses IR and CR (risk of material misstatement) and adjusts detection risk (via procedures) to keep audit risk acceptably low.
Audit Risk = Inherent Risk x Control Risk x Detection Risk
RMM (risk of material misstatement) = IR x CR
Real-world example Assessing high inherent and control risk, the auditor lowers detection risk by doing more extensive substantive testing.

Common follow-ups: What is the risk of material misstatement? | How does the auditor control detection risk?

Audit Evidence & Procedures Internal Controls Evaluation Audit Risk & Materiality

What is inherent risk?

Beginner
Inherent risk is the susceptibility of an assertion or account to material misstatement, before considering related controls, due to its nature or circumstances—complexity, estimation, susceptibility to fraud, or volatile conditions. Cash is lower inherent risk than complex financial instruments or management estimates, which are higher.
Real-world example Fair-value estimates for illiquid assets carry high inherent risk due to judgment and uncertainty.

Common follow-ups: What factors raise inherent risk? | How does inherent risk differ from control risk?

Internal Controls Evaluation Audit Evidence & Procedures Audit Risk & Materiality

What is control risk?

Beginner
Control risk is the risk that a material misstatement in an assertion won't be prevented, or detected and corrected, on a timely basis by the entity's internal controls. It depends on the design and operating effectiveness of controls. Weak controls mean high control risk, requiring more substantive audit work.
Real-world example A company with no segregation of duties in cash handling has high control risk over misappropriation.

Common follow-ups: How is control risk assessed? | What raises control risk?

Internal Controls Evaluation Audit Evidence & Procedures Audit Risk & Materiality

What is detection risk and how does the auditor manage it?

Intermediate
Detection risk is the risk that the auditor's procedures fail to detect a material misstatement that exists. It's the component the auditor controls: when the assessed risk of material misstatement (IR x CR) is high, the auditor lowers acceptable detection risk by performing more effective, extensive, or year-end procedures. It's inversely related to RMM.
If RMM is high -> set detection risk low -> more/better procedures.
If RMM is low -> higher detection risk acceptable -> less testing.
Real-world example Facing high RMM on revenue, the auditor reduces detection risk with larger samples and external confirmations.

Common follow-ups: Why is detection risk inversely related to RMM? | Which risks can the auditor not change?

Audit Sampling Audit Evidence & Procedures Audit Risk & Materiality

What is materiality in auditing?

Beginner
Materiality is the magnitude of an omission or misstatement that could influence the economic decisions of users taken on the basis of the financial statements. Auditors set materiality to plan procedures and evaluate misstatements: items above it are material. It has quantitative and qualitative dimensions.
Real-world example A $50,000 error is immaterial to a company with $500m revenue but material to a small business with $1m revenue.

Common follow-ups: Is materiality only about size? | Who are the 'users' materiality considers?

Audit Sampling Audit Report & Opinions Audit Risk & Materiality

How is materiality calculated in practice?

Intermediate
Auditors apply a percentage to a chosen benchmark reflecting users' focus: commonly 0.5-1% of revenue or total assets, or 5-10% of profit before tax. The benchmark and percentage depend on the entity and users. This gives overall materiality; performance materiality is set lower to reduce the risk that aggregated errors exceed materiality.
Overall materiality example:
  5% x profit before tax (2,000,000) = 100,000
Performance materiality:
  75% x 100,000 = 75,000
Real-world example For a profitable company, the team sets overall materiality at 5% of PBT and performance materiality at 75% of that.

Common follow-ups: What benchmarks are common? | Why apply a percentage to a benchmark?

Audit Sampling Audit Evidence & Procedures Audit Risk & Materiality

What is performance materiality and why is it lower than overall materiality?

Intermediate
Performance materiality is an amount set below overall materiality to reduce the probability that the aggregate of uncorrected and undetected misstatements exceeds overall materiality (aggregation risk). It's applied to procedures and sample sizes, giving a margin so many small individually-immaterial errors don't collectively become material.
Performance materiality = 50-75% of overall materiality
(lower when risk is higher).
Real-world example Setting performance materiality at 65% of overall gives a buffer so several small undetected errors won't breach materiality in total.

Common follow-ups: What is aggregation risk? | How does risk affect the percentage chosen?

Audit Sampling Audit Evidence & Procedures Audit Risk & Materiality

What is qualitative materiality and give examples?

Intermediate
Qualitative materiality means some misstatements matter regardless of size due to their nature or context: those changing a loss to profit or breaching a covenant, affecting management bonuses, involving fraud or illegal acts, misclassifications that mislead, or related-party issues. Auditors consider these even when amounts are numerically small.
Real-world example A small misstatement that turns a reported loss into a profit is material by nature, despite its tiny size.

Common follow-ups: Why can a small item be material? | Give an example of qualitative materiality.

Audit Report & Opinions Fraud & Error Responsibilities Audit Risk & Materiality

What is a significant risk and how does the auditor respond to it?

Advanced
A significant risk is an identified risk of material misstatement requiring special audit consideration—often involving fraud, complex/subjective estimates, significant unusual or related-party transactions, or judgment. The auditor must understand related controls and perform substantive procedures specifically responsive to it, and cannot rely solely on analytical procedures or prior-year evidence.
Real-world example Revenue recognition is treated as a significant risk, prompting targeted substantive tests and scrutiny of period-end cutoff.

Common follow-ups: What makes a risk 'significant'? | Can you rely only on controls for a significant risk?

Audit Evidence & Procedures Fraud & Error Responsibilities Audit Risk & Materiality

How do you evaluate misstatements found during the audit?

Intermediate
Accumulate identified misstatements (other than clearly trivial), consider whether individually or in aggregate they're material (quantitatively and qualitatively), request management to correct them, and evaluate uncorrected misstatements against materiality—including the effect of prior-period uncorrected items. Material uncorrected misstatements affect the opinion.
Uncorrected misstatements total 90,000 vs materiality 100,000
  -> below materiality, but assess qualitative factors and trend.
Real-world example The team aggregates uncorrected errors, finds them just below materiality, but flags a qualitative concern for the audit committee.

Common follow-ups: What is a 'clearly trivial' threshold? | How do prior-year misstatements factor in?

Audit Report & Opinions Audit Sampling Audit Risk & Materiality