Audit Risk Article Index for
Audit
Website Links For
Audit
 

Information About

Audit Risk




Audit Risk is the highest desired assessment of belief or Probability that audited Financial Statements are materially misstated, if the auditor wishes to issue a "clean opinion", one without reservation. It is typically limited to 5% when conducting an audit. It is a function of three components: Inherent Risk, Control Risk, and Detection Risk (sometimes called Substantive Risk).

Audit Risk is an intersection of three sets also called components. They are defined as:

# ''Inherent Risk'': is the auditor's assessment that there are material misstatements in the financial statements before considering the effectiveness of internal controls. If the auditor concludes that there is a high likelihood of misstamtement, ignoring internal controls, the auditor would conclude that the inherent risk is high. Internal controls are ignored in setting inherent risk because they are considered separetly in the audit risk model as control risk. It is often an area of professional judgement on the part of an auditor. Examples of acounts with low inherent risk are fixed Assets , easy to observe, or Securities traded in the Stock Market whose Market Price is easily observable.

# ''Control Risk'': is a measure of the auditor's assessment of the likelihood that misstatements exceeding a tolerable level will not be prevented or detected by the client's internal control system. This assessment includes an assessment of whether a client's internal controls are effective for preventing or detecting misstatements and the auditor's intention to make that assesment at a level below the maximum (100 pecent) as part of the audit plan.

# ''Acceptable Audit Risk'': is a measure of how willing the auditor is to accept that the financial statements may be materially misstated after the audit is completed and an unqualified (or clean) opinion was issued. If the auditor decides to lower audit risk, that means that the auditor wants to be more certain that the financial statements are not materially mistated

It should be noted that the product of inherent risk and control risk is referred to as the Risk of Material Mistatement. It is allowable to make a combined assessment of inherent and control risk, called Risk of Material Mistatement.

Mathematics of audit risk :

Audit standards proposed probability theory to be applied on audit risk concept. Practitionneers also attached probability to audit risk concept. But audit standards did not adopted probability theory as the unique formalism of audit risk.

In fact, audit risk is an intersection of three sets. Modeling audit risk issued different models depending on mathematical theories used :

- Probability theory measures audit risk if these three components (inherent risk, control risk...) of audit risk concept are considered as events. Audit risk become a set of events. it become a product of three probabilities.

- Belief-function theory can measure audit risk if these three components are considered as evidences. Audit risk become a combination (with dempster-shafer rule) of mass of evidence.

- Finally, fuzzy logic measures audit risk concept if these three components are considered as sets of linguistic assessements.

References :

- Srivastava R.P. & Shafer G.R. (1992) " Belief function Formula for audit risk " Review : Accounting Review, Vol. 67 n° 2, pp. 249-283, for evidence theory applied on audit risk.

- Lesage (1999)" Evaluation du risque d'audit : proposition d'un modele linguistique " Review : Comptabilite, Controle, Audit, Tome 5, Vol. 2, September 1999, pp.107-126, for fuzzy audit risk.

- Fendri-Kharrat et al. (2005)"Logique floue appliquee a l'inference du risque inherent en audit financier ", Review : RNTI : Revue des Nouvelles Technologies de l'Information, n° RNTI-E-5, (extraction des connaissances : etats et perspectives), November 2005, pp.37-49, Cepadues editions, for fuzzy inherent audit risk.