Instiq
Chapter 2 · Audit planning·v1.0.0·Updated 7/11/2026·~16 min

What's changed: Initial version

2.1Risk-based approach & audit risk

Key points

Covers the risk-based approach, which concentrates limited audit resources on high-risk areas, and the relationship audit risk = inherent risk x control risk x detection risk. Inherent and control risk are givens the auditor assesses, while only detection risk is what the auditor controls through audit procedures; the section covers how to lower detection risk to hold audit risk to an acceptable level in areas of high inherent and control risk.

The audit resources (time, staff) available to a systems auditor are always finite. Since scrutinizing every process and system to the same depth is impractical, the auditor concentrates resources on high-risk areas—this is the risk-based approach. The core concept that disciplines that resource allocation is audit risk, which frames the risk that "the auditor overlooks a material problem in the audit opinion" by decomposing it into three components: inherent risk, control risk, and detection risk. This section builds on the difference in the roles of the three risks—above all the point that only detection risk is something the auditor can control through procedures—as the starting point of audit planning.

2.1.1The three components of audit risk and their differing roles

  • Inherent risk is the risk of error or fraud that a process or system inherently carries, assuming no internal controls exist at all. It depends on transaction complexity, monetary magnitude, frequency of change, and so on. The auditor "assesses" this as a given; it is not something the auditor can lower.
  • Control risk is the risk that error or fraud remains un-prevented and un-detected even by the audited entity's internal controls. It depends on the design and operating effectiveness of controls. This too is a given the auditor "assesses" by evaluating the controls; the auditor does not lower it itself (designing and operating the controls is the audited department's job).
  • Detection risk is the risk that a material problem actually exists but the auditor's procedures fail to detect it, letting it slip through. This is the only element the auditor can "control", through the design of the nature, extent, and timing of audit procedures. Detection risk can be lowered by widening the extent of testing, moving closer to full examination, or selecting effective audit techniques.

2.1.2The audit-risk relationship and resource allocation

  • Audit risk = inherent risk x control risk x detection risk. The auditor first assesses inherent and control risk, then works backward to decide how far detection risk must be lowered to keep audit risk within its own acceptable level.
  • The higher inherent and control risk are assessed to be in an area, the more detection risk must be lowered to hold audit risk to an acceptable level—concretely, this means widening the extent of testing, selecting procedures with stronger evidential force, or moving closer to full examination. Conversely, where both risks are low, even limited testing keeps audit risk within an acceptable level.
Exam point

Most-tested: "audit risk = inherent risk x control risk x detection risk", "inherent and control risk are givens the auditor assesses", and "only detection risk is what the auditor controls through audit procedures". Watch for the wrong statement that "the auditor directly lowers inherent or control risk"—what the auditor designs and strengthens is the audit procedures, and that only affects detection risk.

A systems auditor is drafting the audit plan for a newly launched revenue-recognition system. A preliminary survey assesses inherent risk as high because the area has an enormous transaction volume and complex recognition logic (multiple currencies, several discount conditions), and it assesses control risk as high as well because the pre-recognition approval control is not systematized and depends on manual work by staff. Here the auditor judges that, to hold audit risk (the ultimate risk of overlooking a material recognition error) to an acceptable level, detection risk must be lowered substantially. The key point is that the auditor cannot itself lower inherent risk (the transaction complexity) or control risk (the weakness of the approval control): those are properties of the audited entity, and strengthening the controls is the responsibility of the audited department, not the auditor. What the auditor can do is control detection risk through the design of its own procedures. Concretely, the auditor strengthens the plan by switching from the originally planned limited-sample testing (limited sampling) to a procedure closer to full examination—exhaustively reconciling every recognition transaction in the target period with generalized audit software—and combining several audit techniques to raise the evidential force of the evidence. Conversely, had the preliminary survey assessed both inherent and control risk as low, limited testing would keep audit risk within an acceptable level, making it appropriate to redirect resources to other high-risk areas. The audit-risk relationship thus disciplines the very judgment of "how much audit procedure to invest in which area."

RiskMeaningAuditor's relationship
Inherent riskInherent risk of error/fraud assuming no controlsA given to assess (cannot lower)
Control riskRisk that remains un-prevented by internal controlA given to assess via control evaluation (the audited dept. lowers it)
Detection riskRisk that procedures fail to detect a problemControlled by procedure design (the only one)
Warning

Trap: "Since inherent and control risk are high, the auditor lowers them before starting the audit" is wrong—inherent and control risk are properties of the audited entity that the auditor assesses as givens, and it is out of place for the auditor to lower them (the audited department strengthens the controls). The only one the auditor can lower through procedures is detection risk. Also wrong: "lowering detection risk automatically lowers inherent risk too"—the three components are assessed independently, and the only one the auditor can manipulate is the single detection-risk component.

Inherent, control & detection risk.
Only detection risk is controllable

2.1.3Section summary

  • The risk-based approach concentrates finite audit resources on high-risk areas
  • Audit risk = inherent x control x detection risk; inherent and control risk are givens the auditor assesses
  • The only risk the auditor controls through procedures is detection risk; the higher inherent/control risk, the more detection risk must be lowered (testing moves toward full examination)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. A preliminary survey assesses both inherent risk and control risk as high for a revenue-recognition area. Which response is most appropriate for holding audit risk to the auditor's acceptable level?

Q2. Which statement most accurately describes the three components of audit risk and how the auditor relates to each?

Q3. In a risk-based audit plan, which response is most appropriate for an area where the preliminary survey assesses both inherent risk and control risk as low?

Check your understandingPractice questions for Chapter 2: Audit planning