ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessMedium
During the planning phase of an audit, an IS auditor identifies that the organization recently implemented a new, highly complex data analytics platform. Management has expressed concerns about the system's accuracy and integrity due to its novelty and the specialized skills required to operate it. What type of risk does this situation PRIMARILY represent from an audit perspective?
- ADetection risk
- BInherent risk
- CControl risk
- DBusiness risk
Show answer & explanationAnswer & explanation
Correct answer: B. Inherent risk
Inherent risk is the susceptibility of an assertion about a class of transactions, account balance, or disclosure to a misstatement that could be material, either individually or when aggregated with other misstatements, before consideration of any related controls. The complexity and novelty of the system, along with management's concerns about accuracy, directly point to a higher inherent risk.
Why the other options are wrong
- A. Detection risk is the risk that the auditor will not detect a material misstatement that exists in an assertion.
- C. Control risk is the risk that a material misstatement will not be prevented or detected and corrected on a timely basis by the entity's internal control.
- D. Business risk is a broader term referring to risks that could impact the organization's objectives, not specifically audit risk components.
Inherent Risk
The susceptibility of an assertion to material misstatement, assuming no related internal controls.
- Exists independently of the audit.
- Influenced by complexity, novelty, or unusual transactions.
- Cannot be eliminated, only managed.
Memory trick: IR-CR-DR: Inherent Risk is 'initial risk', Control Risk is 'control failure', Detection Risk is 'auditor misses it'.