CPA Exam — AUDEthics, Professional Responsibilities, and General PrinciplesMedium
An auditor is planning an audit of a non-issuer. The auditor's preliminary assessment indicates a high inherent risk for accounts receivable due to the client's complex revenue recognition policies and a history of significant adjustments. The control risk for accounts receivable is assessed as moderate because some controls are present but not consistently applied. Based on these assessments, what level of detection risk is the auditor most likely to accept for accounts receivable?
- ALow
- BModerate
- CCannot be determined without a quantitative assessment.
- DHigh
Show answer & explanationAnswer & explanation
Correct answer: A. Low
The Audit Risk Model (AR = IR x CR x DR) dictates that if inherent risk (IR) is high and control risk (CR) is moderate, the auditor must accept a low detection risk (DR) to achieve an acceptably low overall audit risk (AR). This means performing more substantive procedures.
Why the other options are wrong
- B. Moderate detection risk would still result in a higher than desired overall audit risk given the high inherent risk and moderate control risk.
- C. While quantitative assessments can be used, the qualitative relationship between the risk components is sufficient to determine the relative level of detection risk.
- D. Accepting high detection risk would lead to an unacceptably high overall audit risk when inherent and control risks are high/moderate.
Audit Risk Model (ARM)
The Audit Risk Model (AR = IR x CR x DR) is used by auditors to plan the audit, determining the acceptable level of detection risk based on assessed inherent and control risks to achieve an acceptably low overall audit risk.
- AR: Overall audit risk (kept low).
- IR: Inherent risk (susceptibility to misstatement).
- CR: Control risk (failure of internal controls).
- DR: Detection risk (failure of auditor to detect misstatement).
Memory trick: Risk Balance: Inherent, Control, Detect.