CPA Exam — AUDAssessing Risk and Developing a Planned ResponseMedium

An auditor assesses control risk for accounts payable as moderate because some documentation supporting vendor invoices was occasionally missing during prior periods, though the issue was not pervasive. To mitigate this moderate control risk and achieve an acceptable level of audit risk, what adjustment should the auditor make to the planned substantive procedures for accounts payable?

  1. ADecrease the extent of cutoff testing for accounts payable.
  2. BIncrease the sample size for tests of details of accounts payable.
  3. CEliminate the need for external confirmations of accounts payable.
  4. DPerform substantive analytical procedures as the primary evidence.
Show answer & explanation

Correct answer: B. Increase the sample size for tests of details of accounts payable.

According to the audit risk model (Audit Risk = Inherent Risk x Control Risk x Detection Risk), if control risk is assessed as moderate (not low), the auditor must decrease detection risk to maintain an acceptable overall audit risk. Decreasing detection risk generally involves increasing the effectiveness and/or extent of substantive procedures. Increasing the sample size for tests of details is a direct way to increase the extent of substantive procedures.

Why the other options are wrong

  • A. Decreasing cutoff testing would increase detection risk, which is inappropriate when control risk is moderate.
  • C. Eliminating external confirmations would decrease the quality/extent of substantive procedures, increasing detection risk, which is contrary to the required response for moderate control risk.
  • D. Substantive analytical procedures alone are often not sufficient as primary evidence when control risk is moderate, especially for assertions like completeness in accounts payable.

Audit Risk Model - Inverse Relationship

The audit risk model demonstrates an inverse relationship between the auditor's assessed risks of material misstatement (Inherent Risk and Control Risk) and the acceptable level of Detection Risk. As assessed RMM increases, acceptable Detection Risk decreases.

  • AR = IR x CR x DR.
  • IR and CR are client-side risks.
  • DR is auditor-controlled.

Memory trick: Higher client risk? Lower auditor risk action!

More Assessing Risk and Developing a Planned Response questions