CPA Exam — AUDAssessing Risk and Developing a Planned ResponseMedium

During the planning phase, an auditor notes that a client, a large e-commerce retailer, processes millions of transactions daily through a highly automated system with minimal human intervention. The system automatically calculates prices, applies discounts, processes payments, and updates inventory. What is the most likely implication for the auditor's assessment of control risk related to sales transactions?

  1. AControl risk is irrelevant, as the volume of transactions makes manual controls impractical.
  2. BControl risk might be assessed at a lower level, provided that general IT controls are strong and application controls are effective.
  3. CControl risk will be assessed at a high level due to the inherent complexity of automated systems.
  4. DThe auditor will need to perform extensive substantive testing of all individual sales transactions.
Show answer & explanation

Correct answer: B. Control risk might be assessed at a lower level, provided that general IT controls are strong and application controls are effective.

In a highly automated environment, effective automated application controls can be very reliable and consistent. If these controls are designed and operating effectively, and are supported by strong general IT controls (e.g., access, change management), the auditor can assess control risk at a lower level, allowing for reduced substantive testing. The consistency of automated controls is a key advantage.

Why the other options are wrong

  • A. Control risk is always relevant; the nature of controls changes from manual to automated, but the risk assessment process remains.
  • C. Complexity doesn't automatically mean high control risk; effective automated controls can mitigate this.
  • D. A lower control risk assessment, supported by effective automated controls, would allow for a reduction in the extent of substantive testing, not an increase.

Control Risk - Automated Systems

The risk that a misstatement will not be prevented or detected by the entity's internal control system, specifically when controls are highly automated. Automated controls, if effective, can be very consistent.

  • Reliance on automated controls requires testing their effectiveness.
  • General IT controls (GITC) are crucial for the reliability of automated application controls.
  • If controls are strong, control risk can be assessed lower, impacting detection risk.

Memory trick: Robots Rule, If Rules Are Set.

More Assessing Risk and Developing a Planned Response questions