CPA Exam — AUDAssessing Risk and Developing a Planned ResponseEasy

During the planning phase of an audit, an auditor identified that the client operates in a highly regulated industry with frequent changes in environmental compliance laws. Which component of the entity's internal control is most directly impacted by this external factor?

  1. AMonitoring Activities
  2. BInformation and Communication
  3. CRisk Assessment
  4. DControl Activities
Show answer & explanation

Correct answer: C. Risk Assessment

Frequent changes in environmental compliance laws directly increase the risk of non-compliance for the client. The client's risk assessment process should be designed to identify, analyze, and respond to such risks, making it the most directly impacted component.

Why the other options are wrong

  • A. Monitoring activities evaluate the effectiveness of internal controls over time, not the initial identification of new risks.
  • B. Information and communication systems disseminate risk information, but don't identify the initial risk.
  • D. Control activities are implemented in response to risks, but the identification of the risk itself falls under risk assessment.

COSO Internal Control - Risk Assessment

The component of internal control that involves the entity's identification and analysis of relevant risks to the achievement of its objectives, forming a basis for determining how risks should be managed.

  • Identifies and analyzes risks to achieving objectives.
  • Considers internal and external factors.
  • Forms basis for managing risks.

Memory trick: CRIME: Control Environment, Risk Assessment, Information, Monitoring, Existing Controls.

More Assessing Risk and Developing a Planned Response questions