CPA Exam — AUDAssessing Risk and Developing a Planned ResponseEasy

An auditor is planning the audit for a software development company. The company relies heavily on a single, complex proprietary algorithm for its core product, and the lead developer, who designed the algorithm, recently left the company. The auditor should assess this situation as creating a significant increase in which type of risk?

  1. ADetection risk
  2. BSampling risk
  3. CInherent risk
  4. DControl risk
Show answer & explanation

Correct answer: C. Inherent risk

The departure of a key individual responsible for a complex proprietary algorithm introduces a risk that the underlying calculations or functionality could be misstated or misunderstood, independent of internal controls. This is a characteristic of inherent risk.

Why the other options are wrong

  • A. Detection risk relates to the auditor's procedures failing to detect a material misstatement, not the client's internal factors.
  • B. Sampling risk arises from testing less than 100% of a population, which is not directly related to the complexity of an algorithm or key personnel departure.
  • D. Control risk relates to the client's internal controls failing to prevent or detect a material misstatement; this situation is independent of control effectiveness.

Inherent Risk

The susceptibility of an assertion about a class of transaction, account balance, or disclosure to a misstatement that could be material, either individually or when aggregated with other misstatements, before consideration of any related controls.

  • Exists independently of the audit.
  • Higher for complex transactions or estimates.
  • Increased by industry factors, management characteristics, or business operations.

Memory trick: DR = IR x CR x DR (Detection = Inherent x Control x Detection)

More Assessing Risk and Developing a Planned Response questions