CPA Exam — AUDAssessing Risk and Developing a Planned ResponseEasy
An auditor is planning the audit for a private company client that processes a high volume of similar, low-value transactions (e.g., daily sales at a convenience store chain). The auditor assesses control risk as low due to effective automated controls over these transactions. What is the most appropriate impact of this assessment on the auditor's planned substantive procedures for these transactions?
- AEliminate all substantive testing, relying solely on control tests.
- BShift the focus from tests of details to substantive analytical procedures.
- CIncrease the extent of substantive tests of details.
- DReduce the extent of substantive tests of details.
Show answer & explanationAnswer & explanation
Correct answer: D. Reduce the extent of substantive tests of details.
According to the audit risk model, if control risk is assessed as low (meaning controls are effective), the auditor can reduce the planned detection risk. This typically translates to a reduction in the extent of substantive procedures, such as tests of details, because less direct evidence is needed from substantive tests to achieve the desired overall audit risk.
Why the other options are wrong
- A. Auditing standards generally require some level of substantive testing for material financial statement accounts, even when control risk is assessed as very low.
- B. While substantive analytical procedures are often used for high-volume transactions, reducing the *extent* of tests of details is the direct consequence of a low control risk assessment, not necessarily a shift in *type* of substantive procedure.
- C. Increasing substantive tests would be appropriate if control risk were assessed as high, not low.
Audit Risk Model & Control Risk
The Audit Risk Model (AR = IR x CR x DR) illustrates the inverse relationship between control risk (CR) and detection risk (DR); a lower assessed control risk allows for a higher acceptable detection risk, leading to less substantive testing.
- AR = Audit Risk, IR = Inherent Risk, CR = Control Risk, DR = Detection Risk.
- Auditor controls DR by adjusting substantive procedures.
- Effective controls reduce CR, allowing reduced DR (less substantive testing).
Memory trick: Low Controls, Less Detections, Less Substantives.