CPA Exam — AUDAssessing Risk and Developing a Planned ResponseMedium
An auditor is developing an overall audit strategy for a public company client that operates several distinct business segments across different industries. The auditor determines that each segment has its own management team, financial reporting systems, and internal control structures. What is the most appropriate approach for the auditor to assess control risk in this scenario?
- AFocus solely on substantive testing for all segments, as control testing would be too complex.
- BAssess control risk at the entity level based on the consolidated financial statements.
- CAssume control risk is high across all segments due to the decentralized nature.
- DAssess control risk separately for each significant business segment.
Show answer & explanationAnswer & explanation
Correct answer: D. Assess control risk separately for each significant business segment.
When a client has distinct business segments with separate management, systems, and controls, control risk should be assessed individually for each significant segment. This allows for a tailored audit response that reflects the specific control environment and effectiveness within each part of the entity.
Why the other options are wrong
- A. Foregoing control testing entirely and relying solely on substantive testing might be inefficient and ignores the potential for effective controls in some segments to reduce substantive testing.
- B. Assessing control risk only at the entity level would overlook the unique control environments and potential weaknesses within individual segments.
- C. Assuming high control risk across all segments without evaluation is not an efficient or necessarily accurate approach; some segments might have effective controls.
Assessing Control Risk in Decentralized Entities
For entities with distinct operating segments or decentralized structures, control risk is often assessed separately for each significant component due to varying control environments and systems.
- Each segment may have different control strengths/weaknesses.
- Tailored audit approach for each segment is often more efficient.
- Entity-level controls still need to be considered for overall impact.
Memory trick: Decentralized means 'Divide and Conquer Controls'.