Risk assessment Flashcards
Business risk
The risk inherent to the company in its operations.
Includes risk at all levels of the business
3 general categories of business risk
Financial
Risks arising from the financial activities or consequences of an operation e.g. cash flow issues/overtrading
Operational
Risks arising w regard to operations
Compliance
Risk that arises from non-compliance with laws and regs that surround the business
Audit risk
The risk of giving an inappropriate opinion on the FSs
Inherent
Control
Detection
Inherent risk
The susceptibility of an assertion to misstatement (that could be material, individually or when aggregated), assuming that there were no related internal controls
Control risk
The risk that a misstatement (that could be material, individually or when aggregated with other misstatements), will not be prevented or detected and corrected on a timely basis by the entity’s internal control
Limitations of internal controls
Cost > benefit Routine/non-routine transactions Human error Mgmt override Circumvention by collusion Changes in procedures
Detection risk
The risk that an auditor’s procedures will not detect a misstatement (that could be material, individually or when aggregated with other misstatements)
Significant risks
a risk of material misstatement that, in the auditor’s judgement, requires special audit consideration
If an auditor decides that an acceptable level of audit risk is x%, what does this mean?
x% chance of an invalid conclusion being drawn after all procedures completed
(100 - x)% confident that audit opinion will be valid
Examples of indicators in a business that the risk of fraud and error may be high
Previous experience of integrity or competence of mgmt
Financial reporting pressures (profit-based rewards)
Weaknesses in design or operation of systems
High staff turnover
Industry characteristics eg cash handling
Unusual transactions
Problems in obtaining audit evidence
Inadequate control over IT systems data
5 components of internal control
The control environment Risk assessment process Control activities Information and communication Monitoring activities