Lingnan University · FACULTY OF ACCOUNTING

ACT501 Chap.9 Planning the Audit and the Audit Risk Model

- one subject, every graph, every model, every mark
9 Chapters5-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 9 of 12 · ACT501

Planning the Audit and the Audit Risk Model

Where this sits in the term

The published teaching schedule gives week three to planning an audit, covering preliminary engagement activities, planning activities and materiality, and week four to audit risk and risk assessment.

Those two weeks are the hinge of the course: everything before them explains what an audit is, and everything after them is work that only makes sense once a risk assessment has said where to do it. This chapter sets out the standard framework so the lectures land on prepared ground.

Acceptance is not part of planning

The stage list separates preliminary engagement activities from planning activities.

The preliminary stage asks whether the firm should take the work at all: whether ethical requirements including independence can be met, whether the firm has the competence and the capacity, what is known about the integrity of those in charge, and whether the terms can be agreed and recorded in an engagement letter. Those are acceptance and continuance questions and none of them can be repaired later by working harder.

Only once the engagement is accepted does planning proper begin, producing an overall strategy that fixes scope, timing and direction, and then a plan setting out the nature, timing and extent of procedures.

Planning is a narrowing

It runs from the entity and its environment, to the significant classes of transactions and balances, to the assertions that could be materially misstated, to the procedure that answers each one.

A plan that stops at the second band has described a business rather than designed an audit.

Evidence accumulates from the preliminary activities onwards, so nothing in this stage is preparation for the audit; all of it is part of it, and all of it belongs on the file.

Materiality becomes three decisions

Defined as the threshold above which a misstatement could reasonably be expected to influence users' economic decisions, materiality in planning becomes a set of linked judgements.

Choose a benchmark reflecting what the readers of these statements care about, and say why: a profit measure suits a company whose readers are investors, an asset or revenue measure suits one whose profit is small, volatile or near break-even. Set overall materiality for the statements as a whole.

Set a lower working figure for performing procedures, so individually immaterial errors cannot aggregate past the overall threshold unnoticed. Set a lower threshold again for particular classes, balances or disclosures where a smaller amount would influence a reader.

And revise all of it if the audit turns up information that would have changed the original judgement.

Three risks, and which one is yours

The risk of material misstatement is the likelihood that a material misstatement, from error or from fraud, exists before the auditor's work is considered, and at the assertion level it has two components.

Inherent risk is the susceptibility of an assertion to material misstatement before controls are considered. Control risk is the risk that the entity's controls will not prevent, or detect and correct, such a misstatement in time.

Detection risk is the danger that the auditor's own work fails to find an error that is really there, and it is the only one of the three the auditor controls.

The asymmetry is the point

Inherent and control risk are properties of the client that the auditor discovers and records; assessing control risk as low because a low assessment would be convenient is not an assessment.

Detection risk is genuinely chosen, and it is chosen in three currencies: the nature of the procedures, which is what kind of work is done; their timing, which is how close to the year end the work happens; and their extent, which is how much of the population is covered.

A higher assessment on the first two forces a lower setting on the third, and a lower setting means more work, better procedures and later timing.

Reading client facts as risk

The examinable skill is turning a paragraph of business facts into assessments at the assertion level. Two habits make it reliable.

Ask of every fact whether it speaks to inherent risk, to control risk, or to neither, and refuse to record a fact that speaks to neither. And attach each assessment to a named assertion rather than to a caption, because a caption can be high risk for valuation and low risk for existence at the same time.

Most marks are lost by stopping at the assessment: a risk assessment that does not end in a change to the audit has not been used.

In this chapter

What this chapter covers

  • 01

    Where planning and risk sit in the published teaching schedule

  • 02

    Acceptance and continuance as a separate stage

  • 03

    Overall strategy against detailed audit plan

  • 04

    Planning as a narrowing that ends in named procedures

  • 05

    Choosing and defending a materiality benchmark

  • 06

    Overall, performance and lower thresholds

  • 07

    Inherent risk, control risk and the risk of material misstatement

  • 08

    Detection risk as the component the auditor sets

  • 09

    Nature, timing and extent as the three currencies of that setting

Worked example · free

Four planning facts, three risk components, one testing consequence

Q [12 marks]. AskSia-authored practice. A family-controlled electronics retailer with twenty-two shops presents four facts at the planning meeting. The founder owns seventy per cent of the shares and has told the bank profit will exceed a covenant threshold this year. Revenue is almost entirely card and cash at the till with automated daily banking. The finance team lost two of its four staff in the autumn and has not replaced them. Inventory includes discontinued handsets bought three years ago and still carried at cost. Say what each fact does to the risk components and what it does to the amount of testing. The marks shown are an AskSia study allocation and not a University marking scheme.
  • 4Classify each fact as inherent risk, control risk, or neither.
  • 4Attach each assessment to a named assertion rather than to a caption.
  • 4State the consequence for detection risk and name the resulting procedures.
The covenant raises inherent risk at the financial statement level, because a specific incentive to reach a number exists, and it points at occurrence and cutoff for revenue and valuation for anything discretionary. The till process reduces inherent risk for revenue completeness, since automated banking leaves an independent record, but says nothing about occurrence. The staff losses raise control risk across the finance function, because reviews and reconciliations are the first tasks to slip when a team is short. The obsolete handsets raise inherent risk for the valuation assertion specifically, which is a judgement area rather than a processing one. Taken together the assessed risk of material misstatement rises, so detection risk must fall, which means more work, better procedures and timing closer to the year end: a substantive approach to revenue cutoff, a net realisable value test on the discontinued line, and no reliance on controls over reconciliations.
Sia tip — Finish every risk sentence with a procedure. An assessment that does not change the programme is an observation about the client rather than a plan.
Glossary

Key terms

Inherent Risk
The susceptibility of an assertion to a material misstatement before any related controls are taken into account.
Control Risk
The danger that the entity's own controls fail to stop a material error, or fail to catch and correct it in time.
Detection Risk
The danger that the auditor's own work fails to find an error that is really there. It is set rather than assessed, through what work is done, when, and how widely.
Performance Materiality
A figure set below overall materiality for performing procedures, so that individually immaterial errors cannot aggregate past the overall threshold unnoticed.
Overall Audit Strategy
The document fixing the scope, timing and direction of the engagement, from which the detailed audit plan is developed.
Engagement Letter
The record of agreed terms produced at the preliminary stage, setting out scope, the responsibilities of each party and the reporting arrangements.
FAQ

Planning the Audit and the Audit Risk Model FAQ

Which benchmark should materiality be based on?

Whichever one reflects what the readers of these particular statements care about, and the defence matters more than the choice. A profit measure suits a company whose principal readers are investors watching earnings. An asset or revenue measure suits a loss-making or volatile business, and a company borrowing against its asset base has readers whose decisions turn on asset amounts.

A question that supplies revenue, profit and total assets together is inviting a choice and an explanation, and the marks are in the explanation.

If control risk is high, what actually changes?

The work does, in three ways at once. High control risk means the auditor will not rely on the entity's controls, so a substantive approach replaces a reliance approach; the nature of the procedures shifts towards tests of details and externally sourced evidence; the timing moves closer to the year end, because interim work depends on controls holding over the intervening period; and the extent increases.

Saying only that control risk is high describes the client. Naming those changes describes an audit.

Does a high risk of material misstatement mean detection risk is high too?

No, and reversing this is the single most common error on the topic. The components move in opposite directions because the overall risk of expressing a wrong opinion has to stay acceptably low. If the assessed risk that a material misstatement exists is high, the auditor must accept a lower risk of failing to detect one, which means more and better work.

Detection risk is set by the auditor as a response, not observed as a finding.

Study strategy

Exam move

Take any company's published annual report and read the business description as a planning file: list five facts, mark each as inherent risk, control risk or neither, name the assertion it touches, and write one procedure. The discipline that matters is throwing out the facts that speak to neither, because a planning answer that records everything interesting about a company has not yet started to plan an audit.

Working through Planning the Audit and the Audit Risk Model in ACT501? Sia is AskSia’s AI Accounting tutor — ask any ACT501 Planning the Audit and the Audit Risk Model question and get a clear, step-by-step explanation grounded in how ACT501 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 2 of your Lingnan University subjects - and 1,000+ Bibles across every Australian university.
Sia - your ACT501 tutor, unlimited, worked the way the exam marks it
The full 5-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works