ACT501 Chap.9 Planning the Audit and the Audit Risk Model
Planning the Audit and the Audit Risk Model
Where this sits in the term
The published teaching schedule gives week three to planning an audit, covering preliminary engagement activities, planning activities and materiality, and week four to audit risk and risk assessment.
Those two weeks are the hinge of the course: everything before them explains what an audit is, and everything after them is work that only makes sense once a risk assessment has said where to do it. This chapter sets out the standard framework so the lectures land on prepared ground.
Acceptance is not part of planning
The stage list separates preliminary engagement activities from planning activities.
The preliminary stage asks whether the firm should take the work at all: whether ethical requirements including independence can be met, whether the firm has the competence and the capacity, what is known about the integrity of those in charge, and whether the terms can be agreed and recorded in an engagement letter. Those are acceptance and continuance questions and none of them can be repaired later by working harder.
Only once the engagement is accepted does planning proper begin, producing an overall strategy that fixes scope, timing and direction, and then a plan setting out the nature, timing and extent of procedures.
Planning is a narrowing
It runs from the entity and its environment, to the significant classes of transactions and balances, to the assertions that could be materially misstated, to the procedure that answers each one.
A plan that stops at the second band has described a business rather than designed an audit.
Evidence accumulates from the preliminary activities onwards, so nothing in this stage is preparation for the audit; all of it is part of it, and all of it belongs on the file.
Materiality becomes three decisions
Defined as the threshold above which a misstatement could reasonably be expected to influence users' economic decisions, materiality in planning becomes a set of linked judgements.
Choose a benchmark reflecting what the readers of these statements care about, and say why: a profit measure suits a company whose readers are investors, an asset or revenue measure suits one whose profit is small, volatile or near break-even. Set overall materiality for the statements as a whole.
Set a lower working figure for performing procedures, so individually immaterial errors cannot aggregate past the overall threshold unnoticed. Set a lower threshold again for particular classes, balances or disclosures where a smaller amount would influence a reader.
And revise all of it if the audit turns up information that would have changed the original judgement.
Three risks, and which one is yours
The risk of material misstatement is the likelihood that a material misstatement, from error or from fraud, exists before the auditor's work is considered, and at the assertion level it has two components.
Inherent risk is the susceptibility of an assertion to material misstatement before controls are considered. Control risk is the risk that the entity's controls will not prevent, or detect and correct, such a misstatement in time.
Detection risk is the danger that the auditor's own work fails to find an error that is really there, and it is the only one of the three the auditor controls.
The asymmetry is the point
Inherent and control risk are properties of the client that the auditor discovers and records; assessing control risk as low because a low assessment would be convenient is not an assessment.
Detection risk is genuinely chosen, and it is chosen in three currencies: the nature of the procedures, which is what kind of work is done; their timing, which is how close to the year end the work happens; and their extent, which is how much of the population is covered.
A higher assessment on the first two forces a lower setting on the third, and a lower setting means more work, better procedures and later timing.
Reading client facts as risk
The examinable skill is turning a paragraph of business facts into assessments at the assertion level. Two habits make it reliable.
Ask of every fact whether it speaks to inherent risk, to control risk, or to neither, and refuse to record a fact that speaks to neither. And attach each assessment to a named assertion rather than to a caption, because a caption can be high risk for valuation and low risk for existence at the same time.
Most marks are lost by stopping at the assessment: a risk assessment that does not end in a change to the audit has not been used.
What this chapter covers
- 01
Where planning and risk sit in the published teaching schedule
- 02
Acceptance and continuance as a separate stage
- 03
Overall strategy against detailed audit plan
- 04
Planning as a narrowing that ends in named procedures
- 05
Choosing and defending a materiality benchmark
- 06
Overall, performance and lower thresholds
- 07
Inherent risk, control risk and the risk of material misstatement
- 08
Detection risk as the component the auditor sets
- 09
Nature, timing and extent as the three currencies of that setting
Four planning facts, three risk components, one testing consequence
- 4Classify each fact as inherent risk, control risk, or neither.
- 4Attach each assessment to a named assertion rather than to a caption.
- 4State the consequence for detection risk and name the resulting procedures.
Key terms
- Inherent Risk
- The susceptibility of an assertion to a material misstatement before any related controls are taken into account.
- Control Risk
- The danger that the entity's own controls fail to stop a material error, or fail to catch and correct it in time.
- Detection Risk
- The danger that the auditor's own work fails to find an error that is really there. It is set rather than assessed, through what work is done, when, and how widely.
- Performance Materiality
- A figure set below overall materiality for performing procedures, so that individually immaterial errors cannot aggregate past the overall threshold unnoticed.
- Overall Audit Strategy
- The document fixing the scope, timing and direction of the engagement, from which the detailed audit plan is developed.
- Engagement Letter
- The record of agreed terms produced at the preliminary stage, setting out scope, the responsibilities of each party and the reporting arrangements.
Planning the Audit and the Audit Risk Model FAQ
Which benchmark should materiality be based on?
Whichever one reflects what the readers of these particular statements care about, and the defence matters more than the choice. A profit measure suits a company whose principal readers are investors watching earnings. An asset or revenue measure suits a loss-making or volatile business, and a company borrowing against its asset base has readers whose decisions turn on asset amounts.
A question that supplies revenue, profit and total assets together is inviting a choice and an explanation, and the marks are in the explanation.
If control risk is high, what actually changes?
The work does, in three ways at once. High control risk means the auditor will not rely on the entity's controls, so a substantive approach replaces a reliance approach; the nature of the procedures shifts towards tests of details and externally sourced evidence; the timing moves closer to the year end, because interim work depends on controls holding over the intervening period; and the extent increases.
Saying only that control risk is high describes the client. Naming those changes describes an audit.
Does a high risk of material misstatement mean detection risk is high too?
No, and reversing this is the single most common error on the topic. The components move in opposite directions because the overall risk of expressing a wrong opinion has to stay acceptably low. If the assessed risk that a material misstatement exists is high, the auditor must accept a lower risk of failing to detect one, which means more and better work.
Detection risk is set by the auditor as a response, not observed as a finding.
Exam move
Take any company's published annual report and read the business description as a planning file: list five facts, mark each as inherent risk, control risk or neither, name the assertion it touches, and write one procedure. The discipline that matters is throwing out the facts that speak to neither, because a planning answer that records everything interesting about a company has not yet started to plan an audit.
Working through Planning the Audit and the Audit Risk Model in ACT501? Sia is AskSia’s AI Accounting tutor — ask any ACT501 Planning the Audit and the Audit Risk Model question and get a clear, step-by-step explanation grounded in how ACT501 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.