Audit Risk Model
The framework expressing audit risk as the product of inherent risk, control risk, and detection risk.
AUD loves to hold audit risk constant and move one input: if inherent and control risk rise, the acceptable detection risk falls, forcing more persuasive evidence — more effective procedures, year-end rather than interim timing, and larger sample sizes. The “tell” is any prompt asking how an assessment change affects evidence; the answer almost always hinges on this inverse relationship between detection risk and the risk of material misstatement. Inherent risk and control risk combine into RMM, the assessment that actually drives planning (under SAS 145 you assess the two separately, not as one blended number).
The classic trap is treating all three as auditor-set. The auditor assesses inherent and control risk (they exist in the client and its controls) but only sets detection risk by altering the nature, timing, and extent of substantive testing — don’t confuse assessing with controlling. Another snare: students lower detection risk yet pick “decrease testing,” reversing the logic. Memory hook: detection risk and substantive evidence move in opposite directions — push detection risk down, push evidence up.
PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →