Control Risk
The risk that a material misstatement will not be prevented or detected on a timely basis by internal control.
Expect AUD to give a fact pattern and ask what happens to the rest of the model when assessed control risk changes. The “tell”: a clue about controls (well-designed and operating, or weak/overridden), then a question about substantive testing. The answer hinges on the inverse relationship — because acceptable detection risk is set inversely to the assessed risk of material misstatement, a lower control risk permits a higher detection risk, so the auditor can do less substantive work; high control risk forces detection risk down and pushes testing toward year-end, larger samples, and more reliable evidence. To assess control risk below maximum, you must test operating effectiveness of controls — understanding alone never lowers it (no test of controls means control risk stays at maximum).
The classic trap is swapping it with inherent risk: control risk is about whether controls catch a misstatement, inherent risk exists before controls; together they form RMM, which the entity owns (SAS 145 now requires assessing the two separately). Detection risk is the only piece the auditor controls. Memory hook: inherent and control are the client’s risks; detection is yours. Don’t say the auditor “sets” control risk — they assess it.
PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →