MCDMAccountingAudit Planning and Risk AssessmentMath steps

Audit Risk Model

Also known as: Risk-Based Audit Planning Model

OriginatorAmerican Institute of Certified Public Accountants (AICPA)Year1983Sources2Related methods11

The Audit Risk Model is a foundational framework developed by the American Institute of Certified Public Accountants (AICPA) that structures audit planning by decomposing overall audit risk into three components: inherent risk, control risk, and detection risk. This model guides auditors in allocating resources and designing audit procedures proportionate to the level of risk in each account or assertion.

Key highlights

  • Structured, transparent framework that improves communication of audit strategy to management and audit committees
  • Enables efficient resource allocation by concentrating effort on genuinely high-risk areas
  • Provides a documented basis for audit planning decisions, enhancing audit quality and defensibility
  • Flexible enough to accommodate judgments about specific risks while maintaining consistency across audits

Intuition

This section is available to Pro members. Upgrade to Pro

How it works

This section is available to Pro members. Upgrade to Pro

When to use it

Use the Audit Risk Model during the planning phase of all financial statement audits to guide the nature, timing, and extent of audit procedures. It is particularly valuable when dealing with complex accounts, significant management judgments, or high-risk areas such as revenue recognition or asset valuation. The model is mandatory in US Generally Accepted Auditing Standards (GAAS).

Strengths & limitations

Strengths
  • Structured, transparent framework that improves communication of audit strategy to management and audit committees
  • Enables efficient resource allocation by concentrating effort on genuinely high-risk areas
  • Provides a documented basis for audit planning decisions, enhancing audit quality and defensibility
  • Flexible enough to accommodate judgments about specific risks while maintaining consistency across audits
Limitations
  • Inherent subjectivity in assessing and quantifying risk; different auditors may reach different conclusions
  • Does not directly address fraud risk or management override of controls
  • Assumes risk components are independent; in reality, they are often correlated
  • May underestimate emerging risks if based solely on historical information

Common pitfalls

This section is available to Pro members. Upgrade to Pro

Applications

This section is available to Pro members. Upgrade to Pro

Frequently asked

Can I assign numerical values to inherent risk and control risk?

While the model conceptually assumes numerical multiplication, in practice auditors typically use qualitative ratings (low, moderate, high) or ranges. Precise numerical values are difficult to justify and may imply false precision.

What is an acceptable level of detection risk?

This depends on the auditor's planned overall audit risk, which is typically set at 5% or lower. The inverse relationship means lower inherent and control risk allow higher detection risk, requiring less intensive procedures.

How often should I reassess risk during the audit?

Risk assessment is an ongoing process. Auditors should update assessments as they perform procedures and learn new information about the entity, controls, and potential misstatements.

Does the Audit Risk Model apply to non-public companies?

Yes, the principles apply to audits of all entity sizes and types under GAAS. The specific application may vary based on the entity's complexity and risk profile.

Sources

  1. 1.
    American Institute of Certified Public Accountants (AICPA). (2015). Audit Risk. AU-C Section 200. AICPA Professional Standards.
  2. 2.
    Arens, A. A., Elder, R. J., & Beasley, M. S. (2014). Auditing and assurance services (15th ed.). Pearson Education.

You have read it. What now?

Cite this page

ScholarGate. (2026, June 3). Audit Risk Model. ScholarGate. https://scholargate.app/accounting/audit-risk-model