What does assessed risk mean on the CPA exam?
Assessed risk. The auditor's judgment about the risk of material misstatement at the assertion level, combining inherent and control risk. It drives the nature, timing and extent of everything that follows.
Defined against AU-C 315.30.
Which CPA exam sections use assessed risk?
Assessed risk appears in the ISC section of the CPA exam.
Other terms defined against AU-C 315
- application controls: Controls built into one business process or system, such as a validity check on an input field or a three-way match.
- control environment: The governance and management functions and the attitudes, awareness, and actions of those charged with governance and management concerning the entity's system of internal control.
- general controls: Controls over the IT environment as a whole -- access, change management, operations -- that everything else depends on.
- general IT control: A control over the entity's IT processes that supports the continued effective functioning of information-processing controls and the integrity of information.
- information and communication: One of the five components of internal control: how an entity obtains the information it needs and gets it to the people who have to act on it.
- information-processing control: A control over processing in an IT application or a manual information process that directly addresses a risk to the integrity of information.
- rights and obligations: The assertion that the entity genuinely owns the assets it reports and genuinely owes the liabilities.
- risk assessment procedures: The audit procedures designed and performed to identify and assess the risks of material misstatement at the financial statement and assertion levels.
Related terms
- risk of material misstatement: The risk that the statements are materially misstated before the audit begins.
- control risk: The risk that the entity's own controls will not prevent, or detect and correct, a material misstatement on a timely basis.
- inherent risk: The susceptibility of an assertion to material misstatement before any control is considered.
- significant risk: A risk of material misstatement that warrants special audit attention because of its likelihood or its size.
- further audit procedures: The work done in response to assessed risk: tests of controls and substantive procedures.
- nature, timing, and extent: The three dials on any audit procedure: what kind of test, when it is run, and how much of the population it covers.