What does control risk mean on the CPA exam?
Control risk. The risk that the entity's own controls will not prevent, or detect and correct, a material misstatement on a timely basis. The second half of the risk of material misstatement, assessed after inherent risk.
Defined against AU-C 200.14.
Which CPA exam sections use control risk?
Control risk appears in 6 CPA exam sections: AUD, BAR, FAR, ISC, REG, TCP.
What is the difference between control risk and inherent risk?
Inherent risk is the susceptibility of an assertion to misstatement BEFORE considering controls. Control risk is the risk that the entity’s controls fail to prevent or detect one. Both belong to the entity, and the auditor assesses rather than sets them. Detection risk is the only one the auditor controls, by changing the nature, timing and extent of procedures. (AU-C 315)
Other terms defined against AU-C 200
- applicable financial reporting framework: The framework management adopts for the statements, such as GAAP or a special purpose framework.
- inherent risk: The susceptibility of an assertion to material misstatement before any control is considered.
- level of assurance: How much confidence the practitioner expresses.
- professional skepticism: An attitude that includes a questioning mind and a critical assessment of evidence.
- risk of material misstatement: The risk that the statements are materially misstated before the audit begins.
Related terms
- assessed risk: The auditor's judgment about the risk of material misstatement at the assertion level, combining inherent and control risk.
- significant risk: A risk of material misstatement that warrants special audit attention because of its likelihood or its size.
- material weakness: A deficiency, or combination of deficiencies, in internal control over financial reporting where there is a reasonable possibility that a material misstatement will not be prevented, or detected and corrected, on a timely basis.
- material misstatement: An error or omission in the financial statements large enough, or of a kind, that it could change the decision of a reasonable user relying on them.
- further audit procedures: The work done in response to assessed risk: tests of controls and substantive procedures.
- risk assessment procedures: The audit procedures designed and performed to identify and assess the risks of material misstatement at the financial statement and assertion levels.