What does inherent risk mean on the CPA exam?
Inherent risk. The susceptibility of an assertion to material misstatement before any control is considered. It is the risk the business itself brings, which is why it is assessed first and never assessed at zero.
Defined against AU-C 200.14.
Which CPA exam sections use inherent risk?
Inherent risk appears in 6 CPA exam sections: AUD, BAR, FAR, ISC, REG, TCP.
What is the difference between inherent risk and control risk?
Inherent risk is the susceptibility of an assertion to misstatement BEFORE considering controls. Control risk is the risk that the entity’s controls fail to prevent or detect one. Both belong to the entity, and the auditor assesses rather than sets them. Detection risk is the only one the auditor controls, by changing the nature, timing and extent of procedures. (AU-C 315)
Other terms defined against AU-C 200
- applicable financial reporting framework: The framework management adopts for the statements, such as GAAP or a special purpose framework.
- control risk: The risk that the entity's own controls will not prevent, or detect and correct, a material misstatement on a timely basis.
- level of assurance: How much confidence the practitioner expresses.
- professional skepticism: An attitude that includes a questioning mind and a critical assessment of evidence.
- risk of material misstatement: The risk that the statements are materially misstated before the audit begins.
Related terms
- assessed risk: The auditor's judgment about the risk of material misstatement at the assertion level, combining inherent and control risk.
- significant risk: A risk of material misstatement that warrants special audit attention because of its likelihood or its size.
- risk assessment procedures: The audit procedures designed and performed to identify and assess the risks of material misstatement at the financial statement and assertion levels.
- material misstatement: An error or omission in the financial statements large enough, or of a kind, that it could change the decision of a reasonable user relying on them.
- further audit procedures: The work done in response to assessed risk: tests of controls and substantive procedures.
- control environment: The governance and management functions and the attitudes, awareness, and actions of those charged with governance and management concerning the entity's system of internal control.