What does risk assessment procedures mean on the CPA exam?
Risk assessment procedures. The audit procedures designed and performed to identify and assess the risks of material misstatement at the financial statement and assertion levels. They comprise inquiry, analytical procedures, and observation and inspection.
Defined against AU-C 315.12.
Which CPA exam sections use risk assessment procedures?
Risk assessment procedures appears in the AUD section of the CPA exam.
What is the difference between risk assessment procedures and substantive procedures?
They differ by purpose rather than technique, and one technique can serve either. A risk assessment procedure is designed and performed to identify and assess the risks of material misstatement at the financial statement and assertion levels. A substantive procedure is designed to detect material misstatement at the assertion level, and comprises exactly two things: tests of details and substantive analytical procedures. The reason risk assessment alone cannot carry an opinion is AU-C 330.18, which requires substantive procedures for each relevant assertion of each significant class of transactions, account balance and disclosure REGARDLESS of the assessed level of control risk. (AU-C 315 and AU-C 330.18)
Other terms defined against AU-C 315
- application controls: Controls built into one business process or system, such as a validity check on an input field or a three-way match.
- assessed risk: The auditor's judgment about the risk of material misstatement at the assertion level, combining inherent and control risk.
- control environment: The governance and management functions and the attitudes, awareness, and actions of those charged with governance and management concerning the entity's system of internal control.
- general controls: Controls over the IT environment as a whole -- access, change management, operations -- that everything else depends on.
- general IT control: A control over the entity's IT processes that supports the continued effective functioning of information-processing controls and the integrity of information.
- information and communication: One of the five components of internal control: how an entity obtains the information it needs and gets it to the people who have to act on it.
- information-processing control: A control over processing in an IT application or a manual information process that directly addresses a risk to the integrity of information.
- rights and obligations: The assertion that the entity genuinely owns the assets it reports and genuinely owes the liabilities.
Related terms
- audit procedures: The specific work performed: inspection, observation, inquiry, confirmation, recalculation, reperformance and analytical procedures.
- analytical procedures: Evaluations of financial information by studying plausible relationships among financial and nonfinancial data.
- further audit procedures: The work done in response to assessed risk: tests of controls and substantive procedures.
- substantive procedures: Work aimed directly at detecting misstatement in a balance or disclosure, as opposed to testing whether a control operated.
- agreed-upon procedures: An engagement where the practitioner performs procedures the parties have specified and reports the findings, expressing no opinion.
- material misstatement: An error or omission in the financial statements large enough, or of a kind, that it could change the decision of a reasonable user relying on them.