Audit risk (audit risk) is the risk that the auditor gives an inappropriate opinion when the financial statements actually contain a material misstatement. In simple terms: the error exists, but it slips past the examination and the auditor still states the financial statements are fair.
Audit risk can never be reduced to zero, only pressed down to an acceptable level. That's why the auditor needs to measure it, using three components combined in a formula. This article discusses the meaning of audit risk, its three types, the calculation formula, example cases, and how to determine it.
Understanding Audit Risk
Audit risk is the possibility that the auditor states an incorrect opinion on financial statements containing a material misstatement. That misstatement may come from an unintentional error or from fraud, and it can slip through because the entity's internal controls are weak or because the audit procedures performed do not reach far enough to catch it.
In practice, the auditor first sets how much audit risk is still acceptable — generally very low, for example 5% — then designs the entire audit engagement so the actual risk does not exceed that figure. This approach underlies risk-based audit, in which internal audit focuses resources on the areas most likely to be problematic.
3 Types of Audit Risk

Audit risk consists of three components. The first two are attached to the audited entity and are outside the auditor's control; only the third is truly controllable by the auditor.
1. Inherent Risk (Inherent Risk)
Inherent risk is the susceptibility of an account balance or class of transactions to material misstatement, before taking any internal control into account. This risk is attached to the nature of the business and its transactions.
Examples: an allowance for doubtful accounts estimate has high inherent risk because it involves subjective judgment, while a petty cash balance has low inherent risk because its calculation is simple and objective.
See also: Inherent risk in auditing: definition, examples and ways of measuring
2. Control Risk (Control Risk)
Control risk is the risk that a material misstatement will not be prevented, or detected and corrected in a timely manner, by the internal control of the entity. The weaker the design and operation of the controls, the higher this risk.
Examples: a company that does not separate the function of recording and holding cash has high control risk, because one person can commit and conceal an irregularity at the same time.
See also: Control Risk in Auditing: Definition, Examples, and How to Assess It
3. Detection Risk (Detection Risk)
Detection risk is the risk that the audit procedures performed fail to find a material misstatement that actually exists. This is the only component within the auditor's control, since its size is determined by the extent, timing, and type of testing chosen.
Its relationship with the other two components is inverse: when inherent risk and control risk are assessed as high, the auditor must lower detection risk by extending substantive testing, increasing the sample size, or moving testing to the end of the period.
Examples: the auditor samples 20 of 5,000 sales transactions. Such a small sample makes detection risk high, because the chance that a misstatement lies outside the sample becomes large.
Audit Risk Formula
The three components above are combined in the following audit risk model:
Audit Risk = Inherent Risk × Control Risk × Detection Risk
Audit Risk (AR) = Inherent Risk (IR) × Control Risk (CR) × Detection Risk (DR)
In practice this formula is reversed. The auditor sets an acceptable audit risk, assesses inherent risk and control risk based on the entity's condition, then calculates how much detection risk can still be tolerated:
Detection Risk = Audit Risk ÷ (Inherent Risk × Control Risk)
Calculation example
The auditor sets an acceptable audit risk of 5%. After assessing the entity, inherent risk is estimated at 80% and control risk at 50%. So the acceptable detection risk is:
DR = 5% ÷ (80% × 50%) = 0.05 ÷ 0.40 = 12.5%
This means the auditor may only bear a 12.5% risk of failing to detect a misstatement. Such a low figure demands sufficiently extensive substantive testing. Compare this to a case where the entity's internal control is strong, so control risk is only 20%: then DR becomes 5% ÷ (80% × 20%) = 31.25% — the auditor can work with lighter testing.
| Components | Controlled by | If assessed as high |
|---|---|---|
| Inherent risk | The nature of the entity's business and transactions | The auditor must tighten testing |
| Control risk | The quality of the entity's internal controls | The auditor cannot rely on the controls; substantive testing is extended |
| Detection risk | The auditor themself | Must be lowered so audit risk stays within an acceptable limit |
How to determine risk in an Audit
Risk assessment is carried out at the planning stage and reviewed throughout the engagement. Factors considered include:
- Transaction complexity. Transactions involving estimates, valuations, or related parties carry higher inherent risk.
- Quality of internal control. Well-designed and well-operated controls lower control risk, allowing the auditor to reduce the extent of substantive testing.
- History of misstatements and findings in prior periods. Accounts that have had problems before tend to be assessed as higher risk.
- Pressure on management. Aggressive performance targets or profit-based incentive schemes increase the risk of fraud.
- Experience and competence of the audit team. An experienced team lowers detection risk at the same level of testing.
The results of this assessment are then mapped to each account and process, and translated into the audit plan. The method is discussed in more detail in risk assessment.
Examples Of Audit Risk Cases

A company records revenue from a long-term contract using the percentage-of-completion method. Management overestimates the project's percentage of completion, so current-year revenue is overstated.
All three risk components operate at once in this case. Inherent risk high, because the completion estimate is subjective. Control risk high, if there is no independent review of the project's technical estimates. Detection risk becomes real if the auditor only examines the contract documents without testing the project's physical progress in the field.
If the auditor still issues an unqualified opinion under these conditions, audit risk has materialized: the opinion given is inappropriate for financial statements that are materially misstated.
The Importance Of Risk-Based Auditing
Risk-based audit is becoming increasingly important in a complex business world. By identifying higher-risk areas, the auditor can add more value through recommendations that improve the effectiveness of internal control.
This approach not only reduces the risk of errors in the financial statements, but also helps the organization achieve its objectives more effectively — because audit time is spent on what is genuinely risky, rather than spread evenly across the whole process.
FAQ About Audit Risk
What is audit risk?
Audit risk is the risk that the auditor gives an inappropriate opinion when the financial statements actually contain a material misstatement. In English it is called audit risk.
What is the audit risk formula?
Audit Risk = Inherent Risk × Control Risk × Detection Risk (AR = IR × CR × DR). To determine the acceptable detection risk, this formula is reversed into DR = AR ÷ (IR × CR).
What are the types of audit risk?
There are three types: inherent risk attached to the nature of the business and transactions before accounting for controls, control risk when internal controls fail to prevent or detect a misstatement, and detection risk when audit procedures fail to find an existing misstatement.
What is detection risk?
Detection risk is the risk that the audit procedures performed fail to find a material misstatement that actually exists. This is the only component controlled by the auditor, since its size is determined by the extent, timing, and type of testing chosen.
What is inherent risk in audit?
Inherent risk (inherent risk) is the susceptibility of an account balance or class of transactions to material misstatement before taking internal control into account. For example, a subjective allowance for receivables estimate has high inherent risk.
How is risk determined in an audit?
Through an assessment of transaction complexity, the quality of internal control, the history of misstatements in prior periods, pressure on management, and the audit team's experience. The results are mapped to each account and then translated into the audit plan.
What is an example of an audit risk case?
A company overestimates a project's percentage of completion, so revenue is overstated. If the auditor only examines the contract documents without testing the project's physical progress and still issues an unqualified opinion, audit risk has materialized.
What is risk-based auditing?
Risk-based audit is an approach that focuses examination on the areas with the highest risk level to ensure the reliability of financial information, so that audit time is spent on what is genuinely risky.
Manage Audit Risk Assessment with Audithink
Assessing inherent risk and control risk for dozens of accounts and units manually makes the audit plan hard to justify and quickly outdated. Audithink, internal audit management software for companies and state-owned enterprises in Indonesia, helping internal audit teams map risk, prepare a risk-based audit plan, and link every testing procedure to the risk it addresses.
See Audithink's features or schedule a demo to see how it works.
Consultation with the Audithink Team to discuss your company's internal audit needs.



