Every textbook draws the same equation: audit risk equals inherent risk times control risk times detection risk. It's a useful teaching device, and it's not what either auditing standard actually says.
PCAOB's AS 1101 and the AICPA's SAS 145 both describe audit risk the same way: a function of the risk of material misstatement and detection risk. Neither standard multiplies anything. That distinction matters more than it sounds, because SAS 145 changed how inherent and control risk get assessed, and a lot of secondary material still explains the old approach as if nothing moved.
PCAOB's AS 1101.04 states the relationship in a single sentence: "Audit risk is a function of the risk of material misstatement and detection risk." AICPA's AU-C 200, as amended through SAS 145, says the same thing for GAAS audits. Neither standard turns that relationship into an equation, and neither one tells the auditor to multiply percentages together to land on a number.
That gap between the standard and the classroom formula isn't a technicality. The multiplication model implies inherent risk, control risk, and detection risk are independent probabilities that combine mechanically, when in practice auditors assess inherent and control risk through judgment, informed by evidence, and then calibrate detection risk against that judgment, not against a calculated percentage.
The formula survives in textbooks because it's a clean way to illustrate the inverse relationship between risk and evidence. It survives in practice as a mental model, not as something either standard requires an auditor to compute.
Inherent risk describes how prone an assertion, a class of transactions, an account balance, or a disclosure, is to misstatement before any control gets credit. Both frameworks define it almost identically: a higher inherent risk assertion is simply one more exposed to error or fraud on its own terms.
What SAS 145 adds is a vocabulary for explaining why: it introduces inherent risk factors, characteristics that push an assertion's susceptibility to misstatement up or down. The standard names five inherent risk factors:
These factors may be qualitative or quantitative. For example, the size of a balance or the volume and uniformity of the items processed can affect where an assertion sits on the spectrum. Depending on how strongly these factors apply, inherent risk sits somewhere along what SAS 145 calls the spectrum of inherent risk, a frame of reference rather than a simple high or low label.
That spectrum does more than describe risk: it directly feeds the revised definition of significant risk. Under SAS 145, a significant risk is one where the inherent risk assessment lands close to the upper end of that spectrum, based on the combined likelihood and magnitude of a potential misstatement.
The earlier definition turned on whether, in the auditor's professional judgment, the risk required special audit consideration. The current one ties it to where the risk actually sits before any response is designed, which is a meaningfully different starting point for audit planning.
Control risk is the risk that a misstatement able to occur in an assertion won't be prevented, or detected and corrected, in time by the entity's own system of internal control. Like inherent risk, it belongs to the entity, not the auditor; the auditor's job is to assess it based on evidence.
The procedural shift under SAS 145 is specific and easy to miss: for each identified risk of material misstatement at the assertion level, the auditor now has to assess inherent risk and control risk separately, rather than arriving at one combined risk of material misstatement figure.
There's a default built into that requirement, too: if the auditor doesn't plan to test whether relevant controls actually operate effectively, the assessment of the risks of material misstatement is the same as the inherent risk assessment, which in effect means control risk sits at the maximum. Reducing assessed control risk below maximum now requires planning to test, and actually testing, operating effectiveness. There's no middle ground where a lower control risk is assumed without that work.
To assess control risk, the auditor first has to understand the entity's system of internal control, which SAS 145 defines as having five interrelated components:
The auditor has to understand and evaluate each component. The requirement to evaluate design and confirm implementation of individual controls applies to identified controls in the control activities component: controls that address a significant risk, controls over journal entries, controls the auditor plans to test for operating effectiveness (including controls over risks where substantive procedures alone cannot provide sufficient appropriate evidence), and any other control the auditor considers appropriate. For those controls, SAS 145 requires evaluating whether the control is designed effectively and confirming it has actually been put into practice.
Confirming that a control has been implemented, not just that it exists on paper, is where a walkthrough audit procedure earns its keep. SAS 145 is explicit that implementation can't be confirmed by inquiry of entity personnel alone: it requires additional procedures, which in practice usually means tracing a transaction through the system end to end and observing the control as it actually operates. That's the mechanical core of a walkthrough, and it's also how auditors identify the general IT controls that support any automated control they're relying on.
Detection risk is the risk that the auditor's own procedures fail to catch a misstatement that's genuinely there. Unlike inherent and control risk, it isn't a property of the client; it's a direct consequence of what the auditor decides to do and how well it gets done.
The relationship between detection risk and the other two is inverse, not additive. When inherent and control risk sit higher, the auditor needs detection risk to be lower, which means more persuasive substantive evidence: a larger sample, more reliable procedures, testing closer to year end instead of at an interim date.
When the risk of material misstatement is lower, a lighter substantive program can still bring overall audit risk down to an appropriately low level. Nothing in either standard assigns a specific numeric target to any of this: "appropriately low" is a judgment the auditor documents, not a threshold pulled from a table.
Assertions are the categories auditors use to think about what could actually be wrong with a number or a disclosure. The classic breakdown, used under PCAOB standards, groups them into five categories:
SAS 145 organizes assertions somewhat differently, by classes of transactions, account balances, and presentation and disclosure, but the bigger shift is a related concept: which of these audit assertions actually matter for a given engagement. Under the revised definition, an assertion is relevant only when it carries an identified risk of material misstatement, which SAS 145 defines with a two-part test:
An assertion that doesn't clear both parts isn't relevant, and the determination is made before considering any control, based purely on inherent risk.
That definition does real work downstream: a class of transactions, account balance, or disclosure counts as significant only when it has at least one relevant assertion attached to it, which is itself a term SAS 145 formally defines for the first time. Everything that follows, which controls get evaluated, where substantive procedures concentrate, traces back to this relevance test.
Beyond inherent risk factors and the control risk default, a few other requirements are new or revised, and they're worth knowing even if they don't come up in every engagement:
To build the understanding all of this depends on, SAS 145 requires the auditor's risk assessment procedures to include three types of work:
Risk assessment procedures must include all three types, although the auditor need not apply every type to every aspect of the understanding being developed. SAS 145 also keeps the long-standing requirement for an engagement team discussion about where the financial statements are susceptible to material misstatement, a conversation meant to surface what one team member knows that another doesn't.
The audit risk model survives as a way of explaining the relationship between risk and evidence to someone new to the concept. It stops being useful the moment it's treated as a literal computation the standards require, because neither AS 1101 nor SAS 145 asks for one. What they ask for is documented judgment: a separate read on inherent risk, an honest answer on whether control risk testing was actually planned and performed, and a detection risk response that's calibrated to both.
Bizora's Audit Research traces questions like these back to the exact paragraph, whether that's SAS 145 on risk assessment or AS 3105 on a modified opinion. Bizora's guide to the types of audit opinions covers what happens downstream, once risk assessment and the evidence gathered in response lead to a qualified, adverse, or disclaimed opinion instead of a clean one.
It's the relationship between audit risk, the risk of material misstatement, and detection risk. PCAOB's AS 1101 and the AICPA's SAS 145 both describe audit risk as a function of these two things, not as a mathematical formula. The common textbook equation, audit risk equals inherent risk times control risk times detection risk, is a teaching simplification rather than a requirement in either standard.
Inherent risk is how susceptible an assertion is to misstatement before any control is considered. Control risk is the risk that the entity's own system of internal control fails to prevent or catch that misstatement in time. Both belong to the entity, not the auditor, and under SAS 145 they must now be assessed separately rather than combined into one figure.
Detection risk is the risk that the auditor's own procedures fail to detect a misstatement that actually exists. It's the one component of audit risk the auditor directly controls, set through the nature, timing, and extent of substantive procedures, and it moves inversely to how high inherent and control risk were assessed.
SAS 145 applies to audits of financial statements for periods ending on or after December 15, 2023. Its effective date was aligned with SAS 143, on accounting estimates, because the two standards share the inherent risk factors and spectrum of inherent risk concepts.
They're the characteristics SAS 145 identifies as driving how susceptible an assertion is to misstatement before controls are considered: complexity, subjectivity, change, uncertainty, and susceptibility to misstatement from management bias or other fraud risk factors. They can be qualitative or quantitative, and they explain where an assertion sits on the spectrum of inherent risk.
The old definition turned on whether, in the auditor's professional judgment, the risk required special audit consideration. SAS 145 ties it instead to the inherent risk assessment itself: a risk is significant when that assessment sits close to the upper end of the spectrum of inherent risk, based on the combined likelihood and magnitude of a potential misstatement.
The control environment, the entity's risk assessment process, the entity's process to monitor its system of internal control, the information system and communication, and control activities. SAS 145 requires understanding all five, though only certain control activities require evaluating design and confirming implementation.
Bizora AI turns hours of manual research into seconds, with every answer backed by primary source citations. Start your 7-day free trial. No credit card required.
Start Free Trial