What it means
Audit risk is conventionally broken into three components that multiply together. Inherent risk is how error-prone an area is by nature, control risk is the chance the company's own systems fail to catch an error, and detection risk is the chance the auditor's own procedures miss it.
The first two belong to the company and the auditor cannot change them. Detection risk is the only lever the auditor controls, so once inherent and control risk have been assessed, the required detection risk falls out of the arithmetic and dictates how much testing is needed.
This has a direct commercial consequence for the business being audited. Strong, evidenced internal controls lower control risk, which allows a higher detection risk, which means fewer substantive tests and typically a shorter and cheaper audit.
Certain areas attract high inherent risk almost automatically: estimates and provisions, revenue recognition on long contracts, related party transactions, and anything involving management judgement or a bonus that depends on the number. Cash in a simple bank account sits at the other end of the scale.
The nuance worth understanding is that audit risk is always assessed alongside materiality. An error of $5,000 in a company with $80,000,000 of revenue is not what the auditor is protecting against, so risk is only ever measured against misstatements big enough to change a reader's decision.
In practice
Real-world examples.
Example
An auditor planning work at a software company identifies revenue recognition on multi-year licences as high inherent risk. The team tests 45 contracts in detail rather than the 15 it would sample for a simple product sale, because detection risk must be pushed lower in that area.
Example
A distribution group invests $150,000 in automated three-way matching between purchase orders, goods receipts and invoices. The auditors reassess control risk downward the following year and the audit fee falls by roughly 12%, recovering part of the investment.
Example
A family company where the owner approves and posts journal entries alone is assessed with control risk at the maximum. The auditor cannot rely on the system at all and tests every journal above $10,000 substantively, extending the audit by two weeks.
Think of it
“Audit risk is the chance of getting it wrong-issuing wrong opinion on bad statements.
Formula
Calculation
Audit Risk = Inherent Risk x Control Risk x Detection Risk
Rearranged for planning: Detection Risk = Audit Risk / (Inherent Risk x Control Risk)
An audit team sets acceptable audit risk at 5%. Reviewing a construction client with long-term contracts and significant estimates, it assesses inherent risk at 80% and control risk at 50%, because contract records are only partially reviewed by a second person.
Risk of material misstatement = 80% x 50% = 40%
Detection Risk = 5% / 40% = 12.5%
A detection risk of 12.5% is low, so the team must perform extensive substantive testing to be 87.5% confident of catching any material error itself. Now assume the client introduces a second-person review over every contract valuation, reducing control risk to 25%.
Risk of material misstatement = 80% x 25% = 20%
Detection Risk = 5% / 20% = 25%
The auditor may now accept twice as much detection risk, which translates into a smaller sample and fewer hours, and this is the mechanism by which better controls reduce audit fees.Case study
Seen in the real world.
This is an illustrative and entirely fictional example. Rowanbank Care Homes had grown from four sites to seventeen, but its finance function had not grown with it, and the same manager raised invoices, approved payments and reconciled the bank. The auditors assessed control risk at 100% and inherent risk at 70%, meaning that against a 5% audit risk target the required detection risk was 5% / 70% = 7.1%, an unusually demanding standard.
The consequence was a substantive audit with almost no reliance on systems, and the fee rose from $48,000 to $86,000 in a single year. The board's instinct was to challenge the auditors, but the finance director instead presented the arithmetic and asked for a budget to fix the underlying controls.
Over the next year in this fictional story the company separated payment approval from invoice processing, introduced monthly reviewed reconciliations and added an authorisation matrix. Control risk was reassessed at 40%, detection risk rose to 5% / (70% x 40%) = 17.9%, the sample sizes shrank accordingly, and the fee settled back to $59,000.
Watch out
Common mistakes.
- Reading audit risk as the risk that the business will fail, when it is purely the risk that the auditor gives a clean opinion on materially wrong accounts.
- Assuming a higher audit fee reflects an expensive firm, when it very often reflects weak internal controls forcing more substantive testing.
- Thinking auditors aim for zero risk, when the whole model is built on accepting a small, defined and deliberately low level of risk.
Questions
People also ask.
Which component can the auditor actually control?
Only detection risk, since inherent and control risk are properties of the company and its systems that the auditor assesses rather than changes.
How do better controls reduce cost?
Lower control risk permits a higher acceptable detection risk, which allows smaller samples and less substantive testing, so fewer chargeable hours are required.
Is a 5% audit risk target a legal requirement?
No, it is a common planning convention rather than a rule, and firms set the level using professional judgement based on the client and the users of the accounts.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%