Back to Glossary

Entry · Accounting

Control Risk

Control risk is the chance that a company's own internal checks will fail to prevent or detect a significant error in its financial statements. It is one of three components auditors combine when planning how much testing to do.

High control risk does not mean the accounts are wrong; it means the auditor cannot rely on the company's systems and must look harder at the numbers themselves.

What it means

Auditors break the risk of signing off wrong accounts into three parts. Inherent risk is how error prone an area is by nature, control risk is the chance the company's own controls miss such an error, and detection risk is the chance the auditor's own procedures fail to find it.

The first two belong to the business and exist whether or not an audit happens. Only detection risk is under the auditor's direct control, which is precisely why the model is useful: it tells the auditor how much work is needed to bring overall audit risk down to an acceptable level.

Assessing control risk starts with understanding the process, then testing whether the relevant controls actually operated during the year. If a monthly bank reconciliation was performed and reviewed in all twelve months, the auditor can lower the assessed control risk and reduce detailed testing of cash transactions.

When controls cannot be relied upon, the auditor takes a substantive approach, meaning larger samples, more third party confirmations and more analytical work on the underlying transactions. That is more expensive and more disruptive, so a poor control assessment usually translates directly into a higher audit fee.

The same idea has value to managers who never speak to an auditor. Asking where a process would fail if one person were absent, or which numbers nobody independently checks, is an informal control risk assessment and often the cheapest way to find weak points before they cost money.

An important nuance is that control risk can never be assessed at zero. Every control system is subject to human error, collusion between two people, and management override, so auditors always perform some substantive procedures regardless of how good the controls appear.

In practice

Real-world examples.

1

Example

A distributor gives its auditor evidence that every credit note above $5,000 was authorised by a director during the year. The auditor lowers assessed control risk over revenue and reduces the sample of credit notes tested from eighty to thirty.

2

Example

A hotel group replaces its booking system halfway through the financial year, and access controls in the new system were not configured for six weeks. The auditor assesses control risk over room revenue as high for that period and performs additional analytical work on occupancy and rate data.

3

Example

A start-up has a single finance employee who raises invoices, processes payments and prepares the accounts. With no segregation of duties possible, the auditor assesses control risk at maximum and confirms cash balances and major receivables directly with third parties.

Think of it

Control risk is how likely controls will fail-the chance controls don't catch errors.

Formula

Calculation

Audit risk = inherent risk x control risk x detection risk, which rearranges to detection risk = audit risk / (inherent risk x control risk) An auditor is willing to accept audit risk of 5% on a manufacturer's revenue figure. Revenue recognition involves complex delivery terms, so inherent risk is assessed as high at 80%. The company performs a monthly reconciliation between the despatch system and the sales ledger, which the auditor tests and finds effective, so control risk is assessed at 50%. Detection risk = 0.05 / (0.80 x 0.50) = 0.05 / 0.40 = 12.5%. The auditor can therefore tolerate a 12.5% chance that their own procedures miss a material error, which supports a moderate sample of sales invoices. Suppose instead that the reconciliation had not been performed for six months of the year, so control risk is assessed at the maximum of 100%. Detection risk = 0.05 / (0.80 x 1.00) = 6.25%, which is half the previous figure. The auditor must roughly double the depth of substantive testing to reach the same overall confidence.

Case study

Seen in the real world.

The following example is fictional and purely illustrative. Ardsley Components, an invented engineering firm, was surprised when its audit fee rose 45% in a year with no change in size or complexity. The audit partner explained that two of the three controls he had relied on previously had lapsed: the stock count had been performed by the warehouse manager alone with no independent observer, and the monthly gross margin review had stopped when the financial controller left.

With control risk assessed at maximum over inventory, the auditors had to attend a full count themselves, test far more purchase invoices and confirm a larger share of trade receivables. The extra work accounted for almost the entire fee increase.

Ardsley's fictional response was to restore both controls and document them properly. At the following audit, the team was able to rely on the company's own count procedures, testing dropped back and the fee fell close to its previous level, which made the internal controls look considerably cheaper than the alternative.

Watch out

Common mistakes.

  • Reading a high control risk assessment as an accusation that the accounts are misstated, when it is a statement about reliance rather than accuracy.
  • Assuming a control that is documented in a policy has therefore operated, when control risk depends on evidence that it was actually performed all year.
  • Believing control risk can be reduced to zero through better systems, which ignores management override and collusion.

Questions

People also ask.

Who assesses control risk, the company or the auditor?

The auditor makes the formal assessment for audit planning, but the risk itself belongs to the company and is created by how it designs and runs its processes.

How does control risk affect what a business pays for its audit?

Weak controls force the auditor to do more substantive testing, so higher assessed control risk usually means a higher fee and a longer audit.

Can a very small company ever have low control risk?

It is difficult because segregation of duties is limited, though active owner review of bank statements, approvals and monthly accounts can genuinely reduce it.

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · September 4, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.