What it means
Auditors split the risk of signing off on financial statements that are wrong into three components: inherent risk, control risk and detection risk. The first two belong to the business being audited, describing how error-prone the numbers naturally are and how likely the company's own controls are to miss a problem.
Detection risk is the auditor's own contribution, and it moves in the opposite direction to the other two. The practical consequence is that detection risk is a planning dial rather than a measurement.
If a client operates in a complex area with weak internal checks, the auditor must accept a lower detection risk, which means more testing, larger samples and more senior staff on the job. That is why audit scopes and fees tend to rise after a company reports a control weakness.
For a finance leader who is not an auditor, this concept explains a lot of otherwise puzzling behaviour during fieldwork. When the audit team suddenly asks for a much bigger sample of invoices, they are usually responding to an assessment that the company's own controls cannot be relied on, so their own testing has to carry more of the load.
Improving controls is often the cheapest way to bring the following year's audit effort back down. Detection risk is usually expressed through the audit risk model, where audit risk equals inherent risk multiplied by control risk multiplied by detection risk.
Auditors rearrange that equation to solve for the detection risk they can tolerate given a target level of overall audit risk. Many firms use qualitative bands such as low, moderate and high rather than precise percentages, but the logic is identical.
One important nuance is that detection risk can never be reduced to zero. Audits rely on sampling rather than checking every transaction, so there is always sampling risk, plus non-sampling risk from misjudged evidence or a procedure applied badly.
The goal is not perfection but keeping the combined risk low enough that an unqualified opinion is defensible.
In practice
Real-world examples.
Example
A regional food manufacturer installs a new stock system three months before year end. The auditors judge that control risk over inventory has risen while staff learn the system, so they lower tolerable detection risk and attend four warehouse counts instead of one.
Example
A software company's audit team finds that the same person raises customer credit notes and approves them. Because that segregation of duties failure pushes control risk to its maximum, the auditors accept a much lower detection risk and test every credit note above $5,000 rather than a sample.
Example
A family-owned haulage business has simple, stable revenue and strong bank reconciliation controls. The auditors assess both inherent and control risk as low, accept a higher detection risk, and complete testing with a modest sample of journals and a focused review of vehicle depreciation.
Think of it
“Detection risk is the chance auditors miss something-errors audit procedures don't find.
Formula
Calculation
Formula: Detection Risk = Audit Risk / (Inherent Risk x Control Risk).
Suppose an audit partner is willing to accept an overall audit risk of 5%, meaning a 5% chance of giving a clean opinion on materially wrong accounts. She assesses inherent risk at 80% because the client recognises revenue on long, complicated construction contracts. She assesses control risk at 50% because the contract review process works but is not consistently documented.
Detection Risk = 0.05 / (0.80 x 0.50) = 0.05 / 0.40 = 0.125, or 12.5%.
The team can therefore tolerate a 12.5% chance that its own procedures miss a material problem, which means designing testing that gives roughly an 87.5% chance of catching one. If the client's contract controls had failed entirely and control risk were set at 100%, the calculation would become 0.05 / (0.80 x 1.00) = 0.0625, or 6.25%. Halving the tolerable detection risk in that way roughly doubles the depth of substantive testing required, which is exactly why a control failure is expensive.Case study
Seen in the real world.
In this illustrative example, Harborline Medical Supplies is a fictional distributor with revenue of about $90,000,000. During planning, the audit team notes that Harborline has just acquired two smaller competitors and is running three different billing systems in parallel. Inherent risk over revenue is assessed as high, and because the acquired entities' credit control procedures have not yet been aligned, control risk is also assessed as high.
Working backwards from an acceptable audit risk of 5%, the team concludes that tolerable detection risk is low, and rewrites the audit plan accordingly. Sample sizes for revenue testing triple, two extra staff are assigned, and the team performs direct confirmations with a wider group of customers. The fee quote rises by roughly a third, which the finance director initially disputes.
The following year, Harborline consolidates onto a single billing platform and documents a monthly reconciliation between shipments and invoices. Control risk drops, tolerable detection risk rises, and the audit team returns to a normal sample-based approach. This illustrative sequence shows the trade-off clearly: money spent on controls inside the business reduces the testing the auditor has to do outside it.
Watch out
Common mistakes.
- Treating detection risk as something the company can manage. The business influences inherent and control risk, but detection risk is set by the auditor's own procedures.
- Assuming a clean audit opinion means detection risk was zero. Every audit accepts some chance that testing missed something, which is why opinions provide reasonable rather than absolute assurance.
- Reading a larger audit sample as a sign the auditors distrust management personally. Sample size is usually a mechanical response to higher assessed inherent or control risk, not an accusation.
Questions
People also ask.
Does detection risk go up or down when a company's controls improve?
It goes up in the sense that the auditor can tolerate more of it, which means less substantive testing is needed to reach the same overall audit risk.
Can detection risk be measured precisely?
Rarely; most firms use qualitative categories such as low, moderate and high, and the numeric model mainly serves to make the relationships between the components explicit.
Why does detection risk matter to a finance team at all?
Because it drives audit scope, timing and cost, so understanding it helps a finance leader predict and influence next year's audit effort.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%