The risk assessment process provides a structured means of evaluating
information and applying professional judgment as to the most important
areas for audit examination.
A detailed risk assessment is undertaken during the planning phase of the engagement to confirm that the lines of enquiry and the initial objectives have indeed focused on the most important risks associated with the program or activity being audited.
The objective statements for the audit, as outlined in the Risk-based Audit Plan, may need to be amended if the more detailed risk assessment reveals additional risks or assigns higher or lower risk scores to those risks already identified.
The steps involved in performing a detailed risk assessment are:
A detailed risk assessment is undertaken during the planning phase of the engagement to confirm that the lines of enquiry and the initial objectives have indeed focused on the most important risks associated with the program or activity being audited.
The objective statements for the audit, as outlined in the Risk-based Audit Plan, may need to be amended if the more detailed risk assessment reveals additional risks or assigns higher or lower risk scores to those risks already identified.
The steps involved in performing a detailed risk assessment are:
- Identify the risks associated with the achievement of the auditee's objectives and expected results
- Assess the relative significance of the risks in terms of the likelihood of each risk occurring and the impact should it occur
- Determine on a preliminary basis whether management's assertions on controls are likely to prevent or mitigate the occurrence of the risks of greatest concern and
- Plan to focus audit objectives and scope on testing the existence or adequacy and effectiveness of key controls over areas of greatest risk. Appendix G provides a Template for Documenting Engagement Risk Assessment.