How an Audit Works, Part 2: Risk, Materiality and Assertions
Kyle Ashcraft, CPA · 2019 CPA Exam Scores · 95 FAR · 98 BEC · 91 REG · 90 AUD
Part one covered everything before the audit starts. This part covers the machinery that drives every decision afterwards, and it is where most AUD points get lost.
Audit risk, materiality, assertions and the split between tests of controls and substantive procedures are not four topics. They are one decision framework wearing four names. Learn them as separate lists and you will spend the rest of the section guessing. Learn how they connect and the procedural material in parts three and four mostly answers itself.
AUD 101: the complete audit process
- Client acceptance, engagement letter, documentation and planning
- Audit risk, materiality, assertions and types of procedures (you are here)
- Substantive testing: cash, receivables and revenue
- Audit reports and opinions
Prefer the app? Watch on YouTube.
In this article
Why does risk assessment drive everything?
Auditors do not have unlimited hours, staff or budget, and no audit tests every transaction. Risk assessment is how the auditor works out which parts of the company are most likely to be wrong, so the limited resource goes where it matters.
Picture a surgeon who skips the consultation. They walk into theatre planning to replace the legs, the arms and several organs, because without a diagnosis they have no idea where the problem is. That is an audit without risk assessment: enormous effort, distributed by guesswork. The diagnosis tells you where to operate.
This is also why AUD questions phrased as "how should the auditor respond" almost always trace back here. The response is not a fact to memorize. It falls out of the risk that was assessed.
What is the audit risk model?
Audit risk is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated. Note where the definition sits. It is about the opinion, not merely about an error existing somewhere.
| Component | What it is | Whose it is |
|---|---|---|
| Inherent risk | The susceptibility of an assertion to misstatement before considering controls. Cash is inherently risky because it is liquid and easy to misappropriate. Prepaid expenses are not, because there is little to gain and little to get wrong. | The client's |
| Control risk | The risk that a misstatement will not be prevented, or detected and corrected, by the entity's internal control. | The client's |
| Detection risk | The risk that the auditor's own procedures fail to find a misstatement that exists. | The auditor's |
Risk of material misstatement against detection risk
The first two combine:
RMM is the client's side of the equation, and the auditor cannot change it. Inherent risk is a property of the account and its environment. Control risk is a property of the client's controls. Both are assessed, not chosen.
Detection risk is the only thing the auditor moves, and it moves inversely:
As the risk of material misstatement rises, detection risk must fall. Higher client-side risk means the auditor must work harder to hold overall audit risk at an acceptably low level.
Lowering detection risk means changing the nature of procedures to more persuasive ones, shifting the timing closer to year-end, and increasing the extent of testing. Those three levers are the only response available, which is why the same answer keeps appearing across dozens of differently worded questions.
A kitchen, if the formula stays abstract. Inherent risk is the difficulty of the dish, since a steak cooked to temperature goes wrong far more often than fries. Control risk is whether the head chef checks plates before they leave. Detection risk is the driver checking the bag before handing it over. Hard dish plus a chef who never looks means the driver has to check very carefully indeed, because the customer is the one who ends up with the mistake.
What the auditor does and does not set. The auditor determines the acceptably low level of audit risk for the engagement, which is a judgment about how much assurance the opinion needs to carry. What the auditor cannot do is change inherent or control risk. So with audit risk fixed by judgment and RMM fixed by the client, detection risk is the residual. It is not chosen so much as forced by the other three numbers.
At what levels is risk assessed?
Two, and the exam expects you to tell them apart because the correct response differs.
| Financial statement level | Relevant assertion level | |
|---|---|---|
| Scope | Pervasive risks affecting the statements as a whole | Risks tied to specific classes of transactions, balances and disclosures |
| Examples | The CFO leaves mid-year, going concern doubt, significant related party transactions, a weak control environment | Existence of inventory, completeness of accounts payable, occurrence of revenue |
| Response | Adjust the overall strategy: more experienced staff, heightened professional skepticism, an element of unpredictability in procedures | Design specific further audit procedures targeted at the assertion at risk |
Most of the fieldwork happens at the assertion level, which is why candidates default there. But when a question describes something pervasive, a CFO departure or a deteriorating control environment, and asks for the response, the answer is a strategy change rather than a procedure on one account. Recognizing which level the question sits at is half the work.
What is the difference between tests of controls and substantive procedures?
Two categories, and the choice between them is the central strategic decision of the audit.
| Tests of controls | Substantive procedures |
|---|---|
| Test whether the entity's controls are operating effectively | Detect material misstatement directly in balances, transactions and disclosures |
| Optional in a financial statement audit, required in an integrated audit of internal control | Always required. Some substantive work is performed for every relevant assertion regardless of how good the controls are. |
| Success reduces control risk below maximum, allowing less substantive work | Split into tests of details and substantive analytical procedures |
That second row is worth pausing on. Even where controls test as highly effective, the auditor cannot eliminate substantive procedures entirely. Controls reduce how much substantive work is needed. They never reduce it to nothing.
The procedures themselves
| Procedure | What the auditor does | Category |
|---|---|---|
| External confirmation | Obtains a response directly from a third party, such as a bank or customer | Test of details |
| Inspection of records | Examines source documents: invoices, contracts, bank statements | Test of details |
| Inspection of assets | Physically examines a tangible asset | Test of details |
| Recalculation | Checks the mathematical accuracy of the client's figures | Test of details |
| Reperformance | Independently re-executes a procedure or control the client performed | Test of details |
| Observation | Watches a process being performed, such as an inventory count | Evidence limited to the moment observed |
| Analytical procedures | Builds an expectation and compares it to the recorded amount | Substantive analytical, not a test of details |
| Inquiry | Asks management or staff | Never sufficient on its own |
Two rows there are traps rather than facts.
Observation only tells you about the moment you were watching. A control performed impeccably while the auditor stood there says nothing about the other 364 days, which is why observation is usually corroborated with something else.
Inquiry alone never provides sufficient appropriate evidence. It is useful for direction and it is a required part of risk assessment, but an answer choice offering inquiry as the sole basis for a conclusion is wrong essentially every time it appears.
Substantive analytical procedures are not tests of details. Tests of details examine individual items. Analytical procedures reason about relationships between amounts. The exam tests that boundary directly, and candidates who file everything substantive under one heading lose the question.
How the choice feeds back into the risk model
→ higher detection risk acceptable → less substantive work
Skip controls → control risk at maximum → RMM higher
→ detection risk must fall → more substantive work
This chain is the most useful thing in the section. Almost any AUD question about how the auditor should respond can be traced along it, and if you can locate where the question sits on the chain, the answer is the next link.
Start free with CPA 101
Practice all 25 of the 2026 AICPA released MCQs, plus a free study outline. FAR, AUD and REG tracks available. No credit card required.
What are management assertions?
Assertions are the claims management makes, implicitly, by handing over a set of financial statements. These numbers exist. Nothing is missing. Everything is in the right account and the right period, at the right amount. We own the assets and owe the liabilities. The disclosures are complete and understandable.
Each of those is separately testable, which is the point. Rather than vaguely auditing accounts receivable, the auditor tests whether receivables exist, whether the balance is complete, whether it is valued correctly.
Assertions are a grading rubric. A professor marking an essay does not simply write "good." They score structure, argument, grammar and citation separately, because a single verdict tells the student nothing about what to fix. Assertions do the same job for a set of financial statements.
The two categories
Current standards group assertions into two categories rather than the three that older materials describe. Disclosures no longer form a separate bucket. They are folded into each category, which is why "presentation" now appears in both.
| Classes of transactions and events, and related disclosures | Account balances, and related disclosures |
|---|---|
| Occurrence | Existence |
| Completeness | Completeness |
| Accuracy | Accuracy, valuation and allocation |
| Cutoff | Rights and obligations |
| Classification | Classification |
| Presentation | Presentation |
If your notes describe three categories with disclosures standing alone, they predate the current structure. The individual assertions have not changed much; where they live has.
| Assertion | The question | A failure looks like |
|---|---|---|
| Existence and occurrence | Is it really there? Did it really happen? | Inventory on the books that is not in the warehouse |
| Completeness | Is anything missing? | A note payable left off the balance sheet |
| Classification | Is it in the right account? | A repair capitalized into fixed assets |
| Cutoff | Is it in the right period? | January revenue recorded in December |
| Accuracy and valuation | Is the amount right? | Receivables overstated because the allowance is too small |
| Rights and obligations | Do we own it? Do we owe it? | Consignment inventory shown as the company's own |
| Presentation | Is it disclosed properly? | An undisclosed material contingent liability |
Which assertion matters most for which account?
This is the highest-value pattern in the whole topic, and it comes from management's incentives rather than from the accounting.
| Account type | Critical assertion | Because |
|---|---|---|
| Assets | Existence | Management wants assets to look larger, so the risk is overstatement |
| Revenue | Occurrence | Management wants revenue to look larger, so the risk is fabrication |
| Liabilities | Completeness | Management wants liabilities to look smaller, so the risk is omission |
| Expenses | Completeness | Management wants expenses to look smaller, so the risk is omission |
Anything management wants bigger gets tested for existence and occurrence. Anything management wants smaller gets tested for completeness. That single sentence answers a large share of assertion questions, and it also explains why the search for unrecorded liabilities exists at all.
How is materiality determined?
Not every error matters. A $3 discrepancy at a company with $500 million of revenue changes no one's decision about anything, and an auditor who treats it as a finding has misunderstood the job.
A misstatement is material if it could reasonably be expected to influence the economic decisions of users taken on the basis of the financial statements. Size is part of it. So is nature: a small misstatement that turns a loss into a profit, or that conceals a related party transaction, can be material at a trivial dollar amount.
Benchmarks
Materiality is set during planning as a percentage of a benchmark chosen to fit the entity. Common starting points, none of them prescribed by the standards:
| Benchmark | Typical range | Suits |
|---|---|---|
| Pretax income | About 5% | Profit-oriented entities with stable earnings |
| Total revenue | Roughly 0.5% to 2% | Entities with volatile or marginal earnings |
| Total assets | Roughly 0.5% to 2% | Asset-heavy entities and funds |
The choice of benchmark is a judgment about which number the users of these particular statements actually care about. That is why a loss-making company usually gets a revenue or asset base: a percentage of a pretax loss near zero would produce a nonsensical threshold.
The four thresholds
| Term | What it is | Where it sits |
|---|---|---|
| Overall materiality | The threshold for the financial statements as a whole | Largest, set first |
| Performance materiality | A lower figure creating a buffer, so undetected and uncorrected misstatements together are unlikely to exceed overall materiality | Below overall |
| Tolerable misstatement | Performance materiality applied to a particular account or class of transactions | At account level |
| Clearly trivial | So small that misstatements need not even be accumulated | The floor |
It works as a funnel. Overall materiality is the mouth. Performance materiality narrows it to leave room for error. Tolerable misstatement narrows it again for an individual account. Clearly trivial is the bottom, below which nothing is worth recording.
Materiality is not fixed for the engagement. If the auditor learns during fieldwork that revenue was materially different from the planning estimate, materiality is revised up or down and the planned procedures change with it.
Immaterial does not mean ignorable. The auditor accumulates identified misstatements above the clearly trivial threshold and evaluates them together at the end. Six individually immaterial errors pointing the same direction can be material in aggregate, which is exactly the situation the accumulation requirement exists to catch.
And as part one covered, materiality is never disclosed to management in the engagement letter. A client who knows the threshold knows precisely how much it can misstate without consequence.
How does it all connect?
Everything above is one sequence:
- Set materiality, which decides what size of error is worth finding.
- Assess inherent risk for each relevant assertion, based on the nature of the account and its environment.
- Decide whether to test controls. Effective controls lower control risk, which lowers RMM, which permits less substantive work.
- Design substantive procedures aimed at the specific assertions most at risk, not at accounts in general.
- Execute and evaluate, accumulating misstatements and comparing the total against materiality.
Part three works through that final stage on cash, receivables and revenue. Every procedure there is a consequence of a decision made here.
Where does Maxwell CPA Review fit?
Concessions first. If you want the largest question bank available, that goes to Gleim or UWorld. If your firm sponsors a course, it is usually Becker, and there is no reason to decline something already paid for. If you want adaptive software that scores your readiness, Surgent does that better than I do.
What Maxwell CPA Review does is different, and this article is a sample of it. Every other option in this category answers a shortage: more questions, longer explanations, more visuals. Maxwell answers a surplus. AUD is not hard because there is too little material. It is hard because the material arrives as a thousand separate rules when it is really one chain of reasoning, and almost nobody teaches the chain.
Here is what is in the AUD section:
| Video lessons | 6 hours |
|---|---|
| Practice MCQs | 750 |
| Task-based simulations | 32 |
| Textbook | 190 pages |
| Study outlines | 60 pages |
| Also included | Final review and a full simulated exam |
Across the whole course: 50 hours of video content, 5,000 practice MCQs and 150 task-based simulations, covering all six sections, FAR, AUD, REG, BAR, ISC and TCP, with no discipline upcharge. Built to the current AICPA Blueprint, with every lecture, textbook and outline created by one CPA who scored 90 or above on every section.
Best for candidates who want the reasoning before the rules: Maxwell CPA Review, with bite-sized lessons focused on the concepts that matter most, at $49 per month, billed monthly, cancel anytime.
Use it as your primary course. Use it to retake a section you failed. Use it alongside what you already bought.
Frequently asked questions
What is the audit risk model?
Audit risk equals inherent risk times control risk times detection risk. Inherent and control risk combine into the risk of material misstatement, which belongs to the client and cannot be changed by the auditor. Detection risk is the auditor's side and the only component the auditor adjusts.
How do risk of material misstatement and detection risk relate?
Inversely. When the risk of material misstatement rises, detection risk must fall, which the auditor achieves by changing the nature of procedures, moving the timing closer to year-end and increasing the extent of testing.
What are the categories of management assertions?
Two under current standards, with disclosures folded into each rather than standing alone. Classes of transactions and events and related disclosures cover occurrence, completeness, accuracy, cutoff, classification and presentation. Account balances and related disclosures cover existence, rights and obligations, completeness, accuracy and valuation, classification and presentation.
Which assertion matters most for assets compared with liabilities?
Existence for assets and completeness for liabilities. Management has an incentive to overstate assets and revenue, so the risk there is that recorded items are not real. It has an incentive to understate liabilities and expenses, so the risk there is omission.
What is the difference between tests of controls and substantive procedures?
Tests of controls evaluate whether controls operate effectively and are optional in a financial statement audit. Substantive procedures detect misstatement directly and are always required, since some substantive work is performed for every relevant assertion no matter how strong the controls prove to be.
Is inquiry alone sufficient audit evidence?
No. Inquiry is a required part of risk assessment and useful for direction, but it never provides sufficient appropriate evidence on its own and always needs corroboration.
What is the difference between materiality and performance materiality?
Overall materiality is the threshold for the financial statements as a whole. Performance materiality is set below it as a buffer, so that undetected and uncorrected misstatements together are unlikely to exceed overall materiality. Tolerable misstatement applies performance materiality to an individual account.
Ready for part three?
Part three covers substantive testing on cash, receivables and revenue. In the meantime, start with the 2026 AICPA released questions and the free study outline.
Kyle Ashcraft, CPA scored 90 or above on every section of the CPA exam in 2019, including a 90 on AUD and a 95 on FAR. He is the founder and sole instructor of Maxwell CPA Review, where he creates every lecture, textbook and study outline himself.
Reach him at MaxwellCPAreview@gmail.com.
Explore the Complete AUD 101 Series
The foundation of the audit, from engagement letters to initial strategy.
Master the audit risk formula, materiality, and the framework that drives procedures.
A complete walkthrough of the balance sheet, sampling, and the legal letter.
Concluding the audit, handling subsequent events, and issuing the final report.
