Inherent risk and control risk are the two components of the risk of material misstatement in an audit. Inherent risk is the likelihood that a financial statement account or disclosure contains a material error because of what it is, before any consideration of internal controls. Control risk is the likelihood that the company’s own internal controls will fail to prevent or detect that error in time. One belongs to the nature of the account. The other belongs to the company’s defenses around it.
The Core Difference
Inherent risk asks a question about the account itself. How much judgment goes into the number? How complex are the underlying transactions? How exposed is the balance to theft, estimation error, or manipulation? None of this depends on whether the company has any controls in place. Even a perfectly controlled company would face high inherent risk on a hard-to-estimate account.
Control risk asks a different question, and it’s about the company. Are the right controls designed to catch errors in this account? Do the people operating those controls understand them? Does management actually enforce them throughout the year? A company with weak segregation of duties, an outdated IT system, or a history of documented control failures carries elevated control risk regardless of how simple or complex its accounts happen to be.
The distinction matters because auditors assess the two separately and then combine them. The PCAOB’s Auditing Standard No. 8 formally defines the risk of material misstatement at the assertion level as consisting of inherent risk and control risk.1Public Company Accounting Oversight Board. Auditing Standard No. 8 – Audit Risk AS 2110 then spells out how auditors go about identifying and assessing each one.2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement
Examples of Inherent Risk
Some accounts are just harder to get right than others. The valuation of Level 3 financial instruments is a textbook high-inherent-risk area, because these instruments rely on unobservable inputs like internally developed growth rates, volatility assumptions, or illiquidity discounts. The more judgment baked into a number, the more susceptible it is to error or manipulation.3Public Company Accounting Oversight Board. Staff Guidance – Auditing Fair Value of Financial Instruments
Other common high-inherent-risk accounts include warranty reserves, the allowance for doubtful accounts, and inventory in industries where obsolescence moves fast, such as consumer electronics or fashion. Each requires significant estimation, and reasonable people can disagree on the right answer. Revenue recognition is another one, especially where a company uses complex contract structures or variable pricing.
Cash is an interesting case. Calculating the balance is simple, but cash is uniquely susceptible to theft, which pushes inherent risk higher for the existence and completeness assertions even though the arithmetic isn’t hard.
On the other end, a fixed-rate long-term debt balance typically carries low inherent risk. The amount is contractual, the calculation is straightforward, and there is little room for judgment to creep in.
AS 2110 lists the specific factors auditors weigh: the size and composition of the account, the complexity and volume of transactions, susceptibility to fraud, exposure to losses, the presence of related-party transactions, and changes in the account from the prior year. For accounts involving estimates, the standard adds the degree of uncertainty in assumptions, the complexity of the estimation process, how subjective the key inputs are, and the length of any forecast period.2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement
Changes in the regulatory or accounting environment can push inherent risk up almost overnight. When a new standard forces a company to develop new processes and estimates for an existing asset, the transition period itself creates vulnerability.
Examples of Control Risk
Control risk is about the company’s own defenses against error. When the same employee handles cash receipts and reconciles the bank statement, there is no segregation of duties, and control risk for that cash account shoots up. An outdated IT system without access controls or audit trails raises control risk across every account that flows through it.
Strong controls push control risk the other direction. An automated three-way match comparing purchase order, receiving report, and invoice before payment is a well-designed preventive control. Mandatory supervisory review of journal entries above a set dollar threshold is a detective control, catching errors before the books close. The auditor evaluates both the design of these controls, meaning whether they are capable of catching errors at all, and their operating effectiveness, meaning whether they actually worked throughout the period.1Public Company Accounting Oversight Board. Auditing Standard No. 8 – Audit Risk
The broader control environment shapes the assessment too. Management’s integrity, commitment to competence, and how seriously it takes financial reporting all factor in. A history of control failures in prior audit reports immediately elevates the assessed control risk. So does weak accounting personnel: a well-designed control operated by someone who doesn’t understand it is effectively no control at all.
General IT controls deserve special attention. If program change management and system access security are weak, the auditor typically raises control risk for every account processed through that system, because automated controls are only as reliable as the technology underneath them.
How the Two Combine
Inherent risk and control risk combine to produce the risk of material misstatement, or RMM. This represents the likelihood that the financial statements contain a material error before the auditor performs any testing. It is the company’s risk, whether or not an audit happens.
The combination is multiplicative, not additive, and that matters. It means a very low assessment on one factor can offset a higher assessment on the other. An account with high inherent risk from complex estimation, but low control risk because the company has rigorous review processes and automated checks, may land at a moderate RMM. The controls are doing real work to offset the natural complexity. The reverse also holds. A simple, formulaic account with virtually no controls can also produce a moderate RMM, because there just isn’t much to go wrong even without safeguards.
When both inherent risk and control risk are assessed as high, RMM peaks. The account is both naturally prone to misstatement and inadequately protected. Those are the areas that draw the most audit attention.
Where Fraud Fits
Fraud risk touches both sides of the assessment. It raises inherent risk, because management has an incentive to manipulate a subjective estimate, and it raises control risk, because management can override the very controls it designed. AS 2110 requires the engagement team to discuss fraud scenarios and to ask the audit committee, management, and others where fraud risks might exist.2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement Areas that combine high subjectivity with strong management incentives get particular skepticism.
How the Assessment Shapes the Audit
The two risks matter because they determine how much work the auditor has to do. The audit risk model expresses overall audit risk as inherent risk multiplied by control risk multiplied by detection risk. Auditors control only detection risk, which reflects the effectiveness of their own testing. Inherent risk and control risk belong to the company; the auditor assesses them and adjusts detection risk in response.
AS 2301 requires more persuasive evidence as assessed risk increases.4Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement When RMM is high, detection risk has to be driven low, which means larger sample sizes, more detailed transaction vouching, and independent recalculations. When RMM is low, the auditor can accept a higher detection risk and rely more on analytical procedures, such as comparing current-year balances to prior years or industry benchmarks.
One boundary is worth noting. No matter how low the assessed RMM is, the auditor must still perform some substantive procedures for every relevant assertion of every significant account. There is no level of control reliance that eliminates substantive testing entirely.5Public Company Accounting Oversight Board. Auditing Standard No. 13 – The Auditor’s Responses to the Risks of Material Misstatement And if the auditor plans to rely on the company’s controls to reduce control risk below the maximum, those controls have to be tested. If they don’t hold up, the auditor revises the control risk assessment upward and expands substantive testing to compensate.