21/03/2026
Audit Risk ဆိုတာကို ရိုးရိုးရှင်းရှင်းပြောရရင် - ကုမ္ပဏီရဲ့ Financial Statements တွေမှာ ကြီးမားတဲ့မှားယွင်းမှုတွေ (Material Misstatement) ရှိနေလျက်နဲ့ Auditor က ရှာမတွေ့ဘဲ "စာရင်းတွေ မှန်ပါတယ်" ဆိုပြီး မှားယွင်းတဲ့ Audit Opinion (Inappropriate Opinion) ပေးမိဖို့ ဖြစ်နိုင်ခြေ (Possibility) ကို ဆိုလိုတာပါ။
ဒါဟာ Auditor တစ်ယောက်အတွက် အကြီးမားဆုံး အမှားအယွင်းနဲ့ Risk ဖြစ်ပါတယ်။ ဒါကြောင့် Audit လုပ်ငန်းစဉ်တစ်ခုလုံးဟာ ဒီ Risk ကို လက်ခံနိုင်လောက်တဲ့ အနိမ့်ဆုံးအဆင့် (Acceptably Low Level) သို့ လျှော့ချဖို့အတွက်ပဲ ပုံဖော်ထားတာ ဖြစ်ပါတယ်။
🔍 Audit Risk Model ကို နားလည်ခြင်း
Audit Risk ကို ပိုမိုစနစ်တကျ တွက်ချက်စီမံနိုင်ဖို့အတွက် အောက်ပါ Model ကို အသုံးပြုပါတယ်:
🧮 Audit Risk (AR) = Inherent Risk (IR) × Control Risk (CR) × Detection Risk (DR)
ဒီ Model အရ Audit Risk ဟာ အပိုင်း ၃ ပိုင်းကြောင့် ဖြစ်ပေါ်လာတာပါ:
🔺 ၁. Inherent Risk (IR) - သဘာဝအလျောက်ရှိနေသော Risk
Internal Controls တွေကို ထည့်မစဉ်းစားခင်မှာပဲ၊ စာရင်းတစ်ခု သို့မဟုတ် Transaction တစ်ခုရဲ့ သဘာဝအရကိုက Material Misstatement ဖြစ်ဖို့ များနေတဲ့ risk ပါ။ Complex ဖြစ်တဲ့ area တွေ၊ Judgment အများကြီးသုံးရတဲ့ area တွေမှာ IR မြင့်တတ်ပါတယ်။
👉 High IR examples:
Revenue Recognition with complex contracts (ရှုပ်ထွေးသော စာချုပ်များမှ ဝင်ငွေအသိအမှတ်ပြုခြင်း)
Accounting Estimates (ECL provisions, Impairment) - ခန့်မှန်းခြေစာရင်းများ
Foreign Currency transactions
Related Party transactions
🔺 ၂. Control Risk (CR) - ထိန်းချုပ်မှုဆိုင်ရာ Risk
ဒါကတော့ Client ရဲ့ Internal Controls စနစ်က Material Misstatements တွေကို အချိန်မီ တားဆီးဖို့ (Prevent) သို့မဟုတ် ရှာဖွေပြင်ဆင်ဖို့ (Detect & Correct) ပျက်ကွက်မယ့် Risk ပါ။ Client ဘက်မှာ Control အားနည်းရင် CR မြင့်ပါတယ်။
👉 High CR examples:
No Segregation of Duties (တာဝန်ခွဲဝေမှု မရှိခြင်း)
Weak IT access control (Software access ကို စနစ်တကျ မထိန်းချုပ်ခြင်း)
No review of Bank/Receivable Reconciliations (စာရင်းတိုက်ဆိုင်စစ်ဆေးမှုများအား review မလုပ်ခြင်း)
💡 praktically, IR နဲ့ CR ကိုပေါင်းပြီး Risk of Material Misstatement (RMM) လို့ ခေါ်ပါတယ်။ ဒါဟာ Client ဘက်မှာ Audit မတိုင်ခင်ကတည်းက ရှိနေတဲ့ Risk ပါ။ (RMM = IR × CR)
🔺 ၃. Detection Risk (DR) - ရှာဖွေမှုဆိုင်ရာ Risk
ဒါကတော့ Auditor ရဲ့ Procedures တွေက စာရင်းထဲမှာရှိနေတဲ့ Material Misstatement ကို ရှာမတွေ့မိဘဲ လွတ်သွားမယ့် Risk ပါ။ ဒီ Risk တစ်ခုတည်းသာ Auditor က တိုက်ရိုက် လွှမ်းမိုးစီမံနိုင်ပါတယ်။
👉 DR ဖြစ်စေတဲ့ အကြောင်းရင်းများ:
Sample size too small (နမူနာယူမှု နည်းလွန်းခြင်း)
Wrong audit procedure selected (မှားယွင်းသော စစ်ဆေးမှုနည်းလမ်းသုံးခြင်း)
Lack of Professional Skepticism (ဝေဖန်ပိုင်းခြားနိုင်သော သံသယစိတ် အားနည်းခြင်း)
✅ Audit Risk Model ၏ အပြန်အလှန်ဆက်သွယ်မှု (Interrelationship)
Audit Risk Concept ရဲ့ အဓိက သော့ချက်ကတော့ RMM နှင့် Detection Risk (DR) တို့ကြားရှိ ဆန့်ကျင်ဘက်ဆက်ဆံရေး (Inverse Relationship) ပါပဲ။
Auditor က Client ဆီမှာ RMM (IR + CR) မြင့်တယ် လို့ သုံးသပ်ရင် -> Audit Risk ကို လျှော့ချဖို့အတွက် Auditor ဘက်က DR ကို အနိမ့်ဆုံးဖြစ်အောင် လုပ်ရပါမယ်။
DR နိမ့်အောင် ဘယ်လိုလုပ်မလဲ? -> Audit work တွေကို ပိုမိုကျယ်ကျယ်ပြန့်ပြန့် လုပ်ရပါမယ် (More Extensive Substantive Procedures - Increase Sample Size, Use experienced staff, Year-end testing).
ပြန်ချုပ်ရရင်: High IR & CR -> Lower DR needed -> More Audit Work needed.
📊 Financial Statement Level Risk vs Assertion Level Risk
RMM (Risk of Material Misstatement) ကို level ၂ ခုမှာ သုံးသပ်ရပါတယ်-
🅰️ Financial Statement Level Risk:
ဒါဟာ Financial Statements တစ်ခုလုံးကို ခြုံငုံပြီး သက်ရောက်မှုရှိတဲ့ Risk တွေပါ။ (ဥပမာ - Weak management integrity, poor accounting system, Going concern problems).
➡️ Response: Broader response needed, more supervision, experienced team.
🅱️ Assertion Level Risk:
ဒါကတော့ သီးခြား account balance, class of transactions သို့မဟုတ် disclosure တွေနဲ့ သက်ဆိုင်တဲ့ Risk ပါ။ (assertions are Existence, Completeness, Accuracy, Valuation etc.).
👉 For Receivables: Risk of Existence (Debtors are real?) သို့မဟုတ် Risk of Valuation (Recoverable?).
⚠️ Business Risk vs Audit Risk (မရောထွေးပါနဲ့)
Business Risk: ကုမ္ပဏီက သူ့ရဲ့ Objectives တွေ မအောင်မြင်မှာကို စိုးရိမ်ရတဲ့ Risk ပါ (ဥပမာ - Loss of customers, Economic downturn).
Audit Risk: Auditor က Opinion မှားပေးမိမှာကို စိုးရိမ်ရတဲ့ Risk ပါ။
Connection: သို့သော် Business Risk ကြီးမားတဲ့အခါ (ဥပမာ- Cash flow ပြဿနာ) Management က profit ကို manipulation လုပ်ဖို့ ဖိအားရှိလာနိုင်တဲ့အတွက် Audit Risk ကို မြင့်တက်စေပါတယ်။
💡 Conclusion
Auditor တစ်ယောက်အနေနဲ့ Acceptably Low Level of Audit Risk သို့ ရောက်ရှိအောင် စစ်ဆေးဖို့အတွက်- Professional Skepticism ကို အပြည့်အဝ သုံးရမယ်၊ Experienced staff တွေ သုံးရမယ်၊ Supervision & Review ကောင်းရမယ်၊ ပြီးတော့ Significant Estimates နဲ့ Manual Journal Entries တွေလို high-risk area တွေကို Focus လုပ်ပြီး substantive testing ပိုမိုလုပ်ဆောင်ရပါမယ်။
Audit strategy ကောင်းကောင်းဆွဲဖို့အတွက် Audit Risk Model ကို နားလည်ဖို့က မရှိမဖြစ်ပါပဲ။
AI နဲ့ အောက်က English လေးတွေလဲ လေ့လာကြည့်ရအောင် 😊
Audit Risk means the risk that an auditor gives an inappropriate audit opinion when the financial statements are materially misstated.
In simple words:
The auditor says the financial statements are okay, but actually they contain a material error or fraud.
1) Standard meaning of audit risk
Audit risk is the possibility that:
Material misstatement exists
but
the auditor fails to detect it
and issues an unmodified / clean opinion
This is one of the most important concepts in audit because the whole audit approach is built around managing this risk.
---
2) Audit Risk Model
The common audit risk model is:
Audit Risk (AR) = Inherent Risk (IR) × Control Risk (CR) × Detection Risk (DR)
This means audit risk comes from three parts:
A. Inherent Risk (IR)
This is the risk that an account balance, transaction, or disclosure is naturally prone to material misstatement before considering internal controls.
It exists because some areas are more difficult, judgmental, complex, or open to fraud.
Examples:
Revenue recognition with many contracts
Inventory with obsolete or damaged goods
Construction WIP and percentage of completion
Estimates like provision, impairment, ECL
Related party transactions
Foreign currency transactions
Higher inherent risk means the area is naturally riskier.
---
B. Control Risk (CR)
This is the risk that the client’s internal controls fail to prevent or detect and correct material misstatements on time.
Examples:
No segregation of duties
No approval for journal entries
Weak IT access control
No reconciliation of bank or receivable balances
No review of contract cost allocation
Poor control over inventory counting
If internal controls are weak, control risk is high.
---
C. Detection Risk (DR)
This is the risk that the auditor’s procedures will not detect a material misstatement that already exists.
This risk relates to the audit work itself.
Examples:
Sample size too small
Wrong audit procedure selected
Auditor overlooks unusual entries
Poor professional skepticism
Inadequate follow-up on exceptions
Reliance on unreliable evidence
Unlike IR and CR, detection risk can be influenced by the auditor.
---
3) Relationship between the three risks
If IR and CR are high:
Then the auditor must keep detection risk low.
How?
Increase sample size
Perform more substantive testing
Use more experienced staff
Test year-end balances instead of interim only
Obtain stronger external evidence
Perform unpredictable procedures
If IR and CR are low:
The auditor may accept a relatively higher detection risk.
That means:
Less extensive testing may be acceptable
More reliance may be placed on controls
---
4) Why audit risk is important
Audit risk is important because it affects:
Audit planning
Nature, timing, and extent of procedures
Staffing and supervision
Materiality considerations
Areas requiring more professional skepticism
Final audit opinion
Auditors do not eliminate risk completely.
They reduce audit risk to an acceptably low level.
---
5) Components explained with easy example
Take inventory as an example:
Inherent Risk
Inventory may be:
damaged
obsolete
stolen
wrongly valued
wrongly counted
So IR may be high.
Control Risk
If the company:
does not perform stock counts
has weak warehouse control
does not reconcile stock records
allows one person to receive, record, and issue stock
Then CR is high.
Detection Risk
If the auditor:
attends stock count carelessly
takes too few samples
does not test valuation properly
ignores slow-moving items
Then DR is high.
Result:
Overall audit risk becomes high.
---
6) Types of risk in practical audit work
When auditors discuss audit risk in practice, they often focus on:
a) Risk of Material Misstatement (RMM)
This is:
RMM = IR × CR
It means the risk that the financial statements are materially misstated before the audit procedures detect it.
This is assessed at:
Financial statement level
Assertion level
---
b) Detection Risk
This is managed by the auditor through procedures.
So practically:
Audit Risk = Risk of Material Misstatement × Detection Risk
---
7) Financial statement level risk vs assertion level risk
A. Financial Statement Level Risk
These are risks affecting the financial statements as a whole.
Examples:
Weak management integrity
Poor accounting system
Going concern problems
Inexperienced finance team
Weak overall internal control environment
Pressure to meet profit targets
Impact:
Broader audit response needed
More supervision
More unpredictability
More experienced team members
---
B. Assertion Level Risk
These relate to specific account balances, classes of transactions, or disclosures.
Assertions include:
Existence
Completeness
Accuracy
Valuation
Cut-off
Rights and obligations
Presentation and disclosure
Example: For receivables:
Existence: are debtors real?
Valuation: are they recoverable?
Completeness: are all balances recorded?
---
8) Example of audit risk in construction company
Since construction companies are high-risk in audit, this is a good example.
Common risk areas:
Revenue recognition by stage of completion
Contract cost allocation
Variation orders and claims
Accrual for subcontractor cost
Retention receivables
Cut-off of project revenue and cost
WIP valuation
Provision for foreseeable loss contracts
Why risk is high:
Heavy management judgment
Complex contracts
Many supporting documents
Manual estimates
Risk of manipulation to show profit
Audit response:
Review contracts
Test certified progress billings
Recalculate stage of completion
Test cost incurred to source documents
Check cut-off around year-end
Review post year-end settlement
Confirm balances when necessary
Evaluate provision for loss-making projects
---
9) Example of high audit risk indicators
Auditors become more alert when they see:
Unusual journal entries at year-end
Rapid growth in revenue
Weak documentation
Large manual adjustments
Related party transactions
Management override of controls
Poor segregation of duties
Significant estimates
Complex new accounting policies
Prior year misstatements
Fraud allegations
Negative cash flow despite reported profit
These are red flags.
---
10) Difference between business risk and audit risk
Business Risk
Risk that the company fails to achieve its objectives.
Examples:
Loss of customers
Economic downturn
Increased raw material prices
Legal disputes
Liquidity problems
Audit Risk
Risk that the auditor gives the wrong opinion on materially misstated financial statements.
Business risk can increase audit risk, but they are not the same.
Example: If a company has serious cash flow problems, management may manipulate revenue or understate liabilities.
So business risk may lead to higher audit risk.
---
11) How auditor responds to high audit risk
When audit risk is high, auditor may:
Increase professional skepticism
Assign experienced staff
Increase supervision and review
Perform more substantive procedures
Increase sample size
Obtain external confirmations
Use experts
Focus on year-end testing
Perform surprise procedures
Test journal entries and management override
Reassess going concern
Lower performance materiality
---
12) Audit risk and materiality relationship
Audit risk and materiality are closely linked.
If materiality is lower, auditor needs more work
If risk is higher, auditor usually performs more extensive work
High-risk areas often require lower tolerable misstatement
So both affect audit strategy.
---
13) Very simple formula meaning
You can remember like this:
IR = How risky the area is by nature
CR = How weak the client’s controls are
DR = How likely the auditor misses the error
If:
the account is risky,
controls are weak,
and audit testing is poor,
then audit risk becomes very high.
---
14) Easy real-life example
Imagine auditing cash:
Cash is highly susceptible to theft → IR
No independent bank reconciliation → CR
Auditor does not obtain bank confirmation → DR
Then there is a strong chance material misstatement is not detected.
---
15) Final summary
Audit risk is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated.
It has 3 parts:
Inherent Risk = natural susceptibility to misstatement
Control Risk = failure of internal controls
Detection Risk = auditor fails to detect the misstatement
Formula:
AR = IR × CR × DR
Main idea:
High IR + high CR → auditor must reduce DR
Auditor reduces DR by stronger audit procedures
AMH 21 Mar 2026