Mr Audit

Mr Audit Audit, Account, General Knowledge

Audit/Finance နယ်ပယ်မှာ အလုပ်လုပ်နေသူတွေအတွက် အရမ်းအသုံးဝင်မယ့် "Professional ဆန်ဆန် File တွေ နာမည်ပေးနည်းနဲ့ Folder စနစ...
17/04/2026

Audit/Finance နယ်ပယ်မှာ အလုပ်လုပ်နေသူတွေအတွက် အရမ်းအသုံးဝင်မယ့် "Professional ဆန်ဆန် File တွေ နာမည်ပေးနည်းနဲ့ Folder စနစ်တကျထားသိုနည်း"
**🚨 "Final final.xlsx", "Latest update 2.xlsx" လိုမျိုး File နာမည်တွေ ပေးနေတုန်းပဲလား?**
Auditor တွေ၊ Accountant တွေအတွက် အလုပ်လုပ်ရတာ အဆင်ပြေစေမယ့်၊ Review လုပ်တဲ့အခါ ရှာရလွယ်ကူစေမယ့် **"Professional Audit File Naming & Folder Structure"** လမ်းညွှန်ကို မျှဝေပေးချင်ပါတယ်။
Audit လောကမှာ File တွေကို စနစ်တကျ နာမည်ပေးတာဟာ အချိန်ကုန်သက်သာစေရုံသာမကဘဲ အမှားအယွင်းတွေကိုပါ အများကြီး လျှော့ချပေးနိုင်ပါတယ်။
📌 **(၁) မှတ်ထားရမယ့် ရွှေစည်းမျဉ်းများ (Golden Rules)**
🔸 Format တစ်မျိုးတည်းကိုပဲ အသေအချာသုံးပါ။
🔸 ရက်စွဲကို အမြဲတမ်း **YYYY-MM-DD** (ဥပမာ - 2025-12-31) ပုံစံနဲ့ပဲ ရေးပါ။ (ဒီလိုရေးမှ Computer မှာ Date အလိုက် အစီအစဉ်တကျ ပေါ်မှာပါ)
🔸 Space တွေ၊ Special character တွေ (* ? / < >) မသုံးပါနဲ့။ စာလုံးတွေကြားမှာ Underscore (_) သို့မဟုတ် Hyphen (-) ကိုပဲ သုံးပါ။
🔸 "Final", "New File", "Test" စတဲ့ ဝေဝါးတဲ့ နာမည်တွေ မသုံးပါနဲ့။
🔸 Version တွေကို သေချာတပ်ပါ (v01, v02, v03)။
🔸 Status ကို ရှင်းရှင်းလင်းလင်းပြပါ (Draft, ForReview, Final, ClientProvided)။
📌 **(၂) Auditor တွေအတွက် အကောင်းဆုံး File Naming Formula**
ဒီ Formula လေးကို ကိုယ့် Team တစ်ခုလုံး Standard အနေနဲ့ သတ်မှတ်ထားသင့်ပါတယ်-
👉 **[ClientCode]*[FY]*[SectionRef]*[Area]*[Description]*[Date]*[Status]_[v # #]**
💡 **ဥပမာ -**
ABC_2025_C2_COGS_GL_to_ProjectCostBridge_2025-12-31_ForReview_v02.xlsx
ဒီဖိုင်နာမည်လေး တစ်ကြောင်းတည်းကြည့်လိုက်တာနဲ့...
* ဘယ် Client လဲ (ABC)
* ဘယ်နှစ်အတွက်လဲ (2025)
* ဘယ် Audit Section လဲ (C2 - COGS)
* ဖိုင်က ဘာအကြောင်းလဲ (GL to Project Cost Bridge)
* ဘယ်ရက်စွဲနဲ့လဲ (2025-12-31)
* Status က ဘာလဲ (Review လုပ်ဖို့ - ForReview)
* ဘယ်နှစ်ကြိမ်မြောက် ပြင်ထားတာလဲ (Version 2) ဆိုတာ ချက်ချင်းသိနိုင်ပါတယ်။
📌 **(၃) စနစ်ကျတဲ့ Audit Folder Structure ဘယ်လိုဆောက်မလဲ?**
Folder တွေကို နာမည်ပေးတဲ့အခါ ရှေ့မှာ နံပါတ်လေးတွေ တပ်ပေးရင် Review လုပ်တဲ့ အစီအစဉ်အတိုင်း အစဉ်လိုက်လေး ဖြစ်နေပါလိမ့်မယ်။
(ဥပမာ - **2025_ABC_FS_Audit**)
📂 00_Admin
📂 01_EngagementSetup
📂 02_Planning
📂 03_RiskAssessment
📂 04_InternalControl
📂 05_SubstantiveTesting
*(ဒီအထဲမှာမှ A_Cash, B_Receivables, H_Revenue စသဖြင့် ထပ်ခွဲပါ)*
📂 06_FS_Close_and_Disclosure
📂 07_Completion
📂 08_ClientProvided (Client ဆီကရသမျှ အကြမ်းဖိုင်တွေ သိမ်းရန်)
📂 09_Reports_and_Deliverables
📂 10_Archive
📌 **(၄) ရှောင်ကြဉ်ရမယ့် အမှားများ (Common Mistakes)**
❌ **မသုံးသင့်တဲ့ နာမည်များ:**
* Final TB.xlsx
* Latest version.xlsx
* Scan0001.pdf
* Revenue test revised new final.xlsx
✅ **ပြောင်းလဲ အသုံးပြုသင့်တဲ့ နာမည်များ:**
* ABC_2025_PBC_TB_2025-12-31_ClientProvided.xlsx (Client ဆီကရတဲ့ Trial Balance)
* ABC_2025_H1_Revenue_TOC_Test_2025-12-31_v02.xlsx (Working Paper)
* ABC_2025_PBC_SignedContract_Project5005_2025-07-01.pdf (Client Contract)
(*မှတ်ချက် - PBC ဆိုတာ Prepared by Client ကို ဆိုလိုပါတယ်*)
📌 **(၅) လက်တွေ့အသုံးချဖို့ အကြံပြုချက်များ**
1️⃣ **Client ဆီက ဖိုင်ရတာနဲ့ ချက်ချင်း Rename လုပ်ပါ:** "Final TB updated.xlsx" ဆိုပြီး ရလာရင် Folder ထဲမှာ ဒီတိုင်းမသိမ်းပါနဲ့။ Standard နာမည် ချက်ချင်းပြောင်းပြီး 08_ClientProvided ထဲကို ထည့်ပါ။
2️⃣ **Duplicate ဖိုင်တွေ မထားပါနဲ့:** Working Paper တစ်ခုအတွက် ဖိုင်တစ်ခုပဲ ရှိရပါမယ်။ Desktop မှာတစ်ခု၊ Download မှာတစ်ခု၊ Shared Folder မှာတစ်ခု ဖြစ်မနေပါစေနဲ့။
3️⃣ **Draft နဲ့ Final ကို သေချာခွဲပါ:** မလိုအပ်တော့တဲ့ အဟောင်းတွေကို _Superseded သို့မဟုတ် Archive Folder ထဲ ရွှေ့ထားပါ။
ဒီနည်းလမ်းလေးတွေကို ကိုယ့်ရဲ့ လုပ်ငန်းခွင်မှာ စတင်အသုံးပြုကြည့်ရင် အလုပ်လုပ်ရတာ ပိုမိုမြန်ဆန်သွက်လက်ပြီး၊ အထက်လူကြီး ဒါမှမဟုတ် Manager တွေ Review လုပ်တဲ့အခါမှာလည်း Professional အရမ်းဆန်တဲ့အတွက် အထူးသဘောကျစေမှာ အမှန်ပါပဲ။ 💯

မြန်မာနှစ်ဆန်း ၁ ရက်နေ့မှာ အားလုံးပဲ အစစအရာရာ အဆင်ပြေကြပါစေ

📘 AI အသုံးပြုထားသော အလိုအလျောက် နမူနာရွေးချယ်ခြင်း မူဘောင် (AI-Driven Auto Sampling Framework)ရည်ရွယ်ချက် (Objective): A...
02/04/2026

📘 AI အသုံးပြုထားသော အလိုအလျောက် နမူနာရွေးချယ်ခြင်း မူဘောင် (AI-Driven Auto Sampling Framework)
ရည်ရွယ်ချက် (Objective): Audit စစ်ဆေးမှု လွှမ်းခြုံနိုင်စွမ်း (Coverage)၊ ထိရောက်မှု (Efficiency) နှင့် ယုံကြည်ရမှု (Assurance) တို့ကို တိုးတက်စေရန်အတွက် အရည်အသွေးမြင့်မားပြီး အန္တရာယ် (Risk) ပေါ်အခြေခံသော Audit Sample များကို AI နှင့် Data Analytics အသုံးပြု၍ ရွေးချယ်ရန်။
🧠 ၁။ ဘာကြောင့် AI Sampling ကို သုံးသင့်တာလဲ (Traditional vs. AI Sampling)
ရိုးရာစနစ်နဲ့ AI စနစ်ရဲ့ အဓိကကွာခြားချက်ကတော့ "အမြင်ကျယ်မှု" ပါပဲ။
* ရိုးရာစနစ် (Traditional): လူရဲ့ ဆုံးဖြတ်ချက် ဒါမှမဟုတ် ကျပန်း (Random) ရွေးချယ်တဲ့အတွက် Sample အရေအတွက် အကန့်အသတ်ရှိပြီး၊ ပုန်းကွယ်နေတဲ့ အမှားတွေ/လိမ်လည်မှုတွေကို လွတ်သွားနိုင်ပါတယ်။
* AI စနစ်: ဒေတာတစ်ခုလုံး (Full Population) ကို Scan ဖတ်ပြီး ပုံမှန်မဟုတ်တဲ့ Pattern တွေကို ထောက်လှမ်းပေးပါတယ်။
👉 ကောက်ချက်: AI ဟာ ရိုးရှင်းတဲ့ Sample ကောက်ခြင်းသက်သက်မဟုတ်ဘဲ၊ စာရင်းတစ်ခုလုံးကို ခွဲခြမ်းစိတ်ဖြာပြီးမှ တကယ့်ပြဿနာရှိနိုင်တဲ့ နေရာတွေကို ပစ်မှတ်ထား ရွေးချယ်ပေးတာ ဖြစ်ပါတယ်။
🔍 ၂။ AI Sampling ၏ အဓိက အလုပ်လုပ်ပုံ (Core AI Sampling Logic)
AI ဟာ Transaction (အရောင်းအဝယ်မှတ်တမ်း) တစ်ခုချင်းစီကို Risk Score (အန္တရာယ်ရှိနိုင်ခြေ အမှတ်) သတ်မှတ်ပေးပါတယ်။
📊 Risk အမှတ်ပေးမည့် အချက်များ (Scoring Factors):
* ငွေပမာဏ ကြီးမားလွန်းခြင်း (Large value)
* ဘဏ္ဍာရေးနှစ်ကုန်ရက်တွင် ရေးသွင်းခြင်း (Year-end posting)
* လူကိုယ်တိုင် ရိုက်သွင်းသော စာရင်းများ (Manual journal)
* သံသယဖြစ်ဖွယ် အကြောင်းအရာများ (ဥပမာ - “Adjustment”, “Reclass”)
* အန္တရာယ်ရှိသော Vendor သို့မဟုတ် ဆက်စပ်ပတ်သက်သူများ (Related party)
* အနှုတ်ပြနေသော သို့မဟုတ် ပြန်ပြောင်းထားသော စာရင်းများ (Negative/Reversal)
* မကြာခဏ ထပ်ခါထပ်ခါ ဖြစ်နေမှုများ (Frequency anomalies)
📌 Risk Score တွက်ချက်နည်း ဥပမာ:
အချက်တစ်ခုချင်းစီကို အလေးချိန် (Weight/Score) ပေးထားပြီး ပေါင်းထည့်တဲ့စနစ်ပါ။ (ဥပမာ - Manual Entry ဆိုရင် ၂၅ မှတ်၊ Related Party ဆို ၃၀ မှတ် စသဖြင့်)။
👉 ရလဒ်ခွဲခြားခြင်း:
* 🔴 High Risk (အန္တရာယ်များ): မဖြစ်မနေ စစ်ဆေးရမည့် စာရင်း (Must test)
* 🟠 Medium Risk (အလယ်အလတ်): Sample ကောက်၍ စစ်ဆေးရန်
* 🟢 Low Risk (အန္တရာယ်နည်း): အနည်းငယ်သာ စစ်ဆေးရန် သို့မဟုတ် Analytical လုပ်ရန်
🔄 ၃။ Walkthrough Test အတွက် AI Sampling အသုံးပြုခြင်း
🎯 ရည်ရွယ်ချက်: လုပ်ငန်းစဉ် စီးဆင်းမှုနှင့် ထိန်းချုပ်မှု (Control) အဆင့်များကို နားလည်ရန်။
🤖 AI ချဉ်းကပ်ပုံ: လုပ်ငန်းစဉ် အမျိုးအစားတစ်ခုလျှင် Transaction ၁ ခု သို့မဟုတ် ၂ ခုကို ရွေးချယ်ပေးပါမည်။ (ဥပမာ - ဝယ်ယူခြင်းမှ COGS သို့၊ WIP မှ COGS သို့ ပြောင်းလဲခြင်း)။
အစမှအဆုံး လွှမ်းခြုံမှုရှိရမည့်အပြင် ပုံမှန်အခြေအနေနှင့် ချွင်းချက်အခြေအနေ (Normal & Exception) နှစ်မျိုးလုံး ပါဝင်ရပါမည်။
📌 ရွေးချယ်မှု စံနှုန်းများ:
* ပုံမှန် Transaction တစ်ခု (ဥပမာ - ပုံမှန် ကုန်ကြမ်းအမြောက်အမြား ဝယ်ယူခြင်း)
* Risk များသော Transaction တစ်ခု
* Exception တစ်ခု (ဥပမာ - စာရွက်စာတမ်း မပြည့်စုံသော ကိစ္စ)
🛡️ ၄။ TOC (Test of Controls) အတွက် AI Sampling အသုံးပြုခြင်း
🎯 ရည်ရွယ်ချက်: ချမှတ်ထားသော Controls များ ထိရောက်စွာ အလုပ်လုပ်ခြင်း ရှိ/မရှိ စစ်ဆေးရန်။
🤖 AI အလုပ်လုပ်ပုံအဆင့်ဆင့်:
* Population Segmentation: လအလိုက်၊ ပရောဂျက်အလိုက် သို့မဟုတ် Control အမျိုးအစားအလိုက် အုပ်စုခွဲခြင်း။
* AI Selection: ကျပန်းရွေးချယ်မှု (Random) နှင့် အန္တရာယ်အပေါ်အခြေခံသော ရွေးချယ်မှု (Risk-based) ကို ပေါင်းစပ်ခြင်း။
📊 Sample အရေအတွက် သတ်မှတ်ချက် (Guidelines):
| Control အကြိမ်အရေအတွက် | AI ရွေးချယ်မည့် Sample အရေအတွက်
>>နေ့စဉ် (Daily) | ၂၅ - ၄၀ ခု
>>လစဉ် (Monthly) | ၃ - ၆ ခု
>>နှစ်စဉ် (Annual) | ၁ - ၂ ခု
🔍 ဥပမာ (COGS ခွင့်ပြုချက် Control စစ်ဆေးခြင်း):
AI သည် တန်ဖိုးကြီး Transaction ၁၀ ခု၊ Random ၁၀ ခု နှင့် ပုံမှန်မဟုတ်သော ၅ ခု ကို ရွေးချယ်ပေးမည် ဖြစ်သည်။
📑 ၅။ TOD (Test of Details) အတွက် AI Sampling အသုံးပြုခြင်း
🎯 ရည်ရွယ်ချက်: လက်ကျန်ငွေများနှင့် အရောင်းအဝယ်မှတ်တမ်းများ မှန်ကန်ကြောင်း အသေးစိတ် အထောက်အထား စစ်ဆေးရန် (Substantive testing)။
🤖 AI ချဉ်းကပ်ပုံ မဟာဗျူဟာ:
* Full Population Analysis: GL သို့မဟုတ် ပရောဂျက် ဒေတာတစ်ခုလုံးကို Scan ဖတ်ခြင်း။
* Stratification (အလွှာခွဲခြားခြင်း):
(1) အဆင့် (Tier)
(2) သတ်မှတ်ချက်(Criteria)
(3)လုပ်ဆောင်ချက် (Action)
| Tier 1 | တန်ဖိုးအကြီးဆုံး စာရင်းများ (ဥပမာ - အကြီးဆုံး Top 10) | ၁၀၀% အားလုံးကို စစ်ဆေးမည် |
| Tier 2 | Medium Risk ရှိသော စာရင်းများ | AI ဖြင့် Sample ရွေးချယ်စစ်ဆေးမည် |
| Tier 3 | Low Risk ရှိသော စာရင်းများ | Analytical Review (ခြုံငုံသုံးသပ်ခြင်း) သာ လုပ်မည် |
📌 အထူးဂရုပြုရမည့် အချက်များ: နှစ်ကုန်ပိုင်းသွင်းသော စာရင်းများ၊ Manual ဝင်ထားသော Journal များ၊ Related parties များနှင့် Reclassifications (စာရင်းပြောင်းလဲမှုများ) ကို အဓိကထား စစ်ဆေးရပါမည်။
⚙️ ၆။ AI Sampling လုပ်ငန်းစဉ် အဆင့်ဆင့် (End-to-End Workflow)
* Import: GL သို့မဟုတ် Project Data များကို System ထဲသို့ ထည့်သွင်းခြင်း။
* Calculate: AI မှ Risk Score များကို တွက်ချက်ပေးခြင်း။
* Classify: Transaction များကို High / Medium / Low အဖြစ် ခွဲခြားပေးခြင်း။
* Generate: Walkthrough, TOC, TOD တို့အတွက် လိုအပ်သော Sample စာရင်းများကို အလိုအလျောက် ထုတ်ပေးခြင်း။
* Export: Audit လုပ်မည့် Working Paper (Excel) သို့ ပြောင်းလဲထုတ်ယူခြင်း။
📊 ၇။ Excel + AI လက်တွေ့ အကောင်အထည်ဖော်ခြင်း (Practical Setup)
Excel တွင် အောက်ပါအတိုင်း Sheet များ ခွဲခြားတည်ဆောက်နိုင်ပါသည်။
* Sheet 1: Raw Data - GL, Vendor, Amount, Date, Description စသည့် အကြမ်းထည် ဒေတာများ။
* Sheet 2: Risk Scoring - AI (သို့) Formula များသုံး၍ Risk တွက်ချက်ခြင်း။
(ဥပမာ - =IF(Amount>Threshold,20,0) + IF(Round=TRUE,20,0) + IF(YearEnd=TRUE,15,0))
* Sheet 3: Sampling Output - Filter များသုံး၍ High risk ကို ထည့်သွင်းပြီး၊ Medium ကို Random ရွေးကာ၊ Low ကို ဖယ်ထုတ်ထားသော ရလဒ် Sheet။
🔐 ၈။ Audit ထိန်းချုပ်မှုဆိုင်ရာ သတိပြုရန်များ (Control & Audit Consideration)
* AI မော်ဒယ်၏ အလုပ်လုပ်ပုံ (Logic) ကို စာရွက်စာတမ်းဖြင့် သေချာ မှတ်တမ်းတင်ထားရန်။
* AI ၏ ရလဒ်များကို Auditor မှ ပြန်လည်သုံးသပ်ရန်နှင့် လိုအပ်ပါက မိမိ၏ Professional Judgment ဖြင့် ပြင်ဆင်နိုင်ခွင့် (Override) ရှိရန်။
* မည်သို့ ရွေးချယ်ခဲ့သည်ဆိုသော မှတ်တမ်း (Audit Trail) ကို သိမ်းဆည်းထားရန်။
⚠️ ၉။ AI Sampling ၏ အားနည်းချက်များနှင့် ဖြေရှင်းနည်း (Risks & Mitigation)
AI အပေါ် အလွန်အမင်း မှီခိုလွန်းခြင်း၊ Risk တွက်ချက်သည့် လော့ဂျစ် မှားယွင်းခြင်း၊ ဒေတာတွင် Bias ပါဝင်နေခြင်းနှင့် AI က မသိနိုင်သော (Qualitative) အချက်အလက်များ လွတ်သွားနိုင်ခြင်း စသည့် အန္တရာယ်များ ရှိပါသည်။
👉 ဖြေရှင်းနည်း: AI ၏ စွမ်းဆောင်ရည်နှင့် Auditor ၏ ဝေဖန်ပိုင်းခြားနိုင်စွမ်း (Judgment) ကို ပေါင်းစပ်အသုံးပြုရန်နှင့် AI Model ကို အခါအားလျော်စွာ ပြန်လည်စစ်ဆေး အကဲဖြတ်ရန် လိုအပ်ပါသည်။
📌 ၁၀။ နောက်ဆုံး ကောက်ချက် (Final Audit Conclusion)
> "AI ကို အခြေခံသော Sampling စနစ်သည် စာရင်းတစ်ခုလုံးကို ပိုင်းခြားစိတ်ဖြာနိုင်စွမ်းနှင့် Risk ပေါ်အခြေခံသော ရွေးချယ်မှုတို့ကို ပေါင်းစပ်ထားသောကြောင့် Audit ၏ ထိရောက်မှုကို များစွာ မြှင့်တင်ပေးပါသည်။ စနစ်တကျ ထိန်းချုပ်ပြီး သေချာစွာ သုံးသပ်နိုင်မည်ဆိုပါက၊ Audit လွှမ်းခြုံနိုင်မှု (Coverage) ကို သိသာစွာ တိုးတက်စေပြီး၊ ပုံမှန်မဟုတ်သော အမှားအယွင်းများကို ပိုမိုဖော်ထုတ်နိုင်ကာ Audit လုပ်ငန်းစဉ်တစ်ခုလုံးကို ပိုမိုသွက်လက် အားကောင်းစေမည် ဖြစ်ပါသည်။

AMH
3 Apr 2026

စာရွက်ရှားပါးလာမှုနှင့် ပြောင်းလဲလာမယ့် အနာဂတ် Finance လောက နဲ့ Audit Evidence Risk အတွက် AI နဲ့ ဘာတွေ လုပ်သွားနိုင်မလဲ ...
01/04/2026

စာရွက်ရှားပါးလာမှုနှင့် ပြောင်းလဲလာမယ့် အနာဂတ် Finance လောက နဲ့ Audit Evidence Risk အတွက် AI နဲ့ ဘာတွေ လုပ်သွားနိုင်မလဲ လေ့လာကြည့်ရအောင်
Edit : (IA = Internal Auditor , EA = External Auditor
AI = Artificial Intelligence ဉာဏ်ရည်တုနည်းပညာ အတိုခေါက်ရောမှာစိုးလို့ ။ အထူးသဖြင့် IA vs AI)

စာရွက်ရှားပါးမှုကြောင့် Finance ဌာနက Paperless (စာရွက်မဲ့) ကျင့်သုံးလာတာဟာ Internal Audit (IA) ဌာနအတွက် လုပ်ထုံးလုပ်နည်းဟောင်းတွေကို စွန့်လွှတ်ပြီး ခေတ်မီတဲ့ ဒစ်ဂျစ်တယ်စစ်ဆေးရေးစနစ်သို့ ကူးပြောင်းဖို့ တွန်းအားတစ်ခုဖြစ်ပါတယ်။
ဒီအပြောင်းအလဲရဲ့ အကျိုးဆက်တွေ၊ ကြိုတင်ပြင်ဆင်ရမယ့်အချက်တွေနဲ့ AI ကို အသုံးပြုပြီး စစ်ဆေးရမယ့် နည်းလမ်းတွေကို အသေးစိတ် ရှင်းပြပေးပါမယ်။
အပိုင်း (၁) Finance ဌာန Paperless ကျင့်သုံးခြင်းရဲ့ အကျိုးဆက်များ (Impact)
Finance ဌာနက ဒစ်ဂျစ်တယ်စနစ်သို့ ပြောင်းလဲလိုက်တဲ့အခါ IA အနေနဲ့ အောက်ပါကောင်းကျိုးနဲ့ ဆိုးကျိုး (Risks) တွေကို ရင်ဆိုင်ရပါလိမ့်မယ်။
ကောင်းကျိုးများ:
ပိုမိုမြန်ဆန်သော သတင်းအချက်အလက်ရယူမှု: စာရွက်စာတမ်းတွဲတွေကို လိုက်ရှာစရာမလိုဘဲ ကွန်ပျူတာထဲမှာတင် လိုအပ်တဲ့ Voucher, Invoice တွေကို စက္ကန့်ပိုင်းအတွင်း ရှာဖွေနိုင်ပါတယ်။
အချိန်နှင့်တစ်ပြေးညီ စစ်ဆေးနိုင်ခြင်း (Real-time Auditing): Transactions တွေ ဖြစ်ပျက်နေစဉ်မှာတင် ချက်ချင်း ဝင်ရောက်ကြည့်ရှု စစ်ဆေးနိုင်ပါတယ်။
ဒေတာတိကျမှု ပိုမိုကောင်းမွန်ခြင်း: လူက ရိုက်ထည့်ရတဲ့ (Manual Entry) နေရာမှာ စနစ်အချင်းချင်း ချိတ်ဆက်မှု (ဥပမာ - Bank API နှင့် ERP) တွေကြောင့် မှားယွင်းမှု နည်းပါးသွားပါတယ်။
ကုန်ကျစရိတ် သက်သာခြင်း: စာရွက်၊ မှင်၊ ပုံနှိပ်စရိတ်နဲ့ စာရွက်စာတမ်း သိုလှောင်ရတဲ့ ဂိုဒေါင်ခတွေ သက်သာသွားပါတယ်။
စိန်ခေါ်မှုနှင့် ရင်ဆိုင်ရမယ့် Risks များ:
Cybersecurity Risk: ဒစ်ဂျစ်တယ် စာရွက်စာတမ်းတွေဟာ ဟက်ကာ (Hacker) တွေရဲ့ အန္တရာယ် သို့မဟုတ် ဗိုင်းရပ်စ်ကြောင့် ပျက်စီးဆုံးရှုံးနိုင်ခြေ ရှိပါတယ်။
Internal Control အသစ်များ လိုအပ်ခြင်း: စာရွက်ပေါ်မှာ လက်မှတ်ထိုးတဲ့စနစ် (Physical Signature) အစား ဒစ်ဂျစ်တယ်လက်မှတ် (Digital Signature) သို့မဟုတ် စနစ်အတွင်း ခွင့်ပြုချက် (System Approval Flow) တွေကို မှန်ကန်စွာ သတ်မှတ်ထားဖို့ လိုအပ်ပါတယ်။
IT စနစ်အပေါ် မှီခိုမှု: ERP စနစ် သို့မဟုတ် Server ပျက်စီးသွားပါက စစ်ဆေးရေးလုပ်ငန်းစဉ်လုံးဝ ရပ်ဆိုင်းသွားနိုင်ပါတယ်။
Data Privacy: အထိခိုက်မခံတဲ့ ဘဏ္ဍာရေးဒေတာတွေကို ဝန်ထမ်းတိုင်း မမြင်အောင် Access Control တွေ တင်းကျပ်ဖို့ လိုပါတယ်။
အပိုင်း (၂) Internal Audit များ အနေနဲ့ ဘာတွေ ကြိုပြင်ဆင်ထားရမလဲ
ဒစ်ဂျစ်တယ် ပတ်ဝန်းကျင်မှာ ထိရောက်စွာ စစ်ဆေးနိုင်ဖို့ IA အဖွဲ့ဟာ အောက်ပါအတိုင်း ပြင်ဆင်ရပါမယ်။
၁။ ကျွမ်းကျင်မှု မြှင့်တင်ခြင်း (Skill Upgrading):
Data Analytics ကျွမ်းကျင်မှု: Excel အဆင့်မြင့်သုံးနိုင်ရုံတင်မကဘဲ SQL, Power BI, Tableau, သို့မဟုတ် Python လိုမျိုး ဒေတာခွဲခြမ်းစိတ်ဖြာတဲ့ Tool တွေကို အခြေခံအဆင့်ကနေ အလယ်အလတ်အဆင့်အထိ တတ်မြောက်ထားရပါမယ်။
IT General Controls (ITGC) ကို နားလည်ခြင်း: စနစ်တစ်ခုရဲ့ လုံခြုံရေး၊ Access Control၊ Change Management တွေကို ဘယ်လိုစစ်ဆေးရမလဲဆိုတာ သိထားရပါမယ်။
၂။ စစ်ဆေးရေး နည်းလမ်းများ ပြောင်းလဲခြင်း (Methodology Change):
Remote Auditing စွမ်းရည်: Clients သို့မဟုတ် ဆိုင်ခွဲတွေကို ကိုယ်တိုင်သွားစရာမလိုဘဲ VPN သို့မဟုတ် Cloud-based platform တွေကနေ စစ်ဆေးနိုင်တဲ့ လုပ်ငန်းစဉ်တွေ ချမှတ်ရပါမယ်။
Sampling အစား 100% Population Testing: စာရွက်နဲ့စစ်တုန်းက အစောင် ၁၀၀ မှာ ၁၀ စောင်ပဲ စစ်နိုင်ပေမယ့်၊ ဒစ်ဂျစ်တယ်ဖြစ်သွားတဲ့အတွက် Transactions အားလုံး (100%) ကို Software သုံးပြီး စစ်ဆေးဖို့ ပြင်ဆင်ရပါမယ်။
၃။ Policy နှင့် Infrastructure ပြင်ဆင်ခြင်း:
ဒစ်ဂျစ်တယ် စာရွက်စာတမ်း သိမ်းဆည်းမှု Policy: Finance ဌာနက Scan ဖတ်ထားတဲ့ PDF တွေကို ဘယ်လို Indexing (စနစ်တကျ အမည်ပေးသိမ်းဆည်း) လုပ်ရမလဲ၊ ဘယ်နှစ်နှစ်သိမ်းရမလဲဆိုတာ တိကျတဲ့ Policy ရှိမရှိ စစ်ဆေးပြီး IA အတွက်လည်း Read-only Access ရယူထားရပါမယ်။
SecurePBC စနစ်: Client ဆီကနေ စစ်ဆေးခံမယ့် စာရွက်စာတမ်းတွေကို Email နဲ့ တောင်းမယ့်အစား Secure File Transfer Protocol (SFTP) သို့မဟုတ် GRC platform တွေ သုံးပြီး စနစ်တကျ တောင်းခံရပါမယ်။
အပိုင်း (၃) AI နဲ့ ဒါတွေ ဘယ်လို စစ်ဆေးသင့်လဲ (AI-based Auditing)
AI ဟာ ဒစ်ဂျစ်တယ်စာရွက်စာတမ်းတွေကို လူထက် အဆပေါင်းများစွာ မြန်ဆန်ပြီး တိကျစွာ စစ်ဆေးနိုင်ပါတယ်။
၁။ Anomaly Detection (ပုံမှန်မဟုတ်မှုများကို ရှာဖွေခြင်း) - Machine Learning အသုံးပြုခြင်း:
AI Algorithm တွေကို လွန်ခဲ့တဲ့ ၂ နှစ်၊ ၃ နှစ်က ဘဏ္ဍာရေးဒေတာတွေနဲ့ Train လုပ်ထားပြီး၊ ယခုနှစ်အတွင်း ဖြစ်ပျက်နေတဲ့ Transactions တွေကို နေ့စဉ် စောင့်ကြည့်စေရပါမယ်။
စစ်ဆေးနည်း: AI က Normal Pattern ထဲမှာ မပါတဲ့ ပုံမှန်မဟုတ်တဲ့ ငွေပမာဏ၊ မူမမှန်တဲ့ အချိန် (ဥပမာ - ရုံးပိတ်ရက် ညသန်းခေါင်)၊ သို့မဟုတ် မကြာခဏ အကောင့်တစ်ခုအလီလီ ငွေလွှဲမှုတွေကို လူကို Flag (သတိပေးချက်) ပြပါလိမ့်မယ်။ IA က အဲဒီ Flag ပြတဲ့အချက်တွေကိုပဲ အသေးစိတ်စစ်ဆေးရပါမယ်။
၂။ Travel & Entertainment (T&E) Expenses စစ်ဆေးခြင်း - Computer Vision & NLP:
ဝန်ထမ်းတွေ တင်ပြတဲ့ ဓာတ်ပုံရိုက်ထားတဲ့ Receipt (ပြေစာ) အတုတွေကို AI သုံးပြီး စစ်ဆေးနိုင်ပါတယ်။
စစ်ဆေးနည်း: AI က ပြေစာပေါ်က စာသားတွေကို ဖတ်တယ် (OCR)၊ ပြီးတော့ လက်ရှိစနစ်ထဲက ဒေတာနဲ့ တိုက်ဆိုင်စစ်ဆေးတယ်။ AI က တူညီတဲ့ Receipt ဓာတ်ပုံကိုပဲ နှစ်ခါသုံးထားတာ (Duplicate Claim)၊ Receipt ပေါ်က နေ့စွဲကို ပြင်ထားတာ၊ သို့မဟုတ် Travel Expense Voucher မှာ ကိုယ့်လုပ်ငန်းက ခွင့်မပြုတဲ့ အသုံးစရိတ်တွေကို (Unusual)တင်ပြထားတာတွေကို စက္ကန့်ပိုင်းအတွင်း ရှာဖွေပေးနိုင်ပါတယ်။
၃။ Contract (စာချုပ်) များ စစ်ဆေးခြင်း - Natural Language Processing (NLP):
ထောင်ပေါင်းများစွာသော ဒစ်ဂျစ်တယ်စာချုပ် (PDF) တွေကို AI ကို ဖတ်ခိုင်းနိုင်ပါတယ်။
စစ်ဆေးနည်း: AI ကို "ပေးချေမှုရက်စွဲသည် ရက်ပေါင်း ၆၀ ကျော်ပါက သတင်းပို့ပါ" သို့မဟုတ် "ကန့်သတ်ချက်ထက်ကျော်လွန်သော လျှော့စျေးများပါက Flag ပြပါ" လို့ ညွှန်ကြားထားနိုင်ပါတယ်။ AI က စာချုပ်အားလုံးကို ဖတ်ပြီး high-risk ဖြစ်တဲ့ စာချုပ်တွေကို ခွဲထုတ်ပေးပါလိမ့်မယ်။
၄။ စာရင်းဝင်ပေါက်များ စစ်ဆေးခြင်း (Journal Entry Testing) - Predictive Analytics:
Generative AI (ဥပမာ - ChatGPT သို့မဟုတ် Big 4 တွေရဲ့ ကိုယ်ပိုင် AI Tools) တွေကို သုံးပြီး General Ledger (GL) ထဲက ဒေတာတွေကို ခွဲခြမ်းစိတ်ဖြာခိုင်းနိုင်ပါတယ်။
စစ်ဆေးနည်း: "လွန်ခဲ့တဲ့ ၃ လအတွင်း အခွန်နဲ့ပတ်သက်ပြီး manual ဝင်ထားတဲ့၊ error frequent ဖြစ်တဲ့ user တွေ ဝင်ထားတဲ့ Journal entries တွေကို Summary လုပ်ပေးပါ" လို့ AI ကို မေးခွန်းထုတ်ပြီး ချက်ချင်း အဖြေရယူနိုင်ပါတယ်။

နောက်မှ ဆက်လေ့လာကြအုံးစို့

AMH
2 Apr 2026

AI ကို သုံးပြီး Internal Audit ဌာနာကို ဘယ်လို အကျိုးပြုအောင်လုပ်မလဲ ?Internal Audit (IA) ရဲ့ အဓိက ရည်ရွယ်ချက်က လုပ်ငန်းရ...
21/03/2026

AI ကို သုံးပြီး Internal Audit ဌာနာကို ဘယ်လို အကျိုးပြုအောင်လုပ်မလဲ ?

Internal Audit (IA) ရဲ့ အဓိက ရည်ရွယ်ချက်က လုပ်ငန်းရဲ့ Risk Management, Internal Controls နဲ့ Governance ဖြစ်စဉ်တွေကို အကဲဖြတ်ပြီး တိုးတက်အောင် အကြံဉာဏ်ပေးဖို့ ဖြစ်ပါတယ်။ AI နည်းပညာကို အသုံးချလိုက်တဲ့အခါ Internal Audit ဟာ "အတိတ်ကဖြစ်ခဲ့တာကို နောက်ကြောင်းပြန်စစ်ဆေးတဲ့ (Reactive)" ပုံစံကနေ "အနာဂတ်မှာ ဖြစ်လာနိုင်တာကို ကြိုတင်ခန့်မှန်းကာကွယ်တဲ့ (Proactive)" ပုံစံကို အသွင်ကူးပြောင်းသွားပါတယ်။
AI ကို အသုံးပြုပြီး Internal Audit ကို ဘယ်လို အကျိုးပြုစေသလဲဆိုတာနဲ့ Internal Controls တွေကို ဘယ်လို ခိုင်မာအောင် တည်ဆောက်မလဲဆိုတာကို အသေးစိတ် ရှင်းပြပေးပါမယ်။
၁။ AI ဖြင့် Internal Audit ကို အကျိုးပြုစေခြင်း (Benefits of AI in Internal Audit)
AI ဟာ Auditor တွေရဲ့ နေ့စဉ်လုပ်ငန်းဆောင်တာတွေကို ပိုမိုမြန်ဆန်၊ တိကျပြီး ကျယ်ကျယ်ပြန့်ပြန့် လုပ်ဆောင်နိုင်အောင် ကူညီပေးပါတယ်။
* စဉ်ဆက်မပြတ် စစ်ဆေးခြင်း (Continuous Auditing): အရင်ကလို ၆ လတစ်ခါ၊ တစ်နှစ်တစ်ခါမှ Sample ဆွဲပြီး စစ်ဆေးတာမျိုး မဟုတ်တော့ဘဲ AI က Financial Data တွေကို Real-time စောင့်ကြည့်နေပါတယ်။ ဒါကြောင့် အမှားအယွင်း (Error) သို့မဟုတ် လိမ်လည်မှု (Fraud) တစ်ခု ဖြစ်ပေါ်တာနဲ့ ချက်ချင်း သိရှိနိုင်ပါတယ်။
* ၁၀၀ ရာခိုင်နှုန်း စစ်ဆေးနိုင်ခြင်း (Full Population Testing):
AI ကို အသုံးပြုခြင်းဖြင့် Sampling Risk ကို ဖယ်ရှားနိုင်ပါတယ်။ Transaction သန်းပေါင်းများစွာကို စက္ကန့်ပိုင်းအတွင်း ၁၀၀% အကုန်အစင် စစ်ဆေးပေးနိုင်ပါတယ်။
* စာချုပ်စာတမ်းများကို ခွဲခြမ်းစိတ်ဖြာခြင်း (Natural Language Processing - NLP):
NLP နည်းပညာကို သုံးပြီး စာမျက်နှာ ရာချီရှိတဲ့ ရှုပ်ထွေးသော စာချုပ်များ (Contracts)၊ Board Meeting Minutes တွေထဲကနေ Audit အတွက် အရေးကြီးတဲ့ အချက်အလက်တွေ (ဥပမာ - Compliance လိုက်နာရမယ့် အချက်များ၊ Covenants များ) ကို အလိုအလျောက် ဖတ်ရှုပြီး ဆွဲထုတ်ပေးနိုင်ပါတယ်။
* ကြိုတင်ခန့်မှန်းနိုင်သော စွမ်းရည် (Predictive Risk Analytics):
အတိတ်က ဖြစ်ခဲ့တဲ့ Data တွေ၊ စီးပွားရေး အခြေအနေတွေနဲ့ Industry trends တွေကို ပေါင်းစပ်ပြီး ဘယ် Department သို့မဟုတ် ဘယ် Branch မှာတော့ Control Failure ဖြစ်နိုင်ခြေ အများဆုံးလဲဆိုတာကို AI က ကြိုတင် သတိပေး (Red Flag) နိုင်ပါတယ်။
၂။ AI ကို အသုံးပြု၍ Internal Controls များ တည်ဆောက်ခြင်း
Internal Controls စနစ်ကို ပိုမိုခိုင်မာစေဖို့ AI ကို Preventive, Detective နဲ့ Corrective ဆိုတဲ့ အဆင့် ၃ ဆင့်လုံးမှာ ပေါင်းစပ် တည်ဆောက်နိုင်ပါတယ်။
(က) ကြိုတင်တားဆီးသော ထိန်းချုပ်မှုများ (Preventive Controls)
ပြဿနာ မဖြစ်ခင်ကတည်းက ကြိုတင်တားဆီးပေးတဲ့ Controls တွေဖြစ်ပါတယ်။
* Smart Authorization (စမတ် ခွင့်ပြုချက်စနစ်): AI က Purchasing limits၊ Vendor history နဲ့ Market price တွေကို ချက်ချင်း တိုက်ဆိုင်စစ်ဆေးပါတယ်။ ဥပမာ - Duplicate Invoice (ငွေတောင်းခံလွှာ အထပ်) တက်လာရင်ဖြစ်စေ၊ ပုံမှန်မဟုတ်တဲ့ ဈေးနှုန်းနဲ့ တောင်းခံလာရင်ဖြစ်စေ Payment မထွက်ခင် AI က အလိုအလျောက် Block လုပ်ပစ်တာမျိုး ဖြစ်ပါတယ်။
* Behavioral Access Control: System ထဲကို ဝင်ရောက်တဲ့ User ရဲ့ အပြုအမူကို AI က လေ့လာထားပါတယ်။ ပုံမှန် ရန်ကုန်ကနေ ရုံးချိန်အတွင်း ဝင်နေကျ User Account က ညသန်းခေါင်ယံမှာ နိုင်ငံခြားကနေ ဝင်ရောက်ဖို့ ကြိုးစားလာရင် AI က ချက်ချင်း Lock ချပြီး တားဆီးပေးပါတယ်။
(ခ) ရှာဖွေဖော်ထုတ်သော ထိန်းချုပ်မှုများ (Detective Controls)
အမှားအယွင်းများ၊ လိမ်လည်မှုများကို လျင်မြန်စွာ ရှာဖွေဖော်ထုတ်ပေးတဲ့ Controls တွေဖြစ်ပါတယ်။
* Anomaly Detection (ပုံမှန်မဟုတ်သည်များကို ရှာဖွေခြင်း): Machine Learning Algorithm တွေက ကုမ္ပဏီရဲ့ ပုံမှန် Transaction ပုံစံတွေကို သင်ယူထားပါတယ်။ အကယ်၍ ပုံမှန်မဟုတ်တဲ့ Journal Entries တွေ (ဥပမာ - စနေ၊ တနင်္ဂနွေ ရုံးပိတ်ရက်မှာ စာရင်းသွင်းခြင်း၊ အမြတ်ကို ရုတ်တရက် ပြောင်းလဲသွားစေလောက်တဲ့ Manual Adjustment များသွင်းခြင်း) ကို တွေ့တာနဲ့ Exception Report အဖြစ် ချက်ချင်း ထုတ်ပေးပါတယ်။
* Automated Reconciliations (အလိုအလျောက် စာရင်းတိုက်ဆိုင်စစ်ဆေးခြင်း): Bank Statements တွေနဲ့ Ledger Transactions တွေ၊ Intercompany balances တွေကို AI က အလိုအလျောက် တွဲဖက် (Match) ပေးပါတယ်။ မကိုက်ညီတဲ့ (Unreconciled) အချက်တွေကိုသာ Auditor က ဝင်ရောက် ဖြေရှင်းဖို့ ချန်ထားပေးပါတယ်။
(ဂ) ပြင်ဆင်ပေးသော ထိန်းချုပ်မှုများ (Corrective Controls)
တွေ့ရှိလာတဲ့ ပြဿနာတွေကို မြန်မြန်ဆန်ဆန် ပြုပြင်နိုင်ဖို့ ကူညီပေးပါတယ်။
* Automated Alert & Workflow: AI က Control ပျက်ကွက်မှုတစ်ခုကို တွေ့ရှိတာနဲ့ သက်ဆိုင်ရာ Manager သို့မဟုတ် Chief Audit Executive (CAE) ဆီကို ချက်ချင်း Notification ပို့ပါတယ်။ ထို့အပြင် ယခင်က အလားတူ ပြဿနာမျိုး ဖြစ်ခဲ့စဉ်က ဘယ်လို ဖြေရှင်းခဲ့သလဲ ဆိုတဲ့ သမိုင်းကြောင်းကိုပါ ပြန်လည်ရှာဖွေပြီး Corrective Action Plan ကို အကြံပြုပေးပါတယ်။
၃။ လက်တွေ့ အကောင်အထည်ဖော်ရန် အဆင့်များ (Step-by-Step Implementation)
* Data Standardisation (ဒေတာများ စနစ်တကျ ပြင်ဆင်ခြင်း): AI ဟာ ဒေတာအပေါ်မှာ မှီခိုရတဲ့အတွက် ကုမ္ပဏီရဲ့ Accounting Data တွေ၊ SOP တွေ၊ Policy တွေကို Digital format ဖြစ်အောင် အရင် ပြင်ဆင်ရပါမယ်။ (Garbage In, Garbage Out မဖြစ်စေရန်)။
* Start Small with a Pilot (စမ်းသပ်စီမံကိန်းဖြင့် စတင်ခြင်း): လုပ်ငန်းစဉ်အားလုံးကို တစ်ပြိုင်နက် AI ပြောင်းမယ့်အစား Rule-based ဖြစ်တဲ့ နေရာတွေဖြစ်တဲ့ Accounts Payable (AP) သို့မဟုတ် Payroll Process ကနေ စတင်ပြီး AI Controls တွေကို တည်ဆောက်စမ်းသပ်ပါ။
* Human-in-the-Loop (လူသားနှင့် ပူးပေါင်းလုပ်ဆောင်ခြင်း): AI က သံသယဖြစ်ဖွယ် အချက်တွေကို ဖော်ထုတ်ပေးနိုင်ပေမယ့် နောက်ဆုံး ဆုံးဖြတ်ချက်နဲ့ Professional Skepticism (ဝေဖန်ပိုင်းခြားနိုင်သော သံသယစိတ်) ကတော့ Auditor ဆီမှာပဲ ရှိရပါမယ်။ AI ကို အလုပ်သမားအစားထိုးဖို့မဟုတ်ဘဲ Auditor ရဲ့ စွမ်းဆောင်ရည်ကို မြှင့်တင်ပေးတဲ့ (Augmentation) ကိရိယာအဖြစ် သုံးရပါမယ်။
ဒီလို နည်းစနစ်ကျကျ ပေါင်းစပ်လိုက်မယ်ဆိုရင် Internal Audit Department ဟာ လုပ်ငန်းရဲ့ Risk တွေကို အထိရောက်ဆုံး ကာကွယ်ပေးနိုင်တဲ့ မရှိမဖြစ် မဟာဗျူဟာမြောက် အစိတ်အပိုင်းတစ်ခု ဖြစ်လာမှာပါ။

AMH 21Mar2026

Auditor တစ်ယောက်အတွက် AI ဆိုတာ အလုပ်ကို မြန်ဆန်စေရုံတင်မဟုတ်ဘဲ Audit Risk ကို သိသိသာသာ လျှော့ချပေးနိုင်တဲ့ လက်နက်ကောင်းတ...
21/03/2026

Auditor တစ်ယောက်အတွက် AI ဆိုတာ အလုပ်ကို မြန်ဆန်စေရုံတင်မဟုတ်ဘဲ Audit Risk ကို သိသိသာသာ လျှော့ချပေးနိုင်တဲ့ လက်နက်ကောင်းတစ်ခုပါ။ AI ကို အသုံးပြုပြီး Audit Risk Model ထဲက အစိတ်အပိုင်းတစ်ခုချင်းစီကို ဘယ်လို Manage လုပ်မလဲဆိုတာ အသေးစိတ် ရှင်းပြပေးပါ့မယ်။
၁။ Inherent Risk (IR) ကို AI ဖြင့် ဆန်းစစ်ခြင်း
Inherent Risk ဆိုတာ လုပ်ငန်းရဲ့ သဘာဝအရ ရှိနေတဲ့ Risk ဖြစ်ပါတယ်။ AI က ဒီနေရာမှာ "ဒေတာအမြောက်အမြားကို ခွဲခြမ်းစိတ်ဖြာခြင်း" အားဖြင့် ကူညီပေးပါတယ်။
* Predictive Analytics: AI ကို အသုံးပြုပြီး Industry trend တွေကို တွက်ချက်နိုင်ပါတယ်။ ဥပမာ - Construction လုပ်ငန်းဆိုရင် ကုန်ကြမ်းဈေးနှုန်း အတက်အကျနဲ့ ပတ်သက်တဲ့ ဒေတာတွေကို AI နဲ့ ခွဲခြမ်းစိတ်ဖြာပြီး Management ရဲ့ Estimates တွေ (ဥပမာ - Cost to complete) ဟာ လက်တွေ့ကျရဲ့လားဆိုတာကို ပိုမိုတိကျစွာ ဆန်းစစ်နိုင်ပါတယ်။
* Complex Pattern Recognition: ရှုပ်ထွေးတဲ့ စာချုပ်တွေ (Contracts) ထဲမှာပါတဲ့ အချက်အလက်တွေကို NLP (Natural Language Processing) သုံးပြီး ရှာဖွေနိုင်ပါတယ်။ ဒါကြောင့် ဝင်ငွေသတ်မှတ်မှု (Revenue Recognition) မှားယွင်းနိုင်ခြေရှိတဲ့ အချက်တွေကို လူက လိုက်ဖတ်တာထက် ပိုမိုမြန်ဆန်ပြီး တိကျစွာ ရှာဖွေနိုင်ပါတယ်။
၂။ Control Risk (CR) ကို AI ဖြင့် လျှော့ချခြင်း
Client ရဲ့ Internal Control အားနည်းမှုကို AI သုံးပြီး စောင့်ကြည့်စစ်ဆေးနိုင်ပါတယ်။
* Continuous Monitoring: ပုံမှန် Audit မှာဆိုရင် တစ်နှစ်ကို တစ်ခါ ဒါမှမဟုတ် ၆ လတစ်ခါပဲ Control တွေကို စစ်ဆေးလေ့ရှိပါတယ်။ AI သုံးရင်တော့ Real-time Monitoring လုပ်နိုင်ပါတယ်။ ဥပမာ - Segregation of Duties (SoD) ကို ချိုးဖောက်ပြီး တစ်ဦးတည်းက Payment တင်တာရော Approve လုပ်တာရော ဖြစ်နေရင် AI က ချက်ချင်း Alert ပေးနိုင်ပါတယ်။
* Automated Exception Reporting: ပုံမှန်မဟုတ်တဲ့ Transaction တွေ (ဥပမာ - အားလပ်ရက်မှာ စာရင်းသွင်းတာ၊ ပမာဏ အရမ်းများတဲ့ Manual Journal တွေ) ကို AI က ချက်ချင်း ခွဲထုတ်ပေးတဲ့အတွက် Control ပျက်ကွက်မှုတွေကို ချက်ချင်း သိနိုင်ပါတယ်။
၃။ Detection Risk (DR) ကို AI ဖြင့် လျှော့ချခြင်း (The Game Changer)
ဒါဟာ Auditor တစ်ယောက်အတွက် AI ရဲ့ အကျိုးကျေးဇူး အရှိဆုံးအပိုင်းပါ။ Detection Risk ကို လျှော့ချဖို့ AI က အောက်ပါအတိုင်း ကူညီပေးပါတယ်-
(က) 100% Full Population Testing
အရင်က Sampling (နမူနာယူစစ်ဆေးခြင်း) ပဲ လုပ်နိုင်ခဲ့ရာကနေ အခု AI သုံးရင် Transaction သန်းပေါင်းများစွာကို (၁၀၀ ရာခိုင်နှုန်း) စစ်ဆေးနိုင်ပါတယ်။ ဒါကြောင့် Sample ထဲမှာ မပါလို့ အမှားလွတ်သွားမယ့် Risk (Sampling Risk) ကို လုံးဝ ပျောက်ကွယ်သွားစေပါတယ်။
(ခ) Anomaly Detection (Machine Learning)
AI က ပုံမှန် Transaction တွေရဲ့ သဘာဝကို သင်ယူထားပြီး အဲဒီထဲကမှ ထူးခြားနေတဲ့ "Anomaly" (ပုံမှန်မဟုတ်တဲ့ အချက်) တွေကို ရှာပေးပါတယ်။ ဥပမာ - လူက စစ်ရင် မတွေ့နိုင်တဲ့ သိမ်မွေ့တဲ့ Fraud pattern တွေကို AI ရဲ့ Algorithm တွေက ရှာဖွေပေးနိုင်ပါတယ်။
(ဂ) Unstructured Data Analysis
Auditor တွေအတွက် အခက်ခဲဆုံးက စာရင်းဇယားမဟုတ်တဲ့ စာရွက်စာတမ်းတွေ (ဥပမာ - PDF invoices, Emails, Meeting minutes) ကို စစ်ရတာပါ။ AI (OCR & NLP) ကို သုံးပြီး ဒီစာရွက်စာတမ်းတွေထဲက အချက်အလက်တွေကို စာရင်းဇယားတွေနဲ့ အလိုအလျောက် တိုက်ဆိုင်စစ်ဆေးနိုင်တဲ့အတွက် Detection Risk ကို အနိမ့်ဆုံးအဆင့်အထိ လျှော့ချနိုင်ပါတယ်။
၄။ AI ကို အသုံးပြုရာတွင် သတိပြုရမယ့် အချက်များ (Best Practices)
AI ကို သုံးပြီး Audit Risk လျှော့ချတဲ့အခါ "Human-in-the-loop" ဖြစ်ဖို့ လိုပါတယ်။
* Verify the Data: AI ဆီ ကျွေးမယ့် ဒေတာတွေက မှန်ကန်ဖို့ လိုပါတယ်။ (Garbage In, Garbage Out)။
* Professional Skepticism: AI က "အိုကေတယ်" လို့ ပြောတိုင်း မယုံပါနဲ့။ AI ရဲ့ output ကို ပြန်လည် ဆန်းစစ်ဝေဖန်နိုင်တဲ့ Auditor ရဲ့ ဦးနှောက်က အမြဲ လိုအပ်ပါတယ်။
* Explainability: AI က ဘာကြောင့် ဒါကို Risk လို့ သတ်မှတ်တာလဲဆိုတဲ့ အကြောင်းရင်း (The "Why") ကို နားလည်အောင် လုပ်ရပါမယ်။

AI ကို အသုံးချခြင်းအားဖြင့် သင်ဟာ Auditor တစ်ယောက်အနေနဲ့ အမှားအယွင်းတွေကို ပိုမိုထိရောက်စွာ ရှာဖွေနိုင်ပြီး Audit Quality ကို Level အသစ်တစ်ခုအထိ မြှင့်တင်နိုင်မှာပါ။

AMH 21 Mar 2026

Auditor တစ်ယောက်ရဲ့ အဓိက ပန်းတိုင်ကတော့ Audit Risk ကို လက်ခံနိုင်တဲ့ အနိမ့်ဆုံးအဆင့် (Acceptably Low Level) ရောက်အောင် လ...
21/03/2026

Auditor တစ်ယောက်ရဲ့ အဓိက ပန်းတိုင်ကတော့ Audit Risk ကို လက်ခံနိုင်တဲ့ အနိမ့်ဆုံးအဆင့် (Acceptably Low Level) ရောက်အောင် လျှော့ချဖို့ပဲ ဖြစ်ပါတယ်။ ဒါဟာ Audit တစ်ခုလုံးရဲ့ အရည်အသွေးကို ဆုံးဖြတ်ပေးတဲ့ အချက်လည်း ဖြစ်ပါတယ်။
ပေးထားတဲ့ အချက်အလက်တွေအပေါ် အခြေခံပြီး "How to Reduce Audit Risk" ကို အဆင့်ဆင့် (Step-by-Step) နားလည်လွယ်အောင် ရှင်းပြပေးလိုက်ပါတယ်။
🚀 Audit Risk ကို စနစ်တကျ လျှော့ချနည်း (A Step-by-Step Guide)
Audit Risk ဆိုတာ AR = IR \times CR \times DR ဆိုတဲ့ Model အပေါ်မှာ မူတည်နေတာကြောင့် ဒီ Risk ကို လျှော့ချဖို့ဆိုရင် အပိုင်း ၃ ပိုင်းလုံးကို စနစ်တကျ စီမံခန့်ခွဲရမှာ ဖြစ်ပါတယ်။
အဆင့် (၁) - Inherent Risk (IR) ကို အသေအချာ ဆန်းစစ်ခြင်း
Inherent Risk ဆိုတာကတော့ လုပ်ငန်းရဲ့ သဘာဝအရကိုက ရှိနေတဲ့ Risk ဖြစ်ပါတယ်။ ဒါကို Auditor က ပြောင်းလဲလို့ မရပေမယ့် အသေအချာ သိရှိနားလည်ခြင်း အားဖြင့် ကြိုတင်ပြင်ဆင်နိုင်ပါတယ်။
* High-Risk Areas တွေကို အာရုံစိုက်ပါ: Revenue Recognition (ဝင်ငွေသတ်မှတ်ခြင်း)၊ Construction WIP (ဆောက်လုပ်ဆဲလုပ်ငန်းများ) နဲ့ Accounting Estimates တွေလိုမျိုး Management Judgment အများကြီးသုံးရတဲ့ နေရာတွေကို အထူးသတိထားပါ။
* Industry Risk ကို ကြည့်ပါ: လုပ်ငန်းကဏ္ဍအလိုက် ရှိနိုင်တဲ့ Risk (ဥပမာ - Construction ဆိုရင် Cost shifting risk သို့မဟုတ် Stage of completion risk) ကို နားလည်အောင် အရင်လုပ်ပါ။
အဆင့် (၂) - Control Risk (CR) ကို လျှော့ချခြင်း (သို့မဟုတ်) အကဲဖြတ်ခြင်း
Client ရဲ့ Internal Controls တွေက အမှားတွေကို မတားဆီးနိုင်ရင် Control Risk မြင့်တက်လာပါတယ်။ ဒါကို Auditor က အောက်ပါအတိုင်း လုပ်ဆောင်နိုင်ပါတယ်-
* Evaluate Internal Controls: Client ရဲ့ လုပ်ငန်းစဉ်တွေမှာ Segregation of Duties (တာဝန်ခွဲဝေမှု) ရှိရဲ့လား၊ Authorization (ခွင့်ပြုချက်) စနစ်တွေ ကောင်းရဲ့လားဆိုတာ အရင်ကြည့်ပါ။
* Test of Controls (ToC): Controls တွေက စာရွက်ပေါ်မှာတင်မကဘဲ လက်တွေ့မှာပါ ထိရောက်မှု ရှိမရှိ (Operating Effectiveness) ကို စမ်းသပ်ပါ။
* Recommend Improvements: အားနည်းချက်ရှိရင် Client ကို အကြံပြုချက်တွေ ပေးပြီး Controls တွေ ပိုကောင်းအောင် လုပ်ခိုင်းပါ။
အဆင့် (၃) - Detection Risk (DR) ကို လျှော့ချခြင်း (Auditor's Direct Job)
Auditor တစ်ယောက် တိုက်ရိုက် ထိန်းချုပ်ပြီး လျှော့ချနိုင်တဲ့ တစ်ခုတည်းသော Risk ကတော့ Detection Risk ပါ။ IR နဲ့ CR (RMM) မြင့်နေရင် Auditor က DR ကို အနိမ့်ဆုံးဖြစ်အောင် လုပ်ရပါမယ်။
* Substantive Procedures များများလုပ်ပါ: Vouching (စာရင်းမှ အထောက်အထားသို့ ပြန်စစ်ခြင်း) နဲ့ Tracing (အထောက်အထားမှ စာရင်းသို့ စစ်ဆေးခြင်း) တွေကို အသေးစိတ်လုပ်ပါ။
* External Confirmations: ကုမ္ပဏီတွင်း အထောက်အထားထက် ပိုခိုင်မာတဲ့ ပြင်ပအထောက်အထား (ဥပမာ - Bank/Debtor confirmations) တွေကို ရယူပါ။
* Analytical Procedures: ပုံမှန်မဟုတ်တဲ့ Trends တွေ၊ Unusual fluctuations တွေကို ရှာဖွေဖို့ Analytical review တွေ သုံးပါ။
အဆင့် (၄) - Professional Skepticism ကို လက်ကိုင်ထားခြင်း
အချက်အလက်တွေကို ယုံကြည်ရုံတင် မဟုတ်ဘဲ "Questioning Mind" နဲ့ အမြဲဆန်းစစ်ပါ။
* Challenge Management Assumptions: Management ရဲ့ ခန့်မှန်းချက်တွေ (ဥပမာ- Provision for bad debts) ဟာ လက်တွေ့ကျရဲ့လားဆိုတာကို ပြင်းပြင်းထန်ထန် မေးခွန်းထုတ်ပါ။
* Contradictory Evidence: ကိုယ်ရထားတဲ့ အထောက်အထားတွေအချင်းချင်း ဆန့်ကျင်နေတာမျိုး ရှိမရှိ (ဥပမာ- Profit ပြနေပေမယ့် Cash flow က Negative ဖြစ်နေတာမျိုး) ကို သတိပြုပါ။
အဆင့် (၅) - Materiality နှင့် Sampling ကို ပြန်လည်ညှိနှိုင်းခြင်း
Risk မြင့်တဲ့နေရာတွေမှာ အမှားအယွင်း အနည်းငယ်တောင် မရှိစေဖို့အတွက်-
* Lower Materiality: Risk များတဲ့ နေရာတွေမှာ Performance Materiality ကို လျှော့ချသတ်မှတ်ပြီး ပိုမိုစေ့စပ်အောင် စစ်ဆေးပါ။
* Increase Sample Size: Risk မြင့်လေလေ၊ စစ်ဆေးရမယ့် နမူနာ (Sample) ပမာဏကို တိုးမြှင့်လေလေ လုပ်ရပါမယ်။
📌 Final Professional Summary
Audit Risk ကို လုံးဝ (Zero) ဖြစ်အောင် မလုပ်နိုင်ပေမယ့်၊ စနစ်တကျ Planning ဆွဲခြင်း၊ Internal Controls တွေကို နားလည်ခြင်းနဲ့ ခိုင်မာတဲ့ Substantive Testing တွေ ပြုလုပ်ခြင်းအားဖြင့် Acceptably Low Level ရောက်အောင် လျှော့ချနိုင်ပါတယ်။

AMH 21 Mar 2026
Audit

Audit Risk ဆိုတာကို ရိုးရိုးရှင်းရှင်းပြောရရင် - ကုမ္ပဏီရဲ့ Financial Statements တွေမှာ ကြီးမားတဲ့မှားယွင်းမှုတွေ (Mater...
21/03/2026

Audit Risk ဆိုတာကို ရိုးရိုးရှင်းရှင်းပြောရရင် - ကုမ္ပဏီရဲ့ Financial Statements တွေမှာ ကြီးမားတဲ့မှားယွင်းမှုတွေ (Material Misstatement) ရှိနေလျက်နဲ့ Auditor က ရှာမတွေ့ဘဲ "စာရင်းတွေ မှန်ပါတယ်" ဆိုပြီး မှားယွင်းတဲ့ Audit Opinion (Inappropriate Opinion) ပေးမိဖို့ ဖြစ်နိုင်ခြေ (Possibility) ကို ဆိုလိုတာပါ။

ဒါဟာ Auditor တစ်ယောက်အတွက် အကြီးမားဆုံး အမှားအယွင်းနဲ့ Risk ဖြစ်ပါတယ်။ ဒါကြောင့် Audit လုပ်ငန်းစဉ်တစ်ခုလုံးဟာ ဒီ Risk ကို လက်ခံနိုင်လောက်တဲ့ အနိမ့်ဆုံးအဆင့် (Acceptably Low Level) သို့ လျှော့ချဖို့အတွက်ပဲ ပုံဖော်ထားတာ ဖြစ်ပါတယ်။

🔍 Audit Risk Model ကို နားလည်ခြင်း

Audit Risk ကို ပိုမိုစနစ်တကျ တွက်ချက်စီမံနိုင်ဖို့အတွက် အောက်ပါ Model ကို အသုံးပြုပါတယ်:

🧮 Audit Risk (AR) = Inherent Risk (IR) × Control Risk (CR) × Detection Risk (DR)

ဒီ Model အရ Audit Risk ဟာ အပိုင်း ၃ ပိုင်းကြောင့် ဖြစ်ပေါ်လာတာပါ:

🔺 ၁. Inherent Risk (IR) - သဘာဝအလျောက်ရှိနေသော Risk

Internal Controls တွေကို ထည့်မစဉ်းစားခင်မှာပဲ၊ စာရင်းတစ်ခု သို့မဟုတ် Transaction တစ်ခုရဲ့ သဘာဝအရကိုက Material Misstatement ဖြစ်ဖို့ များနေတဲ့ risk ပါ။ Complex ဖြစ်တဲ့ area တွေ၊ Judgment အများကြီးသုံးရတဲ့ area တွေမှာ IR မြင့်တတ်ပါတယ်။

👉 High IR examples:

Revenue Recognition with complex contracts (ရှုပ်ထွေးသော စာချုပ်များမှ ဝင်ငွေအသိအမှတ်ပြုခြင်း)

Accounting Estimates (ECL provisions, Impairment) - ခန့်မှန်းခြေစာရင်းများ

Foreign Currency transactions

Related Party transactions

🔺 ၂. Control Risk (CR) - ထိန်းချုပ်မှုဆိုင်ရာ Risk

ဒါကတော့ Client ရဲ့ Internal Controls စနစ်က Material Misstatements တွေကို အချိန်မီ တားဆီးဖို့ (Prevent) သို့မဟုတ် ရှာဖွေပြင်ဆင်ဖို့ (Detect & Correct) ပျက်ကွက်မယ့် Risk ပါ။ Client ဘက်မှာ Control အားနည်းရင် CR မြင့်ပါတယ်။

👉 High CR examples:

No Segregation of Duties (တာဝန်ခွဲဝေမှု မရှိခြင်း)

Weak IT access control (Software access ကို စနစ်တကျ မထိန်းချုပ်ခြင်း)

No review of Bank/Receivable Reconciliations (စာရင်းတိုက်ဆိုင်စစ်ဆေးမှုများအား review မလုပ်ခြင်း)

💡 praktically, IR နဲ့ CR ကိုပေါင်းပြီး Risk of Material Misstatement (RMM) လို့ ခေါ်ပါတယ်။ ဒါဟာ Client ဘက်မှာ Audit မတိုင်ခင်ကတည်းက ရှိနေတဲ့ Risk ပါ။ (RMM = IR × CR)

🔺 ၃. Detection Risk (DR) - ရှာဖွေမှုဆိုင်ရာ Risk

ဒါကတော့ Auditor ရဲ့ Procedures တွေက စာရင်းထဲမှာရှိနေတဲ့ Material Misstatement ကို ရှာမတွေ့မိဘဲ လွတ်သွားမယ့် Risk ပါ။ ဒီ Risk တစ်ခုတည်းသာ Auditor က တိုက်ရိုက် လွှမ်းမိုးစီမံနိုင်ပါတယ်။

👉 DR ဖြစ်စေတဲ့ အကြောင်းရင်းများ:

Sample size too small (နမူနာယူမှု နည်းလွန်းခြင်း)

Wrong audit procedure selected (မှားယွင်းသော စစ်ဆေးမှုနည်းလမ်းသုံးခြင်း)

Lack of Professional Skepticism (ဝေဖန်ပိုင်းခြားနိုင်သော သံသယစိတ် အားနည်းခြင်း)

✅ Audit Risk Model ၏ အပြန်အလှန်ဆက်သွယ်မှု (Interrelationship)

Audit Risk Concept ရဲ့ အဓိက သော့ချက်ကတော့ RMM နှင့် Detection Risk (DR) တို့ကြားရှိ ဆန့်ကျင်ဘက်ဆက်ဆံရေး (Inverse Relationship) ပါပဲ။

Auditor က Client ဆီမှာ RMM (IR + CR) မြင့်တယ် လို့ သုံးသပ်ရင် -> Audit Risk ကို လျှော့ချဖို့အတွက် Auditor ဘက်က DR ကို အနိမ့်ဆုံးဖြစ်အောင် လုပ်ရပါမယ်။

DR နိမ့်အောင် ဘယ်လိုလုပ်မလဲ? -> Audit work တွေကို ပိုမိုကျယ်ကျယ်ပြန့်ပြန့် လုပ်ရပါမယ် (More Extensive Substantive Procedures - Increase Sample Size, Use experienced staff, Year-end testing).

ပြန်ချုပ်ရရင်: High IR & CR -> Lower DR needed -> More Audit Work needed.

📊 Financial Statement Level Risk vs Assertion Level Risk

RMM (Risk of Material Misstatement) ကို level ၂ ခုမှာ သုံးသပ်ရပါတယ်-

🅰️ Financial Statement Level Risk:

ဒါဟာ Financial Statements တစ်ခုလုံးကို ခြုံငုံပြီး သက်ရောက်မှုရှိတဲ့ Risk တွေပါ။ (ဥပမာ - Weak management integrity, poor accounting system, Going concern problems).

➡️ Response: Broader response needed, more supervision, experienced team.

🅱️ Assertion Level Risk:

ဒါကတော့ သီးခြား account balance, class of transactions သို့မဟုတ် disclosure တွေနဲ့ သက်ဆိုင်တဲ့ Risk ပါ။ (assertions are Existence, Completeness, Accuracy, Valuation etc.).

👉 For Receivables: Risk of Existence (Debtors are real?) သို့မဟုတ် Risk of Valuation (Recoverable?).

⚠️ Business Risk vs Audit Risk (မရောထွေးပါနဲ့)

Business Risk: ကုမ္ပဏီက သူ့ရဲ့ Objectives တွေ မအောင်မြင်မှာကို စိုးရိမ်ရတဲ့ Risk ပါ (ဥပမာ - Loss of customers, Economic downturn).

Audit Risk: Auditor က Opinion မှားပေးမိမှာကို စိုးရိမ်ရတဲ့ Risk ပါ။

Connection: သို့သော် Business Risk ကြီးမားတဲ့အခါ (ဥပမာ- Cash flow ပြဿနာ) Management က profit ကို manipulation လုပ်ဖို့ ဖိအားရှိလာနိုင်တဲ့အတွက် Audit Risk ကို မြင့်တက်စေပါတယ်။

💡 Conclusion

Auditor တစ်ယောက်အနေနဲ့ Acceptably Low Level of Audit Risk သို့ ရောက်ရှိအောင် စစ်ဆေးဖို့အတွက်- Professional Skepticism ကို အပြည့်အဝ သုံးရမယ်၊ Experienced staff တွေ သုံးရမယ်၊ Supervision & Review ကောင်းရမယ်၊ ပြီးတော့ Significant Estimates နဲ့ Manual Journal Entries တွေလို high-risk area တွေကို Focus လုပ်ပြီး substantive testing ပိုမိုလုပ်ဆောင်ရပါမယ်။

Audit strategy ကောင်းကောင်းဆွဲဖို့အတွက် Audit Risk Model ကို နားလည်ဖို့က မရှိမဖြစ်ပါပဲ။

AI နဲ့ အောက်က English လေးတွေလဲ လေ့လာကြည့်ရအောင် 😊

Audit Risk means the risk that an auditor gives an inappropriate audit opinion when the financial statements are materially misstated.

In simple words:

The auditor says the financial statements are okay, but actually they contain a material error or fraud.

1) Standard meaning of audit risk

Audit risk is the possibility that:

Material misstatement exists

but

the auditor fails to detect it

and issues an unmodified / clean opinion

This is one of the most important concepts in audit because the whole audit approach is built around managing this risk.

---

2) Audit Risk Model

The common audit risk model is:

Audit Risk (AR) = Inherent Risk (IR) × Control Risk (CR) × Detection Risk (DR)

This means audit risk comes from three parts:

A. Inherent Risk (IR)

This is the risk that an account balance, transaction, or disclosure is naturally prone to material misstatement before considering internal controls.

It exists because some areas are more difficult, judgmental, complex, or open to fraud.

Examples:

Revenue recognition with many contracts

Inventory with obsolete or damaged goods

Construction WIP and percentage of completion

Estimates like provision, impairment, ECL

Related party transactions

Foreign currency transactions

Higher inherent risk means the area is naturally riskier.

---

B. Control Risk (CR)

This is the risk that the client’s internal controls fail to prevent or detect and correct material misstatements on time.

Examples:

No segregation of duties

No approval for journal entries

Weak IT access control

No reconciliation of bank or receivable balances

No review of contract cost allocation

Poor control over inventory counting

If internal controls are weak, control risk is high.

---

C. Detection Risk (DR)

This is the risk that the auditor’s procedures will not detect a material misstatement that already exists.

This risk relates to the audit work itself.

Examples:

Sample size too small

Wrong audit procedure selected

Auditor overlooks unusual entries

Poor professional skepticism

Inadequate follow-up on exceptions

Reliance on unreliable evidence

Unlike IR and CR, detection risk can be influenced by the auditor.

---

3) Relationship between the three risks

If IR and CR are high:

Then the auditor must keep detection risk low.

How?

Increase sample size

Perform more substantive testing

Use more experienced staff

Test year-end balances instead of interim only

Obtain stronger external evidence

Perform unpredictable procedures

If IR and CR are low:

The auditor may accept a relatively higher detection risk.

That means:

Less extensive testing may be acceptable

More reliance may be placed on controls

---

4) Why audit risk is important

Audit risk is important because it affects:

Audit planning

Nature, timing, and extent of procedures

Staffing and supervision

Materiality considerations

Areas requiring more professional skepticism

Final audit opinion

Auditors do not eliminate risk completely.

They reduce audit risk to an acceptably low level.

---

5) Components explained with easy example

Take inventory as an example:

Inherent Risk

Inventory may be:

damaged

obsolete

stolen

wrongly valued

wrongly counted

So IR may be high.

Control Risk

If the company:

does not perform stock counts

has weak warehouse control

does not reconcile stock records

allows one person to receive, record, and issue stock

Then CR is high.

Detection Risk

If the auditor:

attends stock count carelessly

takes too few samples

does not test valuation properly

ignores slow-moving items

Then DR is high.

Result:

Overall audit risk becomes high.

---

6) Types of risk in practical audit work

When auditors discuss audit risk in practice, they often focus on:

a) Risk of Material Misstatement (RMM)

This is:

RMM = IR × CR

It means the risk that the financial statements are materially misstated before the audit procedures detect it.

This is assessed at:

Financial statement level

Assertion level

---

b) Detection Risk

This is managed by the auditor through procedures.

So practically:

Audit Risk = Risk of Material Misstatement × Detection Risk

---

7) Financial statement level risk vs assertion level risk

A. Financial Statement Level Risk

These are risks affecting the financial statements as a whole.

Examples:

Weak management integrity

Poor accounting system

Going concern problems

Inexperienced finance team

Weak overall internal control environment

Pressure to meet profit targets

Impact:

Broader audit response needed

More supervision

More unpredictability

More experienced team members

---

B. Assertion Level Risk

These relate to specific account balances, classes of transactions, or disclosures.

Assertions include:

Existence

Completeness

Accuracy

Valuation

Cut-off

Rights and obligations

Presentation and disclosure

Example: For receivables:

Existence: are debtors real?

Valuation: are they recoverable?

Completeness: are all balances recorded?

---

8) Example of audit risk in construction company

Since construction companies are high-risk in audit, this is a good example.

Common risk areas:

Revenue recognition by stage of completion

Contract cost allocation

Variation orders and claims

Accrual for subcontractor cost

Retention receivables

Cut-off of project revenue and cost

WIP valuation

Provision for foreseeable loss contracts

Why risk is high:

Heavy management judgment

Complex contracts

Many supporting documents

Manual estimates

Risk of manipulation to show profit

Audit response:

Review contracts

Test certified progress billings

Recalculate stage of completion

Test cost incurred to source documents

Check cut-off around year-end

Review post year-end settlement

Confirm balances when necessary

Evaluate provision for loss-making projects

---

9) Example of high audit risk indicators

Auditors become more alert when they see:

Unusual journal entries at year-end

Rapid growth in revenue

Weak documentation

Large manual adjustments

Related party transactions

Management override of controls

Poor segregation of duties

Significant estimates

Complex new accounting policies

Prior year misstatements

Fraud allegations

Negative cash flow despite reported profit

These are red flags.

---

10) Difference between business risk and audit risk

Business Risk

Risk that the company fails to achieve its objectives.

Examples:

Loss of customers

Economic downturn

Increased raw material prices

Legal disputes

Liquidity problems

Audit Risk

Risk that the auditor gives the wrong opinion on materially misstated financial statements.

Business risk can increase audit risk, but they are not the same.

Example: If a company has serious cash flow problems, management may manipulate revenue or understate liabilities.

So business risk may lead to higher audit risk.

---

11) How auditor responds to high audit risk

When audit risk is high, auditor may:

Increase professional skepticism

Assign experienced staff

Increase supervision and review

Perform more substantive procedures

Increase sample size

Obtain external confirmations

Use experts

Focus on year-end testing

Perform surprise procedures

Test journal entries and management override

Reassess going concern

Lower performance materiality

---

12) Audit risk and materiality relationship

Audit risk and materiality are closely linked.

If materiality is lower, auditor needs more work

If risk is higher, auditor usually performs more extensive work

High-risk areas often require lower tolerable misstatement

So both affect audit strategy.

---

13) Very simple formula meaning

You can remember like this:

IR = How risky the area is by nature

CR = How weak the client’s controls are

DR = How likely the auditor misses the error

If:

the account is risky,

controls are weak,

and audit testing is poor,

then audit risk becomes very high.

---

14) Easy real-life example

Imagine auditing cash:

Cash is highly susceptible to theft → IR

No independent bank reconciliation → CR

Auditor does not obtain bank confirmation → DR

Then there is a strong chance material misstatement is not detected.

---

15) Final summary

Audit risk is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated.

It has 3 parts:

Inherent Risk = natural susceptibility to misstatement

Control Risk = failure of internal controls

Detection Risk = auditor fails to detect the misstatement

Formula:

AR = IR × CR × DR

Main idea:

High IR + high CR → auditor must reduce DR

Auditor reduces DR by stronger audit procedures

AMH 21 Mar 2026

Address


Website

Alerts

Be the first to know and let us send you an email when Mr Audit posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Mr Audit:

Shortcuts

  • Want your business to be the top-listed Business?

Share