Hubbry Logo
search
search button
Sign in
Historyarrow-down
starMorearrow-down
Welcome to the community hub built on top of the Risk-based auditing Wikipedia article. Here, you can discuss, collect, and organize anything related to Risk-based auditing. The purpose of the hub is to connect people, foster deeper knowledge, and help improve the root Wikipedia article.
Add your contribution
Inside this hub
Risk-based auditing

Risk-based auditing is a style of auditing which focuses upon the analysis and management of risk.

In the UK, the 1999 Turnbull Report on corporate governance required directors to provide a statement to shareholders of the significant risks to the business. This then encouraged the audit activity of studying these risks rather than just checking compliance with existing controls.[1]

Standards for risk management have included the COSO guidelines and the first international standard, AS/NZS 4360.[2] The latter is now the basis for a family of international standards for risk management — ISO 31000.

A traditional audit would focus upon the transactions which would make up financial statements such as the balance sheet. A risk-based approach will seek to identify risks with the greatest potential impact. Strategic risk analysis will then include political and social risks such as the potential effect of legislation and demographic change.[3]

An experiment suggested that managers might respond to risk-based auditing by transferring activity to accounts which are ostensibly low risk. Auditors would need to anticipate such attempts to game the process.[4]

References

[edit]
Add your contribution
Related Hubs