Audit Risk Model
Control Risk by Process
Assessed control risk for each major business process based on tested control reliability.
Why control risk follows tested reliability
Control risk, the chance that a misstatement is not prevented or detected by controls, can only be assessed credibly from evidence of how controls actually perform, not from how they are designed on paper. The ISSAI audit risk model uses control risk to determine how much substantive testing each process needs. AuditPro Core assesses control risk per major process from tested control reliability so reliance decisions rest on results, not optimism.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Processes assessed
16
Low control risk
6
reliance possible
High control risk
5
substantive focus
Controls relied on
61%
▲ 4%
Control risk rating by process
Control reliance decision by process
| Process | Controls tested | Control risk | Audit approach |
|---|---|---|---|
| Procurement | 22 | 4.1 | Substantive |
| Billing & revenue | 18 | 3.4 | Combined |
| Payroll | 14 | 2.6 | Controls reliance |
| Asset management | 16 | 3.9 | Substantive |
| Grants & transfers | 12 | 3.2 | Combined |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Control risk defined
Control risk is the risk that controls fail to prevent or detect a material misstatement. It is lower where controls are proven reliable and higher where they are untested or failing.
Tested reliability
Reliability is established by testing the control's operation over the period, not by reviewing its design. A well-designed control that fails in operation carries high control risk.
Process-level assessment
Control risk varies by process; procurement may be reliable while payroll is weak. Assessing per process directs substantive effort to the processes least able to be relied upon.
Effect on substantive work
Lower control risk justifies less substantive testing and vice versa. The assessment is the lever that balances controls reliance against detailed verification.
How AuditPro Core Bridges the Gap
- Reliability scoring: control risk per process is derived from actual test results, not design alone.
- Reliance logic: the platform links assessed control risk to the substantive testing each process requires.
- Exception workflow: processes with failing controls and high control risk are flagged for attention.
- Traceability to source: each process rating links to the underlying control tests and evidence.
Key Takeaways
- Control risk must rest on tested operation, not design on paper.
- A well-designed control that fails in operation is still high control risk.
- Assess per process so reliance follows where controls actually work.
- Lower control risk justifies less substantive testing, and vice versa.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
