Back to Explore
⚠️

Audit Risk Model

Control Risk by Process

Assessed control risk for each major business process based on tested control reliability.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why control risk follows tested reliability

Control risk, the chance that a misstatement is not prevented or detected by controls, can only be assessed credibly from evidence of how controls actually perform, not from how they are designed on paper. The ISSAI audit risk model uses control risk to determine how much substantive testing each process needs. AuditPro Core assesses control risk per major process from tested control reliability so reliance decisions rest on results, not optimism.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Processes assessed

16

Low control risk

6

reliance possible

High control risk

5

substantive focus

Controls relied on

61%

▲ 4%

Control risk rating by process

Control reliance decision by process

ProcessControls testedControl riskAudit approach
Procurement224.1Substantive
Billing & revenue183.4Combined
Payroll142.6Controls reliance
Asset management163.9Substantive
Grants & transfers123.2Combined

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Control risk defined

Control risk is the risk that controls fail to prevent or detect a material misstatement. It is lower where controls are proven reliable and higher where they are untested or failing.

Tested reliability

Reliability is established by testing the control's operation over the period, not by reviewing its design. A well-designed control that fails in operation carries high control risk.

Process-level assessment

Control risk varies by process; procurement may be reliable while payroll is weak. Assessing per process directs substantive effort to the processes least able to be relied upon.

Effect on substantive work

Lower control risk justifies less substantive testing and vice versa. The assessment is the lever that balances controls reliance against detailed verification.

How AuditPro Core Bridges the Gap

  • Reliability scoring: control risk per process is derived from actual test results, not design alone.
  • Reliance logic: the platform links assessed control risk to the substantive testing each process requires.
  • Exception workflow: processes with failing controls and high control risk are flagged for attention.
  • Traceability to source: each process rating links to the underlying control tests and evidence.

Key Takeaways

  • Control risk must rest on tested operation, not design on paper.
  • A well-designed control that fails in operation is still high control risk.
  • Assess per process so reliance follows where controls actually work.
  • Lower control risk justifies less substantive testing, and vice versa.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.