Audit Risk Model
Significant Risks Register
Risks designated as significant under the audit standards, with rationale and planned procedures.
Why a significant risks register matters
The audit standards require auditors to identify significant risks, those warranting special audit consideration, and to design specific responses to each, with the rationale documented and reviewable. A dedicated register of significant risks, their justification and planned procedures is core evidence of compliant risk-based auditing under the ISAs and ISSAIs. AuditPro Core maintains the significant-risks register with rationale and linked procedures so the audit's most demanding judgements are transparent to reviewers and the AGSA.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Significant risks
7
Presumed fraud risks
2
revenue & override
Procedures designed
100%
Open at planning
7
Significant risks by category
Designation rationale
| Significant risk | Type | Assertion | Procedures |
|---|---|---|---|
| Revenue cut-off | Fraud | Cut-off | 6 |
| Journal override | Fraud | Occurrence | 5 |
| Tender splitting | Inherent | Occurrence | 7 |
| Impairment estimate | Inherent | Valuation | 4 |
| Going concern | Inherent | Disclosure | 3 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Significant risk
A significant risk is an identified risk of material misstatement that, in the auditor's judgement, requires special audit consideration. Designation triggers specific obligations the auditor cannot meet through ordinary procedures alone.
Documented rationale
Each significant-risk designation must record why the risk meets the threshold, considering factors such as complexity, fraud potential and significant judgement. The rationale is what makes the judgement auditable.
Tailored procedures
Significant risks demand responsive procedures designed specifically for them, and the auditor cannot rely on controls testing alone without also performing substantive work. Generic testing is insufficient.
Fraud and judgement risks
Risks involving fraud, significant non-routine transactions or substantial management judgement are commonly significant. In the public sector these often include irregular expenditure and complex grant arrangements.
How AuditPro Core Bridges the Gap
- Designation rationale: each significant risk records the documented basis for its classification under the standards.
- Procedure linkage: every significant risk links to the specific planned procedures designed to address it.
- Completeness checks: the register flags significant risks lacking a tailored response so none go unaddressed.
- Audit-ready file: the register exports as engagement-file evidence for quality review and AGSA scrutiny.
Key Takeaways
- Significant risks require special audit consideration and tailored procedures.
- Document the rationale; it is what makes the judgement auditable.
- Controls testing alone is insufficient for a significant risk.
- Fraud, judgement and non-routine transactions commonly qualify.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
