Back to Explore
🏷️

Audit Risk Model

Significant Risks Register

Risks designated as significant under the audit standards, with rationale and planned procedures.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why a significant risks register matters

The audit standards require auditors to identify significant risks, those warranting special audit consideration, and to design specific responses to each, with the rationale documented and reviewable. A dedicated register of significant risks, their justification and planned procedures is core evidence of compliant risk-based auditing under the ISAs and ISSAIs. AuditPro Core maintains the significant-risks register with rationale and linked procedures so the audit's most demanding judgements are transparent to reviewers and the AGSA.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Significant risks

7

Presumed fraud risks

2

revenue & override

Procedures designed

100%

Open at planning

7

Significant risks by category

Designation rationale

Significant riskTypeAssertionProcedures
Revenue cut-offFraudCut-off6
Journal overrideFraudOccurrence5
Tender splittingInherentOccurrence7
Impairment estimateInherentValuation4
Going concernInherentDisclosure3

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Significant risk

A significant risk is an identified risk of material misstatement that, in the auditor's judgement, requires special audit consideration. Designation triggers specific obligations the auditor cannot meet through ordinary procedures alone.

Documented rationale

Each significant-risk designation must record why the risk meets the threshold, considering factors such as complexity, fraud potential and significant judgement. The rationale is what makes the judgement auditable.

Tailored procedures

Significant risks demand responsive procedures designed specifically for them, and the auditor cannot rely on controls testing alone without also performing substantive work. Generic testing is insufficient.

Fraud and judgement risks

Risks involving fraud, significant non-routine transactions or substantial management judgement are commonly significant. In the public sector these often include irregular expenditure and complex grant arrangements.

How AuditPro Core Bridges the Gap

  • Designation rationale: each significant risk records the documented basis for its classification under the standards.
  • Procedure linkage: every significant risk links to the specific planned procedures designed to address it.
  • Completeness checks: the register flags significant risks lacking a tailored response so none go unaddressed.
  • Audit-ready file: the register exports as engagement-file evidence for quality review and AGSA scrutiny.

Key Takeaways

  • Significant risks require special audit consideration and tailored procedures.
  • Document the rationale; it is what makes the judgement auditable.
  • Controls testing alone is insufficient for a significant risk.
  • Fraud, judgement and non-routine transactions commonly qualify.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.