PCAOB AS 2301: Identifying Risk Is Not Enough—The Auditor Must Respond to It
- John C. Blackshire, Jr.

- Aug 8
- 10 min read
Learn How to Translate Risk Assessment into Effective Audit Procedures
External auditors spend substantial time identifying and assessing risks of material misstatement.
But identifying the risk is only half the job.
The harder question is:
What are you going to do about it?
That question is the foundation of PCAOB Auditing Standard AS 2301 — The Auditor's Responses to the Risks of Material Misstatement.
PCAOB AS 2301 requires auditors to design and implement audit responses addressing the risks of material misstatement identified and assessed under PCAOB AS 2110.
Those responses include both changes affecting the overall conduct of the audit and changes to the nature, timing and extent of specific audit procedures.
Corporate Compliance Seminars' PCAOB AS 2301: The Auditor's Response to the Risks of Material Misstatements CPE webinar takes auditors beyond simply understanding the standard. The program focuses on applying AS 2301 to risk assessment, control testing, substantive procedures, significant risks, fraud risks, professional skepticism and audit documentation.
The Audit Risk Assessment Must Drive the Audit
A risk assessment should not be something prepared during planning and then filed away in the workpapers.
It should determine what the auditor does.
The logic should be:
Identify the risk → Assess the risk → Determine the relevant assertions → Design the audit response → Obtain evidence → Evaluate the evidence → Reach the conclusion
PCAOB AS 2301 establishes a direct connection between the risks identified under PCAOB AS 2110 and the procedures ultimately performed by the engagement team.
This sounds obvious.
In practice, it can be one of the most difficult parts of auditing.
An engagement team may identify revenue recognition as a significant risk and then perform essentially the same revenue procedures it performed the previous year.
That raises the critical PCAOB AS 2301 question:
How did the assessed risk actually change the audit response?
If the answer is unclear, the audit may have a risk-response problem.
PCAOB AS 2301 Is Where Risk Assessment Becomes Audit Work
Consider a company experiencing substantial pressure to meet quarterly earnings expectations.
The auditor identifies a heightened risk involving revenue cutoff.
The auditor should not merely write:
"Revenue cutoff represents a risk of material misstatement."
That documents the risk.
It does not address it.
The engagement team now needs to determine how that risk affects the audit procedures.
Should the auditor:
Increase sample sizes?
Examine transactions closer to year-end?
Expand procedures after year-end?
Examine unusual sales terms?
Review shipping documentation?
Inspect customer contracts?
Perform additional confirmations?
Examine subsequent credits and returns?
Test manual journal entries affecting revenue?
Increase unpredictability?
That is PCAOB AS 2301 in practice.
Higher Risk Should Produce More Persuasive Evidence
One of the most important concepts in PCAOB AS 2301 is the relationship between risk and audit evidence.
As risk increases, the auditor should think differently about the evidence necessary to address that risk.
The question should not be:
"Did we complete our audit program?"
It should be:
"Did the procedures we performed provide sufficient appropriate evidence for this level of risk?"
That distinction separates risk-based auditing from checklist auditing.
A procedure that provides reasonable assurance for a routine account may not provide sufficient assurance for a significant risk.
Nature, Timing and Extent Are Three Different Levers
PCAOB AS 2301 repeatedly brings auditors back to three fundamental elements:
Nature
What procedure will we perform?
For example:
Inquiry
Inspection
Observation
Confirmation
Recalculation
Reperformance
Analytical procedures
Timing
When will we perform it?
For example:
Interim
Year-end
After year-end
Throughout the period
Extent
How much testing will we perform?
For example:
Sample size
Number of locations
Number of transactions
Period covered
Amount of supporting evidence
The auditor can change any combination of these elements to develop a response appropriate to the assessed risk. PCAOB AS 2301 specifically addresses responses involving the nature, timing and extent of audit procedures.
Sometimes the Right Response Is to Assign a Better Auditor
One of the less-discussed requirements of PCAOB AS 2301 is particularly important for audit leaders.
The auditor's response to risk is not limited to testing.
PCAOB AS 2301 requires significant engagement responsibilities to be assigned to people whose knowledge, skill and ability are commensurate with the assessed risks. The standard also requires an appropriate level of supervision based on the circumstances and assessed risk.
Think about what that means.
If the engagement involves:
Complex derivatives
Difficult valuations
Cryptocurrency
Sophisticated IT systems
Significant cybersecurity dependencies
Complex revenue arrangements
Highly judgmental estimates
the answer may not simply be:
"Perform more testing."
The audit response may require: Different people.
More experienced auditors.
Specialists.
Greater partner involvement.
More intensive supervision.
A difficult risk assigned to an auditor who lacks the necessary competence creates an audit-quality risk before testing even begins.
Unpredictability Is Part of the Auditor's Response
Management knows auditors have routines.
Employees know what auditors normally request.
If auditors perform exactly the same procedures every year, those procedures become predictable.
PCAOB AS 2301 specifically requires auditors to incorporate an element of unpredictability into audit procedures as part of responding to assessed risks, including fraud risks.
The PCAOB provides examples such as:
Testing accounts or assertions that might not ordinarily be selected.
Changing the timing of procedures.
Selecting lower-dollar transactions.
Performing unannounced procedures.
Changing locations or procedures in multi-location audits.
This is especially important when addressing management override and fraud.
If management knows exactly what the auditor will test, management may know exactly what the auditor will not test.
Significant Risks Require Significant Thinking
Not all risks deserve identical audit responses.
When the auditor identifies a significant risk, the engagement team should be able to explain:
Why is this risk significant?
Which assertions are affected?
How could the material misstatement occur?
What controls address it?
Will we rely upon those controls?
What substantive procedures directly address the risk?
What evidence will be persuasive enough?
What contradictory evidence might exist?
What fraud considerations apply?
This is where professional judgment becomes critical.
Fraud Risk Changes the Audit Response
Fraud is different from error because fraud involves intentional behavior.
The person committing the fraud may:
Conceal evidence.
Override controls.
Create false documentation.
Collude with others.
Manipulate systems.
Provide misleading explanations.
The audit response must recognize that reality.
CCS's PCAOB AS 2301 course specifically includes responses to fraud risks as a major element of the program.
An auditor responding to fraud risk should therefore think beyond simply increasing a sample from 25 to 40.
The auditor should consider whether a different type of procedure is necessary.
Control Reliance Has to Be Earned
Suppose the auditor identifies a significant risk and decides to rely upon a management control.
That decision creates another requirement: Test the control.
PCAOB AS 2301 addresses control testing, assessment of control risk, substantive procedures and dual-purpose tests.
The auditor needs evidence supporting the reliance being placed on the control.
That requires understanding:
How the control operates.
Who performs it.
How frequently it operates.
What evidence exists.
Whether the control addresses the relevant assertion.
Whether information used by the control is reliable.
Whether deviations occurred.
Simply documenting that management has a control does not justify reducing substantive procedures.
A Control That Worked Last Year Has Not Passed This Year's Audit
Auditors need to be careful about becoming overly comfortable with longstanding controls.
Management may say:
"You've tested this control for five years."
That is not evidence that the control operated effectively this year.
Things change.
Personnel change.
Systems change.
Reports change.
Responsibilities change.
Business volumes change.
Management incentives change.
Processes become automated.
Controls become informal.
Workarounds develop.
Risk assessment and audit response therefore need to remain dynamic.
Substantive Procedures Still Matter
PCAOB AS 2301 does not allow auditors to assume that strong controls eliminate the need for substantive work.
The standard contains specific requirements for substantive procedures, and CCS's course devotes part of the agenda to substantive testing and audit evidence.
The engagement team should determine whether substantive procedures appropriately address:
Relevant assertions
Identified risks
Significant risks
Fraud risks
Evidence obtained from other procedures
Again, the question is not:
"Did we perform substantive testing?"
The question is:
"Did our substantive testing actually address the risk?"
Dual-Purpose Testing Can Improve Efficiency
Audit efficiency matters.
PCAOB AS 2301 recognizes situations involving dual-purpose tests, where a procedure may serve both as a test of controls and a substantive test.
CCS includes dual-purpose testing in the PCAOB AS 2301 curriculum.
When properly designed, this can make an audit more efficient.
But efficiency cannot come at the expense of evidence.
The auditor must understand exactly:
Which control objective is being tested.
Which substantive objective is being tested.
What evidence supports each conclusion.
One procedure can accomplish two objectives only when it has actually been designed to accomplish both.
Professional Skepticism Changes the Auditor's Response
Professional skepticism should affect what auditors do when the evidence does not fit their expectations.
Suppose management forecasts a 20% increase in sales.
The auditor asks why.
Management responds:
"We expect the market to improve."
A checklist auditor documents the explanation.
A skeptical auditor asks:
What evidence supports the market improvement?
What do current orders show?
What do customer forecasts show?
What do competitors report?
What happened after year-end?
What assumptions drive the forecast?
What happens if the assumption is wrong?
The difference is not hostility toward management.
It is evidence-based auditing.
CCS specifically identifies strengthening professional skepticism as one of the program's major objectives.
Contradictory Evidence Should Change the Audit
Suppose management's evidence supports a conclusion.
Then the auditor discovers another document that contradicts it.
That contradictory information should not be treated as an administrative inconvenience.
It may require:
Additional inquiry.
Expanded testing.
Different procedures.
Reconsideration of control reliance.
Reassessment of risk.
Consultation.
Modification of the audit conclusion.
One of the most important elements of audit tradecraft is recognizing when the evidence is telling the auditor:
Keep digging.
PCAOB AS 2301 and PCAOB AS 2201 Work Together
For integrated audits, PCAOB AS 2301 and PCAOB AS 2201 — An Audit of Internal Control Over Financial Reporting are closely connected.
PCAOB AS 2201 addresses whether controls over financial reporting are effectively designed and operating.
PCAOB AS 2301 addresses how the auditor responds to assessed risks through controls testing and substantive procedures.
The connection can be summarized as:
Risk identified
↓
Relevant assertion determined
↓
Controls identified
↓
Controls tested
↓
Control risk assessed
↓
Substantive procedures designed
↓
Evidence evaluated
↓
Audit conclusion reached
A weakness in control testing can therefore have consequences for the substantive audit strategy.
PCAOB AS 2301 Is Also an Audit Efficiency Standard
There is an important point that often gets missed.
Risk-based auditing is not simply about doing more work in high-risk areas.
It is also about doing less unnecessary work in lower-risk areas.
If auditors understand risk correctly, they can allocate their limited time toward the accounts, assertions, controls, transactions and estimates that matter most.
That can produce:
Better audit coverage.
Better evidence.
Greater partner attention on difficult areas.
Less unnecessary testing.
More efficient staff utilization.
Better audit quality.
The objective is not the largest audit file.
It is the right audit work.
AI Can Help Auditors Design Better Risk Responses
Artificial intelligence is becoming particularly useful during audit planning.
Using an approved AI environment, an engagement team may be able to:
Research industry risks.
Analyze prior-year findings.
Summarize contracts.
Identify potential fraud scenarios.
Generate potential misstatement scenarios.
Develop walkthrough questions.
Compare risks with proposed procedures.
Identify gaps in an audit program.
Analyze unusual transactions.
Develop alternative audit procedures.
Imagine providing an AI tool with an appropriately protected and authorized description of a revenue process and asking:
"Identify ten ways a material revenue overstatement could occur, identify the assertions affected, and suggest potential controls and substantive audit procedures for each risk."
That can be an excellent brainstorming tool.
But the AI has not performed the audit.
The auditor must determine whether those risks actually exist and whether the proposed procedures are appropriate.
AI can help design the response. The auditor remains responsible for the response.
Documentation Should Demonstrate the Connection
A good PCAOB AS 2301 workpaper should allow an experienced reviewer to see:
Risk → Response → Procedure → Evidence → Conclusion
The reviewer should not have to guess why a procedure was performed.
For every important risk, the audit documentation should make clear:
What the risk was.
Why it mattered.
Which assertions were affected.
What the auditor did.
Why those procedures were appropriate.
What evidence was obtained.
Whether contradictory evidence existed.
What conclusion was reached.
CCS specifically includes documentation requirements and best practices among the program's core topics.
Why PCAOB Inspection Findings Matter
The CCS program does something particularly useful for practicing auditors: it does not teach AS 2301 only as regulatory text.
The course also examines PCAOB inspection observations and the AS 2301 paragraphs auditors should focus on. The course materials identify AS 2301 as one of the most frequently cited standards in the inspection reports CCS analyzes.
That creates an important learning opportunity.
Auditors should not merely ask:
"What does PCAOB AS 2301 require?"
They should also ask:
"Where are other auditors getting PCAOB AS 2301 wrong?"
Inspection findings provide an opportunity to learn from somebody else's audit failure rather than your own.
What You'll Study in the CCS PCAOB AS 2301 CPE Webinar
The two-CPE program begins with the PCAOB auditing standards context and then moves into the practical concepts underlying PCAOB AS 2301.
Topics include:
Material misstatement
Audit risk assessment
Financial statement risk assessment
Inherent risk
Control risk
Detection risk
Audit risk
Substantive procedures
Audit evidence
Overall audit responses
Responses to significant risks
Responses to fraud risks
Testing controls
Assessing control risk
Substantive procedures
Dual-purpose tests
PCAOB inspection observations
Key PCAOB AS 2301 paragraphs requiring particular attention
The emphasis is on making auditors more efficient and more effective by designing holistic procedures responsive to identified risks and strengthening professional skepticism.
Who Should Attend?
The program is designed for professionals involved in public-company financial auditing and risk management, particularly:
External Auditors
Audit Associates
Senior Auditors
Audit Managers
Engagement Leaders
Financial Professionals
Compliance Professionals
SOX Professionals
The program is presented live as a Group Internet Based webinar, carries 2 NASBA-approved CPE credits in Auditing, is classified at the Basic level, and requires no prerequisites or advance preparation. CCS currently lists the program at $140 and notes that private sessions can be arranged for groups of two or more.
The Bottom Line: Make the Audit Response Match the Risk
The fundamental lesson of AS 2301 is straightforward:
Identifying a risk does not protect investors. Responding appropriately to that risk does.
Auditors need to be able to demonstrate:
We understood the risk.
We determined why it mattered.
We designed procedures specifically responsive to it.
We assigned people capable of performing those procedures.
We obtained persuasive evidence.
We challenged contradictory information.
We documented our reasoning.
We reached a conclusion supported by the evidence.
That is risk-based auditing.
And that is why PCAOB AS 2301 deserves considerably more attention than simply being another standard in the PCAOB manual.
Corporate Compliance Seminars' PCAOB AS 2301: The Auditor's Response to the Risks of Material Misstatements CPE webinar is designed to help external auditors understand that connection and apply it during real PCAOB engagements.
Comments