top of page
Search

PCAOB AS 2301: Identifying Risk Is Not Enough—The Auditor Must Respond to It

Aug 8
10 min read

Learn How to Translate Risk Assessment into Effective Audit Procedures


External auditors spend substantial time identifying and assessing risks of material misstatement.


But identifying the risk is only half the job.


The harder question is:

What are you going to do about it?

That question is the foundation of PCAOB Auditing Standard AS 2301 — The Auditor's Responses to the Risks of Material Misstatement.


PCAOB AS 2301 requires auditors to design and implement audit responses addressing the risks of material misstatement identified and assessed under PCAOB AS 2110.


Those responses include both changes affecting the overall conduct of the audit and changes to the nature, timing and extent of specific audit procedures.


Corporate Compliance Seminars' PCAOB AS 2301: The Auditor's Response to the Risks of Material Misstatements CPE webinar takes auditors beyond simply understanding the standard. The program focuses on applying AS 2301 to risk assessment, control testing, substantive procedures, significant risks, fraud risks, professional skepticism and audit documentation.



The Audit Risk Assessment Must Drive the Audit

A risk assessment should not be something prepared during planning and then filed away in the workpapers.


It should determine what the auditor does.


The logic should be:

Identify the risk → Assess the risk → Determine the relevant assertions → Design the audit response → Obtain evidence → Evaluate the evidence → Reach the conclusion


PCAOB AS 2301 establishes a direct connection between the risks identified under PCAOB AS 2110 and the procedures ultimately performed by the engagement team.


This sounds obvious.


In practice, it can be one of the most difficult parts of auditing.


An engagement team may identify revenue recognition as a significant risk and then perform essentially the same revenue procedures it performed the previous year.


That raises the critical PCAOB AS 2301 question:

How did the assessed risk actually change the audit response?

If the answer is unclear, the audit may have a risk-response problem.


PCAOB AS 2301 Is Where Risk Assessment Becomes Audit Work


Consider a company experiencing substantial pressure to meet quarterly earnings expectations.


The auditor identifies a heightened risk involving revenue cutoff.


The auditor should not merely write:

"Revenue cutoff represents a risk of material misstatement."

That documents the risk.

It does not address it.


The engagement team now needs to determine how that risk affects the audit procedures.


Should the auditor:

  • Increase sample sizes?

  • Examine transactions closer to year-end?

  • Expand procedures after year-end?

  • Examine unusual sales terms?

  • Review shipping documentation?

  • Inspect customer contracts?

  • Perform additional confirmations?

  • Examine subsequent credits and returns?

  • Test manual journal entries affecting revenue?

  • Increase unpredictability?


That is PCAOB AS 2301 in practice.


Higher Risk Should Produce More Persuasive Evidence


One of the most important concepts in PCAOB AS 2301 is the relationship between risk and audit evidence.


As risk increases, the auditor should think differently about the evidence necessary to address that risk.


The question should not be:

"Did we complete our audit program?"

It should be:

"Did the procedures we performed provide sufficient appropriate evidence for this level of risk?"

That distinction separates risk-based auditing from checklist auditing.


A procedure that provides reasonable assurance for a routine account may not provide sufficient assurance for a significant risk.


Nature, Timing and Extent Are Three Different Levers


PCAOB AS 2301 repeatedly brings auditors back to three fundamental elements:


Nature

What procedure will we perform?


For example:

  • Inquiry

  • Inspection

  • Observation

  • Confirmation

  • Recalculation

  • Reperformance

  • Analytical procedures


Timing

When will we perform it?


For example:

  • Interim

  • Year-end

  • After year-end

  • Throughout the period


Extent

How much testing will we perform?


For example:

  • Sample size

  • Number of locations

  • Number of transactions

  • Period covered

  • Amount of supporting evidence


The auditor can change any combination of these elements to develop a response appropriate to the assessed risk. PCAOB AS 2301 specifically addresses responses involving the nature, timing and extent of audit procedures.


Sometimes the Right Response Is to Assign a Better Auditor


One of the less-discussed requirements of PCAOB AS 2301 is particularly important for audit leaders.


The auditor's response to risk is not limited to testing.


PCAOB AS 2301 requires significant engagement responsibilities to be assigned to people whose knowledge, skill and ability are commensurate with the assessed risks. The standard also requires an appropriate level of supervision based on the circumstances and assessed risk.


Think about what that means.


If the engagement involves:

  • Complex derivatives

  • Difficult valuations

  • Cryptocurrency

  • Sophisticated IT systems

  • Significant cybersecurity dependencies

  • Complex revenue arrangements

  • Highly judgmental estimates

the answer may not simply be:

"Perform more testing."

The audit response may require: Different people.


More experienced auditors.


Specialists.


Greater partner involvement.


More intensive supervision.


A difficult risk assigned to an auditor who lacks the necessary competence creates an audit-quality risk before testing even begins.


Unpredictability Is Part of the Auditor's Response


Management knows auditors have routines.


Employees know what auditors normally request.


If auditors perform exactly the same procedures every year, those procedures become predictable.


PCAOB AS 2301 specifically requires auditors to incorporate an element of unpredictability into audit procedures as part of responding to assessed risks, including fraud risks.


The PCAOB provides examples such as:

  • Testing accounts or assertions that might not ordinarily be selected.

  • Changing the timing of procedures.

  • Selecting lower-dollar transactions.

  • Performing unannounced procedures.

  • Changing locations or procedures in multi-location audits.


This is especially important when addressing management override and fraud.


If management knows exactly what the auditor will test, management may know exactly what the auditor will not test.


Significant Risks Require Significant Thinking


Not all risks deserve identical audit responses.


When the auditor identifies a significant risk, the engagement team should be able to explain:

  • Why is this risk significant?

  • Which assertions are affected?

  • How could the material misstatement occur?

  • What controls address it?

  • Will we rely upon those controls?

  • What substantive procedures directly address the risk?

  • What evidence will be persuasive enough?

  • What contradictory evidence might exist?

  • What fraud considerations apply?


This is where professional judgment becomes critical.


Fraud Risk Changes the Audit Response


Fraud is different from error because fraud involves intentional behavior.


The person committing the fraud may:

  • Conceal evidence.

  • Override controls.

  • Create false documentation.

  • Collude with others.

  • Manipulate systems.

  • Provide misleading explanations.


The audit response must recognize that reality.


CCS's PCAOB AS 2301 course specifically includes responses to fraud risks as a major element of the program.


An auditor responding to fraud risk should therefore think beyond simply increasing a sample from 25 to 40.


The auditor should consider whether a different type of procedure is necessary.


Control Reliance Has to Be Earned


Suppose the auditor identifies a significant risk and decides to rely upon a management control.


That decision creates another requirement: Test the control.


PCAOB AS 2301 addresses control testing, assessment of control risk, substantive procedures and dual-purpose tests.


The auditor needs evidence supporting the reliance being placed on the control.


That requires understanding:

  • How the control operates.

  • Who performs it.

  • How frequently it operates.

  • What evidence exists.

  • Whether the control addresses the relevant assertion.

  • Whether information used by the control is reliable.

  • Whether deviations occurred.


Simply documenting that management has a control does not justify reducing substantive procedures.


A Control That Worked Last Year Has Not Passed This Year's Audit


Auditors need to be careful about becoming overly comfortable with longstanding controls.


Management may say:

"You've tested this control for five years."

That is not evidence that the control operated effectively this year.


Things change.

  • Personnel change.

  • Systems change.

  • Reports change.

  • Responsibilities change.

  • Business volumes change.

  • Management incentives change.

  • Processes become automated.

  • Controls become informal.

  • Workarounds develop.


Risk assessment and audit response therefore need to remain dynamic.


Substantive Procedures Still Matter

PCAOB AS 2301 does not allow auditors to assume that strong controls eliminate the need for substantive work.


The standard contains specific requirements for substantive procedures, and CCS's course devotes part of the agenda to substantive testing and audit evidence.


The engagement team should determine whether substantive procedures appropriately address:

  • Relevant assertions

  • Identified risks

  • Significant risks

  • Fraud risks

  • Evidence obtained from other procedures


Again, the question is not:

"Did we perform substantive testing?"

The question is:

"Did our substantive testing actually address the risk?"

Dual-Purpose Testing Can Improve Efficiency


Audit efficiency matters.


PCAOB AS 2301 recognizes situations involving dual-purpose tests, where a procedure may serve both as a test of controls and a substantive test.


CCS includes dual-purpose testing in the PCAOB AS 2301 curriculum.


When properly designed, this can make an audit more efficient.


But efficiency cannot come at the expense of evidence.


The auditor must understand exactly:

  • Which control objective is being tested.

  • Which substantive objective is being tested.

  • What evidence supports each conclusion.


One procedure can accomplish two objectives only when it has actually been designed to accomplish both.


Professional Skepticism Changes the Auditor's Response


Professional skepticism should affect what auditors do when the evidence does not fit their expectations.


Suppose management forecasts a 20% increase in sales.


The auditor asks why.


Management responds:

"We expect the market to improve."

A checklist auditor documents the explanation.


A skeptical auditor asks:

  • What evidence supports the market improvement?

  • What do current orders show?

  • What do customer forecasts show?

  • What do competitors report?

  • What happened after year-end?

  • What assumptions drive the forecast?

  • What happens if the assumption is wrong?


The difference is not hostility toward management.


It is evidence-based auditing.


CCS specifically identifies strengthening professional skepticism as one of the program's major objectives.


Contradictory Evidence Should Change the Audit


Suppose management's evidence supports a conclusion.


Then the auditor discovers another document that contradicts it.


That contradictory information should not be treated as an administrative inconvenience.


It may require:

  • Additional inquiry.

  • Expanded testing.

  • Different procedures.

  • Reconsideration of control reliance.

  • Reassessment of risk.

  • Consultation.

  • Modification of the audit conclusion.


One of the most important elements of audit tradecraft is recognizing when the evidence is telling the auditor:

Keep digging.

PCAOB AS 2301 and PCAOB AS 2201 Work Together


For integrated audits, PCAOB AS 2301 and PCAOB AS 2201 — An Audit of Internal Control Over Financial Reporting are closely connected.


PCAOB AS 2201 addresses whether controls over financial reporting are effectively designed and operating.


PCAOB AS 2301 addresses how the auditor responds to assessed risks through controls testing and substantive procedures.


The connection can be summarized as:


Risk identified

Relevant assertion determined

Controls identified

Controls tested

Control risk assessed

Substantive procedures designed

Evidence evaluated

Audit conclusion reached


A weakness in control testing can therefore have consequences for the substantive audit strategy.


PCAOB AS 2301 Is Also an Audit Efficiency Standard


There is an important point that often gets missed.


Risk-based auditing is not simply about doing more work in high-risk areas.


It is also about doing less unnecessary work in lower-risk areas.


If auditors understand risk correctly, they can allocate their limited time toward the accounts, assertions, controls, transactions and estimates that matter most.


That can produce:

  • Better audit coverage.

  • Better evidence.

  • Greater partner attention on difficult areas.

  • Less unnecessary testing.

  • More efficient staff utilization.

  • Better audit quality.


The objective is not the largest audit file.


It is the right audit work.


AI Can Help Auditors Design Better Risk Responses


Artificial intelligence is becoming particularly useful during audit planning.


Using an approved AI environment, an engagement team may be able to:

  • Research industry risks.

  • Analyze prior-year findings.

  • Summarize contracts.

  • Identify potential fraud scenarios.

  • Generate potential misstatement scenarios.

  • Develop walkthrough questions.

  • Compare risks with proposed procedures.

  • Identify gaps in an audit program.

  • Analyze unusual transactions.

  • Develop alternative audit procedures.


Imagine providing an AI tool with an appropriately protected and authorized description of a revenue process and asking:

"Identify ten ways a material revenue overstatement could occur, identify the assertions affected, and suggest potential controls and substantive audit procedures for each risk."

That can be an excellent brainstorming tool.


But the AI has not performed the audit.


The auditor must determine whether those risks actually exist and whether the proposed procedures are appropriate.


AI can help design the response. The auditor remains responsible for the response.


Documentation Should Demonstrate the Connection


A good PCAOB AS 2301 workpaper should allow an experienced reviewer to see:


Risk → Response → Procedure → Evidence → Conclusion


The reviewer should not have to guess why a procedure was performed.


For every important risk, the audit documentation should make clear:

  • What the risk was.

  • Why it mattered.

  • Which assertions were affected.

  • What the auditor did.

  • Why those procedures were appropriate.

  • What evidence was obtained.

  • Whether contradictory evidence existed.

  • What conclusion was reached.


CCS specifically includes documentation requirements and best practices among the program's core topics.


Why PCAOB Inspection Findings Matter

The CCS program does something particularly useful for practicing auditors: it does not teach AS 2301 only as regulatory text.


The course also examines PCAOB inspection observations and the AS 2301 paragraphs auditors should focus on. The course materials identify AS 2301 as one of the most frequently cited standards in the inspection reports CCS analyzes.


That creates an important learning opportunity.


Auditors should not merely ask:

"What does PCAOB AS 2301 require?"

They should also ask:

"Where are other auditors getting PCAOB AS 2301 wrong?"

Inspection findings provide an opportunity to learn from somebody else's audit failure rather than your own.


What You'll Study in the CCS PCAOB AS 2301 CPE Webinar


The two-CPE program begins with the PCAOB auditing standards context and then moves into the practical concepts underlying PCAOB AS 2301.


Topics include:

  • Material misstatement

  • Audit risk assessment

  • Financial statement risk assessment

  • Inherent risk

  • Control risk

  • Detection risk

  • Audit risk

  • Substantive procedures

  • Audit evidence

  • Overall audit responses

  • Responses to significant risks

  • Responses to fraud risks

  • Testing controls

  • Assessing control risk

  • Substantive procedures

  • Dual-purpose tests

  • PCAOB inspection observations

  • Key PCAOB AS 2301 paragraphs requiring particular attention


The emphasis is on making auditors more efficient and more effective by designing holistic procedures responsive to identified risks and strengthening professional skepticism.


Who Should Attend?

The program is designed for professionals involved in public-company financial auditing and risk management, particularly:

  • External Auditors

  • Audit Associates

  • Senior Auditors

  • Audit Managers

  • Engagement Leaders

  • Financial Professionals

  • Compliance Professionals

  • SOX Professionals


The program is presented live as a Group Internet Based webinar, carries 2 NASBA-approved CPE credits in Auditing, is classified at the Basic level, and requires no prerequisites or advance preparation. CCS currently lists the program at $140 and notes that private sessions can be arranged for groups of two or more.


The Bottom Line: Make the Audit Response Match the Risk


The fundamental lesson of AS 2301 is straightforward:

Identifying a risk does not protect investors. Responding appropriately to that risk does.

Auditors need to be able to demonstrate:

  • We understood the risk.

  • We determined why it mattered.

  • We designed procedures specifically responsive to it.

  • We assigned people capable of performing those procedures.

  • We obtained persuasive evidence.

  • We challenged contradictory information.

  • We documented our reasoning.

  • We reached a conclusion supported by the evidence.


That is risk-based auditing.


And that is why PCAOB AS 2301 deserves considerably more attention than simply being another standard in the PCAOB manual.


Corporate Compliance Seminars' PCAOB AS 2301: The Auditor's Response to the Risks of Material Misstatements CPE webinar is designed to help external auditors understand that connection and apply it during real PCAOB engagements.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page