Eduints
Audit & Assurance

Audit Risk Assessment: Building a Risk Register

A blank risk register, five columns, and one instruction: fill it in. Before writing a single row, there’s one distinction that decides whether the register means anything at all.

Written by the Eduints teamPublished 1 October 2026

Business risk vs risk of material misstatement

A supplier could go bankrupt. Sales could fall. Those are business risks, and they matter — but they’re not what an audit risk register is for. This register is about risks of material misstatement: what could make the numbers in the financial statements wrong? A business risk only belongs on the register when it changes that.

Five columns, filled from what you already know

The area of the accounts. What could go wrong. The assertion at risk. And two ratings: how likely it is, and how big the misstatement could be. Each row needs a reason behind it that comes from something actually observed — that’s what makes a rating defensible, not just a guess dressed up as a number.

A worked example: goods dispatched after year-end but counted as this year’s sales — assertion: cut-off, a classic and often significant risk. A single customer carrying 31% of total receivables, with a recently raised credit limit — assertion: valuation, and with that concentration, both likelihood and magnitude rate high.

What makes a risk “significant”

Significant risks need special audit consideration. In practice that usually means fraud risks, risks from significant related-party transactions outside normal business, and areas with high estimation uncertainty. A risk can be unlikely and still be significant — a related-party supplier whose ownership was never confirmed might be low-probability, but if it’s real, it matters a great deal. Low likelihood, high magnitude is exactly the kind of risk that earns careful attention anyway.

Five things that raise inherent risk

When a rating needs a reason and none comes to mind, these five factors are the checklist to run through:

  • —Complexity — many steps, many systems, many calculations.
  • —Subjectivity — the number depends on judgment, like an estimate.
  • —Change — new products, new systems, or new people.
  • —Uncertainty — the outcome isn’t known yet, like a pending legal claim.
  • —Susceptibility to bias or fraud — an incentive or opportunity to distort the number, such as a bonus tied to a profit target.

If none of the five apply, the risk is probably lower than it first looks.

The mistake that erases the register’s purpose

A junior, worried about missing something, rates every single risk high. Asked what the register tells the team now, she says: that everything matters. It tells the team nothing — equal effort would go everywhere, and the areas that actually matter most would get lost in the noise. The entire point of rating risk is deciding where to spend a limited budget. A register where everything is a priority has no priorities.

A risk register is never finished

New evidence changes the register — a duplicate payment found later asks whether it changes the risk rating for purchases and payments, and the plan updates accordingly. Prior-year findings matter too: if last year’s auditor found a cut-off error, that raises this year’s likelihood rating for cut-off, unless the underlying process (not just the one journal entry) has demonstrably changed. A register nobody updates is only a record of what the team knew in week one.

This guide illustrates standard audit risk-assessment concepts using a fictional teaching case. It is practical educational content, not professional audit guidance — a real engagement team builds and documents its own risk register for an actual client.

Go deeper with the full engagement

This risk-assessment framework is Lesson 8 of Advanced Audit & Assurance, one module inside a full fictional engagement — from accepting the client through planning, testing, and forming the final opinion.

Have a question this guide didn’t answer? See the full FAQ or contact us directly.