Achievable logoAchievable logo
CMA Part 1
Sign in
Sign up
Purchase
Textbook
Practice exams
Support
How it works
Exam catalog
Mountain with a flag at the peak
Textbook
1. External financial reporting decisions
2. Planning, budgeting, and forecasting
3. Performance management
4. Cost management
5. Internal control
5.1 Governance, risk and compliance
5.1.1 Internal control objectives and the COSO Framework
5.1.2 Responsibility for internal control and segregation of duties
5.1.3 Internal control limitations, risks, and deficiencies
5.1.4 Corporate governance structure and responsibilities
5.1.5 Corporate governance roles and responsibilities
5.1.6 External audit
5.1.7 The Sarbanes-oxley Act
5.1.8 Other regulatory bodies
5.2 System controls and security measures
6. Technology and analytics
Achievable logoAchievable logo
5.1.6 External audit
Achievable CMA Part 1
5. Internal control
5.1. Governance, risk and compliance
Our CMA Part 1 course is currently in development and is a work-in-progress.

External audit

6 min read
Font
Discuss
Share
Feedback

Learning outcome statements

The learning outcome statements relevant for this section are:

  1. define inherent risk, control risk, and detection risk
  2. demonstrate an understanding of external auditor responsibilities, including the types of audit opinions that external auditors issue

External audit

External auditors are independent professionals or firms engaged to examine an organization’s financial statements and express an opinion on their fairness and conformity with applicable accounting standards, typically Generally Accepted Accounting Principles (GAAP) or International Financial Reporting Standards (IFRS). Their core responsibilities include planning and conducting audits, assessing the risk of material misstatement, testing internal controls, evaluating accounting estimates, and forming a professional judgment on whether the financial statements are free from material misstatement.

In the United States, these responsibilities are governed by auditing standards issued by the Public Company Accounting Oversight Board (PCAOB) for audits of public companies, and by the AICPA’s Auditing Standards Board (ASB) for private entities. Additionally, under the Sarbanes-Oxley Act of 2002 (SOX), auditors of publicly traded companies must evaluate and report on the effectiveness of internal control over financial reporting (Section 404).

By adhering to regulatory standards and maintaining independence from management, external auditors help promote transparency, accountability, and trust in financial reporting. Their work provides assurance to shareholders, regulators, creditors, and the investing public.

Prominent examples of external audit firms include the “Big Four”:

  • Deloitte
  • PricewaterhouseCoopers (PwC)
  • Ernst & Young (EY)
  • KPMG

These firms serve global clients and are known for their audit, tax, advisory, and risk consulting services.

Reasonable assurance

Auditors do not guarantee absolute accuracy or the complete absence of misstatements. Instead, they aim to provide reasonable assurance, which is a high, but not absolute, level of confidence that the financial statements are free from material misstatement. Reasonable assurance recognizes that audits are conducted within the limits of time, cost, and available evidence, and that judgment is involved in both performing audit procedures and interpreting results.

Audit risk and components

A core concept in external auditing is audit risk.

Definitions
Audit risk
The possibility that the auditor may unknowingly fail to appropriately modify their opinion on financial statements that are materially misstated.

In other words, despite conducting an audit in accordance with professional standards, there remains a risk that the auditor will issue an unqualified opinion on financial statements that contain significant errors or fraud.

Audit risk is composed of three interrelated components:

Inherent Risk

The susceptibility of an assertion to a material misstatement, assuming no related controls are in place. This risk arises from the nature of the business, industry conditions, complexity of transactions, and level of judgment involved. For example, companies in high-tech or financial sectors with rapidly changing environments or reliance on estimates and assumptions may have higher inherent risk.

Control Risk

The risk that a material misstatement will not be prevented or detected and corrected on a timely basis by the entity’s internal control system. Control risk depends on the design and operating effectiveness of internal controls. Weak or poorly implemented controls increase the likelihood that errors or fraud may occur and remain undetected.

Detection Risk

The risk that the auditor’s own procedures will not detect a material misstatement that exists. Detection risk is influenced by the nature and extent of audit procedures, auditor judgment, and the possibility of sampling errors. Auditors try to keep detection risk low by designing appropriate audit tests, using professional skepticism, and ensuring sufficient audit evidence is obtained.

These risks are commonly visualized in the Audit Risk Model:

Audit Risk (AR)=Inherent Risk (IR)×Control Risk (CR)×Detection Risk (DR)

Risk of Material Misstatement (RMM)=IR×CR.

This is assessed by the auditor during planning phase of the audit to tailor the audit procedures.

Audit responses to RMM

If RMM is high, auditors increase the nature, timing, and extent of their audit procedures: e.g., more detailed testing, performing procedures at year-end instead of interim, or using more experienced staff.

If RMM is low, auditors may rely more on internal controls and reduce substantive procedures.

Types of audit opinions

At the conclusion of the audit, the external auditor issues an audit opinion. Types include:

  • Unqualified opinion: The financial statements present fairly, in all material respects, in accordance with the applicable financial reporting framework. This is the most favorable outcome and indicates that the financial statements are reliable. For companies, it enhances investor confidence and may positively influence credit ratings and share price.
  • Qualified opinion: The auditor concludes that, except for a specific issue, the financial statements are fairly presented. This issue is material but not pervasive. While the financial statements are mostly accurate, the qualification can raise concerns among investors or lenders, prompting follow-up questions about the nature of the issue.
  • Adverse opinion: The auditor determines that the financial statements contain material and pervasive misstatements and do not present a true and fair view. This is the most serious type of opinion and can severely damage a company’s credibility, trigger regulatory investigations, and negatively affect market value and stakeholder trust.
  • Disclaimer of opinion: The auditor is unable to obtain sufficient appropriate audit evidence and thus does not express an opinion on the financial statements. This often results from limitations on audit scope or unresolved uncertainties. A disclaimer can lead to significant doubt about the integrity of the company’s financial reporting and may hinder its ability to attract investment or financing.

Emerging risks for external auditors

In today’s rapidly evolving business environment, external auditors face new and growing risks:

  • Cybersecurity threats and digital fraud
  • ESG disclosures (Environmental, Social, and Governance) requiring assurance
  • Complex global transactions and evolving accounting standards
  • Pressure to deliver audits under tight deadlines or resource constraints
  • Maintaining independence and avoiding conflicts of interest in an era of expanding advisory services

Understanding the responsibilities, risks, and methods of external auditors gives students a clearer picture of how independent assurance is provided in financial reporting. In the next sections, we will explore key regulations such as the Sarbanes-Oxley Act (SOX), the role of the PCAOB, and anti-corruption compliance under the FCPA.

External audit

  • Independent examination of financial statements for fairness and conformity (GAAP/IFRS)
  • Responsibilities: plan/conduct audits, assess risk, test controls, evaluate estimates, form audit opinion
  • Governed by PCAOB (public companies), ASB (private), SOX Section 404 (internal controls)

Reasonable assurance

  • High, but not absolute, confidence in financial statements
  • Audits limited by time, cost, evidence, and professional judgment

Audit risk and components

  • Audit risk: possibility auditor fails to modify opinion on materially misstated statements
  • Audit Risk Model:
    • Audit Risk (AR) = Inherent Risk (IR) × Control Risk (CR) × Detection Risk (DR)

    • Risk of Material Misstatement (RMM) = IR × CR

    • Inherent Risk: risk of misstatement without controls; driven by business nature, complexity, estimates

    • Control Risk: risk internal controls fail to prevent/detect/correct misstatements

    • Detection Risk: risk auditor’s procedures miss existing misstatements

Audit responses to RMM

  • High RMM: increase audit procedures (more tests, year-end work, experienced staff)
  • Low RMM: rely more on internal controls, reduce substantive procedures

Types of audit opinions

  • Unqualified opinion: statements fairly presented; most favorable
  • Qualified opinion: fairly presented except for specific material issue
  • Adverse opinion: statements materially/pervasively misstated; most serious
  • Disclaimer of opinion: insufficient evidence; no opinion expressed

Emerging risks for external auditors

  • Cybersecurity and digital fraud
  • ESG disclosure assurance
  • Complex global transactions, evolving standards
  • Tight deadlines, resource constraints
  • Maintaining independence amid advisory services

Sign up for free to take 10 quiz questions on this topic

Previous
Next  | 5.1.7 The Sarbanes-oxley Act
All rights reserved ©2016 - 2026 Achievable, Inc.

External audit

Learning outcome statements

The learning outcome statements relevant for this section are:

  1. define inherent risk, control risk, and detection risk
  2. demonstrate an understanding of external auditor responsibilities, including the types of audit opinions that external auditors issue

External audit

External auditors are independent professionals or firms engaged to examine an organization’s financial statements and express an opinion on their fairness and conformity with applicable accounting standards, typically Generally Accepted Accounting Principles (GAAP) or International Financial Reporting Standards (IFRS). Their core responsibilities include planning and conducting audits, assessing the risk of material misstatement, testing internal controls, evaluating accounting estimates, and forming a professional judgment on whether the financial statements are free from material misstatement.

In the United States, these responsibilities are governed by auditing standards issued by the Public Company Accounting Oversight Board (PCAOB) for audits of public companies, and by the AICPA’s Auditing Standards Board (ASB) for private entities. Additionally, under the Sarbanes-Oxley Act of 2002 (SOX), auditors of publicly traded companies must evaluate and report on the effectiveness of internal control over financial reporting (Section 404).

By adhering to regulatory standards and maintaining independence from management, external auditors help promote transparency, accountability, and trust in financial reporting. Their work provides assurance to shareholders, regulators, creditors, and the investing public.

Prominent examples of external audit firms include the “Big Four”:

  • Deloitte
  • PricewaterhouseCoopers (PwC)
  • Ernst & Young (EY)
  • KPMG

These firms serve global clients and are known for their audit, tax, advisory, and risk consulting services.

Reasonable assurance

Auditors do not guarantee absolute accuracy or the complete absence of misstatements. Instead, they aim to provide reasonable assurance, which is a high, but not absolute, level of confidence that the financial statements are free from material misstatement. Reasonable assurance recognizes that audits are conducted within the limits of time, cost, and available evidence, and that judgment is involved in both performing audit procedures and interpreting results.

Audit risk and components

A core concept in external auditing is audit risk.

Definitions
Audit risk
The possibility that the auditor may unknowingly fail to appropriately modify their opinion on financial statements that are materially misstated.

In other words, despite conducting an audit in accordance with professional standards, there remains a risk that the auditor will issue an unqualified opinion on financial statements that contain significant errors or fraud.

Audit risk is composed of three interrelated components:

Inherent Risk

The susceptibility of an assertion to a material misstatement, assuming no related controls are in place. This risk arises from the nature of the business, industry conditions, complexity of transactions, and level of judgment involved. For example, companies in high-tech or financial sectors with rapidly changing environments or reliance on estimates and assumptions may have higher inherent risk.

Control Risk

The risk that a material misstatement will not be prevented or detected and corrected on a timely basis by the entity’s internal control system. Control risk depends on the design and operating effectiveness of internal controls. Weak or poorly implemented controls increase the likelihood that errors or fraud may occur and remain undetected.

Detection Risk

The risk that the auditor’s own procedures will not detect a material misstatement that exists. Detection risk is influenced by the nature and extent of audit procedures, auditor judgment, and the possibility of sampling errors. Auditors try to keep detection risk low by designing appropriate audit tests, using professional skepticism, and ensuring sufficient audit evidence is obtained.

These risks are commonly visualized in the Audit Risk Model:

Audit Risk (AR)=Inherent Risk (IR)×Control Risk (CR)×Detection Risk (DR)

Risk of Material Misstatement (RMM)=IR×CR.

This is assessed by the auditor during planning phase of the audit to tailor the audit procedures.

Audit responses to RMM

If RMM is high, auditors increase the nature, timing, and extent of their audit procedures: e.g., more detailed testing, performing procedures at year-end instead of interim, or using more experienced staff.

If RMM is low, auditors may rely more on internal controls and reduce substantive procedures.

Types of audit opinions

At the conclusion of the audit, the external auditor issues an audit opinion. Types include:

  • Unqualified opinion: The financial statements present fairly, in all material respects, in accordance with the applicable financial reporting framework. This is the most favorable outcome and indicates that the financial statements are reliable. For companies, it enhances investor confidence and may positively influence credit ratings and share price.
  • Qualified opinion: The auditor concludes that, except for a specific issue, the financial statements are fairly presented. This issue is material but not pervasive. While the financial statements are mostly accurate, the qualification can raise concerns among investors or lenders, prompting follow-up questions about the nature of the issue.
  • Adverse opinion: The auditor determines that the financial statements contain material and pervasive misstatements and do not present a true and fair view. This is the most serious type of opinion and can severely damage a company’s credibility, trigger regulatory investigations, and negatively affect market value and stakeholder trust.
  • Disclaimer of opinion: The auditor is unable to obtain sufficient appropriate audit evidence and thus does not express an opinion on the financial statements. This often results from limitations on audit scope or unresolved uncertainties. A disclaimer can lead to significant doubt about the integrity of the company’s financial reporting and may hinder its ability to attract investment or financing.

Emerging risks for external auditors

In today’s rapidly evolving business environment, external auditors face new and growing risks:

  • Cybersecurity threats and digital fraud
  • ESG disclosures (Environmental, Social, and Governance) requiring assurance
  • Complex global transactions and evolving accounting standards
  • Pressure to deliver audits under tight deadlines or resource constraints
  • Maintaining independence and avoiding conflicts of interest in an era of expanding advisory services

Understanding the responsibilities, risks, and methods of external auditors gives students a clearer picture of how independent assurance is provided in financial reporting. In the next sections, we will explore key regulations such as the Sarbanes-Oxley Act (SOX), the role of the PCAOB, and anti-corruption compliance under the FCPA.

Key points

External audit

  • Independent examination of financial statements for fairness and conformity (GAAP/IFRS)
  • Responsibilities: plan/conduct audits, assess risk, test controls, evaluate estimates, form audit opinion
  • Governed by PCAOB (public companies), ASB (private), SOX Section 404 (internal controls)

Reasonable assurance

  • High, but not absolute, confidence in financial statements
  • Audits limited by time, cost, evidence, and professional judgment

Audit risk and components

  • Audit risk: possibility auditor fails to modify opinion on materially misstated statements
  • Audit Risk Model:
    • Audit Risk (AR) = Inherent Risk (IR) × Control Risk (CR) × Detection Risk (DR)

    • Risk of Material Misstatement (RMM) = IR × CR

    • Inherent Risk: risk of misstatement without controls; driven by business nature, complexity, estimates

    • Control Risk: risk internal controls fail to prevent/detect/correct misstatements

    • Detection Risk: risk auditor’s procedures miss existing misstatements

Audit responses to RMM

  • High RMM: increase audit procedures (more tests, year-end work, experienced staff)
  • Low RMM: rely more on internal controls, reduce substantive procedures

Types of audit opinions

  • Unqualified opinion: statements fairly presented; most favorable
  • Qualified opinion: fairly presented except for specific material issue
  • Adverse opinion: statements materially/pervasively misstated; most serious
  • Disclaimer of opinion: insufficient evidence; no opinion expressed

Emerging risks for external auditors

  • Cybersecurity and digital fraud
  • ESG disclosure assurance
  • Complex global transactions, evolving standards
  • Tight deadlines, resource constraints
  • Maintaining independence amid advisory services

More from Governance, risk and compliance

  • Internal control objectives and the COSO Framework
  • Responsibility for internal control and segregation of duties
  • Internal control limitations, risks, and deficiencies
  • Corporate governance structure and responsibilities
  • Corporate governance roles and responsibilities