Published by Shah Teelani & Associates | PCAOB-Registered Audit Firm | Reg. No. 7161


Audit risk assessment techniques are the foundation of every PCAOB engagement. They determine which accounts get tested, what procedures get performed, and whether the audit opinion is supportable. Get risk assessment wrong and everything downstream is compromised.

If the risk assessment is wrong, the audit approach is also inherently wrong. Inspection and enforcement staff consistently challenge engagement teams on their identification of significant risks. Furthermore, an auditor’s failure to understand the client’s accounting procedures or policies is the most detrimental type of deficiency for future reporting quality.

PCAOB AS 2110, Identifying and Assessing Risks of Material Misstatement, governs the entire risk assessment process. The updated AS 2110, effective December 15, 2026, strengthens requirements around risk identification and assessment, emphasizing a more thorough understanding of the company and its environment to support audit procedures.

At Shah Teelani & Associates, we build audit risk assessment into every engagement from the first day of planning. This blog explains the key techniques and tools that PCAOB auditors must apply — and where inspection findings most commonly arise.


What Audit Risk Assessment Requires Under PCAOB Standards

AS 2110 establishes requirements for the process of identifying and assessing risks of material misstatement of the financial statements. It covers the auditor’s responsibilities for performing risk assessment procedures and for identifying and assessing risks using information obtained from those procedures.

Risk assessment under PCAOB standards is not a preliminary formality. It drives the entire audit approach. Every substantive procedure and every control test must link back to a specific risk identified during this phase. Moreover, the amended AS 2110 — effective December 15, 2026 — reinforces that this linkage must be explicit, documented, and traceable throughout the engagement file.

Therefore, risk assessment is both a technical process and a documentation obligation. Performing the work without recording the reasoning fails the PCAOB standard just as surely as not performing the work at all.


Technique 1 — Understanding the Entity and Its Environment

The first and most fundamental audit risk assessment technique is obtaining a thorough understanding of the company. This understanding covers six interconnected areas.

Industry and external environment. The auditor must understand the industry the company operates in — its competitive dynamics, regulatory requirements, and economic pressures. Industry-specific accounting risks, margin patterns, and revenue recognition practices all flow from this understanding.

Nature of the company. This includes the company’s operations, ownership structure, investments, financing arrangements, and financial reporting practices. Understanding how the business actually works is the prerequisite for identifying where financial statements might be misstated.

Accounting policies and practices. An auditor’s failure to understand the client’s accounting procedures or policies is the most detrimental deficiency type for future reporting quality. Auditors must understand not just what accounting policies management has adopted but whether those policies are appropriate for the company’s transactions and industry.

Objectives, strategies, and business risks. Management’s strategic goals create financial reporting risks. Aggressive growth targets create revenue recognition risk. Acquisitions create valuation and goodwill impairment risk. Understanding what management is trying to achieve helps auditors identify where financial statements are most likely to be misstated.

Financial performance measures. Key performance indicators, analyst expectations, bonus targets, and debt covenant thresholds all create incentives that affect financial reporting. Auditors must understand what metrics management monitors — and what pressure those metrics create.

Internal control environment. Understanding internal control at the entity level is required before the auditor can assess control risk at the assertion level. This includes the control environment, risk assessment processes, information systems, and monitoring activities.


Technique 2 — Inquiry Across Multiple Sources

Inquiry is a required risk assessment procedure under AS 2110. However, effective inquiry extends well beyond management. It targets a broad range of personnel — each of whom may have different perspectives on where risks exist.

AS 2110 requires the auditor to inquire of the audit committee, management, and others within the company about the risks of material misstatement. Other individuals to whom inquiries should be directed include employees with varying levels of authority, operating personnel not directly involved in financial reporting, and employees involved in initiating, recording, or processing transactions.

This breadth is intentional. Management may not disclose risks candidly — particularly where fraud risk exists. Employees at different levels often observe inconsistencies, pressures, or unusual transactions that management does not surface. Therefore, limiting inquiry to senior management understates the evidence gathered and creates an incomplete risk picture.

Inquiry and Fraud Risk Assessment

Required risk assessment procedures include conducting a discussion among engagement team members about the potential for material misstatement due to fraud, and inquiring of the audit committee, management, internal auditors, and others about fraud risks.

The fraud risk discussion must happen before the team sets its audit approach. Moreover, it must be documented. PCAOB inspection findings in 2024 show that failure to adequately consider fraud — both in identifying fraud risks and in designing responses — was among the most common Part I.B deficiencies across all firm categories.


Technique 3 — Analytical Procedures as Risk Assessment Tools

Analytical procedures are a required risk assessment technique under AS 2110. They help identify unusual relationships, unexpected trends, and potential misstatements that warrant further investigation.

AS 2110 requires the auditor to apply analytical procedures for the purpose of identifying unusual or unexpected relationships involving revenue accounts that might indicate a material misstatement, including material misstatement due to fraud. When performing an analytical procedure, the auditor should use their understanding of the company to develop expectations about plausible relationships among the data.

Effective analytical procedures at the risk assessment stage include:

The key discipline is developing independent expectations before making inquiry. Performing substantive analytical procedures using disaggregated data — for example, comparing gross profit or operating margins by location, line of business, or month to auditor-developed expectations — is a specific technique for responding to identified fraud risks.

Explanations that simply attribute variances to business growth without independent corroboration do not satisfy PCAOB standards. Each variance explanation requires evidence.


Technique 4 — Understanding Internal Controls

Internal control understanding is an integral component of audit risk assessment techniques under PCAOB standards. The auditor must understand controls sufficiently to assess control risk at the assertion level.

This understanding covers five components of internal control:

Internal Controls and Risk Assessment Linkage

Understanding internal controls feeds directly into risk assessment conclusions. Where controls are strong and operating effectively, control risk is lower. Where controls have weaknesses — or where the auditor cannot confirm operating effectiveness — control risk is higher and substantive procedures must be more extensive.

PCAOB inspectors evaluate whether auditors genuinely assessed internal controls during risk assessment or simply documented that procedures were performed. Surface-level control documentation without real evaluation of design and operating effectiveness is a recurring deficiency.


Technique 5 — Identifying and Evaluating Significant Risks

AS 2110 requires auditors to identify significant risks — those that require special audit consideration. These are risks where the likelihood of material misstatement is high, the potential magnitude is significant, or the nature of the risk involves complexity, subjectivity, or fraud.

AS 2110 discusses the identification of significant risks and states that fraud risks are significant risks. Beyond fraud, significant risks typically arise in areas such as:

Increasingly, PCAOB inspection and enforcement staff challenge engagement teams on their identification of significant risks. The issue seen in practice is a failure of engagement teams to properly identify and document risk assessment and specifically, significant risks.

Every significant risk must be explicitly identified and documented. Furthermore, the audit response to each significant risk must be specifically tailored — not drawn from a generic audit program. This tailoring requirement is one of the most consistently scrutinized aspects of PCAOB risk assessment.


Technique 6 — Evaluating Risks at the Assertion Level

Risk assessment under PCAOB standards operates at two levels. The first is the overall financial statement level. The second — and more demanding — is the individual assertion level.

Assertions are the specific claims embedded in financial statements. For each material account balance and class of transactions, management implicitly asserts that amounts are complete, accurate, properly valued, appropriately classified, and presented in the correct period.

Auditors must identify which assertions carry the highest risk for each significant account or transaction class. A receivables balance may carry high completeness risk in one engagement and high valuation risk in another. The risk assessment must reflect the specific circumstances of the engagement — not a standardized template.

The linkage between assertion-level risk assessment and the nature, timing, and extent of planned procedures is what PCAOB inspectors evaluate most closely. Where that linkage is not explicit in the documentation, the risk assessment is deficient regardless of how much work was actually performed.


Technology-Assisted Risk Assessment Tools

Technology is changing how audit risk assessment techniques are applied in practice. Data analytics, automated testing tools, and AI-assisted review capabilities allow auditors to analyze entire populations of transactions rather than samples — identifying outliers, patterns, and anomalies that manual procedures might miss.

Under amended PCAOB standards effective in 2025 and 2026, the PCAOB has clarified auditor responsibilities when using technology-assisted analysis. The use of these tools does not reduce the auditor’s obligation to exercise professional judgment. Moreover, it does not replace the requirement to understand the entity, identify risks, and document the basis for risk assessment conclusions.

Technology tools support risk assessment most effectively when auditors use them to:

The tool produces the data. The auditor still exercises the judgment.


What the 2026 Inspection Environment Means for Risk Assessment

In 2024, the most common Part I.B deficiencies related to audit committee communications and consideration of fraud. Deficiency examples included auditors failing to communicate to the audit committee the basis for identifying and assessing the risks of material misstatement, whether due to error or fraud.

Furthermore, in 2025, PCAOB inspection selection prioritized the financial, real estate, and information technology sectors. Inspectors also focused on public companies impacted by supply chain challenges, companies engaging in merger and acquisition activities, and companies with heightened going concern risk.

These selection priorities signal where risk assessment must be most rigorous. M&A activity creates business combination accounting risk. Supply chain disruption creates inventory valuation and going concern risk. IT sector complexity creates revenue recognition and intangible asset risk. Each of these areas requires specific, documented risk assessment — not standardized language drawn from prior-year files.


Common Risk Assessment Failures That PCAOB Inspectors Identify

Understanding what goes wrong in risk assessment helps auditors build processes that consistently get it right. The most common failures include:


What Issuers and Finance Teams Should Know

Audit risk assessment is not solely an auditor responsibility. Finance teams affect its quality directly through the information they make available and the transparency they bring to the process.

Auditors perform more effective risk assessments when issuers provide:

Strong cooperation at the risk assessment stage sets the tone for the entire engagement. It reduces surprises, supports a more targeted audit approach, and produces a more defensible opinion.


The Bottom Line

Audit risk assessment techniques are the foundation of every PCAOB audit. They determine what gets tested, how extensively, and whether the resulting opinion is supportable. Where risk assessment fails — whether through insufficient entity understanding, inadequate fraud risk consideration, or failure to link risks to assertions — the entire audit approach built on top of it is compromised.

In 2026, with amended AS 2110 strengthening requirements and inspection deficiency rates still elevated at smaller firms, building rigorous risk assessment into every engagement from day one is not optional. It is the prerequisite for everything else.

Shah Teelani & Associates (PCAOB Reg. No. 7161) applies structured, assertion-level risk assessment on every engagement. We work with US-listed and OTC public companies that understand the difference between an audit that completes procedures and one that genuinely earns its opinion.

If your organization requires a PCAOB-registered auditor who takes risk assessment seriously, we welcome the conversation.


Shah Teelani & Associates PCAOB-Registered Audit Firm | Reg. No. 7161 Ahmedabad | Dubai | United States

Leave a Reply

Your email address will not be published. Required fields are marked *