Published by Shah Teelani & Associates | PCAOB-Registered Audit Firm | Reg. No. 7161
Audit risk assessment techniques are the foundation of every PCAOB engagement. They determine which accounts get tested, what procedures get performed, and whether the audit opinion is supportable. Get risk assessment wrong and everything downstream is compromised.
If the risk assessment is wrong, the audit approach is also inherently wrong. Inspection and enforcement staff consistently challenge engagement teams on their identification of significant risks. Furthermore, an auditor’s failure to understand the client’s accounting procedures or policies is the most detrimental type of deficiency for future reporting quality.
PCAOB AS 2110, Identifying and Assessing Risks of Material Misstatement, governs the entire risk assessment process. The updated AS 2110, effective December 15, 2026, strengthens requirements around risk identification and assessment, emphasizing a more thorough understanding of the company and its environment to support audit procedures.
At Shah Teelani & Associates, we build audit risk assessment into every engagement from the first day of planning. This blog explains the key techniques and tools that PCAOB auditors must apply — and where inspection findings most commonly arise.
What Audit Risk Assessment Requires Under PCAOB Standards
AS 2110 establishes requirements for the process of identifying and assessing risks of material misstatement of the financial statements. It covers the auditor’s responsibilities for performing risk assessment procedures and for identifying and assessing risks using information obtained from those procedures.
Risk assessment under PCAOB standards is not a preliminary formality. It drives the entire audit approach. Every substantive procedure and every control test must link back to a specific risk identified during this phase. Moreover, the amended AS 2110 — effective December 15, 2026 — reinforces that this linkage must be explicit, documented, and traceable throughout the engagement file.
Therefore, risk assessment is both a technical process and a documentation obligation. Performing the work without recording the reasoning fails the PCAOB standard just as surely as not performing the work at all.
Technique 1 — Understanding the Entity and Its Environment
The first and most fundamental audit risk assessment technique is obtaining a thorough understanding of the company. This understanding covers six interconnected areas.
Industry and external environment. The auditor must understand the industry the company operates in — its competitive dynamics, regulatory requirements, and economic pressures. Industry-specific accounting risks, margin patterns, and revenue recognition practices all flow from this understanding.
Nature of the company. This includes the company’s operations, ownership structure, investments, financing arrangements, and financial reporting practices. Understanding how the business actually works is the prerequisite for identifying where financial statements might be misstated.
Accounting policies and practices. An auditor’s failure to understand the client’s accounting procedures or policies is the most detrimental deficiency type for future reporting quality. Auditors must understand not just what accounting policies management has adopted but whether those policies are appropriate for the company’s transactions and industry.
Objectives, strategies, and business risks. Management’s strategic goals create financial reporting risks. Aggressive growth targets create revenue recognition risk. Acquisitions create valuation and goodwill impairment risk. Understanding what management is trying to achieve helps auditors identify where financial statements are most likely to be misstated.
Financial performance measures. Key performance indicators, analyst expectations, bonus targets, and debt covenant thresholds all create incentives that affect financial reporting. Auditors must understand what metrics management monitors — and what pressure those metrics create.
Internal control environment. Understanding internal control at the entity level is required before the auditor can assess control risk at the assertion level. This includes the control environment, risk assessment processes, information systems, and monitoring activities.
Technique 2 — Inquiry Across Multiple Sources
Inquiry is a required risk assessment procedure under AS 2110. However, effective inquiry extends well beyond management. It targets a broad range of personnel — each of whom may have different perspectives on where risks exist.
AS 2110 requires the auditor to inquire of the audit committee, management, and others within the company about the risks of material misstatement. Other individuals to whom inquiries should be directed include employees with varying levels of authority, operating personnel not directly involved in financial reporting, and employees involved in initiating, recording, or processing transactions.
This breadth is intentional. Management may not disclose risks candidly — particularly where fraud risk exists. Employees at different levels often observe inconsistencies, pressures, or unusual transactions that management does not surface. Therefore, limiting inquiry to senior management understates the evidence gathered and creates an incomplete risk picture.
Inquiry and Fraud Risk Assessment
Required risk assessment procedures include conducting a discussion among engagement team members about the potential for material misstatement due to fraud, and inquiring of the audit committee, management, internal auditors, and others about fraud risks.
The fraud risk discussion must happen before the team sets its audit approach. Moreover, it must be documented. PCAOB inspection findings in 2024 show that failure to adequately consider fraud — both in identifying fraud risks and in designing responses — was among the most common Part I.B deficiencies across all firm categories.
Technique 3 — Analytical Procedures as Risk Assessment Tools
Analytical procedures are a required risk assessment technique under AS 2110. They help identify unusual relationships, unexpected trends, and potential misstatements that warrant further investigation.
AS 2110 requires the auditor to apply analytical procedures for the purpose of identifying unusual or unexpected relationships involving revenue accounts that might indicate a material misstatement, including material misstatement due to fraud. When performing an analytical procedure, the auditor should use their understanding of the company to develop expectations about plausible relationships among the data.
Effective analytical procedures at the risk assessment stage include:
- Comparing current period results against prior periods and identifying significant variances
- Comparing actual results against budgets, forecasts, and analyst expectations
- Calculating key ratios — gross margin, operating margin, days sales outstanding, inventory turnover — and comparing against industry benchmarks
- Performing disaggregated analytics by product line, geography, or business unit to identify patterns not visible at the consolidated level
- Analyzing revenue trends month by month to identify unusual timing patterns
The key discipline is developing independent expectations before making inquiry. Performing substantive analytical procedures using disaggregated data — for example, comparing gross profit or operating margins by location, line of business, or month to auditor-developed expectations — is a specific technique for responding to identified fraud risks.
Explanations that simply attribute variances to business growth without independent corroboration do not satisfy PCAOB standards. Each variance explanation requires evidence.
Technique 4 — Understanding Internal Controls
Internal control understanding is an integral component of audit risk assessment techniques under PCAOB standards. The auditor must understand controls sufficiently to assess control risk at the assertion level.
This understanding covers five components of internal control:
- Control environment — the tone set by management and governance, including ethical values, competence, and oversight
- Risk assessment process — how management identifies and addresses business risks that could affect financial reporting
- Information and communication systems — how transactions are initiated, recorded, processed, and reported
- Control activities — specific policies and procedures that help ensure management directives are carried out
- Monitoring activities — processes management uses to assess whether controls are operating effectively
Internal Controls and Risk Assessment Linkage
Understanding internal controls feeds directly into risk assessment conclusions. Where controls are strong and operating effectively, control risk is lower. Where controls have weaknesses — or where the auditor cannot confirm operating effectiveness — control risk is higher and substantive procedures must be more extensive.
PCAOB inspectors evaluate whether auditors genuinely assessed internal controls during risk assessment or simply documented that procedures were performed. Surface-level control documentation without real evaluation of design and operating effectiveness is a recurring deficiency.
Technique 5 — Identifying and Evaluating Significant Risks
AS 2110 requires auditors to identify significant risks — those that require special audit consideration. These are risks where the likelihood of material misstatement is high, the potential magnitude is significant, or the nature of the risk involves complexity, subjectivity, or fraud.
AS 2110 discusses the identification of significant risks and states that fraud risks are significant risks. Beyond fraud, significant risks typically arise in areas such as:
- Complex accounting estimates — goodwill impairment, fair value measurements, revenue recognition involving variable consideration
- Non-routine or unusual transactions — acquisitions, restructurings, related party arrangements
- Significant judgments — going concern assessments, contingent liabilities, tax positions
- Areas with management bias risk — incentive compensation arrangements, debt covenant compliance, earnings targets
Increasingly, PCAOB inspection and enforcement staff challenge engagement teams on their identification of significant risks. The issue seen in practice is a failure of engagement teams to properly identify and document risk assessment and specifically, significant risks.
Every significant risk must be explicitly identified and documented. Furthermore, the audit response to each significant risk must be specifically tailored — not drawn from a generic audit program. This tailoring requirement is one of the most consistently scrutinized aspects of PCAOB risk assessment.
Technique 6 — Evaluating Risks at the Assertion Level
Risk assessment under PCAOB standards operates at two levels. The first is the overall financial statement level. The second — and more demanding — is the individual assertion level.
Assertions are the specific claims embedded in financial statements. For each material account balance and class of transactions, management implicitly asserts that amounts are complete, accurate, properly valued, appropriately classified, and presented in the correct period.
Auditors must identify which assertions carry the highest risk for each significant account or transaction class. A receivables balance may carry high completeness risk in one engagement and high valuation risk in another. The risk assessment must reflect the specific circumstances of the engagement — not a standardized template.
The linkage between assertion-level risk assessment and the nature, timing, and extent of planned procedures is what PCAOB inspectors evaluate most closely. Where that linkage is not explicit in the documentation, the risk assessment is deficient regardless of how much work was actually performed.
Technology-Assisted Risk Assessment Tools
Technology is changing how audit risk assessment techniques are applied in practice. Data analytics, automated testing tools, and AI-assisted review capabilities allow auditors to analyze entire populations of transactions rather than samples — identifying outliers, patterns, and anomalies that manual procedures might miss.
Under amended PCAOB standards effective in 2025 and 2026, the PCAOB has clarified auditor responsibilities when using technology-assisted analysis. The use of these tools does not reduce the auditor’s obligation to exercise professional judgment. Moreover, it does not replace the requirement to understand the entity, identify risks, and document the basis for risk assessment conclusions.
Technology tools support risk assessment most effectively when auditors use them to:
- Identify journal entry anomalies that may indicate management override
- Analyze revenue transactions for unusual timing, counterparty patterns, or authorization exceptions
- Compare large datasets against expected ranges developed from industry benchmarks
- Flag related party transactions for more intensive review
The tool produces the data. The auditor still exercises the judgment.
What the 2026 Inspection Environment Means for Risk Assessment
In 2024, the most common Part I.B deficiencies related to audit committee communications and consideration of fraud. Deficiency examples included auditors failing to communicate to the audit committee the basis for identifying and assessing the risks of material misstatement, whether due to error or fraud.
Furthermore, in 2025, PCAOB inspection selection prioritized the financial, real estate, and information technology sectors. Inspectors also focused on public companies impacted by supply chain challenges, companies engaging in merger and acquisition activities, and companies with heightened going concern risk.
These selection priorities signal where risk assessment must be most rigorous. M&A activity creates business combination accounting risk. Supply chain disruption creates inventory valuation and going concern risk. IT sector complexity creates revenue recognition and intangible asset risk. Each of these areas requires specific, documented risk assessment — not standardized language drawn from prior-year files.
Common Risk Assessment Failures That PCAOB Inspectors Identify
Understanding what goes wrong in risk assessment helps auditors build processes that consistently get it right. The most common failures include:
- Rolling forward prior-year risk assessments without reconsidering whether the company’s circumstances have changed
- Limiting inquiry to senior management without seeking corroborating information from operational personnel
- Performing analytical procedures without independent expectations — accepting management explanations without developing an auditor-independent view first
- Identifying risks generically without linking them to specific assertions, accounts, and transaction classes
- Failing to identify fraud risks as significant risks or treating them as a separate exercise disconnected from the broader risk assessment
- Not updating risk assessment when new information emerges during the audit — risk assessment is a continuous process, not a one-time planning activity
What Issuers and Finance Teams Should Know
Audit risk assessment is not solely an auditor responsibility. Finance teams affect its quality directly through the information they make available and the transparency they bring to the process.
Auditors perform more effective risk assessments when issuers provide:
- Organized management discussion and analysis materials that explain current-period developments
- Clear documentation of significant accounting judgments and the basis for each
- Timely access to key personnel across departments — not just the finance team
- Transparent disclosure of unusual transactions, related party arrangements, and significant estimates
- Updated internal control documentation reflecting current-period processes
Strong cooperation at the risk assessment stage sets the tone for the entire engagement. It reduces surprises, supports a more targeted audit approach, and produces a more defensible opinion.
The Bottom Line
Audit risk assessment techniques are the foundation of every PCAOB audit. They determine what gets tested, how extensively, and whether the resulting opinion is supportable. Where risk assessment fails — whether through insufficient entity understanding, inadequate fraud risk consideration, or failure to link risks to assertions — the entire audit approach built on top of it is compromised.
In 2026, with amended AS 2110 strengthening requirements and inspection deficiency rates still elevated at smaller firms, building rigorous risk assessment into every engagement from day one is not optional. It is the prerequisite for everything else.
Shah Teelani & Associates (PCAOB Reg. No. 7161) applies structured, assertion-level risk assessment on every engagement. We work with US-listed and OTC public companies that understand the difference between an audit that completes procedures and one that genuinely earns its opinion.
If your organization requires a PCAOB-registered auditor who takes risk assessment seriously, we welcome the conversation.
Shah Teelani & Associates PCAOB-Registered Audit Firm | Reg. No. 7161 Ahmedabad | Dubai | United States