The IAASB discussed the issues arising from the exposure draft process and the task force's initial reaction and proposed response to the issues at its July 2003 meeting.

Organizations must have adequate internal controls in place to prevent and detect instances of fraud and error. Control risk is considered to be high where the audit entity does not have adequate internal controls to prevent and detect instances of fraud and error in the financial statements.

It is also more likely when significant estimates must be included in audit risk model, where an estimation error can be made. Inherent risk is also more likely when the transactions in which a client engages are highly complex, and so are more likely to be completed or recorded incorrectly.

The only risk that auditors can actually act directly upon is detection risk. This means that if control risk and inherent risk are high, they’ll have to adjust their process to focus on lowering detection risk. We’ll touch more on this shortly as we will see how audit risk affects overall audit strategy. For example, an auditor takes a sample of transactions that display no foul play. However, if the auditor is able to expand their sample size, they may decrease detection risk.

Explain why an audit of internal controls provides value to the investing public.