1. Deconstructing the Audit Risk Model
Audit Risk (AR) is the risk that the auditor expresses an inappropriate, clean audit opinion when the financial statements are materially misstated. It is mathematically decomposed into three distinct operational risks:
 
AR = IR × CR × DR
  ┌─────────────────────────────── AUDIT RISK ───────────────────────────────┐
  │                                                                          │
  │   ┌─────────────── RISK OF MATERIAL MISSTATEMENT (RMM) ──────────────┐   │
  │   │                                                                  │   │
  │   │  • Inherent Risk (IR): Natural susceptibility of transaction.    │   │
  │   │  • Control Risk (CR): Internal controls fail to catch error.      │   │
  │   └───────────────────────────────────┬──────────────────────────────┘   │
  │                                       │                                  │
  │                                       ▼ Controlled by Auditor            │
  │   ┌───────────────────────── Detection Risk (DR) ────────────────────┐   │
  │   │                                                                  │   │
  │   │  • Auditor's testing procedures fail to identify the misstatement│   │
  │   └──────────────────────────────────────────────────────────────────┘   │
  └──────────────────────────────────────────────────────────────────────────┘

2. Components of Risk of Material Misstatement (RMM)
RMM exists completely independent of the audit and is owned by the client. It comprises:
  • Inherent Risk (IR): The susceptibility of an assertion to a misstatement before considering any related internal controls (e.g., highly complex derivative transactions, subjective management estimates, high risk of technological inventory obsolescence).
  • Control Risk (CR): The risk that a material misstatement will not be prevented, or detected and corrected, on a timely basis by the entity’s internal control infrastructure.
3. Detection Risk and Auditor Control Mechanics
Detection Risk (DR) is the only component of the model that the auditor directly controls. It represents the risk that the auditor’s own substantive testing procedures fail to detect a misstatement that exists.
  • The Inverse Relationship: If RMM (Inherent Risk × Control Risk) is assessed as High, the auditor must minimize Detection Risk (Low) to bring overall Audit Risk down to an acceptably low level. To achieve a low Detection Risk, the auditor must expand substantive testing, use larger sample sizes, and assign more experienced staff.