Courseiva
mediumMatchingObjective-mapped

CISA Practice Question: Match each audit risk component to its definition.

Match each audit risk component to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Risk without controls

Risk that controls fail

Risk that audit misses errors

Overall risk of incorrect opinion

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Inherent Risk: The susceptibility of an account balance or class of transactions to a material misstatement assuming there are no related internal controls.

The audit risk model consists of inherent risk, control risk, detection risk, and overall audit risk. Inherent risk is the risk of misstatement without controls, control risk is the risk controls fail, detection risk is the risk audit procedures miss misstatements, and audit risk is the risk of issuing an inappropriate opinion. Common confusions include swapping the definitions of inherent and control risks or misattributing detection risk to inherent risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Inherent Risk: The susceptibility of an account balance or class of transactions to a material misstatement assuming there are no related internal controls.

    Why this is correct

    Inherent risk is the risk of material misstatement before considering internal controls.

  • Control Risk: The risk that a material misstatement could occur and not be prevented or detected on a timely basis by the entity's internal controls.

    Why this is correct

    Control risk is the risk that internal controls fail to prevent or detect material misstatements.

  • Detection Risk: The risk that the auditor's procedures will fail to detect a material misstatement.

    Why this is correct

    Detection risk is the risk that audit procedures do not catch a material misstatement.

  • Audit Risk: The risk that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated.

    Why this is correct

    Audit risk is the overall risk of issuing a wrong opinion.

  • Inherent Risk: The risk that the auditor's procedures will fail to detect a material misstatement.

    Why it's wrong here

    Incorrect — this definition describes Detection Risk, not Inherent Risk.

  • Control Risk: The susceptibility of an account balance to material misstatement assuming no internal controls.

    Why it's wrong here

    Incorrect — this definition describes Inherent Risk, not Control Risk.

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.