Inherent, Control and Detection Risk
When preparing an ISO/IEC 27001 audit, a Lead Auditor uses the audit risk model to plan an effective, risk-based audit. Audit risk is the risk that the auditor reaches an incorrect conclusion, such as recommending certification when the ISMS contains significant nonconformities, or reporting a nonc… When preparing an ISO/IEC 27001 audit, a Lead Auditor uses the audit risk model to plan an effective, risk-based audit. Audit risk is the risk that the auditor reaches an incorrect conclusion, such as recommending certification when the ISMS contains significant nonconformities, or reporting a nonconformity that does not exist. It is commonly described as the product of three components: Audit Risk = Inherent Risk x Control Risk x Detection Risk. 1. Inherent Risk: This is the likelihood that a significant nonconformity or information security weakness exists before any controls are considered. It arises from the nature of the auditee, including its industry, regulatory exposure, size, process complexity, technology, outsourcing, rate of change and the sensitivity of the information it handles. A cloud service provider processing health data has higher inherent risk than a small office with limited IT. The auditor cannot change inherent risk, only assess it. 2. Control Risk: This is the risk that the organization's ISMS processes and Annex A controls fail to prevent, or to detect and correct, a nonconformity in time. Weak risk assessment, poor internal audits, an immature management review or ineffective corrective action all increase control risk. The auditor evaluates it during the document review and Stage 1 audit, but cannot directly reduce it. 3. Detection Risk: This is the risk that the auditor's own procedures fail to detect an existing nonconformity. It is the only component under the audit team's control. It depends on sampling methods, sample size, audit duration, team competence, the audit plan and the evidence-gathering techniques used, such as interviews, observation and technical verification. Planning implication: Because the auditor must keep overall audit risk at an acceptably low level, detection risk is set inversely to the assessed inherent and control risks. Where these are high, the Lead Auditor lowers detection risk by allocating more audit time, larger and more targeted samples, technical experts and deeper testing of high-risk processes and controls.
Inherent, Control and Detection Risk: A Complete Guide for ISO/IEC 27001 Lead Auditors
Introduction
When preparing an ISO/IEC 27001 audit, a Lead Auditor must decide where to focus limited time and resources. The concepts of Inherent Risk, Control Risk and Detection Risk together make up Audit Risk. This is the risk that the auditor reaches an incorrect conclusion about the auditee's Information Security Management System (ISMS). Understanding these three components is essential for planning a risk-based audit, as recommended by ISO 19011 (Guidelines for auditing management systems) and ISO/IEC 27007 (Guidelines for ISMS auditing).
Why It Is Important
1. Audits are based on sampling. An auditor cannot examine every record, process, asset or control. Sampling always carries the risk that a nonconformity goes unnoticed.
2. Risk-based audit planning. ISO 19011 requires the audit programme and audit plan to be risk-based. Assessing inherent and control risk tells the auditor which areas deserve more depth.
3. Credibility of certification. If a certification body certifies an organisation with serious undetected weaknesses, the value of the certificate is damaged. Managing audit risk protects the auditee, the certification body and interested parties.
4. Efficient allocation of resources. Low-risk areas can be sampled lightly. High-risk areas receive more audit time, more experienced auditors and larger samples.
5. Professional due care. Understanding audit risk shows that the auditor follows the principles of evidence-based approach and due professional care.
What It Is: The Audit Risk Model
Audit Risk is commonly expressed as:
Audit Risk = Inherent Risk x Control Risk x Detection Risk
1. Inherent Risk (IR)
Inherent risk is the susceptibility of a process, activity or area to a significant error, nonconformity or security failure before considering any controls.
It comes from the nature of the business and its environment. Typical drivers are:
- complexity of operations
- volume of sensitive data
- regulatory pressure
- rapid change
- reliance on outsourcing or cloud
- new technology
- history of incidents
Example: A payment processor handling millions of card transactions has high inherent risk regarding confidentiality and integrity. A small design studio storing public brochures has low inherent risk.
The auditor cannot change inherent risk. It can only be assessed.
2. Control Risk (CR)
Control risk is the risk that the auditee's own controls will fail to prevent, or to detect and correct, a significant nonconformity or security event in time.
It reflects how well controls are designed and how effectively they operate. This covers:
- the ISMS processes in clauses 4 to 10
- the Annex A controls
- monitoring, internal audit and management review
Example: An organisation with no access review process, weak change management and an ineffective internal audit function has high control risk.
The auditor cannot change control risk either. It belongs to the auditee and can only be assessed, for example through the Stage 1 review, documentation review and previous audit results.
3. Detection Risk (DR)
Detection risk is the risk that the auditor's procedures will fail to detect a nonconformity that exists.
It is caused by factors such as:
- sample size and sampling method
- the audit techniques chosen
- the competence of the audit team
- time constraints
- misinterpretation of evidence
Detection risk is the only component the auditor controls.
How It Works in Practice
Step 1: Assess Inherent Risk. During audit preparation and Stage 1, gather information about the organisation, its context (clause 4), scope, sector, legal requirements, information assets and threat landscape.
Step 2: Assess Control Risk. Review the following to judge whether controls are likely to be effective:
- ISMS documentation
- risk assessment and risk treatment plan
- Statement of Applicability
- internal audit reports
- management review outputs
- incident records
- previous audit findings
Step 3: Determine Acceptable Audit Risk. The certification body and audit team set an acceptable, low level of overall audit risk.
Step 4: Set the Planned Detection Risk. Because audit risk is fixed at an acceptable level, detection risk must be adjusted to compensate:
- High IR and/or high CR means the auditor must achieve low detection risk. This calls for more substantive testing, larger samples, more audit time, more experienced or technical experts, more direct observation and more re-performance.
- Low IR and low CR means the auditor can accept higher detection risk. This allows smaller samples, more reliance on interviews and document review, and less time.
Step 5: Build the Audit Plan. Allocate audit days, assign auditors and select sampling plans based on this analysis. Record the rationale.
Step 6: Adjust During the Audit. If evidence shows controls are weaker than expected, control risk rises. The auditor should then reduce detection risk by expanding samples or digging deeper.
Summary Matrix
- IR High + CR High: plan for very low DR, with extensive testing and large samples.
- IR High + CR Low: plan for moderate DR, with focused testing of key controls.
- IR Low + CR High: plan for moderate DR, testing control weaknesses.
- IR Low + CR Low: accept higher DR, with lighter sampling.
Examples in an ISMS Context
- A cloud hosting provider with multiple data centres (high IR) whose access logs are not reviewed (high CR). The auditor samples a large number of user accounts, re-performs access reviews and examines privileged account activity.
- A mature organisation with an effective internal audit programme and long certification history (low CR). The auditor can place some reliance on internal audit results and reduce sample sizes in stable areas, while still verifying their effectiveness.
- A first-time certification with a newly written ISMS. Control risk is uncertain, so it is treated as higher until evidence proves otherwise.
Relationship to Other Audit Concepts
- Sampling (ISO 19011, Annex A): Larger or statistical samples reduce detection risk.
- Materiality and significance: Focus on nonconformities that could affect the ISMS's ability to achieve its intended outcomes.
- Audit team competence: Using technical experts reduces detection risk in specialised areas.
- Stage 1 and Stage 2: Stage 1 helps assess IR and CR. Stage 2 applies procedures designed to keep DR acceptably low.
- Organisational risk versus audit risk: Do not confuse the auditee's information security risk assessment (clause 6.1.2) with audit risk. One concerns information security risks to the business. The other concerns the risk of an incorrect audit conclusion.
Exam Tips: Answering Questions on Inherent, Control and Detection Risk
1. Memorise the definitions precisely.
- Inherent risk is the nature of the activity, before controls.
- Control risk is the failure of the auditee's controls.
- Detection risk is the failure of the auditor's procedures.
2. Know who controls what. This is the most frequently tested point. The auditor can only influence detection risk. Inherent and control risk are assessed, not controlled, by the auditor. If an answer suggests the auditor reduces control risk, it is wrong.
3. Remember the inverse relationship. When inherent and/or control risk are high, the acceptable detection risk must be low, so the auditor does more work. When they are low, detection risk can be higher, so the auditor does less work. Watch for answer options that reverse this.
4. Translate 'reduce detection risk' into actions. Correct actions include:
- increasing sample size
- using more reliable evidence, such as observation, re-performance and system records over verbal statements
- allocating more time
- using technical experts
- auditing at different times or shifts
- triangulating evidence
5. Identify the risk type in scenario questions. Ask yourself these questions:
- Is the scenario describing the business environment, such as sensitive data, complexity or regulation? That is inherent risk.
- Is it describing weak or missing safeguards, such as no backups tested or no access reviews? That is control risk.
- Is it describing the audit approach, such as a small sample, an inexperienced auditor or a rushed audit? That is detection risk.
6. Link to ISO 19011 and ISO/IEC 27007. In essay or long-answer questions, mention that a risk-based approach to auditing is required. Explain that audit planning should consider risks to achieving audit objectives, and that the audit plan should be adjusted as new information emerges.
7. Justify your answers in case studies. Explain your reasoning, for example: 'Because the organisation processes health data (high inherent risk) and its last internal audit was not completed (high control risk), I would reduce detection risk by allocating additional audit time to Annex A access control and logging, increasing the sample of user accounts reviewed, and including a technical expert.'
8. Do not confuse audit risk with the auditee's risk assessment. Exam questions may deliberately mix the terms. Audit risk is about the auditor reaching the wrong conclusion.
9. Recognise that audit risk can never be zero. Because audits use sampling, some residual risk always remains. An answer claiming the auditor can eliminate audit risk is incorrect. This is why certification statements are based on sampled evidence.
10. Use keywords examiners look for. These include:
- risk-based approach
- sampling
- audit evidence
- reliability of evidence
- professional judgement
- audit plan adjustment
- competence
- Stage 1 findings
Quick Revision Checklist
- Audit Risk = IR x CR x DR
- IR: nature of the business, not controllable by the auditor
- CR: effectiveness of the auditee's controls, not controllable by the auditor
- DR: effectiveness of the auditor's procedures, controllable by the auditor
- High IR/CR leads to low DR, which means more audit effort
- Low IR/CR allows higher DR, which means less audit effort
- Audit risk can be minimised but never eliminated
Conclusion
Inherent, control and detection risk form the backbone of risk-based audit planning. A competent ISO/IEC 27001 Lead Auditor assesses the inherent and control risks of the auditee. The auditor then designs audit procedures that keep detection risk low enough for a reliable, defensible audit conclusion. In the exam, always identify which risk is being described and remember that only detection risk is in the auditor's hands. Then justify how your audit plan responds to the risk levels.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!