An auditor planning a review of a bank's small-business lending unit maps risks specific to that unit but omits considering the bank's recent group-wide switch to an aggressive growth incentive plan and a new data-privacy regulation taking effect next year. Which category of risk has the auditor most clearly failed to incorporate into the detailed risk assessment?
- ADetection risk arising from the sampling approach the engagement team intends to apply to the loan files during fieldwork later this year.
- BResidual risk, because the auditor recorded inherent exposures for the unit without netting them against the controls management operates.
- CSampling risk, because omitting the group-level factors changes the population of individual loan files the team must select and test.
- DPervasive and emerging risks, because the incentive plan can affect behaviour across the unit and the pending regulation is a developing external exposure. Correct
Why A is wrong: Tempting because sampling affects assurance quality, but detection risk concerns the audit procedures themselves, not the external and organisation-wide exposures the auditor overlooked.
Why B is wrong: Tempting since residual risk matters, but the omission described is entering wider organisational and external factors, not the separate step of assessing control effectiveness.
Why C is wrong: Tempting as scope shapes populations, but sampling risk is about whether a sample represents a population, not about missing pervasive and emerging exposures in the assessment.
Why D is correct: Correct: an incentive that shifts conduct across the whole activity is pervasive, and a not-yet-effective regulation is an emerging risk; a detailed assessment must consider both alongside unit-specific risks.