How are risks and controls identified from process evidence?
Risks and controls are identified by understanding each stage of the process, considering what could go wrong in relation to financial reporting, and determining which activities prevent or detect that outcome.
The auditor should connect the process to relevant assertions and look at how transactions are initiated, authorised, processed, changed and reported. A manual journal transfer may create a completeness or accuracy risk. An independent reconciliation or system validation may be a relevant control. The existence of a described activity does not by itself prove that the control is suitably designed or implemented.
AI can assist by reading the walkthrough and supporting documents, proposing risks and controls, and explaining the evidence behind each suggestion. It can also identify where the narrative describes a risk but no mitigating control, or where a control appears in a policy but not in the observed process.
The auditor then decides which risks and controls are relevant to the audit, whether the control is sufficiently precise and what further work is required. The aim is not to create the longest possible risk-and-control list. It is to create a clear, defensible link between the process, the risk and the audit response.
Platformed capability: Platformed proposes risks and controls from process evidence, shows why each was suggested and highlights gaps in the risk-control relationship. The auditor accepts, changes or rejects each item.
References: ISA 315 risk assessment resources · Platformed risk assessment engine