17/04/2026
Audit/Finance နယ်ပယ်မှာ အလုပ်လုပ်နေသူတွေအတွက် အရမ်းအသုံးဝင်မယ့် "Professional ဆန်ဆန် File တွေ နာမည်ပေးနည်းနဲ့ Folder စနစ်တကျထားသိုနည်း"
**🚨 "Final final.xlsx", "Latest update 2.xlsx" လိုမျိုး File နာမည်တွေ ပေးနေတုန်းပဲလား?**
Auditor တွေ၊ Accountant တွေအတွက် အလုပ်လုပ်ရတာ အဆင်ပြေစေမယ့်၊ Review လုပ်တဲ့အခါ ရှာရလွယ်ကူစေမယ့် **"Professional Audit File Naming & Folder Structure"** လမ်းညွှန်ကို မျှဝေပေးချင်ပါတယ်။
Audit လောကမှာ File တွေကို စနစ်တကျ နာမည်ပေးတာဟာ အချိန်ကုန်သက်သာစေရုံသာမကဘဲ အမှားအယွင်းတွေကိုပါ အများကြီး လျှော့ချပေးနိုင်ပါတယ်။
📌 **(၁) မှတ်ထားရမယ့် ရွှေစည်းမျဉ်းများ (Golden Rules)**
🔸 Format တစ်မျိုးတည်းကိုပဲ အသေအချာသုံးပါ။
🔸 ရက်စွဲကို အမြဲတမ်း **YYYY-MM-DD** (ဥပမာ - 2025-12-31) ပုံစံနဲ့ပဲ ရေးပါ။ (ဒီလိုရေးမှ Computer မှာ Date အလိုက် အစီအစဉ်တကျ ပေါ်မှာပါ)
🔸 Space တွေ၊ Special character တွေ (* ? / < >) မသုံးပါနဲ့။ စာလုံးတွေကြားမှာ Underscore (_) သို့မဟုတ် Hyphen (-) ကိုပဲ သုံးပါ။
🔸 "Final", "New File", "Test" စတဲ့ ဝေဝါးတဲ့ နာမည်တွေ မသုံးပါနဲ့။
🔸 Version တွေကို သေချာတပ်ပါ (v01, v02, v03)။
🔸 Status ကို ရှင်းရှင်းလင်းလင်းပြပါ (Draft, ForReview, Final, ClientProvided)။
📌 **(၂) Auditor တွေအတွက် အကောင်းဆုံး File Naming Formula**
ဒီ Formula လေးကို ကိုယ့် Team တစ်ခုလုံး Standard အနေနဲ့ သတ်မှတ်ထားသင့်ပါတယ်-
👉 **[ClientCode]*[FY]*[SectionRef]*[Area]*[Description]*[Date]*[Status]_[v # #]**
💡 **ဥပမာ -**
ABC_2025_C2_COGS_GL_to_ProjectCostBridge_2025-12-31_ForReview_v02.xlsx
ဒီဖိုင်နာမည်လေး တစ်ကြောင်းတည်းကြည့်လိုက်တာနဲ့...
* ဘယ် Client လဲ (ABC)
* ဘယ်နှစ်အတွက်လဲ (2025)
* ဘယ် Audit Section လဲ (C2 - COGS)
* ဖိုင်က ဘာအကြောင်းလဲ (GL to Project Cost Bridge)
* ဘယ်ရက်စွဲနဲ့လဲ (2025-12-31)
* Status က ဘာလဲ (Review လုပ်ဖို့ - ForReview)
* ဘယ်နှစ်ကြိမ်မြောက် ပြင်ထားတာလဲ (Version 2) ဆိုတာ ချက်ချင်းသိနိုင်ပါတယ်။
📌 **(၃) စနစ်ကျတဲ့ Audit Folder Structure ဘယ်လိုဆောက်မလဲ?**
Folder တွေကို နာမည်ပေးတဲ့အခါ ရှေ့မှာ နံပါတ်လေးတွေ တပ်ပေးရင် Review လုပ်တဲ့ အစီအစဉ်အတိုင်း အစဉ်လိုက်လေး ဖြစ်နေပါလိမ့်မယ်။
(ဥပမာ - **2025_ABC_FS_Audit**)
📂 00_Admin
📂 01_EngagementSetup
📂 02_Planning
📂 03_RiskAssessment
📂 04_InternalControl
📂 05_SubstantiveTesting
*(ဒီအထဲမှာမှ A_Cash, B_Receivables, H_Revenue စသဖြင့် ထပ်ခွဲပါ)*
📂 06_FS_Close_and_Disclosure
📂 07_Completion
📂 08_ClientProvided (Client ဆီကရသမျှ အကြမ်းဖိုင်တွေ သိမ်းရန်)
📂 09_Reports_and_Deliverables
📂 10_Archive
📌 **(၄) ရှောင်ကြဉ်ရမယ့် အမှားများ (Common Mistakes)**
❌ **မသုံးသင့်တဲ့ နာမည်များ:**
* Final TB.xlsx
* Latest version.xlsx
* Scan0001.pdf
* Revenue test revised new final.xlsx
✅ **ပြောင်းလဲ အသုံးပြုသင့်တဲ့ နာမည်များ:**
* ABC_2025_PBC_TB_2025-12-31_ClientProvided.xlsx (Client ဆီကရတဲ့ Trial Balance)
* ABC_2025_H1_Revenue_TOC_Test_2025-12-31_v02.xlsx (Working Paper)
* ABC_2025_PBC_SignedContract_Project5005_2025-07-01.pdf (Client Contract)
(*မှတ်ချက် - PBC ဆိုတာ Prepared by Client ကို ဆိုလိုပါတယ်*)
📌 **(၅) လက်တွေ့အသုံးချဖို့ အကြံပြုချက်များ**
1️⃣ **Client ဆီက ဖိုင်ရတာနဲ့ ချက်ချင်း Rename လုပ်ပါ:** "Final TB updated.xlsx" ဆိုပြီး ရလာရင် Folder ထဲမှာ ဒီတိုင်းမသိမ်းပါနဲ့။ Standard နာမည် ချက်ချင်းပြောင်းပြီး 08_ClientProvided ထဲကို ထည့်ပါ။
2️⃣ **Duplicate ဖိုင်တွေ မထားပါနဲ့:** Working Paper တစ်ခုအတွက် ဖိုင်တစ်ခုပဲ ရှိရပါမယ်။ Desktop မှာတစ်ခု၊ Download မှာတစ်ခု၊ Shared Folder မှာတစ်ခု ဖြစ်မနေပါစေနဲ့။
3️⃣ **Draft နဲ့ Final ကို သေချာခွဲပါ:** မလိုအပ်တော့တဲ့ အဟောင်းတွေကို _Superseded သို့မဟုတ် Archive Folder ထဲ ရွှေ့ထားပါ။
ဒီနည်းလမ်းလေးတွေကို ကိုယ့်ရဲ့ လုပ်ငန်းခွင်မှာ စတင်အသုံးပြုကြည့်ရင် အလုပ်လုပ်ရတာ ပိုမိုမြန်ဆန်သွက်လက်ပြီး၊ အထက်လူကြီး ဒါမှမဟုတ် Manager တွေ Review လုပ်တဲ့အခါမှာလည်း Professional အရမ်းဆန်တဲ့အတွက် အထူးသဘောကျစေမှာ အမှန်ပါပဲ။ 💯
မြန်မာနှစ်ဆန်း ၁ ရက်နေ့မှာ အားလုံးပဲ အစစအရာရာ အဆင်ပြေကြပါစေ
02/04/2026
📘 AI အသုံးပြုထားသော အလိုအလျောက် နမူနာရွေးချယ်ခြင်း မူဘောင် (AI-Driven Auto Sampling Framework)
ရည်ရွယ်ချက် (Objective): Audit စစ်ဆေးမှု လွှမ်းခြုံနိုင်စွမ်း (Coverage)၊ ထိရောက်မှု (Efficiency) နှင့် ယုံကြည်ရမှု (Assurance) တို့ကို တိုးတက်စေရန်အတွက် အရည်အသွေးမြင့်မားပြီး အန္တရာယ် (Risk) ပေါ်အခြေခံသော Audit Sample များကို AI နှင့် Data Analytics အသုံးပြု၍ ရွေးချယ်ရန်။
🧠 ၁။ ဘာကြောင့် AI Sampling ကို သုံးသင့်တာလဲ (Traditional vs. AI Sampling)
ရိုးရာစနစ်နဲ့ AI စနစ်ရဲ့ အဓိကကွာခြားချက်ကတော့ "အမြင်ကျယ်မှု" ပါပဲ။
* ရိုးရာစနစ် (Traditional): လူရဲ့ ဆုံးဖြတ်ချက် ဒါမှမဟုတ် ကျပန်း (Random) ရွေးချယ်တဲ့အတွက် Sample အရေအတွက် အကန့်အသတ်ရှိပြီး၊ ပုန်းကွယ်နေတဲ့ အမှားတွေ/လိမ်လည်မှုတွေကို လွတ်သွားနိုင်ပါတယ်။
* AI စနစ်: ဒေတာတစ်ခုလုံး (Full Population) ကို Scan ဖတ်ပြီး ပုံမှန်မဟုတ်တဲ့ Pattern တွေကို ထောက်လှမ်းပေးပါတယ်။
👉 ကောက်ချက်: AI ဟာ ရိုးရှင်းတဲ့ Sample ကောက်ခြင်းသက်သက်မဟုတ်ဘဲ၊ စာရင်းတစ်ခုလုံးကို ခွဲခြမ်းစိတ်ဖြာပြီးမှ တကယ့်ပြဿနာရှိနိုင်တဲ့ နေရာတွေကို ပစ်မှတ်ထား ရွေးချယ်ပေးတာ ဖြစ်ပါတယ်။
🔍 ၂။ AI Sampling ၏ အဓိက အလုပ်လုပ်ပုံ (Core AI Sampling Logic)
AI ဟာ Transaction (အရောင်းအဝယ်မှတ်တမ်း) တစ်ခုချင်းစီကို Risk Score (အန္တရာယ်ရှိနိုင်ခြေ အမှတ်) သတ်မှတ်ပေးပါတယ်။
📊 Risk အမှတ်ပေးမည့် အချက်များ (Scoring Factors):
* ငွေပမာဏ ကြီးမားလွန်းခြင်း (Large value)
* ဘဏ္ဍာရေးနှစ်ကုန်ရက်တွင် ရေးသွင်းခြင်း (Year-end posting)
* လူကိုယ်တိုင် ရိုက်သွင်းသော စာရင်းများ (Manual journal)
* သံသယဖြစ်ဖွယ် အကြောင်းအရာများ (ဥပမာ - “Adjustment”, “Reclass”)
* အန္တရာယ်ရှိသော Vendor သို့မဟုတ် ဆက်စပ်ပတ်သက်သူများ (Related party)
* အနှုတ်ပြနေသော သို့မဟုတ် ပြန်ပြောင်းထားသော စာရင်းများ (Negative/Reversal)
* မကြာခဏ ထပ်ခါထပ်ခါ ဖြစ်နေမှုများ (Frequency anomalies)
📌 Risk Score တွက်ချက်နည်း ဥပမာ:
အချက်တစ်ခုချင်းစီကို အလေးချိန် (Weight/Score) ပေးထားပြီး ပေါင်းထည့်တဲ့စနစ်ပါ။ (ဥပမာ - Manual Entry ဆိုရင် ၂၅ မှတ်၊ Related Party ဆို ၃၀ မှတ် စသဖြင့်)။
👉 ရလဒ်ခွဲခြားခြင်း:
* 🔴 High Risk (အန္တရာယ်များ): မဖြစ်မနေ စစ်ဆေးရမည့် စာရင်း (Must test)
* 🟠 Medium Risk (အလယ်အလတ်): Sample ကောက်၍ စစ်ဆေးရန်
* 🟢 Low Risk (အန္တရာယ်နည်း): အနည်းငယ်သာ စစ်ဆေးရန် သို့မဟုတ် Analytical လုပ်ရန်
🔄 ၃။ Walkthrough Test အတွက် AI Sampling အသုံးပြုခြင်း
🎯 ရည်ရွယ်ချက်: လုပ်ငန်းစဉ် စီးဆင်းမှုနှင့် ထိန်းချုပ်မှု (Control) အဆင့်များကို နားလည်ရန်။
🤖 AI ချဉ်းကပ်ပုံ: လုပ်ငန်းစဉ် အမျိုးအစားတစ်ခုလျှင် Transaction ၁ ခု သို့မဟုတ် ၂ ခုကို ရွေးချယ်ပေးပါမည်။ (ဥပမာ - ဝယ်ယူခြင်းမှ COGS သို့၊ WIP မှ COGS သို့ ပြောင်းလဲခြင်း)။
အစမှအဆုံး လွှမ်းခြုံမှုရှိရမည့်အပြင် ပုံမှန်အခြေအနေနှင့် ချွင်းချက်အခြေအနေ (Normal & Exception) နှစ်မျိုးလုံး ပါဝင်ရပါမည်။
📌 ရွေးချယ်မှု စံနှုန်းများ:
* ပုံမှန် Transaction တစ်ခု (ဥပမာ - ပုံမှန် ကုန်ကြမ်းအမြောက်အမြား ဝယ်ယူခြင်း)
* Risk များသော Transaction တစ်ခု
* Exception တစ်ခု (ဥပမာ - စာရွက်စာတမ်း မပြည့်စုံသော ကိစ္စ)
🛡️ ၄။ TOC (Test of Controls) အတွက် AI Sampling အသုံးပြုခြင်း
🎯 ရည်ရွယ်ချက်: ချမှတ်ထားသော Controls များ ထိရောက်စွာ အလုပ်လုပ်ခြင်း ရှိ/မရှိ စစ်ဆေးရန်။
🤖 AI အလုပ်လုပ်ပုံအဆင့်ဆင့်:
* Population Segmentation: လအလိုက်၊ ပရောဂျက်အလိုက် သို့မဟုတ် Control အမျိုးအစားအလိုက် အုပ်စုခွဲခြင်း။
* AI Selection: ကျပန်းရွေးချယ်မှု (Random) နှင့် အန္တရာယ်အပေါ်အခြေခံသော ရွေးချယ်မှု (Risk-based) ကို ပေါင်းစပ်ခြင်း။
📊 Sample အရေအတွက် သတ်မှတ်ချက် (Guidelines):
| Control အကြိမ်အရေအတွက် | AI ရွေးချယ်မည့် Sample အရေအတွက်
>>နေ့စဉ် (Daily) | ၂၅ - ၄၀ ခု
>>လစဉ် (Monthly) | ၃ - ၆ ခု
>>နှစ်စဉ် (Annual) | ၁ - ၂ ခု
🔍 ဥပမာ (COGS ခွင့်ပြုချက် Control စစ်ဆေးခြင်း):
AI သည် တန်ဖိုးကြီး Transaction ၁၀ ခု၊ Random ၁၀ ခု နှင့် ပုံမှန်မဟုတ်သော ၅ ခု ကို ရွေးချယ်ပေးမည် ဖြစ်သည်။
📑 ၅။ TOD (Test of Details) အတွက် AI Sampling အသုံးပြုခြင်း
🎯 ရည်ရွယ်ချက်: လက်ကျန်ငွေများနှင့် အရောင်းအဝယ်မှတ်တမ်းများ မှန်ကန်ကြောင်း အသေးစိတ် အထောက်အထား စစ်ဆေးရန် (Substantive testing)။
🤖 AI ချဉ်းကပ်ပုံ မဟာဗျူဟာ:
* Full Population Analysis: GL သို့မဟုတ် ပရောဂျက် ဒေတာတစ်ခုလုံးကို Scan ဖတ်ခြင်း။
* Stratification (အလွှာခွဲခြားခြင်း):
(1) အဆင့် (Tier)
(2) သတ်မှတ်ချက်(Criteria)
(3)လုပ်ဆောင်ချက် (Action)
| Tier 1 | တန်ဖိုးအကြီးဆုံး စာရင်းများ (ဥပမာ - အကြီးဆုံး Top 10) | ၁၀၀% အားလုံးကို စစ်ဆေးမည် |
| Tier 2 | Medium Risk ရှိသော စာရင်းများ | AI ဖြင့် Sample ရွေးချယ်စစ်ဆေးမည် |
| Tier 3 | Low Risk ရှိသော စာရင်းများ | Analytical Review (ခြုံငုံသုံးသပ်ခြင်း) သာ လုပ်မည် |
📌 အထူးဂရုပြုရမည့် အချက်များ: နှစ်ကုန်ပိုင်းသွင်းသော စာရင်းများ၊ Manual ဝင်ထားသော Journal များ၊ Related parties များနှင့် Reclassifications (စာရင်းပြောင်းလဲမှုများ) ကို အဓိကထား စစ်ဆေးရပါမည်။
⚙️ ၆။ AI Sampling လုပ်ငန်းစဉ် အဆင့်ဆင့် (End-to-End Workflow)
* Import: GL သို့မဟုတ် Project Data များကို System ထဲသို့ ထည့်သွင်းခြင်း။
* Calculate: AI မှ Risk Score များကို တွက်ချက်ပေးခြင်း။
* Classify: Transaction များကို High / Medium / Low အဖြစ် ခွဲခြားပေးခြင်း။
* Generate: Walkthrough, TOC, TOD တို့အတွက် လိုအပ်သော Sample စာရင်းများကို အလိုအလျောက် ထုတ်ပေးခြင်း။
* Export: Audit လုပ်မည့် Working Paper (Excel) သို့ ပြောင်းလဲထုတ်ယူခြင်း။
📊 ၇။ Excel + AI လက်တွေ့ အကောင်အထည်ဖော်ခြင်း (Practical Setup)
Excel တွင် အောက်ပါအတိုင်း Sheet များ ခွဲခြားတည်ဆောက်နိုင်ပါသည်။
* Sheet 1: Raw Data - GL, Vendor, Amount, Date, Description စသည့် အကြမ်းထည် ဒေတာများ။
* Sheet 2: Risk Scoring - AI (သို့) Formula များသုံး၍ Risk တွက်ချက်ခြင်း။
(ဥပမာ - =IF(Amount>Threshold,20,0) + IF(Round=TRUE,20,0) + IF(YearEnd=TRUE,15,0))
* Sheet 3: Sampling Output - Filter များသုံး၍ High risk ကို ထည့်သွင်းပြီး၊ Medium ကို Random ရွေးကာ၊ Low ကို ဖယ်ထုတ်ထားသော ရလဒ် Sheet။
🔐 ၈။ Audit ထိန်းချုပ်မှုဆိုင်ရာ သတိပြုရန်များ (Control & Audit Consideration)
* AI မော်ဒယ်၏ အလုပ်လုပ်ပုံ (Logic) ကို စာရွက်စာတမ်းဖြင့် သေချာ မှတ်တမ်းတင်ထားရန်။
* AI ၏ ရလဒ်များကို Auditor မှ ပြန်လည်သုံးသပ်ရန်နှင့် လိုအပ်ပါက မိမိ၏ Professional Judgment ဖြင့် ပြင်ဆင်နိုင်ခွင့် (Override) ရှိရန်။
* မည်သို့ ရွေးချယ်ခဲ့သည်ဆိုသော မှတ်တမ်း (Audit Trail) ကို သိမ်းဆည်းထားရန်။
⚠️ ၉။ AI Sampling ၏ အားနည်းချက်များနှင့် ဖြေရှင်းနည်း (Risks & Mitigation)
AI အပေါ် အလွန်အမင်း မှီခိုလွန်းခြင်း၊ Risk တွက်ချက်သည့် လော့ဂျစ် မှားယွင်းခြင်း၊ ဒေတာတွင် Bias ပါဝင်နေခြင်းနှင့် AI က မသိနိုင်သော (Qualitative) အချက်အလက်များ လွတ်သွားနိုင်ခြင်း စသည့် အန္တရာယ်များ ရှိပါသည်။
👉 ဖြေရှင်းနည်း: AI ၏ စွမ်းဆောင်ရည်နှင့် Auditor ၏ ဝေဖန်ပိုင်းခြားနိုင်စွမ်း (Judgment) ကို ပေါင်းစပ်အသုံးပြုရန်နှင့် AI Model ကို အခါအားလျော်စွာ ပြန်လည်စစ်ဆေး အကဲဖြတ်ရန် လိုအပ်ပါသည်။
📌 ၁၀။ နောက်ဆုံး ကောက်ချက် (Final Audit Conclusion)
> "AI ကို အခြေခံသော Sampling စနစ်သည် စာရင်းတစ်ခုလုံးကို ပိုင်းခြားစိတ်ဖြာနိုင်စွမ်းနှင့် Risk ပေါ်အခြေခံသော ရွေးချယ်မှုတို့ကို ပေါင်းစပ်ထားသောကြောင့် Audit ၏ ထိရောက်မှုကို များစွာ မြှင့်တင်ပေးပါသည်။ စနစ်တကျ ထိန်းချုပ်ပြီး သေချာစွာ သုံးသပ်နိုင်မည်ဆိုပါက၊ Audit လွှမ်းခြုံနိုင်မှု (Coverage) ကို သိသာစွာ တိုးတက်စေပြီး၊ ပုံမှန်မဟုတ်သော အမှားအယွင်းများကို ပိုမိုဖော်ထုတ်နိုင်ကာ Audit လုပ်ငန်းစဉ်တစ်ခုလုံးကို ပိုမိုသွက်လက် အားကောင်းစေမည် ဖြစ်ပါသည်။
AMH
3 Apr 2026
01/04/2026
စာရွက်ရှားပါးလာမှုနှင့် ပြောင်းလဲလာမယ့် အနာဂတ် Finance လောက နဲ့ Audit Evidence Risk အတွက် AI နဲ့ ဘာတွေ လုပ်သွားနိုင်မလဲ လေ့လာကြည့်ရအောင်
Edit : (IA = Internal Auditor , EA = External Auditor
AI = Artificial Intelligence ဉာဏ်ရည်တုနည်းပညာ အတိုခေါက်ရောမှာစိုးလို့ ။ အထူးသဖြင့် IA vs AI)
စာရွက်ရှားပါးမှုကြောင့် Finance ဌာနက Paperless (စာရွက်မဲ့) ကျင့်သုံးလာတာဟာ Internal Audit (IA) ဌာနအတွက် လုပ်ထုံးလုပ်နည်းဟောင်းတွေကို စွန့်လွှတ်ပြီး ခေတ်မီတဲ့ ဒစ်ဂျစ်တယ်စစ်ဆေးရေးစနစ်သို့ ကူးပြောင်းဖို့ တွန်းအားတစ်ခုဖြစ်ပါတယ်။
ဒီအပြောင်းအလဲရဲ့ အကျိုးဆက်တွေ၊ ကြိုတင်ပြင်ဆင်ရမယ့်အချက်တွေနဲ့ AI ကို အသုံးပြုပြီး စစ်ဆေးရမယ့် နည်းလမ်းတွေကို အသေးစိတ် ရှင်းပြပေးပါမယ်။
အပိုင်း (၁) Finance ဌာန Paperless ကျင့်သုံးခြင်းရဲ့ အကျိုးဆက်များ (Impact)
Finance ဌာနက ဒစ်ဂျစ်တယ်စနစ်သို့ ပြောင်းလဲလိုက်တဲ့အခါ IA အနေနဲ့ အောက်ပါကောင်းကျိုးနဲ့ ဆိုးကျိုး (Risks) တွေကို ရင်ဆိုင်ရပါလိမ့်မယ်။
ကောင်းကျိုးများ:
ပိုမိုမြန်ဆန်သော သတင်းအချက်အလက်ရယူမှု: စာရွက်စာတမ်းတွဲတွေကို လိုက်ရှာစရာမလိုဘဲ ကွန်ပျူတာထဲမှာတင် လိုအပ်တဲ့ Voucher, Invoice တွေကို စက္ကန့်ပိုင်းအတွင်း ရှာဖွေနိုင်ပါတယ်။
အချိန်နှင့်တစ်ပြေးညီ စစ်ဆေးနိုင်ခြင်း (Real-time Auditing): Transactions တွေ ဖြစ်ပျက်နေစဉ်မှာတင် ချက်ချင်း ဝင်ရောက်ကြည့်ရှု စစ်ဆေးနိုင်ပါတယ်။
ဒေတာတိကျမှု ပိုမိုကောင်းမွန်ခြင်း: လူက ရိုက်ထည့်ရတဲ့ (Manual Entry) နေရာမှာ စနစ်အချင်းချင်း ချိတ်ဆက်မှု (ဥပမာ - Bank API နှင့် ERP) တွေကြောင့် မှားယွင်းမှု နည်းပါးသွားပါတယ်။
ကုန်ကျစရိတ် သက်သာခြင်း: စာရွက်၊ မှင်၊ ပုံနှိပ်စရိတ်နဲ့ စာရွက်စာတမ်း သိုလှောင်ရတဲ့ ဂိုဒေါင်ခတွေ သက်သာသွားပါတယ်။
စိန်ခေါ်မှုနှင့် ရင်ဆိုင်ရမယ့် Risks များ:
Cybersecurity Risk: ဒစ်ဂျစ်တယ် စာရွက်စာတမ်းတွေဟာ ဟက်ကာ (Hacker) တွေရဲ့ အန္တရာယ် သို့မဟုတ် ဗိုင်းရပ်စ်ကြောင့် ပျက်စီးဆုံးရှုံးနိုင်ခြေ ရှိပါတယ်။
Internal Control အသစ်များ လိုအပ်ခြင်း: စာရွက်ပေါ်မှာ လက်မှတ်ထိုးတဲ့စနစ် (Physical Signature) အစား ဒစ်ဂျစ်တယ်လက်မှတ် (Digital Signature) သို့မဟုတ် စနစ်အတွင်း ခွင့်ပြုချက် (System Approval Flow) တွေကို မှန်ကန်စွာ သတ်မှတ်ထားဖို့ လိုအပ်ပါတယ်။
IT စနစ်အပေါ် မှီခိုမှု: ERP စနစ် သို့မဟုတ် Server ပျက်စီးသွားပါက စစ်ဆေးရေးလုပ်ငန်းစဉ်လုံးဝ ရပ်ဆိုင်းသွားနိုင်ပါတယ်။
Data Privacy: အထိခိုက်မခံတဲ့ ဘဏ္ဍာရေးဒေတာတွေကို ဝန်ထမ်းတိုင်း မမြင်အောင် Access Control တွေ တင်းကျပ်ဖို့ လိုပါတယ်။
အပိုင်း (၂) Internal Audit များ အနေနဲ့ ဘာတွေ ကြိုပြင်ဆင်ထားရမလဲ
ဒစ်ဂျစ်တယ် ပတ်ဝန်းကျင်မှာ ထိရောက်စွာ စစ်ဆေးနိုင်ဖို့ IA အဖွဲ့ဟာ အောက်ပါအတိုင်း ပြင်ဆင်ရပါမယ်။
၁။ ကျွမ်းကျင်မှု မြှင့်တင်ခြင်း (Skill Upgrading):
Data Analytics ကျွမ်းကျင်မှု: Excel အဆင့်မြင့်သုံးနိုင်ရုံတင်မကဘဲ SQL, Power BI, Tableau, သို့မဟုတ် Python လိုမျိုး ဒေတာခွဲခြမ်းစိတ်ဖြာတဲ့ Tool တွေကို အခြေခံအဆင့်ကနေ အလယ်အလတ်အဆင့်အထိ တတ်မြောက်ထားရပါမယ်။
IT General Controls (ITGC) ကို နားလည်ခြင်း: စနစ်တစ်ခုရဲ့ လုံခြုံရေး၊ Access Control၊ Change Management တွေကို ဘယ်လိုစစ်ဆေးရမလဲဆိုတာ သိထားရပါမယ်။
၂။ စစ်ဆေးရေး နည်းလမ်းများ ပြောင်းလဲခြင်း (Methodology Change):
Remote Auditing စွမ်းရည်: Clients သို့မဟုတ် ဆိုင်ခွဲတွေကို ကိုယ်တိုင်သွားစရာမလိုဘဲ VPN သို့မဟုတ် Cloud-based platform တွေကနေ စစ်ဆေးနိုင်တဲ့ လုပ်ငန်းစဉ်တွေ ချမှတ်ရပါမယ်။
Sampling အစား 100% Population Testing: စာရွက်နဲ့စစ်တုန်းက အစောင် ၁၀၀ မှာ ၁၀ စောင်ပဲ စစ်နိုင်ပေမယ့်၊ ဒစ်ဂျစ်တယ်ဖြစ်သွားတဲ့အတွက် Transactions အားလုံး (100%) ကို Software သုံးပြီး စစ်ဆေးဖို့ ပြင်ဆင်ရပါမယ်။
၃။ Policy နှင့် Infrastructure ပြင်ဆင်ခြင်း:
ဒစ်ဂျစ်တယ် စာရွက်စာတမ်း သိမ်းဆည်းမှု Policy: Finance ဌာနက Scan ဖတ်ထားတဲ့ PDF တွေကို ဘယ်လို Indexing (စနစ်တကျ အမည်ပေးသိမ်းဆည်း) လုပ်ရမလဲ၊ ဘယ်နှစ်နှစ်သိမ်းရမလဲဆိုတာ တိကျတဲ့ Policy ရှိမရှိ စစ်ဆေးပြီး IA အတွက်လည်း Read-only Access ရယူထားရပါမယ်။
SecurePBC စနစ်: Client ဆီကနေ စစ်ဆေးခံမယ့် စာရွက်စာတမ်းတွေကို Email နဲ့ တောင်းမယ့်အစား Secure File Transfer Protocol (SFTP) သို့မဟုတ် GRC platform တွေ သုံးပြီး စနစ်တကျ တောင်းခံရပါမယ်။
အပိုင်း (၃) AI နဲ့ ဒါတွေ ဘယ်လို စစ်ဆေးသင့်လဲ (AI-based Auditing)
AI ဟာ ဒစ်ဂျစ်တယ်စာရွက်စာတမ်းတွေကို လူထက် အဆပေါင်းများစွာ မြန်ဆန်ပြီး တိကျစွာ စစ်ဆေးနိုင်ပါတယ်။
၁။ Anomaly Detection (ပုံမှန်မဟုတ်မှုများကို ရှာဖွေခြင်း) - Machine Learning အသုံးပြုခြင်း:
AI Algorithm တွေကို လွန်ခဲ့တဲ့ ၂ နှစ်၊ ၃ နှစ်က ဘဏ္ဍာရေးဒေတာတွေနဲ့ Train လုပ်ထားပြီး၊ ယခုနှစ်အတွင်း ဖြစ်ပျက်နေတဲ့ Transactions တွေကို နေ့စဉ် စောင့်ကြည့်စေရပါမယ်။
စစ်ဆေးနည်း: AI က Normal Pattern ထဲမှာ မပါတဲ့ ပုံမှန်မဟုတ်တဲ့ ငွေပမာဏ၊ မူမမှန်တဲ့ အချိန် (ဥပမာ - ရုံးပိတ်ရက် ညသန်းခေါင်)၊ သို့မဟုတ် မကြာခဏ အကောင့်တစ်ခုအလီလီ ငွေလွှဲမှုတွေကို လူကို Flag (သတိပေးချက်) ပြပါလိမ့်မယ်။ IA က အဲဒီ Flag ပြတဲ့အချက်တွေကိုပဲ အသေးစိတ်စစ်ဆေးရပါမယ်။
၂။ Travel & Entertainment (T&E) Expenses စစ်ဆေးခြင်း - Computer Vision & NLP:
ဝန်ထမ်းတွေ တင်ပြတဲ့ ဓာတ်ပုံရိုက်ထားတဲ့ Receipt (ပြေစာ) အတုတွေကို AI သုံးပြီး စစ်ဆေးနိုင်ပါတယ်။
စစ်ဆေးနည်း: AI က ပြေစာပေါ်က စာသားတွေကို ဖတ်တယ် (OCR)၊ ပြီးတော့ လက်ရှိစနစ်ထဲက ဒေတာနဲ့ တိုက်ဆိုင်စစ်ဆေးတယ်။ AI က တူညီတဲ့ Receipt ဓာတ်ပုံကိုပဲ နှစ်ခါသုံးထားတာ (Duplicate Claim)၊ Receipt ပေါ်က နေ့စွဲကို ပြင်ထားတာ၊ သို့မဟုတ် Travel Expense Voucher မှာ ကိုယ့်လုပ်ငန်းက ခွင့်မပြုတဲ့ အသုံးစရိတ်တွေကို (Unusual)တင်ပြထားတာတွေကို စက္ကန့်ပိုင်းအတွင်း ရှာဖွေပေးနိုင်ပါတယ်။
၃။ Contract (စာချုပ်) များ စစ်ဆေးခြင်း - Natural Language Processing (NLP):
ထောင်ပေါင်းများစွာသော ဒစ်ဂျစ်တယ်စာချုပ် (PDF) တွေကို AI ကို ဖတ်ခိုင်းနိုင်ပါတယ်။
စစ်ဆေးနည်း: AI ကို "ပေးချေမှုရက်စွဲသည် ရက်ပေါင်း ၆၀ ကျော်ပါက သတင်းပို့ပါ" သို့မဟုတ် "ကန့်သတ်ချက်ထက်ကျော်လွန်သော လျှော့စျေးများပါက Flag ပြပါ" လို့ ညွှန်ကြားထားနိုင်ပါတယ်။ AI က စာချုပ်အားလုံးကို ဖတ်ပြီး high-risk ဖြစ်တဲ့ စာချုပ်တွေကို ခွဲထုတ်ပေးပါလိမ့်မယ်။
၄။ စာရင်းဝင်ပေါက်များ စစ်ဆေးခြင်း (Journal Entry Testing) - Predictive Analytics:
Generative AI (ဥပမာ - ChatGPT သို့မဟုတ် Big 4 တွေရဲ့ ကိုယ်ပိုင် AI Tools) တွေကို သုံးပြီး General Ledger (GL) ထဲက ဒေတာတွေကို ခွဲခြမ်းစိတ်ဖြာခိုင်းနိုင်ပါတယ်။
စစ်ဆေးနည်း: "လွန်ခဲ့တဲ့ ၃ လအတွင်း အခွန်နဲ့ပတ်သက်ပြီး manual ဝင်ထားတဲ့၊ error frequent ဖြစ်တဲ့ user တွေ ဝင်ထားတဲ့ Journal entries တွေကို Summary လုပ်ပေးပါ" လို့ AI ကို မေးခွန်းထုတ်ပြီး ချက်ချင်း အဖြေရယူနိုင်ပါတယ်။
နောက်မှ ဆက်လေ့လာကြအုံးစို့
AMH
2 Apr 2026
21/03/2026
AI ကို သုံးပြီး Internal Audit ဌာနာကို ဘယ်လို အကျိုးပြုအောင်လုပ်မလဲ ?
Internal Audit (IA) ရဲ့ အဓိက ရည်ရွယ်ချက်က လုပ်ငန်းရဲ့ Risk Management, Internal Controls နဲ့ Governance ဖြစ်စဉ်တွေကို အကဲဖြတ်ပြီး တိုးတက်အောင် အကြံဉာဏ်ပေးဖို့ ဖြစ်ပါတယ်။ AI နည်းပညာကို အသုံးချလိုက်တဲ့အခါ Internal Audit ဟာ "အတိတ်ကဖြစ်ခဲ့တာကို နောက်ကြောင်းပြန်စစ်ဆေးတဲ့ (Reactive)" ပုံစံကနေ "အနာဂတ်မှာ ဖြစ်လာနိုင်တာကို ကြိုတင်ခန့်မှန်းကာကွယ်တဲ့ (Proactive)" ပုံစံကို အသွင်ကူးပြောင်းသွားပါတယ်။
AI ကို အသုံးပြုပြီး Internal Audit ကို ဘယ်လို အကျိုးပြုစေသလဲဆိုတာနဲ့ Internal Controls တွေကို ဘယ်လို ခိုင်မာအောင် တည်ဆောက်မလဲဆိုတာကို အသေးစိတ် ရှင်းပြပေးပါမယ်။
၁။ AI ဖြင့် Internal Audit ကို အကျိုးပြုစေခြင်း (Benefits of AI in Internal Audit)
AI ဟာ Auditor တွေရဲ့ နေ့စဉ်လုပ်ငန်းဆောင်တာတွေကို ပိုမိုမြန်ဆန်၊ တိကျပြီး ကျယ်ကျယ်ပြန့်ပြန့် လုပ်ဆောင်နိုင်အောင် ကူညီပေးပါတယ်။
* စဉ်ဆက်မပြတ် စစ်ဆေးခြင်း (Continuous Auditing): အရင်ကလို ၆ လတစ်ခါ၊ တစ်နှစ်တစ်ခါမှ Sample ဆွဲပြီး စစ်ဆေးတာမျိုး မဟုတ်တော့ဘဲ AI က Financial Data တွေကို Real-time စောင့်ကြည့်နေပါတယ်။ ဒါကြောင့် အမှားအယွင်း (Error) သို့မဟုတ် လိမ်လည်မှု (Fraud) တစ်ခု ဖြစ်ပေါ်တာနဲ့ ချက်ချင်း သိရှိနိုင်ပါတယ်။
* ၁၀၀ ရာခိုင်နှုန်း စစ်ဆေးနိုင်ခြင်း (Full Population Testing):
AI ကို အသုံးပြုခြင်းဖြင့် Sampling Risk ကို ဖယ်ရှားနိုင်ပါတယ်။ Transaction သန်းပေါင်းများစွာကို စက္ကန့်ပိုင်းအတွင်း ၁၀၀% အကုန်အစင် စစ်ဆေးပေးနိုင်ပါတယ်။
* စာချုပ်စာတမ်းများကို ခွဲခြမ်းစိတ်ဖြာခြင်း (Natural Language Processing - NLP):
NLP နည်းပညာကို သုံးပြီး စာမျက်နှာ ရာချီရှိတဲ့ ရှုပ်ထွေးသော စာချုပ်များ (Contracts)၊ Board Meeting Minutes တွေထဲကနေ Audit အတွက် အရေးကြီးတဲ့ အချက်အလက်တွေ (ဥပမာ - Compliance လိုက်နာရမယ့် အချက်များ၊ Covenants များ) ကို အလိုအလျောက် ဖတ်ရှုပြီး ဆွဲထုတ်ပေးနိုင်ပါတယ်။
* ကြိုတင်ခန့်မှန်းနိုင်သော စွမ်းရည် (Predictive Risk Analytics):
အတိတ်က ဖြစ်ခဲ့တဲ့ Data တွေ၊ စီးပွားရေး အခြေအနေတွေနဲ့ Industry trends တွေကို ပေါင်းစပ်ပြီး ဘယ် Department သို့မဟုတ် ဘယ် Branch မှာတော့ Control Failure ဖြစ်နိုင်ခြေ အများဆုံးလဲဆိုတာကို AI က ကြိုတင် သတိပေး (Red Flag) နိုင်ပါတယ်။
၂။ AI ကို အသုံးပြု၍ Internal Controls များ တည်ဆောက်ခြင်း
Internal Controls စနစ်ကို ပိုမိုခိုင်မာစေဖို့ AI ကို Preventive, Detective နဲ့ Corrective ဆိုတဲ့ အဆင့် ၃ ဆင့်လုံးမှာ ပေါင်းစပ် တည်ဆောက်နိုင်ပါတယ်။
(က) ကြိုတင်တားဆီးသော ထိန်းချုပ်မှုများ (Preventive Controls)
ပြဿနာ မဖြစ်ခင်ကတည်းက ကြိုတင်တားဆီးပေးတဲ့ Controls တွေဖြစ်ပါတယ်။
* Smart Authorization (စမတ် ခွင့်ပြုချက်စနစ်): AI က Purchasing limits၊ Vendor history နဲ့ Market price တွေကို ချက်ချင်း တိုက်ဆိုင်စစ်ဆေးပါတယ်။ ဥပမာ - Duplicate Invoice (ငွေတောင်းခံလွှာ အထပ်) တက်လာရင်ဖြစ်စေ၊ ပုံမှန်မဟုတ်တဲ့ ဈေးနှုန်းနဲ့ တောင်းခံလာရင်ဖြစ်စေ Payment မထွက်ခင် AI က အလိုအလျောက် Block လုပ်ပစ်တာမျိုး ဖြစ်ပါတယ်။
* Behavioral Access Control: System ထဲကို ဝင်ရောက်တဲ့ User ရဲ့ အပြုအမူကို AI က လေ့လာထားပါတယ်။ ပုံမှန် ရန်ကုန်ကနေ ရုံးချိန်အတွင်း ဝင်နေကျ User Account က ညသန်းခေါင်ယံမှာ နိုင်ငံခြားကနေ ဝင်ရောက်ဖို့ ကြိုးစားလာရင် AI က ချက်ချင်း Lock ချပြီး တားဆီးပေးပါတယ်။
(ခ) ရှာဖွေဖော်ထုတ်သော ထိန်းချုပ်မှုများ (Detective Controls)
အမှားအယွင်းများ၊ လိမ်လည်မှုများကို လျင်မြန်စွာ ရှာဖွေဖော်ထုတ်ပေးတဲ့ Controls တွေဖြစ်ပါတယ်။
* Anomaly Detection (ပုံမှန်မဟုတ်သည်များကို ရှာဖွေခြင်း): Machine Learning Algorithm တွေက ကုမ္ပဏီရဲ့ ပုံမှန် Transaction ပုံစံတွေကို သင်ယူထားပါတယ်။ အကယ်၍ ပုံမှန်မဟုတ်တဲ့ Journal Entries တွေ (ဥပမာ - စနေ၊ တနင်္ဂနွေ ရုံးပိတ်ရက်မှာ စာရင်းသွင်းခြင်း၊ အမြတ်ကို ရုတ်တရက် ပြောင်းလဲသွားစေလောက်တဲ့ Manual Adjustment များသွင်းခြင်း) ကို တွေ့တာနဲ့ Exception Report အဖြစ် ချက်ချင်း ထုတ်ပေးပါတယ်။
* Automated Reconciliations (အလိုအလျောက် စာရင်းတိုက်ဆိုင်စစ်ဆေးခြင်း): Bank Statements တွေနဲ့ Ledger Transactions တွေ၊ Intercompany balances တွေကို AI က အလိုအလျောက် တွဲဖက် (Match) ပေးပါတယ်။ မကိုက်ညီတဲ့ (Unreconciled) အချက်တွေကိုသာ Auditor က ဝင်ရောက် ဖြေရှင်းဖို့ ချန်ထားပေးပါတယ်။
(ဂ) ပြင်ဆင်ပေးသော ထိန်းချုပ်မှုများ (Corrective Controls)
တွေ့ရှိလာတဲ့ ပြဿနာတွေကို မြန်မြန်ဆန်ဆန် ပြုပြင်နိုင်ဖို့ ကူညီပေးပါတယ်။
* Automated Alert & Workflow: AI က Control ပျက်ကွက်မှုတစ်ခုကို တွေ့ရှိတာနဲ့ သက်ဆိုင်ရာ Manager သို့မဟုတ် Chief Audit Executive (CAE) ဆီကို ချက်ချင်း Notification ပို့ပါတယ်။ ထို့အပြင် ယခင်က အလားတူ ပြဿနာမျိုး ဖြစ်ခဲ့စဉ်က ဘယ်လို ဖြေရှင်းခဲ့သလဲ ဆိုတဲ့ သမိုင်းကြောင်းကိုပါ ပြန်လည်ရှာဖွေပြီး Corrective Action Plan ကို အကြံပြုပေးပါတယ်။
၃။ လက်တွေ့ အကောင်အထည်ဖော်ရန် အဆင့်များ (Step-by-Step Implementation)
* Data Standardisation (ဒေတာများ စနစ်တကျ ပြင်ဆင်ခြင်း): AI ဟာ ဒေတာအပေါ်မှာ မှီခိုရတဲ့အတွက် ကုမ္ပဏီရဲ့ Accounting Data တွေ၊ SOP တွေ၊ Policy တွေကို Digital format ဖြစ်အောင် အရင် ပြင်ဆင်ရပါမယ်။ (Garbage In, Garbage Out မဖြစ်စေရန်)။
* Start Small with a Pilot (စမ်းသပ်စီမံကိန်းဖြင့် စတင်ခြင်း): လုပ်ငန်းစဉ်အားလုံးကို တစ်ပြိုင်နက် AI ပြောင်းမယ့်အစား Rule-based ဖြစ်တဲ့ နေရာတွေဖြစ်တဲ့ Accounts Payable (AP) သို့မဟုတ် Payroll Process ကနေ စတင်ပြီး AI Controls တွေကို တည်ဆောက်စမ်းသပ်ပါ။
* Human-in-the-Loop (လူသားနှင့် ပူးပေါင်းလုပ်ဆောင်ခြင်း): AI က သံသယဖြစ်ဖွယ် အချက်တွေကို ဖော်ထုတ်ပေးနိုင်ပေမယ့် နောက်ဆုံး ဆုံးဖြတ်ချက်နဲ့ Professional Skepticism (ဝေဖန်ပိုင်းခြားနိုင်သော သံသယစိတ်) ကတော့ Auditor ဆီမှာပဲ ရှိရပါမယ်။ AI ကို အလုပ်သမားအစားထိုးဖို့မဟုတ်ဘဲ Auditor ရဲ့ စွမ်းဆောင်ရည်ကို မြှင့်တင်ပေးတဲ့ (Augmentation) ကိရိယာအဖြစ် သုံးရပါမယ်။
ဒီလို နည်းစနစ်ကျကျ ပေါင်းစပ်လိုက်မယ်ဆိုရင် Internal Audit Department ဟာ လုပ်ငန်းရဲ့ Risk တွေကို အထိရောက်ဆုံး ကာကွယ်ပေးနိုင်တဲ့ မရှိမဖြစ် မဟာဗျူဟာမြောက် အစိတ်အပိုင်းတစ်ခု ဖြစ်လာမှာပါ။
AMH 21Mar2026
21/03/2026
Auditor တစ်ယောက်အတွက် AI ဆိုတာ အလုပ်ကို မြန်ဆန်စေရုံတင်မဟုတ်ဘဲ Audit Risk ကို သိသိသာသာ လျှော့ချပေးနိုင်တဲ့ လက်နက်ကောင်းတစ်ခုပါ။ AI ကို အသုံးပြုပြီး Audit Risk Model ထဲက အစိတ်အပိုင်းတစ်ခုချင်းစီကို ဘယ်လို Manage လုပ်မလဲဆိုတာ အသေးစိတ် ရှင်းပြပေးပါ့မယ်။
၁။ Inherent Risk (IR) ကို AI ဖြင့် ဆန်းစစ်ခြင်း
Inherent Risk ဆိုတာ လုပ်ငန်းရဲ့ သဘာဝအရ ရှိနေတဲ့ Risk ဖြစ်ပါတယ်။ AI က ဒီနေရာမှာ "ဒေတာအမြောက်အမြားကို ခွဲခြမ်းစိတ်ဖြာခြင်း" အားဖြင့် ကူညီပေးပါတယ်။
* Predictive Analytics: AI ကို အသုံးပြုပြီး Industry trend တွေကို တွက်ချက်နိုင်ပါတယ်။ ဥပမာ - Construction လုပ်ငန်းဆိုရင် ကုန်ကြမ်းဈေးနှုန်း အတက်အကျနဲ့ ပတ်သက်တဲ့ ဒေတာတွေကို AI နဲ့ ခွဲခြမ်းစိတ်ဖြာပြီး Management ရဲ့ Estimates တွေ (ဥပမာ - Cost to complete) ဟာ လက်တွေ့ကျရဲ့လားဆိုတာကို ပိုမိုတိကျစွာ ဆန်းစစ်နိုင်ပါတယ်။
* Complex Pattern Recognition: ရှုပ်ထွေးတဲ့ စာချုပ်တွေ (Contracts) ထဲမှာပါတဲ့ အချက်အလက်တွေကို NLP (Natural Language Processing) သုံးပြီး ရှာဖွေနိုင်ပါတယ်။ ဒါကြောင့် ဝင်ငွေသတ်မှတ်မှု (Revenue Recognition) မှားယွင်းနိုင်ခြေရှိတဲ့ အချက်တွေကို လူက လိုက်ဖတ်တာထက် ပိုမိုမြန်ဆန်ပြီး တိကျစွာ ရှာဖွေနိုင်ပါတယ်။
၂။ Control Risk (CR) ကို AI ဖြင့် လျှော့ချခြင်း
Client ရဲ့ Internal Control အားနည်းမှုကို AI သုံးပြီး စောင့်ကြည့်စစ်ဆေးနိုင်ပါတယ်။
* Continuous Monitoring: ပုံမှန် Audit မှာဆိုရင် တစ်နှစ်ကို တစ်ခါ ဒါမှမဟုတ် ၆ လတစ်ခါပဲ Control တွေကို စစ်ဆေးလေ့ရှိပါတယ်။ AI သုံးရင်တော့ Real-time Monitoring လုပ်နိုင်ပါတယ်။ ဥပမာ - Segregation of Duties (SoD) ကို ချိုးဖောက်ပြီး တစ်ဦးတည်းက Payment တင်တာရော Approve လုပ်တာရော ဖြစ်နေရင် AI က ချက်ချင်း Alert ပေးနိုင်ပါတယ်။
* Automated Exception Reporting: ပုံမှန်မဟုတ်တဲ့ Transaction တွေ (ဥပမာ - အားလပ်ရက်မှာ စာရင်းသွင်းတာ၊ ပမာဏ အရမ်းများတဲ့ Manual Journal တွေ) ကို AI က ချက်ချင်း ခွဲထုတ်ပေးတဲ့အတွက် Control ပျက်ကွက်မှုတွေကို ချက်ချင်း သိနိုင်ပါတယ်။
၃။ Detection Risk (DR) ကို AI ဖြင့် လျှော့ချခြင်း (The Game Changer)
ဒါဟာ Auditor တစ်ယောက်အတွက် AI ရဲ့ အကျိုးကျေးဇူး အရှိဆုံးအပိုင်းပါ။ Detection Risk ကို လျှော့ချဖို့ AI က အောက်ပါအတိုင်း ကူညီပေးပါတယ်-
(က) 100% Full Population Testing
အရင်က Sampling (နမူနာယူစစ်ဆေးခြင်း) ပဲ လုပ်နိုင်ခဲ့ရာကနေ အခု AI သုံးရင် Transaction သန်းပေါင်းများစွာကို (၁၀၀ ရာခိုင်နှုန်း) စစ်ဆေးနိုင်ပါတယ်။ ဒါကြောင့် Sample ထဲမှာ မပါလို့ အမှားလွတ်သွားမယ့် Risk (Sampling Risk) ကို လုံးဝ ပျောက်ကွယ်သွားစေပါတယ်။
(ခ) Anomaly Detection (Machine Learning)
AI က ပုံမှန် Transaction တွေရဲ့ သဘာဝကို သင်ယူထားပြီး အဲဒီထဲကမှ ထူးခြားနေတဲ့ "Anomaly" (ပုံမှန်မဟုတ်တဲ့ အချက်) တွေကို ရှာပေးပါတယ်။ ဥပမာ - လူက စစ်ရင် မတွေ့နိုင်တဲ့ သိမ်မွေ့တဲ့ Fraud pattern တွေကို AI ရဲ့ Algorithm တွေက ရှာဖွေပေးနိုင်ပါတယ်။
(ဂ) Unstructured Data Analysis
Auditor တွေအတွက် အခက်ခဲဆုံးက စာရင်းဇယားမဟုတ်တဲ့ စာရွက်စာတမ်းတွေ (ဥပမာ - PDF invoices, Emails, Meeting minutes) ကို စစ်ရတာပါ။ AI (OCR & NLP) ကို သုံးပြီး ဒီစာရွက်စာတမ်းတွေထဲက အချက်အလက်တွေကို စာရင်းဇယားတွေနဲ့ အလိုအလျောက် တိုက်ဆိုင်စစ်ဆေးနိုင်တဲ့အတွက် Detection Risk ကို အနိမ့်ဆုံးအဆင့်အထိ လျှော့ချနိုင်ပါတယ်။
၄။ AI ကို အသုံးပြုရာတွင် သတိပြုရမယ့် အချက်များ (Best Practices)
AI ကို သုံးပြီး Audit Risk လျှော့ချတဲ့အခါ "Human-in-the-loop" ဖြစ်ဖို့ လိုပါတယ်။
* Verify the Data: AI ဆီ ကျွေးမယ့် ဒေတာတွေက မှန်ကန်ဖို့ လိုပါတယ်။ (Garbage In, Garbage Out)။
* Professional Skepticism: AI က "အိုကေတယ်" လို့ ပြောတိုင်း မယုံပါနဲ့။ AI ရဲ့ output ကို ပြန်လည် ဆန်းစစ်ဝေဖန်နိုင်တဲ့ Auditor ရဲ့ ဦးနှောက်က အမြဲ လိုအပ်ပါတယ်။
* Explainability: AI က ဘာကြောင့် ဒါကို Risk လို့ သတ်မှတ်တာလဲဆိုတဲ့ အကြောင်းရင်း (The "Why") ကို နားလည်အောင် လုပ်ရပါမယ်။
AI ကို အသုံးချခြင်းအားဖြင့် သင်ဟာ Auditor တစ်ယောက်အနေနဲ့ အမှားအယွင်းတွေကို ပိုမိုထိရောက်စွာ ရှာဖွေနိုင်ပြီး Audit Quality ကို Level အသစ်တစ်ခုအထိ မြှင့်တင်နိုင်မှာပါ။
AMH 21 Mar 2026
21/03/2026
Auditor တစ်ယောက်ရဲ့ အဓိက ပန်းတိုင်ကတော့ Audit Risk ကို လက်ခံနိုင်တဲ့ အနိမ့်ဆုံးအဆင့် (Acceptably Low Level) ရောက်အောင် လျှော့ချဖို့ပဲ ဖြစ်ပါတယ်။ ဒါဟာ Audit တစ်ခုလုံးရဲ့ အရည်အသွေးကို ဆုံးဖြတ်ပေးတဲ့ အချက်လည်း ဖြစ်ပါတယ်။
ပေးထားတဲ့ အချက်အလက်တွေအပေါ် အခြေခံပြီး "How to Reduce Audit Risk" ကို အဆင့်ဆင့် (Step-by-Step) နားလည်လွယ်အောင် ရှင်းပြပေးလိုက်ပါတယ်။
🚀 Audit Risk ကို စနစ်တကျ လျှော့ချနည်း (A Step-by-Step Guide)
Audit Risk ဆိုတာ AR = IR \times CR \times DR ဆိုတဲ့ Model အပေါ်မှာ မူတည်နေတာကြောင့် ဒီ Risk ကို လျှော့ချဖို့ဆိုရင် အပိုင်း ၃ ပိုင်းလုံးကို စနစ်တကျ စီမံခန့်ခွဲရမှာ ဖြစ်ပါတယ်။
အဆင့် (၁) - Inherent Risk (IR) ကို အသေအချာ ဆန်းစစ်ခြင်း
Inherent Risk ဆိုတာကတော့ လုပ်ငန်းရဲ့ သဘာဝအရကိုက ရှိနေတဲ့ Risk ဖြစ်ပါတယ်။ ဒါကို Auditor က ပြောင်းလဲလို့ မရပေမယ့် အသေအချာ သိရှိနားလည်ခြင်း အားဖြင့် ကြိုတင်ပြင်ဆင်နိုင်ပါတယ်။
* High-Risk Areas တွေကို အာရုံစိုက်ပါ: Revenue Recognition (ဝင်ငွေသတ်မှတ်ခြင်း)၊ Construction WIP (ဆောက်လုပ်ဆဲလုပ်ငန်းများ) နဲ့ Accounting Estimates တွေလိုမျိုး Management Judgment အများကြီးသုံးရတဲ့ နေရာတွေကို အထူးသတိထားပါ။
* Industry Risk ကို ကြည့်ပါ: လုပ်ငန်းကဏ္ဍအလိုက် ရှိနိုင်တဲ့ Risk (ဥပမာ - Construction ဆိုရင် Cost shifting risk သို့မဟုတ် Stage of completion risk) ကို နားလည်အောင် အရင်လုပ်ပါ။
အဆင့် (၂) - Control Risk (CR) ကို လျှော့ချခြင်း (သို့မဟုတ်) အကဲဖြတ်ခြင်း
Client ရဲ့ Internal Controls တွေက အမှားတွေကို မတားဆီးနိုင်ရင် Control Risk မြင့်တက်လာပါတယ်။ ဒါကို Auditor က အောက်ပါအတိုင်း လုပ်ဆောင်နိုင်ပါတယ်-
* Evaluate Internal Controls: Client ရဲ့ လုပ်ငန်းစဉ်တွေမှာ Segregation of Duties (တာဝန်ခွဲဝေမှု) ရှိရဲ့လား၊ Authorization (ခွင့်ပြုချက်) စနစ်တွေ ကောင်းရဲ့လားဆိုတာ အရင်ကြည့်ပါ။
* Test of Controls (ToC): Controls တွေက စာရွက်ပေါ်မှာတင်မကဘဲ လက်တွေ့မှာပါ ထိရောက်မှု ရှိမရှိ (Operating Effectiveness) ကို စမ်းသပ်ပါ။
* Recommend Improvements: အားနည်းချက်ရှိရင် Client ကို အကြံပြုချက်တွေ ပေးပြီး Controls တွေ ပိုကောင်းအောင် လုပ်ခိုင်းပါ။
အဆင့် (၃) - Detection Risk (DR) ကို လျှော့ချခြင်း (Auditor's Direct Job)
Auditor တစ်ယောက် တိုက်ရိုက် ထိန်းချုပ်ပြီး လျှော့ချနိုင်တဲ့ တစ်ခုတည်းသော Risk ကတော့ Detection Risk ပါ။ IR နဲ့ CR (RMM) မြင့်နေရင် Auditor က DR ကို အနိမ့်ဆုံးဖြစ်အောင် လုပ်ရပါမယ်။
* Substantive Procedures များများလုပ်ပါ: Vouching (စာရင်းမှ အထောက်အထားသို့ ပြန်စစ်ခြင်း) နဲ့ Tracing (အထောက်အထားမှ စာရင်းသို့ စစ်ဆေးခြင်း) တွေကို အသေးစိတ်လုပ်ပါ။
* External Confirmations: ကုမ္ပဏီတွင်း အထောက်အထားထက် ပိုခိုင်မာတဲ့ ပြင်ပအထောက်အထား (ဥပမာ - Bank/Debtor confirmations) တွေကို ရယူပါ။
* Analytical Procedures: ပုံမှန်မဟုတ်တဲ့ Trends တွေ၊ Unusual fluctuations တွေကို ရှာဖွေဖို့ Analytical review တွေ သုံးပါ။
အဆင့် (၄) - Professional Skepticism ကို လက်ကိုင်ထားခြင်း
အချက်အလက်တွေကို ယုံကြည်ရုံတင် မဟုတ်ဘဲ "Questioning Mind" နဲ့ အမြဲဆန်းစစ်ပါ။
* Challenge Management Assumptions: Management ရဲ့ ခန့်မှန်းချက်တွေ (ဥပမာ- Provision for bad debts) ဟာ လက်တွေ့ကျရဲ့လားဆိုတာကို ပြင်းပြင်းထန်ထန် မေးခွန်းထုတ်ပါ။
* Contradictory Evidence: ကိုယ်ရထားတဲ့ အထောက်အထားတွေအချင်းချင်း ဆန့်ကျင်နေတာမျိုး ရှိမရှိ (ဥပမာ- Profit ပြနေပေမယ့် Cash flow က Negative ဖြစ်နေတာမျိုး) ကို သတိပြုပါ။
အဆင့် (၅) - Materiality နှင့် Sampling ကို ပြန်လည်ညှိနှိုင်းခြင်း
Risk မြင့်တဲ့နေရာတွေမှာ အမှားအယွင်း အနည်းငယ်တောင် မရှိစေဖို့အတွက်-
* Lower Materiality: Risk များတဲ့ နေရာတွေမှာ Performance Materiality ကို လျှော့ချသတ်မှတ်ပြီး ပိုမိုစေ့စပ်အောင် စစ်ဆေးပါ။
* Increase Sample Size: Risk မြင့်လေလေ၊ စစ်ဆေးရမယ့် နမူနာ (Sample) ပမာဏကို တိုးမြှင့်လေလေ လုပ်ရပါမယ်။
📌 Final Professional Summary
Audit Risk ကို လုံးဝ (Zero) ဖြစ်အောင် မလုပ်နိုင်ပေမယ့်၊ စနစ်တကျ Planning ဆွဲခြင်း၊ Internal Controls တွေကို နားလည်ခြင်းနဲ့ ခိုင်မာတဲ့ Substantive Testing တွေ ပြုလုပ်ခြင်းအားဖြင့် Acceptably Low Level ရောက်အောင် လျှော့ချနိုင်ပါတယ်။
AMH 21 Mar 2026
Audit
21/03/2026
Audit Risk ဆိုတာကို ရိုးရိုးရှင်းရှင်းပြောရရင် - ကုမ္ပဏီရဲ့ Financial Statements တွေမှာ ကြီးမားတဲ့မှားယွင်းမှုတွေ (Material Misstatement) ရှိနေလျက်နဲ့ Auditor က ရှာမတွေ့ဘဲ "စာရင်းတွေ မှန်ပါတယ်" ဆိုပြီး မှားယွင်းတဲ့ Audit Opinion (Inappropriate Opinion) ပေးမိဖို့ ဖြစ်နိုင်ခြေ (Possibility) ကို ဆိုလိုတာပါ။
ဒါဟာ Auditor တစ်ယောက်အတွက် အကြီးမားဆုံး အမှားအယွင်းနဲ့ Risk ဖြစ်ပါတယ်။ ဒါကြောင့် Audit လုပ်ငန်းစဉ်တစ်ခုလုံးဟာ ဒီ Risk ကို လက်ခံနိုင်လောက်တဲ့ အနိမ့်ဆုံးအဆင့် (Acceptably Low Level) သို့ လျှော့ချဖို့အတွက်ပဲ ပုံဖော်ထားတာ ဖြစ်ပါတယ်။
🔍 Audit Risk Model ကို နားလည်ခြင်း
Audit Risk ကို ပိုမိုစနစ်တကျ တွက်ချက်စီမံနိုင်ဖို့အတွက် အောက်ပါ Model ကို အသုံးပြုပါတယ်:
🧮 Audit Risk (AR) = Inherent Risk (IR) × Control Risk (CR) × Detection Risk (DR)
ဒီ Model အရ Audit Risk ဟာ အပိုင်း ၃ ပိုင်းကြောင့် ဖြစ်ပေါ်လာတာပါ:
🔺 ၁. Inherent Risk (IR) - သဘာဝအလျောက်ရှိနေသော Risk
Internal Controls တွေကို ထည့်မစဉ်းစားခင်မှာပဲ၊ စာရင်းတစ်ခု သို့မဟုတ် Transaction တစ်ခုရဲ့ သဘာဝအရကိုက Material Misstatement ဖြစ်ဖို့ များနေတဲ့ risk ပါ။ Complex ဖြစ်တဲ့ area တွေ၊ Judgment အများကြီးသုံးရတဲ့ area တွေမှာ IR မြင့်တတ်ပါတယ်။
👉 High IR examples:
Revenue Recognition with complex contracts (ရှုပ်ထွေးသော စာချုပ်များမှ ဝင်ငွေအသိအမှတ်ပြုခြင်း)
Accounting Estimates (ECL provisions, Impairment) - ခန့်မှန်းခြေစာရင်းများ
Foreign Currency transactions
Related Party transactions
🔺 ၂. Control Risk (CR) - ထိန်းချုပ်မှုဆိုင်ရာ Risk
ဒါကတော့ Client ရဲ့ Internal Controls စနစ်က Material Misstatements တွေကို အချိန်မီ တားဆီးဖို့ (Prevent) သို့မဟုတ် ရှာဖွေပြင်ဆင်ဖို့ (Detect & Correct) ပျက်ကွက်မယ့် Risk ပါ။ Client ဘက်မှာ Control အားနည်းရင် CR မြင့်ပါတယ်။
👉 High CR examples:
No Segregation of Duties (တာဝန်ခွဲဝေမှု မရှိခြင်း)
Weak IT access control (Software access ကို စနစ်တကျ မထိန်းချုပ်ခြင်း)
No review of Bank/Receivable Reconciliations (စာရင်းတိုက်ဆိုင်စစ်ဆေးမှုများအား review မလုပ်ခြင်း)
💡 praktically, IR နဲ့ CR ကိုပေါင်းပြီး Risk of Material Misstatement (RMM) လို့ ခေါ်ပါတယ်။ ဒါဟာ Client ဘက်မှာ Audit မတိုင်ခင်ကတည်းက ရှိနေတဲ့ Risk ပါ။ (RMM = IR × CR)
🔺 ၃. Detection Risk (DR) - ရှာဖွေမှုဆိုင်ရာ Risk
ဒါကတော့ Auditor ရဲ့ Procedures တွေက စာရင်းထဲမှာရှိနေတဲ့ Material Misstatement ကို ရှာမတွေ့မိဘဲ လွတ်သွားမယ့် Risk ပါ။ ဒီ Risk တစ်ခုတည်းသာ Auditor က တိုက်ရိုက် လွှမ်းမိုးစီမံနိုင်ပါတယ်။
👉 DR ဖြစ်စေတဲ့ အကြောင်းရင်းများ:
Sample size too small (နမူနာယူမှု နည်းလွန်းခြင်း)
Wrong audit procedure selected (မှားယွင်းသော စစ်ဆေးမှုနည်းလမ်းသုံးခြင်း)
Lack of Professional Skepticism (ဝေဖန်ပိုင်းခြားနိုင်သော သံသယစိတ် အားနည်းခြင်း)
✅ Audit Risk Model ၏ အပြန်အလှန်ဆက်သွယ်မှု (Interrelationship)
Audit Risk Concept ရဲ့ အဓိက သော့ချက်ကတော့ RMM နှင့် Detection Risk (DR) တို့ကြားရှိ ဆန့်ကျင်ဘက်ဆက်ဆံရေး (Inverse Relationship) ပါပဲ။
Auditor က Client ဆီမှာ RMM (IR + CR) မြင့်တယ် လို့ သုံးသပ်ရင် -> Audit Risk ကို လျှော့ချဖို့အတွက် Auditor ဘက်က DR ကို အနိမ့်ဆုံးဖြစ်အောင် လုပ်ရပါမယ်။
DR နိမ့်အောင် ဘယ်လိုလုပ်မလဲ? -> Audit work တွေကို ပိုမိုကျယ်ကျယ်ပြန့်ပြန့် လုပ်ရပါမယ် (More Extensive Substantive Procedures - Increase Sample Size, Use experienced staff, Year-end testing).
ပြန်ချုပ်ရရင်: High IR & CR -> Lower DR needed -> More Audit Work needed.
📊 Financial Statement Level Risk vs Assertion Level Risk
RMM (Risk of Material Misstatement) ကို level ၂ ခုမှာ သုံးသပ်ရပါတယ်-
🅰️ Financial Statement Level Risk:
ဒါဟာ Financial Statements တစ်ခုလုံးကို ခြုံငုံပြီး သက်ရောက်မှုရှိတဲ့ Risk တွေပါ။ (ဥပမာ - Weak management integrity, poor accounting system, Going concern problems).
➡️ Response: Broader response needed, more supervision, experienced team.
🅱️ Assertion Level Risk:
ဒါကတော့ သီးခြား account balance, class of transactions သို့မဟုတ် disclosure တွေနဲ့ သက်ဆိုင်တဲ့ Risk ပါ။ (assertions are Existence, Completeness, Accuracy, Valuation etc.).
👉 For Receivables: Risk of Existence (Debtors are real?) သို့မဟုတ် Risk of Valuation (Recoverable?).
⚠️ Business Risk vs Audit Risk (မရောထွေးပါနဲ့)
Business Risk: ကုမ္ပဏီက သူ့ရဲ့ Objectives တွေ မအောင်မြင်မှာကို စိုးရိမ်ရတဲ့ Risk ပါ (ဥပမာ - Loss of customers, Economic downturn).
Audit Risk: Auditor က Opinion မှားပေးမိမှာကို စိုးရိမ်ရတဲ့ Risk ပါ။
Connection: သို့သော် Business Risk ကြီးမားတဲ့အခါ (ဥပမာ- Cash flow ပြဿနာ) Management က profit ကို manipulation လုပ်ဖို့ ဖိအားရှိလာနိုင်တဲ့အတွက် Audit Risk ကို မြင့်တက်စေပါတယ်။
💡 Conclusion
Auditor တစ်ယောက်အနေနဲ့ Acceptably Low Level of Audit Risk သို့ ရောက်ရှိအောင် စစ်ဆေးဖို့အတွက်- Professional Skepticism ကို အပြည့်အဝ သုံးရမယ်၊ Experienced staff တွေ သုံးရမယ်၊ Supervision & Review ကောင်းရမယ်၊ ပြီးတော့ Significant Estimates နဲ့ Manual Journal Entries တွေလို high-risk area တွေကို Focus လုပ်ပြီး substantive testing ပိုမိုလုပ်ဆောင်ရပါမယ်။
Audit strategy ကောင်းကောင်းဆွဲဖို့အတွက် Audit Risk Model ကို နားလည်ဖို့က မရှိမဖြစ်ပါပဲ။
AI နဲ့ အောက်က English လေးတွေလဲ လေ့လာကြည့်ရအောင် 😊
Audit Risk means the risk that an auditor gives an inappropriate audit opinion when the financial statements are materially misstated.
In simple words:
The auditor says the financial statements are okay, but actually they contain a material error or fraud.
1) Standard meaning of audit risk
Audit risk is the possibility that:
Material misstatement exists
but
the auditor fails to detect it
and issues an unmodified / clean opinion
This is one of the most important concepts in audit because the whole audit approach is built around managing this risk.
---
2) Audit Risk Model
The common audit risk model is:
Audit Risk (AR) = Inherent Risk (IR) × Control Risk (CR) × Detection Risk (DR)
This means audit risk comes from three parts:
A. Inherent Risk (IR)
This is the risk that an account balance, transaction, or disclosure is naturally prone to material misstatement before considering internal controls.
It exists because some areas are more difficult, judgmental, complex, or open to fraud.
Examples:
Revenue recognition with many contracts
Inventory with obsolete or damaged goods
Construction WIP and percentage of completion
Estimates like provision, impairment, ECL
Related party transactions
Foreign currency transactions
Higher inherent risk means the area is naturally riskier.
---
B. Control Risk (CR)
This is the risk that the client’s internal controls fail to prevent or detect and correct material misstatements on time.
Examples:
No segregation of duties
No approval for journal entries
Weak IT access control
No reconciliation of bank or receivable balances
No review of contract cost allocation
Poor control over inventory counting
If internal controls are weak, control risk is high.
---
C. Detection Risk (DR)
This is the risk that the auditor’s procedures will not detect a material misstatement that already exists.
This risk relates to the audit work itself.
Examples:
Sample size too small
Wrong audit procedure selected
Auditor overlooks unusual entries
Poor professional skepticism
Inadequate follow-up on exceptions
Reliance on unreliable evidence
Unlike IR and CR, detection risk can be influenced by the auditor.
---
3) Relationship between the three risks
If IR and CR are high:
Then the auditor must keep detection risk low.
How?
Increase sample size
Perform more substantive testing
Use more experienced staff
Test year-end balances instead of interim only
Obtain stronger external evidence
Perform unpredictable procedures
If IR and CR are low:
The auditor may accept a relatively higher detection risk.
That means:
Less extensive testing may be acceptable
More reliance may be placed on controls
---
4) Why audit risk is important
Audit risk is important because it affects:
Audit planning
Nature, timing, and extent of procedures
Staffing and supervision
Materiality considerations
Areas requiring more professional skepticism
Final audit opinion
Auditors do not eliminate risk completely.
They reduce audit risk to an acceptably low level.
---
5) Components explained with easy example
Take inventory as an example:
Inherent Risk
Inventory may be:
damaged
obsolete
stolen
wrongly valued
wrongly counted
So IR may be high.
Control Risk
If the company:
does not perform stock counts
has weak warehouse control
does not reconcile stock records
allows one person to receive, record, and issue stock
Then CR is high.
Detection Risk
If the auditor:
attends stock count carelessly
takes too few samples
does not test valuation properly
ignores slow-moving items
Then DR is high.
Result:
Overall audit risk becomes high.
---
6) Types of risk in practical audit work
When auditors discuss audit risk in practice, they often focus on:
a) Risk of Material Misstatement (RMM)
This is:
RMM = IR × CR
It means the risk that the financial statements are materially misstated before the audit procedures detect it.
This is assessed at:
Financial statement level
Assertion level
---
b) Detection Risk
This is managed by the auditor through procedures.
So practically:
Audit Risk = Risk of Material Misstatement × Detection Risk
---
7) Financial statement level risk vs assertion level risk
A. Financial Statement Level Risk
These are risks affecting the financial statements as a whole.
Examples:
Weak management integrity
Poor accounting system
Going concern problems
Inexperienced finance team
Weak overall internal control environment
Pressure to meet profit targets
Impact:
Broader audit response needed
More supervision
More unpredictability
More experienced team members
---
B. Assertion Level Risk
These relate to specific account balances, classes of transactions, or disclosures.
Assertions include:
Existence
Completeness
Accuracy
Valuation
Cut-off
Rights and obligations
Presentation and disclosure
Example: For receivables:
Existence: are debtors real?
Valuation: are they recoverable?
Completeness: are all balances recorded?
---
8) Example of audit risk in construction company
Since construction companies are high-risk in audit, this is a good example.
Common risk areas:
Revenue recognition by stage of completion
Contract cost allocation
Variation orders and claims
Accrual for subcontractor cost
Retention receivables
Cut-off of project revenue and cost
WIP valuation
Provision for foreseeable loss contracts
Why risk is high:
Heavy management judgment
Complex contracts
Many supporting documents
Manual estimates
Risk of manipulation to show profit
Audit response:
Review contracts
Test certified progress billings
Recalculate stage of completion
Test cost incurred to source documents
Check cut-off around year-end
Review post year-end settlement
Confirm balances when necessary
Evaluate provision for loss-making projects
---
9) Example of high audit risk indicators
Auditors become more alert when they see:
Unusual journal entries at year-end
Rapid growth in revenue
Weak documentation
Large manual adjustments
Related party transactions
Management override of controls
Poor segregation of duties
Significant estimates
Complex new accounting policies
Prior year misstatements
Fraud allegations
Negative cash flow despite reported profit
These are red flags.
---
10) Difference between business risk and audit risk
Business Risk
Risk that the company fails to achieve its objectives.
Examples:
Loss of customers
Economic downturn
Increased raw material prices
Legal disputes
Liquidity problems
Audit Risk
Risk that the auditor gives the wrong opinion on materially misstated financial statements.
Business risk can increase audit risk, but they are not the same.
Example: If a company has serious cash flow problems, management may manipulate revenue or understate liabilities.
So business risk may lead to higher audit risk.
---
11) How auditor responds to high audit risk
When audit risk is high, auditor may:
Increase professional skepticism
Assign experienced staff
Increase supervision and review
Perform more substantive procedures
Increase sample size
Obtain external confirmations
Use experts
Focus on year-end testing
Perform surprise procedures
Test journal entries and management override
Reassess going concern
Lower performance materiality
---
12) Audit risk and materiality relationship
Audit risk and materiality are closely linked.
If materiality is lower, auditor needs more work
If risk is higher, auditor usually performs more extensive work
High-risk areas often require lower tolerable misstatement
So both affect audit strategy.
---
13) Very simple formula meaning
You can remember like this:
IR = How risky the area is by nature
CR = How weak the client’s controls are
DR = How likely the auditor misses the error
If:
the account is risky,
controls are weak,
and audit testing is poor,
then audit risk becomes very high.
---
14) Easy real-life example
Imagine auditing cash:
Cash is highly susceptible to theft → IR
No independent bank reconciliation → CR
Auditor does not obtain bank confirmation → DR
Then there is a strong chance material misstatement is not detected.
---
15) Final summary
Audit risk is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated.
It has 3 parts:
Inherent Risk = natural susceptibility to misstatement
Control Risk = failure of internal controls
Detection Risk = auditor fails to detect the misstatement
Formula:
AR = IR × CR × DR
Main idea:
High IR + high CR → auditor must reduce DR
Auditor reduces DR by stronger audit procedures
AMH 21 Mar 2026