Risk Assessment Checklist
Governance and Strategy
Confirm the enterprise risk management policy is signed by the board and dated within the last 12 months. Note any drift between the stated risk appetite and current strategic plan — that gap is the partner discussion.
Read the last four quarters of audit committee minutes. Tag any open risk items not yet remediated and any management responses that the committee declined to accept.
Verify the committee has met at least quarterly per its charter and that membership still satisfies independence requirements. Document attendance gaps as a governance deficiency.
Risk Identification
Run a 90-minute structured workshop covering revenue, procurement, treasury, IT, and HR process owners. Capture entity-level and process-level risks separately; the most common miss is omitting the IT general controls layer.
Roll forward last quarter's register, retire risks that are no longer relevant, and add risks raised in the workshop. Each risk needs an owner, a category (financial, operational, compliance, strategic, IT), and a current control reference.
Check recent SEC enforcement actions, FASB ASUs, AICPA risk alerts, and industry-specific guidance issued since the last assessment. Cyber, climate disclosure, and crypto holdings are the recurring 2024–25 themes.
Risk Assessment
Use the firm's 1–5 likelihood × 1–5 impact heat map. Score gross (inherent) and net (residual after controls) separately — partners want to see where existing controls are actually pulling the rating down.
Apply performance materiality (typically 50–75% of overall materiality) to flag risks that could individually cause a material misstatement. Anything rated High on the residual heat map should be cross-referenced to a key control.
Reconcile this quarter's heat map to last year's. Material rating changes need a written rationale in the workpaper — auditors and the audit committee both ask why a risk dropped from High to Medium.
Control Activities
Every High residual risk needs at least one named key control with a documented owner, frequency, and evidence type. Manual reviews without sign-off evidence are the most common audit finding.
Walk through each key control with the owner. Confirm segregation of duties for the journal-entry, wire-approval, and user-access controls — these three account for the bulk of significant deficiencies in SMB engagements.
Record each deficiency with severity, affected assertion, and management response. Include the workpaper reference so the deficiency ties back to evidence in the engagement binder.
For any significant deficiency, draft a remediation plan with named owner, target date, and re-test date. Significant deficiencies must be communicated in writing to the audit committee under AU-C 265 / AS 1305.
Information and Communication
Send each owner the slice of the register they own — not the full document. Confirm receipt; the register is a shared accountability artifact, not a CYA email.
When residual ratings include any High, the chair expects a written alert ahead of the next scheduled meeting. Include the risk, owner, and proposed mitigation timeline — keep it to one page.
Present the heat map, year-over-year rating changes, deficiencies identified, and remediation status. Allow time for executive session without management present — the committee often raises items there that don't surface in the open meeting.
Index workpapers in Caseware or CCH Engagement under the risk-assessment section. Include the workshop notes, register, heat map, deficiency log, and committee deck — these become the audit support for the planning section.
Monitoring and Sign-Off
Put the next workshop, the audit committee meeting, and the deficiency re-test dates on the engagement calendar. Re-tests of significant deficiencies should land before the next external audit fieldwork.
Partner reviews the heat map, deficiency log, and committee communication. Sign-off is the gate to closing the assessment in the workflow tool and releasing the binder to the audit team.
Use this template in Manifestly
- Month-End Close Checklist
- New Vendor Onboarding Checklist
- New Employee Onboarding Checklist
- Staff Offboarding Checklist
- Quarterly Bookkeeping Checklist
- Year-End Accounting Checklist
- Deal Closure Checklist
- Monthly Bookkeeping Close Checklist
- Engagement Budgeting Checklist
- Project Cost Control Checklist
- Tax Audit Documentation Checklist
- Engagement Risk Management Checklist
- Monthly Financial Close Checklist
- Contract Review Checklist
- Segregation of Duties Assessment
- Acquisition Integration Checklist
- Profitability Analysis Checklist
- Post-Merger Audit Checklist
- Financial Ratio Analysis Checklist
- M&A Due Diligence Checklist
- Legal Entity Management Checklist
- Cash Flow Analysis Checklist
- Year-End Bookkeeping Checklist
- Year-End Tax Planning Checklist
- Monthly Financial Review Checklist
- Financial Audit Checklist
- Billing Process Checklist
- Client Engagement Closeout Checklist
- Corporate Tax Preparation Checklist
- Cost-Benefit Analysis Checklist
- SOX Compliance Checklist
- Fraud Prevention Checklist
- Weekly Bookkeeping Checklist
- Cash Application Checklist
- Daily Bookkeeping Checklist
- Internal Audit Preparation Checklist
- Customer Credit Approval Checklist
- Internal Control Procedures Checklist
- Accounts Receivable Aging Report Checklist
- Quarterly Internal Control Review Checklist
- Corporate Tax Return Preparation Checklist
- Budget Variance Analysis Checklist
- Monthly Accounting Close Checklist
- Accounts Payable Aging Report Checklist
- Client Engagement Letter Renewal
- Capital Expenditure (CapEx) Approval Checklist
- Payroll Tax Filing Checklist
- Employee Expense Reimbursement Checklist
- Annual Financial Statements Checklist
- Quarterly Payroll Tax Compliance Checklist
- Grant Accounting Checklist
- End-of-Month Sales and Revenue Reporting
- Collections Management Checklist
- Cost Accounting Checklist
- System Access Control Checklist
- Accounting Policy Update Cycle
- Financial Analysis Checklist
- New Client Onboarding Checklist
- Firm Insurance Renewal Checklist
- Cash Flow Management Checklist
- Payroll Services Checklist
- New Employee Onboarding Checklist (Accounting Department)
- Business Tax Compliance Checklist
- Employee Expense Policy Compliance Checklist
- Credit and Collections Checklist
- Regulatory Compliance Checklist
- External Audit Preparation Checklist
- Investment Reconciliation Checklist
- Monthly Management Reports Checklist
- Annual Budget Preparation Checklist
- Accounts Payable Ledger Checklist
- AP Payment Processing Checklist
- Merger and Acquisition Due Diligence Checklist
- Lease Accounting Checklist
- Journal Entry Checklist
- Chart of Accounts Maintenance Checklist
- Payroll Processing Checklist
- Accounting Department Workflow Optimization
- Financial Reporting Checklist
- New Business Structuring Checklist
- Audit Preparation Checklist
- Accounts Payable Checklist
- Financial Project Planning Checklist
- Yearly Accounting Department Goals Setting
- Consulting and Advisory Services Checklist
- Account Reconciliation Checklist
- Chart of Accounts Review Checklist
- Tax Planning Checklist
- Fixed Assets Audit Checklist
- Vendor Setup and Maintenance Checklist
- Client Onboarding Checklist
- Individual Tax Return Preparation Checklist
- Employee Termination Checklist (Accounting Department)
- Cash Flow Analysis Checklist
- Risk Management Checklist
- Expense Reporting and Reimbursement Checklist
- Monthly Close Process
- Business Valuation Checklist
- Bank Reconciliation Checklist
- Sales Tax Reporting Checklist
- Internal Controls Review Checklist
- Budgeting and Forecasting Checklist
- Financial Statement Audit Checklist
- Accounting Standards Update Adoption Checklist
- Monthly Bookkeeping and Accounting Close
- Business Succession Planning
- Financial Statement Preparation Checklist
- Inventory Accounting Close Checklist
- Accounts Receivable Checklist
- Monthly Financial Reporting Checklist
- Financial Risk Assessment Checklist
- Quarterly Financial Reporting Checklist
- Performance Review Checklist (Accounting Staff)
- Vendor Contract Negotiation Checklist
- Accounting Software Migration Checklist
- Quarterly Budget Review Checklist
- Debt Management Checklist
- Fixed Assets Management Checklist
- Loan Covenant Compliance Checklist
- Accounting Software Implementation Checklist
- Cash Management Checklist
- Financial Statement Audit Checklist
- Audit Preparation Checklist
- Fixed Assets Audit Checklist
- External Audit Preparation Checklist
- Financial Audit Checklist
- Post-Merger Audit Checklist
- Employee File Audit Checklist
- Engagement Risk Management Checklist
- Rent Roll Audit Checklist
- Financial Audit Checklist
- Quarterly Industry Standards Compliance Review
- Audit Preparation Checklist
- Compliance Audit Checklist
- HR Audit Checklist
- Social Media Audit Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
