> For the complete documentation index, see [llms.txt](https://engyon.gitbook.io/engyon/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://engyon.gitbook.io/engyon/training/training-english/module-8-risk-response-three-point-model.md).

# Module 8: Risk Response Three-Point Model

For each identified risk, an audit response must be designed: the procedures that need to be performed to reduce the risk to an acceptably low level.

For engagements that use the `Three-Point Model`, the assurance obtained from the procedures can be documented in the engagement file and supported with an explanation.

In this module, we will add substantive procedures to a risk. For each procedure, we will then indicate how much assurance is obtained from that procedure.

### Creating a Risk Response

1. Navigate to the `Risk Response` page using the navigation menu.

   This page provides an overview of all financial statement line items, identified risks, and substantive procedures planned to address those risks. Financial statement line items that are not `In Scope` are shown as dimmed.

   Click financial statement line items, risks, or procedures to show the relationships between these objects.
2. Open the risk you created by clicking its title.
3. You will be taken to the risk detail screen, on the `Risk Response` tab.

   For each financial statement line item and assertion, the audit plans are shown for each component.
4. No procedures have been planned yet, which means that the assurance score is still insufficient.

   Click the assurance score to see where assurance can be obtained from.
5. Click the add button on the right-hand side of the screen, next to `Procedures`, to plan substantive procedures for the audit plan.
6. Add several procedures and link them to your audit plan.

   Once the procedures have been linked, you will see them appear in the audit plan.
7. You have now planned procedures and can assign an assurance score to them.

   Click the assurance score for each procedure to adjust it, and confirm by clicking the `✓` button. Do this for all procedures.
8. Add an explanation of the assurance obtained from the audit plan and why this is sufficient.

### Specifying Planned Procedures

9. Click one of the procedures, such as `Capital Expenditure (Sample Testing)`, that is linked to your audit  plan.
10. This opens the detail screen of the procedure.

    As you can see, the procedure is still in `Draft`, meaning it can still be further specified by adding instructions or by adding or removing activities.

    * Click the AI button next to the instruction on the procedure step. This opens a text field. Based on the context of the procedure, Engyon will suggest an instruction. You can accept and edit the suggestion, or reject it.
    * Delete an activity by clicking the delete button.
    * Hover your mouse between activities. The option `Add Activity` will appear.
    * Click `Add Activity` to add an activity.
    * Edit the title and instructions by clicking them, entering the desired text, and clicking the `✓` button.
11. As you can see, you cannot yet perform the activities. This is because you are still planning the procedures and the procedure is therefore still in `Draft`.

    Below, we explain how to move the procedure step out of `Draft`.

    > It is also possible to add an empty template to the audit plan and add activities as needed.

### Finalizing the Audit Plan Specification

12. Navigate back to the `Risk Response` on your risk by clicking back in your browser, or by navigating to the risk again through the `Risk Response` page.
13. You can move all planned substantive procedures out of `Draft` at once by clicking `Status: In Progress` and then clicking `Close Specification`.
14. The audit plan on your risk is now `Ready for Review`.

    You can assign it to a colleague for review or, depending on your role, review it yourself.
15. Once the control plan has been reviewed, the audit plan and the related procedures are no longer in `Draft`.

    The status is now changed to `Unassigned`, and procedures can no longer be added or removed.

    To make changes at a later stage, the audit plan can be moved back to `Draft` by clicking the `Status` bar and reopening the specification.

    Closing the audit plan helps prevent both `Over-Auditing` and `Under-Auditing`.

### Performing Procedures and Working with Audit Documentation

16. Click a procedure.
17. Assign the procedure to a colleague by clicking the assignment icon in the top-left corner.
18. Open one of the procedures within the audit plan.

    As you can see, you can now perform the activities.
19. Drag the Excel file `Working Paper Substantive Procedure` onto an activity.
20. The uploaded document is now part of your `Audit Documentation`.

    Edit the document by clicking the edit button. This opens the Microsoft environment.  This does require that your Office environment uses the same e-mail address as the email address you are logged into Engyon with.

    Multiple colleagues can work in an audit documentation document at the same time, and all changes are automatically saved within the engagement file in Engyon.
21. Click the create file button to create a blank file that becomes part of your `Audit Documentation`.

{% hint style="info" %}
The first time you open a Microsoft Office document from Engyon, the loading time will be slightly longer and you will need to grant permission for the OneDrive connection.
{% endhint %}
