Auditing Standard No. (AS) 5 provides guidance in the required audit of internal control over financial reporting and its integration into the financial statement audit. AS 5 advocates a “top-down” approach, in which control testing helps the auditor assess the risk of financial misstatement across multiple locations. We consider a manager who oversees two locations and who has private information about internal control strength in each location. Only when controls are weak can the manager commit fraud. We show how the manager's opportunity to commit fraud and informational characteristics of internal control tests impact the manager's probability choice of fraud and the auditor's choice of substantive test effort.

