ISA 315 (Revised 2019)
Identifying and Assessing the Risks of Material Misstatement
1Objective and scope
ISA 315 (Revised 2019) deals with the auditor's responsibility to identify and assess the risks of material misstatement in the financial statements, whether due to fraud or error, through understanding the entity and its environment, the applicable financial reporting framework, and the entity's system of internal control. It is the foundation for the responses designed under ISA 330. The 2019 revision, effective for periods beginning on or after 15 December 2021, introduced the inherent risk factors and the spectrum of inherent risk, separated the assessment of inherent and control risk, redefined the five components of the system of internal control, expanded the treatment of IT (general IT controls and the IT environment), and added a stand-back evaluation.
The objective is to identify and assess the risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels, thereby providing a basis for designing and implementing responses to the assessed risks.
2Key definitions
3Requirements
Risk assessment procedures and sources of information
- Perform risk assessment procedures to obtain audit evidence that provides an appropriate basis for identifying and assessing risks and for designing further procedures. They must include inquiries of management and of others within the entity (internal audit, those charged with governance, staff outside finance), analytical procedures, and observation and inspection.
- Consider information from acceptance and continuance, from other engagements for the entity, and, on a recurring audit, from previous experience, after determining whether changes have occurred that affect its relevance.
- The engagement partner and key team members discuss the application of the framework and the susceptibility of the financial statements to material misstatement; matters discussed are communicated to team members not present.
- Exercise professional scepticism throughout, and design the procedures so that evidence is obtained in an unbiased manner (not only evidence that corroborates management's view).
Understanding the entity, its environment and the framework
The auditor obtains an understanding of the entity's organisational structure, ownership and governance, and business model (including the extent to which it integrates IT); the industry, regulatory and other external factors; the measures used internally and externally to assess financial performance; the applicable financial reporting framework and the entity's accounting policies and the reasons for any changes; and how inherent risk factors affect susceptibility of assertions to misstatement. The understanding is used to identify where misstatements are likely and to evaluate whether the accounting policies are appropriate and consistent with the framework.
Understanding the system of internal control
| Component | What the auditor does |
|---|---|
| Control environment | Understand how management's oversight, integrity and ethical values, commitment to competence, organisational structure and assignment of authority, and HR policies establish the foundation for the other components; evaluate whether management has created a culture of honesty and whether control environment deficiencies undermine the other components. |
| Entity's risk assessment process | Understand how the entity identifies business risks relevant to financial reporting, assesses their significance and likelihood, and addresses them; evaluate whether the process is appropriate to the entity's circumstances. A failure to identify a risk the auditor finds is evaluated for what it says about the process. |
| Process to monitor the system of internal control | Understand how the entity monitors its controls (ongoing evaluations, internal audit) and remediates deficiencies, and the sources of information used; evaluate appropriateness. |
| Information system and communication | Understand how transactions are initiated, recorded, processed, corrected, transferred to the ledger and reported, including the IT environment (applications, infrastructure, IT processes), the records and journal entries (including non-standard entries), and how the entity communicates financial reporting roles and responsibilities. |
| Control activities | Identify controls that address risks at the assertion level: controls over significant risks, over journal entries, controls the auditor plans to test for operating effectiveness, and other controls judged appropriate. For each, evaluate the design and determine whether it has been implemented. Identify the IT applications and general IT controls those controls depend on, and the risks arising from the use of IT. |
Identifying and assessing the risks
- Identify risks of material misstatement and determine whether they exist at the financial statement level (pervasive risks such as a weak control environment, going concern doubt, management override) or the assertion level, and identify the relevant assertions and the significant classes of transactions, balances and disclosures.
- Assess inherent risk for each identified risk at the assertion level by assessing the likelihood and magnitude of misstatement, taking into account how and the degree to which the inherent risk factors affect susceptibility, and place the risk on the spectrum. Determine whether any is a significant risk.
- Assess control risk: if the auditor plans to test the operating effectiveness of controls, control risk is assessed on the expectation that they operate effectively; if not, control risk is assessed so that the assessment of the risk of material misstatement is the same as the assessment of inherent risk.
- Determine whether substantive procedures alone cannot provide sufficient appropriate evidence for any risk at the assertion level (routine, highly automated processing with little manual intervention), in which case controls must be tested.
- Stand back: evaluate whether the evidence from the risk assessment procedures provides an appropriate basis for the identification and assessment, and whether the classes of transactions, balances and disclosures not identified as significant are indeed not significant. Revise the assessment where new information is inconsistent with the original evidence.
Placing a risk on the spectrum
A manufacturer's finished goods inventory: valuation involves overhead absorption (complexity), an estimate of net realisable value for slow-moving lines (subjectivity, uncertainty), a new costing system this year (change), and a management bonus tied to gross margin (bias).
Several inherent risk factors act on the valuation assertion, the possible misstatement is likely and could be large, so inherent risk sits near the upper end: a significant risk.
Response under ISA 330: understand the entity's controls over costing, test them if reliance is planned, and perform substantive procedures specifically responsive to the significant risk, including tests of detail on NRV and overhead rates, not analytical procedures alone.
4Documentation and reporting
The auditor documents the discussion among the team and the significant decisions reached; the key elements of the understanding of the entity, its environment, the framework and each component of the system of internal control, the sources of information, and the risk assessment procedures performed; the evaluation of the design and implementation of identified controls; the identified and assessed risks at both levels, including significant risks and risks for which substantive procedures alone are insufficient, and the rationale for the significant judgements. Findings about internal control feed the ISA 265 communication, and significant risks are communicated to those charged with governance under ISA 260 as part of the planned scope and timing; nothing from ISA 315 appears in the auditor's report directly, though the significant risks are often the source of key audit matters under ISA 701.
5Examinable focus
What KASNEB tests
The heaviest examined standard after ISA 200: know the assertions for transactions and for balances and be able to name the assertion a procedure tests; know the five components of internal control (with the 2019 names) and the inherent risk factors; and be able to work a scenario, identifying risks of material misstatement with the assertion affected and the reason, then placing them on the spectrum and flagging significant risks. Expect questions on the risk assessment procedures (inquiry, analytical procedures, observation and inspection) and on how control risk is assessed differently depending on whether controls will be tested. General IT controls and the risks arising from IT (unauthorised access, unauthorised program changes, failure to update systems, inappropriate manual intervention, data loss) are current favourites in Advanced Auditing.