ISA standards contents

ISA standards

ISA 315 (Revised 2019)

Identifying and Assessing the Risks of Material Misstatement

1Objective and scope

ISA 315 (Revised 2019) deals with the auditor's responsibility to identify and assess the risks of material misstatement in the financial statements, whether due to fraud or error, through understanding the entity and its environment, the applicable financial reporting framework, and the entity's system of internal control. It is the foundation for the responses designed under ISA 330. The 2019 revision, effective for periods beginning on or after 15 December 2021, introduced the inherent risk factors and the spectrum of inherent risk, separated the assessment of inherent and control risk, redefined the five components of the system of internal control, expanded the treatment of IT (general IT controls and the IT environment), and added a stand-back evaluation.

The objective is to identify and assess the risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels, thereby providing a basis for designing and implementing responses to the assessed risks.

2Key definitions

Assertions
Representations, explicit or otherwise, with respect to the recognition, measurement, presentation and disclosure of information in the financial statements, inherent in management representing that the statements are prepared in accordance with the framework. For classes of transactions: occurrence, completeness, accuracy, cut-off, classification, presentation. For account balances: existence, rights and obligations, completeness, accuracy valuation and allocation, classification, presentation.
Inherent risk factors
Characteristics of events or conditions that affect susceptibility to misstatement, before consideration of controls: complexity, subjectivity, change, uncertainty, and susceptibility to misstatement due to management bias or other fraud risk factors.
Spectrum of inherent risk
The range of likelihood and magnitude of a possible misstatement on which the auditor places an assessed inherent risk. Significant risks lie at the upper end.
Significant risk
An identified risk of material misstatement for which the assessment of inherent risk is close to the upper end of the spectrum because of the degree to which the inherent risk factors affect the combination of likelihood and magnitude, or that is to be treated as significant under another ISA (fraud risks under ISA 240, significant related party transactions outside the normal course of business under ISA 550).
Relevant assertion
An assertion about a class of transactions, account balance or disclosure where there is a reasonable possibility of a misstatement that would be material. The class, balance or disclosure is then a significant class of transactions, account balance or disclosure.
System of internal control
The system designed, implemented and maintained by those charged with governance, management and other personnel to provide reasonable assurance about the achievement of objectives regarding the reliability of financial reporting, effectiveness and efficiency of operations, and compliance with law. Five components: the control environment, the entity's risk assessment process, the entity's process to monitor the system, the information system and communication, and control activities.
General IT controls
Controls over the entity's IT processes that support the continued proper operation of the IT environment, including the continued effective functioning of information processing controls and the integrity of information. They cover access, program changes and IT operations.
Controls
Policies or procedures an entity establishes to achieve its control objectives. Information processing controls relate directly to the processing of information in the information system; the auditor identifies controls that address risks of material misstatement at the assertion level and evaluates their design and whether they have been implemented.

3Requirements

Risk assessment procedures and sources of information

  • Perform risk assessment procedures to obtain audit evidence that provides an appropriate basis for identifying and assessing risks and for designing further procedures. They must include inquiries of management and of others within the entity (internal audit, those charged with governance, staff outside finance), analytical procedures, and observation and inspection.
  • Consider information from acceptance and continuance, from other engagements for the entity, and, on a recurring audit, from previous experience, after determining whether changes have occurred that affect its relevance.
  • The engagement partner and key team members discuss the application of the framework and the susceptibility of the financial statements to material misstatement; matters discussed are communicated to team members not present.
  • Exercise professional scepticism throughout, and design the procedures so that evidence is obtained in an unbiased manner (not only evidence that corroborates management's view).

Understanding the entity, its environment and the framework

The auditor obtains an understanding of the entity's organisational structure, ownership and governance, and business model (including the extent to which it integrates IT); the industry, regulatory and other external factors; the measures used internally and externally to assess financial performance; the applicable financial reporting framework and the entity's accounting policies and the reasons for any changes; and how inherent risk factors affect susceptibility of assertions to misstatement. The understanding is used to identify where misstatements are likely and to evaluate whether the accounting policies are appropriate and consistent with the framework.

Understanding the system of internal control

ComponentWhat the auditor does
Control environmentUnderstand how management's oversight, integrity and ethical values, commitment to competence, organisational structure and assignment of authority, and HR policies establish the foundation for the other components; evaluate whether management has created a culture of honesty and whether control environment deficiencies undermine the other components.
Entity's risk assessment processUnderstand how the entity identifies business risks relevant to financial reporting, assesses their significance and likelihood, and addresses them; evaluate whether the process is appropriate to the entity's circumstances. A failure to identify a risk the auditor finds is evaluated for what it says about the process.
Process to monitor the system of internal controlUnderstand how the entity monitors its controls (ongoing evaluations, internal audit) and remediates deficiencies, and the sources of information used; evaluate appropriateness.
Information system and communicationUnderstand how transactions are initiated, recorded, processed, corrected, transferred to the ledger and reported, including the IT environment (applications, infrastructure, IT processes), the records and journal entries (including non-standard entries), and how the entity communicates financial reporting roles and responsibilities.
Control activitiesIdentify controls that address risks at the assertion level: controls over significant risks, over journal entries, controls the auditor plans to test for operating effectiveness, and other controls judged appropriate. For each, evaluate the design and determine whether it has been implemented. Identify the IT applications and general IT controls those controls depend on, and the risks arising from the use of IT.

Identifying and assessing the risks

  • Identify risks of material misstatement and determine whether they exist at the financial statement level (pervasive risks such as a weak control environment, going concern doubt, management override) or the assertion level, and identify the relevant assertions and the significant classes of transactions, balances and disclosures.
  • Assess inherent risk for each identified risk at the assertion level by assessing the likelihood and magnitude of misstatement, taking into account how and the degree to which the inherent risk factors affect susceptibility, and place the risk on the spectrum. Determine whether any is a significant risk.
  • Assess control risk: if the auditor plans to test the operating effectiveness of controls, control risk is assessed on the expectation that they operate effectively; if not, control risk is assessed so that the assessment of the risk of material misstatement is the same as the assessment of inherent risk.
  • Determine whether substantive procedures alone cannot provide sufficient appropriate evidence for any risk at the assertion level (routine, highly automated processing with little manual intervention), in which case controls must be tested.
  • Stand back: evaluate whether the evidence from the risk assessment procedures provides an appropriate basis for the identification and assessment, and whether the classes of transactions, balances and disclosures not identified as significant are indeed not significant. Revise the assessment where new information is inconsistent with the original evidence.

Placing a risk on the spectrum

A manufacturer's finished goods inventory: valuation involves overhead absorption (complexity), an estimate of net realisable value for slow-moving lines (subjectivity, uncertainty), a new costing system this year (change), and a management bonus tied to gross margin (bias).

Several inherent risk factors act on the valuation assertion, the possible misstatement is likely and could be large, so inherent risk sits near the upper end: a significant risk.

Response under ISA 330: understand the entity's controls over costing, test them if reliance is planned, and perform substantive procedures specifically responsive to the significant risk, including tests of detail on NRV and overhead rates, not analytical procedures alone.

4Documentation and reporting

The auditor documents the discussion among the team and the significant decisions reached; the key elements of the understanding of the entity, its environment, the framework and each component of the system of internal control, the sources of information, and the risk assessment procedures performed; the evaluation of the design and implementation of identified controls; the identified and assessed risks at both levels, including significant risks and risks for which substantive procedures alone are insufficient, and the rationale for the significant judgements. Findings about internal control feed the ISA 265 communication, and significant risks are communicated to those charged with governance under ISA 260 as part of the planned scope and timing; nothing from ISA 315 appears in the auditor's report directly, though the significant risks are often the source of key audit matters under ISA 701.

5Examinable focus

What KASNEB tests

The heaviest examined standard after ISA 200: know the assertions for transactions and for balances and be able to name the assertion a procedure tests; know the five components of internal control (with the 2019 names) and the inherent risk factors; and be able to work a scenario, identifying risks of material misstatement with the assertion affected and the reason, then placing them on the spectrum and flagging significant risks. Expect questions on the risk assessment procedures (inquiry, analytical procedures, observation and inspection) and on how control risk is assessed differently depending on whether controls will be tested. General IT controls and the risks arising from IT (unauthorised access, unauthorised program changes, failure to update systems, inappropriate manual intervention, data loss) are current favourites in Advanced Auditing.