HKSA 315 - Identifying and Assessing Risks of Material Misstatement (Condensed)
| Section Name | Key Concept | Brief Description |
|---|---|---|
| Introduction | Scope & Objective | Auditorโs responsibility to identify and assess risks of material misstatement at financial statement and assertion levels. |
| Definitions (para 12) | Key Terms | Defines assertions, business risk, controls, IT controls, inherent risk factors, significant risk, system of internal control, etc. |
| Risk Assessment Procedures (para 13-18) | Procedures & Discussion | Inquiries, analytical procedures, observation/inspection; engagement team discussion; use of previous audit information. |
| Understanding the Entity (para 19-27) | Entity & Internal Control | Understanding entity, environment, financial reporting framework, and five components of internal control. |
| Identifying & Assessing Risks (para 28-37) | Risk Identification & Assessment | Identify risks at financial statement and assertion levels; assess inherent risk, control risk, significant risks. |
| Documentation (para 38) | Required Documentation | Document discussion, understanding, control evaluation, identified and assessed risks. |
| Application Material | Key Explanatory Points | Professional skepticism, scalability, iterative process, spectrum of inherent risk. |
Introduction & Objective (para 1-11)
Scope of HKSA 315 (Revised 2019)
Deals with auditor's responsibility to identify and assess risks of material misstatement in financial statements. Effective for periods beginning on or after 15 December 2021.
Audit Risk Framework (HKSA 200)
Audit risk = function of risks of material misstatement and detection risk. Risks exist at two levels: overall financial statement level and assertion level.
Components of Risk at Assertion Level
| Component | Description |
|---|---|
| Inherent Risk | Susceptibility of an assertion to a material misstatement before consideration of any related controls. |
| Control Risk | Risk that a misstatement will not be prevented, or detected and corrected, on a timely basis by the entity's controls. |
Objective
Identify and assess risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels, providing a basis for designing and implementing responses.
Definitions (para 12)
Key Definitions
| Term | Definition |
|---|---|
| Assertions | Representations inherent in management's statement that financial statements are prepared in accordance with the applicable financial reporting framework. |
| Business Risk | Risk resulting from conditions, events, circumstances, actions or inactions that could adversely affect an entity's ability to achieve its objectives. |
| Controls | Policies or procedures established to achieve control objectives. |
| General IT Controls | Controls over IT processes that support continued proper operation of the IT environment. |
| Information Processing Controls | Controls relating to processing of information that directly address risks to integrity of information. |
| Inherent Risk Factors | Characteristics affecting susceptibility to misstatement before consideration of controls: complexity, subjectivity, change, uncertainty, susceptibility to management bias. |
| Significant Risk | Risk where assessment of inherent risk is close to the upper end of the spectrum of inherent risk. |
| System of Internal Control | System designed to provide reasonable assurance about achievement of objectives regarding reliability of financial reporting, effectiveness of operations, and compliance. |
Five Inter-related Components of Internal Control
- Control environment
- The entity's risk assessment process
- The entity's process to monitor the system of internal control
- The information system and communication
- Control activities
Risk Assessment Procedures (para 13-18)
Design and Performance of Risk Assessment Procedures (para 13)
Auditor shall design and perform risk assessment procedures to obtain audit evidence that provides an appropriate basis for identification and assessment of risks of material misstatement.
Types of Risk Assessment Procedures (para 14)
| Procedure | Description |
|---|---|
| Inquiries | Of management and other appropriate individuals within the entity, including internal audit function. |
| Analytical Procedures | Help identify inconsistencies, unusual transactions or events, amounts, ratios, and trends. |
| Observation and Inspection | May support, corroborate or contradict inquiries; provides information about entity and its environment. |
Information from Other Sources (para 15-16)
Consider information from acceptance/continuance procedures and other engagements. Evaluate whether information from previous audits remains relevant and reliable.
Engagement Team Discussion (para 17-18)
Engagement partner and key team members shall discuss application of the financial reporting framework and susceptibility of financial statements to material misstatement.
Understanding the Entity & Environment (para 19-20)
Required Understanding (para 19)
Auditor shall perform risk assessment procedures to obtain understanding of:
| Aspect | Details |
|---|---|
| Organizational structure, ownership, governance, and business model | Complexity of structure, ownership relationships, governance oversight, business objectives and strategies, integration of IT. |
| Industry, regulatory and other external factors | Market conditions, competition, regulatory framework, legislation, economic conditions. |
| Measures used to assess financial performance | Key performance indicators, budgets, forecasts, variance analyses, incentive compensation policies. |
| Applicable financial reporting framework and accounting policies | Accounting principles, industry-specific practices, revenue recognition, financial instruments, unusual transactions. |
| How inherent risk factors affect susceptibility of assertions | Understanding events or conditions that may affect likelihood or magnitude of misstatement. |
Evaluation of Accounting Policies (para 20)
Auditor shall evaluate whether the entity's accounting policies are appropriate and consistent with the applicable financial reporting framework.
Understanding Internal Control Components (para 21-27)
Control Environment (para 21)
Understand the set of controls, processes and structures addressing management's oversight responsibilities, independence of those charged with governance, assignment of authority and responsibility, attracting competent individuals, and accountability.
Entity's Risk Assessment Process (para 22-23)
Understand the entity's process for identifying business risks relevant to financial reporting objectives, assessing significance, and addressing those risks. If management failed to identify risks the auditor expects would have been identified, consider implications.
Entity's Process to Monitor Internal Control (para 24)
Understand ongoing and separate evaluations for monitoring effectiveness of controls, identification and remediation of control deficiencies, and the internal audit function.
Information System and Communication (para 25)
Understand information processing activities, how transactions are initiated, recorded, processed, and reported, and how the entity communicates significant matters supporting financial statement preparation.
Control Activities (para 26)
Identify controls that address risks at assertion level, including controls over significant risks, journal entries, and controls for which the auditor plans to test operating effectiveness. Evaluate design and implementation of identified controls.
Control Deficiencies (para 27)
Determine whether one or more control deficiencies have been identified based on evaluation of each component of internal control.
Identifying & Assessing Risks (para 28-37)
Identifying Risks of Material Misstatement (para 28-29)
Identify risks and determine whether they exist at financial statement level or assertion level. Determine relevant assertions and related significant classes of transactions, account balances and disclosures.
Categories of Assertions
| Category | Description |
|---|---|
| Occurrence | Transactions recorded have occurred and pertain to the entity. |
| Completeness | All transactions that should have been recorded have been recorded. |
| Accuracy | Amounts and other data have been recorded appropriately. |
| Cutoff | Transactions recorded in the correct accounting period. |
| Classification | Transactions recorded in the proper accounts. |
| Existence | Assets, liabilities and equity interests exist. |
| Rights and obligations | Entity holds rights to assets and liabilities are obligations of the entity. |
| Valuation | Assets, liabilities and equity interests are included at appropriate amounts. |
| Presentation | Transactions, events, accounts and disclosures are appropriately aggregated or disaggregated and clearly described. |
Assessing Risks at Financial Statement Level (para 30)
Assess risks, determine whether they affect assertion level risks, and evaluate their pervasive effect on financial statements.
Assessing Inherent Risk at Assertion Level (para 31-33)
Assess likelihood and magnitude of misstatement, taking into account inherent risk factors and financial statement level risks. Determine whether any assessed risks are significant risks.
Assessing Control Risk (para 34)
If planning to test operating effectiveness of controls, assess control risk. If not, assessment of control risk shall be such that assessment of risk of material misstatement is the same as assessment of inherent risk.
Evaluation of Audit Evidence (para 35-37)
Evaluate whether audit evidence obtained provides appropriate basis for risk identification and assessment. Take into account all audit evidence, whether corroborative or contradictory. Revise risk assessment if new inconsistent information is obtained.
Documentation (para 38)
Required Documentation
| Requirement | Description |
|---|---|
| (a) | The discussion among the engagement team and the significant decisions reached. |
| (b) | Key elements of the auditor's understanding in accordance with paragraphs 19, 21, 22, 24 and 25; sources of information; and risk assessment procedures performed. |
| (c) | The evaluation of the design of identified controls and determination whether such controls have been implemented. |
| (d) | The identified and assessed risks of material misstatement at the financial statement level and at the assertion level, including significant risks and risks for which substantive procedures alone cannot provide sufficient appropriate audit evidence, and the rationale for significant judgments made. |
Key Takeaways
| Topic | Key Point |
|---|---|
| Objective | Identify and assess risks of material misstatement at financial statement and assertion levels. |
| Risk Assessment Procedures | Inquiries, analytical procedures, observation and inspection. |
| Understanding Required | Entity and its environment, applicable financial reporting framework, system of internal control. |
| Internal Control Components | Control environment, risk assessment process, monitoring process, information system and communication, control activities. |
| Inherent Risk Assessment | Assess likelihood and magnitude of misstatement considering inherent risk factors. |
| Control Risk Assessment | Assess if planning to test operating effectiveness; otherwise same as inherent risk. |
| Significant Risk | Inherent risk close to upper end of spectrum. |
| Documentation | Discussion, understanding, evaluation of controls, identified and assessed risks. |
| Professional Skepticism | Essential throughout the risk assessment process. |
| Iterative Process | Risk assessment is dynamic and continues throughout the audit. |
โ Ready to Test?
50 MCQs โข 1.25 min each โข 62.5 min total
๐ Start Q&A โ๐ Full Reference Version๐จ๏ธ Save as PDF