HKSA 315 - Identifying and Assessing Risks of Material Misstatement
HKSA 315 (Revised 2019) - Identifying and Assessing the Risks of Material Misstatement
INTRODUCTION
Scope of HKSA 315
HKSA 315 (Revised 2019) deals with the auditor's responsibility to identify and assess the risks of material misstatement in the financial statements. This standard is effective for audits of financial statements for periods beginning on or after 15 December 2021.
Key Concepts
Audit Risk Framework (HKSA 200)
Professional Requirements
Components of Risk at Assertion Level
| Component | Description |
|---|---|
| Inherent Risk | Susceptibility of an assertion to a misstatement that could be material, before consideration of any related controls |
| Control Risk | Risk that a misstatement will not be prevented, or detected and corrected, on a timely basis by the entity's controls |
Spectrum of Inherent Risk
Nature of Risks
Iterative and Dynamic Process
Scalability
HKSA 315 is intended for audits of all entities, regardless of size or complexity. The application material incorporates specific considerations for both less complex and more complex entities. While the size of an entity may be an indicator of its complexity, some smaller entities may be complex and some larger entities may be less complex.
Objective
The objective of the auditor is to identify and assess the risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels, thereby providing a basis for designing and implementing responses to the assessed risks of material misstatement.
DEFINITIONS (Paragraph 12)
Assertions (12(a))
Representations, explicit or otherwise, with respect to the recognition, measurement, presentation and disclosure of information in the financial statements which are inherent in management representing that the financial statements are prepared in accordance with the applicable financial reporting framework. Assertions are used by the auditor to consider the different types of potential misstatements that may occur when identifying, assessing and responding to the risks of material misstatement.
Business Risk (12(b))
A risk resulting from significant conditions, events, circumstances, actions or inactions that could adversely affect an entity's ability to achieve its objectives and execute its strategies, or from the setting of inappropriate objectives and strategies.
Controls (12(c))
Policies or procedures that an entity establishes to achieve the control objectives of management or those charged with governance.
| Element | Description |
|---|---|
| Policies | Statements of what should, or should not, be done within the entity to effect control. May be documented, explicitly stated in communications, or implied through actions and decisions |
| Procedures | Actions to implement policies |
General Information Technology (IT) Controls (12(d))
Controls over the entity's IT processes that support the continued proper operation of the IT environment, including the continued effective functioning of information processing controls and the integrity of information (i.e., the completeness, accuracy and validity of information) in the entity's information system.
Information Processing Controls (12(e))
Controls relating to the processing of information in IT applications or manual information processes in the entity's information system that directly address risks to the integrity of information (i.e., the completeness, accuracy and validity of transactions and other information).
Inherent Risk Factors (12(f))
Characteristics of events or conditions that affect susceptibility to misstatement, whether due to fraud or error, of an assertion about a class of transactions, account balance or disclosure, before consideration of controls. Such factors may be qualitative or quantitative, and include:
| Factor | Description |
|---|---|
| Complexity | Degree of difficulty in understanding or processing |
| Subjectivity | Extent of judgment involved |
| Change | Degree of change in conditions or circumstances |
| Uncertainty | Lack of certainty about outcomes |
| Susceptibility to misstatement due to management bias or other fraud risk factors | Potential for intentional or unintentional bias |
IT Environment (12(g))
The IT applications and supporting IT infrastructure, as well as the IT processes and personnel involved in those processes, that an entity uses to support business operations and achieve business strategies.
| Component | Description |
|---|---|
| IT Application | A program or set of programs used in the initiation, processing, recording and reporting of transactions or information. Includes data warehouses and report writers |
| IT Infrastructure | Network, operating systems, databases and their related hardware and software |
| IT Processes | Entity's processes to manage access to the IT environment, manage program changes or changes to the IT environment and manage IT operations |
Relevant Assertions (12(h))
An assertion about a class of transactions, account balance or disclosure is relevant when it has an identified risk of material misstatement. The determination of whether an assertion is a relevant assertion is made before consideration of any related controls (i.e., the inherent risk).
Risks Arising from the Use of IT (12(i))
Susceptibility of information processing controls to ineffective design or operation, or risks to the integrity of information (i.e., the completeness, accuracy and validity of transactions and other information) in the entity's information system, due to ineffective design or operation of controls in the entity's IT processes.
Risk Assessment Procedures (12(j))
The audit procedures designed and performed to identify and assess the risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels.
Significant Class of Transactions, Account Balance or Disclosure (12(k))
A class of transactions, account balance or disclosure for which there is one or more relevant assertions.
Significant Risk (12(l))
An identified risk of material misstatement:
System of Internal Control (12(m))
The system designed, implemented and maintained by those charged with governance, management and other personnel, to provide reasonable assurance about the achievement of an entity's objectives with regard to reliability of financial reporting, effectiveness and efficiency of operations, and compliance with applicable laws and regulations.
Five Inter-related Components:
REQUIREMENTS
Risk Assessment Procedures and Related Activities (Paragraphs 13-18)
Design and Performance of Risk Assessment Procedures (Paragraph 13)
The auditor shall design and perform risk assessment procedures to obtain audit evidence that provides an appropriate basis for:
Critical Requirement: The auditor shall design and perform risk assessment procedures in a manner that is not biased towards obtaining audit evidence that may be corroborative or towards excluding audit evidence that may be contradictory.
Why Unbiased Evidence is Important (A14)
Designing and performing risk assessment procedures to obtain audit evidence in an unbiased manner may assist the auditor in identifying potentially contradictory information, which may assist the auditor in exercising professional skepticism in identifying and assessing the risks of material misstatement.
Sources of Audit Evidence (A15)
Sources of information for risk assessment procedures may include:
Types of Risk Assessment Procedures (Paragraph 14)
The risk assessment procedures shall include:
(a) Inquiries of management and of other appropriate individuals within the entity, including individuals within the internal audit function (if the function exists)
Why Inquiries are Made (A22-A23)
Examples of Inquiries (A23)
(b) Analytical procedures
Why Analytical Procedures are Performed (A27-A28)
Types of Analytical Procedures (A29)
(c) Observation and inspection
Why Observation and Inspection are Performed (A32)
Examples of Observation and Inspection (A34)
Information from Other Sources (Paragraph 15)
In obtaining audit evidence, the auditor shall consider information from:
Why Other Sources are Important (A37)
Information from other sources may provide insights about:
Information from Previous Audits (Paragraph 16)
When the auditor intends to use information obtained from the auditor's previous experience with the entity and from audit procedures performed in previous audits, the auditor shall evaluate whether such information remains relevant and reliable as audit evidence for the current audit.
Nature of Information from Previous Audits (A40)
Engagement Team Discussion (Paragraphs 17-18)
The engagement partner and other key engagement team members shall discuss:
When there are engagement team members not involved in the discussion, the engagement partner shall determine which matters are to be communicated to those members.
Why Discussion is Required (A42)
Scalability Considerations (A44-A45)
Obtaining an Understanding of the Entity and Its Environment, the Applicable Financial Reporting Framework and the Entity's System of Internal Control (Paragraphs 19-27)
Understanding the Entity and Its Environment, and the Applicable Financial Reporting Framework (Paragraphs 19-20)
Paragraph 19 - Required Understanding
The auditor shall perform risk assessment procedures to obtain an understanding of:
(a) The following aspects of the entity and its environment:
(i) The entity's organizational structure, ownership and governance, and its business model, including the extent to which the business model integrates the use of IT
Organizational Structure and Ownership (A56)
Governance (A59-A60)
Business Model (A61-A65)
(ii) Industry, regulatory and other external factors
Industry Factors (A68-A69)
Regulatory Factors (A70)
Other External Factors (A73)
(iii) The measures used, internally and externally, to assess the entity's financial performance
Why Understanding Measures is Important (A74-A75)
Key Indicators (A77)
(b) The applicable financial reporting framework, and the entity's accounting policies and the reasons for any changes thereto
Matters to Consider (A82)
(c) How inherent risk factors affect susceptibility of assertions to misstatement and the degree to which they do so
Why Understanding Inherent Risk Factors is Important (A85-A86)
Paragraph 20 - Evaluation of Accounting Policies
The auditor shall evaluate whether the entity's accounting policies are appropriate and consistent with the applicable financial reporting framework.
Understanding the Components of the Entity's System of Internal Control (Paragraphs 21-27)
Control Environment, the Entity's Risk Assessment Process and the Entity's Process to Monitor the System of Internal Control (Paragraphs 21-24)
Control Environment (Paragraph 21)
The auditor shall obtain an understanding of the control environment relevant to the preparation of the financial statements by:
(a) Understanding the set of controls, processes and structures that address:
(b) Evaluating whether:
The Entity's Risk Assessment Process (Paragraphs 22-23)
The auditor shall obtain an understanding of the entity's risk assessment process relevant to the preparation of the financial statements by:
(a) Understanding the entity's process for:
(b) Evaluating whether the entity's risk assessment process is appropriate to the entity's circumstances considering the nature and complexity of the entity
Paragraph 23 - If the auditor identifies risks of material misstatement that management failed to identify:
The Entity's Process to Monitor the System of Internal Control (Paragraph 24)
The auditor shall obtain an understanding of the entity's process for monitoring the system of internal control relevant to the preparation of the financial statements by:
(a) Understanding those aspects of the entity's process that address:
(b) Understanding the sources of the information used in the entity's process to monitor the system of internal control, and the basis upon which management considers the information to be sufficiently reliable for the purpose
(c) Evaluating whether the entity's process for monitoring the system of internal control is appropriate to the entity's circumstances considering the nature and complexity of the entity
Information System and Communication, and Control Activities (Paragraphs 25-26)
The Information System and Communication (Paragraph 25)
The auditor shall obtain an understanding of the entity's information system and communication relevant to the preparation of the financial statements by:
(a) Understanding the entity's information processing activities, including its data and information, the resources to be used in such activities and the policies that define, for significant classes of transactions, account balances and disclosures:
(b) Understanding how the entity communicates significant matters that support the preparation of the financial statements and related reporting responsibilities:
(c) Evaluating whether the entity's information system and communication appropriately support the preparation of the entity's financial statements in accordance with the applicable financial reporting framework
Control Activities (Paragraph 26)
The auditor shall obtain an understanding of the control activities component by:
(a) Identifying controls that address risks of material misstatement at the assertion level in the control activities component as follows:
(b) Based on controls identified in (a), identifying the IT applications and the other aspects of the entity's IT environment that are subject to risks arising from the use of IT
(c) For such IT applications and other aspects of the IT environment identified in (b), identifying:
(d) For each control identified in (a) or (c)(ii):
Control Deficiencies Within the Entity's System of Internal Control (Paragraph 27)
Based on the auditor's evaluation of each of the components of the entity's system of internal control, the auditor shall determine whether one or more control deficiencies have been identified.
Identifying and Assessing the Risks of Material Misstatement (Paragraphs 28-37)
Identifying Risks of Material Misstatement (Paragraphs 28-29)
Paragraph 28 - Identification of Risks
The auditor shall identify the risks of material misstatement and determine whether they exist at:
Paragraph 29 - Relevant Assertions and Significant Classes
The auditor shall determine the relevant assertions and the related significant classes of transactions, account balances and disclosures.
Categories of Assertions (A190)
Assertions are used by auditors to consider different types of potential misstatements. Examples include:
Assessing Risks of Material Misstatement at the Financial Statement Level (Paragraph 30)
For identified risks of material misstatement at the financial statement level, the auditor shall:
Financial Statement Level Risks (A193-A200)
Assessing Risks of Material Misstatement at the Assertion Level (Paragraphs 31-34)
Assessing Inherent Risk (Paragraphs 31-33)
Paragraph 31 - Assessment of Inherent Risk
For identified risks of material misstatement at the assertion level, the auditor shall assess inherent risk by assessing the likelihood and magnitude of misstatement. In doing so, the auditor shall take into account how, and the degree to which:
Paragraph 32 - Significant Risks
The auditor shall determine whether any of the assessed risks of material misstatement are significant risks.
Characteristics of Significant Risks (A218-A221)
Paragraph 33 - Substantive Procedures Alone Cannot Provide Sufficient Appropriate Audit Evidence
The auditor shall determine whether substantive procedures alone cannot provide sufficient appropriate audit evidence for any of the risks of material misstatement at the assertion level.
Examples (A222-A225)
Assessing Control Risk (Paragraph 34)
If the auditor plans to test the operating effectiveness of controls, the auditor shall assess control risk.
If the auditor does not plan to test the operating effectiveness of controls, the auditor's assessment of control risk shall be such that the assessment of the risk of material misstatement is the same as the assessment of inherent risk.
Evaluating the Audit Evidence Obtained from the Risk Assessment Procedures (Paragraph 35)
The auditor shall evaluate whether the audit evidence obtained from the risk assessment procedures provides an appropriate basis for the identification and assessment of the risks of material misstatement. If not, the auditor shall perform additional risk assessment procedures until audit evidence has been obtained to provide such a basis.
Critical Requirement: In identifying and assessing the risks of material misstatement, the auditor shall take into account all audit evidence obtained from the risk assessment procedures, whether corroborative or contradictory to assertions made by management.
Classes of Transactions, Account Balances and Disclosures that Are Not Significant, but Which Are Material (Paragraph 36)
For material classes of transactions, account balances or disclosures that have not been determined to be significant classes of transactions, account balances or disclosures, the auditor shall evaluate whether the auditor's determination remains appropriate.
Revision of Risk Assessment (Paragraph 37)
If the auditor obtains new information which is inconsistent with the audit evidence on which the auditor originally based the identification or assessments of the risks of material misstatement, the auditor shall revise the identification or assessment.
Documentation (Paragraph 38)
The auditor shall include in the audit documentation:
| Documentation Requirement | Description |
|---|---|
| (a) | The discussion among the engagement team and the significant decisions reached |
| (b) | Key elements of the auditor's understanding in accordance with paragraphs 19, 21, 22, 24 and 25; the sources of information from which the auditor's understanding was obtained; and the risk assessment procedures performed |
| (c) | The evaluation of the design of identified controls, and determination whether such controls have been implemented, in accordance with the requirements in paragraph 26 |
| (d) | The identified and assessed risks of material misstatement at the financial statement level and at the assertion level, including significant risks and risks for which substantive procedures alone cannot provide sufficient appropriate audit evidence, and the rationale for the significant judgments made |
APPLICATION AND OTHER EXPLANATORY MATERIAL - KEY POINTS
Definitions (A1-A10)
Assertions (A1)
Categories of assertions are used by auditors to consider different types of potential misstatements. Assertions differ from written representations required by HKSA 580.
Controls (A2-A5)
Information Processing Controls (A6)
Inherent Risk Factors (A7-A8)
Relevant Assertions (A9)
Significant Risk (A10)
Risk Assessment Procedures and Related Activities (A11-A47)
Professional Skepticism (A12-A13)
Scalability (A16-A18)
Automated Tools and Techniques (A21)
Obtaining an Understanding (A48-A183)
Dynamic and Iterative Process (A48)
Why Understanding is Required (A50-A51)
Scalability of Understanding (A52-A55)
Identifying and Assessing Risks (A184-A236)
Financial Statement Level Risks (A193-A200)
Assertion Level Risks (A201)
Spectrum of Inherent Risk (A205-A217)
Significant Risks (A218-A221)
KEY TAKEAWAYS SUMMARY
| Topic | Key Point |
|---|---|
| Objective | Identify and assess risks of material misstatement at financial statement and assertion levels |
| Risk Assessment Procedures | Inquiries, analytical procedures, observation and inspection |
| Understanding Required | Entity and its environment, applicable financial reporting framework, system of internal control |
| Internal Control Components | Control environment, risk assessment process, monitoring process, information system and communication, control activities |
| Inherent Risk Assessment | Assess likelihood and magnitude of misstatement considering inherent risk factors |
| Control Risk Assessment | Assess if planning to test operating effectiveness; otherwise same as inherent risk |
| Significant Risk | Inherent risk close to upper end of spectrum |
| Documentation | Discussion, understanding, evaluation of controls, identified and assessed risks |
| Professional Skepticism | Essential throughout the risk assessment process |
| Iterative Process | Risk assessment is dynamic and continues throughout the audit |
❓ Ready to Test Your Knowledge?
50 MCQs covering all sections. Timed at 1.25 min each (62.5 min total).
📝 Start Q&A →🖨️ Save as PDF