📄 PDF — HKICPA Handbook Vol III (Code of Ethics)

PDF viewer not supported.

🎥 Video Lesson (Coming Soon)
🎬HKSA 315 - Identifying and Assessing Risks of Material Misstatement walkthrough video coming soon.

HKSA 315 (Revised 2019) - Identifying and Assessing the Risks of Material Misstatement

Ad Space
Ad Space

INTRODUCTION

Scope of HKSA 315

HKSA 315 (Revised 2019) deals with the auditor's responsibility to identify and assess the risks of material misstatement in the financial statements. This standard is effective for audits of financial statements for periods beginning on or after 15 December 2021.

Key Concepts

Audit Risk Framework (HKSA 200)

  • Audit risk is a function of the risks of material misstatement and detection risk
  • Risks of material misstatement may exist at two levels:
  • Overall financial statement level
  • Assertion level for classes of transactions, account balances and disclosures
  • Professional Requirements

  • The auditor must exercise professional judgment in planning and performing an audit
  • The auditor must plan and perform an audit with professional skepticism, recognizing that circumstances may exist that cause the financial statements to be materially misstated
  • Components of Risk at Assertion Level

    ComponentDescription
    Inherent RiskSusceptibility of an assertion to a misstatement that could be material, before consideration of any related controls
    Control RiskRisk that a misstatement will not be prevented, or detected and corrected, on a timely basis by the entity's controls

    Spectrum of Inherent Risk

  • The degree to which inherent risk varies is referred to as the "spectrum of inherent risk"
  • For identified risks at the assertion level, a separate assessment of inherent risk and control risk is required
  • Nature of Risks

  • Risks of material misstatement include both those due to error and those due to fraud
  • HKSA 240 provides additional requirements and guidance for fraud-related risks
  • Iterative and Dynamic Process

  • The auditor's risk identification and assessment process is iterative and dynamic
  • Initial expectations of risks may be developed and further refined as the auditor progresses through the risk identification and assessment process
  • HKSA 330 requires the auditor to revise risk assessments and modify further overall responses based on audit evidence obtained
  • Scalability

    HKSA 315 is intended for audits of all entities, regardless of size or complexity. The application material incorporates specific considerations for both less complex and more complex entities. While the size of an entity may be an indicator of its complexity, some smaller entities may be complex and some larger entities may be less complex.

    Objective

    The objective of the auditor is to identify and assess the risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels, thereby providing a basis for designing and implementing responses to the assessed risks of material misstatement.

    Ad Space

    DEFINITIONS (Paragraph 12)

    Assertions (12(a))

    Representations, explicit or otherwise, with respect to the recognition, measurement, presentation and disclosure of information in the financial statements which are inherent in management representing that the financial statements are prepared in accordance with the applicable financial reporting framework. Assertions are used by the auditor to consider the different types of potential misstatements that may occur when identifying, assessing and responding to the risks of material misstatement.

    Business Risk (12(b))

    A risk resulting from significant conditions, events, circumstances, actions or inactions that could adversely affect an entity's ability to achieve its objectives and execute its strategies, or from the setting of inappropriate objectives and strategies.

    Controls (12(c))

    Policies or procedures that an entity establishes to achieve the control objectives of management or those charged with governance.

    ElementDescription
    PoliciesStatements of what should, or should not, be done within the entity to effect control. May be documented, explicitly stated in communications, or implied through actions and decisions
    ProceduresActions to implement policies

    General Information Technology (IT) Controls (12(d))

    Controls over the entity's IT processes that support the continued proper operation of the IT environment, including the continued effective functioning of information processing controls and the integrity of information (i.e., the completeness, accuracy and validity of information) in the entity's information system.

    Information Processing Controls (12(e))

    Controls relating to the processing of information in IT applications or manual information processes in the entity's information system that directly address risks to the integrity of information (i.e., the completeness, accuracy and validity of transactions and other information).

    Inherent Risk Factors (12(f))

    Characteristics of events or conditions that affect susceptibility to misstatement, whether due to fraud or error, of an assertion about a class of transactions, account balance or disclosure, before consideration of controls. Such factors may be qualitative or quantitative, and include:

    FactorDescription
    ComplexityDegree of difficulty in understanding or processing
    SubjectivityExtent of judgment involved
    ChangeDegree of change in conditions or circumstances
    UncertaintyLack of certainty about outcomes
    Susceptibility to misstatement due to management bias or other fraud risk factorsPotential for intentional or unintentional bias

    IT Environment (12(g))

    The IT applications and supporting IT infrastructure, as well as the IT processes and personnel involved in those processes, that an entity uses to support business operations and achieve business strategies.

    ComponentDescription
    IT ApplicationA program or set of programs used in the initiation, processing, recording and reporting of transactions or information. Includes data warehouses and report writers
    IT InfrastructureNetwork, operating systems, databases and their related hardware and software
    IT ProcessesEntity's processes to manage access to the IT environment, manage program changes or changes to the IT environment and manage IT operations

    Relevant Assertions (12(h))

    An assertion about a class of transactions, account balance or disclosure is relevant when it has an identified risk of material misstatement. The determination of whether an assertion is a relevant assertion is made before consideration of any related controls (i.e., the inherent risk).

    Risks Arising from the Use of IT (12(i))

    Susceptibility of information processing controls to ineffective design or operation, or risks to the integrity of information (i.e., the completeness, accuracy and validity of transactions and other information) in the entity's information system, due to ineffective design or operation of controls in the entity's IT processes.

    Risk Assessment Procedures (12(j))

    The audit procedures designed and performed to identify and assess the risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels.

    Significant Class of Transactions, Account Balance or Disclosure (12(k))

    A class of transactions, account balance or disclosure for which there is one or more relevant assertions.

    Significant Risk (12(l))

    An identified risk of material misstatement:

  • For which the assessment of inherent risk is close to the upper end of the spectrum of inherent risk due to the degree to which inherent risk factors affect the combination of the likelihood of a misstatement occurring and the magnitude of the potential misstatement should that misstatement occur; OR
  • That is to be treated as a significant risk in accordance with the requirements of other HKSAs (e.g., HKSA 240, HKSA 550)
  • System of Internal Control (12(m))

    The system designed, implemented and maintained by those charged with governance, management and other personnel, to provide reasonable assurance about the achievement of an entity's objectives with regard to reliability of financial reporting, effectiveness and efficiency of operations, and compliance with applicable laws and regulations.

    Five Inter-related Components:

  • Control environment
  • The entity's risk assessment process
  • The entity's process to monitor the system of internal control
  • The information system and communication
  • Control activities
  • Ad Space

    REQUIREMENTS

    Risk Assessment Procedures and Related Activities (Paragraphs 13-18)

    Design and Performance of Risk Assessment Procedures (Paragraph 13)

    The auditor shall design and perform risk assessment procedures to obtain audit evidence that provides an appropriate basis for:

  • The identification and assessment of risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels
  • The design of further audit procedures in accordance with HKSA 330
  • Critical Requirement: The auditor shall design and perform risk assessment procedures in a manner that is not biased towards obtaining audit evidence that may be corroborative or towards excluding audit evidence that may be contradictory.

    Why Unbiased Evidence is Important (A14)

    Designing and performing risk assessment procedures to obtain audit evidence in an unbiased manner may assist the auditor in identifying potentially contradictory information, which may assist the auditor in exercising professional skepticism in identifying and assessing the risks of material misstatement.

    Sources of Audit Evidence (A15)

    Sources of information for risk assessment procedures may include:

  • Interactions with management, those charged with governance, and other key entity personnel
  • Certain external parties such as regulators
  • Publicly available information about the entity
  • Types of Risk Assessment Procedures (Paragraph 14)

    The risk assessment procedures shall include:

    (a) Inquiries of management and of other appropriate individuals within the entity, including individuals within the internal audit function (if the function exists)

    Why Inquiries are Made (A22-A23)

  • Information obtained through inquiries supports an appropriate basis for identification and assessment of risks
  • Inquiries of different individuals with varying levels of authority may offer varying perspectives
  • Examples of Inquiries (A23)

  • Those charged with governance: understanding oversight over financial statement preparation
  • Employees responsible for complex transactions: evaluating appropriateness of accounting policies
  • In-house legal counsel: litigation, compliance, fraud knowledge
  • Marketing/sales personnel: changes in marketing strategies, sales trends
  • Risk management function: operational and regulatory risks
  • IT personnel: system changes, control failures
  • (b) Analytical procedures

    Why Analytical Procedures are Performed (A27-A28)

  • Help identify inconsistencies, unusual transactions or events, amounts, ratios, and trends
  • Unusual or unexpected relationships may assist in identifying risks of material misstatement, especially due to fraud
  • Assist in understanding how inherent risk factors affect susceptibility of assertions to misstatement
  • Types of Analytical Procedures (A29)

  • May include both financial and non-financial information
  • May use data aggregated at a high level
  • Results may provide a broad initial indication about the likelihood of a material misstatement
  • (c) Observation and inspection

    Why Observation and Inspection are Performed (A32)

  • May support, corroborate or contradict inquiries of management and others
  • May provide information about the entity and its environment
  • Examples of Observation and Inspection (A34)

  • The entity's operations
  • Internal documents, records, and internal control manuals
  • Reports prepared by management and those charged with governance
  • The entity's premises and plant facilities
  • Information from external sources
  • Behaviors and actions of management or those charged with governance
  • Information from Other Sources (Paragraph 15)

    In obtaining audit evidence, the auditor shall consider information from:

  • The auditor's procedures regarding acceptance or continuance of the client relationship or the audit engagement
  • When applicable, other engagements performed by the engagement partner for the entity
  • Why Other Sources are Important (A37)

    Information from other sources may provide insights about:

  • The nature of the entity and its business risks
  • The integrity and ethical values of management and those charged with governance
  • The applicable financial reporting framework and its application
  • Information from Previous Audits (Paragraph 16)

    When the auditor intends to use information obtained from the auditor's previous experience with the entity and from audit procedures performed in previous audits, the auditor shall evaluate whether such information remains relevant and reliable as audit evidence for the current audit.

    Nature of Information from Previous Audits (A40)

  • Past misstatements and whether they were corrected on a timely basis
  • Nature of the entity and its environment, and the entity's system of internal control
  • Significant changes that the entity or its operations may have undergone
  • Particular types of transactions or account balances where the auditor experienced difficulty
  • Engagement Team Discussion (Paragraphs 17-18)

    The engagement partner and other key engagement team members shall discuss:

  • The application of the applicable financial reporting framework
  • The susceptibility of the entity's financial statements to material misstatement
  • When there are engagement team members not involved in the discussion, the engagement partner shall determine which matters are to be communicated to those members.

    Why Discussion is Required (A42)

  • Provides opportunity for more experienced members to share insights
  • Allows exchange of information about business risks and inherent risk factors
  • Assists team members in understanding potential for material misstatement in specific areas
  • Provides basis for communication and sharing of new information throughout the audit
  • Scalability Considerations (A44-A45)

  • For sole practitioners: consideration of matters may still assist in identifying risks
  • For large engagement teams: not necessary for all members to participate in a single discussion; engagement partner may discuss with key members and delegate discussion with others
  • Obtaining an Understanding of the Entity and Its Environment, the Applicable Financial Reporting Framework and the Entity's System of Internal Control (Paragraphs 19-27)

    Understanding the Entity and Its Environment, and the Applicable Financial Reporting Framework (Paragraphs 19-20)

    Paragraph 19 - Required Understanding

    The auditor shall perform risk assessment procedures to obtain an understanding of:

    (a) The following aspects of the entity and its environment:

    (i) The entity's organizational structure, ownership and governance, and its business model, including the extent to which the business model integrates the use of IT

    Organizational Structure and Ownership (A56)

  • Complexity of the entity's structure (single entity vs. subsidiaries, divisions, multiple locations)
  • Ownership and relationships between owners and other parties, including related parties
  • Distinction between owners, those charged with governance, and management
  • Structure and complexity of the entity's IT environment
  • Governance (A59-A60)

  • Understanding governance assists in understanding the entity's ability to provide appropriate oversight
  • Matters to consider include: whether those charged with governance are involved in managing the entity, existence of non-executive Board, existence of audit committee, responsibilities for oversight of financial reporting
  • Business Model (A61-A65)

  • Understanding objectives, strategy and business model helps understand business risks
  • Business risks that have an effect on the financial statements assist in identifying risks of material misstatement
  • Not all business risks give rise to risks of material misstatement
  • Business risks may arise from: inappropriate objectives or strategies, ineffective execution, change or complexity, failure to recognize need for change, incentives and pressures on management
  • (ii) Industry, regulatory and other external factors

    Industry Factors (A68-A69)

  • Market and competition, including demand, capacity, and price competition
  • Cyclical or seasonal activity
  • Product technology
  • Energy supply and cost
  • Industry may give rise to specific risks of material misstatement
  • Regulatory Factors (A70)

  • Regulatory framework for a regulated industry
  • Legislation and regulation that significantly affect operations
  • Taxation legislation and regulations
  • Government policies
  • Environmental requirements
  • Other External Factors (A73)

  • General economic conditions
  • Interest rates and availability of financing
  • Inflation or currency revaluation
  • (iii) The measures used, internally and externally, to assess the entity's financial performance

    Why Understanding Measures is Important (A74-A75)

  • Assists in considering whether measures create pressures on the entity to achieve performance targets
  • Pressures may motivate management to take actions that increase susceptibility to misstatement
  • Measures may indicate likelihood of risks of material misstatement
  • Key Indicators (A77)

  • Key performance indicators (financial and non-financial)
  • Period-on-period financial performance analyses
  • Budgets, forecasts, variance analyses
  • Employee performance measures and incentive compensation policies
  • Comparisons with competitors
  • (b) The applicable financial reporting framework, and the entity's accounting policies and the reasons for any changes thereto

    Matters to Consider (A82)

  • Accounting principles and industry-specific practices
  • Revenue recognition
  • Accounting for financial instruments
  • Foreign currency assets, liabilities and transactions
  • Accounting for unusual or complex transactions
  • Methods used to recognize, measure, present and disclose significant and unusual transactions
  • Effect of significant accounting policies in controversial or emerging areas
  • Changes in environment that may necessitate change in accounting policies
  • (c) How inherent risk factors affect susceptibility of assertions to misstatement and the degree to which they do so

    Why Understanding Inherent Risk Factors is Important (A85-A86)

  • Assists in understanding events or conditions that may affect susceptibility of assertions to misstatement
  • Inherent risk factors may affect susceptibility by influencing likelihood of occurrence or magnitude of misstatement
  • Understanding the degree to which inherent risk factors affect susceptibility assists in assessing likelihood and magnitude of possible misstatement
  • Paragraph 20 - Evaluation of Accounting Policies

    The auditor shall evaluate whether the entity's accounting policies are appropriate and consistent with the applicable financial reporting framework.

    Understanding the Components of the Entity's System of Internal Control (Paragraphs 21-27)

    Control Environment, the Entity's Risk Assessment Process and the Entity's Process to Monitor the System of Internal Control (Paragraphs 21-24)

    Control Environment (Paragraph 21)

    The auditor shall obtain an understanding of the control environment relevant to the preparation of the financial statements by:

    (a) Understanding the set of controls, processes and structures that address:

  • How management's oversight responsibilities are carried out, such as the entity's culture and management's commitment to integrity and ethical values
  • When those charged with governance are separate from management, the independence of, and oversight over the entity's system of internal control by, those charged with governance
  • The entity's assignment of authority and responsibility
  • How the entity attracts, develops, and retains competent individuals
  • How the entity holds individuals accountable for their responsibilities in the pursuit of the objectives of the system of internal control
  • (b) Evaluating whether:

  • Management, with the oversight of those charged with governance, has created and maintained a culture of honesty and ethical behavior
  • The control environment provides an appropriate foundation for the other components of the entity's system of internal control considering the nature and complexity of the entity
  • Control deficiencies identified in the control environment undermine the other components of the entity's system of internal control
  • The Entity's Risk Assessment Process (Paragraphs 22-23)

    The auditor shall obtain an understanding of the entity's risk assessment process relevant to the preparation of the financial statements by:

    (a) Understanding the entity's process for:

  • Identifying business risks relevant to financial reporting objectives
  • Assessing the significance of those risks, including the likelihood of their occurrence
  • Addressing those risks
  • (b) Evaluating whether the entity's risk assessment process is appropriate to the entity's circumstances considering the nature and complexity of the entity

    Paragraph 23 - If the auditor identifies risks of material misstatement that management failed to identify:

  • Determine whether any such risks are of a kind that the auditor expects would have been identified by the entity's risk assessment process and, if so, obtain an understanding of why the entity's risk assessment process failed to identify such risks
  • Consider the implications for the auditor's evaluation in paragraph 22(b)
  • The Entity's Process to Monitor the System of Internal Control (Paragraph 24)

    The auditor shall obtain an understanding of the entity's process for monitoring the system of internal control relevant to the preparation of the financial statements by:

    (a) Understanding those aspects of the entity's process that address:

  • Ongoing and separate evaluations for monitoring the effectiveness of controls, and the identification and remediation of control deficiencies identified
  • The entity's internal audit function, if any, including its nature, responsibilities and activities
  • (b) Understanding the sources of the information used in the entity's process to monitor the system of internal control, and the basis upon which management considers the information to be sufficiently reliable for the purpose

    (c) Evaluating whether the entity's process for monitoring the system of internal control is appropriate to the entity's circumstances considering the nature and complexity of the entity

    Information System and Communication, and Control Activities (Paragraphs 25-26)

    The Information System and Communication (Paragraph 25)

    The auditor shall obtain an understanding of the entity's information system and communication relevant to the preparation of the financial statements by:

    (a) Understanding the entity's information processing activities, including its data and information, the resources to be used in such activities and the policies that define, for significant classes of transactions, account balances and disclosures:

  • How information flows through the entity's information system, including:
  • How transactions are initiated, recorded, processed, corrected as necessary, incorporated in the general ledger and reported in the financial statements
  • How information about events and conditions, other than transactions, is captured, processed and disclosed in the financial statements
  • The accounting records, specific accounts in the financial statements and other supporting records relating to the flows of information
  • The financial reporting process used to prepare the entity's financial statements, including disclosures
  • The entity's resources, including the IT environment, relevant to the above
  • (b) Understanding how the entity communicates significant matters that support the preparation of the financial statements and related reporting responsibilities:

  • Between people within the entity, including how financial reporting roles and responsibilities are communicated
  • Between management and those charged with governance
  • With external parties, such as regulatory authorities
  • (c) Evaluating whether the entity's information system and communication appropriately support the preparation of the entity's financial statements in accordance with the applicable financial reporting framework

    Control Activities (Paragraph 26)

    The auditor shall obtain an understanding of the control activities component by:

    (a) Identifying controls that address risks of material misstatement at the assertion level in the control activities component as follows:

  • Controls that address a risk that is determined to be a significant risk
  • Controls over journal entries, including non-standard journal entries used to record non-recurring, unusual transactions or adjustments
  • Controls for which the auditor plans to test operating effectiveness in determining the nature, timing and extent of substantive testing, which shall include controls that address risks for which substantive procedures alone do not provide sufficient appropriate audit evidence
  • Other controls that the auditor considers are appropriate to enable the auditor to meet the objectives of paragraph 13 with respect to risks at the assertion level, based on the auditor's professional judgment
  • (b) Based on controls identified in (a), identifying the IT applications and the other aspects of the entity's IT environment that are subject to risks arising from the use of IT

    (c) For such IT applications and other aspects of the IT environment identified in (b), identifying:

  • The related risks arising from the use of IT
  • The entity's general IT controls that address such risks
  • (d) For each control identified in (a) or (c)(ii):

  • Evaluating whether the control is designed effectively to address the risk of material misstatement at the assertion level, or effectively designed to support the operation of other controls
  • Determining whether the control has been implemented by performing procedures in addition to inquiry of the entity's personnel
  • Control Deficiencies Within the Entity's System of Internal Control (Paragraph 27)

    Based on the auditor's evaluation of each of the components of the entity's system of internal control, the auditor shall determine whether one or more control deficiencies have been identified.

    Identifying and Assessing the Risks of Material Misstatement (Paragraphs 28-37)

    Identifying Risks of Material Misstatement (Paragraphs 28-29)

    Paragraph 28 - Identification of Risks

    The auditor shall identify the risks of material misstatement and determine whether they exist at:

  • The financial statement level
  • The assertion level for classes of transactions, account balances and disclosures
  • Paragraph 29 - Relevant Assertions and Significant Classes

    The auditor shall determine the relevant assertions and the related significant classes of transactions, account balances and disclosures.

    Categories of Assertions (A190)

    Assertions are used by auditors to consider different types of potential misstatements. Examples include:

  • Occurrence - Transactions and events that have been recorded have occurred and pertain to the entity
  • Completeness - All transactions and events that should have been recorded have been recorded
  • Accuracy - Amounts and other data relating to recorded transactions and events have been recorded appropriately
  • Cutoff - Transactions and events have been recorded in the correct accounting period
  • Classification - Transactions and events have been recorded in the proper accounts
  • Existence - Assets, liabilities and equity interests exist
  • Rights and obligations - The entity holds or controls the rights to assets and liabilities are the obligations of the entity
  • Valuation - Assets, liabilities and equity interests are included at appropriate amounts
  • Presentation - Transactions, events, accounts and disclosures are appropriately aggregated or disaggregated and clearly described
  • Assessing Risks of Material Misstatement at the Financial Statement Level (Paragraph 30)

    For identified risks of material misstatement at the financial statement level, the auditor shall:

  • Assess the risks
  • Determine whether such risks affect the assessment of risks at the assertion level
  • Evaluate the nature and extent of their pervasive effect on the financial statements
  • Financial Statement Level Risks (A193-A200)

  • Relate pervasively to the financial statements as a whole
  • Potentially affect many assertions
  • May arise from a weak control environment
  • Affect the auditor's overall responses (HKSA 330)
  • Assessing Risks of Material Misstatement at the Assertion Level (Paragraphs 31-34)

    Assessing Inherent Risk (Paragraphs 31-33)

    Paragraph 31 - Assessment of Inherent Risk

    For identified risks of material misstatement at the assertion level, the auditor shall assess inherent risk by assessing the likelihood and magnitude of misstatement. In doing so, the auditor shall take into account how, and the degree to which:

  • Inherent risk factors affect the susceptibility of relevant assertions to misstatement
  • The risks of material misstatement at the financial statement level affect the assessment of inherent risk for risks of material misstatement at the assertion level
  • Paragraph 32 - Significant Risks

    The auditor shall determine whether any of the assessed risks of material misstatement are significant risks.

    Characteristics of Significant Risks (A218-A221)

  • Assessment of inherent risk is close to the upper end of the spectrum of inherent risk
  • Determined by the degree to which inherent risk factors affect the combination of likelihood and magnitude
  • May include: significant non-routine transactions, transactions that involve significant judgment, transactions that are unusual
  • Paragraph 33 - Substantive Procedures Alone Cannot Provide Sufficient Appropriate Audit Evidence

    The auditor shall determine whether substantive procedures alone cannot provide sufficient appropriate audit evidence for any of the risks of material misstatement at the assertion level.

    Examples (A222-A225)

  • Risks related to the routine processing of significant classes of transactions where automated processing is involved
  • When information is processed in a manner that involves little or no manual intervention
  • When the entity uses IT to initiate, record, process or report transactions
  • Assessing Control Risk (Paragraph 34)

    If the auditor plans to test the operating effectiveness of controls, the auditor shall assess control risk.

    If the auditor does not plan to test the operating effectiveness of controls, the auditor's assessment of control risk shall be such that the assessment of the risk of material misstatement is the same as the assessment of inherent risk.

    Evaluating the Audit Evidence Obtained from the Risk Assessment Procedures (Paragraph 35)

    The auditor shall evaluate whether the audit evidence obtained from the risk assessment procedures provides an appropriate basis for the identification and assessment of the risks of material misstatement. If not, the auditor shall perform additional risk assessment procedures until audit evidence has been obtained to provide such a basis.

    Critical Requirement: In identifying and assessing the risks of material misstatement, the auditor shall take into account all audit evidence obtained from the risk assessment procedures, whether corroborative or contradictory to assertions made by management.

    Classes of Transactions, Account Balances and Disclosures that Are Not Significant, but Which Are Material (Paragraph 36)

    For material classes of transactions, account balances or disclosures that have not been determined to be significant classes of transactions, account balances or disclosures, the auditor shall evaluate whether the auditor's determination remains appropriate.

    Revision of Risk Assessment (Paragraph 37)

    If the auditor obtains new information which is inconsistent with the audit evidence on which the auditor originally based the identification or assessments of the risks of material misstatement, the auditor shall revise the identification or assessment.

    Documentation (Paragraph 38)

    The auditor shall include in the audit documentation:

    Documentation RequirementDescription
    (a)The discussion among the engagement team and the significant decisions reached
    (b)Key elements of the auditor's understanding in accordance with paragraphs 19, 21, 22, 24 and 25; the sources of information from which the auditor's understanding was obtained; and the risk assessment procedures performed
    (c)The evaluation of the design of identified controls, and determination whether such controls have been implemented, in accordance with the requirements in paragraph 26
    (d)The identified and assessed risks of material misstatement at the financial statement level and at the assertion level, including significant risks and risks for which substantive procedures alone cannot provide sufficient appropriate audit evidence, and the rationale for the significant judgments made

    Ad Space

    APPLICATION AND OTHER EXPLANATORY MATERIAL - KEY POINTS

    Definitions (A1-A10)

    Assertions (A1)

    Categories of assertions are used by auditors to consider different types of potential misstatements. Assertions differ from written representations required by HKSA 580.

    Controls (A2-A5)

  • Controls are embedded within the components of the entity's system of internal control
  • Policies are implemented through actions of personnel or restraint from taking conflicting actions
  • Procedures may be mandated through formal documentation or result from behaviors conditioned by the entity's culture
  • Controls may be direct (precise enough to address risks at assertion level) or indirect (support direct controls)
  • Information Processing Controls (A6)

  • Risks to integrity of information arise from susceptibility to ineffective implementation of information policies
  • Information processing controls may be automated or manual
  • May rely on other controls, including other information processing controls or general IT controls
  • Inherent Risk Factors (A7-A8)

  • Qualitative inherent risk factors include: complexity, subjectivity, change, uncertainty, susceptibility to misstatement due to management bias or other fraud risk factors
  • Other inherent risk factors include: quantitative or qualitative significance, volume or lack of uniformity in composition
  • Relevant Assertions (A9)

  • A risk of material misstatement may relate to more than one assertion
  • If an assertion does not have an identified risk of material misstatement, it is not a relevant assertion
  • Significant Risk (A10)

  • Significance is judged by the auditor in the context in which the matter is being considered
  • For inherent risk, significance may be considered in the context of how inherent risk factors affect the combination of likelihood and magnitude
  • Risk Assessment Procedures and Related Activities (A11-A47)

    Professional Skepticism (A12-A13)

  • Necessary for critical assessment of audit evidence
  • Assists in remaining alert to audit evidence that is not biased towards corroborating risks
  • May include: questioning contradictory information, considering responses to inquiries, being alert to conditions indicating possible misstatement
  • Scalability (A16-A18)

  • Nature and extent of risk assessment procedures vary based on nature and circumstances of the entity
  • Less complex entities may not have established structured processes and systems
  • More complex entities are expected to have more formalized and documented policies and procedures
  • First-time engagements may require more extensive procedures than recurring engagements
  • Automated Tools and Techniques (A21)

  • May be used to perform risk assessment procedures on large volumes of data
  • May include analysis, recalculations, reperformance or reconciliations
  • Obtaining an Understanding (A48-A183)

    Dynamic and Iterative Process (A48)

  • Obtaining understanding is a dynamic and iterative process of gathering, updating and analyzing information
  • Continues throughout the audit
  • Auditor's expectations may change as new information is obtained
  • Why Understanding is Required (A50-A51)

  • Establishes a frame of reference for identifying and assessing risks
  • Assists in planning the audit and exercising professional judgment and professional skepticism
  • Informs how the auditor plans and performs further audit procedures
  • Scalability of Understanding (A52-A55)

  • Nature and extent of understanding varies based on size and complexity of entity
  • May be less extensive in audits of less complex entities
  • Depth of understanding is expected to be less than that possessed by management
  • Identifying and Assessing Risks (A184-A236)

    Financial Statement Level Risks (A193-A200)

  • Relate pervasively to the financial statements as a whole
  • May arise from a weak control environment
  • Affect the auditor's overall responses
  • Assertion Level Risks (A201)

  • Relate to specific classes of transactions, account balances and disclosures
  • Require separate assessment of inherent risk and control risk
  • Spectrum of Inherent Risk (A205-A217)

  • Inherent risk varies along a spectrum
  • Assessment involves considering likelihood and magnitude of misstatement
  • Higher on the spectrum = more persuasive audit evidence needed
  • Significant Risks (A218-A221)

  • Inherent risk assessment is close to the upper end of the spectrum
  • May include significant non-routine transactions
  • May include transactions that involve significant judgment
  • Ad Space

    KEY TAKEAWAYS SUMMARY

    TopicKey Point
    ObjectiveIdentify and assess risks of material misstatement at financial statement and assertion levels
    Risk Assessment ProceduresInquiries, analytical procedures, observation and inspection
    Understanding RequiredEntity and its environment, applicable financial reporting framework, system of internal control
    Internal Control ComponentsControl environment, risk assessment process, monitoring process, information system and communication, control activities
    Inherent Risk AssessmentAssess likelihood and magnitude of misstatement considering inherent risk factors
    Control Risk AssessmentAssess if planning to test operating effectiveness; otherwise same as inherent risk
    Significant RiskInherent risk close to upper end of spectrum
    DocumentationDiscussion, understanding, evaluation of controls, identified and assessed risks
    Professional SkepticismEssential throughout the risk assessment process
    Iterative ProcessRisk assessment is dynamic and continues throughout the audit

    ❓ Ready to Test Your Knowledge?

    50 MCQs covering all sections. Timed at 1.25 min each (62.5 min total).

    📝 Start Q&A →🖨️ Save as PDF