๐Ÿ“ Condensed Version โ€” Key points only ๐Ÿ“š Full Reference โ†’
๐Ÿ“„ PDF โ€” HKICPA Handbook Vol III

PDF viewer not supported.

๐ŸŽฅ Video Lesson (Coming Soon)
๐ŸŽฌVideo walkthrough coming soon.
Section NameKey ConceptBrief Description
IntroductionScope & ObjectiveAuditorโ€™s responsibility to identify and assess risks of material misstatement at financial statement and assertion levels.
Definitions (para 12)Key TermsDefines assertions, business risk, controls, IT controls, inherent risk factors, significant risk, system of internal control, etc.
Risk Assessment Procedures (para 13-18)Procedures & DiscussionInquiries, analytical procedures, observation/inspection; engagement team discussion; use of previous audit information.
Understanding the Entity (para 19-27)Entity & Internal ControlUnderstanding entity, environment, financial reporting framework, and five components of internal control.
Identifying & Assessing Risks (para 28-37)Risk Identification & AssessmentIdentify risks at financial statement and assertion levels; assess inherent risk, control risk, significant risks.
Documentation (para 38)Required DocumentationDocument discussion, understanding, control evaluation, identified and assessed risks.
Application MaterialKey Explanatory PointsProfessional skepticism, scalability, iterative process, spectrum of inherent risk.
Ad Space

Introduction & Objective (para 1-11)

Scope of HKSA 315 (Revised 2019)

Deals with auditor's responsibility to identify and assess risks of material misstatement in financial statements. Effective for periods beginning on or after 15 December 2021.

Audit Risk Framework (HKSA 200)

Audit risk = function of risks of material misstatement and detection risk. Risks exist at two levels: overall financial statement level and assertion level.

Components of Risk at Assertion Level

ComponentDescription
Inherent RiskSusceptibility of an assertion to a material misstatement before consideration of any related controls.
Control RiskRisk that a misstatement will not be prevented, or detected and corrected, on a timely basis by the entity's controls.
Key Point: The auditor must exercise professional skepticism, recognizing that circumstances may exist that cause the financial statements to be materially misstated.

Objective

Identify and assess risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels, providing a basis for designing and implementing responses.

Ad Space

Definitions (para 12)

Key Definitions

TermDefinition
AssertionsRepresentations inherent in management's statement that financial statements are prepared in accordance with the applicable financial reporting framework.
Business RiskRisk resulting from conditions, events, circumstances, actions or inactions that could adversely affect an entity's ability to achieve its objectives.
ControlsPolicies or procedures established to achieve control objectives.
General IT ControlsControls over IT processes that support continued proper operation of the IT environment.
Information Processing ControlsControls relating to processing of information that directly address risks to integrity of information.
Inherent Risk FactorsCharacteristics affecting susceptibility to misstatement before consideration of controls: complexity, subjectivity, change, uncertainty, susceptibility to management bias.
Significant RiskRisk where assessment of inherent risk is close to the upper end of the spectrum of inherent risk.
System of Internal ControlSystem designed to provide reasonable assurance about achievement of objectives regarding reliability of financial reporting, effectiveness of operations, and compliance.

Five Inter-related Components of Internal Control

  1. Control environment
  2. The entity's risk assessment process
  3. The entity's process to monitor the system of internal control
  4. The information system and communication
  5. Control activities
Ad Space

Risk Assessment Procedures (para 13-18)

Design and Performance of Risk Assessment Procedures (para 13)

Auditor shall design and perform risk assessment procedures to obtain audit evidence that provides an appropriate basis for identification and assessment of risks of material misstatement.

Critical Requirement: The auditor shall design and perform risk assessment procedures in a manner that is not biased towards obtaining audit evidence that may be corroborative or towards excluding audit evidence that may be contradictory.

Types of Risk Assessment Procedures (para 14)

ProcedureDescription
InquiriesOf management and other appropriate individuals within the entity, including internal audit function.
Analytical ProceduresHelp identify inconsistencies, unusual transactions or events, amounts, ratios, and trends.
Observation and InspectionMay support, corroborate or contradict inquiries; provides information about entity and its environment.

Information from Other Sources (para 15-16)

Consider information from acceptance/continuance procedures and other engagements. Evaluate whether information from previous audits remains relevant and reliable.

Engagement Team Discussion (para 17-18)

Engagement partner and key team members shall discuss application of the financial reporting framework and susceptibility of financial statements to material misstatement.

Ad Space

Understanding the Entity & Environment (para 19-20)

Required Understanding (para 19)

Auditor shall perform risk assessment procedures to obtain understanding of:

AspectDetails
Organizational structure, ownership, governance, and business modelComplexity of structure, ownership relationships, governance oversight, business objectives and strategies, integration of IT.
Industry, regulatory and other external factorsMarket conditions, competition, regulatory framework, legislation, economic conditions.
Measures used to assess financial performanceKey performance indicators, budgets, forecasts, variance analyses, incentive compensation policies.
Applicable financial reporting framework and accounting policiesAccounting principles, industry-specific practices, revenue recognition, financial instruments, unusual transactions.
How inherent risk factors affect susceptibility of assertionsUnderstanding events or conditions that may affect likelihood or magnitude of misstatement.

Evaluation of Accounting Policies (para 20)

Auditor shall evaluate whether the entity's accounting policies are appropriate and consistent with the applicable financial reporting framework.

Ad Space

Understanding Internal Control Components (para 21-27)

Control Environment (para 21)

Understand the set of controls, processes and structures addressing management's oversight responsibilities, independence of those charged with governance, assignment of authority and responsibility, attracting competent individuals, and accountability.

Entity's Risk Assessment Process (para 22-23)

Understand the entity's process for identifying business risks relevant to financial reporting objectives, assessing significance, and addressing those risks. If management failed to identify risks the auditor expects would have been identified, consider implications.

Entity's Process to Monitor Internal Control (para 24)

Understand ongoing and separate evaluations for monitoring effectiveness of controls, identification and remediation of control deficiencies, and the internal audit function.

Information System and Communication (para 25)

Understand information processing activities, how transactions are initiated, recorded, processed, and reported, and how the entity communicates significant matters supporting financial statement preparation.

Control Activities (para 26)

Identify controls that address risks at assertion level, including controls over significant risks, journal entries, and controls for which the auditor plans to test operating effectiveness. Evaluate design and implementation of identified controls.

Control Deficiencies (para 27)

Determine whether one or more control deficiencies have been identified based on evaluation of each component of internal control.

Ad Space

Identifying & Assessing Risks (para 28-37)

Identifying Risks of Material Misstatement (para 28-29)

Identify risks and determine whether they exist at financial statement level or assertion level. Determine relevant assertions and related significant classes of transactions, account balances and disclosures.

Categories of Assertions

CategoryDescription
OccurrenceTransactions recorded have occurred and pertain to the entity.
CompletenessAll transactions that should have been recorded have been recorded.
AccuracyAmounts and other data have been recorded appropriately.
CutoffTransactions recorded in the correct accounting period.
ClassificationTransactions recorded in the proper accounts.
ExistenceAssets, liabilities and equity interests exist.
Rights and obligationsEntity holds rights to assets and liabilities are obligations of the entity.
ValuationAssets, liabilities and equity interests are included at appropriate amounts.
PresentationTransactions, events, accounts and disclosures are appropriately aggregated or disaggregated and clearly described.

Assessing Risks at Financial Statement Level (para 30)

Assess risks, determine whether they affect assertion level risks, and evaluate their pervasive effect on financial statements.

Assessing Inherent Risk at Assertion Level (para 31-33)

Assess likelihood and magnitude of misstatement, taking into account inherent risk factors and financial statement level risks. Determine whether any assessed risks are significant risks.

Significant Risk: Assessment of inherent risk is close to the upper end of the spectrum of inherent risk.

Assessing Control Risk (para 34)

If planning to test operating effectiveness of controls, assess control risk. If not, assessment of control risk shall be such that assessment of risk of material misstatement is the same as assessment of inherent risk.

Evaluation of Audit Evidence (para 35-37)

Evaluate whether audit evidence obtained provides appropriate basis for risk identification and assessment. Take into account all audit evidence, whether corroborative or contradictory. Revise risk assessment if new inconsistent information is obtained.

Ad Space

Documentation (para 38)

Required Documentation

RequirementDescription
(a)The discussion among the engagement team and the significant decisions reached.
(b)Key elements of the auditor's understanding in accordance with paragraphs 19, 21, 22, 24 and 25; sources of information; and risk assessment procedures performed.
(c)The evaluation of the design of identified controls and determination whether such controls have been implemented.
(d)The identified and assessed risks of material misstatement at the financial statement level and at the assertion level, including significant risks and risks for which substantive procedures alone cannot provide sufficient appropriate audit evidence, and the rationale for significant judgments made.

Key Takeaways

TopicKey Point
ObjectiveIdentify and assess risks of material misstatement at financial statement and assertion levels.
Risk Assessment ProceduresInquiries, analytical procedures, observation and inspection.
Understanding RequiredEntity and its environment, applicable financial reporting framework, system of internal control.
Internal Control ComponentsControl environment, risk assessment process, monitoring process, information system and communication, control activities.
Inherent Risk AssessmentAssess likelihood and magnitude of misstatement considering inherent risk factors.
Control Risk AssessmentAssess if planning to test operating effectiveness; otherwise same as inherent risk.
Significant RiskInherent risk close to upper end of spectrum.
DocumentationDiscussion, understanding, evaluation of controls, identified and assessed risks.
Professional SkepticismEssential throughout the risk assessment process.
Iterative ProcessRisk assessment is dynamic and continues throughout the audit.

โ“ Ready to Test?

50 MCQs โ€ข 1.25 min each โ€ข 62.5 min total

๐Ÿ“ Start Q&A โ†’๐Ÿ“š Full Reference Version๐Ÿ–จ๏ธ Save as PDF