Skip to content

CA Final · Advanced Auditing, Assurance and Professional Ethics

Materiality, Risk Assessment and Internal Control: formula sheet

Full chapter guide

Key formulas

Overall materiality
Overall materiality = chosen benchmark × chosen percentage
SA 320 gives no fixed percentage. The benchmark and percentage are judgments that you must justify and document.
Performance materiality
Performance materiality < Overall materiality
Set by judgment based on risk assessment, past misstatements and control environment. It is not a fixed fraction under SA 320.
Specific materiality
Materiality for particular items ≤ Overall materiality
Set lower where users' decisions could be influenced by smaller misstatements in certain items or disclosures.
Revision rule
New information → revise materiality (and performance materiality)
If a lower amount would have been set initially, reassess performance materiality and whether the audit procedures remain appropriate.
Clearly trivial threshold (SA 450 link)
Clearly trivial < Materiality
Misstatements below this need not be accumulated. It is set by the auditor and is not the same as performance materiality.
Risk assessment procedures
Inquiries + Analytical procedures + Observation and inspection
Risk assessment procedures shall include these three types. Inquiry alone does not provide an adequate basis for the risk assessment.
Purpose of understanding
Understanding → Identify RMM → Assess RMM → Design responses
RMM is identified at the financial statement level and at the assertion level.
Areas of understanding (entity and environment)
Organisation, ownership, governance, business model + Industry, regulatory and external factors + Performance measures
Use these as headings for a structured answer.
Framework and policies
Applicable framework + Accounting policies (selection, changes, appropriateness)
Assess whether policies suit the entity's business and the framework.
Team discussion
Engagement partner + Key team members discuss susceptibility to material misstatement + application of the framework
A separate requirement of SA 315, not a risk assessment procedure. The engagement partner decides what is communicated to members not present.
Nature of evidence
Risk assessment procedures ≠ sufficient appropriate evidence for the opinion
They support the risk assessment only. Further audit procedures are still needed.
Five components of the system of internal control
Control environment + Entity's risk assessment process + Process to monitor the system of internal control + Information system and communication + Control activities
For the first, second and third, the auditor understands and evaluates the component. For the information system and communication, the auditor understands the component. For control activities, the auditor identifies controls and evaluates design and implementation. Use the SA 315 (Revised 2019) names.
Understanding versus testing
Understanding of identified controls = evaluate design + determine implementation. Testing = check operating effectiveness
Understanding of the system is always required. Testing is needed when relying on controls or when substantive procedures alone are insufficient.
Limitation of internal control
Reasonable assurance, not absolute assurance
Limits include human error, collusion, management override and cost-benefit considerations.
Manual versus automated controls
Manual = performed by people, prone to error and override. Automated = performed by IT, consistent, depends on general IT controls
An automated control works consistently only if general IT controls are effective.
Controls relevant to the audit
Significant risk controls + journal entry controls + controls where substantive procedures alone are not sufficient + others judged relevant
For these identified controls the auditor evaluates design and determines implementation.
Manual control: when suitable
Judgment needed + large, unusual or non-recurring items + hard-to-predict errors → manual
Also useful where control activities are needed in changing circumstances. Weakness: easier to bypass, override or make errors; less reliable.
Automated control: when suitable
High volume + recurring items + predictable errors → automated
Applies the same logic consistently, if the IT environment is effective. Risk: it fails everywhere if programming or access is compromised.
Reliance chain
Effective ITGCs → reliable application controls → reliable automated processing and information
Weak ITGCs undermine automated controls and system-generated reports.
ITGC areas
Access security | Program change | Program development | IT operations
These support the continued effective operation of application controls.
Core IT risk themes
Inaccurate processing | Unauthorised access | Unauthorised changes (data, master files, programs) | Failure to change | Manual intervention | Data loss
Use these as a checklist when a case describes an IT system.
Audit risk model
Audit risk = Risk of material misstatement × Detection risk
RMM is the combination of inherent risk and control risk. Lower assessed RMM allows higher acceptable detection risk.
Components of RMM
RMM = Inherent risk and Control risk (assessed separately at assertion level)
SA 315 (Revised) requires separate assessment of inherent risk and control risk. Do not present them as one blended figure.
Inherent risk factors
Complexity, Subjectivity, Change, Uncertainty, Susceptibility to misstatement due to management bias or other fraud risk factors
Use these words in your answer. Remember them as a list.
Significant risk
Inherent risk assessed close to the upper end of the spectrum of inherent risk
Judgment based on likelihood and magnitude. Non-routine transactions and judgmental matters often qualify. Identified risks of material misstatement due to fraud are treated as significant risks (SA 240). For significant risks, identify the controls that address them, evaluate their design and determine whether they are implemented.
Control risk rule
If no plan to test operating effectiveness of controls (and tests of controls are not required), RMM = assessed inherent risk
This holds only where tests of controls are not required. SA 330 (para 8(b)) requires tests of controls where substantive procedures alone cannot give sufficient appropriate evidence. In that case tests of controls are mandatory, and control risk cannot be set at maximum without them. SA 315 (Revised) requires you to identify such risks and evaluate the related controls. Controls relied on for significant risks must be tested in the current period.
Deficiency
Control cannot prevent, or detect and correct, misstatements on a timely basis, or a needed control is missing
Covers design, implementation and operation failures, and absent controls.
Significant deficiency
Deficiency, or combination of deficiencies, important enough in the auditor's judgment to merit TCWG attention
Judgment-based. Combinations of deficiencies can together be significant.
Written communication to TCWG
Significant deficiencies: in writing, on a timely basis, ordinarily before the audit report is issued
Oral communication alone is not enough for significant deficiencies.
Communication to management
(a) Significant deficiencies: in writing or orally, at an appropriate level, unless it is inappropriate to do so. (b) Other deficiencies that merit management's attention and have not been communicated to management by others: in writing or orally, at an appropriate level.
If a communication to management is oral, document it in the working papers. The 'not communicated by others' condition applies only to the other deficiencies in (b), not to significant deficiencies.
Content of the written communication
Description + explanation of potential effects + information for corrective action + limitation statements
Explain the potential effects in suitable terms; they need not be quantified. Say the audit purpose was to express an opinion on the financial statements, not on internal control, and that only deficiencies identified are reported. State that the communication is solely for use by TCWG (and management, or others in the organisation) and is not to be used by third parties.
Management response
Management's written responses may be included in the communication
Do not let management's response replace your own communication. If the responses were not subjected to audit procedures, you may add a comment saying so.

Quick revision

  • Materiality is a judgement. Benchmarks such as profit before tax or revenue are starting points, not fixed rules.
  • Performance materiality is set below materiality to lower the chance that uncorrected and undetected misstatements together exceed materiality.
  • Materiality has a qualitative side. A small misstatement can still be material, for example if it hides a breach of law or turns a loss into a profit.
  • Revise materiality if you learn new information during the audit that would have changed the original figure.
  • The auditor must understand the entity, its environment, the applicable financial reporting framework and the entity's system of internal control.
  • The five components of internal control: control environment, entity's risk assessment process, process to monitor the system of internal control, information system and communication, and control activities.
  • Controls are manual or automated. Automated controls are consistent but depend on general IT controls working.
  • General IT controls support the IT environment. Application controls work at the transaction level.
  • Risks of material misstatement are assessed at the financial statement level and at the assertion level.
  • A significant risk needs special audit consideration. For significant risks, the auditor must identify the controls that address them, evaluate their design and determine whether they have been implemented.
  • The risk of material misstatement consists of inherent risk and control risk. SA 315 (Revised 2019) requires the auditor to assess inherent risk and control risk separately. Detection risk is set by the auditor in response to the assessed risks.
  • Under SA 265, communicate significant deficiencies in writing to those charged with governance on a timely basis, and report other deficiencies to the appropriate level of management.

Common mistakes

  • Treating performance materiality as equal to or higher than overall materiality. Fix: Remember it is always set below overall materiality, to cover aggregate undetected and uncorrected misstatements.
  • Claiming SA 320 prescribes a percentage such as 5% of profit. Fix: Say the standard gives no fixed percentage. Percentages are judgment, and you use the one provided in the question.
  • Listing only inquiry as the way to understand the entity Fix: Write all three types of procedure. Add that inquiry alone does not provide an adequate basis for the risk assessment.
  • Treating risk assessment procedures as audit evidence for the opinion Fix: State that these procedures support the risk assessment. Substantive procedures or tests of controls are needed for the opinion.
  • Using the short forms 'risk assessment' and 'monitoring' instead of the revised names for the components. Fix: The short forms are imprecise but not wrong. Prefer the SA 315 (Revised 2019) names: the entity's risk assessment process and the process to monitor the system of internal control, which is the revised name for 'monitoring of controls'. The order of listing is not a requirement of the SA, so do not lose time on it.
  • Placing a control activity, such as bank reconciliation, under monitoring. Fix: Control activities operate on transactions and balances. Monitoring evaluates whether the control system itself is working over time.
  • Saying automated controls are always more reliable than manual controls. Fix: Write that automated controls are generally more reliable only if ITGCs are effective. Weak ITGCs undermine them.
  • Saying manual controls are useless or should never be relied on. Fix: Manual controls suit judgment areas and unusual or non-recurring transactions. The point is they are more prone to error and override, not that they cannot be relied on.
  • Treating detection risk as part of the risk of material misstatement. Fix: RMM is only inherent risk plus control risk. Detection risk is the auditor's own risk of not finding a misstatement.
  • Assessing inherent risk after taking controls into account. Fix: Assess inherent risk before considering controls. Controls affect control risk only.

Exam tips

  • Show the working: benchmark, percentage, result. Marks go to the method even if the percentage is a judgment.
  • Always link performance materiality to specific risk facts in the case, not generic wording.
  • Mention that materiality has both quantitative and qualitative aspects whenever the case hints at related parties, fraud or covenants.
  • In MCQs, remember performance materiality is below overall materiality and that no percentage is fixed by SA 320.
  • Connect with SA 450: misstatements are evaluated against materiality, and clearly trivial items need not be accumulated.
  • Begin every answer with the three types of procedure. Many marks are for naming them.
  • In case scenarios, link each fact to a risk and an assertion. Generic lists score poorly.
  • Remember the framework and accounting policies. Examiners often test this less obvious part.