Skip to content

ACCA Applied Skills · Audit and Assurance

Understanding the Entity, Its Environment and the Financial Reporting Framework

Under ISA 315 (Revised 2019), the auditor must understand the entity, its environment, the applicable financial reporting framework and its internal control system. They do this through risk assessment procedures such as inquiries, analytical procedures, observation and inspection. The aim is to identify and assess the risks of material misstatement that drive the rest of the audit.

What this chapter covers

This chapter covers the start of the audit risk process. Before you can plan any testing, you must understand the client. That means its industry, regulation, ownership, governance, business model, objectives, strategies, and how its financial performance is measured. It also means knowing the financial reporting framework that applies, such as IFRS Accounting Standards, and how the entity's accounting policies fit that framework.

The chapter then moves to the entity's system of internal control. You look at the components of control: the control environment, the entity's risk assessment process, the process to monitor the system of internal control, the information system and communication, and control activities. You also learn how to use risk assessment procedures and analytical procedures to spot where the financial statements may be misstated.

This chapter feeds almost everything else in the paper. Risk assessment leads into materiality, audit planning, audit evidence, tests of controls, substantive procedures and the final audit report. The OT cases in Section A and the constructed response questions in Section B are based on scenarios about a client. If you read the scenario for business and control clues, you can answer questions on risk, procedures and evidence much more accurately.

AA is a scenario-driven paper. The Section A OT cases and the Section B constructed response questions are based on scenarios that give you a client with facts to interpret. You are usually asked to identify risks, explain why they matter, or suggest procedures that respond to them. If you do not understand how business facts, the reporting framework and weak controls create risks of material misstatement, you will give generic answers that earn few marks. Objective test questions are marked all or nothing, so you also need exact knowledge of terms such as inherent risk, control risk, and the components of internal control. Time spent here improves marks across the whole paper.

Understanding the entity and its environment and the applicable financial reporting framework: topics in the order to study them

  1. 1Obtaining an Understanding of the Entity and Its EnvironmentStart here because it sets the context: the business, its industry, objectives and performance measures, which every later risk idea builds on.
  2. 2Applicable Financial Reporting FrameworkNext, learn the framework against which misstatements are judged, so you can link business facts to accounting risks such as estimates, revenue and disclosures.
  3. 3Understanding the Internal Control SystemWith the business and framework clear, you can see how controls prevent or detect misstatement and where weaknesses create control risk.
  4. 4Risk Assessment Procedures and Analytical ProceduresStudy this last because it is the practical toolkit that pulls the earlier topics together to identify and assess risks of material misstatement.

How to prepare Understanding the entity and its environment and the applicable financial reporting framework

Treat this chapter as a skill, not a list of facts. You need to read a scenario, spot the clues, and turn them into risks and responses.

  1. Read the chapter once for the logic of the risk assessment process: understand the client, identify risks, assess them, then respond.
  2. Learn the key terms and lists exactly, such as the components of internal control and the types of risk assessment procedure, so you can answer objective questions with certainty.
  3. For each business factor (industry, regulation, ownership, performance measures), practise stating the risk it creates for the financial statements in one clear sentence.
  4. Practise analytical procedures on small sets of figures: calculate ratios and trends, then explain what unusual movements might indicate and what you would ask the client.
  5. Work through past scenario questions. Highlight facts in the text, link each fact to a risk, and say why it matters before suggesting a procedure.
  6. For written answers, use a clear layout: one point per risk with the fact, the risk and the audit response. Check your timing, as marks follow the number of valid points.
  7. Finish with timed objective test cases to build speed and accuracy, and keep a log of wrong answers to revisit.

Common mistakes in Understanding the entity and its environment and the applicable financial reporting framework

  • Describing the client's business without stating the risk it creates.

    Fix: Use a fact, risk, response pattern. After each fact, say what could be misstated and why.

  • Confusing business risk with the risk of material misstatement.

    Fix: Remember that business risk is wider; it matters to the audit only where it could lead to a material misstatement in the financial statements.

  • Listing the components of internal control from memory but being unable to apply them.

    Fix: Practise classifying scenario weaknesses, such as no authorisation of purchases, into the right component and explain the effect on risk.

  • Treating analytical procedures as proof rather than a pointer to risk.

    Fix: Say that an unusual movement needs explanation, give possible causes, and state the inquiries or further procedures that follow.

  • Giving generic control weaknesses and recommendations.

    Fix: Tie each weakness to the described process, explain the consequence and give a practical recommendation specific to the client.

  • Confusing the auditor's risk assessment with the audit procedures that respond to it.

    Fix: Separate assessing risk from responding to it. Use the question's wording to decide which one is asked for.

Last-day revision: Understanding the entity and its environment and the applicable financial reporting framework

  • ISA 315 (Revised 2019) requires the auditor to understand the entity, its environment, the reporting framework and internal control.
  • The purpose is to identify and assess the risks of material misstatement at the financial statement and assertion levels.
  • Risk assessment procedures include inquiries, analytical procedures, and observation and inspection.
  • Risk of material misstatement is made up of inherent risk and control risk.
  • Detection risk is the risk that the auditor's procedures fail to detect a material misstatement.
  • Components of internal control: control environment, entity's risk assessment process, process to monitor the system of internal control, information system and communication, and control activities.
  • Controls can prevent or detect and correct misstatements; they give reasonable, not absolute, assurance.
  • Analytical procedures at the planning stage help identify unusual items, but they are only as good as the data and expectations behind them.
  • Always link a scenario fact to a specific risk, then to an audit response.
  • Understand how the applicable framework, such as IFRS Accounting Standards, affects areas like estimates, revenue and disclosures.
  • Significant risks need special audit consideration and a response designed specifically for them.
  • Objective test questions score all or nothing, so read every option carefully.

Understanding the entity and its environment and the applicable financial reporting framework in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Understanding the entity and its environment and the applicable financial reporting framework: frequently asked questions

What is the main purpose of understanding the entity in an audit?

The purpose is to identify and assess the risks of material misstatement in the financial statements. This gives a basis for designing audit procedures that respond to those risks. Without it, the audit would not be properly targeted.

Why does the applicable financial reporting framework matter to the auditor?

The framework sets the criteria the financial statements must meet, so it defines what a misstatement is. The auditor needs to understand how the entity applies it, particularly for estimates, judgements and disclosures. Risks often arise where the framework is complex or policies are unusual.

What are risk assessment procedures?

They are procedures performed to obtain an understanding of the entity and its environment and to identify risks of material misstatement. They include inquiries of management and others, analytical procedures, and observation and inspection. They do not by themselves provide enough evidence to support an audit opinion.

How should I answer a scenario question on risks?

Read the scenario and note facts that point to possible misstatement. For each, state the risk, explain why it matters and, if asked, give the audit response. Keep each point separate and specific to the client.