Skip to content

Advanced Audit and Assurance (International) · Planning, materiality and assessing the risk of material misstatement

Assessing the Risk of Material Misstatement in AAA

Updated 11 October 2026 · Fact-checked

Risk of material misstatement (RMM) is the risk that the financial statements are materially wrong before the audit. It combines inherent risk and control risk. You identify risks from the scenario, assess them at financial statement and assertion level, flag significant risks, then design specific responses under ISA 330.

Understand Assessing the Risk of Material Misstatement

Audit risk is the risk that you give an inappropriate opinion when the financial statements are materially misstated. It has two parts. The first is the risk of material misstatement (RMM), which exists in the entity. The second is detection risk, which is the risk that your procedures fail to find a material misstatement. You control detection risk. You do not control RMM.

Inherent risk is the susceptibility of an assertion to material misstatement before considering any controls. Complex estimates, unusual transactions, pressure on management to hit targets, new accounting standards and obsolete inventory all raise inherent risk. Control risk is the risk that the entity's internal controls will not prevent, or detect and correct, a material misstatement in time. Weak segregation of duties, no authorisation limits or poor IT controls raise control risk. Inherent risk exists even with perfect controls. Control risk exists because controls are weak or not working.

Under ISA 315 (Revised 2019) you assess RMM at two levels. Financial statement level risks affect the statements as a whole, for example management override, weak control environment, going concern doubt or an inexperienced finance team. Assertion level risks affect a specific class of transactions, balance or disclosure, for example valuation of inventory or occurrence of revenue. ISA 315 asks you to assess inherent risk and control risk separately for assertions. You assess inherent risk by considering how likely and how large a misstatement could be.

A significant risk is an identified risk of material misstatement that is close to the upper end of the spectrum of inherent risk. It needs special audit consideration. Under ISA 240, assessed risks of material misstatement due to fraud are treated as significant risks. Management override of controls is always treated as a significant risk. Revenue recognition is a presumed fraud risk. You may rebut that presumption only where it is not applicable to the engagement, and you must document the reasons. Other examples are major related party transactions outside the normal course of business and highly subjective estimates. For significant risks you must understand and evaluate the design and implementation of the related controls, and you must perform substantive procedures that respond specifically to the risk. If your response to a significant risk is solely substantive procedures, they must include tests of details, not analytical procedures alone.

ISA 330 links the assessment to your response. You design overall responses for financial statement level risks, such as assigning more experienced staff, adding unpredictability to procedures or doing more testing at the year end. For assertion level risks you design further audit procedures, which are tests of controls and substantive procedures, whose nature, timing and extent respond to the assessed risk. The higher the RMM, the more persuasive the evidence you need.

Key rules to remember

Audit risk model
Audit risk = Risk of material misstatement × Detection risk
A conceptual model, not a calculation. Higher RMM means you must lower detection risk by doing more or better work.
Components of RMM
RMM is a combination of inherent risk and control risk, assessed separately at assertion level
This is conceptual, not an arithmetic product. ISA 315 requires separate assessments of inherent and control risk at assertion level. Do not merge them in your answer.
Detection risk and RMM
Higher RMM → lower acceptable detection risk → more extensive, more reliable evidence
This is the logic behind ISA 330. State the link explicitly.
Levels of assessment
Financial statement level (pervasive) and assertion level (specific)
Financial statement level risks get overall responses. Assertion level risks get specific further procedures.
Significant risk requirements
Significant risk → evaluate design and implementation of controls + substantive procedures specific to the risk. If the response is solely substantive procedures, they must include tests of details.
Tests of controls alone are not enough. Analytical procedures alone are not enough where the response is solely substantive. If you plan to rely on controls over a significant risk, you must test those controls in the current period (ISA 330). This is not a general requirement for all controls.
Assertion examples
Transactions: occurrence, completeness, accuracy, cutoff, classification. Balances: existence, rights and obligations, completeness, accuracy, valuation and allocation. Presentation and disclosure: occurrence and rights and obligations, completeness, classification and understandability, accuracy and valuation.
Tie every risk to an assertion so your response is targeted.

How to solve Assessing the Risk of Material Misstatement questions

Use this method for any requirement asking you to identify, assess or respond to audit risks from a scenario.

  1. 1Read the requirement. Note whether it asks for risks only, or risks and responses, and how many marks are available. Roughly one mark per well-made point is a guide.
  2. 2Scan the scenario for triggers: new systems, rapid growth, targets and bonuses, estimates, complex or unusual transactions, staff turnover, new standards, going concern signs.
  3. 3For each trigger, state the risk in terms of what could be misstated. Name the assertion, such as valuation of inventory or occurrence of revenue.
  4. 4Explain why it is a risk using the scenario facts. Say whether it is inherent risk, control risk, or both.
  5. 5Decide whether it is financial statement level or assertion level. Flag any significant risks and say why, for example fraud, estimates or non-routine transactions.
  6. 6Give a specific audit response for each risk. State the nature of the procedure, and where useful the timing and extent. Link it clearly to the risk.
  7. 7For control weaknesses, say whether you would rely on controls or go fully substantive, and the effect on detection risk.
  8. 8Check you have used scenario facts in every point and that your responses are not generic.

Quickest way: Risk, Why, Response (RWR) per scenario fact

When to use it: Use under time pressure when the scenario is long and the requirement asks for risks and audit responses.

  1. Highlight each scenario fact that could cause misstatement as you read.
  2. Write one line for each: the risk and assertion.
  3. Add a short reason, using a number or detail from the scenario.
  4. Add one specific procedure, for example inspect post year end sales returns for cut-off.
  5. Mark any fraud, estimate or unusual transaction as significant.
  6. Spend the most time on the largest and highest risk items.

Common mistakes in Assessing the Risk of Material Misstatement

  • Writing generic risks such as 'there may be errors in inventory'.

    Students recall a standard list and do not apply the scenario.

    Fix: Quote the scenario fact, name the assertion, and say what could go wrong. For example, 'slow-moving stock of ₹40,00,000 may be overvalued'.

  • Confusing inherent risk and control risk.

    Both lead to misstatement, so they feel the same.

    Fix: Ask whether the risk exists before any controls (inherent) or arises because controls are weak or missing (control).

  • Treating detection risk as something the client controls or as part of RMM.

    The audit risk model is memorised without understanding.

    Fix: Detection risk is the auditor's risk. You reduce it by changing the nature, timing and extent of procedures.

  • Listing risks without audit responses, or responses that do not match the risk.

    Students run out of time or think identifying risks is enough.

    Fix: Pair every risk with a targeted procedure. Check that the procedure tests the assertion you named.

  • Missing that revenue recognition and management override are significant risks.

    Students judge significance on size alone.

    Fix: Under ISA 240 assessed fraud risks are treated as significant risks, and management override is always a significant risk. Revenue recognition is a presumed fraud risk. You may rebut that presumption only where it is not applicable, and you document the reasons. Mention them where the scenario fits, and explain why.

  • Confusing business risks with risks of material misstatement.

    Scenarios describe commercial problems such as falling sales.

    Fix: Only include a business risk if it can lead to a material misstatement, and show that link, for example impairment or going concern.

Worked examples

Example 1

You are the audit senior on Zenith Retail, a listed company. In the year, it introduced a new inventory system, and the finance director's bonus depends on reaching a profit target. Year end inventory is a large balance and includes slow-moving lines. Identify and explain the risks of material misstatement and state your audit responses. (8 marks)

Show the solution
  1. New inventory system: inherent risk of data migration errors and control risk from unproven controls. Assertion: existence, accuracy and completeness of inventory. The new system creates both inherent risk and control risk at assertion level.
  2. Response: obtain an understanding of the new system, test migration by agreeing opening balances from the old system to the new system, and attend the inventory count to test count records to the system.
  3. Bonus linked to profit: this is a fraud risk factor, because it creates incentive and pressure. It gives rise to a fraud risk of overstated profit through inventory or revenue, so treat that fraud risk as significant. Management override is also always a significant risk.
  4. Response: use more experienced staff, include unpredictable procedures, test journals for unusual entries, and review estimates for bias.
  5. Slow-moving inventory: inherent risk that inventory is overvalued if cost exceeds net realisable value under IAS 2. Assertion: valuation. The estimate involves judgement, so it may be significant.
  6. Response: review the inventory ageing report, compare cost to post year end selling prices, test the provision calculation, and discuss with management the plans for sale.
  7. Overall: because controls are not yet proven, RMM is high. High RMM requires a lower acceptable detection risk. You achieve this with a mainly substantive approach and more extensive testing near the year end.

Answer: Key risks are: (1) inherent risk and control risk over the new system, affecting existence, completeness and accuracy of inventory, answered with migration testing, count attendance and testing of system records; (2) the bonus as a fraud risk factor giving a fraud risk of overstated profit, treated as significant along with management override, answered with senior staff, journal testing, unpredictability and bias review; (3) valuation risk on slow-moving inventory under IAS 2, answered with ageing review, NRV testing against post year end prices and provision testing. Because controls are not yet proven, RMM is high, so you need a lower acceptable detection risk. You achieve it with a mainly substantive approach and more extensive testing near the year end.

Example 2

Explain the difference between inherent risk and control risk and show how an assessment of high RMM changes the audit approach. Use a company that sells goods to many customers on credit and has weak credit control. (6 marks)

Show the solution
  1. Define inherent risk: the susceptibility of an assertion to material misstatement before considering controls. In the scenario, trade receivables carry inherent risk because many credit customers raise the chance that some will not pay, so valuation depends on judgement.
  2. Define control risk: the risk that controls will not prevent, or detect and correct, a material misstatement. Weak credit control means there is no credit-limit approval or timely chasing, so overdue balances may go undetected and unprovided.
  3. Show the difference: inherent risk exists because of the nature of the receivables balance. Control risk exists because of the company's weak controls. Both feed into RMM.
  4. Effect on approach: because RMM for valuation is high, the auditor must reduce detection risk. Given the weaknesses, you would expect not to rely on controls and would adopt a primarily substantive approach.
  5. Nature: send receivable confirmations, which mainly support existence. Review cash received after the year end and the aged balances, which support recoverability and valuation. If you judge the valuation risk to be a significant risk, analytical procedures alone would not be sufficient (ISA 330), so you would include tests of details.
  6. Extent: increase sample size for receivables and test more overdue balances.
  7. Timing: you would expect to perform the main testing at or near the year end rather than at an interim date.
  8. Valuation: review the aged receivables listing and test the allowance for expected credit losses under IFRS 9.

Answer: Inherent risk is the risk arising from the nature of receivables before controls. Control risk arises because weak credit control will not stop or detect misstatement. Together they give a high RMM for receivables valuation. Given the weaknesses, the auditor would expect not to rely on controls and would lower detection risk by going primarily substantive: confirmations for existence, after-date cash testing and ageing review for recoverability and valuation, testing the expected credit loss allowance, a larger sample size and year end timing.

Exam tips

  • Always tie each risk to a scenario fact and an assertion. A risk without scenario application earns few marks.
  • Separate risk identification from response, then link them. Markers award marks for both and for the link.
  • State when a risk is significant and why. Use fraud, estimates and unusual transactions as your reasons.
  • Use professional skills: show scepticism by questioning management's explanations, and prioritise the highest risks in your answer.
  • Do not describe business risks alone. Show how each could lead to a material misstatement.

Practice questions from Planning, materiality and assessing the risk of material misstatement

Assessing the Risk of Material Misstatement in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Assessing the Risk of Material Misstatement: frequently asked questions

What is the difference between inherent risk and control risk?

Inherent risk is the susceptibility of an assertion to material misstatement before considering controls. Control risk is the risk that the entity's controls will not prevent, or detect and correct, that misstatement in time. Inherent risk comes from the nature of the item. Control risk comes from the quality of the controls.

What is a significant risk under ISA 315?

It is an identified risk of material misstatement that is close to the upper end of the spectrum of inherent risk, so it needs special audit consideration. Examples are fraud risks, highly subjective estimates and unusual transactions. You must evaluate the design and implementation of related controls and perform specific substantive procedures.

How does detection risk relate to the risk of material misstatement?

They have an inverse relationship. When RMM is assessed as high, you accept a lower detection risk. You achieve this by changing the nature, timing and extent of your procedures to get more persuasive evidence.

How do I identify audit risks from an AAA scenario?

Look for triggers such as new systems, bonus targets, estimates, unusual transactions, rapid growth and staff turnover. For each one, state what could be misstated, name the assertion and explain why. Then give a specific response.