Advanced Audit and Assurance (International) · Planning, materiality and assessing the risk of material misstatement
ISA 315 (Revised 2019): Understanding the Entity and Its Environment
Updated 11 October 2026 · Fact-checked
Under ISA 315 (Revised 2019), you understand the entity, its environment, the applicable financial reporting framework and its system of internal control using risk assessment procedures: inquiries, analytical procedures, and observation and inspection. You then use that understanding to identify and assess risks of material misstatement at financial statement and assertion level.
Understand Understanding the Entity and Its Environment
An auditor cannot assess what could go wrong in the financial statements without knowing the business. ISA 315 (Revised 2019) requires you to obtain this understanding as the basis for identifying and assessing the risks of material misstatement (RMM). The standard makes this work mandatory and not a one-off. It is done at planning and updated as the audit goes on.
The understanding has three broad parts. First, the entity and its environment: its organisational structure, ownership and governance, business model, industry, regulation, and how it measures its own performance. Second, the applicable financial reporting framework, for example IFRS Accounting Standards, and how the entity's accounting policies fit its business. Third, the system of internal control: the control environment, the entity's risk assessment process, the process to monitor the system, the information system and communication, and control activities.
You gather this through risk assessment procedures: inquiries of management and others, analytical procedures, and observation and inspection. Inquiries alone do not provide sufficient appropriate audit evidence for the risk assessment. You also consider information from client acceptance or continuance, from prior audits, and from other engagements. The engagement partner and key team members must discuss the susceptibility of the financial statements to material misstatement.
Business risk and RMM are related but different. Business risk is a risk resulting from significant conditions, events or actions that could stop the entity achieving its objectives, such as a new competitor or a regulatory change. RMM is the risk that the financial statements are materially misstated prior to the audit. You assess RMM at both the financial statement level and the assertion level. At the assertion level, you assess inherent risk and control risk separately. Many business risks lead to RMM, but not all do. A failed product launch is a business risk. It becomes an RMM if it means inventory should be written down or an impairment recorded.
In the exam you are given a scenario. You pick out the facts, link each to a possible misstatement, and say what you would do about it. Marks go to the link, not to a list of facts.
Key rules to remember
- Risk assessment procedures
- Inquiries + analytical procedures + observation and inspection
- These are the types of risk assessment procedures the standard requires you to perform. Inquiry alone does not provide sufficient appropriate audit evidence for the risk assessment.
- Components of the system of internal control
- Control environment, entity's risk assessment process, process to monitor the system, information system and communication, control activities
- ISA 315 (Revised 2019) sets these out as five components. Know the five names.
- Audit risk
- Audit risk = risk of material misstatement × detection risk
- A conceptual relationship, not a calculation with fixed figures. RMM is assessed at both the financial statement level and the assertion level. At the assertion level, inherent risk and control risk are assessed separately.
- Assessing inherent risk
- Inherent risk is assessed by likelihood and magnitude of possible misstatement
- Consider the inherent risk factors: complexity, subjectivity, change, uncertainty and susceptibility to misstatement due to management bias or fraud.
- Levels of RMM
- Financial statement level and assertion level
- Pervasive risks sit at financial statement level. Assertion-level risks are tied to a class of transactions, balance or disclosure.
How to solve Understanding the Entity and Its Environment questions
Use this method for any requirement asking you to identify risks, explain business risks, or say what you learn about the entity from a scenario.
- 1Read the requirement. Decide whether it asks for business risks, risks of material misstatement, procedures, or all three.
- 2Scan the scenario and tick each fact about the industry, ownership, strategy, regulation, systems, controls or accounting. Each fact is a possible risk.
- 3For each fact, state the business risk or the feature in one short sentence.
- 4Link it to the financial statements. Name the balance, transaction or disclosure and the assertion affected, such as valuation or completeness.
- 5Say whether the risk is at financial statement level or assertion level, and whether it is a significant risk (for example, fraud or estimation uncertainty).
- 6State the audit response, for example more substantive work, specialist input, or extra team supervision.
- 7Where the requirement asks how you gain understanding, name the risk assessment procedure used: inquiry, analytical procedure, or observation and inspection.
- 8Finish with a short professional skills point, such as scepticism about management's explanations, where it fits the question.
Quickest way: Fact, risk, account, response
When to use it: Use this when time is short, or for a 10 to 15 mark risk identification requirement in the case study.
- Mark each risk-relevant fact in the scenario as you read.
- Write one line per fact in this pattern: fact, so risk, so account and assertion, so response.
- Put the highest-risk items first: fraud, estimates, going concern, unusual transactions.
- Stop when you have enough distinct, well-explained points for the marks. Do not pad with generic risks.
Common mistakes in Understanding the Entity and Its Environment
Listing business risks without linking them to the financial statements.
Students see the scenario fact and stop after describing it.
Fix: Always add: so which balance, which assertion, and what could be misstated.
Treating business risk and risk of material misstatement as the same thing.
The two terms sound alike and often overlap.
Fix: Define each in a line. Business risk affects objectives. RMM affects the financial statements. Show how the first can create the second.
Saying inquiry of management alone is enough to understand the entity.
It is the easiest procedure to describe.
Fix: Pair inquiry with analytical procedures and observation or inspection, such as a site visit or reading minutes.
Writing generic risks that could apply to any company.
Students rely on memorised lists.
Fix: Use names, figures and events from the scenario. Each point must be specific to this client.
Ignoring the system of internal control, or only describing control activities.
Students think controls belong only in the testing stage.
Fix: Cover all five components when the requirement asks about the system of internal control, and prioritise those the scenario evidences. The control environment and the monitoring process often show fraud and error risk.
Giving no audit response.
The requirement says identify, so students stop early.
Fix: Add a short response to each major risk where the requirement allows. It shows commercial and professional judgement.
Worked examples
Example 1
You are planning the audit of Ridgeway, a manufacturer of electric scooters. Management has told you that a competitor launched a cheaper model six months ago, sales have fallen, and the company has large finished goods inventory. Its bank loan has a covenant on minimum profit. Identify the business risks and explain the related risks of material misstatement. (8 marks)
Show the solution
- Business risk 1: the competitor's cheaper model reduces demand and selling prices.
- Link: inventory may be held at cost above net realisable value. The assertion is valuation. Management may delay write-downs.
- Business risk 2: falling sales put profit under pressure.
- Link: there is a risk of overstated revenue or understated expenses, such as cut-off errors and early recognition. The assertions are occurrence and cut-off.
- Business risk 3: the loan covenant on minimum profit.
- Link: this gives management an incentive to manipulate profit. It is a fraud risk factor. ISA 240 presumes a fraud risk in revenue recognition (a rebuttable presumption), and the covenant strengthens that presumption, so I would treat revenue as a significant fraud risk.
- Business risk 4: with sales falling, the covenant on minimum profit may be breached. We are not told that it has been.
- Link: if the covenant is breached, the loan may become repayable on demand. That could raise doubt about going concern (ISA 570), and the classification of the loan and the disclosures may be inadequate. The classification and disclosure assertions are affected.
- Response: test the inventory net realisable value using post year-end sales, review the covenant calculations and any lender correspondence, evaluate management's going concern assessment under ISA 570, and apply professional scepticism to management's explanations.
Answer: Four main points: falling demand creates a risk of overstated inventory, the profit pressure creates a risk of overstated revenue, the covenant creates a fraud incentive that strengthens the ISA 240 presumed fraud risk in revenue, and a possible covenant breach, if it occurs, creates going concern (ISA 570) and classification risk. Each is tied to an assertion and has an audit response.
Example 2
Explain the risk assessment procedures you would use at Kelvin Co, a new audit client that is a retail chain, to understand the entity and its environment. State one matter you would learn from each. (6 marks)
Show the solution
- Inquiries: ask management, finance staff, internal audit and those charged with governance about strategy, new stores, changes in systems and known fraud. You learn where management sees risk and where estimates are used.
- Analytical procedures: compare monthly sales, gross margins and inventory days against prior years and the retail sector. You learn about unusual trends, such as a falling margin that may indicate inventory write-down issues.
- Observation and inspection: visit stores and the warehouse, observe the till and stock processes, and read board minutes, budgets and the internal control documentation. You learn how controls operate in practice and how management monitors performance.
- Other sources: review the client acceptance file and the predecessor auditor's information. You learn about prior issues.
- Also hold a team discussion on where the financial statements may be susceptible to material misstatement.
Answer: Use inquiries, analytical procedures, and observation and inspection, supported by acceptance information and a team discussion. Each gives a different type of understanding, and together they support the risk assessment.
Exam tips
- Always tie each business risk to a financial statement account and assertion. This is where most marks are won.
- Use the figures and names in the scenario. Generic answers score poorly.
- If the requirement asks about the system of internal control, structure your answer by the five components.
- Show professional skills: challenge management's explanations and state what evidence you would want.
- Keep each point short: fact, risk, response. Cover more distinct points rather than expanding one.
Practice questions from Planning, materiality and assessing the risk of material misstatement
- Oakfield Foods Ltd has a CEO bonus that depends entirely on reported operating profit margin, which management reviews monthly as its key pe…
- Brightwater Telecom Ltd has recently acquired a competitor and introduced a new billing system. The audit team is documenting its understand…
- When determining materiality for a not-for-profit charity, Mercy Trust, audited by Clarke & Partners, which benchmark would normally be most…
- During planning of the audit of Alderwick plc, the auditor identifies a risk relating to management's override of controls and to revenue re…
- At the planning stage of Orchard Media's audit, the engagement partner holds a team discussion on the susceptibility of the financial statem…
Understanding the Entity and Its Environment in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Understanding the Entity and Its Environment: frequently asked questions
What are the risk assessment procedures in ISA 315 (Revised 2019)?
They are inquiries, analytical procedures, and observation and inspection. You use them to understand the entity, its environment, the reporting framework and its internal control system. They give the basis for identifying and assessing RMM.
What is the difference between business risk and risk of material misstatement?
Business risk is a threat to the entity achieving its objectives. RMM is the risk that the financial statements are materially misstated prior to the audit. A business risk may lead to RMM if it affects what is reported, such as a fall in demand affecting inventory valuation.
Do I need to understand all of the entity's internal controls?
Not every control. Under ISA 315 (Revised 2019) you obtain an understanding of each of the five components of the system of internal control: the control environment, the entity's risk assessment process, the process to monitor the system, the information system and communication, and control activities. For control activities, you identify only the controls relevant to the audit. These include controls that address significant risks, controls over journal entries, controls where substantive procedures alone cannot provide sufficient appropriate evidence, and controls you plan to test for operating effectiveness. For each identified relevant control, you evaluate its design and determine whether it has been implemented.
Is understanding the entity done only at the planning stage?
No. You start at planning, but you update your understanding and risk assessment as new information appears during the audit. If the assessment changes, you change your planned procedures.