Skip to content

Advanced Auditing, Assurance and Professional Ethics · Materiality, Risk Assessment and Internal Control

Identifying and Assessing Risks of Material Misstatement (SA 315)

Updated 5 October 2026 · Fact-checked

Under SA 315 (Revised 2019), you identify risks of material misstatement at the financial statement level and at the assertion level, assess inherent risk and control risk separately, and decide which are significant risks. You then link each risk to responses under SA 330, including tests of controls or substantive procedures.

Understand Identifying and Assessing Risks of Material Misstatement

A risk of material misstatement (RMM) is the risk that the financial statements are materially misstated before the audit. It has two parts: inherent risk and control risk. You assess both. Detection risk is the one you control through your own procedures, so it is not part of the RMM.

Inherent risk is the susceptibility of an assertion to a misstatement, before considering any controls. SA 315 (Revised) lists inherent risk factors that affect it: complexity, subjectivity, change, uncertainty, and susceptibility to misstatement due to management bias or other fraud risk factors. Example: a fair value estimate based on unobservable inputs has high subjectivity and uncertainty, so its inherent risk is high.

Control risk is the risk that the entity's controls will not prevent, or detect and correct, a misstatement on a timely basis. If you plan to test the operating effectiveness of controls, you can assess control risk below the maximum. If you do not plan to test operating effectiveness, the assessment of control risk is such that the risk of material misstatement equals the assessment of inherent risk. This applies only where tests of controls are not required. Where substantive procedures alone cannot provide sufficient appropriate audit evidence, tests of controls are mandatory, and you cannot set control risk at maximum without them.

SA 330 (para 8(b)) requires you to test controls where substantive procedures alone cannot give sufficient appropriate audit evidence at the assertion level. SA 315 (Revised) requires you to identify such risks and evaluate the related controls.

Risks are identified at two levels. Financial statement level risks affect the statements as a whole and may affect many assertions, for example weak control environment or management override. Assertion level risks relate to classes of transactions, account balances and disclosures, for example occurrence of revenue or valuation of inventory. You use a spectrum of inherent risk: the higher the combination of likelihood and magnitude of misstatement, the higher the assessed inherent risk.

A significant risk is an identified risk of material misstatement for which the assessed inherent risk is close to the upper end of the spectrum. It needs special audit consideration. For significant risks, you identify the controls that address the risk, evaluate their design and determine whether they have been implemented. If you rely on those controls, you must test them in the current period (SA 330).

Separately, SA 315 (Revised) requires you to identify risks for which substantive procedures alone cannot provide sufficient appropriate audit evidence, for example highly automated routine transactions with little or no manual intervention. For these, you evaluate the design and implementation of the related controls. This is a different requirement from the significant risk definition.

Key rules to remember

Audit risk model
Audit risk = Risk of material misstatement × Detection risk
RMM is the combination of inherent risk and control risk. Lower assessed RMM allows higher acceptable detection risk.
Components of RMM
RMM = Inherent risk and Control risk (assessed separately at assertion level)
SA 315 (Revised) requires separate assessment of inherent risk and control risk. Do not present them as one blended figure.
Inherent risk factors
Complexity, Subjectivity, Change, Uncertainty, Susceptibility to misstatement due to management bias or other fraud risk factors
Use these words in your answer. Remember them as a list.
Significant risk
Inherent risk assessed close to the upper end of the spectrum of inherent risk
Judgment based on likelihood and magnitude. Non-routine transactions and judgmental matters often qualify. Identified risks of material misstatement due to fraud are treated as significant risks (SA 240). For significant risks, identify the controls that address them, evaluate their design and determine whether they are implemented.
Control risk rule
If no plan to test operating effectiveness of controls (and tests of controls are not required), RMM = assessed inherent risk
This holds only where tests of controls are not required. SA 330 (para 8(b)) requires tests of controls where substantive procedures alone cannot give sufficient appropriate evidence. In that case tests of controls are mandatory, and control risk cannot be set at maximum without them. SA 315 (Revised) requires you to identify such risks and evaluate the related controls. Controls relied on for significant risks must be tested in the current period.

How to solve Identifying and Assessing Risks of Material Misstatement questions

Use this order for any scenario question on risk assessment. It keeps your answer in provision-facts-conclusion form.

  1. 1Read the facts and mark features of the entity: industry, size, ownership, IT systems, new transactions, estimates, management pressure.
  2. 2Decide the level. State whether each risk is at the financial statement level or at the assertion level, and name the assertion (occurrence, completeness, accuracy, cut-off, classification, existence, rights and obligations, valuation, presentation).
  3. 3Apply the inherent risk factors. Name the one that applies, such as subjectivity, complexity, change, uncertainty or management bias.
  4. 4Assess control risk from the facts. Say whether controls are designed and implemented, and whether you plan to test them.
  5. 5Decide if the risk is significant. Use the position on the spectrum of inherent risk, and note that fraud risks and non-routine, judgmental matters are usually significant.
  6. 6Check if substantive procedures alone are enough. If routine data is highly automated with little manual intervention, state that tests of controls are also needed.
  7. 7Conclude with the response: tailored procedures, identification and evaluation of related controls, and communication with those charged with governance where required. Keep the link to SA 330 short.

Quickest way: Level, Factor, Control, Significance

When to use it: Use this in the exam when a case gives many facts and you have only a few minutes per part.

  1. Underline each risky fact in the case.
  2. Next to each, write the level and the assertion.
  3. Tag the inherent risk factor in one word.
  4. Write one line on controls: present, absent or not tested.
  5. Mark S if the risk is significant. Mark T if tests of controls are also needed.
  6. Write the answer as: fact, risk, factor, response.

Common mistakes in Identifying and Assessing Risks of Material Misstatement

  • Treating detection risk as part of the risk of material misstatement.

    The audit risk model has three words and students mix them up.

    Fix: RMM is only inherent risk plus control risk. Detection risk is the auditor's own risk of not finding a misstatement.

  • Assessing inherent risk after taking controls into account.

    Students think a good control reduces every risk.

    Fix: Assess inherent risk before considering controls. Controls affect control risk only.

  • Listing risks without stating the level or assertion.

    Students write general business risks and stop there.

    Fix: For each risk write whether it is at the financial statement or assertion level and name the assertion affected.

  • Calling every large balance a significant risk.

    Size is confused with risk.

    Fix: Significant risk depends on the likelihood and magnitude of misstatement, not size alone. A large routine balance can be low risk. Use the spectrum of inherent risk.

  • Forgetting that controls relied on for a significant risk must be tested in the current period.

    Students rely on prior year audit evidence out of habit.

    Fix: For significant risks, do not rely on prior period evidence about control operation. Test in the current period.

  • Writing that substantive procedures are always enough.

    Students ignore automated environments.

    Fix: If there is little or no manual intervention in a highly automated process, state that substantive procedures alone cannot give sufficient appropriate evidence, so tests of controls are needed.

Worked examples

Example 1

Case: Zenith Foods Ltd has a new ERP for sales and billing. During the year it entered a long-term contract with bundled goods and services, and revenue is recognised over time based on management's estimate of the stage of completion. The sales head's bonus depends on reported revenue. Identify the risks of material misstatement and state which are significant risks.

Show the solution
  1. Level: Pressure on the sales head through a revenue-linked bonus is a fraud risk factor. It affects revenue broadly, so it can be a financial statement level concern. It also bears on the occurrence and cut-off assertions for revenue at the assertion level.
  2. Inherent risk factors: Stage of completion is an estimate, so subjectivity and uncertainty apply. The bundled contract adds complexity. The bonus links to management bias and fraud risk factors. The new ERP is a change that affects control risk and IT controls, covered in the next step.
  3. Control risk: A new ERP means controls may not be stable. Evaluate the design and implementation of the controls. If you plan to rely on them, you must test them.
  4. Significance: Revenue recognition under a judgmental, non-routine contract with an incentive to overstate is close to the upper end of the spectrum. Treat it as a significant risk. Presumed fraud risk in revenue recognition also supports this under SA 240.
  5. Response: Identify the controls that address the risk and evaluate their design and implementation. Test ERP controls and data migration if relying on them. Perform tailored substantive procedures on the stage of completion, contract terms and cut-off.

Answer: The main risks are overstatement of revenue (occurrence, cut-off, accuracy) and misstated stage of completion. Revenue on the bundled long-term contract is a significant risk, driven by subjectivity, uncertainty, complexity and management bias. The new ERP is a separate change that affects control risk and IT controls. The auditor must identify the controls addressing the risk, evaluate their design and implementation, test them (including ERP controls) if relying on them, and design tailored substantive procedures.

Example 2

Case: Ravi & Co. audits Delta Retail Ltd. Sales are thousands of small cash and card transactions a day, processed through an automated point-of-sale system that posts to the general ledger with no manual intervention. Explain how you would assess the risk for the completeness and accuracy of revenue and why substantive procedures alone may not be enough.

Show the solution
  1. Identify the assertions: completeness and accuracy of revenue, plus occurrence.
  2. Inherent risk: The transactions are routine and not subjective, but the volume is high. Inherent risk may be assessed at a lower level than for estimates, unless other factors apply. It is a judgment on the spectrum.
  3. Nature of the process: The data is created and posted automatically with little or no manual intervention. The evidence exists mainly in electronic form.
  4. Rule: This is a risk for which substantive procedures alone cannot provide sufficient appropriate audit evidence. You evaluate the design and implementation of the related controls, and tests of controls are also necessary.
  5. Response: Test the general IT controls and the automated controls over the point-of-sale interface, such as access, change management and posting logic. Then perform limited substantive procedures such as reconciling takings to bank credits.

Answer: The risk on completeness and accuracy of revenue is one for which substantive procedures alone are not sufficient, because the process is highly automated with little manual intervention. The auditor should evaluate the design and implementation of related controls, test relevant IT general controls and automated controls, and supplement with substantive procedures.

Exam tips

  • Always name the assertion and the inherent risk factor. Examiners reward these exact terms.
  • For questions asking to distinguish inherent risk and control risk, give the definition, who it depends on (the nature of the item versus the entity's controls), and one example each.
  • If a case mentions management pressure, bonuses or unusual transactions, link it to significant risk and fraud risk under SA 240.
  • In MCQs, check whether the question asks about the financial statement level or the assertion level before choosing.
  • Keep the response short and linked to SA 330. The question is about assessment, not a full audit programme.

Practice questions from Materiality, Risk Assessment and Internal Control

Identifying and Assessing Risks of Material Misstatement in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Identifying and Assessing Risks of Material Misstatement: frequently asked questions

What is the difference between inherent risk and control risk?

Inherent risk is the susceptibility of an assertion to material misstatement before considering controls. Control risk is the risk that the entity's controls will not prevent, or detect and correct, that misstatement on a timely basis. You assess them separately under SA 315 (Revised).

What are the inherent risk factors in SA 315 (Revised)?

They are complexity, subjectivity, change, uncertainty and susceptibility to misstatement due to management bias or other fraud risk factors. You use them to judge where an assertion sits on the spectrum of inherent risk.

What is a significant risk in audit?

It is an identified risk of material misstatement where inherent risk is assessed close to the upper end of the spectrum. It needs special audit consideration. You identify the controls that address it, evaluate their design and determine whether they are implemented, and test them in the current period if you rely on them.

Are risks assessed at financial statement level or assertion level?

Both. Financial statement level risks pervasively affect the statements as a whole, such as a weak control environment. Assertion level risks relate to specific classes of transactions, balances and disclosures, and drive the nature, timing and extent of further procedures.