Advanced Auditing, Assurance and Professional Ethics · Materiality, Risk Assessment and Internal Control
Understanding the Entity and Its Environment (SA 315)
Updated 5 October 2026 · Fact-checked
SA 315 (Revised 2019) requires you to perform risk assessment procedures to understand the entity, its environment, the applicable financial reporting framework and its accounting policies. The procedures include inquiries, analytical procedures, and observation and inspection. Use this understanding to identify and assess risks of material misstatement, then design responses.
Understand Understanding the Entity and Its Environment (SA 315)
Audit starts with risk, not with testing. Before you can decide what to test, you must know the business: what it does, how it is owned and run, how it earns money, and what could go wrong in its financial statements. SA 315 (Revised 2019) makes this understanding a mandatory first stage.
The standard asks you to perform risk assessment procedures. These give the basis to identify and assess risks of material misstatement (RMM) at the financial statement level and at the assertion level, whether due to fraud or error. The procedures shall include:
- Inquiries of management, those charged with governance, internal audit, and others within the entity.
- Analytical procedures to spot unusual or unexpected relationships.
- Observation and inspection of operations, documents, records, premises and internal control manuals.
Inquiry alone does not provide an adequate basis for the risk assessment. Together, the procedures must give a sufficient basis to identify and assess RMM.
You may also use information from other sources: acceptance or continuance of the client relationship, other engagements for the entity, and your past experience with it. If you use prior-period information, you must check whether it is still relevant.
Separately from the risk assessment procedures, SA 315 has its own requirement for a team discussion. The engagement partner and other key engagement team members must discuss two things: the susceptibility of the entity's financial statements to material misstatement, and the application of the applicable financial reporting framework in light of the entity's nature and circumstances. The engagement partner decides which matters are communicated to team members who were not part of the discussion. This discussion is not itself one of the three procedures.
The understanding has two parts. First, the entity and its environment: organisational structure, ownership, governance and business model; the industry, regulatory and other external factors; and the measures used to assess financial performance. Second, the applicable financial reporting framework and the entity's accounting policies: why the policies are appropriate, whether changes were made and why, and how events and conditions are reflected in the statements.
Then you evaluate whether the accounting policies are appropriate for the business and consistent with the framework. This understanding feeds into SA 315's later requirements on internal control and on identifying and assessing RMM. Risk assessment procedures alone do not give sufficient appropriate evidence to support the opinion. They only support the risk assessment.
Key rules to remember
- Risk assessment procedures
- Inquiries + Analytical procedures + Observation and inspection
- Risk assessment procedures shall include these three types. Inquiry alone does not provide an adequate basis for the risk assessment.
- Purpose of understanding
- Understanding → Identify RMM → Assess RMM → Design responses
- RMM is identified at the financial statement level and at the assertion level.
- Areas of understanding (entity and environment)
- Organisation, ownership, governance, business model + Industry, regulatory and external factors + Performance measures
- Use these as headings for a structured answer.
- Framework and policies
- Applicable framework + Accounting policies (selection, changes, appropriateness)
- Assess whether policies suit the entity's business and the framework.
- Team discussion
- Engagement partner + Key team members discuss susceptibility to material misstatement + application of the framework
- A separate requirement of SA 315, not a risk assessment procedure. The engagement partner decides what is communicated to members not present.
- Nature of evidence
- Risk assessment procedures ≠ sufficient appropriate evidence for the opinion
- They support the risk assessment only. Further audit procedures are still needed.
How to solve Understanding the Entity and Its Environment (SA 315) questions
Use this method for any question on SA 315 understanding, whether it asks you to list procedures, apply them to a case, or explain why they matter.
- 1Read the case and mark what is given: industry, ownership, business model, recent changes, and any unusual data.
- 2State the rule first: SA 315 requires risk assessment procedures to understand the entity, environment, framework and policies.
- 3Name the three procedures: inquiries, analytical procedures, observation and inspection. Tie each to a fact in the case.
- 4Cover the areas of understanding relevant to the case: industry and regulation, ownership and governance, business model, performance measures, framework and policies.
- 5Link each fact to a possible risk of material misstatement and name the affected assertion or balance.
- 6Mention the team discussion (susceptibility to misstatement and application of the framework) and the use of prior-period or acceptance information if the case hints at either.
- 7Conclude: the understanding is used to identify and assess RMM and to design responses, and it does not replace further audit procedures.
Quickest way: Three procedures, five areas, one link to RMM
When to use it: Use when time is short, such as a 4 to 5 mark question or a case-based MCQ.
- Write the three procedures in one line: inquiry, analytical procedures, observation and inspection.
- List the areas as: organisation and governance, business model, industry and regulation, performance measures, framework and policies.
- Pick the two or three areas the case highlights and attach a fact and a risk to each.
- Close with one sentence: this assesses RMM and does not by itself give evidence for the opinion.
Common mistakes in Understanding the Entity and Its Environment (SA 315)
Listing only inquiry as the way to understand the entity
Inquiry feels like the natural first step and students forget the others.
Fix: Write all three types of procedure. Add that inquiry alone does not provide an adequate basis for the risk assessment.
Treating risk assessment procedures as audit evidence for the opinion
Students mix up risk assessment with further audit procedures.
Fix: State that these procedures support the risk assessment. Substantive procedures or tests of controls are needed for the opinion.
Ignoring the applicable financial reporting framework and accounting policies
Students focus only on the business and industry.
Fix: Add a point on the framework and whether policies are appropriate, consistent and changed.
Using prior-year knowledge without checking it
Continuing clients feel familiar.
Fix: Say you must determine whether prior information is still relevant to the current period.
Writing a generic answer that does not use case facts
Students memorise the list and stop reading the scenario.
Fix: Tie every point to a fact in the case and name the likely risk and affected assertion.
Treating the team discussion as one of the risk assessment procedures
It happens during planning, so students club it with inquiries and analytical procedures.
Fix: Present it as a separate SA 315 requirement among the engagement partner and key team members, covering susceptibility to misstatement and application of the framework.
Worked examples
Example 1
Case: ABC Pharma Ltd, a new audit client, makes generic drugs and exports to several countries. It recently began selling through distributors under extended credit terms. Management says that sales growth is the key performance measure. The auditor wants to understand the entity. Which risk assessment procedures apply, and what risks could they reveal?
Show the solution
- Rule: SA 315 requires risk assessment procedures to understand the entity, environment, framework and policies.
- Inquiries: ask management and sales staff about distributor terms, returns, credit policy and regulatory approvals. Ask those charged with governance about pressure to achieve targets.
- Analytical procedures: compare monthly sales, receivables ageing and returns with prior periods and with industry trends to spot unusual growth.
- Observation and inspection: inspect distributor agreements, observe dispatch and warehouse processes, and read management reports and minutes.
- Environment: export regulation, drug approvals and foreign exchange affect the business and its disclosures.
- Performance measures: a sole focus on sales growth is an incentive that may lead to revenue overstatement.
- Link to risk: possible risks are revenue recognition (cut-off, occurrence), receivables valuation and inventory valuation of near-expiry stock.
Answer: The auditor uses inquiries, analytical procedures, and observation and inspection to understand the business, regulation, performance measures and policies. The facts point to risks of material misstatement in revenue, receivables and inventory. These procedures assess risk and do not themselves support the opinion.
Example 2
Case: XYZ Ltd, a continuing audit client, changed its inventory valuation method this year and reorganised into two business segments. The audit senior says that last year's understanding is enough and no team discussion is needed. Comment.
Show the solution
- Rule: prior-period information may be used only after determining that it is still relevant. SA 315 requires evaluating its relevance.
- Facts: a change in accounting policy and a reorganisation are changes that may make last year's understanding outdated.
- Policies: the auditor must understand why the policy changed, whether the new method is appropriate and consistent with the framework, and how the change is disclosed.
- Entity: the new segment structure affects organisation, governance, performance measures and possibly segment reporting.
- Team discussion: SA 315 separately requires the engagement partner and key team members to discuss the susceptibility of the financial statements to material misstatement and the application of the framework in light of the entity's circumstances, here including the new inventory policy and segment structure.
- Conclusion: the senior's view is wrong on both points.
Answer: The senior is incorrect. Prior understanding must be updated for the policy change and the reorganisation, and the required team discussion must be held, covering susceptibility to misstatement and application of the framework. The auditor must also assess the appropriateness of the new inventory policy.
Exam tips
- Begin every answer with the three types of procedure. Many marks are for naming them.
- In case scenarios, link each fact to a risk and an assertion. Generic lists score poorly.
- Remember the framework and accounting policies. Examiners often test this less obvious part.
- If the case involves a continuing client, mention checking relevance of prior information and the team discussion.
- In MCQs, rule out options that say risk assessment procedures alone give sufficient evidence for the opinion.
Practice questions from Materiality, Risk Assessment and Internal Control
- At Sundaram Engineering Pvt Ltd, the auditor is evaluating controls over a large, unusual one-off sale of a division. The existing automated…
- Banyan Foods Pvt Ltd processes thousands of sales invoices daily through an ERP that applies predefined pricing and discount rules. The audi…
- CA Rao audited Delta Realty Ltd last year and communicated to the board a significant deficiency in controls over related party approvals. T…
- The auditor of Pinnacle Auto Ltd discovers that the finance head concealed an inventory writedown of a small value. The entity's controls di…
- While auditing Kaveri Textiles Ltd, CA Mehra finds that the company has no formal process for identifying business risks, although a company…
Understanding the Entity and Its Environment (SA 315) in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Understanding the Entity and Its Environment (SA 315): frequently asked questions
What are the risk assessment procedures under SA 315?
They include inquiries, analytical procedures, and observation and inspection. You perform them to understand the entity and its environment. They help you identify and assess risks of material misstatement.
Is inquiry alone enough to understand the entity?
No. SA 315 says inquiry alone does not provide an adequate basis for the risk assessment. Risk assessment procedures shall include inquiries, analytical procedures, and observation and inspection, and together they must give a sufficient basis to identify and assess RMM.
Do risk assessment procedures give audit evidence for the opinion?
No. They support the identification and assessment of risks. You still need further audit procedures, such as tests of controls or substantive procedures, to respond to those risks.
Can I use last year's understanding of a continuing client?
You may use prior-period information, but you must determine whether it is still relevant. Changes in the business, policies or environment may make it outdated.