Skip to content

Integrated Business Solutions (Multidisciplinary Case Study with Strategic Management) · Advanced Auditing, Assurance and Professional Ethics

Audit Planning, Risk Assessment and Materiality for CA Final

Updated 5 October 2026 · Fact-checked

Audit planning sets the audit strategy and plan. Risk assessment (SA 315) identifies and assesses risks of material misstatement from your understanding of the entity. Materiality (SA 320) sets the size of misstatement that would influence users. To solve a case: identify the risk, classify it, set materiality, then respond with procedures.

Understand Audit Planning, Risk Assessment and Materiality

An audit cannot test every transaction. So the auditor decides where to look and how deeply. Three ideas drive that decision: planning, risk and materiality.

Planning (SA 300) means the auditor develops an overall audit strategy (scope, timing, direction of the audit) and a more detailed audit plan (nature, timing and extent of procedures). The engagement partner and key team members take part, and planning continues throughout the audit. It is not a one-time step at the start.

Risk assessment (SA 315, Revised) starts with understanding the entity: its industry and regulatory environment, nature of business, objectives and strategies, accounting policies, financial performance measures, and its internal control. From this the auditor identifies risks of material misstatement (RMM) at two levels: the financial statement level and the assertion level. RMM has two components: inherent risk (susceptibility of an assertion to misstatement, before considering controls) and control risk (the risk that the entity's controls will not prevent or detect a misstatement on time). Detection risk is the risk that the auditor's procedures will miss a misstatement. The auditor controls detection risk. The higher the assessed RMM, the lower the detection risk must be, so more extensive substantive work is needed.

Materiality (SA 320) is judged by whether misstatements, individually or in aggregate, could reasonably be expected to influence the economic decisions of users. The auditor sets overall materiality for the financial statements, usually by applying a percentage to a suitable benchmark (such as profit before tax, revenue or total assets), and performance materiality below it to reduce the chance that uncorrected and undetected misstatements add up to more than overall materiality. Where needed, lower materiality applies to specific classes of transactions, balances or disclosures. Materiality is revised if new information arises during the audit.

Responses (SA 330) link it all together: overall responses to financial-statement-level risks, and further audit procedures (tests of controls and substantive procedures) matched to assessed assertion-level risks. A significant risk needs special audit consideration and substantive procedures specifically responsive to it. Documentation (SA 230) must record the strategy, plan, risk assessment, materiality figures and the reasons for significant judgements.

Key rules to remember

Audit Risk Model
Audit Risk = Risk of Material Misstatement × Detection Risk
RMM = Inherent Risk × Control Risk (combined or separate assessment). Used for reasoning, not a precise calculation.
Detection risk relationship
Higher assessed RMM → Lower acceptable Detection Risk → More substantive work
Detection risk moves in the opposite direction to RMM.
Overall materiality
Overall materiality = Benchmark × Chosen percentage
SA 320 gives no fixed percentage. The percentage is professional judgement. State the benchmark and reason for choosing it.
Performance materiality
Performance materiality < Overall materiality
Set by judgement, often a proportion of overall materiality. Higher assessed risk means a lower proportion.
Clearly trivial threshold
Misstatements below the threshold need not be accumulated
Clearly trivial is not the same as immaterial. It is set well below materiality.
Significant risk
Significant risk → substantive procedures responsive to it; tests of controls if relying on controls
Significant risks require the auditor to understand and evaluate the related controls.

How to solve Audit Planning, Risk Assessment and Materiality questions

Use this order for any case scenario on planning, risk or materiality. It also gives you a ready answer structure of provision, facts and conclusion.

  1. 1Read the facts and note entity features: industry, size, ownership, systems, recent changes, management attitude and unusual transactions.
  2. 2Name the relevant Standard (SA 300, 315, 320 or 330) and state the rule in one line.
  3. 3Identify each risk and classify it: financial-statement level or assertion level; inherent or control; significant risk or not. Link each to a fact from the case.
  4. 4If materiality is asked, pick a suitable benchmark, apply a reasoned percentage, then set performance materiality lower. Check for any qualitative factors that call for lower thresholds.
  5. 5State the response: change in audit strategy, team composition, nature, timing and extent of procedures, and tests of controls versus substantive tests.
  6. 6Mention documentation and communication, such as the strategy memo, risk assessment, and discussion with those charged with governance where relevant.
  7. 7Close with a one-line conclusion that answers the exact question asked.

Quickest way: Fact-Risk-Response in three lines

When to use it: Use for case-scenario MCQs and short written parts where time is tight.

  1. Underline the facts that signal risk: new system, fraud hint, related parties, estimates, rapid growth, weak controls.
  2. Tag each fact as inherent or control risk, and mark any that looks like a significant risk.
  3. Pick the answer that raises the assessed risk and lowers detection risk, with more substantive work. For materiality MCQs, look for the option that uses a stated benchmark and keeps performance materiality below overall materiality.

Common mistakes in Audit Planning, Risk Assessment and Materiality

  • Treating detection risk as something the entity controls or assesses from its business.

    The three risk terms look alike, so students mix who controls what.

    Fix: Inherent and control risks exist in the entity. Detection risk belongs to the auditor and is set in response to RMM.

  • Saying materiality is a fixed percentage of profit or revenue.

    Students remember rule-of-thumb percentages from practice.

    Fix: State that SA 320 requires judgement. Name the benchmark, give a reasoned percentage and say it is revisited if circumstances change.

  • Setting performance materiality equal to or above overall materiality.

    Students forget its purpose is to cover aggregation of undetected misstatements.

    Fix: Always set performance materiality lower and explain it reduces the chance that total misstatements exceed overall materiality.

  • Ignoring qualitative factors in materiality.

    Case solutions are often numerical, so students stop at the calculation.

    Fix: Add that a small misstatement can be material if it hides a trend, changes a loss into profit, affects covenants or involves related parties or management fraud.

  • Writing that the audit plan is prepared once and never changed.

    Students picture planning as a start-of-audit step only.

    Fix: Write that planning is continuous and the strategy and plan are updated as new information emerges.

  • Listing risks without tying them to the case facts.

    Students write textbook lists to save time.

    Fix: For each risk, quote the fact from the case that creates it, then give the specific response.

Worked examples

Example 1

Case: Zenith Ltd, a manufacturing company, has implemented a new ERP system in the current year. Inventory is held in five locations, and management bonuses depend on profit. Last year's audit found frequent errors in inventory costing. Identify the key risks and state how the auditor should respond.

Show the solution
  1. Standard: SA 315 requires the auditor to identify and assess RMM at financial statement and assertion levels using an understanding of the entity and its controls.
  2. Financial-statement-level risk: the new ERP system affects many balances, and bonuses linked to profit create an incentive to overstate profit. Respond by assigning experienced staff, including IT specialists, and keeping an attitude of professional scepticism.
  3. Assertion-level risk: inventory existence and valuation have high inherent risk because of five locations and past costing errors. Control risk is also high since the ERP is new and its controls are untested.
  4. Because the profit-linked bonus creates a fraud incentive, the auditor should consider whether inventory valuation is a significant risk and respond with specific substantive procedures.
  5. Response: attend physical counts at key locations, test cost build-up and net realisable value, and test ERP general and application controls before relying on them. Since RMM is high, detection risk must be low, so more extensive year-end substantive testing is required.
  6. Documentation: record the risks, reasons for the assessment and the planned responses in the audit file.

Answer: The main risks are high inherent and control risk over inventory existence and valuation, and a fraud risk from profit-linked bonuses. The auditor should treat inventory as a significant risk, use IT specialists, test ERP controls, attend counts at key locations, perform extended substantive tests and document the assessment.

Example 2

Case: For Orion Ltd, profit before tax is ₹8,00,00,000 and revenue is ₹120,00,00,000. The auditor decides to use profit before tax as the benchmark and applies 5%. Performance materiality is set at 75% of overall materiality. Calculate both figures and explain why the auditor may reduce performance materiality.

Show the solution
  1. Overall materiality = ₹8,00,00,000 × 5% = ₹40,00,000.
  2. Performance materiality = ₹40,00,000 × 75% = ₹30,00,000.
  3. Purpose: performance materiality is lower so that the total of uncorrected and undetected misstatements is unlikely to exceed overall materiality.
  4. Reason to reduce further: a high assessed risk, many misstatements found in prior audits, weak controls or expected large adjustments in the current audit.
  5. Benchmark check: profit before tax suits a profit-oriented entity if earnings are stable. If profit were volatile or near zero, revenue or total assets might be a better benchmark.
  6. Documentation: record the benchmark, percentage, reasons and the resulting figures. Revise them if actual results differ significantly from the figures used at planning.

Answer: Overall materiality is ₹40,00,000 and performance materiality is ₹30,00,000. Performance materiality may be reduced further when risks are higher, past misstatements were frequent or controls are weak.

Exam tips

  • In case-scenario MCQs, look for the one fact that changes the risk, such as a new system, management override or an unusual deal. It usually decides the answer.
  • Write in provision-facts-conclusion form: the Standard, the case fact, then the response. Do not quote paragraph numbers unless you are certain of them.
  • In Paper 6 integrated cases, link audit risk to other areas, for example an Ind AS estimate that raises inherent risk or a tax dispute that affects disclosure.
  • For materiality numbers, always show the benchmark, percentage and performance materiality in separate lines so marks can be awarded for each step.
  • The auditor assesses inherent and control risks but cannot change the risks themselves. Only detection risk is adjusted by the auditor, in response to the assessed RMM.

Practice questions from Advanced Auditing, Assurance and Professional Ethics

Audit Planning, Risk Assessment and Materiality in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Audit Planning, Risk Assessment and Materiality: frequently asked questions

What is the difference between inherent risk and control risk?

Inherent risk is the susceptibility of an assertion to material misstatement before considering any controls. Control risk is the risk that the entity's internal controls will fail to prevent or detect and correct a misstatement on time. Together they form the risk of material misstatement.

Does SA 320 prescribe a percentage for materiality?

No. SA 320 requires professional judgement and does not fix percentages. The auditor chooses a suitable benchmark and a reasoned percentage, and documents the basis.

What is a significant risk?

It is an identified and assessed risk of material misstatement that needs special audit consideration. Common examples are fraud risks, complex estimates and unusual related party transactions. The auditor must perform substantive procedures that respond specifically to it.

Can materiality change during the audit?

Yes. If new information arises or actual financial results differ from those used at planning, the auditor revises overall and performance materiality. The auditor then reconsiders the nature, timing and extent of further procedures.