Skip to content

Auditing and Ethics · Risk Assessment and Internal Control

Audit Risk and Materiality (SA 320) for CA Intermediate

Updated 4 October 2026 · Fact-checked

Audit risk is the risk that the auditor gives an inappropriate opinion on materially misstated financial statements. It has two parts: risks of material misstatement (inherent and control risk) and detection risk. Materiality is the size of misstatement that could influence users' decisions. Set it at planning, set a lower performance materiality, and revise it if facts change.

Understand Audit Risk and Materiality

Audit risk is the risk that you express an inappropriate opinion when the financial statements are materially misstated. You can never reduce it to zero, because you test samples and rely on judgment. So the aim is to keep it at an acceptably low level.

Audit risk has two main components. Risk of material misstatement (RMM) exists in the entity before your audit. It has two parts: inherent risk, the susceptibility of an assertion to a material misstatement before considering controls, and control risk, the risk that the entity's internal control will not prevent or detect and correct a misstatement on time. Detection risk is the risk that your own procedures fail to detect a material misstatement. You control only detection risk. If RMM is high, you must set detection risk low, which means more extensive or stronger procedures.

Materiality is about size and nature. A misstatement, including an omission, is material if it could reasonably be expected to influence the economic decisions of users taken on the basis of the financial statements. Under SA 320, you decide materiality using professional judgment, and you think about the common information needs of users as a group, not of one particular user.

You set materiality for the financial statements as a whole at planning, often by applying a percentage to a benchmark such as profit before tax, revenue, total assets or net assets. The choice of benchmark depends on the entity. For a loss-making or not-for-profit entity, revenue or expenses may suit better. If particular items could influence users at a lower amount, such as related party transactions or directors' remuneration, you set a lower materiality for those classes.

Performance materiality is an amount set below overall materiality. Its purpose is to bring down to an appropriately low level the chance that uncorrected and undetected misstatements added together exceed overall materiality. You revise materiality if you learn new information during the audit, such as actual results that differ a lot from the figures you used at planning.

Materiality and audit risk are different ideas. Materiality is a threshold of size that decides what matters. Audit risk is the chance that you miss a misstatement above that threshold. A lower materiality level requires more extensive audit procedures, because you must detect smaller misstatements. Materiality is used to decide the nature, timing and extent of risk assessment and further audit procedures.

Key rules to remember

Audit risk model
Audit risk = Risk of material misstatement × Detection risk
RMM = Inherent risk × Control risk. It is a conceptual relationship, not a precise calculation in the exam.
Risk of material misstatement
RMM = Inherent risk × Control risk
Both exist independently of the audit. The auditor assesses them but cannot change them.
Detection risk relationship
Higher RMM ⇒ lower acceptable detection risk
Lower detection risk means more or better substantive procedures.
Benchmark-based materiality
Materiality = Benchmark × Chosen percentage
Percentage is a matter of judgment. SA 320 does not fix a percentage.
Performance materiality
Performance materiality < Materiality for the financial statements as a whole
Set to cover aggregation of uncorrected and undetected misstatements.
Revision of materiality
Revise if new information arises during the audit
If the revised level is lower, reconsider performance materiality and the nature, timing and extent of further procedures.

How to solve Audit Risk and Materiality questions

Use this order for any question on audit risk or materiality, whether it is theory, a case study or a calculation.

  1. 1Identify what is asked: risk components, materiality determination, performance materiality or revision.
  2. 2Define the term in one line, using the standard's wording.
  3. 3For risk questions, split into inherent, control and detection risk and state who controls each.
  4. 4For materiality, name the benchmark, the percentage and why the benchmark suits the entity.
  5. 5Compute the amount carefully and state performance materiality as a lower figure with a reason.
  6. 6Apply the facts: link any high-risk area, low-materiality item or new information to your conclusion.
  7. 7Conclude with the effect on audit work: nature, timing and extent of procedures, or revision of materiality.

Quickest way: Define, split, compute, conclude

When to use it: Use this in the exam when you have 3 to 4 minutes on a 4 to 5 mark written question, and for MCQs on risk components.

  1. MCQs: ask 'which risk does the auditor control?' Only detection risk. Inherent and control risk belong to the entity.
  2. MCQs: performance materiality is always lower than overall materiality. Eliminate options saying it is equal or higher.
  3. MCQs: materiality is a matter of professional judgment. Reject options saying SA 320 prescribes a fixed percentage.
  4. Written: start with a one-line definition, then a bullet for each component or step.
  5. Written: show the calculation as benchmark × percentage = amount, on its own line, so step marks are visible.
  6. Written: end with a one-line conclusion on the effect on audit procedures.

Common mistakes in Audit Risk and Materiality

  • Saying the auditor can reduce inherent or control risk.

    Students think the auditor manages all risks.

    Fix: Remember that inherent and control risk exist in the entity. The auditor only assesses them and responds through detection risk.

  • Treating audit risk and materiality as the same thing.

    Both are used when planning, so they blur together.

    Fix: Materiality is the size threshold. Audit risk is the chance of giving a wrong opinion. Say this in one line when asked for the difference.

  • Setting performance materiality equal to or above overall materiality.

    Students forget its purpose is to cover aggregation of small misstatements.

    Fix: Always state performance materiality as a lower figure and give the reason.

  • Stating that SA 320 gives a fixed percentage of profit as materiality.

    Textbook examples use 5% of profit and it gets remembered as a rule.

    Fix: Write that the percentage is a matter of professional judgment and depends on the entity and benchmark.

  • Looking only at the amount and ignoring the nature of the item.

    Materiality feels like a purely numerical idea.

    Fix: Add that small amounts can be material by nature, for example related party dealings or fraud-related items.

  • Not revising materiality when facts change.

    Students think it is fixed at planning.

    Fix: State that new information or changed circumstances require revision, and that a lower revised figure affects further procedures.

Worked examples

Example 1

An entity has profit before tax of ₹80,00,000. The auditor uses 5% of profit before tax as materiality for the financial statements as a whole and sets performance materiality at 75% of that figure. Compute both amounts and explain why performance materiality is lower.

Show the solution
  1. Benchmark is profit before tax = ₹80,00,000.
  2. Materiality = ₹80,00,000 × 5% = ₹4,00,000.
  3. Performance materiality = ₹4,00,000 × 75% = ₹3,00,000.
  4. Reason: several small misstatements, each below materiality, may together exceed it. A lower threshold for testing reduces the chance that uncorrected and undetected misstatements added together exceed overall materiality.

Answer: Materiality is ₹4,00,000 and performance materiality is ₹3,00,000. The lower figure keeps aggregate undetected misstatements within overall materiality. The 5% and 75% are judgments, not fixed by SA 320.

Example 2

During the audit of a company, the auditor assesses inherent risk and control risk for the trade receivables assertions as both high. Explain how this affects detection risk and the audit work.

Show the solution
  1. Risk of material misstatement = inherent risk × control risk. Both are high, so RMM is high.
  2. Audit risk = RMM × detection risk. To keep audit risk at an acceptably low level, detection risk must be set low.
  3. Detection risk is controlled by the nature, timing and extent of substantive procedures.
  4. So the auditor performs more extensive procedures, such as direct confirmations from debtors, with a larger sample, and may perform more substantive procedures at or near the period end instead of at an interim date.
  5. The auditor does not rely on tests of controls, since control risk is assessed as high.

Answer: High RMM requires a low detection risk. The auditor responds with more persuasive substantive procedures and larger samples, may do more of the testing at or near the period end, and does not rely on controls.

Exam tips

  • Learn the one-line difference between materiality and audit risk. It is a favourite short-answer question.
  • For any case study, state the benchmark, percentage and amount on separate lines. Step marks are given for the working.
  • In MCQs, watch for 'the auditor can reduce inherent risk'. It is incorrect.
  • Always add a sentence on revision of materiality when the question mentions new information or changed results.
  • Mention both quantitative and qualitative aspects when asked about the concept of materiality.

Practice questions from Risk Assessment and Internal Control

Audit Risk and Materiality in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Audit Risk and Materiality: frequently asked questions

What is performance materiality with an example?

Performance materiality is an amount set below materiality for the financial statements as a whole. It reduces the chance that undetected and uncorrected misstatements together exceed overall materiality. If materiality is ₹4,00,000, the auditor may set performance materiality at ₹3,00,000.

What are the components of audit risk?

Audit risk consists of the risk of material misstatement and detection risk. The risk of material misstatement has two parts: inherent risk and control risk. The auditor controls only detection risk.

What is the difference between materiality and audit risk?

Materiality is the size or nature of a misstatement that could influence users' decisions. Audit risk is the risk that the auditor gives an inappropriate opinion on materially misstated financial statements. Materiality sets the threshold, and audit risk is the chance of missing a misstatement above it.

Does SA 320 give a fixed percentage for materiality?

No. SA 320 leaves the choice of benchmark and percentage to professional judgment. The auditor considers the nature of the entity and the needs of users.

When must the auditor revise materiality?

The auditor revises materiality if new information arises during the audit or circumstances change, such as actual results being very different from those used at planning. A lower revised figure means reconsidering performance materiality and further audit procedures.