Skip to content

Auditing and Ethics · Risk Assessment and Internal Control

Risk Assessment Procedures and Understanding the Entity (SA 315)

Updated 4 October 2026 · Fact-checked

Under SA 315 (Revised 2019), the auditor performs risk assessment procedures - inquiries, analytical procedures, and observation and inspection - to understand the entity, its environment and its internal control. This helps identify and assess risks of material misstatement at the financial statement and assertion levels, which then drive further audit procedures.

Understand Risk Assessment Procedures and Understanding the Entity

An audit cannot test everything. So the auditor must decide where the financial statements are most likely to be wrong. SA 315 tells you how: first understand the entity, then identify and assess the risks of material misstatement (RMM).

The auditor gets this understanding through risk assessment procedures. There are three types: inquiries of management and others in the entity, analytical procedures, and observation and inspection. These procedures alone do not give sufficient audit evidence for the opinion. They give a basis for planning the next steps. The engagement team should also discuss the susceptibility of the financial statements to material misstatement.

The auditor must understand several areas. These are: the industry, regulatory and other external factors; the nature of the entity (operations, ownership, governance, structure, investments and financing); how the entity selects and applies accounting policies; its objectives, strategies and related business risks; and how its financial performance is measured and reviewed. The auditor must also understand the components of internal control relevant to financial reporting.

RMM has two parts: inherent risk and control risk. Inherent risk is the susceptibility of an assertion to a material misstatement before considering any controls. Control risk is the risk that the entity's controls fail to prevent or detect and correct that misstatement in time. Detection risk is the risk that the auditor's procedures fail to detect a material misstatement. It is the auditor's lever. The higher the assessed RMM, the lower the detection risk the auditor must accept, so more or better audit work is needed.

Risks are assessed at two levels. Financial statement level risks affect the statements as a whole, such as weak management integrity. Assertion level risks relate to specific classes of transactions, balances or disclosures. The auditor also identifies significant risks, which need special audit consideration, such as fraud risks, and risks from complex or unusual transactions. The assessment is not fixed. The auditor revises it if new evidence appears during the audit.

Key rules to remember

Audit risk model
Audit Risk = Risk of Material Misstatement × Detection Risk
This is a conceptual relationship, not a calculation tool. RMM is made up of inherent risk and control risk.
Components of RMM
RMM = Inherent Risk and Control Risk
SA 315 (Revised 2019) requires separate assessment of inherent risk and control risk at the assertion level.
Risk assessment procedures
Inquiries + Analytical procedures + Observation and inspection
Remember all three. Inquiry alone is not enough. These procedures do not by themselves give sufficient evidence for the opinion.
Relationship of risk to detection risk
Higher RMM → Lower acceptable detection risk → More extensive substantive work
Detection risk is inversely related to assessed RMM.

How to solve Risk Assessment Procedures and Understanding the Entity questions

Use this method for any question on SA 315, understanding the entity, or RMM.

  1. 1Identify what the question asks: the procedures, the areas to understand, the type of risk, or the assessment at a given level.
  2. 2State the SA 315 requirement in one line, for example that the auditor must perform risk assessment procedures to identify and assess RMM.
  3. 3List the relevant risk assessment procedures: inquiries, analytical procedures, observation and inspection.
  4. 4Apply the facts of the case. Pick the entity factors that matter, such as industry, regulation, ownership, accounting policies, business risks or internal control.
  5. 5Classify each risk: financial statement level or assertion level, and inherent risk or control risk. Flag any significant risk.
  6. 6State the effect on the audit: higher RMM means lower detection risk and more or stronger further procedures.
  7. 7Conclude clearly with the auditor's response, and mention that the assessment is revised if new information arises.

Quickest way: Three procedures, entity areas, then risk response

When to use it: Use this when you have limited time, especially for short written answers and MCQs.

  1. For MCQs, check the wording. If the option says 'inquiry alone' provides sufficient evidence, or that risk assessment procedures replace substantive work, eliminate it.
  2. Remember inherent and control risk belong to the entity. Detection risk belongs to the auditor. This eliminates many options.
  3. For written answers, write a short opening line, then bullet the three procedures, then the areas of understanding, then the risk response.
  4. Match the case facts to the risk: new complex product means inherent risk, weak approvals means control risk.
  5. End with one line linking assessed RMM to the nature, timing and extent of further procedures. This earns the final marks.

Common mistakes in Risk Assessment Procedures and Understanding the Entity

  • Saying inquiry is enough to understand the entity.

    Students remember inquiry as the main procedure and forget the other two.

    Fix: Always list all three: inquiries, analytical procedures, observation and inspection. Add that inquiry alone is not sufficient.

  • Treating detection risk as a risk of the entity.

    All three risk names look alike, so students group them together.

    Fix: Inherent and control risk exist independently of the audit. Detection risk depends on the auditor's procedures and can be changed by the auditor.

  • Believing risk assessment procedures give enough evidence for the opinion.

    Students confuse understanding the entity with testing balances.

    Fix: Say that these procedures give a basis for assessing risk. Further audit procedures (tests of controls and substantive procedures) give the evidence for the opinion.

  • Ignoring the two levels of risk.

    Students list risks without saying where they sit.

    Fix: Label each risk as financial statement level or assertion level. State the different responses, such as overall changes versus specific procedures.

  • Treating the risk assessment as final once made.

    Students see planning as a one-time step.

    Fix: State that the auditor revises the assessment and further procedures if evidence during the audit differs from the original expectation.

  • Listing entity factors without applying them to the case.

    Students recite the syllabus list from memory.

    Fix: Choose only the factors that fit the facts given and explain the risk each creates.

Worked examples

Example 1

List the risk assessment procedures an auditor performs under SA 315 to understand an entity and explain why they are performed.

Show the solution
  1. Start with the purpose: the auditor must identify and assess the risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels.
  2. Name the first procedure: inquiries of management, those charged with governance, internal audit staff and others who may hold useful information.
  3. Name the second: analytical procedures, which can show unusual transactions, events, amounts, ratios or trends that may indicate risk.
  4. Name the third: observation and inspection, such as watching entity operations and reading business plans, records and internal control manuals.
  5. Note that these procedures give a basis for risk assessment. They do not by themselves provide sufficient evidence for the audit opinion.

Answer: The three risk assessment procedures are inquiries, analytical procedures, and observation and inspection. They are performed to understand the entity and identify and assess RMM, which forms the basis for designing further audit procedures. They do not alone support the opinion.

Example 2

An auditor is auditing a company that has recently launched a complex derivative product, and its approval controls over such contracts are weak. Explain how the auditor should assess the risk and respond.

Show the solution
  1. Identify inherent risk: complex derivative contracts are open to misstatement in valuation and disclosure before considering any controls.
  2. Identify control risk: weak approval controls mean the entity may not prevent or detect and correct errors in these contracts on time.
  3. Combine them: the RMM at the assertion level, for valuation and presentation, is assessed as high. The auditor should consider whether it is a significant risk, as it involves a complex, unusual transaction.
  4. Consider the financial statement level: ask whether the weak control environment affects other areas too.
  5. Respond: since RMM is high, the auditor must accept a lower detection risk. This means more extensive substantive procedures, possibly the use of an expert for valuation, and assigning more experienced team members.
  6. Revise the assessment if later evidence differs.

Answer: Inherent risk is high due to complexity, and control risk is high due to weak approvals, so RMM is high and likely a significant risk. The auditor sets a lower detection risk, performs more extensive substantive procedures, considers an expert, and revises the assessment if new evidence arises.

Exam tips

  • Write the three procedures by name every time. Examiners look for the list.
  • In case-based questions, split the risk into inherent and control risk, then link it to the response. This structure earns step marks.
  • Be sure of who owns each risk: detection risk is the auditor's. MCQs often test this.
  • Mention both levels, financial statement and assertion, whenever the question asks about assessing RMM.
  • Use the exact SA 315 wording where you can: 'identify and assess the risks of material misstatement'.

Practice questions from Risk Assessment and Internal Control

Risk Assessment Procedures and Understanding the Entity in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Assessment Procedures and Understanding the Entity: frequently asked questions

What are the risk assessment procedures under SA 315?

They are inquiries, analytical procedures, and observation and inspection. The auditor uses them to understand the entity and its environment and to assess the risks of material misstatement.

What is the difference between inherent risk, control risk and detection risk?

Inherent risk is the susceptibility of an assertion to misstatement before considering controls. Control risk is the risk that controls fail to prevent or detect and correct the misstatement. Detection risk is the risk that the auditor's procedures fail to detect a material misstatement.

Do risk assessment procedures provide enough evidence for the audit opinion?

No. They give a basis for identifying and assessing risks. The auditor still needs further audit procedures, such as tests of controls and substantive procedures, to get sufficient appropriate evidence.

What is a significant risk?

A significant risk is an identified risk of material misstatement that needs special audit consideration. Examples include fraud risks and risks from complex or unusual transactions.