Standards2025-12-10

ISA 315 — Risk Assessment

Revised ISA 315 and its impact on how we identify and assess risks of material misstatement.

ISA 315 requires the auditor to identify and assess the risks of material misstatement at the financial statement and assertion levels, through understanding the entity and its environment, its internal control, and the applicable financial reporting framework. Risk assessment is not a formality — it drives the entire audit response.

The standard identifies three risk categories: inherent risk (susceptibility to misstatement before controls), control risk (the risk that controls fail to prevent or detect misstatement), and detection risk (the risk that the auditor's procedures fail to detect misstatement). The auditor controls only detection risk; the product of inherent and control risk determines how much detection risk can be tolerated.

Significant risks — those requiring special audit consideration — deserve the most attention. These are risks that are likely to require bespoke audit responses, not standardised procedures. Common examples include management override of controls, revenue recognition, and complex estimates. The auditor must identify these early and design specific responses.

The risk assessment must be documented and updated throughout the engagement. If conditions change — a new system, a significant transaction, a control failure — the assessment must be revised and the audit response recalibrated. A static risk assessment is a failed risk assessment.