AA · Professional Level

Planning and Risk Assessment

ISA 300 (planning an audit), ISA 315 (Revised 2019) (identifying and assessing risks of material misstatement — understanding the entity and its environment, understanding the entity's information system and internal control components, inherent risk factors, significant risks), ISA 320 (materiality — overall materiality, performance materiality, specific materiality), ISA 330 (the auditor's responses to assessed risks — overall responses and further audit procedures responsive to risks at the assertion level), ISA 240 (the auditor's responsibilities relating to fraud — management override, fraudulent financial reporting, misappropriation of assets, fraud risk procedures), and ISA 250 (consideration of laws and regulations).

50 min read

Learning Objectives

  • Explain the purpose and content of the overall audit strategy and the audit plan under ISA 300
  • Describe the process of understanding the entity and its environment under ISA 315 (Revised 2019)
  • Explain the components of internal control and how the auditor obtains an understanding of the information system
  • Describe how inherent risk factors are used to assess the spectrum of inherent risk
  • Identify and explain significant risks and the auditor's required response
  • Calculate overall materiality and performance materiality, and explain specific materiality
  • Explain how the auditor designs overall responses and further audit procedures in response to assessed risks under ISA 330
  • Describe the auditor's responsibilities for fraud under ISA 240, including the presumption of fraud risk in revenue recognition
  • Explain the auditor's responsibilities regarding laws and regulations under ISA 250

ISA 300 — Planning an Audit of Financial Statements

Planning is not a one-off phase — it is an iterative process that continues throughout the audit as the auditor obtains new information.

Overall audit strategy: The high-level plan that sets the scope, timing, and direction of the audit. It guides the development of the more detailed audit plan. Includes: the characteristics of the engagement (reporting framework, industry, locations), reporting objectives and timing, significant factors (materiality, areas of higher risk, involvement of experts, group audit considerations), and the resources needed (team composition, timing of visits).

Audit plan: The detailed plan of the nature, timing, and extent of audit procedures to be performed. More detailed than the strategy — specifies the procedures for each area, the team members responsible, and the timetable.

Key planning activities:

  • Performing engagement acceptance/continuance procedures (ISQM 1, ISA 220)
  • Understanding the entity and its environment (ISA 315) — the foundation of risk assessment
  • Establishing materiality (ISA 320)
  • Identifying and assessing risks of material misstatement (ISA 315)
  • Determining the audit approach — combined approach (tests of controls + substantive procedures) or fully substantive
  • Considering the need for specialists, internal audit reliance, component auditors
  • Communicating with those charged with governance (TCWG) about the planned scope and timing

Matters to consider in planning: The results of prior year audits and whether issues need follow-up, analytical procedures performed at the planning stage (to identify unusual items and risk areas), changes in the entity's operations or environment, new accounting standards or regulatory requirements, and preliminary assessment of fraud risk.

ISA 315 (Revised 2019) — Identifying and Assessing Risks of Material Misstatement

ISA 315 is the cornerstone of the risk-based audit approach. It requires the auditor to obtain an understanding of the entity and its environment in order to identify and assess risks of material misstatement (RoMM) at both the financial statement level and the assertion level.

Understanding the Entity and Its Environment

The auditor must obtain an understanding of:

1. The entity and its environment:

  • Industry, regulatory, and other external factors: Industry conditions (competition, supply and demand, cyclicality), regulatory environment (accounting framework, tax, sector-specific regulations), general economic conditions (interest rates, inflation, currency)
  • Nature of the entity: Operations and revenue streams, ownership and governance structure, types of investments (subsidiaries, associates), organisational structure, financing arrangements
  • Accounting policies: Selection and application of significant accounting policies, including reasons for changes and whether they are appropriate
  • Objectives, strategies, and business risks: The entity's objectives (financial and operational), strategies to achieve them, and business risks that may result in material misstatement. Business risk is broader than RoMM — but business risks may create RoMM (e.g., obsolete technology → inventory impairment risk).
  • Measurement and review of financial performance: KPIs, budgets and variance analysis, management accounts, analyst reports, credit ratings

2. The entity's system of internal control: See below.

Procedures to obtain understanding: Inquiries of management and others, analytical procedures (comparing expectations with actual results), observation and inspection, discussion among the engagement team (including the engagement partner).

Understanding the Information System and Internal Control

ISA 315 (Revised 2019) requires the auditor to understand the entity's system of internal control relevant to the audit. The standard identifies five components (aligned with the COSO framework):

ComponentDescriptionKey areas for the auditor
1. Control environmentThe overall attitude, awareness, and actions of management and TCWG regarding internal control. Sets the "tone at the top."Commitment to competence, management's philosophy and operating style, organisational structure, assignment of authority and responsibility, HR policies
2. Entity's risk assessment processHow the entity identifies and responds to business risks relevant to financial reporting.How risks are identified (new products, changes in operations, new IT systems), how risks are assessed (likelihood, impact), how management responds to risks
3. Information system (including related business processes) relevant to financial reportingThe system for capturing, processing, and reporting financial transactions.Classes of transactions and how they are initiated, recorded, processed, and reported. The accounting records and financial reporting process. IT applications and infrastructure.
4. Control activities relevant to the auditThe policies and procedures that help ensure management directives are carried out.Authorisation, performance reviews, information processing controls (IT and manual), physical controls, segregation of duties. The auditor focuses on control activities relevant to significant risks and areas where substantive procedures alone are insufficient.
5. Monitoring of controlsHow the entity assesses whether its internal controls are operating effectively over time.Ongoing monitoring activities (management review, supervisory activities), separate evaluations (internal audit), how deficiencies are communicated and corrected

The information system: ISA 315 (Revised 2019) places particular emphasis on understanding the information system and related business processes. The auditor must understand: how transactions are initiated, how IT is used, the journal entry process (including non-standard entries), how information is transferred from the transaction processing system to the general ledger and financial statements, and the financial reporting process (consolidation, adjustments, disclosures).

Identifying and Assessing Risks of Material Misstatement

Risks are assessed at two levels:

  • Financial statement level: Pervasive risks that relate to the financial statements as a whole and potentially affect many assertions. Examples: weak control environment (poor tone at the top), going concern doubts, management integrity concerns, pervasive fraud risk, economic downturn affecting the entire business.
  • Assertion level: Risks related to specific classes of transactions, account balances, or disclosures. These are assessed for each relevant assertion (existence/occurrence, completeness, accuracy/valuation, cut-off, classification, rights and obligations, presentation and disclosure).

Inherent risk factors (ISA 315 Revised 2019):

The revised standard introduces the concept of inherent risk factors — the characteristics of events, transactions, or account balances that affect susceptibility to misstatement before considering controls. These factors determine where an assertion sits on the spectrum of inherent risk (from lower to higher):

  • Complexity: Complex transactions or calculations (e.g., financial instruments, pension obligations)
  • Subjectivity: Reliance on estimates, judgements, or assumptions (e.g., fair value measurements, impairment assessments, provisions)
  • Change: Changes in the entity or environment (new systems, restructuring, new accounting standards)
  • Uncertainty: Inherent uncertainty in outcomes (e.g., litigation provisions, going concern)
  • Susceptibility to misstatement due to management bias or fraud: Revenue recognition, related party transactions, management estimates

Significant risks:

A significant risk is a risk that requires special audit consideration — identified when the assessed inherent risk is close to the upper end of the spectrum. Characteristics: involves significant management judgement, involves unusual/non-routine transactions, susceptibility to fraud, complexity, or significant transactions with related parties.

Required responses to significant risks:

  • Obtain an understanding of controls specifically relevant to the significant risk
  • Perform substantive procedures specifically responsive to the risk — not just general procedures
  • If the auditor plans to rely on controls: test those controls in the current period (cannot rely on prior period testing for significant risks)
  • External confirmations, detailed analytical procedures, or other targeted procedures

ISA 240 presumption: Revenue recognition is presumed to involve a fraud risk (and therefore a significant risk) unless the auditor can rebut this presumption with evidence to the contrary.

ISA 320 — Materiality in Planning and Performing an Audit

Materiality is the threshold above which misstatements (individually or in aggregate) could reasonably be expected to influence the economic decisions of users of the financial statements.

Three levels of materiality:

1. Overall materiality (for the financial statements as a whole):

Set at the planning stage based on a benchmark — typically a percentage of a key financial figure:

BenchmarkTypical percentage rangeWhen used
Profit before tax (PBT)5% to 10%Profit-oriented entities with stable profits
Revenue0.5% to 1%Entities with volatile or low profits, or where revenue is the key driver
Total assets1% to 2%Asset-intensive entities (e.g., investment companies, property companies)
Gross profit1% to 2%Entities in retail/distribution where gross margin is key
Total expenditure0.5% to 2%Not-for-profit entities

The choice of benchmark and percentage involves professional judgement considering the nature of the entity, its industry, the users of the financial statements, and the entity's life cycle stage.

2. Performance materiality:

Set at an amount less than overall materiality to reduce to an appropriately low level the probability that the aggregate of uncorrected and undetected misstatements exceeds overall materiality.

Typically set at 50% to 75% of overall materiality (higher end if few expected misstatements, lower end if many expected or if prior year had significant adjustments). Performance materiality determines the scope of individual audit procedures — it is the amount used to determine sample sizes and the extent of testing.

3. Specific materiality (for particular classes of transactions, balances, or disclosures):

A lower materiality threshold set for items where misstatements of lesser amounts could reasonably be expected to influence users' decisions. Examples: related party transactions, directors' remuneration, compliance with debt covenants, regulatory disclosures. Specific materiality is set by considering the nature of the items and the expectations of users.

Revision of materiality: If during the audit the auditor becomes aware of information that would have led to a different materiality at the planning stage, materiality should be revised. This may require revising the audit plan and extending procedures.

ISA 330 — The Auditor's Responses to Assessed Risks

ISA 330 requires the auditor to design and implement responses to the assessed risks of material misstatement at both the financial statement level and the assertion level.

1. Overall responses (financial statement level risks):

Address pervasive risks that affect the financial statements as a whole:

  • Assign more experienced staff or those with specialist skills to high-risk areas
  • Provide more supervision and review of work
  • Incorporate additional unpredictability into the selection of audit procedures (to counteract management's ability to predict the auditor's approach)
  • Make changes to the nature, timing, or extent of procedures (e.g., performing more procedures at the period end rather than at interim)
  • Emphasise professional scepticism in the engagement team discussions

2. Further audit procedures (assertion-level risks):

The auditor designs procedures that are clearly linked to the specific risks identified. The nature, timing, and extent of procedures should be responsive to the assessed risk:

AspectHigher assessed risk →Lower assessed risk →
NatureMore reliable procedures (external confirmations rather than inquiry, physical inspection rather than documentation review), more substantive procedures rather than reliance on controlsLess resource-intensive procedures, greater reliance on analytical procedures and inquiry
TimingPerform procedures at or near the period end (less opportunity for management to manipulate after testing)Procedures can be performed at interim with a rollforward to the year end
ExtentLarger sample sizes, more locations visited, more items testedSmaller sample sizes, fewer locations

Combined approach vs fully substantive approach:

  • Combined approach: Test controls (tests of controls) AND perform substantive procedures. Used when the auditor plans to rely on the operating effectiveness of controls to reduce the extent of substantive procedures.
  • Fully substantive approach: No reliance on controls — substantive procedures only. Used when: controls are not reliable, controls are not relevant to the assertion, or it is more efficient to go straight to substantive testing.

Regardless of the approach, ISA 330 requires substantive procedures for all material classes of transactions, account balances, and disclosures — the auditor cannot rely solely on controls without any substantive testing.

ISA 240 — The Auditor's Responsibilities Relating to Fraud

ISA 240 addresses the auditor's responsibility to consider fraud in an audit of financial statements. Fraud involves intentional acts — it is different from error (unintentional).

Two types of fraud relevant to the auditor:

  • Fraudulent financial reporting: Intentional misstatement or omission in the financial statements to deceive users. Examples: fictitious revenues, inappropriate capitalisation, failure to recognise liabilities, manipulating estimates, concealing transactions.
  • Misappropriation of assets: Theft of the entity's assets. Examples: embezzlement, theft of inventory, paying for goods not received, using company assets for personal use.

Management override of controls:

ISA 240 recognises that management has a unique ability to override controls — they can direct staff to bypass controls, override system settings, or make journal entries outside the normal process. Because of this, ISA 240 requires the auditor to perform specific procedures regardless of the assessed risk of fraud:

  • Test the appropriateness of journal entries and other adjustments made in the preparation of the financial statements (particularly unusual entries, entries made at the period end or after the reporting date, and entries to accounts that contain significant estimates)
  • Review accounting estimates for bias — evaluate whether the assumptions and methods used reflect management bias. Perform a retrospective review of prior year estimates.
  • Evaluate the business rationale of significant transactions that are outside the normal course of business, or that otherwise appear unusual

The fraud triangle: Three conditions are usually present when fraud occurs:

  1. Incentive/pressure: Reason to commit fraud (e.g., performance targets, bonus schemes, personal financial pressure, debt covenants)
  2. Opportunity: Ability to commit fraud (e.g., weak controls, management override, lack of segregation of duties)
  3. Rationalisation/attitude: The mindset that justifies the fraud (e.g., "I'll pay it back," "I'm underpaid," "everyone does it")

Revenue recognition as a fraud risk: ISA 240 includes a rebuttable presumption that there are risks of fraud in revenue recognition. The auditor should evaluate which types of revenue transactions give rise to fraud risk (timing of recognition, fictitious revenue, cut-off, bill-and-hold, side agreements). The presumption can be rebutted if the auditor concludes there is no fraud risk in revenue — but this is unusual and the reasons must be documented.

ISA 250 — Consideration of Laws and Regulations

ISA 250 distinguishes between two categories of laws and regulations:

Category (a): Laws with a direct effect on the financial statements.

These determine amounts and disclosures in the financial statements — e.g., tax legislation (determines the tax charge and deferred tax), companies legislation (determines disclosure requirements), pension legislation (affects employee benefit obligations).

Auditor's responsibility: Obtain sufficient appropriate audit evidence that the entity has complied. These are treated as part of the normal audit of the relevant balances and disclosures.

Category (b): Laws that do not have a direct effect on the financial statements but may be fundamental to the entity's operations.

Non-compliance may result in fines, litigation, or the entity ceasing operations — which could affect the financial statements indirectly. Examples: environmental regulations, health and safety, data protection, anti-bribery, industry-specific regulations (banking, insurance).

Auditor's responsibility: Perform limited procedures — inquire of management and TCWG about compliance, inspect correspondence with regulators, remain alert during the audit for indications of non-compliance. The auditor does NOT actively search for non-compliance with category (b) laws.

If non-compliance is identified or suspected:

  • Obtain an understanding of the nature of the act and the circumstances
  • Evaluate the possible effect on the financial statements (provisions, contingent liabilities, going concern implications)
  • Discuss with management and TCWG
  • Consider the impact on the audit opinion (material misstatement, limitation of scope)
  • Consider reporting obligations — the auditor may have a legal duty to report to regulators (e.g., reporting suspicion of money laundering to the NCA under POCA 2002, or reporting to the FCA for regulated entities)
  • Consider the need to withdraw from the engagement if management integrity is fundamentally compromised

Examiner Focus

ISA 315 (Revised 2019) is the most important ISA for the AA exam. You must understand: the five components of internal control, inherent risk factors (complexity, subjectivity, change, uncertainty, bias/fraud), the spectrum of inherent risk, and significant risks. Expect scenario-based questions asking you to identify risks and explain why they are significant.

Common Pitfall

Materiality: students often just calculate a number without EXPLAINING their choice of benchmark. The examiner expects you to: (1) identify the benchmark (PBT, revenue, total assets), (2) explain WHY it is appropriate for this entity, (3) select a percentage and justify it, (4) cross-check against other benchmarks. A bare calculation without justification scores poorly.

Study Tip

ISA 330 responses: for HIGHER risk, use procedures that are more reliable in NATURE (external confirmations > inquiry), performed CLOSER to the period end in TIMING, and with LARGER sample sizes in EXTENT. For significant risks: test controls in the current period, perform substantive procedures specifically responsive to the risk.

Examiner Focus

ISA 240 fraud: know the THREE mandatory procedures for management override (test journal entries, review estimates for bias, evaluate unusual transactions). Know the revenue recognition fraud risk presumption — and that it can be rebutted but rarely is. Know the fraud triangle (incentive, opportunity, rationalisation).

Watch Out

ISA 330: regardless of the audit approach, substantive procedures are ALWAYS required for material balances. The auditor can NEVER rely solely on controls without any substantive testing. Even with a combined approach, substantive procedures are performed — they are just reduced in extent.

Study Tip

ISA 250: two categories of laws. Category (a) — direct effect on FS (tax, companies law) → obtain SUFFICIENT APPROPRIATE evidence. Category (b) — fundamental to operations but indirect effect (environmental, H&S) → LIMITED procedures (inquiry, inspect regulatory correspondence, stay alert). Don't confuse the level of responsibility.

Written Practice

Planning and Risk Assessment: Applied Requirement

Prepare a focused written answer with clear workings and justified recommendations.

22 mins · 12 marks

A client has asked for a concise exam-style written response for a client or senior manager on planning and risk assessment. Use the key rules, calculations, risks, and professional judgement from this topic to structure your answer.

Answer Prompts

  • Identify the issue and explain why it matters in the scenario.
  • Apply the relevant technical rule, calculation, or framework.
  • State the commercial, ethical, tax, reporting, or assurance implication.
  • Conclude with a clear recommendation or exam-ready judgement.

Marking Focus

  • Application to facts rather than textbook recall
  • Clear structure and answer-first communication
  • Balanced judgement where there is uncertainty
  • Commercially sensible conclusion

Key Definitions

Overall audit strategy

The high-level plan setting the scope, timing, and direction of the audit. Guides the detailed audit plan. Includes: engagement characteristics, reporting objectives, significant factors, and required resources.

Audit plan

The detailed plan of the nature, timing, and extent of audit procedures. More specific than the strategy — specifies procedures for each area, team members, and timetable.

Risk of material misstatement (RoMM)

The risk that the financial statements are materially misstated before the audit. Comprises inherent risk (susceptibility to misstatement before controls) and control risk (failure of controls to prevent/detect). Assessed at financial statement and assertion level.

Inherent risk factors

Characteristics affecting susceptibility to misstatement: complexity, subjectivity, change, uncertainty, and susceptibility to management bias/fraud. Determine where assertions sit on the spectrum of inherent risk.

Significant risk

A risk near the upper end of the inherent risk spectrum requiring special audit consideration. Involves significant judgement, non-routine transactions, fraud susceptibility, or complexity. Requires specific responses and current-period control testing.

Overall materiality

The threshold above which misstatements could influence users' decisions. Set using a benchmark (PBT 5-10%, revenue 0.5-1%, total assets 1-2%). Involves professional judgement.

Performance materiality

Set below overall materiality (typically 50-75%) to reduce the risk that aggregate uncorrected/undetected misstatements exceed overall materiality. Determines the scope of individual audit procedures and sample sizes.

Specific materiality

A lower materiality for particular items where misstatements of lesser amounts could influence users (e.g., related party transactions, directors' remuneration, covenant compliance).

Combined approach

An audit approach that relies on both tests of controls and substantive procedures. Used when the auditor plans to rely on the operating effectiveness of internal controls.

Fully substantive approach

An audit approach that does not rely on controls — only substantive procedures. Used when controls are unreliable, not relevant, or it is more efficient.

Management override of controls

The unique ability of management to bypass internal controls. ISA 240 requires specific procedures regardless of assessed risk: test journal entries, review estimates for bias, evaluate unusual transactions.

Fraud triangle

Three conditions usually present when fraud occurs: incentive/pressure (reason to commit fraud), opportunity (ability to commit it), rationalisation/attitude (mindset that justifies it).

Revenue recognition fraud risk presumption

ISA 240 presumes fraud risk in revenue recognition unless the auditor can rebut with evidence. The auditor must evaluate which types of revenue give rise to fraud risk and design specific procedures.

Key Formulas

Worked Examples

Key Takeaways

  • ISA 300: Planning is iterative. Overall audit strategy (scope, timing, direction) guides the detailed audit plan (nature, timing, extent of procedures). Planning activities include: acceptance, understanding the entity, materiality, risk assessment, audit approach.
  • ISA 315 (Revised 2019): Understand the entity and environment (industry, nature, policies, strategies, performance). Understand the five components of internal control (control environment, risk assessment, information system, control activities, monitoring).
  • Inherent risk factors: complexity, subjectivity, change, uncertainty, susceptibility to management bias/fraud. These determine where assertions sit on the spectrum of inherent risk. Higher inherent risk → more audit attention.
  • Significant risks: near the upper end of the inherent risk spectrum. Require: understanding specific controls, substantive procedures responsive to the risk, current-period control testing if relying on controls. Revenue recognition is presumed a fraud/significant risk (ISA 240).
  • ISA 320 Materiality: Overall (PBT 5-10%, revenue 0.5-1%, assets 1-2%). Performance materiality: 50-75% of overall (determines scope of testing). Specific materiality: lower threshold for sensitive items (directors' remuneration, related parties, covenants).
  • ISA 330: Higher risk → more reliable procedures (nature), closer to period end (timing), larger samples (extent). Combined approach: controls + substantive. Fully substantive: no reliance on controls. Substantive procedures always required for material items.
  • ISA 240 Fraud: two types (fraudulent reporting, misappropriation). Three mandatory management override procedures: test journal entries, review estimates for bias, evaluate unusual transactions. Fraud triangle: incentive, opportunity, rationalisation.
  • ISA 250: Category (a) laws (direct FS effect — tax, companies law) → full evidence. Category (b) laws (fundamental to operations — environmental, H&S) → limited procedures (inquiry, inspect, stay alert). If non-compliance found: evaluate FS impact, discuss with TCWG, consider reporting obligations.

Practice Questions

Question 1 of 8

Under ISA 315 (Revised 2019), the five components of internal control are:

Question 2 of 8

Performance materiality is typically set at:

Question 3 of 8

ISA 240 includes a rebuttable presumption that there are risks of fraud in:

Question 4 of 8

A "significant risk" under ISA 315 is one that:

Question 5 of 8

Which of the following is NOT one of the inherent risk factors under ISA 315 (Revised 2019)?

Question 6 of 8

Under ISA 330, when the assessed risk is HIGHER, the auditor should:

Question 7 of 8

The three elements of the fraud triangle are:

Question 8 of 8

Under ISA 250, the auditor's responsibility for laws that do NOT directly affect the financial statements (Category b) is to:

Source and Version

Syllabus: ICAEW ACA Professional Level 2026 · Reviewed: 2026-05-04

ICAEW ACA syllabusLocal syllabus coverage review