SA 315 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
SA 315 is where the audit becomes risk-based. The auditor learns the business, its industry and its controls well enough to see where the financial statements could go wrong. This first part covers what the auditor must understand; the second covers how that understanding is turned into assessed risks.
SA 315, as effective for audits of financial statements for periods beginning on or after 1 April 2008, applies to every audit. ICAI may revise standards, so check icai.org for the current text. Part 2 covers assessment and documentation.
The auditor must perform risk assessment procedures: inquiries, analytical procedures, and observation and inspection. The team must discuss how the statements may be misstated. The auditor must understand the entity and its environment, and the internal control relevant to the audit through five components: control environment, entity's risk assessment process, information system, control activities and monitoring. These procedures alone do not give enough evidence for the opinion.
Objective and key terms (paragraphs 1-4)
The objective is to identify and assess the risks of material misstatement, due to fraud or error, at the financial statement and assertion levels, through understanding the entity and its environment, including internal control. That gives a basis for designing responses (paragraph 3). The application material (A1) calls the understanding a "continuous, dynamic process", gathered and updated throughout the audit.
| Term | Meaning (paragraph 4) |
|---|---|
| Assertions | Management's representations, explicit or otherwise, embodied in the financial statements, used to consider the different types of potential misstatement |
| Business risk | A risk from significant conditions, events, actions or inactions that could stop the entity achieving its objectives and strategies |
| Internal control | The process designed, implemented and maintained by governance, management and others to give reasonable assurance on reliable reporting, effective and efficient operations, safeguarding of assets, and compliance with law |
| Risk assessment procedures | The procedures used to understand the entity and its controls so that risks of material misstatement can be identified and assessed |
| Significant risk | An identified and assessed risk that, in the auditor's judgment, needs special audit consideration |
Risk assessment procedures (paragraphs 5-10)
Paragraph 5 requires risk assessment procedures as a basis for identifying and assessing risks, but they do not alone give sufficient evidence for the opinion. They include (paragraph 6):
- Inquiries of management, internal audit if there is one, and others who may have information on risks of fraud or error;
- Analytical procedures; and
- Observation and inspection.
The auditor also considers information from client acceptance or continuance (paragraph 7), information from other engagements the engagement partner has done for the entity (paragraph 8), and, if relying on past experience or earlier audits, whether things have changed since (paragraph 9).
The engagement team discussion (paragraph 10)
The engagement partner and key team members discuss how susceptible the entity's statements are to material misstatement and how the framework applies to the entity's facts. The engagement partner decides which matters to pass on to team members who did not attend. Fraud adds emphasis to this discussion; see SA 240 part 1.
The entity and its environment (paragraph 11)
| Area | What the auditor understands |
|---|---|
| Industry, regulatory and other external factors | Including the applicable financial reporting framework (11(a)) |
| Nature of the entity | Operations, ownership and governance, investments including special-purpose entities, structure and financing, so as to expect the right classes of transactions, balances and disclosures (11(b)) |
| Accounting policies | Selection and application, and reasons for changes; the auditor evaluates whether they suit the business and the framework and are consistent with the industry (11(c)) |
| Objectives, strategies and related business risks | Those that may lead to risks of material misstatement (11(d)) |
| Measurement and review of financial performance | How the entity and others judge its performance (11(e)) |
For a company's accountant, this is why the auditor asks for organisation charts, group structure, major contracts, budgets, management reports and accounting policy notes in the first weeks.
Internal control relevant to the audit (paragraphs 12-13)
The auditor obtains an understanding of internal control relevant to the audit. Most relevant controls relate to financial reporting, but not all financial reporting controls are relevant; the auditor decides by professional judgment (paragraph 12). For relevant controls, the auditor evaluates their design and determines whether they have been implemented, using procedures beyond inquiry (paragraph 13). This is different from testing whether they operated effectively through the year, which comes under SA 330.
The five components
1. Control environment (paragraph 14)
The auditor evaluates whether management, with governance oversight, has created and maintained a culture of honesty and ethical behaviour, and whether the strengths in the environment provide an appropriate foundation for the other components. A75 describes the control environment as setting the tone of the organisation. A76 lists elements: communication and enforcement of integrity and ethics, commitment to competence, participation of those charged with governance, management's philosophy and operating style, organisational structure, assignment of authority and responsibility, and human resource policies. A79 explains that some elements have a pervasive effect on the assessment of risk.
2. The entity's risk assessment process (paragraphs 15-17)
The auditor understands whether the entity has a process for identifying business risks relevant to financial reporting, estimating their significance, assessing the likelihood and deciding on actions (paragraph 15). If there is one, the auditor understands it and its results; if the auditor finds a risk that management missed, the auditor asks why the process failed and whether there is a significant deficiency (paragraph 16). If there is none, or only an ad hoc one, the auditor discusses with management how risks have been addressed and evaluates whether the absence of a documented process is appropriate or a significant deficiency (paragraph 17). Reporting of such deficiencies is in SA 265.
3. Information system and communication (paragraphs 18-19)
The auditor understands the significant classes of transactions; the IT and manual procedures by which transactions are initiated, recorded, processed, corrected, transferred to the ledger and reported; the related records and accounts; how non-transaction events are captured; the financial reporting process including estimates and disclosures; and the controls over journal entries, including non-standard entries (paragraph 18). The auditor also understands how roles, responsibilities and significant matters are communicated within the entity and externally, for example to regulators (paragraph 19).
4. Control activities relevant to the audit (paragraphs 20-21)
Only those control activities the auditor judges necessary to assess risks at the assertion level and design further procedures need to be understood, related to significant classes of transactions, balances and disclosures (paragraph 20). Examples in A95 are authorisation, performance reviews, information processing, physical controls and segregation of duties. A96 adds that controls related to significant risks, and risks that substantive procedures alone cannot address, are always relevant. The auditor also understands how the entity has responded to risks from IT (paragraph 21); general IT controls and application controls are described in A102-A104.
5. Monitoring of controls (paragraphs 22-24)
The auditor understands the major activities the entity uses to monitor internal control over financial reporting and how it takes remedial action (paragraph 22), the internal audit function's responsibilities, status and activities if there is one (paragraph 23), and the sources of information used in monitoring and why management considers them reliable (paragraph 24). See SA 610 on using internal auditors' work.
Illustrative example
For Lotus Hospitality Pvt Ltd, an invented restaurant company, the auditor reviews the franchise agreements and licences, observes the daily cash collection at two outlets, and asks the finance head about fraud risks. The control environment is reasonable but the owner approves most journal entries. The company has no formal risk assessment process, so the auditor discusses food cost and cash-handling risks with management and notes the absence. The point-of-sale system posts sales to the ledger daily, and the auditor traces one day's takings through each step. Monitoring consists of a monthly outlet performance review by the owner; there is no internal audit function.
Need help with understanding controls?
If you want your process documentation, authorisation limits and reconciliations organised before the auditor starts their risk assessment, TaxClue's books of accounts compliance team can help you set them up. Finance teams can also use our books of accounts compliance support to prepare a process walk-through pack.
Key takeaways
- Risk assessment procedures are inquiries, analytics, and observation and inspection.
- The team discusses the susceptibility of the statements to misstatement before the audit begins.
- The auditor must understand the entity, its environment, policies, strategies and performance measures.
- Five components of internal control are understood to the extent relevant to the audit: design and implementation, not yet operating effectiveness.
- Risk assessment procedures alone do not support the opinion.
Read next
- SA 315, part 2: assessing risks, significant risks and documentation
- SA 200: overall objectives of the auditor
- SA 265: communicating internal control deficiencies
- SA 330: responses to assessed risks
Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.
