Next due
7 OCTTDS / TCS deposit · Deducted in Sep 2026in 2 days 11 OCTGSTR-1 · Outward supplies · Sep 2026in 6 days 15 OCTPF & ESI · Contributions · Sep 2026in 10 days 20 OCTGSTR-3B · Summary return · Sep 2026in 15 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 25 days 31 OCTITR filing · Audit cases · AY 2026-27in 26 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 55 days 15 DECAdvance Tax · 3rd (75%) instalment · FY 2026-27in 71 days
All due dates

SA 315, Identifying and Assessing the Risks of Material Misstatement Through Understanding the Entity and Its Environment (part 2 of 2): assertion-level risks, significant risks, revising the assessment and documentation

The auditor identifies and assesses risks at two levels, the financial statements as a whole and the assertion level for classes of transactions, balances and disclosures. Risks...

Published
Updated
Reading time
8 min
Views
5
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 3, 2026
Last updated
Oct 4, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

This second part of SA 315 explains how the auditor turns understanding into assessed risks: where the risks sit, which ones are significant, which ones need controls to be understood, when the assessment must change, and what is recorded.

SA 315, as effective for audits of financial statements for periods beginning on or after 1 April 2008, applies to every audit. ICAI may revise standards, so check icai.org for the current text. Part 1 covers the understanding the auditor must obtain.

Two levels of risk (paragraphs 25-26)

Paragraph 25 requires the auditor to identify and assess risks of material misstatement at (a) the financial statement level and (b) the assertion level, as a basis for further procedures.

Financial statement level. A117 says these risks relate pervasively to the statements and may affect many assertions; they are not tied to one assertion, and include circumstances that raise risk at the assertion level, such as management override. A118 notes they can come from a deficient control environment, for example lack of management competence, and may need an overall response. A119 gives two cases that raise doubts about auditability: serious concerns about management's integrity, and concerns about the condition and reliability of records so that sufficient appropriate evidence is unlikely to be available. In such cases the auditor considers qualification, disclaimer or withdrawal under SA 705 (A120).

Assertion level. Risks are assessed for each class of transactions, balance and disclosure because this directly determines the nature, timing and extent of further procedures (A121).

What the auditor does (paragraph 26)

  1. Identify risks throughout the process of understanding the entity, including relevant controls, by considering classes of transactions, balances and disclosures.
  2. Assess the risks, and evaluate whether they relate more pervasively to the statements as a whole.
  3. Relate the risks to what can go wrong at the assertion level, taking account of relevant controls the auditor intends to test.
  4. Consider the likelihood of misstatement, including multiple misstatements, and whether it could be material.

Assertions used by the auditor

A123 describes three categories. They are the building blocks of every audit program.

CategoryAssertions
Classes of transactions and events for the periodOccurrence, completeness, accuracy, cut-off, classification
Account balances at period endExistence, rights and obligations, completeness, valuation and allocation
Presentation and disclosureOccurrence and rights and obligations, completeness, classification and understandability, accuracy and valuation

The auditor may express assertions differently, provided all aspects are covered (A124). The application material also explains how a control relates to an assertion: for example, controls over the inventory count relate directly to existence and completeness of inventory (A129), while a sales manager's review of regional sales summaries relates only indirectly to completeness of sales, and matching shipping documents with invoices is more direct (A130). Often it takes several control activities together to address a risk (A128).

Significant risks (paragraphs 27-29)

The auditor decides which risks are significant. In doing so the auditor excludes the effect of identified controls related to the risk (paragraph 27). Paragraph 28 lists at least six matters to consider:

  1. whether the risk is a risk of fraud;
  2. whether it relates to recent significant economic, accounting or other developments, such as regulatory change, needing specific attention;
  3. the complexity of transactions;
  4. whether it involves significant related party transactions;
  5. the degree of subjectivity in measurement, especially with a wide range of uncertainty; and
  6. whether it involves significant transactions outside the normal course of business or otherwise unusual.

A131 notes that significant risks often relate to significant non-routine transactions or judgmental matters, such as estimates with significant measurement uncertainty; routine, non-complex, systematically processed transactions are less likely to be significant. A132-A133 explain why non-routine transactions and judgmental estimates carry greater risk: more management intervention, more manual processing, complex calculations, and differing interpretations of principles for estimates or revenue recognition.

When there is a significant risk, the auditor must understand the entity's controls, including control activities, relevant to it (paragraph 29). A136 gives examples of management responses to non-routine risks: a senior management or expert review of assumptions, documented estimation processes and approval by those charged with governance. A138 says that failure to implement controls over significant risks is an indicator of a significant deficiency, which brings in SA 265. Fraud risks are treated as significant risks under SA 240 (A135), and the audit consequences are in SA 330.

Risks where substantive procedures alone are not enough (paragraph 30)

For some risks the auditor may judge that substantive procedures alone cannot give sufficient appropriate evidence. These typically involve routine and significant classes of transactions, such as revenue, purchases and cash receipts and payments, processed in a highly automated way with little or no manual intervention. In such cases the controls are relevant and the auditor must understand them (paragraph 30). A140 explains why: evidence may exist only in electronic form, so its sufficiency and appropriateness depend on the effectiveness of controls over accuracy and completeness, and improper changes may go undetected if controls are not working.

Revising the assessment (paragraph 31)

The assessment at assertion level may change as evidence builds up. If further procedures or new information are inconsistent with the evidence on which the assessment was based, the auditor revises the assessment and modifies the planned procedures (paragraph 31). A142 gives examples: tests of controls show they were not effective at relevant times, or substantive procedures find misstatements in larger amounts or higher frequency than expected.

Documentation (paragraph 32)

The auditor documents:

  • the team discussion and significant decisions;
  • key elements of the understanding of the entity, its environment and each internal control component, the sources of information, and the risk assessment procedures performed;
  • the identified and assessed risks at both levels; and
  • the risks identified, and the related controls understood, for significant risks and risks where substantive procedures alone are not enough.

The form and extent are for the auditor's judgment (A143). For simple businesses, documentation may be brief, and it need not cover the entire understanding; the key elements on which the assessment was based are enough (A144). Less experienced teams may need more detail (A145); for recurring audits, documentation may be carried forward and updated (A146). Small audits can fold this into the strategy and plan under SA 300. The appendices of SA 315 summarise the internal control components and give examples of conditions and events that may indicate risks of material misstatement; the examples include unstable or volatile operating environments, complex regulation, liquidity problems, new products or locations, acquisitions and reorganisations, complex financing, significant related party transactions, shortages of skilled accounting staff, key personnel changes and unaddressed control deficiencies. The auditor can use them as a prompt list.

Illustrative example

For Azad Auto Components Pvt Ltd, an invented company, the auditor's assessment table looks as follows (illustrative).

AreaAssertion at riskAssessmentWhy
Revenue from a new export contractOccurrence, cut-offSignificant riskFraud presumption, new customer, large amount near year end
Goodwill on acquisitionValuationSignificant riskSubjective forecasts, wide range of outcomes
Domestic purchases through ERPCompleteness, accuracySubstantive procedures alone not enoughFully automated, no paper trail
Cash balancesExistenceLower riskFew accounts, confirmations available

Midway through the audit, a test of automated three-way matching shows exceptions, so the auditor raises the risk for purchases and extends testing.

Need help with risk mapping?

If you want a clear map of your business risks, processes and controls before the auditor builds theirs, TaxClue's books of accounts compliance team can help you document them. Finance teams can also use our books of accounts compliance support to sort out the areas an auditor is likely to flag.

Key takeaways

  • Risks are assessed at both statement and assertion levels, and tied to specific assertions.
  • Significant risks are judged without the effect of controls; the auditor then understands the controls for them.
  • Fraud risks, related party risks, non-routine transactions and subjective estimates often give rise to significant risks.
  • Highly automated routine processing may need controls to be understood because substantive procedures alone are not enough.
  • Revise the assessment when evidence contradicts it, and document the basis.

Read next

Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About SA 315

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What is a significant risk?

An identified and assessed risk of material misstatement that, in the auditor's judgment, requires special audit consideration (paragraph 4).

Why are controls ignored when deciding whether a risk is significant?

Paragraph 27 requires the auditor to exclude the effects of identified controls related to the risk, so that the inherent nature of the risk drives the judgment.

Keep the acknowledgement. A filing you cannot prove is a filing you may have to defend.

— TaxClue Compliance Desk

SA 315: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,327 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

An identified and assessed risk of material misstatement that, in the auditor's judgment, requires special audit consideration (paragraph 4).

Paragraph 27 requires the auditor to exclude the effects of identified controls related to the risk, so that the inherent nature of the risk drives the judgment.

Yes; SA 240 requires the assessed risks of fraud to be treated as significant risks, and paragraph 28 includes fraud as a factor.

Management's representations embodied in the financial statements, such as existence, completeness, valuation and cut-off, used to consider types of potential misstatement.

In the cases in A119: serious concerns about management integrity or about the reliability of records so that enough evidence is unlikely to be available.

The auditor revises it and modifies the planned procedures (paragraph 31).