SA 315 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
This second part of SA 315 explains how the auditor turns understanding into assessed risks: where the risks sit, which ones are significant, which ones need controls to be understood, when the assessment must change, and what is recorded.
SA 315, as effective for audits of financial statements for periods beginning on or after 1 April 2008, applies to every audit. ICAI may revise standards, so check icai.org for the current text. Part 1 covers the understanding the auditor must obtain.
The auditor identifies and assesses risks at two levels, the financial statements as a whole and the assertion level for classes of transactions, balances and disclosures. Risks needing special audit consideration are significant risks, judged ignoring the effect of controls, and the auditor must understand the controls relevant to them. Where substantive procedures alone cannot give enough evidence, the controls must also be understood. The assessment is revised if later evidence contradicts it, and the work is documented.
Two levels of risk (paragraphs 25-26)
Paragraph 25 requires the auditor to identify and assess risks of material misstatement at (a) the financial statement level and (b) the assertion level, as a basis for further procedures.
Financial statement level. A117 says these risks relate pervasively to the statements and may affect many assertions; they are not tied to one assertion, and include circumstances that raise risk at the assertion level, such as management override. A118 notes they can come from a deficient control environment, for example lack of management competence, and may need an overall response. A119 gives two cases that raise doubts about auditability: serious concerns about management's integrity, and concerns about the condition and reliability of records so that sufficient appropriate evidence is unlikely to be available. In such cases the auditor considers qualification, disclaimer or withdrawal under SA 705 (A120).
Assertion level. Risks are assessed for each class of transactions, balance and disclosure because this directly determines the nature, timing and extent of further procedures (A121).
What the auditor does (paragraph 26)
- Identify risks throughout the process of understanding the entity, including relevant controls, by considering classes of transactions, balances and disclosures.
- Assess the risks, and evaluate whether they relate more pervasively to the statements as a whole.
- Relate the risks to what can go wrong at the assertion level, taking account of relevant controls the auditor intends to test.
- Consider the likelihood of misstatement, including multiple misstatements, and whether it could be material.
Assertions used by the auditor
A123 describes three categories. They are the building blocks of every audit program.
| Category | Assertions |
|---|---|
| Classes of transactions and events for the period | Occurrence, completeness, accuracy, cut-off, classification |
| Account balances at period end | Existence, rights and obligations, completeness, valuation and allocation |
| Presentation and disclosure | Occurrence and rights and obligations, completeness, classification and understandability, accuracy and valuation |
The auditor may express assertions differently, provided all aspects are covered (A124). The application material also explains how a control relates to an assertion: for example, controls over the inventory count relate directly to existence and completeness of inventory (A129), while a sales manager's review of regional sales summaries relates only indirectly to completeness of sales, and matching shipping documents with invoices is more direct (A130). Often it takes several control activities together to address a risk (A128).
Significant risks (paragraphs 27-29)
The auditor decides which risks are significant. In doing so the auditor excludes the effect of identified controls related to the risk (paragraph 27). Paragraph 28 lists at least six matters to consider:
- whether the risk is a risk of fraud;
- whether it relates to recent significant economic, accounting or other developments, such as regulatory change, needing specific attention;
- the complexity of transactions;
- whether it involves significant related party transactions;
- the degree of subjectivity in measurement, especially with a wide range of uncertainty; and
- whether it involves significant transactions outside the normal course of business or otherwise unusual.
A131 notes that significant risks often relate to significant non-routine transactions or judgmental matters, such as estimates with significant measurement uncertainty; routine, non-complex, systematically processed transactions are less likely to be significant. A132-A133 explain why non-routine transactions and judgmental estimates carry greater risk: more management intervention, more manual processing, complex calculations, and differing interpretations of principles for estimates or revenue recognition.
When there is a significant risk, the auditor must understand the entity's controls, including control activities, relevant to it (paragraph 29). A136 gives examples of management responses to non-routine risks: a senior management or expert review of assumptions, documented estimation processes and approval by those charged with governance. A138 says that failure to implement controls over significant risks is an indicator of a significant deficiency, which brings in SA 265. Fraud risks are treated as significant risks under SA 240 (A135), and the audit consequences are in SA 330.
Risks where substantive procedures alone are not enough (paragraph 30)
For some risks the auditor may judge that substantive procedures alone cannot give sufficient appropriate evidence. These typically involve routine and significant classes of transactions, such as revenue, purchases and cash receipts and payments, processed in a highly automated way with little or no manual intervention. In such cases the controls are relevant and the auditor must understand them (paragraph 30). A140 explains why: evidence may exist only in electronic form, so its sufficiency and appropriateness depend on the effectiveness of controls over accuracy and completeness, and improper changes may go undetected if controls are not working.
Revising the assessment (paragraph 31)
The assessment at assertion level may change as evidence builds up. If further procedures or new information are inconsistent with the evidence on which the assessment was based, the auditor revises the assessment and modifies the planned procedures (paragraph 31). A142 gives examples: tests of controls show they were not effective at relevant times, or substantive procedures find misstatements in larger amounts or higher frequency than expected.
Documentation (paragraph 32)
The auditor documents:
- the team discussion and significant decisions;
- key elements of the understanding of the entity, its environment and each internal control component, the sources of information, and the risk assessment procedures performed;
- the identified and assessed risks at both levels; and
- the risks identified, and the related controls understood, for significant risks and risks where substantive procedures alone are not enough.
The form and extent are for the auditor's judgment (A143). For simple businesses, documentation may be brief, and it need not cover the entire understanding; the key elements on which the assessment was based are enough (A144). Less experienced teams may need more detail (A145); for recurring audits, documentation may be carried forward and updated (A146). Small audits can fold this into the strategy and plan under SA 300. The appendices of SA 315 summarise the internal control components and give examples of conditions and events that may indicate risks of material misstatement; the examples include unstable or volatile operating environments, complex regulation, liquidity problems, new products or locations, acquisitions and reorganisations, complex financing, significant related party transactions, shortages of skilled accounting staff, key personnel changes and unaddressed control deficiencies. The auditor can use them as a prompt list.
Illustrative example
For Azad Auto Components Pvt Ltd, an invented company, the auditor's assessment table looks as follows (illustrative).
| Area | Assertion at risk | Assessment | Why |
|---|---|---|---|
| Revenue from a new export contract | Occurrence, cut-off | Significant risk | Fraud presumption, new customer, large amount near year end |
| Goodwill on acquisition | Valuation | Significant risk | Subjective forecasts, wide range of outcomes |
| Domestic purchases through ERP | Completeness, accuracy | Substantive procedures alone not enough | Fully automated, no paper trail |
| Cash balances | Existence | Lower risk | Few accounts, confirmations available |
Midway through the audit, a test of automated three-way matching shows exceptions, so the auditor raises the risk for purchases and extends testing.
Need help with risk mapping?
If you want a clear map of your business risks, processes and controls before the auditor builds theirs, TaxClue's books of accounts compliance team can help you document them. Finance teams can also use our books of accounts compliance support to sort out the areas an auditor is likely to flag.
Key takeaways
- Risks are assessed at both statement and assertion levels, and tied to specific assertions.
- Significant risks are judged without the effect of controls; the auditor then understands the controls for them.
- Fraud risks, related party risks, non-routine transactions and subjective estimates often give rise to significant risks.
- Highly automated routine processing may need controls to be understood because substantive procedures alone are not enough.
- Revise the assessment when evidence contradicts it, and document the basis.
Read next
- SA 315, part 1: understanding the entity and its internal control
- SA 320: materiality
- SA 330: responses to assessed risks
- SA 240, part 1: fraud risk assessment
Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.
