What you need to know first
- ISA 315 (Revised) separates the assessment of Inherent Risk from Control Risk and introduces a spectrum of inherent risk.
- Five inherent risk factors—complexity, subjectivity, change, uncertainty, and susceptibility to management bias or fraud—drive audit focus.
- Even if an auditor does not plan to rely on operating effectiveness of controls, they must still evaluate the design and implementation of key controls.
1. The Spectrum of Inherent Risk
Not every account balance carries the same risk of material misstatement. ISA 315 requires auditors to evaluate how complexity, management judgment, and external economic changes affect each significant class of transactions, account balance, and disclosure.
- High subjectivity: Provision for expected credit losses (IFRS 9), inventory obsolescence, and tax contingencies.
- High complexity: Multi-element revenue contracts, group consolidations, and related-party pricing.
- IT environment risks: Access controls, segregation of duties in ERP systems, and manual journal entry overrides.
2. How Management Can Prepare Before Audit Fieldwork
Audit delays most often happen when walkthrough documentation is assembled reactively. Preparing process narratives, authorization matrices, and bank/tax reconciliations upfront significantly shortens fieldwork.
Preparation Checklist: Keep signed approval trails for manual journal entries, monthly bank reconciliations, supplier master-file changes, and payroll sign-offs ready for walkthrough testing.
