Audit Planning and Risk Assessment
Planning
Audit Planning and Risk Assessment
Syllabus tag: KASNEB CPA | Advanced Level | CA36 Advanced Auditing and Assurance
1. Why planning matters
ISA 300 requires the auditor to plan the audit so that it is performed in an effective manner. Planning produces the overall audit strategy (high-level scope and approach) and the audit plan (detailed nature, timing, and extent of procedures).
2. Understanding the entity — ISA 315
The auditor must understand: the entity's industry, regulatory environment, and external factors; the nature of the entity (operations, ownership, governance, business model); accounting policies and changes; objectives, strategies, and business risks; measurement and review of financial performance; and internal control (the five COSO components: control environment, risk assessment, control activities, information and communication, monitoring).
3. The audit risk model
Audit Risk = Inherent Risk × Control Risk × Detection Risk
- Inherent risk (IR): susceptibility of an assertion to misstatement assuming no controls — higher for complex transactions, judgement-heavy estimates, related parties
- Control risk (CR): risk that misstatement will not be prevented or detected by internal controls — reduced by testing controls
- Detection risk (DR): risk that audit procedures will not detect an existing misstatement — the auditor controls this by adjusting the nature, timing, and extent of substantive procedures
4. Significant risks
ISA 315 requires identification of significant risks — those requiring special consideration. Indicators: high subjectivity/estimation, unusual transactions, fraud risk, related-party transactions. Substantive procedures must be tailored for each significant risk; controls testing alone is insufficient.
5. Materiality
Overall materiality benchmarks: 5% of PBT (profit-making entities), 0.5–1% of revenue (low-margin), 1–2% of total assets (asset-heavy or not-for-profit). Performance materiality (60–75% of overall) reduces the probability that aggregate uncorrected and undetected misstatements exceed overall materiality. Trivial threshold (5% of overall) — misstatements below this need not be accumulated.
6. Analytical procedures in planning
ISA 520 mandates analytical procedures at planning and the overall review stage. Planning analytics identify unusual transactions, trends, and high-risk areas using ratio analysis, trend analysis, and common-size statements.
7. Preliminary engagement activities
Confirm independence, assess client acceptance/continuance, agree engagement terms in writing. If a predecessor auditor existed, communicate with them (with client consent) to identify any professional reasons not to accept the engagement.
