UNSW Business School
School of Accounting, Auditing and Taxation
ACCT5908 Auditing and Assurance Services
Topic 3
Understanding the Entity and Assessing
Business Risk and Inherent Risk
Course Overview
2
Fundamental Importance of Risk
Assessment
• If auditors do not effectively conduct risk assessment, audit
quality suffers.
• Auditors ‘respond to risk of material misstatement’. So if risks
are not identified, they cannot respond to them.
• Risk assessment is the ‘heart’ of the audit
3
Recent Developments
• In February 2020, the Australian Auditing and Assurance
Standards Board reissued ASA315 ‘Identifying and Assessing
Risk of Material Misstatement’.
• Specifies a more robust process of risk identification and
assessment.
• A key change is to require a separate assessment of inherent
and control risk.
• Operative for financial reporting periods commencing on or
after 15 December 2021.
4
Business risk
• After gaining an understanding of the entity, the next two
stages of the risk assessment process are to identify and
assess risk, as outlined below:
5
Business risk defined
“A risk resulting from significant conditions, events,
circumstances, actions or inactions that could adversely affect
an entity’s ability to achieve its objectives and execute its
strategies, or from the setting of inappropriate objectives and
strategies”.
6
Assessing business risk
• The auditor uses entity and industry information to identify
business risks that may affect the audit.
• The assessment of client business risk is an input into the
auditor’s assessment of the risk of material misstatement in
the financial report (by way of inherent risk).
• Auditing standards require, the members of the audit
engagement team to discuss the susceptibility of the entity’s
financial report to material misstatement.
7
Techniques for assessing business risk
• To obtain information about the risks arising due to the nature
of the entity and its environment, auditors may use strategic
management techniques such as:
• Strengths-Weaknesses-Opportunities-Threats (SWOT) analysis.
• Political-Economic-Social-Technological (PEST) risk analysis.
• Value chain analysis
• Non financial performance measurement.
8
Analytical procedures
• Analytical procedures involve the use of ratios, trend analysis
and operating statistics for comparison with internal and
external data.
• Can be used at all stages of the audit, but must be performed
at the planning and review stages. It is an optional type of
substantive procedure.
9
Analytical procedures at the planning
stage
• The risk analysis approach requires analytical procedures to
be used during the planning stage of the audit.
• Allows the auditor to understand the business and identify
areas of potential risk, thereby assisting in the determination
of the nature, timing and extent of audit procedures.
10
Types of analytical procedures
Simple procedures More complex procedures
• Simple comparisons • Time series modelling
• Ratio analysis • Regression analysis
• Common-size statements • Financial modelling
• Trend statements
• Time series analysis
11
Analytical procedures most commonly
used in planning
• Comparison of current balances in the financial report with
balances of previous periods and budgeted amounts (simple
comparisons).
• Computation of ratios and percentage relationships for
comparison with previous years, budgets and industry
averages (ratio analysis)
• Significant variations from expectations indicate areas
requiring investigation.
12
Ratio analysis
• At the planning stage the auditor is undertaking ratio analysis
on unaudited financial information, thus any ratios not in
accordance with the auditor’s expectations will indicate areas
requiring significant audit attention.
• These ratios may be compared to:
• Industry data:
• Average ratios in industries listed on the ASX
• Internal data:
• Previous years
• Budgets or forecasts
• Segment or division data
13
Ratios commonly used at the planning
stage
1. Short Term Liquidity:
• Current ratio (current assets to current liabilities)
• Quick asset ratio (liquid assets to current liabilities)
• Operating cash flow ratio (cash flow from operations to current
liabilities).
2. Activity:
• Receivables turnover / days in receivables (net sales to average
accounts receivable365 days to receivables turnover).
• Inventory turnover/days in inventory (cost of goods sold to
average inventory/365 days to turnover).
14
Ratios commonly used at the planning
stage
3. Profitability:
• Gross profit and net profit ratio (gross profit or net profit to net
sales)
• Return on total assets (net profit before interest and taxes to total
assets)
• Return on shareholders’ equity (net profit to ordinary
shareholders’ equity).
2. Solvency
• Debt to equity ratio (total liabilities to shareholder’s equity)
• Times interest earned (net profit before interest and taxes to
annual interest expense..
15
Common size statements
Express balance sheet components as a percentage of total
assets and income statement components as a percentage of
total revenue.
16
Trend statements
Each item is expressed as a percentage of its own level from a
base year, thus allowing focus on trend rather than absolute
magnitude of dollar change.
17
Data used in analytical procedures
• Auditor must consider whether data needed are easily
available and their reliability.
• For reliability:
• Data from an independent source outside the entity are generally
more reliable than internal data.
• Data from a system with effective internal controls are more
reliable than data from a poorly controlled system.
• Data audited in the previous year or in the current audit are more
reliable than unaudited data.
• Data from a variety of sources that corroborate each other are
more reliable than data from only one source.
• Data from the department within which the entity that is
responsible for the amount being audited are generally less
reliable than data from another department.
18
Data used
• With increases in data availability, auditors are increasingly
using different types of data that may be related to business
activity. Examples include;.
• Economic data
• Weather / climate data
• Customer reviews
• Social media
19
Plausibility, predictability and precision
of analytical relationships
• Relationships in a stable environment are more predictable
than relationships in a changing environment.
• Direct relationships are more predictable than indirect
relationships.
• Disaggregated relationships show clearer relationships than
combined or aggregated relationships.
• Relationships involving Income statement amounts tend to be
more predictable than relationships involving only balance
sheet accounts (amounts at a point in time).
• Relationships involving transactions subject to management
discretion are less predictable than those not subject to such
discretion.
• …
20
Examination of significant fluctuations
• The auditor must decide which fluctuations are significant and
thus warrant investigation.
• Thus the audit working papers must show:
• Identification of each significant fluctuation
• Explanations provided by management should be considered
• The results of work done to corroborate explanations received.
21
Business risks and risks of material
misstatement
• Many business risks eventually have financial consequences
and therefore eventually affect inherent risk and risk of
material misstatement.
• However, not all business risks impact the risk of material
misstatement.
Business Risk Fraud Risk
Inherent Risk
22
Significant risks
• The auditor is required to determine whether any identified
risk is a ‘significant risk’, being a risk of material misstatement
that requires special audit consideration.
• Factors to consider when determining significant risks include:
• The risk of fraud.
• Relationship to recent significant economic, accounting or other
developments that require specific attention.
• Complexity of the transactions.
• Involvement of significant transactions with related parties.
• Degree of subjectivity in measuring related financial information.
• Whether significant transactions are unusual or outside the
normal course of business for the entity.
23
Inherent risk
Susceptibility of account balance or class of transactions to
material misstatement given inherent and environmental
characteristics, but without regard to internal control.
• An auditor is required to:
• Assess IR at financial report level.
• Assessment must then be related to assertions at account
balance or class of transactions level when developing audit plan
or program.
24
Inherent risk at the financial report level
and business risk
• An entity’s business strategy and associated risks will affect
an auditor’s assessment of inherent risk at the financial report
level.
• Where possible, an auditor traces business risks to areas of a
financial report that are likely to be misstated.
25
Factors affecting Inherent risk at financial
report level
• Integrity of management
• Management experience, knowledge and changes during the
period
• Unusual pressure on management
• Nature of the entity’s business
• Factors affecting the industry in which the entity operates
26
Inherent risk at assertion level
• Inherent risk is greater for some assertions and related
classes of transactions, account balances and disclosures
than for others.
• Auditor will normally focus on:
• Accounts likely to require adjustment
• Complexity of underlying transactions
• Judgment involved in determining account balances
• Susceptibility of assets to loss or misappropriation
• Occurrence of unusual and complex transactions, particularly at
or near year end
• Transactions not subject to ordinary processing.
27
Effect of inherent risk on an account
balance assertion
28
Tips on explaining risk to the auditor
RISK OF MISSTATEMENT (STEP 1)
– Specify whether it is at risk of Overstatement or Understatement
WHY (STEP 2 AND STEP 3)
– Use information from the case facts (and link to assertion at risk)
e.g. Because of xxxx, customers are unlikely to pay, value of
property likely to be impaired, etc.
– State appropriate accounting principle/treatment that explains
why account is at risk of over/under-statement e.g. inventory
needs to be recorded at lower of cost and NRV ; A/R needs to be
recorded at amount expected to be collected, not amount owed ;
amount recorded in PPE should embody future economic
benefits etc.
29
Business and Inherent risk
30
Business risk
31
Topic 3 Discussion Question - IR
Italio Pty Limited is a producer of frozen pizzas. At a recent
university orientation day, a large number of students were
taken to hospital. The problem is believed to be related to
an ingredient in the pizza, which comes from a well known
meat supplier.
Identify 3 key balance sheet accounts at risk, why they are
at risk to the auditor (IR) and the key assertions impacted?
step 1 - Inventory is account at risk, overstatement
step 2 - it has to be written off due to the health issue
step 3
32
Fraud
• At the planning stage, an auditor should consider the risk that
material misstatements resulting from fraud will not be
detected, and consider risk of fraud when deciding which risks
are significant.
• It is easier to miss material misstatements resulting from fraud
because fraud involves acts designed to conceal it, such as
collusion, forgery or intentional misrepresentation to the
auditor.
33
Fraud
• Fraud is defined as:
‘An intentional act by one or more individuals among
management, those charged with governance, employees, or
third parties, involving the use of deception to obtain an unjust or
illegal advantage’
• There are two types of fraudulent misstatement that are
relevant to the auditor:
• Misstatement resulting from fraudulent financial reporting.
• Misstatement resulting from misappropriation of assets.
34
Fraud
35
Fraudulent financial reporting
• Fraudulent financial reporting may involve:
• Manipulation, falsification or alteration of records or documents.
• Suppression or omission of the effects of transactions from
records or documents.
• Recording of transactions without substance.
• Intentional misapplication of accounting policies.
36
Misappropriation of assets
• Misappropriation of assets may involve:
• Embezzling cash receipts.
• Stealing assets.
• Causing the entity to pay for goods not received.
• Using an entity’s assets for personal use.
37
Fraud triangle
38
Responsibility for the detection and
prevention of fraud
• The primary responsibility for the prevention and detection of
fraud rests with those charged with governance of the entity
and management.
• The audit should be planned to obtain a reasonable
assurance that fraud that may be material has not occurred
or, if it has , that the effect of the fraud is properly reflected in
the financial report and therefore that the financial report is
free from material misstatement due to fraud or error.
39
Auditors responsibility for the detection
and prevention of fraud
• In planning and conducting the audit, the auditor must
exercise reasonable care and skill and maintain an attitude of
professional scepticism.
• An auditor will use his or her experience, knowledge and
training to determine whether fraud could occur.
• An auditor needs a thorough understanding of a client’s
business in order to identify opportunities for fraud.
• If there is a particular risk of fraud because of the nature of an
item, it should receive more attention.
40
Responsibility for the detection and
prevention of fraud
• Auditors now have to proactively consider fraud. Auditing
standards require the auditor to:
• Specifically consider risks of material misstatement in a financial
report due to fraud.
• Discuss an entity’s susceptibility to fraud with other members of
the audit team.
• Make more extensive enquiries of management with respect to
fraud.
41
Reporting fraud
• The auditor has a duty to report fraud, irrespective of
materiality, to an appropriate level of management when
suspicions are aroused.
• Auditors should obtain legal advice if there is any doubt as to the
appropriate course of action to take.
• While the auditor may be reluctant to report fraud due to the risk
of defamation, in most cases the auditor is protected from
defamation actions by qualified privilege as long as reporting
matters in good faith and without malice to people who have a
proper interest in receiving the information.
42
Fraud risk factors
• An auditor commonly uses a checklist to identify increased
risks of fraud. Where risk is high, it is called a ‘red flag’.
• Risks can be grouped under six headings
• Management
• Unusual pressures within an entity
• Market pressures
• Unusual transactions
• Unsatisfactory records
• IT environment
43
Earnings management
• Earnings management occurs when judgment in financial
reporting and in structuring transactions is used to alter
financial reports to influence the perceptions of stakeholders.
• Earnings management involves those responsible for
preparing the financial report such at the Chief Financial
Officer (CFO) and Chief Executive Officer (CEO).
• Incentives to manage earnings can be either behavioral or
market-based.
44
Broad categories of earnings
management
• Earnings management by clients may fall into the following
categories:
• Intentional violations of accounting standards and other reporting
requirements that are individually immaterial.
• Inappropriate revenue recognition.
• ‘Big bath’ charges under the guise of restructuring.
• Improper accruals and estimation of liabilities in good times.
45
Related parties
• Related parties are defined in AASB124 as follows:
Entities are related if one entity is able to significantly influence or
control the operating, financing or investing decisions of another; or
if several entities are subject to control from the same entity; or if
the party is a joint venture in which the entity is a venturer.
• Related parties include key management personnel (including
directors), their close family members and entities controlled
by them as well as superannuation funds run for the benefit of
employees or related parties of the entity.
46
Assessing risks associated with related
parties
• Auditing standards require auditors to specifically assess the
risk that related parties and related party transactions will not
be identified, or appropriately disclosed and/or measured.
• An auditor must identify all related parties when planning the
audit because:
• The existence of related parties or related party transactions can affect
the financial information.
• The reliability of audit evidence is a function of the source of that
evidence.
• The initiation of a related party transaction might be motivated by other
than ordinary business conditions, such as fraud.
47
Examples of related parties fraud
• Examples of possible frauds involving related parties:
• Creating fictitious terms of transactions with related parties.
• Fraudulently transferring assets at amounts significantly above
or below market value.
• Engaging in complex transactions with related parties, such as
special purpose entities, that are structured to misrepresent the
financial position or performance of the entity.
48
Procedures for identifying related parties
• Review the previous period’s working papers for known
related parties.
• Make enquires of management concerning the names of all
related parties.
• Review the entity’s procedures for identifying related parties.
• Enquire about management’s and directors’ affiliations with
other entities.
• Review minutes of meetings.
• Enquire of other auditors involved in the audit.
49
Identifying the existence of related
parties
• Examples of transactions that may indicate the existence of
related parties include transactions that:
• Are overly complex (for example, transactions involving multiple
parties within a consolidated group).
• Have abnormal terms of trade, such as unusual prices, interest
rates, repayment terms, or guarantees.
• Lack an apparent logical business reason to justify their
occurrence.
• Have been processed in an unusual manner.
50
Appropriateness of the going concern assumption
• Going concern assumption:
• Entity is viewed as continuing in business for the foreseeable future
without any intention or necessity to liquidate or otherwise cease its
operations.
• Auditing standards require auditors to assess going concern at the planning
stage, as imminent business failure might affect the appropriateness of
presentation of financial report or might motivate management
representations.
• ASA 570 (revised May 2025) applies for financial reporting periods
commencing on or after 15 December 2026, although early adoption is
permitted. The revised standard significantly enhances the auditor’s work in
evaluating management’s assessment of an entity’s ability to continue as a
going concern and includes new requirements for the auditor to respond to
identified risks of material misstatement related to going concern. The
standard also strengthens the auditor’s reporting requirements (topic 9).
51
Appropriateness of the going concern basis
• Early identification helps focus audit effort on appropriate
assertions in the financial report and permits early
communication with management.
• An auditor is required to evaluate management’s assessment
of going concern that covers a period of at least 12 months
from the date of approval of the financial report (ASA570.21, revised
May 2025), which is typically aligned with the audit report date.
• This evaluation includes understanding the significant
management judgements on which their assessment is
based, and audit procedures must address the method,
significant assumptions and data used by management.
(ASA570.19, revised May 2025).
52
Examples of indications of going concern
problems
• Financial indicators include:
• High gearing, fixed term, or reliance on short term borrowings.
• Withdrawal of financial creditors, inability to pay creditors or
denial of trade credit by suppliers.
• Negative operating cash flows or adverse key financial ratios.
• Lack of sustainable operating profits.
• Dividend in arrears.
• Difficulty in complying with terms of loan agreements
• Inability to obtain necessary financing.
53
Examples of indications of going concern
problems
• Operating indicators include:
• Management’s intention to cease operations
• Loss of key management personnel
• Loss of major market, license or franchise
• Prolonged industrial action
• Shortage of important supplies
• Emergence of highly successful competitors.
54
Examples of indicators of going concern
problems
• Other indicators
• Non-compliance with capital or statutory requirements.
• Legal proceedings against the entity.
• Adverse changes in legislation or government policy.
• Uninsured or underinsured disasters.
Note that all going concern indicators are identified by auditors on a
gross basis - before consideration of mitigating factors included in
management’s plans for future actions (refer next slide).
55
Mitigating factors
The auditor shall evaluate management’s plans for future actions in relation to its going
concern assessment, including whether:
(a) The outcome of these plans is likely to be sufficient to mitigate the effects of the
identified events or conditions;
(b) Management’s plans are feasible in the circumstances; and
(c) Management has both the intent and ability to carry out specific courses of action
(ASA570.26, revised May 2025)
If management’s plans for future actions include financial support by third parties or
related parties, including the entity’s owner-manager, the auditor shall obtain audit
evidence about the intent and ability of those parties to maintain or provide the
necessary financial support (ASA570.28, revised May 2025)
Examples of mitigating factors include:
• Asset factors – sale of assets, or delayed replacement.
• Debt factors – unused lines of credit, ability to renew or extend existing loans.
• Cost factors – ability to reduce or delay costs
• Equity factors – additional contributions from owners, subsidiaries or associates.
56
Summary
• Inherent risk is a major component of audit risk.
• Inherent risk is the risk of errors occurring due to the
characteristics of the entity and the environment in which it
operates.
• Other special risk areas that need to be considered are fraud,
including earnings management, related party transactions;
and the appropriateness of the going concern basis for
preparing the financial report.
57
Final thoughts
• Understanding the entity and its environment is fundamental
not only to assessing inherent risk, but also to interpreting the
audit evidence that is collected.
• Evidence is interpreted through the lens of this understanding.
58
Next Step
• The entity may have controls in place that prevent and/or
detect material misstatements.
• The auditor must understand these controls before planning
controls testing and substantive testing.
• In Topic 4, we will look at an understanding of internal
controls and an assessment of control risk.
59