Audit planning
1 Overview

All audits start by:
Planning
Understanding.
After these stages auditor can assess the risk of material misstatement and respond to that risk. We will see later how the risk of material misstatement can be broken down into several causes, but if you are dealing with a relatively new company with inexperienced staff, and which has high value, portable inventory and many cash transactions, you will probably see that the risk of material misstatement is relatively high. If the auditors conclude that is the case then they have to plan for their audit work to reduce the risk of material misstatement finding its way into the financial statements.
2 Audit planning
Audit planning is very important and the auditors state in the auditor's report that they planned and performed their audit. ISA 300 Planning an Audit of Financial Statements is written in the context of recurring audits.
2.1 Reasons why planning is important
If you don’t plan it you won’t carry out the audit effectively. You would not know something as obvious as when the year end is, or how many branches or factories a company has, or how many staff members you may need to conduct the audit, or whether the company has a lot of valuable inventory.
You have to think both of a general strategy and a detailed approach. For example, in some very large companies auditors do not visit all the branches every year. They may visit only a quarter of the branches one year, another quarter the next year and so on. They have to decide whether or not to attend a physical inventory count. They may have to decide whether or not opinions from other experts are required. For example, on the adequacy of the company’s pension scheme.
2.2 Objectives of adequate planning
To give appropriate attention to important areas. Is there a high inventory? Is there a high volume of cash transactions? Are trade receivables particularly significant? Important areas will certainly be material areas, and materiality is discussed below.
To identify potential problems. For example, if the company has recently changed its computerised accounting system there may well have been problems at the switch-over time, and staff may still be inexperienced.
To carry out the work expeditiously. That really means reasonably quickly and efficiently.
To ensure that the right numbers of staff are in the audit team with the right skills. They have to be timetabled so that the work for this client and other clients can be accommodated.
To coordinate, if necessary, with other parties. For example, the internal audit department of the company.
To facilitate the direction and supervision of the audit team and the review of their work.
2.3 Planning activities
To perform an audit in an effective matter, the auditor must establish the overall audit strategy (sets out the scope, timing and direction of the audit) and develop an audit plan. The audit plan describes the nature, timing and extent of:
Risk assessment procedures (ISA 315 Identifying and Assessing the Risks of Material Misstatement)
Further audit procedures at the assertion level (ISA 330 The Auditor’s Response to Assessed Risks)
Both the strategy and the plan should be updated, as necessary, as the audit progresses and the strategy, plan and significant changes must be included in the audit documentation.
3 Understanding the entity
In order to identify and assess the risks of material misstatement, the auditor must obtain an understanding of:
the entity;
its environment;
the applicable financial reporting framework; and
system of internal control.
3.1 Required understanding
Nature of the entity. We have to understand the nature of the entity. For example, we simply have to understand what it does: is it in a financial sector, the retail sector, the manufacturing sector? This may seen trivial but it may help you to think of a new audit client. You can often tell very little from the name of the client. You have to go and find out about the entity itself.
Particular regulations. Banks, insurance companies, and many other operations in the financial sector are subject to regulation and sometimes the auditor has to ensure that these regulations have been adhered to.
Applicable financial report framework. An understanding of the applicable financial reporting framework is essential to evaluating whether the entity's accounting policies are appropriate. An entity may apply industry-specific practices or account for transactions in emerging areas (e.g. cryptocurrency).
Objectives and strategies. The auditors must gain an understanding of the entity’s, objectives, and strategies. The entity’s management defines objectives, and strategies are devised to try and achieve those objectives.
Nature of business risks. Business risks can arise from circumstances which mean that the company’s objectives and strategies may not be achieved. Business risk is broader than the risk of material misstatement of the financial statements. Most business risks will eventually have financial consequences and therefore an effect on the financial statements. It is important for the auditors, therefore, to understand what the risks are.
System of internal control. The auditor has to gain an understanding of the entity’s internal controls. Whether they exist and to what extent they are expected to operate.
The control environment. The effectiveness of the control environment has a significant bearing on the auditor's confidence in the other components of the system of internal control which will affect the nature, timing and extent of audit procedures.
How does management identify business risks? It is important for management to identify business risks. Management has a real expertise of the business sector and if they can’t identify business risks it can be relatively difficult for the auditor to ensure that all business risks have been covered.
Financial performance. Performance measures create pressures on management. Obtaining an understanding of the entity’s performance measures assists the auditor in considering whether such pressures may result in management actions that could increase the risks of material misstatements. A review of key performance indicators, ratios and trends may indicate that risks of misstatement exist (eg unusually rapid growth or profitability compared to other entities in the same industry).
3.2 Risk assessment procedures
Risk assessment procedures must include:
Enquiries of management and others (e.g. internal audit) who may have information that is likely to assist in identifying risks of material misstatements.
Analytical procedures which may help identify unusual transactions/events and ratios or trends that have audit implications.
Observation and inspection to support the enquiries and provide information (e.g. business plans, internal control manuals and premises).
Prior year information obtained can be used as long as it remains relevant and reliable as audit evidence for the current audit. Information obtained during client acceptance procedures may also be relevant.
3.3 System of internal control
ISA 315 requires the auditor not only to understand the controls relevant to the audit but also:
To evaluate the design of controls – Should they prevent or detect and correct material misstatement?
To determine whether they have been implemented – Are the controls operating effectively?
Enquiry alone is NOT sufficient to answer these questions.
See Chapter 12 of our AA notes if you need to revise the five inter-related components of a system of internal control and the different types of control activities. Remember than control activities are just one of the components.
3.4 Risks of Material Misstatement (RoMM)
A risk of material misstatement exists when there is a reasonable possibility of:
1. A misstatement occurring (i.e. likelihood); and
It being material if it were to occur (i.e. magnitude).
RoMM must be assessed at two levels to provide a basis for designing further audit procedures:
The financial statement level (i.e. relating to the financial statements, for example, the risk of management override of internal control).
The assertion level (i.e. relating to classes of transactions, account balances and disclosures).
See Chapter 16 of our AA notes if you need to revise the financial statement assertions.
RoMM is assessed at the assertion level to determine the nature, timing and extent of further audit procedures necessary to obtain sufficient appropriate audit evidence. It has two components – inherent risk and control risk (see Chapter 11 for details).
IAS 315 (Revised 2019) introduced new concepts and definitions to assist with the identification and assessment of risks of material misstatement.
Inherent risk factors – characteristics of events or conditions that affect the susceptibility of an assertion to misstatement, before consideration of controls.
Spectrum of inherent risk – the degree to which inherent risk varies.
Relevant assertion – an assertion with an identified risk of material misstatement.
Significant class of transactions, account balance or disclosure – one for which there is one or more relevant assertion.
Significant risk – a risk of misstatement which is close to the upper end of the spectrum of inherent risk or treated as significant in accordance with an ISA (e.g. revenue recognition).

4 Materiality
One of the key areas of planning is to determine materiality. An audit gives only a reasonable assurance that the financial statements are free from material misstatement, so it is essential to know what is meant by ‘material’.
Information is material if omitting, misstating or obscuring it could reasonably be expected to influence decisions that the primary users of general purpose financial statements make on the basis of those financial statements, which provide financial information about a specific reporting entity.
It is affected by the size or nature of the misstatement.
The auditor’s judgment flows all the way through the audit process, from planning and deciding the amount of work that should be done, to deciding what action should be taken should errors be found in the accounts. When judging materiality, the audit partner should consider the common information needs of users, as a group. (The specific needs of individual users are not considered as they may vary widely.)
5 Guidance on materiality
It’s all very well saying that a matter is material if it would reasonably influence decisions of users, but that gives very little guidance to the audit team (or to you when you are doing a question).
Therefore, some rules of thumb have been developed. These are only guidelines, but an amount will generally be considered immaterial if it is less than the following and material if it is greater:
0.5% to 1% of revenue
1% to 2% of total assets
5% to 10% of profit before tax
Points to note:
Professional judgement will be used to decide whether amounts within these ranges are material (eg considering qualitative factors).
Which benchmarks to use will depend on specific circumstances (eg revenue may be most relevant for a company which provides services with few assets or which has a relatively small draft profit or a loss).
IT IS VERY COMMON FOR AAA EXAM QUESTIONS TO PROVIDE REVENUE, ASSET AND PROFIT FIGURES. YOU MUST USE THE RELEVANT FIGURE(S) TO ASSESS WHETHER MATTERS ARE MATERIAL.
In a real audit a running total of errors is kept so that their net effect can be calculated. However, when designing and carrying out audit tests and when noting down errors, smaller amounts should be set for materiality to reduce the risk that misstatements in aggregate exceed financial statement materiality. This is known as performance materiality: the materiality that is important in the performance of the audit work.
Note that errors which are less than the suggested guidelines could be judged to be material. An error which turns a small loss into a small profit could cause unfounded optimism in some situations, perhaps a feeling that the company has turned a corner. So, although in absolute terms, the size of an error is relatively small, the way in which the accounts are then interpreted could lead to unreasonable decisions being made. Therefore, you can talk about both quantitative and qualitative materiality.
Finally, there are some amounts in the financial statements where no errors are tolerable. For example, there is often a statutory duty to disclose directors’ remuneration and that has to be stated with absolute accuracy.
Note that the evaluation of misstatements identified during the audit is considered in ISA 450 (see Chapter 8).


