SA 300-499
Planning, materiality, risk assessment, responses to assessed risks and service organisations.
SA 300-499
Planning, materiality, risk assessment, responses to assessed risks and service organisations.
← Back to hubSection-wise decoding
1. Objective
The 300-series standards govern the risk-based audit approach: understanding the entity well enough to identify where a material misstatement could occur, setting materiality, and designing procedures that actually respond to the risks identified — rather than running the same standard checklist regardless of the entity's risk profile.
2. Applicability
Applies to every audit; the depth of application scales with the entity's complexity, but the underlying risk-assessment discipline (SA 315) is not optional even for a simple entity.
3. Core Rules
| SA | Subject |
|---|---|
| SA 300 | Planning an audit of financial statements |
| SA 315 | Identifying and assessing the risks of material misstatement through understanding the entity and its environment |
| SA 320 | Materiality in planning and performing an audit |
| SA 330 | The auditor's responses to assessed risks |
| SA 402 | Audit considerations relating to an entity using a service organisation |
| SA 450 | Evaluation of misstatements identified during the audit |
4. Practical Example
Under SA 320, materiality is not one fixed number — the auditor sets overall materiality, performance materiality (a lower amount to reduce the risk that immaterial misstatements aggregate to a material one), and a threshold below which misstatements are clearly trivial; all three are revisited if new information emerges during the audit.
5. Common Mistake
Setting materiality once at planning and never reassessing it. SA 320 and SA 450 together require the auditor to reconsider materiality if facts emerge during the audit that would have led to a different determination had they been known at the outset.
Risk-response chain
| Stage | Standard | Output |
|---|---|---|
| Understand the entity and environment | SA 315 | Documented understanding of the entity, its internal control, and assessed risks at financial-statement and assertion level |
| Set materiality | SA 320 | Overall materiality, performance materiality, and the clearly-trivial threshold |
| Design and perform responses | SA 330 | Further audit procedures (tests of controls and/or substantive procedures) linked to the specific assessed risk |
| Evaluate identified misstatements | SA 450 | Aggregate of uncorrected misstatements compared against materiality; conclusion on financial-statement effect |
Exceptions and red flags
- Risk: Designing substantive procedures without first linking them to a specific assessed risk at the assertion level (SA 330) — a generic "test everything a bit" approach is not a valid substitute for a risk-based response.
- Risk: Treating a service organisation (e.g. a payroll processor or a cloud hosting provider) as outside audit scope — SA 402 requires the auditor to obtain an understanding of relevant controls at the service organisation, including considering a Type I/Type II assurance report where available.
- Risk: Netting misstatements of opposite direction against each other when evaluating aggregate effect under SA 450, rather than considering their gross effect and nature.
Implementation checklist
- ✓ Document the entity understanding and risk assessment (SA 315) before finalising the audit plan, not as a retrofit after fieldwork.
- ✓ Set and record overall materiality, performance materiality, and the trivial threshold explicitly (SA 320), with the basis for each.
- ✓ Trace every significant substantive/control test back to the specific risk it responds to (SA 330).
- ✓ Maintain a running schedule of identified misstatements (corrected and uncorrected) throughout the audit for the SA 450 evaluation.
Q&A
| Why does performance materiality exist separately from overall materiality? | It is set lower than overall materiality specifically to reduce, to an appropriately low level, the probability that the aggregate of uncorrected and undetected misstatements exceeds overall materiality. |
|---|---|
| Is SA 315 only relevant for large or complex entities? | No — the standard applies to every audit; the extent and formality of documentation scales with complexity, but the risk-identification requirement itself does not disappear for a small entity. |
| What happens to uncorrected misstatements below the trivial threshold? | They are not required to be accumulated, but the auditor must still be satisfied the threshold itself is set appropriately low enough that nothing individually or in aggregate could be material. |
| Can this be used as professional advice? | No. Confirm the exact current text of each SA before applying a materiality or risk-response judgement to a live engagement. |
Finin2min Summary
SA 300-499 in 2 minutes: Plan (SA 300), understand the entity and assess risk (SA 315), set materiality at three levels (SA 320), design responses tied to specific assessed risks (SA 330), extend understanding to service organisations where used (SA 402), and evaluate all misstatements found against materiality before concluding (SA 450).
Source log
- ICAI — Standards on Auditing, complete text — SA complete text
- ICAI — Guidance Notes on Auditing Aspects — Guidance Notes
- ICAI — Checklist on Standards on Auditing — SA checklist