Auditing — Materiality and Audit Risk: Setting Performance Materiality and Detection Risk
Auditors do not try to find every error. They concentrate on misstatements material enough to change users’ decisions and reduce the risk of missing them to an acceptable level. These two concepts, materiality and audit risk, are the backbone of audit planning. The purpose of an audit was covered in chapter 1.
1. Materiality
Misstatements are material if, individually or in aggregate, they could reasonably be expected to influence the economic decisions of users of the financial statements (KSA 320). Materiality considers both amount (quantitative) and nature (qualitative). Even a small amount can be material if it turns a profit into a loss, conceals a covenant breach or involves management fraud.
A. Three amounts
| Item | Definition | AE amount |
|---|---|---|
| Overall materiality | Benchmark × percentage (e.g. 5% of profit before tax) | ₩100 million |
| Performance materiality | Set below overall materiality so that undetected and uncorrected misstatements in total do not exceed it (e.g. 70%) | ₩70 million |
| Clearly trivial threshold | Misstatements below this amount are not accumulated (e.g. 5% of overall) | ₩5 million |
The benchmark is the figure users focus on. Profit before tax is used for companies with stable profits; revenue or total assets for loss-making companies or those with volatile profits; total expenses for not-for-profit organizations. The percentage is a matter of the auditor’s judgement, with 5% of profit before tax, 0.5–1% of revenue and 1–2% of total assets commonly used as reference points.
2. The audit risk model
Audit risk is the risk that the auditor expresses an inappropriate (unmodified) opinion when the financial statements are materially misstated.
Inherent and control risk belong to the company; the auditor cannot change them and can only assess them. The only thing the auditor controls is detection risk. The higher the risk of material misstatement, the lower detection risk must be, which means more and stronger substantive procedures.
3. Worked example
AE’s auditor wants to reduce audit risk to 5%. The assessments by account are as follows.
| Account | Inherent risk | Control risk | Acceptable detection risk | Substantive procedures |
|---|---|---|---|---|
| Revenue (revenue recognition) | 80% | 50% | 5% ÷ 40% = 12.5% | More and stronger: large samples, close to period-end, external evidence |
| Cash | 30% | 30% | 5% ÷ 9% ≈ 55.6% | Fewer: centred on bank confirmations and reviewing reconciliations |
| Inventories | 70% | 80% | 5% ÷ 56% ≈ 8.9% | Very strong: attending the count, extended review of lower of cost and NRV |
In practice, rather than calculating exact probabilities, risks are assessed as high, medium or low and responses set accordingly. Revenue recognition is an area where fraud risk is presumed under KSA 240, so inherent risk is assessed as high. The risk of management override of controls is treated as a significant risk in every audit.
4. Risk assessment procedures
The auditor identifies and assesses the risks of material misstatement by understanding the entity and its environment, the applicable financial reporting framework and internal control (KSA 315). Inquiry, analytical procedures, observation and inspection are the risk assessment procedures. The revised standard applicable from 2022 assesses inherent risk through inherent risk factors such as complexity, subjectivity, change, uncertainty and management bias, and strengthens the understanding of the IT environment.
Check your understanding
AF’s revenue is ₩80 billion, and its profit before tax is only ₩200 million this year because of a one-off loss. If the auditor uses 0.5% of revenue as the benchmark instead of profit and sets performance materiality at 60% of overall materiality, what are the two amounts? If inventory’s inherent risk is assessed at 60% and control risk at 100% (no reliance on controls), with audit risk at 5%, what is the acceptable detection risk?
Overall materiality is (₩400 million) and performance materiality (₩240 million). Using 5% of the ₩200 million profit before tax (₩10 million) would make materiality far too small because of the one-off loss, so the revenue benchmark is more appropriate. Acceptable detection risk is . With no reliance on controls, risk must be reduced through substantive procedures alone.
References
- Korean Institute of CPAs, Korean Standards on Auditing, KSA 320 Materiality in Planning and Performing an Audit and KSA 450 Evaluation of Misstatements Identified during the Audit
- Korean Institute of CPAs, Korean Standards on Auditing, KSA 315 Identifying and Assessing the Risks of Material Misstatement and KSA 240 The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
- Alvin Arens, Randal Elder and Mark Beasley, Auditing and Assurance Services, ch. 9
Oiyo
Editorial DeskThe OIYO editorial desk researches money, law, lifestyle, and self-understanding topics against primary sources and public statistics. Every piece carries source notes and is reviewed on a regular cycle for accuracy and usefulness.