The SAS 145 risk assessment standard reshaped how auditors identify and respond to the risk of material misstatement, and the first peer-review findings are now confirming where firms stumbled. Statement on Auditing Standards No. 145, Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement, took effect for audits of financial statements for periods ending on or after December 15, 2023. That makes the December 31, 2023 year-end the first widespread test, and the 2025 peer-review cycle is surfacing consistent patterns. If your organization is audited, understanding these patterns helps you anticipate sharper questions and heavier documentation expectations during a SAS 145 risk assessment.
Quick answer: SAS 145 did not change audit objectives, but it did change the mechanics. Auditors must now separately assess inherent risk and control risk at the assertion level, document an understanding of controls over journal entries even when they plan no controls testing, and apply a “stand-back” check to confirm they identified every significant class of transactions, account balance, and disclosure. The most common first-year peer-review findings center on missing journal-entry control documentation, generic revenue-fraud risks that were never tailored to the client, and risk assessments that were assigned without support.
What Actually Changed Under SAS 145
The headline change is the required separation of inherent risk and control risk. Under the prior standard, auditors could combine the two into a single risk-of-material-misstatement conclusion. SAS 145 now requires a documented, standalone inherent risk assessment at the assertion level under AU-C 315.35, evaluated without reference to internal controls or planned audit procedures.
Control risk is then assessed separately, and the mechanical consequence matters. When the auditor does not plan to test the operating effectiveness of controls, control risk is set at maximum, and the risk of material misstatement must equal the inherent risk assessment. Per AICPA & CIMA guidance, a frequent peer-review error involves a low inherent risk paired with a high control risk that produced a “moderate” risk conclusion, which is not how the model works.
This is not merely a paperwork distinction. Because the two assessments now stand on their own, a weak control environment can no longer pull a high inherent risk down to a comfortable middle ground, and a strong control environment cannot be assumed without testing. The auditor has to reason through each piece on its own terms and show that reasoning in the file.
SAS 145 also redefined a “relevant assertion.” An assertion is relevant only when there is an identified risk of material misstatement, which requires both a reasonable possibility of occurrence and a magnitude that could be material. As one firm leader told the Journal of Accountancy, areas that were “barely material” but low-risk previously stayed in scope because practitioners were “afraid to reduce testing.” The clarified definition gives auditors a defensible basis to scale effort toward genuine risk.
Two more additions round out the changes. The standard introduced explicit requirements to understand and document general IT controls that address risks arising from the use of information technology. It also added a “stand-back” requirement: a final evaluation of whether the auditor identified the complete population of significant classes of transactions, account balances, and disclosures. These changes are explained in the AICPA’s own overview of the new risk assessment standard.
Taken together, these revisions push the audit toward a more disciplined, evidence-first approach to risk. They do not raise the bar on what an audit is meant to achieve, but they do raise the bar on how clearly the auditor must connect the risks identified, the assertions affected, and the procedures performed.
What Documentation Pitfalls Are Peer Reviewers Flagging?
The first-year findings cluster tightly. According to the Journal of Accountancy‘s first-year lessons on SAS 145, the single most frequent issue is journal-entry controls. Firms knew who could post and approve entries, and they often examined the underlying support, but they failed to document an actual understanding of the controls, including required reviews, approvals, and restrictions on financial-reporting system access.
The second recurring problem is generic, un-tailored fraud risk in revenue. SAS 145 retains the presumption of a fraud risk related to revenue recognition, but reviewers found firms copying boilerplate language that never described the specific revenue streams and assertions actually at risk for the client. Documentation that could apply to any company is documentation that describes no company.
A related finding is a misalignment between the risks documented and the procedures performed. Reviewers cited cases where a firm documented a revenue cutoff risk but then walked through cash-receipts controls, so the testing did not respond to the stated risk. Others wrote lengthy process narratives, then identified no controls and performed nothing beyond inquiry, which does not satisfy the requirement to evaluate the design and implementation of relevant controls.
Significant-risk designations cut the other way. Some firms over-identified significant risks, tagging immaterial or industry-inappropriate items, which then led to incomplete responses because attention was spread too thin. A significant risk carries specific response obligations, so labeling too many items as significant creates work the firm then struggles to complete properly.
There is also a caution about overcorrecting. AICPA & CIMA guidance notes that some peer-review “Matters for Further Consideration” assert documentation expectations broader than what AU-C 315 actually requires, so the goal is meeting the standard, not papering the file. A file that grows for its own sake can bury the judgments that matter and still miss the specific control or assertion a reviewer is looking for. Strengthening the controls environment ahead of an audit is exactly the kind of work our risk advisory services team helps clients address before findings ever reach a workpaper.
What Should Audited Organizations Expect and Prepare?
For clients, the practical effect of SAS 145 is more questions and more evidence requests, particularly around technology and journal entries. Expect auditors to ask who can post journal entries, who reviews and approves them, whether the accounting system restricts those rights, and how that segregation is enforced. Having current process narratives, an accurate user-access listing, and evidence of management review ready will shorten the audit and reduce back-and-forth.
IT controls deserve specific attention. First-year experience showed that deeper conversations about remote access, change management, and disaster recovery surfaced control deficiencies and material weaknesses that clients had never formally documented. A clear inventory of your significant IT systems, who administers them, and how access is granted and removed lets the audit team complete its understanding efficiently rather than reconstructing it during fieldwork.
Better upfront planning was the other clear first-year lesson. Firms that ran industry-focused risk brainstorming and built templates linking controls to specific risks worked faster and produced cleaner files. From the client side, an early planning meeting where you walk through new revenue streams, system changes, unusual transactions, and any new lending or investment activity gives auditors the raw material to tailor their risk assessment. Our audit and assurance services team uses these planning conversations to align documented risks with the procedures actually performed, which is precisely the alignment peer reviewers are checking.
That alignment is worth emphasizing, because it is where so many first-year files fell short. When the risk you describe and the procedure you run point at the same assertion, the file tells a coherent story and the audit moves quickly. When they diverge, the auditor has to rework the response, and the engagement slows for everyone, including you.
Finally, do not read the separation of inherent and control risk as automatically more testing. In genuinely low-risk areas, the clarified definition of a relevant assertion can support scaling procedures down. The standard rewards judgment that is supported and documented, and it penalizes conclusions that appear in the file without a basis. Organizations that maintain orderly records of their controls, especially over journal entries and IT, are the ones whose audits move smoothly through this standard.
Frequently Asked Questions
What is the SAS 145 effective date?
SAS 145 is effective for audits of financial statements for periods ending on or after December 15, 2023. Calendar-year December 31, 2023 audits were the first broad application, and findings from those engagements are appearing in the 2025 peer-review cycle.
Does SAS 145 change my responsibilities as a client, or only the auditor’s?
The standard directly governs the auditor’s procedures, not your accounting. In practice, though, you will see more requests for evidence about journal-entry controls, IT access, and the design of controls over significant processes, so being able to produce that documentation makes the audit more efficient.
Why are auditors now asking so much about journal entries?
SAS 145 added an explicit requirement to understand controls over the journal-entry process, and incomplete documentation in this area is the most common first-year peer-review finding. Auditors need to understand who posts entries, who reviews and approves them, and how system access is restricted, not just inspect the supporting documents.
What is the SAS 145 “stand-back” requirement?
The stand-back is a final completeness check. After identifying risks, the auditor evaluates whether every significant class of transactions, account balance, and disclosure has been considered, reducing the chance that a material area was overlooked during planning.




