AU-C Section 240 is the auditing standard, published in the AICPA Professional Standards, that governs how an auditor considers fraud during a financial statement audit of a nonpublic entity conducted under generally accepted auditing standards. It tells the auditor to plan and perform every engagement with the possibility of fraud in mind, to apply specific risk assessment and response procedures, and to communicate what they find to the right people. The objective is reasonable assurance that the financial statements are free of material misstatement, whether caused by an honest mistake or deliberate manipulation.1AICPA & CIMA. Exposure Draft, Proposed SAS Fraud in an Audit of Financial Statements Public company audits fall under a substantially similar standard, PCAOB AS 2401, rather than AU-C 240 itself.
What Counts as Fraud Under the Standard
AU-C 240 draws a hard line between fraud and error. An error is unintentional: a transposition in a journal entry, an accidental misapplication of an accounting rule. Fraud is intentional. Someone deliberately manipulates the numbers, conceals information, or steals assets.
The standard covers two categories:
- Fraudulent financial reporting, where management or others intentionally misstate the financial statements by manipulating records, fabricating transactions, or misapplying accounting principles to distort the entity’s financial picture.
- Misappropriation of assets, where someone steals from the entity in a way that causes the financial statements to be materially wrong. Embezzlement, skimming receipts, and diverting company assets all fit here.
The categories call for different audit responses. Fraudulent reporting typically involves management and is harder to detect because the people committing it can override the controls that would otherwise catch them. Asset theft can happen at any level and leaves different footprints in the accounting records.
Professional Skepticism Runs Through the Whole Engagement
Skepticism is not a phase of the audit. AU-C 240 requires it throughout, meaning the auditor approaches every piece of evidence with a questioning mind and critically evaluates whether it actually supports what management is claiming. The standard strikes a specific balance: the auditor should not assume management is dishonest, but neither can they assume unquestioned honesty. Past experience with a client’s integrity does not justify lowering the bar for the current engagement.
In practice, this means seeking corroborating evidence from independent sources when management’s explanations are inconsistent, vague, or implausible. The standard also acknowledges an inherent limitation: collusion, forged documentation, and coordinated cover stories can defeat controls that would ordinarily flag problems. That reality is a reason to be more rigorous, not less. It does not reduce the auditor’s obligation to perform the required procedures.
Required Risk Assessment Procedures
Before the auditor can respond to fraud risk, they have to identify it. AU-C 240 specifies procedures during planning that feed directly into decisions about where to focus substantive testing and how much of it to do.
Engagement Team Discussion
Every audit begins with a discussion among the engagement team about how and where the entity’s financial statements might be susceptible to material misstatement due to fraud. The standard treats this as brainstorming, not a formality. The discussion must cover both fraudulent financial reporting and asset misappropriation, and team members share what they know about risk factors, unusual transactions, and areas where management has the ability and incentive to manipulate results.2Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit
Inquiries of Management and Others
The auditor makes specific inquiries of management about their own assessment of fraud risk, the process they use to identify and respond to it, any specific fraud risks they have flagged, and whether they know of any actual, suspected, or alleged fraud. If the entity has an internal audit function, the auditor asks about its procedures for identifying fraud, any findings it has reported, and how management responded.2Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit The auditor also asks those charged with governance, typically the board or audit committee, about their views on fraud risks, their oversight of management’s fraud-related processes, and whether they know of any fraud affecting the entity.
These inquiries produce information for the risk assessment and create opportunities to compare accounts. Inconsistencies between what management, internal audit, and the governance body describe are themselves a red flag.
Analytical Procedures
During planning, the auditor performs analytical procedures to spot unusual or unexpected relationships that could signal fraud risk.2Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit A sudden change in receivables turnover, a spike in period-end sales with no clear business explanation, or gross margins that diverge from industry norms without a plausible reason can all point to revenue manipulation or other distortion. The results feed the overall risk assessment alongside what came out of the team discussion and inquiries.
The Three Conditions the Standard Looks For
AU-C 240 structures the fraud risk assessment around three conditions that are generally present when fraud occurs. The auditor identifies risk factors related to each.
- Incentive or pressure. Someone has a reason to commit fraud. Management might face intense pressure to meet earnings forecasts or debt covenants. An employee might have personal financial problems. Compensation heavily tied to financial performance creates a direct motive to inflate results.
- Opportunity. The environment allows fraud to happen. Weak internal controls, poor segregation of duties, ineffective board oversight, and complex organizational structures all create openings. Management inherently has more opportunity than other employees because they can override controls.
- Rationalization or attitude. The person committing fraud can justify it internally. This surfaces in a culture where management pushes aggressive accounting interpretations, dismisses regulatory compliance, has a strained relationship with auditors, or fails to correct known control weaknesses.
These elements rarely appear in isolation. An auditor who spots one should look harder for the other two.
Revenue Recognition Carries a Presumed Fraud Risk
AU-C 240 establishes a rebuttable presumption that fraud risk exists in revenue recognition. The auditor must evaluate which types of revenue, revenue transactions, or assertions give rise to fraud risk based on that presumption.3American Institute of Certified Public Accountants. Supplement No. 2 to Fraud Exposure Draft – Mapping of Extant AU-C Section 240
The presumption can be rebutted only in limited circumstances. An entity with a single type of simple revenue transaction, such as leasehold income from one rental property, might justify a conclusion that no fraud risk exists in revenue recognition. When the auditor does rebut the presumption, the reasons must be documented. In most engagements with any complexity to their revenue streams, the presumption stands and the auditor designs specific procedures to address it.
Responding to Assessed Fraud Risks
Once fraud risks are identified and assessed, AU-C 240 requires responses at two levels.
Overall Responses
At the financial statement level, the auditor adjusts the audit’s general design. That can mean assigning team members with specialized skills, such as forensic accountants or IT specialists, to handle high-risk areas. The auditor also evaluates whether the entity’s selection and application of accounting principles could itself indicate fraudulent reporting, with particular attention to areas involving subjective measurement and complex transactions. Heightened skepticism across the engagement is a required overall response whenever fraud risks are assessed, not an option.
Assertion-Level Responses
At the assertion level, procedures are tailored to the specific risks identified. If the risk involves fictitious sales, the auditor might modify confirmations to verify not just balances but the actual terms of sale. Inventory counts can be performed on an unannounced basis at unexpected locations. Computer-assisted audit techniques can scan the full population of journal entries for patterns that suggest manipulation, such as entries posted after hours, round-dollar adjustments, or entries made by people who don’t normally have access.
For complex valuations involving financial instruments, inventory, or fair value measurements, the auditor may need an independent specialist to review the models and test the underlying assumptions with greater rigor than a standard audit would apply.
Three Mandatory Procedures for Management Override
This is where AU-C 240 draws its hardest line. The risk that management can override internal controls exists in every audit, regardless of the entity’s size, industry, or control environment. No favorable risk assessment removes it. The standard requires three specific procedures on every engagement to address it.2Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit
Testing Journal Entries and Other Adjustments
The auditor tests the appropriateness of journal entries recorded in the general ledger and other adjustments made during the preparation of financial statements. The focus falls on entries posted at period-end, entries made by individuals who don’t typically make journal entries, entries with no supporting documentation or vague descriptions, and entries to accounts that are rarely used. The auditor needs to understand the entity’s financial reporting process well enough to distinguish normal from suspicious.
Reviewing Accounting Estimates for Bias
The auditor performs a retrospective review of prior-year accounting estimates, comparing what management estimated to what actually happened. If management’s estimates consistently skew in the same direction, that pattern suggests bias rather than honest misjudgment. The estimates selected for review should be those in significant accounts where a fraud risk has been assessed.2Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit
Evaluating Unusual Significant Transactions
The auditor evaluates the business rationale for significant transactions that fall outside the entity’s normal course of business or otherwise appear unusual. Related-party transactions, deals lacking a clear economic purpose, and arrangements with unusual terms all warrant scrutiny. The auditor reads the underlying documentation, verifies that the transaction was authorized through proper channels, and assesses whether the financial capacity of the other parties supports the claimed terms.
Communication Requirements
AU-C 240 sets out a layered communication structure that escalates based on who is involved and how serious the matter is.
To Management
Whenever the auditor identifies fraud or obtains information indicating fraud may exist, the matter must be communicated promptly to the appropriate level of management, meaning at least one level above the people who appear to be involved. Even a minor theft by a low-level employee gets reported. The standard does not include a materiality threshold for this initial notification.
To Those Charged With Governance
The auditor communicates directly to those charged with governance, typically the audit committee, when the fraud involves management, employees who have significant roles in internal control, or anyone else when the fraud results in a material misstatement. When the auditor suspects management involvement, the communication must include a discussion about the nature, timing, and extent of additional audit procedures needed to complete the engagement. Other fraud-related matters that the auditor judges relevant to the governance body’s oversight responsibilities should also be communicated.
To Regulators
For nonpublic entities, the auditor’s duty of client confidentiality generally prevents disclosure to outside parties unless a specific legal or regulatory requirement demands it. AU-C 240 does not impose a blanket duty to report fraud to law enforcement.
For public companies, Section 10A of the Securities Exchange Act of 1934 creates a specific escalation path when an auditor detects likely illegal acts during a financial statement audit. The auditor first determines whether an illegal act likely occurred and whether it could materially affect the financial statements. If so, the auditor informs management and ensures the audit committee or board is adequately notified. If senior management fails to take timely and appropriate remedial action, the auditor must report its conclusions directly to the board.4Office of the Law Revision Counsel. 15 U.S. Code 78j-1 – Audit Requirements
Once the board receives that report, the company must notify the SEC within one business day and send the auditor a copy of that notice. If the auditor does not receive the company’s notice within the one-business-day window, the auditor must either resign from the engagement or furnish its own report directly to the SEC.4Office of the Law Revision Counsel. 15 U.S. Code 78j-1 – Audit Requirements
When Fraud Forces the Auditor to Consider Withdrawal
Identifying fraud triggers obligations beyond the standard workflow. If the auditor concludes that the financial statements are, or may be, materially misstated as a result of fraud, the auditor evaluates the implications for the audit. A material misstatement that management refuses to correct leads to a modified audit opinion.
Some situations are serious enough that the auditor must consider withdrawing from the engagement entirely. AU-C 240 identifies three circumstances that typically raise the question: the entity refuses to take appropriate action even when the fraud is not material to the financial statements, the results of audit procedures indicate a significant risk of material and pervasive fraud, or the auditor has serious concerns about the competence or integrity of management or those charged with governance.
If the auditor withdraws, two things must happen. The auditor discusses the withdrawal and its reasons with the appropriate level of management and those charged with governance, and the auditor determines whether any professional or legal obligation requires reporting the withdrawal to the party that engaged the auditor or to regulatory authorities.
Documentation the Standard Requires
AU-C 240 requires specific documentation at every stage. A vague workpaper file will not satisfy it. The auditor must document:
- The significant decisions reached during the engagement team discussion, including who participated and when and how it occurred.
- The identified and assessed risks of material misstatement due to fraud at both the financial statement and assertion levels.
- The overall responses at the financial statement level, the nature, timing, and extent of specific procedures performed, and how those procedures link back to the assessed risks.
- The results of the three mandatory procedures addressing management override.
- All fraud-related communications made to management, those charged with governance, regulators, or others.
- If the auditor concluded that the presumption of fraud risk in revenue recognition does not apply, the reasons supporting that conclusion.
The standard is designed so that an experienced auditor who was not part of the engagement could review the workpapers and understand what fraud risks were identified, what was done about them, and why the auditor reached the conclusions reflected in the audit report.
Proposed Revisions on the Horizon
The AICPA’s Auditing Standards Board has issued an exposure draft proposing a new Statement on Auditing Standards that would supersede AU-C 240.5AICPA & CIMA. AICPA Seeks Comment on Proposed Update to Auditors’ Responsibilities Related to Fraud The proposal would broaden the definition of fraud to explicitly include acts by third parties, treat the risk of management override as a fraud risk at the financial statement level rather than at the assertion level, and expand the auditor’s obligations around fraud-related risks tied to revenue transactions. It also introduces a stand-back provision requiring the auditor, near the end of the audit, to reconsider whether accumulated evidence changes the fraud risk assessment. The effective date has not been finalized, so auditors currently applying AU-C 240 should track the AICPA’s progress because the final version could change several of the procedures described above.