The consideration of fraud in a financial statement audit is the set of procedures a PCAOB-registered auditor must perform to obtain reasonable assurance that the financial statements are free of material misstatement caused by fraud. It runs through every phase of the engagement: risk assessment, response, communication, and documentation. Reasonable assurance is high, but it is not a guarantee. Fraud involves concealment, collusion, and forgery, and those things make it harder to catch than an honest error.
What the Auditor Is Responsible For
Preventing and detecting fraud is management’s job. Management designs the controls; those charged with governance oversee them. The auditor evaluates how well that system works and whether the gaps in it leave room for a material fraud to occur or go undetected.
That framing matters, because it sets the bar. The auditor is not an insurer against fraud. What the auditor owes is a properly planned and executed audit that has a reasonable chance of catching material misstatement, whether the cause is a mistake or a lie.
Why a Small-Dollar Fraud Can Still Be Material
Materiality is not just a percentage of net income. The SEC has rejected the idea that a misstatement below a common quantitative threshold such as 5% of net income is automatically immaterial.1U.S. Securities and Exchange Commission. Staff Accounting Bulletin No. 99 – Materiality A misstatement can be material even at a small dollar amount if it involves self-dealing by senior management, masks a change in earnings trends, or turns a reported profit into a loss. When the auditor finds a scheme by a senior executive, the qualitative factors will usually push it into material territory regardless of the number.
The Two Kinds of Fraud the Auditor Is Looking For
PCAOB standards divide financial statement fraud into two categories. The distinction shapes where the auditor looks and how the schemes tend to be concealed.
Fraudulent Financial Reporting
This is intentional misstatement or omission designed to mislead users of the financial statements. It is overwhelmingly a management-level problem. The motives are familiar: hitting analyst forecasts, staying inside debt covenants, propping up a stock price, protecting a bonus. The mechanics are also familiar — premature revenue, off-balance-sheet liabilities, capitalization of costs that belong in the income statement.
Misappropriation of Assets
This is theft. Skimmed cash receipts, stolen inventory, inflated expense reports, payments for goods never received. Employees below the executive level are the more common perpetrators, though management can be involved. Individual amounts are often smaller, but they accumulate, and the entries used to cover them up distort the financial statements the same way reporting fraud does.
Assessing Fraud Risk
The starting point is professional skepticism. The auditor does not assume management is dishonest, but does not accept honesty without corroboration either. Representations get tested against independent evidence.
The Fraud Triangle
PCAOB standards identify three conditions that tend to be present when fraud occurs: an incentive or pressure, an opportunity, and an attitude or rationalization that lets the person justify the act. The auditor does not need to see all three before concluding a fraud risk exists. One can be enough.2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement
Incentives at the management level tend to cluster around aggressive earnings targets, tight debt covenants, and short-term performance-based pay. At the employee level, personal financial difficulty or perceived under-compensation does the same work. Opportunity comes from weak controls: poor segregation of duties, lax board oversight, transactions no one fully understands, concentrated authority. Rationalization is the internal story the person tells themselves — the employee who plans to pay it back, the executive who believes next quarter will make the numbers whole. An aggressive tone at the top is itself a rationalization signal.
The Engagement Team Brainstorming Session
Before the audit begins in earnest, the engagement team is required to hold a discussion about how the entity’s financial statements might be susceptible to material misstatement from fraud. The lead engagement partner has to participate. The conversation covers specific fraud risk factors and must include how management could override controls.3Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit The point is to set the team’s mindset for the whole engagement and push back against any comfort built up from prior years. The discussion continues informally as new information surfaces.
Inquiries
The auditor makes direct inquiries of management, the audit committee, internal auditors, and other relevant personnel about actual or suspected fraud and about management’s own process for identifying and responding to fraud risks.4Public Company Accounting Oversight Board. Fraud Risk Resources The questions cover both direct knowledge of fraud and observation of conditions that might indicate it.
Analytical Procedures
The auditor runs analytics aimed at spotting unusual or unexpected relationships. Revenue climbing while cash collections stall. Margins expanding while industry peers report the opposite. These patterns are not proof of fraud, but they steer the auditor toward accounts that deserve closer work. When a fraud risk involving revenue has been identified, disaggregated analytics — revenue by month, product line, or business segment against prior periods — help surface anomalies that aggregate numbers hide.3Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit
The Revenue Recognition Presumption
PCAOB standards presume that improper revenue recognition is a fraud risk in every audit. The auditor must evaluate which types of revenue, which revenue transactions, or which assertions could give rise to the risk.2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement If the auditor concludes on a particular engagement that revenue recognition is not a fraud risk, the reasons for that conclusion have to be documented.3Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit Revenue manipulation — premature recognition, fictitious sales, channel stuffing — is the single most common form of fraudulent reporting, which is why the presumption exists.
Responding to Identified Fraud Risks
Once fraud risks are identified, the auditor tailors the nature, timing, and extent of planned procedures to address them. A high risk of revenue manipulation, for example, might push substantive testing from an interim date to year-end, replace reliance on internal documents with external customer confirmations, or add detailed testing of transactions booked near period-end. The goal is to make the procedures harder to anticipate and harder to work around.
Unpredictability
The auditor must build unpredictability into the audit. That means departing from routines management might expect: surprise inventory counts at unexpected dates or locations, testing accounts not examined in prior periods, counting cash without notice, oral inquiries of customers and suppliers instead of only written confirmations.3Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit When management can predict exactly what will be tested and when, concealment gets easier.
Procedures Aimed at Management Override
Every audit must include specific procedures addressing the risk that management overrode otherwise effective controls. This risk is presumed to exist regardless of the auditor’s assessment of other fraud risks, because management sits in a position to manipulate records directly.2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement Three categories of procedure are required:
- Journal entry testing. The auditor selects entries from the general ledger and examines the support. Focus falls on entries made at or near period-end and entries posted outside the normal course of business, though entries throughout the period should also be considered.3Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit
- Retrospective review of accounting estimates. Prior-year estimates get compared against how things actually turned out. Estimates that consistently lean in one direction can indicate bias, and bias is itself a fraud risk.3Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit
- Evaluation of significant unusual transactions. Transactions outside the normal course of business get examined for their business rationale. No apparent economic purpose, or unusual complexity, calls for heightened scrutiny.3Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit
Communication Obligations
When the auditor finds evidence of possible fraud, a layered set of communication duties kicks in based on who was involved and how serious it is.
Inside the Company
Any evidence of possible fraud, even a small theft by a low-level employee, must be brought to the attention of an appropriate level of management. Fraud involving senior management, and any fraud that causes a material misstatement, must be reported directly to the audit committee before the audit report is issued. Fraud risks with continuing control implications — where the absence of preventive or detective controls is a significant deficiency or material weakness — get communicated as well.3Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit
Section 10A Reporting to the SEC
Auditors of SEC registrants carry an additional obligation under Section 10A of the Securities Exchange Act of 1934 (15 U.S.C. § 78j-1). When the auditor becomes aware of information indicating that an illegal act may have occurred, the auditor must determine whether the act is likely, assess the possible effect on the financial statements, and inform management as soon as practicable.5Office of the Law Revision Counsel. 15 USC 78j-1 – Audit Requirements
The escalation has three specific triggers. If the auditor concludes that the illegal act has a material effect on the financial statements, that senior management has failed to take appropriate remedial action, and that this failure warrants either a departure from the standard audit report or the auditor’s resignation, the auditor must report those conclusions directly to the board.5Office of the Law Revision Counsel. 15 USC 78j-1 – Audit Requirements
Once the board receives that report, the company has one business day to notify the SEC. If the auditor does not receive a copy of the company’s notice within that one-business-day window, the auditor must furnish its own report directly to the SEC and resign from the engagement.5Office of the Law Revision Counsel. 15 USC 78j-1 – Audit Requirements This is the mechanism sometimes called the auditor’s “whistleblower” provision — the auditor becomes the conduit to the SEC only after management and the board have failed to act.
The Confidentiality Boundary
Outside of the Section 10A process, the auditor’s duty to report fraud externally is narrow. The ethical obligation of confidentiality generally prohibits voluntary disclosure to third parties. Limited exceptions include responding to a subpoena and communicating with a successor auditor during an auditor change. Legal counsel should be consulted before any external disclosure.
When Withdrawal Comes Into Play
Finding fraud does not automatically end the engagement, but it can create conditions where continuing is no longer appropriate. The auditor has to evaluate whether the nature and scope of the misstatement affect the reliability of the financial statements as a whole and whether an opinion can still be formed.
Fraud by senior management creates the sharper problem. The people who run the financial reporting process are the same people who manipulated it, which undermines the reliability of the management representations the audit depends on. In that situation the auditor has to seriously weigh withdrawal.
What Must Be Documented
PCAOB standards require documentation of every significant step in the fraud consideration process:
- The engagement team brainstorming session — how and when it happened, who participated, what was discussed.
- The risk assessment procedures performed to gather the information used to identify and assess fraud risks.
- The specific fraud risks identified at the financial statement level and the assertion level, with a clear link between each risk and the procedures designed to respond to it.
- If the auditor concluded that improper revenue recognition is not a fraud risk on this engagement, the reasons supporting that conclusion.
- The results of procedures performed in response to assessed fraud risks, including the management override procedures.
- The nature of any communications about fraud made to management, the audit committee, or others.3Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit
Documentation carries more weight in this area than in most. PCAOB inspections have repeatedly cited deficiencies in fraud work: substantive procedures that were not responsive to identified risks, insufficient journal entry testing, failure to identify revenue recognition as a fraud risk, and failure to communicate fraud risks to audit committees.6U.S. Securities and Exchange Commission. Statement – The Auditors Responsibility for Fraud Detection Work that is not documented is treated as work that was not done.