Under ISA 240, the auditor’s fraud responsibilities in a financial statement audit are to plan and perform the engagement with professional skepticism, carry out specific procedures targeted at areas where fraud is most likely, and communicate what they find to management, those charged with governance, and in some cases external authorities. The standard does not make the auditor a guarantor against fraud. It requires reasonable assurance that the financial statements are free of material misstatement, and it acknowledges that some material fraud may still go undetected even in a properly executed audit. A revised version of ISA 240 takes effect for audit periods beginning on or after December 15, 2026.
The Two Kinds of Fraud the Standard Addresses
The line between fraud and error is intent. An error is an accidental misstatement, like a data-entry mistake or an honest misapplication of an accounting rule. Fraud is a deliberate act by management, employees, those charged with governance, or outside parties that causes a misstatement. That intentional element drives every requirement in ISA 240.
The standard groups fraudulent acts into two categories. Fraudulent financial reporting means manipulating accounting records or deliberately misapplying reporting standards so the financial picture looks different than it actually is. It can range from fabricated journal entries to omitted disclosures to inflated revenue. Misappropriation of assets means theft of company resources that causes the financial statements to understate what the entity owns or overstate what it has spent, such as skimming cash receipts, processing payments for goods never delivered, or diverting company funds.
The distinction matters because the risk factors, the people involved, and the procedures needed to detect each type differ. Fraudulent financial reporting tends to originate at the management level and can hide inside the accounting system itself. Asset misappropriation often involves employees further down the organization and leaves different evidentiary trails.
The Limits of What an Audit Can Detect
An audit under ISA 240 provides reasonable assurance, not a guarantee. The standard explicitly acknowledges an unavoidable risk that some material fraud goes undetected. Fraud involves concealment: perpetrators forge documents, collude, or withhold information from the auditor. Management-level fraud is especially difficult to detect because the people committing it often control the records the auditor relies on. An auditor working from fabricated evidence may have no visible reason to question it. The audit opinion is a professional judgment that the auditor followed ISA 240 and found no material misstatement due to fraud based on the evidence available. It is not a certificate that no fraud occurred.
Professional Skepticism and the Engagement Team Discussion
Professional skepticism is the foundation of every fraud-related requirement in ISA 240. The auditor must maintain a questioning mind throughout the engagement and critically evaluate the evidence collected rather than accept it at face value. This applies even where the auditor has a long history with the client and no reason to distrust management. Past honesty is not evidence of current honesty, and the standard makes that explicit.1IAASB. Auditor’s Responsibility to Consider Fraud in an Audit of Financial Statements – ISA 240
Skepticism means paying attention to contradictory information, questioning the reliability of documents, and probing management’s explanations for unusual transactions. When something does not add up, the auditor is expected to dig deeper rather than rationalize it away.
Before fieldwork begins, ISA 240 requires the engagement team to hold a discussion about where the entity’s financial statements are vulnerable to material misstatement from fraud. The discussion pools the team’s knowledge about the entity, its industry, and its people, and works through how fraud could actually be committed and concealed in this specific organization. It must cover both fraudulent financial reporting and asset misappropriation, and the engagement partner must consider what to communicate to team members who were not part of the conversation.1IAASB. Auditor’s Responsibility to Consider Fraud in an Audit of Financial Statements – ISA 240
Assessing Fraud Risk
ISA 240 centers its risk assessment on three conditions that tend to be present when fraud occurs:
- Incentive or pressure. A reason to commit fraud. Pressure to meet earnings targets, debt covenants, or performance-based compensation can push management toward manipulation. Employees facing personal financial difficulties may be tempted toward theft.
- Opportunity. A gap in controls that makes fraud possible. Weak oversight by those charged with governance, poor segregation of duties, complex transactions that are hard to monitor, and inadequate internal controls all create openings.
- Rationalization. A way to justify the act internally. Management’s attitude toward controls matters here. Aggressive interpretations of accounting rules, a dismissive tone about compliance, or a culture that tolerates corner-cutting can signal a higher likelihood of rationalized dishonesty.
Fraud risk assessment is not a one-time exercise. ISA 240 treats it as ongoing throughout the audit, and new information obtained during fieldwork can change the assessment.
The Revenue Recognition Presumption
ISA 240 establishes a rebuttable presumption that fraud risks exist in revenue recognition. Revenue is the line item most commonly manipulated in fraudulent reporting schemes. The auditor must evaluate which types of revenue, which transactions, and which assertions give rise to fraud risk. For entities with straightforward revenue streams the presumption can be rebutted, but the rationale must be documented.
The Management Override Presumption
The second mandatory presumption is that management override of controls exists in every entity, regardless of how good the internal controls are. Management can manipulate records, prepare fraudulent entries, and override otherwise effective controls in ways that are hard to predict. ISA 240 treats this as a significant risk that cannot be reduced through normal assessment, which triggers three mandatory procedures.2International Federation of Accountants. International Standard on Auditing 240 – The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
Three Mandatory Procedures for Management Override
Because management override cannot be assessed away, ISA 240 requires three specific procedures regardless of the auditor’s overall fraud risk conclusions.2International Federation of Accountants. International Standard on Auditing 240 – The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
Testing Journal Entries and Adjustments
The auditor must test whether journal entries and other adjustments recorded in preparing the financial statements are appropriate. Focus falls on entries that look unusual: entries outside the normal course of business, entries recorded by people who do not typically process them, and entries posted near the end of the reporting period when pressure to hit targets is highest. The standard requires the auditor to make inquiries of individuals involved in the financial reporting process about any inappropriate or unusual activity, to specifically select entries made at the end of the reporting period, and to consider whether testing should extend throughout the year. Data analytics and computer-assisted techniques can help surface patterns that manual review would miss.2International Federation of Accountants. International Standard on Auditing 240 – The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
Reviewing Accounting Estimates for Bias
Management exercises significant judgment on estimates like asset impairment, loan loss reserves, warranty provisions, and fair value measurements. That discretion creates room to tilt results. ISA 240 requires the auditor to evaluate whether management’s judgments and assumptions, even if individually reasonable, reveal a pattern of bias when taken together. A key part of this procedure is retrospective: the auditor must look back at estimates management made in prior years and compare them to what actually happened.2International Federation of Accountants. International Standard on Auditing 240 – The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
Evaluating Business Rationale for Unusual Transactions
The third mandatory procedure targets significant transactions outside the entity’s normal business operations or that otherwise appear unusual. The auditor must evaluate whether the business rationale for these transactions, or the lack of one, suggests they were entered into to manipulate financial reporting or conceal stolen assets. Transactions with related parties, transactions structured with unusual complexity, and transactions occurring right before the reporting date deserve particular scrutiny. A transaction with no clear economic benefit to the entity is a red flag.2International Federation of Accountants. International Standard on Auditing 240 – The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
Building Unpredictability Into the Audit
ISA 240 requires auditors to build an element of unpredictability into their procedures. If the team follows the same playbook every year, testing the same accounts, visiting the same locations, and asking the same questions at the same time, anyone planning fraud can work around it. Unpredictability might mean selecting different samples than in prior years, adjusting the timing of procedures without warning, testing accounts or locations that would not normally be high priority, or using unexpected analytical approaches.
What the Auditor Must Do When Fraud Is Identified or Suspected
When the auditor identifies fraud or obtains information suggesting fraud may exist, ISA 240 triggers specific communication obligations, even for matters that seem minor. A small fraud can point to a larger control breakdown or a cultural problem.
Communication Inside the Entity
Fraud involving lower-level employees is communicated to a management level above the person involved, unless that manager is suspected of participation. Where fraud involves senior management or causes a material misstatement, the auditor must report directly to those charged with governance. The communication must cover the nature of the fraud, its scope, and its implications for the financial statements and the control environment. The auditor must also consider whether identified fraud changes the assessment of other audit areas, because a scheme in one division can indicate weaknesses that reach the whole entity.
Effect on the Audit Opinion
If fraud produces a material misstatement in the financial statements and management does not correct it, the auditor must modify the opinion. The modification may be a qualified opinion or an adverse opinion, depending on how pervasive the effect is. A single misstated line item that can be isolated may warrant a qualification. A pervasive scheme affecting multiple areas typically leads to an adverse opinion.
Withdrawal From the Engagement
In extreme cases where circumstances make continuing the audit untenable, ISA 240 permits the auditor to consider withdrawing. Before doing so, the auditor must determine the professional and legal responsibilities that apply, discuss the withdrawal and its reasons with management and those charged with governance, and assess whether there is a legal obligation to report the withdrawal to regulators or the person who appointed the auditor.3International Federation of Accountants. International Standard on Auditing 240 – The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements
External Reporting and the Confidentiality Boundary
The auditor’s duty of confidentiality generally prevents reporting fraud to parties outside the entity. In many jurisdictions, however, laws or regulations require the auditor to report fraud to external authorities, such as financial regulators or enforcement agencies, and those legal obligations override confidentiality. The auditor must assess the applicable legal framework before making any external disclosure.
What Changes Under the 2026 Revision
The IAASB approved a revised ISA 240 that takes effect for audits of financial statements covering periods beginning on or after December 15, 2026, with early adoption encouraged. The revision does not overhaul the fundamental framework. It sharpens several existing requirements.4IAASB. IAASB Revises Fraud Standard to Enhance Public Trust
- Clearer responsibilities. The revised standard more precisely defines what auditors are expected to do when addressing fraud risk, reducing ambiguity.
- Reinforced professional skepticism. New requirements elevate skepticism expectations across all stages of the audit, not just planning.
- A fraud lens for risk assessment. Auditors must apply a more focused fraud perspective when identifying and assessing risks, with stronger links to ISA 315 on risk identification.
- Clearer fraud responses. A new section establishes enhanced requirements for how auditors respond when they actually identify or suspect fraud during the engagement.
- Greater transparency. The revised standard emphasizes timelier communication with management and those charged with governance, along with clearer disclosures in auditor’s reports for publicly traded entities.
For audit firms, the transition means updating methodologies, training teams on the enhanced skepticism and response requirements, and revising audit report templates before the effective date.5IAASB. ISA 240 (Revised) – The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements