ISA 240
The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements
1Objective and scope
ISA 240 deals with the auditor's responsibilities relating to fraud in an audit of financial statements, expanding on how ISA 315 and ISA 330 are applied to the risks of material misstatement due to fraud. Two types of intentional misstatement are relevant to the auditor: misstatements resulting from fraudulent financial reporting and misstatements resulting from misappropriation of assets. The primary responsibility for the prevention and detection of fraud rests with those charged with governance and management; the auditor is responsible for obtaining reasonable assurance that the financial statements as a whole are free from material misstatement, whether caused by fraud or error. A revised ISA 240, strengthening the requirements on scepticism, the fraud risk assessment and communication with those charged with governance and adding fraud-related transparency to the auditor's report, is effective for periods beginning on or after 15 December 2026.
The objectives are to identify and assess the risks of material misstatement due to fraud, to obtain sufficient appropriate evidence about those risks through designing and implementing appropriate responses, and to respond appropriately to fraud or suspected fraud identified during the audit. Because fraud is concealed, the risk of not detecting a material misstatement due to fraud is higher than for error, and higher for management fraud than employee fraud.
2Key definitions
3Requirements
Scepticism, discussion and risk assessment
- Maintain professional scepticism throughout the audit, recognising the possibility of material misstatement due to fraud notwithstanding past experience of the honesty and integrity of management. Unless there is reason to believe otherwise, records may be accepted as genuine, but if conditions cast doubt, investigate further.
- Hold a discussion among the engagement team (ISA 315) that places particular emphasis on how and where the financial statements may be susceptible to fraud, including how management could perpetrate and conceal it, setting aside beliefs that management is honest.
- Make inquiries of management about its assessment of the risk of fraud, its process for identifying and responding to fraud risks, its communication with those charged with governance and employees on the subject, and its knowledge of any actual, suspected or alleged fraud. Make inquiries of internal audit and of those charged with governance about their oversight and knowledge of fraud.
- Evaluate whether unusual or unexpected relationships identified in analytical procedures, including those on revenue, indicate fraud risk, and consider whether other information obtained and the fraud risk factors present indicate risks of material misstatement due to fraud.
- Identify and assess the risks of material misstatement due to fraud at the financial statement level and the assertion level, treating them as significant risks, and obtain an understanding of the entity's related controls.
- Presume that there are risks of fraud in revenue recognition, and evaluate which types of revenue, revenue transactions or assertions give rise to such risks; where the presumption is rebutted, document the reasons.
Responses to the assessed risks
At the financial statement level the auditor determines overall responses: assigning and supervising personnel with appropriate skills (forensic or IT specialists), evaluating whether the selection and application of accounting policies, particularly in subjective areas, indicate fraudulent reporting, and incorporating unpredictability into the nature, timing and extent of procedures (unannounced visits, testing low-value balances, varying sample methods). At the assertion level the nature, timing and extent of procedures are altered: more reliable evidence, procedures closer to or at period end, larger samples, and more use of computer-assisted techniques.
- Irrespective of the assessed risks, respond to the risk of management override: test the appropriateness of journal entries and other adjustments made in preparing the financial statements (selecting entries at period end and throughout the period, with inquiry of those involved in the process), review accounting estimates for bias and perform a retrospective review of prior-year estimates, and evaluate the business rationale for significant transactions outside the normal course of business.
- Consider whether a misstatement identified is indicative of fraud; if so, evaluate the implications for the rest of the audit, including the reliability of management representations, because an instance of fraud is unlikely to be isolated.
- If the auditor identifies or suspects fraud involving management, employees with significant roles in internal control, or others where the misstatement is material, re-evaluate the assessment of risks, the responses, and the evidence obtained.
- Where the auditor concludes the audit cannot be continued because of fraud (management involvement, doubts about representations), consider the professional and legal responsibilities, including reporting to the appointing party or regulators, and whether withdrawal is appropriate, discussing the reasons with management and those charged with governance.
Written representations
The auditor obtains written representations from management and, where appropriate, those charged with governance that they acknowledge their responsibility for internal control to prevent and detect fraud; that they have disclosed the results of their assessment of the risk of fraud; that they have disclosed their knowledge of fraud or suspected fraud involving management, employees with significant roles in internal control, or others where the fraud could be material; and that they have disclosed allegations of fraud communicated by employees, former employees, analysts, regulators or others.
4Documentation and reporting
- Document the significant decisions from the team discussion on fraud, the identified and assessed fraud risks at both levels, the overall responses and the procedures at the assertion level, the results of the procedures including those addressing management override, communications about fraud made to management, those charged with governance, regulators and others, and, where the revenue presumption is rebutted, the reasons.
- Communicate identified fraud, or information indicating fraud may exist, to the appropriate level of management on a timely basis, and to those charged with governance where the fraud involves management, employees with significant internal control roles, or others where the misstatement is material. Communicate other fraud-related matters relevant to their responsibilities, such as concerns about management's risk assessment or a failure to address deficiencies.
- Consider whether there is a duty to report fraud to a party outside the entity: professional confidentiality may be overridden by law (the Proceeds of Crime and Anti-Money Laundering Act, the Capital Markets Act for listed entities, the Banking Act) or by the public interest, and legal advice may be needed.
- Fraud that results in a material misstatement not corrected leads to a modified opinion under ISA 705; an inability to obtain evidence because of suspected fraud is a limitation on scope. Under the 2026 revision the auditor's report for listed entities will also describe how the auditor addressed fraud risks, in a dedicated section.
5Examinable focus
What KASNEB tests
The fraud triangle (incentive or pressure, opportunity, rationalisation) with examples for each corner is almost guaranteed; so is the distinction between fraudulent financial reporting and misappropriation of assets, and between the responsibilities of management and of the auditor (the expectation gap). Scenario questions describe a bonus scheme tied to profit, a dominant managing director, sales pushed through before year end or a cashier who never takes leave, and ask for fraud risk factors and the auditor's response. State the two presumed risks (revenue recognition and management override) and the three mandatory procedures on override (journal entries, estimates for bias, unusual transactions). Reporting fraud, including confidentiality and the duty to report to regulators, is a common final part of the question.