Fraud in financial reporting can take many forms – from intentional manipulation of revenue or expenses to the overstatement of assets, to the circumvention of internal controls. In multinational companies, the situation is complicated by the multitude of systems, transactions, and responsible parties across different countries. Identifying an irregular transaction may therefore not be easy, even for a well-organized finance department.
ISA 240 (Revised) – The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements – responds precisely to the growing expectations of the public and users of financial statements. The revised International Standard on Auditing will apply to audits of financial statements for periods beginning on or after December 15, 2026, with earlier application permitted. For a company with a calendar fiscal year, this means in practice that the first financial statements audited under the revised standard will be those for the year 2027, i.e., the audit to be conducted in 2028.
One of the main objectives of the revised ISA 240 is to strengthen auditors’ consistent approach to fraud risk. Greater emphasis is placed on professional skepticism, the identification and assessment of fraud risks, and the auditor’s subsequent response. The standard introduces the so-called “fraud lens” – a requirement to assess fraud risk systematically at all stages of the audit and in conjunction with other standards, particularly those related to risk assessment and internal controls.
Responses to identified or suspected fraud are now addressed in a separate section of the standard, which, among other things, clarifies the procedure for fraud committed by a third party. Another new feature is the so-called “stand-back” review at the conclusion of the audit. The auditor must assess whether the evidence obtained is truly sufficient and whether the audit procedures were designed in a biased manner, for example, to confirm an expected outcome. For the company, this means that questions regarding fraud do not end with audit planning – they may also arise during the final phase of the audit.
In practice, we can expect a more detailed discussion of where and how fraud might occur within the company, which individuals have the ability to circumvent established controls, and whether there are circumstances creating pressure or motivation to manipulate financial results. This does not automatically mean that every audit will be significantly more extensive. It does mean, however, that the assessment of fraud risk will be an even more visible and systematic part of the audit.
Management and finance departments should prepare for more specific questions. For example, the auditor will be interested in:
Attention may also focus on transactions outside the normal business model, manual accounting entries, significant management estimates, related-party transactions, or unusual transactions carried out shortly before the end of the reporting period. The timing of communication will also change. The revised standard calls for ongoing two-way dialogue with management and those charged with governance throughout the audit, not just initial inquiries and a final management letter. If a suspicion or a significant control failure arises during the year, the issue is addressed immediately, rather than waiting several months. For international groups, a specific issue may also be the varying levels of internal controls across individual subsidiaries or countries.
For publicly traded companies and public interest entities, the revised ISA 240 brings greater transparency directly to the auditor’s report – a clearer description of the auditor’s responsibilities regarding fraud and a more understandable link to key audit matters when they relate to fraud risk. This is the only change that readers of financial statements – such as banks, investors, or business partners – will notice. That is precisely why companies that actively use their financial statements for financing purposes should also pay attention to this area.
The revised ISA 240, together with ISA 570 (Revised 2024) on going concern, forms a single package—both standards take effect on the same date, and the IAASB presents them as an interconnected pair. The reason is logical: fraud and financial difficulties often occur together in practice, because pressure to deliver results tends to be stronger precisely when a company is struggling.
The primary responsibility for preventing and detecting fraud lies with the company’s management and those charged with governance. The auditor’s role is to obtain reasonable assurance that the financial statements as a whole are free from material misstatement due to fraud or error. An audit is therefore not an investigation of every potential instance of fraud and does not provide an absolute guarantee that every instance of fraud will be detected. However, the revised ISA 240 strengthens the way in which the auditor assesses the risk of fraud and responds to identified risks. For management, this means that the argument “the auditor should have caught that” will not be a substitute for a high-quality system of internal controls.
It should be noted that the standard itself does not prescribe specific technologies—this is a development in auditing practice that, however, aligns well with the revised ISA 240’s emphasis on the systematic search for anomalies. Furthermore, technology alone cannot detect fraud. It alerts us to an anomaly, which we must then evaluate in the context of the business, internal processes, and other audit evidence.