Fraud Audits Are Becoming More Stringent: What Will the New ISA 240 Bring?

8/25/2026
Fraud Audits Are Becoming More Stringent: What Will the New ISA 240 Bring?

Auditors will be expected to assess fraud risk more thoroughly, communicate more regularly with management, and, in the case of publicly traded companies, provide more transparent audit reports. The revised ISA 240 also sends an important message to company management: fraud prevention and detection are not solely the auditor’s responsibility. 

Fraud is no longer a peripheral issue in auditing


Fraud in financial reporting can take many forms – from intentional manipulation of revenue or expenses to the overstatement of assets, to the circumvention of internal controls. In multinational companies, the situation is complicated by the multitude of systems, transactions, and responsible parties across different countries. Identifying an irregular transaction may therefore not be easy, even for a well-organized finance department.

ISA 240 (Revised) – The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements – responds precisely to the growing expectations of the public and users of financial statements. The revised International Standard on Auditing will apply to audits of financial statements for periods beginning on or after December 15, 2026, with earlier application permitted. For a company with a calendar fiscal year, this means in practice that the first financial statements audited under the revised standard will be those for the year 2027, i.e., the audit to be conducted in 2028.

What is changing in fraud audits? 

One of the main objectives of the revised ISA 240 is to strengthen auditors’ consistent approach to fraud risk. Greater emphasis is placed on professional skepticism, the identification and assessment of fraud risks, and the auditor’s subsequent response. The standard introduces the so-called “fraud lens” – a requirement to assess fraud risk systematically at all stages of the audit and in conjunction with other standards, particularly those related to risk assessment and internal controls.

Responses to identified or suspected fraud are now addressed in a separate section of the standard, which, among other things, clarifies the procedure for fraud committed by a third party. Another new feature is the so-called “stand-back” review at the conclusion of the audit. The auditor must assess whether the evidence obtained is truly sufficient and whether the audit procedures were designed in a biased manner, for example, to confirm an expected outcome. For the company, this means that questions regarding fraud do not end with audit planning – they may also arise during the final phase of the audit.

In practice, we can expect a more detailed discussion of where and how fraud might occur within the company, which individuals have the ability to circumvent established controls, and whether there are circumstances creating pressure or motivation to manipulate financial results. This does not automatically mean that every audit will be significantly more extensive. It does mean, however, that the assessment of fraud risk will be an even more visible and systematic part of the audit.

The auditor will ask more questions


Fraud Audits Are Becoming More Stringent: What Will the New ISA 240 Bring?

Management and finance departments should prepare for more specific questions. For example, the auditor will be interested in:

  • how the company identifies fraud risks,
  • what internal controls it has in place,
  • how it addresses suspicions of irregular conduct,
  • how management monitors the functioning of the control environment.

Attention may also focus on transactions outside the normal business model, manual accounting entries, significant management estimates, related-party transactions, or unusual transactions carried out shortly before the end of the reporting period. The timing of communication will also change. The revised standard calls for ongoing two-way dialogue with management and those charged with governance throughout the audit, not just initial inquiries and a final management letter. If a suspicion or a significant control failure arises during the year, the issue is addressed immediately, rather than waiting several months. For international groups, a specific issue may also be the varying levels of internal controls across individual subsidiaries or countries.

The auditor’s report will also change 

For publicly traded companies and public interest entities, the revised ISA 240 brings greater transparency directly to the auditor’s report – a clearer description of the auditor’s responsibilities regarding fraud and a more understandable link to key audit matters when they relate to fraud risk. This is the only change that readers of financial statements – such as banks, investors, or business partners – will notice. That is precisely why companies that actively use their financial statements for financing purposes should also pay attention to this area.

ISA 240 does not stand alone 

The revised ISA 240, together with ISA 570 (Revised 2024) on going concern, forms a single package—both standards take effect on the same date, and the IAASB presents them as an interconnected pair. The reason is logical: fraud and financial difficulties often occur together in practice, because pressure to deliver results tends to be stronger precisely when a company is struggling.

Who is actually responsible for detecting fraud?


The primary responsibility for preventing and detecting fraud lies with the company’s management and those charged with governance. The auditor’s role is to obtain reasonable assurance that the financial statements as a whole are free from material misstatement due to fraud or error. An audit is therefore not an investigation of every potential instance of fraud and does not provide an absolute guarantee that every instance of fraud will be detected. However, the revised ISA 240 strengthens the way in which the auditor assesses the risk of fraud and responds to identified risks. For management, this means that the argument “the auditor should have caught that” will not be a substitute for a high-quality system of internal controls.

Data and internal controls will take on greater importance 

Modern auditing increasingly relies on data analytics. Instead of reviewing a relatively small number of documents, with the right data, we can analyze large populations of transactions and identify non-standard patterns. Typical red flags may include unusual manual journal entries, transactions executed outside standard business hours, repeatedly rounded amounts, unusual changes to supplier information, or accounting transactions performed just before the closing date.

It should be noted that the standard itself does not prescribe specific technologies—this is a development in auditing practice that, however, aligns well with the revised ISA 240’s emphasis on the systematic search for anomalies. Furthermore, technology alone cannot detect fraud. It alerts us to an anomaly, which we must then evaluate in the context of the business, internal processes, and other audit evidence.

What should companies do before the new ISA 240 takes effect? 

We recommend not waiting until the first audit under the revised standard. We can already verify whether a company has clearly defined fraud risks and whether existing controls effectively address these risks. We should pay particular attention to approval authorities, the division of responsibilities, manual accounting entries, access rights to ERP systems, the process for changing suppliers’ bank details, and mechanisms for reporting suspicious behavior. It is equally important that control mechanisms do not exist merely “on paper.” The auditor will also be interested in whether controls are actually being carried out and whether there is relevant evidence of their implementation.

The new standard is an opportunity to view the company through the eyes of a fraudster 

We need not view the revised ISA 240 merely as another regulatory requirement. For management, it can serve as an impetus to identify weaknesses in financial processes before anyone exploits them. The question, therefore, is not just “Can our auditor detect fraud?” but, above all, “As a company, can we effectively prevent it?”

Prepare for the audit well in advance

If you are unsure whether your internal controls, processes, and documentation are ready to meet the requirements of the revised ISA 240, please contact us. Together, we can identify areas of risk and organize your audit preparation so that the new standard does not result in any unpleasant surprises in your next financial statements.

Learn more