Fraud can be deliberately concealed through collusion, falsified documentation, complex transactions, or management override of controls. These characteristics make fraud fundamentally different from unintentional error.
ISA 240 (Revised) strengthens the auditor’s responsibilities for addressing fraud risks throughout the financial statement audit. The revised standard applies to periods beginning on or after 15 December 2026, with early adoption permitted.
The revised standard reinforces the need to consider fraud throughout the audit rather than treating it as an isolated planning exercise.
Greater emphasis is placed on:
For audits of publicly traded entities, the revised standard also provides greater transparency in auditor reporting about fraud-related responsibilities and procedures.
The revised requirements do not convert every financial statement audit into a forensic investigation.
The auditor’s objective remains to obtain reasonable assurance that the financial statements are free from material misstatement, whether caused by fraud or error. The risk of failing to detect a material misstatement resulting from fraud is higher because fraud may involve deliberate concealment or collusion.
A forensic or investigative engagement has a different purpose, scope, evidential approach, and reporting structure. It may become appropriate when specific allegations, indicators, or suspected schemes require focused investigation.
Management and those charged with governance retain primary responsibility for preventing and detecting fraud.
An effective anti-fraud framework should include:
Entities should not wait for the external audit to identify weaknesses that management could reasonably detect through effective controls and oversight.
Financial pressure can increase incentives to manipulate revenue, defer expenses, conceal liabilities, overstate assets, or apply optimistic estimates.
Boards and audit committees should consider how liquidity constraints, covenant pressure, declining performance, financing uncertainty, or management remuneration may affect fraud risk.
The interaction between fraud risk and going concern is consequently important. Assumptions used in forecasts and estimates should be consistent, transparent, and supported by evidence.
Organizations can prepare by reassessing fraud risks, strengthening documentation, reviewing controls over management estimates and journals, and ensuring that concerns can be escalated without interference.
Those charged with governance should also establish clear communication with the external auditor and understand significant fraud risks, audit responses, identified control deficiencies, and management’s remediation actions.
The revised standard sharpens the audit response to fraud risk.. but credible prevention and detection begin within the organization.