
- Introduction
SA 240 prescribes the auditor’s responsibilities relating to fraud in an audit of financial statements.
The standard requires the auditor to consider fraud while planning and performing the audit and to obtain reasonable assurance that the financial statements are free from material misstatement, whether caused by fraud or error.
However, the standard clearly recognizes that fraud is inherently difficult to detect, particularly when it involves collusion or management override of controls.
- Meaning of Fraud
Fraud refers to an intentional act of deception committed by:
- Management,
- Those charged with governance,
- Employees, or
- Third parties,
which results in a misstatement in the financial statements.
Thus, intent is the key distinguishing factor between fraud and error.
- Types of Intentional Misstatements
SA 240 identifies two types of intentional misstatements that are relevant to the auditor:
- a) Fraudulent Financial Reporting
This involves intentional misstatements or omissions designed to deceive users of financial statements, such as:
- Manipulation or falsification of accounting records
- Misrepresentation or omission of significant information
- Intentional misapplication of accounting principles
- b) Misappropriation of Assets
This involves theft of an entity’s assets, often accompanied by false records to conceal the theft, such as:
- Theft of cash or inventory
- Fraudulent expense claims
- Payroll fraud
- Responsibility for Prevention and Detection of Fraud
Primarily, management and those charged with governance bear the responsibility for prevention and detection of fraud.
Accordingly, management, under the oversight of those charged with governance, must:
- Establish a strong control environment
- Implement effective internal controls
- Emphasize ethical behavior and integrity
- Reduce opportunities for fraud and act as a deterrent
- Auditor’s Overall Responsibility
The auditor’s responsibility is to obtain reasonable assurance that the financial statements as a whole are free from material misstatement due to fraud or error.
Nevertheless:
- The auditor does not guarantee detection of all frauds
- Fraud involving management override of controls poses a higher detection risk
- Misstatements in judgmental areas, such as accounting estimates, are difficult to evaluate
- Risk of Not Detecting Fraud
The risk of non-detection is higher for management fraud than employee fraud because management is often in a position to:
- Manipulate accounting records
- Override internal controls
- Influence financial reporting processes
Therefore, the auditor must remain particularly alert to management-related fraud risks.
- Professional Skepticism
Throughout the audit, the auditor must maintain an attitude of professional skepticism.
This means the auditor should:
- Maintain a questioning mind
- Critically assess audit evidence
- Remain alert to conditions indicating possible fraud
- Recognize that audit procedures effective for detecting errors may not be effective for detecting fraud
Importantly, the auditor must always consider the possibility of management override of controls.
- Identification and Assessment of Fraud Risks
The auditor shall identify and assess risks of material misstatement due to fraud at:
- The financial statement level, and
- The assertion level for classes of transactions, account balances, and disclosures
For this purpose, the auditor shall:
- Make appropriate inquiries of management
- Discuss fraud risks with those charged with governance, as they oversee:
- Financial reporting
- Internal control systems
- Compliance with laws and regulations
- Auditor’s Responses to Assessed Fraud Risks
After assessing fraud risks, the auditor shall:
- Design and implement appropriate audit procedures
- Modify the nature, timing, and extent of audit procedures
- Address risks related to management override of controls, which are presumed to exist in every audit
- Evaluation of Audit Evidence
When the auditor identifies a misstatement, the auditor must evaluate whether:
- The misstatement indicates fraud
- Similar misstatements may exist elsewhere
- Management representations remain reliable
Thus, a single fraud may cast doubt on the integrity of management.
- Communication of Fraud
When the auditor identifies or suspects fraud, the auditor should communicate the matter to:
- Management, and
- Those charged with governance
Further, when laws or regulations require, the auditor must also communicate such matters to:
- Regulatory authorities, or
- Enforcement agencies
- Written Representations
The auditor shall obtain written representations from management confirming that:
- Management acknowledges responsibility for prevention and detection of fraud
- Management has disclosed all known or suspected frauds
- Management has disclosed any allegations of fraud received from employees or others
- Documentation
The auditor shall document:
- The understanding of the entity and its environment
- Fraud risk assessment and related judgments
- Audit procedures performed in response to fraud risks
- Communications with management, those charged with governance, regulators, and others
- Conclusion
In conclusion, SA 240 reinforces that:
- Management bears primary responsibility for fraud prevention and detection
- The auditor plays a crucial role by maintaining professional skepticism
- Proper risk assessment, appropriate audit responses, and effective communication ensure audit quality
