Auditing & Assurance
Fraud & Error Responsibilities
The distinguishing factor is intent. Error is an unintentional misstatement (a mistake in gathering/processing data, an incorrect estimate, or a misapplication of accounting). Fraud is an intentional act by one or more individuals involving deception to obtain an unjust or illegal advantage. Both can cause material misstatement; fraud is harder to detect because it's concealed.
Real-world example
A miskeyed figure is an error; deliberately booking fictitious sales to hit targets is fraud.
Audit Risk & Materiality
ISA Standards
Fraud & Error Responsibilities
ISA 240 identifies fraudulent financial reporting (intentional misstatement of the financial statements, e.g., overstating revenue or assets to mislead users) and misappropriation of assets (theft of the entity's assets, e.g., stealing cash or inventory, often concealed by falsified records). Auditors consider both, though financial-reporting fraud usually has the larger statement impact.
Real-world example
Overstating earnings to boost the share price is fraudulent financial reporting; an employee stealing petty cash is misappropriation.
Audit Risk & Materiality
Internal Controls Evaluation
Fraud & Error Responsibilities
The primary responsibility for preventing and detecting fraud rests with those charged with governance and management, through a strong control environment and effective internal controls. The auditor is responsible for obtaining reasonable assurance the statements are free of material misstatement from fraud or error—but is not primarily responsible for fraud prevention.
Real-world example
Management builds anti-fraud controls; the auditor independently seeks reasonable assurance the statements aren't materially misstated by fraud.
Audit Objectives & Types
Internal Controls Evaluation
Fraud & Error Responsibilities
The fraud triangle describes three conditions generally present when fraud occurs: incentive/pressure (a reason to commit fraud, e.g., targets, personal debt), opportunity (a way to do it, e.g., weak controls or override ability), and rationalization/attitude (justifying the act). Auditors use it to identify fraud risk factors during risk assessment.
Fraud triangle: Incentive/Pressure + Opportunity + Rationalization.
Real-world example
Aggressive bonus targets (pressure), weak controls (opportunity), and a 'everyone does it' attitude (rationalization) flag high fraud risk.
Audit Risk & Materiality
Internal Controls Evaluation
Fraud & Error Responsibilities
ISA 240 requires the auditor to maintain professional skepticism, discuss fraud susceptibility within the team, perform risk assessment procedures to identify fraud risks, presume a fraud risk in revenue recognition, respond with appropriate procedures, specifically address management override (test journal entries, review estimates for bias, evaluate unusual significant transactions), and obtain written representations.
Real-world example
Following ISA 240, the team holds a fraud brainstorming session and designs journal-entry testing to counter override risk.
ISA Standards
Audit Evidence & Procedures
Fraud & Error Responsibilities
ISA 240 presumes fraud risk in revenue recognition because revenue is the primary performance metric users focus on, giving strong incentives to manipulate it (premature or fictitious sales, channel stuffing, holding books open). Its volume and cutoff sensitivity create opportunity. Auditors must specifically address this presumption or document why it doesn't apply.
Real-world example
The auditor tests period-end cutoff and reviews late contracts because revenue is a presumed fraud risk under ISA 240.
Audit Evidence & Procedures
Audit Risk & Materiality
Fraud & Error Responsibilities
Because management can override even effective controls, ISA 240 requires specific procedures regardless of assessed risk: testing the appropriateness of journal entries and other adjustments (especially unusual, large, or late ones), reviewing accounting estimates for bias (retrospective review of prior estimates), and evaluating the business rationale for significant unusual transactions. Unpredictability in procedures also helps.
Real-world example
A retrospective review of last year's estimates reveals a consistent optimistic bias, indicating possible management manipulation.
Internal Controls Evaluation
Audit Evidence & Procedures
Fraud & Error Responsibilities
Fraud risk factors are events or conditions indicating incentive/pressure, opportunity, or rationalization. Examples: pressure to meet analyst forecasts or debt covenants, management compensation tied heavily to results, weak controls or dominant management, complex or related-party transactions, high staff turnover in accounting, and a history of aggressive accounting or override.
Real-world example
A dominant CEO, thin controls, and bonus-driven targets together constitute strong fraud risk factors.
Audit Risk & Materiality
Internal Controls Evaluation
Fraud & Error Responsibilities
Evaluate the implications for the audit (reliability of representations and evidence, reassess risks), perform additional procedures, and communicate on a timely basis to the appropriate level of management and those charged with governance (and, if it involves senior management, directly to governance). Consider legal/regulatory reporting duties, and whether to withdraw. Document thoroughly.
Real-world example
On finding evidence of manipulated revenue, the auditor extends testing, informs the audit committee, and reassesses management's integrity.
Audit Report & Opinions
Ethics & Independence
Fraud & Error Responsibilities
Fraud undermines the reliability of audit evidence and management representations, so the auditor must reconsider the integrity of management, reassess risks of material misstatement across the statements (fraud rarely occurs in isolation), extend or redesign procedures, and consider whether previously obtained evidence is still reliable. It may lead to a modified opinion or withdrawal.
Real-world example
After uncovering one fraudulent scheme, the team re-examines related estimates and disclosures, suspecting pervasive manipulation.
Audit Report & Opinions
Audit Risk & Materiality
Fraud & Error Responsibilities