📄 PDF — HKICPA Handbook Vol III (Code of Ethics)

Open PDF →" data-zh="不支援PDF檢視。打開PDF →">PDF viewer not supported.

🎥 Video Lesson (Coming Soon)
🎬HKSA 240 - Responsibilities Relating to Fraud walkthrough video coming soon.

HKSA 240 - The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements

Ad Space
Ad Space
Ad Space

1. Introduction and Scope

1.1 Scope of HKSA 240

HKSA 240 deals with the auditor's responsibilities relating to fraud in an audit of financial statements. It expands on how HKSA 315 (Revised 2019) and HKSA 330 are to be applied in relation to risks of material misstatement due to fraud.

Effective Date: This HKSA is effective for audits of financial statements for periods beginning on or after 15 December 2009.

1.2 Characteristics of Fraud

Definition of Fraud (Paragraph 12(a)):

Fraud – An intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage.

Distinction between Fraud and Error (Paragraph 2):

  • The distinguishing factor between fraud and error is whether the underlying action that results in the misstatement of the financial statements is intentional or unintentional.
  • Two Types of Intentional Misstatements Relevant to the Auditor (Paragraph 3):

    TypeDescription
    Fraudulent Financial ReportingIntentional misstatements including omissions of amounts or disclosures in financial statements to deceive financial statement users
    Misappropriation of AssetsTheft of an entity's assets, often perpetrated by employees in relatively small and immaterial amounts, but can also involve management

    Important Note: The auditor does not make legal determinations of whether fraud has actually occurred, even though the auditor may suspect or, in rare cases, identify the occurrence of fraud.

    1.3 Three Conditions Generally Present When Fraud Exists (Paragraph A1)

    ConditionDescription
    Incentive or PressureManagement under pressure to achieve expected earnings targets; individuals living beyond their means
    Perceived OpportunityIndividual believes internal control can be overridden; knowledge of specific deficiencies in internal control
    RationalizationAttitude, character, or set of ethical values that allow knowingly and intentionally committing a dishonest act

    Ad Space

    2. Responsibility for Prevention and Detection of Fraud

    2.1 Primary Responsibility (Paragraph 4)

    Primary responsibility for the prevention and detection of fraud rests with both:

  • Those charged with governance of the entity
  • Management
  • Management's Responsibilities:

  • Place strong emphasis on fraud prevention (reduces opportunities for fraud)
  • Place strong emphasis on fraud deterrence (persuades individuals not to commit fraud due to likelihood of detection and punishment)
  • Create a culture of honesty and ethical behavior
  • This commitment is reinforced by active oversight by those charged with governance
  • Oversight by Those Charged with Governance Includes:

  • Considering the potential for override of controls
  • Considering other inappropriate influence over the financial reporting process
  • Considering efforts by management to manage earnings to influence perceptions of analysts
  • 2.2 Responsibilities of the Auditor (Paragraphs 5-8)

    The Auditor's Objective:

    An auditor conducting an audit in accordance with HKSAs is responsible for obtaining reasonable assurance that the financial statements taken as a whole are free from material misstatement, whether caused by fraud or error.

    Key Points:

  • Owing to inherent limitations of an audit, there is an unavoidable risk that some material misstatements may not be detected
  • The risk of not detecting a material misstatement resulting from fraud is higher than the risk of not detecting one resulting from error
  • Fraud may involve sophisticated and carefully organized schemes designed to conceal it (forgery, deliberate failure to record transactions, intentional misrepresentations)
  • Collusion makes detection even more difficult
  • The auditor's ability to detect fraud depends on: skillfulness of perpetrator, frequency and extent of manipulation, degree of collusion, relative size of individual amounts manipulated, seniority of individuals involved
  • Management Fraud vs. Employee Fraud (Paragraph 7):

    The risk of the auditor not detecting a material misstatement resulting from management fraud is greater than for employee fraud, because management is frequently in a position to directly or indirectly manipulate accounting records, present fraudulent financial information or override controls designed to prevent similar frauds by other employees.

    Auditor's Responsibilities When Obtaining Reasonable Assurance (Paragraph 8):

  • Maintain professional skepticism throughout the audit
  • Consider the potential for management override of controls
  • Recognize that audit procedures effective for detecting error may not be effective in detecting fraud
  • 2.3 Additional Responsibilities Under Law or Regulation (Paragraph 9)

    The auditor may have additional responsibilities under law, regulation or relevant ethical requirements regarding an entity's non-compliance with laws and regulations, including fraud, which may differ from or go beyond HKSAs:

    ResponsibilityDescription
    Responding to identified or suspected non-complianceIncluding requirements for specific communications with management and those charged with governance
    Assessing appropriateness of responseEvaluating management's response to non-compliance and determining whether further action is needed
    Communicating to other auditorsIn group audit situations
    Documentation requirementsRegarding identified or suspected non-compliance with laws and regulations

    Ad Space

    3. Objectives (Paragraph 11)

    The objectives of the auditor are:

    ObjectiveDescription
    (a)To identify and assess the risks of material misstatement of the financial statements due to fraud
    (b)To obtain sufficient appropriate audit evidence regarding the assessed risks of material misstatement due to fraud, through designing and implementing appropriate responses
    (c)To respond appropriately to fraud or suspected fraud identified during the audit

    Ad Space

    4. Definitions (Paragraph 12)

    TermDefinition
    FraudAn intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage
    Fraud risk factorsEvents or conditions that indicate an incentive or pressure to commit fraud or provide an opportunity to commit fraud

    Ad Space

    5. Requirements - Professional Skepticism (Paragraphs 13-15)

    5.1 Maintaining Professional Skepticism (Paragraph 13)

    In accordance with HKSA 200, the auditor shall maintain professional skepticism throughout the audit, recognizing the possibility that a material misstatement due to fraud could exist, notwithstanding the auditor's past experience of the honesty and integrity of the entity's management and those charged with governance.

    Key Points (Paragraph A8-A9):

  • Requires an ongoing questioning of whether information and audit evidence obtained suggests that a material misstatement due to fraud may exist
  • Includes considering the reliability of information to be used as audit evidence
  • Particularly important when considering risks of material misstatement due to fraud
  • Auditor cannot be expected to disregard past experience, but professional skepticism is important because circumstances may have changed
  • 5.2 Authenticity of Documents (Paragraph 14)

    Unless the auditor has reason to believe the contrary, the auditor may accept records and documents as genuine. If conditions identified during the audit cause the auditor to believe that a document may not be authentic or that terms in a document have been modified but not disclosed to the auditor, the auditor shall investigate further.

    Possible Procedures to Investigate Further (Paragraph A10):

  • Confirming directly with the third party
  • Using the work of an expert to assess the document's authenticity
  • 5.3 Inconsistent Responses (Paragraph 15)

    Where responses to inquiries of management or those charged with governance are inconsistent, the auditor shall investigate the inconsistencies.

    Ad Space

    6. Discussion Among the Engagement Team (Paragraph 16)

    6.1 Requirements

    HKSA 315 (Revised 2019) requires a discussion among the engagement team members and a determination by the engagement partner of which matters are to be communicated to those team members not involved in the discussion.

    This discussion shall place particular emphasis on:

  • How and where the entity's financial statements may be susceptible to material misstatement due to fraud
  • How fraud might occur
  • The discussion shall occur setting aside beliefs that the engagement team members may have that management and those charged with governance are honest and have integrity
  • 6.2 Matters to Include in the Discussion (Paragraph A12)

    CategorySpecific Matters
    Susceptibility to FraudHow and where financial statements may be susceptible to material misstatement due to fraud; how management could perpetrate and conceal fraudulent financial reporting; how assets could be misappropriated
    Earnings ManagementCircumstances indicative of earnings management; practices management might follow to manage earnings that could lead to fraudulent financial reporting
    Disclosure PresentationRisk that management may attempt to present disclosures in a manner that obscures proper understanding (too much immaterial information, unclear or ambiguous language)
    Incentives and PressuresKnown external and internal factors creating incentive or pressure to commit fraud; opportunities for fraud; culture enabling rationalization
    Asset MisappropriationManagement's involvement in overseeing employees with access to cash or other assets susceptible to misappropriation
    Behavioral IndicatorsUnusual or unexplained changes in behavior or lifestyle of management or employees
    Professional MindsetImportance of maintaining a proper state of mind regarding the potential for material misstatement due to fraud
    UnpredictabilityHow an element of unpredictability will be incorporated into audit procedures
    Audit ProceduresWhich procedures might be selected; whether certain types are more effective than others
    AllegationsAny allegations of fraud that have come to the auditor's attention
    Management OverrideRisk of management override of controls

    Ad Space

    7. Risk Assessment Procedures and Related Activities (Paragraphs 17-25)

    7.1 Overview

    When performing risk assessment procedures and related activities to obtain an understanding of the entity and its environment, the applicable financial reporting framework and the entity's system of internal control, the auditor shall perform the procedures in paragraphs 18-25 to obtain information for use in identifying the risks of material misstatement due to fraud.

    7.2 Inquiries of Management (Paragraph 18)

    The auditor shall make inquiries of management regarding:

    Inquiry TopicDetails (Ref: Para.)
    (a) Management's assessment of fraud riskNature, extent and frequency of assessments of the risk that financial statements may be materially misstated due to fraud (A13-A14)
    (b) Management's process for identifying and responding to fraud risksIncluding any specific risks identified, classes of transactions, account balances, or disclosures for which fraud risk is likely to exist (A15)
    (c) Communication to those charged with governanceManagement's communication regarding its processes for identifying and responding to fraud risks
    (d) Communication to employeesManagement's communication regarding its views on business practices and ethical behavior

    7.3 Inquiries of Management and Others Within the Entity (Paragraph 19)

    The auditor shall make inquiries of management, and others within the entity as appropriate, to determine whether they have knowledge of any actual, suspected or alleged fraud affecting the entity.

    Examples of Others Within the Entity to Inquire (Paragraph A17):

  • Operating personnel not directly involved in the financial reporting process
  • Employees with different levels of authority
  • Employees involved in initiating, processing or recording complex or unusual transactions
  • Those who supervise or monitor such employees
  • In-house legal counsel
  • Chief ethics officer or equivalent person
  • Person or persons charged with dealing with allegations of fraud
  • 7.4 Inquiries of Internal Audit (Paragraph 20)

    For entities that have an internal audit function, the auditor shall make inquiries of appropriate individuals within the function to determine whether they have knowledge of any actual, suspected or alleged fraud affecting the entity, and to obtain its views about the risks of fraud.

    Specific Activities to Inquire About (Paragraph A19):

  • Procedures performed by the internal audit function during the year to detect fraud
  • Whether management has satisfactorily responded to any findings resulting from those procedures
  • 7.5 Those Charged with Governance (Paragraphs 21-22)

    Understanding Oversight (Paragraph 21):

    Unless all of those charged with governance are involved in managing the entity, the auditor shall obtain an understanding of how those charged with governance exercise oversight of:

  • Management's processes for identifying and responding to the risks of fraud in the entity
  • The controls that management has established to mitigate these risks
  • Inquiries of Those Charged with Governance (Paragraph 22):

    Unless all of those charged with governance are involved in managing the entity, the auditor shall make inquiries of those charged with governance to determine whether they have knowledge of any actual, suspected or alleged fraud affecting the entity. These inquiries are made in part to corroborate the responses to the inquiries of management.

    7.6 Unusual or Unexpected Relationships (Paragraph 23)

    The auditor shall evaluate whether unusual or unexpected relationships that have been identified in performing analytical procedures, including those related to revenue accounts, may indicate risks of material misstatement due to fraud.

    7.7 Other Information (Paragraph 24)

    The auditor shall consider whether other information obtained by the auditor indicates risks of material misstatement due to fraud.

    Sources of Other Information (Paragraph A23):

  • Discussion among team members
  • Information from client acceptance and retention processes
  • Experience gained on other engagements performed for the entity (e.g., review of interim financial information)
  • 7.8 Evaluation of Fraud Risk Factors (Paragraph 25)

    The auditor shall evaluate whether the information obtained from the other risk assessment procedures and related activities performed indicates that one or more fraud risk factors are present.

    Important Note: While fraud risk factors may not necessarily indicate the existence of fraud, they have often been present in circumstances where frauds have occurred and therefore may indicate risks of material misstatement due to fraud.

    Fraud Risk Factors Classification (Paragraph A26):

    CategoryDescription
    Incentive/PressureConditions that create susceptibility to misstatement before consideration of controls
    OpportunityConditions within the entity's system of internal control that provide opportunity to commit fraud
    Attitude/RationalizationConditions that may affect management's attitude or ability to rationalize fraudulent actions

    Ad Space

    8. Identification and Assessment of Risks of Material Misstatement Due to Fraud (Paragraphs 26-28)

    8.1 General Requirements (Paragraph 26)

    In accordance with HKSA 315 (Revised 2019), the auditor shall identify and assess the risks of material misstatement due to fraud:

  • At the financial statement level
  • At the assertion level for classes of transactions, account balances and disclosures
  • 8.2 Presumption of Fraud in Revenue Recognition (Paragraph 27)

    When identifying and assessing the risks of material misstatement due to fraud, the auditor shall, based on a presumption that there are risks of fraud in revenue recognition, evaluate which types of revenue, revenue transactions or assertions give rise to such risks.

    Documentation Requirement (Paragraph 48):

    If the auditor concludes that the presumption is not applicable in the circumstances of the engagement and accordingly has not identified revenue recognition as a risk of material misstatement due to fraud, the auditor shall include in the audit documentation the reasons for that conclusion.

    When the Presumption May Be Rebutted (Paragraph A31):

    For example, the auditor may conclude that there is no risk of material misstatement due to fraud relating to revenue recognition in the case where there is a single type of simple revenue transaction, e.g., leasehold revenue from a single unit rental property.

    Common Revenue Recognition Fraud Schemes (Paragraph A29):

  • Overstatement of revenues: Premature revenue recognition, recording fictitious revenues
  • Understatement of revenues: Improperly shifting revenues to a later period
  • 8.3 Treatment as Significant Risks (Paragraph 28)

    The auditor shall treat those assessed risks of material misstatement due to fraud as significant risks and accordingly, to the extent not already done so, the auditor shall identify the entity's controls that address such risks, and evaluate their design and determine whether they have been implemented.

    Ad Space

    9. Responses to Assessed Risks of Material Misstatement Due to Fraud (Paragraphs 29-34)

    9.1 Overall Responses (Paragraphs 29-30)

    Determining Overall Responses (Paragraph 29):

    In accordance with HKSA 330, the auditor shall determine overall responses to address the assessed risks of material misstatement due to fraud at the financial statement level.

    Components of Overall Responses (Paragraph 30):

    ComponentDescriptionRef: Para.
    (a) Assignment and Supervision of PersonnelAssign and supervise personnel taking account of knowledge, skill and ability of individuals and the auditor's assessment of risksA35-A36
    (b) Evaluation of Accounting PoliciesEvaluate whether selection and application of accounting policies, particularly those related to subjective measurements and complex transactions, may be indicative of fraudulent financial reporting resulting from management's effort to manage earnings-
    (c) UnpredictabilityIncorporate an element of unpredictability in the selection of the nature, timing and extent of audit proceduresA37

    How Overall Conduct Reflects Increased Professional Skepticism (Paragraph A34):

  • Increased sensitivity in the selection of the nature and extent of documentation to be examined in support of material transactions
  • Increased recognition of the need to corroborate management explanations or representations concerning material matters
  • Ways to Incorporate Unpredictability (Paragraph A37):

  • Performing substantive procedures on selected account balances and assertions not otherwise tested due to their materiality or risk
  • Adjusting the timing of audit procedures from that otherwise expected
  • Using different sampling methods
  • Performing audit procedures at different locations or at locations on an unannounced basis
  • 9.2 Audit Procedures at the Assertion Level (Paragraph 31)

    In accordance with HKSA 330, the auditor shall design and perform further audit procedures whose nature, timing and extent are responsive to the assessed risks of material misstatement due to fraud at the assertion level.

    Changes to Nature, Timing and Extent (Paragraph A38):

    AspectChanges
    NaturePhysical observation or inspection may become more important; use computer-assisted audit techniques; design procedures to obtain additional corroborative information
    TimingPerforming substantive testing at or near period end; applying substantive procedures to transactions occurring earlier in or throughout the reporting period
    ExtentIncreasing sample sizes; performing analytical procedures at a more detailed level; using computer-assisted audit techniques to test entire populations

    9.3 Audit Procedures Responsive to Management Override of Controls (Paragraphs 32-34)

    The Unique Position of Management (Paragraph 32):

    Management is in a unique position to perpetrate fraud because of management's ability to manipulate accounting records and prepare fraudulent financial statements by overriding controls that otherwise appear to be operating effectively.

    Key Points:

  • The risk of management override of controls is present in all entities
  • Due to the unpredictable way in which such override could occur, it is a risk of material misstatement due to fraud and thus a significant risk
  • Required Audit Procedures (Paragraph 33):

    ProcedureRequirementsRef: Para.
    (a) Testing Journal Entries and Other Adjustments(i) Make inquiries of individuals involved in financial reporting about inappropriate or unusual activity relating to journal entries and other adjustments; (ii) Select journal entries and other adjustments made at the end of a reporting period; (iii) Consider the need to test journal entries and other adjustments throughout the periodA42-A45
    (b) Reviewing Accounting Estimates for Bias(i) Evaluate whether judgments and decisions by management indicate possible bias that may represent a risk of material misstatement due to fraud; (ii) Perform a retrospective review of management judgments and assumptions related to significant accounting estimates reflected in the prior year financial statementsA46-A48
    (c) Evaluating Business Rationale for Significant Unusual TransactionsFor significant transactions outside the normal course of business or that appear unusual, evaluate whether the business rationale suggests they may have been entered into to engage in fraudulent financial reporting or to conceal misappropriation of assetsA49

    Additional Procedures (Paragraph 34):

    The auditor shall determine whether, in order to respond to the identified risks of management override of controls, the auditor needs to perform other audit procedures in addition to those specifically referred to above.

    Characteristics of Fraudulent Journal Entries (Paragraph A44):

  • Made to unrelated, unusual, or seldom-used accounts
  • Made by individuals who typically do not make journal entries
  • Recorded at the end of the period or as post-closing entries with little or no explanation
  • Made before or during preparation of financial statements without account numbers
  • Containing round numbers or consistent ending numbers
  • Indicators of Fraudulent Business Rationale (Paragraph A49):

  • Form of transactions appears overly complex
  • Management has not discussed nature and accounting with those charged with governance
  • Management places more emphasis on particular accounting treatment than underlying economics
  • Transactions involve non-consolidated related parties not properly reviewed or approved
  • Transactions involve previously unidentified related parties or parties without substance or financial strength
  • Ad Space

    10. Evaluation of Audit Evidence (Paragraphs 35-38)

    10.1 Analytical Procedures Near End of Audit (Paragraph 35)

    The auditor shall evaluate whether analytical procedures that are performed near the end of the audit, when forming an overall conclusion as to whether the financial statements are consistent with the auditor's understanding of the entity, indicate a previously unrecognized risk of material misstatement due to fraud.

    Unusual Relationships to Consider (Paragraph A51):

  • Uncharacteristically large amounts of income reported in the last few weeks of the reporting period
  • Unusual transactions
  • Income inconsistent with trends in cash flow from operations
  • 10.2 Evaluation of Identified Misstatements (Paragraph 36)

    If the auditor identifies a misstatement, the auditor shall evaluate whether such a misstatement is indicative of fraud. If there is such an indication, the auditor shall evaluate the implications of the misstatement in relation to other aspects of the audit, particularly the reliability of management representations, recognizing that an instance of fraud is unlikely to be an isolated occurrence.

    10.3 Fraud Involving Management (Paragraph 37)

    If the auditor identifies a misstatement, whether material or not, and the auditor has reason to believe that it is or may be the result of fraud and that management (in particular, senior management) is involved, the auditor shall reevaluate the assessment of the risks of material misstatement due to fraud and its resulting impact on the nature, timing and extent of audit procedures to respond to the assessed risks. The auditor shall also consider whether circumstances or conditions indicate possible collusion involving employees, management or third parties when reconsidering the reliability of evidence previously obtained.

    10.4 Confirmed or Inconclusive Fraud (Paragraph 38)

    If the auditor confirms that, or is unable to conclude whether, the financial statements are materially misstated as a result of fraud the auditor shall evaluate the implications for the audit.

    Ad Space

    11. Auditor Unable to Continue the Engagement (Paragraph 39)

    11.1 Requirements

    If, as a result of a misstatement resulting from fraud or suspected fraud, the auditor encounters exceptional circumstances that bring into question the auditor's ability to continue performing the audit, the auditor shall:

    StepAction
    (a)Determine the professional and legal responsibilities applicable in the circumstances, including whether there is a requirement to report to the person or persons who made the audit appointment or to regulatory authorities
    (b)Consider whether it is appropriate to withdraw from the engagement, where withdrawal is possible under applicable law or regulation
    (c)(i)If the auditor withdraws, discuss with the appropriate level of management and those charged with governance the auditor's withdrawal and the reasons for the withdrawal
    (c)(ii)Determine whether there is a professional or legal requirement to report the withdrawal and reasons to the person or persons who made the audit appointment or to regulatory authorities

    11.2 Examples of Exceptional Circumstances (Paragraph A55)

  • The entity does not take appropriate action regarding fraud that the auditor considers necessary, even where the fraud is not material to the financial statements
  • The auditor's consideration of risks and results of audit tests indicate a significant risk of material and pervasive fraud
  • The auditor has significant concern about the competence or integrity of management or those charged with governance
  • Ad Space

    12. Written Representations (Paragraph 40)

    12.1 Requirements

    The auditor shall obtain written representations from management and, where appropriate, those charged with governance that:

    RepresentationContent
    (a)They acknowledge their responsibility for the design, implementation and maintenance of internal control to prevent and detect fraud
    (b)They have disclosed to the auditor the results of management's assessment of the risk that the financial statements may be materially misstated as a result of fraud
    (c)They have disclosed to the auditor their knowledge of fraud, or suspected fraud, affecting the entity involving: (i) Management; (ii) Employees who have significant roles in internal control; or (iii) Others where the fraud could have a material effect on the financial statements
    (d)They have disclosed to the auditor their knowledge of any allegations of fraud, or suspected fraud, affecting the entity's financial statements communicated by employees, former employees, analysts, regulators or others

    Ad Space

    13. Communications to Management and Those Charged with Governance (Paragraphs 41-43)

    13.1 Communication to Management (Paragraph 41)

    If the auditor has identified a fraud or has obtained information that indicates that a fraud may exist, the auditor shall communicate these matters, unless prohibited by law or regulation, on a timely basis with the appropriate level of management in order to inform those with primary responsibility for the prevention and detection of fraud of matters relevant to their responsibilities.

    Determining the Appropriate Level of Management (Paragraph A62):

  • At least one level above the persons who appear to be involved with the suspected fraud
  • Affected by factors such as likelihood of collusion and nature and magnitude of suspected fraud
  • 13.2 Communication with Those Charged with Governance (Paragraph 42)

    Unless all of those charged with governance are involved in managing the entity, if the auditor has identified or suspects fraud involving:

  • (a) management;
  • (b) employees who have significant roles in internal control; or
  • (c) others where the fraud results in a material misstatement in the financial statements,
  • the auditor shall communicate these matters with those charged with governance on a timely basis.

    Special Rule for Suspected Management Fraud:

    If the auditor suspects fraud involving management, the auditor shall communicate these suspicions with those charged with governance and discuss with them the nature, timing and extent of audit procedures necessary to complete the audit.

    13.3 Other Matters Related to Fraud (Paragraph 43)

    The auditor shall communicate, unless prohibited by law or regulation, with those charged with governance any other matters related to fraud that are, in the auditor's judgment, relevant to their responsibilities.

    Examples of Other Matters (Paragraph A66):

  • Concerns about the nature, extent and frequency of management's assessments of controls and fraud risk
  • Failure by management to appropriately address identified significant deficiencies in internal control
  • The auditor's evaluation of the entity's control environment
  • Actions by management that may be indicative of fraudulent financial reporting
  • Concerns about the adequacy and completeness of authorization of transactions outside the normal course of business
  • Ad Space

    14. Reporting Fraud to an Appropriate Authority Outside the Entity (Paragraph 44)

    14.1 Requirements

    If the auditor has identified or suspects a fraud, the auditor shall determine whether law, regulation or relevant ethical requirements:

    (a) Require the auditor to report to an appropriate authority outside the entity.

    (b) Establish responsibilities under which reporting to an appropriate authority outside the entity may be appropriate in the circumstances.

    14.2 Additional Local Guidance (Appendix 4)

    Key Considerations:

  • Where the auditor becomes aware of a suspected or actual instance of fraud which could have a material effect on the financial statements, the auditor shall:
  • Consider whether the matter ought to be reported to a proper authority in the public interest
  • Except when prohibited by law or when the matter casts doubt on the integrity of those charged with governance, discuss the matter with those charged with governance
  • Reporting Procedure:

  • If the auditor concludes the matter ought to be reported, notify those charged with governance in writing
  • If the entity does not voluntarily report the matter, the auditor shall consider reporting it himself
  • Exceptions - Report Without Delay and Without Informing Those Charged with Governance:

  • When the auditor concludes the matter ought to be reported in the public interest AND
  • The auditor is prohibited by law from informing any party other than the proper authority OR the matter casts doubt on the integrity of those charged with governance
  • Confidentiality Note:

  • Confidentiality is an implied term of the auditor's contract
  • The duty of confidentiality is not absolute
  • In certain exceptional circumstances, an auditor is not bound by the duty of confidentiality
  • Ad Space

    15. Documentation Requirements (Paragraphs 45-48)

    15.1 Documentation of Risk Assessment (Paragraph 45)

    The auditor shall include the following in the audit documentation of the identification and the assessment of the risks of material misstatement:

    ItemDescription
    (a)The significant decisions reached during the discussion among the engagement team regarding the susceptibility of the entity's financial statements to material misstatement due to fraud
    (b)The identified and assessed risks of material misstatement due to fraud at the financial statement level and at the assertion level
    (c)Identified controls in the control activities component that address assessed risks of material misstatement due to fraud

    15.2 Documentation of Responses (Paragraph 46)

    The auditor shall include the following in the audit documentation of the auditor's responses to the assessed risks of material misstatement:

    ItemDescription
    (a)The overall responses to the assessed risks of material misstatement due to fraud at the financial statement level and the nature, timing and extent of audit procedures, and the linkage of those procedures with the assessed risks at the assertion level
    (b)The results of the audit procedures, including those designed to address the risk of management override of controls

    15.3 Documentation of Communications (Paragraph 47)

    The auditor shall include in the audit documentation communications about fraud made to management, those charged with governance, regulators and others.

    15.4 Documentation of Rebuttal of Revenue Recognition Presumption (Paragraph 48)

    If the auditor has concluded that the presumption that there is a risk of material misstatement due to fraud related to revenue recognition is not applicable in the circumstances of the engagement, the auditor shall include in the audit documentation the reasons for that conclusion.

    Ad Space

    16. Fraudulent Financial Reporting - Detailed Analysis

    16.1 Methods of Fraudulent Financial Reporting (Paragraph A3)

    MethodDescription
    Manipulation, falsification, or alterationOf accounting records or supporting documentation from which the financial statements are prepared
    Misrepresentation or intentional omissionIn the financial statements of events, transactions or other significant information
    Intentional misapplicationOf accounting principles relating to amounts, classification, manner of presentation, or disclosure

    16.2 Management Override Techniques (Paragraph A4)

    TechniqueDescription
    Recording fictitious journal entriesParticularly close to the end of an accounting period to manipulate operating results
    Inappropriately adjusting assumptionsChanging judgments used to estimate account balances
    Omitting, advancing or delaying recognitionOf events and transactions that have occurred during the reporting period
    Omitting, obscuring or misstating disclosuresRequired by the applicable financial reporting framework or necessary for fair presentation
    Concealing factsThat could affect the amounts recorded in the financial statements
    Engaging in complex transactionsStructured to misrepresent financial position or financial performance
    Altering records and termsRelated to significant and unusual transactions

    Ad Space

    17. Misappropriation of Assets - Detailed Analysis

    17.1 Methods of Misappropriation (Paragraph A5)

    MethodExamples
    Embezzling receiptsMisappropriating collections on accounts receivable; diverting receipts in respect of written-off accounts to personal bank accounts
    Stealing physical assets or intellectual propertyStealing inventory for personal use or sale; stealing scrap for resale; colluding with a competitor by disclosing technological data
    Causing entity to pay for goods/services not receivedPayments to fictitious vendors; kickbacks from vendors to purchasing agents; payments to fictitious employees
    Using entity's assets for personal useUsing entity's assets as collateral for personal loans or loans to related parties

    Note: Misappropriation of assets is often accompanied by false or misleading records or documents to conceal the fact that the assets are missing or have been pledged without proper authorization.

    Ad Space

    18. Fraud Risk Factors - Appendix 1 Summary

    18.1 Risk Factors for Fraudulent Financial Reporting

    Incentives/Pressures:

    CategoryExamples
    Financial stability/profitability threatenedHigh competition with declining margins; vulnerability to rapid changes; significant declines in customer demand; operating losses; recurring negative cash flows; rapid growth or unusual profitability; new accounting or regulatory requirements
    Excessive pressure to meet third-party expectationsProfitability expectations of analysts/investors/creditors; need for additional financing; marginal ability to meet listing or debt covenant requirements; adverse effects of poor results on pending transactions
    Personal financial situation threatenedSignificant financial interests in the entity; compensation contingent on aggressive targets; personal guarantees of entity's debts
    Excessive pressure to meet financial targetsSales or profitability incentive goals established by those charged with governance

    Opportunities:

    CategoryExamples
    Nature of industry/operationsSignificant related-party transactions; strong financial presence allowing dictation of terms; significant estimates involving subjective judgments; significant unusual complex transactions; operations across international borders; business intermediaries without clear justification; bank accounts in tax-haven jurisdictions
    Ineffective monitoring of managementDomination by single person or small group without compensating controls; ineffective oversight by those charged with governance
    Complex or unstable organizational structureDifficulty determining controlling interest; overly complex structure; high turnover of senior management, legal counsel, or those charged with governance
    Internal control deficienciesInadequate monitoring of internal control; high turnover of accounting/IT/internal audit staff; ineffective accounting and information systems

    Attitudes/Rationalizations:

    Examples
    Ineffective communication or enforcement of ethical standards
    Nonfinancial management's excessive participation in selection of accounting policies
    Known history of violations of securities laws or other regulations
    Excessive interest in maintaining or increasing stock price or earnings trend
    Committing to analysts/creditors to achieve aggressive forecasts
    Failure to remedy known significant deficiencies in internal control
    Interest in employing inappropriate means to minimize reported earnings for tax reasons
    Low morale among senior management
    Owner-manager makes no distinction between personal and business transactions
    Dispute between shareholders in closely held entity
    Recurring attempts to justify marginal or inappropriate accounting on basis of materiality
    Strained relationship between management and current/predecessor auditor

    18.2 Risk Factors for Misappropriation of Assets

    Incentives/Pressures:

    CategoryExamples
    Personal financial obligationsMay create pressure on management or employees with access to cash or other assets susceptible to theft
    Adverse relationshipsKnown or anticipated future employee layoffs; recent or anticipated changes to compensation or benefit plans; promotions or rewards inconsistent with expectations

    Opportunities:

    CategoryExamples
    Nature of assetsLarge amounts of cash; inventory items small in size, high value, or in high demand; easily convertible assets; fixed assets small in size, marketable, or lacking observable identification of ownership
    Inadequate controlsInadequate segregation of duties; inadequate oversight of senior management expenditures; inadequate management oversight of employees responsible for assets; inadequate job applicant screening; inadequate record keeping; inadequate system of authorization and approval; inadequate physical safeguards; lack of complete and timely reconciliations; lack of timely documentation; lack of mandatory vacations; inadequate management understanding of IT; inadequate access controls over automated records

    Attitudes/Rationalizations:

    Examples
    Disregard for need for monitoring or reducing risks related to misappropriation of assets
    Disregard for controls by overriding existing controls or failing to take appropriate remedial action
    Behavior indicating displeasure or dissatisfaction with the entity or its treatment of the employee
    Changes in behavior or lifestyle that may indicate assets have been misappropriated
    Tolerance of petty theft

    Ad Space

    19. Examples of Audit Procedures - Appendix 2 Summary

    19.1 Procedures at the Assertion Level

    Procedure CategoryExamples
    Surprise/unannounced proceduresVisiting locations or performing tests on surprise basis; observing inventory at unannounced locations; counting cash on surprise basis
    Timing adjustmentsRequesting inventories be counted at end of reporting period or closer to period end
    Altering audit approachContacting major customers and suppliers orally in addition to written confirmation; sending confirmations to specific parties; seeking more or different information
    Detailed review of adjustmentsPerforming detailed review of quarter-end or year-end adjusting entries
    Significant/unusual transactionsInvestigating possibility of related parties and sources of financial resources supporting transactions
    Substantive analytical proceduresUsing disaggregated data; comparing sales and cost of sales by location, line of business or month
    InterviewsConducting interviews of personnel in areas where fraud risk has been identified
    Other auditorsDiscussing with other independent auditors the extent of work necessary
    Expert workPerforming additional procedures relating to expert's assumptions, methods or findings
    Opening balance sheetPerforming procedures to analyze selected opening balance sheet accounts
    ReconciliationsPerforming procedures on account or other reconciliations
    Computer-assisted techniquesData mining to test for anomalies; testing integrity of computer-produced records and transactions
    External evidenceSeeking additional audit evidence from sources outside the entity

    19.2 Specific Procedures for Revenue Recognition Fraud

    ProcedureDescription
    Substantive analytical proceduresUsing disaggregated data; comparing revenue by month, product line, or business segment with prior periods
    Confirmation of contract termsConfirming with customers relevant contract terms and absence of side agreements
    Inquiries of sales/marketing personnelRegarding sales or shipments near period end and unusual terms or conditions
    Physical presence at period endObserving goods being shipped or readied for shipment; performing sales and inventory cutoff procedures
    Testing controlsFor electronically initiated, processed, and recorded revenue transactions

    19.3 Specific Procedures for Inventory Fraud

    ProcedureDescription
    Examine inventory recordsIdentify locations or items requiring specific attention
    Unannounced observationsObserve inventory counts at certain locations on unannounced basis or conduct counts at all locations on same date
    Timing of countsConduct counts at or near end of reporting period
    Additional procedures during observationExamine contents of boxed items, manner of stacking, labeling, quality of substances
    Comparative analysisCompare quantities with prior periods by class, category, location
    Computer-assisted techniquesSort by tag number to test tag controls; sort by item serial number to test omission or duplication

    19.4 Specific Procedures for Management Estimates

    ProcedureDescription
    Use of expertDevelop independent estimate for comparison to management's estimate
    Extended inquiriesInquire of individuals outside management and accounting department to corroborate management's ability and intent

    19.5 Specific Procedures for Misappropriation of Assets

    ProcedureDescription
    Counting cash or securitiesAt or near year-end
    Confirming account activityDirectly with customers
    Analyzing recoveriesOf written-off accounts
    Analyzing inventory shortagesBy location or product type
    Comparing inventory ratiosTo industry norm
    Reviewing supporting documentationFor reductions to perpetual inventory records
    Computerized matchingVendor list with employee list to identify matches of addresses or phone numbers
    Computerized search of payroll recordsTo identify duplicate addresses, employee identification or bank accounts
    Reviewing personnel filesFor those with little or no evidence of activity
    Analyzing sales discounts and returnsFor unusual patterns or trends
    Confirming specific contract termsWith third parties
    Obtaining evidence of contract performanceThat contracts are being carried out in accordance with terms
    Reviewing propriety of expensesLarge and unusual expenses
    Reviewing senior management loansAuthorization and carrying value
    Reviewing expense reportsLevel and propriety of senior management expense reports

    Ad Space

    20. Circumstances Indicating Possibility of Fraud - Appendix 3 Summary

    20.1 Discrepancies in Accounting Records

    TypeExamples
    Recording issuesTransactions not recorded completely or timely; improperly recorded as to amount, accounting period, classification, or entity policy
    Unsupported itemsUnsupported or unauthorized balances or transactions
    Last-minute adjustmentsThat significantly affect financial results
    Access issuesEvidence of employees' access to systems and records inconsistent with authorized duties
    Tips/complaintsTo the auditor about alleged fraud

    20.2 Conflicting or Missing Evidence

    TypeExamples
    Missing documentsDocuments that appear to have been altered; unavailability of original documents when expected to exist
    Reconciliation issuesSignificant unexplained items on reconciliations
    Unusual changesBalance sheet changes; changes in trends or important ratios (e.g., receivables growing faster than revenues)
    Implausible responsesInconsistent, vague, or implausible responses from management or employees
    Confirmation discrepanciesUnusual discrepancies between entity's records and confirmation replies
    Accounts receivable issuesLarge numbers of credit entries and adjustments; unexplained differences between sub-ledger and control account
    Missing itemsMissing cancelled checks; missing inventory or physical assets of significant magnitude
    Electronic evidence issuesUnavailable or missing electronic evidence inconsistent with record retention practices
    Confirmation response issuesFewer or greater responses than anticipated
    System development issuesInability to produce evidence of key systems development and program change testing

    20.3 Problematic or Unusual Relationships with Management

    TypeExamples
    Denial of accessTo records, facilities, certain employees, customers, vendors, or others
    Time pressuresUndue time pressures to resolve complex or contentious issues
    Complaints/intimidationComplaints about conduct of audit; intimidation of engagement team members
    DelaysUnusual delays in providing requested information
    Unwillingness to facilitateUnwillingness to facilitate access to key electronic files for testing
    Denial of access to ITDenial of access to key IT operations staff and facilities
    Unwillingness regarding disclosuresUnwillingness to add or revise disclosures
    Unwillingness regarding deficienciesUnwillingness to address identified deficiencies in internal control

    20.4 Other Circumstances

    TypeExamples
    Meeting restrictionsUnwillingness to permit auditor to meet privately with those charged with governance
    Accounting policiesPolicies that appear at variance with industry norms
    Frequent estimate changesChanges in accounting estimates that do not appear to result from changed circumstances
    Code of conduct violationsTolerance of violations of the entity's code of conduct

    Ad Space

    21. Key Takeaways Summary Table

    TopicKey Points
    Definition of FraudIntentional act involving deception to obtain unjust or illegal advantage
    Two TypesFraudulent financial reporting and misappropriation of assets
    Three ConditionsIncentive/pressure, opportunity, rationalization
    Primary ResponsibilityManagement and those charged with governance
    Auditor's ResponsibilityReasonable assurance that financial statements are free from material misstatement due to fraud or error
    Professional SkepticismMust be maintained throughout the audit; recognize possibility of fraud despite past experience
    Revenue RecognitionPresumption of fraud risk; can be rebutted with documentation
    Management OverrideSignificant risk in all entities; requires specific procedures for journal entries, estimates, and unusual transactions
    CommunicationTimely communication to management and those charged with governance
    DocumentationRisk assessment, responses, communications, and rebuttal of revenue recognition presumption
    WithdrawalPossible in exceptional circumstances; consider legal and professional responsibilities
    Reporting Outside EntityDetermine if law, regulation, or ethical requirements require or permit reporting

    Ad Space

    ---

    ❓ Ready to Test Your Knowledge?

    50 MCQs covering all sections. Timed at 1.25 min each (62.5 min total).

    📝 Start Q&A →🖨️ Save as PDF