HKSA 240 - Responsibilities Relating to Fraud
HKSA 240 - The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements
1. Introduction and Scope
1.1 Scope of HKSA 240
HKSA 240 deals with the auditor's responsibilities relating to fraud in an audit of financial statements. It expands on how HKSA 315 (Revised 2019) and HKSA 330 are to be applied in relation to risks of material misstatement due to fraud.
Effective Date: This HKSA is effective for audits of financial statements for periods beginning on or after 15 December 2009.
1.2 Characteristics of Fraud
Definition of Fraud (Paragraph 12(a)):
Fraud – An intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage.
Distinction between Fraud and Error (Paragraph 2):
Two Types of Intentional Misstatements Relevant to the Auditor (Paragraph 3):
| Type | Description |
|---|---|
| Fraudulent Financial Reporting | Intentional misstatements including omissions of amounts or disclosures in financial statements to deceive financial statement users |
| Misappropriation of Assets | Theft of an entity's assets, often perpetrated by employees in relatively small and immaterial amounts, but can also involve management |
Important Note: The auditor does not make legal determinations of whether fraud has actually occurred, even though the auditor may suspect or, in rare cases, identify the occurrence of fraud.
1.3 Three Conditions Generally Present When Fraud Exists (Paragraph A1)
| Condition | Description |
|---|---|
| Incentive or Pressure | Management under pressure to achieve expected earnings targets; individuals living beyond their means |
| Perceived Opportunity | Individual believes internal control can be overridden; knowledge of specific deficiencies in internal control |
| Rationalization | Attitude, character, or set of ethical values that allow knowingly and intentionally committing a dishonest act |
2. Responsibility for Prevention and Detection of Fraud
2.1 Primary Responsibility (Paragraph 4)
Primary responsibility for the prevention and detection of fraud rests with both:
Management's Responsibilities:
Oversight by Those Charged with Governance Includes:
2.2 Responsibilities of the Auditor (Paragraphs 5-8)
The Auditor's Objective:
An auditor conducting an audit in accordance with HKSAs is responsible for obtaining reasonable assurance that the financial statements taken as a whole are free from material misstatement, whether caused by fraud or error.
Key Points:
Management Fraud vs. Employee Fraud (Paragraph 7):
The risk of the auditor not detecting a material misstatement resulting from management fraud is greater than for employee fraud, because management is frequently in a position to directly or indirectly manipulate accounting records, present fraudulent financial information or override controls designed to prevent similar frauds by other employees.
Auditor's Responsibilities When Obtaining Reasonable Assurance (Paragraph 8):
2.3 Additional Responsibilities Under Law or Regulation (Paragraph 9)
The auditor may have additional responsibilities under law, regulation or relevant ethical requirements regarding an entity's non-compliance with laws and regulations, including fraud, which may differ from or go beyond HKSAs:
| Responsibility | Description |
|---|---|
| Responding to identified or suspected non-compliance | Including requirements for specific communications with management and those charged with governance |
| Assessing appropriateness of response | Evaluating management's response to non-compliance and determining whether further action is needed |
| Communicating to other auditors | In group audit situations |
| Documentation requirements | Regarding identified or suspected non-compliance with laws and regulations |
3. Objectives (Paragraph 11)
The objectives of the auditor are:
| Objective | Description |
|---|---|
| (a) | To identify and assess the risks of material misstatement of the financial statements due to fraud |
| (b) | To obtain sufficient appropriate audit evidence regarding the assessed risks of material misstatement due to fraud, through designing and implementing appropriate responses |
| (c) | To respond appropriately to fraud or suspected fraud identified during the audit |
4. Definitions (Paragraph 12)
| Term | Definition |
|---|---|
| Fraud | An intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage |
| Fraud risk factors | Events or conditions that indicate an incentive or pressure to commit fraud or provide an opportunity to commit fraud |
5. Requirements - Professional Skepticism (Paragraphs 13-15)
5.1 Maintaining Professional Skepticism (Paragraph 13)
In accordance with HKSA 200, the auditor shall maintain professional skepticism throughout the audit, recognizing the possibility that a material misstatement due to fraud could exist, notwithstanding the auditor's past experience of the honesty and integrity of the entity's management and those charged with governance.
Key Points (Paragraph A8-A9):
5.2 Authenticity of Documents (Paragraph 14)
Unless the auditor has reason to believe the contrary, the auditor may accept records and documents as genuine. If conditions identified during the audit cause the auditor to believe that a document may not be authentic or that terms in a document have been modified but not disclosed to the auditor, the auditor shall investigate further.
Possible Procedures to Investigate Further (Paragraph A10):
5.3 Inconsistent Responses (Paragraph 15)
Where responses to inquiries of management or those charged with governance are inconsistent, the auditor shall investigate the inconsistencies.
6. Discussion Among the Engagement Team (Paragraph 16)
6.1 Requirements
HKSA 315 (Revised 2019) requires a discussion among the engagement team members and a determination by the engagement partner of which matters are to be communicated to those team members not involved in the discussion.
This discussion shall place particular emphasis on:
6.2 Matters to Include in the Discussion (Paragraph A12)
| Category | Specific Matters |
|---|---|
| Susceptibility to Fraud | How and where financial statements may be susceptible to material misstatement due to fraud; how management could perpetrate and conceal fraudulent financial reporting; how assets could be misappropriated |
| Earnings Management | Circumstances indicative of earnings management; practices management might follow to manage earnings that could lead to fraudulent financial reporting |
| Disclosure Presentation | Risk that management may attempt to present disclosures in a manner that obscures proper understanding (too much immaterial information, unclear or ambiguous language) |
| Incentives and Pressures | Known external and internal factors creating incentive or pressure to commit fraud; opportunities for fraud; culture enabling rationalization |
| Asset Misappropriation | Management's involvement in overseeing employees with access to cash or other assets susceptible to misappropriation |
| Behavioral Indicators | Unusual or unexplained changes in behavior or lifestyle of management or employees |
| Professional Mindset | Importance of maintaining a proper state of mind regarding the potential for material misstatement due to fraud |
| Unpredictability | How an element of unpredictability will be incorporated into audit procedures |
| Audit Procedures | Which procedures might be selected; whether certain types are more effective than others |
| Allegations | Any allegations of fraud that have come to the auditor's attention |
| Management Override | Risk of management override of controls |
7. Risk Assessment Procedures and Related Activities (Paragraphs 17-25)
7.1 Overview
When performing risk assessment procedures and related activities to obtain an understanding of the entity and its environment, the applicable financial reporting framework and the entity's system of internal control, the auditor shall perform the procedures in paragraphs 18-25 to obtain information for use in identifying the risks of material misstatement due to fraud.
7.2 Inquiries of Management (Paragraph 18)
The auditor shall make inquiries of management regarding:
| Inquiry Topic | Details (Ref: Para.) |
|---|---|
| (a) Management's assessment of fraud risk | Nature, extent and frequency of assessments of the risk that financial statements may be materially misstated due to fraud (A13-A14) |
| (b) Management's process for identifying and responding to fraud risks | Including any specific risks identified, classes of transactions, account balances, or disclosures for which fraud risk is likely to exist (A15) |
| (c) Communication to those charged with governance | Management's communication regarding its processes for identifying and responding to fraud risks |
| (d) Communication to employees | Management's communication regarding its views on business practices and ethical behavior |
7.3 Inquiries of Management and Others Within the Entity (Paragraph 19)
The auditor shall make inquiries of management, and others within the entity as appropriate, to determine whether they have knowledge of any actual, suspected or alleged fraud affecting the entity.
Examples of Others Within the Entity to Inquire (Paragraph A17):
7.4 Inquiries of Internal Audit (Paragraph 20)
For entities that have an internal audit function, the auditor shall make inquiries of appropriate individuals within the function to determine whether they have knowledge of any actual, suspected or alleged fraud affecting the entity, and to obtain its views about the risks of fraud.
Specific Activities to Inquire About (Paragraph A19):
7.5 Those Charged with Governance (Paragraphs 21-22)
Understanding Oversight (Paragraph 21):
Unless all of those charged with governance are involved in managing the entity, the auditor shall obtain an understanding of how those charged with governance exercise oversight of:
Inquiries of Those Charged with Governance (Paragraph 22):
Unless all of those charged with governance are involved in managing the entity, the auditor shall make inquiries of those charged with governance to determine whether they have knowledge of any actual, suspected or alleged fraud affecting the entity. These inquiries are made in part to corroborate the responses to the inquiries of management.
7.6 Unusual or Unexpected Relationships (Paragraph 23)
The auditor shall evaluate whether unusual or unexpected relationships that have been identified in performing analytical procedures, including those related to revenue accounts, may indicate risks of material misstatement due to fraud.
7.7 Other Information (Paragraph 24)
The auditor shall consider whether other information obtained by the auditor indicates risks of material misstatement due to fraud.
Sources of Other Information (Paragraph A23):
7.8 Evaluation of Fraud Risk Factors (Paragraph 25)
The auditor shall evaluate whether the information obtained from the other risk assessment procedures and related activities performed indicates that one or more fraud risk factors are present.
Important Note: While fraud risk factors may not necessarily indicate the existence of fraud, they have often been present in circumstances where frauds have occurred and therefore may indicate risks of material misstatement due to fraud.
Fraud Risk Factors Classification (Paragraph A26):
| Category | Description |
|---|---|
| Incentive/Pressure | Conditions that create susceptibility to misstatement before consideration of controls |
| Opportunity | Conditions within the entity's system of internal control that provide opportunity to commit fraud |
| Attitude/Rationalization | Conditions that may affect management's attitude or ability to rationalize fraudulent actions |
8. Identification and Assessment of Risks of Material Misstatement Due to Fraud (Paragraphs 26-28)
8.1 General Requirements (Paragraph 26)
In accordance with HKSA 315 (Revised 2019), the auditor shall identify and assess the risks of material misstatement due to fraud:
8.2 Presumption of Fraud in Revenue Recognition (Paragraph 27)
When identifying and assessing the risks of material misstatement due to fraud, the auditor shall, based on a presumption that there are risks of fraud in revenue recognition, evaluate which types of revenue, revenue transactions or assertions give rise to such risks.
Documentation Requirement (Paragraph 48):
If the auditor concludes that the presumption is not applicable in the circumstances of the engagement and accordingly has not identified revenue recognition as a risk of material misstatement due to fraud, the auditor shall include in the audit documentation the reasons for that conclusion.
When the Presumption May Be Rebutted (Paragraph A31):
For example, the auditor may conclude that there is no risk of material misstatement due to fraud relating to revenue recognition in the case where there is a single type of simple revenue transaction, e.g., leasehold revenue from a single unit rental property.
Common Revenue Recognition Fraud Schemes (Paragraph A29):
8.3 Treatment as Significant Risks (Paragraph 28)
The auditor shall treat those assessed risks of material misstatement due to fraud as significant risks and accordingly, to the extent not already done so, the auditor shall identify the entity's controls that address such risks, and evaluate their design and determine whether they have been implemented.
9. Responses to Assessed Risks of Material Misstatement Due to Fraud (Paragraphs 29-34)
9.1 Overall Responses (Paragraphs 29-30)
Determining Overall Responses (Paragraph 29):
In accordance with HKSA 330, the auditor shall determine overall responses to address the assessed risks of material misstatement due to fraud at the financial statement level.
Components of Overall Responses (Paragraph 30):
| Component | Description | Ref: Para. |
|---|---|---|
| (a) Assignment and Supervision of Personnel | Assign and supervise personnel taking account of knowledge, skill and ability of individuals and the auditor's assessment of risks | A35-A36 |
| (b) Evaluation of Accounting Policies | Evaluate whether selection and application of accounting policies, particularly those related to subjective measurements and complex transactions, may be indicative of fraudulent financial reporting resulting from management's effort to manage earnings | - |
| (c) Unpredictability | Incorporate an element of unpredictability in the selection of the nature, timing and extent of audit procedures | A37 |
How Overall Conduct Reflects Increased Professional Skepticism (Paragraph A34):
Ways to Incorporate Unpredictability (Paragraph A37):
9.2 Audit Procedures at the Assertion Level (Paragraph 31)
In accordance with HKSA 330, the auditor shall design and perform further audit procedures whose nature, timing and extent are responsive to the assessed risks of material misstatement due to fraud at the assertion level.
Changes to Nature, Timing and Extent (Paragraph A38):
| Aspect | Changes |
|---|---|
| Nature | Physical observation or inspection may become more important; use computer-assisted audit techniques; design procedures to obtain additional corroborative information |
| Timing | Performing substantive testing at or near period end; applying substantive procedures to transactions occurring earlier in or throughout the reporting period |
| Extent | Increasing sample sizes; performing analytical procedures at a more detailed level; using computer-assisted audit techniques to test entire populations |
9.3 Audit Procedures Responsive to Management Override of Controls (Paragraphs 32-34)
The Unique Position of Management (Paragraph 32):
Management is in a unique position to perpetrate fraud because of management's ability to manipulate accounting records and prepare fraudulent financial statements by overriding controls that otherwise appear to be operating effectively.
Key Points:
Required Audit Procedures (Paragraph 33):
| Procedure | Requirements | Ref: Para. |
|---|---|---|
| (a) Testing Journal Entries and Other Adjustments | (i) Make inquiries of individuals involved in financial reporting about inappropriate or unusual activity relating to journal entries and other adjustments; (ii) Select journal entries and other adjustments made at the end of a reporting period; (iii) Consider the need to test journal entries and other adjustments throughout the period | A42-A45 |
| (b) Reviewing Accounting Estimates for Bias | (i) Evaluate whether judgments and decisions by management indicate possible bias that may represent a risk of material misstatement due to fraud; (ii) Perform a retrospective review of management judgments and assumptions related to significant accounting estimates reflected in the prior year financial statements | A46-A48 |
| (c) Evaluating Business Rationale for Significant Unusual Transactions | For significant transactions outside the normal course of business or that appear unusual, evaluate whether the business rationale suggests they may have been entered into to engage in fraudulent financial reporting or to conceal misappropriation of assets | A49 |
Additional Procedures (Paragraph 34):
The auditor shall determine whether, in order to respond to the identified risks of management override of controls, the auditor needs to perform other audit procedures in addition to those specifically referred to above.
Characteristics of Fraudulent Journal Entries (Paragraph A44):
Indicators of Fraudulent Business Rationale (Paragraph A49):
10. Evaluation of Audit Evidence (Paragraphs 35-38)
10.1 Analytical Procedures Near End of Audit (Paragraph 35)
The auditor shall evaluate whether analytical procedures that are performed near the end of the audit, when forming an overall conclusion as to whether the financial statements are consistent with the auditor's understanding of the entity, indicate a previously unrecognized risk of material misstatement due to fraud.
Unusual Relationships to Consider (Paragraph A51):
10.2 Evaluation of Identified Misstatements (Paragraph 36)
If the auditor identifies a misstatement, the auditor shall evaluate whether such a misstatement is indicative of fraud. If there is such an indication, the auditor shall evaluate the implications of the misstatement in relation to other aspects of the audit, particularly the reliability of management representations, recognizing that an instance of fraud is unlikely to be an isolated occurrence.
10.3 Fraud Involving Management (Paragraph 37)
If the auditor identifies a misstatement, whether material or not, and the auditor has reason to believe that it is or may be the result of fraud and that management (in particular, senior management) is involved, the auditor shall reevaluate the assessment of the risks of material misstatement due to fraud and its resulting impact on the nature, timing and extent of audit procedures to respond to the assessed risks. The auditor shall also consider whether circumstances or conditions indicate possible collusion involving employees, management or third parties when reconsidering the reliability of evidence previously obtained.
10.4 Confirmed or Inconclusive Fraud (Paragraph 38)
If the auditor confirms that, or is unable to conclude whether, the financial statements are materially misstated as a result of fraud the auditor shall evaluate the implications for the audit.
11. Auditor Unable to Continue the Engagement (Paragraph 39)
11.1 Requirements
If, as a result of a misstatement resulting from fraud or suspected fraud, the auditor encounters exceptional circumstances that bring into question the auditor's ability to continue performing the audit, the auditor shall:
| Step | Action |
|---|---|
| (a) | Determine the professional and legal responsibilities applicable in the circumstances, including whether there is a requirement to report to the person or persons who made the audit appointment or to regulatory authorities |
| (b) | Consider whether it is appropriate to withdraw from the engagement, where withdrawal is possible under applicable law or regulation |
| (c)(i) | If the auditor withdraws, discuss with the appropriate level of management and those charged with governance the auditor's withdrawal and the reasons for the withdrawal |
| (c)(ii) | Determine whether there is a professional or legal requirement to report the withdrawal and reasons to the person or persons who made the audit appointment or to regulatory authorities |
11.2 Examples of Exceptional Circumstances (Paragraph A55)
12. Written Representations (Paragraph 40)
12.1 Requirements
The auditor shall obtain written representations from management and, where appropriate, those charged with governance that:
| Representation | Content |
|---|---|
| (a) | They acknowledge their responsibility for the design, implementation and maintenance of internal control to prevent and detect fraud |
| (b) | They have disclosed to the auditor the results of management's assessment of the risk that the financial statements may be materially misstated as a result of fraud |
| (c) | They have disclosed to the auditor their knowledge of fraud, or suspected fraud, affecting the entity involving: (i) Management; (ii) Employees who have significant roles in internal control; or (iii) Others where the fraud could have a material effect on the financial statements |
| (d) | They have disclosed to the auditor their knowledge of any allegations of fraud, or suspected fraud, affecting the entity's financial statements communicated by employees, former employees, analysts, regulators or others |
13. Communications to Management and Those Charged with Governance (Paragraphs 41-43)
13.1 Communication to Management (Paragraph 41)
If the auditor has identified a fraud or has obtained information that indicates that a fraud may exist, the auditor shall communicate these matters, unless prohibited by law or regulation, on a timely basis with the appropriate level of management in order to inform those with primary responsibility for the prevention and detection of fraud of matters relevant to their responsibilities.
Determining the Appropriate Level of Management (Paragraph A62):
13.2 Communication with Those Charged with Governance (Paragraph 42)
Unless all of those charged with governance are involved in managing the entity, if the auditor has identified or suspects fraud involving:
the auditor shall communicate these matters with those charged with governance on a timely basis.
Special Rule for Suspected Management Fraud:
If the auditor suspects fraud involving management, the auditor shall communicate these suspicions with those charged with governance and discuss with them the nature, timing and extent of audit procedures necessary to complete the audit.
13.3 Other Matters Related to Fraud (Paragraph 43)
The auditor shall communicate, unless prohibited by law or regulation, with those charged with governance any other matters related to fraud that are, in the auditor's judgment, relevant to their responsibilities.
Examples of Other Matters (Paragraph A66):
14. Reporting Fraud to an Appropriate Authority Outside the Entity (Paragraph 44)
14.1 Requirements
If the auditor has identified or suspects a fraud, the auditor shall determine whether law, regulation or relevant ethical requirements:
(a) Require the auditor to report to an appropriate authority outside the entity.
(b) Establish responsibilities under which reporting to an appropriate authority outside the entity may be appropriate in the circumstances.
14.2 Additional Local Guidance (Appendix 4)
Key Considerations:
Reporting Procedure:
Exceptions - Report Without Delay and Without Informing Those Charged with Governance:
Confidentiality Note:
15. Documentation Requirements (Paragraphs 45-48)
15.1 Documentation of Risk Assessment (Paragraph 45)
The auditor shall include the following in the audit documentation of the identification and the assessment of the risks of material misstatement:
| Item | Description |
|---|---|
| (a) | The significant decisions reached during the discussion among the engagement team regarding the susceptibility of the entity's financial statements to material misstatement due to fraud |
| (b) | The identified and assessed risks of material misstatement due to fraud at the financial statement level and at the assertion level |
| (c) | Identified controls in the control activities component that address assessed risks of material misstatement due to fraud |
15.2 Documentation of Responses (Paragraph 46)
The auditor shall include the following in the audit documentation of the auditor's responses to the assessed risks of material misstatement:
| Item | Description |
|---|---|
| (a) | The overall responses to the assessed risks of material misstatement due to fraud at the financial statement level and the nature, timing and extent of audit procedures, and the linkage of those procedures with the assessed risks at the assertion level |
| (b) | The results of the audit procedures, including those designed to address the risk of management override of controls |
15.3 Documentation of Communications (Paragraph 47)
The auditor shall include in the audit documentation communications about fraud made to management, those charged with governance, regulators and others.
15.4 Documentation of Rebuttal of Revenue Recognition Presumption (Paragraph 48)
If the auditor has concluded that the presumption that there is a risk of material misstatement due to fraud related to revenue recognition is not applicable in the circumstances of the engagement, the auditor shall include in the audit documentation the reasons for that conclusion.
16. Fraudulent Financial Reporting - Detailed Analysis
16.1 Methods of Fraudulent Financial Reporting (Paragraph A3)
| Method | Description |
|---|---|
| Manipulation, falsification, or alteration | Of accounting records or supporting documentation from which the financial statements are prepared |
| Misrepresentation or intentional omission | In the financial statements of events, transactions or other significant information |
| Intentional misapplication | Of accounting principles relating to amounts, classification, manner of presentation, or disclosure |
16.2 Management Override Techniques (Paragraph A4)
| Technique | Description |
|---|---|
| Recording fictitious journal entries | Particularly close to the end of an accounting period to manipulate operating results |
| Inappropriately adjusting assumptions | Changing judgments used to estimate account balances |
| Omitting, advancing or delaying recognition | Of events and transactions that have occurred during the reporting period |
| Omitting, obscuring or misstating disclosures | Required by the applicable financial reporting framework or necessary for fair presentation |
| Concealing facts | That could affect the amounts recorded in the financial statements |
| Engaging in complex transactions | Structured to misrepresent financial position or financial performance |
| Altering records and terms | Related to significant and unusual transactions |
17. Misappropriation of Assets - Detailed Analysis
17.1 Methods of Misappropriation (Paragraph A5)
| Method | Examples |
|---|---|
| Embezzling receipts | Misappropriating collections on accounts receivable; diverting receipts in respect of written-off accounts to personal bank accounts |
| Stealing physical assets or intellectual property | Stealing inventory for personal use or sale; stealing scrap for resale; colluding with a competitor by disclosing technological data |
| Causing entity to pay for goods/services not received | Payments to fictitious vendors; kickbacks from vendors to purchasing agents; payments to fictitious employees |
| Using entity's assets for personal use | Using entity's assets as collateral for personal loans or loans to related parties |
Note: Misappropriation of assets is often accompanied by false or misleading records or documents to conceal the fact that the assets are missing or have been pledged without proper authorization.
18. Fraud Risk Factors - Appendix 1 Summary
18.1 Risk Factors for Fraudulent Financial Reporting
Incentives/Pressures:
| Category | Examples |
|---|---|
| Financial stability/profitability threatened | High competition with declining margins; vulnerability to rapid changes; significant declines in customer demand; operating losses; recurring negative cash flows; rapid growth or unusual profitability; new accounting or regulatory requirements |
| Excessive pressure to meet third-party expectations | Profitability expectations of analysts/investors/creditors; need for additional financing; marginal ability to meet listing or debt covenant requirements; adverse effects of poor results on pending transactions |
| Personal financial situation threatened | Significant financial interests in the entity; compensation contingent on aggressive targets; personal guarantees of entity's debts |
| Excessive pressure to meet financial targets | Sales or profitability incentive goals established by those charged with governance |
Opportunities:
| Category | Examples |
|---|---|
| Nature of industry/operations | Significant related-party transactions; strong financial presence allowing dictation of terms; significant estimates involving subjective judgments; significant unusual complex transactions; operations across international borders; business intermediaries without clear justification; bank accounts in tax-haven jurisdictions |
| Ineffective monitoring of management | Domination by single person or small group without compensating controls; ineffective oversight by those charged with governance |
| Complex or unstable organizational structure | Difficulty determining controlling interest; overly complex structure; high turnover of senior management, legal counsel, or those charged with governance |
| Internal control deficiencies | Inadequate monitoring of internal control; high turnover of accounting/IT/internal audit staff; ineffective accounting and information systems |
Attitudes/Rationalizations:
| Examples |
|---|
| Ineffective communication or enforcement of ethical standards |
| Nonfinancial management's excessive participation in selection of accounting policies |
| Known history of violations of securities laws or other regulations |
| Excessive interest in maintaining or increasing stock price or earnings trend |
| Committing to analysts/creditors to achieve aggressive forecasts |
| Failure to remedy known significant deficiencies in internal control |
| Interest in employing inappropriate means to minimize reported earnings for tax reasons |
| Low morale among senior management |
| Owner-manager makes no distinction between personal and business transactions |
| Dispute between shareholders in closely held entity |
| Recurring attempts to justify marginal or inappropriate accounting on basis of materiality |
| Strained relationship between management and current/predecessor auditor |
18.2 Risk Factors for Misappropriation of Assets
Incentives/Pressures:
| Category | Examples |
|---|---|
| Personal financial obligations | May create pressure on management or employees with access to cash or other assets susceptible to theft |
| Adverse relationships | Known or anticipated future employee layoffs; recent or anticipated changes to compensation or benefit plans; promotions or rewards inconsistent with expectations |
Opportunities:
| Category | Examples |
|---|---|
| Nature of assets | Large amounts of cash; inventory items small in size, high value, or in high demand; easily convertible assets; fixed assets small in size, marketable, or lacking observable identification of ownership |
| Inadequate controls | Inadequate segregation of duties; inadequate oversight of senior management expenditures; inadequate management oversight of employees responsible for assets; inadequate job applicant screening; inadequate record keeping; inadequate system of authorization and approval; inadequate physical safeguards; lack of complete and timely reconciliations; lack of timely documentation; lack of mandatory vacations; inadequate management understanding of IT; inadequate access controls over automated records |
Attitudes/Rationalizations:
| Examples |
|---|
| Disregard for need for monitoring or reducing risks related to misappropriation of assets |
| Disregard for controls by overriding existing controls or failing to take appropriate remedial action |
| Behavior indicating displeasure or dissatisfaction with the entity or its treatment of the employee |
| Changes in behavior or lifestyle that may indicate assets have been misappropriated |
| Tolerance of petty theft |
19. Examples of Audit Procedures - Appendix 2 Summary
19.1 Procedures at the Assertion Level
| Procedure Category | Examples |
|---|---|
| Surprise/unannounced procedures | Visiting locations or performing tests on surprise basis; observing inventory at unannounced locations; counting cash on surprise basis |
| Timing adjustments | Requesting inventories be counted at end of reporting period or closer to period end |
| Altering audit approach | Contacting major customers and suppliers orally in addition to written confirmation; sending confirmations to specific parties; seeking more or different information |
| Detailed review of adjustments | Performing detailed review of quarter-end or year-end adjusting entries |
| Significant/unusual transactions | Investigating possibility of related parties and sources of financial resources supporting transactions |
| Substantive analytical procedures | Using disaggregated data; comparing sales and cost of sales by location, line of business or month |
| Interviews | Conducting interviews of personnel in areas where fraud risk has been identified |
| Other auditors | Discussing with other independent auditors the extent of work necessary |
| Expert work | Performing additional procedures relating to expert's assumptions, methods or findings |
| Opening balance sheet | Performing procedures to analyze selected opening balance sheet accounts |
| Reconciliations | Performing procedures on account or other reconciliations |
| Computer-assisted techniques | Data mining to test for anomalies; testing integrity of computer-produced records and transactions |
| External evidence | Seeking additional audit evidence from sources outside the entity |
19.2 Specific Procedures for Revenue Recognition Fraud
| Procedure | Description |
|---|---|
| Substantive analytical procedures | Using disaggregated data; comparing revenue by month, product line, or business segment with prior periods |
| Confirmation of contract terms | Confirming with customers relevant contract terms and absence of side agreements |
| Inquiries of sales/marketing personnel | Regarding sales or shipments near period end and unusual terms or conditions |
| Physical presence at period end | Observing goods being shipped or readied for shipment; performing sales and inventory cutoff procedures |
| Testing controls | For electronically initiated, processed, and recorded revenue transactions |
19.3 Specific Procedures for Inventory Fraud
| Procedure | Description |
|---|---|
| Examine inventory records | Identify locations or items requiring specific attention |
| Unannounced observations | Observe inventory counts at certain locations on unannounced basis or conduct counts at all locations on same date |
| Timing of counts | Conduct counts at or near end of reporting period |
| Additional procedures during observation | Examine contents of boxed items, manner of stacking, labeling, quality of substances |
| Comparative analysis | Compare quantities with prior periods by class, category, location |
| Computer-assisted techniques | Sort by tag number to test tag controls; sort by item serial number to test omission or duplication |
19.4 Specific Procedures for Management Estimates
| Procedure | Description |
|---|---|
| Use of expert | Develop independent estimate for comparison to management's estimate |
| Extended inquiries | Inquire of individuals outside management and accounting department to corroborate management's ability and intent |
19.5 Specific Procedures for Misappropriation of Assets
| Procedure | Description |
|---|---|
| Counting cash or securities | At or near year-end |
| Confirming account activity | Directly with customers |
| Analyzing recoveries | Of written-off accounts |
| Analyzing inventory shortages | By location or product type |
| Comparing inventory ratios | To industry norm |
| Reviewing supporting documentation | For reductions to perpetual inventory records |
| Computerized matching | Vendor list with employee list to identify matches of addresses or phone numbers |
| Computerized search of payroll records | To identify duplicate addresses, employee identification or bank accounts |
| Reviewing personnel files | For those with little or no evidence of activity |
| Analyzing sales discounts and returns | For unusual patterns or trends |
| Confirming specific contract terms | With third parties |
| Obtaining evidence of contract performance | That contracts are being carried out in accordance with terms |
| Reviewing propriety of expenses | Large and unusual expenses |
| Reviewing senior management loans | Authorization and carrying value |
| Reviewing expense reports | Level and propriety of senior management expense reports |
20. Circumstances Indicating Possibility of Fraud - Appendix 3 Summary
20.1 Discrepancies in Accounting Records
| Type | Examples |
|---|---|
| Recording issues | Transactions not recorded completely or timely; improperly recorded as to amount, accounting period, classification, or entity policy |
| Unsupported items | Unsupported or unauthorized balances or transactions |
| Last-minute adjustments | That significantly affect financial results |
| Access issues | Evidence of employees' access to systems and records inconsistent with authorized duties |
| Tips/complaints | To the auditor about alleged fraud |
20.2 Conflicting or Missing Evidence
| Type | Examples |
|---|---|
| Missing documents | Documents that appear to have been altered; unavailability of original documents when expected to exist |
| Reconciliation issues | Significant unexplained items on reconciliations |
| Unusual changes | Balance sheet changes; changes in trends or important ratios (e.g., receivables growing faster than revenues) |
| Implausible responses | Inconsistent, vague, or implausible responses from management or employees |
| Confirmation discrepancies | Unusual discrepancies between entity's records and confirmation replies |
| Accounts receivable issues | Large numbers of credit entries and adjustments; unexplained differences between sub-ledger and control account |
| Missing items | Missing cancelled checks; missing inventory or physical assets of significant magnitude |
| Electronic evidence issues | Unavailable or missing electronic evidence inconsistent with record retention practices |
| Confirmation response issues | Fewer or greater responses than anticipated |
| System development issues | Inability to produce evidence of key systems development and program change testing |
20.3 Problematic or Unusual Relationships with Management
| Type | Examples |
|---|---|
| Denial of access | To records, facilities, certain employees, customers, vendors, or others |
| Time pressures | Undue time pressures to resolve complex or contentious issues |
| Complaints/intimidation | Complaints about conduct of audit; intimidation of engagement team members |
| Delays | Unusual delays in providing requested information |
| Unwillingness to facilitate | Unwillingness to facilitate access to key electronic files for testing |
| Denial of access to IT | Denial of access to key IT operations staff and facilities |
| Unwillingness regarding disclosures | Unwillingness to add or revise disclosures |
| Unwillingness regarding deficiencies | Unwillingness to address identified deficiencies in internal control |
20.4 Other Circumstances
| Type | Examples |
|---|---|
| Meeting restrictions | Unwillingness to permit auditor to meet privately with those charged with governance |
| Accounting policies | Policies that appear at variance with industry norms |
| Frequent estimate changes | Changes in accounting estimates that do not appear to result from changed circumstances |
| Code of conduct violations | Tolerance of violations of the entity's code of conduct |
21. Key Takeaways Summary Table
| Topic | Key Points |
|---|---|
| Definition of Fraud | Intentional act involving deception to obtain unjust or illegal advantage |
| Two Types | Fraudulent financial reporting and misappropriation of assets |
| Three Conditions | Incentive/pressure, opportunity, rationalization |
| Primary Responsibility | Management and those charged with governance |
| Auditor's Responsibility | Reasonable assurance that financial statements are free from material misstatement due to fraud or error |
| Professional Skepticism | Must be maintained throughout the audit; recognize possibility of fraud despite past experience |
| Revenue Recognition | Presumption of fraud risk; can be rebutted with documentation |
| Management Override | Significant risk in all entities; requires specific procedures for journal entries, estimates, and unusual transactions |
| Communication | Timely communication to management and those charged with governance |
| Documentation | Risk assessment, responses, communications, and rebuttal of revenue recognition presumption |
| Withdrawal | Possible in exceptional circumstances; consider legal and professional responsibilities |
| Reporting Outside Entity | Determine if law, regulation, or ethical requirements require or permit reporting |
---
❓ Ready to Test Your Knowledge?
50 MCQs covering all sections. Timed at 1.25 min each (62.5 min total).
📝 Start Q&A →🖨️ Save as PDF