๐Ÿ“ Condensed Version โ€” Key points only ๐Ÿ“š Full Reference โ†’
๐Ÿ“„ PDF โ€” HKICPA Handbook Vol III

PDF viewer not supported.

๐ŸŽฅ Video Lesson (Coming Soon)
๐ŸŽฌVideo walkthrough coming soon.
SectionKey ConceptBrief Description
1. Introduction and ScopeScope & Characteristics of FraudHKSA 240 covers auditor's responsibilities for fraud in FS audits; fraud is intentional, error is unintentional; two types: fraudulent financial reporting & misappropriation of assets; three conditions: incentive/pressure, opportunity, rationalization.
2. Responsibility for Prevention and DetectionPrimary vs Auditor ResponsibilityManagement & governance have primary responsibility; auditor obtains reasonable assurance FS are free from material misstatement due to fraud; risk of not detecting fraud is higher than error; management fraud harder to detect than employee fraud.
3. ObjectivesThree Objectives(a) Identify & assess risks of material misstatement due to fraud; (b) Obtain sufficient appropriate audit evidence via designed responses; (c) Respond appropriately to identified/suspected fraud.
4. DefinitionsFraud & Fraud Risk FactorsFraud: intentional act using deception for unjust advantage; fraud risk factors: events/conditions indicating incentive/pressure or opportunity to commit fraud.
5. Professional SkepticismMaintain Skepticism ThroughoutOngoing questioning of whether evidence suggests material misstatement due to fraud; accept documents as genuine unless reason to believe otherwise; investigate inconsistent responses.
6. Discussion Among Engagement TeamTeam BrainstormingEmphasis on how/where FS may be susceptible to fraud; set aside assumptions of honesty; cover earnings management, disclosure presentation, incentives, asset misappropriation, management override.
7. Risk Assessment ProceduresInquiries & EvaluationInquire of management, internal audit, governance; evaluate unusual relationships; consider other information; evaluate fraud risk factors (incentive/pressure, opportunity, attitude/rationalization).
8. Identification & Assessment of RisksPresumption of Revenue Recognition FraudPresume risks of fraud in revenue recognition unless rebutted; treat assessed risks as significant; document reasons if presumption rebutted.
9. Responses to Assessed RisksOverall & Assertion Level ResponsesAssign personnel, evaluate accounting policies, incorporate unpredictability; design further procedures responsive to assertion-level risks; specific procedures for management override (journal entries, estimates, unusual transactions).
10. Evaluation of Audit EvidenceAnalytical Procedures & Misstatement EvaluationEvaluate near-end analytical procedures for unrecognized fraud risks; if misstatement indicates fraud, evaluate implications; if management involved, reassess risks and evidence reliability.
11. Auditor Unable to ContinueWithdrawal ConsiderationsIf exceptional circumstances (e.g., entity not addressing fraud, significant risk of pervasive fraud, integrity concerns), determine legal responsibilities, consider withdrawal, communicate reasons.
12. Written RepresentationsManagement RepresentationsObtain written representations acknowledging responsibility for internal control, disclosing fraud risk assessment results, knowledge of fraud/suspected fraud, and allegations.
13. CommunicationsTo Management & GovernanceCommunicate identified/suspected fraud to appropriate management level (at least one above involved); communicate to governance if management, key employees, or material fraud involved; discuss suspicions of management fraud with governance.
14. Reporting to External AuthorityPublic Interest ReportingDetermine if law/ethics require reporting to external authority; consider public interest; if reporting, notify governance in writing unless prohibited or integrity doubted.
15. DocumentationRequired DocumentationDocument team discussion decisions, assessed risks, identified controls, overall responses, results of procedures, communications, and reasons for rebutting revenue recognition presumption.
16-20. AppendicesDetailed GuidanceMethods of fraudulent financial reporting & misappropriation; fraud risk factors (incentives, opportunities, attitudes); example audit procedures; circumstances indicating possible fraud.
Ad Space

1. Introduction & Scope (Paras 1-3, A1)

1. Introduction & Scope

Scope of HKSA 240

Deals with auditor's responsibilities relating to fraud in an audit of financial statements. Expands on HKSA 315 (Revised 2019) and HKSA 330 for risks of material misstatement due to fraud.

Effective Date: Audits for periods beginning on or after 15 December 2009.

Characteristics of Fraud

Definition: An intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving deception to obtain an unjust or illegal advantage.

Distinction from Error: The key factor is whether the action is intentional (fraud) or unintentional (error).

Two Types of Intentional Misstatements

TypeDescription
Fraudulent Financial ReportingIntentional misstatements/omissions to deceive users
Misappropriation of AssetsTheft of assets, often by employees but can involve management
Important: The auditor does not make legal determinations of whether fraud has actually occurred.

Three Conditions When Fraud Exists

ConditionDescription
Incentive or PressureManagement under pressure to meet targets; individuals living beyond means
Perceived OpportunityBelief that internal control can be overridden; knowledge of deficiencies
RationalizationAttitude/ethics allowing intentional dishonest act
Ad Space

2. Responsibility for Prevention & Detection (Paras 4-9)

2. Responsibility for Prevention & Detection

Primary Responsibility

Rests with those charged with governance and management.

  • Management: Emphasis on fraud prevention (reduce opportunities) and deterrence (likelihood of detection/punishment); create culture of honesty and ethical behavior.
  • Governance: Oversight includes considering potential for override of controls and inappropriate influence over financial reporting.

Auditor's Responsibility

Obtain reasonable assurance that financial statements are free from material misstatement, whether caused by fraud or error.

Key Points:
  • Risk of not detecting fraud is higher than for error.
  • Fraud may involve sophisticated concealment (forgery, collusion).
  • Detection depends on: skill of perpetrator, frequency/extent of manipulation, degree of collusion, size of amounts, seniority of individuals.
Management Fraud vs Employee Fraud: Risk of not detecting management fraud is greater because management can manipulate records, present fraudulent information, or override controls.

Auditor's Responsibilities for Reasonable Assurance

  1. Maintain professional skepticism throughout the audit.
  2. Consider potential for management override of controls.
  3. Recognize that procedures effective for detecting error may not be effective for fraud.

Additional Responsibilities Under Law/Regulation

ResponsibilityDescription
Responding to non-complianceSpecific communications with management and governance
Assessing appropriateness of responseEvaluating management's response and determining further action
Communicating to other auditorsIn group audit situations
Documentation requirementsRegarding identified or suspected non-compliance
Ad Space

3. Objectives & Definitions (Paras 11-12)

3. Objectives & Definitions

Objectives of the Auditor

ObjectiveDescription
(a)Identify and assess risks of material misstatement due to fraud
(b)Obtain sufficient appropriate audit evidence through designing and implementing appropriate responses
(c)Respond appropriately to fraud or suspected fraud identified during the audit

Definitions

TermDefinition
FraudAn intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage
Fraud risk factorsEvents or conditions that indicate an incentive or pressure to commit fraud or provide an opportunity to commit fraud
Ad Space

4. Professional Skepticism & Team Discussion (Paras 13-16, A8-A12)

4. Professional Skepticism & Team Discussion

Maintaining Professional Skepticism

In accordance with HKSA 200, the auditor shall maintain professional skepticism throughout the audit, recognizing the possibility of material misstatement due to fraud despite past experience of honesty and integrity.

Key Points:
  • Ongoing questioning of whether information/evidence suggests fraud.
  • Consider reliability of information used as audit evidence.
  • Cannot disregard past experience, but circumstances may have changed.

Authenticity of Documents

Accept records/documents as genuine unless reason to believe otherwise. If conditions indicate a document may not be authentic or terms modified, investigate further.

Possible Procedures:

  1. Confirming directly with the third party
  2. Using the work of an expert to assess authenticity

Inconsistent Responses

Where responses to inquiries of management or governance are inconsistent, the auditor shall investigate the inconsistencies.

Discussion Among Engagement Team

Emphasis on how and where the financial statements may be susceptible to material misstatement due to fraud. Set aside beliefs that management and governance are honest and have integrity.

CategorySpecific Matters
Susceptibility to FraudHow management could perpetrate/conceal fraudulent financial reporting; how assets could be misappropriated
Earnings ManagementCircumstances indicative of earnings management; practices that could lead to fraudulent financial reporting
Disclosure PresentationRisk that management may obscure proper understanding (too much immaterial info, unclear language)
Incentives and PressuresKnown external/internal factors creating incentive/pressure; opportunities; culture enabling rationalization
Asset MisappropriationManagement's involvement in overseeing employees with access to cash or other susceptible assets
Behavioral IndicatorsUnusual or unexplained changes in behavior or lifestyle of management or employees
Professional MindsetMaintaining proper state of mind regarding potential for material misstatement due to fraud
UnpredictabilityHow to incorporate unpredictability into audit procedures
Audit ProceduresWhich procedures might be selected; whether certain types are more effective
AllegationsAny allegations of fraud that have come to the auditor's attention
Management OverrideRisk of management override of controls
Ad Space

5. Risk Assessment Procedures (Paras 17-25, A13-A26)

5. Risk Assessment Procedures

Overview

Perform procedures to obtain information for identifying risks of material misstatement due to fraud.

Inquiries of Management

TopicDetails
Management's assessment of fraud riskNature, extent, frequency of assessments
Process for identifying/responding to fraud risksSpecific risks identified; classes of transactions/accounts/disclosures where fraud risk likely
Communication to those charged with governanceRegarding processes for identifying/responding to fraud risks
Communication to employeesRegarding views on business practices and ethical behavior

Inquiries of Others Within the Entity

Determine whether they have knowledge of any actual, suspected or alleged fraud.

Examples: Operating personnel, employees with different authority levels, those involved in complex transactions, in-house legal counsel, chief ethics officer.

Inquiries of Internal Audit

Determine knowledge of fraud and obtain views about fraud risks. Inquire about procedures performed to detect fraud and management's response to findings.

Those Charged with Governance

Obtain understanding of how they exercise oversight of management's processes for identifying/responding to fraud risks and related controls. Inquire about knowledge of any actual, suspected or alleged fraud.

Unusual or Unexpected Relationships

Evaluate whether relationships identified in analytical procedures (including revenue accounts) may indicate risks of material misstatement due to fraud.

Other Information

Consider whether other information obtained (e.g., from team discussion, client acceptance, other engagements) indicates fraud risks.

Evaluation of Fraud Risk Factors

Evaluate whether information indicates one or more fraud risk factors are present.

CategoryDescription
Incentive/PressureConditions creating susceptibility to misstatement before consideration of controls
OpportunityConditions within internal control that provide opportunity to commit fraud
Attitude/RationalizationConditions affecting management's attitude or ability to rationalize fraudulent actions
Ad Space

6. Identification, Assessment & Responses to Fraud Risks (Paras 26-34, A29-A49)

6. Identification, Assessment & Responses to Fraud Risks

Identification and Assessment

Identify and assess risks of material misstatement due to fraud at the financial statement level and assertion level.

Presumption of Fraud in Revenue Recognition: The auditor shall presume there are risks of fraud in revenue recognition. If rebutted, document reasons in audit documentation.

Common Revenue Recognition Fraud Schemes: Overstatement (premature recognition, fictitious revenues) or understatement (shifting revenues to later period).

Treat assessed risks as significant risks and identify/evaluate controls addressing such risks.

Overall Responses

ComponentDescription
Assignment and Supervision of PersonnelAssign personnel considering knowledge, skill, ability, and risk assessment
Evaluation of Accounting PoliciesEvaluate whether selection/application may indicate fraudulent financial reporting (earnings management)
UnpredictabilityIncorporate unpredictability in nature, timing, and extent of audit procedures

Ways to Incorporate Unpredictability:

  • Perform substantive procedures on accounts not otherwise tested
  • Adjust timing of procedures
  • Use different sampling methods
  • Perform procedures at different locations on unannounced basis

Audit Procedures at the Assertion Level

Design further audit procedures responsive to assessed risks. Changes may include:

AspectChanges
NaturePhysical observation/inspection; computer-assisted techniques; additional corroborative information
TimingSubstantive testing at/near period end; procedures throughout the period
ExtentIncreasing sample sizes; more detailed analytical procedures; testing entire populations

Audit Procedures Responsive to Management Override of Controls

Key Point: Management is in a unique position to perpetrate fraud by overriding controls. This risk is present in all entities and is a significant risk.

Required Procedures:

ProcedureRequirements
Testing Journal Entries and Other AdjustmentsInquire about inappropriate/unusual activity; select entries at end of period; consider need to test throughout period
Reviewing Accounting Estimates for BiasEvaluate judgments for possible bias; perform retrospective review of prior year assumptions
Evaluating Business Rationale for Significant Unusual TransactionsEvaluate whether business rationale suggests fraudulent financial reporting or concealment of misappropriation

Characteristics of Fraudulent Journal Entries: Made to unrelated/unusual accounts; by individuals who typically don't make entries; at end of period; with little explanation; round numbers.

Indicators of Fraudulent Business Rationale: Overly complex transactions; management not discussing with governance; emphasis on accounting treatment over economics; transactions with non-consolidated related parties.

Ad Space

7. Evaluation of Evidence, Written Representations & Communications (Paras 35-44, A51-A66)

7. Evaluation of Evidence, Written Representations & Communications

Evaluation of Audit Evidence

Analytical Procedures Near End of Audit: Evaluate whether procedures indicate a previously unrecognized risk of material misstatement due to fraud.

Unusual Relationships to Consider: Uncharacteristically large income in last weeks; unusual transactions; income inconsistent with cash flow trends.

Evaluation of Identified Misstatements: If a misstatement is indicative of fraud, evaluate implications for other aspects of the audit, particularly reliability of management representations.

Fraud Involving Management: If fraud involves senior management, reassess risks of material misstatement due to fraud and impact on nature, timing, and extent of audit procedures. Consider possible collusion.

Auditor Unable to Continue the Engagement

If exceptional circumstances bring into question the auditor's ability to continue:

  1. Determine professional and legal responsibilities
  2. Consider whether to withdraw from the engagement
  3. If withdraw, discuss with management and governance; determine if reporting is required

Examples of Exceptional Circumstances: Entity not taking appropriate action; significant risk of material and pervasive fraud; significant concern about competence/integrity of management or governance.

Written Representations

Obtain written representations from management and, where appropriate, governance that:

  • They acknowledge responsibility for internal control to prevent/detect fraud
  • They have disclosed results of management's fraud risk assessment
  • They have disclosed knowledge of fraud/suspected fraud involving management, employees with significant roles in internal control, or others where fraud could have a material effect
  • They have disclosed knowledge of any allegations of fraud

Communications to Management and Those Charged with Governance

To Management: Communicate identified fraud or information indicating fraud may exist to appropriate level of management (at least one level above those involved).

To Those Charged with Governance: Communicate if fraud involves management, employees with significant roles in internal control, or others where fraud results in material misstatement. If suspect management fraud, communicate suspicions and discuss nature, timing, and extent of audit procedures.

Other Matters: Communicate concerns about assessments of controls, failure to address deficiencies, evaluation of control environment, actions indicative of fraudulent financial reporting, concerns about authorization of unusual transactions.

Reporting Fraud to an Appropriate Authority Outside the Entity

Determine whether law, regulation, or ethical requirements require or permit reporting to an external authority.

Additional Local Guidance: If fraud could have a material effect, consider whether to report in the public interest. Discuss with governance unless prohibited or integrity doubted. If entity does not voluntarily report, consider reporting yourself.

Confidentiality Note: The duty of confidentiality is not absolute. In certain exceptional circumstances, an auditor is not bound by it.
Ad Space

8. Documentation & Appendices (Paras 45-48, Appendices 1-3)

8. Documentation & Appendices

Documentation Requirements

ItemDescription
Risk Assessment DocumentationSignificant decisions from team discussion; identified/assessed risks at financial statement and assertion levels; identified controls addressing assessed risks
Responses DocumentationOverall responses; nature, timing, extent of procedures; linkage with assessed risks; results of procedures including those for management override
Communications DocumentationCommunications about fraud made to management, governance, regulators, and others
Rebuttal of Revenue Recognition PresumptionIf concluded presumption is not applicable, document reasons

Appendix 1: Fraud Risk Factors

Fraudulent Financial Reporting - Incentives/Pressures: Financial stability threatened; excessive pressure to meet third-party expectations; personal financial situation threatened; excessive pressure to meet financial targets.

Fraudulent Financial Reporting - Opportunities: Nature of industry/operations (significant related-party transactions, estimates, complex transactions); ineffective monitoring of management; complex organizational structure; internal control deficiencies.

Fraudulent Financial Reporting - Attitudes/Rationalizations: Ineffective communication of ethical standards; excessive interest in stock price/earnings trend; failure to remedy deficiencies; strained relationship with auditor.

Misappropriation of Assets - Incentives/Pressures: Personal financial obligations; adverse relationships (layoffs, changes to benefits).

Misappropriation of Assets - Opportunities: Nature of assets (cash, high-value items); inadequate controls (segregation of duties, oversight, record keeping, physical safeguards).

Misappropriation of Assets - Attitudes/Rationalizations: Disregard for controls; behavior indicating dissatisfaction; changes in lifestyle; tolerance of petty theft.

Appendix 2: Examples of Audit Procedures

Procedures at the Assertion Level: Surprise visits; timing adjustments; altering audit approach; detailed review of adjustments; investigating related parties; substantive analytical procedures; interviews; computer-assisted techniques.

Specific Procedures for Revenue Recognition Fraud: Substantive analytical procedures (disaggregated data); confirmation of contract terms; inquiries of sales/marketing personnel; physical presence at period end; testing controls for electronic transactions.

Specific Procedures for Inventory Fraud: Examine inventory records; unannounced observations; timing of counts; additional procedures during observation; comparative analysis; computer-assisted techniques.

Specific Procedures for Management Estimates: Use of expert; extended inquiries of individuals outside management/accounting.

Specific Procedures for Misappropriation of Assets: Counting cash/securities; confirming account activity; analyzing recoveries; comparing inventory ratios; computerized matching of vendor/employee lists; reviewing personnel files; analyzing sales discounts/returns.

Appendix 3: Circumstances Indicating Possibility of Fraud

Discrepancies in Accounting Records: Transactions not recorded completely/timely; unsupported balances; last-minute adjustments; access issues; tips/complaints.

Conflicting or Missing Evidence: Missing/altered documents; significant unexplained reconciliation items; unusual changes in trends; implausible responses; confirmation discrepancies; missing inventory; unavailable electronic evidence.

Problematic Relationships with Management: Denial of access; undue time pressures; complaints/intimidation; unusual delays; unwillingness to facilitate access to IT or key files.

โ“ Ready to Test?

50 MCQs โ€ข 1.25 min each โ€ข 62.5 min total

๐Ÿ“ Start Q&A โ†’๐Ÿ“š Full Reference Version๐Ÿ–จ๏ธ Save as PDF