HKSA 240 - Responsibilities Relating to Fraud (Condensed)
| Section | Key Concept | Brief Description |
|---|---|---|
| 1. Introduction and Scope | Scope & Characteristics of Fraud | HKSA 240 covers auditor's responsibilities for fraud in FS audits; fraud is intentional, error is unintentional; two types: fraudulent financial reporting & misappropriation of assets; three conditions: incentive/pressure, opportunity, rationalization. |
| 2. Responsibility for Prevention and Detection | Primary vs Auditor Responsibility | Management & governance have primary responsibility; auditor obtains reasonable assurance FS are free from material misstatement due to fraud; risk of not detecting fraud is higher than error; management fraud harder to detect than employee fraud. |
| 3. Objectives | Three Objectives | (a) Identify & assess risks of material misstatement due to fraud; (b) Obtain sufficient appropriate audit evidence via designed responses; (c) Respond appropriately to identified/suspected fraud. |
| 4. Definitions | Fraud & Fraud Risk Factors | Fraud: intentional act using deception for unjust advantage; fraud risk factors: events/conditions indicating incentive/pressure or opportunity to commit fraud. |
| 5. Professional Skepticism | Maintain Skepticism Throughout | Ongoing questioning of whether evidence suggests material misstatement due to fraud; accept documents as genuine unless reason to believe otherwise; investigate inconsistent responses. |
| 6. Discussion Among Engagement Team | Team Brainstorming | Emphasis on how/where FS may be susceptible to fraud; set aside assumptions of honesty; cover earnings management, disclosure presentation, incentives, asset misappropriation, management override. |
| 7. Risk Assessment Procedures | Inquiries & Evaluation | Inquire of management, internal audit, governance; evaluate unusual relationships; consider other information; evaluate fraud risk factors (incentive/pressure, opportunity, attitude/rationalization). |
| 8. Identification & Assessment of Risks | Presumption of Revenue Recognition Fraud | Presume risks of fraud in revenue recognition unless rebutted; treat assessed risks as significant; document reasons if presumption rebutted. |
| 9. Responses to Assessed Risks | Overall & Assertion Level Responses | Assign personnel, evaluate accounting policies, incorporate unpredictability; design further procedures responsive to assertion-level risks; specific procedures for management override (journal entries, estimates, unusual transactions). |
| 10. Evaluation of Audit Evidence | Analytical Procedures & Misstatement Evaluation | Evaluate near-end analytical procedures for unrecognized fraud risks; if misstatement indicates fraud, evaluate implications; if management involved, reassess risks and evidence reliability. |
| 11. Auditor Unable to Continue | Withdrawal Considerations | If exceptional circumstances (e.g., entity not addressing fraud, significant risk of pervasive fraud, integrity concerns), determine legal responsibilities, consider withdrawal, communicate reasons. |
| 12. Written Representations | Management Representations | Obtain written representations acknowledging responsibility for internal control, disclosing fraud risk assessment results, knowledge of fraud/suspected fraud, and allegations. |
| 13. Communications | To Management & Governance | Communicate identified/suspected fraud to appropriate management level (at least one above involved); communicate to governance if management, key employees, or material fraud involved; discuss suspicions of management fraud with governance. |
| 14. Reporting to External Authority | Public Interest Reporting | Determine if law/ethics require reporting to external authority; consider public interest; if reporting, notify governance in writing unless prohibited or integrity doubted. |
| 15. Documentation | Required Documentation | Document team discussion decisions, assessed risks, identified controls, overall responses, results of procedures, communications, and reasons for rebutting revenue recognition presumption. |
| 16-20. Appendices | Detailed Guidance | Methods of fraudulent financial reporting & misappropriation; fraud risk factors (incentives, opportunities, attitudes); example audit procedures; circumstances indicating possible fraud. |
1. Introduction & Scope (Paras 1-3, A1)
1. Introduction & Scope
Scope of HKSA 240
Deals with auditor's responsibilities relating to fraud in an audit of financial statements. Expands on HKSA 315 (Revised 2019) and HKSA 330 for risks of material misstatement due to fraud.
Characteristics of Fraud
Definition: An intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving deception to obtain an unjust or illegal advantage.
Distinction from Error: The key factor is whether the action is intentional (fraud) or unintentional (error).
Two Types of Intentional Misstatements
| Type | Description |
|---|---|
| Fraudulent Financial Reporting | Intentional misstatements/omissions to deceive users |
| Misappropriation of Assets | Theft of assets, often by employees but can involve management |
Three Conditions When Fraud Exists
| Condition | Description |
|---|---|
| Incentive or Pressure | Management under pressure to meet targets; individuals living beyond means |
| Perceived Opportunity | Belief that internal control can be overridden; knowledge of deficiencies |
| Rationalization | Attitude/ethics allowing intentional dishonest act |
2. Responsibility for Prevention & Detection (Paras 4-9)
2. Responsibility for Prevention & Detection
Primary Responsibility
Rests with those charged with governance and management.
- Management: Emphasis on fraud prevention (reduce opportunities) and deterrence (likelihood of detection/punishment); create culture of honesty and ethical behavior.
- Governance: Oversight includes considering potential for override of controls and inappropriate influence over financial reporting.
Auditor's Responsibility
Obtain reasonable assurance that financial statements are free from material misstatement, whether caused by fraud or error.
- Risk of not detecting fraud is higher than for error.
- Fraud may involve sophisticated concealment (forgery, collusion).
- Detection depends on: skill of perpetrator, frequency/extent of manipulation, degree of collusion, size of amounts, seniority of individuals.
Auditor's Responsibilities for Reasonable Assurance
- Maintain professional skepticism throughout the audit.
- Consider potential for management override of controls.
- Recognize that procedures effective for detecting error may not be effective for fraud.
Additional Responsibilities Under Law/Regulation
| Responsibility | Description |
|---|---|
| Responding to non-compliance | Specific communications with management and governance |
| Assessing appropriateness of response | Evaluating management's response and determining further action |
| Communicating to other auditors | In group audit situations |
| Documentation requirements | Regarding identified or suspected non-compliance |
3. Objectives & Definitions (Paras 11-12)
3. Objectives & Definitions
Objectives of the Auditor
| Objective | Description |
|---|---|
| (a) | Identify and assess risks of material misstatement due to fraud |
| (b) | Obtain sufficient appropriate audit evidence through designing and implementing appropriate responses |
| (c) | Respond appropriately to fraud or suspected fraud identified during the audit |
Definitions
| Term | Definition |
|---|---|
| Fraud | An intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage |
| Fraud risk factors | Events or conditions that indicate an incentive or pressure to commit fraud or provide an opportunity to commit fraud |
4. Professional Skepticism & Team Discussion (Paras 13-16, A8-A12)
4. Professional Skepticism & Team Discussion
Maintaining Professional Skepticism
In accordance with HKSA 200, the auditor shall maintain professional skepticism throughout the audit, recognizing the possibility of material misstatement due to fraud despite past experience of honesty and integrity.
- Ongoing questioning of whether information/evidence suggests fraud.
- Consider reliability of information used as audit evidence.
- Cannot disregard past experience, but circumstances may have changed.
Authenticity of Documents
Accept records/documents as genuine unless reason to believe otherwise. If conditions indicate a document may not be authentic or terms modified, investigate further.
Possible Procedures:
- Confirming directly with the third party
- Using the work of an expert to assess authenticity
Inconsistent Responses
Where responses to inquiries of management or governance are inconsistent, the auditor shall investigate the inconsistencies.
Discussion Among Engagement Team
Emphasis on how and where the financial statements may be susceptible to material misstatement due to fraud. Set aside beliefs that management and governance are honest and have integrity.
| Category | Specific Matters |
|---|---|
| Susceptibility to Fraud | How management could perpetrate/conceal fraudulent financial reporting; how assets could be misappropriated |
| Earnings Management | Circumstances indicative of earnings management; practices that could lead to fraudulent financial reporting |
| Disclosure Presentation | Risk that management may obscure proper understanding (too much immaterial info, unclear language) |
| Incentives and Pressures | Known external/internal factors creating incentive/pressure; opportunities; culture enabling rationalization |
| Asset Misappropriation | Management's involvement in overseeing employees with access to cash or other susceptible assets |
| Behavioral Indicators | Unusual or unexplained changes in behavior or lifestyle of management or employees |
| Professional Mindset | Maintaining proper state of mind regarding potential for material misstatement due to fraud |
| Unpredictability | How to incorporate unpredictability into audit procedures |
| Audit Procedures | Which procedures might be selected; whether certain types are more effective |
| Allegations | Any allegations of fraud that have come to the auditor's attention |
| Management Override | Risk of management override of controls |
5. Risk Assessment Procedures (Paras 17-25, A13-A26)
5. Risk Assessment Procedures
Overview
Perform procedures to obtain information for identifying risks of material misstatement due to fraud.
Inquiries of Management
| Topic | Details |
|---|---|
| Management's assessment of fraud risk | Nature, extent, frequency of assessments |
| Process for identifying/responding to fraud risks | Specific risks identified; classes of transactions/accounts/disclosures where fraud risk likely |
| Communication to those charged with governance | Regarding processes for identifying/responding to fraud risks |
| Communication to employees | Regarding views on business practices and ethical behavior |
Inquiries of Others Within the Entity
Determine whether they have knowledge of any actual, suspected or alleged fraud.
Examples: Operating personnel, employees with different authority levels, those involved in complex transactions, in-house legal counsel, chief ethics officer.
Inquiries of Internal Audit
Determine knowledge of fraud and obtain views about fraud risks. Inquire about procedures performed to detect fraud and management's response to findings.
Those Charged with Governance
Obtain understanding of how they exercise oversight of management's processes for identifying/responding to fraud risks and related controls. Inquire about knowledge of any actual, suspected or alleged fraud.
Unusual or Unexpected Relationships
Evaluate whether relationships identified in analytical procedures (including revenue accounts) may indicate risks of material misstatement due to fraud.
Other Information
Consider whether other information obtained (e.g., from team discussion, client acceptance, other engagements) indicates fraud risks.
Evaluation of Fraud Risk Factors
Evaluate whether information indicates one or more fraud risk factors are present.
| Category | Description |
|---|---|
| Incentive/Pressure | Conditions creating susceptibility to misstatement before consideration of controls |
| Opportunity | Conditions within internal control that provide opportunity to commit fraud |
| Attitude/Rationalization | Conditions affecting management's attitude or ability to rationalize fraudulent actions |
6. Identification, Assessment & Responses to Fraud Risks (Paras 26-34, A29-A49)
6. Identification, Assessment & Responses to Fraud Risks
Identification and Assessment
Identify and assess risks of material misstatement due to fraud at the financial statement level and assertion level.
Common Revenue Recognition Fraud Schemes: Overstatement (premature recognition, fictitious revenues) or understatement (shifting revenues to later period).
Treat assessed risks as significant risks and identify/evaluate controls addressing such risks.
Overall Responses
| Component | Description |
|---|---|
| Assignment and Supervision of Personnel | Assign personnel considering knowledge, skill, ability, and risk assessment |
| Evaluation of Accounting Policies | Evaluate whether selection/application may indicate fraudulent financial reporting (earnings management) |
| Unpredictability | Incorporate unpredictability in nature, timing, and extent of audit procedures |
Ways to Incorporate Unpredictability:
- Perform substantive procedures on accounts not otherwise tested
- Adjust timing of procedures
- Use different sampling methods
- Perform procedures at different locations on unannounced basis
Audit Procedures at the Assertion Level
Design further audit procedures responsive to assessed risks. Changes may include:
| Aspect | Changes |
|---|---|
| Nature | Physical observation/inspection; computer-assisted techniques; additional corroborative information |
| Timing | Substantive testing at/near period end; procedures throughout the period |
| Extent | Increasing sample sizes; more detailed analytical procedures; testing entire populations |
Audit Procedures Responsive to Management Override of Controls
Required Procedures:
| Procedure | Requirements |
|---|---|
| Testing Journal Entries and Other Adjustments | Inquire about inappropriate/unusual activity; select entries at end of period; consider need to test throughout period |
| Reviewing Accounting Estimates for Bias | Evaluate judgments for possible bias; perform retrospective review of prior year assumptions |
| Evaluating Business Rationale for Significant Unusual Transactions | Evaluate whether business rationale suggests fraudulent financial reporting or concealment of misappropriation |
Characteristics of Fraudulent Journal Entries: Made to unrelated/unusual accounts; by individuals who typically don't make entries; at end of period; with little explanation; round numbers.
Indicators of Fraudulent Business Rationale: Overly complex transactions; management not discussing with governance; emphasis on accounting treatment over economics; transactions with non-consolidated related parties.
7. Evaluation of Evidence, Written Representations & Communications (Paras 35-44, A51-A66)
7. Evaluation of Evidence, Written Representations & Communications
Evaluation of Audit Evidence
Analytical Procedures Near End of Audit: Evaluate whether procedures indicate a previously unrecognized risk of material misstatement due to fraud.
Unusual Relationships to Consider: Uncharacteristically large income in last weeks; unusual transactions; income inconsistent with cash flow trends.
Evaluation of Identified Misstatements: If a misstatement is indicative of fraud, evaluate implications for other aspects of the audit, particularly reliability of management representations.
Auditor Unable to Continue the Engagement
If exceptional circumstances bring into question the auditor's ability to continue:
- Determine professional and legal responsibilities
- Consider whether to withdraw from the engagement
- If withdraw, discuss with management and governance; determine if reporting is required
Examples of Exceptional Circumstances: Entity not taking appropriate action; significant risk of material and pervasive fraud; significant concern about competence/integrity of management or governance.
Written Representations
Obtain written representations from management and, where appropriate, governance that:
- They acknowledge responsibility for internal control to prevent/detect fraud
- They have disclosed results of management's fraud risk assessment
- They have disclosed knowledge of fraud/suspected fraud involving management, employees with significant roles in internal control, or others where fraud could have a material effect
- They have disclosed knowledge of any allegations of fraud
Communications to Management and Those Charged with Governance
To Management: Communicate identified fraud or information indicating fraud may exist to appropriate level of management (at least one level above those involved).
To Those Charged with Governance: Communicate if fraud involves management, employees with significant roles in internal control, or others where fraud results in material misstatement. If suspect management fraud, communicate suspicions and discuss nature, timing, and extent of audit procedures.
Other Matters: Communicate concerns about assessments of controls, failure to address deficiencies, evaluation of control environment, actions indicative of fraudulent financial reporting, concerns about authorization of unusual transactions.
Reporting Fraud to an Appropriate Authority Outside the Entity
Determine whether law, regulation, or ethical requirements require or permit reporting to an external authority.
Additional Local Guidance: If fraud could have a material effect, consider whether to report in the public interest. Discuss with governance unless prohibited or integrity doubted. If entity does not voluntarily report, consider reporting yourself.
8. Documentation & Appendices (Paras 45-48, Appendices 1-3)
8. Documentation & Appendices
Documentation Requirements
| Item | Description |
|---|---|
| Risk Assessment Documentation | Significant decisions from team discussion; identified/assessed risks at financial statement and assertion levels; identified controls addressing assessed risks |
| Responses Documentation | Overall responses; nature, timing, extent of procedures; linkage with assessed risks; results of procedures including those for management override |
| Communications Documentation | Communications about fraud made to management, governance, regulators, and others |
| Rebuttal of Revenue Recognition Presumption | If concluded presumption is not applicable, document reasons |
Appendix 1: Fraud Risk Factors
Fraudulent Financial Reporting - Incentives/Pressures: Financial stability threatened; excessive pressure to meet third-party expectations; personal financial situation threatened; excessive pressure to meet financial targets.
Fraudulent Financial Reporting - Opportunities: Nature of industry/operations (significant related-party transactions, estimates, complex transactions); ineffective monitoring of management; complex organizational structure; internal control deficiencies.
Fraudulent Financial Reporting - Attitudes/Rationalizations: Ineffective communication of ethical standards; excessive interest in stock price/earnings trend; failure to remedy deficiencies; strained relationship with auditor.
Misappropriation of Assets - Incentives/Pressures: Personal financial obligations; adverse relationships (layoffs, changes to benefits).
Misappropriation of Assets - Opportunities: Nature of assets (cash, high-value items); inadequate controls (segregation of duties, oversight, record keeping, physical safeguards).
Misappropriation of Assets - Attitudes/Rationalizations: Disregard for controls; behavior indicating dissatisfaction; changes in lifestyle; tolerance of petty theft.
Appendix 2: Examples of Audit Procedures
Procedures at the Assertion Level: Surprise visits; timing adjustments; altering audit approach; detailed review of adjustments; investigating related parties; substantive analytical procedures; interviews; computer-assisted techniques.
Specific Procedures for Revenue Recognition Fraud: Substantive analytical procedures (disaggregated data); confirmation of contract terms; inquiries of sales/marketing personnel; physical presence at period end; testing controls for electronic transactions.
Specific Procedures for Inventory Fraud: Examine inventory records; unannounced observations; timing of counts; additional procedures during observation; comparative analysis; computer-assisted techniques.
Specific Procedures for Management Estimates: Use of expert; extended inquiries of individuals outside management/accounting.
Specific Procedures for Misappropriation of Assets: Counting cash/securities; confirming account activity; analyzing recoveries; comparing inventory ratios; computerized matching of vendor/employee lists; reviewing personnel files; analyzing sales discounts/returns.
Appendix 3: Circumstances Indicating Possibility of Fraud
Discrepancies in Accounting Records: Transactions not recorded completely/timely; unsupported balances; last-minute adjustments; access issues; tips/complaints.
Conflicting or Missing Evidence: Missing/altered documents; significant unexplained reconciliation items; unusual changes in trends; implausible responses; confirmation discrepancies; missing inventory; unavailable electronic evidence.
Problematic Relationships with Management: Denial of access; undue time pressures; complaints/intimidation; unusual delays; unwillingness to facilitate access to IT or key files.
โ Ready to Test?
50 MCQs โข 1.25 min each โข 62.5 min total
๐ Start Q&A โ๐ Full Reference Version๐จ๏ธ Save as PDF