Audit

SA 240 Fraud Risk in Audit: Auditor Responsibilities, Red Flags and Practical Procedures

A practical guide to SA 240 covering fraud versus error, management and auditor responsibilities, revenue fraud risk, management override, red flags, audit responses and documentation.

SA 240 Fraud Risk in Audit: Auditor Responsibilities, Red Flags and Practical Procedures

Fraud risk in a financial statement audit is often misunderstood. An auditor is not engaged to guarantee that every fraud will be found, and management does not transfer its responsibility for preventing fraud to the auditor. Under ICAI's SA 240, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements, the auditor's job is to identify and assess risks of material misstatement due to fraud, obtain sufficient appropriate audit evidence in response to those risks, and respond appropriately to identified or suspected fraud.

Fraud and error are not the same thing

The distinguishing feature is intent. An error is an unintentional misstatement. Fraud involves intentional deception. SA 240 discusses two broad types relevant to an audit: fraudulent financial reporting and misappropriation of assets. Fraudulent financial reporting can include fictitious journal entries, deliberately biased estimates, premature or delayed recognition, concealed facts, or transactions structured to misrepresent financial performance. Misappropriation can include diverted receipts, stolen inventory, fictitious vendors or employees, and personal use of company assets.

Who is responsible for preventing and detecting fraud?

The primary responsibility rests with management and those charged with governance. Their responsibilities include establishing a culture of honesty and ethical behaviour and maintaining controls designed to prevent and detect fraud. The auditor, by contrast, seeks reasonable assurance that the financial statements as a whole are free from material misstatement, whether caused by fraud or error. Reasonable assurance is high assurance, but not an absolute guarantee.

This distinction matters because fraud can be deliberately concealed through collusion, forged documentation, intentional omission or management override. The risk of not detecting a material misstatement caused by fraud is therefore higher than the risk of not detecting one caused by error.

What SA 240 requires the auditor to do

1. Maintain professional scepticism

The auditor must maintain professional scepticism throughout the audit. Past experience that management is honest does not remove the need to question contradictory evidence, unusual transactions or documents whose authenticity appears doubtful. Scepticism is not an assumption that management is dishonest; it is a disciplined refusal to accept weak evidence simply because an explanation sounds plausible.

2. Discuss fraud risk within the engagement team

The engagement team should discuss where and how the financial statements may be susceptible to material fraud. A useful discussion focuses on incentives, opportunities, unusual transactions, areas involving significant judgement, management override and ways controls could be circumvented.

3. Make enquiries and perform risk assessment procedures

The auditor makes enquiries of management about its fraud-risk assessment, known or suspected fraud, and communications about ethical conduct. Enquiries may also extend to internal audit and others within the entity. The auditor evaluates unusual relationships identified through analytical procedures and considers other information that may indicate fraud risk factors.

4. Treat management override as a fraud risk

Management is in a unique position to manipulate accounting records because it can override controls that otherwise appear effective. SA 240 therefore requires specific work addressing management override. This includes testing the appropriateness of journal entries and other adjustments, reviewing accounting estimates for possible management bias, and evaluating the business rationale for significant unusual transactions.

5. Address the presumed fraud risk in revenue recognition

SA 240 requires the auditor to presume that there are fraud risks in revenue recognition and evaluate which types of revenue, transactions or assertions create those risks. The presumption may be rebutted in particular circumstances, but the conclusion and reasons should be documented. The practical response depends on the entity: a subscription business, construction company and cash retailer can have very different revenue-fraud pathways.

A practical fraud-risk example

Assume a company is under pressure to meet a year-end earnings target and revenue rises sharply in the final week of March. Several large sales are posted through manual journal entries, and some goods are dispatched after year-end.

A weak response would be to select a routine invoice sample and stop once invoices are found. A stronger SA 240 response would connect the facts to possible management override and revenue cut-off or occurrence risks. The auditor could inspect late manual journals, trace sales to dispatch and acceptance evidence, review subsequent credit notes and returns, examine unusual customer terms, compare margins, and expand testing if exceptions cluster around year-end. The aim is not merely to prove that documents exist, but to determine whether the recorded revenue represents genuine current-period sales.

Fraud red flags that should change the audit response

  • Unusual or unexplained journal entries near period end.
  • Significant transactions outside the normal course of business.
  • Accounting estimates that consistently favour a desired result.
  • Management restrictions on access to records, people or locations.
  • Conflicting explanations from management and operational staff.
  • Unusual related-party arrangements or transactions lacking commercial rationale.
  • Repeated last-minute adjustments that improve key performance measures.
  • Evidence that controls can be overridden by privileged users without independent review.

A red flag is not proof of fraud. It is a reason to reassess risk and determine whether different or additional audit procedures are needed.

What happens when fraud is identified or suspected?

The auditor must respond to the circumstances rather than silently treating the matter as an ordinary audit difference. That can involve further procedures, reconsideration of the reliability of management representations and previously obtained evidence, and communication with the appropriate level of management or those charged with governance. Legal or regulatory reporting duties may also arise depending on the facts and applicable law.

If the circumstances are so exceptional that they call into question the auditor's ability to continue the engagement, SA 240 requires consideration of professional and legal responsibilities, including whether withdrawal is appropriate where permitted. The auditor should not assume that resignation automatically satisfies any reporting obligation.

A working-paper checklist for fraud risk

  1. Document the engagement-team fraud discussion and key susceptibility areas.
  2. Record management and governance enquiries and any known or suspected fraud.
  3. Identify fraud risks at financial-statement and assertion level.
  4. Document the revenue-recognition fraud assessment and any rebuttal of the presumption.
  5. Design procedures for management override, including journal entries, estimates and unusual transactions.
  6. Record contradictory evidence and how it was resolved.
  7. Evaluate whether identified misstatements indicate a broader fraud issue.
  8. Document required communications and the effect on the audit conclusion.

Practical takeaway

SA 240 does not turn a statutory audit into a forensic investigation, but it does require fraud risk to shape the audit from planning through conclusion. The strongest approach is to connect incentives and opportunities to specific financial-statement risks, respond with evidence designed for those risks, and remain alert to management override and contradictory evidence. ICAI's current Auditing, Review and Other Standards repository provides the official standards framework for practitioners who need to read SA 240 alongside related Standards on Auditing.

Related Articles

Subscribe To Our Newsletter

Subscribe us to get updates on latest Jobs Openings, News, Articles, Notices/ Circulars

Submit

© 2026 CA Samaaj. All rights reserved.

Join Whatsapp Group of CA Samaaj