Skip to content

ACCA Strategic Professional · Advanced Audit and Assurance (International)

Fraud and error: formula sheet

Full chapter guide

Key formulas

Fraud (ISA 240)
Fraud = intentional act + deception + unjust or illegal advantage
Perpetrators can be management, those charged with governance, employees or third parties.
Error
Error = unintentional misstatement or omission
Intent is the only distinguishing factor. The size of the amount does not decide it.
Types of fraud
Fraudulent financial reporting | Misappropriation of assets
The two types relevant to the auditor under ISA 240.
Non-compliance (ISA 250)
Non-compliance = act or omission by the entity contrary to law, intentional or not
Distinct from fraud. It does not require deception.
Auditor's duty
Reasonable assurance that financial statements are free from material misstatement, whether from fraud or error
This is not a guarantee. The risk of missing fraud is higher than for error.
Fraud triangle
Fraud risk = Incentive or pressure + Opportunity + Rationalisation
A conceptual model, not a calculation. Fraud is most likely when all three are present.
Types of intentional misstatement
Fraudulent financial reporting; Misappropriation of assets
These are the two types of fraud relevant to the auditor under ISA 240.
Presumed risks under ISA 240
Management override of controls is always a significant risk; revenue recognition is presumed to be a fraud risk
The revenue presumption can be rebutted, but you must document why. The override risk cannot be rebutted.
Auditor's responsibility
Reasonable assurance that the financial statements are free from material misstatement, whether due to fraud or error
The auditor is not responsible for preventing fraud. Management and those charged with governance are.
Management and TCWG responsibility
Prevention and detection of fraud = management (with oversight by TCWG)
Management designs and operates internal control. TCWG oversee it and set the tone.
Auditor responsibility
Reasonable assurance that the financial statements are free from material misstatement, whether due to fraud or error
Reasonable assurance is high but not absolute. The auditor does not guarantee that fraud is found.
Professional scepticism
Questioning mind + alertness to misstatement + critical assessment of evidence
Maintain it throughout the audit, even if you believe management is honest.
Inherent limitation
Risk of not detecting fraud > risk of not detecting error
Fraud may involve collusion, forgery, deliberate omission or management override.
Mandatory risk presumption
Management override of controls = a fraud risk present in every audit
Respond with tests of journals, estimates and significant unusual transactions.
Fraud risk factors
Incentive or pressure + Opportunity + Rationalisation (attitude)
Use these three headings to structure risk factors you find in a scenario.
Presumed risk: revenue
Revenue recognition = presumed fraud risk (rebuttable, with documented reason)
Rebuttal is possible only with a clear reason, for example simple, non-judgemental revenue.
Presumed risk: management override
Management override = always a significant risk (not rebuttable)
Three mandatory responses: journal entries, estimates bias, significant unusual transactions.
Fraud risk is a significant risk
Identified fraud risk → significant risk → evaluate related controls
Also requires substantive procedures specifically responsive to the risk.
Levels of response
Overall response + Specific procedures + Unpredictability
Cover all three when a question asks how the auditor should respond.
Who to tell first
Fraud by employees → management at an appropriate level. Fraud involving management (or employees with significant internal control roles, or fraud causing material misstatement) → TCWG, on a timely basis. Then external parties if a legal or professional duty exists
If management is involved, go to TCWG. Always consider timeliness.
Confidentiality exceptions
Disclosure only if: (a) required by law; (b) permitted by law and authorised by the client; or (c) a professional duty or right to disclose, when not prohibited by law
Take legal advice. Disclose only what is needed, to the right body.
Tipping off
Do not reveal that a money laundering report was made or an investigation is under way
Report internally to the MLRO. Tipping off can be a criminal offence in many jurisdictions.
Written representations on fraud
Management confirms: responsibility for fraud prevention and detection; disclosure of known or suspected fraud; disclosure of allegations of fraud
If management refuses or the representations are unreliable, reconsider the opinion and the engagement.
Effect on audit report
Uncorrected material misstatement from fraud: material but not pervasive → qualified; material and pervasive → adverse. Inability to obtain evidence (limitation on scope): possible effects material but not pervasive → qualified; material and pervasive → disclaimer
Pervasiveness decides between the two outcomes in each case (ISA 705).

Quick revision

  • Fraud is intentional. Error is unintentional.
  • Two types of fraud: fraudulent financial reporting and misappropriation of assets.
  • Fraud triangle: incentive or pressure, opportunity, rationalisation.
  • Management and those charged with governance are responsible for preventing and detecting fraud.
  • The auditor obtains reasonable assurance, not a guarantee that fraud is found.
  • Fraud risk is higher where there is collusion or concealment, so detection is harder than for error.
  • Maintain professional scepticism throughout the audit.
  • Hold a team discussion on how and where the financial statements may be misstated by fraud.
  • Revenue recognition is presumed to be a fraud risk, and management override of controls is always a risk.
  • Respond with journal entry testing, review of estimates for bias, and understanding the business rationale of unusual transactions.
  • Add an element of unpredictability to procedures.
  • Communicate fraud to management and those charged with governance on a timely basis, and consider legal and ethical duties on confidentiality and reporting.

Common mistakes

  • Calling any large misstatement fraud. Fix: Size is not the test. Look for intent and deception. Without them, it is error.
  • Saying the auditor must prove or decide that fraud occurred. Fix: The auditor assesses risk and responds. The legal decision belongs to the courts.
  • Listing facts from the scenario without explaining why they raise fraud risk. Fix: Use the pattern fact, risk, effect. Say what could be misstated and why.
  • Putting factors under the wrong side of the triangle, such as weak controls under pressure. Fix: Pressure is the motive. Opportunity is weak controls or access. Rationalisation is attitude or justification.
  • Saying the auditor is responsible for preventing and detecting fraud. Fix: Say management and TCWG are responsible. The auditor obtains reasonable assurance on the financial statements.
  • Claiming the auditor gives absolute assurance. Fix: Use the phrase reasonable assurance. Explain the inherent limitations of an audit.
  • Listing generic audit procedures that ignore the scenario. Fix: Link each procedure to a named fact, balance or person in the scenario.
  • Saying the auditor is responsible for preventing fraud. Fix: State that management and those charged with governance are responsible for prevention and detection. The auditor obtains reasonable assurance.
  • Saying the auditor must report all fraud to the regulator. Fix: State that confidentiality applies unless law requires or permits disclosure, or there is a professional duty. Check whether the entity is regulated and take legal advice.
  • Telling the client's management that a money laundering report was made. Fix: Explain that tipping off can be an offence. Report to the MLRO and say nothing that reveals the report.

Exam tips

  • Define fraud with all three elements: intentional, deception, unjust or illegal advantage. Examiners reward a complete definition.
  • Always apply to the scenario. Quote facts that show intent, such as bonus pressure or falsified documents.
  • Name the correct type of fraud, then say who is likely to commit it and why that matters.
  • State that the auditor gives reasonable assurance and that fraud is harder to detect because of concealment and collusion.
  • If law is mentioned, add a short note that non-compliance falls under ISA 250 and is separate from fraud.
  • Use the three triangle headings in the answer. They give structure and make marking easy.
  • Always link each factor to a type of fraud and an account. This shows application, not recall.
  • Include management override whenever the scenario mentions dominant individuals or weak review.