ACCA Strategic Professional · Advanced Audit and Assurance (International)
Fraud and error: formula sheet
Key formulas
- Fraud (ISA 240)
- Fraud = intentional act + deception + unjust or illegal advantage
- Perpetrators can be management, those charged with governance, employees or third parties.
- Error
- Error = unintentional misstatement or omission
- Intent is the only distinguishing factor. The size of the amount does not decide it.
- Types of fraud
- Fraudulent financial reporting | Misappropriation of assets
- The two types relevant to the auditor under ISA 240.
- Non-compliance (ISA 250)
- Non-compliance = act or omission by the entity contrary to law, intentional or not
- Distinct from fraud. It does not require deception.
- Auditor's duty
- Reasonable assurance that financial statements are free from material misstatement, whether from fraud or error
- This is not a guarantee. The risk of missing fraud is higher than for error.
- Fraud triangle
- Fraud risk = Incentive or pressure + Opportunity + Rationalisation
- A conceptual model, not a calculation. Fraud is most likely when all three are present.
- Types of intentional misstatement
- Fraudulent financial reporting; Misappropriation of assets
- These are the two types of fraud relevant to the auditor under ISA 240.
- Presumed risks under ISA 240
- Management override of controls is always a significant risk; revenue recognition is presumed to be a fraud risk
- The revenue presumption can be rebutted, but you must document why. The override risk cannot be rebutted.
- Auditor's responsibility
- Reasonable assurance that the financial statements are free from material misstatement, whether due to fraud or error
- The auditor is not responsible for preventing fraud. Management and those charged with governance are.
- Management and TCWG responsibility
- Prevention and detection of fraud = management (with oversight by TCWG)
- Management designs and operates internal control. TCWG oversee it and set the tone.
- Auditor responsibility
- Reasonable assurance that the financial statements are free from material misstatement, whether due to fraud or error
- Reasonable assurance is high but not absolute. The auditor does not guarantee that fraud is found.
- Professional scepticism
- Questioning mind + alertness to misstatement + critical assessment of evidence
- Maintain it throughout the audit, even if you believe management is honest.
- Inherent limitation
- Risk of not detecting fraud > risk of not detecting error
- Fraud may involve collusion, forgery, deliberate omission or management override.
- Mandatory risk presumption
- Management override of controls = a fraud risk present in every audit
- Respond with tests of journals, estimates and significant unusual transactions.
- Fraud risk factors
- Incentive or pressure + Opportunity + Rationalisation (attitude)
- Use these three headings to structure risk factors you find in a scenario.
- Presumed risk: revenue
- Revenue recognition = presumed fraud risk (rebuttable, with documented reason)
- Rebuttal is possible only with a clear reason, for example simple, non-judgemental revenue.
- Presumed risk: management override
- Management override = always a significant risk (not rebuttable)
- Three mandatory responses: journal entries, estimates bias, significant unusual transactions.
- Fraud risk is a significant risk
- Identified fraud risk → significant risk → evaluate related controls
- Also requires substantive procedures specifically responsive to the risk.
- Levels of response
- Overall response + Specific procedures + Unpredictability
- Cover all three when a question asks how the auditor should respond.
- Who to tell first
- Fraud by employees → management at an appropriate level. Fraud involving management (or employees with significant internal control roles, or fraud causing material misstatement) → TCWG, on a timely basis. Then external parties if a legal or professional duty exists
- If management is involved, go to TCWG. Always consider timeliness.
- Confidentiality exceptions
- Disclosure only if: (a) required by law; (b) permitted by law and authorised by the client; or (c) a professional duty or right to disclose, when not prohibited by law
- Take legal advice. Disclose only what is needed, to the right body.
- Tipping off
- Do not reveal that a money laundering report was made or an investigation is under way
- Report internally to the MLRO. Tipping off can be a criminal offence in many jurisdictions.
- Written representations on fraud
- Management confirms: responsibility for fraud prevention and detection; disclosure of known or suspected fraud; disclosure of allegations of fraud
- If management refuses or the representations are unreliable, reconsider the opinion and the engagement.
- Effect on audit report
- Uncorrected material misstatement from fraud: material but not pervasive → qualified; material and pervasive → adverse. Inability to obtain evidence (limitation on scope): possible effects material but not pervasive → qualified; material and pervasive → disclaimer
- Pervasiveness decides between the two outcomes in each case (ISA 705).
Quick revision
- Fraud is intentional. Error is unintentional.
- Two types of fraud: fraudulent financial reporting and misappropriation of assets.
- Fraud triangle: incentive or pressure, opportunity, rationalisation.
- Management and those charged with governance are responsible for preventing and detecting fraud.
- The auditor obtains reasonable assurance, not a guarantee that fraud is found.
- Fraud risk is higher where there is collusion or concealment, so detection is harder than for error.
- Maintain professional scepticism throughout the audit.
- Hold a team discussion on how and where the financial statements may be misstated by fraud.
- Revenue recognition is presumed to be a fraud risk, and management override of controls is always a risk.
- Respond with journal entry testing, review of estimates for bias, and understanding the business rationale of unusual transactions.
- Add an element of unpredictability to procedures.
- Communicate fraud to management and those charged with governance on a timely basis, and consider legal and ethical duties on confidentiality and reporting.
Common mistakes
- Calling any large misstatement fraud. Fix: Size is not the test. Look for intent and deception. Without them, it is error.
- Saying the auditor must prove or decide that fraud occurred. Fix: The auditor assesses risk and responds. The legal decision belongs to the courts.
- Listing facts from the scenario without explaining why they raise fraud risk. Fix: Use the pattern fact, risk, effect. Say what could be misstated and why.
- Putting factors under the wrong side of the triangle, such as weak controls under pressure. Fix: Pressure is the motive. Opportunity is weak controls or access. Rationalisation is attitude or justification.
- Saying the auditor is responsible for preventing and detecting fraud. Fix: Say management and TCWG are responsible. The auditor obtains reasonable assurance on the financial statements.
- Claiming the auditor gives absolute assurance. Fix: Use the phrase reasonable assurance. Explain the inherent limitations of an audit.
- Listing generic audit procedures that ignore the scenario. Fix: Link each procedure to a named fact, balance or person in the scenario.
- Saying the auditor is responsible for preventing fraud. Fix: State that management and those charged with governance are responsible for prevention and detection. The auditor obtains reasonable assurance.
- Saying the auditor must report all fraud to the regulator. Fix: State that confidentiality applies unless law requires or permits disclosure, or there is a professional duty. Check whether the entity is regulated and take legal advice.
- Telling the client's management that a money laundering report was made. Fix: Explain that tipping off can be an offence. Report to the MLRO and say nothing that reveals the report.
Exam tips
- Define fraud with all three elements: intentional, deception, unjust or illegal advantage. Examiners reward a complete definition.
- Always apply to the scenario. Quote facts that show intent, such as bonus pressure or falsified documents.
- Name the correct type of fraud, then say who is likely to commit it and why that matters.
- State that the auditor gives reasonable assurance and that fraud is harder to detect because of concealment and collusion.
- If law is mentioned, add a short note that non-compliance falls under ISA 250 and is separate from fraud.
- Use the three triangle headings in the answer. They give structure and make marking easy.
- Always link each factor to a type of fraud and an account. This shows application, not recall.
- Include management override whenever the scenario mentions dominant individuals or weak review.