Audit and Assurance · Audit planning and documentation
Fraud, Laws and Going Concern at Audit Planning
Updated 11 October 2026 · Fact-checked
At planning, the auditor must assess the risks of material misstatement from fraud, error and non-compliance with laws, and consider whether going concern doubts exist. Management is responsible for prevention and detection. The auditor obtains reasonable assurance, maintains scepticism, discusses risks with the team, and designs responses to the risks identified.
Understand Fraud, Laws and Going Concern at Planning Stage
Start with who is responsible. Management and those charged with governance are responsible for preventing and detecting fraud, for complying with laws and regulations, and for assessing going concern when preparing the financial statements. The auditor does not take over these duties.
The auditor's job is different. Under ISA 240 you obtain reasonable assurance that the financial statements are free from material misstatement, whether caused by fraud or error. Fraud is intentional: an act involving deception to gain an unjust or illegal advantage. Error is unintentional. Fraud is harder to find than error because it may involve concealment, collusion and forgery, and management can override controls. So an audit cannot guarantee that fraud is found.
At planning, ISA 240 expects you to do several things. Keep professional scepticism throughout. Hold a team discussion on where the financial statements may be open to fraud. Make enquiries of management, those charged with governance and internal audit about fraud risks. Consider fraud risk factors: incentive or pressure, opportunity and attitude or rationalisation (the fraud triangle). Presume that revenue recognition is a fraud risk and treat management override of controls as a risk. Identified fraud risks are significant risks.
ISA 250 covers laws and regulations. Some have a direct effect on the numbers, such as tax and pension laws. Others do not affect the numbers directly but may matter for the business, such as health and safety or licensing. For the first group you obtain sufficient appropriate evidence of compliance. For the second you perform limited procedures: enquiries of management and inspecting correspondence with regulators. You stay alert for non-compliance when other procedures are carried out.
ISA 570 covers going concern. Management assesses whether the entity can continue for at least twelve months from the date of the financial statements. At planning, the auditor performs risk assessment procedures to identify events or conditions that may cast significant doubt on this. Typical indicators are financial (net current liability position, negative operating cash flows, loan defaults, loss of key finance), operating (loss of key management, a major customer or supplier, labour problems) and other (legal action, changes in law, uninsured disasters). Early identification shapes the audit plan, the team and the work needed later.
Key rules to remember
- Fraud risk factors (fraud triangle)
- Fraud = Incentive or pressure + Opportunity + Attitude or rationalisation
- Use these three headings to structure answers on why a fraud risk exists in a scenario.
- Responsibility split for fraud
- Management and those charged with governance: prevent and detect. Auditor: reasonable assurance on material misstatement.
- The auditor is not responsible for preventing fraud.
- Presumed fraud risks (ISA 240)
- Revenue recognition + management override of controls
- Revenue is a presumption that can be rebutted with reasons. Management override cannot be rebutted. Both are treated as significant risks.
- ISA 250 two categories of law
- Laws with direct effect on the numbers: obtain sufficient appropriate evidence. Other laws: limited procedures (enquiry, inspection of regulator correspondence).
- Always say which category a law falls into.
- Going concern period
- Management assessment covers at least 12 months from the date of the financial statements
- The auditor considers events up to the date of the auditor's report.
How to solve Fraud, Laws and Going Concern at Planning Stage questions
Use this method for any scenario question on fraud, laws or going concern at planning.
- 1Read the requirement and note whether it asks for responsibilities, risks, indicators or audit responses.
- 2Scan the scenario and highlight facts that point to pressure, opportunity or attitude (targets, bonuses, weak controls, dominant director), non-compliance (regulator letters, fines, licences) or going concern (losses, loan covenants, cash problems).
- 3For each fact, state the risk in one sentence: what could be misstated or what could go wrong.
- 4Explain why it matters, such as overstated revenue, unrecorded liabilities or an inappropriate going concern basis.
- 5Give the auditor's response: team discussion, enquiries, senior staff, more testing, evidence of laws or management's forecasts.
- 6If responsibilities are asked, state management's role first, then the auditor's role, and add that the audit cannot guarantee detection.
- 7Finish with the effect on the audit plan, such as treating the item as a significant risk.
Quickest way: Fact, risk, response in three lines
When to use it: Use this under time pressure in Section C or a Section B case with a scenario.
- Underline each fact that signals a problem.
- Write each point as: fact, risk, auditor response.
- Name the category: fraud (triangle heading), law (direct or indirect) or going concern (financial, operating or other).
- Check each point has a response, since marks usually go for responses too.
Common mistakes in Fraud, Laws and Going Concern at Planning Stage
Saying the auditor is responsible for preventing and detecting fraud.
Students link the audit with finding problems and forget the responsibility split.
Fix: Say management and those charged with governance prevent and detect. The auditor obtains reasonable assurance and responds to risks.
Confusing fraud and error.
Both cause misstatement, so the key difference of intent is overlooked.
Fix: Fraud is intentional. Error is unintentional. Define the term before you apply it.
Listing going concern indicators without explaining why they matter or what the auditor does.
Students memorise lists and stop there.
Fix: Link each indicator to the risk of an inappropriate going concern basis and add an audit response, such as reviewing cash flow forecasts and loan agreements.
Treating all laws and regulations the same way under ISA 250.
Students remember that auditors must watch for non-compliance but not the two categories.
Fix: Separate laws with a direct effect on the numbers from other laws. State the evidence level for each.
Giving generic fraud answers that ignore the scenario.
Students recite the fraud triangle without using the facts.
Fix: Quote or paraphrase specific facts from the scenario for each triangle heading.
Forgetting the presumed risks of revenue and management override.
Students focus on asset theft and overlook financial reporting fraud.
Fix: Always consider revenue and management override at planning and call them significant risks.
Worked examples
Example 1
Pemberton Co's finance director receives a bonus only if profit exceeds a target. The company has weak controls over journal entries and the finance director also dominates the board. Profit is currently just below the target. Explain the fraud risk factors and the auditor's planning response.
Show the solution
- Incentive or pressure: the bonus depends on profit, and profit is just below target, so there is motivation to overstate profit.
- Opportunity: weak control over journals and a dominant director make override and manipulation easier.
- Attitude or rationalisation: a dominant individual may feel the rules do not apply, so this is a possible risk. Note that this is an indicator and not proof.
- Risk: revenue may be overstated or expenses understated, and journals may be used to adjust results.
- Response: hold a team discussion on fraud, apply scepticism, treat revenue and management override as significant risks, assign experienced staff and test journals and unusual entries.
- Also make enquiries of management and those charged with governance about their awareness of fraud.
Answer: The bonus and near-miss profit give incentive, weak journal controls and dominance give opportunity, and the dominant director suggests a risky attitude. The auditor should treat revenue and management override as significant risks, test journals, use senior staff and apply scepticism.
Example 2
Harlow Ltd is a manufacturer. It has breached a loan covenant, its bank overdraft is at its limit, it has lost its largest customer and it received a letter from an environmental regulator about a possible breach of emissions rules. Explain the planning implications under ISA 570 and ISA 250.
Show the solution
- Going concern, financial indicator: the covenant breach means the lender could demand repayment, and the overdraft at limit shows liquidity pressure.
- Going concern, operating indicator: loss of the largest customer reduces future revenue and cash inflows.
- Planning response: ask management for its going concern assessment and cash flow forecasts, review loan terms, discuss with the lender if possible and plan to test the forecast assumptions.
- ISA 250: emissions rules are unlikely to affect the figures directly, so they are in the second category. However, fines or closure could create provisions, contingent liabilities or a going concern problem.
- Response on law: enquire of management, inspect the regulator's correspondence and consider legal advice, and be alert to non-compliance during the audit.
- Consequence: these matters raise the risk of material misstatement, so treat going concern as a significant risk and consider the effect on disclosures.
Answer: The covenant breach, overdraft limit and loss of the main customer are going concern indicators requiring assessment of forecasts and funding. The emissions issue falls under ISA 250 limited procedures but may lead to fines, provisions or disclosure. The auditor should plan extra work on going concern and make enquiries on the regulator's letter.
Exam tips
- Start every responsibility question with management's duty, then the auditor's, and add that the audit gives reasonable and not absolute assurance.
- In Section C, tie each risk to a fact in the scenario. Generic lists score poorly.
- For Section A and B objective questions, watch for wording such as intentional, direct effect or reasonable assurance, because one word often decides the answer.
- Always give an audit response, not just the risk. Typical responses are team discussion, enquiries, senior staff and extra testing.
- State going concern indicators by type (financial, operating, other) so your answer is organised and complete.
Fraud, Laws and Going Concern at Planning Stage in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Fraud, Laws and Going Concern at Planning Stage: frequently asked questions
Who is responsible for fraud, the auditor or management?
Management and those charged with governance are responsible for preventing and detecting fraud. The auditor obtains reasonable assurance that the financial statements are free from material misstatement, whether from fraud or error. The auditor is not a guarantor that fraud will be found.
What does ISA 250 require the auditor to do?
The auditor obtains sufficient appropriate evidence of compliance with laws that have a direct effect on the financial statements. For other laws, the auditor performs limited procedures such as enquiries and inspecting regulator correspondence. The auditor also stays alert to possible non-compliance during the audit.
What are examples of going concern indicators at planning?
Financial examples include net current liabilities, negative cash flows and loan defaults. Operating examples include loss of key management, a major customer or a main supplier. Other examples include legal proceedings and changes in law that threaten the business.
How do I answer a fraud risk question in ACCA AA?
Identify facts in the scenario and group them under incentive or pressure, opportunity and attitude or rationalisation. State the resulting risk of misstatement for each. Then give the auditor's response, such as a team discussion, enquiries, senior staff and targeted testing.