Skip to content

ACCA Applied Skills · Audit and Assurance

Fraud, Laws and Regulations for ACCA Audit and Assurance

This chapter covers the auditor's duties on fraud (ISA 240), non-compliance with laws and regulations (ISA 250) and money laundering. You learn who is responsible, how to assess risks, what procedures to perform and when to report. Auditors obtain reasonable assurance, not a guarantee that fraud is found.

What this chapter covers

This chapter deals with what an auditor must do when financial statements may be misstated through fraud, or when the entity breaks laws and regulations. ISA 240 covers fraud. ISA 250 covers laws and regulations. Money laundering sits alongside them because it is a legal duty that can override normal confidentiality.

The key idea is responsibility. Management and those charged with governance are responsible for preventing and detecting fraud. The auditor is responsible for obtaining reasonable assurance that the financial statements are free from material misstatement, whether caused by fraud or error. The auditor must also keep professional scepticism throughout.

The chapter links to many other parts of the paper. Risk assessment, internal controls, audit evidence, the audit report and communication with those charged with governance all come back here. Fraud ideas also appear in the other paper areas you may meet in scenarios, such as revenue recognition and inventory. Learn this chapter well and your answers in other areas improve too.

Fraud and laws questions are very testable in both objective test cases and the constructed response section. Many are knowledge-based: who is responsible, what is the difference between fraud and error, what procedures respond to a risk. You can score reliably if your definitions are precise. In written answers, you must apply the points to the scenario facts, such as a dominant director or aggressive targets, rather than reciting the standard. The chapter rewards disciplined technique and is easy to prepare in a short time.

Fraud, laws and regulations: topics in the order to study them

  1. 1Fraud, Error and Responsibilities (ISA 240)Start here. It sets the definitions and the split of responsibility between management, those charged with governance and the auditor, which everything else depends on.
  2. 2Fraudulent Financial Reporting and Misappropriation of AssetsNext, learn the two types of fraud and the fraud triangle of incentive, opportunity and rationalisation. You need these to spot risks in a scenario.
  3. 3Auditor's Response to Fraud RisksOnce you can identify risks, learn what the auditor does about them: team discussion, scepticism, overall and specific responses, and journal entry testing.
  4. 4Reporting Fraud and Management RepresentationsThis follows the response. It covers who to tell when fraud is suspected or found, and how written representations are used, including their limits.
  5. 5Laws and Regulations (ISA 250)Move to the wider topic of non-compliance. It reuses the reporting logic from fraud, but with different responsibilities and a distinction between direct and indirect laws.
  6. 6Money Laundering and Auditor Reporting DutiesFinish with this, as it builds on confidentiality and reporting duties. It makes most sense once you know how ISA 250 handles non-compliance.

How to prepare Fraud, laws and regulations

Use a build-then-apply method. Learn the definitions first, then practise applying them to scenarios, since exam questions are scenario-led.

  1. Write the definitions of fraud, error, fraudulent financial reporting and misappropriation in your own words, and state who is responsible for what.
  2. Memorise the fraud triangle and link each element to a typical scenario fact, such as pressure to meet a bonus target or weak controls over cash.
  3. Build a list of responses to fraud risk: team discussion, unpredictable procedures, journal entry testing, reviewing estimates for bias and checking unusual transactions.
  4. Draw a simple flow for reporting: management, those charged with governance, then external parties where law requires or permits. Note the confidentiality point.
  5. Compare ISA 240 and ISA 250 in a short table in your notes: auditor's duty, procedures, and what to do when non-compliance is found.
  6. Practise objective test questions under time, then write two or three constructed responses. Use a point, scenario fact and consequence structure for each mark.
  7. Revise from your own one-page summary, and review every wrong answer to find whether the cause was knowledge or reading.

Common mistakes in Fraud, laws and regulations

  • Saying the auditor is responsible for preventing fraud.

    Fix: Remember that prevention and detection belong to management and those charged with governance. The auditor only assesses and responds to the risk of material misstatement.

  • Listing generic audit procedures that do not fit the scenario.

    Fix: Tie each procedure to a named risk in the scenario, such as a director with a bonus linked to profit, and say what the procedure would show.

  • Confusing fraudulent financial reporting with misappropriation of assets.

    Fix: Ask whether the aim is to mislead users of the accounts or to steal. Misappropriation is often hidden by false records, but the motive is theft.

  • Reporting to the wrong party when fraud involves management.

    Fix: If management is involved, consider those charged with governance or an external route. State the confidentiality position and the need for legal advice where relevant.

  • Treating written representations as sufficient evidence.

    Fix: Say that representations corroborate other evidence and are not a substitute for it. If doubt exists about management integrity, their reliability falls.

  • Ignoring tipping off in money laundering answers.

    Fix: Always cover both parts: report suspicion to the appropriate authority or officer, and avoid alerting the person concerned.

Last-day revision: Fraud, laws and regulations

  • Fraud is intentional; error is unintentional.
  • Management and those charged with governance are responsible for preventing and detecting fraud.
  • The auditor obtains reasonable assurance, not absolute assurance, that the financial statements are free from material misstatement.
  • Fraud risk factors fall under incentive or pressure, opportunity and rationalisation.
  • Fraudulent financial reporting means misstating the accounts; misappropriation means stealing assets.
  • Under ISA 240, management override of controls is always treated as a risk, so journal entries and estimates are tested.
  • Revenue recognition is presumed to be a fraud risk unless the auditor concludes otherwise and documents why.
  • Maintain professional scepticism and hold a team discussion about where fraud could occur.
  • Written representations support other evidence but cannot replace it.
  • Under ISA 250, the auditor is not responsible for preventing non-compliance and cannot be expected to detect all of it.
  • Money laundering reporting is a legal duty, and tipping off the suspect is an offence in many jurisdictions.
  • If fraud is suspected, the auditor communicates with the right level of management or those charged with governance, depending on who may be involved.

Fraud, laws and regulations in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Fraud, laws and regulations: frequently asked questions

What is the difference between fraud and error in the audit?

Fraud is an intentional act to obtain an unjust or illegal advantage. Error is an unintentional mistake, such as a calculation slip. The distinction matters because fraud is harder to detect, as it often involves concealment or collusion.

Is the auditor responsible for detecting all fraud?

No. The auditor must obtain reasonable assurance that the financial statements are free from material misstatement, whether due to fraud or error. An audit carried out under the ISAs may still fail to detect a material fraud, especially where there is collusion.

Why is management override of controls always a risk?

Management can manipulate records and override controls that otherwise appear to work. The auditor cannot rule this out, so ISA 240 requires procedures such as testing journal entries, reviewing estimates and examining unusual transactions.

How should I answer a question on ISA 250?

Define the auditor's duty clearly, then apply it to the scenario. Say what procedures the auditor performs, who should be informed and whether the audit opinion or report is affected. Keep the distinction between laws with a direct effect on the accounts and other laws.

How is this chapter tested in the exam?

You may see short objective questions on definitions and responsibilities, or a scenario in an objective test case. It can also appear in a constructed response question asking for fraud risks, audit procedures or actions on discovering non-compliance.