Skip to content

Audit and Assurance · Fraud, laws and regulations

Auditor's Response to Fraud Risks under ISA 240

Updated 11 October 2026 · Fact-checked

The auditor responds to fraud risk by keeping professional scepticism, discussing fraud within the team, assessing fraud risks, and designing procedures aimed at them: testing journals, reviewing estimates and examining unusual transactions. If fraud is suspected, the auditor investigates, reassesses risk, and reports to management or those charged with governance.

Understand Auditor's Response to Fraud Risks

Fraud is an intentional act by management, those charged with governance, employees or third parties, using deception to gain an unjust or illegal advantage. Under ISA 240, the auditor does not prevent or detect all fraud. Management and those charged with governance carry primary responsibility. The auditor must obtain reasonable assurance that the financial statements are free from material misstatement, whether from fraud or error.

Fraud is harder to detect than error because it is concealed. Collusion, forged documents and management override make it worse. This is why the auditor must keep professional scepticism throughout. That means a questioning mind, alertness to conditions that suggest misstatement, and a critical assessment of evidence. The auditor should not assume management is dishonest, and should not assume it is honest either.

The response starts at planning. The engagement team discusses how and where the financial statements might be susceptible to fraud. This uses the fraud triangle: incentive or pressure, opportunity, and attitude or rationalisation. The auditor then makes enquiries of management, those charged with governance and internal audit. The auditor also reviews unusual or unexpected relationships from analytical procedures.

ISA 240 requires the auditor to presume a risk of fraud in revenue recognition, unless the presumption can be rebutted. The auditor must also treat the risk of management override of controls as a significant risk. Identified fraud risks are significant risks, so the auditor must understand the related controls and respond with specific procedures.

The response has three layers. First, overall responses, such as assigning more experienced staff, adding unpredictability to procedures, and reviewing accounting policies. Second, specific procedures at assertion level. Third, procedures to address management override: test journals and other adjustments, review accounting estimates for bias, and evaluate the business rationale for significant unusual transactions. If fraud is suspected or found, the auditor considers the implications, communicates on a timely basis and considers legal or ethical reporting duties.

Key rules to remember

Fraud triangle
Fraud risk = Incentive or pressure + Opportunity + Rationalisation
Use it to explain why a fraud risk factor exists. Name all three parts.
Presumed fraud risks
Revenue recognition (presumed, rebuttable) + Management override of controls (always a significant risk)
Management override cannot be rebutted. The revenue presumption can be rebutted only with a reason.
Mandatory override procedures
Test journals and adjustments + Review estimates for bias + Evaluate rationale for significant unusual transactions
Required whatever the auditor's assessment of fraud risk.
Overall responses
Senior staff + Supervision + Unpredictability + Review of accounting policies
Use these when the risk affects the financial statements as a whole.

How to solve Auditor's Response to Fraud Risks questions

Use this method for scenario questions on fraud risk and response. Tie every point to the facts given.

  1. 1Read the scenario and underline fraud risk factors: pressure on targets, bonuses, weak controls, dominant management, unusual transactions.
  2. 2Classify each factor using the fraud triangle: incentive, opportunity or rationalisation.
  3. 3Identify the risk: fraudulent financial reporting, misappropriation of assets, or management override. Link it to a specific balance or assertion.
  4. 4State the overall response if the risk is pervasive: experienced staff, more supervision, unpredictable procedures.
  5. 5Give specific procedures aimed at that risk. Say what you test, what evidence you seek and why it addresses the risk.
  6. 6For journals and estimates, use the mandatory procedures: select journals by risk criteria, and review estimates for bias in hindsight.
  7. 7If fraud is suspected, state the actions: investigate, reassess risks, discuss with management or governance, consider legal advice and reporting duties.
  8. 8Finish with the effect on the audit: a modified opinion if material misstatement is not corrected or evidence is limited, or withdrawal in serious cases.

Quickest way: Risk, response, report

When to use it: Use this in Section A and B objective questions and for short written requirements when time is tight.

  1. Name the risk: revenue, override, or asset misappropriation.
  2. Match the standard response: journals, estimates, unusual transactions.
  3. Check who is told: management first, unless they are involved, then those charged with governance.
  4. Remember the auditor investigates and reports; the auditor does not accuse or prevent fraud.
  5. In a written answer, give one procedure per mark, each linked to the scenario.

Common mistakes in Auditor's Response to Fraud Risks

  • Saying the auditor is responsible for preventing and detecting fraud.

    Students mix up the roles of management and the auditor.

    Fix: Say management and those charged with governance are responsible for prevention and detection. The auditor gets reasonable assurance on material misstatement.

  • Giving generic procedures such as 'check invoices' for a fraud risk.

    Students recall standard audit tests instead of tailoring them.

    Fix: Name the risk and the assertion. Then say what you test, such as cut-off on year-end sales or journals posted near year end.

  • Treating professional scepticism as assuming management is dishonest.

    The word sounds negative.

    Fix: Describe it as a questioning mind and critical assessment of evidence, with no assumption of dishonesty or honesty.

  • Forgetting that management override is always a significant risk.

    Students focus on revenue only.

    Fix: Always include journals, estimates and unusual transactions when asked about the response to fraud risk.

  • Reporting suspected fraud straight to outside authorities.

    Students ignore confidentiality and the usual reporting line.

    Fix: Communicate to management or those charged with governance first. Consider legal or ethical duties to report externally, and take legal advice where unsure.

  • Listing fraud risk factors without explaining the audit response.

    Students stop at identification.

    Fix: For each risk factor, add the matching audit procedure and its purpose.

Worked examples

Example 1

During the audit of Lumen Co, the finance director's bonus depends on reaching a profit target. Revenue rose sharply in the last week of the year. Suggest audit procedures to address the fraud risk in revenue. (4 marks)

Show the solution
  1. Risk: revenue is presumed to be a fraud risk, and the bonus is an incentive to overstate profit.
  2. Procedure 1: test cut-off by tracing the last week's sales invoices to dispatch notes and delivery dates.
  3. Procedure 2: review credit notes issued after the year end for reversals of year-end sales.
  4. Procedure 3: confirm large year-end receivables directly, or perform alternative procedures where no reply comes.
  5. Procedure 4: test journals that raised revenue near the year end, looking at who posted them and the support.

Answer: Because revenue is a presumed fraud risk and the bonus gives an incentive, the auditor should test cut-off, review post year-end credit notes, confirm large receivables, and test year-end revenue journals.

Example 2

Explain the auditor's procedures to address the risk of management override of controls in the audit of Brightwell Co. (5 marks)

Show the solution
  1. Management override is always a significant risk, so the response is mandatory.
  2. Journals: obtain a listing and select entries using risk criteria such as round sums, unusual accounts, late posting, posting by senior staff and entries with no description. Agree to support.
  3. Estimates: review key estimates, such as provisions and inventory valuation, for bias. Compare prior-year estimates with actual outcomes in hindsight.
  4. Unusual transactions: for significant transactions outside normal business, obtain the business rationale. Check whether the substance matches the form and whether related parties are involved.
  5. Maintain scepticism: discuss the findings with the engagement partner and the team.

Answer: The auditor tests journals and other adjustments using risk criteria, reviews estimates for management bias including a hindsight review of prior-year estimates, and evaluates the business rationale for significant unusual transactions.

Exam tips

  • Tailor every procedure to the scenario. Generic points earn few marks.
  • Always cover the three mandatory override procedures when the question mentions management pressure or dominant management.
  • In objective questions, look for the absolute word. 'The auditor is responsible for preventing fraud' is wrong.
  • For suspected fraud, order your answer: investigate, reassess risk, communicate, consider reporting duties, consider the audit opinion.
  • Use the fraud triangle labels when asked to explain why a risk exists.

Auditor's Response to Fraud Risks in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Auditor's Response to Fraud Risks: frequently asked questions

What does ISA 240 require the auditor to do about fraud risk?

The auditor must keep professional scepticism, hold a team discussion, make enquiries, assess fraud risks, and design responses. Revenue recognition is presumed to be a fraud risk, and management override is always treated as a significant risk.

What audit procedures address journals and estimates?

For journals, the auditor selects entries using risk criteria and checks their support and authorisation. For estimates, the auditor reviews them for bias and compares prior-year estimates with actual outcomes.

What should the auditor do if fraud is suspected?

The auditor investigates further, reassesses the risks of material misstatement, and communicates with management or those charged with governance. The auditor also considers legal and ethical reporting duties and the effect on the audit opinion.

Can the auditor rebut the presumed fraud risk in revenue?

Yes, if the auditor concludes that fraud risk in revenue recognition is not present in the circumstances of the engagement. The reasons must be documented. The risk of management override cannot be rebutted.