Skip to content

Advanced Audit and Assurance (International) · Fraud and error

Fraud vs Error: Definitions and Types of Fraud under ISA 240

Updated 11 October 2026 · Fact-checked

Under ISA 240, fraud is an intentional act by management, those charged with governance, employees or third parties, using deception to gain an unjust or illegal advantage. Error is an unintentional misstatement. The key test is intent. Fraud takes two forms: fraudulent financial reporting and misappropriation of assets.

Understand Fraud vs Error: Definitions and Types of Fraud

Every financial statement misstatement comes from one of two sources: fraud or error. The difference is intent. If someone meant to mislead, it is fraud. If it was a mistake, it is error.

ISA 240 defines fraud as an intentional act by one or more individuals among management, those charged with governance, employees or third parties, involving the use of deception to obtain an unjust or illegal advantage. Examples of error include a calculation slip, a misread fact, or an honest misapplication of an accounting policy. An accounting estimate that differs from the outcome is not fraud just because it was wrong.

There are two types of fraud relevant to the auditor. Fraudulent financial reporting is intentional misstatement or omission of amounts or disclosures to deceive users. Typical methods are manipulating records, misrepresenting events, and misapplying accounting principles on purpose. Examples are early revenue recognition, hiding liabilities and inflating assets. The usual drivers are meeting targets, bonuses or loan covenants, and management is often the perpetrator.

Misappropriation of assets is theft of an entity's assets. Examples are stealing cash receipts, diverting customer payments, fictitious suppliers, payroll fraud with ghost employees, and taking inventory for personal use. It is usually carried out by employees and often involves small amounts, but senior management can be involved too. It is often accompanied by false records to hide the theft.

Fraud is different from non-compliance with laws and regulations, which covers acts of omission or commission, intentional or unintentional, by the entity contrary to prevailing law. That is dealt with under ISA 250 (Revised). Some acts overlap: a fraud is also often illegal. Fraud is judged by intent and deception, while non-compliance is judged against law.

The auditor does not decide legally whether fraud has occurred. That is for the courts. The auditor's job is to assess the risk of material misstatement from fraud, respond, and report. Fraud is harder to detect than error because it involves concealment, such as forgery, collusion and management override of controls. Management and those charged with governance hold primary responsibility for prevention and detection. The auditor obtains reasonable assurance, so a properly planned audit can still miss a material fraud.

Key rules to remember

Fraud (ISA 240)
Fraud = intentional act + deception + unjust or illegal advantage
Perpetrators can be management, those charged with governance, employees or third parties.
Error
Error = unintentional misstatement or omission
Intent is the only distinguishing factor. The size of the amount does not decide it.
Types of fraud
Fraudulent financial reporting | Misappropriation of assets
The two types relevant to the auditor under ISA 240.
Non-compliance (ISA 250)
Non-compliance = act or omission by the entity contrary to law, intentional or not
Distinct from fraud. It does not require deception.
Auditor's duty
Reasonable assurance that financial statements are free from material misstatement, whether from fraud or error
This is not a guarantee. The risk of missing fraud is higher than for error.

How to solve Fraud vs Error: Definitions and Types of Fraud questions

Use this method for any question asking you to classify, explain or discuss fraud and error.

  1. 1Read the scenario and underline the act. Note who did it, what was affected and why.
  2. 2Test for intent. Ask whether there is evidence of deliberate deception, such as concealment, falsified documents or pressure to hit a target. If not, treat it as error.
  3. 3Classify the fraud. If financial statements are deliberately misstated, it is fraudulent financial reporting. If assets are stolen, it is misappropriation of assets.
  4. 4Check whether the act also breaches law or regulation. If so, mention ISA 250 as a separate consideration.
  5. 5Identify who is involved. Management involvement is more serious, as it brings override of controls and doubts about integrity.
  6. 6Link to the audit. State the effect on risk assessment, scepticism and the response, and say that the auditor gets reasonable assurance, not a guarantee.
  7. 7Finish with a short professional conclusion that answers the exact requirement.

Quickest way: Intent, Target, Person

When to use it: Use for short classification or definition requirements when time is tight.

  1. Intent: deliberate or accidental? Deliberate means fraud and accidental means error.
  2. Target: financial statements misstated means fraudulent reporting. Assets taken means misappropriation.
  3. Person: management or employee? This sets the severity and the audit response.
  4. Add one line on law: is it also non-compliance under ISA 250?

Common mistakes in Fraud vs Error: Definitions and Types of Fraud

  • Calling any large misstatement fraud.

    Students link size with seriousness.

    Fix: Size is not the test. Look for intent and deception. Without them, it is error.

  • Saying the auditor must prove or decide that fraud occurred.

    The everyday meaning of fraud is legal, so students assume the auditor rules on it.

    Fix: The auditor assesses risk and responds. The legal decision belongs to the courts.

  • Mixing up the two types, for example calling inflated revenue misappropriation.

    Both involve dishonesty, and students do not look at what is affected.

    Fix: Misstated statements are fraudulent reporting. Stolen assets are misappropriation. Remember that theft is often concealed by false records.

  • Assuming misappropriation is always small and carried out by junior staff.

    Textbook examples feature low-level staff.

    Fix: Say it is often by employees but can involve management and be material.

  • Treating fraud and non-compliance with law as the same thing.

    Many frauds are also illegal.

    Fix: Fraud needs intentional deception. Non-compliance may be unintentional. Cite ISA 240 for fraud and ISA 250 for law.

  • Writing definitions only and not applying them to the scenario.

    Students rely on memorised notes.

    Fix: Quote the facts from the scenario, classify the act, and then discuss the audit effect. This earns the professional skills marks.

Worked examples

Example 1

During the audit of Kiran Co, you find that the finance director delayed recording $400,000 of December expenses until January so the company would meet a profit target linked to his bonus. Explain whether this is fraud or error and classify it.

Show the solution
  1. Identify the act: expenses were deliberately recorded in the wrong period.
  2. Test intent: the delay was timed to meet a target tied to his bonus, so it was deliberate and aimed at personal gain.
  3. Conclude: this is fraud, because it is an intentional act using deception to gain an unjust advantage.
  4. Classify: financial statements are misstated (expenses understated, profit overstated), so it is fraudulent financial reporting.
  5. Note the person: it involves senior management, so there is a risk of management override and a doubt about integrity.
  6. Audit effect: raise the assessed fraud risk, apply greater scepticism, test cut-off and journals near the year end, and consider reporting to those charged with governance.

Answer: The act is fraud, not error, because it was intentional and for the finance director's gain. It is fraudulent financial reporting, as expenses were understated to inflate profit. Management involvement raises the risk and calls for heightened scepticism and extra cut-off and journal testing.

Example 2

At Mehta Ltd, a payroll clerk added a former employee to the payroll and diverted the salary to her own bank account. Separately, a junior accountant applied the wrong depreciation rate to one asset class, overstating profit by a small amount. Distinguish the two matters and explain how each affects the audit.

Show the solution
  1. Payroll matter: intentional, uses a ghost employee as deception, and the clerk gains personally. This is fraud.
  2. Classify it: assets (cash) are stolen, so it is misappropriation of assets. The perpetrator is an employee.
  3. Audit effect: consider the control weaknesses that allowed it, and extend payroll testing such as employee verification and bank detail checks. Assess whether the amount is material and report to management.
  4. Depreciation matter: no evidence of intent. It looks like a mistake in applying a rate, so it is an error.
  5. Audit effect: evaluate the misstatement against materiality, request correction, and add it to the summary of misstatements. If a pattern appears, reconsider the intent.
  6. Contrast: the difference between the two is intent, not amount.

Answer: The payroll diversion is fraud, specifically misappropriation of assets by an employee. The depreciation rate is an error, as nothing suggests it was deliberate. The fraud needs a control-focused response and reporting, while the error is evaluated against materiality and corrected.

Exam tips

  • Define fraud with all three elements: intentional, deception, unjust or illegal advantage. Examiners reward a complete definition.
  • Always apply to the scenario. Quote facts that show intent, such as bonus pressure or falsified documents.
  • Name the correct type of fraud, then say who is likely to commit it and why that matters.
  • State that the auditor gives reasonable assurance and that fraud is harder to detect because of concealment and collusion.
  • If law is mentioned, add a short note that non-compliance falls under ISA 250 and is separate from fraud.

Practice questions from Fraud and error

Fraud vs Error: Definitions and Types of Fraud in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Fraud vs Error: Definitions and Types of Fraud: frequently asked questions

What is the main difference between fraud and error under ISA 240?

Intent. Fraud is an intentional act involving deception to gain an unjust or illegal advantage. Error is an unintentional misstatement, such as a mistake in calculation or in applying a policy.

What are the two types of fraud in ISA 240?

Fraudulent financial reporting and misappropriation of assets. The first is deliberate misstatement of the financial statements to deceive users. The second is theft of the entity's assets, often hidden by false records.

Does the auditor have to decide whether fraud has legally occurred?

No. Whether fraud has occurred legally is a matter for the courts. The auditor assesses risks of material misstatement due to fraud, responds to them, and reports as required.

How is fraud different from non-compliance with laws and regulations?

Fraud needs intentional deception. Non-compliance is any act or omission by the entity that is contrary to law, whether intentional or not. They can overlap, but they are handled under ISA 240 and ISA 250 respectively.