Advanced Audit and Assurance (International) · Fraud and error
Responsibilities of Management, TCWG and Auditors for Fraud under ISA 240
Updated 11 October 2026 · Fact-checked
Under ISA 240, management and those charged with governance are responsible for preventing and detecting fraud. The auditor is responsible for obtaining reasonable assurance that the financial statements are free from material misstatement, whether from fraud or error, and for keeping professional scepticism throughout the audit.
Understand Responsibilities of Management, Those Charged with Governance and Auditors
Start with the split of roles. Management runs the business and designs and operates internal control. So management is responsible for preventing and detecting fraud. Those charged with governance (TCWG) oversee management. They set the tone, oversee the control environment and challenge management on fraud risk.
The auditor does not stop fraud. The auditor gives an opinion on whether the financial statements are free from material misstatement. ISA 240 asks for reasonable assurance. This is high, but not absolute. A fraud can be hidden by collusion, forged documents or management override of controls. An audit carried out in line with ISAs can still miss a material fraud.
Fraud is harder to find than error. Fraud is intentional and often concealed. A fraud by management is harder still to detect, because management can override controls and manipulate records. So the risk of missing a material misstatement from fraud is higher than from error.
Professional scepticism is an attitude. It includes a questioning mind, alertness to conditions that suggest possible misstatement, and a critical assessment of evidence. You must keep it throughout the audit. Do not assume management is dishonest. Do not assume it is honest. Past experience of the client's honesty does not excuse you from it.
The auditor must also discuss fraud risk within the engagement team, make enquiries of management and TCWG, and treat management override of controls as a risk in every audit. Presumed risks of fraud in revenue recognition must be considered too. The auditor must respond to identified fraud risks and report as required.
Key rules to remember
- Management and TCWG responsibility
- Prevention and detection of fraud = management (with oversight by TCWG)
- Management designs and operates internal control. TCWG oversee it and set the tone.
- Auditor responsibility
- Reasonable assurance that the financial statements are free from material misstatement, whether due to fraud or error
- Reasonable assurance is high but not absolute. The auditor does not guarantee that fraud is found.
- Professional scepticism
- Questioning mind + alertness to misstatement + critical assessment of evidence
- Maintain it throughout the audit, even if you believe management is honest.
- Inherent limitation
- Risk of not detecting fraud > risk of not detecting error
- Fraud may involve collusion, forgery, deliberate omission or management override.
- Mandatory risk presumption
- Management override of controls = a fraud risk present in every audit
- Respond with tests of journals, estimates and significant unusual transactions.
How to solve Responsibilities of Management, Those Charged with Governance and Auditors questions
Use this method for any question on who is responsible for fraud and what the auditor must do.
- 1Read the requirement. Is it asking for responsibilities, a comparison, or a response to a scenario?
- 2Name the three parties: management, TCWG and the auditor. Say what each is responsible for.
- 3State the auditor's objective: reasonable assurance on material misstatement from fraud or error.
- 4Explain the limits: collusion, forgery, concealment and management override mean an audit cannot guarantee detection.
- 5Link to the scenario. Pick out facts such as pressure, weak controls or a dominant director, and say how scepticism applies.
- 6Give specific auditor actions: team discussion, enquiries, fraud risk assessment, journal testing, review of estimates and significant unusual transactions.
- 7Add reporting. Mention communication with management or TCWG and consider the ethical and legal duties.
- 8Finish with the professional skills point: a clear, balanced conclusion for the reader.
Quickest way: Three parties, one limit, one action
When to use it: Use when time is short and the question asks you to explain or compare responsibilities.
- Write: Management = prevent and detect. TCWG = oversee. Auditor = reasonable assurance.
- Add one line on inherent limits: collusion and override.
- Add one line on scepticism: questioning mind, critical of evidence.
- Tie to the case with one or two facts and one specific audit response.
Common mistakes in Responsibilities of Management, Those Charged with Governance and Auditors
Saying the auditor is responsible for preventing and detecting fraud.
Students think the auditor is the main safeguard against fraud.
Fix: Say management and TCWG are responsible. The auditor obtains reasonable assurance on the financial statements.
Claiming the auditor gives absolute assurance.
The word assurance sounds like a guarantee.
Fix: Use the phrase reasonable assurance. Explain the inherent limitations of an audit.
Describing scepticism as assuming management is dishonest.
Students confuse scepticism with distrust.
Fix: Define it as a questioning mind and critical assessment of evidence, without assuming either honesty or dishonesty.
Relaxing scepticism because the client has been honest in past years.
Long relationships create familiarity.
Fix: State that past experience does not remove the need for scepticism. Circumstances can change.
Giving a generic list of responsibilities with no link to the scenario.
Students recall theory but skip the application.
Fix: Use named facts from the case, such as a dominant owner or a sales target, and link each to a specific audit response.
Forgetting management override of controls.
Students focus on weaknesses in controls and miss that management can bypass good ones.
Fix: State it is a risk in every audit and describe journal, estimate and unusual transaction testing.
Worked examples
Example 1
The directors of Kestrel Co say that fraud is the auditor's job because the auditor is paid to find it. Explain to them the respective responsibilities for fraud. (6 marks)
Show the solution
- Management responsibility: management is responsible for the prevention and detection of fraud. It designs, implements and operates internal control and creates a culture of honesty and ethical behaviour.
- TCWG responsibility: those charged with governance oversee management's processes, challenge management on fraud risk and set the tone.
- Auditor responsibility: the auditor obtains reasonable assurance that the financial statements as a whole are free from material misstatement, whether from fraud or error.
- Limits: the audit is not a guarantee. Collusion, forged documents or management override can hide fraud. Fraud is more difficult to detect than error.
- Auditor conduct: the auditor keeps professional scepticism throughout and carries out specific procedures on fraud risk.
- Communication: explain this in clear terms, politely, so the directors understand their own duties.
Answer: Management, supported by TCWG oversight, is responsible for preventing and detecting fraud. The auditor is responsible only for reasonable assurance that the financial statements are free from material misstatement, whether from fraud or error. The audit cannot guarantee that all fraud is found.
Example 2
You are auditing Brindle Ltd. The finance director dominates the board, bonuses depend on revenue targets, and the audit manager says: 'The client has been honest for ten years, so we can reduce our fraud work.' Respond. (8 marks)
Show the solution
- Reject the suggestion. Professional scepticism must be kept throughout the audit. Past honesty does not remove that duty.
- Identify the risk factors: a dominant finance director raises the risk of management override, and revenue-linked bonuses create pressure and incentive to overstate revenue.
- Note that fraud by management is harder to detect because management can override controls and manipulate records.
- Revenue recognition is a presumed fraud risk, so the team should test cut-off, unusual sales near the year end and credit notes after the year end.
- Management override is a risk in every audit: test journal entries, review estimates for bias and examine significant unusual transactions.
- Hold a team discussion on how and where fraud could occur, and make enquiries of management and TCWG about their fraud risk assessment.
- Consider assigning more experienced staff and adding unpredictability to procedures.
- Conclusion: fraud work should not be reduced. It should be increased and targeted at the risks identified.
Answer: The manager is wrong. Scepticism applies regardless of past experience. The dominant finance director and revenue-linked bonuses raise fraud risk, so the auditor should respond with targeted revenue and journal testing, estimate review and enquiries, not reduce work.
Exam tips
- Always name all three parties. Many answers lose marks by mentioning only the auditor.
- Use the exact phrase reasonable assurance, and explain why it is not absolute.
- In case questions, quote facts from the scenario and link each to a specific audit response. This earns professional skills marks.
- Show scepticism in your tone: balanced, not accusatory. Do not say the client is committing fraud unless the facts clearly say so.
- Always mention management override of controls when asked for the auditor's response to fraud.
Practice questions from Fraud and error
- During planning of the audit of Kestrel Retail Ltd, the engagement team discusses where the financial statements might be susceptible to mat…
- Auditor Kiran is auditing Orion Ltd and finds that the chief executive probably inflated revenue through false invoices. Kiran must decide w…
- Karim & Co audits Zenith Ltd, where the chief executive also acts as chair, controls all board decisions, and the finance team has no indepe…
- Auditor Priya has identified a significant risk of material misstatement due to fraud in the inventory valuation of Dunmore Foods. Which res…
- In auditing Dalton Retail, the auditor learns that the warehouse manager has been removing inventory and concealing the shortfall by posting…
Responsibilities of Management, Those Charged with Governance and Auditors in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Responsibilities of Management, Those Charged with Governance and Auditors: frequently asked questions
Who is responsible for detecting fraud under ISA 240?
Management is primarily responsible for preventing and detecting fraud, with oversight from those charged with governance. The auditor is responsible for obtaining reasonable assurance that the financial statements are free from material misstatement, whether from fraud or error.
What is professional scepticism in ISA 240?
It is an attitude that includes a questioning mind and a critical assessment of audit evidence. You stay alert to signs of possible misstatement from fraud or error. You do not assume management is dishonest, and you do not assume it is honest.
Why can an audit miss a material fraud?
An audit gives reasonable, not absolute, assurance. Fraud can involve collusion, forged documents, deliberate omissions or management override of controls. These make it harder to detect than error.
Does the auditor have to assume management is dishonest?
No. The auditor keeps professional scepticism without assuming either honesty or dishonesty. Past experience of management's honesty does not allow the auditor to accept weak evidence.