Skip to content

Advanced Audit and Assurance (International) · Planning, materiality and assessing the risk of material misstatement

Fraud, Laws and Going Concern in Audit Planning

Updated 11 October 2026 · Fact-checked

At planning, the auditor assesses fraud risk under ISA 240, considers non-compliance with laws under ISA 250, and looks for going concern events or conditions under ISA 570 (Revised). You identify risks, link them to the scenario, assess their effect on the financial statements, and design a response.

Understand Fraud, Laws and Regulations and Going Concern in Planning

Three standards ask you to think about what could stop the financial statements being reliable. Fraud (ISA 240) is about deliberate misstatement. Laws and regulations (ISA 250) are about breaches that affect the numbers or the entity's ability to operate. Going concern (ISA 570 (Revised 2024)) is about whether the entity can keep trading, with management's assessment covering at least twelve months from the date of approval of the financial statements.

Fraud. Management is responsible for preventing and detecting fraud. The auditor is responsible for obtaining reasonable assurance that the financial statements are free from material misstatement, whether from fraud or error. Fraud is harder to detect than error because it is concealed. At planning, the team must hold a discussion about where the statements might be susceptible to fraud, and must keep professional scepticism throughout.

The fraud triangle explains why fraud happens: incentive or pressure (for example, bonus targets or loan covenants), opportunity (weak controls, management override) and attitude or rationalisation (a belief that the act is justified). ISA 240 presumes risks of fraud in revenue recognition, and management override of controls is always a risk. Fraudulent financial reporting and misappropriation of assets are the two main types.

Laws and regulations. Under ISA 250 (Revised), the auditor obtains a general understanding of the legal framework and how the entity complies. There are two groups of laws. The first group has a direct effect on the amounts and disclosures, such as tax and pension laws. For these, the auditor obtains sufficient appropriate audit evidence about compliance with the provisions of those laws. The second group does not affect the numbers directly but may be fundamental to the business, such as operating licences. For these, the auditor performs specified procedures to identify non-compliance that may have a material effect: enquiry of management and, where appropriate, those charged with governance, and inspection of correspondence with licensing or regulatory authorities. Management is responsible for compliance.

Going concern. Management assesses going concern, and the auditor evaluates that assessment. At planning, the auditor considers events or conditions that may cast significant doubt, such as net current liabilities, loan repayments falling due with no realistic refinancing, negative operating cash flows, loss of a key customer or licence, and adverse key ratios. The auditor also checks the period management covered, which should be at least twelve months from the date of approval of the financial statements, and considers events or conditions beyond that period. The auditor plans procedures in response and considers whether the risk affects the audit strategy.

Key rules to remember

Fraud triangle
Fraud = Incentive or pressure + Opportunity + Attitude or rationalisation
Use it to organise risk factors in a scenario. Label each fact under one of the three sides.
ISA 240 presumed risks
Revenue recognition (presumed, rebuttable) + Management override of controls (always, cannot be rebutted)
The presumption that revenue recognition is a fraud risk may be rebutted only where the auditor concludes, in the circumstances of the engagement, that it is not applicable. The reasons must be documented. Management override cannot be rebutted.
Responsibility split
Management and TCWG: prevent and detect. Auditor: reasonable assurance.
Never say the auditor is responsible for preventing fraud.
ISA 250 two categories
Direct-effect laws: obtain sufficient appropriate audit evidence about compliance. Other laws: enquiry of management and, where appropriate, TCWG, plus inspection of correspondence with licensing or regulatory authorities.
Tax and pension laws are direct-effect examples. Operating licences are examples of the second group, where the procedures help identify non-compliance that may have a material effect.
ISA 570 period
Management's going concern assessment covers at least 12 months from the date of approval of the financial statements (ISA 570 (Revised 2024))
If management covered a shorter period, the auditor asks management to extend it. The auditor also considers events or conditions beyond that period.

How to solve Fraud, Laws and Regulations and Going Concern in Planning questions

Use this method for any planning question on fraud, laws or going concern. Always tie each point to the facts in the scenario.

  1. 1Read the requirement and note which of the three areas it asks about, and whether it asks for risks, procedures or both.
  2. 2Scan the scenario and highlight facts that suggest pressure, opportunity, non-compliance or financial difficulty.
  3. 3Classify each fact. For fraud, use incentive, opportunity and attitude. For laws, decide if direct-effect or not. For going concern, decide if financial, operating or other.
  4. 4Explain why each fact matters: which assertion, balance or disclosure is affected, and whether the risk is significant.
  5. 5State the planning response: team discussion, senior staff, unpredictability, extra procedures, journal testing, or enquiry about legal matters.
  6. 6For going concern, add the work on management's assessment, cash flow forecasts and facilities, and the effect on reporting.
  7. 7Add a professional skills point: sceptical challenge of management's explanations and a clear, concise structure.

Quickest way: Fact, Risk, Response

When to use it: Use when time is short and the scenario has many facts. It earns marks for applying the standards.

  1. Underline each worrying fact in the scenario.
  2. Write a short label beside it: pressure, opportunity, attitude, law or going concern.
  3. For each label write one line: the risk it creates.
  4. Add one planning response per risk.
  5. Finish by stating the overall effect on audit strategy and sceptical stance.

Common mistakes in Fraud, Laws and Regulations and Going Concern in Planning

  • Saying the auditor is responsible for preventing fraud.

    Students mix up the auditor's role with that of management.

    Fix: State that management and those charged with governance prevent and detect fraud. The auditor obtains reasonable assurance.

  • Listing fraud triangle headings without linking to the scenario.

    Students recall the theory but do not apply it.

    Fix: Quote the scenario fact, label the side of the triangle, then say what could be misstated.

  • Forgetting the presumed risk in revenue recognition and management override.

    Students focus on unusual facts and ignore standard requirements.

    Fix: Mention both in any fraud risk answer, and explain management override is never rebutted.

  • Treating all laws the same under ISA 250.

    Students do not separate direct-effect laws from other laws.

    Fix: State the two groups and the different level of work for each.

  • Treating going concern as only a year-end issue.

    Students link it to the audit report and ignore planning.

    Fix: Identify indicators at planning and explain how they change the risk assessment and the audit approach.

  • Recommending a modified opinion at the planning stage.

    Students jump to the conclusion before evidence exists.

    Fix: At planning, describe risks and responses. Report implications come after evidence is evaluated.

Worked examples

Example 1

Your audit client, a manufacturer, has a bonus scheme for directors linked to profit. The finance director also controls the journal approval process and has recently closed down the group's internal audit function to cut costs. Explain the fraud risk factors and the planning responses.

Show the solution
  1. Incentive or pressure: directors' bonuses depend on profit, so there is motivation to overstate profit.
  2. Opportunity: the finance director controls journal approval and internal audit has been removed, so oversight is weak and management override is easier.
  3. Attitude: no direct fact is given. Ask about the culture and the past record of management integrity, and stay sceptical.
  4. Risk: revenue may be overstated and expenses understated. Management override of controls is a significant risk.
  5. Response: hold a team discussion on fraud, use experienced staff, test journals and unusual entries, review estimates for bias, and add unpredictability to testing.
  6. Revenue: perform cut-off testing and test contracts near the year end.

Answer: The bonus link is pressure. The finance director's control of journals and the loss of internal audit create opportunity. The main risks are revenue overstatement and management override. Respond with a team discussion, journal testing, cut-off work, review of estimates for bias and unpredictable procedures.

Example 2

A client has $4 million of loans repayable in four months. It has made losses for two years, and its main customer, 40% of sales, has just moved to a competitor. Management has prepared cash flow forecasts for only six months. Identify the going concern indicators and the planning response.

Show the solution
  1. Financial indicators: recurring losses and loans due within four months with no stated refinancing.
  2. Operating indicator: loss of the main customer, 40% of sales, reduces future cash inflows.
  3. Management's assessment is limited: forecasts cover six months, which is less than the twelve months from the date of approval of the financial statements.
  4. Planning response: treat going concern as a significant risk and plan for extra work.
  5. Procedures: ask management to extend the assessment period, review the forecast assumptions, compare them with past accuracy, check the loan agreements and the lender's willingness to refinance, and consider replacement sales.
  6. Reporting: consider adequacy of disclosure and whether a material uncertainty exists once the evidence is obtained.

Answer: The indicators are losses, near-term loan repayment and loss of a major customer, and management's six-month forecast is too short. The auditor treats going concern as a significant risk, asks for an assessment covering at least twelve months from the date of approval of the financial statements, tests the forecasts and financing, and evaluates disclosure and reporting later.

Exam tips

  • Always apply: name the scenario fact, then the risk, then the response. Generic lists earn few marks.
  • In fraud questions, use the three sides of the fraud triangle as a structure and add the presumed revenue risk.
  • For ISA 250, show the two groups of laws and state that management is responsible for compliance.
  • For going concern, cover financial, operating and other indicators, and mention that management's assessment should cover at least twelve months from the date of approval of the financial statements.
  • Use the professional skills marks: keep answers concise, challenge management's explanations and state your conclusion.

Practice questions from Planning, materiality and assessing the risk of material misstatement

Fraud, Laws and Regulations and Going Concern in Planning in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Fraud, Laws and Regulations and Going Concern in Planning: frequently asked questions

What are the main fraud risk factors in ISA 240?

They fall under incentive or pressure, opportunity, and attitude or rationalisation. Examples are profit-linked bonuses, weak controls and management override. In the exam, link each to a scenario fact.

Is revenue always a fraud risk under ISA 240?

ISA 240 presumes there are fraud risks in revenue recognition. The auditor may rebut this only where the auditor concludes, in the circumstances of the engagement, that the risk is not applicable, and must document the reasons. Management override of controls is always a risk and cannot be rebutted.

What is the auditor's role under ISA 250?

The auditor obtains a general understanding of the legal framework and obtains sufficient appropriate audit evidence about compliance with laws that have a direct effect on the financial statements. For other laws, the auditor performs specified procedures to identify non-compliance: enquiry of management and, where appropriate, those charged with governance, and inspection of correspondence with licensing or regulatory authorities. Management remains responsible for compliance.

What are examples of going concern indicators in ISA 570?

Examples include net current liabilities, loans nearing maturity without refinancing, negative operating cash flows, loss of a key customer or licence, and legal or regulatory problems. Write the indicators from the scenario and explain the effect of each on cash flows.