Requirements
Professional Scepticism
19
In applying ASA 200, the auditor shall maintain professional scepticism throughout the audit, recognising the possibility that a material misstatement due to fraud could exist. (Ref: Para. A27)
20
The auditor shall remain alert throughout the audit for information that indicates that one or more fraud risk factors are present and circumstances that may be indicative of fraud or suspected fraud. (Ref: Para. A28–A32)
21
Where responses to enquiries of management, those charged with governance, individuals within the internal audit function, or others within the entity are inconsistent, the auditor shall investigate the inconsistencies. (Ref: Para. A33)
22
If conditions identified during the audit cause the auditor to believe that a record or document may not be authentic or that terms in a document have been modified but not disclosed to the auditor, the auditor shall investigate further. (Ref: Para. A34–A37)
Engagement Resources
23
In applying ASA 220, the engagement partner shall determine that members of the engagement team collectively have the appropriate competence and capabilities, including sufficient time and appropriate specialised skills or knowledge to perform risk assessment procedures, identify and assess the risks of material misstatement due to fraud, design and perform further audit procedures to respond to those risks, or evaluate the audit evidence obtained. (Ref: Para. A38–A42)
Engagement Performance
24
In applying ASA 220, the engagement partner shall determine that the nature, timing and extent of direction, supervision and review is responsive to the nature and circumstances of the audit engagement, considering matters identified during the course of the audit engagement, including: (Ref: Para. A43)
24(a)
Fraud risk factors;
24(b)
Fraud or suspected fraud; and
24(c)
Control deficiencies related to the prevention or detection of fraud.
Ongoing Nature of Communications with Management and Those Charged with Governance
25
The auditor shall communicate with management and those charged with governance matters related to fraud at appropriate times throughout the audit engagement. (Ref: Para. A44–A48)
Risk Assessment Procedures and Related Activities
26
In applying ASA 315, the auditor shall perform the procedures in paragraphs 27–38. In doing so, the auditor shall consider whether one or more fraud risk factors are present. (Ref: Para. A49)
Information from Other Sources
27
In applying ASA 315, the auditor shall consider whether information from other sources obtained by the auditor indicates that one or more fraud risk factors are present. (Ref: Para. A50–A51)
Retrospective Review of the Outcome of Previous Accounting Estimates
28
In applying ASA 540, the auditor shall perform a retrospective review of management judgements and assumptions related to the outcome of previous accounting estimates, or where applicable, their subsequent re-estimation to assist in identifying and assessing the risks of material misstatement due to fraud in the current period. In doing so, the auditor shall take into account the characteristics of the accounting estimates in determining the nature and extent of that review. (Ref: Para. A52)
Engagement Team Discussion
29
In applying ASA 315, when holding the engagement team discussion, the engagement partner and other key engagement team members shall place particular emphasis on how and where the entity’s financial report may be susceptible to material misstatement due to fraud, including how fraud may occur. In doing so, the engagement team discussion shall include: (Ref: Para. A43, A53–A54 and A59)
29(a)
An exchange of ideas about:
The entity’s culture, management’s commitment to integrity and ethical values, and related oversight by those charged with governance; (Ref: Para. A55)
Fraud risk factors, including: (Ref: Para. A56–A57)
Incentives or pressures on management, those charged with governance, or employees to commit fraud;
How one or more individuals among management, those charged with governance, or employees could perpetrate and conceal fraudulent financial reporting; and
How assets of the entity could be misappropriated by management, those charged with governance, employees or third parties.
Which types of revenue, revenue transactions or relevant assertions may give rise to the risks of material misstatement due to fraud in revenue recognition; and
How management may be able to override controls. (Ref: Para. A58)
29(b)
A consideration of any fraud or suspected fraud that may impact the overall audit strategy and audit plan, including fraud that has occurred at the entity during the current or prior years.
Analytical Procedures Performed and Unusual or Unexpected Relationships Identified
30
The auditor shall determine whether unusual or unexpected relationships that have been identified in performing analytical procedures, including those related to revenue accounts, may indicate risks of material misstatement due to fraud. (Ref: Para. A60)
Understanding the Entity and Its Environment, and the Applicable Financial Reporting Framework
31
In applying ASA 315, based on the auditor’s understanding of the entity and its environment, the applicable financial reporting framework and the entity’s accounting policies, the auditor shall obtain an understanding of matters that may lead to an increased susceptibility to misstatement due to management bias or other fraud risk factors. (Ref: Para. A61–A70)
Control Environment
32
In applying ASA 315, the auditor shall:
32(a)
Obtain an understanding of:
How management’s oversight responsibilities are carried out, such as the entity’s culture and management’s commitment to integrity and ethical values, including how management communicates with its employees its views on business practices and ethical behaviour with respect to the prevention and detection of fraud. (Ref: Para. A71–A72)
The entity’s whistleblower program (or other program to report fraud), if the entity has such a program, including how management and, if applicable, those charged with governance address allegations of fraud made through the program. (Ref: Para. A73–A75)
How those charged with governance exercise oversight of management’s processes for identifying and responding to the fraud risks and the controls that management has established to address these risks. (Ref: Para. A76–A79)
32(b)
Make enquiries of management regarding management’s communications with those charged with governance regarding its processes for identifying and responding to the risks of fraud in the entity.
32(c)
Make enquiries of those charged with governance about: (Ref: Para. A80–A82)
Whether they have knowledge of any fraud or suspected fraud including allegations of fraud, including those received from tips or complaints, affecting the entity, and if so, how they have responded to such matters;
Their views about whether and how the financial report may be materially misstated due to fraud, including their views on possible areas that are susceptible to misstatement due to management bias or management fraud; and
Whether they are aware of deficiencies in the system of internal control related to the prevention and detection of fraud, and the remediation efforts to address such deficiencies.
The Entity’s Risk Assessment Process
33
In applying ASA 315, the auditor shall:
33(a)
Obtain an understanding of how the entity’s risk assessment process: (Ref: Para. A83–A91, A107)
Identifies fraud risks related to the misappropriation of assets and fraudulent financial reporting, including any classes of transactions, account balances, or disclosures for which risks of fraud exist;
Assesses the significance of the identified fraud risks, including the likelihood of their occurrence; and
Addresses the assessed fraud risks.
33(b)
Make enquiries of management and of other appropriate individuals within the entity about: (Ref: Para. A92–A95)
Whether they have knowledge of any fraud or suspected fraud, including allegations of fraud, affecting the entity; and
Their views about whether and how the financial report may be materially misstated due to fraud.
The Entity’s Process to Monitor the System of Internal Control
34
In applying ASA 315, the auditor shall:
34(a)
Obtain an understanding of:
Aspects of the entity’s process to monitor the system of internal control that address the ongoing and separate evaluations for monitoring the effectiveness of controls to prevent or detect fraud, and the identification and remediation of related control deficiencies identified; and (Ref: Para. A96)
If the entity has an internal audit function, the internal audit function’s objectives in respect of monitoring controls over risks of fraud.
34(b)
If the entity has an internal audit function, make enquiries of appropriate individuals within the internal audit function about whether: (Ref: Para. A97–A98)
They have performed any procedures in respect of monitoring controls over risks of fraud during the period;
They have knowledge of any fraud or suspected fraud, including allegations of fraud, affecting the entity and to obtain their views about the risks of fraud; and
They are aware of deficiencies in the system of internal control related to the prevention and detection of fraud.
The Information System and Communication
35
In applying ASA 315, the auditor’s understanding of the entity’s information system and communication relevant to the preparation of the financial report shall include understanding how journal entries and other adjustments are initiated, processed, recorded, and corrected as necessary. (Ref: Para. A99–A101)
Control Activities
36
In applying ASA 315,the auditor’s understanding of the entity’s control activities shall include identifying controls that address risks of material misstatement due to fraud at the assertion level, including controls over journal entries and other adjustments, designed to prevent or detect fraud. (Ref: Para. A102–A107)
Control Deficiencies Within the Entity’s System of Internal Control
37
In applying ASA 315, based on the auditor’s evaluation of each of the components of the entity’s system of internal control, the auditor shall determine whether there are deficiencies in internal control identified that are relevant to the prevention or detection of fraud. (Ref: Para. A108–A109)
Evaluation of Fraud Risk Factors
38
The auditor shall evaluate whether the audit evidence obtained from the risk assessment procedures and related activities indicates that one or more fraud risk factors are present. (Ref: Para. A24–A26 and A110–A112)
Identifying and Assessing the Risks of Material Misstatement due to Fraud
39
In applying ASA 315, the auditor shall:
39(a)
Identify and assess the risks of material misstatement due to fraud and determine whether they exist at the financial report level, or the assertion level for classes of transactions, account balances and disclosures, taking into account fraud risk factors. (Ref: Para. A113–A114, A116)
39(b)
Treat those assessed risks of material misstatement due to fraud as significant risks. Accordingly, to the extent not already done so, the auditor shall identify controls that address such significant risks, evaluate whether they have been designed effectively to address the risks of material misstatement, or designed effectively to support the operation of other controls, and determine whether they have been implemented. (Ref: Para. A115)
Risks of Material Misstatement Due to Fraud Related to Management Override of Controls
40
Due to the unpredictable way in which management is able to override controls and irrespective of the auditor’s assessment of the risks of management override of controls, the auditor shall: (Ref: Para. A117–A118)
40(a)
Treat the risks of management override of controls as risks of material misstatement due to fraud at the financial report level; and
40(b)
Determine whether such risks affect the assessment of risks at the assertion level.
Risks of Material Misstatement Due to Fraud in Revenue Recognition
41
When identifying and assessing the risks of material misstatement due to fraud, the auditor shall, based on a presumption that there are risks of material misstatement due to fraud in revenue recognition, determine which types of revenue, revenue transactions or relevant assertions give rise to such risks, taking into account related fraud risk factors. (Ref: Para. A119–A125)
Designing and Performing Audit Procedures in a Manner That Is Not Biased
42
The auditor shall design and perform audit procedures in response to the assessed risks of material misstatement due to fraud in a manner that is not biased towards obtaining audit evidence that may corroborate management’s assertions or towards excluding audit evidence that may contradict such assertions.
Unpredictability in the Selection of Audit Procedures
43
In determining responses to address assessed risks of material misstatement due to fraud, the auditor shall incorporate an element of unpredictability in the selection of the nature, timing and extent of audit procedures. (Ref: Para. A126–A127)
Overall Responses
44
In accordance with ASA 330, the auditor shall determine overall responses to address the assessed risks of material misstatement due to fraud at the financial report level. (Ref: Para. A128)
45
In determining overall responses to address the assessed risks of material misstatement due to fraud at the financial report level, the auditor shall evaluate whether the selection and application of accounting policies by the entity, particularly those related to subjective measurements and complex transactions, may be indicative of fraudulent financial reporting.
Audit Procedures Responsive to the Assessed Risks of Material Misstatement Due to Fraud at the Assertion Level
46
In accordance with ASA 330, the auditor shall design and perform further audit procedures whose nature, timing and extent are based on and are responsive to the assessed risks of material misstatement due to fraud at the assertion level. (Ref: Para. A129–A135)
Audit Procedures Responsive to Risks of Material Misstatement Due to Fraud Related to Management Override of Controls
47
Irrespective of the auditor’s assessment of the risks of management override of controls, the auditor shall design and perform the audit procedures in accordance with paragraphs 48–52, and determine whether other audit procedures are needed in addition to those in paragraphs 48–52, in order to respond to the identified risks of management override of controls.
Journal Entries and Other Adjustments
48
The auditor shall design and perform audit procedures to test the appropriateness of journal entries recorded in the general ledger and other adjustments made in the preparation of the financial report. (Ref: Para. A136–A139)
49
In designing and performing audit procedures in accordance with paragraph 48, the auditor shall: (Ref: Para. A99)
49(a)
Make enquiries of individuals involved in the financial reporting process about their knowledge of inappropriate or unusual activity relating to the processing of journal entries and other adjustments;
49(b)
Obtain audit evidence about the completeness of the population of journal entries and other adjustments made throughout the period; (Ref: Para. A140 and A147)
49(c)
Select journal entries and other adjustments made at the end of a reporting period; and (Ref: Para. A141–A143, A144 and A146–A147)
49(d)
Determine the need to test journal entries and other adjustments made throughout the period. (Ref: Para. A142–A143 and A145–A146)
Accounting Estimates
50
In applying ASA 540, if indicators of possible management bias are identified, the auditor shall evaluate whether they may represent a risk of material misstatement due to fraud. (Ref: Para. A148–A150)
51
In performing the evaluation in accordance with paragraph 50, the auditor shall:
51(a)
Consider the audit evidence obtained from the retrospective review performed in accordance with paragraph 28; and
51(b)
If indicators of possible management bias are identified, re-evaluate the accounting estimates taken as a whole. (Ref: Para. A150–A152)
Significant Transactions Outside the Normal Course of Business or Otherwise Appear Unusual
52
For significant transactions that are outside the normal course of business for the entity, or that otherwise appear to be unusual given the auditor’s understanding of the entity and its environment and information from other sources obtained during the audit, the auditor shall evaluate whether the business rationale (or the lack thereof) of the transactions suggests that they may have been entered into to engage in fraudulent financial reporting or to conceal misappropriation of assets. (Ref: Para. A153)
Analytical Procedures Performed Near the End of the Audit in Forming an Overall Conclusion
53
In applying ASA 520, the auditor shall determine whether the results of analytical procedures that are performed near the end of the audit, when forming an overall conclusion as to whether the financial report is consistent with the auditor’s understanding of the entity, indicate a previously unrecognised risk of material misstatement due to fraud. (Ref: Para. A154–A155)
Overall Evaluation Based on Audit Procedures Performed
54
In applying ASA 330, the auditor shall evaluate, based on the audit procedures performed and audit evidence obtained, whether:
54(a)
The assessments of the risks of material misstatement due to fraud remain appropriate; and
54(b)
Sufficient appropriate audit evidence has been obtained in response to the assessed risks of material misstatement due to fraud.
Fraud or Suspected Fraud (Ref: Para. A7–A11, A28 and A156–A172)
55
If the auditor identifies fraud or suspected fraud, the auditor shall obtain an understanding of the matter(s) in order to determine the effect on the audit engagement. In doing so, the auditor shall: (Ref: Para.A158–A162)
55(a)
Make enquiries about the matter(s) with the appropriate level of management and, when appropriate in the circumstances, make enquiries about the matter(s) with those charged with governance;
55(b)
If the entity has a process to investigate the matter(s), evaluate whether it is appropriate in the circumstances; and
55(c)
If the entity has implemented remedial actions to respond to the matter(s), evaluate whether they are appropriate in the circumstances.
56
Except for fraud or suspected fraud determined by the auditor to be clearly inconsequential based on the procedures performed in paragraph 55, the engagement partner shall: (Ref: Para. A163–A165)
56(a)
Determine whether:
To perform additional risk assessment procedures to provide an appropriate basis for the identification and assessment of the risks of material misstatement due to fraud in accordance with ASA 315;
To design and perform further audit procedures to appropriately respond to the risks of material misstatement due to fraud in accordance with ASA 330; and
There are additional responsibilities for the auditor under law, regulation or relevant ethical requirements about the entity’s non-compliance with laws or regulations in accordance with ASA 250.
56(b)
If applicable, consider the impact on prior period audits.
57
If the auditor identifies a misstatement due to fraud, the auditor shall: (Ref: Para. A166–A172)
57(a)
Determine whether the identified misstatement is material by considering the nature of the qualitative or quantitative circumstances giving rise to the misstatement;
57(b)
Determine whether control deficiencies exist, including significant deficiencies in internal control related to the prevention or detection of fraud, relating to the identified fraud or suspected fraud;
57(c)
Determine the implications of the misstatement in relation to other aspects of the audit, including when the auditor has reason to believe that management is involved; and
57(d)
Reconsider the reliability of management’s representations and audit evidence previously obtained, including when the circumstances or conditions giving rise to the misstatement indicate possible collusion involving employees, management or third parties.
58
If the auditor determines that the financial report is materially misstated due to fraud or the auditor is unable to obtain sufficient appropriate audit evidence to enable the auditor to conclude whether the financial report is materially misstated due to fraud, the auditor shall:
58(a)
Determine the implications for the audit and the auditor’s opinion on the financial report in accordance with ASA 705; and
58(b)
If appropriate, obtain advice from legal counsel.
Auditor Unable to Continue the Audit Engagement
59
If, as a result of a misstatement resulting from fraud or suspected fraud, the auditor encounters exceptional circumstances that bring into question the auditor’s ability to continue performing the audit engagement, the auditor shall:
59(a)
Determine the professional and legal responsibilities applicable in the circumstances, including whether there is a requirement for the auditor to report to the person or persons who made the audit appointment or, in some cases, to regulatory authorities;
59(b)
Consider whether it is appropriate to withdraw from the engagement, where withdrawal is possible under applicable law or regulation;
59(c)
If the auditor withdraws:
Discuss with the appropriate level of management and those charged with governance the auditor’s withdrawal from the engagement and the reasons for the withdrawal; and
Determine whether there is a professional or legal requirement to report to the person or persons who made the audit appointment or, in some cases, to regulatory authorities, the auditor’s withdrawal from the engagement and the reasons for the withdrawal; and (Ref: Para. A173–A176)
59(d)
Where law or regulation prohibits the auditor from withdrawing from the engagement, consider whether the exceptional circumstances will result in a disclaimer of opinion on the financial report.
Determining Key Audit Matters Related to Fraud
60
In applying ASA 701, the auditor shall determine, from the matters related to fraud communicated with those charged with governance, those matters that required significant auditor attention in performing the audit. In making this determination, the auditor shall take into account the following: (Ref: Para. A177–A183)
60(a)
Identified and assessed risks of material misstatement due to fraud;
60(b)
The identification of fraud or suspected fraud; and
60(c)
The identification of significant deficiencies in internal control that are relevant to the prevention and detection of fraud.
61
In applying ASA 701, the auditor shall determine which of the matters determined in accordance with paragraph 60 were of most significance in the audit of the financial report of the current period and therefore are key audit matters. (Ref: Para. A184–A186)
Communicating Key Audit Matters Related to Fraud
62
In applying ASA 701, in the Key Audit Matters section of the auditor’s report, the auditor shall use an appropriate subheading that clearly describes that the matter relates to fraud. (Ref: Para. A187–A192)
Written Representations
63
The auditor shall obtain written representations from management and, where appropriate, those charged with governance that: (Ref: Para. A193–A194)
63(a)
They acknowledge their responsibility for the design, implementation, and maintenance of internal control to prevent or detect fraud and have appropriately fulfilled those responsibilities;
63(b)
They have disclosed to the auditor the results of management’s assessment of the risk that the financial report may be materially misstated as a result of fraud;
63(c)
They have disclosed to the auditor their knowledge of any fraud or suspected fraud, including allegations of fraud, affecting the entity involving:
Management;
Employees who have significant roles in internal control; or
Others where the fraud could have an effect on the financial report; and
63(d)
They have disclosed to the auditor their knowledge of suspected fraud, including allegations of fraud, affecting the entity’s financial report communicated by employees, former employees, analysts, regulators, or others.
Communication with Management
64
If the auditor identifies fraud or suspected fraud, the auditor shall communicate these matters, unless prohibited by law or regulation, on a timely basis with the appropriate level of management in order to inform those with primary responsibility for the prevention and detection of fraud of matters relevant to their responsibilities. (Ref: Para. A195–A196)
Communication with Those Charged with Governance
65
Unless all of those charged with governance are involved in managing the entity, if the auditor identifies fraud or suspected fraud, involving:
65(a)
Management;
65(b)
Employees who have significant roles in internal control; or
65(c)
Others, except for matters that are clearly inconsequential,
66
the auditor shall communicate these matters with those charged with governance on a timely basis. If the auditor identifies suspected fraud involving management, the auditor shall communicate the suspected fraud with those charged with governance and discuss with them the nature, timing, and extent of audit procedures necessary to complete the audit. Such communications with those charged with governance are required unless the communication is prohibited by law or regulation. (Ref: Para. A195 and A197–A199)
67
The auditor shall communicate, unless prohibited by law or regulation, with those charged with governance any other matters related to fraud that are, in the auditor’s judgement, relevant to the responsibilities of those charged with governance. (Ref: Para. A195 and A200)
Reporting to an Appropriate Authority Outside the Entity
68
If the auditor identifies fraud or suspected fraud, the auditor shall determine whether law, regulation or relevant ethical requirements: (Ref: Para. A201–A205)
68(a)
Require the auditor to report to an appropriate authority outside the entity.
68(b)
Establish responsibilities or rights under which reporting to an appropriate authority outside the entity may be appropriate in the circumstances.
Documentation
69
In applying ASA 230, the auditor shall include the following in the audit documentation: (Ref: Para. A206)
69(a)
The matters discussed among the engagement team regarding the susceptibility of the entity’s financial report to material misstatement due to fraud in accordance with paragraph 29.
69(b)
Key elements of the auditor’s understanding in accordance with paragraphs 31–36, the sources of information from which the auditor’s understanding was obtained and the risk assessment procedures performed.
69(c)
The identified and assessed risks of material misstatement due to fraud at the financial report level and at the assertion level, and the rationale for the significant judgements made.
69(d)
If the auditor has concluded that the presumption that a risk of material misstatement due to fraud related to revenue recognition is not applicable in the circumstances of the engagement, the reasons for that conclusion.
69(e)
The results of audit procedures performed to address the risks of management override of controls, the significant professional judgements made, and the conclusions reached.
69(f)
Fraud or suspected fraud identified, the results of audit procedures performed, the significant professional judgements made, and the conclusions reached.
69(g)
The matters related to fraud or suspected fraud communicated with management, those charged with governance, regulatory and enforcement authorities, and others, including how management, and where applicable, those charged with governance have responded to the matters.
* * *