Requirements
20
The auditor shall remain alert throughout the audit for information that indicates that one or more fraud risk factors are present and circumstances that may be indicative of fraud or suspected fraud. (Ref: Para. A28–A32)
21
Where responses to enquiries of management, those charged with governance, individuals within the internal audit function, or others within the entity are inconsistent, the auditor shall investigate the inconsistencies. (Ref: Para. A33)
22
If conditions identified during the audit cause the auditor to believe that a record or document may not be authentic or that terms in a document have been modified but not disclosed to the auditor, the auditor shall investigate further. (Ref: Para. A34–A37)
Engagement Resources
23
In applying ASA 220,[12] the engagement partner shall determine that members of the engagement team collectively have the appropriate competence and capabilities, including sufficient time and appropriate specialised skills or knowledge to perform risk assessment procedures, identify and assess the risks of material misstatement due to fraud, design and perform further audit procedures to respond to those risks, or evaluate the audit evidence obtained. (Ref: Para. A38–A42)
Engagement Performance
24
In applying ASA 220,[13] the engagement partner shall determine that the nature, timing and extent of direction, supervision and review is responsive to the nature and circumstances of the audit engagement, considering matters identified during the course of the audit engagement, including: (Ref: Para. A43)
a. Fraud risk factors;
b. Fraud or suspected fraud; and
c. Control deficiencies related to the prevention or detection of fraud.
Ongoing Nature of Communications with Management and Those Charged with Governance
25
The auditor shall communicate with management and those charged with governance matters related to fraud at appropriate times throughout the audit engagement. (Ref: Para. A44–A48)
Risk Assessment Procedures and Related Activities
26
In applying ASA 315,[14] the auditor shall perform the procedures in paragraphs 27–38. In doing so, the auditor shall consider whether one or more fraud risk factors are present. (Ref: Para. A49)
Information from Other Sources
Retrospective Review of the Outcome of Previous Accounting Estimates
28
In applying ASA 540,[16] the auditor shall perform a retrospective review of management judgements and assumptions related to the outcome of previous accounting estimates, or where applicable, their subsequent re-estimation to assist in identifying and assessing the risks of material misstatement due to fraud in the current period. In doing so, the auditor shall take into account the characteristics of the accounting estimates in determining the nature and extent of that review. (Ref: Para. A52)
Engagement Team Discussion
29
In applying ASA 315,[17] when holding the engagement team discussion, the engagement partner and other key engagement team members shall place particular emphasis on how and where the entity’s financial report may be susceptible to material misstatement due to fraud, including how fraud may occur. In doing so, the engagement team discussion shall include: (Ref: Para. A43, A53–A54 and A59)
a. An exchange of ideas about:
i. The entity’s culture, management’s commitment to integrity and ethical values, and related oversight by those charged with governance; (Ref: Para. A55)
ii. Fraud risk factors, including: (Ref: Para. A56–A57)
a. Incentives or pressures on management, those charged with governance, or employees to commit fraud;
b. How one or more individuals among management, those charged with governance, or employees could perpetrate and conceal fraudulent financial reporting; and
c. How assets of the entity could be misappropriated by management, those charged with governance, employees or third parties.
iii. Which types of revenue, revenue transactions or relevant assertions may give rise to the risks of material misstatement due to fraud in revenue recognition; and
iv. How management may be able to override controls. (Ref: Para. A58)
b. A consideration of any fraud or suspected fraud that may impact the overall audit strategy and audit plan, including fraud that has occurred at the entity during the current or prior years.
Analytical Procedures Performed and Unusual or Unexpected Relationships Identified
30
The auditor shall determine whether unusual or unexpected relationships that have been identified in performing analytical procedures, including those related to revenue accounts, may indicate risks of material misstatement due to fraud. (Ref: Para. A60)
Obtaining an Understanding of the Entity and Its Environment, the Applicable Financial Reporting Framework and the Entity's System of Internal Control
Understanding the Entity and Its Environment, and the Applicable Financial Reporting Framework
31
In applying ASA 315,[18] based on the auditor’s understanding of the entity and its environment, the applicable financial reporting framework and the entity’s accounting policies, the auditor shall obtain an understanding of matters that may lead to an increased susceptibility to misstatement due to management bias or other fraud risk factors. (Ref: Para. A61–A70)
Understanding the Components of the Entity’s System of Internal Control
Control Environment
32
In applying ASA 315,[19] the auditor shall:
a. Obtain an understanding of:
i. How management’s oversight responsibilities are carried out, such as the entity’s culture and management’s commitment to integrity and ethical values, including how management communicates with its employees its views on business practices and ethical behaviour with respect to the prevention and detection of fraud. (Ref: Para. A71–A72)
ii. The entity’s whistleblower program (or other program to report fraud), if the entity has such a program, including how management and, if applicable, those charged with governance address allegations of fraud made through the program. (Ref: Para. A73–A75)
iii. How those charged with governance exercise oversight of management’s processes for identifying and responding to the fraud risks and the controls that management has established to address these risks. (Ref: Para. A76–A79)
b. Make enquiries of management regarding management’s communications with those charged with governance regarding its processes for identifying and responding to the risks of fraud in the entity.
c. Make enquiries of those charged with governance about: (Ref: Para. A80–A82)
i. Whether they have knowledge of any fraud or suspected fraud including allegations of fraud, including those received from tips or complaints, affecting the entity, and if so, how they have responded to such matters;
ii. Their views about whether and how the financial report may be materially misstated due to fraud, including their views on possible areas that are susceptible to misstatement due to management bias or management fraud; and
iii. Whether they are aware of deficiencies in the system of internal control related to the prevention and detection of fraud, and the remediation efforts to address such deficiencies.
The Entity’s Risk Assessment Process
33
In applying ASA 315,[20] the auditor shall:
- Obtain an understanding of how the entity’s risk assessment process: (Ref: Para. A83–A91, A107)
- Identifies fraud risks related to the misappropriation of assets and fraudulent financial reporting, including any classes of transactions, account balances, or disclosures for which risks of fraud exist;
- Assesses the significance of the identified fraud risks, including the likelihood of their occurrence; and
- Addresses the assessed fraud risks.
- Make enquiries of management and of other appropriate individuals within the entity about: (Ref: Para. A92–A95)
- Whether they have knowledge of any fraud or suspected fraud, including allegations of fraud, affecting the entity; and
- Their views about whether and how the financial report may be materially misstated due to fraud.
The Entity’s Process to Monitor the System of Internal Control
34
In applying ASA 315,[21] the auditor shall:
- Obtain an understanding of:
- Aspects of the entity’s process to monitor the system of internal control that address the ongoing and separate evaluations for monitoring the effectiveness of controls to prevent or detect fraud, and the identification and remediation of related control deficiencies identified; and (Ref: Para. A96)
- If the entity has an internal audit function, the internal audit function’s objectives in respect of monitoring controls over risks of fraud.
- If the entity has an internal audit function, make enquiries of appropriate individuals within the internal audit function about whether: (Ref: Para. A97–A98)
- They have performed any procedures in respect of monitoring controls over risks of fraud during the period;
- They have knowledge of any fraud or suspected fraud, including allegations of fraud, affecting the entity and to obtain their views about the risks of fraud; and
- They are aware of deficiencies in the system of internal control related to the prevention and detection of fraud.
The Information System and Communication
35
In applying ASA 315,[22] the auditor’s understanding of the entity’s information system and communication relevant to the preparation of the financial report shall include understanding how journal entries and other adjustments are initiated, processed, recorded, and corrected as necessary. (Ref: Para. A99–A101)
Control Activities
36
In applying ASA 315,[23] the auditor’s understanding of the entity’s control activities shall include identifying controls that address risks of material misstatement due to fraud at the assertion level, including controls over journal entries and other adjustments, designed to prevent or detect fraud. (Ref: Para. A102–A107)
Control Deficiencies Within the Entity’s System of Internal Control
37
In applying ASA 315,[24] based on the auditor’s evaluation of each of the components of the entity’s system of internal control, the auditor shall determine whether there are deficiencies in internal control identified that are relevant to the prevention or detection of fraud. (Ref: Para. A108–A109)
Identifying and Assessing the Risks of Material Misstatement due to Fraud
39
In applying ASA 315,[25] the auditor shall:
a. Identify and assess the risks of material misstatement due to fraud and determine whether they exist at the financial report level, or the assertion level for classes of transactions, account balances and disclosures, taking into account fraud risk factors. (Ref: Para. A113–A114, A116)
b. Treat those assessed risks of material misstatement due to fraud as significant risks. Accordingly, to the extent not already done so, the auditor shall identify controls that address such significant risks, evaluate whether they have been designed effectively to address the risks of material misstatement, or designed effectively to support the operation of other controls, and determine whether they have been implemented. (Ref: Para. A115)
Risks of Material Misstatement Due to Fraud Related to Management Override of Controls
40
Due to the unpredictable way in which management is able to override controls and irrespective of the auditor’s assessment of the risks of management override of controls, the auditor shall: (Ref: Para. A117–A118)
a. Treat the risks of management override of controls as risks of material misstatement due to fraud at the financial report level; and
b. Determine whether such risks affect the assessment of risks at the assertion level.
Risks of Material Misstatement Due to Fraud in Revenue Recognition
41
When identifying and assessing the risks of material misstatement due to fraud, the auditor shall, based on a presumption that there are risks of material misstatement due to fraud in revenue recognition, determine which types of revenue, revenue transactions or relevant assertions give rise to such risks, taking into account related fraud risk factors. (Ref: Para. A119–A125)
Responses to the Assessed Risks of Material Misstatement Due to Fraud
Designing and Performing Audit Procedures in a Manner That Is Not Biased
42
The auditor shall design and perform audit procedures in response to the assessed risks of material misstatement due to fraud in a manner that is not biased towards obtaining audit evidence that may corroborate management’s assertions or towards excluding audit evidence that may contradict such assertions.
Unpredictability in the Selection of Audit Procedures
43
In determining responses to address assessed risks of material misstatement due to fraud, the auditor shall incorporate an element of unpredictability in the selection of the nature, timing and extent of audit procedures. (Ref: Para. A126–A127)
Overall Responses
45
In determining overall responses to address the assessed risks of material misstatement due to fraud at the financial report level, the auditor shall evaluate whether the selection and application of accounting policies by the entity, particularly those related to subjective measurements and complex transactions, may be indicative of fraudulent financial reporting.
Audit Procedures Responsive to the Assessed Risks of Material Misstatement Due to Fraud at the Assertion Level
Audit Procedures Responsive to Risks of Material Misstatement Due to Fraud Related to Management Override of Controls
47
Irrespective of the auditor’s assessment of the risks of management override of controls, the auditor shall design and perform the audit procedures in accordance with paragraphs 48–52, and determine whether other audit procedures are needed in addition to those in paragraphs 48–52, in order to respond to the identified risks of management override of controls.
Journal Entries and Other Adjustments
48
The auditor shall design and perform audit procedures to test the appropriateness of journal entries recorded in the general ledger and other adjustments made in the preparation of the financial report. (Ref: Para. A136–A139)
49
In designing and performing audit procedures in accordance with paragraph 48, the auditor shall: (Ref: Para. A99)
a. Make enquiries of individuals involved in the financial reporting process about their knowledge of inappropriate or unusual activity relating to the processing of journal entries and other adjustments;
b. Obtain audit evidence about the completeness of the population of journal entries and other adjustments made throughout the period; (Ref: Para. A140 and A147)
c. Select journal entries and other adjustments made at the end of a reporting period; and (Ref: Para. A141–A143, A144 and A146–A147)
d. Determine the need to test journal entries and other adjustments made throughout the period. (Ref: Para. A142–A143 and A145–A146)
Accounting Estimates
51
In performing the evaluation in accordance with paragraph 50, the auditor shall:
a. Consider the audit evidence obtained from the retrospective review performed in accordance with paragraph 28; and
b. If indicators of possible management bias are identified, re-evaluate the accounting estimates taken as a whole. (Ref: Para. A150–A152)
Significant Transactions Outside the Normal Course of Business or Otherwise Appear Unusual
52
For significant transactions that are outside the normal course of business for the entity, or that otherwise appear to be unusual given the auditor’s understanding of the entity and its environment and information from other sources obtained during the audit, the auditor shall evaluate whether the business rationale (or the lack thereof) of the transactions suggests that they may have been entered into to engage in fraudulent financial reporting or to conceal misappropriation of assets. (Ref: Para. A153)
Analytical Procedures Performed Near the End of the Audit in Forming an Overall Conclusion
53
In applying ASA 520,[29] the auditor shall determine whether the results of analytical procedures that are performed near the end of the audit, when forming an overall conclusion as to whether the financial report is consistent with the auditor’s understanding of the entity, indicate a previously unrecognised risk of material misstatement due to fraud. (Ref: Para. A154–A155)
Overall Evaluation Based on Audit Procedures Performed
54
In applying ASA 330,[30] the auditor shall evaluate, based on the audit procedures performed and audit evidence obtained, whether:
a. The assessments of the risks of material misstatement due to fraud remain appropriate; and
b. Sufficient appropriate audit evidence has been obtained in response to the assessed risks of material misstatement due to fraud.
55
If the auditor identifies fraud or suspected fraud, the auditor shall obtain an understanding of the matter(s) in order to determine the effect on the audit engagement. In doing so, the auditor shall: (Ref: Para. A158–A162)
a. Make enquiries about the matter(s) with the appropriate level of management and, when appropriate in the circumstances, make enquiries about the matter(s) with those charged with governance;
b. If the entity has a process to investigate the matter(s), evaluate whether it is appropriate in the circumstances; and
c. If the entity has implemented remedial actions to respond to the matter(s), evaluate whether they are appropriate in the circumstances.
56
Except for fraud or suspected fraud determined by the auditor to be clearly inconsequential based on the procedures performed in paragraph 55, the engagement partner shall: (Ref: Para. A163–A165)
a. Determine whether:
i. To perform additional risk assessment procedures to provide an appropriate basis for the identification and assessment of the risks of material misstatement due to fraud in accordance with ASA 315;
ii. To design and perform further audit procedures to appropriately respond to the risks of material misstatement due to fraud in accordance with ASA 330; and
iii. There are additional responsibilities for the auditor under law, regulation or relevant ethical requirements about the entity’s non-compliance with laws or regulations in accordance with ASA 250.
b. If applicable, consider the impact on prior period audits.
57
If the auditor identifies a misstatement due to fraud, the auditor shall: (Ref: Para. A166–A172)
a. Determine whether the identified misstatement is material by considering the nature of the qualitative or quantitative circumstances giving rise to the misstatement;
b. Determine whether control deficiencies exist, including significant deficiencies in internal control related to the prevention or detection of fraud, relating to the identified fraud or suspected fraud;
c. Determine the implications of the misstatement in relation to other aspects of the audit, including when the auditor has reason to believe that management is involved; and
d. Reconsider the reliability of management’s representations and audit evidence previously obtained, including when the circumstances or conditions giving rise to the misstatement indicate possible collusion involving employees, management or third parties.
58
If the auditor determines that the financial report is materially misstated due to fraud or the auditor is unable to obtain sufficient appropriate audit evidence to enable the auditor to conclude whether the financial report is materially misstated due to fraud, the auditor shall:
a. Determine the implications for the audit and the auditor’s opinion on the financial report in accordance with ASA 705;[31] and
b. If appropriate, obtain advice from legal counsel.
Auditor Unable to Continue the Audit Engagement
59
If, as a result of a misstatement resulting from fraud or suspected fraud, the auditor encounters exceptional circumstances that bring into question the auditor’s ability to continue performing the audit engagement, the auditor shall:
a. Determine the professional and legal responsibilities applicable in the circumstances, including whether there is a requirement for the auditor to report to the person or persons who made the audit appointment or, in some cases, to regulatory authorities;
b. Consider whether it is appropriate to withdraw from the engagement, where withdrawal is possible under applicable law or regulation;
c. If the auditor withdraws:
i. Discuss with the appropriate level of management and those charged with governance the auditor’s withdrawal from the engagement and the reasons for the withdrawal; and
ii. Determine whether there is a professional or legal requirement to report to the person or persons who made the audit appointment or, in some cases, to regulatory authorities, the auditor’s withdrawal from the engagement and the reasons for the withdrawal; and (Ref: Para. A173–A176)
d. Where law or regulation prohibits the auditor from withdrawing from the engagement, consider whether the exceptional circumstances will result in a disclaimer of opinion on the financial report.
Auditor's Report
Determining Key Audit Matters Related to Fraud
60
In applying ASA 701,[32] the auditor shall determine, from the matters related to fraud communicated with those charged with governance, those matters that required significant auditor attention in performing the audit. In making this determination, the auditor shall take into account the following: (Ref: Para. A177–A183)
a. Identified and assessed risks of material misstatement due to fraud;
b. The identification of fraud or suspected fraud; and
c. The identification of significant deficiencies in internal control that are relevant to the prevention and detection of fraud.
Communicating Key Audit Matters Related to Fraud
Written Representations
63
The auditor shall obtain written representations from management and, where appropriate, those charged with governance that: (Ref: Para. A193–A194)
a. They acknowledge their responsibility for the design, implementation, and maintenance of internal control to prevent or detect fraud and have appropriately fulfilled those responsibilities;
b. They have disclosed to the auditor the results of management’s assessment of the risk that the financial report may be materially misstated as a result of fraud;
c. They have disclosed to the auditor their knowledge of any fraud or suspected fraud, including allegations of fraud, affecting the entity involving:
i. Management;
ii. Employees who have significant roles in internal control; or
iii. Others where the fraud could have an effect on the financial report; and
d. They have disclosed to the auditor their knowledge of suspected fraud, including allegations of fraud, affecting the entity’s financial report communicated by employees, former employees, analysts, regulators, or others.
Communications with Management and Those Charged with Governance
Communication with Management
64
If the auditor identifies fraud or suspected fraud, the auditor shall communicate these matters, unless prohibited by law or regulation, on a timely basis with the appropriate level of management in order to inform those with primary responsibility for the prevention and detection of fraud of matters relevant to their responsibilities. (Ref: Para. A195–A196)
Communication with Those Charged with Governance
65
Unless all of those charged with governance are involved in managing the entity, if the auditor identifies fraud or suspected fraud, involving:
a. Management;
b. Employees who have significant roles in internal control; or
c. Others, except for matters that are clearly inconsequential,
the auditor shall communicate these matters with those charged with governance on a timely basis. If the auditor identifies suspected fraud involving management, the auditor shall communicate the suspected fraud with those charged with governance and discuss with them the nature, timing, and extent of audit procedures necessary to complete the audit. Such communications with those charged with governance are required unless the communication is prohibited by law or regulation. (Ref: Para. A195 and A197–A199)
Reporting to an Appropriate Authority Outside the Entity
67
If the auditor identifies fraud or suspected fraud, the auditor shall determine whether law, regulation or relevant ethical requirements: (Ref: Para. A201–A205)
a. Require the auditor to report to an appropriate authority outside the entity.
b. Establish responsibilities or rights under which reporting to an appropriate authority outside the entity may be appropriate in the circumstances.
Documentation
68
In applying ASA 230,[35] the auditor shall include the following in the audit documentation: (Ref: Para. A206)
a. The matters discussed among the engagement team regarding the susceptibility of the entity’s financial report to material misstatement due to fraud in accordance with paragraph 29.
b. Key elements of the auditor’s understanding in accordance with paragraphs 31–36, the sources of information from which the auditor’s understanding was obtained and the risk assessment procedures performed.
c. The identified and assessed risks of material misstatement due to fraud at the financial report level and at the assertion level, and the rationale for the significant judgements made.
d. If the auditor has concluded that the presumption that a risk of material misstatement due to fraud related to revenue recognition is not applicable in the circumstances of the engagement, the reasons for that conclusion.
e. The results of audit procedures performed to address the risks of management override of controls, the significant professional judgements made, and the conclusions reached.
f. Fraud or suspected fraud identified, the results of audit procedures performed, the significant professional judgements made, and the conclusions reached.
g. The matters related to fraud or suspected fraud communicated with management, those charged with governance, regulatory and enforcement authorities, and others, including how management, and where applicable, those charged with governance have responded to the matters.
See ASA 200, paragraph 15.
See ASA 220, paragraphs 25–28.
See ASA 220, paragraph 30(b).
See ASA 315, paragraphs 13–27.
See ASA 315, paragraphs 15–16.
See ASA 540 Auditing Accounting Estimates and Related Disclosures, paragraph 14.
See ASA 315, paragraphs 17 and A42–A43.
See ASA 315, paragraph 19.
See ASA 315, paragraph 21.
See ASA 315, paragraph 22.
See ASA 315, paragraph 24.
See ASA 315, paragraph 25.
See ASA 315, paragraph 26.
See ASA 315, paragraph 27.
See ASA 315, paragraph 28–34.
See ASA 330, paragraph 5.
See ASA 330, paragraph 6.
See ASA 540, paragraph 32.
See ASA 520, Analytical Procedures, paragraph 6.
See ASA 705, Modifications to the Opinion in the Independent Auditor’s Report.
See ASA 701, paragraph 9.
See ASA 701, paragraph 10.
See ASA 701, paragraph 11.