Application and Other Explanatory Material
Considerations Specific to Public Sector Entities
A1
The public sector auditor’s responsibilities relating to fraud may be a result of law, regulation or other authority applicable to public sector entities or separately covered by the auditor’s mandate. Consequently, the public sector auditor’s responsibilities may not be limited to consideration of risks of material misstatement of the financial report but may also include a broader responsibility to consider risks of fraud.
Characteristics of Fraud (Ref: Para. 5)
A3
Examples:
Incentive or pressure to commit fraudulent financial reporting may exist when management is under pressure, from sources outside or inside the entity, to achieve an expected (and perhaps unrealistic) earnings target or financial outcome — particularly when the consequences to management for failing to meet financial goals can be significant. Similarly, individuals may have an incentive to misappropriate assets — for example, because the individuals are living beyond their means.
A perceived opportunity to commit fraud may exist when an individual believes controls can be overridden, for example, because the individual is in a position of trust or has knowledge of specific control deficiencies.
Individuals may rationalise committing a fraudulent act as they may possess an attitude, character or set of ethical values that allow them to knowingly and intentionally commit a dishonest act. However, even otherwise honest individuals can commit fraud in an environment that imposes sufficient pressure on them.
Characteristics of Fraud (Ref: Para. 5)
A3
Fraud, whether fraudulent financial reporting or misappropriation of assets, involves incentive or pressure to commit fraud, a perceived opportunity to do so and some rationalisation of the act.
A5
Examples:
Management intentionally takes positions that lead to fraudulent financial reporting by materially misstating the financial report due to pressures to meet market expectations or a desire to maximise compensation based on performance.
Management reduces earnings by a material amount to minimise tax.
Management inflates earnings to secure bank financing.
In the public sector, misreporting of revenues or underreporting of expenditures, especially when such expenditures are subject to statutory limits.
A5
Fraudulent financial reporting involves intentional misstatements, including omissions of amounts or disclosures in financial report, to deceive financial report users. It can be caused by the efforts of management to manage earnings to deceive financial report users by influencing their perceptions as to the entity’s performance and profitability. Such earnings management may start out with small actions, or adjustment of assumptions, and changes in judgements by management. Pressures and incentives may lead these actions to increase to the extent that they result in material fraudulent financial reporting.
A6
Fraudulent financial reporting may be accomplished by the following:
Manipulation, falsification (including forgery), or alteration of accounting records or supporting documentation from which the financial report is prepared.
Misrepresentation in, or intentional omission from, the financial report of events, transactions or other significant information.
Intentional misapplication of the applicable financial reporting framework relating to amounts, classification, manner of presentation, or disclosure.
A7
Fraudulent financial reporting often involves management override of controls that otherwise may appear to be operating effectively. Fraud can be committed by management overriding controls using such techniques as intentionally:
Recording fictitious journal entries to manipulate operating results or achieve other objectives.
Inappropriately adjusting assumptions and changing judgements used to estimate account balances.
Omitting, advancing or delaying recognition in the financial report of events and transactions that have occurred during the reporting period.
Misstating disclosures, including omitting and obscuring disclosures, required by the applicable financial reporting framework, or disclosures that are necessary to achieve fair presentation.
Concealing facts that could affect the amounts recorded in the financial report.
Engaging in complex transactions that are structured to misrepresent the financial position or financial performance of the entity.
Altering records and terms related to transactions.
Altering reports that would highlight inappropriate activity or transactions.
Taking advantage of inadequate information processing controls in information technology (IT) applications, including controls over and review of IT application event logs (e.g., modifying the application logic, or where users can access a common database using generic access identification, or modify access identification, to conceal activity).
A9
Examples:
Embezzling funds (e.g., misappropriating collections of accounts receivable or diverting receipts in respect of written-off accounts to personal bank accounts).
Theft of assets (e.g., stealing inventory for personal use, stealing scrap for resale, theft of digital assets by exploiting a private key and in doing so allowing the perpetrator to control the entity’s funds, theft of intellectual property by colluding with a competitor to disclose technological data in return for payment).
Causing an entity to pay for goods and services not received (e.g., payments to fictitious suppliers, kickbacks paid by suppliers to the entity’s purchasing agents in return for approving payment for inflated prices, or payments to fictitious employees).
Using an entity’s assets for personal use (e.g., using the entity’s assets as collateral for a personal loan or a loan to a related party).
A9
Misappropriation of assets involves the theft of an entity’s assets and is often perpetrated by employees in relatively small and immaterial amounts. However, it can also involve management, who are usually better positioned to disguise or conceal misappropriations in ways that are difficult to detect. In addition, misappropriation of assets can involve third parties who are able to exploit the entity’s assets in order to obtain an unjust or illegal advantage. Misappropriation of assets can be accomplished in a variety of ways and is often accompanied by false or misleading records or documents in order to conceal the fact that the assets are missing or have been pledged without proper authorisation.
Fraud or Suspected Fraud (Ref: Para. 7, 8 and 55–58)
A11
Examples:
When obtaining an understanding of the entity’s whistleblower program, the auditor identified a tip submitted to the entity’s fraud reporting hotline which alleged that management had inflated earnings by entering into transactions with related parties which lacked a business purpose.
When performing further audit procedures to respond to assessed risks of material misstatement due to fraud at the assertion level for inventory, the auditor obtained audit evidence that indicated the possible misappropriation of products from the entity’s warehouse by employees.
Fraud or Suspected Fraud (Ref: Para. 7, 8 and 55–58)
A11
Audit evidence obtained when performing risk assessment procedures and further audit procedures in accordance with this ASA may indicate the existence of fraud or suspected fraud.
A12
Audit procedures performed to comply with other ASAs may also bring instances of fraud or suspected fraud to the auditor’s attention including, for example, those performed in accordance with ASA 600 when responding to assessed risks of material misstatement due to fraud arising from the consolidation process.
A13
The auditor may use automated tools and techniques to perform audit procedures related to identifying and assessing the risks of material misstatement due to fraud or when responding to assessed risks of material misstatement due to fraud. This may allow the auditor to evaluate large amounts of data more easily to, for example, provide deeper insights or identify unusual trends, which enhances the ability of the auditor to exercise professional scepticism and more effectively challenge management’s assertions. The auditor may also use automated tools and techniques to perform audit procedures related to journal entry testing in a more efficient and effective manner. However, the use of automated tools and techniques does not replace the need to maintain professional scepticism and to exercise professional judgement throughout the audit.
A14
For the purpose of this ASA, allegations of fraud by another party involving the entity are treated by the auditor as suspected fraud once the allegations have come to the auditor’s attention (e.g., identified as a result of enquiries made by the auditor of management, or when obtaining an understanding of the entity’s whistleblower program (or other program to report fraud)). The party making the allegations may be internal or external to the entity. Accordingly, the auditor performs audit procedures in accordance with paragraphs 55–58 to address the suspected fraud.
A15
Even when an identified misstatement due to fraud is not quantitatively material, it may be qualitatively material depending on:
Who instigated or perpetrated the fraud – an otherwise insignificant fraud perpetrated by senior management, or a public official is ordinarily considered qualitatively material irrespective of the amount involved. This may in turn give rise to concerns about the integrity of management responsible for the entity’s system of internal control.
Why the fraud was perpetrated – misstatements that are not material quantitatively, either individually or in the aggregate, may have been made intentionally by management to “manage” key performance indicators in order to, for example, meet market expectations, maximise compensation based on performance, or comply with the terms of debt covenants. In the public sector, misstatements may have been made intentionally by management to achieve a surplus when a deficit is prohibited by legislation or to misreport expenses incurred to avoid breaching statutory limits.
Inherent Limitations (Ref: Para. 10)
A16
The risk of not detecting a material misstatement resulting from fraud exists because fraud may involve sophisticated and carefully organised schemes designed to conceal it, such as forgery, deliberate failure to record transactions, or intentional misrepresentations being made to the auditor. Such attempts at concealment may be even more difficult to detect when accompanied by collusion. Collusion may cause the auditor to believe that audit evidence is persuasive when it is, in fact, false. The auditor’s ability to detect a fraud depends on factors such as the skilfulness of the perpetrator, the frequency and extent of manipulation, the degree of collusion involved, the relative size of individual amounts manipulated, and the seniority of those individuals involved. While the auditor may be able to identify potential opportunities for fraud to be perpetrated, it is difficult for the auditor to determine whether misstatements in areas requiring judgement such as accounting estimates are caused by fraud or error.
Professional Scepticism and Professional Judgement (Ref: Para. 13)
A17
ASQM 1 requires the firm to design, implement and operate a system of quality management for audits of the financial report. The firm’s commitment to an effective system of quality management underpins the requirement for the auditor to exercise professional scepticism when performing the audit engagement. This commitment is recognised and reinforced in the governance and leadership component, including a:
Commitment to quality by the leadership of the firm, such as the tone at the top by leadership contributes to the firm’s culture which in turn supports and encourages the auditor to focus on the auditor’s responsibilities relating to fraud in an audit of a financial report.
Recognition that the resource needs are planned for, and resources are obtained, allocated, or assigned in a manner that is consistent with the firm’s commitment to quality, such as resources with the appropriate specialised knowledge and skills that may be needed when performing audit procedures related to fraud in an audit of a financial report.
A18
ASQM 1 also explains that the quality of professional judgements exercised by the firm is likely to be enhanced when individuals making such judgements demonstrate an attitude that includes an enquiring mind.
Non-Compliance with Laws and Regulations (Ref: Para. 14)
A20
Example:
When obtaining an understanding of the entity’s general IT controls, the auditor was informed of a cybersecurity breach involving unauthorised access by a third party to the entity’s confidential customer files, including related banking information. After obtaining an understanding of the suspected fraud, the engagement partner determined that the cybersecurity breach likely violated local data protection laws.
Non-Compliance with Laws and Regulations (Ref: Para. 14)
A20
The identification by the auditor of fraud or suspected fraud affecting the entity that has been perpetrated by a third party (see paragraphs 18(a) and A22) may also give rise to additional responsibilities for the auditor in accordance with ASA 250.
A22
Example:
When performing tests of details on a bank’s loan portfolio, the auditor identified a series of loans to newly formed entities connected to senior management that lacked appropriate documentation. The auditor determined the circumstances were indicative of fraudulent approvals of loans by senior management to related parties. After obtaining an understanding of the suspected fraud in accordance with paragraph 55, the auditor concluded the understanding was also sufficient to meet the requirement in paragraph 19(a) of ASA 250. The auditor evaluated the possible effect on the financial report of the fine for the entity’s suspected violation of banking regulations regarding related-party lending in accordance with paragraph 19(b) of ASA 250.
A22
Complying with the requirements of this ASA may also fulfill certain applicable requirements in ASA 250.
A23
Law, regulation, or relevant ethical requirements may require the auditor to perform additional procedures and take further actions. For example, the Accounting Professional & Ethical Standards Board’s APES 110 Code of Ethics for Professional Accountants (including Independence Standards) (the Code) requires the auditor to take steps to respond to identified or suspected non-compliance with laws and regulations.
Relationship with Other ASAs (Ref: Para. 15)
A24
Appendix 5 identifies other ASAs that address specific topics that reference fraud or suspected fraud.
Relationship of Fraud with Corruption, Bribery and Money Laundering (Ref: Para. 18(a))
A25
Depending on the nature and circumstances of the entity, certain laws, regulations or aspects of relevant ethical requirements dealing with corruption, bribery or money laundering may be relevant to the auditor’s responsibilities to consider laws and regulations in an audit of a financial report in accordance with ASA 250.
A27
Examples:
Corruption involving fraud – Management colluded with other competing parties to raise prices or lower the quality of goods or services for purchasers who wish to acquire products or services through a bidding process (i.e., bid rigging). The bid rigging included monetary payments by the designated winning bidder to colluding parties using fraudulent consulting contracts for which no actual work took place.
Bribery to conceal fraud – Management offered inducements to employees for concealing the misappropriation of assets by management.
Money laundering to facilitate fraud – An employee laundered money, to an offshore bank account, that was illegally obtained from embezzling payments for fictitious purchases of inventory through the creation of false purchase orders, supplier shipping documents, and supplier invoices.
A27
Corruption, bribery and money laundering are forms of illegal or unethical acts. Corruption, bribery, and money laundering may be distinct concepts in law or regulation; however, they may also be fraudulent acts, or may be carried out to facilitate or conceal fraud.
A28
While the auditor may identify or suspect corruption, bribery, or money laundering, as with fraud, the auditor does not make legal determinations on whether such acts have actually occurred.
Third-Party Fraud (Ref: Para. 18(a))
A29
Fraud or suspected fraud committed against the entity by parties external to the entity is generally described as third-party fraud. Fraud as defined in paragraph 18(a) can include an intentional act by a third party and, accordingly, if an intentional act by a third party is identified or suspected that may have resulted in misappropriation of the entity’s assets or fraudulent financial reporting by the entity, the auditor performs audit procedures in paragraphs 55–58.
A30
Parties external to the entity that may commit third-party fraud may include:
Related parties, where potential opportunities for collusion with management, overly complex transactions, or bias in the structure of transactions may exist, as explained in ASA 550.
Third parties with which the entity has a relationship to support their business model such as customers, suppliers, service providers or other external parties known to the entity. These relationships may introduce the risk of collusion with employees or others in the entity to, for example, create fictitious transactions to manipulate financial results.
Third parties unknown to the entity that may, for example, attempt to gain unauthorised access to an entity’s IT environment that affects financial reporting or assets, or disrupts the entity’s business operations or financial reporting processes.
Fraud Risk Factors (Ref: Para. 18(b) and 38)
A31
The presence of fraud risk factors may affect the auditor’s assessment of inherent risk or control risk. Fraud risk factors may:
Be inherent risk factors, insofar as they affect inherent risk, and may be due to management bias. They may also arise from other identified inherent risk factors (e.g., complexity or uncertainty may create opportunities that result in a susceptibility to misstatement due to fraud). When fraud risk factors are inherent risk factors, the inherent risk is assessed before consideration of controls.
Relate to events or conditions that may exist in the entity’s system of internal control that provide an opportunity to commit fraud and are relevant to the consideration of the entity’s controls (i.e., related to control risk), and may be an indicator that other fraud risk factors are present.
A32
While fraud risk factors may not necessarily indicate the existence of fraud, they have often been present in circumstances where frauds have occurred and therefore may indicate risks of material misstatement due to fraud.
A33
Examples of fraud risk factors related to fraudulent financial reporting and misappropriation of assets are presented in Appendix 1. These illustrative fraud risk factors are classified based on the three conditions that are, individually or in combination, generally present when fraud exists:
An incentive or pressure to commit fraud;
A perceived opportunity to commit fraud; and
An attitude or rationalisation that justifies the fraudulent action.
A34
Fraud risk factors reflective of an attitude that permits rationalisation of the fraudulent action may not be susceptible to observation by the auditor. Nevertheless, the auditor may become aware of the existence of such information through, for example, the required understanding of the entity’s control environment. Although the fraud risk factors described in Appendix 1 cover a broad range of situations that may be faced by auditors, they are only examples and other fraud risk factors may exist.
Professional Scepticism (Ref: Para. 7, 19–22 and 55–58)
A35
Maintaining professional scepticism throughout the audit involves an ongoing questioning of whether the information and audit evidence obtained suggests that a material misstatement due to fraud may exist. It includes considering the reliability of the information intended to be used as audit evidence and identified controls in the control activities component, if any, over its preparation and maintenance. Due to the characteristics of fraud, the auditor’s professional scepticism is particularly important when considering the risks of material misstatement due to fraud.
A37
Examples:
Possible sources that may provide information about circumstances that may be indicative of fraud or suspected fraud that affects the entity include:
The auditor (e.g., when performing audit procedures in accordance with ASA 550, the auditor becomes aware of the existence of a related party relationship that management intentionally did not disclose to the auditor).
Those charged with governance (e.g., when members of the audit committee conduct an independent investigation of unusual journal entries and other adjustments).
Management (e.g., when evaluating the results of the entity’s risk assessment process).
Individuals within the internal audit function (e.g., when individuals conduct the annual compliance procedures related to the entity’s system of internal control).
An employee (e.g., by filing a tip using the entity’s whistleblower program).
A former employee (e.g., by sending a complaint via electronic mail to the internal audit function).
A37
The manner in which circumstances that may be indicative of fraud or suspected fraud that affects the entity come to the auditor’s attention throughout the audit may vary.
A38
Remaining alert for circumstances that may be indicative of fraud or suspected fraud throughout the audit is important, including when performing audit procedures near the end of the audit when time pressures to complete the audit engagement may exist. For example, audit evidence may be obtained near the end of the audit that may call into question the reliability of other audit evidence obtained or cast doubt on the integrity of management or those charged with governance. Appendix 3 contains examples of circumstances that may be indicative of fraud or suspected fraud.
A40
Examples:
A lack of cooperation and undue time pressures imposed by management negatively affected the engagement team’s ability to resolve a complex and contentious issue. These circumstances were, based on the engagement partner’s professional judgement, indicative of possible efforts by management to conceal fraud. The engagement partner involved more experienced members of the engagement team to deal with members of management who were difficult to interact with and communicated with those charged with governance as to the nature of the challenging circumstances, including the possible effect on the audit.
Impediments imposed by management created difficulties for the engagement team in obtaining access to records, facilities, certain employees, customers, suppliers, and others. These circumstances were, based on the engagement partner’s professional judgement, indicative of possible efforts by management to conceal fraud. The engagement partner reminded the engagement team not to be satisfied with audit evidence that was less than persuasive when responding to assessed risks of material misstatement due to fraud and communicated with those charged with governance as to the nature of the challenging circumstances, including the possible effect on the audit.
A40
As explained in ASA 220, conditions inherent in some audit engagements can create pressures on the engagement team that may impede the appropriate exercise of professional scepticism when designing and performing audit procedures and evaluating audit evidence. Paragraphs A35–A37 of ASA 220 list examples of impediments to the exercise of professional scepticism at the engagement level, unconscious or conscious biases that may affect the engagement team’s professional judgements, and actions that may be taken to mitigate impediments to the exercise of professional scepticism.
A41
Circumstances may also be encountered which may create threats to compliance with relevant ethical requirements. ASA 220 discusses that relevant ethical requirements, for example the Code, may contain provisions regarding the identification and evaluation of threats and how they are to be dealt with.
A42
The auditor may also address the threat to compliance with relevant ethical requirements, such as the principle of integrity, by communicating on a timely basis with those charged with governance about the circumstances giving rise to the threat. This communication may include a discussion about any inconsistencies in audit evidence obtained for which a satisfactory explanation has not been provided by management.
Inconsistent Responses
A43
Inconsistent responses to enquiries may include inconsistencies both between the different groups of individuals specified in paragraph 21 (i.e., management, those charged with governance, individuals within the internal audit function, or others within the entity) and among individuals within the same group. For example, the auditor may identify inconsistent responses among different individuals within management.
Conditions That Cause the Auditor to Believe That a Record or Document May Not Be Authentic or That the Terms in a Document Have Been Modified
A44
ASA 500 requires the auditor to consider the reliability of information intended to be used as audit evidence when designing and performing audit procedures. The reliability of information intended to be used as audit evidence deals with the degree to which the auditor may depend on such information. Authenticity is an attribute of the reliability of information that the auditor may consider. In doing so, the auditor may consider whether the source actually generated or provided the information, and was authorised to do so, and the information has not been inappropriately altered.
A46
Examples:
Conditions that, if identified, may cause the auditor to believe that a record or document is not authentic or that terms in a document have been modified but not disclosed to the auditor include:
Unexplained alterations to documents received from external sources.
Serial numbers used out of sequence or duplicated.
Addresses and logos not as expected.
Document style different to others of the same type from the same source (e.g., changes in fonts and formatting).
Information that would be expected to be included is absent.
Invoice references or descriptors that differ from other invoices received from the entity.
Unusual terms of trade, such as unusual prices, interest rates, guarantees and repayment terms (e.g., purchase costs that appear unreasonable for the goods or services being charged for).
Information that appears implausible or inconsistent with the auditor’s understanding and knowledge.
A change from authorised signatory.
Electronic documents with a last edited date that is after the date they were represented as finalised.
A46
Audit procedures performed in accordance with ASA 500, this or other ASAs, or information from other sources, may bring to the auditor’s attention conditions that cause the auditor to believe that a record or document may not be authentic or that terms in a document have been modified but not disclosed to the auditor. The auditor is not, however, required to perform procedures that are specifically designed to identify conditions that indicate that a record or document may not be authentic or that terms in a document have been modified. Paragraph 22 applies if the auditor identifies such conditions during the course of the audit.
A47
When conditions are identified that cause the auditor to believe that a record or document may not be authentic or that terms in a document have been modified but not disclosed to the auditor, possible additional audit procedures to investigate further may include:
Enquiries of management or others within the entity.
Confirming directly with the third party.
Using the work of an expert to evaluate the document’s authenticity.
Using automated tools and techniques, such as document authenticity or integrity technology, to evaluate the authenticity of the record or document.
A48
When the results of the additional audit procedures indicate that a record or document is not authentic or that the terms in a document have been modified, the auditor may determine that the circumstances are indicative of fraud or suspected fraud and, accordingly, performs audit procedures in accordance with paragraphs 55–58.
Engagement Resources (Ref: Para. 23)
A49
ASA 220 explains that the engagement partner’s determination of whether additional engagement level resources are required to be assigned to the engagement team is a matter of professional judgement and is influenced by the nature and circumstances of the audit engagement, taking into account any changes that may have arisen during the engagement.
A51
Examples:
The entity is investigating fraud or suspected fraud that may have a material effect on the financial report (e.g., when it involves senior management). An individual with forensic skills may assist in planning and performing audit procedures as it relates to the specific audit area where the fraud or suspected fraud was identified.
The entity is undergoing an investigation by an authority outside the entity for fraud or suspected fraud, or for instances of non-compliance or suspected non-compliance with laws and regulations (e.g., materially misstated tax provision related to tax evasion and materially misstated revenues due to such revenues being generated from illegal activities facilitated through money laundering). Tax and anti-money laundering experts may assist with identifying those fraudulent aspects of the non-compliance or suspected non-compliance that may have a financial report impact.
The complexity of the entity’s organisational structure and related party relationships, including the creation or existence of special purpose entities, may present an opportunity for management to misrepresent the financial position or financial performance of the entity. For example, an expert in taxation law may assist in understanding the business purpose and activities or business units within complex organisations, including how its structure for tax purposes may be different from its operating structure.
The complexity of the industry or regulatory environment in which the entity operates may present an opportunity or pressure for management to engage in fraudulent financial reporting. For example, an individual specialising in fraud schemes in specific emerging markets may assist in identifying fraud risk factors or where the financial report may be susceptible to risks of material misstatement due to fraud.
The use of complex financial instruments or other complex financing arrangements may present an opportunity to inadequately disclose the risks and nature of complex structured products. For example, a valuation expert may assist in understanding the product’s structure, purpose, underlying assets, and market conditions, which may highlight fraud risk factors such as discrepancies between market conditions and the valuation of the structured product.
A51
The nature, timing, and extent of the involvement of individuals with specialised skills or knowledge, such as forensic and other experts when determined to be necessary or the involvement of more experienced individuals, may vary based on the nature and circumstances of the audit engagement.
A53
Examples:
Forensic skills may include specialised skills or knowledge in:
Identifying and evaluating fraud risk factors.
Identifying and assessing the risks of material misstatement due to fraud.
Evaluating the effectiveness of controls implemented by management to prevent or detect fraud.
Assessing the authenticity of information intended to be used as audit evidence.
Gathering, analysing, and evaluating information or data using automated tools and techniques to identify links, patterns, or trends that may be indicative of fraud or suspected fraud.
Applying knowledge in fraud schemes, and techniques for interviews, information gathering and data analytics, in the detection of fraud.
Interviewing techniques used in discussing sensitive matters with management and those charged with governance.
Analysing financial and non-financial information by using automated tools and techniques to look for inconsistencies, unusual patterns, or anomalies that may indicate intentional management bias or that may be the result of management override of controls.
A53
Forensic skills, in the context of an audit of a financial report, may combine accounting, auditing and investigative skills. Such skills may be applied in an investigation and evaluation of an entity’s accounting records to obtain possible evidence of fraudulent financial reporting or misappropriation of assets, or in performing audit procedures. The use of forensic skills may also assist the auditor in evaluating whether there is management override of controls or intentional management bias in financial reporting.
A54
In determining whether the engagement team has the appropriate competence and capabilities, the engagement partner may consider matters such as expertise in IT systems or IT applications used by the entity or automated tools or techniques that are to be used by the engagement team in planning and performing the audit (e.g., when testing a high volume of journal entries and other adjustments when responding to the risks related to management override of controls).
A55
In determining whether the members of the engagement team collectively have the appropriate competence and capabilities to respond to identified risks of material misstatement due to fraud, the engagement partner may consider, for example:
Assigning additional individuals with specialised skills or knowledge, such as forensic and other experts;
Changing the composition of the engagement team to include more experienced individuals; or
Assigning more experienced members of the engagement team to conduct certain audit procedures for those specific audit areas that require significant auditor attention, including to make enquiries of management and, when appropriate in the circumstances, those charged with governance related to those specific audit areas.
Engagement Performance (Ref: Para. 24 and 29)
A57
Examples:
Sudden changes in business activity or performance (e.g., decrease in operating cashflows of an entity arising from economic conditions resulting in increased pressure internally by management to meet publicly disclosed earnings targets).
Unexpected changes in the senior management of the entity (e.g., the chief financial officer resigns, with no explanation given for the sudden departure, providing an opportunity for other employees in the treasury department to commit fraud given the lack of senior management oversight).
Engagement Performance (Ref: Para. 24 and 29)
A57
Depending on the nature and circumstances of the audit engagement, the engagement partner’s approach to direction, supervision and review may include increasing the extent and frequency of the engagement team discussions. It may be beneficial to hold additional engagement team discussions based on the occurrence of events or conditions that have impacted the entity, which may identify new, or provide additional information about existing, fraud risk factors (see Appendix 1 for examples of fraud risk factors).
Ongoing Nature of Communications with Management and Those Charged with Governance (Ref: Para. 25)
A58
Robust two-way communication between management or those charged with governance and the auditor assists in identifying and assessing the risks of material misstatement due to fraud.
A59
The extent of the auditor’s communications with management and those charged with governance depends on the fraud-related facts and circumstances of the entity, as well as the progress and outcome of the fraud-related audit procedures performed in the audit engagement.
A61
Examples:
Making the required enquiries of management and those charged with governance about matters referred to in paragraphs 32(b)–32(c) and 33(b) as early as possible in the audit engagement, for example, as part of the auditor’s communications regarding planning matters.
When ASA 701 applies, the auditor may communicate preliminary views about key audit matters related to fraud when discussing the planned scope and timing of the audit.
Having specific discussions with management and those charged with governance as relevant audit evidence is obtained relating to the auditor’s evaluation of each of the components of the entity’s system of internal control and assessment of the risks of material misstatement due to fraud. These discussions may form part of the auditor’s communications on significant findings from the audit.
Communicating, on a timely basis in accordance with ASA 265, significant deficiencies in internal control (including those that are relevant to the prevention or detection of fraud) with the appropriate level(s) of management and those charged with governance may allow them to take necessary and timely remedial actions.
A61
The appropriate timing of the communications may vary depending on the significance and nature of the fraud-related matters and the expected action(s) to be taken by management or those charged with governance.
Assigning Appropriate Member(s) within the Engagement Team with the Responsibility to Communicate with Management and Those Charged with Governance
A62
ASA 220 deals with the engagement partner’s overall responsibility with respect to engagement resources and engagement performance. Due to the nature and sensitivity of fraud, particularly those involving senior management, assigning tasks or actions to appropriately skilled or suitably experienced members of the engagement team and providing appropriate levels of direction, supervision, and review of their work is also important for the required communications in accordance with this ASA. This includes involving appropriately skilled or suitably experienced members of the engagement team when communicating matters related to fraud with management and those charged with governance.
A63
ASA 220 deals with the engagement partner’s responsibility to make members of the engagement team aware of the relevant ethical requirements. For example, the Code requires compliance with the principle of integrity, which involves standing one’s ground when confronted by dilemmas and difficult situations; or challenging others as and when circumstances warrant in a manner appropriate to the circumstances. It is important, especially for those members of the engagement team who will be engaging with management and those charged with governance about matters related to fraud, to consider the content of the communications and the manner in which such communications are to be conducted.
Risk Assessment Procedures and Related Activities (Ref: Para. 26)
A64
As explained in ASA 315, obtaining an understanding of the entity and its environment, the applicable financial reporting framework and the entity’s system of internal control is a dynamic and iterative process of gathering, updating and analysing information and continues throughout the audit. Therefore, the auditor’s expectations with respect to risks of material misstatements due to fraud may change as new information is obtained.
Information from Other Sources (Ref: Para. 27)
A65
Information obtained from other sources in accordance with paragraphs 15–16 of ASA 315 may be relevant to the identification of fraud risk factors by providing information and insights about:
The entity and the industry in which the entity operates and its related business risks, which may create pressures on the organisation to meet targeted financial results.
Management’s commitment to integrity and ethical values.
Management’s commitment to remedy known significant deficiencies in internal control on a timely basis.
Complexity in the application of the applicable financial reporting framework due to the nature and circumstances of the entity that may create opportunities for management to perpetrate and conceal fraudulent financial activity.
A66
In conducting an initial audit engagement in accordance with ASA 510, in some circumstances, subject to law, regulation or relevant ethical requirements, the proposed successor auditor may request the predecessor auditor to provide information regarding identified or suspected fraud. Such information may give an indication of the presence of fraud risk factors or may give an indication of fraud or suspected fraud.
Retrospective Review of the Outcome of Previous Accounting Estimates (Ref: Para. 28)
A67
The purpose of performing a retrospective review of management’s judgements and assumptions related to accounting estimates reflected in the financial report of a previous period is to evaluate whether there is an indication of a possible bias on the part of management. It is not intended to call into question the auditor’s judgements about previous period accounting estimates that were appropriate based on information available at the time they were made.
Engagement Team Discussion (Ref: Para. 29)
A68
As explained in ASA 220, the engagement partner is responsible for creating an environment that emphasises the importance of open and robust communication within the engagement team. The engagement team discussion enables the engagement team members to share insights in a timely manner based on their skills, knowledge and experience about how and where the financial report may be susceptible to material misstatement due to fraud.
A69
Individuals who have specialised skills or knowledge, such as forensic and other experts, may be invited to attend the engagement team discussion to provide deeper insights about the susceptibility of the entity’s financial report to material misstatement due to fraud. The involvement and contributions of individuals with specialised skills or knowledge may elevate the quality of the discussion taking place.
A70
The exchange of ideas may serve to inform the auditor’s initial perspective about the tone at the top. The conversation may include a discussion about the actions and behaviours of management and those charged with governance, including whether there are clear and consistent actions and communications about integrity and ethical behaviour at all levels within the entity.
A71
The following approaches may be useful to facilitate the exchange of ideas:
‘What-if’ scenarios – these may be helpful when discussing whether certain events or conditions create an environment at the entity where one or more individuals among management, those charged with governance, or employees have the incentive or pressure to commit fraud, a perceived opportunity to do so and some rationalisation of the act, and if so, how the fraud may occur.
Automated tools and techniques – these may be used to support the discussion about the susceptibility of the entity’s financial report to material misstatement due to fraud. For example, automated tools and techniques may be used to support the identification of fraud risk factors, including techniques that further the understanding of incentives and pressures, such as industry or sector financial ratio benchmarking. Unusual relationships within the entity’s current period data (e.g., financial and operating data) may indicate adverse ratios or trends compared to competitors or the entity’s past performance.
A73
Examples:
Based on the auditor’s understanding of the entity’s information processing activities, the auditor identified a fraud risk factor (i.e., opportunity to commit fraud) resulting from management’s lack of oversight over significant business processes outsourced to a third-party service provider.
Based on the auditor’s understanding of the entity’s physical access controls, the auditor identified a fraud risk factor (i.e., opportunity to commit fraud) resulting from the entity’s lack of sufficient security at locations with a material amount of small, lightweight, high-value assets.
Based on the auditor’s understanding of revenue contracts, the auditor became aware that the entity is using consignment agreements, where third parties sell the entity’s inventory on its behalf, and the entity earns revenue from these sales. The auditor identified a fraud risk factor (i.e., incentive to commit fraud) resulting from the third party’s incentive to underreport to the entity consigned sales in order for the third party to meet its own sales targets.
A73
The exchange of ideas may include, among other matters, whether:
The interactions, as observed by the engagement team, among management (e.g., between the chief executive officer and the chief financial officer) or between management and those charged with governance may indicate a lack of cooperation or mutual respect among the parties. This circumstance in turn may be indicative of an environment that is conducive to the existence of fraud.
Any unusual or unexplained changes in behaviour or lifestyle of management or employees that have come to the attention of the engagement team may indicate the possibility of fraudulent activity.
Known information (e.g., obtained through reading trade journals, or accessing reports issued by regulatory bodies), about frauds impacting other entities that resulted in the misstatement of the financial report of those entities, such as entities in the same industry or geographical region, may be indicative of risks of material misstatement due to fraud for the entity being audited.
Disclosures, or lack thereof, may be used by management to obscure a proper understanding of the entity’s financial report (e.g., by including too much immaterial information, by using unclear or ambiguous language, or by a lack of disclosures such as those disclosures relating to off-balance sheet financing arrangements or leasing arrangements).
Events or conditions exist that may cast significant doubt on the entity’s ability to continue as a going concern (e.g., a drug patent of an entity in the pharmaceutical industry expired leading to a decline in revenue). In such circumstances, there may be incentives or pressures for management to commit fraud in order to conceal a material uncertainty about the entity’s ability to continue as a going concern.
The entity has significant related party relationships and transactions (e.g., the entity has a complex organisational structure that includes several special-purpose entities controlled by management). These circumstances may provide the opportunity for management to perpetrate fraud; for example, by inflating earnings, or concealing debt.
The entity has other third-party relationships that give rise to a fraud risk factor, or a risk of third-party fraud.
A75
Examples:
Creating fictious employee records or vendors in an attempt to transfer cash to personal accounts.
Modifying the timing of legitimate transactions to manipulate the financial records.
A75
The engagement team may consider other ways in which management may override controls beyond the use of journal entries and other adjustments, significant estimates or transactions outside the normal course of business.
A76
The engagement partner and other key engagement team members participating in the engagement team discussion may also, as applicable, use this as an opportunity to:
Emphasise the importance of maintaining a questioning mind throughout the audit regarding the potential for material misstatement due to fraud.
Remind engagement team members of their role in serving the public interest by performing quality audit engagements and the importance of engagement team members remaining objective in order to better facilitate the critical assessment of audit evidence obtained from persons within or outside the financial reporting or accounting functions, or outside the entity.
Consider the audit procedures that may be selected to respond appropriately to the susceptibility of the entity’s financial report to material misstatement due to fraud, including whether certain types of audit procedures may be more effective than others and how to incorporate an element of unpredictability into the nature, timing and extent of audit procedures to be performed. Appendix 2 contains examples of procedures that incorporate an element of unpredictability.
Analytical Procedures Performed and Unusual or Unexpected Relationships Identified (Ref: Para. 30)
A78
Example:
Array
Analytical Procedures Performed and Unusual or Unexpected Relationships Identified (Ref: Para. 30)
A78
The auditor may identify fluctuations or relationships when performing analytical procedures in accordance with ASA 315 that are inconsistent with other relevant information or that differ from expected values significantly.
The Entity’s Organisational Structure and Ownership, Governance, Objectives and Strategy, and Geographic Dispersion
A80
Example:
Where there are complex intercompany transactions, this increases the opportunity to manipulate balances or create fictitious transactions.
The Entity’s Organisational Structure and Ownership, Governance, Objectives and Strategy, and Geographic Dispersion
A80
Understanding the entity’s organisational structure and ownership assists the auditor in identifying fraud risk factors. An overly complex organisational structure involving unusual legal entities or unnecessarily complex or unusual organisational structures compared to other entities in the same industry may indicate that a fraud risk factor is present.
A82
Example:
If the entity is undergoing significant digital transformation activities, poor governance arrangements over newly implemented technologies impacting the entity’s information system relevant to the preparation of the financial report may increase the opportunity for fraud.
A82
Understanding the nature of the entity’s governance arrangements assists the auditor in identifying fraud risk factors. For example, poor governance or accountability arrangements may weaken oversight and increase the opportunity for fraud (see also paragraphs A71–A82). However, some entities may have assigned the responsibility for overseeing the processes for identifying and responding to fraud in the entity to a senior member of management or to someone with designated responsibility.
A84
Example:
When the entity has a very aggressive growth strategy, this may create pressures on personnel within the entity to commit fraud to meet the goals set.
A84
Understanding the entity’s objectives and strategy assists the auditor in identifying fraud risk factors. Objectives and strategy impact expectations, internally and externally, and may create pressures on the entity to achieve financial performance targets.
A86
Examples:
Weak legal and regulatory frameworks that create a permissive environment for fraudulent financial reporting without significant consequences.
Offshore financial centres that have less restrictive regulations and tax incentives that may facilitate fraud through money laundering.
Cultural norms in which bribery is an accepted practice of doing business, which could lead to bribery being used to facilitate or conceal fraud.
A86
Understanding the entity’s geographic dispersion assists the auditor in identifying fraud risk factors. The entity may have operations in locations that may be susceptible to fraud, or other illegal or unethical acts that may be carried out to facilitate or conceal fraud. The auditor may obtain information about these locations from a variety of internal and external sources, including searches of relevant databases.
Industry and Regulatory Environment
A87
Understanding the industry and the regulatory environment in which the entity operates assists the auditor in identifying fraud risk factors. The entity may operate in an industry that may be susceptible to fraud, or other illegal or unethical acts that may be carried out to facilitate or conceal fraud. The auditor may obtain an understanding about whether the entity operates in:
An industry where there are greater opportunities to commit fraud (e.g., in the construction industry the revenue recognition policies may be complex and subject to significant judgement which may create an opportunity to commit fraud).
An industry that is under pressure (e.g., a high degree of competition or market saturation, accompanied by declining margins in that sector). Such characteristics may create an incentive to commit fraud as it may be harder to achieve the financial performance targets.
An industry that is susceptible to acts of money laundering (e.g., the banking, or gaming and gambling industries may be particularly vulnerable to money laundering, which could facilitate fraud).
A regulatory environment that may create incentives or pressures to commit fraud (e.g., government aid programs may include thresholds to be met to obtain the aid).
Performance Measures Used, Whether Internal or External
A89
Example:
Automated tools and techniques, such as analysis of disaggregated data, for example by business segment or product line, may be used by the auditor to identify inconsistencies or anomalies in the data used in performance measures.
Performance Measures Used, Whether Internal or External
A89
Performance measures, whether internal or external, may create pressures on the entity. These pressures, in turn, may motivate management or employees to take action to inappropriately improve the business performance or to misstate the financial report. Internal performance measures may include employee performance measures and incentive compensation policies. External performance measures may include expectations from shareholders, analysts, or other users.
A90
The auditor may consider listening to the entity’s earnings calls with analysts or reading analysts’ research reports. This may provide the auditor with information about whether analysts have aggressive or unrealistic expectations about an entity’s financial performance. Auditors may also learn about management’s attitudes regarding those expectations based on how management interacts with analysts. Aggressive expectations by analysts that are met by commitments by management to meet those expectations may be indicative of pressures and rationalisations for management to manipulate key performance metrics.
A91
Other matters that the auditor may consider include:
Management’s compensation packages. When a significant portion of management’s compensation packages are contingent on achieving financial targets, management may have an incentive to manipulate financial results.
Negative media attention, short-selling reports, or negative analyst reports. When management is under pressure or intense scrutiny to respond to these matters, management may have an incentive to manipulate financial results.
Considerations specific to public sector entities
A92
In the case of a public sector entity, legislators and regulators are often the primary users of its financial report and may therefore have expectations in relation to external performance measures. The auditor may also consider the nature and extent of external scrutiny from other parties or citizens as management of the public sector entity may have an incentive to manipulate financial results when they are under pressure or intense scrutiny.
Understanding the Applicable Financial Reporting Framework and the Entity’s Accounting Policies (Ref: Para. 31)
A94
Examples:
Management may consistently trend toward one end of a range of possible outcomes that provide a more favourable financial reporting outcome for management.
Management may use a model that applies a method that is not established or commonly used in a particular industry or environment.
Understanding the Applicable Financial Reporting Framework and the Entity’s Accounting Policies (Ref: Para. 31)
A94
Matters related to the applicable financial reporting framework that the auditor may consider when obtaining an understanding of where there may be an increased susceptibility to misstatement due to management bias or other fraud risk factors, include:
Areas in the applicable financial reporting framework that require:
A measurement basis that results in the need for a complex method relating to an accounting estimate.
Management to make significant judgements, such as accounting estimates with high estimation uncertainty or where an accounting treatment has not yet been established for new and emerging financial products (e.g., types of digital assets).
Expertise in a field other than accounting, such as actuarial calculations, valuations, or engineering data. Particularly where management can influence, and direct work performed, and conclusions reached by management’s experts.
Changes in the applicable financial reporting framework. For example, management may intentionally misapply new accounting requirements relating to amounts, classification, manner of presentation, or disclosures.
The selection of and application of accounting policies by management. For example, management’s choice of accounting policy is not consistent with similar entities in the same industry.
The amount of an accounting estimate selected by management for recognition or disclosure in the financial report.
Entity’s culture and management’s commitment to integrity and ethical values (Ref: Para. 32(a)(i))
A95
Understanding aspects of the entity’s control environment that address the entity’s culture and understanding management’s commitment to integrity and ethical values assists the auditor in determining management’s attitude and tone at the top with regards to the prevention and detection of fraud.
A96
In considering the extent to which management demonstrates a commitment to ethical behaviour, the auditor may obtain an understanding through enquiries of management and employees, and through considering information from external sources, about:
Management’s commitment to integrity and ethical values through their actions. This is important as employees may be more likely to behave ethically when management is committed to integrity and ethical behaviours.
The entity’s communications with respect to integrity and ethical values. For example, the entity may have a mission statement, a code of ethics, or a fraud policy that sets out the expectations of entity personnel in respect to their commitment to integrity and ethical values regarding managing fraud risk. In larger or more complex entities, management may also have set up a process that requires employees to annually confirm that they have complied with the entity’s code of ethics.
Whether the entity has developed fraud awareness training. For example, the entity may require employees to undertake ethics and code of conduct training as part of an ongoing or induction program. In a larger or more complex entity, specific training may be required for those with a role in the prevention and detection of fraud (e.g., the internal audit function).
Management’s response to fraudulent activity. For example, where minor unethical practices are overlooked (e.g., petty theft, expenses frauds), this may indicate that more significant frauds committed by key employees may be treated in a similar lenient fashion.
The entity’s whistleblower program (or other program to report fraud) (Ref: Para. 32(a)(ii))
A97
Often frauds are discovered through tips or complaints submitted through an entity’s whistleblower program. Whistleblower programs, which some entities may refer to by other names including, for example fraud reporting hotline, are designed to gather, among other things, information from employees, customers, and other stakeholders about allegations of fraud impacting the entity. A whistleblower program is often an essential component of an entity’s fraud risk management.
A98
The design of a whistleblower program will vary depending on the nature and complexity of the entity, including the entity’s exposure to fraud risks. For example, more formalised whistleblower programs may include a dedicated email, website or telephone reporting mechanism, formal training for all employees, periodic reporting to management and those charged with governance for matters reported through the program, or management of the program by a third party. Alternatively, whistleblower programs may consist of less formal processes, which may include verbal communication of the program or communication via the entity’s website where tips or complaints can be received, along with monitoring performed by the entity’s human resource personnel or by an independent party, such as external counsel.
A99
When obtaining an understanding of the entity’s whistleblower program, the auditor may:
Obtain an understanding of how the entity receives tips or complaints, the objectivity and competence of the individuals involved in administering the program, the appropriateness of the entity’s processes for addressing the matters raised, including its investigation and remediation processes and protections afforded to whistleblowers. In a larger or more complex entity, the lack of a whistleblower program, or an ineffective one, may be indicative of deficiencies in the entity’s control environment.
Inspect the whistleblower program files for any tips or complaints that may allege fraud that are not under investigation by the entity, or for information that may raise questions about management’s commitment to creating and maintaining a culture of honesty and ethical behaviour.
Perform additional procedures related to allegations of fraud that are under investigation by the entity in accordance with the requirements in paragraphs 55-58.
Oversight exercised by those charged with governance (Ref: Para. 32(a)(iii))
A100
In many jurisdictions, corporate governance practices are well developed and those charged with governance play an active role in oversight of the entity’s assessment of risks, including risks of fraud and the controls that address such risks. Since the responsibilities of those charged with governance and management may vary by entity and by jurisdiction, it is important that the auditor understands their respective responsibilities to enable the auditor to obtain an understanding of the oversight exercised by the appropriate individuals with respect to the prevention and detection of fraud.
A101
An understanding of the oversight exercised by those charged with governance may provide insights regarding the susceptibility of the entity to management fraud, the adequacy of controls that prevent or detect fraud, and the competency and integrity of management. The auditor may obtain this understanding in several ways, such as by attending meetings where such discussions take place, reading the minutes from such meetings, or making enquiries of those charged with governance.
A102
The effectiveness of oversight by those charged with governance is influenced by their objectivity and familiarity with the processes and controls management has put in place to prevent or detect fraud. For example, the oversight by those charged with governance of the effectiveness of controls to prevent or detect fraud is an important aspect of their oversight role and the objectivity of such evaluation is influenced by their independence from management.
Scalability (Ref: Para. 32(a)(iii))
A103
In some cases, all of those charged with governance are involved in managing the entity. This may be the case in a smaller or less complex entity where a single owner manages the entity and no one else has a governance role. In these cases, there is ordinarily no action on the part of the auditor because there is no oversight separate from management.
Enquiries of those charged with governance (Ref: Para. 32(c))
A104
The auditor may also enquire of those charged with governance about how the entity assesses the risk of fraud, and the entity’s controls to prevent or detect fraud, the entity’s culture and management’s commitment to integrity and ethical values.
A105
Specific enquiries on areas that are susceptible to misstatement due to management bias or management fraud may relate to both inherent risk and control risk. Specific enquiries may include management judgement when accounting for complex accounting estimates or unusual or complex transactions, including those in controversial or emerging areas, which may be susceptible to fraudulent financial reporting.
A106
Enquiries on whether those charged with governance are aware of any control deficiencies related to the prevention and detection of fraud may inform the auditor’s evaluation of the components of the entity’s system of internal control. Such enquiries may highlight conditions within the entity’s system of internal control that provide opportunity to commit fraud or that may affect management’s attitude or ability to rationalise fraudulent actions. For example, understanding incentives or pressures on management that may result in intentional or unintentional management bias may inform the auditor’s understanding of the entity’s risk assessment process and understanding of business risks. Such information may affect the auditor’s consideration of the effect on the reasonableness of significant assumptions made by, or the expectations of, management.
The entity’s process for identifying, assessing, and addressing fraud risks (Ref: Para. 33(a))
A107
Management may place a strong emphasis on fraud prevention by implementing a fraud risk management program. The design of the fraud risk management program may be impacted by the nature and complexity of the entity and may include the following elements:
Establishing fraud risk governance policies.
Performing a fraud risk assessment.
Designing and deploying fraud preventive and detective control activities.
Conducting investigations.
Monitoring and evaluating the total fraud risk management program.
Identifying fraud risks (Ref: Para. 33(a)(i))
A108
The entity’s risk assessment process may include an assessment of the incentives, pressures, and opportunities to commit fraud, or how the entity may be susceptible to third-party fraud. An entity’s risk assessment process may also consider the potential override of controls by management as well as areas where there are control deficiencies, including a lack of segregation of duties.
A109
Where legal or regulatory requirements apply, management may consider risks relating to misappropriation of assets or fraudulent financial reporting in relation to the entity’s compliance with laws or regulations. For example, a fraud risk may include the preparation of inaccurate information for a regulatory filing in order to improve the appearance of an entity’s performance and thereby avoid inspection by regulatory authorities or penalties.
Considerations specific to public sector entities
A110
In the public sector, management may need to consider risks related to political pressures to achieve specific outcomes, and pressures to meet or stay within the approved budget, including expenditures subject to statutory limits.
Assessing the significance of the identified fraud risks and addressing the assessed fraud risks (Ref: Para. 33(a)(ii)–(iii))
A111
There are several approaches management may use to assess fraud risks, and the approach may vary depending on the nature and circumstances of the entity. The entity may assess fraud risks using different forms, such as a complex matrix of risk ratings or a simple narrative.
A112
When determining the likelihood of fraud, management may consider both probability and frequency (i.e., the number of fraud incidents that can be expected). Other factors that management may consider in determining the likelihood may include the volume of transactions or the quantitative benefit to the perpetrator.
A114
Example:
During the entity’s risk assessment process relating to third-party fraud, management identified an unusual level of disbursements to recently added vendors to the entity’s approved-vendor database. Upon investigating the matter, management determined that purchasing and procurement personnel had colluded with the vendors when it added those vendors to the database. Management designed and implemented controls to prevent and detect the reoccurrence of vendor-related fraud.
A114
Management may address the likelihood of a fraud risk by taking action within the other components of the entity’s system of internal control or by making changes to certain aspects of the entity or its environment. To address fraud risks, an entity may choose to cease doing business in certain locations, reallocate authority among key personnel, or make changes to aspects of the entity’s business model.
A115
If the auditor identifies risks of material misstatement due to fraud that management failed to identify, the auditor is required to determine whether any such risks are of a kind that the auditor expects would have been identified by the entity’s risk assessment process and, if so, obtain an understanding of why the entity’s risk assessment process failed to identify such risks of material misstatement.
Scalability (Ref: Para. 33(a))
A116
In smaller and less complex entities, and in particular owner-managed entities, the way the entity’s risk assessment process is designed, implemented, and maintained may vary with the entity’s size and complexity. When there are no formalised processes or documented policies or procedures, the auditor is still required to obtain an understanding of how management, or where appropriate, those charged with governance identify fraud risks related to the misappropriation of assets and fraudulent financial reporting, assesses the significance of the identified fraud risks and addresses the assessed risks.
Enquiries of management and others within the entity (Ref: Para. 33(b))
A117
Management accepts responsibility for the entity’s system of internal control and for the preparation of the entity’s financial report. Accordingly, it is appropriate for the auditor to make enquiries of management regarding management’s own process for identifying and responding to the entity’s fraud risks. The nature, extent and frequency of management’s risk assessment process may vary from entity to entity. In some entities, management’s process may occur on an annual basis or as part of ongoing monitoring. In other entities, management’s process may be less structured and less frequent. The nature, extent and frequency of management’s risk assessment process is relevant to the auditor’s understanding of the entity’s control environment. For example, the fact that management does not have a risk assessment process or when the entity’s risk assessment process does not address the identified fraud risks may be indicative of the lack of importance that management places on internal control.
A119
Examples:
Others within the entity to whom the auditor may direct enquiries about the existence or suspicion of fraud include:
Operating personnel not directly involved in the financial reporting process.
Employees with different levels of authority.
Employees involved in initiating, processing, or recording complex or unusual transactions and those who supervise or monitor such employees.
In-house legal counsel.
Chief ethics officer, chief compliance officer or equivalent person.
The person or persons charged with dealing with allegations of fraud
A119
Enquiries of management may provide useful information concerning the risks of material misstatements resulting from employee fraud. However, such enquiries are unlikely to provide useful information regarding the risks of material misstatement resulting from management fraud. Enquiries of others within the entity may provide additional insight into fraud prevention controls, tone at the top, and culture of the organisation. The responses from these enquiries may also serve to corroborate responses received from management or provide information regarding the possibility of management override of controls.
A120
Management is often in the best position to perpetrate fraud. Accordingly, when evaluating management’s responses to enquiries with an attitude of professional scepticism, the auditor may judge it necessary to corroborate responses to enquiries with information from other sources.
A121
Enquiries of management and others within the entity may be most effective when they involve a discussion and when conducted by senior members of the engagement team. This allows for a two- way dialogue with the interviewees and provides the opportunity for the auditor to ask probing and clarifying questions.
Ongoing and separate evaluations for monitoring the effectiveness of controls to prevent or detect fraud (Ref: Para. 34(a))
A122
Matters that may be relevant for the auditor to consider when understanding those aspects of the entity’s process that addresses the ongoing and separate evaluations for monitoring the effectiveness of controls to prevent or detect fraud, and the identification and remediation of related control deficiencies may include:
Whether management has identified particular operating locations, or business segments for which the risk of fraud may be more likely to exist and whether management has introduced different approaches to monitor these operating locations or business segments.
How the entity monitors controls that address fraud risks in each component of the entity’s system of internal control, including the operating effectiveness of anti-fraud controls, and the remediation of control deficiencies as necessary.
Enquiries of internal audit (Ref: Para. 34(b))
A123
The internal audit function of an entity may perform assurance and advisory activities designed to evaluate and improve the effectiveness of the entity’s governance, risk management and internal control processes. In that capacity, the internal audit function may identify frauds or be involved throughout a fraud investigation process. Enquiries of appropriate individuals within the internal audit function may therefore provide the auditor with useful information about instances of fraud, suspected fraud, or allegations of fraud, and the risk of fraud.
A125
Examples:
In applying ASA 315 and ASA 610 in the context of fraud, the auditor may, for example, enquire about:
How the entity’s risk assessment process addresses the risk of fraud.
The entity’s processes and controls to prevent or detect fraud.
The entity’s culture and management’s commitment to integrity and ethical values.
Whether the internal audit function is aware of any instances of management override of controls.
The procedures performed, if any, by the internal audit function during the year related to fraud and whether management and those charged with governance have satisfactorily responded to any findings resulting from those procedures.
The procedures performed, if any, by the internal audit function in investigating frauds and suspected violations of the entity’s code of ethics and values, and whether management and those charged with governance have satisfactorily responded to any findings resulting from those procedures.
The fraud-related reports, if any, or communications prepared by the internal audit function and whether management and those charged with governance have satisfactorily responded to any findings resulting from those reports.
Control deficiencies identified by the internal audit function that are relevant to the prevention and detection of fraud and whether management and those charged with governance have satisfactorily responded to any findings resulting from those deficiencies.
A125
ASA 315 and ASA 610 establish requirements and provide guidance relevant to audits of those entities that have an internal audit function.
The Information System and Communication (Ref: Para. 35 and 49)
A126
Obtaining an understanding of the entity’s information system and communication relevant to the preparation of the financial report includes the manner in which an entity incorporates information from transaction processing into the general ledger. This ordinarily involves the use of journal entries, whether standard or non-standard, or automated or manual. This understanding enables the auditor to identify the population of journal entries and other adjustments that is required to be tested in accordance with paragraph 49(b). Obtaining an understanding of the population may provide the auditor with insights about journal entries and other adjustments that may be susceptible to unauthorised or inappropriate intervention or manipulation. This may assist the auditor in designing and performing audit procedures over journal entries and other adjustments in accordance with paragraphs 49(c) and 49(d).
A127
Appendix 4 includes additional considerations when selecting journal entries and other adjustments for testing, including matters that the required understanding provides the auditor knowledge about.
A128
When performing risk assessment procedures, the auditor may consider changes in the entity’s IT environment because of the introduction of new IT applications or enhancements to the IT infrastructure, which may impact the susceptibility of the entity to fraud or create vulnerabilities in the IT environment (e.g., changes to the databases involved in processing or storing transactions). There may also be an increased susceptibility to misstatement due to management bias or other fraud risk factors when there are complex IT applications used to initiate or process transactions or information, such as the use of artificial intelligence or machine learning algorithms to calculate and initiate accounting entries. In such circumstances, the auditor may assign individuals with specialised skills and knowledge, such as forensic and IT experts, or more experienced individuals to the engagement.
Control Activities (Ref: Para. 33 and 36)
A129
Management may make judgements on the nature and extent of the controls it chooses to implement and the nature and extent of the risks it chooses to accept given the nature and circumstances of the entity. In determining which controls to implement to prevent or detect fraud, management considers the risks that the financial report may be materially misstated due to fraud.
A131
Examples:
Preventive controls
Clearly defined and documented decision makers using delegations, authorisations, and other instructions.
Access controls, including those that address physical security of assets against unauthorised access, acquisition, use or disposal and those that prevent unauthorised access to the entity’s IT environment and information, such as authentication technology.
Controls over the process to design, program, test and migrate changes to the IT system.
Entry level checks, probationary periods, suitability assessments or security vetting in order to assess the integrity of new employees, contractors or third parties.
Sensitive or confidential information cannot leave the entity's IT environment without authority or detection.
Detective controls
Exception reports to identify activities that are unusual or not in the ordinary course of business for further investigation.
Mechanisms for employees of the entity and third parties to make anonymous or confidential communications to appropriate persons within the entity about identified or suspected fraud.
Fraud detection software programs incorporated into the IT infrastructure that automatically analyse transactions data or enable data monitoring and analysis to detect what is different from what is standard, normal, or expected and may therefore indicate fraud.
A131
Controls designed to prevent or detect fraud are generally classified as either preventive (designed to prevent a fraudulent event or transaction from occurring) or detective (designed to discover a fraudulent event or transaction after the fraud has occurred). Addressing fraud risks may involve a combination of manual and automated fraud prevention and detection controls that enable the entity to monitor for indicators of fraud within the scope of its risk tolerance.
A132
ASA 315 requires the auditor to obtain an understanding of controls over journal entries as well as to evaluate their design and determine whether they have been implemented as part of understanding the entity’s system of internal control. This understanding focuses on the controls over journal entries that address risks of material misstatement at the assertion level, whether due to fraud or error. Paragraphs 48–49 of this ASA require the auditor to design and perform audit procedures to test the appropriateness of journal entries and are specifically focused on the risks of material misstatement due to fraud (see Appendix 4 for additional considerations when testing journal entries).
A133
Information from understanding controls over journal entries, designed to prevent or detect fraud, or the absence of such controls, may also be useful in identifying fraud risk factors that may affect the auditor’s assessment of the risks of material misstatement due to fraud.
A135
Examples:
Controls that segregate access to make changes to a production (i.e., end user) environment.
Access controls to manage:
Privileged access – such as controls over administrative or powerful users’ access.
Provisioning – such as controls to authorise modifications to existing users’ access privileges, including non-personal or generic accounts that are not tied to specific individuals within the entity
Review of system logs that track access to the information system, enabling user activity to be monitored and security violations to be reported to management.
A135
The following are examples of general IT controls that may address the risks arising from the use of IT and may also be relevant to the prevention or detection of fraud.
Scalability
A136
For some entities whose nature and circumstances are more complex, such as those operating in the insurance or banking industries, there may be more complex preventative and detective controls in place. These controls may also affect the extent to which specialised skills are needed to assist the auditor in obtaining an understanding of the entity’s risk assessment process.
Control Deficiencies Within the Entity’s System of Internal Control (Ref: Para. 37)
A137
In performing the evaluations of each of the components of the entity’s system of internal control, the auditor may determine that certain of the entity’s policies in a component are not appropriate to the nature and circumstances of the entity. Such a determination may be an indicator, which assists the auditor in identifying deficiencies in internal control that are relevant to the prevention and detection of fraud. If the auditor has identified one or more control deficiencies relevant to the prevention or detection of fraud, the auditor may consider the effect of those control deficiencies on the design of further audit procedures in accordance with ASA 330.
A138
Paragraph 60(c) of this ASA and ASA 265 establish other requirements on identified deficiencies in internal control.
Evaluation of Fraud Risk Factors (Ref: Para. 38)
A139
The significance of fraud risk factors varies widely. Some of these factors will be present in entities where the specific conditions do not present risks of material misstatement. Accordingly, the determination as to whether fraud risk factors, individually or in combination, indicate that there are risks of material misstatement due to fraud is a matter of professional judgement.
A140
The size, complexity, and ownership characteristics of the entity have a significant influence on the consideration of fraud risk factors. For example, depending on the nature and circumstances of the entity, there may be factors that generally constrain improper conduct by management, such as:
Effective oversight by those charged with governance.
An effective internal audit function.
The existence and enforcement of a written code of conduct.
The existence of an effective whistleblower program (or other program to report fraud).
A141
Furthermore, fraud risk factors considered at a business segment operating level may provide different insights when compared with those obtained when considered at an entity-wide level.
Scalability
A142
In the case of a smaller or less complex entity, some or all of these considerations may not be applicable or less relevant. For example, a smaller or less complex entity may not have a written code of conduct but, instead, may have developed a culture that emphasises the importance of integrity and ethical behaviour through oral communication and by management example. Domination of management by a single individual in a smaller or less complex entity does not generally, in and of itself, indicate a failure by management to display and communicate an appropriate attitude regarding internal control and the financial reporting process. In some entities, the need for management authorisation can compensate for otherwise deficient controls and reduce the risk of employee fraud. However, domination of management by a single individual creates a conducive environment for management override of controls.
Identifying and Assessing the Risks of Material Misstatement due to Fraud (Ref: Para. 39)
A143
In determining whether fraud risk factors, individually or in combination, indicate that there are risks of material misstatement due to fraud, the auditor may consider:
The likelihood and magnitude of fraud resulting from fraud risk factors. Fraud risk factors influence the auditor’s assessment of the likelihood and magnitude of a potential misstatement for the identified risks of misstatement due to fraud. Considering the degree to which fraud risk factors affect the susceptibility of an assertion to misstatement assists the auditor in appropriately assessing risks of material misstatement at the assertion level due to fraud.
The number of fraud risk factors that relate to the same class of transactions, account balance or disclosure. When several fraud risk factors relate to the same class of transactions, account balance or disclosure, it may indicate that there is a risk of material misstatement due to fraud at the assertion level.
A145
Examples:
Relevant assertions and the related classes of transactions, account balances or disclosures that may be susceptible to material misstatement due to fraud include:
Accuracy or valuation of revenue from contracts with customers — revenue from contracts with customers may be susceptible to inappropriate estimates of the amount of consideration to which an entity expects to be entitled in exchange for transferring promised goods or services to a customer.
Occurrence or classification of expenses — expenses may be susceptible to inclusion of fictitious or personal expenses to minimise tax or other statutory obligations.
Existence of cash balances — cash balances may be susceptible to the creation of falsified or altered external confirmations or bank statements.
Valuation of account balances involving complex accounting estimates — account balances involving complex accounting estimates such as goodwill and other intangible assets, impairment of inventories, expected credit losses, insurance contract liabilities, employee retirement benefits liabilities, environmental liabilities or environmental remediation provisions may be susceptible to high estimation uncertainty, significant subjectivity and management bias in making judgements about future events or conditions.
Classification — certain income or expenses may be susceptible to misclassification within the statement of comprehensive income, for example, to manipulate key performance measures.
Presentation of disclosures — disclosures may be susceptible to omission, or incomplete or inaccurate presentation, for example, disclosures relating to contingent liabilities, off-balance sheet arrangements, financial guarantees or debt covenant requirements.
A145
Determining whether the risks of material misstatement due to fraud exist at the financial report level, or the assertion level for classes of transactions, account balances and disclosures, may assist the auditor in determining appropriate responses to address the assessed risks of material misstatement due to fraud.
A146
Evaluating the design of controls that address significant risks, or support the operation of other controls that address significant risks, involves the auditor’s consideration of whether the control, individually or in combination with other controls, is capable of effectively preventing, or detecting and correcting material misstatements due to fraud (i.e., the control objective). The auditor determines whether identified controls have been implemented by establishing that the control exists, and that the entity is using it. The controls in the control environment, the entity’s risk assessment process and the entity’s process to monitor the system of internal control are primarily indirect controls. For example, a whistleblower program (or other program to report fraud) may be an indirect control within the control environment. Indirect controls may not be sufficiently precise to prevent, detect or correct misstatements due to fraud at the assertion level but support other controls and may therefore have an indirect effect on the likelihood that a misstatement due to fraud will be prevented or detected on a timely basis. However, some controls within these components may also be direct controls.
Considerations Specific to Public Sector Entities
A148
Example:
Fraud risk factors may be present when an individual with a significant role in a public sector entity has the sole authority to commit the public sector entity to sensitive expenditure, including travel, accommodation, or entertainment, and that sensitive expenditure provides personal benefits to the individual.
Considerations Specific to Public Sector Entities
A148
In the public sector, misappropriation of assets (including the misuse of public money for private benefit) may be a more common type of fraud compared to fraudulent financial reporting. In addition, there may be more opportunities for third parties to commit fraud through grant programs, contracts and social welfare or benefit programs.
Risks of Material Misstatement Due to Fraud Related to Management Override of Controls (Ref: Para. 40)
A149
Management is in a unique position to perpetrate fraud because of management’s ability to manipulate accounting records and prepare fraudulent financial report by overriding controls that otherwise appear to be operating effectively. Although the level of risks of management override of controls will vary from entity to entity, the risk is nevertheless present in all entities. See also paragraphs 47–52.
A151
Examples:
Based on the risk assessment procedures performed, the auditor identified an aggressive employee performance measure in management’s incentive program related to the entities’ profit and loss statement. Therefore, the auditor determined that risks of management override of controls also exist at the assertion level and identified a risk of material misstatement due to fraud related to management override of controls at the assertion level. The auditor determined that the risk relates to the completeness of expenses, as the calculation of the performance measure may be susceptible to manipulation from management via adjustments made to the expense accounts. In addition to the procedures performed as described in paragraphs 48–52, the auditor designed and performed further audit procedures to address this significant risk.
Based on the risk assessment procedures performed, the auditor identified a pressure on management to meet the financial ratios for the entity’s loan covenants to avoid insolvency. Therefore, the auditor identified a risk of material misstatement due to fraud related to management override of controls at the assertion level. The auditor determined that the risk relates to the valuation of inventory and completeness of liabilities, as the valuation methods may be susceptible to inappropriate adjustment by management or records may be manipulated to understate net liabilities. In addition to the procedures performed as described in paragraphs 48–52, the auditor designed and performed further audit procedures to address this significant risk.
A151
In certain circumstances, the auditor may determine that the risks of material misstatement due to fraud related to management override of controls affect individual assertions and related significant classes of transactions, account balances and disclosures. In such cases, in addition to the requirements in paragraphs 48–52, the auditor identifies these risks at the assertion level and designs and performs further audit procedures to address the assessed risks of material misstatement due to fraud at the assertion level in accordance with paragraph 46.
Risks of Material Misstatement Due to Fraud in Revenue Recognition (Ref: Para. 41)
A152
Material misstatement due to fraudulent financial reporting in revenue recognition often results from an overstatement of revenues through, for example, premature revenue recognition or recording fictitious revenues. It may also result from an understatement of revenues through, for example, improperly deferring revenues to a later period.
A153
The risks of material misstatement due to fraud in revenue recognition may be greater in some entities than others. For example, there may be pressures or incentives on management to commit fraudulent financial reporting through inappropriate revenue recognition in the case of publicly traded entities when, for example, performance is measured in terms of year over year revenue growth or profit. Similarly, for example, there may be greater risks of material misstatement due to fraud in revenue recognition in the case of entities that generate a substantial portion of revenues through cash sales that present an opportunity for theft, or that have complex revenue recognition arrangements (e.g., licenses of intellectual property or percentage of completion) that are susceptible to management bias when determining percentage of completion for revenue recognition.
A155
Examples:
When there are changes in the financial reporting framework relating to revenue recognition, which may present an opportunity for management to commit fraudulent financial reporting or bring to light the lack of (or significant deficiency in) controls for managing changes in the financial reporting framework.
When an entity’s accounting principles for revenue recognition are more aggressive than, or inconsistent with, its industry peers.
When the entity operates in emerging industries.
When revenue recognition involves complex accounting estimates.
When revenue recognition is based on complex contractual arrangements with a high degree of estimation uncertainty, for example, construction-type or production-type contracts (e.g., tolling arrangements) and multiple-element arrangements.
When contradictory evidence is obtained from performing risk assessment procedures.
When the entity has a history of significant adjustments for the improper recognition of revenue (e.g., premature recognition of revenue).
When circumstances indicate the recording of fictitious revenues.
When circumstances indicate the omission of required disclosures or presentation of incomplete or inaccurate disclosures regarding revenue, for example, to manipulate the entity’s financial performance due to pressures to meet investor / market expectations, or due to the incentive for management to maximise compensation linked to the entity’s financial performance.
When the entity is part of an unnecessarily complex structure increasing the risk of undisclosed transactions with related parties.
A155
Understanding the entity’s business and its environment, the applicable financial reporting framework and the entity’s system of internal control helps the auditor understand the nature of the revenue transactions, the applicable revenue recognition criteria and the appropriate industry practice related to revenue. This understanding may assist the auditor in identifying events or conditions (see examples below) relating to the types of revenue, revenue transactions, or relevant assertions, that could give rise to fraud risk factors.
A156
If fraud risk factors related to revenue recognition are present, determining whether such fraud risk factors indicate a risk of material misstatement due to fraud is a matter of professional judgement. The significance of fraud risk factors (see paragraphs A110–A112) related to revenue recognition, individually or in combination, ordinarily makes it inappropriate for the auditor to rebut the presumption that there are risks of material misstatement due to fraud in revenue recognition.
A158
Examples:
Leasehold revenue from a single unit of rental property, or multiple rental properties, with a single tenant. Based on the risk assessment procedures performed, the auditor determined that leasehold revenue is not a key performance indicator for the lessor as it is predictable and stable. Therefore, there are no significant incentives or pressures related to leasehold revenue. The auditor also determined that the accounting is outsourced to an independent asset management company such that there are no significant opportunities for management to manipulate leasehold revenue.
Simple or straightforward ancillary revenue sources, which are determined by fixed rates or externally published rates (e.g., interest or dividend revenue from investments with level 1 inputs). Based on the risk assessment procedures performed, the auditor determined that management’s key performance indicators do not relate to interest or dividend revenue from investments such that there are no significant incentives or pressures related to the interest or dividend revenue from investments because the transactions are recorded in a highly automated system with no significant opportunities for management to manipulate the interest or dividend revenue from investments.
A158
There may be limited circumstances where it may be appropriate to rebut the presumption that there are risks of material misstatement due to fraud in revenue recognition. The auditor may conclude that there are no risks of material misstatement due to fraud relating to revenue recognition in the case where fraud risk factors are not significant.
A159
Paragraph 68(d) specifies the documentation required when the auditor concludes that the presumption is not applicable in the circumstances of the engagement and, accordingly, has not identified revenue recognition as a risk of material misstatement due to fraud.
Considerations Specific to Public Sector Entities
A160
In public sector entities, there may be fewer incentives or pressures to engage in fraudulent financial reporting by intentionally overstating or understating revenue but there may be fraud risks related to expenditures, especially when such expenditures are subject to statutory limits.
Unpredictability in the Selection of Audit Procedures (Ref: Para. 43)
A162
Examples:
Performing further audit procedures on selected classes of transactions, account balances or disclosures that were not determined to be material.
Performing tests of detail where the auditor performed substantive analytical procedures in previous audits.
Adjusting the timing of audit procedures from that otherwise expected.
Using different sampling methods or using different approaches to stratify the population.
Performing audit procedures at different locations or at locations on an unannounced basis.
Performing substantive analytical procedures at a more detailed level or lowering thresholds when performing substantive analytical procedures for further investigation of unusual or unexpected relationships.
Using automated tools and techniques, such as anomaly detection or statistical methods, on an entire population to identify items for further investigation.
Unpredictability in the Selection of Audit Procedures (Ref: Para. 43)
A162
Incorporating an element of unpredictability in the selection of the nature, timing, and extent of audit procedures to be performed is essential, particularly where individuals within the entity who are familiar with the audit procedures normally performed on engagements may be better positioned to conceal fraudulent financial reporting and misappropriation of assets. It is therefore important that the auditor maintains an open mind to new ideas or different perspectives when selecting the audit procedures to be performed to address the risks of material misstatement due to fraud.
A163
The extent to which the auditor chooses to incorporate an element of unpredictability in the selection of the nature, timing, and extent of audit procedures is a matter of professional judgement. The auditor may, when incorporating an element of unpredictability in the selection of the nature, timing, and extent of audit procedures, refer to Appendix 2 of this ASA for examples of possible audit procedures to use when addressing the assessed risks of material misstatement due to fraud.
Overall Responses (Ref: Para. 44)
A165
Examples:
Increased sensitivity in the selection of the nature and extent of documentation to be examined in support of material transactions.
Increased recognition of the need to corroborate management’s explanations or representations concerning significant matters.
Increased involvement of auditor’s experts to assist the engagement team with complex or subjective areas of the audit.
Changing the composition of the engagement team by, for example, requesting that more experienced individuals with greater skills or knowledge or specific expertise are assigned to the engagement.
Increasing the extent and frequency of the direction and supervision of engagement team members and a more detailed review of their work.
Using direct extraction methods or technologies when obtaining data from the entity’s information system for use in automated tools and techniques to address the risk of data manipulation.
Increased emphasis on tests of details.
Overall Responses (Ref: Para. 44)
A165
In accordance with paragraph 39(b), assessed risks of material misstatement due to fraud at the financial report level are also treated as significant risks. This has a significant bearing on the auditor’s general approach and thereby the auditor’s overall responses to such risks.
Audit Procedures Responsive to the Assessed Risks of Material Misstatement Due to Fraud at the Assertion Level (Ref: Para. 46)
A167
Examples:
Nature
The auditor identifies that management is under pressure to meet earnings expectations and accordingly there may be a related risk that management is inflating sales by entering into sales agreements that include terms that preclude revenue recognition or by invoicing sales before delivery. In these circumstances, the auditor may, for example, design external confirmations not only to confirm outstanding amounts, but also to confirm the details of the sales agreements, including date, any rights of return and delivery terms. In addition, the auditor may find it effective to supplement such external confirmations with enquiries of non-financial personnel in the entity regarding any changes in sales agreements and delivery terms.
Timing
The auditor may conclude that performing substantive testing at or near the period end better addresses an assessed risk of material misstatement due to fraud. The auditor may conclude that, given the assessed risks of intentional misstatement or manipulation, audit procedures to extend audit conclusions from an interim date to the period end would not be effective. In contrast, because an intentional misstatement — for example, a misstatement involving improper revenue recognition — may have been initiated in an interim period, the auditor may elect to apply substantive procedures to transactions occurring earlier in or throughout the reporting period.
Extent
The auditor may use automated tools and techniques to perform more extensive testing of digital information. Such automated techniques may be used to test all items in a population, select specific items for testing that are responsive to risks of material misstatement due to fraud, or select items for testing when performing audit sampling. For example, the auditor may stratify the population based on specific characteristics to obtain more relevant audit evidence that is responsive to the risks of material misstatement due to fraud.
Audit Procedures Responsive to the Assessed Risks of Material Misstatement Due to Fraud at the Assertion Level (Ref: Para. 46)
A167
In accordance with paragraph 39(b), assessed risks of material misstatement due to fraud are treated as significant risks. ASA 330 requires the auditor to obtain more persuasive evidence the higher the auditor’s assessment of risk. When obtaining more persuasive audit evidence to respond to assessed risks of material misstatement due to fraud, the auditor may increase the quantity of the evidence, or obtain evidence that is more relevant and reliable, for example, by placing more emphasis on obtaining third party evidence or by obtaining audit evidence from a number of independent sources.
External Confirmation Procedures
A168
In applying ASA 330, external confirmation procedures may be considered useful when seeking audit evidence that is not biased towards corroborating or contradicting a relevant assertion in the financial report, especially in instances where risks of material misstatement due to fraud have been identified related to the class of transactions, account balance or disclosure.
A169
ASA 505 requires the auditor to maintain control over the external confirmation requests and to evaluate the implications of management’s refusal to allow the auditor to send a confirmation request. If the auditor is unable to maintain control over the confirmation process or obtains an unsatisfactory response as to why management refuses to allow the auditor to send a confirmation request, as applicable, then this may be an indication of a fraud risk factor.
A171
Example:
The auditor may request confirmation of the contractual terms for a specific class of revenue transactions, such as pricing, payment and discount terms, applicable guarantees and the existence, or absence, of any side agreements.
A171
The use of external confirmation procedures may be more effective or provide more persuasive audit evidence over the terms and conditions of a contractual agreement.
A172
ASA 505 includes factors that may indicate doubts about the reliability of a response to an external confirmation request, since all responses carry some risk of interception, alteration, or fraud. This may be the case when the response to a confirmation request:
Is sent from an e-mail address that is not recognised.
Does not include the original electronic mail chain or any other information indicating that the confirming party is responding to the auditor’s confirmation request.
Contains unusual restrictions or disclaimers.
A174
Example:
A response to a bank confirmation request indicated that a bank account, in the name of wholly owned subsidiary incorporated in an offshore financial centre, did not exist. Upon investigating the exception, the auditor determined that the entity misstated its financial report by overstating its cash balance.
A174
ASA 505 includes guidance for the auditor when a response to a confirmation request indicates a difference between information requested to be confirmed, or contained in the entity’s records, and information provided by the confirming party.
Examples of Other Further Audit Procedures
A175
Examples of possible audit procedures to address the assessed risks of material misstatement due to fraud are presented in Appendix 2. The Appendix includes examples of responses to the auditor’s assessment of the risks of material misstatement resulting from both fraudulent financial reporting, including fraudulent financial reporting resulting from revenue recognition, and misappropriation of assets.
Why the testing of journal entries and other adjustments is performed
A176
Material misstatements of the financial report due to fraud often involve the manipulation of the financial reporting process by recording inappropriate or unauthorised journal entries in the general ledger and other adjustments. This may occur throughout the year or at period end, or by management making adjustments to amounts reported in the financial report that are not reflected in journal entries, such as through consolidation adjustments and reclassifications.
A177
Testing the appropriateness of journal entries recorded in the general ledger and other adjustments (e.g., entries made directly to the financial report such as eliminating adjustments for transactions, unrealised profits and intra-group account balances at the group level) may assist the auditor in identifying fraudulent journal entries and other adjustments.
A178
The auditor’s consideration of the risks of material misstatement associated with management override of controls over journal entries is important because automated processes and controls may reduce the risk of inadvertent error but do not overcome the risk that management may inappropriately override such automated processes and controls, for example, by changing the amounts being automatically posted in the general ledger or to the financial reporting system. Further, where IT is used to transfer information automatically, there may be little or no visible evidence of such intervention in the information systems.
A179
In planning the audit, drawing on the experience and insight of the engagement partner or other key members of the engagement team may be helpful in designing audit procedures to test the appropriateness of journal entries and other adjustments (e.g., to address the risks of management override of controls), including planning for the appropriate resources, and determining the nature, timing and extent of the related direction, supervision, and review of the work being performed.
Obtaining audit evidence about the completeness of the population of journal entries and other adjustments (Ref: Para. 49(b))
A180
The population of journal entries may include manual adjustments, or other “top-side” adjustments that are made directly to the amounts reported in the financial report. Failing to obtain audit evidence about the completeness of the population may limit the effectiveness of the audit procedures in responding to the risks of management override of controls associated with fraudulent journal entries and other adjustments.
Selecting journal entries and other adjustments (Ref: Para. 49(c) and 49(d))
A181
Prior to selecting items to test, the auditor may need to consider whether the integrity of the population of journal entries and other adjustments has been maintained throughout all stages of information processing based on the auditor’s understanding and evaluation of the entity’s information system and control activities (e.g., general IT controls that safeguard and maintain the integrity of financial information) in accordance with the requirements of ASA 315.
A183
Examples:
The process of selecting journal entries and other adjustments for testing may be enhanced if the auditor leverages insights based on the auditor’s understanding about:
How the financial report (including events and transactions) may be susceptible to material misstatement due to fraud, particularly in areas where fraud risk factors are present.
The application of accounting principles and methods that may be susceptible to material misstatement due to management bias.
Deficiencies in internal control that present opportunities for those charged with governance, management, or others within the entity to commit fraud.
A183
The auditor’s understanding of the entity and its environment, the applicable financial reporting framework, and the entity’s system of internal control may assist the auditor in selecting journal entries and other adjustments for testing.
A184
Appendix 4 provides additional considerations that may be used by the auditor when selecting journal entries and other adjustments for testing.
Timing of testing journal entries and other adjustments (Ref: Para. 49(c) and 49(d))
A186
Example:
Among the journal entries and other adjustments most susceptible to management override of controls are manual adjusting journal entries and other adjustments directly made to the financial report that occur after the closing of a financial reporting period and have little or no explanatory support.
Timing of testing journal entries and other adjustments (Ref: Para. 49(c) and 49(d))
A186
Fraudulent journal entries and other adjustments are often made at the end of a reporting period; consequently, paragraph 49(c) requires the auditor to select journal entries and other adjustments made at that time.
A188
Examples:
Risks of material misstatement that may be strongly linked to fraud schemes that can occur over a long period of time (e.g., complex related party transaction structures that may obscure their economic substance).
Anomalies or outliers in the journal entry data throughout the period that may be detected from the use of automated tools and techniques.
A188
Paragraph 49(d) requires the auditor to determine whether there is also a need to test journal entries and other adjustments throughout the period because material misstatements due to fraud can occur throughout the period and may involve extensive efforts to conceal how the fraud is accomplished.
Examining the underlying support for journal entries and other adjustments selected (Ref: Para. 49(c) and 49(d))
A189
When testing the appropriateness of journal entries and other adjustments, the auditor may need to obtain and examine supporting documentation to determine the business rationale for recording them, including whether the recording of the journal entry reflects the substance of the transaction and complies with the applicable financial reporting framework.
Considering the use of automated tools and techniques when testing journal entries and other adjustments (Ref: Para. 49(b) and 49(c))
A190
The auditor may consider the use of automated tools and techniques when testing journal entries and other adjustments (e.g., determining the completeness of the population or selecting items to test). Such consideration may be impacted by the entity’s use of technology in processing journal entries and other adjustments.
Why the review of accounting estimates for management bias is performed
A191
The preparation of the financial report requires management to make a number of judgements or assumptions that affect accounting estimates and to monitor the reasonableness of such estimates on an ongoing basis. Fraudulent financial reporting is often accomplished through intentional misstatement of accounting estimates. For example, this may be achieved by understating or overstating provisions or reserves so as to be designed either to smooth earnings over two or more accounting periods, or to achieve a designated earnings level in order to deceive financial report users by influencing their perceptions as to the entity’s performance and profitability.
A192
ASA 315 provides guidance that management bias is often associated with certain conditions that have the potential to give rise to management not maintaining neutrality in exercising judgement (i.e., indicators of potential management bias), which could lead to a material misstatement of the information that would be fraudulent if intentional.
Indicators of possible management bias
A194
Examples:
Indicators of possible management bias in how management made the accounting estimates that may represent a risk of material misstatement due to fraud include:
Changes in methods, significant assumptions, sources, or items of data selected that are not based on new circumstances or new information, which may not be reasonable in the circumstances nor in compliance with the applicable financial reporting framework.
Adjustments, made to the output of the model(s), that are not appropriate in the circumstances when considering the requirements of the applicable financial reporting framework.
Indicators of possible management bias
A194
ASA 540 includes a requirement and related application material addressing indicators of possible management bias.
A196
Examples:
Analysing the activity in an estimate account during the year and comparing it to the current and prior period estimates.
Benchmarking assumptions used for the estimate, using data visualisation to understand the location of point estimates within the range of acceptable outcomes.
Using predictive analytics to identify the likelihood of future outcomes based on historical data.
A196
The auditor may use automated tools and techniques to review accounting estimates for management bias.
A197
If there are indicators of possible management bias that may be intentional, the auditor may consider it appropriate to involve individuals with forensic skills in performing the review of accounting estimates for management bias in accordance with paragraphs 50–51. Applying forensic skills through analysing accounting records, conducting interviews, reviewing internal and external communications, investigating related party transactions, or reviewing internal controls may also assist the auditor in evaluating whether the indicators of possible management bias represent a material misstatement due to fraud.
Significant Transactions Outside the Normal Course of Business or Otherwise Appear Unusual (Ref: Para. 52)
A198
Indicators that may suggest that significant transactions that are outside the normal course of business for the entity, or that otherwise appear to be unusual, may have been entered into to engage in fraudulent financial reporting or to conceal misappropriation of assets include:
The form of such transactions appears overly complex (e.g., the transaction involves multiple entities within a consolidated group or multiple unrelated third parties).
Management has not discussed the nature of and accounting for such transactions with those charged with governance of the entity, and there is inadequate documentation.
Management is placing more emphasis on the need for a particular accounting treatment than on the underlying economics of the transaction.
Transactions that involve non-consolidated related parties, including special purpose entities, have not been properly reviewed or approved by those charged with governance of the entity.
Unusual activities with no logical business rationale.
The transactions involve previously unidentified related parties or parties that do not have the substance or the financial strength to support the transaction without assistance from the entity under audit.
Analytical Procedures Performed Near the End of the Audit in Forming an Overall Conclusion (Ref: Para. 53)
A200
Examples:
Uncharacteristically large amounts of income being reported in the last few weeks of the reporting period.
Unusual transactions.
Income or expenses that is inconsistent with trends in cash flow from operations:
Uncharacteristically low amounts of revenue or expenses at the start of the subsequent period; or
Uncharacteristically high levels of refunds or credit notes at the start of the subsequent period.
Analytical Procedures Performed Near the End of the Audit in Forming an Overall Conclusion (Ref: Para. 53)
A200
ASA 520 explains that the analytical procedures performed near the end of the audit are intended to corroborate conclusions formed during the audit of individual components or elements of the financial report. However, the auditor may perform the analytical procedures at a more granular level for certain higher risk classes of transactions, account balances, and disclosures to determine whether certain trends or relationships may indicate a previously unidentified risk of material misstatement due to fraud. Determining which particular trends and relationships may indicate a risk of material misstatement due to fraud requires professional judgement. Unusual relationships involving year-end revenue and income are particularly relevant.
A201
The auditor may use automated tools and techniques to identify unusual or inconsistent transaction posting patterns in order to determine if there is a previously unrecognised risk of material misstatement due to fraud.
Fraud or Suspected Fraud (Ref: Para. 55–58)
A203
Examples:
Consulting with others in the firm.
Obtaining legal advice from external counsel to understand the engagement partner’s options and the professional or legal implications of taking any particular course of action.
Consulting on a confidential basis with a regulator or professional body (unless doing so is prohibited by law or regulation or would breach the duty of confidentiality).
Fraud or Suspected Fraud (Ref: Para. 55–58)
A203
If the auditor identifies fraud or suspected fraud, the firm’s policies or procedures may include actions for the engagement partner to take, depending on the facts and circumstances of the audit engagement and the nature of the fraud.
A204
In accordance with ASA 220, the engagement partner is required to take responsibility for making the engagement team aware of the firm’s policies or procedures related to relevant ethical requirements. This includes the responsibilities of members of the engagement team when they become aware of an instance of non-compliance with laws and regulations by the entity, which includes instances of fraud.
Obtaining an Understanding of the Fraud or Suspected Fraud
A205
The determination of which level of management is the appropriate one is a matter of professional judgement and is affected by such factors as the likelihood of collusion and the nature and magnitude of the suspected fraud. Ordinarily, the appropriate level of management is at least one level above the persons who appear to be involved with the fraud or suspected fraud.
A206
When obtaining an understanding of the fraud or suspected fraud, the auditor may do one or more of the following depending on the facts and circumstances of the audit engagement and the nature of the fraud:
Involve an auditor’s expert, such as an individual with forensic skills.
Inspect the entity’s whistleblower program files for additional information.
Make further enquiries of:
The entity’s in-house counsel or external legal counsel.
Individuals within the internal audit function (if the function exists).
Evaluating the Entity’s Process to Investigate and Remediate the Fraud or Suspected Fraud
A208
Examples:
New allegations of fraud were made by a disgruntled former employee. Management followed the policies and procedures in place at the entity and referred the matter to the legal and human resources departments. Since the entity’s policies and procedures were followed and prior allegations with similar facts and circumstances had been investigated and determined to be without merit, management determined that no further action was necessary.
A suspected fraud involving a senior member of management was reported to those charged with governance by an employee. As a result, those charged with governance followed the policies and procedures in place at the entity, including engaging a certified fraud examiner to perform an independent forensic investigation.
Evaluating the Entity’s Process to Investigate and Remediate the Fraud or Suspected Fraud
A208
The nature and extent of the entity’s process to investigate the fraud or suspected fraud undertaken by management or those charged with governance may vary based on the circumstances, and may be influenced by the entity’s assessment of the significance of fraud risks relevant to the entity’s financial reporting objectives. For example, an entity’s whistleblower program (or other program to report fraud) may set out policies or procedures to be followed in relation to investigation and remediation of matters, including the establishment of thresholds for taking further action.
A209
When evaluating the appropriateness of the entity’s investigation process and remedial actions implemented to respond to the fraud or suspected fraud in accordance with paragraphs 55(b) and 55(c), the auditor may consider:
In relation to the entity’s process to investigate the fraud or suspected fraud:
The objectivity and competence of individuals involved in the entity’s process to investigate the fraud or suspected fraud.
The nature, timing and extent of procedures to investigate the fraud or suspected fraud, including identification of root causes, if applicable.
In relation to the entity’s actions to remediate the fraud or suspected fraud:
Whether the remedial actions address the root cause(s).
Whether the remedial actions are proportionate to the severity and pervasiveness of the identified fraud or suspected fraud and the urgency with which the matter needs to be addressed, including how management:
Responded to any misstatements that were identified (e.g., the timeliness of when the identified misstatements were corrected by management).
Responded to the fraud (e.g., disciplinary, or legal sanctions imposed on the individuals involved in perpetrating the fraud).
Addressed the control deficiencies regarding the prevention or detection of the fraud.
A211
Example:
Based on an understanding of the suspected fraud obtained through understanding the entity’s whistleblower program, the engagement partner determined the suspected fraud was clearly inconsequential because it was limited to the misappropriation of immaterial assets by employees.
A211
The auditor may use information obtained from their understanding of the entity’s whistleblower program in accordance with paragraph 32(a)(ii), including the entity’s process for investigating and remediating allegations of fraud that came through the entity’s whistleblower program, to determine whether a fraud or suspected fraud is clearly inconsequential.
Impact on the Overall Audit Strategy
A212
The understanding obtained about the fraud or suspected fraud impacts the engagement partner’s determination of whether and how to adjust the overall audit strategy, including determining whether there is a need to perform additional risk assessment procedures or further audit procedures, especially in circumstances when information comes to the engagement partner’s attention that differs significantly from the information available when the overall audit strategy was originally established.
A213
As described in ASA 220, in fulfilling the requirement in paragraph 56, the engagement partner may obtain information from other members of the engagement team (e.g., component auditors).
A215
Example:
Based on an understanding of the suspected fraud, the engagement partner believed the integrity of management was in question. Given the significance and pervasiveness of the matter, the engagement partner determined that no further work was to be performed across the entire audit engagement until the matter had been appropriately resolved.
A215
Based on the understanding obtained about the fraud or suspected fraud and the impact on the overall audit strategy, the engagement partner may determine that it is necessary to discuss an extension of the audit reporting deadlines with management and those charged with governance, where an extension is possible under applicable law or regulation. If an extension is not possible, ASA 705 deals with the implications for the auditor’s opinion on the financial report.
The Auditor Identifies a Misstatement Due to Fraud
A216
ASA 450 and ASA 700 establish requirements and provide guidance on the evaluation of misstatements and the effect on the auditor’s opinion in the auditor’s report.
A218
Examples:
Qualitative circumstances include whether a misstatement:
Involves those charged with governance, management, related parties, or third parties that brings into question the integrity or competence of those involved.
Affects compliance with law or regulation which may also affect the auditor’s consideration of the integrity of management, those charged with governance or employees.
Affects compliance with debt covenants or other contractual requirements which may cause the auditor to question the pressures being exerted on management to meet certain earnings expectations.
Quantitative circumstances include whether a misstatement:
Affects key performance indicators such as earnings per share, net income and working capital, that may have a negative effect on the calculation of compensation arrangements for senior management at the entity.
Affects multiple reporting periods such as when a misstatement has an immaterial effect on the current period’s financial report but is likely to have a material effect on future periods’ financial report.
A218
The following are examples of qualitative or quantitative circumstances that may be relevant when determining whether the misstatement due to fraud is material:
A219
The implications of an identified misstatement due to fraud on the reliability of information intended to be used as audit evidence depends on the circumstances. For example, an otherwise insignificant fraud may be significant if it involves senior management. In such circumstances, the reliability of information previously obtained and intended to be used as audit evidence may be called into question as there may be doubts about the completeness and truthfulness of representations made and about the authenticity of accounting records and documentation.
A220
Since fraud involves incentive or pressure to commit fraud, a perceived opportunity to do so or some rationalisation of the act, an instance of fraud is unlikely to be an isolated occurrence. Misstatements, such as numerous misstatements at a business unit or geographical location even though the cumulative effect is not material, may also be indicative of a risk of material misstatement due to fraud.
Considerations Specific to Public Sector Entities
A221
For public sector entities, an example of both qualitative and quantitative circumstance includes whether a misstatement affects the determination of the surplus or deficit reported for the period, or whether or not the public sector entity has met or exceeded its approved budget, including where relevant, whether its expenses are within statutory limits.
Determining if Control Deficiencies Exist
A222
ASA 265 provides requirements and guidance about the auditor’s communication of significant deficiencies in internal control identified during the audit to those charged with governance. Examples of matters that the auditor considers in determining whether a deficiency or combination of deficiencies in internal control constitutes a significant deficiency include:
The susceptibility to loss due to fraud of the related asset or liability.
The importance of the controls to the financial reporting process (e.g., controls over the prevention and detection of fraud).
A223
Indicators of significant deficiencies in internal control include, for example:
Evidence of ineffective aspects of the control environment, such as the identification of management fraud, whether or not material, that was not prevented by the entity’s system of internal control.
The lack of a process to investigate the fraud or suspected fraud or a process to investigate the fraud or suspected fraud that is not appropriate in the circumstances.
The lack of, or ineffective, remediation measures implemented by management to prevent or detect the reoccurrence of the fraud or suspected fraud.
Auditor Unable to Continue the Audit Engagement (Ref: Para. 59)
A224
Examples of exceptional circumstances that may arise and that may bring into question the auditor’s ability to continue performing the audit include:
The entity does not take the appropriate action regarding fraud that the auditor considers necessary in the circumstances, even where the fraud is not material to the financial report;
The auditor’s consideration of the risks of material misstatement due to fraud or the results of audit procedures performed indicate a material and pervasive fraud; or
The auditor has significant concern about the competence or integrity of management or those charged with governance.
A225
Because of the variety of circumstances that may arise, it is not possible to describe definitively when withdrawal from an engagement is appropriate. Factors that affect the auditor’s conclusion include the implications of the involvement of a member of management or of those charged with governance (which may affect the reliability of management representations) and the effects on the auditor of a continuing association with the entity.
A226
The auditor has professional and legal responsibilities in such circumstances and these responsibilities may vary by jurisdiction. In some countries, for example, the auditor may be entitled to, or required to, make a statement or report to the person or persons who made the audit appointment or, in some cases, to regulatory authorities. Given the exceptional nature of the circumstances and the need to consider the legal requirements, the auditor may consider it appropriate to seek legal advice when deciding whether to withdraw from an engagement and in determining an appropriate course of action, including the possibility of reporting to shareholders, regulators or others.
aus 0.4
Aus . For an audit engagement under the Corporations Act 2001 (the Act), the possibility of withdrawing from the engagement or resigning from the appointment as an auditor can only be made in accordance with the provisions of the Act, including in certain circumstances, obtaining consent to resign from the Australian Securities and Investments Commission (ASIC).
Considerations Specific to Public Sector Entities
A227
In many cases in the public sector, the option of withdrawing from the engagement may not be available to the auditor due to the nature of their legal mandate, based on public interest considerations.
Determining Key Audit Matters Related to Fraud
A228
Users of the financial report are interested in matters related to fraud about which the auditor had a robust dialogue with those charged with governance. The considerations in paragraph 60 focus on the nature of matters communicated with those charged with governance that are intended to reflect matters related to fraud that may be of particular interest to intended users.
A229
In addition to matters that relate to the specific required considerations in paragraph 60, there may be other matters related to fraud communicated with those charged with governance that required significant auditor attention and that therefore may be determined to be key audit matters in accordance with paragraph 61.
A230
Matters related to fraud are often matters that require significant auditor attention. For example, the identification of fraud or suspected fraud may require significant changes to the auditor’s risk assessment and re-evaluation of the planned audit procedures (i.e., a significant change in the audit approach).
A231
The determination of key audit matters involves making a judgement about the relative importance of matters that required significant auditor attention. Therefore, it may be rare that the auditor of a complete set of general-purpose financial report of a publicly traded entity would not determine at least one key audit matter related to fraud. However, in certain limited circumstances, the auditor may determine that there are no matters related to fraud that are key audit matters in accordance with paragraph 61.
A233
Example:
The auditor determines significant auditor attention was required to respond to the risk of material misstatement due to fraud associated with the entity’s estimate of expected credit losses. Management utilises a model that requires a complex set of assumptions about future developments in a variety of entity-specific scenarios that are difficult to predict. Based on the auditor’s identification of aggressive profitability expectations of investment analysts about the entity, the auditor identified a risk of material misstatement due to fraud because of the subjectivity involved in the expected credit losses estimate and the incentive this creates for intentional management bias.
A233
Accounting estimates are often the most complex areas of the financial report because they may be dependent on significant management judgement. Significant auditor attention may be required in accordance with paragraph 60(a) to respond to assessed risks of material misstatement due to fraud associated with an accounting estimate that involves significant management judgement. Significant management judgement is often involved when an accounting estimate is subject to a high degree of estimation uncertainty and subjectivity.
A234
ASA 265 requires the auditor to communicate a significant deficiency in internal control to those charged with governance that is relevant to the prevention and detection of fraud. Significant deficiencies may exist even though the auditor has not identified misstatements during the audit. For example, the lack of a whistleblower program (or other program to report fraud) may be indicative of deficiencies in the entity’s control environment, but it may not directly relate to a risk of material misstatement due to fraud. The auditor may also communicate these deficiencies to management.
A235
This ASA requires management override of controls to be a risk of material misstatement due to fraud (see paragraph 40) and presumes that there are risks of material misstatement due to fraud in revenue recognition (see paragraph 41). The auditor may determine these matters to be key audit matters related to fraud because risks of material misstatement due to fraud are often matters that both require significant auditor attention and are of most significance in the audit. However, this may not be the case for all these matters. The auditor may determine that certain risks of material misstatement due to fraud did not require significant auditor attention and, therefore, these risks would not be considered in the auditor’s determination of key audit matters in accordance with paragraph 60.
A236
As described in ASA 701, the auditor’s decision-making process in determining key audit matters is based on the auditor’s professional judgement about which matters were of most significance in the audit of the financial report of the current period. Significance can be considered in the context of quantitative and qualitative factors, such as relative magnitude, the nature and effect on the subject matter and the expressed interests of intended users or recipients.
A237
One of the considerations that may be relevant in determining the relative significance of a matter that required significant auditor attention, and whether such a matter is a key audit matter, is the importance of the matter to intended users’ understanding of the financial report as a whole. As users of the financial report are interested in matters related to fraud, one or more of the matters related to fraud that required significant auditor attention in performing the audit, determined in accordance with paragraph 60, would ordinarily be of most significance in the audit of the financial report of the current period and therefore are key audit matters.
A238
ASA 701 includes other considerations that may be relevant to determining which matters related to fraud that required significant auditor attention, were of most significance in the current period and therefore are key audit matters.
Communicating Key Audit Matters Related to Fraud
A239
If a matter related to fraud is determined to be a key audit matter and there are a number of separate, but related, considerations that were of most significance in the audit, the auditor may communicate the matters together in the auditor’s report. For example, long-term contracts may involve significant auditor attention with respect to revenue recognition and revenue recognition may also be identified as a risk of material misstatement due to fraud. In such circumstances, the auditor may include in the auditor’s report one key audit matter related to revenue recognition with an appropriate subheading that clearly describes the matter, including that it relates to fraud.
A240
Relating a matter directly to the specific circumstances of the entity may help to minimise the potential that such descriptions become overly standardised and less useful over time. In describing why the auditor considered the matter to be one of most significance in the audit, the auditor may highlight aspects specific to the entity (e.g., circumstances that affected the underlying judgements made in the financial report of the current period) so as to make the description more relevant for intended users. This may be particularly important in describing a key audit matter that recurs over multiple periods. Similarly, in describing how the key audit matter related to fraud was addressed in the audit, the auditor may highlight matters directly related to the specific circumstances of the entity, while avoiding generic or standardised language.
A241
ASA 701 includes considerations and guidance on original information (information about the entity that has not otherwise been made publicly available by the entity) that may be particularly relevant in the context of communicating key audit matters related to fraud.
A242
ASA 701 describes that management or those charged with governance may decide to include new or enhanced disclosures in the financial report or elsewhere in the annual report relating to a key audit matter in light of the fact that the matter will be communicated in the auditor’s report. Such new or enhanced disclosures, for example, may be included to provide more robust information about identified fraud or suspected fraud or identified deficiencies in internal control that are relevant to the prevention and detection of fraud.
Circumstances in Which a Matter Determined to Be a Key Audit Matter Is Not Communicated in the Auditor’s Report
A243
ASA 701, paragraph 14(b), indicates that it will be extremely rare for a matter determined to be a key audit matter not to be communicated in the auditor’s report and includes guidance on circumstances in which such a matter determined to be a key audit matter is not communicated in the auditor’s report. For example:
Law or regulation may preclude public disclosure by either management or the auditor about a specific matter determined to be a key audit matter.
There is presumed to be a public interest benefit in providing greater transparency about the audit for intended users. Accordingly, the judgement not to communicate a key audit matter is appropriate only in cases when the adverse consequences to the entity or the public as a result of such communication are viewed as so significant that they would reasonably be expected to outweigh the public interest benefits of communicating about the matter.
A244
It may also be necessary for the auditor to consider the implications of communicating about a matter determined to be a key audit matter in light of relevant ethical requirements. In addition, the auditor may be required by law or regulation to communicate with applicable regulatory, enforcement or supervisory authorities in relation to the matter, regardless of whether the matter is communicated in the auditor’s report.
Written Representations (Ref: Para. 63)
A245
ASA 580 establishes requirements and provides guidance on obtaining appropriate representations from management and, where appropriate, those charged with governance in the audit. Although written representations are an important source of audit evidence, they do not provide sufficient appropriate audit evidence on their own about any of the matters with which they deal. In addition, since management are in a unique position to perpetrate fraud, it is important for the auditor to consider all audit evidence obtained, including audit evidence that is consistent or inconsistent with other audit evidence in drawing the conclusion required in accordance with ASA 330.
A246
ASA 580 also addresses circumstances when the auditor has doubt as to the reliability of written representations, including if written representations are inconsistent with other audit evidence. Doubts about the reliability of information from management may indicate a risk of material misstatement due to fraud.
Communications with Management and Those Charged with Governance (Ref: Para. 64–66)
A247
In some jurisdictions, law or regulation may restrict the auditor’s communication of certain matters with management and those charged with governance. Law or regulation may specifically prohibit a communication, or other action, that might prejudice an investigation by an appropriate authority into an actual, or suspected, illegal act, including alerting the entity, for example, when the auditor is required to report the fraud to an appropriate authority pursuant to anti-money laundering legislation. In these circumstances, the issues considered by the auditor may be complex and the auditor may consider it appropriate to obtain legal advice.
aus 0.5
Aus . Legislation may require the auditor or a member of the audit team to maintain the confidentiality of information disclosed to the auditor, or a member of the audit team, by a person regarding contraventions or possible contraventions of the law.* In such circumstances, the auditor or a member of the audit team may be prevented from communicating that information to management or those charged with governance in order to protect the identity of the person who has disclosed confidential information that alleges a breach of the law. In such circumstances, the auditor may consider obtaining legal advice to assist in determining the appropriate course of action and may need to consider the implications for the audit engagement.
Communication with Management (Ref: Para. 64)
A248
If the auditor identifies fraud or suspected fraud, it is important that the matter be brought to the attention of the appropriate level of management as soon as practicable, even if the matter may be considered clearly inconsequential (e.g., a minor misappropriation of funds by an employee at a low level in the entity’s organisation).
Communication with Those Charged with Governance (Ref: Para. 65)
A249
The auditor’s communication with those charged with governance may be made orally or in writing. ASA 260 identifies factors the auditor considers in determining whether to communicate orally or in writing. Due to the nature and sensitivity of fraud involving senior management, or fraud that results in a material misstatement in the financial report, the auditor reports such matters on a timely basis and may consider it necessary to also report such matters in writing.
A250
In some cases, the auditor may consider it appropriate to communicate with those charged with governance fraud or suspected fraud involving others that the auditor determined to be clearly inconsequential. Similarly, those charged with governance may wish to be informed of such circumstances. The communication process is assisted if the auditor and those charged with governance agree at an early stage in the audit about the nature and extent of the auditor’s communications in this regard.
A251
In the exceptional circumstances where the auditor has doubts about the integrity or honesty of management or those charged with governance, the auditor may consider it appropriate to obtain legal advice to assist in determining the appropriate course of action.
Other Matters Related to Fraud (Ref: Para. 66)
A252
Other matters related to fraud to be discussed with those charged with governance of the entity may include, for example:
Concerns about the nature, extent, and frequency of management’s assessments of the controls in place to prevent or detect fraud and of the risk that the financial report may be misstated.
A failure by management to appropriately address identified significant deficiencies in internal control, or to appropriately respond to an identified fraud.
The auditor’s evaluation of the entity’s control environment, including questions regarding the competence and integrity of management.
Actions by management that may be indicative of fraudulent financial reporting, such as management’s selection and application of accounting policies that may be indicative of management’s effort to manage earnings in order to deceive financial report users by influencing their perceptions as to the entity’s performance and profitability.
Concerns about the adequacy and completeness of the authorisation of transactions that appear to be outside the normal course of business.
Reporting to an Appropriate Authority Outside the Entity (Ref: Para. 67)
A253
The reporting may be to applicable regulatory, enforcement, supervisory or other appropriate authority outside the entity.
A254
ASA 250 provides further guidance with respect to the auditor’s determination of whether reporting identified or suspected non-compliance with laws or regulations to an appropriate authority outside the entity is required or appropriate in the circumstances, including consideration of the auditor’s duty of confidentiality.
aus 0.6
Aus . An auditor is required by the Corporations Act 2001 to notify the Australian Securities and Investments Commission (ASIC) if the auditor is aware of certain circumstances.*
A255
Factors the auditor may consider in determining whether it is appropriate to report the matter to an appropriate authority outside the entity, when not prohibited by law, regulation, or relevant ethical requirements, may include:
Any views expressed by regulatory, enforcement, supervisory or other appropriate authority outside of the entity.
Whether reporting the matter would be acting in the public interest.
A256
Reporting fraud matters to an appropriate authority outside the entity may involve complex considerations and professional judgements. In those circumstances, the auditor may consider consulting internally (e.g., within the firm or a network firm) or on a confidential basis with a regulator or professional body (unless doing so is prohibited by law or regulation or would breach the duty of confidentiality). The auditor may also consider obtaining legal advice to understand the auditor’s options and the professional or legal implications of taking any particular course of action.
Considerations Specific to Public Sector Entities
A257
In the public sector, requirements for reporting fraud, whether or not discovered through the audit process, may be subject to specific provisions of the audit mandate or related law, regulation, or other authority.
Documentation (Ref: Para. 68)
A258
ASA 230 addresses circumstances when the auditor identifies information that is inconsistent with the auditor’s final conclusion regarding a significant matter and requires the auditor to document how the auditor addressed the inconsistency.
Appendix 1
(Ref: Para. A26 and A43)