2.4 Professional Scepticism, Fraud vs. Error & The Expectation Gap
Key Takeaways
- Professional scepticism is an attitude that includes a questioning mind, alertness to possible misstatements due to error or fraud, and critical assessment of audit evidence.
- Fraud is distinguished from error by intentionality; fraud encompasses fraudulent financial reporting and misappropriation of assets under ISA 240.
- The Fraud Triangle explains fraud occurrence through three drivers: Incentive/Pressure, Opportunity, and Rationalization/Attitude.
- Management and Those Charged With Governance (TCWG) hold primary responsibility for fraud prevention and control, while auditors provide reasonable assurance regarding material fraud.
- The audit expectation gap consists of the knowledge gap, performance gap, and evolution gap, which can be narrowed through enhanced reporting like ISA 701 Key Audit Matters.
Professional Scepticism, Fraud vs. Error & The Expectation Gap
Quick Reference: Assurance practitioners are neither naive believers nor cynical prosecutors. Professional standards demand Professional Scepticism—an attitude that includes a questioning mind, being alert to conditions which may indicate possible misstatement due to error or fraud, and a critical assessment of audit evidence (ISA 200 / ISA 240).
Understanding professional scepticism, the nature of fraud, and the public expectation gap is fundamental to passing the ICAB CA Certificate Level Assurance examination.
Professional Scepticism in Assurance
Professional scepticism is required throughout the entire assurance engagement lifecycle. It requires the practitioner to maintain awareness that misstatements could exist, regardless of the practitioner’s past experience with the honesty and integrity of entity management.
+-------------------------------------------------------------------------+
| CORE PILLARS OF PROFESSIONAL SCEPTICISM |
+-------------------------------------------------------------------------+
| 1. Questioning Mindset: Never accept explanations at face value |
| 2. Alertness to Contradictions: Identifying conflicting evidence |
| 3. Critical Assessment: Evaluating document reliability & sufficiency |
| 4. Resistance to Presumptions: Neither assuming honesty nor dishonesty |
+-------------------------------------------------------------------------+
Practical Applications of Scepticism:
- Questioning Management Explanations: If management asserts that a surge in year-end sales is due to market demand, the auditor does not accept this verbally; they cross-examine dispatch notes, customer sign-offs, and bank receipts.
- Evaluating Document Authenticity: Remaining alert to altered invoices, backdated contracts, or photocopied bank statements where originals should exist.
- Contradictory Evidence: Investigating situations where internal sales records contradict external bank confirmation replies.
Fraud vs. Error: Fundamental Concepts
Misstatements in financial statements can arise from either fraud or error. The distinguishing factor between fraud and error is intentionality.
MISSTATEMENTS IN FINANCIAL STATEMENTS
|
+------------------------------+------------------------------+
| |
UNINTENTIONAL INTENTIONAL
(ERROR) (FRAUD)
| |
- Mathematical mistake +-----------------+-----------------+
- Oversight / Misinterpretation | |
- Accidental omission FRAUDULENT FINANCIAL MISAPPROPRIATION
REPORTING OF ASSETS
(e.g. Cooking books) (e.g. Theft of cash)
1. Error (Unintentional Misstatement)
An error is an unintentional misstatement in financial statements, including an omission of an amount or a disclosure. Examples include:
- A mathematical error in compiling inventory valuation sheets.
- Unintentionally ignoring a shipping cutoff date.
- Misinterpreting accounting standards (e.g., accidentally capitalizing routine repair expenses).
2. Fraud (Intentional Misstatement - ISA 240)
Under ISA 240 (The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements), fraud is defined as an intentional act by one or more individuals among management, Those Charged With Governance (TCWG), employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage.
ISA 240 categorizes audit-relevant fraud into two distinct types:
| Fraud Category | Primary Perpetrators | Common Examples |
|---|---|---|
| Fraudulent Financial Reporting ("Cooking the Books") | Management / Board | Falsifying accounting records, recorded fake sales, intentional omission of liabilities, inappropriate application of accounting policies. |
| Misappropriation of Assets ("Theft/Embezzlement") | Employees / Lower Management | Stealing cash collections, theft of physical inventory, causing company payments to fake vendors, using company assets for personal gain. |
The Fraud Triangle Framework
Developed by criminologist Donald Cressey, the Fraud Triangle identifies three elements that are present when fraud occurs:
- Incentive or Pressure: Management or employees have a motive or are under pressure to commit fraud (e.g., earnings targets to secure bonuses, debt covenants with commercial banks, personal financial difficulties).
- Opportunity: Weak internal controls, lack of segregation of duties, or management override of controls create a situation where fraud can be committed and concealed without immediate detection.
- Rationalization / Attitude: Perpetrators possess a mindset or ethical value system that allows them to justify their fraudulent actions (e.g., "Management owes me this promotion," or "We are only borrowing the funds until next quarter").
Division of Responsibilities for Fraud
ICAB exams heavily test the distinction between management’s responsibilities and the auditor’s responsibilities regarding fraud.
Management & TCWG Responsibility:
- Primary Responsibility: Management and TCWG (e.g., Audit Committee) hold the primary responsibility for the prevention and detection of fraud.
- Implementation: Designing, implementing, and maintaining a robust internal control system, promoting an ethical corporate culture, and carrying out fraud risk assessments.
Auditor Responsibility (ISA 240):
- Reasonable Assurance: The auditor is responsible for obtaining reasonable assurance that the financial statements as a whole are free from material misstatement, whether caused by fraud or error.
- Inherent Risk Acknowledgment: Because of the inherent limitations of an audit, there is an unavoidable risk that some material misstatements may not be detected, even though the audit is properly planned and performed in accordance with ISAs (especially fraud involving sophisticated concealment or collusion).
- Reporting Protocol: When fraud is identified or suspected, the auditor must communicate it promptly to management and TCWG. In Bangladesh, under NOCLAR (Non-Compliance with Laws and Regulations) and Financial Reporting Act 2015, auditors may also have a statutory duty to report material fraud to regulatory bodies (such as BSEC, Bangladesh Bank, or FRC).
The Audit Expectation Gap
The Audit Expectation Gap is the difference between what the public, investors, and general stakeholders expect auditors to do and what auditors actually do under professional audit standards.
+-------------------------------------------------------------------------+
| COMPONENTS OF THE EXPECTATION GAP |
+-------------------------------------------------------------------------+
| |
| EXPECTATION GAP = Knowledge Gap + Performance Gap + Evolution Gap |
| |
| 1. Knowledge Gap: Public misunderstanding of audit duties/scope |
| 2. Performance Gap: Auditor failure to follow existing ISAs |
| 3. Evolution Gap: Public demands for duties not yet in standards |
+-------------------------------------------------------------------------+
Breakdown of the Gap:
- The Knowledge Gap: Misunderstandings by financial users regarding the nature of an audit. For example, many retail investors falsely believe that:
- An audit guarantees that a company will not go bankrupt.
- The auditor tests 100% of all transactions.
- The primary purpose of an audit is to detect all instances of small employee fraud.
- The Performance Gap: Occurs when auditors fail to comply with established standards (e.g., failing to exercise professional scepticism or gathering inadequate evidence).
- The Evolution Gap: Areas where public expectations evolve faster than professional audit standards (e.g., demanding real-time fraud detection or corporate ESG audit assurances).
Strategies to Narrow the Expectation Gap:
- Enhanced Reporting Standards (ISA 701 Key Audit Matters): Requiring auditors of listed companies to explicitly describe the most significant risks of material misstatement and how the auditor addressed them.
- Explicit Responsibility Statements: Clearly delineating management duties vs. auditor duties in the statutory audit report.
- Audit Committee Oversight: Strengthening the role of independent Audit Committees under the BSEC Corporate Governance Code 2018.
What is the primary distinguishing factor between 'fraud' and 'error' in financial statement misstatements under ISA 240?
According to ISA 240, who holds the PRIMARY responsibility for the prevention and detection of fraud within an organization?
The 'Knowledge Gap' component of the Audit Expectation Gap is best illustrated by which of the following scenarios?