6.1 Fraud Risk Assessment & Auditor Responses (AU-C 240)
Key Takeaways
- AU-C 240 defines fraud as an intentional act involving deception that results in a material misstatement, categorized into fraudulent financial reporting ('cooking the books') and misappropriation of assets (theft/defalcation).
- The Fraud Triangle consists of three mandatory conditions: Incentive/Pressure, Opportunity, and Rationalization/Attitude; the audit team must maintain professional skepticism and presumptive doubt during the mandatory planning brainstorming session.
- GAAS establishes two mandatory presumed fraud risks in every audit: improper revenue recognition (which may be rebutted only under rare circumstances with comprehensive workpaper documentation) and management override of controls (which can NEVER be rebutted).
- Mandatory substantive responses addressing management override comprise journal entry testing (focusing on non-standard, post-closing, and end-of-period entries), retrospective reviews of prior-year accounting estimates for bias, and evaluating the business rationale of significant unusual transactions.
- Any fraud involving senior management must be reported directly to Those Charged With Governance (Audit Committee) regardless of dollar materiality, whereas immaterial employee fraud is reported to management at least one level above the perpetrator.
6.1 Fraud Risk Assessment & Auditor Responses (AU-C 240)
Core Principle: Fraud involves an intentional act by one or more individuals among management, those charged with governance, employees, or third parties involving the use of deception to obtain an unjust or illegal advantage. Under AU-C 240 (Consideration of Fraud in a Financial Statement Audit), the auditor's responsibility is to obtain reasonable assurance that the financial statements as a whole are free from material misstatement, whether caused by fraud or error. Because fraud is concealed through forgery, collusion, or management override, the auditor must maintain an attitude of professional skepticism—characterized by a questioning mind, critical assessment of audit evidence, and presumptive doubt regarding management integrity.
1. Fraud vs. Error & Types of Misstatements Relevant to Fraud
The fundamental distinction between fraud and error is purely a matter of intent:
- Error: An unintentional misstatement or omission of amounts or disclosures in financial statements (e.g., mathematical mistakes in data compilation, misapplication of accounting principles due to ignorance, or misinterpretation of complex facts).
- Fraud: An intentional act involving deception, misrepresentation, or concealment resulting in a misstatement in the financial statements.
MISSTATEMENT IN FINANCIAL STATEMENTS
|
+--------------------------+--------------------------+
| |
[ UNINTENTIONAL ] [ INTENTIONAL ]
| |
ERROR FRAUD
- Mathematical oversight - Deception & concealment
- Inadvertent misinterpretation - Collusion & falsification
- Flawed clerical processing - Management override
Under AU-C 240, two distinct types of intentional misstatements are relevant to the auditor's work:
Comparison: Fraudulent Financial Reporting vs. Misappropriation of Assets
| Dimension | Fraudulent Financial Reporting ("Cooking the Books") | Misappropriation of Assets ("Theft / Defalcation") |
|---|---|---|
| Primary Perpetrators | Senior executive management, officers, controllers | Operating employees, lower-level management, or outside conspirators |
| Primary Motivation | Deceive financial statement users, meet financial forecasts/analysts' expectations, preserve executive compensation/bonuses, inflate stock price, comply with debt covenants | Personal financial gain, living beyond financial means, gambling or substance addictions, resentment toward employer |
| Common Mechanisms | - Fictitious journal entries (especially near period-end)<br>- Premature revenue recognition (recognizing sales before delivery/acceptance)<br>- Altering accounting records or underlying documents<br>- Intentional omission of liabilities, contingencies, or disclosures<br>- Deliberate bias in complex accounting estimates | - Stealing cash receipts before recording (skimming)<br>- Stealing cash after recording (larceny)<br>- Submitting fictitious vendor invoices or ghost employees (billing/payroll schemes)<br>- Diverting company inventory or assets for personal use<br>- Causing the entity to pay for goods not received |
| Typical Magnitude | Almost always material to financial statements | Often immaterial individually, but can aggregate to material misstatement if systemic |
| Financial Impact | Distorts earnings, net assets, gross margins, and equity | Reduces assets, inflates expenses, or creates unrecorded losses |
2. The Fraud Triangle: Forensic Analysis of Causal Conditions
Forensic criminologists and standard setters recognize that three interconnected conditions are virtually always present when fraud occurs—collectively designated as The Fraud Triangle (reflected in the fraud risk factors of AU-C 240):
[ INCENTIVE / PRESSURE ]
/ \
/ \
/ THE FRAUD TRIANGLE \
/ \
/ \
[ OPPORTUNITY ] ---------------------------------------- [ RATIONALIZATION / ATTITUDE ]
1. Incentive / Pressure (The "Why")
Management or employees have an incentive or are under financial pressure to commit fraud:
- Executive / Financial Reporting Pressures: Excessive pressure to meet quarterly analyst earnings forecasts; threat of imminent bankruptcy, foreclosure, or hostile takeover; high vulnerability to rapid technological change or industry decline; debt covenants tied to strict interest coverage or debt-to-equity ratios; executive compensation heavily weighted toward performance-based stock options or aggressive bonuses.
- Employee Pressures: Personal debt, lavish lifestyles, medical emergencies, addictions, or perceived unfair compensation relative to peers.
2. Opportunity (The "How")
Circumstances exist that provide an opening for management or employees to commit and conceal fraud. Opportunity is the only leg of the fraud triangle that the entity's internal controls can directly control or eliminate:
- Deficiencies in Internal Control: Ineffective segregation of duties (e.g., an individual authorized to approve invoices and execute cash disbursements); lack of supervisory review; absence of mandatory vacations or independent job rotations; weak IT access controls allowing unauthorized general ledger postings.
- Entity & Industry Vulnerabilities: Highly subjective accounting estimates (Level 3 fair value measurements, complex warranty liabilities); significant transactions with related parties not in the ordinary course of business; dominant, unchecked Chief Executive Officer or founder; complex corporate structure with foreign subsidiaries in jurisdictions with opaque regulatory environments; high turnover of senior financial management or legal counsel.
3. Rationalization / Attitude (The "Justification")
Individuals possess an attitude, character, or ethical mindset that allows them to knowingly and intentionally commit a dishonest act, or they rationalize the behavior to preserve their self-image:
- Common Executive Rationalizations: "This is just a temporary timing difference—we'll make it up next quarter," "We must protect the company's stock price to preserve employee jobs," or "Our aggressive accounting reflects the true underlying value of our technology."
- Common Employee Rationalizations: "The company underpays me, so they owe me this money," "I'm only borrowing the money and will repay it before the audit," or "Senior management wastes corporate funds on private jets, so my expense report is harmless."
Exam Trap: Do not confuse risk factors with evidence of fraud. The presence of all three fraud triangle components does not automatically mean fraud has occurred; it elevates the Assessed Risk of Material Misstatement (RMM) due to fraud and demands heightened audit responsiveness.
3. Mandatory Engagement Team Brainstorming Session
AU-C 240 and PCAOB AS 2401 mandate that the engagement partner and key engagement team members hold a structured brainstorming session during the planning phase of every audit:
Key Operational Rules of Brainstorming
- Mandatory Participation: Led by the engagement partner or senior manager, with all key team members participating. If multidisciplinary specialists (IT auditors, tax specialists, forensic experts) are assigned, they should participate in relevant discussions.
- Presumptive Doubt & Setting Aside Preconceptions: The team must explicitly set aside past beliefs regarding management's honesty and integrity. Even if the auditor has audited the client for 15 years with zero historical adjustments, the brainstorming discussion must assume management possesses both the incentive and ability to override controls.
- Core Focus Areas:
- How and where the financial statements are most susceptible to material misstatement due to fraud.
- How management could perpetrate and conceal fraudulent financial reporting (e.g., through side agreements, off-balance-sheet structures, or year-end adjustments).
- How assets could be misappropriated across operating units or branch locations.
- Known external and internal factors affecting management incentives.
- Unpredictability in audit procedures.
- Ongoing Requirement: Brainstorming is not a one-time planning ritual. The engagement team must maintain ongoing communication throughout the audit, sharing unexpected findings, anomalies, or suspicious documentation as evidence is collected.
4. The Two Universal Presumed Fraud Risks in Every Audit
GAAS establishes that in every single financial statement audit, the auditor must treat two specific areas as presumed fraud risks:
+-------------------------------------------------------------------------------------------------------+
| TWO UNIVERSAL PRESUMED FRAUD RISKS |
| |
| 1. IMPROPER REVENUE RECOGNITION RISK 2. RISK OF MANAGEMENT OVERRIDE OF CONTROLS |
| - Presumed present in EVERY audit - Presumed present in EVERY audit |
| - REBUTTABLE only under rare, unusual circumstances - NON-REBUTTABLE under any circumstances |
| - If rebutted: Must document complete rationale - Inherent in every entity, regardless of size |
| and supporting evidence in workpapers or internal control strength |
+-------------------------------------------------------------------------------------------------------+
Deep-Dive: Improper Revenue Recognition
- Rationale: Revenue is the primary metric scrutinized by investors, lenders, and analysts. Entities have widespread incentives to accelerate, inflate, or fabricate revenue transactions.
- Common Schemes: Bill-and-hold sales lacking economic substance; channel stuffing (shipping unordered inventory to distributors with liberal right-of-return privileges); holding books open past period-end to record subsequent-period sales; recognizing revenue on contracts prior to fulfilling performance obligations under ASC 606.
- The Rebuttal Exception: In rare cases, the auditor may conclude that the presumption does not apply (e.g., an entity with a single, non-complex income stream, such as a company whose sole asset is a real estate parcel generating a single, fixed, long-term prepaid lease payment). If the auditor rebuts the presumption, the auditor must document the complete rationale and supporting evidence in the audit workpapers.
Deep-Dive: Management Override of Controls
- Rationale: Management occupies a unique position of authority enabling them to manipulate accounting records and override established internal controls directly or indirectly. Management can order subordinates to bypass controls, forge approvals, or record improper journal entries.
- The Non-Rebuttable Rule: This risk is pervasive and non-rebuttable. It exists in every company—from Fortune 500 multinationals with sophisticated audit committees down to small family-owned machine shops. The auditor can never conclude that the risk of management override is low or non-existent.
5. Mandatory Substantive Procedures for Management Override
Because management override cannot be prevented by internal controls alone, AU-C 240 requires the auditor to execute three mandatory procedures on every audit engagement:
+-------------------------------------------------------------------------------------------------+
| THREE MANDATORY PROCEDURES FOR MANAGEMENT OVERRIDE |
| |
| 1. JOURNAL ENTRY TESTING 2. RETROSPECTIVE ESTIMATE REVIEW 3. BUSINESS RATIONALE |
| Test non-standard, post-closing, Compare prior-year estimates Evaluate significant |
| and weekend/evening manual JEs to actual subsequent outcomes to unusual transactions |
| for fraud characteristics detect cumulative management bias lacking economic logic |
+-------------------------------------------------------------------------------------------------+
1. Testing Journal Entries & Adjustments
- The auditor must understand the entity's financial reporting process and controls over journal entries.
- Target High-Risk Entries: Examine manual, non-standard, or post-closing entries made directly to the general ledger or financial statement consolidation workpapers.
- Characteristics of Fraudulent Entries:
- Entries made to unrelated, unusual, or inactive accounts.
- Entries made by individuals who do not normally make accounting entries (e.g., the CEO or IT director).
- Entries recorded at period-end or post-closing with little or no explanation or supporting documentation.
- Entries made before or during the preparation of financial statements that have no account numbers.
- Entries containing round numbers, numbers ending in 999, or consistent amounts just below supervisory approval thresholds.
2. Reviewing Accounting Estimates for Bias (Retrospective Review)
- Accounting estimates involve significant management discretion, providing substantial opportunity for bias.
- The Retrospective Review: The auditor must perform a retrospective review of management judgments and assumptions reflected in the financial statements of the prior year.
- Audit Objective: Compare prior-year estimates (e.g., allowance for doubtful accounts, inventory obsolescence reserves, warranty liabilities) to actual subsequent outcomes. The goal is not to question past professional judgment, but to determine whether a cumulative, multi-year pattern of management bias exists (e.g., consistently under-reserving when earnings are weak and over-reserving when earnings are strong to create "cookie jar" reserves).
3. Evaluating the Business Rationale for Significant Unusual Transactions
- The auditor must evaluate transactions outside the normal course of business or that appear unusual given the auditor's understanding of the entity and its environment.
- Forensic Assessment: Determine whether the transactions involve related parties, lack economic substance, or are engineered specifically to achieve improper financial reporting outcomes (e.g., selling an asset to an offshore special purpose vehicle at an inflated price with an undisclosed buyback agreement).
6. Overall Responses vs. Assertion-Level Responses
When the auditor identifies assessed risks of material misstatement due to fraud, responses operate on two distinct levels:
Overall Responses (Engagement-Wide Level)
- Staffing and Supervision: Assign personnel with specialized forensic or industry skills; increase direct supervision by managers and partners.
- Evaluating Accounting Policies: Scrutinize management's selection and application of accounting policies, particularly those involving subjective measurements or revenue recognition.
- Incorporating Unpredictability:
- Perform substantive tests on selected accounts, locations, or assertions that would not otherwise be tested (e.g., accounts below tolerable misstatement).
- Vary the timing of audit testing (e.g., perform inventory counts unannounced or on different dates than prior years).
- Change sampling methodologies or test 100% of an account using Audit Data Analytics (ADA).
- Request confirmations from non-traditional sources or perform unannounced site visits.
Assertion-Level Responses (Specific Accounts & Cycles)
- Nature: Obtain more reliable, external third-party evidence (e.g., direct bank and customer confirmations, physical asset inspections) rather than relying on internal documentation.
- Timing: Perform substantive procedures at or near period-end rather than at an interim date, minimizing the roll-forward period where unmonitored manipulation could occur.
- Extent: Increase sample sizes, expand data analytics to test full transaction populations, or lower tolerable misstatement.
7. Communication Hierarchy & Professional Protocols
When the auditor identifies or obtains evidence indicating fraud, AU-C 240 dictates a strict reporting hierarchy based on the seniority of the perpetrator and the materiality of the act:
The Mandatory Communication Protocol
FRAUD IDENTIFIED OR SUSPECTED
|
+--------------------------+--------------------------+
| |
[ INVOLVES SENIOR MANAGEMENT ] [ INVOLVES LOWER-LEVEL EMPLOYEES ]
| |
REPORT DIRECTLY TO: IS THE FRAUD MATERIAL?
THOSE CHARGED WITH GOVERNANCE |
(Audit Committee) +-----------------+-----------------+
| | |
*MANDATORY EVEN IF $1!* [ YES ] [ NO ]
Quantitative materiality is | |
completely IRRELEVANT when REPORT DIRECTLY TO: REPORT TO:
management integrity is THOSE CHARGED WITH GOVERNANCE APPROPRIATE MANAGEMENT
compromised. (Audit Committee) (At least one level above)
1. Fraud Involving Senior Management
If the auditor obtains evidence of fraud involving executive management (CEO, CFO, controllers, internal audit directors), the auditor must communicate the matter directly to Those Charged With Governance (the Audit Committee) on a timely basis.
Critical Exam Rule: Dollar materiality does not apply. If the CFO steals $500 from petty cash or deliberately misstates an expense report by $1,000, it must be reported directly to the Audit Committee. Management integrity has been compromised, calling into question the reliability of all representations and internal controls.
2. Fraud Involving Lower-Level Employees
- Immaterial Fraud: If a retail cashier or warehouse clerk misappropriates $2,000, the auditor communicates the matter to an appropriate level of management—specifically at least one management level above the perpetrator. The Audit Committee does not need to be burdened with immaterial employee defalcations.
- Material Fraud: If an employee embezzlement scheme is material to the financial statements, the auditor must communicate the matter directly to Those Charged With Governance.
3. External Disclosures & Confidentiality Exceptions
Under the AICPA Code of Professional Conduct (ET 1.700.001), client confidentiality is paramount. The auditor's communication of fraud to parties outside the client entity is generally precluded, except under four strict legal and professional exceptions:
- Statutory/Regulatory Mandates: Complying with specific statutory requirements, such as Section 10A of the Securities Exchange Act of 1934 for SEC registrants or Form 8-K disclosures.
- Inquiry of Successor Auditor: Responding to communications from a prospective successor auditor in accordance with AU-C 210, provided client consent has been granted.
- Subpoena or Court Summons: Complying with a valid legal subpoena, court order, or formal grand jury proceeding.
- Government Funding Agencies: Complying with reporting requirements for audits of entities receiving federal financial assistance under Government Auditing Standards (GAGAS / Yellow Book) or the Single Audit Act.
During audit planning for a commercial manufacturer, the engagement team evaluates fraud risks in accordance with AU-C 240. Which of the following statements accurately characterizes the auditor's responsibilities regarding the mandatory fraud risk presumptions?
An audit senior is designing substantive procedures to respond specifically to the risk of management override of controls under AU-C 240. Which of the following procedures is a mandatory audit procedure required to address this pervasive risk?
During substantive testing of travel and entertainment expenditures, the audit team discovers that the Chief Financial Officer (CFO) submitted forged vendor receipts and diverted $12,500 of corporate funds into a personal bank account over the past fiscal year. The audit team determines that $12,500 is far below overall planning materiality ($250,000) and tolerable misstatement ($125,000). Under AU-C 240, what is the auditor's required communication responsibility?
During the mandatory engagement team brainstorming session required by AU-C 240, an audit junior notes that the client's management team has exhibited unquestioned integrity, transparent communication, and stellar character over a ten-year audit relationship. How should the engagement partner guide the team's mindset in response to this observation?