7.1 Fraud Risk Assessment, Fraud Triangle & ISA 240
Key Takeaways
ISA 240 and ISSAI 2240 define fraud as an intentional act involving deception to obtain an unjust or illegal advantage, distinguishing it from unintentional error solely by intent.
The two principal categories of intentional misstatements relevant to auditors are fraudulent financial reporting and misappropriation of assets, with management fraud presenting higher detection difficulty than employee fraud.
The Fraud Triangle conceptualizes fraud risk through three conditions: Incentive/Pressure, Opportunity (control weaknesses or override), and Rationalization/Attitude, which form the basis for mandatory engagement team brainstorming.
ISA 240 establishes two presumed fraud risks: revenue recognition (a rebuttable presumption requiring documentation if rebutted) and management override of internal controls (a non-rebuttable, universal risk present in all entities).
Auditing management override mandates three specific substantive procedures: testing journal entries and end-of-period adjustments, retrospectively reviewing accounting estimates for management bias, and evaluating the business rationale of significant unusual transactions.
7.1 Fraud Risk Assessment, Fraud Triangle & ISA 240
Core Principle: In public sector auditing, the discovery of fraud carries profound consequences that transcend financial loss. While private sector audits focus primarily on the true and fair view of balance sheets, public sector auditors must also safeguard democratic trust, uphold the rule of law, and protect public funds against deliberate predation. Under ISA 240 and ISSAI 2240, auditors must approach every engagement with rigorous professional skepticism, recognizing that sophisticated concealment and management override require targeted, unannounced, and forensic-grade audit procedures.
1. Professional Standards Framework: ISA 240 & ISSAI 2240
The international architecture governing fraud in financial statement audits is established by the International Auditing and Assurance Standards Board (IAASB) and adapted for Supreme Audit Institutions by INTOSAI:
- ISA 240: The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements establishes binding requirements for private and public sector auditors to identify, assess, and respond to the risks of material misstatement due to fraud.
- ISSAI 2240: INTOSAI's Practice Note to ISA 240, which contextualizes fraud standards within public sector environments. It expands the auditor's focus to encompass public expenditure fraud, abuse of delegated administrative power, grant subsidies, and reporting obligations to legislative and judicial authorities.
Primary Responsibility vs. Auditor's Responsibility
A foundational tenet of both ISA 240 and ISSAI 2240 is the strict demarcation of responsibilities:
- Those Charged with Governance and Management: Bear the primary responsibility for the prevention and detection of fraud. They are legally obligated to establish an ethical tone at the top, design and enforce robust internal control systems, and maintain continuous surveillance over operational risks.
- The Independent Auditor: Is responsible for obtaining reasonable assurance that the financial statements taken as a whole are free from material misstatement, whether caused by fraud or error. The auditor does not provide an absolute guarantee, nor does the auditor perform the duties of a judicial magistrate or criminal investigator.
2. Fraud vs. Error: The Defining Element of Intent
Misstatements in financial accounts and expenditure declarations arise from two distinct sources: fraud or error. Under ISA 240.11, the sole distinguishing criterion between fraud and error is intentionality.
+---------------------------------+
| FINANCIAL MISSTATEMENT |
+---------------------------------+
|
Is the underlying action intentional?
|
+-----------------+-----------------+
| |
NO (Unintentional) YES (Intentional)
| |
+-----------+ +-----------+
| ERROR | | FRAUD |
+-----------+ +-----------+
| Clerical | | Deception |
| Over- | | Collusion |
| sights | | Conceal- |
| Math | | ment |
| slips | | Override |
+-----------+ +-----------+
- Error: An unintentional misstatement in financial statements, including mathematical mistakes in data processing, clerical oversights, misinterpretation of complex regulatory clauses, or accidental omissions of accounting disclosures.
- Fraud: An intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage.
The Two Categories of Intentional Misstatements Under ISA 240
Auditors are concerned with two specific categories of fraud that generate material financial misstatements:
| Dimension | Fraudulent Financial Reporting | Misappropriation of Assets |
|---|---|---|
| Definition | Intentional misstatements or omissions of amounts or disclosures designed to deceive financial statement users | Theft or unauthorized diversion of an entity's assets for personal enrichment or unauthorized purposes |
| Perpetrators | Usually senior management, executives, or project directors | Usually operational employees, contractors, or mid-level managers (though management may also engage) |
| Common Mechanisms | Manipulation, falsification, or alteration of accounting records; deliberate misapplication of accounting principles; intentional omission of transactions | Embezzling receipts, stealing physical assets or intellectual property, submitting claims for ghost services, diverting public grants |
| Public Sector Context | Fictitious achievement of operational indicators, concealing budgetary deficits, inflating co-financing claims to avoid fund clawbacks | Embezzlement of EU structural funds, fictitious travel claims, ghost employees on technical assistance grants, payroll diversion |
| Detection Difficulty | Extremely high; frequently involves complex override of existing internal controls and collusion with external entities | Moderate to high; often concealed by falsified records or omitted reconciliations |
Inherent Limitations and Management Fraud
The risk of not detecting a material misstatement resulting from fraud is substantially higher than the risk of not detecting one resulting from error. Fraud often involves sophisticated, carefully organized schemes designed to deceive auditors—such as forgery, deliberate failure to record transactions, or intentional misrepresentations made to the auditor.
Furthermore, the risk of the auditor failing to detect management fraud is far greater than for employee fraud. Management occupies a position of organizational authority that permits it to override established controls, manipulate ledgers, and compel subordinates to assist in concealment.
3. The Fraud Triangle & Team Brainstorming
To identify where and how fraud might occur, auditors utilize the Fraud Triangle framework, originally formulated by criminologist Donald Cressey and codified in ISA 240 Appendix 1.
INCENTIVE / PRESSURE
/\ \
/ \ \
/ \ \
/ \ \
/ \ \
/ \ \
/ \ \
/ \ \
/________________\ \
OPPORTUNITY <------------------------------------> RATIONALIZATION / ATTITUDE
The Three Dimensions in Public Administration
-
Incentive / Pressure (The Motive):
- Public Sector Pressures: Extreme pressure on public managers to fully absorb EU funds before the n+2 or n+3 decommitment deadline (dégagement d'office); political mandates to hit employment or green transition targets; threats of project cancellation; budget cuts; personal financial difficulties of public procurement officials.
- Example: A regional authority risks losing EUR 15 million in European Regional Development Fund (ERDF) allocations unless funds are certified by December 31. This creates acute institutional pressure to accept incomplete infrastructure works and certify premature expenditures.
-
Opportunity (The Pathway):
- Vulnerabilities: Weak internal controls, absence of segregation of duties, complex organizational structures across multiple regional bodies, high staff turnover in audit authorities, management override capabilities, and deficient verification of delivery.
- Example: A sole project coordinator has exclusive authority to draft tender technical specifications, evaluate commercial bids, certify delivery of consulting reports, and approve supplier invoices without independent verification.
-
Rationalization / Attitude (The Justification):
- Mindset: Individuals develop an internal moral justification for illicit conduct. Common public administration rationalizations include: "EU regulations are excessively bureaucratic and detached from local realities," "We are diverting these funds to another noble public school project," or "Everyone in this sector splits contracts to get things done quickly."
Mandatory Engagement Team Brainstorming (ISA 240.15 / ISSAI 2240)
ISA 240 mandates that the engagement partner and key team members conduct a formal discussion (brainstorming session) during the planning phase:
- Core Objective: Exchange perspectives on how and where the entity's financial statements or expenditure declarations might be susceptible to material misstatement due to fraud.
- Focus Areas: Discussing known external and internal pressure factors; identifying operational areas vulnerable to management override; examining how assets could be misappropriated; and assessing red flags in procurement and grant disbursement.
- Tone Setting: The engagement partner must emphasize the continuous maintenance of professional skepticism throughout the audit, explicitly instructing team members to set aside any personal belief that management is inherently honest or that long-standing auditees are beyond suspicion.
4. Presumed Risks Under ISA 240: Revenue vs. Management Override
ISA 240 establishes two specific, explicit presumptions regarding fraud risks in an audit:
+---------------------------------------------------------------------------------------------------+
| ISA 240 PRESUMED FRAUD RISKS |
+---------------------------------------------------------------------------------------------------+
| 1. FRAUD IN REVENUE RECOGNITION (ISA 240.26) |
| - REBUTTABLE PRESUMPTION |
| - Must evaluate which revenue streams pose fraud risks |
| - If rebutted, the auditor MUST document the explicit justification in working papers (240.47)|
+---------------------------------------------------------------------------------------------------+
| 2. MANAGEMENT OVERRIDE OF INTERNAL CONTROLS (ISA 240.31) |
| - NON-REBUTTABLE PRESUMPTION |
| - Present in EVERY entity regardless of governance or internal control strength |
| - Requires mandatory substantive audit procedures tailored to override mechanisms |
+---------------------------------------------------------------------------------------------------+
Presumed Risk 1: Fraud in Revenue Recognition (ISA 240.26)
- Rule: Auditors must presume that there are risks of fraud in revenue recognition and evaluate which types of revenue, revenue transactions, or assertions give rise to such risks (such as improper cutoff, fictitious billings, or premature recognition).
- Rebuttability: This presumption is rebuttable. If the auditor concludes that the presumption does not apply—for instance, where an entity has a single, highly regulated revenue stream (such as a straightforward, fixed-rate lease of a single public asset)—the auditor may rebut the presumption. However, under ISA 240.47, the auditor must document the detailed rationale supporting this conclusion in the working papers.
- Public Sector Dimension (ISSAI 2240): Supreme audit institutions scrutinize sovereign revenues, including customs duties (Traditional Own Resources), VAT contributions, and corporate tax collections. Furthermore, in public spending bodies, auditors frequently transpose this risk assessment to the expenditure side, recognizing that the declaration and certification of grant expenditures poses parallel risks of artificial inflation.
Presumed Risk 2: Management Override of Controls (ISA 240.31)
- Rule: The risk of management override of controls is a non-rebuttable presumption. It is inherently present in all organizations without exception.
- Rationale: Management is uniquely positioned to commit fraud because it possesses the administrative power to manipulate accounting records and bypass controls that appear to function effectively for subordinate employees.
- Mandatory Substantive Procedures: ISA 240.32 mandates that the auditor design and execute three specific procedures to address management override:
-
Testing Journal Entries and Adjustments:
- Test the appropriateness of journal entries recorded in the general ledger and other adjustments made in the preparation of financial statements.
- Audit Target: Inquire about unusual journal entry activity; examine entries made at the end of a reporting period; test entries made by individuals who do not normally create journal entries; analyze entries with round numbers, unusual account combinations, or entries posted post-closing without clear descriptions.
-
Reviewing Accounting Estimates for Biases:
- Review accounting estimates, judgments, and underlying assumptions for evidence of management bias that could represent a material fraud risk.
- Audit Target: Perform a retrospective review of management's judgments and estimates reflected in the financial statements of the prior year (e.g., environmental remediation provisions, litigation contingencies, asset impairment models) to evaluate whether prior estimates reflect intentional bias when compared to actual outcomes.
-
Evaluating the Business Rationale of Significant Unusual Transactions:
- Scrutinize significant transactions outside the normal course of business for the entity, or that otherwise appear unusual given the auditor's understanding of the entity and its environment.
- Audit Target: Assess whether the economic and operational rationale (or lack thereof) suggests that the transactions may have been entered into to engage in fraudulent financial reporting or conceal misappropriation of assets (e.g., complex circular fund flows, off-balance sheet special purpose vehicles, or transactions with non-transparent offshore entities).
5. Fraud Red Flags in Public Sector Procurement & Grant Management
Public sector auditors must maintain heightened vigilance regarding behavioral, operational, and documentary warning indicators (red flags):
Procurement Red Flags
- Contract Splitting (Artificial Disaggregation): Dividing a major public works or service contract into multiple smaller lots just below statutory thresholds (such as EU Directive procurement thresholds) to evade mandatory competitive tendering and permit direct awards.
- Tailored Tender Specifications: Drafting technical specifications so narrow or idiosyncratic that only one pre-selected commercial bidder can satisfy them (e.g., specifying proprietary patents or precise dimensions irrelevant to functional performance).
- Bid-Rigging and Collusion Indicators:
- Competing bids showing identical formatting, identical typographical errors, or matching metadata timestamps.
- Bid prices clustered abnormally close together, followed by the lowest bidder inexplicably withdrawing their offer to allow a higher-priced co-conspirator to win.
- Systematic rotation of winning bids among a small cartel of local contractors across successive procurement tenders.
- Ghost Vendors and Shell Companies: Invoices submitted by entities with no physical commercial address, no employees, newly incorporated bank accounts, or corporate directors shared with the contracting authority's evaluation committee.
Grant Management & Expenditure Red Flags
- Double Funding: Submitting the exact same expenditure items, personnel timesheets, or capital invoices to two different financing streams (e.g., claiming a single research activity under both Horizon Europe and national regional development subsidies).
- Fictitious Expenditure: Submitting falsified timesheets for non-existent project researchers ("ghost workers"), forged training attendance registers, or invoices for consulting reports plagiarized from open internet sources.
- Year-End Expenditure Surges: Unexplained spikes in procurement awards and grant disbursements occurring during the final weeks of the fiscal year or immediately prior to multiannual fund closure deadlines, unaccompanied by physical verification of deliverables.
Under ISA 240 and ISSAI 2240, what is the fundamental distinguishing factor between fraud and error in financial statements?
The intentionality of the underlying action that results in the misstatement
The total monetary amount of the financial distortion relative to materiality
Whether the misstatement occurred in a procurement contract or a staff payroll account
Whether the transaction was approved by an internal auditor or an external controller
How does ISA 240 treat the risk of management override of internal controls compared to the risk of fraud in revenue recognition?
Both management override of controls and revenue recognition are treated as rebuttable presumptions that can be dismissed after conducting initial walkthrough tests
Management override of controls is a non-rebuttable risk presumed present in all entities, whereas fraud in revenue recognition is a rebuttable presumption that requires documented justification if rebutted
Management override of controls is an optional assessment reserved only for listed private corporations, whereas revenue recognition fraud is non-rebuttable across all public sector bodies
Neither risk is presumed by international standards, as the auditor must establish fraud risk exclusively through empirical forensic investigations
Which set of substantive procedures is explicitly required by ISA 240 to address the risk of management override of internal controls?
Conducting physical stock counts of office supplies, auditing external vendor websites, and checking employee biometric badges
Recalculating employee tax withholdings, re-interviewing all shortlisted procurement applicants, and inspecting bank vaults
Testing the appropriateness of journal entries and adjustments, reviewing accounting estimates for biases, and evaluating the business rationale of significant unusual transactions
Reviewing email correspondence between junior staff, reconciling petty cash floats, and updating building insurance policies
During an audit of an EU-funded regional development project, an auditor observes that a works contract worth EUR 4.8 million was divided into ten separate contracts of EUR 480,000 awarded through direct negotiation without competitive tendering. Furthermore, the winning contractors submitted consecutively numbered invoices with identical typographical errors. Which red flag does this scenario illustrate?
Routine administrative simplification permitted under EU cohesion rules
Unintentional clerical error resulting from shared accounting software templates
Authorized accelerated procurement under crisis emergency provisions
Contract splitting to circumvent EU public procurement thresholds combined with collusive bidding indicators
Sections you finish are checked off in the contents.