top of page
Search

PCAOB AS 2401: What Auditors Must Do When Considering Fraud in a Financial Statement Audit

Fraud risk is not a box auditors can check during planning and then ignore for the rest of the engagement. Under PCAOB Auditing Standard AS 2401, auditors must consider the possibility of material misstatement caused by fraud throughout the financial statement audit.


That responsibility extends from audit planning and fraud-risk assessment through the performance of audit procedures, evaluation of audit evidence, communication of suspected fraud, and completion of the audit documentation.


Corporate Compliance Seminars’ two-CPE webinar, PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit, gives external auditors and other financial professionals a practical review of these requirements.


Fraud Is Different From Error


The primary distinction between fraud and error is intent.


An error is an unintentional misstatement. Fraud involves an intentional act that results in a material misstatement of the financial statements. Fraud is also harder to detect because the individuals involved may deliberately conceal it through:

  • Falsified or altered documents

  • Collusion between employees or third parties

  • Misleading representations

  • Intentional omissions

  • Complex or unusual transactions

  • Management override of internal controls

  • Unauthorized journal entries or financial statement adjustments


Auditors do not make legal determinations about whether fraud has occurred. Their responsibility concerns fraud that causes the financial statements to be materially misstated.


The PCAOB AS 2401 standard identifies two types of fraud-related misstatements relevant to an audit:

  1. Fraudulent financial reporting

  2. Misappropriation of assets


Fraudulent Financial Reporting

Fraudulent financial reporting involves intentional misstatements or omissions designed to deceive users of the financial statements.


It may include:

  • Altering accounting records or supporting documents

  • Recording transactions that did not occur

  • Omitting transactions or disclosures

  • Improperly recognizing revenue

  • Manipulating accounting estimates

  • Misclassifying transactions

  • Concealing liabilities or expenses

  • Intentionally misapplying accounting principles


Fraudulent reporting does not always begin with a large conspiracy. Management may initially rationalize an improper accounting treatment as aggressive, temporary, or necessary to meet a short-term objective. What begins as a “temporary adjustment” can become a material financial statement fraud.


Misappropriation of Assets

Misappropriation of assets involves theft or improper use of an organization’s resources when the resulting misstatement is material to the financial statements.


Examples include:

  • Embezzling cash receipts

  • Creating fictitious vendors

  • Submitting fraudulent expense reports

  • Stealing inventory or equipment

  • Diverting customer payments

  • Causing the company to pay for goods or services it never received


Asset misappropriation is often concealed by false invoices, altered accounting records, fictitious transactions, missing documentation, or deliberate circumvention of internal controls.


The Three Conditions Commonly Associated With Fraud

AS 2401 discusses three conditions that are generally present when fraud occurs:


Incentive or Pressure

Management or employees may face pressure to meet earnings targets, maintain loan covenants, qualify for compensation, conceal poor performance, or satisfy market expectations.


Personal financial problems, unrealistic performance goals, job insecurity, and pressure from senior management may also create incentives to commit fraud.


Opportunity

Fraud requires an opportunity to commit and conceal the act. Opportunities may arise from:

  • Weak segregation of duties

  • Ineffective internal controls

  • Poor oversight

  • Excessive access to accounting systems

  • Inadequate review of journal entries

  • Complex organizational structures

  • Significant related-party transactions

  • Management’s ability to override established controls


Attitude or Rationalization

Individuals involved in fraud frequently develop a justification for their actions. They may believe that they are only borrowing the money, deserve additional compensation, are protecting the organization, or will correct the financial statements in a later period.

Auditors may not be able to directly observe a person’s rationalization. However, they should remain alert to behaviors, circumstances, and management attitudes that may indicate an elevated fraud risk.


Professional Skepticism Is Essential

Auditors must approach the engagement with professional skepticism—a questioning mind and a critical assessment of audit evidence.


This does not mean assuming that management is dishonest. It also does not mean assuming that management is unquestionably honest.


Auditors should critically evaluate the evidence, investigate inconsistencies, and avoid accepting explanations that are unsupported or contradicted by other information.


Warning signs may include:

  • Management providing inconsistent explanations

  • Missing or altered documentation

  • Unusual delays in responding to audit requests

  • Transactions lacking a clear business purpose

  • Significant period-end adjustments

  • Excessive pressure to complete the audit

  • Restrictions on access to personnel or records

  • Complaints or tips alleging misconduct

  • Disagreements between management and accounting personnel

  • Transactions with undisclosed related parties


The Engagement-Team Fraud Discussion

The audit team’s discussion of fraud risk should be more than a routine administrative meeting.


Team members should discuss how and where the financial statements could be materially misstated due to fraud, how management might conceal fraudulent reporting, and how company assets could be misappropriated.


A meaningful discussion should consider:

  • The company’s financial performance and operating environment

  • Incentives and pressures affecting management

  • Opportunities to override internal controls

  • Unusual or complex transactions

  • Related-party relationships

  • Vulnerable accounts and disclosures

  • Revenue-recognition practices

  • Management estimates and assumptions

  • Information obtained from prior audits

  • Allegations, complaints, or whistleblower reports


The engagement partner should help establish an environment in which team members can openly identify concerns and challenge assumptions.


Revenue Recognition and Fraud Risk

Improper revenue recognition remains one of the most important areas of fraud risk in financial statement audits.


Auditors should understand the company’s revenue streams, contractual terms, sales practices, return provisions, side agreements, performance obligations, cutoff procedures, and related internal controls.


Potential responses may include:

  • Analyzing revenue by month, location, product, or customer

  • Examining transactions recorded near period-end

  • Confirming relevant contractual terms with customers

  • Looking for side agreements or unusual return rights

  • Interviewing sales, marketing, and legal personnel

  • Testing shipping and cutoff documentation

  • Evaluating controls over electronically processed revenue

  • Investigating unexpected trends or relationships


Audit procedures must be tailored to the company’s operations and the specific fraud risks identified.


Management Override of Internal Controls

Management may have the authority to initiate, approve, record, or conceal transactions. It may also be able to override controls that appear to be properly designed and operating effectively.


Because management override can occur unpredictably, auditors must perform procedures specifically addressing this risk.


These procedures include:

  • Testing journal entries and other adjustments

  • Reviewing accounting estimates for evidence of bias

  • Evaluating the business rationale for significant unusual transactions


Management override is not eliminated simply because the company has strong internal controls. Effective controls may reduce risk, but management’s position gives it a unique ability to manipulate the financial reporting process.


Journal-Entry Testing Is Not Optional

Fraudulent financial reporting often involves inappropriate journal entries or other adjustments.


Auditors should understand:

  • Who can create and post journal entries

  • Who approves entries

  • Which accounts are commonly used

  • How system-generated and manual entries are processed

  • Whether entries can be posted after the books are closed

  • How consolidating and financial statement adjustments are recorded

  • What controls exist over nonstandard entries


Entries that may warrant additional attention include those:

  • Posted to unusual or seldom-used accounts

  • Made by individuals who do not ordinarily create entries

  • Recorded at or after period-end

  • Containing round numbers

  • Lacking explanations or supporting documentation

  • Affecting accounts with significant estimates

  • Posted outside the normal course of business

  • Made directly to financial statement drafts

  • Involving intercompany or related-party accounts


Journal-entry testing should not automatically be limited to the last few days of the reporting period. Fraudulent entries can occur throughout the year and may be followed by additional entries intended to conceal them.


Accounting Estimates and Management Bias

Accounting estimates provide opportunities for management judgment. They can also provide opportunities to manipulate financial results.


Auditors should evaluate estimates involving areas such as:

  • Allowances and reserves

  • Fair-value measurements

  • Asset impairments

  • Warranty liabilities

  • Pension obligations

  • Credit losses

  • Environmental liabilities

  • Acquisition-related valuations


A retrospective review of prior-period estimates may help the auditor determine whether management’s past judgments indicate a pattern of bias.


An estimate does not need to be individually unreasonable to raise concern. A series of estimates consistently positioned at the optimistic or pessimistic end of an acceptable range may indicate an intentional effort to achieve a desired financial result.


Responding to Identified Fraud Risks

Once a fraud risk is identified, the auditor must connect that risk to the affected accounts, disclosures, and assertions. The auditor must then design procedures responsive to the specific risk.


Possible responses include:

  • Performing procedures on an unannounced basis

  • Changing the timing of audit testing

  • Increasing sample sizes

  • Obtaining more persuasive evidence

  • Using disaggregated data in analytical procedures

  • Confirming information with third parties

  • Interviewing employees outside the accounting department

  • Testing additional locations or business units

  • Using audit data analytics

  • Involving forensic, valuation, information technology, or other specialists


Generic audit procedures are not enough when they fail to address the method by which the suspected fraud could occur.


Communicating Possible Fraud

When auditors identify possible fraud, they must determine the appropriate level of management or governance to notify.


Communication may need to involve:

  • Senior management

  • The audit committee

  • The board of directors

  • Legal counsel

  • Regulatory authorities

  • The Securities and Exchange Commission


The appropriate communication depends on the nature, significance, and parties involved. Suspected fraud involving senior management cannot be handled in the same manner as an isolated matter involving a lower-level employee.


Documentation Must Tell the Story

Audit documentation should demonstrate how the engagement team considered fraud throughout the audit.


The workpapers should address:

  • The engagement-team fraud discussion

  • Procedures performed to obtain information about fraud risks

  • Identified and assessed fraud risks

  • Audit responses linked to those risks

  • Revenue-recognition conclusions

  • Management-override procedures

  • Journal entries and adjustments selected for testing

  • Evaluation of accounting estimates and management bias

  • Communications made to management and the audit committee

  • The effect of identified fraud or suspected fraud on the audit


A generic fraud checklist does not establish that the auditor exercised professional skepticism or responded appropriately to the risks.


Strengthen Your Understanding of PCAOB AS 2401

Fraud consideration affects audit planning, risk assessment, internal-control testing, substantive procedures, audit evidence, communications, and documentation.

Corporate Compliance Seminars’ PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit webinar provides two CPE credits and practical guidance for applying the standard.


The webinar is designed for external auditors, audit associates, senior associates, managers, partners, engagement quality reviewers, internal auditors, corporate accounting professionals, controllers, and other professionals involved in financial reporting and audit compliance.


Do not let fraud consideration become a boilerplate section of the audit file. Learn how to identify the risks, connect them to the financial statements, design responsive procedures, evaluate the evidence, and document the work.


 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page