PCAOB AS 2401: What Auditors Must Do When Considering Fraud in a Financial Statement Audit
- John C. Blackshire, Jr.

- 1 day ago
- 7 min read
Fraud risk is not a box auditors can check during planning and then ignore for the rest of the engagement. Under PCAOB Auditing Standard AS 2401, auditors must consider the possibility of material misstatement caused by fraud throughout the financial statement audit.
That responsibility extends from audit planning and fraud-risk assessment through the performance of audit procedures, evaluation of audit evidence, communication of suspected fraud, and completion of the audit documentation.
Corporate Compliance Seminars’ two-CPE webinar, PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit, gives external auditors and other financial professionals a practical review of these requirements.
Fraud Is Different From Error
The primary distinction between fraud and error is intent.
An error is an unintentional misstatement. Fraud involves an intentional act that results in a material misstatement of the financial statements. Fraud is also harder to detect because the individuals involved may deliberately conceal it through:
Falsified or altered documents
Collusion between employees or third parties
Misleading representations
Intentional omissions
Complex or unusual transactions
Management override of internal controls
Unauthorized journal entries or financial statement adjustments
Auditors do not make legal determinations about whether fraud has occurred. Their responsibility concerns fraud that causes the financial statements to be materially misstated.
The PCAOB AS 2401 standard identifies two types of fraud-related misstatements relevant to an audit:
Fraudulent financial reporting
Misappropriation of assets
Fraudulent Financial Reporting
Fraudulent financial reporting involves intentional misstatements or omissions designed to deceive users of the financial statements.
It may include:
Altering accounting records or supporting documents
Recording transactions that did not occur
Omitting transactions or disclosures
Improperly recognizing revenue
Manipulating accounting estimates
Misclassifying transactions
Concealing liabilities or expenses
Intentionally misapplying accounting principles
Fraudulent reporting does not always begin with a large conspiracy. Management may initially rationalize an improper accounting treatment as aggressive, temporary, or necessary to meet a short-term objective. What begins as a “temporary adjustment” can become a material financial statement fraud.
Misappropriation of Assets
Misappropriation of assets involves theft or improper use of an organization’s resources when the resulting misstatement is material to the financial statements.
Examples include:
Embezzling cash receipts
Creating fictitious vendors
Submitting fraudulent expense reports
Stealing inventory or equipment
Diverting customer payments
Causing the company to pay for goods or services it never received
Asset misappropriation is often concealed by false invoices, altered accounting records, fictitious transactions, missing documentation, or deliberate circumvention of internal controls.
The Three Conditions Commonly Associated With Fraud
AS 2401 discusses three conditions that are generally present when fraud occurs:
Incentive or Pressure
Management or employees may face pressure to meet earnings targets, maintain loan covenants, qualify for compensation, conceal poor performance, or satisfy market expectations.
Personal financial problems, unrealistic performance goals, job insecurity, and pressure from senior management may also create incentives to commit fraud.
Opportunity
Fraud requires an opportunity to commit and conceal the act. Opportunities may arise from:
Weak segregation of duties
Ineffective internal controls
Poor oversight
Excessive access to accounting systems
Inadequate review of journal entries
Complex organizational structures
Significant related-party transactions
Management’s ability to override established controls
Attitude or Rationalization
Individuals involved in fraud frequently develop a justification for their actions. They may believe that they are only borrowing the money, deserve additional compensation, are protecting the organization, or will correct the financial statements in a later period.
Auditors may not be able to directly observe a person’s rationalization. However, they should remain alert to behaviors, circumstances, and management attitudes that may indicate an elevated fraud risk.
Professional Skepticism Is Essential
Auditors must approach the engagement with professional skepticism—a questioning mind and a critical assessment of audit evidence.
This does not mean assuming that management is dishonest. It also does not mean assuming that management is unquestionably honest.
Auditors should critically evaluate the evidence, investigate inconsistencies, and avoid accepting explanations that are unsupported or contradicted by other information.
Warning signs may include:
Management providing inconsistent explanations
Missing or altered documentation
Unusual delays in responding to audit requests
Transactions lacking a clear business purpose
Significant period-end adjustments
Excessive pressure to complete the audit
Restrictions on access to personnel or records
Complaints or tips alleging misconduct
Disagreements between management and accounting personnel
Transactions with undisclosed related parties
The Engagement-Team Fraud Discussion
The audit team’s discussion of fraud risk should be more than a routine administrative meeting.
Team members should discuss how and where the financial statements could be materially misstated due to fraud, how management might conceal fraudulent reporting, and how company assets could be misappropriated.
A meaningful discussion should consider:
The company’s financial performance and operating environment
Incentives and pressures affecting management
Opportunities to override internal controls
Unusual or complex transactions
Related-party relationships
Vulnerable accounts and disclosures
Revenue-recognition practices
Management estimates and assumptions
Information obtained from prior audits
Allegations, complaints, or whistleblower reports
The engagement partner should help establish an environment in which team members can openly identify concerns and challenge assumptions.
Revenue Recognition and Fraud Risk
Improper revenue recognition remains one of the most important areas of fraud risk in financial statement audits.
Auditors should understand the company’s revenue streams, contractual terms, sales practices, return provisions, side agreements, performance obligations, cutoff procedures, and related internal controls.
Potential responses may include:
Analyzing revenue by month, location, product, or customer
Examining transactions recorded near period-end
Confirming relevant contractual terms with customers
Looking for side agreements or unusual return rights
Interviewing sales, marketing, and legal personnel
Testing shipping and cutoff documentation
Evaluating controls over electronically processed revenue
Investigating unexpected trends or relationships
Audit procedures must be tailored to the company’s operations and the specific fraud risks identified.
Management Override of Internal Controls
Management may have the authority to initiate, approve, record, or conceal transactions. It may also be able to override controls that appear to be properly designed and operating effectively.
Because management override can occur unpredictably, auditors must perform procedures specifically addressing this risk.
These procedures include:
Testing journal entries and other adjustments
Reviewing accounting estimates for evidence of bias
Evaluating the business rationale for significant unusual transactions
Management override is not eliminated simply because the company has strong internal controls. Effective controls may reduce risk, but management’s position gives it a unique ability to manipulate the financial reporting process.
Journal-Entry Testing Is Not Optional
Fraudulent financial reporting often involves inappropriate journal entries or other adjustments.
Auditors should understand:
Who can create and post journal entries
Who approves entries
Which accounts are commonly used
How system-generated and manual entries are processed
Whether entries can be posted after the books are closed
How consolidating and financial statement adjustments are recorded
What controls exist over nonstandard entries
Entries that may warrant additional attention include those:
Posted to unusual or seldom-used accounts
Made by individuals who do not ordinarily create entries
Recorded at or after period-end
Containing round numbers
Lacking explanations or supporting documentation
Affecting accounts with significant estimates
Posted outside the normal course of business
Made directly to financial statement drafts
Involving intercompany or related-party accounts
Journal-entry testing should not automatically be limited to the last few days of the reporting period. Fraudulent entries can occur throughout the year and may be followed by additional entries intended to conceal them.
Accounting Estimates and Management Bias
Accounting estimates provide opportunities for management judgment. They can also provide opportunities to manipulate financial results.
Auditors should evaluate estimates involving areas such as:
Allowances and reserves
Fair-value measurements
Asset impairments
Warranty liabilities
Pension obligations
Credit losses
Environmental liabilities
Acquisition-related valuations
A retrospective review of prior-period estimates may help the auditor determine whether management’s past judgments indicate a pattern of bias.
An estimate does not need to be individually unreasonable to raise concern. A series of estimates consistently positioned at the optimistic or pessimistic end of an acceptable range may indicate an intentional effort to achieve a desired financial result.
Responding to Identified Fraud Risks
Once a fraud risk is identified, the auditor must connect that risk to the affected accounts, disclosures, and assertions. The auditor must then design procedures responsive to the specific risk.
Possible responses include:
Performing procedures on an unannounced basis
Changing the timing of audit testing
Increasing sample sizes
Obtaining more persuasive evidence
Using disaggregated data in analytical procedures
Confirming information with third parties
Interviewing employees outside the accounting department
Testing additional locations or business units
Using audit data analytics
Involving forensic, valuation, information technology, or other specialists
Generic audit procedures are not enough when they fail to address the method by which the suspected fraud could occur.
Communicating Possible Fraud
When auditors identify possible fraud, they must determine the appropriate level of management or governance to notify.
Communication may need to involve:
Senior management
The audit committee
The board of directors
Legal counsel
Regulatory authorities
The Securities and Exchange Commission
The appropriate communication depends on the nature, significance, and parties involved. Suspected fraud involving senior management cannot be handled in the same manner as an isolated matter involving a lower-level employee.
Documentation Must Tell the Story
Audit documentation should demonstrate how the engagement team considered fraud throughout the audit.
The workpapers should address:
The engagement-team fraud discussion
Procedures performed to obtain information about fraud risks
Identified and assessed fraud risks
Audit responses linked to those risks
Revenue-recognition conclusions
Management-override procedures
Journal entries and adjustments selected for testing
Evaluation of accounting estimates and management bias
Communications made to management and the audit committee
The effect of identified fraud or suspected fraud on the audit
A generic fraud checklist does not establish that the auditor exercised professional skepticism or responded appropriately to the risks.
Strengthen Your Understanding of PCAOB AS 2401
Fraud consideration affects audit planning, risk assessment, internal-control testing, substantive procedures, audit evidence, communications, and documentation.
Corporate Compliance Seminars’ PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit webinar provides two CPE credits and practical guidance for applying the standard.
The webinar is designed for external auditors, audit associates, senior associates, managers, partners, engagement quality reviewers, internal auditors, corporate accounting professionals, controllers, and other professionals involved in financial reporting and audit compliance.
Do not let fraud consideration become a boilerplate section of the audit file. Learn how to identify the risks, connect them to the financial statements, design responsive procedures, evaluate the evidence, and document the work.
Register for the two-CPE webinar: PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit
Comments