Skip to main content
Category: Internal Audit

Consideration of Fraud

Also known as: Consideration of Fraud in a Financial Statement Audit, AU-C 240, SAS No. 99
Simply put

Consideration of fraud refers to the responsibility of an external auditor to think about, and actively look for, the risk that fraud could cause a company's financial statements to be materially wrong. It requires the auditor to approach the audit with professional skepticism, plan procedures to address possible fraud, and respond when signs of fraud appear. It is an auditing responsibility performed by the independent auditor, and it is distinct from management's own responsibility to prevent and detect fraud.

Formal definition

Consideration of Fraud is the auditing requirement, in a financial statement audit, that the external independent auditor identify and assess the risks of material misstatement due to fraud, design and perform audit procedures responsive to those assessed risks, and evaluate audit evidence with professional skepticism. In the United States, this responsibility is addressed for audits of non-issuers by AICPA AU-C 240, 'Consideration of Fraud in a Financial Statement Audit' (which superseded SAS No. 99), and for audits of public companies (issuers) by the Public Company Accounting Oversight Board (PCAOB) Auditing Standard AS 2401, 'Consideration of Fraud in a Financial Statement Audit.' The standards commonly address types of fraud relevant to financial reporting, such as fraudulent financial reporting and misappropriation of assets. This is an assurance activity carried out by the auditor and should not be confused with management's responsibility to design and operate controls that prevent and detect fraud; consideration of fraud provides reasonable, not absolute, assurance and does not guarantee detection of all fraud. Note that securities regulators such as the U.S. Securities and Exchange Commission may issue statements on auditors' fraud-related responsibilities, but auditing standards in this area are set by the AICPA (for non-issuers) and the PCAOB (for issuers), not by the SEC. This entry defines the concept and its governing standards and does not cover specific audit procedures, engagement-level implementation, or legal definitions of fraud as a civil tort or criminal offense.

Why it matters

Consideration of fraud is central to the credibility of financial statement audits because material misstatements arising from fraud can distort the picture investors, lenders, and other stakeholders rely on. Unlike errors, fraud is intentional and often concealed through collusion, override of controls, or falsified documentation, which makes it inherently harder to detect. Placing an explicit fraud-consideration responsibility on the external independent auditor is intended to sharpen professional skepticism and reduce the chance that fraudulent financial reporting or misappropriation of assets goes unaddressed during the audit.

The requirement also matters because it draws a firm line between assurance and management responsibilities. The external auditor's job is to identify and assess the risks of material misstatement due to fraud and to respond to them; it is not the auditor's role to design or operate the controls that prevent and detect fraud, which remains management's responsibility. Understanding this distinction helps users avoid the expectation gap in which stakeholders assume an unqualified audit opinion guarantees that no fraud exists.

Equally important is recognizing the limits of the concept. Consideration of fraud is designed to provide reasonable, not absolute, assurance, and it does not guarantee that all fraud will be detected. Concealment, collusion, and management override can defeat otherwise well-planned procedures. Users of audit reports should therefore treat fraud consideration as a disciplined, risk-based responsibility rather than a warranty against fraud.

Who it's relevant to

External auditors and audit firms
Independent auditors of both non-issuers and issuers carry out consideration of fraud as a core assurance responsibility. Which standard applies matters in practice: AU-C 240 governs non-issuer audits, while PCAOB AS 2401 governs audits of public issuers. Auditors apply professional skepticism when planning and performing procedures responsive to assessed fraud risks.
Management and those charged with governance
Company management is responsible for designing and operating controls that prevent and detect fraud, which is distinct from the auditor's consideration of fraud. Boards and audit committees benefit from understanding that the auditor provides reasonable, not absolute, assurance and does not guarantee detection of all fraud.
Investors, lenders, and other financial statement users
Users relying on audited financial statements should understand what fraud consideration does and does not provide. An audit addresses the risk of material misstatement due to fraud but is not a warranty that no fraud exists, particularly where concealment or collusion is involved.
Compliance and regulatory specialists
Professionals tracking assurance obligations should note the division of standard-setting authority: the AICPA sets standards for non-issuer audits and the PCAOB for issuer audits, while the SEC may issue statements on fraud-related responsibilities without setting the auditing standards themselves.

Inside Consideration of Fraud

Auditor's Responsibility to Consider Fraud
Under external financial-statement auditing standards, the auditor is responsible for obtaining reasonable assurance that the financial statements as a whole are free from material misstatement, whether caused by fraud or error. In the United States, AU-C section 240 (issued by the AICPA Auditing Standards Board) applies to audits of non-issuers, while PCAOB Auditing Standard AS 2401 governs the consideration of fraud in audits of public issuers. This is an external assurance responsibility and should not be conflated with management's or internal audit's roles.
Two Types of Misstatement from Fraud
Applicable standards commonly distinguish misstatements arising from fraudulent financial reporting (intentional misstatement or omission to deceive users) from those arising from misappropriation of assets (theft of an entity's assets). The auditor's procedures typically address both, though the nature and extent may differ.
Professional Skepticism
The auditor is expected to maintain an attitude of professional skepticism throughout the engagement, recognizing the possibility that a material misstatement due to fraud could exist regardless of past experience with the entity's honesty and integrity.
Fraud Risk Identification and Assessment
The engagement team typically discusses the susceptibility of the financial statements to material misstatement due to fraud and identifies and assesses fraud risks. The fraud risk factors are often considered in terms of incentives or pressures, opportunities, and attitudes or rationalizations.
Response to Assessed Risks
The auditor designs and performs procedures responsive to assessed fraud risks, which may include addressing the risk of management override of controls, incorporating an element of unpredictability, and evaluating whether the results of procedures indicate fraud risk.
Distinction Between Fraud and Error
The defining characteristic that distinguishes fraud from error is intent. Fraud involves an intentional act, whereas error refers to an unintentional misstatement. The auditor is concerned with fraud that causes a material misstatement, not with making legal determinations of whether fraud has occurred.

Common questions

Answers to the questions practitioners most commonly ask about Consideration of Fraud.

Does 'consideration of fraud' apply to internal auditors?
In its standard-setting sense, the term refers to the responsibilities of external financial-statement auditors, not internal audit. In the United States, AU-C 240 (issued by the AICPA Auditing Standards Board) applies to audits of nonissuers, while PCAOB Auditing Standard AS 2401 governs fraud considerations in audits of public issuers. Internal auditors may address fraud within their own remit, but they do so under different professional guidance and are not the subject of these external-audit requirements. The classification matters because it defines the scope, independence, and objectives at play.
Does the SEC set the auditing standards that require auditors to consider fraud?
No. The SEC does not set auditing standards. For U.S. public-issuer audits, fraud-consideration requirements are established by the PCAOB through AS 2401; for audits of nonissuers, they are established by the AICPA Auditing Standards Board through AU-C 240. SEC staff have issued statements touching on fraud, but references to such statements should not be read as giving the SEC a standard-setting role over audit methodology.
Which standard applies when planning an audit, AU-C 240 or AS 2401?
This depends on the type of entity being audited. Audits of U.S. public issuers typically fall under PCAOB standards, including AS 2401. Audits of nonissuers typically fall under AICPA standards, including AU-C 240. The applicable framework should be confirmed based on the entity's status and jurisdiction, and other jurisdictions apply their own equivalent standards.
How does an auditor's consideration of fraud typically fit into the engagement?
It is commonly integrated throughout the engagement rather than treated as a single step. This often includes assessing risks of material misstatement due to fraud, discussion among the engagement team, and designing responses to identified risks. The specifics vary by standard and engagement; this entry does not prescribe implementation methodology.
Does consideration of fraud mean the auditor is responsible for detecting all fraud?
No. The requirement concerns obtaining reasonable assurance about whether the financial statements are free of material misstatement, whether caused by fraud or error. Because of the inherent limitations of an audit, even a properly planned and performed audit may not detect all fraud, particularly where collusion or management override is involved. The standards address the auditor's responsibilities, not a guarantee of detection.
What is out of scope for this term?
This entry addresses the concept as it applies to external financial-statement auditors and does not cover fraud investigation techniques, forensic accounting engagements, internal anti-fraud controls maintained by management, or legal advice. It also does not substitute for the text of the applicable standards (such as AU-C 240 or AS 2401) or for jurisdiction-specific requirements.

Common misconceptions

Consideration of fraud is primarily an internal audit or management function under these standards.
The consideration of fraud described in AU-C 240 and PCAOB AS 2401 is an external financial-statement audit responsibility. It should not be confused with management's responsibility to prevent and detect fraud, nor with internal audit's assurance and advisory activities, which are distinct roles.
A single U.S. standard covers fraud consideration for all audits.
In the United States the applicable standard depends on the type of entity. AU-C section 240, issued by the AICPA Auditing Standards Board, applies to audits of non-issuers, while PCAOB Auditing Standard AS 2401 applies to audits of public issuers. Requirements can also differ under other jurisdictions' standards.
The auditor's consideration of fraud guarantees that any fraud will be detected.
The standards require reasonable, not absolute, assurance. Because of the inherent limitations of an audit and the concealment characteristics of fraud, a properly conducted audit may not detect a material misstatement due to fraud, particularly where collusion or management override is involved.

Best practices

Identify at the outset whether the engagement is subject to AU-C section 240 (non-issuers) or PCAOB AS 2401 (public issuers), and apply the correct standard rather than assuming a single set of requirements.
Maintain professional skepticism throughout the engagement, and avoid allowing prior positive experience with the entity's integrity to reduce alertness to potential fraud.
Conduct and document the required engagement-team discussion of the entity's susceptibility to material misstatement due to fraud early in the audit.
Assess fraud risk factors across incentives or pressures, opportunities, and attitudes or rationalizations, and design responsive procedures accordingly.
Specifically address the risk of management override of controls and incorporate an element of unpredictability into the nature, timing, and extent of procedures.
Keep the auditor's assurance role distinct from management's fraud prevention responsibilities and from internal audit activities, preserving the independence and objectivity of the external audit function.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.