SA 240 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
SA 240 deals with what an auditor must do about fraud while auditing financial statements. This first part covers the nature of fraud, the auditor's skeptical attitude, the team discussion and the steps to identify and assess the risk that fraud has caused a material misstatement.
SA 240, as effective for audits of financial statements for periods beginning on or after 1 April 2009, applies to every audit. ICAI may revise standards, so check icai.org for the current text. Part 2 deals with responses, evaluation and reporting.
The auditor is concerned with fraud that causes a material misstatement: either fraudulent financial reporting or misappropriation of assets. Primary responsibility for preventing and detecting fraud rests with management and those charged with governance. The auditor must keep professional skepticism whatever past experience of management's honesty, hold a team discussion on how fraud might occur, make specified inquiries, and treat risks of fraud as significant risks. Revenue recognition is presumed to carry a fraud risk unless the auditor concludes otherwise.
What SA 240 covers (paragraphs 1-8)
Paragraph 1 says SA 240 expands on how SA 315 and SA 330 apply to the risks of material misstatement due to fraud. The distinction between fraud and error is intent (paragraph 2). Fraud is defined as an intentional act by management, those charged with governance, employees or third parties, involving deception to obtain an unjust or illegal advantage (paragraph 11). Although fraud is a broad legal concept, two types of intentional misstatement matter: fraudulent financial reporting and misappropriation of assets. The auditor may suspect or, rarely, identify fraud but does not make legal determinations (paragraph 3).
Paragraph 4 puts the primary responsibility for prevention and detection on management and those charged with governance, with a culture of honesty and ethical behaviour and active oversight, including attention to the chance of management override and earnings management.
The auditor's responsibility is reasonable assurance that the statements are not materially misstated, whether by fraud or error, but with an unavoidable risk that some may not be detected (paragraph 5). Paragraphs 6-7 explain why fraud is harder to find than error: concealment through forgery, unrecorded transactions or false statements to the auditor, collusion, and, for management fraud, the ability to override controls. The ability to detect depends on the perpetrator's skill, how often and how much is manipulated, the collusion involved, the size of individual amounts and the seniority of those involved. It is also difficult to tell whether misstatements in judgment areas such as estimates arise from fraud or error.
Objectives (paragraph 10)
The auditor must identify and assess the risks of material misstatement due to fraud, obtain sufficient appropriate evidence about those risks by designing and implementing responses, and respond appropriately to identified or suspected fraud.
Professional skepticism (paragraphs 12-14)
| Requirement | Meaning in practice | Paragraph |
|---|---|---|
| Stay skeptical throughout | Recognise that a fraud-related misstatement could exist despite past experience of management's honesty | 12 |
| Documents | Records may be accepted as genuine unless there is reason to believe otherwise; if a document may not be authentic or terms may have been modified but not disclosed, investigate further | 13 |
| Inquiries | Investigate inconsistent responses from management or those charged with governance | 14 |
The engagement team discussion (paragraph 15)
SA 315 requires a team discussion. SA 240 adds emphasis on how and where the financial statements may be susceptible to fraud, including how fraud might occur, and the discussion must happen even if team members believe management and those charged with governance are honest. According to A10, it lets experienced members share insights, helps the auditor decide responses and who should do which procedures, and sets how results are shared and how allegations are handled.
Risk assessment procedures (paragraphs 16-24)
The auditor performs these procedures alongside the risk assessment procedures under SA 315.
| Who or what | What the auditor does | Paragraph |
|---|---|---|
| Management | Asks how management assesses the risk of fraud in the statements and how often; how it identifies and responds to fraud risks; what it has told those charged with governance; what it has told employees about business practices and ethics | 17 |
| Management and others | Asks whether they know of any actual, suspected or alleged fraud | 18 |
| Internal audit | Asks internal audit, if there is one, about knowledge of fraud and its view of fraud risk | 19 |
| Those charged with governance | Unless all are involved in management, understands how they oversee management's fraud processes and controls | 20 |
| Those charged with governance | Asks whether they know of actual, suspected or alleged fraud, in part to corroborate management's answers | 21 |
| Analytics | Evaluates whether unusual or unexpected relationships, including those in revenue accounts, may indicate fraud risk | 22 |
| Other information | Considers whether other information obtained indicates fraud risk | 23 |
| Fraud risk factors | Evaluates whether the information shows incentive, pressure or opportunity; these factors do not necessarily mean fraud exists but have often been present where fraud occurred | 24 |
Fraud risk factors by category
Appendix 1 of the SA lists examples. Without reproducing them, they are grouped as follows for each of fraudulent financial reporting and misappropriation of assets: incentives or pressures, opportunities, and attitudes or rationalisations. For reporting fraud the examples include financial stability or performance pressures, ineffective oversight and complex or unusual transactions, and management attitudes toward aggressive accounting. For misappropriation they include personal financial pressures, weak controls over assets, and disgruntlement. Appendix 3 separately lists circumstances that may indicate fraud, such as missing documents, last-minute adjustments or denial of access to records.
Identifying and assessing the risks (paragraphs 25-27)
The auditor identifies and assesses fraud risks at the financial statement level and at the assertion level (paragraph 25). Paragraph 26 requires the auditor, on the presumption that there are risks of fraud in revenue recognition, to evaluate which types of revenue, revenue transactions or assertions give rise to such risks. If the auditor concludes that the presumption does not apply, the reasons must be documented (paragraph 47). A28 notes that the risk can be overstatement through premature or fictitious revenue, or understatement by shifting revenue to a later period. A29 says the risk may be higher for listed entities measured on year-on-year growth, or entities with substantial cash sales. A30 says the presumption may be rebutted, for example for a single simple lease revenue stream.
Assessed fraud risks are treated as significant risks, so the auditor obtains an understanding of the entity's related controls, including control activities (paragraph 27). A31-A32 note that management may decide a control is not cost effective and so accept some risk; the auditor needs to understand what management has designed and implemented. The consequences for the audit are in SA 315 part 2.
Illustrative example
At the planning meeting for Kapoor Electronics Pvt Ltd, an invented manufacturer, the partner leads a discussion on fraud. The team notes that sales staff earn bonuses on year-end dispatches, that the CEO is also the main shareholder, and that two years ago a warehouse supervisor was found diverting scrap. The auditor asks the CFO how she monitors fraud risk, asks the audit committee chair about any whistle-blower complaints, and asks the head of internal audit whether any issues are open. Analytics show March sales up 40% on a month earlier, with returns in April, so the auditor treats revenue cut-off as a fraud risk and plans extra procedures; the responses are explained in part 2.
Need help with fraud risk and due diligence?
If you are assessing fraud exposure in a business, or reviewing controls before a deal or an audit, TaxClue's financial and legal due diligence team can help you look at the areas an auditor will test. For more on investigative work, read our guide to forensic audit in India. Teams preparing for an audit can also use our financial and legal due diligence service.
Key takeaways
- The auditor looks at fraudulent financial reporting and misappropriation of assets that could materially misstate the statements.
- Management and those charged with governance are primarily responsible for prevention and detection.
- Skepticism applies even when past experience of management is good; the team discussion is mandatory.
- Inquiries cover management, internal audit and those charged with governance.
- Revenue is presumed to carry fraud risk unless the auditor documents why not.
Read next
- SA 240, part 2: responses, management override and reporting
- SA 315 part 1: understanding the entity and its internal control
- SA 260: communication with those charged with governance
- Forensic audit in India
Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.
