Next due
7 OCTTDS / TCS deposit · Deducted in Sep 2026tomorrow 11 OCTGSTR-1 · Outward supplies · Sep 2026in 5 days 15 OCTPF & ESI · Contributions · Sep 2026in 9 days 20 OCTGSTR-3B · Summary return · Sep 2026in 14 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 15 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 24 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 46 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 54 days
All due dates

SA 240, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements (part 1 of 2): fraudulent reporting and misappropriation, professional skepticism, the engagement team discussion and identifying fraud risks

The auditor is concerned with fraud that causes a material misstatement: either fraudulent financial reporting or misappropriation of assets. Primary responsibility for preventing...

Published
Updated
Reading time
8 min
Views
12
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 3, 2026
Last updated
Oct 6, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

SA 240 deals with what an auditor must do about fraud while auditing financial statements. This first part covers the nature of fraud, the auditor's skeptical attitude, the team discussion and the steps to identify and assess the risk that fraud has caused a material misstatement.

SA 240, as effective for audits of financial statements for periods beginning on or after 1 April 2009, applies to every audit. ICAI may revise standards, so check icai.org for the current text. Part 2 deals with responses, evaluation and reporting.

What SA 240 covers (paragraphs 1-8)

Paragraph 1 says SA 240 expands on how SA 315 and SA 330 apply to the risks of material misstatement due to fraud. The distinction between fraud and error is intent (paragraph 2). Fraud is defined as an intentional act by management, those charged with governance, employees or third parties, involving deception to obtain an unjust or illegal advantage (paragraph 11). Although fraud is a broad legal concept, two types of intentional misstatement matter: fraudulent financial reporting and misappropriation of assets. The auditor may suspect or, rarely, identify fraud but does not make legal determinations (paragraph 3).

Paragraph 4 puts the primary responsibility for prevention and detection on management and those charged with governance, with a culture of honesty and ethical behaviour and active oversight, including attention to the chance of management override and earnings management.

The auditor's responsibility is reasonable assurance that the statements are not materially misstated, whether by fraud or error, but with an unavoidable risk that some may not be detected (paragraph 5). Paragraphs 6-7 explain why fraud is harder to find than error: concealment through forgery, unrecorded transactions or false statements to the auditor, collusion, and, for management fraud, the ability to override controls. The ability to detect depends on the perpetrator's skill, how often and how much is manipulated, the collusion involved, the size of individual amounts and the seniority of those involved. It is also difficult to tell whether misstatements in judgment areas such as estimates arise from fraud or error.

Objectives (paragraph 10)

The auditor must identify and assess the risks of material misstatement due to fraud, obtain sufficient appropriate evidence about those risks by designing and implementing responses, and respond appropriately to identified or suspected fraud.

Professional skepticism (paragraphs 12-14)

RequirementMeaning in practiceParagraph
Stay skeptical throughoutRecognise that a fraud-related misstatement could exist despite past experience of management's honesty12
DocumentsRecords may be accepted as genuine unless there is reason to believe otherwise; if a document may not be authentic or terms may have been modified but not disclosed, investigate further13
InquiriesInvestigate inconsistent responses from management or those charged with governance14

The engagement team discussion (paragraph 15)

SA 315 requires a team discussion. SA 240 adds emphasis on how and where the financial statements may be susceptible to fraud, including how fraud might occur, and the discussion must happen even if team members believe management and those charged with governance are honest. According to A10, it lets experienced members share insights, helps the auditor decide responses and who should do which procedures, and sets how results are shared and how allegations are handled.

Risk assessment procedures (paragraphs 16-24)

The auditor performs these procedures alongside the risk assessment procedures under SA 315.

Who or whatWhat the auditor doesParagraph
ManagementAsks how management assesses the risk of fraud in the statements and how often; how it identifies and responds to fraud risks; what it has told those charged with governance; what it has told employees about business practices and ethics17
Management and othersAsks whether they know of any actual, suspected or alleged fraud18
Internal auditAsks internal audit, if there is one, about knowledge of fraud and its view of fraud risk19
Those charged with governanceUnless all are involved in management, understands how they oversee management's fraud processes and controls20
Those charged with governanceAsks whether they know of actual, suspected or alleged fraud, in part to corroborate management's answers21
AnalyticsEvaluates whether unusual or unexpected relationships, including those in revenue accounts, may indicate fraud risk22
Other informationConsiders whether other information obtained indicates fraud risk23
Fraud risk factorsEvaluates whether the information shows incentive, pressure or opportunity; these factors do not necessarily mean fraud exists but have often been present where fraud occurred24

Fraud risk factors by category

Appendix 1 of the SA lists examples. Without reproducing them, they are grouped as follows for each of fraudulent financial reporting and misappropriation of assets: incentives or pressures, opportunities, and attitudes or rationalisations. For reporting fraud the examples include financial stability or performance pressures, ineffective oversight and complex or unusual transactions, and management attitudes toward aggressive accounting. For misappropriation they include personal financial pressures, weak controls over assets, and disgruntlement. Appendix 3 separately lists circumstances that may indicate fraud, such as missing documents, last-minute adjustments or denial of access to records.

Identifying and assessing the risks (paragraphs 25-27)

The auditor identifies and assesses fraud risks at the financial statement level and at the assertion level (paragraph 25). Paragraph 26 requires the auditor, on the presumption that there are risks of fraud in revenue recognition, to evaluate which types of revenue, revenue transactions or assertions give rise to such risks. If the auditor concludes that the presumption does not apply, the reasons must be documented (paragraph 47). A28 notes that the risk can be overstatement through premature or fictitious revenue, or understatement by shifting revenue to a later period. A29 says the risk may be higher for listed entities measured on year-on-year growth, or entities with substantial cash sales. A30 says the presumption may be rebutted, for example for a single simple lease revenue stream.

Assessed fraud risks are treated as significant risks, so the auditor obtains an understanding of the entity's related controls, including control activities (paragraph 27). A31-A32 note that management may decide a control is not cost effective and so accept some risk; the auditor needs to understand what management has designed and implemented. The consequences for the audit are in SA 315 part 2.

Illustrative example

At the planning meeting for Kapoor Electronics Pvt Ltd, an invented manufacturer, the partner leads a discussion on fraud. The team notes that sales staff earn bonuses on year-end dispatches, that the CEO is also the main shareholder, and that two years ago a warehouse supervisor was found diverting scrap. The auditor asks the CFO how she monitors fraud risk, asks the audit committee chair about any whistle-blower complaints, and asks the head of internal audit whether any issues are open. Analytics show March sales up 40% on a month earlier, with returns in April, so the auditor treats revenue cut-off as a fraud risk and plans extra procedures; the responses are explained in part 2.

Need help with fraud risk and due diligence?

If you are assessing fraud exposure in a business, or reviewing controls before a deal or an audit, TaxClue's financial and legal due diligence team can help you look at the areas an auditor will test. For more on investigative work, read our guide to forensic audit in India. Teams preparing for an audit can also use our financial and legal due diligence service.

Key takeaways

  • The auditor looks at fraudulent financial reporting and misappropriation of assets that could materially misstate the statements.
  • Management and those charged with governance are primarily responsible for prevention and detection.
  • Skepticism applies even when past experience of management is good; the team discussion is mandatory.
  • Inquiries cover management, internal audit and those charged with governance.
  • Revenue is presumed to carry fraud risk unless the auditor documents why not.

Read next

Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About SA 240

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Is the auditor responsible for detecting all fraud?

No. The auditor obtains reasonable assurance that the statements are not materially misstated by fraud or error, but there is an unavoidable risk that some material misstatements are not detected (paragraph 5).

Why is fraud harder to detect than error?

Fraud may involve concealment, forged documents and collusion, and management fraud may involve override of controls (paragraphs 6-7).

Do not copy last year's filing without checking whether last year's law still applies.

— TaxClue Compliance Desk

SA 240: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

No. The auditor obtains reasonable assurance that the statements are not materially misstated by fraud or error, but there is an unavoidable risk that some material misstatements are not detected (paragraph 5).

Fraud may involve concealment, forged documents and collusion, and management fraud may involve override of controls (paragraphs 6-7).

No. The auditor may suspect or identify fraud but does not make legal determinations (paragraph 3).

SA 240 presumes risks of fraud in revenue recognition. The presumption can be rebutted only with documented reasons (paragraphs 26 and 47).

Management, others in the entity as appropriate, internal audit, and those charged with governance (paragraphs 17-21).

Reporting of fraud by auditors of companies is covered in part 2, with links to the Companies Act position.