SA 240 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
The second half of SA 240 tells the auditor what to do once fraud risks have been identified: how to shape the audit, the three procedures required in every audit to address management override, what to do when a misstatement may be fraud, and who must be told.
SA 240, as effective for audits of financial statements for periods beginning on or after 1 April 2009, applies to every audit. ICAI may revise standards, so check icai.org for the current text. Part 1 covers risk assessment.
In every audit, whatever the assessed risk, the auditor must test journal entries and other adjustments, review accounting estimates for bias and evaluate the business rationale of significant unusual transactions, because management is in a unique position to override controls. The auditor adds an element of unpredictability, evaluates whether misstatements point to fraud, obtains written representations, and communicates fraud matters on time to management and those charged with governance.
Overall responses (paragraphs 28-29)
For fraud risks at the financial statement level, the auditor decides overall responses under SA 330 (paragraph 28) and, in doing so:
- assigns and supervises people with the knowledge, skill and ability that the fraud risk calls for (paragraph 29(a));
- evaluates whether accounting policies, especially those on subjective measurements and complex transactions, suggest management is managing earnings (29(b)); and
- builds in an element of unpredictability in the nature, timing and extent of procedures (29(c)).
A36 gives examples of unpredictability. In practice it can mean testing items that would not normally be tested, shifting the timing of tests, using different sampling methods or visiting locations unannounced.
Responses at the assertion level (paragraph 30)
The auditor designs further procedures responsive to the assessed fraud risks at assertion level under SA 330. Our SA 330 article covers the general framework. Appendix 2 of SA 240 lists example procedures; they are not reproduced here.
Management override of controls (paragraphs 31-33)
Management can manipulate records and prepare fraudulent statements by overriding controls that otherwise appear to operate effectively. The risk is present in all entities, varies in degree, and, because of the unpredictable way it could occur, is treated as a fraud risk and a significant risk (paragraph 31). Whatever the assessment, the auditor must do the following (paragraph 32).
| Procedure | What it involves | Paragraph |
|---|---|---|
| Journal entries and other adjustments | Inquire of people in the financial reporting process about inappropriate or unusual activity; select entries made at the end of a reporting period; consider whether to test entries throughout the period | 32(a) |
| Accounting estimates | Evaluate whether management's judgments, even if each is reasonable, indicate possible bias; if so, re-evaluate the estimates as a whole; do a retrospective review of last year's significant estimates | 32(b) |
| Significant unusual transactions | Evaluate whether the business rationale, or lack of it, suggests the transaction was entered to commit fraudulent reporting or conceal misappropriation | 32(c) |
| Other procedures | Decide whether more procedures are needed for specific override risks | 33 |
Journal entry testing in practice
A41 notes that fraud often involves recording inappropriate or unauthorised journal entries, or adjustments outside the ledger such as consolidation adjustments and reclassifications. A42 warns that automated controls do not overcome the risk that people override them, for example by changing amounts passed to the ledger, and with IT there may be little visible evidence of that. In choosing items, the auditor looks at fraud risk factors, the controls over journal entries (testing their operation may reduce substantive work), the entity's reporting process and the characteristics of fraudulent entries (A43). A44 explains why period-end entries are required: fraud is often made at period end, but because it can occur throughout the year the auditor also considers testing across the period.
For estimates, A45 says fraudulent reporting is often done by intentionally misstating estimates, for example by understating or overstating provisions or reserves in the same direction to smooth earnings. Our SA 540 part 2 covers management bias in more detail.
Evaluating audit evidence (paragraphs 34-37)
- Analytical procedures near the end of the audit are evaluated for a previously unrecognised fraud risk (paragraph 34).
- When a misstatement is found, the auditor evaluates whether it indicates fraud, and if so, the implications for other parts of the audit, especially the reliability of management representations, recognising that fraud is unlikely to be an isolated occurrence (paragraph 35).
- If the auditor believes a misstatement, material or not, is or may be the result of fraud involving management, particularly senior management, the auditor re-evaluates the fraud risk assessment, the effect on procedures, and whether there may be collusion that casts doubt on evidence already obtained (paragraph 36).
- If fraud is confirmed, or the auditor cannot conclude, the implications for the audit are evaluated (paragraph 37).
Unable to continue (paragraph 38)
If exceptional circumstances caused by fraud or suspected fraud bring into question the auditor's ability to continue, the auditor determines professional and legal responsibilities, including any duty to report to whoever made the appointment or to regulators; considers whether withdrawal is appropriate where legally permitted; and, if withdrawing, discusses it and the reasons with management and those charged with governance and decides whether a professional or legal requirement exists to report the withdrawal and the reasons.
Written representations (paragraph 39)
The auditor obtains written representations that management, and where applicable those charged with governance, acknowledge responsibility for internal control to prevent and detect fraud; have disclosed their assessment of fraud risk; have disclosed knowledge of fraud or suspected fraud involving management, employees with significant roles in internal control, or others where there could be a material effect; and have disclosed any allegations of fraud from employees, former employees, analysts, regulators or others. Our SA 580 article covers representations generally.
Communications (paragraphs 40-43)
| Audience | What is communicated | Paragraph |
|---|---|---|
| Management | Any identified fraud or information indicating fraud may exist, on a timely basis, at the appropriate level | 40 |
| Those charged with governance | Fraud or suspected fraud involving management, employees with significant roles in internal control, or others where it results in a material misstatement; if management is suspected, also discuss the nature, timing and extent of procedures needed to complete the audit | 41 |
| Those charged with governance | Any other fraud-related matters relevant to their responsibilities, under SA 260 | 42 |
| Outside parties | Determine whether there is a responsibility to report to a party outside the entity; the duty of confidentiality may preclude reporting, but legal responsibilities may override it | 43 |
The application material says legal duties vary by law, gives bank audits as an example where the auditor has a statutory duty to report fraud to the supervisory authority, and suggests legal advice may help the auditor decide what to do (A64-A65).
Companies Act position. For company audits the reporting of fraud is also governed by section 143(12) of the Companies Act, 2013 and the rules under it. Read our posts on the 60-day rule and reporting to SFIO, the one crore dividing line under section 143(12) and the Audit and Auditors Rules on fraud reporting and Form ADT-4. On the report side, see the CARO clause on fraud in our CARO guidance on clauses 3(x) and 3(xi).
Documentation (paragraphs 44-47)
The auditor documents the significant decisions in the team discussion, the identified and assessed fraud risks, the overall responses and linked procedures with their results (including those addressing management override), communications about fraud to management, those charged with governance, regulators and others, and, if the revenue presumption was rejected, the reasons.
Illustrative example
Continuing with Kapoor Electronics Pvt Ltd, the auditor selects journal entries posted in the last three days of March and the first week of April, filters for entries made by senior finance staff outside normal hours and entries to revenue and provisions with round amounts, and finds a manual adjustment that reduces the provision for warranty claims by a round figure on 31 March. The finance head explains the adjustment, but the supporting calculation is missing. The auditor treats it as a possible indicator of bias, widens the retrospective review of last year's provision, communicates the matter to the audit committee chair and asks for a specific representation.
Need help with fraud and control reviews?
If you want an independent look at override risks, journal entry controls or unusual transactions, TaxClue's financial and legal due diligence team can help you assess them before the audit. Boards that want a view of their controls can also use our financial and legal due diligence service.
Key takeaways
- Test journal entries, review estimates for bias and examine unusual transactions in every audit.
- Add unpredictability to procedures so that management cannot anticipate them.
- Evaluate each misstatement for signs of fraud and its effect on the rest of the audit.
- Communicate fraud matters promptly to management and those charged with governance.
- For companies, section 143(12) and the rules under it also apply; use the linked posts.
Read next
- SA 240, part 1: skepticism and fraud risk assessment
- SA 330: responses to assessed risks
- SA 540, part 2: management bias in estimates
- Reporting fraud: the 60-day rule and SFIO
Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.
