Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026in 3 days 15 OCTPF & ESI · Contributions · Sep 2026in 7 days 20 OCTGSTR-3B · Summary return · Sep 2026in 12 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 13 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 22 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 30 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 44 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 52 days
All due dates

SA 240, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements (part 2 of 2): responses to fraud risks, management override, journal entry testing, evidence, representations and reporting

In every audit, whatever the assessed risk, the auditor must test journal entries and other adjustments, review accounting estimates for bias and evaluate the business rationale...

Published
Updated
Reading time
9 min
Views
9
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 3, 2026
Last updated
Oct 7, 2026
Reading time
9 min
0:00
Last updated: October 2026Verified against: Government sources

The second half of SA 240 tells the auditor what to do once fraud risks have been identified: how to shape the audit, the three procedures required in every audit to address management override, what to do when a misstatement may be fraud, and who must be told.

SA 240, as effective for audits of financial statements for periods beginning on or after 1 April 2009, applies to every audit. ICAI may revise standards, so check icai.org for the current text. Part 1 covers risk assessment.

Overall responses (paragraphs 28-29)

For fraud risks at the financial statement level, the auditor decides overall responses under SA 330 (paragraph 28) and, in doing so:

  1. assigns and supervises people with the knowledge, skill and ability that the fraud risk calls for (paragraph 29(a));
  2. evaluates whether accounting policies, especially those on subjective measurements and complex transactions, suggest management is managing earnings (29(b)); and
  3. builds in an element of unpredictability in the nature, timing and extent of procedures (29(c)).

A36 gives examples of unpredictability. In practice it can mean testing items that would not normally be tested, shifting the timing of tests, using different sampling methods or visiting locations unannounced.

Responses at the assertion level (paragraph 30)

The auditor designs further procedures responsive to the assessed fraud risks at assertion level under SA 330. Our SA 330 article covers the general framework. Appendix 2 of SA 240 lists example procedures; they are not reproduced here.

Management override of controls (paragraphs 31-33)

Management can manipulate records and prepare fraudulent statements by overriding controls that otherwise appear to operate effectively. The risk is present in all entities, varies in degree, and, because of the unpredictable way it could occur, is treated as a fraud risk and a significant risk (paragraph 31). Whatever the assessment, the auditor must do the following (paragraph 32).

ProcedureWhat it involvesParagraph
Journal entries and other adjustmentsInquire of people in the financial reporting process about inappropriate or unusual activity; select entries made at the end of a reporting period; consider whether to test entries throughout the period32(a)
Accounting estimatesEvaluate whether management's judgments, even if each is reasonable, indicate possible bias; if so, re-evaluate the estimates as a whole; do a retrospective review of last year's significant estimates32(b)
Significant unusual transactionsEvaluate whether the business rationale, or lack of it, suggests the transaction was entered to commit fraudulent reporting or conceal misappropriation32(c)
Other proceduresDecide whether more procedures are needed for specific override risks33

Journal entry testing in practice

A41 notes that fraud often involves recording inappropriate or unauthorised journal entries, or adjustments outside the ledger such as consolidation adjustments and reclassifications. A42 warns that automated controls do not overcome the risk that people override them, for example by changing amounts passed to the ledger, and with IT there may be little visible evidence of that. In choosing items, the auditor looks at fraud risk factors, the controls over journal entries (testing their operation may reduce substantive work), the entity's reporting process and the characteristics of fraudulent entries (A43). A44 explains why period-end entries are required: fraud is often made at period end, but because it can occur throughout the year the auditor also considers testing across the period.

For estimates, A45 says fraudulent reporting is often done by intentionally misstating estimates, for example by understating or overstating provisions or reserves in the same direction to smooth earnings. Our SA 540 part 2 covers management bias in more detail.

Evaluating audit evidence (paragraphs 34-37)

  • Analytical procedures near the end of the audit are evaluated for a previously unrecognised fraud risk (paragraph 34).
  • When a misstatement is found, the auditor evaluates whether it indicates fraud, and if so, the implications for other parts of the audit, especially the reliability of management representations, recognising that fraud is unlikely to be an isolated occurrence (paragraph 35).
  • If the auditor believes a misstatement, material or not, is or may be the result of fraud involving management, particularly senior management, the auditor re-evaluates the fraud risk assessment, the effect on procedures, and whether there may be collusion that casts doubt on evidence already obtained (paragraph 36).
  • If fraud is confirmed, or the auditor cannot conclude, the implications for the audit are evaluated (paragraph 37).

Unable to continue (paragraph 38)

If exceptional circumstances caused by fraud or suspected fraud bring into question the auditor's ability to continue, the auditor determines professional and legal responsibilities, including any duty to report to whoever made the appointment or to regulators; considers whether withdrawal is appropriate where legally permitted; and, if withdrawing, discusses it and the reasons with management and those charged with governance and decides whether a professional or legal requirement exists to report the withdrawal and the reasons.

Written representations (paragraph 39)

The auditor obtains written representations that management, and where applicable those charged with governance, acknowledge responsibility for internal control to prevent and detect fraud; have disclosed their assessment of fraud risk; have disclosed knowledge of fraud or suspected fraud involving management, employees with significant roles in internal control, or others where there could be a material effect; and have disclosed any allegations of fraud from employees, former employees, analysts, regulators or others. Our SA 580 article covers representations generally.

Communications (paragraphs 40-43)

AudienceWhat is communicatedParagraph
ManagementAny identified fraud or information indicating fraud may exist, on a timely basis, at the appropriate level40
Those charged with governanceFraud or suspected fraud involving management, employees with significant roles in internal control, or others where it results in a material misstatement; if management is suspected, also discuss the nature, timing and extent of procedures needed to complete the audit41
Those charged with governanceAny other fraud-related matters relevant to their responsibilities, under SA 26042
Outside partiesDetermine whether there is a responsibility to report to a party outside the entity; the duty of confidentiality may preclude reporting, but legal responsibilities may override it43

The application material says legal duties vary by law, gives bank audits as an example where the auditor has a statutory duty to report fraud to the supervisory authority, and suggests legal advice may help the auditor decide what to do (A64-A65).

Companies Act position. For company audits the reporting of fraud is also governed by section 143(12) of the Companies Act, 2013 and the rules under it. Read our posts on the 60-day rule and reporting to SFIO, the one crore dividing line under section 143(12) and the Audit and Auditors Rules on fraud reporting and Form ADT-4. On the report side, see the CARO clause on fraud in our CARO guidance on clauses 3(x) and 3(xi).

Documentation (paragraphs 44-47)

The auditor documents the significant decisions in the team discussion, the identified and assessed fraud risks, the overall responses and linked procedures with their results (including those addressing management override), communications about fraud to management, those charged with governance, regulators and others, and, if the revenue presumption was rejected, the reasons.

Illustrative example

Continuing with Kapoor Electronics Pvt Ltd, the auditor selects journal entries posted in the last three days of March and the first week of April, filters for entries made by senior finance staff outside normal hours and entries to revenue and provisions with round amounts, and finds a manual adjustment that reduces the provision for warranty claims by a round figure on 31 March. The finance head explains the adjustment, but the supporting calculation is missing. The auditor treats it as a possible indicator of bias, widens the retrospective review of last year's provision, communicates the matter to the audit committee chair and asks for a specific representation.

Need help with fraud and control reviews?

If you want an independent look at override risks, journal entry controls or unusual transactions, TaxClue's financial and legal due diligence team can help you assess them before the audit. Boards that want a view of their controls can also use our financial and legal due diligence service.

Key takeaways

  • Test journal entries, review estimates for bias and examine unusual transactions in every audit.
  • Add unpredictability to procedures so that management cannot anticipate them.
  • Evaluate each misstatement for signs of fraud and its effect on the rest of the audit.
  • Communicate fraud matters promptly to management and those charged with governance.
  • For companies, section 143(12) and the rules under it also apply; use the linked posts.

Read next

Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About SA 240

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Are journal entries tested in every audit?

Yes. The procedures for management override, including journal entry testing, are required whatever the auditor's assessment of that risk (paragraph 32).

Why select period-end entries?

Because fraudulent entries are often made at the end of a period; the auditor also considers testing across the whole period (paragraph 32(a) and A44).

One person should own every deadline. A deadline that belongs to everyone belongs to no one.

— TaxClue Compliance Desk

SA 240: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

Yes. The procedures for management override, including journal entry testing, are required whatever the auditor's assessment of that risk (paragraph 32).

Because fraudulent entries are often made at the end of a period; the auditor also considers testing across the whole period (paragraph 32(a) and A44).

The auditor re-evaluates the fraud risk assessment, considers collusion and communicates the suspicion to those charged with governance (paragraphs 36 and 41).

The auditor determines whether a responsibility exists to report outside the entity; confidentiality may preclude it unless a legal responsibility overrides it (paragraph 43). For companies, see the section 143(12) posts.

It covers responsibility for fraud-prevention controls, the fraud risk assessment, knowledge of fraud or suspected fraud, and allegations of fraud (paragraph 39).

In exceptional circumstances, where legally permitted, after considering professional and legal responsibilities (paragraph 38).