Skip to content

Fraud, Error, the Evaluation of Misstatements and Reporting Control Weaknesses

VIVA Subject Guide
YouTube video

1 Definitions

Fraud is an intentional act, involving deception, to obtain an unjust or illegal advantage.

Fraud can be:

  • Fraudulent financial reporting. For example, overstating profits to attract investors and lenders.

  • Misappropriation of assets. For example, the theft of cash, inventory or non-current assets.

Error is an unintentional misstatement, including omission, of an amount or disclosure in financial statements.

Misstatement is a difference between what is reported and what should be reported (eg in accordance with IFRS). A misstatement can be caused by either error or fraud. A misstatement can be:

  • An incorrect amount.

  • Incorrect classification or presentation.

  • Incorrect disclosure.

2 Fraud

It is management’s responsibility to prevent and detect fraud – not the auditor’s. It is management’s responsibility to ensure that there is an effective system of internal control as this will greatly decrease the risk of fraud and increase the likelihood of detecting fraud. Auditors are not expected to find every fraud, but they are expected (with reasonable assurance) to find material misstatements, whether innocent or fraudulent. They are expected to exercise professional scepticism and to follow up any suspicions that they might have, for example if the results of analytical procedures do not make sense. Once a suspected fraud or error is discovered the auditor must perform more audit work, such as:

  • Discovering how the fraud or error occurred.

  • Discovering if the incident is isolated or is part of a larger pattern.

  • Consider applying computer assisted auditing techniques to look for similar patterns within the records (for example, all orders placed with a particular supplier).

  • Estimating the financial effect.

This risk of failing to detect material misstatement due to fraud is greater than material misstatement due to error because fraudsters seek to conceal their activities. For example, by creating forged documents or by collusion with other parties.

Three conditions are usually present when fraud exists:

  • Incentive or pressure to commit the fraud

  • Opportunity to commit the fraud

  • Attitude to go through with the fraud

At the planning stage the susceptibility of an entity to fraud should be discussed with the audit team and with management of the client. The following are examples of fraud risk factors that indicate an increased risk of fraud:

  • Lack of segregation of duties or independent checks.

  • Significant deficiencies in internal control components (e.g. ineffective internal audit function).

  • Management failing to remedy known significant deficiencies in internal control on a timely basis.

  • Complex transactions that pose difficult 'substance over form' questions.

  • Significant estimates that are difficult to corroborate.

  • Easy-to-steal assets: cash, compact but high-value inventory.

  • Complex group structures so that related party transactions are difficult to discover.

  • Excessive pressure on management to meet financial targets.

A fraud must be communicated to TCWG if it results in material misstatement or if management is implicated. Other frauds should be communicated to a suitable level of management. It is important, even for what appears to be a small fraud, to investigate how long it has been going on for, how much is involved and who is behind the fraud.

In exceptional circumstances, the auditor may be unable to continue performing the audit. For example:

  • Management or TCWG appear to be responsible for committing a fraud.

  • There is a significant risk of material and pervasive fraud.

  • Failure to take appropriate action raises significant concern about management's integrity.

3 Management bias

‘Management bias’ (a lack of neutrality) may represent a risk of fraudulent reporting. Factors that may produce bias include:

  • Bonuses dependent on hitting a profit target.

  • Jobs dependent on a level of performance.

  • The business is going to be floated on the stock exchange so higher profits increase the flotation price.

  • The business is targeted for a takeover and the purchase price be will be influenced by performance.

In these situations auditors should be wary of managers being more optimistic than is warranted so that the value of inventory, recoverability of receivables, profit budgets and construction contract profitability are overstated and potential liabilities are understated.

At some point optimism and wishful thinking will become more like deliberate misstatement and fraud: making demonstrably undue claims about company performance and the deliberate omission of liabilities.

Management bias is a common element of AAA questions: many describe bonus schemes or buy-outs and you must respond to these by recognising the increased audit risk that inevitably arises.

4 Evaluation of misstatements identified

ISA 450 Evaluation of Misstatements Identified during the Audit requires auditors to accumulate identified misstatements other than those which are clearly trivial. The triviality threshold will generally be much lower than the materiality threshold.

  • All misstatements accumulated during the audit should be communicated to the appropriate level of management on a timely basis.

  • Management should correct them or explain why not. Often the audit committee will be involved in these discussions. Misstatements can be categorised as:

    • Factual (definitely incorrect, like a mistake when adding up the stock-take sheets).

    • Judgmental (where the auditor and client have different opinions, such as the valuation of inventory or recoverability of debts).

    • Projected. The auditors best estimate of the error of a population based on the errors in the audit sample.

  • The categorisations affect how much negotiation or compromise is acceptable when it comes to amending the financial statements:

    • no room for compromise with factual misstatements

    • discussion of judgmental errors may reach a compromise

    • extended testing to find actual errors rather than make adjustments for projected errors.

  • Obtain written representations from management that they believe uncorrected misstatements are not material or their reasons for believing that certain uncorrected misstatements are not misstatements.

  • Assess materiality of uncorrected misstatements individually and in aggregate. Note that materiality levels may have been revised as the audit progressed (ISA 320 Materiality in Planning and Performing an Audit).

If management refuses to correct a misstatement which the auditor thinks is material then the auditor will have to issue a qualified opinion (or adverse if the matter is pervasive).

Note it is management’s responsibility to correct errors in the financial statements. Auditors cannot unilaterally adjust the financial statements that have been prepared by management.

5 Reporting deficiencies in internal controls

Deficiencies in internal control may be identified when assessing risks (ie at the planning stage) or at any later stage. ISA 265 Communicating Deficiencies in Internal Control to Those Charged with Governance and Management requires the auditor to determine whether deficiencies, individually or in combination, are 'significant'.

A significant deficiency is one that is sufficiently important to merit attention of TCWG.

Factors influencing this include:

  • The likelihood that the deficiencies will lead to material misstatement.

  • The susceptibility to loss or fraud of the related asset or liability.

  • The subjectivity and complexity of determining estimated amounts.

  • The financial statement amounts exposed to the deficiencies.

  • The volume of activity in the account balance or class of transactions exposed to the deficiency.

The auditor must communicate in writing significant deficiencies in internal control to TCWG on a timely basis.

Other deficiencies should be communicated to management at the appropriate level.