Whose job is it to detect fraud — the auditor's or the company's?
Primarily the company's. AU-C 240 ¶.04 — the fraud standard for audits of US entities other than SEC issuers, performed under generally accepted auditing standards — states that the primary responsibility for the prevention and detection of fraud rests with both those charged with governance of the entity and management. PCAOB AS 2401, which governs audits of SEC issuers and whose paragraph numbering does not transfer, does the parallel work at its own ¶.04: “it is management's responsibility to design and implement programs and controls to prevent, deter, and detect fraud.”
Primary is not exclusive, and this is where readings of AU-C 240 go wrong in one direction or the other. AU-C 240 ¶.05 binds the auditor to obtain reasonable assurance that the financial statements as a whole are free from material misstatement, whether caused by fraud or error, while acknowledging that an unavoidable risk of non-detection exists even where the audit is properly planned and performed in accordance with GAAS. Reasonable assurance is an affirmative obligation, not a disclaimer.
The SEC's Office of the Chief Accountant has said so in terms. In a statement titled “The Auditor's Responsibility for Fraud Detection,” issued 11 October 2022, then-Acting Chief Accountant Paul Munter reported hearing that auditors “many times frame the discussion of their responsibilities related to fraud by describing what is beyond the auditor's responsibilities,” and described that focus on limits, rather than on the affirmative requirement to plan and perform the audit to obtain reasonable assurance, as “deeply concerning.” Anyone treating AU-C 240 ¶.04 as the end of the analysis has stopped reading one paragraph too early.
Does a clean audit opinion mean no fraud occurred?
No, and AU-C 240 says as much in its own text. ¶.03 states that although the auditor may suspect or, in rare cases, identify the occurrence of fraud, “the auditor does not make legal determinations of whether fraud has actually occurred,” and the same paragraph confines the auditor's concern to fraud that causes a material misstatement in the financial statements. An unqualified opinion is an opinion about the financial statements as a whole. It is not a finding about anyone's conduct.
Materiality is the hinge, and it produces a scale mismatch that surprises boards. A misappropriation that is the entire subject of a lawsuit, a termination and a fidelity claim can sit well below the materiality threshold applied to financial statements it never visibly disturbed. In the Association of Certified Fraud Examiners' Occupational Fraud 2026: A Report to the Nations, the median loss across 2,402 cases was $104,000 — a figure immaterial to most audited entities and ruinous to a small one.
A fraud examination is bounded by the allegation rather than by materiality, and the difference is structural rather than a matter of effort. Douglas R. Carmichael, PhD, CPA, CFE, writing in The CPA Journal in March 2018, sets out the operative distinctions: an audit covers the complete financial statements and is significantly affected by the concept of materiality, while a fraud examination targets specific allegations and accounts and is not constrained by a materiality threshold. A fraud examination also begins only on predication — in the ACFE's formulation, the totality of circumstances that would lead a reasonable, professionally trained and prudent person to believe a fraud has occurred, is occurring or will occur — which has no analogue in auditing, where no suspicion is required for the auditor to proceed. That is why the same $104,000 can be invisible to one engagement and the whole of the other.
Why is fraud harder for an audit to detect than an ordinary error?
Because concealment is part of the scheme, and AU-C 240 ¶.06 names the forms it takes: “sophisticated and carefully organized schemes designed to conceal it, such as forgery, deliberate failure to record transactions, or intentional misrepresentations being made to the auditor.” The same paragraph adds that such attempts at concealment may be even more difficult to detect when accompanied by collusion, which “may cause the auditor to believe that audit evidence is persuasive when it is, in fact, false.” AU-C 240 ¶.07 then explains why management fraud carries greater non-detection risk than employee fraud: management is frequently in a position to directly or indirectly manipulate accounting records, present fraudulent financial information, or override control procedures.
PCAOB AS 2401 reaches the same place for audits of SEC issuers. ¶.12 states that “absolute assurance is not attainable and thus even a properly planned and performed audit may not detect a material misstatement resulting from fraud,” and ¶.05 identifies the only thing separating fraud from error as “whether the underlying action that results in the misstatement of the financial statements is intentional or unintentional.” Two sets of records can look identical; intent is what distinguishes them, and neither the auditor nor the forensic accountant is the party who decides it.
AU-C 240 ¶¶.06 and .07 run in both directions, which is the part worth taking away. Where a scheme involved forgery, collusion or management override of controls, the standard anticipated the outcome and says so on the page. Where it involved none of them — the transactions were recorded, the documents were genuine, the entries were made by one person with no accomplice and no authority to override — the standard supplies considerably less cover, and the question becomes what the engagement actually did. That is an argument about one engagement file, not a proposition about audits in general.
If audits are not how fraud gets found, what is?
Tips, by a margin nothing else approaches. In the Association of Certified Fraud Examiners' Occupational Fraud 2026: A Report to the Nations, tips were the source of initial detection in 43% of occupational fraud cases, internal audit in 15%, and external audit in just 2% — fewer than automated transaction and data monitoring, and one-seventh the rate of internal audit. More than half of the tips came from employees of the organization.
Those detection percentages are not a quality ranking, because the channels are not doing the same work: an audit is scoped to support an opinion on the financial statements, not to run down an allegation. What the figures do establish is where the evidence of first notice usually lives. Hotline logs, human resources files, the emails around a complaint that was closed out and the record of what was done with it are frequently more decisive than anything in the general ledger — and they are the records most likely to be sitting on short retention settings. The same ACFE report puts the median scheme at 12 months before detection, with cases running beyond five years producing median losses above $1.1 million against roughly $40,000 for those caught within six months.
The auditing standards are moving toward that channel, though not yet in force. SAS No. 151, “The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements,” approved by the AICPA's Auditing Standards Board on 19 August 2026, will require the auditor to understand the entity's whistleblower program or other fraud-reporting program where the entity has one, including how management and, if applicable, those charged with governance address allegations of fraud made through it. It is effective for audits of financial statements for periods ending on or after 15 December 2028, with early implementation permitted, and AU-C 240 remains the operative standard until then — which means AU-C 240 governs essentially every audit now in dispute.
Are there specific fraud requirements an auditor can be measured against?
Yes, and they are the reason audit-failure claims are argued from paragraph numbers rather than from the fact that a scheme happened. AU-C 240 ¶.26 requires the auditor, “based on a presumption that risks of fraud exist in revenue recognition,” to evaluate which types of revenue, revenue transactions or assertions give rise to such risks. The presumption is rebuttable — and ¶.46 requires that where the auditor concludes it has been overcome in the circumstances of the engagement, the audit documentation include the reasons for that conclusion. A workpaper that either exists or does not is a different order of evidence from an argument about what a careful auditor would have noticed.
Journal entry testing is the second such requirement, and its second half is the one most often left out. AU-C 240 ¶.32(a) requires the auditor to test journal entries and other adjustments as a response to management override risk, including selecting entries made at the end of a reporting period and considering the need to test entries throughout the period. The application material at ¶.A47 explains why, and locates the manipulation in two places: “recording inappropriate or unauthorized journal entries throughout the year or at period end,” and “making adjustments to amounts reported in the financial statements that are not reflected in formal journal entries, such as through consolidating adjustments, report combinations, and reclassifications.” Adjustments of the second kind can sit outside the general ledger entirely, which is why they go missing from a data set assembled from the ledger alone.
One argument is not available: that the auditor should have used forensic techniques. Writing in the Journal of Accountancy in June 2024, J. Gregory Jenkins, CPA, Ph.D., catalogs forensic-style approaches drawn from the Auditing Standards Board's own interviews with forensic professionals — recharacterising fraud inquiries as discussions rather than checklist questions, conducting them face to face, searching payroll registers and credit card statements for unreasonable items, identifying controls that should exist and do not — and states that the suggestions “are not intended to expand the fraud-related requirements” of the professional standards. For audits of SEC issuers there is a separate route that is statutory rather than professional: Section 10A of the Securities Exchange Act of 1934, codified at 15 U.S.C. § 78j-1, requires each audit to include “procedures designed to provide reasonable assurance of detecting illegal acts that would have a direct and material effect on the determination of financial statement amounts,” and sets an escalation chain — the auditor informs the appropriate level of management and assures that the audit committee is adequately informed, reports to the board where a material illegal act goes unremedied, the issuer must notify the Commission within one business day of receiving that report, and an auditor who does not receive a copy of that notice must either resign from the engagement or furnish its own report to the Commission within one business day. That converts a diffuse should-have-caught-it theory into a checkable question about who told whom, and when.
How would anyone actually assess whether the audit fell short?
By reading the engagement file against the specific requirement said to have been missed, and against what was knowable during fieldwork rather than after the scheme was unwound. That is the whole discipline and it is unglamorous: map the alleged failure to a paragraph of AU-C 240 or PCAOB AS 2401, establish from the workpapers what was actually done, and test whether the evidence available at the time supported the conclusion recorded. A general negligence theory rarely survives contact with the standard the engagement was performed under, and hindsight is the first thing an opposing expert will take out of it.
Two practical constraints shape any review of an engagement file. Audit documentation sits with the audit firm, so access ordinarily runs through discovery, a regulatory process or a records request rather than through the client relationship; for audits of SEC issuers, PCAOB AS 1215 ¶.14 requires the auditor to retain audit documentation for seven years from the report release date, and ¶.15 requires a complete and final set to be assembled for retention no more than 14 days after that date, which fixes both what should still exist and when the file stopped changing. Separately, a company's own reconstruction carries a privilege problem — there is no federal accountant-client privilege (Couch v. United States, 409 U.S. 322 (1973)), so an investigation begun in-house may simply be discoverable. See Retention, Scope & Privilege for how the retention chain is normally structured, and Detection & the Auditor's Duty for the standards map.
What an audit failure is worth, if one is established, is a separate question from whether one occurred — a difference of subject matter rather than of profession, and the same accountant frequently does both halves. This Institute covers the records-based half: what the engagement file shows, what the journal entries and other adjustments show, and where funds moved. Measuring a loss against a counterfactual in which the scheme was caught earlier is damages work, and it is covered by our Economic Damages Institute rather than here. Nothing on this page is an opinion on whether any particular audit was deficient, or on whether fraud occurred in any matter — AICPA Statement on Standards for Forensic Services No. 1 ¶10 reserves the ultimate conclusion of fraud to the trier of fact and prohibits an AICPA member performing forensic services from opining on it.