home  /  detection & investigation  /  detection & the auditor's duty
how fraud surfaces · who retains whom

Detection and the auditor's duty.

Tips find more of it than every other channel. External audits find almost none of it. Both facts follow from what the standards actually say, and both sides of an audit-failure case live in the same paragraphs.

begin here

What did you find, and how did you find it?

Start a conversation with the Forensic Concierge, already scoped to detection & the auditor's duty. Pick a starting point, or describe the matter directly.

Forensic Conciergedetection & the auditor's duty · orientation, not a finding of fraud
Tell me what kind of entity was audited, roughly when, and what the alleged failure is. I will help you see which standard governs and what it requires. I will not tell you whether your auditor was negligent, or whether fraud occurred.

The audit was never the fraud-detection function, and saying so plainly is not an auditor's defense. AU-C 240, which governs private-company audits, assigns primary responsibility for the prevention and detection of fraud to those charged with governance and to management at ¶.04. ¶.05 commits the auditor to reasonable assurance that the statements as a whole are free from material misstatement, whether caused by fraud or error, and concedes that some material misstatements may go undetected even in a properly planned and performed audit. Materiality is the hinge: a defalcation that is the whole of a lawsuit can be immaterial to a set of financial statements. But the standard also imposes specific, testable obligations — and their presence or absence in the workpapers is where audit-failure matters are actually decided.

mechanisms

What the standards actually require.

Six AU-C 240 provisions that carry most of the argument, in both directions. Issuer audits run on the PCAOB's parallel text in AS 2401, where the numbering does not transfer.

Where responsibility sits

AU-C 240 ¶.04: primary responsibility for prevention and detection rests with both those charged with governance and management. Primary, not exclusive — ¶.05 still binds the auditor to reasonable assurance.

Reasonable, never absolute

¶.05 promises reasonable assurance about material misstatement and states that an unavoidable risk of non-detection exists even in a properly performed audit.

Materiality as the boundary

The auditor is bounded by materiality; a fraud examination is bounded by the allegation. That is why the same theft can be invisible to one and central to the other.

Management override

¶.07 explains why management fraud carries greater non-detection risk than employee fraud, and ¶.32(a) responds by requiring testing of journal entries and other adjustments.

The revenue presumption

¶.26 presumes that fraud risks exist in revenue recognition. It is rebuttable — and ¶.46 requires the reasons to be documented when the auditor concludes it is overcome.

Why concealment works

¶.06 anticipates forgery, deliberate failure to record transactions and intentional misrepresentation, and notes that collusion can make false audit evidence look persuasive.

methodology

What the evidence shows — and what we examine.

How a detection or audit-failure question gets worked rather than argued.

Notice timelineWhen each channel — hotline, internal audit, management review, external audit — first had something, and what was done with it.
Workpaper readingReading the file against the standard the engagement was performed under, and against what was knowable then rather than now.
Entries and other adjustmentsIncluding adjustments that never became formal journal entries — consolidating adjustments, report combinations and reclassifications.
Paragraph mappingTying the alleged failure to a specific requirement, because a general negligence theory rarely survives contact with the standard.
what's at stake

What turns on it

Whether an audit-failure theory exists at all, and what the board is told while it is being tested.

whether an audit claim has a paragraph behind it when the organization is treated as being on notice what a clean opinion is taken to mean at trial which standard governs — private, issuer or international whether hotline and whistleblower records survived

A clean audit opinion is not a finding that no fraud occurred.

AU-C 240 ¶.03 says the auditor does not make legal determinations of whether fraud has actually occurred, and confines the auditor's concern to fraud causing material misstatement. ¶.05 promises reasonable, never absolute, assurance. A board reading an unqualified opinion as a fraud sweep has misread the document it paid for.

common questions

Detection & the auditor's duty — practical questions

Which fraud standard applies to my matter?

Three different ones, and naming the wrong one costs credibility immediately. Audits of private companies under US generally accepted auditing standards are governed by AU-C 240. Audits of SEC issuers are governed by PCAOB AS 2401, which the Board has an open project to reconsider but on which it has issued no proposal. Internationally, ISA 240 (Revised) was issued in July 2025 and applies to periods beginning on or after 15 December 2026. AU-C 240 is itself being superseded: SAS No. 151 was approved on 19 August 2026 and takes effect for periods ending on or after 15 December 2028, which means AU-C 240 remains the operative standard for essentially every audit now in dispute. State both dates together or the sentence is misleading.

If tips find far more than audits do, what is the audit for?

A different question entirely, and the detection statistics are not a quality measure. In the ACFE's 2026 Report to the Nations, tips were the source of initial detection in 43% of cases, internal audit in 15%, and external audit in just 2% — fewer than automated transaction and data monitoring, and one-seventh the rate of internal audit. An audit is scoped to support an opinion on whether the financial statements as a whole are free from material misstatement, not to run down allegations. The numbers do argue for something, though: more than half of tips came from employees, and from 2028 SAS No. 151 will require the auditor to understand the entity's whistleblower or other fraud-reporting program, if it has one, including how management and those charged with governance address allegations made through it.

Does the auditor decide whether fraud occurred?

No, and the symmetry with the forensic side is worth noticing. AU-C 240 ¶.03 states that although the auditor may suspect or, in rare cases, identify the occurrence of fraud, the auditor does not make legal determinations of whether fraud has actually occurred. AICPA SSFS No. 1 ¶10 imposes the same limit on a member performing forensic services, reserving the ultimate conclusion of fraud to the trier of fact while expressly permitting opinions on whether evidence is consistent with certain elements. Two very different engagements, one prohibition. What separates them is objective, scope and materiality — not which professional gets to announce a verdict, because neither does.

Is there a duty to escalate that is separate from the audit standards?

For issuers, yes, and it is often the more concrete theory. Section 10A of the Securities Exchange Act of 1934, codified at 15 U.S.C. § 78j-1, requires that each audit include procedures designed to detect illegal acts having a direct and material effect on the financial statements, and establishes a reporting chain when the auditor becomes aware of one: escalation within the issuer, notification to the Commission by the issuer, and a direct report by the auditor if the issuer fails to notify. That is a statutory obligation, not a professional standard, which matters because the remedies and the enforcement posture differ. It also converts a diffuse should-have-caught-it theory into a checkable question about who told whom, and when.

related

Related specialization areas & resources.

Find out which standard the argument actually lives in.

Describe the engagement, the entity and the period. The Institute will help you see which paragraphs are in play.

forensic conciergeorientation · not a finding of fraud
Tell me what kind of entity was audited, roughly when, and what the alleged failure is. I will help you see which standard governs and what it requires. I will not tell you whether your auditor was negligent, or whether fraud occurred.