Tips find more of it than every other channel. External audits find almost none of it. Both facts follow from what the standards actually say, and both sides of an audit-failure case live in the same paragraphs.
Start a conversation with the Forensic Concierge, already scoped to detection & the auditor's duty. Pick a starting point, or describe the matter directly.
The audit was never the fraud-detection function, and saying so plainly is not an auditor's defense. AU-C 240, which governs private-company audits, assigns primary responsibility for the prevention and detection of fraud to those charged with governance and to management at ¶.04. ¶.05 commits the auditor to reasonable assurance that the statements as a whole are free from material misstatement, whether caused by fraud or error, and concedes that some material misstatements may go undetected even in a properly planned and performed audit. Materiality is the hinge: a defalcation that is the whole of a lawsuit can be immaterial to a set of financial statements. But the standard also imposes specific, testable obligations — and their presence or absence in the workpapers is where audit-failure matters are actually decided.
Six AU-C 240 provisions that carry most of the argument, in both directions. Issuer audits run on the PCAOB's parallel text in AS 2401, where the numbering does not transfer.
AU-C 240 ¶.04: primary responsibility for prevention and detection rests with both those charged with governance and management. Primary, not exclusive — ¶.05 still binds the auditor to reasonable assurance.
¶.05 promises reasonable assurance about material misstatement and states that an unavoidable risk of non-detection exists even in a properly performed audit.
The auditor is bounded by materiality; a fraud examination is bounded by the allegation. That is why the same theft can be invisible to one and central to the other.
¶.07 explains why management fraud carries greater non-detection risk than employee fraud, and ¶.32(a) responds by requiring testing of journal entries and other adjustments.
¶.26 presumes that fraud risks exist in revenue recognition. It is rebuttable — and ¶.46 requires the reasons to be documented when the auditor concludes it is overcome.
¶.06 anticipates forgery, deliberate failure to record transactions and intentional misrepresentation, and notes that collusion can make false audit evidence look persuasive.
How a detection or audit-failure question gets worked rather than argued.
Whether an audit-failure theory exists at all, and what the board is told while it is being tested.
AU-C 240 ¶.03 says the auditor does not make legal determinations of whether fraud has actually occurred, and confines the auditor's concern to fraud causing material misstatement. ¶.05 promises reasonable, never absolute, assurance. A board reading an unqualified opinion as a fraud sweep has misread the document it paid for.
Three different ones, and naming the wrong one costs credibility immediately. Audits of private companies under US generally accepted auditing standards are governed by AU-C 240. Audits of SEC issuers are governed by PCAOB AS 2401, which the Board has an open project to reconsider but on which it has issued no proposal. Internationally, ISA 240 (Revised) was issued in July 2025 and applies to periods beginning on or after 15 December 2026. AU-C 240 is itself being superseded: SAS No. 151 was approved on 19 August 2026 and takes effect for periods ending on or after 15 December 2028, which means AU-C 240 remains the operative standard for essentially every audit now in dispute. State both dates together or the sentence is misleading.
A different question entirely, and the detection statistics are not a quality measure. In the ACFE's 2026 Report to the Nations, tips were the source of initial detection in 43% of cases, internal audit in 15%, and external audit in just 2% — fewer than automated transaction and data monitoring, and one-seventh the rate of internal audit. An audit is scoped to support an opinion on whether the financial statements as a whole are free from material misstatement, not to run down allegations. The numbers do argue for something, though: more than half of tips came from employees, and from 2028 SAS No. 151 will require the auditor to understand the entity's whistleblower or other fraud-reporting program, if it has one, including how management and those charged with governance address allegations made through it.
No, and the symmetry with the forensic side is worth noticing. AU-C 240 ¶.03 states that although the auditor may suspect or, in rare cases, identify the occurrence of fraud, the auditor does not make legal determinations of whether fraud has actually occurred. AICPA SSFS No. 1 ¶10 imposes the same limit on a member performing forensic services, reserving the ultimate conclusion of fraud to the trier of fact while expressly permitting opinions on whether evidence is consistent with certain elements. Two very different engagements, one prohibition. What separates them is objective, scope and materiality — not which professional gets to announce a verdict, because neither does.
For issuers, yes, and it is often the more concrete theory. Section 10A of the Securities Exchange Act of 1934, codified at 15 U.S.C. § 78j-1, requires that each audit include procedures designed to detect illegal acts having a direct and material effect on the financial statements, and establishes a reporting chain when the auditor becomes aware of one: escalation within the issuer, notification to the Commission by the issuer, and a direct report by the auditor if the issuer fails to notify. That is a statutory obligation, not a professional standard, which matters because the remedies and the enforcement posture differ. It also converts a diffuse should-have-caught-it theory into a checkable question about who told whom, and when.
Describe the engagement, the entity and the period. The Institute will help you see which paragraphs are in play.