The American Institute of CPAs' Auditing Standards Board adopted new guidance governing the auditor's responsibility for identifying fraud or suspected fraud in a financial statement.
The revised guidance aims to clarify and enhance those responsibilities under the older guidance and takes effect in December 2028. The ASB's adoption of Statement on Auditing Standards (SAS) No. 151, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements, supersedes SAS No. 122, Statements on Auditing Standards: Clarification and Recodification, as amended (Section 240, Consideration of Fraud in a Financial Statement Audit), and amends several other standards.
The new standard arrives after the Public Company Accounting Oversight Board came under pressure in 2024 from major auditing firms and groups including the AICPA to
SAS No. 151 bolsters audit procedures related to fraud while stressing that management and those responsible for governance of an entity remain primarily responsible for preventing and detecting fraud. The standard doesn't actually change the definition of fraud, nor change the auditor's overall objective of obtaining reasonable assurance that financial statements are free of material misstatement due to fraud or error. But it adds more specific requirements for improving auditor skepticism, fraud risk assessment, documentation, communication and responses when fraud is identified or suspected.
The new standard will help auditors more clearly understand their role in assessing risks of material misstatement due to fraud and their response when fraud or suspected fraud is identified in a financial statement audit.
"It is critical for auditors to remain alert to the possibility of fraud throughout an audit engagement," said AICPA chief auditor Jennifer Burns in a statement Thursday. "This standard reinforces the importance of professional skepticism and provides clearer direction for how auditors should respond when fraud is identified or suspected."
The major changes in SAS No. 151 include:
- Enhancing the auditor's risk identification and assessment process as it relates to fraud by providing a fraud lens when performing risk assessment procedures in accordance with AU-C section 315;
- Requiring the auditor to understand the entity's whistleblower program (or other program to report fraud), if the organization has such a program, including how management and, if applicable, those charged with governance address allegations of fraud made through the program;
- More requirements governing how auditors respond when fraud or suspected fraud is identified, and more extensive requirements regarding communications with management and those charged with governance;
- Leaves unchanged the presumption that fraud risks exist in revenue recognition, and requires auditors to determine which types of revenue transactions or relevant assertions give rise to such risks.
The final version of the standard is expected to be published in October. SAS No. 151 will be effective for audits of financial statements for periods ending on or after Dec. 15, 2028, but firms can implement it earlier.






