This article will count 0.25 units (15 minutes) of unverifiable CPD. Remember to log these units under your membership profile.

The AICPA's Auditing Standards Board has issued a new standard, SAS No. 151, The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements. It supersedes SAS No. 122, as amended, including AU-C Section 240, and also amends several other auditing standards. The standard sets out and clarifies what auditors must do when considering fraud in a financial statement audit.

The big picture is that the standard does not move the fundamental goalposts; it tightens and clarifies the process for getting there. In practice, dealing with suspected fraud is difficult not only for auditors but also accountants. How far do you need to go and when do you need to stop? What are the steps that should be followed? While these questions may not be fully addressed by the audit standards, they give useful new insights that should be noted.

What stays the same

  • The definition of fraud is unchanged.

  • The auditor's fundamental objective is unchanged. The auditor still needs to obtain reasonable assurance that the financial statements as a whole are free from material misstatement, whether due to fraud or error.

  • Management and those charged with governance remain responsible for preventing and detecting fraud. The auditor's responsibility is to obtain reasonable assurance that the financial statements are free from material misstatement due to fraud or error. The auditor is not the fraud police.

What is new

  • A fraud perspective in risk assessment. Instead of treating fraud as a separate box to tick, auditors must bring a fraud perspective into the normal risk identification and assessment process.

  • Whistleblower programmes become part of the auditor's understanding of internal control. If the entity has a whistleblower or other fraud-reporting programme, the auditor must understand how the programme operates and how management and, where applicable, those charged with governance respond to allegations of fraud made through it.

  • Clearer requirements when fraud or suspected fraud is identified. There is more prescribed work to do, together with enhanced communication requirements for management and those charged with governance.

  • Revenue remains a presumed fraud risk. But the auditor must determine which types of revenue transactions or relevant assertions give rise to that presumed fraud risk, rather than simply making a general statement about revenue.

  • More documentation and a stronger emphasis on professional scepticism.

Timing matters here. The final text is expected to be posted online in October 2026. SAS No. 151 will apply to audits of financial statements for periods ending on or after 15 December 2028, although early implementation is permitted.

How this compares with ISA 240

The first thing to say is that ISA 240 has already been through a similar revision. The IAASB issued ISA 240 (Revised) in July 2025, and it applies to audits of financial statements for periods beginning on or after 15 December 2026.

For South African practitioners, this is the relevant standard. ISA 240 (Revised) was adopted for use by registered auditors in South Africa, with the standard effective for audits of financial statements for periods beginning on or after 15 December 2026.

So SAS No. 151 is not a completely new idea. There is considerable convergence between the AICPA's new fraud standard and the IAASB's revised ISA 240.

Where the two standards agree

The overlap is striking:

  • Both apply a fraud perspective to risk assessment. ISA 240 (Revised) integrates consideration of fraud risks into the auditor's risk identification and assessment process and aligns this work with ISA 315.

  • Both address whistleblower and fraud-reporting programmes. ISA 240 (Revised) requires the auditor to understand relevant aspects of the entity's internal control, including its whistleblower or other fraud-reporting programme and how the entity responds to allegations of fraud.

  • Both strengthen the response when fraud or suspected fraud is identified. ISA 240 (Revised) contains a dedicated section dealing with the auditor's responsibilities in these circumstances, including understanding the fraud or suspected fraud, considering the entity's response and determining whether additional audit procedures are necessary.

  • Both reinforce communication and professional scepticism. The revised ISA places particular emphasis on professional scepticism, communication with those charged with governance and enhanced documentation.

Where ISA 240 goes further

There are nevertheless some important differences.

  1. Reporting to the public

    This is one of the most significant differences. ISA 240 (Revised) introduces specific requirements for fraud-related matters to be considered when determining Key Audit Matters under ISA 701. Where ISA 701 applies, the auditor considers fraud-related matters that required significant auditor attention and determines which were of most significance for communication as KAMs in the auditor's report.

    SAS No. 151 has no equivalent KAM requirement. The practical effect is that, under the international framework, certain significant fraud-related matters can feed through into the auditor's public reporting, whereas SAS No. 151 does not create a comparable reporting mechanism.

  2. The revenue presumption

    Both standards retain the presumption that revenue recognition gives rise to a fraud risk.

    ISA 240 (Revised) goes further by stating that, because of the significance of fraud risk factors associated with revenue recognition, it will ordinarily be inappropriate to rebut the presumption. SAS No. 151 does not adopt that additional restriction, but it does require auditors to determine which types of revenue transactions or relevant assertions give rise to the presumed fraud risk.

    The practical difference is therefore narrower than simply saying that one standard keeps the presumption and the other does not.

  3. Fraud or suspected fraud gets a dedicated response

    ISA 240 (Revised) introduces a dedicated section setting out what the auditor must do when fraud or suspected fraud is identified. The auditor must obtain an understanding of the fraud or suspected fraud, including how the entity has responded, and determine whether additional audit procedures are necessary.

    The standard also strengthens the related communication requirements. SAS No. 151 introduces similar additional requirements when fraud or suspected fraud is identified.

  4. Fraud and going concern: a package effect

    There is also a package effect internationally. ISA 240 (Revised) was developed alongside the revised ISA 570 on going concern, and the two standards have the same effective date. The IAASB has highlighted the connection between fraud and financial distress, recognising that the two can be interrelated risks that need to be addressed together.

    The AICPA announcement on SAS No. 151 does not make a similar linkage with its going-concern standard.

What this means in South Africa

South African registered auditors will not apply SAS No. 151 simply because it is the newer US standard. The relevant framework for them is ISA 240 (Revised). That means the immediate implementation priority for South African audit practices is ISA 240 (Revised), which becomes effective for audits of financial statements for periods beginning on or after 15 December 2026. Firms should therefore be considering the implications for their audit methodologies, risk assessment processes, fraud inquiries, documentation, communication with those charged with governance and responses to identified or suspected fraud.

Effective dates

This is the practical difference for anyone working across both frameworks. ISA 240 (Revised) applies to periods beginning on or after 15 December 2026. For a calendar-year entity, that generally means the first financial statements audited under the revised standard will be those for the year ending 31 December 2027.

SAS No. 151 applies to periods ending on or after 15 December 2028. For a calendar-year US entity, that generally means the first financial statements audited under the new standard will be those for the year ending 31 December 2028.

Firms operating under both frameworks will therefore have to manage different effective dates and implementation requirements for a period.

One bit of context worth noting

SAS No. 151 also arrives against the backdrop of the PCAOB's separate proposal concerning auditors' responsibilities for a company's noncompliance with laws and regulations, commonly referred to as NOCLAR.

The PCAOB issued its NOCLAR proposal in 2023 and reopened the comment period in February 2024 following a stakeholder roundtable. The proposal would have strengthened auditors' responsibilities to identify, evaluate and communicate matters involving noncompliance with laws and regulations, including fraud.

The two initiatives should not, however, be treated as the same reform. SAS No. 151 deals specifically with fraud in financial statement audits, while the PCAOB's NOCLAR project addresses a broader range of noncompliance with laws and regulations.

The bottom line

SAS No. 151 does not fundamentally redefine the auditor's objective in relation to fraud. Instead, it makes the auditor's responsibilities more explicit and prescriptive.

For US auditors, the changes mean a sharper fraud perspective in risk assessment, greater attention to whistleblower programmes, more specific responses when fraud or suspected fraud is identified, clearer requirements around revenue-related fraud risks, stronger communication and documentation, and an increased emphasis on professional scepticism.

For South African auditors, however, the more immediate development is ISA 240 (Revised), which takes effect from December 2026. While there is substantial convergence between the two standards, practitioners working across both frameworks will need to understand the differences as well as the similarities.

The message is therefore fairly simple: the auditor is not becoming the fraud police, but the standard is making it harder for the auditor's fraud work to remain a box-ticking exercise.

Previous
Previous

AGOA Extended to 2028: What It Means for Exporters

Next
Next

R88 Billion Unclaimed: Treasury's New Framework Explained