ASA 240 Revised Fraud Risk Assessment in Australia: What Businesses Must Know for 2026-27
Revised ASA 240 takes effect December 2026, strengthening auditor fraud risk obligations. Learn what Australian businesses should expect from their auditor.
A landmark revision to Australia's fraud auditing standard is set to reshape how auditors approach risk assessment, professional scepticism, and reporting from December 2026. The revised ASA 240 — The Auditor's Responsibilities Relating to Fraud in an Audit of a Financial Report — introduces the most significant changes to fraud auditing in over 15 years. For Australian businesses subject to audit, understanding what these changes mean in practice is essential for productive engagement with your auditor and for strengthening your own internal controls.
Understanding ASA 240 and Why It Has Been Revised
ASA 240 is the Australian auditing standard that governs how auditors identify, assess, and respond to the risk of material misstatement due to fraud. It is the Australian equivalent of the international standard ISA 240, issued by the International Auditing and Assurance Standards Board (IAASB).
The revision — issued by the Auditing and Assurance Standards Board (AUASB) in October 2025 — responds to sustained stakeholder concern about audit quality following a series of high-profile corporate failures globally and in Australia. Regulators, investors, and the public have questioned whether auditors were doing enough to detect and respond to fraud, and whether existing standards provided sufficient clarity about auditor responsibilities.
The revised standard becomes operative for financial reporting periods beginning on or after 15 December 2026. For most Australian companies with a 30 June year-end, this means the new requirements will first apply to the audit of the financial year ending 30 June 2028. However, auditors are expected to begin updating their methodologies and training well in advance, and businesses should anticipate more rigorous fraud-focused procedures from their auditors in the lead-up to the effective date.
Key Changes in the Revised ASA 240
The revised standard introduces several substantive changes that will affect how audits are conducted and what auditors ask of management and those charged with governance.
The "Fraud Lens" Approach
One of the most significant conceptual shifts in the revised standard is the requirement for auditors to apply a "fraud lens" throughout the entire audit — not just during the risk assessment phase. This means auditors must actively consider the possibility of fraud when understanding the entity, its environment, and its system of internal control, and must remain alert for indicators of fraud right through to the completion of the engagement.
The previous standard allowed auditors to accept records and documents as genuine unless they had specific reason to believe otherwise. The revised ASA 240 deletes this principle, replacing it with an explicit requirement to investigate conditions that suggest a document might not be authentic. This is a meaningful shift in the burden of professional scepticism.
Strengthened Professional Scepticism Requirements
Professional scepticism — the auditor's questioning mind and critical assessment of audit evidence — is central to the revised standard. ASA 240 (Revised) reinforces that auditors must maintain professional scepticism throughout the engagement, not just when specific fraud risk factors are identified. Auditors are now explicitly required to remain alert for information indicative of fraud even near the end of the audit, when time pressure can otherwise lead to reduced vigilance.
Enhanced Fraud Risk Factor Assessment
The revised standard aligns more closely with ASA 315 (Revised), which governs the identification and assessment of risks of material misstatement. Auditors must now apply the fraud lens when understanding internal control components relevant to fraud prevention — including whistleblower programs, anti-fraud policies, and management override controls. There is also a greater emphasis on considering fraud risk factors at both the financial statement level and the assertion level for specific account balances and disclosures.
New Requirements for Responding to Identified Fraud
When fraud is identified or suspected, the revised standard introduces new requirements for how auditors must respond. Except for matters deemed "clearly inconsequential," the engagement partner must determine whether additional risk assessment procedures or substantive audit procedures are necessary. Auditors must also understand how the entity has responded to identified or suspected fraud — including whether management has investigated the matter and what remedial actions have been taken.
Fraud as a Key Audit Matter
Where the auditor's report includes Key Audit Matters (KAMs) — as required for listed entities and certain other public interest entities — the revised standard requires auditors to identify matters related to fraud that required significant attention during the audit and determine whether they should be classified as KAMs. This increases transparency for investors and other stakeholders about the fraud risks the auditor considered most significant.
Australian-Specific Requirements
The AUASB has included specific "Aus" paragraphs in ASA 240 (Revised) to address Australian legislative requirements. These include procedures for resignation or withdrawal from an engagement, which must comply with the Corporations Act 2001 and may require consent from the Australian Securities and Investments Commission (ASIC). Auditors are also reminded of their statutory obligations to notify ASIC of certain circumstances — including suspected contraventions of the Corporations Act — as required by sections 311 and 601HG of that Act.
What This Means for Australian Businesses
The revised ASA 240 will change the nature and intensity of fraud-related audit procedures. Businesses should expect their auditors to ask more probing questions about fraud risk, internal controls, and management's response to identified concerns. These are the practical implications to prepare for.
More Detailed Fraud Risk Discussions
Auditors will be required to have more substantive discussions with management and those charged with governance about fraud risks — including the risk of management override of controls, which is presumed to exist in every audit. Boards and audit committees should be prepared to engage meaningfully with these discussions, not treat them as a formality.
Greater Scrutiny of Internal Controls
The fraud lens approach means auditors will examine internal control components — including whistleblower programs, segregation of duties, and authorisation frameworks — with a more critical eye. Businesses with weak or undocumented controls in these areas should address them proactively rather than waiting for audit findings.
Increased Documentation Requirements
Auditors will need to document their fraud risk assessments, the procedures performed in response to identified risks, and the conclusions reached more thoroughly than under the previous standard. This may increase the volume of information requested from management during the audit process.
Australian Regulatory Context
The revised ASA 240 sits within a broader regulatory environment in which ASIC has been increasing its focus on audit quality and auditor accountability. ASIC's annual audit inspection program regularly identifies deficiencies in fraud risk assessment as a recurring area of concern, and the regulator has made clear that it expects auditors to apply genuine professional scepticism rather than accepting management representations at face value.
The Companies Auditors Disciplinary Board (CADB) has the power to take disciplinary action against Registered Company Auditors (RCAs) who fail to meet professional standards, including those relating to fraud risk assessment. ASIC can refer matters to the CADB where it identifies significant departures from auditing standards.
The revised standard also interacts with ASQM 1 — the Australian standard on quality management for audit firms — which requires firms to have robust systems for managing engagement quality, including the quality of fraud risk assessment procedures. Firms that have not yet fully embedded ASQM 1 into their practice management systems will need to ensure their fraud-related procedures are updated in line with ASA 240 (Revised) before the effective date.
For entities subject to the Corporations Act 2001, the auditor's obligations under ASA 240 (Revised) are reinforced by statutory duties to report suspected fraud or contraventions to ASIC. This creates a direct link between the auditing standard and the regulatory enforcement framework.
Questions to Ask When Choosing an Auditor
In light of the revised ASA 240, these are the key questions Australian businesses should ask when selecting or evaluating an auditor:
- How are you updating your methodology for ASA 240 (Revised)? — Understand what changes the firm is making to its fraud risk assessment procedures and training programs
- How do you apply the fraud lens throughout the audit? — Ask for specific examples of how the firm maintains fraud awareness beyond the initial risk assessment phase
- What is your approach to professional scepticism? — Explore how the firm challenges management representations and tests the authenticity of documents
- How do you assess the risk of management override of controls? — This risk is presumed to exist in every audit; understand what specific procedures the auditor performs
- What fraud-related matters have you identified in similar engagements? — Industry experience with fraud risk factors relevant to your sector is valuable
- How do you communicate fraud findings to the board and audit committee? — Timely, clear communication is essential for effective governance
- Are you registered with ASIC as a Registered Company Auditor? — Confirm the auditor holds the required registration for your entity type
How MyMoney® Can Help
Selecting an auditor who is genuinely prepared for the revised ASA 240 requirements — and who brings the professional scepticism and fraud expertise that the standard demands — is a decision that deserves careful consideration. The right auditor does more than sign off on financial statements; they provide meaningful assurance that your financial reporting is free from material misstatement due to fraud or error.
MyMoney® connects Australian businesses with qualified Registered Company Auditors who are up to date with the latest AUASB standards, including the revised ASA 240. Whether you need an auditor for a proprietary company, a listed entity, an SMSF, or a not-for-profit, the right specialist can provide the rigorous, independent assurance your stakeholders expect.
Post a Brief on MyMoney® to receive tailored proposals from qualified auditors with proven expertise in fraud risk assessment and ASA 240 compliance. Or Browse Auditors on MyMoney® to find experienced professionals ready to deliver high-quality audit assurance for your organisation.
This article provides general information only and does not constitute personal financial advice. Consider whether the information is appropriate for individual circumstances before acting on it. MyMoney® Marketplace is operated by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640).