A fraud encountered in the course of audit of financial statements may pose significant challenges to the auditor in ensuring that he is able to perform sufficient and appropriate audit procedures to mitigate the risk of material misstatement in the financial statements. Quite often, due to the complex nature of the fraud, the auditor may find himself constrained in ensuring that he has considered all possible facets in his evaluation. Read on to find out more….

Background

As per Standard on Auditing (SA) 240, “The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements”, the primary responsibility for the prevention and detection of fraud rests with both those charged with governance of the entity and management. SA 240 also states that an auditor conducting an audit in accordance with SAs is responsible for obtaining reasonable assurance that the financial statements taken as a whole are free from material misstatement, whether caused by fraud or error. One of the objectives of the auditor is to respond appropriately to identified or suspected fraud.

In this article, we shall attempt to look at a few practical considerations in the auditor’s endeavor to respond to a fraud identified by management. The issues discussed in this article are by no means exhaustive and their applicability depends on the facts and circumstances of the company.

Key Areas of Focus

  • Investigation
  • Scope
  • Robustness
  • Digital forensic
  • Ring fencing
  • Remedial actions
  • Audit procedures
  • Reporting implications

A. Review of Work Performed by Management

SA 260 para 12 and SA 200 require the auditor to maintain professional skepticism throughout the audit. Management may have been made aware of the potential fraud either via a whistleblower complaint or any other reviews or audits performed by them. In fact, the 2020 edition of the Report to the Nations on Occupational Fraud and Abuse by Association of Certified Fraud Examiners, USA (ACFE) lists down tips and internal audit as the most common modes through which potential frauds are initially detected. A likely scenario that an auditor is likely to encounter is that the management will have initiated or completed a preliminary investigation or a fact-finding review of some nature into the allegations prior to informing the auditor. This would also be a recommended procedure so that the management is able to verify the genuineness of whistle-blower complaint or is at least able to ensure the veracity of the findings from the internal review or internal audit, prior to informing this to the auditor. Discussing and highlighting the potential fraud to the auditor at the earliest would also hold good for the management so that the auditor’s valuable inputs can be obtained on the next course of action proposed by the management.

From the perspective of the auditor, an active engagement with the management at key stages of the investigation would also assist the auditor to conduct a ‘no surprises’ audit whereby his concerns or otherwise can be discussed with the management at the earliest opportunity available and a mutually agreeable course of action can be arrived at. It would also do well for the auditor to go through the whistleblower complaint (if any) in detail so that he is in a position to corelate them with the findings disclosed by management. A note of caution should also be exercised here. In the context of independence of the auditor, it would be suggested that the auditor does not indulge in over involvement in the process conducted by management lest his involvement is expected to potentially impair his independence and objectivity. He should toe the thin line of guiding management with his inputs on the next steps but also maintain adequate distance.

Now let’s look at a few considerations which the auditor may bear in mind while evaluating the investigative procedures performed by management.

B. Investigative Report or Fact-Finding Report (‘Investigation’)

SA 240 para 14 requires the auditor to investigate the inconsistencies where responses to inquiries of management or those charged with governance are inconsistent. In this pursuit, the auditor may request for documentation from the management which may broadly cover the following:

  1. Background of the matter
  2. Source (i.e. whistleblower, internal audit etc.)
  3. Scope of the review
  4. Work procedures conducted
  5. Detailed findings of the investigation
  6. Any additional potential matters of concerns noted during the review besides the specific matter under review
  7. Root cause
  8. Remedial actions proposed to plug the gaps in processes and internal controls

Such documentation would usually be expected to take the shape and form of a formal investigation report which will likely be shared by the management with the auditor. On some large and complex matters, the auditor may be provided with interim updates or draft reports at periodic intervals. The auditor should ensure that the final reports on all investigative procedures is shared with him by the management well in advance so as to enable the auditor to perform sufficient and appropriate audit procedures. Auditor is also encouraged to exercise professional skepticism at all stages of his review. Any findings which appear in the draft reports or interim updates and eventually dropped from the final report should be adequately explained by the management so that the auditor is satisfied that these do not impact his audit procedures in any manner.

C. Review of the Scope of the Investigation

The auditor may review the investigation report and satisfy himself that he is comfortable with the scope of the investigation. It may be helpful to specifically review the section on disclaimers / limitations / caveats as it may help him with fodder for further discussions with management. A high-level reconciliation of the scope of the investigation with the various allegations being investigated may help him obtain comfort on the completeness of the investigation scope. Any allegations or any area potentially not covered in the scope may be discussed with management and the investigation scope may be updated, if feasible.

D. Robustness of the Investigative Procedures / Fact Finding Review

SA 240 para 15 suggest that a discussion shall place within the engagement team and say particular emphasis on how and where the entity’s financial statements may be susceptible to material misstatement due to fraud, including how fraud might occur.

Engaging Third Party Specialist Investigators

Often depending on the complexity and pervasiveness of the fraud, it is not uncommon to find management engaging third party specialist investigators (‘specialist investigator’) to assist them in conducting a fact-finding review of the potential matter. Having a specialist firm perform the investigation on behalf of management would in all probability make the auditor more comfortable on the robustness of the investigative procedures. This is due to fact that the specialist investigator would be considered more competent since he would leverage on his wide experience in dealing with similar matters for other companies. Additionally, a specialist investigator would also be perceived to be independent from the management which would lend credence to the investigation. As a side note, the auditor should also be cautious before concluding on the independence and objectivity of the specialist investigator. On one occasion, it was found that the specialist investigator team comprised of certain ex-employees of the organization thereby requiring the auditor to closely examine the arrangement to obtain comfort that the review was conducted in an unbiased manner. On another occasion, the external law firm engaged to perform the investigation appeared to be the ex-employer of someone in the position of those charged with governance. This is not to suggest that the auditor cannot rely on the work performed by such specialist firm. The only point to be made is that the auditor should not blindly assume that the investigation has been completed in an independent and objective manner because it has been performed by an external specialist entity. He should perform all appropriate audit procedures which he considers necessary in the given circumstances.

Investigations Conducted by Internal Review Teams

On occasions where the management does not engage a specialist investigator to assist them, it is not uncommon for the investigation to be performed by either of the following: (a) the company’s internal audit team; (b) group internal audit team; (c) internal team (consisting of line managers) setup specially for conducting the investigation (collectively ‘internal review teams’). In situations where an internal review team has conducted the investigation, the auditor would probably need to examine the independence and objectivity of the investigation team in more detail. On one matter, it was observed that the Group Chief People Officer (CPO) was under investigation wherein the investigation team comprised of the HR head of one of the subsidiaries among others. The HR head of the subsidiary had a dotted line reporting to the Group CPO and hence quite obviously his independence and objectivity could be potentially impaired since he would be hesitant to openly highlight concerns or findings which would not be in favor of the CPO.

Internal review teams may also at times be constrained in the robustness of their work procedures due to either lack of appropriate support in the organization, lack of proper experience in conducting the investigation, inability to leverage on the usage of advanced forensic tools and lastly a relatively narrower focus on only investigating the matter at hand and thereby rendering them unable to properly ring-fence the issue. In such cases, it becomes imperative for the auditor to closely examine what was the composition of the internal review team and consider raising appropriate questions such as:

  • i. Was the internal review team independent and objective in terms of the areas which they have reviewed?
  • ii. To whom did the internal review team report to?
  • iii. Could there be any perceived potential conflict of interest?
  • iv. Did the internal review team comprise of individuals competent to investigate the relevant matter?
  • v. Was there due representation from all relevant departments depending on the nature of the alleged fraud?
  • vi. Was there any pressure on the internal review team to prematurely conclude their review?

E. Digital Forensic / Electronic Discovery Procedures

Now what do we mean by digital forensic or electronic discovery procedures? While the terms may sound daunting, simply put it refers to examination of digital evidence in order to examine facts and support the investigation. Electronic devices have proliferated our lives in a deep manner and consequently they harbor a treasure trove of information which can be forensically mined in order to uncover facts and information which otherwise may not be available.

With advent of time, while fraudsters have become smarter, technology is also finding ways and means to keep pace with them. The market is aflush with tools and technologies to assist investigators in uncovering information hidden in the deep crevices of electronic gadgets. Retrieval of deleted information from electronic devices can often provide incriminating evidence adequate to nail the fraudster. Smartphones and the data captured therein (phone call logs, messages etc.) can provide valuable evidence in establishing the identify of various perpetrators of the alleged fraud. The usage of various tools and technologies in the course of the investigation is what is referred to as digital forensic or electronic discovery procedures. These tools assist in forensically examining information stored in electronic devices such as laptops, desktops, smart phones, external storage devices etc. The topic of digital forensics is as vast as it is interesting and for the purpose of this article we shall focus on the key considerations from the perspective of the auditor:

  • Coverage of individuals (‘custodians’): It is recommended that the auditor may obtain a good understanding of the potential fraud and the various alleged individuals so that he is able to obtain comfort that the coverage of individuals for the purpose of digital review procedures is adequate. Key personnel alleged to have been involved in the potential fraud should be covered by management and the electronic devices used by them may be sequestered in order to conduct forensic procedures on them.
  • Coverage of electronic review: It may be helpful for the auditor to confirm with management whether all appropriate electronic devices have been scoped in for the review. In case the alleged individuals are known to use multiple electronic devices (i.e. laptops, desktops, smart phone, external hard drives, pen drives), whether all their devices have been covered under review. If they were not, management should be able to justify to the auditor the rationale for any exclusions.
  • Search terms or key words: Due to the voluminous warehouse of information captured by electronic devices, in the interest of costs and time, rather than boiling the ocean, it is generally preferred that the investigation focusses on the specific allegations and the matter under review so that the necessary supporting information can be retrieved from these electronic sources. In order to conduct a targeted review, it is not uncommon to find that certain specialized tools are deployed over the data obtained from these devices which enable execution of certain ‘search terms’ or ‘key words’ which are devised in a manner such that they would assist in retrieving information relevant to the investigation. In case the investigative approach has relied on a search terms-based review, the auditor may inquire with management on the robustness of these search terms and evaluate whether he comfortable with the same.

Depending on facts and circumstances and the nature of the potential fraud, while it may not be absolutely necessary for digital forensic procedures to be conducted, it would be worthwhile for the auditor to satisfy himself that the absence of digital forensic procedures has not compromised on the effectiveness of the investigation. Considering the importance of conducting digital evidence review, it would be recommended that the auditor obtain a rationale from management for not conducting such procedures.

F. Ring Fencing of the Issues

While have looked at evaluating completeness of the scope in the previous section, it is equally critical to evaluate the completeness of investigative procedures. While we have looked at one element in evaluating completeness earlier namely digital evidence review procedures, another important aspect is to ensure that all appropriate investigative procedures are performed such that there are no additional areas which are impacted by the fraud other than those already identified. The auditor may review the investigation report and obtain comfort that:

  1. Establishing the ‘span of control’ of the alleged individuals and whether it has been established that there are no additional individuals who maybe potentially involved beyond those identified;
  2. Confirming that fraud does not extend beyond the period identified; and
  3. All areas which maybe potentially impacted have been covered under the investigation;
  4. The impact of the fraud has been correctly established.

G. Discussions with the Investigating Team

It may helpful for the auditor to also engage in discussions or meetings with the investigating team either in the presence of management or otherwise, in order to supplement his audit procedures. Interaction with the investigating team may assist the auditor in clarifying any doubts on positions which have been take in the course of the investigation. Inquiries with the investigative team may also assist the auditor in obtaining corroborative evidence that there have not been any undue limitations or scope restrictions placed on the investigating team.

H. Remedial Actions Taken by Management

The auditor may obtain an understanding of what remedial actions have been taken by management once the fraud was identified. Remedial actions may include, but not be limited to, termination of employment of the alleged employees, instituting / reinforcing internal controls over the fraud prone areas, recording additional accounting entries to account for the impact of the fraud etc. In some cases, management may even consider outsourcing the particular business process to a third party shared service centre if the company is not in a position to implement relevant internal controls in the fraud prone area.

I. Additional Audit Procedures Performed by the Auditor

The auditor cannot be merely satisfied knowing that management has taken completed the investigation. The auditor may also be required to adapt and modify his audit procedures to obtain evidence that due and appropriate action for the fraud matters have been taken and the impact of which should be appropriately reflected in the financial statements, depending on materiality. The auditor may consider additional audit procedures such as more in-depth audit testing of the specific areas impact by the fraud which may involve increasing the sample sizes to be tested by him, obtaining appropriate management representations for the fraud matter, performing a review of the working papers of the investigation (if available and feasible), involving the auditor’s expert in verifying any aspect of the investigative procedures if the auditor does not have competency to do so. In summary, the auditor may invariably need to consider altering the nature timing and extent of his audit procedures in order to obtain his audit comfort.

J. Assessing the Impact on the Reporting Implications

Lastly, but also most importantly, the auditor will finally need to consider his reporting obligations for the fraud matter. Depending on the materiality, impact and pervasiveness of the issues, the auditor may have to consider either all or any of:

  • (i) Ensuring that management discloses the matter in the notes to financial statements;
  • (ii) Considering whether the CARO report needs to be modified;
  • (iii) Considering whether there is a impact on the Internal Financial Controls (IFC) and whether these have been remediated in advance of the financial year end for the auditor to consider its impact on the IFC opinion;
  • (iv) Evaluate whether the fraud matter is indicative of potential non-compliance to any laws or regulations (NOCLAR) and then ascertain the disclosure requirements;
  • (v) Considering whether the matter also merits reporting under section 143(12) of the Companies Act, in case certain conditions are met (Refer ‘Guidance Note on Reporting on Fraud under Section 143(12) of the Companies Act, 2013’ issued by the Institute in this regard).

Conclusion

As you have seen above, the road to successfully navigate a fraud matter at the entity, is strewn with potential challenges posed by various complexities and uncertainties. However, if the auditor plans his audit well and in advance, engages in constant dialogue with the management and maintains a razor sharp focus, then all of the challenges can be successfully overcome.


Author may be reached at: vinayknayak@gmail.com and eboard@icai.in