Revising Auditing Standard 240 on Fraud: What It Means for the Finance Function
In August 2026 the Japanese Institute of Certified Public Accountants issued an exposure draft revising Auditing Standard 240, “Fraud in an Audit of Financial Statements.”
It would be a mistake to file this as an audit firm matter. As the auditor’s work on fraud risk becomes more explicit, the demands land on the company’s accounting and internal control functions too. What follows is the view from the audited side.
Why the standard is being revised
The background is a run of corporate scandals internationally. Each one produces the same question: the company was audited, so why was this not found? ISA 240 was revised in response, and Japan is now following.
The point is not an open-ended expansion of auditor responsibility. It is that the fraud lens is being built more explicitly into every stage, from risk assessment through to response.
“Fraud or suspected fraud” — and your response to it
The draft clarifies what the auditor does on identifying fraud or suspected fraud. That covers not only what the auditor finds directly but also allegations raised from inside or outside the company.
The consequential point for management is this: the auditor evaluates whether the company’s own investigation and remediation were adequate. So once a suspicion surfaces, you need to be able to account for who investigated it, how the facts were established, and what was changed as a result. That is a standing capability, not something assembled after the fact.
Whistleblowing becomes an audit topic
Where a company operates a whistleblowing channel, the draft makes explicit that the auditor will seek to understand that system and how management responds to allegations raised through it.
This stops being a finance-only question. It requires information to flow between internal audit, legal, compliance, the audit and supervisory board, and accounting. In particular, the judgement that “a report came in but it does not affect the numbers, so it is not the auditor’s concern” needs to be made far more carefully than it has been.
Revenue recognition and management override
Revenue recognition and management override of controls have long been treated as significant fraud risks, and the draft keeps that position — noting in particular that rebutting the presumption of fraud risk in revenue recognition is not ordinarily appropriate.
Expect more questions than before on cut-off, large transactions near period end, manual journal entries and estimates: not just the number, but the reasoning behind it.
The response is not to generate more audit deliverables. It is to have a working process for how indicators of fraud get identified, shared internally, investigated, and assessed for accounting impact. If whistleblowing, internal audit, accounting treatment and reporting to the audit and supervisory board are managed in four separate places at your company, the handoffs between them are worth revisiting now.
A CPA’s view
“Accounting fraud” brings to mind large-scale financial misstatement. In practice it rarely begins that way. A judgement call on when revenue is recognised, an exception approved by a senior manager, a whistleblowing report that is handled quietly — the small signals are often where it starts.
Read that way, this revision is less a change to audit procedure than an occasion to re-examine your own financial reporting process and governance.
