AICPA Put Fraud Audits On A 2028 Clock

A new auditing standard gives firms two years to tighten how fraud risk is identified, documented, escalated, and explained.

The deadline looks distant. The workflow change does not. SAS No. 151 puts a sharper fraud lens on audit planning, and firms that wait until 2028 will be rebuilding methodology while clients are already asking harder questions about whistleblower reports, revenue recognition, and suspicious findings.

What changed

The Auditing Standards Board approved Statement on Auditing Standards No. 151, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements. The standard supersedes the older fraud guidance in SAS No. 122 as amended, and it adds more specific requirements around skepticism, fraud risk assessment, documentation, communication, and auditor response when fraud or suspected fraud appears.

It does not make auditors responsible for preventing fraud. Management and those charged with governance still own prevention and detection. It also leaves the definition of fraud and the auditor's reasonable-assurance objective intact.

LL

Ledger Lowdown

Get the most important accounting, tax, and finance news in a free daily email. Built for accountants, CPAs, and tax pros.

Subscribe free

The whistleblower file matters more

One practical change is easy to miss: if an entity has a whistleblower program or another fraud-reporting channel, auditors will need to understand it. That includes how management and governance address allegations made through the program.

For audit teams, that means the fraud conversation can no longer live only in planning memos and inquiry checklists. Hotline intake, allegation triage, board reporting, and management's response process may all become part of the audit trail.

Revenue recognition stays presumed risky

The standard keeps the presumption that fraud risks exist in revenue recognition. Auditors still have to determine which revenue transaction types or relevant assertions create those risks, then design responses that fit the client's facts.

That is where firms should expect the most pressure. Generic fraud language will be harder to defend when the standard is asking for clearer links between risk identification, procedures performed, evidence gathered, and communication with management or governance.

The implementation runway is real

SAS No. 151 is expected to be published in October and applies to audits of financial statements for periods ending on or after Dec. 15, 2028. Early implementation is allowed.

The smart move is to use the runway for a controlled methodology review. Compare current fraud-risk templates against the new requirements, test whether engagement files show a fraud lens during AU-C 315 risk assessment, and decide how whistleblower allegations will be documented before teams are in deadline mode.