- Ledger Lowdown
- Posts
- AICPA Put Fraud Audits On A 2028 Clock
AICPA Put Fraud Audits On A 2028 Clock
A new auditing standard gives firms two years to tighten how fraud risk is identified, documented, escalated, and explained.

The deadline looks distant. The workflow change does not. SAS No. 151 puts a sharper fraud lens on audit planning, and firms that wait until 2028 will be rebuilding methodology while clients are already asking harder questions about whistleblower reports, revenue recognition, and suspicious findings.
What changed
The Auditing Standards Board approved Statement on Auditing Standards No. 151, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements. The standard supersedes the older fraud guidance in SAS No. 122 as amended, and it adds more specific requirements around skepticism, fraud risk assessment, documentation, communication, and auditor response when fraud or suspected fraud appears.
It does not make auditors responsible for preventing fraud. Management and those charged with governance still own prevention and detection. It also leaves the definition of fraud and the auditor's reasonable-assurance objective intact.
Ledger Lowdown
Get the most important accounting, tax, and finance news in a free daily email. Built for accountants, CPAs, and tax pros.
Subscribe freeThe whistleblower file matters more
One practical change is easy to miss: if an entity has a whistleblower program or another fraud-reporting channel, auditors will need to understand it. That includes how management and governance address allegations made through the program.
For audit teams, that means the fraud conversation can no longer live only in planning memos and inquiry checklists. Hotline intake, allegation triage, board reporting, and management's response process may all become part of the audit trail.
Revenue recognition stays presumed risky
The standard keeps the presumption that fraud risks exist in revenue recognition. Auditors still have to determine which revenue transaction types or relevant assertions create those risks, then design responses that fit the client's facts.
That is where firms should expect the most pressure. Generic fraud language will be harder to defend when the standard is asking for clearer links between risk identification, procedures performed, evidence gathered, and communication with management or governance.
The implementation runway is real
SAS No. 151 is expected to be published in October and applies to audits of financial statements for periods ending on or after Dec. 15, 2028. Early implementation is allowed.
The smart move is to use the runway for a controlled methodology review. Compare current fraud-risk templates against the new requirements, test whether engagement files show a fraud lens during AU-C 315 risk assessment, and decide how whistleblower allegations will be documented before teams are in deadline mode.