CAS 240 revised: what actually changes on your file
You read "effective December 15, 2026" and your stomach drops, because that sounds like this year. Take a breath. For most of your clients, it isn't.
CAS 240 is the fraud standard, and the revised version is here. Canada adopted the international changes with no new tweaks. The headline date is real, but it points to periods that begin on or after December 15, 2026. For a calendar-year client, that's the 2027 year end, which you'll audit in early 2028. Your December 2026 files run under the old standard.
So, you have a bit of runway. But not as much as it looks, and the work to get ready starts now.
Here's what you'll learn: when this actually hits your files, what changes in your fraud procedures and documentation, what changes in the report you issue, and what to hand your staff before the first periods land.
First, the date everyone gets wrong
"Beginning on or after December 15, 2026" in plain English
The standard applies to audits of financial statements for periods beginning on or after December 15, 2026. That one word, beginning, does a lot of work. It's not periods ending then. It's periods that start on or after that date.
For a calendar year company, the first period that starts after the cutoff is the year that begins January 1, 2027. That's the December 31, 2027 year end. You'll be in the field on it in early 2028.
What this means for your December year ends
Let's run the dates on a real file. Say you have an owner-managed contractor with a December 31, 2026 year end. That period began January 1, 2026. January 2026 is before December 15, 2026, so the file is not caught. It runs under the current CAS 240.
Now an off-calendar example. A client with a June 30 year end. The June 30, 2027 period began July 1, 2026, which is still before the cutoff, so it's out too. The June 30, 2028 period begins July 1, 2027, so that one is in.
The first files you'll see under the new standard are off-calendar year ends that begin just after December 15, 2026. A January 31, 2028 year end starts February 1, 2027 and is caught. After that, the wave of December 31, 2027 calendar files comes through in early 2028.
Why you still can't sit on it
The runway is real, but it's shorter than it feels. Three reasons:
- Off-calendar clients come first. If you have a January or February year end in the book, that's your first live file, and it could land in early 2028 planning. You don't want to be redesigning the fraud program while the engagement is open.
- Templates and methodology take time. Your CaseWare programs, risk assessment forms, and documentation templates all need updating. That's a project, not an afternoon.
- Staff need training. The people who run fraud procedures have to understand the new steps before they apply them. Better to coach them off-season than mid-audit.
So the message to the team is simple. This isn't a fire drill for this season's December files. It's a build-it-now job so you're ready when the first 2027 periods arrive.
The mindset shift: fresh eyes, no free passes
This is the part that changes how the work feels, even before you touch a single procedure.
The line they deleted
The old standard let you exercise skepticism "notwithstanding the auditor's past experience of honesty and integrity" of management and those charged with governance. The revised standard takes that line out. The point is blunt. Past trust in management and those charged with governance is no longer something you lean on.
CPA Ontario puts the intent plainly. The change is meant to push you to approach each engagement with a fresh pair of eyes.
In practice, this means your tenth year on a clean, friendly client doesn't earn them a lighter fraud assessment. You can't write "management has always been honest" and move on. You assess this year's risk on its own.
The no-bias evidence rule
There's a new requirement that's easy to miss and important to get. You have to design and perform your fraud procedures in a way that isn't biased toward evidence that backs up management's story, and isn't biased toward leaving out evidence that contradicts it.
Think about how confirmation bias creeps into a file. You expect a balance to be fine, so you pick the test that confirms it and stop. Under the revised standard, that habit is a documented problem. You build procedures that could turn up a contradiction, and you follow the ones that do.
Stay alert the whole way through
Skepticism isn't just a planning step now. There's a new requirement to stay alert across the whole audit for information that points to fraud risk factors or signs of fraud. Something odd shows up during fieldwork, you don't park it because risk assessment is "done." You loop back.
A sharper fraud lens in risk assessment
The risk side is where most of the real procedure changes sit. The standard calls it a "fraud lens," and it ties tighter to CAS 315.
Management override stays a significant risk
No change in spirit here, but the standard sharpens it. Management override of controls is a risk that lives at the financial statement level and is always a significant risk, because of how unpredictably it can happen. Your job is to work out whether it pushes down into specific assertion-level risks too. Journal entry testing, estimates review, and unusual transactions stay your core responses.
The whistleblower question (and your small clients)
New requirement: obtain an understanding of the entity's whistleblower program, meaning any channel for reporting fraud, and how management or those charged with governance deal with allegations that come through it.
Here's the practical wrinkle for a small private client. A 12-person owner-managed company usually has no formal whistleblower program. That's fine. You still have to obtain and document an understanding, which means writing down that there's no formal program and how concerns actually get raised, often a quiet word to the owner. Don't skip the step just because the answer is "they don't have one."
Journal entries: now prove the population is complete
This one trips people up. There's an added requirement to obtain audit evidence about the completeness of the population of journal entries and other adjustments for the period.
In plain terms, you can't just export whatever the system hands you and test a sample from that. You need evidence that the population you pulled is actually complete. Reconcile the count and dollar total of the extracted journal entries back to a control total in the general ledger before you select anything. If your sample comes from an incomplete population, the testing underneath it doesn't hold.
Estimates get a tighter look too. You review accounting estimates for indicators of possible management bias, and you have to factor in what your retrospective review of prior estimates turned up. The standard links this straight to CAS 540.
The new stand-back step
What you're actually checking
The revised standard adds a stand-back requirement. Before you conclude, you stop and evaluate two things based on the procedures you ran and the evidence you got:
- Do your fraud risk assessments still hold up?
- Did you get sufficient appropriate evidence in response to those assessed risks?
It's a deliberate pause to reassess before you wrap.
Where it sits in the file
This belongs near completion, after fieldwork and before sign-off. A short, dated memo works. What were the assessed fraud risks, what did the work show, do the assessments still make sense in light of what you found, and is the evidence enough. If something shifted during the audit, this is where you show you caught it and responded.
When you find fraud or suspected fraud
The "clearly inconsequential" threshold
Good news for proportionality. When you identify fraud or suspected fraud, the standard now lets you set aside matters that are clearly inconsequential, as long as you've first obtained enough understanding of what happened.
Picture a junior who padded a $40 mileage claim. Once you understand it and you're satisfied it's clearly inconsequential and isolated, you can document why and move on without launching a full fraud response. The judgment, and the write-up of that judgment, has to come first.
The engagement partner's call
The standard is explicit that the engagement partner, with input from the team, owns the evaluation of how identified or suspected fraud affects the audit. That includes whether to run more risk procedures or design further work. It's a partner-level decision, not something a senior quietly resolves and buries in the file.
Documentation: write down more than you used to
Across all of this, the documentation bar goes up. The standard expands what you record in two areas:
- Your understanding and risk work. Key elements of your understanding of the entity, its environment, the reporting framework, and its system of internal control, plus where that understanding came from and the risk procedures you ran.
- Fraud you found and what you did about it. Any fraud or suspected fraud identified, the results of your procedures, the significant judgments you made, and the conclusions you reached.
The theme is consistent. If you exercised judgment, show it. "Fresh eyes" and a stand-back step only mean something if the file proves you actually did them.
What changes in the report (and what doesn't)
This is where a lot of coverage overstates things for a private-company firm. Let's split it cleanly.
Every audit: the TCWG paragraph
For all entities, the auditor's report gets a small update. The paragraph about communicating with those charged with governance now explicitly references identified or suspected fraud and other fraud matters relevant to their responsibilities. So even your standard private-company audit report changes wording slightly. Your report templates need the update, but it's not dramatic.
Listed entities only: fraud as a KAM
The big visible change is key audit matters about fraud, and that applies to listed entities. The standard signals that for a listed entity, it would be rare to land on no fraud-related key audit matter at all. Usually revenue recognition or management override.
If your firm doesn't audit listed entities, this piece doesn't touch your reports at all. Worth knowing so you don't over-prepare for something that doesn't apply, and worth telling clients who've read scary headlines about "fraud in the audit report."
One more thing the standard does not do. It doesn't make you hire a forensic specialist on every job. You use professional judgment on whether a specialist is needed.
The bottom line
- The date points to periods that begin on or after December 15, 2026. Calendar-year clients are caught at the 2027 year end, not 2026. Off-calendar clients with early-2027 start dates come first.
- The work to get ready starts now. Templates, programs, and staff training are off-season jobs.
- Most of the change is in procedures and documentation, not in the report, unless you audit listed entities.
- The mindset shift is real. Fresh eyes, unbiased evidence, and a stand-back before you conclude.
- Brief your staff on the new steps so the file proves the work.
Get the timing right, update the file, and brief your staff before the first 2027 periods land. That's the whole job.
We break down standards changes like this one every week, in plain language you can take straight to the file. Come back next week for the next one.