A New Auditing Standard for Fraud Is Coming. Here's What It Means.
The AICPA's Auditing Standards Board has adopted SAS No. 151, a new standard that sharpens the rules around auditor responsibilities when fraud is identified or suspected.
While the effective date is still a few years away, the direction it sets matters now.
Fraud has always been one of the most complex challenges in auditing. It rarely announces itself, and when it surfaces, the questions that follow are often just as difficult as the discovery itself. Who is responsible for finding it? What are auditors required to do? How should they communicate what they've found?
The American Institute of CPAs' Auditing Standards Board (ASB) has taken a significant step toward answering those questions more clearly. On August 20, 2026, the ASB adopted Statement on Auditing Standards No. 151, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements. The standard supersedes the previous guidance under SAS No. 122 and is set to take effect for audits of financial statements for periods ending on or after December 15, 2028, with early adoption permitted.
Why a New Standard, and Why Now?
The auditing profession has been navigating a more active enforcement environment in recent years. In 2024, major auditing firms and the AICPA successfully pushed back on a proposed PCAOB standard that would have expanded auditor responsibilities for detecting noncompliance with laws and regulations. The PCAOB ultimately stepped back from that effort under its reconstituted board.
But scrutiny of auditors and the financial reporting process has not faded. The SEC recently announced a new Financial Reporting and Accounting Unit within its Division of Enforcement, signaling that financial statement quality will remain a priority from a regulatory standpoint.
Against that backdrop, the AICPA moved to strengthen and clarify existing fraud standards for audits of nonissuers, the term used for entities whose audits are not subject to PCAOB oversight. This is the category that includes most private companies, nonprofits, and government entities. SAS No. 151 is built on the foundation of the International Auditing and Assurance Standards Board's updated fraud standard and represents a meaningful evolution in how auditors are expected to approach fraud risk.
What Changes and What Stays the Same
It is worth being clear about what SAS No. 151 does and does not do.
The standard does not change the definition of fraud. It also does not shift primary responsibility for preventing and detecting fraud away from management and those charged with governance. That responsibility remains where it has always been: with the organization itself.
What the standard does is sharpen the expectations for auditors across several specific areas.
-
A more intentional fraud lens throughout the audit. Under SAS No. 151, auditors are required to apply a more deliberate, fraud-focused perspective during risk assessment procedures, not just at the beginning of an engagement but continuously throughout. Professional skepticism must be maintained from the planning phase through the final stages of the audit, including those moments near the end when time pressures are at their highest and the temptation to wrap up can be strongest.
- Understanding whistleblower programs. If an organization has a whistleblower program or another mechanism for reporting suspected fraud, auditors will now be required to understand how that program functions, including how management and those charged with governance respond to allegations made through it. This is a meaningful addition, as these programs can surface relevant information that would otherwise go unexamined.
- Stronger response requirements when fraud surfaces. The new standard adds more specific direction for what auditors should do when fraud or suspected fraud is identified. That includes clearer requirements for communications with management and those charged with governance, as well as more extensive documentation obligations.
- Revenue recognition stays in the spotlight. SAS No. 151 preserves the longstanding presumption that fraud risks exist in revenue recognition and makes clear that auditors need strong evidence before concluding otherwise.
What This Means for Organizations Being Audited
While SAS No. 151 governs auditor behavior, its effects extend to the organizations undergoing audits. As auditors apply a more structured fraud lens and ask more pointed questions, organizations should be prepared for deeper conversations around internal controls, fraud risk assessment, and governance practices.
For nonprofits, private companies, and government entities in particular, a few areas are worth thinking through now:
-
Internal controls and fraud prevention. The standard reinforces that management holds primary responsibility for fraud prevention. Organizations that have not recently reviewed their internal controls, segregation of duties, and authorization processes may find auditors asking more probing questions once the new standard takes effect.
- Whistleblower programs. If your organization has a whistleblower policy, auditors will want to understand it in more detail, including how allegations are handled and documented. If your organization does not have such a program, that absence may prompt additional discussion.
- Documentation and recordkeeping. Auditors will be expected to document their fraud risk assessments and responses more thoroughly. Organizations that maintain clear, well-organized financial records will be better positioned to support a smoother audit process.
- Board and governance engagement. Because communications with those charged with governance will be more extensive under SAS No. 151, boards and audit committees should expect a more active role in fraud-related conversations during the audit process.
The Bigger Picture
SAS No. 151 reflects a broader recognition that fraud risk is not a box to check at the start of an engagement. It requires ongoing attention, structured skepticism, and a clear framework for what to do when something concerning surfaces.
For organizations undergoing audits, the practical takeaway is straightforward: the audit process will become more focused and more thorough around fraud-related questions. Preparing now, by reviewing governance structures, internal controls, and documentation practices, puts organizations in a stronger position when the standard takes effect.
The final published version of SAS No. 151 is expected in October 2026. If you have questions about how this standard may affect your upcoming audit or want to talk through what your organization can do to prepare, our team is here to help.
To learn more about LGT and how we can serve you, contact us here.
