While the effective date is still a few years away, the direction it sets matters now.
Fraud has always been one of the most complex challenges in auditing. It rarely announces itself, and when it surfaces, the questions that follow are often just as difficult as the discovery itself. Who is responsible for finding it? What are auditors required to do? How should they communicate what they've found?
The American Institute of CPAs' Auditing Standards Board (ASB) has taken a significant step toward answering those questions more clearly. On August 20, 2026, the ASB adopted Statement on Auditing Standards No. 151, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements. The standard supersedes the previous guidance under SAS No. 122 and is set to take effect for audits of financial statements for periods ending on or after December 15, 2028, with early adoption permitted.
The auditing profession has been navigating a more active enforcement environment in recent years. In 2024, major auditing firms and the AICPA successfully pushed back on a proposed PCAOB standard that would have expanded auditor responsibilities for detecting noncompliance with laws and regulations. The PCAOB ultimately stepped back from that effort under its reconstituted board.
But scrutiny of auditors and the financial reporting process has not faded. The SEC recently announced a new Financial Reporting and Accounting Unit within its Division of Enforcement, signaling that financial statement quality will remain a priority from a regulatory standpoint.
Against that backdrop, the AICPA moved to strengthen and clarify existing fraud standards for audits of nonissuers, the term used for entities whose audits are not subject to PCAOB oversight. This is the category that includes most private companies, nonprofits, and government entities. SAS No. 151 is built on the foundation of the International Auditing and Assurance Standards Board's updated fraud standard and represents a meaningful evolution in how auditors are expected to approach fraud risk.
It is worth being clear about what SAS No. 151 does and does not do.
The standard does not change the definition of fraud. It also does not shift primary responsibility for preventing and detecting fraud away from management and those charged with governance. That responsibility remains where it has always been: with the organization itself.
What the standard does is sharpen the expectations for auditors across several specific areas.
A more intentional fraud lens throughout the audit. Under SAS No. 151, auditors are required to apply a more deliberate, fraud-focused perspective during risk assessment procedures, not just at the beginning of an engagement but continuously throughout. Professional skepticism must be maintained from the planning phase through the final stages of the audit, including those moments near the end when time pressures are at their highest and the temptation to wrap up can be strongest.
While SAS No. 151 governs auditor behavior, its effects extend to the organizations undergoing audits. As auditors apply a more structured fraud lens and ask more pointed questions, organizations should be prepared for deeper conversations around internal controls, fraud risk assessment, and governance practices.
For nonprofits, private companies, and government entities in particular, a few areas are worth thinking through now:
Internal controls and fraud prevention. The standard reinforces that management holds primary responsibility for fraud prevention. Organizations that have not recently reviewed their internal controls, segregation of duties, and authorization processes may find auditors asking more probing questions once the new standard takes effect.
SAS No. 151 reflects a broader recognition that fraud risk is not a box to check at the start of an engagement. It requires ongoing attention, structured skepticism, and a clear framework for what to do when something concerning surfaces.
For organizations undergoing audits, the practical takeaway is straightforward: the audit process will become more focused and more thorough around fraud-related questions. Preparing now, by reviewing governance structures, internal controls, and documentation practices, puts organizations in a stronger position when the standard takes effect.
The final published version of SAS No. 151 is expected in October 2026. If you have questions about how this standard may affect your upcoming audit or want to talk through what your organization can do to prepare, our team is here to help.