Guide for firmsAudit standards
ISA 240 (Revised): which audits it covers and a six-gate transition plan
The trigger is when a financial period begins, not when the report is signed. Map your audits by period start, confirm what your jurisdiction applies, then move methodology, training and evidence through six gates.

Short answerWhen does ISA 240 (Revised) take effect?
ISA 240 (Revised) applies to audits of financial statements for periods beginning on or after 15 December 2026. The test is the period start, not the report date: a calendar-year 2026 audit signed afterwards stays on the extant standard, and the year beginning 1 January 2027 is in scope. In Malta, S.L. 281.02 defines generally accepted auditing standards by reference to the ISAs issued from time to time by the IAASB. Have your technical owner confirm the date for each engagement type, then plan by cohort.
Key takeaways
- ISA 240 (Revised) applies to audits of periods beginning on or after 15 December 2026, whatever date the report is signed.
- Malta's S.L. 281.02 defines generally accepted auditing standards by reference to the ISAs issued from time to time by the IAASB; the UK's FRC issued its own version with the same date.
- The main changes sit in risk assessment, responses to management override, work when fraud is suspected, communication and documentation.
- Firms changing methodology and software together should test that original evidence stays reachable.
- Plan by period-start cohort, and release the changes through gates with an owner and evidence for each.
01When does ISA 240 (Revised) take effect, and which audits does it cover?
The IAASB published ISA 240 (Revised) on 8 July 2025. Paragraph 16 makes it effective for audits of financial statements for periods beginning on or after 15 December 2026. ISA 570 (Revised 2024) on going concern, published on 9 April 2025, takes effect from the same date.
The test is when the financial period begins. The date the audit report is signed does not move an audit into or out of scope. A December year-end audit of 2026, signed in the following spring, is still an audit of a period that began before the effective date. Check each engagement against its period start, not its reporting deadline.
| Financial period begins | Example | Version on the IAASB date alone |
|---|---|---|
| 1 January 2026 | Calendar year 2026, report signed the following spring | Extant ISA 240. The period began before 15 December 2026. |
| 1 July 2026 | Twelve months to the following 30 June, report signed after December 2026 | Extant ISA 240. The period began before the effective date. |
| 15 December 2026 | A company whose financial year starts on 15 December, or a first period starting that day | ISA 240 (Revised). This is the first start date in scope. |
| 1 January 2027 | The calendar year that follows 2026 | ISA 240 (Revised). |
The trigger is when the period begins, not when the report is signed.
02How does Malta define auditing standards, and who sets the date elsewhere?
The IAASB sets the international effective date. How a standard takes effect in each jurisdiction depends on that jurisdiction's own law or standard-setter. In Malta, the relevant definitions are in the Accountancy Profession (Accounting and Auditing Standards) Regulations (S.L. 281.02: Legal Notice 19 of 2009, as amended by Legal Notice 233 of 2016). Regulation 4 defines compliance with generally accepted auditing standards as adherence to international auditing standards. Regulation 2 defines those as the ISAs and related standards issued from time to time by the IAASB, insofar as they are relevant to the statutory audit.
For auditing standards, the regulation does not name individual ISAs or set dates of its own. Regulation 4 has two provisos. An ISA adopted by the EU under the Statutory Audit Directive on the same subject would apply instead. For small undertakings, the auditing standards are applied in proportion to the scale and complexity of their activities. Ask your technical owner to confirm which version applies to your Maltese engagements and from which period, and record the source and the date checked.
Some jurisdictions issue their own version. The UK's Financial Reporting Council published ISA (UK) 240 (Revised March 2026) on 30 April 2026, effective for periods beginning on or after 15 December 2026. If your firm audits under more than one national framework, record the applicable version and date for each one.
On early adoption, the IAASB encourages jurisdictions to consider adopting ISA 240 (Revised), ISA 570 (Revised 2024) and the narrow-scope amendments for publicly traded entities early, as one package. The standard's effective-date paragraph says nothing about firms applying it early. Whether you may do so depends on the framework that governs the engagement.
| Where | What applies | Effective for periods beginning | Source |
|---|---|---|---|
| International | ISA 240 (Revised), issued by the IAASB on 8 July 2025 | On or after 15 December 2026 | IAASB final publication |
| Malta, statutory audits | Generally accepted auditing standards: the ISAs issued from time to time by the IAASB, insofar as relevant to the statutory audit (S.L. 281.02, regulations 2 and 4). An ISA adopted by the EU on the same subject would apply instead. | Not set separately in the regulation. Confirm with your technical owner. | legislation.mt, S.L. 281.02 |
| United Kingdom | ISA (UK) 240 (Revised March 2026), published by the FRC on 30 April 2026 | On or after 15 December 2026 | FRC news release |
| Any other jurisdiction | The national standard or adoption notice | Check the national standard-setter | Your technical owner |
Move to the revised standard in five steps
Follow one audit portfolio from the date check to the first in-scope files. Each step has an owner and evidence before the next one starts.
-
01
Confirm
Confirm the version and date your jurisdiction applies, with the source and the date you checked it.
Read this step: Confirm -
02
Map
List every audit by period start and mark the first cohort that falls under the revised standard.
Read this step: Map -
03
Update
Turn the changes into a gap list, then update templates, checklists and software settings.
Read this step: Update -
04
Rehearse
Brief each role and run a fictional case from the first concern to escalation.
Read this step: Rehearse -
05
Pilot
Run the changed path on a pilot file and check that a reviewer can follow the evidence.
Read this step: Pilot
The transition gates further down turn these steps into criteria you can tick, with an owner for each gate.
03What changes in ISA 240 (Revised)?
ISA 240 (Revised) applies to audits of financial statements of every kind of entity. It builds on ISA 315 (Revised 2019) and ISA 330 rather than standing apart from them. The IAASB fact sheet groups the changes into seven areas. The table follows them, with revenue and management override in a row of their own and key audit matters combined with documentation, and maps each row to the paragraphs that carry it and the part of your methodology it touches. Use the final standard for the requirements; the fact sheet and this table are orientation aids.
Fraud-related reporting is not the same for every entity. Where the auditor communicates key audit matters under ISA 701, as for listed entities, the standard adds requirements on fraud-related key audit matters (paragraphs 60 to 62). The IAASB's narrow-scope amendments, effective from the same date, move requirements written for listed entities to publicly traded entities, a definition aligned with the IESBA Code.
| Area | What the revised standard asks | Where it lands in your methodology |
|---|---|---|
| Professional scepticism | Design responses to fraud risks that are not biased towards evidence that corroborates management, or away from evidence that contradicts it (paragraph 42). Near the end, stand back and check that the fraud risk assessments still hold and the evidence is sufficient (paragraph 54). | Planning and completion templates; review notes |
| Auditor responsibilities | The auditor's responsibilities are stated first. Inherent limitations do not reduce them or justify accepting less than persuasive evidence (paragraphs 2, 9 and 10). | Methodology introduction; training |
| Communication | Communicate matters related to fraud with management and those charged with governance at appropriate times throughout the engagement (paragraph 25). | Communication plan; client request templates |
| Risk assessment | Apply a fraud lens to the ISA 315 procedures, including an understanding of the entity's whistleblower programme, if it has one (paragraphs 26 to 39, and 32(a)(ii)). Assessed fraud risks are treated as significant risks (paragraph 39(b)). | Risk assessment forms; the risk register |
| Revenue and management override | Revenue fraud risk is presumed; the work identifies which revenue types or assertions give rise to it (paragraph 41). Management override is always a fraud risk at the financial statement level. Journal entry work covers the completeness of the population, period-end entries and the need to test throughout the period (paragraphs 40 and 47 to 52). | Revenue and journal entry work programmes |
| Fraud or suspected fraud identified | Understand each instance. Unless it is clearly inconsequential, the engagement partner decides whether more risk assessment or further procedures are needed (paragraphs 55 and 56). | Escalation route; engagement partner sign-off |
| Reporting and documentation | Every auditor's report says the auditor communicates identified or suspected fraud to those charged with governance (conforming amendment to ISA 700 (Revised), paragraph 40(a)). A fraud-related key audit matter carries a subheading that says it relates to fraud (paragraph 62). Documentation covers the sources of the auditor's understanding, the rationale for significant judgements and communications about fraud (paragraph 68). | Report templates; documentation checklist |
04How do you turn the changes into a methodology gap list?
Work from your current methodology, not from a blank page. For each row in the table above, record the existing step, the change needed, the template or system affected, who reviews the change and what evidence shows it is done. Start with one complete engagement path: planning discussion, inquiries, risk assessment, responses, communication and completion.
Mark the dependencies. The new requirement to understand the whistleblower programme changes the request list, the risk assessment form and the communication plan. If the request changes but the reviewer's checklist does not, the change will not hold. Keep requirements apart from tool features: testing every journal entry is something some tools offer, but paragraph 49 asks for evidence that the population is complete, period-end entries and a decision on testing throughout the period.
- The paragraph and requirement, taken from the final standard.
- Your current step and its template reference.
- The change, written as an instruction a preparer can follow.
- The templates, checklists and software settings affected.
- The owner, the reviewer and the evidence that the change is complete.
- The engagements and cohorts the change applies to.
05How should you prepare the engagement team?
Paragraph 23 asks the engagement partner to determine that the engagement team collectively has the competence, time and specialised skills to assess and respond to fraud risks. Training is part of the transition plan. Give preparers, managers and engagement partners role-specific instructions: where a concern is recorded, who can change its status, and what the next person needs to see.
Rehearse with a fictional case in which an explanation conflicts with another record. Ask the team to record the issue, preserve the information, escalate it and decide the next work under the updated methodology. Include a version in which the first explanation changes after review. The aim is to make responsibilities and communication visible, not to reward a quick label of fraud or no fraud. The auditor does not make legal determinations of whether fraud has occurred (paragraph 6).
Choose the training focus from your own quality findings. ICAEW's 2026 monitoring insights, published on 29 June 2026, listed revenue audit procedures under ISA 240 among the most common weaknesses in the UK files it reviewed: walkthroughs, independent evidence and covering every relevant assertion. That is a UK monitoring observation, but it is a sensible place to start in your own files.
06How do you change templates and software without losing evidence?
Many firms will update templates, checklists and audit software alongside the methodology. ICAEW's 2026 monitoring insights, published on 29 June 2026, treat technology change as a quality risk. The head of audit in its Quality Assurance Department stressed disciplined change management, including when a firm moves from one audit methodology to another, and noted that some of the smallest firms had lost or lacked original documentation after moving from paper files to audit software.
Test the template path and the evidence path together. Paragraph 68 asks the file to show the sources of the auditor's understanding, the rationale for significant judgements and the fraud-related matters communicated. In the pilot, check that the new templates capture each of those, and that a reviewer can follow them without asking the preparer to reconstruct them. If a document is replaced, the earlier version and any open question should stay available. Files planned under the extant standard must stay readable next to revised ones.
Where Vacei fits: on its audit portal, Vacei's AI, VEE, prepares materiality, the risk register and the audit programme for the auditor's approval. Every step VEE takes is recorded, and a qualified person reviews and signs. Vacei's outsourced audit support prepares the working papers in the firm's own methodology and templates, so an updated methodology has to reach the provider before the first in-scope file. None of this establishes compliance with ISA 240 (Revised). Whatever software or provider you use, your own pilot is what shows whether the changed path works.
07How do you run the transition gate by gate?
Use the planner to move through six gates: applicability, portfolio mapping, methodology, team readiness, pilot, and release with a first-cohort review. A gate passes only when every criterion is ticked, so an unfinished item shows up as the next action instead of disappearing into an average. Give each gate an owner.
Schedule backwards from the planning of your first in-scope cohort. In the worked example, that is the December cohort. The methodology, team and pilot gates need to close before those engagements are planned, with time left to resolve technical questions.
After the first in-scope engagements, review whether teams used the intended methodology and whether reviewers could follow the evidence. Record corrections and update the guidance. A completed planner does not establish compliance with ISA 240 (Revised), prove that fraud will be detected or decide an audit opinion.
Plan your ISA 240 (Revised) transition in six gates
Tick each criterion your firm can evidence today. A gate passes only when all its criteria are ticked. Add an owner to each gate. The result shows your current gate and what is still missing. No client names or confidential records are needed.
How the result is worked out
A gate passes only when every one of its criteria is ticked; there is no partial pass. The current gate is the first gate, in the order listed, that has not passed.
Ticks are your own record of where things stand. Nothing is checked, verified or approved by this page.
Common questions
Does ISA 240 (Revised) apply to every audit report signed after 15 December 2026?
No. The effective date depends on when the financial period begins. An audit of a period that began before 15 December 2026 stays on the extant standard, even if the report is signed later, unless the framework that governs the engagement says otherwise.
What does Malta's S.L. 281.02 say about the auditing standards to follow?
Regulation 4 defines compliance with generally accepted auditing standards as adherence to international auditing standards, and regulation 2 defines those as the ISAs issued from time to time by the IAASB, insofar as they are relevant to the statutory audit. An ISA adopted by the EU on the same subject would apply instead. The regulation sets no date of its own for auditing standards, so have your technical owner confirm which version applies to each engagement type and from when.
Can a firm apply ISA 240 (Revised) early?
The standard's effective-date paragraph says nothing about applying it early. The IAASB encourages jurisdictions to consider adopting it early together with ISA 570 (Revised 2024) and the narrow-scope amendments for publicly traded entities. Whether a firm may do so depends on the national framework.
What does ISA 240 (Revised) say about management override of controls?
The auditor treats the risks of management override as fraud risks at the financial statement level, whatever the assessment (paragraph 40). Required procedures cover journal entries and other adjustments, management bias in accounting estimates, and significant unusual transactions (paragraphs 47 to 52).
Does ISA 240 (Revised) change the auditor's report?
Yes, for every audit. Conforming amendments to ISA 700 (Revised), paragraph 40(a), effective at the same time, add identified fraud or suspected fraud, and other fraud-related matters relevant to those charged with governance, to the report's statement of what the auditor communicates to them. Where key audit matters are communicated under ISA 701, as for listed entities, the auditor determines which fraud-related matters are key audit matters, and each one carries a subheading saying it relates to fraud (paragraphs 60 to 62). The narrow-scope amendments move listed-entity requirements to publicly traded entities from the same date. ISA 570 (Revised 2024), effective from the same date, separately strengthens auditor reporting on going concern.
Can the presumed fraud risk in revenue recognition still be rebutted?
The presumption stays, and the work now focuses on which types of revenue or assertions give rise to the risk (paragraph 41). If the auditor concludes the presumption does not apply, the reasons must be documented (paragraph 68(d)). The IAASB describes the cases where that is appropriate as limited.
Does an audit under ISA 240 (Revised) guarantee that fraud will be found?
No. The auditor seeks reasonable assurance, which is high but not absolute, that the financial statements are free from material misstatement due to fraud (paragraphs 2 and 9). Primary responsibility for preventing and detecting fraud rests with management and those charged with governance (paragraph 3).
Does passing every gate in the planner mean we comply?
No. The planner records your own assessment of the listed planning actions. Compliance depends on the applicable standards and the work performed on each engagement, as judged by the responsible professionals.
How this guide was prepared
Method and limits
This guide works from primary sources: the IAASB's final standard, fact sheet, focus page and news releases; Malta's S.L. 281.02 on legislation.mt; the FRC's April 2026 release; and ICAEW's June 2026 monitoring insights. Each source shows the date we checked it. It is general information for audit firms, not advice on any engagement.
The period-start table and worked example apply the IAASB effective date alone. Whether a particular engagement falls under the revised standard depends on the framework that governs it, which your technical owner must confirm.
The transition gates record what you say you can evidence. They do not inspect files, test methodology or software, or decide whether an audit complies with any standard.
Related Vacei pages: How an audit runs on Vacei · Outsourced audit support · Insights for firms.
Who prepared it
- Author
- A4 Team
- Published
- 6 October 2026
- Last substantive update
- 6 October 2026
- Sources checked
- 6 October 2026
Sources
- IAASB: ISA 240 (Revised), final publication page (issued 8 July 2025)iaasb.org · published 8 July 2025 · checked 6 October 2026
- IAASB: ISA 240 (Revised), full standard (PDF, July 2025)ifacweb.blob.core.windows.net · checked 6 October 2026
- IAASB: ISA 240 (Revised) fact sheet (PDF, July 2025)ifacweb.blob.core.windows.net · checked 6 October 2026
- IAASB: Fraud and going concern, revised standards focus pageiaasb.org · checked 6 October 2026
- IAASB: ISA 570 (Revised 2024), Going Concerniaasb.org · published 9 April 2025 · checked 6 October 2026
- IAASB: new publicly traded entity definition and narrow-scope amendmentsiaasb.org · published 1 September 2025 · checked 6 October 2026
- IAASB: 2026 Handbook announcementiaasb.org · published 1 October 2026 · checked 6 October 2026
- legislation.mt: S.L. 281.02, Accountancy Profession (Accounting and Auditing Standards) Regulations (L.N. 19 of 2009, as amended by L.N. 233 of 2016)legislation.mt · checked 6 October 2026
- FRC: final revisions to UK auditing standards on fraud and going concernfrc.org.uk · published 30 April 2026 · checked 6 October 2026
- ICAEW: Audit monitoring insights 2026icaew.com · published 29 June 2026 · checked 6 October 2026
- Vacei: how an audit runs on the audit portalvacei.com · checked 6 October 2026
- Vacei: outsourced audit support for audit firmsvacei.com · checked 6 October 2026
See how an audit runs on Vacei in a firm demo
Bring your gap list and the scenario you plan to pilot. Ask to see how planning, the risk register, the audit programme, evidence requests and sign-off work on the audit portal. The demo runs on sample data, so no client records are needed.