22/07/2026
With regard to the news report shared in the comments below, I believe many auditors would be concerned by any statement that could be interpreted as suggesting that audit reports are of little value merely because an alleged fraud was not detected.
An audit report is neither useless nor a guarantee that fraud does not exist.
Auditors are required to maintain professional scepticism throughout an audit and to comply with ISA 240, The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements. The auditor is responsible for obtaining reasonable assurance that the financial statements, taken as a whole, are free from material misstatement, whether caused by fraud or error.
This means that auditors must actively:
• identify and assess the risks of material misstatement due to fraud;
• design and perform procedures responsive to those risks;
• address the risk of management override of controls;
• evaluate whether the audit evidence obtained indicates possible fraud; and
• take the appropriate action when fraud or suspected fraud is identified.
ISA 240 (Revised), issued by the IAASB in July 2025, further strengthens these responsibilities by introducing a clearer fraud lens in risk assessment, stronger responses to identified fraud risks and greater transparency in auditors’ reports for publicly traded entities. However, the revised standard is effective for audits of financial statements for periods beginning on or after 15 December 2026.
At the same time, an auditor is not a guarantor that every fraud will be discovered. The objective of an audit is to provide reasonable assurance—not absolute assurance.
Fraud can be particularly difficult to detect where it involves:
• collusion among management, employees or external parties;
• carefully fabricated documents and transactions;
• deliberate concealment or misrepresentation;
• management override of internal controls;
• manipulation of information systems; or
• false representations made consistently to auditors and other stakeholders.
Accordingly, failure to detect fraud does not, by itself, establish audit negligence. The relevant question is whether the auditor properly assessed the fraud risks, designed and performed appropriate procedures, obtained sufficient appropriate audit evidence and exercised professional scepticism in the circumstances.
In relation to eFishery, it is premature to conclude that the external auditors were negligent. Audit negligence has not yet been legally or professionally established based on the information currently available to the public.
There is also insufficient clarity regarding the precise services performed by the various international accounting firms associated with eFishery. Before attributing responsibility to an audit firm, it is necessary to establish:
• Which legal entity was examined?
• Which financial period was covered?
• Which financial reporting framework applied?
• Was the engagement a statutory audit, a review, financial due diligence, agreed-upon procedures, consultancy or another form of engagement?
• What procedures were included in the agreed scope?
• What report or opinion was issued?
• To whom was the report addressed?
• Were investors entitled to rely on that report?
These distinctions are critical. A statutory financial statement audit, a financial due-diligence exercise and an agreed-upon procedures engagement have different objectives, scopes and levels of assurance.
It has been alleged that eFishery maintained two sets of financial information: internal records reflecting its actual financial position and external records containing inflated figures that were presented to outside parties.
However, the complete facts remain unclear. We do not yet know precisely which records were provided to each accounting firm, which entities and periods were covered, what independent evidence was obtained or whether the reports subsequently relied upon by investors were the same reports issued by the accounting firms.
It is possible that different information was provided to auditors, investors, banks and other stakeholders. It is also possible that sophisticated fabrication or collusion was used to support the false information. These matters must be established through a proper regulatory or legal investigation rather than assumed from news headlines.
PwC Indonesia, for example, has publicly clarified that it did not issue an independent audit report for any company within the eFishery group. This illustrates why we should not describe every professional service performed by an accounting firm as an “audit” without first understanding the engagement concerned.
Auditors must be held accountable where they fail to comply with professional standards. Nevertheless, conclusions regarding negligence should be based on the actual engagement scope, audit evidence, procedures performed and circumstances known to the auditor at the relevant time—not merely on the fact that a fraud was subsequently uncovered.
An audit provides valuable independent assurance, but it does not replace the responsibilities of management, directors, audit committees, investors and due-diligence advisers. Effective corporate governance requires each party to perform its own role rather than placing complete reliance on any single professional adviser.
In conclusion, audit reports remain an important component of corporate accountability and investor confidence, but they should not be misunderstood as a guarantee that fraud does not exist. Auditors are required to exercise professional scepticism, assess fraud risks and obtain sufficient appropriate audit evidence, yet even a properly conducted audit may not detect fraud involving sophisticated concealment, collusion or management override.
At the same time, the audit profession should not avoid scrutiny. Where there is evidence that an auditor failed to respond appropriately to significant fraud risks or ignored contradictory information, the matter should be investigated and addressed in accordance with professional and legal standards.
For the eFishery case, the facts presently available are still incomplete. It is therefore fairer and more responsible to establish the exact scope of the engagements, the information provided, the procedures performed and the reports issued before concluding that the auditors were negligent or that audit reports are ineffective.
Accountability should be based on evidence, not assumptions. Management, directors, investors, advisers and auditors each have distinct responsibilities, and no single party should be treated as the sole safeguard against fraud.