The short answer
The Financial Reporting Council published ISA (UK) 240 (Revised March 2026) on 30 April 2026. It is effective for audits of financial statements for periods commencing on or after 15 December 2026.
The FRC says the revision strengthens and clarifies responsibilities relating to fraud, including enhanced risk assessment procedures and greater transparency in audit reporting. It also notes that UK requirements already reflected many of the international changes, so it expects limited additional work beyond the aligned international revision.
What changes for the fraud-risk conversation?
The revised standard keeps fraud risk firmly within the auditor's responsibilities and makes the risk-assessment and response process more explicit. That makes the quality of the underlying population, the rationale for selecting transactions and the trail from an unusual pattern to reviewed evidence particularly important.
It does not say that running a specific software test satisfies the standard. An audit analytics tool is useful only where the auditor understands the population, chooses an appropriate procedure, investigates the result and documents the conclusion.
How ISA (UK) 315 fits alongside ISA (UK) 240
ISA (UK) 315 addresses identifying and assessing risks of material misstatement. It is not a new 2026 standard: the July 2020 revision became effective for periods beginning on or after 15 December 2021.
The connection is practical. Fraud work under ISA (UK) 240 depends on understanding where material misstatement due to fraud could arise. Analytics can help interrogate the accounting population for unusual timing, values, duplication, reversals or counterparties, but those indicators still have to be interpreted in the context of the entity and the engagement.
Where data analytics can add value
Traditional sampling remains relevant, but complete-population analytics can expose patterns that are difficult to see in a spreadsheet extract. The strongest use is not "fraud detection" as a black-box label. It is transparent exception generation followed by reviewable evidence.
- Risk identification: find unusual concentrations, timing or counterparties that may inform further procedures.
- Transaction selection: surface records meeting a defined threshold, tolerance or matching rule.
- Period-end focus: isolate activity close to month or reporting-period boundaries.
- Evidence review: move from an aggregate chart to the underlying records that produced it.
- Repeatability: apply the same conceptual tests to Xero and QuickBooks rather than rebuilding ad hoc spreadsheet logic for each client.
The seven Datplan Audit Analytics tests
| Analysis | Risk question it can help explore |
|---|---|
| Benford's Law | Does the selected numerical population show an unusual first- or second-digit distribution that merits further investigation? |
| Exceptional values | Which high-value records exceed the user-defined threshold for this population and period? |
| Period-end activity | Is transaction activity concentrated within a configurable number of days around month end? |
| Round amounts | Which values sit close to defined round-number multiples within the selected tolerance? |
| Possible duplicates | Which records share counterparty, date and amount, optionally including reference matching? |
| Post-period reversals | Which entries are followed by opposite-value matching entries within the bounded post-period window? |
| Rare high-value counterparties | Which high-value records involve counterparties that appear only rarely in the population? |
These are analytical questions, not predetermined audit conclusions. Their relevance depends on the engagement, the data population and the auditor's assessed risks.
A defensible analytics workflow
- Define the population. Know which Xero or QuickBooks records and period are being tested and why they are relevant.
- Set parameters deliberately. Thresholds, tolerances and matching choices should follow the purpose of the procedure, not defaults accepted without thought.
- Run the analysis. Use the chart to understand the pattern or exception set.
- Open Audit Evidence. Inspect the underlying records used by the analysis.
- Corroborate. Compare exceptions with source documents, explanations, controls, the accounting system's audit trail and other evidence where relevant.
- Document the conclusion. Record why the procedure was performed, what was found, what was investigated and how the result affected the audit response.
What Datplan deliberately does not claim
Datplan does not determine intent, conclude that a transaction is fraudulent, decide materiality, replace the auditor's understanding of the entity, replace professional scepticism, replace source documents or controls evidence, or certify compliance with ISA (UK) 240 or ISA (UK) 315.
The value is narrower and more useful: Audit Analytics gives Xero and QuickBooks users the same seven transparent tests and a drill-down to the records behind each result.
Frequently asked questions
When does ISA (UK) 240 (Revised March 2026) take effect?
It is effective for audits of financial statements for periods commencing on or after 15 December 2026.
Does the revised ISA (UK) 240 require Benford's Law?
No. The standard does not prescribe Datplan's seven analyses. Benford's Law and the other tests can be used as analytical inputs where they are relevant to the auditor's risk assessment and planned procedures.
Is ISA (UK) 315 also changing from 15 December 2026?
No. The current ISA (UK) 315 is based on the July 2020 revision, effective for periods beginning on or after 15 December 2021. It remains relevant because it addresses identifying and assessing risks of material misstatement.
Can audit analytics prove fraud?
No. Analytics can identify unusual patterns or records for further review. Fraud conclusions require professional judgement, corroborating evidence and the procedures appropriate to the engagement.