CORAA

SIA 11 — Consideration of Fraud in an Internal Audit

ICAI Internal Audit Standards Board · Legacy standard, January 2009
Reviewed 1 October 2026

SIA 11 defines fraud and restates that preventing and detecting it is primarily management's responsibility, discharged through internal controls. It sets the internal auditor's responsibility to consider fraud-risk factors and to document them.

This page covers SIA 11 as it stands in ICAI’s October 2022 compendium. ICAI’s February 2026 compendium, applicable from 1 April 2026, renumbers the standards, so check the current number and text in that compendium before citing it in a report.

What the internal auditor has to do

  • Consider fraud-risk factors in the internal audit.
  • Document the fraud-risk factors considered.
  • Keep in view that prevention and detection of fraud rest primarily with management, through internal controls.

How SIA 11 shows up in the internal audit file

  • The fraud-risk factors considered for the assignment and the response to each.
  • For any fraud-risk issue reported earlier, follow-up audit procedures before closure, which is what SIA 390 para 4.2 expects for high-risk and fraud-risk issues.

Common mistakes in practice

  • Assuming internal audit owns the prevention of fraud. The standard places primary responsibility on management.
  • Considering fraud-risk factors and leaving no record of having done so.

The file checklist and the mistakes above are practice points drawn from the requirements of the standard. They are not text from the standard.

Related standards

SIA 390 · Monitoring and Reporting of Prior Audit IssuesSIA 120 · Internal ControlsSIA 320 · Internal Audit Evidence

Status and source

This standard is described here as it stands in the October 2022 compendium, which is the earlier set. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). That compendium renumbers the standards, so check the current number and text there before citing this standard in a report. ICAI's compendium page does not say whether the standards are mandatory or recommendatory, so we do not describe any standard as mandatory. In the October 2022 compendium this standard is still headed as recommendatory in the initial period and mandatory from a date to be notified by the Council of ICAI, and that date is left blank.

These pages summarise each standard as it stands in ICAI's Compendium of Standards on Internal Audit (as on 1 October 2022), working from an extract of that document. They are summaries and close paraphrases, not the text of the standards. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). For that current set we have only the titles, taken from the Board's 2025-26 annual report; its text is available from ICAI through a registration form on the compendium page and is not summarised here. ICAI's compendium page does not say whether the standards are mandatory or recommendatory, so we do not describe any standard as mandatory. Before you cite a number, a paragraph or a status in a report, check the February 2026 compendium. internalaudit.icai.org

Free working files for SIA 11

Take the working versions with you

Editable formats and tools from CORAA’s internal audit library that put SIA 11 into practice. Free to use.

Fraud Risk Assessment →Fraud red flags internal audit checklist →Monitoring rules library →

SIA 11 — frequently asked

What is SIA 11?

SIA 11, Consideration of Fraud in an Internal Audit, is a Standard on Internal Audit issued by the Internal Audit Standards Board of ICAI. SIA 11 defines fraud and restates that preventing and detecting it is primarily management's responsibility, discharged through internal controls. It sets the internal auditor's responsibility to consider fraud-risk factors and to document them. It was published in January 2009 and kept its original number.

Is SIA 11 mandatory?

ICAI's compendium page does not say whether the Standards on Internal Audit are mandatory or recommendatory, so we do not describe SIA 11 as mandatory. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). SIA 11 as described on this page is from the earlier October 2022 compendium. The February 2026 compendium renumbers the standards, so check the current number and text there before citing it in a report.

What should the internal audit file show for SIA 11?

The fraud-risk factors considered for the assignment and the response to each. For any fraud-risk issue reported earlier, follow-up audit procedures before closure, which is what SIA 390 para 4.2 expects for high-risk and fraud-risk issues.

← Previous
SIA 7 — Quality Assurance in Internal Audit
Next →
SIA 18 — Related Parties