top of page

When the CPA is real but the audit is fake

Sep 16
4 min read

RECENT reports within Philippine business and professional circles have described incidents in which audited financial statements (AFS) were circulated using the name, signature and accreditation details of legitimate certified public accountants (CPA), even though the CPA concerned did not accept the engagement, perform the audit, or sign the report.

 

This is not simply an unlicensed person pretending to be a CPA. It is more dangerous.

 

The CPA may be real. The Professional Regulation Commission (PRC) license may be real. The Board of Accountancy (BOA) accreditation may be real. Even the accounting firm’s address may be correct. What is false is the audit itself.

 

That distinction matters because audited financial statements are relied upon by the Securities and Exchange Commission (SEC), the Bureau of Internal Revenue (BIR), banks, financing and lending institutions, investors, suppliers, and other users.

 

A document carrying genuine professional credentials can create a convincing appearance of legitimacy. But there are warning signs.

 

If management has never met or spoken with the supposed external auditor, no engagement letter was signed, no audit inquiries were made, no records were requested for testing, and nobody discussed audit findings with management, yet an “audited” financial statement suddenly appears with an auditor’s opinion, a basic question should follow: who actually performed the audit?

 

The law provides several answers to the fraud.

 

Republic Act (RA) 9298, or the Philippine Accountancy Act of 2004, prohibits the unauthorized practice of accountancy and the unauthorized use of the CPA title. Section 36 provides a fine of not less than P50,000.00, imprisonment not exceeding two years, or both, for violations of RA 9298 or its implementing rules.

 

If another person’s signature is copied or used to make it appear that the CPA participated in an audit when he did not, Article 172, in relation to Article 171 of the Revised Penal Code, may apply to a private individual who commits falsification, depending on the document and circumstances.

 

If the fabrication is done electronically, RA 10175, or the Cybercrime Prevention Act, separately punishes computer-related forgery and computer-related identity theft. These offenses may carry prisión mayor, a fine of at least P200,000.00 up to an amount commensurate with the damage, or both.

 

The National Internal Revenue Code of 1997, as Amended, is even more direct. Section 257 penalizes, among others, a person who offers to sign and certify financial statements without an audit. It also penalizes an independent CPA who willfully falsifies an audit report or renders accountancy work that was not properly verified personally, under his supervision, or by his firm or staff in accordance with sound auditing practices. A CPA convicted under this provision faces automatic revocation or cancellation of his CPA certificate.

 

One distinction should not be lost. A CPA whose credentials were stolen is a victim. A CPA who knowingly lends his name, signature or accreditation to a report without performing the audit stands on entirely different ground. The latter may also run afoul of the Code of Ethics for Professional Accountants, particularly the principles of integrity, professional competence and due care, and professional behavior.

 

The auditing standards reinforce the same point.

 

Philippine Standard on Auditing (PSA) 200 requires an auditor to obtain reasonable assurance and form an opinion on the financial statements through an audit performed in accordance with the PSA. The signature is the result of that process. It is not a substitute for it. If the named CPA never accepted or performed the engagement, there was no audit by that CPA in the first place.

 

Businesses also have responsibilities. Part I, Section 3(D) of the Revised Securities Regulation Code Rule 68 requires the company, through its Board of Directors or Audit Committee when applicable, to conduct due diligence on the identity and professional qualifications of the independent auditor before engagement.

 

The company must require the CPA’s PRC professional license and BOA Certificate of Accreditation and confirm the BOA accreditation against the latest official list. For regulated entities, the corresponding SEC accreditation must likewise be verified.

 

Verification should not end with the company that supposedly engaged the auditor.

 

Banks, financing companies, and other users who rely on AFS in granting credit should treat authenticity as part of credit due diligence. Bangko Sentral ng Pilipinas (BSP) credit-risk rules require financial institutions to conduct comprehensive assessments of borrowers and, to the extent available, use credible audited financial statements and other relevant sources.

 

A lender should therefore not assume that an AFS is authentic merely because the CPA’s license and accreditation numbers are valid. For material credit exposures, it is prudent to verify the auditor independently, check the relevant PRC, BOA and SEC accreditation where applicable, compare the AFS with documents filed with the BIR or SEC when available, and contact the audit firm through independently obtained contact details to confirm that it actually issued the report. Any inconsistency should be resolved before the AFS is relied upon.

 

This is not an unreasonable burden. A lender may spend hours validating collateral, titles and corporate authority. The audit report supporting the borrower’s financial capacity should not receive less scrutiny. A genuine-looking AFS backed by a stolen CPA identity can be as misleading as a forged title offered as collateral.

 

CPAs and accounting firms must likewise protect their professional identity.

 

Digital copies of signatures, licenses and accreditation certificates should be controlled. Copies released for particular transactions can be watermarked. Firms should maintain a register of audit reports actually issued. Once unauthorized use is discovered, the CPA should preserve the evidence, formally deny the report where appropriate, and consider notifying the PRC/BOA, SEC, BIR and law enforcement authorities.

 

There is also room for a stronger verification system. We currently verify whether a CPA exists and whether an accreditation is valid. Regulators should consider a mechanism allowing users to verify whether a particular auditor’s report was actually issued by that CPA or firm, through a unique verification number, QR code, or similar authentication system.

 

An audit derives its value from trust, but trust should not mean blind reliance. A genuine CPA number can still appear on a fraudulent report. Whether one is the company engaging the auditor or a bank, investor or creditor relying on the statements, the safer rule is the same: verify the CPA, verify the accreditation, and verify the audit.

---------------------------------------------------------------------------------------------------------------------------

Atty. Emmanuel Dumayas, CPA, CrFA, is the managing partner of Paguio, Dumayas & Associates, CPAs (PrimeGlobal Philippines), the managing partner of Dumayas & Mamanteo Law Offices, and the liaison director for Chapters and Membership Development of the Association of CPAs in Public Practice (Acpapp). His opinion does not reflect in any way those of the institutions.

 



Comments


2026 THEME LOGO.png
Post: Blog2_Post

©2026 by Association of CPAs in Public Practice, Inc.

bottom of page