ISA 250 (Revised)
Consideration of Laws and Regulations in an Audit of Financial Statements
1Objective and scope
ISA 250 (Revised) deals with the auditor's responsibility to consider laws and regulations in an audit of financial statements. It does not apply to other assurance engagements where the auditor is specifically engaged to test compliance. The standard separates two categories of law: (a) those whose provisions have a direct effect on the determination of material amounts and disclosures (tax law, pension law, the Companies Act's accounting provisions), and (b) other laws that do not directly affect amounts but where compliance may be fundamental to operating the business, continuing in it, or avoiding material penalties (an operating licence, environmental law, banking prudential guidelines, the Data Protection Act). The auditor's responsibilities differ between the two. The 2016 revision aligned the standard with the IESBA Code's NOCLAR (non-compliance with laws and regulations) provisions.
The objectives are to obtain sufficient appropriate evidence about compliance with laws in the first category, to perform specified procedures to help identify instances of non-compliance with other laws that may have a material effect on the financial statements, and to respond appropriately to identified or suspected non-compliance. Management, with the oversight of those charged with governance, is responsible for ensuring the entity's operations comply with law; the auditor is not responsible for preventing non-compliance and cannot be expected to detect all of it.
2Key definitions
3Requirements
Consideration of compliance
- As part of understanding the entity (ISA 315), obtain a general understanding of the legal and regulatory framework applicable to the entity and its industry, and how the entity complies with it.
- For laws with a direct effect: obtain sufficient appropriate audit evidence regarding compliance with those provisions, in the same way as for any other assertion.
- For other laws: perform procedures to help identify non-compliance that may have a material effect: inquire of management and those charged with governance whether the entity is in compliance, and inspect correspondence with the relevant licensing or regulatory authorities (KRA, the Central Bank, the Capital Markets Authority, NEMA, county licensing offices).
- Throughout the audit remain alert to the possibility that other procedures may bring instances of non-compliance to the auditor's attention: reading minutes, inquiring about litigation and claims, performing substantive tests of transactions.
- Request written representations that all known instances of non-compliance or suspected non-compliance whose effects should be considered in preparing the financial statements have been disclosed to the auditor.
When non-compliance is identified or suspected
If the auditor becomes aware of information concerning an instance of non-compliance or suspected non-compliance, the auditor obtains an understanding of the nature of the act and the circumstances, and further information to evaluate the possible effect on the financial statements: the potential financial consequences (fines, penalties, damages, threat of expropriation, enforced discontinuation of operations, litigation), whether they require disclosure, and whether they are so serious as to call the fair presentation into question or affect going concern. The auditor discusses the matter with the appropriate level of management and, where appropriate, those charged with governance; where they do not provide sufficient information that the entity is in compliance, and the effect may be material, the auditor considers obtaining legal advice.
- Indicators of possible non-compliance include investigations by regulators, payment of fines or penalties, payments for unspecified services or to consultants, related parties or government officials, sales commissions that appear excessive, purchases at prices significantly above or below market, unusual cash payments or payments to numbered accounts, unusual transactions with tax-haven entities, payments without proper documentation, an information system that fails to provide an audit trail, and adverse media comment.
- If sufficient information about suspected non-compliance cannot be obtained, evaluate the effect of the lack of evidence on the opinion.
- Evaluate the implications for other aspects of the audit, including the risk assessment and the reliability of written representations, and take appropriate action; consider whether the non-compliance indicates fraud (ISA 240).
- Consider whether the auditor's ethical obligations (the IESBA Code's NOCLAR provisions) require further action, such as communicating the matter to a network firm, to a group auditor, or, where the public interest requires it and law permits, to an appropriate authority.
4Documentation and reporting
| To whom | What ISA 250 requires |
|---|---|
| Those charged with governance | Communicate matters involving non-compliance that come to the auditor's attention, unless clearly inconsequential. Where management or those charged with governance are involved, communicate to the next higher level of authority (the audit committee, supervisory board) or, if none exists, consider legal advice. |
| In the auditor's report | A material effect not adequately reflected in the financial statements leads to a qualified or adverse opinion (ISA 705). Being precluded by management from obtaining evidence leads to a qualified opinion or disclaimer for a limitation on scope. Being unable to determine whether non-compliance occurred because of limitations imposed by circumstances is evaluated for its effect on the opinion. |
| Regulatory and enforcement authorities | Determine whether there is a responsibility to report to parties outside the entity, under law, regulation or the ethical requirements (NOCLAR). Confidentiality may be overridden by statute, by court order or by the public interest; legal advice is normally obtained. |
| Audit documentation | Record the identified or suspected non-compliance, the results of discussions with management, those charged with governance and others, including copies of records or documents, and the auditor's evaluation and conclusions. |
5Examinable focus
What KASNEB tests
The two categories of law, and the different responsibility for each, is the core theory point; give Kenyan examples (the Income Tax Act as direct; the Banking Act, NEMA licensing, the Employment Act as other). Expect a list question on indicators of non-compliance and on the procedures to identify it. Scenario questions describe an unexplained payment to a county official, a penalty from KRA disclosed after year end, or a licence revocation that threatens going concern: state the auditor's steps (understand, evaluate effect, discuss with management, legal advice, communicate to those charged with governance, consider the opinion, consider external reporting). Confidentiality versus the public-interest duty to report, and the NOCLAR link to the IESBA Code, is a frequent final part.