📄 PDF — HKICPA Handbook Vol III (Code of Ethics)

Open PDF →" data-zh="不支援PDF檢視。打開PDF →">PDF viewer not supported.

🎥 Video Lesson (Coming Soon)
🎬HKSA 250 - Consideration of Laws and Regulations walkthrough video coming soon.

HKSA 250 (Revised) - Consideration of Laws and Regulations in an Audit of Financial Statements

Ad Space

Ad Space
Ad Space

1. Introduction

1.1 Scope of HKSA 250 (Revised)

HKSA 250 (Revised) deals with the auditor's responsibility to consider laws and regulations in an audit of financial statements. This standard does not apply to other assurance engagements where the auditor is specifically engaged to test and report separately on compliance with specific laws or regulations.

Effective Date: Audits of financial statements for periods beginning on or after 15 December 2017.

1.2 Effect of Laws and Regulations

The effect of laws and regulations on financial statements varies considerably:

CategoryDescriptionExamples
Direct EffectProvisions that determine reported amounts and disclosures in financial statementsTax laws, pension laws
Indirect EffectLaws fundamental to operating aspects, business continuity, or avoiding material penaltiesOperating licenses, regulatory solvency requirements, environmental regulations

Non-compliance may result in:

  • Fines
  • Litigation
  • Other consequences that may have a material effect on financial statements
  • Ad Space

    2. Responsibilities

    2.1 Management's Responsibility (Paragraph 3)

    Management, with oversight from those charged with governance, is responsible for ensuring that the entity's operations are conducted in accordance with laws and regulations, including compliance with provisions that determine reported amounts and disclosures.

    2.2 Auditor's Responsibility (Paragraphs 4-9)

    Key Principle: The auditor is not responsible for preventing non-compliance and cannot be expected to detect non-compliance with all laws and regulations.

    The auditor is responsible for obtaining reasonable assurance that financial statements, taken as a whole, are free from material misstatement, whether due to fraud or error.

    Inherent Limitations affecting detection of non-compliance:

    - Many laws and regulations relating to operating aspects typically do not affect financial statements and are not captured by the entity's information systems relevant to financial reporting

    - Non-compliance may involve concealment (collusion, forgery, deliberate failure to record transactions, management override of controls, intentional misrepresentations)

    - Whether an act constitutes non-compliance is ultimately a matter for a court or other adjudicative body

    General Rule: The further removed non-compliance is from events and transactions reflected in financial statements, the less likely the auditor is to become aware of it.

    2.3 Two Categories of Laws and Regulations (Paragraph 6)

    CategoryDescriptionAuditor's Responsibility
    (a) Direct EffectProvisions generally recognized to have a direct effect on determination of material amounts and disclosures (e.g., tax and pension laws)Obtain sufficient appropriate audit evidence regarding compliance
    (b) Other LawsLaws fundamental to operating aspects, business continuity, or avoiding material penalties (e.g., operating licenses, solvency requirements, environmental regulations)Limited to specified audit procedures to help identify non-compliance that may have a material effect

    2.4 Professional Skepticism (Paragraph 8)

    The auditor must remain alert to the possibility that other audit procedures applied for forming an opinion may bring instances of non-compliance to attention. Maintaining professional skepticism throughout the audit is critical.

    2.5 Additional Responsibilities (Paragraph 9)

    The auditor may have additional responsibilities under law, regulation, or ethical requirements that differ from or go beyond HKSA 250, including:

  • Responding to identified or suspected non-compliance
  • Communicating with management and those charged with governance
  • Assessing appropriateness of responses to non-compliance
  • Determining whether further action is needed
  • Communicating to other auditors (e.g., group audits)
  • Documentation requirements
  • Ad Space

    3. Objectives (Paragraph 11)

    The objectives of the auditor are:

  • To obtain sufficient appropriate audit evidence regarding compliance with provisions of laws and regulations generally recognized to have a direct effect on determination of material amounts and disclosures in financial statements
  • To perform specified audit procedures to help identify instances of non-compliance with other laws and regulations that may have a material effect on financial statements
  • To respond appropriately to identified or suspected non-compliance with laws and regulations identified during the audit
  • Ad Space

    4. Definition (Paragraph 12)

    Non-compliance – Acts of omission or commission, intentional or unintentional, committed by:

  • The entity
  • Those charged with governance
  • Management
  • Other individuals working for or under the direction of the entity
  • Which are contrary to prevailing laws or regulations.

    Exclusion: Non-compliance does not include personal misconduct unrelated to the business activities of the entity.

    Key Points:

  • Includes transactions entered into by, or in the name of, the entity, or on its behalf
  • Includes personal misconduct related to business activities (e.g., a key management person accepting a bribe from a supplier in return for securing contracts)
  • Ad Space

    5. Requirements - Detailed Analysis

    5.1 The Auditor's Consideration of Compliance (Paragraphs 13-18)

    5.1.1 Obtaining Understanding (Paragraph 13)

    As part of obtaining an understanding of the entity and its environment under HKSA 315 (Revised 2019), the auditor shall obtain a general understanding of:

    (a) The legal and regulatory framework applicable to the entity and the industry or sector in which the entity operates

    (b) How the entity is complying with that framework

    Practical Approaches (A11):

    - Use existing understanding of the entity's industry, regulatory and other external factors

    - Update understanding of laws that directly determine reported amounts and disclosures

    - Inquire of management about other laws that may have a fundamental effect on operations

    - Inquire about policies and procedures regarding compliance

    - Inquire about policies for identifying, evaluating and accounting for litigation claims

    5.1.2 Direct Effect Laws (Paragraph 14)

    The auditor shall obtain sufficient appropriate audit evidence regarding compliance with provisions of laws and regulations generally recognized to have a direct effect on determination of material amounts and disclosures.

    Examples of Direct Effect Laws (A12):

  • Form and content of financial statements
  • Industry-specific financial reporting issues
  • Accounting for transactions under government contracts
  • Accrual or recognition of expenses for income tax or pension costs
  • 5.1.3 Other Laws - Specified Procedures (Paragraph 15)

    The auditor shall perform the following audit procedures to help identify instances of non-compliance with other laws that may have a material effect:

    (a) Inquire of management and, where appropriate, those charged with governance, as to whether the entity is in compliance with such laws and regulations

    (b) Inspect correspondence, if any, with relevant licensing or regulatory authorities

    5.1.4 Remaining Alert (Paragraph 16)

    During the audit, the auditor shall remain alert to the possibility that other audit procedures applied may bring instances of non-compliance or suspected non-compliance to attention.

    Examples of Other Procedures That May Identify Non-Compliance (A15):

  • Reading minutes
  • Inquiring of management and legal counsel concerning litigation, claims and assessments
  • Performing substantive tests of details of classes of transactions, account balances or disclosures
  • 5.1.5 Written Representations (Paragraph 17)

    The auditor shall request management and, where appropriate, those charged with governance, to provide written representations that all known instances of non-compliance or suspected non-compliance whose effects should be considered when preparing financial statements have been disclosed to the auditor.

    Important: Written representations do not provide sufficient appropriate audit evidence on their own and do not affect the nature and extent of other audit evidence to be obtained.

    5.1.6 Limitation on Procedures (Paragraph 18)

    In the absence of identified or suspected non-compliance, the auditor is not required to perform audit procedures regarding compliance with laws and regulations other than those set out in paragraphs 13-17.

    5.2 Audit Procedures When Non-Compliance Is Identified or Suspected (Paragraphs 19-22)

    5.2.1 Initial Response (Paragraph 19)

    If the auditor becomes aware of information concerning an instance of non-compliance or suspected non-compliance, the auditor shall obtain:

    (a) An understanding of the nature of the act and the circumstances in which it has occurred

    (b) Further information to evaluate the possible effect on the financial statements

    Indications of Non-Compliance (A18):

    - Investigations by regulatory organizations or government departments

    - Payment of fines or penalties

    - Payments for unspecified services or loans to consultants, related parties, employees or government employees

    - Excessive sales commissions or agent's fees

    - Purchasing at prices significantly above or below market price

    - Unusual cash payments, cashier's checks payable to bearer, transfers to numbered bank accounts

    - Unusual transactions with companies registered in tax havens

    - Payments for goods/services made other than to the country of origin

    - Payments without proper exchange control documentation

    - Information system failing to provide adequate audit trail or sufficient evidence

    - Unauthorized or improperly recorded transactions

    - Adverse media comment

    Matters Relevant to Evaluating Effect on Financial Statements (A19):

    - Potential financial consequences (fines, penalties, damages, threat of expropriation, enforced discontinuation of operations, litigation)

    - Whether potential financial consequences require disclosure

    - Whether potential consequences are so serious as to call into question fair presentation or make financial statements misleading

    5.2.2 Discussion with Management (Paragraph 20)

    If the auditor suspects there may be non-compliance, the auditor shall discuss the matter (unless prohibited by law or regulation) with:

  • The appropriate level of management
  • Where appropriate, those charged with governance
  • If management or those charged with governance do not provide sufficient information supporting compliance, and the suspected non-compliance may be material, the auditor shall consider the need to obtain legal advice.

    Restrictions on Communication (A21):

    In some jurisdictions, law or regulation may restrict communication of certain matters with management and those charged with governance (e.g., anti-money laundering legislation may prohibit alerting the entity when the auditor is required to report to an appropriate authority).

    5.2.3 Insufficient Evidence (Paragraph 21)

    If sufficient information about suspected non-compliance cannot be obtained, the auditor shall evaluate the effect of the lack of sufficient appropriate audit evidence on the auditor's opinion.

    5.2.4 Evaluating Implications (Paragraph 22)

    The auditor shall evaluate the implications of identified or suspected non-compliance in relation to other aspects of the audit, including:

  • The auditor's risk assessment
  • The reliability of written representations
  • Circumstances Affecting Reliability of Written Representations (A24):

    - Auditor suspects or has evidence of involvement or intended involvement of management/those charged with governance in non-compliance

    - Auditor is aware that management/those charged with governance have knowledge of non-compliance and, contrary to legal/regulatory requirements, have not reported or authorized reporting to an appropriate authority

    Potential Withdrawal from Engagement (A25):

    The auditor may consider withdrawing from the engagement (where permitted by law or regulation) when:

  • Management or those charged with governance do not take remedial action the auditor considers appropriate
  • Identified or suspected non-compliance raises questions about integrity of management or those charged with governance
  • Note: Withdrawal is not a substitute for complying with other responsibilities under law, regulation or ethical requirements.

    5.3 Communicating and Reporting Identified or Suspected Non-Compliance (Paragraphs 23-29)

    5.3.1 Communication with Those Charged with Governance (Paragraphs 23-25)

    General Rule (Paragraph 23):

    Unless all those charged with governance are involved in management (and therefore already aware), the auditor shall communicate (unless prohibited by law or regulation) with those charged with governance matters involving non-compliance that come to attention during the audit, other than when matters are clearly inconsequential.

    Intentional and Material Non-Compliance (Paragraph 24):

    If the auditor believes non-compliance is intentional and material, the auditor shall communicate the matter with those charged with governance as soon as practicable.

    Suspected Involvement of Management/Governance (Paragraph 25):

    If the auditor suspects that management or those charged with governance are involved in non-compliance, the auditor shall communicate the matter to the next higher level of authority at the entity (e.g., audit committee, supervisory board). Where no higher authority exists, or if the auditor believes communication may not be acted upon, the auditor shall consider obtaining legal advice.

    5.3.2 Implications for Auditor's Report (Paragraphs 26-28)

    ScenarioRequired Action
    Material non-compliance not adequately reflected in financial statements (Paragraph 26)Express qualified opinion or adverse opinion per HKSA 705 (Revised)
    Precluded by management/governance from obtaining sufficient evidence (Paragraph 27)Express qualified opinion or disclaim an opinion due to scope limitation per HKSA 705 (Revised)
    Unable to determine due to circumstances (not management) (Paragraph 28)Evaluate effect on opinion per HKSA 705 (Revised)

    Additional Reporting Circumstances (A26):

  • When auditor has other reporting responsibilities under HKSA 700 (Revised)
  • When non-compliance is a key audit matter under HKSA 701
  • In exceptional cases when management/governance do not take remedial action and withdrawal is not possible - may describe in an Other Matter paragraph under HKSA 706 (Revised)
  • 5.3.3 Reporting to an Appropriate Authority Outside the Entity (Paragraph 29)

    If the auditor has identified or suspects non-compliance, the auditor shall determine whether law, regulation or relevant ethical requirements:

    (a) Require the auditor to report to an appropriate authority outside the entity

    (b) Establish responsibilities under which reporting may be appropriate in the circumstances

    Reasons for External Reporting (A28-A31):

    1. Required by law, regulation or ethical requirements - e.g., statutory requirements for auditors of financial institutions to report to supervisory authorities

    2. Determined as appropriate action under ethical requirements - e.g., HKICPA Code of Ethics requires determining whether further action is needed, which may include reporting to an appropriate authority

    3. Right to report provided by law or regulation - even if not required, the auditor may have the right to report

    Confidentiality Considerations (A32):

    Reporting may be precluded by the auditor's duty of confidentiality under law, regulation or ethical requirements.

    Complex Considerations (A33):

    The auditor may consider:

  • Consulting internally (within the firm or network firm)
  • Consulting on a confidential basis with a regulator or professional body
  • Obtaining legal advice
  • 5.4 Documentation (Paragraph 30)

    The auditor shall include in audit documentation identified or suspected non-compliance with laws and regulations and:

    (a) The audit procedures performed, significant professional judgments made, and conclusions reached

    (b) Discussions of significant matters related to non-compliance with management, those charged with governance, and others, including how management and, where applicable, those charged with governance have responded

    Examples of Documentation (A35):

  • Copies of records or documents
  • Minutes of discussions held with management, those charged with governance or parties outside the entity
  • Ad Space

    6. Conformity with International Standards

    This HKSA conforms with ISA 250 (Revised), except that references to IESBA's Code of Ethics are replaced by HKICPA's Code of Ethics for Professional Accountants.

    Ad Space

    7. Application and Other Explanatory Material - Key Points

    7.1 Entity's Policies and Procedures (A2)

    Examples of policies and procedures to prevent and detect non-compliance:

    Policy/ProcedureDescription
    Monitoring legal requirementsEnsuring operating procedures meet legal requirements
    Internal control systemsInstituting and operating appropriate systems
    Code of conductDeveloping, publicizing and following
    TrainingEnsuring employees understand the code of conduct
    Monitoring complianceMonitoring and disciplining non-compliance
    Legal advisorsEngaging to assist in monitoring legal requirements
    Register of lawsMaintaining register of significant laws and complaints

    In larger entities, responsibilities may be assigned to:

  • Internal audit function
  • Audit committee
  • Compliance function
  • 7.2 Categories of Laws and Regulations - Examples (A6)

    Examples of laws and regulations that may fall into either category:

  • Fraud, corruption and bribery
  • Money laundering, terrorist financing and proceeds of crime
  • Securities markets and trading
  • Banking and other financial products and services
  • Data protection
  • Tax and pension liabilities and payments
  • Environmental protection
  • Public health and safety
  • 7.3 Public Sector Considerations (A7, A34)

    In the public sector, there may be additional audit responsibilities regarding laws and regulations that may relate to audit of financial statements or extend to other aspects of operations. Public sector auditors may be obliged to report identified or suspected non-compliance to the legislature or other governing body.

    Ad Space

    8. Key Takeaways Summary Table

    AreaKey Requirement
    Management ResponsibilityEnsure operations comply with laws and regulations
    Auditor ResponsibilityReasonable assurance; not responsible for preventing non-compliance
    Direct Effect LawsObtain sufficient appropriate audit evidence
    Other LawsPerform specified procedures (inquiry, inspection of correspondence)
    Professional SkepticismRemain alert throughout the audit
    When Non-Compliance IdentifiedUnderstand nature, evaluate effect, discuss with management
    Insufficient EvidenceEvaluate effect on opinion
    Communication with GovernanceUnless clearly inconsequential or prohibited by law
    Intentional/MaterialCommunicate as soon as practicable
    Management InvolvementEscalate to next higher authority
    Auditor's ReportModify opinion as appropriate per HKSA 705
    External ReportingDetermine if required or appropriate
    DocumentationInclude procedures, judgments, conclusions, discussions

    Ad Space

    ---

    ❓ Ready to Test Your Knowledge?

    50 MCQs covering all sections. Timed at 1.25 min each (62.5 min total).

    📝 Start Q&A →🖨️ Save as PDF