HKSA 250 - Consideration of Laws and Regulations
HKSA 250 (Revised) - Consideration of Laws and Regulations in an Audit of Financial Statements
1. Introduction
1.1 Scope of HKSA 250 (Revised)
HKSA 250 (Revised) deals with the auditor's responsibility to consider laws and regulations in an audit of financial statements. This standard does not apply to other assurance engagements where the auditor is specifically engaged to test and report separately on compliance with specific laws or regulations.
Effective Date: Audits of financial statements for periods beginning on or after 15 December 2017.
1.2 Effect of Laws and Regulations
The effect of laws and regulations on financial statements varies considerably:
| Category | Description | Examples |
|---|---|---|
| Direct Effect | Provisions that determine reported amounts and disclosures in financial statements | Tax laws, pension laws |
| Indirect Effect | Laws fundamental to operating aspects, business continuity, or avoiding material penalties | Operating licenses, regulatory solvency requirements, environmental regulations |
Non-compliance may result in:
2. Responsibilities
2.1 Management's Responsibility (Paragraph 3)
Management, with oversight from those charged with governance, is responsible for ensuring that the entity's operations are conducted in accordance with laws and regulations, including compliance with provisions that determine reported amounts and disclosures.
2.2 Auditor's Responsibility (Paragraphs 4-9)
Key Principle: The auditor is not responsible for preventing non-compliance and cannot be expected to detect non-compliance with all laws and regulations.
The auditor is responsible for obtaining reasonable assurance that financial statements, taken as a whole, are free from material misstatement, whether due to fraud or error.
Inherent Limitations affecting detection of non-compliance:
- Many laws and regulations relating to operating aspects typically do not affect financial statements and are not captured by the entity's information systems relevant to financial reporting
- Non-compliance may involve concealment (collusion, forgery, deliberate failure to record transactions, management override of controls, intentional misrepresentations)
- Whether an act constitutes non-compliance is ultimately a matter for a court or other adjudicative body
General Rule: The further removed non-compliance is from events and transactions reflected in financial statements, the less likely the auditor is to become aware of it.
2.3 Two Categories of Laws and Regulations (Paragraph 6)
| Category | Description | Auditor's Responsibility |
|---|---|---|
| (a) Direct Effect | Provisions generally recognized to have a direct effect on determination of material amounts and disclosures (e.g., tax and pension laws) | Obtain sufficient appropriate audit evidence regarding compliance |
| (b) Other Laws | Laws fundamental to operating aspects, business continuity, or avoiding material penalties (e.g., operating licenses, solvency requirements, environmental regulations) | Limited to specified audit procedures to help identify non-compliance that may have a material effect |
2.4 Professional Skepticism (Paragraph 8)
The auditor must remain alert to the possibility that other audit procedures applied for forming an opinion may bring instances of non-compliance to attention. Maintaining professional skepticism throughout the audit is critical.
2.5 Additional Responsibilities (Paragraph 9)
The auditor may have additional responsibilities under law, regulation, or ethical requirements that differ from or go beyond HKSA 250, including:
3. Objectives (Paragraph 11)
The objectives of the auditor are:
4. Definition (Paragraph 12)
Non-compliance – Acts of omission or commission, intentional or unintentional, committed by:
Which are contrary to prevailing laws or regulations.
Exclusion: Non-compliance does not include personal misconduct unrelated to the business activities of the entity.
Key Points:
5. Requirements - Detailed Analysis
5.1 The Auditor's Consideration of Compliance (Paragraphs 13-18)
5.1.1 Obtaining Understanding (Paragraph 13)
As part of obtaining an understanding of the entity and its environment under HKSA 315 (Revised 2019), the auditor shall obtain a general understanding of:
(a) The legal and regulatory framework applicable to the entity and the industry or sector in which the entity operates
(b) How the entity is complying with that framework
Practical Approaches (A11):
- Use existing understanding of the entity's industry, regulatory and other external factors
- Update understanding of laws that directly determine reported amounts and disclosures
- Inquire of management about other laws that may have a fundamental effect on operations
- Inquire about policies and procedures regarding compliance
- Inquire about policies for identifying, evaluating and accounting for litigation claims
5.1.2 Direct Effect Laws (Paragraph 14)
The auditor shall obtain sufficient appropriate audit evidence regarding compliance with provisions of laws and regulations generally recognized to have a direct effect on determination of material amounts and disclosures.
Examples of Direct Effect Laws (A12):
5.1.3 Other Laws - Specified Procedures (Paragraph 15)
The auditor shall perform the following audit procedures to help identify instances of non-compliance with other laws that may have a material effect:
(a) Inquire of management and, where appropriate, those charged with governance, as to whether the entity is in compliance with such laws and regulations
(b) Inspect correspondence, if any, with relevant licensing or regulatory authorities
5.1.4 Remaining Alert (Paragraph 16)
During the audit, the auditor shall remain alert to the possibility that other audit procedures applied may bring instances of non-compliance or suspected non-compliance to attention.
Examples of Other Procedures That May Identify Non-Compliance (A15):
5.1.5 Written Representations (Paragraph 17)
The auditor shall request management and, where appropriate, those charged with governance, to provide written representations that all known instances of non-compliance or suspected non-compliance whose effects should be considered when preparing financial statements have been disclosed to the auditor.
Important: Written representations do not provide sufficient appropriate audit evidence on their own and do not affect the nature and extent of other audit evidence to be obtained.
5.1.6 Limitation on Procedures (Paragraph 18)
In the absence of identified or suspected non-compliance, the auditor is not required to perform audit procedures regarding compliance with laws and regulations other than those set out in paragraphs 13-17.
5.2 Audit Procedures When Non-Compliance Is Identified or Suspected (Paragraphs 19-22)
5.2.1 Initial Response (Paragraph 19)
If the auditor becomes aware of information concerning an instance of non-compliance or suspected non-compliance, the auditor shall obtain:
(a) An understanding of the nature of the act and the circumstances in which it has occurred
(b) Further information to evaluate the possible effect on the financial statements
Indications of Non-Compliance (A18):
- Investigations by regulatory organizations or government departments
- Payment of fines or penalties
- Payments for unspecified services or loans to consultants, related parties, employees or government employees
- Excessive sales commissions or agent's fees
- Purchasing at prices significantly above or below market price
- Unusual cash payments, cashier's checks payable to bearer, transfers to numbered bank accounts
- Unusual transactions with companies registered in tax havens
- Payments for goods/services made other than to the country of origin
- Payments without proper exchange control documentation
- Information system failing to provide adequate audit trail or sufficient evidence
- Unauthorized or improperly recorded transactions
- Adverse media comment
Matters Relevant to Evaluating Effect on Financial Statements (A19):
- Potential financial consequences (fines, penalties, damages, threat of expropriation, enforced discontinuation of operations, litigation)
- Whether potential financial consequences require disclosure
- Whether potential consequences are so serious as to call into question fair presentation or make financial statements misleading
5.2.2 Discussion with Management (Paragraph 20)
If the auditor suspects there may be non-compliance, the auditor shall discuss the matter (unless prohibited by law or regulation) with:
If management or those charged with governance do not provide sufficient information supporting compliance, and the suspected non-compliance may be material, the auditor shall consider the need to obtain legal advice.
Restrictions on Communication (A21):
In some jurisdictions, law or regulation may restrict communication of certain matters with management and those charged with governance (e.g., anti-money laundering legislation may prohibit alerting the entity when the auditor is required to report to an appropriate authority).
5.2.3 Insufficient Evidence (Paragraph 21)
If sufficient information about suspected non-compliance cannot be obtained, the auditor shall evaluate the effect of the lack of sufficient appropriate audit evidence on the auditor's opinion.
5.2.4 Evaluating Implications (Paragraph 22)
The auditor shall evaluate the implications of identified or suspected non-compliance in relation to other aspects of the audit, including:
Circumstances Affecting Reliability of Written Representations (A24):
- Auditor suspects or has evidence of involvement or intended involvement of management/those charged with governance in non-compliance
- Auditor is aware that management/those charged with governance have knowledge of non-compliance and, contrary to legal/regulatory requirements, have not reported or authorized reporting to an appropriate authority
Potential Withdrawal from Engagement (A25):
The auditor may consider withdrawing from the engagement (where permitted by law or regulation) when:
Note: Withdrawal is not a substitute for complying with other responsibilities under law, regulation or ethical requirements.
5.3 Communicating and Reporting Identified or Suspected Non-Compliance (Paragraphs 23-29)
5.3.1 Communication with Those Charged with Governance (Paragraphs 23-25)
General Rule (Paragraph 23):
Unless all those charged with governance are involved in management (and therefore already aware), the auditor shall communicate (unless prohibited by law or regulation) with those charged with governance matters involving non-compliance that come to attention during the audit, other than when matters are clearly inconsequential.
Intentional and Material Non-Compliance (Paragraph 24):
If the auditor believes non-compliance is intentional and material, the auditor shall communicate the matter with those charged with governance as soon as practicable.
Suspected Involvement of Management/Governance (Paragraph 25):
If the auditor suspects that management or those charged with governance are involved in non-compliance, the auditor shall communicate the matter to the next higher level of authority at the entity (e.g., audit committee, supervisory board). Where no higher authority exists, or if the auditor believes communication may not be acted upon, the auditor shall consider obtaining legal advice.
5.3.2 Implications for Auditor's Report (Paragraphs 26-28)
| Scenario | Required Action |
|---|---|
| Material non-compliance not adequately reflected in financial statements (Paragraph 26) | Express qualified opinion or adverse opinion per HKSA 705 (Revised) |
| Precluded by management/governance from obtaining sufficient evidence (Paragraph 27) | Express qualified opinion or disclaim an opinion due to scope limitation per HKSA 705 (Revised) |
| Unable to determine due to circumstances (not management) (Paragraph 28) | Evaluate effect on opinion per HKSA 705 (Revised) |
Additional Reporting Circumstances (A26):
5.3.3 Reporting to an Appropriate Authority Outside the Entity (Paragraph 29)
If the auditor has identified or suspects non-compliance, the auditor shall determine whether law, regulation or relevant ethical requirements:
(a) Require the auditor to report to an appropriate authority outside the entity
(b) Establish responsibilities under which reporting may be appropriate in the circumstances
Reasons for External Reporting (A28-A31):
1. Required by law, regulation or ethical requirements - e.g., statutory requirements for auditors of financial institutions to report to supervisory authorities
2. Determined as appropriate action under ethical requirements - e.g., HKICPA Code of Ethics requires determining whether further action is needed, which may include reporting to an appropriate authority
3. Right to report provided by law or regulation - even if not required, the auditor may have the right to report
Confidentiality Considerations (A32):
Reporting may be precluded by the auditor's duty of confidentiality under law, regulation or ethical requirements.
Complex Considerations (A33):
The auditor may consider:
5.4 Documentation (Paragraph 30)
The auditor shall include in audit documentation identified or suspected non-compliance with laws and regulations and:
(a) The audit procedures performed, significant professional judgments made, and conclusions reached
(b) Discussions of significant matters related to non-compliance with management, those charged with governance, and others, including how management and, where applicable, those charged with governance have responded
Examples of Documentation (A35):
6. Conformity with International Standards
This HKSA conforms with ISA 250 (Revised), except that references to IESBA's Code of Ethics are replaced by HKICPA's Code of Ethics for Professional Accountants.
7. Application and Other Explanatory Material - Key Points
7.1 Entity's Policies and Procedures (A2)
Examples of policies and procedures to prevent and detect non-compliance:
| Policy/Procedure | Description |
|---|---|
| Monitoring legal requirements | Ensuring operating procedures meet legal requirements |
| Internal control systems | Instituting and operating appropriate systems |
| Code of conduct | Developing, publicizing and following |
| Training | Ensuring employees understand the code of conduct |
| Monitoring compliance | Monitoring and disciplining non-compliance |
| Legal advisors | Engaging to assist in monitoring legal requirements |
| Register of laws | Maintaining register of significant laws and complaints |
In larger entities, responsibilities may be assigned to:
7.2 Categories of Laws and Regulations - Examples (A6)
Examples of laws and regulations that may fall into either category:
7.3 Public Sector Considerations (A7, A34)
In the public sector, there may be additional audit responsibilities regarding laws and regulations that may relate to audit of financial statements or extend to other aspects of operations. Public sector auditors may be obliged to report identified or suspected non-compliance to the legislature or other governing body.
8. Key Takeaways Summary Table
| Area | Key Requirement |
|---|---|
| Management Responsibility | Ensure operations comply with laws and regulations |
| Auditor Responsibility | Reasonable assurance; not responsible for preventing non-compliance |
| Direct Effect Laws | Obtain sufficient appropriate audit evidence |
| Other Laws | Perform specified procedures (inquiry, inspection of correspondence) |
| Professional Skepticism | Remain alert throughout the audit |
| When Non-Compliance Identified | Understand nature, evaluate effect, discuss with management |
| Insufficient Evidence | Evaluate effect on opinion |
| Communication with Governance | Unless clearly inconsequential or prohibited by law |
| Intentional/Material | Communicate as soon as practicable |
| Management Involvement | Escalate to next higher authority |
| Auditor's Report | Modify opinion as appropriate per HKSA 705 |
| External Reporting | Determine if required or appropriate |
| Documentation | Include procedures, judgments, conclusions, discussions |
---
❓ Ready to Test Your Knowledge?
50 MCQs covering all sections. Timed at 1.25 min each (62.5 min total).
📝 Start Q&A →🖨️ Save as PDF