ACCA Strategic Professional · Advanced Audit and Assurance (International)
Laws and Regulations in ACCA AAA: Chapter Guide
Laws and regulations is the AAA chapter on how an auditor deals with non-compliance by a client. ISA 250 (Revised) sets the duties. You identify risks, perform limited procedures, respond to suspected non-compliance, then decide whether to report internally, to regulators, or in the audit report. Confidentiality limits the options.
What this chapter covers
This chapter covers what the auditor must do about laws and regulations when auditing financial statements. It starts with ISA 250 (Revised), which separates laws that have a direct effect on the financial statements, such as tax and pension rules, from other laws that matter to the entity's operations but may not affect the numbers. For the first group the auditor must obtain sufficient appropriate evidence. For the second group the auditor performs specified procedures only to help identify non-compliance.
The chapter then moves from identification to response. You learn the procedures used to spot non-compliance, how to react when you suspect it, and how to report it. The response draws on the IESBA Code of Ethics approach to non-compliance with laws and regulations, usually called NOCLAR. Reporting depends on the duty of confidentiality, which can be overridden in some circumstances, such as a legal duty to report or the public interest.
The chapter links to many other parts of AAA. It connects to risk assessment (ISA 315 (Revised 2019)), fraud (ISA 240), written representations (ISA 580), communication with those charged with governance (ISA 260 and ISA 265), modifications to the audit report (ISA 705), and professional ethics and money laundering. In a Section A case study, a legal breach is often one of several issues you must spot and rank.
Non-compliance appears in scenarios as bribery, environmental breaches, tax evasion, or false customer data, and it often carries both technical marks and professional skills marks. Examiners want you to name the issue, say what you would do, and explain the effect on the audit opinion, ethics, and reporting. The chapter is also a good test of judgement, because the answer rarely sits with one rule. Candidates who can link the facts to the ISA, the Code and the report earn marks across several requirements, and this is worth the effort of learning a clear structure.
Laws and regulations: topics in the order to study them
- 1Auditor Responsibilities for Laws and Regulations (ISA 250)Start here because it sets the two categories of law and the limits of the auditor's duty, which every later topic relies on.
- 2Audit Procedures for Identifying Non-ComplianceNext, learn how the auditor actually finds issues, since you cannot respond to something you have not identified.
- 3Responding to Suspected Non-Compliance (NOCLAR)Once you can spot non-compliance, learn the steps to take: understand the matter, discuss with management, consider the effect and decide on further action.
- 4Reporting Non-Compliance and ConfidentialityFinish with reporting, because it needs everything before it and brings in confidentiality, the audit report and external disclosure.
How to prepare Laws and regulations
Treat this as a process chapter. Learn the sequence of identify, respond and report, then practise applying it to short scenarios.
- Read ISA 250 (Revised) and write a one-page summary of the two categories of law and what the auditor must do for each.
- Build a list of audit procedures: enquiries of management and those charged with governance, inspecting correspondence with regulators, reviewing legal expenses, reading minutes and obtaining written representations.
- Learn the NOCLAR response as a flow: obtain understanding, discuss with management or governance, assess whether to escalate, and consider whether to withdraw.
- Make a table of reporting routes: management, those charged with governance, regulator, and the audit report. Note when each applies and the effect on the opinion.
- Learn the confidentiality exceptions in plain words: legal duty to disclose, legal right or permission, and public interest. Remember that the auditor may need legal advice.
- Practise past-style scenarios. For each one, name the law, classify it, state the audit risk, list the procedures, give the response and conclude on the opinion.
- Write short answers under time pressure, using the scenario facts in every point to earn professional skills marks.
Common mistakes in Laws and regulations
Saying the auditor is responsible for preventing or detecting all non-compliance.
Fix: State that management and governance are responsible for compliance. The auditor obtains reasonable assurance on the financial statements and performs set procedures for each category of law.
Treating all laws the same way.
Fix: Classify each law in the scenario first. Say whether it has a direct effect on the financial statements or not, and tailor the work to that.
Listing generic audit procedures that ignore the scenario.
Fix: Choose procedures that fit the specific breach and say what each would show. Link each one to the facts given.
Jumping to external reporting without first discussing with management and governance.
Fix: Show the steps in order: understand, discuss, assess the effect, then consider escalation and disclosure. Explain why each step comes when it does.
Ignoring confidentiality when discussing disclosure.
Fix: Say that confidentiality applies, then name the grounds that may override it and note that legal advice may be needed.
Forgetting the effect on the audit report.
Fix: Finish every answer by concluding on materiality and pervasiveness, the type of opinion and any need for an emphasis or other matter paragraph, as appropriate.
Last-day revision: Laws and regulations
- ISA 250 (Revised): management is responsible for compliance; the auditor is not responsible for preventing non-compliance.
- Two categories: laws with a direct effect on the financial statements, and other laws that may be fundamental to the business.
- For direct-effect laws, obtain sufficient appropriate audit evidence of compliance.
- For other laws, perform limited procedures: enquire of management and those charged with governance, and inspect correspondence with regulators.
- Stay alert for non-compliance throughout the audit, as audit procedures may reveal it.
- Obtain written representations that management has disclosed all known or suspected non-compliance.
- On suspicion, understand the matter, discuss it with management and consider the effect on the financial statements and the audit.
- Communicate matters to those charged with governance unless they are all involved in the non-compliance.
- Consider the effect on the audit opinion, including a qualified or adverse opinion, or a disclaimer if evidence is limited.
- Confidentiality can be overridden by a legal duty or right, or in the public interest, after considering legal advice.
- If management does not remedy the issue, consider withdrawal from the engagement and the legal and ethical consequences.
- Document the matter, the discussions and the judgements made.
Laws and regulations practice questions
- While auditing Lumen Retail, the auditor suspects the finance director is involved in a tax evasion scheme. What should the auditor do in de…
- During the audit of Harbor Textiles Ltd, an audit senior notices payments to a government official that may breach anti-bribery legislation.…
- Brightwater Ltd operates a chemical plant subject to environmental licensing laws. These laws do not directly affect the amounts in the fina…
- Auditors of Brightwater Utilities, a regulated water company, are obtaining an understanding of the legal and regulatory framework. Which of…
- During the audit of Orion Bank Ltd, the auditor finds likely non-compliance with a banking regulation by a senior director. Management refus…
- While auditing Brightwater Ltd, a manufacturer, the auditor learns from the finance director that the company may have breached an environme…
- Under the IESBA Code, a professional accountant in public practice becomes aware of suspected NOCLAR at a client. Which factor is the accoun…
- Zephyr Foods, an audit client of Marlow & Co, operates in the food manufacturing sector. During planning, the audit team asks what its respo…
Laws and regulations in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Laws and regulations: frequently asked questions
Is Laws and regulations a big topic in AAA?
It is a compact chapter, but the ideas appear in many scenarios. Non-compliance links to ethics, fraud, reporting and the audit opinion, so you can use it in several requirements.
What is NOCLAR?
NOCLAR stands for non-compliance with laws and regulations. It refers to the approach in the IESBA Code of Ethics that tells professional accountants how to respond when they find or suspect such non-compliance, including when to escalate.
Can an auditor breach confidentiality to report non-compliance?
Sometimes. Confidentiality may be overridden where law requires or permits disclosure, or where disclosure is in the public interest. You should consider legal advice before acting.
How do I structure a written answer on a suspected breach?
Identify the law and its category, explain the risk to the financial statements and the audit, list tailored procedures, describe the response and escalation, and end with the effect on the opinion and report.