Advanced Audit and Assurance (International) · Laws and regulations
Auditor Responsibilities for Laws and Regulations (ISA 250)
Updated 11 October 2026 · Fact-checked
ISA 250 (Revised) requires the auditor to obtain reasonable assurance that the financial statements are free from material misstatement caused by non-compliance with laws and regulations. Management is responsible for compliance. The auditor tests laws with a direct effect on the numbers and performs limited procedures for indirect laws.
Understand Auditor Responsibilities for Laws and Regulations (ISA 250)
Start with who is responsible. Management, overseen by those charged with governance, must make sure the entity complies with laws and regulations. The auditor does not guarantee compliance. The auditor's job is narrower: to consider how non-compliance affects the financial statements and the audit opinion.
ISA 250 splits laws into two groups. Direct laws have a direct effect on the amounts and disclosures in the financial statements. Examples are tax legislation, pension rules and the company law rules on distributable profits. For these, the auditor must obtain sufficient appropriate evidence of compliance, just like any other assertion.
Indirect laws do not affect the numbers directly. They are fundamental to the entity's ability to operate, or to avoid penalties. Examples are health and safety rules, environmental licences, data protection and financial services conduct rules. Non-compliance may lead to fines, litigation, loss of a licence or even going concern doubts. For these, ISA 250 requires only specified procedures: enquire of management and those charged with governance, and inspect correspondence with licensing and regulatory authorities.
The auditor must stay alert. Even without specific signs, the auditor must remain aware that audit procedures for other purposes may reveal non-compliance. The auditor also obtains written representations that management has disclosed all known or suspected non-compliance. If non-compliance is identified or suspected, the auditor must understand it, discuss it with management and those charged with governance, and evaluate the effect on the audit, the opinion and reporting. Professional scepticism applies throughout.
In the exam, the skill is to link the law to its consequence: which group it belongs to, what evidence is needed, who must be told, and what happens to the report.
Key rules to remember
- Responsibility split
- Management and TCWG: ensure compliance. Auditor: reasonable assurance on material misstatement from non-compliance.
- The audit does not relieve management of its duty, and the auditor is not responsible for preventing non-compliance.
- Direct laws
- Direct effect on amounts and disclosures → obtain sufficient appropriate audit evidence of compliance
- Typical examples: tax, pensions, distributable profits rules.
- Indirect laws
- Indirect effect → (1) enquire of management and TCWG, (2) inspect correspondence with licensing or regulatory authorities
- These are the only required procedures unless non-compliance is identified or suspected.
- Required understanding
- Understand the legal and regulatory framework and how the entity complies with it
- This is part of risk assessment, linked to understanding the entity.
- Response to identified or suspected non-compliance
- Understand the matter → discuss with management and TCWG → evaluate effect on the audit and opinion → consider reporting
- Reporting can be to TCWG, in the auditor's report, or to an outside authority where required or appropriate.
- Written representation
- Management confirms it has disclosed all known or suspected non-compliance
- Representations do not replace other evidence.
How to solve Auditor Responsibilities for Laws and Regulations (ISA 250) questions
Use this order for any scenario question on laws and regulations. It keeps your answer structured and earns professional skills marks.
- 1Identify the law or regulation in the scenario and the entity's business, so you can say why it matters.
- 2Classify it as direct or indirect, and say why in one sentence.
- 3State who is responsible: management and those charged with governance for compliance, the auditor for the effect on the financial statements.
- 4Set out the audit procedures. For direct laws, gather evidence on the amounts. For indirect laws, enquire and inspect correspondence with regulators.
- 5If non-compliance is identified or suspected, explain the steps: understand it, discuss with management and TCWG, and assess materiality and the effect on the financial statements, including provisions and disclosures.
- 6Assess the impact on the opinion, going concern and the reliability of management representations, and consider whether modification is needed.
- 7Address reporting: TCWG, the auditor's report, and any external reporting duty, remembering confidentiality and ethical requirements.
- 8Close with a clear recommendation, and apply every point to the scenario facts.
Quickest way: Classify, Test, Escalate
When to use it: Use this when time is short and the requirement asks what the auditor should do about a legal issue.
- Classify: direct or indirect.
- Test: direct means obtain evidence on the numbers; indirect means enquire and inspect regulator correspondence.
- Quantify: could fines, claims or lost licences be material or threaten going concern?
- Escalate: discuss with management and TCWG, then consider the opinion and any external reporting.
- Conclude with one line on the effect on the audit report.
Common mistakes in Auditor Responsibilities for Laws and Regulations (ISA 250)
Saying the auditor is responsible for ensuring the client complies with laws.
Students confuse detecting issues with being accountable for them.
Fix: State that management and TCWG are responsible for compliance. The auditor obtains reasonable assurance about the effect on the financial statements.
Applying full testing to every law, including indirect ones.
Students forget that ISA 250 sets limited procedures for indirect laws.
Fix: Say that for indirect laws the auditor enquires and inspects regulator correspondence, unless a problem is suspected.
Classifying laws wrongly, for example calling tax law indirect.
Students focus on the type of law rather than its effect on the numbers.
Fix: Ask whether the law directly determines amounts or disclosures. If yes, it is direct.
Listing procedures without applying them to the scenario.
Students recall the standard but ignore the facts given.
Fix: Name the entity, the specific law, the amounts and the likely consequence in each point.
Ignoring the effect on the audit report and going concern.
Students stop at reporting to management.
Fix: Always conclude on materiality, provisions, disclosure, opinion modification and whether the entity's ability to continue is affected.
Forgetting that reporting externally may conflict with confidentiality.
Students treat confidentiality as absolute.
Fix: Explain that the auditor considers legal advice and the legal or ethical duty to report, and that confidentiality may be overridden where law requires or permits.
Worked examples
Example 1
Aster Foods sells packaged goods. You are the audit senior. Aster must comply with income tax legislation and with food safety rules that allow regulators to close factories. Classify each as direct or indirect and state the audit work required.
Show the solution
- Income tax legislation determines the tax expense, tax liabilities and related disclosures, so it has a direct effect on the financial statements.
- For tax, obtain sufficient appropriate evidence, for example recompute the tax charge, review tax computations and correspondence, and test deferred tax balances.
- Food safety rules do not determine amounts directly, but breaches could cause fines, closure and going concern problems, so they are indirect.
- For food safety, enquire of management and TCWG about compliance and inspect correspondence with the regulators and any inspection reports.
- If these procedures suggest a breach, extend work: assess the potential fines, provisions, contingent liabilities and going concern effect.
Answer: Income tax law is direct, so full evidence is needed on the amounts. Food safety law is indirect, so the required work is enquiry and inspection of regulator correspondence, extended if non-compliance is suspected.
Example 2
During the audit of Brightline Ltd, you find emails suggesting the finance director paid a fine to an environmental regulator that was not recorded. Management says it is trivial. Explain what you should do.
Show the solution
- Understand the matter: obtain the emails, the regulator's notice and the amount, and establish whether the law was breached and who was involved.
- Discuss with management at an appropriate level, and with TCWG if management may be involved, since the finance director's role raises integrity concerns.
- Evaluate materiality, both quantitative and qualitative. An unrecorded fine may be small, but it may signal weak controls and further breaches or licence risks.
- Consider the financial statement effect: record the fine, and assess any provisions, contingent liabilities and disclosure for further penalties.
- Reassess risk and the reliability of management representations, applying professional scepticism, and consider whether other procedures need to be extended.
- Consider the opinion: if the misstatement is material and uncorrected, modify the opinion. Consider whether external reporting is required or appropriate, taking legal advice and weighing confidentiality.
Answer: Investigate, discuss with management and TCWG, evaluate materiality qualitatively and quantitatively, require correction, reassess risk and representations, and then decide on opinion modification and any external reporting.
Exam tips
- Always give the direct versus indirect classification first, with a one-line reason. It is an easy mark.
- Name the responsible party explicitly. Examiners reward a clear management versus auditor distinction.
- Tie each procedure to the scenario facts. Generic lists earn few marks, and professional skills marks reward application.
- If a breach is found, cover materiality, TCWG communication, opinion effect and external reporting in that order.
- Mention ethics and confidentiality when external reporting arises, and say the auditor should consider legal advice.
Practice questions from Laws and regulations
- An audit junior at Hallam & Partners mentions at a social gathering that a client, Orwell Pharma, is under investigation by a regulator. Whi…
- Kestrel Foods Inc's auditor discovers that management has been discharging effluent in breach of environmental law. Management dismisses the…
- Delmar Pharma Ltd's auditor identifies a suspected breach of tax legislation that has an immaterial effect on the financial statements. Mana…
- During the audit of Kestrel Foods, the auditor discovers payments to a government official that appear to be bribes. Management is aware of …
- A firm is asked by a former client's successor auditor for information about why the firm resigned. The firm's partner suspects the client c…
Auditor Responsibilities for Laws and Regulations (ISA 250) in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Auditor Responsibilities for Laws and Regulations (ISA 250): frequently asked questions
What is the difference between direct and indirect laws in ISA 250?
Direct laws have a direct effect on amounts and disclosures in the financial statements, such as tax and pension laws. Indirect laws affect operations, such as health and safety or environmental rules, and may only lead to fines or other consequences. The audit procedures required differ for each group.
Is the auditor responsible for detecting all non-compliance?
No. Management and those charged with governance are responsible for compliance. The auditor obtains reasonable assurance about material misstatement caused by non-compliance, and an audit has inherent limitations.
What must the auditor do for indirect laws if nothing looks wrong?
The auditor enquires of management and those charged with governance about compliance and inspects correspondence with relevant licensing or regulatory authorities. No further testing is required unless non-compliance is identified or suspected.
What happens if the auditor suspects non-compliance?
The auditor seeks to understand the matter, discusses it with management and those charged with governance, and evaluates the effect on the financial statements, the audit and the opinion. The auditor also considers whether reporting outside the entity is required or appropriate.