Skip to content

Advanced Audit and Assurance (International) · Professional and ethical developments

Recent IESBA Changes: NOCLAR, Technology and Fees for ACCA AAA

Updated 11 October 2026

Recent IESBA changes cover three areas. NOCLAR tells accountants how to respond to suspected non-compliance with laws, including when to disclose to an authority. The technology revisions add threats and rules for using technology and providing IT services. The fee revisions tighten fee-dependency and fee-disclosure rules for audit clients, especially public interest entities. Apply each to the scenario.

Understand Recent IESBA Changes: NOCLAR, Technology and Fees

The IESBA Code of Ethics is updated in response to public interest concerns. For AAA you do not need every paragraph. You need to know what each change is for, what it asks the auditor to do, and how to apply it to a scenario.

NOCLAR means non-compliance with laws and regulations. It was issued in 2016 and took effect on 15 July 2017. Before that, confidentiality often stopped accountants from acting. The NOCLAR provisions give a path: understand the matter, raise it with management and those charged with governance (TCWG), judge whether they respond properly, then decide whether further action is needed. Further action can include disclosing to an appropriate authority. It can also include resigning. The Code says such disclosure is not a breach of the duty of confidentiality, but you must still consider local law and take legal advice. The provisions cover acts by the client, TCWG, management or others working for the client. They do not cover matters that are clearly inconsequential, or personal misconduct unrelated to the business.

Technology-related revisions were approved in April 2023 and took effect on 15 December 2024. They recognise that technology now sits inside audits and services. The changes do three things. They add technology-related factors to how you identify and evaluate threats, such as the complexity of a tool or reliance on its output. They extend competence and due care to cover whether you can properly rely on technology and the data going into it. They tighten the rules on IT systems services to audit clients. For public interest entities (PIEs), the firm must not provide such a service if it would create a self-review threat.

Fee-related revisions were approved in 2024. They apply to audits of financial statements for periods beginning on or after 15 December 2025. Their aim is to reduce fee-dependency pressure and improve transparency. The firm must watch the share of its total fees that comes from one audit client and its related entities. For a PIE, the threshold is 15% of the firm's total fees, and the rule bites when the share exceeds it for each of two consecutive years. The firm must tell TCWG and have a pre-issuance review by an external professional accountant or a professional body. A review inside the firm is not enough for a PIE. The firm must also publicly disclose the fact that fees from the PIE audit client are expected to exceed 15% for each of two consecutive years. For other entities, the threshold is 30% of the firm's total fees for two consecutive years. The firm must again tell TCWG, and a pre-issuance or post-issuance review is a safeguard it should consider to address the threat. There are also stronger disclosure requirements on audit and non-audit fees for PIE clients. Fee rules sit beside the existing ban on contingent fees for audits.

In the exam, these are not memory tests. A case study presents a client with suspected bribery, a firm selling a data platform to an audit client, or a client that is a large share of fee income. You identify the rule, name the threat, recommend action and show professional judgement.

Key rules to remember

NOCLAR response sequence
Understand the matter → discuss with management and TCWG → assess their response → decide if further action is needed → consider disclosure to an authority or withdrawal → document
For audit clients, the auditor also meets the ISA 250 requirements. Document each step and the reasoning.
NOCLAR scope
Acts that are intentional or unintentional, committed by the client, TCWG, management or those working for the client, and contrary to prevailing laws and regulations
Excludes clearly inconsequential matters and personal misconduct unrelated to the entity's business.
Disclosure test
Disclose to an authority only if that is the appropriate action in the circumstances, after considering the public interest, local law and legal advice
The Code treats such disclosure as not breaching confidentiality. Local law may still restrict or require it.
Technology and IT services
Evaluate technology-related threats + keep competence and due care when using technology + no IT systems service to a PIE audit client if it creates a self-review threat
Approved in April 2023 and effective 15 December 2024.
Fee dependency
Fees from one audit client and its related entities ÷ firm's total fees. PIE: more than 15% for each of two consecutive years → tell TCWG, have a pre-issuance review by an external professional accountant or a professional body, and publicly disclose that fees are expected to exceed 15% for each of two consecutive years. Other entities: more than 30% for two consecutive years → tell TCWG and consider a pre-issuance or post-issuance review as a safeguard
The PIE threshold is 15% of total firm fees and the non-PIE threshold is 30%, each tested over two consecutive years. An internal review is not sufficient for a PIE. For a non-PIE, the review is a safeguard to consider, not an automatic step.
Fee transparency for PIEs
PIE audit client: communicate fee information to TCWG and make fee information public
Applies to audits of periods beginning on or after 15 December 2025.

How to solve Recent IESBA Changes: NOCLAR, Technology and Fees questions

Use this method for any question on recent IESBA changes. It keeps your answer tied to the scenario and covers professional skills marks.

  1. 1Read the requirement and note whether you must explain, evaluate or recommend. Note who you are: auditor, engagement partner or ethics partner.
  2. 2Identify which change applies: NOCLAR, technology, fees, or more than one. Use the scenario's clues, such as an alleged bribe, an IT platform or a fee percentage.
  3. 3State the rule briefly in your own words. Give the Code's requirement, not only the topic name.
  4. 4Identify the threats from the facts: self-interest, self-review, intimidation, familiarity or advocacy. Say why each arises.
  5. 5Apply the rule with numbers and facts. Calculate fee ratios, check whether the client is a PIE, and judge whether the matter is inconsequential.
  6. 6Recommend actions in order: raise with TCWG, safeguards, reviews, legal advice, disclosure, or withdrawal. Explain why you chose that order.
  7. 7State what you will document and who you will communicate with, including the network firm or the group auditor if relevant.
  8. 8Close with a clear conclusion. Say whether you can continue and on what conditions.

Quickest way: Rule, threat, action, document

When to use it: Use this when time is short and the question gives a short scenario for 5 to 10 marks.

  1. Name the change in one line: NOCLAR, technology or fees.
  2. Name the threat in one line, with the fact that causes it.
  3. Give two or three actions in order, such as discuss with TCWG, apply a safeguard, then consider disclosure or withdrawal.
  4. End with documentation and your conclusion in one line.

Common mistakes in Recent IESBA Changes: NOCLAR, Technology and Fees

  • Reporting suspected non-compliance straight to the authorities.

    Students think a serious breach means immediate disclosure.

    Fix: Show the sequence. Understand the matter and raise it with management and TCWG first. Disclose only after judging their response and the public interest, and after considering local law and legal advice.

  • Saying confidentiality always stops you from disclosing.

    Students remember the fundamental principle but not the NOCLAR exception.

    Fix: State that the Code allows disclosure of NOCLAR to an appropriate authority without breaching confidentiality. Add that you must consider local law and take legal advice.

  • Treating all technology services as banned for audit clients.

    Students overstate the rule on IT services.

    Fix: Say that the key test is self-review threat. The ban applies to PIE clients where the service creates a self-review threat. For other clients, evaluate threats and apply safeguards.

  • Quoting fee percentages without checking whether the client is a PIE.

    Students learn one number and use it everywhere.

    Fix: First decide whether the client is a PIE. The thresholds differ. Say that the ratio is measured against the firm's total fees and covers related entities.

  • Listing the rules without applying them to the scenario.

    Students rely on memorised notes and skip the case facts.

    Fix: After each rule, write a sentence beginning with the client's name or a fact from the case. This earns analysis and professional skills marks.

  • Forgetting the duty of competence when using technology.

    Students focus on independence and skip the competence and due care change.

    Fix: If an audit tool or AI output is used, say you must understand its purpose and limits and check the input data and the output before relying on it.

Worked examples

Example 1

You are the audit manager on Zenith Foods, a listed company. During testing you find payments of $480,000 to a local agent with no contract or services. You suspect they are bribes to a licensing official. Explain how you should respond under the IESBA NOCLAR provisions.

Show the solution
  1. Identify the issue. A suspected bribe is potential non-compliance with anti-corruption law. It affects the financial statements through possible penalties and misstated expenses. It is not clearly inconsequential.
  2. Obtain an understanding. Gather facts about the payments, who approved them, the law involved and the possible consequences. Do not accuse anyone before the facts are clear.
  3. Raise the matter with management one level above those involved, and with TCWG, such as the audit committee. Ask them to investigate, correct the matter and report to the authority if required.
  4. Assess their response. Is it timely and appropriate? Are they investigating, stopping the payments and disclosing where the law requires?
  5. If the response is inadequate, decide on further action. Consider the public interest, the seriousness of the matter and whether there is a threat of substantial harm. Take legal advice and check local law on disclosure. Consider disclosure to the appropriate authority, which the Code permits without breaching confidentiality. Consider withdrawing from the engagement if the matter affects your confidence in management.
  6. Meet the ISA 250 requirements too. Consider the effect on the audit opinion and on the reliability of management's representations.
  7. Document the facts, discussions, judgements and decisions, and tell the engagement partner.

Answer: Understand the facts, raise the matter with management and the audit committee, and assess their response. If it is inadequate, take legal advice and consider disclosure to an authority or withdrawal. Document everything and consider the effect on the audit.

Example 2

Delta Bank, a PIE, paid your firm $2.4 million in fees in the current year, when your firm's total fees were $14 million. Last year Delta Bank paid $2.1 million when your firm's total fees were $13 million. The firm has also offered to build Delta Bank's new financial reporting system. Evaluate the ethical issues.

Show the solution
  1. Calculate the fee share for each year. Current year: $2.4m ÷ $14m = 0.1714, or about 17.1%. Last year: $2.1m ÷ $13m = 0.1615, or about 16.2%.
  2. Compare both years with the PIE threshold of 15% of total firm fees. The ratio is above 15% in both years, so the two-consecutive-year condition is met. This creates a self-interest threat because the firm may fear losing the client. (The 30% threshold for non-PIEs does not apply, because Delta Bank is a PIE.)
  3. Respond to the fee dependency. Communicate it to TCWG. Arrange a pre-issuance review by an external professional accountant or a professional body. A review by someone inside the firm is not sufficient for a PIE. The firm must also publicly disclose the fact that fees from Delta Bank are expected to exceed 15% for each of two consecutive years. Also consider reducing reliance on the client by growing other fee income.
  4. Evaluate the system offer. Building a financial reporting system for an audit client means the firm would later audit its own work. This creates a self-review threat.
  5. Apply the PIE rule. The firm must not provide an IT systems service to a PIE audit client if it creates a self-review threat. Building a system that produces financial statement figures does so, so the service should be declined.
  6. Conclude. Decline the system build, manage the fee dependency through TCWG communication, the external pre-issuance review and public disclosure, and document the decisions.

Answer: Fees are about 17.1% of the firm's total this year and about 16.2% last year, above the 15% PIE threshold for two consecutive years. Tell TCWG, arrange a pre-issuance review by an external professional accountant or professional body, and publicly disclose the fee dependency. The system build creates a self-review threat and should be declined.

Exam tips

  • Link each rule to the scenario facts. Marks go to application and professional judgement, not to a recited list.
  • In NOCLAR answers, show the order of steps. Examiners reward the sequence and the reasoning for disclosure.
  • Check whether the client is a PIE before applying any fee or IT services rule. It often changes the answer.
  • Use dollar figures in calculations and show the ratio working. State clearly which threshold you are comparing it with.
  • Do not name Code paragraph numbers unless you are sure of them. Describe the requirement in plain words.

Practice questions from Professional and ethical developments

Recent IESBA Changes: NOCLAR, Technology and Fees: frequently asked questions

What does NOCLAR stand for in the IESBA Code?

It stands for non-compliance with laws and regulations. The Code sets out how accountants respond when they become aware of, or suspect, such non-compliance. The response follows a defined sequence and may end in disclosure to an authority.

Can an auditor disclose NOCLAR without breaching confidentiality?

The Code says disclosure to an appropriate authority is not a breach of the duty of confidentiality when it is the right action in the circumstances. You still need to consider local law and take legal advice. Disclosure is a last step after management and TCWG have been given the chance to respond.

When did the technology-related IESBA revisions take effect?

They took effect on 15 December 2024. They cover how technology affects threats, competence and due care, and the rules on IT systems services for audit clients.

What do the fee-related revisions change?

They tighten the rules on fee dependency and fee transparency for audit clients, with stricter treatment for PIEs. They apply to audits of financial statements for periods beginning on or after 15 December 2025. Expect questions on disclosing to TCWG and applying safeguards such as independent reviews.