Skip to content

Advanced Audit and Assurance (International) · Professional liability

Audit Negligence and Duty of Care Explained for AAA

Updated 11 October 2026 · Fact-checked

Audit negligence is a civil claim that an auditor failed to use reasonable skill and care. To succeed, the claimant must prove four things: a duty of care was owed, the duty was breached, the breach caused the loss, and the loss was a recognised, foreseeable type of loss. Apply each element to the scenario in turn.

Understand Audit Negligence and Duty of Care

Negligence is a civil wrong (a tort). It is not a crime. A claimant sues for money to put them back where they would have been had the auditor done the job properly. There does not need to be a contract between the parties, which is why shareholders, lenders and buyers can sometimes sue an auditor.

The claimant must prove four elements. First, the auditor owed them a duty of care. Second, the auditor breached that duty by falling below the standard expected. Third, the breach caused the loss. Fourth, the loss was of a kind the law recognises and was not too remote.

Duty of care is the main battleground. To the audited company, the auditor owes a duty through the contract (the engagement letter), and also in tort. To third parties, there is no automatic duty. Courts in many common-law jurisdictions use a test often linked to the English case Caparo Industries plc v Dickman (1990). Under it, the loss must be reasonably foreseeable, there must be a relationship of sufficient proximity between auditor and claimant, and it must be fair, just and reasonable to impose a duty. In that case the House of Lords held that auditors of a company's statutory accounts owed no duty to an individual investor buying shares, or to existing shareholders making investment decisions. The accounts exist so shareholders can oversee management, not to guide share purchases.

Breach is judged against the standard of a reasonably competent auditor. In practice, evidence of compliance with ISAs and the ethical requirements is the key benchmark. A failure to follow ISAs, such as weak scepticism, poor evidence or ignored red flags, is strong evidence of breach. But an auditor is not a guarantor. An audit gives reasonable assurance, so undetected misstatement does not by itself prove negligence if the audit was properly planned and performed.

Causation and loss complete the claim. The claimant must show that, but for the breach, the loss would not have happened. Losses caused by other things, such as market conditions or management fraud that a proper audit would not have found, are not recoverable. The claimant must also take reasonable steps to limit the loss. Where the claimant was partly at fault, the damages may be reduced (contributory negligence). The rules differ between countries, so in the exam, argue from the principles and the facts given.

Key rules to remember

Four elements of negligence
Duty of care + Breach + Causation + Recognised loss = Negligence
The claimant must prove all four. If one fails, the claim fails.
Caparo three-part test
Foreseeability + Proximity + Fair, just and reasonable
Used to decide whether a duty is owed to a third party. Foreseeability alone is not enough.
Standard of care
Standard = a reasonably competent auditor, with ISA compliance as the key benchmark
Non-compliance with ISAs is strong evidence of breach, not automatic proof.
Causation test
But for the breach, would the loss have occurred?
If yes, the breach did not cause the loss.
Burden of proof
Claimant proves negligence on the balance of probabilities
This is the civil standard, lower than the criminal standard.

How to solve Audit Negligence and Duty of Care questions

Use the same four-element structure for any negligence question. Tie every point to the scenario facts.

  1. 1Identify the claimant and the defendant. Is the claimant the audited client or a third party such as a shareholder, lender or buyer?
  2. 2Test duty of care. For the client, state that a duty exists through the contract and in tort. For a third party, apply foreseeability, proximity and fair, just and reasonable.
  3. 3Test breach. Compare what the auditor did with ISAs and the ethical requirements. List the specific failings in the scenario, such as unchallenged management explanations or missing evidence.
  4. 4Test causation. Ask whether the loss would have been avoided had the auditor acted properly. Note other causes, such as management fraud or market events.
  5. 5Test the loss. Confirm it is a recognised and foreseeable loss, and consider remoteness and any duty to limit the loss.
  6. 6Consider defences and reductions: no duty, compliance with ISAs, no causation, contributory negligence, and any liability limitation that applies.
  7. 7Conclude with a clear view on whether the claim is likely to succeed, and add practical advice for the firm if asked.

Quickest way: Four-box scan: D-B-C-L

When to use it: Use when time is short, or for a 5 to 8 mark requirement on whether an auditor is liable.

  1. Draw four boxes on your answer sheet: Duty, Breach, Causation, Loss.
  2. In each box, write one verdict (likely, unlikely or unclear) with one fact from the scenario.
  3. Start with Duty if the claimant is a third party, since that is usually where the claim fails.
  4. Write one sentence on each box, then add a conclusion sentence.
  5. Spend any spare time on breach, where ISA references earn the most credit.

Common mistakes in Audit Negligence and Duty of Care

  • Saying the auditor owes a duty of care to everyone who reads the accounts.

    Students treat foreseeability as the whole test.

    Fix: Apply all three Caparo parts. Say that proximity and fairness usually limit duty to third parties.

  • Treating any misstatement not found as proof of negligence.

    Students forget that an audit gives reasonable, not absolute, assurance.

    Fix: Ask whether a reasonably competent auditor following ISAs would have found it. Refer to the actual procedures performed.

  • Skipping causation and loss and stopping at breach.

    Breach is the most interesting part, so it takes all the time.

    Fix: Always write at least a line on whether the loss would have happened anyway.

  • Listing ISA failings without applying them to the scenario.

    Students recite standards from memory.

    Fix: Quote the scenario fact first, then name the ISA principle it breaches, such as scepticism or sufficient appropriate evidence.

  • Ignoring the client as a claimant and discussing only third parties.

    Caparo is so well known that students assume it covers everything.

    Fix: State that the client has a contractual and tortious claim, then deal with third parties separately.

  • Claiming Caparo is binding law in every jurisdiction.

    Students overlook that the international variant covers many legal systems.

    Fix: Describe it as an influential English case and say the approach to duty varies by jurisdiction.

Worked examples

Example 1

An audit firm gave an unmodified opinion on Zeta Co. Zeta's finance director had overstated receivables, and the audit team accepted a verbal explanation for a large unconfirmed balance without further work. Zeta's board later lost $2m through a decision based on the profit figure. Discuss whether Zeta can sue for negligence.

Show the solution
  1. Claimant: Zeta Co is the audit client. The auditor owes it a duty through the engagement contract and in tort, so duty of care is established.
  2. Breach: Accepting a verbal explanation for a large unconfirmed balance falls short of obtaining sufficient appropriate audit evidence (ISA 500) and of exercising professional scepticism. A reasonably competent auditor would have performed alternative procedures, such as inspecting subsequent receipts. This is likely a breach.
  3. Causation: The board made the decision using the overstated profit. If the audit had found the problem, the decision would probably not have been made on that basis, so the breach plausibly caused the loss. The firm may argue the board should have scrutinised the figures itself, which could support a reduction for contributory negligence.
  4. Loss: The $2m is a financial loss that flows foreseeably from relying on audited figures, so it is a recognised loss. Zeta must also show it took reasonable steps to limit it.
  5. Conclusion: The claim is likely to succeed, though damages may be reduced if Zeta or its finance director contributed to the loss.

Answer: Zeta can probably succeed. Duty exists through the contract, breach is shown by weak evidence and lack of scepticism, and causation and loss are likely met. Damages may be reduced for contributory negligence.

Example 2

Delta Bank lent $5m to Omega Co after reading its audited financial statements. Omega defaulted. The statements were misstated and the audit was negligent. Omega's auditor knew nothing of the loan. Discuss whether Delta Bank can claim against the auditor.

Show the solution
  1. Claimant: Delta is a third party with no contract with the auditor, so it must prove a duty in tort.
  2. Foreseeability: It is foreseeable that lenders might read published accounts. This alone is not enough.
  3. Proximity: The auditor did not know of the loan, was not asked for any assurance for Delta, and had no direct dealings with it. Proximity is weak.
  4. Fair, just and reasonable: The audit exists for shareholders to oversee management. Extending liability to unknown lenders would expose the auditor to an indeterminate class of claimants. A court is unlikely to find it fair.
  5. Breach is assumed from the facts, but without a duty the claim fails before causation and loss are reached.
  6. Practical point: Delta might have a claim if the auditor had known of its reliance and accepted responsibility, for example through a direct statement or a reliance letter.

Answer: Delta is unlikely to succeed because Caparo-type reasoning finds no sufficient proximity and it is not fair to impose a duty. The result could differ if the auditor had known of the specific loan and accepted responsibility.

Exam tips

  • Show the four elements as separate points. Examiners award marks for each element, so a clear structure protects your marks.
  • For third-party claims, spend most of your effort on duty of care. That is where the discussion marks usually are.
  • Link each breach to a specific ISA principle and a fact in the scenario. Generic standards without application earn little.
  • Be balanced. Offer the claimant's argument and the auditor's defence, then reach a conclusion. This earns professional skills marks for analysis and judgement.
  • When advising the firm, add practical steps: documentation, engagement letter wording, liability limitation and insurance.

Practice questions from Professional liability

Audit Negligence and Duty of Care in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Audit Negligence and Duty of Care: frequently asked questions

What must a claimant prove to win an audit negligence claim?

They must prove four things: the auditor owed a duty of care, the auditor breached it, the breach caused the loss, and the loss is recognised and not too remote. All four must be shown. If one fails, the claim fails.

What is the Caparo test for duty of care?

It asks whether the loss was reasonably foreseeable, whether there was a relationship of sufficient proximity between the parties, and whether it is fair, just and reasonable to impose a duty. It is used to limit auditor liability to third parties. Courts in other countries may apply different tests.

Does a missed misstatement prove an auditor was negligent?

No. An audit gives reasonable assurance, not a guarantee. The question is whether a reasonably competent auditor following ISAs would have found the problem.

How can an auditor reduce the risk of a negligence claim?

Follow ISAs and keep clear audit documentation. Use a clear engagement letter, apply quality management procedures, and consider liability limitation where the law allows. Hold professional indemnity insurance as a final protection.