AS · Certificate Level

Professional Ethics in Practice

Practical application of ethical requirements: independence requirements for auditors (financial interests, business relationships, employment relationships, long association/rotation), procedures for accepting new engagements (client due diligence, professional clearance), client identification and anti-money laundering obligations (Proceeds of Crime Act 2002, Money Laundering Regulations 2017, tipping off, Suspicious Activity Reports), conflicts of interest, and professional liability (contractual and tortious, Caparo v Dickman).

32 min read

Learning Objectives

  • Explain the concept of auditor independence (of mind and in appearance) and why it is essential
  • Identify situations involving financial interests, business relationships, and employment relationships that threaten independence, and describe appropriate safeguards
  • Explain the requirements for rotation of key audit personnel (long association)
  • Describe the procedures to follow when accepting a new audit engagement, including professional clearance with the predecessor auditor
  • Explain the accountant's obligations regarding client identification, customer due diligence, and anti-money laundering under POCA 2002 and the Money Laundering Regulations 2017
  • Define money laundering, explain the three principal money laundering offences, and describe the requirements for Suspicious Activity Reports and the offence of tipping off
  • Explain how conflicts of interest arise and the procedures for managing them
  • Describe the auditor's exposure to professional liability and the key legal principles

Independence — Of Mind and In Appearance

Independence is not itself one of the five fundamental principles, but it is essential for auditors to maintain because it underpins objectivity and the credibility of the assurance service.

The FRC Ethical Standard and the IESBA Code distinguish two aspects:

  • Independence of mind: The state of mind that permits the expression of a conclusion without being affected by influences that compromise professional judgement, allowing an individual to act with integrity and exercise objectivity and professional scepticism.
  • Independence in appearance: The avoidance of facts and circumstances that are so significant that a reasonable and informed third party would be likely to conclude that the firm's or audit team member's integrity, objectivity, or professional scepticism has been compromised.

Both aspects must be maintained. An auditor may genuinely believe they are objective, but if the situation appears to compromise independence, the credibility of the audit is undermined.

Financial Interests

Holding a financial interest in an audit client (directly or indirectly) creates a self-interest threat.

Direct financial interest: The individual (or their immediate family) owns shares or other securities in the audit client directly. This is always prohibited for members of the audit team and the engagement partner. No safeguard can reduce this threat to an acceptable level — the interest must be disposed of, or the individual must be removed from the engagement.

Indirect financial interest: The individual has an interest through an intermediary (e.g., a managed fund, pension fund, or family trust). An indirect financial interest is only a threat if it is material to the individual. If material, the same safeguards apply (dispose or remove from team).

Close family: If a close family member (spouse, dependent child) of a member of the audit team holds a financial interest in the client, the same rules apply as if the team member held it directly.

Firm-wide interests: If the audit firm or a partner who is not on the engagement team holds a financial interest in the client, this must also be evaluated. For PIEs, even very small interests are prohibited for the firm's partners.

Business Relationships

A close business relationship between the audit firm (or a member of the audit team) and the client can create self-interest or familiarity threats.

Examples:

  • A joint venture or similar arrangement between the firm and the client
  • A commercial interest in a joint product or service
  • Distribution or marketing arrangements

Treatment: Close business relationships with the audit client are generally prohibited unless the relationship is clearly insignificant to both the firm and the client. If significant, the relationship must be terminated or the firm must decline/resign from the audit.

Buying goods or services from the client in the ordinary course of business (e.g., buying products the client sells to the public) is generally acceptable if the transaction is at arm's length and on normal commercial terms and not material.

Employment Relationships

Employment relationships between the audit firm and the client can create multiple threats:

Former employee of the client joining the audit firm:

  • If a former employee of the client (who held a position of significant influence) joins the audit team, there is a self-review threat (they may be auditing their own previous work) and a familiarity threat (close relationships with former colleagues).
  • Safeguard: The individual should not be assigned to the audit team for at least two years after leaving the client. All work performed during the period the individual was at the client should be reviewed by another team member.

Former member of the audit team joining the client ("revolving door"):

  • If a former engagement partner or senior member of the audit team becomes a director or senior employee of the audit client, this creates self-interest, self-review, and familiarity threats.
  • Safeguard: The FRC Ethical Standard requires a two-year cooling-off period for key audit partners before they can join a PIE audit client in a senior position. The firm must also consider whether any significant connections remain between the individual and the current audit team and take appropriate action (e.g., change the team, perform an independent review).

Audit team member negotiating employment with the client:

  • If a member of the audit team is in discussions about joining the client, the self-interest threat is immediate — they may be influenced to please their potential future employer.
  • Safeguard: The individual must notify the firm immediately and be removed from the engagement team. Their work should be reviewed by another member of the team.

Long Association and Rotation

Long association between the same senior audit personnel and the same audit client creates a familiarity threat and potentially a self-interest threat.

FRC Ethical Standard requirements for PIEs:

  • The engagement partner must rotate off the audit after a maximum of five years, with a five-year cooling-off period before they can return to the engagement
  • The engagement quality control reviewer (EQCR) has the same rotation requirements
  • Other key audit partners must rotate after seven years with a two-year cooling-off period

For non-PIEs: Rotation is not mandated by the FRC Ethical Standard, but the firm should consider safeguards such as an independent partner review if the same partner serves for an extended period.

Firm rotation (for PIEs under EU/UK regulation): The audit firm itself must be rotated periodically. Under UK rules (as amended post-Brexit by the FRC), PIEs must retender the audit at least every 10 years and rotate the audit firm at least every 20 years. There are transitional provisions.

Accepting New Engagements

Before accepting a new audit (or other assurance) engagement, the firm must carry out certain procedures to ensure it can accept the appointment properly.

Key procedures:

  1. Client due diligence / client identification: Verify the identity of the prospective client (directors, beneficial owners). This is required by anti-money laundering legislation (see below). Assess the integrity of the client's management — consider reputation, nature of business, attitude to risk and compliance.
  2. Competence and resources: Confirm the firm has the necessary expertise, experience, and resources (including staff and time) to perform the engagement to the required standard.
  3. Independence: Assess whether there are any existing relationships, interests, or circumstances that could create threats to independence. If threats exist, determine whether safeguards are available.
  4. Conflicts of interest: Check whether accepting the engagement would create a conflict with an existing client (see conflicts section below).
  5. Professional clearance (communication with the predecessor auditor):
    • Before accepting, the proposed new auditor must communicate with the existing/previous auditor (with the client's permission) to inquire whether there are any professional or other reasons why the appointment should not be accepted
    • The previous auditor has a professional duty to respond promptly. If there are matters the proposed auditor should know about (e.g., issues with management integrity, unpaid fees, disagreements over accounting treatment, suspected fraud), these should be disclosed
    • If the client refuses permission to contact the predecessor, the proposed auditor should normally decline the appointment — the refusal itself is a red flag
    • If the predecessor does not respond (despite follow-up), the proposed auditor may accept but should exercise heightened professional scepticism and document the situation
  6. Terms of engagement: Once accepted, the firm agrees the terms of the engagement with the client in an engagement letter. This sets out: the scope and objective of the engagement, the responsibilities of the auditor and management, the applicable financial reporting framework, and the expected form and content of the report.

Money Laundering — Legal Framework and Accountant's Obligations

Money laundering is the process by which the proceeds of crime (criminal property) are converted or transferred to disguise their illegal origin, making them appear to come from legitimate sources.

The three stages of money laundering are often described as:

  1. Placement: Introducing criminal cash into the financial system (e.g., depositing large amounts of cash in a bank, buying high-value goods)
  2. Layering: Moving the money through a series of transactions to distance it from its source (e.g., transfers between accounts, offshore transactions, complex company structures)
  3. Integration: Reintroducing the "cleaned" money into the legitimate economy (e.g., investing in property, businesses, or financial products)

Proceeds of Crime Act 2002 (POCA) — Principal Offences

POCA 2002 creates three principal money laundering offences that can apply to any person (including accountants):

SectionOffenceDescription
s.327Concealing criminal propertyConcealing, disguising, converting, transferring, or removing criminal property from the UK
s.328ArrangementsBecoming concerned in an arrangement which facilitates the acquisition, retention, use, or control of criminal property by or on behalf of another person
s.329Acquisition, use, and possessionAcquiring, using, or possessing criminal property

Criminal property is property that constitutes or represents a person's benefit from criminal conduct — or property the person knows or suspects constitutes or represents such a benefit. The crime generating the property can be any crime (not just drug trafficking or terrorism).

Defence: A person has a defence if they made an authorised disclosure (a Suspicious Activity Report, or SAR) to the National Crime Agency (NCA) before the act, or as soon as practicable after if they had a reasonable excuse for not reporting earlier, and the NCA gave consent to proceed (or the moratorium period expired without objection).

Failure to Report and Tipping Off

Failure to report (s.330 POCA — applies to the "regulated sector" including accountants):

A person in the regulated sector commits an offence if they know or suspect (or have reasonable grounds for knowing or suspecting) that another person is engaged in money laundering, and they fail to make a disclosure (SAR) to the firm's nominated officer (MLRO — Money Laundering Reporting Officer) or directly to the NCA as soon as practicable.

The information must have come to the person in the course of business in the regulated sector. There is a defence of reasonable excuse for not reporting, or where the person had appropriate training and did not actually know or suspect.

Tipping off (s.333A POCA):

It is a criminal offence for a person in the regulated sector to disclose to any person that a SAR has been made (or that an investigation is being contemplated or carried out) if the disclosure is likely to prejudice any investigation. This means the accountant must not inform the client (or anyone else) that a SAR has been filed or that the accountant suspects money laundering.

Penalties: The money laundering offences carry a maximum penalty of 14 years' imprisonment and/or an unlimited fine. Failure to report and tipping off carry a maximum of 5 years' imprisonment and/or a fine.

Money Laundering Regulations 2017 — Customer Due Diligence

The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 (MLR 2017) require firms in the regulated sector (including accountancy firms) to implement systems and controls to prevent money laundering.

Key requirements:

  • Customer Due Diligence (CDD): The firm must verify the identity of the client before establishing a business relationship or carrying out occasional transactions. CDD involves:
    • Identifying the client and verifying their identity from reliable, independent sources (e.g., passport, driving licence, utility bills, Companies House records)
    • Identifying any beneficial owner (a person who ultimately owns or controls the client — typically >25% shareholding) and taking reasonable measures to verify their identity
    • Obtaining information on the purpose and intended nature of the business relationship
  • Enhanced Due Diligence (EDD): Required for higher-risk situations — e.g., politically exposed persons (PEPs), non-face-to-face business relationships, clients from high-risk third countries
  • Simplified Due Diligence (SDD): May be applied in lower-risk situations — e.g., UK-listed companies, public authorities
  • Ongoing monitoring: Firms must conduct ongoing monitoring of the business relationship, including scrutinising transactions and keeping CDD information up to date
  • Record keeping: CDD records must be retained for five years after the business relationship ends
  • Nominated officer (MLRO): The firm must appoint a nominated officer to receive internal suspicious activity reports and decide whether to report externally to the NCA
  • Staff training: All relevant employees must receive appropriate training on AML procedures and how to recognise suspicious activity

The SAR Process in Practice

When an accountant suspects money laundering, the process is:

  1. The individual reports their suspicion to the firm's nominated officer (MLRO) — this is an internal report
  2. The MLRO evaluates the report and, if they agree there are grounds for suspicion, submits a Suspicious Activity Report (SAR) to the National Crime Agency (NCA)
  3. The MLRO requests consent from the NCA to continue acting for the client (if the ongoing work could constitute one of the principal offences)
  4. The NCA has 7 working days to respond. If consent is refused, there is a further moratorium period of 31 calendar days during which the firm must not proceed with the transaction
  5. If the NCA does not respond within 7 working days, consent is deemed given
  6. Throughout, the accountant must not tip off the client or any other person that a SAR has been made

Conflicts of Interest

A conflict of interest arises when a firm or individual has competing interests that could impair objectivity. Common scenarios:

  • Acting for two clients with competing interests: e.g., the firm audits Company A and Company B, which are bidding against each other for the same contract. Information obtained from one client could benefit the other.
  • Client interests conflicting with the firm's interests: e.g., the firm has a financial interest that could be affected by the outcome of the engagement.
  • Same individual acting for two parties in a dispute: e.g., advising both a buyer and a seller in a transaction.

Managing conflicts:

  1. Identify conflicts as early as possible (at the acceptance stage and throughout the engagement)
  2. Notify all affected parties of the conflict and obtain their informed consent to continue acting (preferably in writing)
  3. Implement safeguards:
    • Use separate engagement teams for each client (with no team members in common)
    • Establish information barriers (ethical walls / Chinese walls) to prevent confidential information from one client reaching the team acting for the other
    • Obtain independent review of work performed
    • Issue clear guidelines to team members about confidentiality and information handling
  4. If the conflict cannot be managed through safeguards: decline or withdraw from one or both engagements

Professional Liability

Auditors face potential liability for their work. The two main bases of liability are:

1. Contractual liability (to the client)

  • The auditor has a contract (engagement letter) with the client company
  • If the auditor breaches the terms of that contract (e.g., fails to perform the audit in accordance with ISAs, fails to detect material misstatements caused by negligence), the client can sue for breach of contract
  • Only the parties to the contract can sue — third parties generally cannot bring a contractual claim (privity of contract)
  • Damages are based on the loss suffered by the client as a result of the breach

2. Liability in tort — negligence (to third parties)

  • Third parties (e.g., shareholders, lenders, potential investors) who suffer loss because they relied on negligently audited financial statements may claim in the tort of negligence
  • The key case is Caparo Industries plc v Dickman [1990], which established a three-part test for duty of care:
    1. Foreseeability: Was it reasonably foreseeable that the claimant would suffer loss if the audit was negligent?
    2. Proximity: Was there a sufficiently close relationship between the auditor and the claimant?
    3. Fair, just, and reasonable: Is it fair, just, and reasonable to impose a duty of care in the circumstances?
  • The House of Lords held that the auditor's duty of care in respect of the statutory audit is owed to the shareholders as a body (collectively) for the purpose of enabling them to exercise their rights (e.g., in general meeting) — NOT to individual shareholders making investment decisions, and NOT to potential investors or lenders.
  • This significantly limits the auditor's exposure to claims from third parties who relied on the accounts for investment or lending decisions.
  • Exceptions: A duty to a specific third party may arise if the auditor knew the accounts would be used for a specific purpose by a specific party (e.g., a report prepared specifically for a lender in connection with a loan application).

Limiting liability:

  • Liability limitation agreements (LLAs): Under s.534-538 CA 2006, companies can enter into agreements with their auditors to limit the auditor's liability for negligence, but only to an amount that is fair and reasonable. The agreement must be approved by the shareholders.
  • Professional indemnity insurance (PII): Auditors are required by their professional body to maintain adequate PII coverage.
  • Proportionate liability: Auditors may argue that management (or others) contributed to the loss and that liability should be apportioned.
  • Disclaimers: These have limited effectiveness — courts may disregard disclaimers where a duty of care is established.

Examiner Focus

Independence scenarios (financial interests, employment relationships, long association) are tested frequently. For each scenario, you must: (1) identify the threat type, (2) explain WHY it is a threat, and (3) recommend a specific safeguard or action. Generic answers ("apply safeguards") score poorly — be specific.

Common Pitfall

Students frequently confuse the money laundering offences. Remember: the THREE PRINCIPAL offences (s.327-329 POCA) are about dealing with criminal property. FAILURE TO REPORT (s.330) and TIPPING OFF (s.333A) are separate offences. An accountant's most likely exposure is failure to report (not filing a SAR when they should have) and tipping off (telling the client about the SAR).

Watch Out

NEVER tell the client that a SAR has been filed or that money laundering is suspected. This is the tipping off offence and carries up to 5 years' imprisonment. Even hinting at the reason for a delay in processing a transaction could constitute tipping off.

Study Tip

For professional clearance: the key points are (1) get the client's permission to contact the predecessor, (2) ask the predecessor if there are reasons not to accept, (3) if the client refuses permission, this is a red flag and you should normally decline the appointment.

Examiner Focus

Caparo v Dickman [1990] is frequently examined. Know the three-part test (foreseeability, proximity, fair/just/reasonable) and the key conclusion: the auditor's duty in a statutory audit is owed to shareholders as a BODY, not to individual shareholders or third parties making investment/lending decisions.

Common Pitfall

A direct financial interest (shares) held by the engagement partner or their spouse in an audit client is ALWAYS prohibited — no safeguard is adequate. The interest must be disposed of or the partner must be removed. Don't waste time discussing "possible safeguards" for this scenario.

Key Definitions

Independence of mind

The state of mind that permits the expression of a conclusion without being affected by influences that compromise professional judgement — acting with integrity, objectivity, and professional scepticism.

Independence in appearance

The avoidance of facts and circumstances so significant that a reasonable and informed third party would likely conclude that objectivity has been compromised.

Direct financial interest

A financial interest (e.g., shares) owned directly by the individual or their immediate family. Always prohibited for audit team members in respect of an audit client.

Indirect financial interest

A financial interest held through an intermediary (e.g., managed fund, trust). Only a threat if material to the individual.

Professional clearance

The process of communicating with the predecessor auditor before accepting a new audit appointment, to inquire whether there are reasons the appointment should not be accepted.

Engagement letter

A written agreement between the firm and the client setting out the terms of the engagement: scope, responsibilities, framework, and expected report form.

Money laundering

The process of converting or transferring the proceeds of crime (criminal property) to disguise their illegal origin. Three stages: placement, layering, integration.

Criminal property

Property constituting or representing a person's benefit from criminal conduct, or property the person knows or suspects represents such a benefit (POCA 2002).

Suspicious Activity Report (SAR)

A report made to the NCA (via the firm's MLRO) when an accountant knows or suspects that a person is engaged in money laundering. Filing a SAR provides a defence to the principal money laundering offences.

Tipping off

The criminal offence (s.333A POCA) of disclosing to any person that a SAR has been made or that an investigation is being contemplated, if the disclosure is likely to prejudice any investigation.

MLRO (Money Laundering Reporting Officer)

The nominated officer within a firm responsible for receiving internal suspicious activity reports, evaluating them, and deciding whether to file a SAR with the NCA.

Customer Due Diligence (CDD)

The process of identifying clients and beneficial owners, verifying their identity from reliable sources, and understanding the purpose of the business relationship (MLR 2017).

Conflict of interest

A situation where a firm has competing interests (e.g., acting for two clients with opposing interests) that could impair objectivity.

Caparo v Dickman [1990]

Leading case establishing that the auditor's duty of care for the statutory audit is owed to the shareholders as a body, not to individual investors or third parties making investment decisions.

Liability limitation agreement (LLA)

An agreement under s.534-538 CA 2006 between a company and its auditor limiting the auditor's liability to a fair and reasonable amount, subject to shareholder approval.

Key Formulas

Worked Examples

Key Takeaways

  • Independence has two aspects: independence of mind (actual objectivity) and independence in appearance (perception by a reasonable third party). Both must be maintained.
  • Direct financial interests in an audit client are always prohibited for the engagement partner and audit team members (and their spouses). Dispose of the interest or remove the individual.
  • Employment relationships create threats: former client employees on the audit team (2-year gap), audit team members joining the client (remove from team immediately), former partners joining a PIE client (2-year cooling-off).
  • Long association/rotation: PIE engagement partner and EQCR must rotate after 5 years (5-year cooling-off). Other key partners: 7 years (2-year cooling-off).
  • Before accepting a new engagement: client due diligence, competence check, independence assessment, conflict check, professional clearance with predecessor auditor, engagement letter.
  • Money laundering: three principal offences (s.327-329 POCA — concealing, arrangements, acquisition/use/possession of criminal property). Defence: file a SAR before the act.
  • Failure to report (s.330): an accountant in the regulated sector must report suspicions to the MLRO, who reports to the NCA. Tipping off (s.333A): never tell the client a SAR has been filed.
  • CDD under MLR 2017: identify clients and beneficial owners, verify identity, understand the relationship purpose, maintain ongoing monitoring, retain records for 5 years.
  • Conflicts of interest: identify early, notify affected parties, use separate teams and information barriers, or decline one engagement.
  • Professional liability: contractual (to client), tortious (to third parties — limited by Caparo: duty to shareholders as a body, not individual investors). LLAs can limit liability if fair/reasonable and shareholder-approved.

Practice Questions

Question 1 of 8

An audit engagement partner's spouse holds shares in the audit client (a PIE). The appropriate action is:

Question 2 of 8

An accountant suspects a client is involved in money laundering. The accountant's first action should be to:

Question 3 of 8

Under POCA 2002, the offence of "tipping off" involves:

Question 4 of 8

Before accepting a new audit appointment, the proposed auditor should:

Question 5 of 8

The maximum period for an engagement partner on a PIE audit before mandatory rotation under the FRC Ethical Standard is:

Question 6 of 8

In Caparo v Dickman [1990], the House of Lords held that the auditor's duty of care in a statutory audit is owed to:

Question 7 of 8

A member of the audit team is negotiating employment with the audit client. The appropriate action is:

Question 8 of 8

Under the Money Laundering Regulations 2017, Customer Due Diligence records must be retained for:

Source and Version

Syllabus: ICAEW ACA Certificate Level 2026 · Reviewed: 2026-05-04

ICAEW ACA syllabusLocal syllabus coverage review