AS · Certificate Level
The Regulatory and Ethical Framework
The role and structure of the Financial Reporting Council (FRC), Companies Act 2006 audit requirements (which companies require a statutory audit, appointment and removal of auditors, auditors' rights and duties), the ICAEW Code of Ethics (five fundamental principles: integrity, objectivity, professional competence and due care, confidentiality, professional behaviour), the threats and safeguards conceptual framework, and the five types of threat to independence and objectivity (self-interest, self-review, advocacy, familiarity, intimidation) with practical examples of each.
Learning Objectives
- •Describe the role, structure, and key responsibilities of the Financial Reporting Council (FRC)
- •Explain which companies are required to have a statutory audit under the Companies Act 2006 and the exemption thresholds
- •Describe the rules governing the appointment, removal, and resignation of auditors under the Companies Act 2006
- •State the auditor's statutory rights and duties under the Companies Act 2006
- •Explain the five fundamental principles of the ICAEW Code of Ethics
- •Describe the threats and safeguards conceptual framework approach to ethics
- •Identify and give examples of the five types of threat to the fundamental principles
- •Explain the process for evaluating threats and applying safeguards
The Financial Reporting Council (FRC)
The Financial Reporting Council (FRC) is the UK's independent regulator responsible for promoting high-quality corporate governance, reporting, and audit. It is the key body overseeing the audit profession in the UK.
Key responsibilities of the FRC:
- Setting standards: The FRC sets UK Corporate Governance Code, UK Stewardship Code, UK auditing standards (ISAs (UK)), ethical standards for auditors (FRC Ethical Standard), and accounting standards (FRS 100-105, FRS 102). It also influences international standards through participation in IAASB and IASB.
- Monitoring and enforcement: The FRC monitors the quality of audit through its Audit Quality Review (AQR) team, which inspects the work of auditors of public interest entities (PIEs) and other major audits. It has the power to impose sanctions, fines, and other disciplinary measures.
- Corporate reporting review: The FRC reviews the annual reports and financial statements of public companies to check compliance with accounting standards and company law.
- Actuarial regulation: The FRC oversees the actuarial profession.
- Professional discipline: The FRC can investigate and sanction accountants and auditors for misconduct.
Note: The FRC is expected to be replaced by the Audit, Reporting and Governance Authority (ARGA) under proposed reforms following the Brydon, Kingman, and CMA reviews. At the time of study, the FRC remains the operational body, but be aware of this potential change.
Other relevant regulatory bodies:
- ICAEW — the Institute of Chartered Accountants in England and Wales. A Recognised Supervisory Body (RSB) that authorises firms to conduct audit work. Sets ethical guidance for its members (ICAEW Code of Ethics, based on the IESBA Code).
- IAASB — International Auditing and Assurance Standards Board. Sets international auditing standards (ISAs) which form the basis of ISAs (UK).
- IESBA — International Ethics Standards Board for Accountants. Sets the International Code of Ethics for Professional Accountants, on which the ICAEW Code is based.
Companies Act 2006 — Audit Requirements
The Companies Act 2006 (CA 2006) is the primary legislation governing UK companies. It sets out when a statutory audit is required and the legal framework for auditors.
Which Companies Require a Statutory Audit?
Under CA 2006, all companies must have their annual accounts audited unless they qualify for audit exemption.
Small company audit exemption (s.477 CA 2006): A company qualifies as small if it meets at least two of the following three criteria in the current and preceding financial year:
- Annual turnover not more than £10.2 million
- Balance sheet total not more than £5.1 million
- Average number of employees not more than 50
Companies that can NEVER be exempt from audit (regardless of size):
- Public companies (PLCs)
- Companies that are part of a group containing a public company
- Banks, insurance companies, and other entities authorised under the Financial Services and Markets Act 2000
- Companies whose articles require an audit
Shareholder right to require an audit (s.476): Even if a company qualifies for exemption, members holding at least 10% of the issued share capital (or 10% of any class of shares) can require the company to obtain an audit by giving written notice to the company at least one month before the end of the financial year.
Appointment, Removal, and Resignation of Auditors
Appointment (s.485-491):
- Auditors are normally appointed by the shareholders at the Annual General Meeting (AGM) by ordinary resolution
- For a private company: the directors may appoint the first auditors and fill a casual vacancy. If no appointment is made, the existing auditor is deemed reappointed automatically unless the company is exempt, the auditor has been removed, or the articles require actual appointment.
- For a public company: auditors are appointed at each general meeting at which accounts are laid.
- The directors may appoint the first auditor after incorporation and can fill a casual vacancy (e.g., if an auditor resigns mid-year).
Removal (s.510-511):
- Auditors can be removed at any time by the shareholders by ordinary resolution (simple majority >50%)
- Special notice of 28 days must be given to the company of the intention to propose the resolution
- The company must send a copy of the resolution to the auditor, who has the right to make written representations and require them to be sent to shareholders
- The auditor has the right to attend and speak at the meeting at which the resolution is considered
- Removal does not affect the auditor's right to compensation for breach of contract
Resignation (s.516-520):
- An auditor may resign at any time by giving written notice to the company
- The resignation notice must include a statement of circumstances — either: (a) a statement that there are circumstances connected with the resignation that should be brought to the attention of members or creditors, OR (b) a statement that there are no such circumstances
- If there are relevant circumstances, the company must send the statement to every person entitled to receive the accounts (or apply to the court if it believes the statement is defamatory)
- The resigning auditor may requisition a general meeting to explain the circumstances
Auditor's Statutory Rights and Duties
Rights of auditors under CA 2006:
- Right of access at all times to the company's books, accounts, and vouchers (s.499)
- Right to require from the company's officers (directors, secretary) such information and explanations as the auditor thinks necessary for the performance of the audit (s.499)
- Right to attend any general meeting of the company (s.502)
- Right to receive all notices and communications relating to general meetings
- Right to speak at general meetings on any part of the business that concerns the auditor
- It is a criminal offence for an officer of the company to knowingly or recklessly provide misleading, false, or deceptive information or explanations to the auditor (s.501)
Duties of auditors under CA 2006:
- To report to the members (shareholders) on whether the financial statements give a true and fair view and have been properly prepared in accordance with the applicable framework and CA 2006 (s.495)
- To state whether the directors' report is consistent with the financial statements (s.496)
- To report if adequate accounting records have not been kept, or if the accounts do not agree with the records (s.498)
- To report if they have not received all the information and explanations they require (s.498)
- To include in the report information about directors' remuneration if the required disclosures are not made in the accounts (s.497)
- To report by exception on certain matters — i.e., only mention them in the report if there is a problem
The ICAEW Code of Ethics — Five Fundamental Principles
The ICAEW Code of Ethics is based on the IESBA International Code of Ethics for Professional Accountants. It applies to all ICAEW members and students in all aspects of their professional work. The Code establishes five fundamental principles that every professional accountant must comply with:
| # | Principle | Definition |
|---|---|---|
| 1 | Integrity | To be straightforward and honest in all professional and business relationships. A member must not knowingly be associated with reports, returns, communications, or other information that contain materially false or misleading statements, statements furnished recklessly, or information that omits or obscures required information. |
| 2 | Objectivity | Not to compromise professional or business judgement because of bias, conflict of interest, or the undue influence of others. The accountant must not allow relationships, interests, or pressures to override their professional judgement. |
| 3 | Professional competence and due care | To maintain professional knowledge and skill at a level required to ensure that clients or employers receive competent professional service. To act diligently and in accordance with applicable technical and professional standards. This includes a duty of Continuing Professional Development (CPD). |
| 4 | Confidentiality | To respect the confidentiality of information acquired through professional and business relationships. Not to disclose such information to third parties without proper authority unless there is a legal or professional right or duty to disclose. Not to use confidential information for personal advantage. The duty continues even after the professional relationship ends. |
| 5 | Professional behaviour | To comply with relevant laws and regulations and avoid any conduct that the accountant knows or should know might discredit the profession. This includes avoiding actions that would bring the profession into disrepute, such as making disparaging references or unsubstantiated comparisons to the work of others. |
Exceptions to confidentiality: Disclosure of confidential information is permitted or required in the following circumstances:
- Legal requirement: Where disclosure is required by law (e.g., money laundering reporting under POCA 2002, response to court orders)
- Professional duty or right: Quality reviews by the professional body, responding to a professional inquiry or investigation, protecting the professional interests of the accountant in legal proceedings
- Authorised by the client: Where the client gives informed consent to disclosure (preferably in writing)
The Threats and Safeguards Framework
The ICAEW Code adopts a conceptual framework approach rather than a set of rigid rules. The approach requires the accountant to:
- Identify threats to compliance with the fundamental principles
- Evaluate the significance of each threat (how serious is it?)
- Apply safeguards to eliminate the threat or reduce it to an acceptable level
- If no safeguards can reduce the threat to an acceptable level: decline or discontinue the professional activity or relationship
This approach recognises that it is impossible to define every situation that creates a threat. Instead, the accountant must exercise professional judgement to evaluate each situation on its merits.
Types of safeguard:
- Safeguards created by the profession, legislation, or regulation: Education and training requirements, CPD, corporate governance regulations, professional standards, external review of financial reports, registration and licensing requirements, disciplinary procedures
- Safeguards within the firm (work environment): Quality control procedures, firm-wide policies on independence, rotation of senior personnel, independent partner reviews (hot reviews/EQCR), internal consultation, training and mentoring, confidentiality walls (ethical walls / information barriers)
- Client-specific safeguards: Audit committee oversight, separate engagement teams, involvement of an additional professional accountant, independent review of work performed
The Five Types of Threat
The Code identifies five categories of threat that may compromise the fundamental principles:
1. Self-Interest Threat
The threat that a financial or other interest will inappropriately influence the accountant's judgement or behaviour.
Examples:
- Having a direct or indirect financial interest (shareholding) in an audit client
- A loan or guarantee to or from an audit client
- Undue dependence on fees from one client (e.g., a single client accounts for >15% of the firm's total fees)
- Concern about the possibility of losing a client (fee pressure leading to inadequate work)
- The prospect of employment with the client (the auditor is negotiating a job with the client)
- Contingent fees for assurance engagements (fees dependent on the outcome)
- Close business relationships with the client
Safeguards: Dispose of the financial interest, remove the individual from the engagement team, independent partner review, fee monitoring and disclosure, firm-wide policies on employment negotiations.
2. Self-Review Threat
The threat that the accountant will not appropriately evaluate the results of a previous judgement or service performed by the accountant (or by another individual within the same firm), on which the accountant will rely when forming a judgement as part of the current service.
Examples:
- A member of the audit team was recently an employee of the client in a position to exert significant influence over the subject matter
- The firm provides accounting or bookkeeping services to the audit client AND then audits those same financial records
- The firm prepares the financial statements for the client and then audits them
- The firm provides internal audit services to the client and relies on that work during the external audit
- The firm provides valuation services for amounts that are material to the financial statements being audited
Safeguards: Use separate teams for the non-audit service and the audit, independent partner review, do not include the individual in the audit team for at least two years after leaving the client, obtain management acknowledgement of responsibility for financial statements.
3. Advocacy Threat
The threat that the accountant will promote or support a client's position to the point that their objectivity is compromised.
Examples:
- Promoting shares in an audit client (e.g., acting as a broker or underwriter for the client's share issue)
- Acting as an advocate for the client in litigation or disputes with third parties
- Lobbying on behalf of the client (e.g., with a regulator or tax authority) in a way that goes beyond providing factual information
- Making public statements on behalf of the client that could be seen as championing their position
Safeguards: Decline the advocacy role, use separate individuals for advocacy and audit, ensure the accountant does not take a management decision on behalf of the client.
4. Familiarity Threat
The threat that, due to a long or close relationship with a client or employer, the accountant will be too sympathetic to their interests or too accepting of their work.
Examples:
- Long association — the same senior audit personnel (engagement partner or EQCR) serving an audit client for many years, leading to over-familiarity and reduced professional scepticism
- Close family or personal relationship between a member of the audit team and a director or senior employee of the client
- A former partner of the audit firm joining the client as a director or in a senior position
- Accepting gifts or hospitality from the client that are more than trivial and inconsequential
Safeguards: Rotation of senior audit personnel (mandatory for PIEs — the engagement partner must rotate after a maximum of five years, with a five-year cooling-off period), independent partner review, remove the individual with the personal relationship from the team, firm policies on gifts and hospitality.
5. Intimidation Threat
The threat that the accountant will be deterred from acting objectively because of actual or perceived pressure — including attempts to exercise undue influence over the accountant.
Examples:
- The client threatens to dismiss the audit firm (replace the auditor) if the firm does not agree with the client's accounting treatment
- The client threatens litigation against the auditor to pressure them into changing the audit opinion
- A dominant personality at the client (e.g., a controlling CEO) pressures the auditor to accept inappropriate accounting or to limit the scope of audit procedures
- Pressure from the client to reduce audit fees to a level where the work cannot be performed adequately
- Being pressured to not report a discovered breach or irregularity
Safeguards: Document the threat, consult with senior partners or the firm's ethics partner, consider whether to resign from the engagement, report the threat to those charged with governance (audit committee), refuse to be intimidated and maintain professional scepticism.
Summary — Threat Types at a Glance
| Threat | Essence | Key word | Classic example |
|---|---|---|---|
| Self-interest | Financial or other interest influences judgement | Money / benefit | Auditor owns shares in the client |
| Self-review | Reviewing your own (or your firm's) previous work | Checking own work | Firm prepares accounts then audits them |
| Advocacy | Promoting or supporting the client's position | Championing | Acting as the client's advocate in litigation |
| Familiarity | Too close or too long a relationship | Cosiness | Same partner on the audit for 10+ years |
| Intimidation | Pressure or threats from the client | Fear / pressure | Client threatens to replace the auditor |
Examiner Focus
Study Tip
Common Pitfall
Watch Out
Examiner Focus
Common Pitfall
Key Definitions
Financial Reporting Council (FRC)
The UK's independent regulator responsible for corporate governance, reporting, audit, and actuarial standards. Monitors audit quality and can impose sanctions.
Statutory audit
An audit required by law (Companies Act 2006). The auditor reports to the shareholders on whether the financial statements give a true and fair view.
Small company exemption
Under s.477 CA 2006, a company meeting at least two of three size criteria (turnover ≤£10.2m, balance sheet ≤£5.1m, employees ≤50) is exempt from statutory audit, unless it is a PLC, a banking/insurance company, or part of a group with a PLC.
Integrity
Fundamental principle: to be straightforward and honest in all professional and business relationships. Not to be associated with misleading information.
Objectivity
Fundamental principle: not to compromise professional judgement because of bias, conflict of interest, or undue influence of others.
Professional competence and due care
Fundamental principle: to maintain knowledge and skill at the level required to provide competent professional services, and to act diligently in accordance with applicable standards.
Confidentiality
Fundamental principle: to respect the confidentiality of information acquired through professional relationships. Not to disclose or use such information without proper authority.
Professional behaviour
Fundamental principle: to comply with relevant laws and regulations and avoid any conduct that would discredit the profession.
Conceptual framework approach
The approach to ethics that requires accountants to identify threats, evaluate their significance, and apply safeguards — rather than following rigid rules for every situation.
Self-interest threat
A financial or other interest that could inappropriately influence the accountant's judgement. Example: holding shares in an audit client.
Self-review threat
The risk of not appropriately evaluating the results of a previous service performed by the accountant or their firm. Example: auditing financial statements the firm helped prepare.
Advocacy threat
The risk of promoting or supporting a client's position to the point that objectivity is compromised. Example: acting as the client's advocate in litigation.
Familiarity threat
The risk that a long or close relationship leads to the accountant being too sympathetic or uncritical. Example: same audit partner for many years.
Intimidation threat
The risk of being deterred from acting objectively due to actual or perceived pressure. Example: client threatens to change auditors.
Safeguards
Actions or measures that eliminate or reduce threats to an acceptable level. Include profession-wide safeguards (regulation, CPD), firm safeguards (policies, rotation, EQCR), and engagement-specific safeguards (separate teams, independent review).
Key Formulas
Worked Examples
Related Topics
Key Takeaways
- ✓The FRC is the UK's independent regulator for corporate governance, reporting, and audit. It sets standards (ISAs (UK), Ethical Standard, Corporate Governance Code) and monitors audit quality.
- ✓Under CA 2006, all companies require a statutory audit unless they qualify for small company exemption (two of three: turnover ≤£10.2m, balance sheet ≤£5.1m, employees ≤50). PLCs, banks, and insurers can never be exempt.
- ✓Auditors are appointed by shareholders at the AGM. They can be removed by ordinary resolution with 28 days' special notice. Resigning auditors must file a statement of circumstances.
- ✓Auditor rights include: access to books/records, right to require information from officers, right to attend/speak at general meetings. It is a criminal offence to mislead the auditor.
- ✓The five fundamental principles: Integrity, Objectivity, Professional competence and due care, Confidentiality, Professional behaviour.
- ✓Confidentiality continues after the relationship ends. Exceptions: legal requirement, professional duty/right, client authorisation.
- ✓The conceptual framework approach: identify threats → evaluate significance → apply safeguards → if no adequate safeguard, decline/discontinue.
- ✓Five threat types: Self-interest (financial benefit), Self-review (checking own work), Advocacy (championing client), Familiarity (too close/too long), Intimidation (pressure/threats).
- ✓Key safeguards: partner rotation, separate teams, independent review (EQCR), fee monitoring, policies on gifts/hospitality, ethical walls.
Practice Questions
Question 1 of 8
Which of the following is NOT one of the five fundamental principles in the ICAEW Code of Ethics?
Question 2 of 8
An audit partner has been on the same audit engagement for seven years. This is an example of:
Question 3 of 8
A company qualifies for audit exemption as a small company under CA 2006 if it meets at least two of three size criteria. Which of the following is one of those criteria?
Question 4 of 8
The audit firm prepared a client's financial statements and is now auditing them. This creates a:
Question 5 of 8
Under CA 2006, auditors are normally appointed by:
Question 6 of 8
A client threatens to replace the audit firm unless the firm agrees to the client's preferred accounting treatment. This is an example of:
Question 7 of 8
Which of the following entities can NEVER be exempt from statutory audit, regardless of its size?
Question 8 of 8
Under the ICAEW Code of Ethics, the duty of confidentiality:
Source and Version
Syllabus: ICAEW ACA Certificate Level 2026 · Reviewed: 2026-05-04