AA · Professional Level
Regulatory and Ethical Framework (Advanced)
The IESBA International Code of Ethics for Professional Accountants (full coverage of the five fundamental principles, the conceptual framework approach, threats and safeguards), FRC Ethical Standard (ES) for auditors in the UK, Companies Act 2006 provisions on auditors (appointment, removal, resignation, rights and duties), quality management standards (ISQM 1 — components of a system of quality management, ISQM 2 — engagement quality reviews), ISA 220 quality management for an audit of financial statements at the engagement level, and professional scepticism and professional judgement.
Learning Objectives
- •Explain and apply the five fundamental principles of the IESBA Code of Ethics
- •Describe the conceptual framework approach to ethics: identify threats, evaluate significance, apply safeguards
- •Explain the key requirements of the FRC Ethical Standard for auditors, including independence provisions
- •Describe the Companies Act 2006 provisions on the appointment, removal, resignation, and rights and duties of auditors
- •Explain the components of a system of quality management under ISQM 1
- •Explain the role and requirements of engagement quality reviews under ISQM 2
- •Describe the requirements of ISA 220 regarding quality management at the engagement level
- •Explain the importance of professional scepticism and professional judgement in the audit process
IESBA Code of Ethics — The Five Fundamental Principles
The International Code of Ethics for Professional Accountants (issued by IESBA, part of IFAC) establishes five fundamental principles that all professional accountants must comply with:
| Principle | Requirement | Key implications for auditors |
|---|---|---|
| Integrity | Be straightforward and honest in all professional and business relationships. Do not be associated with information that is materially false, misleading, furnished recklessly, or that omits information likely to mislead. | An auditor must not sign an audit report they know to be misleading. They must not be party to any deception of users of financial statements. |
| Objectivity | Do not allow bias, conflict of interest, or undue influence of others to override professional or business judgements. | The auditor must form an independent opinion based on audit evidence, not influenced by client pressure, financial incentives, or personal relationships. |
| Professional competence and due care | Attain and maintain professional knowledge and skill at the level required. Act diligently and in accordance with applicable technical and professional standards. | Auditors must be properly trained, keep knowledge current (CPD), apply ISAs correctly, and perform work to the required standard. Not accepting engagements beyond the firm's competence. |
| Confidentiality | Respect the confidentiality of information acquired through professional and business relationships. Do not disclose to third parties without proper authority or legal/professional duty. Do not use information for personal advantage. | Client information obtained during the audit must not be disclosed except: with client consent, where there is a legal duty (e.g., money laundering reporting), a professional duty (e.g., to a successor auditor, quality review), or a regulatory requirement. |
| Professional behaviour | Comply with relevant laws and regulations. Avoid any conduct that the accountant knows or should know might discredit the profession. | Includes not making disparaging references to competitors, not making exaggerated claims for services, and complying with advertising/marketing regulations. |
The Conceptual Framework Approach
Rather than providing a list of rules for every situation, the IESBA Code uses a conceptual framework (a "threats and safeguards" approach):
- Identify threats to compliance with the fundamental principles
- Evaluate the significance of the threats (are they at an acceptable level?)
- If not acceptable: Apply safeguards to eliminate the threat or reduce it to an acceptable level
- If no safeguards can reduce the threat: Decline or discontinue the engagement
Categories of threat:
| Threat | Description | Examples in audit context |
|---|---|---|
| Self-interest | A financial or other interest could inappropriately influence the auditor's judgement | Financial interest in the audit client, overdue fees from the client, concern about losing the engagement, close business relationship with client |
| Self-review | The auditor reviews work they or their firm previously performed, which creates a risk of not identifying errors | Preparing the client's financial statements and then auditing them, performing the valuation of an asset then auditing the balance, designing internal controls then evaluating their effectiveness |
| Advocacy | The auditor promotes the client's position to the point that objectivity is compromised | Acting as the client's advocate in litigation, promoting the client's shares, lobbying on behalf of the client |
| Familiarity | A long or close relationship with the client leads to the auditor being too sympathetic or uncritical | Long association with the engagement (same partner for many years), close personal relationship with client directors, former partner joining the client |
| Intimidation | The auditor is deterred from acting objectively due to actual or perceived threats | Threat to replace the auditor if they do not agree with a treatment, dominant personality of a client director, pressure to reduce fees or scope |
FRC Ethical Standard (UK)
In the UK, auditors must comply with the FRC Ethical Standard (issued by the Financial Reporting Council). This is more restrictive than the IESBA Code in several areas, particularly for audits of public interest entities (PIEs) — listed companies, credit institutions, and insurance companies.
Key provisions of the FRC Ethical Standard:
- Non-audit services: Audit firms must not provide certain non-audit services to audit clients (especially PIEs) where these create self-review or management threats. A "whitelist" approach applies for PIE audits — only permitted services can be provided. Total non-audit fees from a PIE audit client must not exceed 70% of the average audit fees over the prior three years.
- Partner rotation: The engagement partner for a PIE audit must be rotated off the engagement after 5 years, with a 5-year cooling-off period before they can return. The engagement quality reviewer also rotates after 7 years (3-year cooling-off).
- Financial interests: Audit engagement partners and other covered persons must not hold financial interests (shares, debentures) in the audit client.
- Employment relationships: A former audit partner joining the audit client in a senior position creates a familiarity threat. The Ethical Standard requires a 2-year cooling-off period after leaving the audit team before joining a PIE audit client as a director or senior manager.
- Long association: For non-PIE audits, firms must consider the familiarity threat of long association and apply safeguards (engagement quality review, additional partner rotation, second partner review).
Companies Act 2006 — Auditors
The Companies Act 2006 governs the statutory framework for auditors of UK companies.
Appointment:
- Auditors are appointed by the shareholders at a general meeting (usually the AGM for public companies) by ordinary resolution
- For private companies: auditors are deemed reappointed automatically unless the company passes a resolution not to reappoint, the directors decide not to appoint, or the members resolve that auditors should not be reappointed (s.487-488)
- The directors may appoint the first auditors or fill a casual vacancy (until the next AGM/general meeting)
- Only registered auditors (individuals or firms registered with a Recognised Supervisory Body such as ICAEW) may be appointed as statutory auditors
Removal (s.510):
- Auditors may be removed by the shareholders at any time by ordinary resolution
- Special notice of 28 days must be given to the company
- The company must send a copy to the auditor, who has the right to make written representations and to attend and speak at the meeting
- The company must notify the relevant regulatory body (e.g., ICAEW) of the removal
Resignation (s.516):
- An auditor may resign by depositing a notice of resignation at the company's registered office
- The notice must be accompanied by a statement of circumstances connected with the resignation that the auditor considers should be brought to the attention of members or creditors (or a statement that there are no such circumstances)
- For PIE audits: the auditor must also notify the relevant audit authority
- The auditor may requisition a general meeting to explain the circumstances of their resignation (s.518)
Rights of auditors:
- Right of access at all times to the company's books, accounts, and vouchers (s.499)
- Right to require directors and employees to provide information and explanations the auditor considers necessary (s.499)
- Right to attend general meetings and to be heard on any business that concerns them as auditors (s.502)
- Right to receive all notices and communications relating to general meetings
Duties of auditors:
- Report to the members (shareholders) on the financial statements — whether they give a true and fair view
- State whether the financial statements have been properly prepared in accordance with the applicable framework (Companies Act, IFRS/UK GAAP)
- Report on whether the directors' report and strategic report are consistent with the financial statements
- Report by exception on certain matters: inadequate accounting records, failure to obtain all information and explanations needed, directors' report inconsistent with accounts, directors' remuneration report not properly prepared
Quality Management — ISQM 1, ISQM 2, and ISA 220
Quality management ensures that audit firms and individual engagements meet professional standards and deliver high-quality audit work.
ISQM 1 — Firm-Level Quality Management
ISQM 1 (International Standard on Quality Management 1) requires audit firms to design, implement, and operate a system of quality management (SoQM). The system is risk-based — the firm identifies quality risks and designs responses.
Eight components of the SoQM:
- The firm's risk assessment process: Identify and assess quality risks relating to the firm's practice. A continuous, iterative process.
- Governance and leadership: Firm culture that recognises quality as essential. Leadership assigns responsibilities and accountability for quality. "Tone at the top."
- Relevant ethical requirements: Ensure all personnel comply with ethical requirements (independence, integrity, objectivity, confidentiality). Policies for identifying and managing threats.
- Acceptance and continuance of client relationships and engagements: Assess the integrity of potential and existing clients, the firm's competence and capacity, and whether engagement can be completed in accordance with professional standards.
- Engagement performance: Ensure engagements are performed in accordance with professional standards and regulatory requirements. Includes: direction, supervision, and review of engagement work; consultation on difficult matters; resolving differences of opinion.
- Resources: Obtain, develop, use, and maintain appropriate resources — human resources (competent personnel, training, CPD), technological resources (audit software, data analytics), intellectual resources (methodologies, templates, guidance).
- Information and communication: Obtain, generate, and use relevant information about the SoQM. Communicate internally (policies, expectations) and externally (regulatory bodies, clients).
- The monitoring and remediation process: Design and implement monitoring activities to evaluate the SoQM's effectiveness. Identify deficiencies, determine root causes, and take remedial action. This is an ongoing process, not just an annual review.
ISQM 2 — Engagement Quality Reviews
ISQM 2 deals with the appointment and eligibility of engagement quality reviewers (EQRs) and the performance of engagement quality reviews.
When is an EQR required?
- Audits of listed entities (PIEs) — always required
- Other engagements where the firm determines an EQR is appropriate (based on risk, complexity, public interest)
Who performs the EQR?
- A suitably qualified and experienced individual who was NOT a member of the engagement team
- Must be objective — no involvement in the engagement that would compromise independence
- Competent to evaluate the significant judgements made by the engagement team
What does the EQR cover?
- The engagement team's evaluation of independence
- Significant risks identified and the responses to those risks
- Significant judgements made (including those relating to materiality, going concern, key audit matters)
- Whether appropriate consultations were made and the conclusions implemented
- Whether the engagement documentation supports the conclusions reached
- The form and content of the auditor's report (including any modifications)
The audit report must not be dated until the EQR is complete — it is a prerequisite for issuing the report.
ISA 220 — Quality Management at Engagement Level
ISA 220 (Revised) establishes the engagement partner's responsibilities for quality management on an individual audit engagement.
Key responsibilities of the engagement partner:
- Overall responsibility for managing and achieving quality on the engagement, including sufficient and appropriate involvement throughout
- Leadership: Set the tone — create an environment that emphasises quality, professional scepticism, and ethical behaviour within the engagement team
- Ethics and independence: Take responsibility for ensuring the engagement team and the firm comply with ethical requirements. Address breaches appropriately.
- Acceptance and continuance: Be satisfied that client acceptance and continuance procedures have been followed and conclusions are appropriate
- Engagement resources: Determine that sufficient and appropriate resources (personnel, time, technology) are assigned or made available
- Direction, supervision, and review: Ensure work is directed, supervised, and reviewed. The nature, timing, and extent depends on the complexity and risk of the engagement and the experience of team members. Review completed work to be satisfied with the conclusions.
- Consultation: Ensure team members consult on difficult or contentious matters, and that agreed conclusions are implemented
- Engagement documentation: Determine that documentation is sufficient and appropriate to support the report (ISA 230)
Professional Scepticism and Professional Judgement
Professional scepticism is an attitude that includes a questioning mind, being alert to conditions that may indicate possible misstatement due to error or fraud, and a critical assessment of audit evidence. It is not suspicion or distrust — it is maintaining an open and inquiring attitude while recognising that circumstances may exist that cause the financial statements to be materially misstated.
Key aspects:
- Not accepting audit evidence at face value — considering its reliability and sufficiency
- Being alert to contradictory evidence — evidence that contradicts other evidence or management's representations
- Questioning management representations — not relying solely on management assertions without corroborating evidence
- Considering the risk of management bias in estimates, accounting policies, and judgements
- Recognising that past experience with the client's honesty does not justify relaxing scepticism
Professional judgement is the application of relevant training, knowledge, and experience in making informed decisions about appropriate courses of action in the circumstances of the audit. It is applied throughout the audit in decisions about materiality, risk assessment, the nature and extent of procedures, evaluating evidence, and forming the opinion.
ISA 200 requires the auditor to plan and perform the audit with professional scepticism, recognising that circumstances may exist that cause the financial statements to be materially misstated. Professional scepticism is particularly important when:
- Evaluating management estimates (high inherent subjectivity)
- Considering related party transactions (risk of non-disclosure or non-arm's-length pricing)
- Assessing going concern (management may be unduly optimistic)
- Identifying and responding to fraud risks (ISA 240 — the auditor must assume revenue recognition is a fraud risk unless evidence to the contrary)
- Evaluating the appropriateness of accounting policies and the reasonableness of disclosures
Examiner Focus
Common Pitfall
Study Tip
Examiner Focus
Watch Out
Study Tip
Written Practice
Regulatory and Ethical Framework (Advanced): Applied Requirement
Prepare a focused written answer with clear workings and justified recommendations.
A client has asked for a concise exam-style written response for a client or senior manager on regulatory and ethical framework (advanced). Use the key rules, calculations, risks, and professional judgement from this topic to structure your answer.
Answer Prompts
- •Identify the issue and explain why it matters in the scenario.
- •Apply the relevant technical rule, calculation, or framework.
- •State the commercial, ethical, tax, reporting, or assurance implication.
- •Conclude with a clear recommendation or exam-ready judgement.
Marking Focus
- Application to facts rather than textbook recall
- Clear structure and answer-first communication
- Balanced judgement where there is uncertainty
- Commercially sensible conclusion
Key Definitions
IESBA Code of Ethics
The International Code of Ethics for Professional Accountants, establishing five fundamental principles (integrity, objectivity, professional competence and due care, confidentiality, professional behaviour) and a conceptual framework of threats and safeguards.
Conceptual framework (ethics)
The threats and safeguards approach: identify threats to the fundamental principles, evaluate their significance, apply safeguards to reduce them to an acceptable level, or decline/discontinue the engagement.
Self-interest threat
A financial or other interest could inappropriately influence judgement. Examples: financial interest in client, overdue fees, concern about losing the engagement.
Self-review threat
The risk that an auditor will not appropriately evaluate their own (or their firm's) previous work. Example: preparing financial statements and then auditing them.
Familiarity threat
A long or close relationship makes the auditor too sympathetic. Examples: long association with the engagement, personal relationship with directors.
FRC Ethical Standard
The UK ethical standard for auditors, issued by the FRC. More restrictive than the IESBA Code for PIE audits: limits on non-audit services, partner rotation (5 years + 5 cooling-off), 70% fee cap.
ISQM 1
International Standard on Quality Management 1. Requires audit firms to design, implement, and operate a system of quality management with eight components, using a risk-based approach.
ISQM 2
Deals with engagement quality reviews. An EQR is required for PIE audits and other high-risk engagements. Reviews significant judgements, independence, and the proposed report before the audit report is dated.
ISA 220
Quality management at the engagement level. The engagement partner has overall responsibility for quality — including leadership, ethics, resources, direction/supervision/review, and consultation.
Professional scepticism
A questioning mind, alertness to conditions indicating possible misstatement, and critical assessment of evidence. Not suspicion, but maintaining an inquiring attitude and not accepting evidence at face value.
Professional judgement
The application of relevant training, knowledge, and experience in making informed decisions about courses of action in audit circumstances. Applied throughout the audit.
Engagement quality review (EQR)
An objective evaluation of significant judgements and the proposed report by a reviewer NOT on the engagement team. The report cannot be dated until the EQR is complete.
Statement of circumstances
A statement an auditor must provide on resignation, setting out any circumstances connected with the resignation that should be brought to the attention of members/creditors (or stating there are none).
Key Formulas
Worked Examples
Related Topics
Key Takeaways
- ✓Five fundamental principles (IESBA): integrity, objectivity, professional competence and due care, confidentiality, professional behaviour. Applied through a conceptual framework of threats and safeguards.
- ✓Five threat categories: self-interest, self-review, advocacy, familiarity, intimidation. Evaluate significance; apply safeguards; if threats too great, decline or resign.
- ✓FRC Ethical Standard (UK): more restrictive for PIE audits — partner rotation (5yr + 5yr cooling-off), non-audit service restrictions (whitelist, 70% fee cap), 2-year cooling-off for former staff joining client, prohibition on financial interests.
- ✓CA 2006: auditors appointed by shareholders (ordinary resolution), removed by shareholders (ordinary resolution + 28 days special notice + representations), resign by notice + statement of circumstances. Rights: access to books, information from directors, attend GMs.
- ✓ISQM 1: eight components of the firm's system of quality management — risk assessment, governance/leadership, ethics, acceptance/continuance, engagement performance, resources, information/communication, monitoring/remediation.
- ✓ISQM 2: engagement quality reviews — required for PIE audits. Performed by qualified individual not on the team. Reviews independence, significant judgements, proposed report. Report cannot be dated until EQR is complete.
- ✓ISA 220: engagement partner has overall responsibility for quality — leadership, ethics, resources, direction/supervision/review, consultation, documentation.
- ✓Professional scepticism: questioning mind, critical assessment of evidence, not accepting at face value, alert to contradictory evidence, recognising management bias risk. Not suspicion — but not blind trust either.
- ✓Professional judgement: application of training, knowledge, and experience to make informed decisions. Applied throughout the audit — materiality, risk, procedures, evidence evaluation, forming the opinion.
Practice Questions
Question 1 of 8
The five fundamental principles of the IESBA Code of Ethics are:
Question 2 of 8
An audit engagement partner has been the engagement partner for a PIE audit for 6 years. Under the FRC Ethical Standard:
Question 3 of 8
ISQM 1 requires audit firms to establish a system of quality management. The number of components in the system is:
Question 4 of 8
Under ISA 220, overall responsibility for quality on an audit engagement lies with:
Question 5 of 8
Professional scepticism requires the auditor to:
Question 6 of 8
Under the Companies Act 2006, auditors may be removed by:
Question 7 of 8
A member of the audit team has inherited shares in the PIE audit client. The appropriate action is:
Question 8 of 8
An engagement quality review must be completed:
Source and Version
Syllabus: ICAEW ACA Professional Level 2026 · Reviewed: 2026-05-04