Auditors regularly encounter questions about licences, taxes, labour requirements, environmental rules, sector regulations and other legal obligations. SA 250, Consideration of Laws and Regulations in an Audit of Financial Statements, provides the framework for deciding what an auditor is expected to do. Its central point is important: management, with oversight from those charged with governance, is responsible for ensuring compliance. The financial statement auditor does not become the entity's legal-compliance officer, but must consider whether non-compliance could cause a material misstatement.
ICAI includes SA 250 in its current Engagement and Quality Control Standards collection. The official SA 250 text explains the auditor's responsibilities and is the primary reference for applying the standard.
What does SA 250 cover?
SA 250 applies to the auditor's consideration of laws and regulations in an audit of financial statements. It distinguishes this role from a separate assurance engagement specifically designed to test and report on compliance with particular laws. That distinction prevents an ordinary financial statement audit from being mistaken for a comprehensive legal compliance certification.
Laws and regulations can affect financial statements in different ways. Some have a direct effect because they determine reported amounts or disclosures. Others govern how the entity conducts its business and may affect the financial statements only when non-compliance produces consequences such as fines, litigation, loss of licence, provisions, impairment or going-concern problems.
Direct-effect laws versus other laws
This distinction drives the auditor's work. For laws and regulations generally recognised to have a direct effect on material amounts and disclosures, the auditor obtains sufficient appropriate audit evidence regarding compliance. Tax legislation affecting tax expense and liability is an intuitive example of a legal framework that may directly influence amounts in the financial statements.
For other laws and regulations that do not directly determine financial statement amounts but whose breach could materially affect the statements, SA 250 requires specified procedures aimed at identifying non-compliance. The auditor should not assume that the same depth of testing applies to every law touching the entity.
Practical example
Consider a manufacturing company subject to an environmental operating licence. The licence conditions may not directly calculate a line item in the financial statements. However, a serious breach could trigger a material penalty, remediation obligation or shutdown risk. The audit response therefore focuses on identifying indications of non-compliance and evaluating the financial reporting consequences, including provisions, disclosures, impairment or going-concern effects where relevant.
Step 1: Understand the legal and regulatory framework
During risk assessment, obtain a general understanding of the legal and regulatory framework applicable to the entity and its industry or sector, and how the entity complies with that framework. A useful approach is to map laws by business process rather than build an unstructured list.
- Corporate and financial reporting: laws governing the entity's constitution, accounts and reporting.
- Tax and statutory payments: legislation affecting material taxes, duties or statutory liabilities.
- Industry regulation: licensing, capital, safety or operating requirements specific to the sector.
- Employment and operations: laws whose breach could lead to material claims, penalties or disruption.
- Contracts and permits: legal permissions essential to continuing important operations.
The objective is not to turn the audit file into a legal encyclopaedia. It is to identify the parts of the framework that could plausibly create material financial statement consequences.
Step 2: Perform the required audit procedures
For laws without a direct effect on financial statement amounts, practical procedures include inquiring of management and, where appropriate, those charged with governance about compliance and inspecting correspondence with relevant licensing or regulatory authorities. The auditor should also remain alert throughout the audit because evidence obtained for another purpose may indicate non-compliance.
For example, legal expense ledgers, board minutes, regulator correspondence, unusual penalties, whistle-blower matters, provisions, contingent liabilities and management discussions may reveal issues that require further investigation even when the original procedure was not labelled a compliance test.
Step 3: Investigate suspected non-compliance
When the auditor becomes aware of information concerning possible non-compliance, the response should be evidence-led. Obtain an understanding of the nature of the act and the circumstances in which it occurred, then obtain further information needed to evaluate its possible effect on the financial statements.
Discuss the matter with management and, where appropriate, those charged with governance. If they do not provide sufficient information supporting compliance and the matter may be material, consider the need for legal advice. The auditor should not make unsupported legal conclusions where specialist interpretation is required.
Step 4: Evaluate the financial statement consequences
A legal breach matters to the audit because of its possible consequences. Ask what the breach could do to the financial statements rather than merely whether a rule was broken.
- Does it create a fine, penalty, damages claim or remediation cost?
- Is a provision or contingent liability assessment required?
- Could a licence, concession or key contract be lost?
- Does it affect asset values, recoverability or impairment?
- Could it threaten the entity's ability to continue operating?
- Are additional disclosures necessary?
- Does it indicate weaknesses in controls or management integrity that affect other audit areas?
A seemingly small monetary penalty can still be significant if the underlying breach signals pervasive management misconduct or threatens an essential operating permission.
Step 5: Communicate appropriately
Unless all those charged with governance are involved in management and are already aware of the matters, the auditor communicates non-compliance that comes to attention, other than matters that are clearly inconsequential. Matters judged intentional and material should be communicated as soon as practicable.
Communication is not merely a closing-meeting formality. Timely escalation gives governance bodies an opportunity to investigate, obtain legal advice, correct accounting and disclosures, and address control failures before the audit is completed.
Step 6: Consider reporting implications
If non-compliance has a material effect on the financial statements and is not adequately reflected, the auditor considers the effect on the audit opinion under the applicable reporting standards. If management or those charged with governance prevent the auditor from obtaining sufficient appropriate audit evidence about suspected material non-compliance, that scope limitation can also affect the auditor's report.
SA 250 additionally requires the auditor to consider whether there is a responsibility to report identified or suspected non-compliance to parties outside the entity. Whether such a duty exists depends on the applicable legal, regulatory and professional framework. Confidentiality should therefore not be treated as an automatic answer where law or regulation creates an external reporting obligation.
Practical SA 250 audit checklist
- Identify the entity's industry, regulators, material licences and key legal frameworks.
- Separate laws with a direct financial statement effect from other laws whose breach could materially affect the statements.
- Ask management and governance about known or suspected non-compliance.
- Inspect relevant regulator and licensing correspondence.
- Stay alert to indicators in minutes, legal expenses, claims, penalties, provisions and audit evidence from other areas.
- Investigate suspected breaches and obtain enough information to understand their financial reporting effect.
- Seek legal advice when interpretation is important and management's explanation is insufficient.
- Evaluate provisions, disclosures, impairment, going concern and control implications.
- Communicate significant matters to those charged with governance on a timely basis.
- Consider audit-report and any external-reporting consequences, then document the work and conclusions.
Common mistakes to avoid
- Treating SA 250 as a checklist requiring detailed testing of every law applicable to the entity.
- Assuming the auditor is responsible for preventing all non-compliance.
- Ignoring operational laws simply because they do not directly calculate an accounting balance.
- Accepting management's verbal explanation when contradictory evidence exists.
- Focusing only on the amount of a penalty and overlooking wider effects on licences, controls, integrity or going concern.
- Leaving communication and reporting implications until the day the auditor's report is signed.
Practical takeaway
SA 250 is best applied as a financial-statement-risk framework for legal and regulatory matters. Understand the entity's framework, distinguish direct-effect laws from other regulations, remain alert for indications of breaches, investigate credible concerns, evaluate the accounting and disclosure consequences, communicate significant matters and consider reporting obligations. The auditor is not expected to guarantee legal compliance, but cannot ignore non-compliance that may materially affect the financial statements or the audit.