Search this Act

Jump directly to a section by number or title.

Section 400

Applying the Conceptual Framework to Independence for Audit and Review Engagements

Introduction

General

400.1 It is in the public interest and required by the Code that chartered accountants in practice be independent when performing audit or review engagements in accordance with the requirements of the Code along with any additional requirements. Such requirements may be prescribed from time to time under the Chartered Accountants Act, 1949, the Chartered Accountants Regulations, 1988, Council guidelines, Companies Act 2013, or by other Regulators such as the Reserve Bank of India (RBI), Securities and Exchange Board of India (SEBI), Insurance Regulatory Development Authority

(IRDA)
etc. 400.2 This Part applies to both audit and review engagements unless otherwise stated. The terms “audit,” “audit team,” “audit engagement,” “audit client,” and “audit report” apply equally to review, review team, review engagement, review client, and review engagement report. 400.3 In this Part, the term “chartered accountant” refers to individual chartered accountants in practice and their firms. 400.4 SQC 1 requires a firm to establish policies and procedures designed to provide it with reasonable assurance that the firm, its personnel and, where applicable, others subject to independence requirements (including network firm personnel), maintain independence where required by relevant ethics requirements. SAs and SREs establish responsibilities for engagement partners and engagement teams at the level of the engagement for audits and reviews, respectively. The allocation of responsibilities within a firm will depend on its size, structure and organization. Many of the provisions of this Part do not prescribe the specific responsibility of individuals within the firm for actions related to independence, instead referring to “firm” for ease of reference. Firms assign responsibility for a particular action to an individual or a group of individuals (such as an audit team), in accordance with SQC 1. In addition, an individual chartered accountant remains responsible for compliance with any provisions that apply to that accountant’s activities, interests or relationships. 400.5 Independence is linked to the principles of objectivity and integrity. It comprises:
(a)
Independence of mind – the state of mind that permits the expression of a conclusion without being affected by influences that compromise professional judgment, thereby allowing an individual to act with integrity, and exercise objectivity and professional skepticism.
(b)
Independence in appearance – the avoidance of facts and circumstances that are so significant that a reasonable and informed third party would be likely to conclude that a firm’s, or an audit team member’s, integrity, objectivity or professional skepticism has been compromised.

In this Part, references to an individual or firm being

“independent” mean that the individual or firm has complied with the provisions of this Part. 400.6 When performing audit engagements, the Code requires firms to comply with the fundamental principles and be independent. This Part sets out specific requirements and application material on how to apply the conceptual framework to maintain independence when performing such engagements. The conceptual framework set out in Section 120 applies to independence as it does to the fundamental principles set out in Section 110. 400.7 This Part describes:

(a)
Facts and circumstances, including professional activities, interests and relationships, that create or might create threats to independence;
(b)
Potential actions, including safeguards, that might be appropriate to address any such threats; and
(c)
Some situations where the threats cannot be eliminated or there can be no safeguards to reduce them to an acceptable level.

Engagement Team and Audit Team

400.8 This Part applies to all audit team members, including engagement team members. 400.9 An engagement team for an audit engagement includes all partners and staff in the firm who perform audit work on the engagement, and any other individuals who perform audit procedures who are from:

(a)
A network firm; or
(b)
A firm that is not a network firm, or another entity registered with ICAI. 400.11 An audit engagement might involve experts within, or engaged by, the firm, a network firm, who assist in the engagement. Depending on the role of the individuals, they might be engagement team or audit team members. For example: • Individuals with expertise in a specialized area of accounting or auditing who perform audit procedures are engagement team members. These include, for example, individuals with expertise in accounting for income taxes or in analyzing complex information produced by automated tools and techniques for the purpose of identifying unusual or unexpected relationships. • Individuals within, or engaged by, the firm who have direct influence over the outcome of the audit engagement through consultation regarding technical or industry-specific issues, transactions or events for the engagement are audit team members but not engagement team members.

However, individuals who are external experts are neither engagement team nor audit team members. 400.12 If the audit engagement is subject to an engagement quality control review, those who provide quality control for the engagement, including those who perform the engagement quality control review for the engagement are audit team members but not engagement team members.

Public Interest Entities

400.13 Some of the requirements and application material set out in this Part are applicable only to the audit of financial statements of public interest entities, reflecting significant public interest in the financial condition of these entities due to the potential impact of their financial well-being on stakeholders. 400.14 Factors to consider in evaluating the extent of public interest in the financial condition of an entity include: • The nature of the business or activities such as taking on financial obligations to the public as part of the entity’s primary business. • Whether the entity is subject to regulatory supervision designed to provide confidence that the entity will meet its financial obligations. • Size of the entity. • The importance of the entity to the sector in which it operates including how easily replaceable it is in the event of financial failure. • Number and nature of stakeholders, including investors, customers, creditors and employees. The potential systemic impact on other sectors and the economy as a whole in the event of financial failure of the entity. 400.15 Stakeholders have heightened expectations regarding the independence of a firm performing an audit engagement for a public interest entity because of the significance of the public interest in the financial condition of the entity. The purpose of the requirements and application material for public interest entities as described in paragraph 400.13 is to meet these expectations, thereby enhancing stakeholders’ confidence in the entity’s financial statements that can be used when assessing the entity’s financial condition.

Reports that Include a Restriction on Use and Distribution

400.16 An audit report might include a restriction on use and distribution. If it does and the conditions set out in Section 800 are met, then the independence requirements in this Part may be modified as provided in Section 800.

Assurance Engagements other than Audit and Review Engagements

400.17 Independence standards for assurance engagements that are not audit or review engagements are set out in Part 4B – Independence for Assurance Engagements Other than Audit and Review Engagements.

Requirements and Application Material

General

R400.18

A firm performing an audit engagement shall be independent.

R400.19

A firm shall apply the conceptual framework set out in Section 120 to identify, evaluate and address threats to independence in relation to an audit engagement.

R400.19.1

Additional independence requirements are set out for a statutory auditor under the Companies Act 2013. Section 139(2) of the Companies Act, 2013 prescribes the auditor rotation requirements which have been discussed in detail in Section 550.

Section 141(3) of the Companies Act 2013 (subject to amendments as may be made from time to time) is reproduced below: “141 (3) The following persons shall not be eligible for appointment as an auditor of a company, namely:—

(a)
a body corporate other than a limited liability partnership registered under the Limited Liability Partnership Act, 2008;
(b)
an officer or employee of the company;
(c)
a person who is a partner, or who is in the employment, of an officer or employee of the company;
(d)
a person who, or his relative or partner—
(i)
is holding any security of or interest in the company or its subsidiary, or of its holding or associate company or a subsidiary of such holding company:
Proviso

Provided that the relative may hold security or interest in the company of face value not exceeding one thousand rupees or such sum as may be prescribed1;

(ii)
is indebted to the company, or its subsidiary, or its holding or associate company or a subsidiary of such holding company, in excess of such amount as may be prescribed2; or
(iii)
has given a guarantee or provided any security in connection with the indebtedness of any third person to the company, or its subsidiary, or its holding or associate company or a subsidiary of such holding company, for such amount as may be prescribed3;
(e)
a person or a firm who, whether directly or indirectly, has business relationship4 with the company, or its As per Rule 10 of The Companies (Audit and Auditors) Rules, 2014:- 1 For the purpose of proviso to sub-clause (i) of clause (d) of sub-section (3) of section 141, a relative of an auditor may hold securities in the company of face value not exceeding rupees one lakh: Provided that the condition under this sub-rule shall, wherever relevant, be also applicable in the case of a company not having share capital or other securities: Provided further that in the event of acquiring any security or interest by a relative, above the threshold prescribed, the corrective action to maintain the limits as specified above shall be taken by the auditor within sixty days of such acquisition or interest. 2 For the purpose of sub-clause (ii) of clause (d) of sub-section (3) of section 141, a person who or whose relative or partner is indebted to the company or its subsidiary or its holding or associate company or a subsidiary of such holding company, in excess of rupees five lakhs shall not be eligible for appointment. 3 For the purpose of sub-clause (iii) of clause (d) of sub-section (3) of section 141, a person who or whose relative or partner has given a guarantee or provided any security in connection with the indebtedness of any third person to the company, or its subsidiary, or its holding or associate company or a subsidiary of such holding company, in excess of one lakh rupees shall not be eligible for appointment. 4 For the purpose of clause (e) of sub-section (3) of section 141, the term "business relationship" shall be construed as any transaction entered into for a commercial purpose, except- subsidiary, or its holding or associate company or subsidiary of such holding company or associate company of such nature as may be prescribed;
(f)
a person whose relative is a director or is in the employment of the company as a director or key managerial personnel;
(g)
a person who is in full time employment elsewhere or a person or a partner of a firm holding appointment as its auditor, if such persons or partner is at the date of such appointment or reappointment holding appointment as auditor of more than twenty companies
(h)
a person who has been convicted by a court of an offence involving fraud and a period of ten years has not elapsed from the date of such conviction;
(i)
a person who, directly or indirectly, renders any service referred to in section 144 to the company or its holding company or its subsidiary company.
Explanation

For the purposes of this clause, the “term

"directly or indirectly" shall have the meaning assigned to it in the Explanation to section 144.

(4)
Where a person appointed as an auditor of a company incurs any of the disqualifications mentioned in sub-section
(3)
after his appointment, he shall vacate his office as such auditor and such vacation shall be deemed to be a casual vacancy in the office of the auditor.”
(i)
commercial transactions which are in the nature of professional services permitted to be rendered by an auditor or audit firm under the Act and the Chartered Accountants Act, 1949 and the rules or the regulations made under those Acts;
(ii)
commercial transactions which are in the ordinary course of business of the company at arm’s length price - like sale of products or services to the auditor, as customer, in the ordinary course of business, by companies engaged in the business of telecommunications, airlines, hospitals, hotels and such other similar businesses.

Prohibition on Assuming Management Responsibilities

R400.20

A firm or a network firm shall not assume a management responsibility for an audit client. 400.20 A1 Management responsibilities involve controlling, leading and directing an entity, including making decisions regarding the acquisition, deployment and control of human, financial, technological, physical and intangible resources. 400.20 A2 When a firm or a network firm assumes a management responsibility for an audit client, self-review, self-interest and familiarity threats are created. Assuming a management responsibility might also create an advocacy threat because the firm or network firm becomes too closely aligned with the views and interests of management. 400.20 A3 Determining whether an activity is a management responsibility depends on the circumstances and requires the exercise of professional judgment. Examples of activities that would be considered a management responsibility include: • Setting policies and strategic direction. • Hiring or dismissing employees. • Directing and taking responsibility for the actions of employees in relation to the employees’ work for the entity. • Authorizing transactions. • Controlling or managing bank accounts or investments. • Deciding which recommendations of the firm or network firm or other third parties to implement. • Reporting to those charged with governance on behalf of management. • Taking responsibility for: o The preparation and fair presentation of the financial statements in accordance with the applicable financial reporting framework. o Designing, implementing, monitoring or maintaining internal control. 400.20 A4 Subject to compliance with paragraph R400.21, providing advice and recommendations to assist the management of an audit client in discharging its responsibilities is not assuming a management responsibility. The provision of advice and recommendations to an audit client might create a self-review threat and is addressed in Section 600.

R400.21

When performing a professional activity for an audit client, the firm shall be satisfied that client management makes all judgments and decisions that are the proper responsibility of management. This includes ensuring that the client’s management:

(a)
Designates an individual who possesses suitable skill, knowledge and experience to be responsible at all times for the client’s decisions and to oversee the activities. Such an individual, preferably within senior management, would understand:
(i)
The objectives, nature and results of the activities; and
(ii)
The respective client and firm or network firm responsibilities.

However, the individual is not required to possess the expertise to perform or re-perform the activities.

(b)
Provides oversight of the activities and evaluates the adequacy of the results of the activities performed for the client’s purpose.
(c)
Accepts responsibility for the actions, if any, to be taken arising from the results of the activities. 400.21 A1 When technology is used in performing a professional activity for an audit client, the requirements in paragraphs R400.20 and R400.21 apply regardless of the nature or extent of such use of the technology.

Public Interest Entities

R400.22

For the purposes of this Part, a firm shall treat an entity as a public interest entity when it falls within any of the following categories:

(a)
A listed entity;
(b)
An entity one of whose main functions is to take deposits from the public;
(c)
An entity:
(i)
Defined by regulation or legislation as a public interest entity; or
(ii)
Having borrowings of 500 crores of rupees or more (to be assessed at both the beginning and end of the year). For purpose of this definition, it may be noted that Banks and Insurance Companies are to be considered as Public Interest Entities. Other entities might also be considered by the Firms to be public interest entities, as set out in paragraph 400.13 and 400.14.

R400.23

In complying with the requirement in paragraph R400.22, a firm shall take into account more explicit definitions established by law or regulation for the categories set out in paragraph R400.22 (a) to (c).

Related Entities

R400.27

As defined, an audit client that is a listed entity in accordance with paragraphs R400.22 and R400.23 includes all of its related entities. For all other entities, references to an audit client in this Part include related entities over which the client has direct or indirect control. When the audit team knows, or has reason to believe, that a relationship or circumstance involving any other related entity of the client is relevant to the evaluation of the firm’s independence from the client, the audit team shall include that related entity when identifying, evaluating and addressing threats to independence. Besides the above, where the audit client is subject to the provisions of Companies Act, 2013, additional restrictions are prescribed under Section 141 and 144 of the Companies Act, 2013.

Period During which Independence is Required

R400.30

Independence, as required by this Part, shall be maintained during both:

(a)
The engagement period; and
(b)
The period covered by the financial statements. 400.30 A1 The engagement period starts when the engagement team begins to perform the audit. The engagement period ends when the audit report is issued. When the engagement is of a recurring nature, it ends at the later of the notification by either party that the professional relationship has ended or the issuance of the final audit report. Where the audit client is a statutory audit client under the Companies Act, 2013, the engagement period shall be determined in accordance with the provisions of Section 139 of the Companies Act, 2013.

R400.31

If an entity becomes an audit client during or after the period covered by the financial statements on which the firm will express an opinion, the firm shall determine whether any threats to independence are created by:

(a)
Financial or business relationships with the audit client during or after the period covered by the financial statements but before accepting the audit engagement; or
(b)
Previous services provided to the audit client by the firm or a network firm. 400.31 A1 Threats to independence are created if a non-assurance service was provided to an audit client during, or after the period covered by the financial statements, but before the engagement team begins to perform the audit, and the service would not be permitted during the engagement period. 400.31 A2 A factor to be considered in such circumstances is whether the results of the service provided might form part of or affect the accounting records, the internal controls over financial reporting, or the financial statements on which the firm will express an opinion. 400.31 A3 Subject to compliance with the requirements of Section 144 of the Companies Act, 2013, where applicable, examples of actions that might be safeguards to address threats to independence include: • Not assigning professionals who performed the non-assurance service to be members of the engagement team. • Having an appropriate reviewer review the audit work or non-assurance service as appropriate. • Engaging another firm outside of the network to evaluate the results of the non-assurance service or having another firm outside of the network re-perform the non-assurance service to the extent necessary to enable the other firm to take responsibility for the service. 400.31 A4 A threat to independence created by the provision of a non-assurance service by a firm or a network firm prior to the audit engagement period or prior to the period covered by the financial statements on which the firm will express an opinion is eliminated or reduced to an acceptable level if the results of such service have been used or implemented in a period audited by another firm.

Audit Clients that are Public Interest Entities

R400.32

Subject to the applicable provisions of any other law(s), a firm shall not accept appointment as auditor of a public interest entity to which the firm or the network firm has provided a non-assurance service prior to such appointment that might create a self-review threat in relation to the financial statements on which the firm will express an opinion unless:

(a)
The provision of such service ceases before the commencement of the audit engagement period;
(b)
The firm takes action to address any threats to its independence; and
(c)
The firm determines that, in the view of a reasonable and informed third party, any threats to the firm’s independence have been or will be eliminated or reduced to an acceptable level. 400.32 A1 Actions that might be regarded by a reasonable and informed third party as eliminating or reducing to an acceptable level any threats to independence created by the provision of non-assurance services to a public interest entity prior to appointment as auditor of that entity include: • The results of the service had been subject to auditing procedures in the course of the audit of the prior year’s financial statements by a predecessor firm. • The firm engages a chartered accountant, who is not a member of the firm expressing the opinion on the financial statements, to perform a review of the first audit engagement affected by the self-review threat that is equivalent to an engagement quality control review. • The public interest entity engages another firm outside of the network to:
(i)
Evaluate the results of the non-assurance service; or
(ii)
Re-perform the service, to the extent necessary to enable the other firm to take responsibility for the result of the service.

Communication with those Charged with Governance

400.40 A1 Paragraphs R300.9 and R300.10 set out requirements with respect to communicating with those charged with governance. 400.40 A2 Even when not required by the Code, applicable professional standards, laws or regulations, regular communication is encouraged between a firm and those charged with governance of the client regarding relationships and other matters that might, in the firm’s opinion, reasonably bear on independence. Such communication enables those charged with governance to:

(a)
Consider the firm’s judgments in identifying and evaluating threats;
(b)
Consider how threats have been addressed including the appropriateness of safeguards when they are available and capable of being applied; and
(c)
Take appropriate action.

Such an approach can be particularly helpful with respect to intimidation and familiarity threats.

Network Firms

400.50 A1 Firms may frequently form larger structures with other firms and entities to enhance their ability to provide professional services. Whether these larger structures create a network depends on the particular facts and circumstances. It does not depend on whether the firms and entities are legally separate and distinct. Reference may be made to the Guidelines of Network issued by the Institute from time to time in this regard.

R400.51

A network firm shall be independent of the audit clients of the other firms within the network as required by this Part. 400.51 A1 The independence requirements in this Part that apply to a network firm apply to any entity that meets the definition of a network firm.

General Documentation of Independence for Audit and Review

Engagements

R400.60

A firm shall document conclusions regarding compliance with this Part, and the substance of any relevant discussions that support those conclusions. In particular:

(a)
When safeguards are applied to address a threat, the firm shall document the nature of the threat and the safeguards in place or applied; and
(b)
When a threat required significant analysis and the firm concluded that the threat was already at an acceptable level, the firm shall document the nature of the threat and the rationale for the conclusion. 400.60 A1 Documentation provides evidence of the firm’s judgments in forming conclusions regarding compliance with this Part.

However, a lack of documentation does not determine whether a firm considered a particular matter or whether the firm is independent.

Mergers and Acquisitions

When a Client Merger Creates a Threat

400.70 A1 An entity might become a related entity of an audit client because of a merger or acquisition. A threat to independence and, therefore, to the ability of a firm to continue an audit engagement might be created by previous or current interests or relationships between a firm or network firm and such a related entity.

R400.71

In the circumstances set out in paragraph 400.70 A1,

(a)
The firm shall identify and evaluate previous and current interests and relationships with the related entity that, taking into account any actions taken to address the threat, might affect its independence and therefore its ability to continue the audit engagement after the effective date of the merger or acquisition; and
(b)
Subject to paragraph R400.72, the firm shall take steps to end any interests or relationships that are not permitted by the Code by the effective date of the merger or acquisition.

R400.72

As an exception to paragraph R400.71(b), if the interest or relationship cannot reasonably be ended by the effective date of the merger or acquisition, the firm shall:

(a)
Evaluate the threat that is created by the interest or relationship; and
(b)
Discuss with those charged with governance the reasons why the interest or relationship cannot reasonably be ended by the effective date and the evaluation of the level of the threat. 400.72 A1 In some circumstances, it might not be reasonably possible to end an interest or relationship creating a threat by the effective date of the merger or acquisition. This might be because the firm provides a non-assurance service to the related entity, which the entity is not able to transition in an orderly manner to another provider by that date. 400.72 A2 Factors that are relevant in evaluating the level of a threat created by mergers and acquisitions when there are interests and relationships that cannot reasonably be ended include: • The nature and significance of the interest or relationship. • The nature and significance of the related entity relationship (for example, whether the related entity is a subsidiary or parent). • The length of time until the interest or relationship can reasonably be ended.

R400.73

Subject to applicable restrictions under Companies Act, 2013 or any other laws and regulations, if, following the discussion set out in paragraph R400.72(b), those charged with governance request the firm to continue as the auditor, the firm shall do so only if:

(a)
The interest or relationship will be ended as soon as reasonably possible but no later than six months after the effective date of the merger or acquisition;
(b)
Any individual who has such an interest or relationship, including one that has arisen through performing a non-assurance service that would not be permitted by Section 600 and its subsections, will not be a member of the engagement team for the audit or the individual responsible for the engagement quality control review; and
(c)
Transitional measures will be applied, as necessary, and discussed with those charged with governance. 400.73 A1 Examples of such transitional measures include: • Having a chartered accountant review the audit or non-assurance work as appropriate. • Having a chartered accountant, who is not a member of the firm expressing the opinion on the financial statements, perform a review that is equivalent to an engagement quality control review. • Engaging another firm to evaluate the results of the non-assurance service or having another firm re-perform the non-assurance service to the extent necessary to enable the other firm to take responsibility for the service.

R400.74

The firm might have completed a significant amount of work on the audit prior to the effective date of the merger or acquisition and might be able to complete the remaining audit procedures within a short period of time. In such circumstances, if those charged with governance request the firm to complete the audit while continuing with an interest or relationship identified in paragraph 400.70 A1, the firm shall only do so if it:

(a)
Has evaluated the level of the threat and discussed the results with those charged with governance;
(b)
Complies with the requirements of paragraph R400.73
(b)
to (c); and
(c)
Ceases to be the auditor no later than the date that the audit report is issued.

If Objectivity Remains Compromised

R400.75

Even if all the requirements of paragraphs R400.71 to

R400.74 could be met, the firm shall determine whether the circumstances identified in paragraph 400.70 A1 create a threat that cannot be addressed such that objectivity would be compromised. If so, the firm shall cease to be the auditor.

Documentation

R400.76

The firm shall document:

(a)
Any interests or relationships identified in paragraph 400.70 A1 that will not be ended by the effective date of the merger or acquisition and the reasons why they will not be ended;
(b)
The transitional measures applied;
(c)
The results of the discussion with those charged with governance; and
(d)
The reasons why the previous and current interests and relationships do not create a threat such that objectivity would be compromised.

Breach of an Independence Provision for Audit and Review

Engagements

When a Firm Identifies a Breach

R400.80

Subject to the eligibility requirements of the auditor mentioned under Section 141 of the Companies Act, 2013, if a firm concludes that a breach of a requirement in this Part has occurred, the firm shall:

(a)
End, suspend or eliminate the interest or relationship that created the breach and address the consequences of the breach;
(b)
Consider whether any legal or regulatory requirements apply to the breach and, if so:
(i)
Comply with those requirements;
(c)
Promptly communicate the breach in accordance with its policies and procedures to:
(i)
The engagement partner;
(ii)
Those with responsibility for the policies and procedures relating to independence;
(iii)
Other relevant personnel in the firm and, where appropriate, the network; and
(iv)
Those subject to the independence requirements in Part 4A who need to take appropriate action;
(d)
Evaluate the significance of the breach and its impact on the firm’s objectivity and ability to issue an audit report; and
(e)
Depending on the significance of the breach, determine:
(i)
Whether to end the audit engagement; or
(ii)
Whether it is possible to take action that satisfactorily addresses the consequences of the breach and whether such action can be taken and is appropriate in the circumstances.

In making this determination, the firm shall exercise professional judgment and take into account whether a reasonable and informed third party would be likely to conclude that the firm's objectivity would be compromised, and therefore, the firm would be unable to issue an audit report. 400.80 A1 A breach of a provision of this Part might occur despite the firm having policies and procedures designed to provide it with reasonable assurance that independence is maintained.

It might be necessary to end the audit engagement because of the breach. 400.80 A2 The significance and impact of a breach on the firm’s objectivity and ability to issue an audit report will depend on factors such as: • The nature and duration of the breach. • The number and nature of any previous breaches with respect to the current audit engagement. • Whether an audit team member had knowledge of the interest or relationship that created the breach. • Whether the individual who created the breach is an audit team member or another individual for whom there are independence requirements. • If the breach relates to an audit team member, the role of that individual. • If the breach was created by providing a professional service, the impact of that service, if any, on the accounting records or the amounts recorded in the financial statements on which the firm will express an opinion. • The extent of the self-interest, advocacy, intimidation or other threats created by the breach. 400.80 A3 Depending upon the significance of the breach, examples of actions that the firm might consider to address the breach satisfactorily include: • Removing the relevant individual from the audit team. • Using different individuals to conduct an additional review of the affected audit work or to re-perform that work to the extent necessary. • Recommending that the audit client engage another firm to review or re-perform the affected audit work to the extent necessary. • If the breach relates to a non-assurance service that affects the accounting records or an amount recorded in the financial statements, engaging another firm to evaluate the results of the non-assurance service or having another firm re-perform the non-assurance service to the extent necessary to enable the other firm to take responsibility for the service.

R400.81

If the firm determines that action cannot be taken to address the consequences of the breach satisfactorily, the firm shall inform those charged with governance as soon as possible and take the steps necessary to end the audit engagement in compliance with any applicable legal or regulatory requirements.

R400.82

If the firm determines that action can be taken to address the consequences of the breach satisfactorily, the firm shall discuss with those charged with governance:

(a)
The significance of the breach, including its nature and duration;
(b)
How the breach occurred and how it was identified;
(c)
The action proposed or taken and why the action will satisfactorily address the consequences of the breach and enable the firm to issue an audit report;
(d)
The conclusion that, in the firm’s professional judgment, objectivity has not been compromised and the rationale for that conclusion; and
(e)
Any steps proposed or taken by the firm to reduce or avoid the risk of further breaches occurring.

Such discussion shall take place as soon as possible unless an alternative timing is specified by those charged with governance for reporting less significant breaches.

Communication of Breaches to Those Charged with Governance

400.83 A1 Paragraphs R300.9 and R300.10 set out requirements with respect to communicating with those charged with governance.

R400.84

With respect to breaches, the firm shall communicate in writing to those charged with governance:

(a)
All matters discussed in accordance with paragraph R400.82 and obtain the concurrence of those charged with governance that action can be, or has been, taken to satisfactorily address the consequences of the breach; and
(b)
A description of:
(i)
The firm’s policies and procedures relevant to the breach designed to provide it with reasonable assurance that independence is maintained; and
(ii)
Any steps that the firm has taken, or proposes to take, to reduce or avoid the risk of further breaches occurring.

R400.85

If those charged with governance do not concur that the action proposed by the firm in accordance with paragraph R400.80(e)(ii) satisfactorily addresses the consequences of the breach, the firm shall take the steps necessary to end the audit engagement in accordance with paragraph R400.81.

Breaches Before the Previous Audit Report Was Issued

R400.86

If the breach occurred prior to the issuance of the previous audit report, the firm shall comply with the provisions of Part 4A in evaluating the significance of the breach and its impact on the firm’s objectivity and its ability to issue an audit report in the current period.

R400.87

The firm shall also:

(a)
Consider the impact of the breach, if any, on the firm’s objectivity in relation to any previously issued audit reports, and the possibility of withdrawing such audit reports; and
(b)
Discuss the matter with those charged with governance.

Documentation

R400.88

In complying with the requirements in paragraphs R400.80 to

R400.87, the firm shall document:

(a)
The breach;
(b)
The actions taken;
(c)
The key decisions made;
(d)
All the matters discussed with those charged with governance; and
(e)
Any discussions with a professional or regulatory body or oversight authority.

R400.89

If the firm continues with the audit engagement, it shall document:

(a)
The conclusion that, in the firm’s professional judgment, objectivity has not been compromised; and
(b)
The rationale for why the action taken satisfactorily addressed the consequences of the breach so that the firm could issue an audit report.