IESBA principles: Integrity, Objectivity, Professional Competence
& Due Care, Confidentiality, Professional Behavior.
Auditing & Assurance
Ethics & Independence
The IESBA Code sets five fundamental principles: integrity (be honest and straightforward), objectivity (no bias or undue influence), professional competence and due care (maintain skill and diligence), confidentiality (protect client information), and professional behavior (comply with laws and avoid discrediting the profession). Auditors must uphold all five.
Real-world example
An auditor declines to disclose a client's confidential data to a third party, upholding confidentiality.
ISA Standards
Audit Objectives & Types
Ethics & Independence
Independence is the auditor's freedom from relationships or interests that could compromise, or appear to compromise, professional judgment—comprising independence of mind (actual objectivity) and independence in appearance (avoiding circumstances a reasonable observer would think impair objectivity). It's essential because the value of an audit rests on users trusting the auditor's impartiality.
Real-world example
An auditor sells shares in a client before the engagement to preserve both actual and perceived independence.
Audit Objectives & Types
ISA Standards
Ethics & Independence
The Code identifies five threat categories: self-interest (financial or other interest, e.g., fees, shares), self-review (auditing one's own prior work), advocacy (promoting a client's position), familiarity (close/long relationship reducing skepticism), and intimidation (pressure, actual or perceived). Auditors identify threats and apply safeguards or decline the work.
Threats: Self-interest, Self-review, Advocacy, Familiarity, Intimidation.
Real-world example
Providing bookkeeping and then auditing the same records creates a self-review threat the firm must avoid or safeguard.
Ethics & Independence
Audit Objectives & Types
ISA Standards
Safeguards reduce threats to an acceptable level: those created by the profession/regulation (standards, monitoring, education, licensing) and those in the firm/engagement (rotation of partners, independent quality reviews (EQCR), separating teams, policies prohibiting certain services, consultation). If no safeguard can reduce a threat sufficiently, the auditor declines or withdraws.
Real-world example
To counter a familiarity threat from a long tenure, the firm rotates the engagement partner and adds an independent review.
Ethics & Independence
ISA Standards
Audit Objectives & Types
A self-review threat arises when the auditor evaluates results of a service they (or their firm) previously performed, so they may not objectively assess their own work. Example: a firm prepares the client's financial statements or does its bookkeeping, then audits those same statements—reducing objectivity. Standards restrict providing such services to audit clients, especially public interest entities.
Real-world example
A firm that designed the client's valuation model faces a self-review threat when auditing the resulting figure.
Ethics & Independence
Internal Controls Evaluation
ISA Standards
Fees create self-interest and intimidation threats: over-dependence on one client (fees a large proportion of firm/office income), overdue fees resembling a loan, contingent fees (prohibited for audits), and lowballing that pressures corners. Safeguards include monitoring fee dependency, disclosure to those charged with governance, independent reviews, and thresholds for public interest entities.
Real-world example
When one client's fees exceed a set percentage of office revenue, the firm imposes an independent review to manage the dependency threat.
Ethics & Independence
Audit Objectives & Types
ISA Standards
Non-audit services can create self-review, advocacy, or self-interest threats. The Code and regulators (e.g., for public interest entities) prohibit certain services (bookkeeping, valuation affecting the statements, internal audit outsourcing of financial controls, management functions, certain tax and legal advocacy) and cap permissible non-audit fees. Any permitted service needs threat evaluation and safeguards, with governance approval.
Real-world example
The firm declines to run the audit client's internal audit of financial controls to avoid a self-review threat.
Ethics & Independence
Internal Controls Evaluation
ISA Standards
A familiarity threat arises from a long or close relationship with a client (long partner tenure, close personal ties, former staff now at the client) that may erode skepticism and objectivity. It's managed through partner and staff rotation, cooling-off periods before joining a client, independent reviews, and policies on personal relationships.
Real-world example
A partner who has served the client for many years is rotated off to counter the familiarity threat.
Ethics & Independence
Audit Objectives & Types
ISA Standards
For public interest entities, ethics rules and regulation require key audit partner rotation (commonly after a set number of years, e.g., 5-7, with a cooling-off period) and, in some jurisdictions (e.g., the EU), mandatory firm rotation after a maximum tenure and tendering. Rotation counters familiarity and self-interest threats and refreshes skepticism.
Real-world example
Under EU rules, a listed company must retender and rotate its audit firm after the maximum permitted tenure.
Ethics & Independence
Audit Objectives & Types
ISA Standards
Confidentiality requires not disclosing client information acquired through the professional relationship without proper authority, and not using it for personal advantage. It can be overridden when disclosure is permitted by law and authorized by the client, required by law (e.g., legal proceedings, providing evidence), or there's a professional duty/right to disclose (e.g., regulatory requirements, protecting public interest, money-laundering reporting).
Real-world example
The auditor reports suspected money laundering to authorities, a lawful override of client confidentiality.
Fraud & Error Responsibilities
ISA Standards
Ethics & Independence