Cheat sheet

CPA Ethics and Governance Cheat Sheet

Quick Facts

Exam
E&G (CPA Program)
Body
CPA Australia
Time
195 min (225 total)
Pass
540 scaled (100-900 scale)
Format
Open book, computer-based
Modules
Five official modules
Core Code
APES 110
Question Type
MCQ + extended response

IFAC vs APESB Roles

IFAC

  • Global federation of accountancy bodies
  • Sets member-body obligations only
  • Does not discipline individual accountants

APESB

  • Australian ethics standard-setter
  • Issues APES 110 directly
  • Independent of CPA Australia

Global body vs local standard-setter

Profession & Public Interest

Social Contract
Trust for privileges granted
Public Interest
Comes before client or employer
Audit Expectation Gap
Belief vs actual assurance level
IFAC
Global accountancy body, sets obligations
IFEA (2023)
Houses IESBA and IAASB now
APESB
Sets ethics standards, e.g. APES 110
AASB
Sets accounting standards
AUASB
Sets auditing standards

Five Principles Mnemonic

Integrity -> Objectivity -> Competence -> Confidentiality -> Behaviour

Integrity: honest, straightforwardObjectivity: no bias or influenceCompetence: skill and diligenceConfidentiality: limited disclosure dutyBehaviour: comply, avoid discredit

Independence of Mind vs Appearance

Independence of Mind

  • Internal, subjective state
  • Actual objectivity in mind
  • Auditor's honest judgment

Independence in Appearance

  • Judged by outside perception
  • RITP test applied
  • Perception equals reality here

Both pillars are mandatory

Threat Response Steps

  1. Threat is already acceptable→Proceed, monitor situation(No action required)
  2. Can remove the circumstance→Eliminate the threat(R120.10(a))
  3. Threat can be reduced→Apply safeguards(R120.10(b))
  4. Threat stays unacceptable still→Decline or end activity(R120.10(c))
  5. Your superior is implicated→Escalate to higher authority(Skip the compromised level)
  6. Internal escalation gets nowhere→Brief the board or TCWG(Audit committee, independent NEDs)
  7. Governance route stays unresolved→Get independent external advice(Ethics service or lawyer)
  8. Client breaks a law→Apply the NOCLAR response(Sections 260 and 360)

Five Fundamental Principles

Integrity
Honest and straightforwardR111.1
Objectivity
No bias or undue influenceR112.1
Competence & Due Care
Skill plus diligent careR113.1
Confidentiality
No unauthorized disclosureR114
Professional Behaviour
Comply, avoid discreditR115
Disassociation Duty
Not associated with misleading reportsR111.2

Five Threats Mnemonic

Self-interest, self-review, advocacy, familiarity, intimidation

Self-interest: your own gainSelf-review: judge own workAdvocacy: promote a positionFamiliarity: too close, biasedIntimidation: pressured or coerced

Teleological vs Deontological Ethics

Teleological

  • Judge by the outcome
  • Utilitarian cost-benefit calculus
  • Used in AAA step six

Deontological

  • Judge by duty, rules
  • Rule-based consistency filter
  • Used in AAA step five

Outcome focus vs rule focus

Ethical Model Selector

  1. Personal reporting dilemma→Use the AAA model(Sequential seven steps)
  2. Corporate strategic decision→Use Tucker's five questions(Stakeholder filter check)
  3. An option is illegal→Reject it immediately(No mitigation possible)
  4. An option is only unfair→Add a mitigation plan(Compensate the affected group)
  5. Weighing rules against outcomes→Filter first, then assess(AAA steps five, six)

Threats & Safeguards Framework

Self-interest
Own financial or personal gain
Self-review
Re-judging your own work
Advocacy
Promoting a client's position
Familiarity
Too close, relationship bias
Intimidation
Pressured or coerced judgment
RITP Test
Reasonable informed third party
Eliminate
Remove the threatening circumstanceR120.10(a)
Safeguard
Reduce threat to acceptableR120.10(b)
Decline or End
Exit if threat remainsR120.10(c)

Tucker's 5 Questions

Profitable -> Legal -> Fair -> Right -> Sustainable

Profitable: economic returnLegal: statutory complianceFair: equitable distributionRight: moral duty, honestySustainable: environmental, long-term

Ethical Theories & Decision Models

Teleological
Judge by outcomes
Deontological
Judge by duty, rules
Virtue Ethics
Judge by character
Egoism
Maximise own self-interest
AAA Model
Seven-step accountant process
Tucker Model
Five-question corporate filter
NOCLAR
Respond to client law breachs260/360

Independence Standards

Independence of Mind
Actual, internal objectivity
Independence in Appearance
Perceived by a reasonable party
Part 4A
Audit and review engagements
Part 4B
Other assurance engagements
PIE
Public interest entity, stricter rules

ASX 8 Principles Grouped

P1-2 board, P3 culture, P4-6 reporting, P7-8 risk+pay

P1: Lay solid foundationsP2: Structure board effectivelyP3: Instil ethical cultureP4: Safeguard report integrityP5: Timely balanced disclosureP6: Respect security holdersP7: Recognise and manage riskP8: Remunerate fairly, responsibly

Agency vs Stewardship Theory

Agency Theory

  • Managers may self-serve
  • Needs monitoring and incentives
  • Assumes distrust by default

Stewardship Theory

  • Managers as trustworthy stewards
  • Needs empowerment, not control
  • Assumes trust by default

Distrust vs trust as default

Corporate Form & Theories

Separate Legal Personality
Company owns itself
Limited Liability
Shareholder risk is capped
Perpetual Succession
Company outlives its owners
Agency Theory
Managers may self-serve
Stewardship Theory
Managers are trustworthy stewards
Stakeholder Theory
Accountable to all affected
Resource Dependency
Control over external resources
Managerial Hegemony
Management dominates a weak board

ASX 8 Principles (4th Ed.)

Principle 1
Lay solid foundations
Principle 2
Structure board effectively
Principle 3
Instil ethical, lawful culture
Principle 4
Safeguard reporting integrity
Principle 5
Timely, balanced disclosure
Principle 6
Respect security holder rights
Principle 7
Recognise and manage risk
Principle 8
Remunerate fairly, responsibly
If Not, Why Not
Explain any departure

Global Codes & Regulators

UK Code 2024
Comply or explain basis
Section 172
UK enlightened shareholder value
Sarbanes-Oxley
US rules-based regime
OECD Principles
G20 global benchmark
ASIC
Market conduct regulator
APRA
Prudential safety regulator
ACCC
Competition and consumer regulator
Twin Peaks
ASIC plus APRA model

Two-Strikes Escalation

25% Twice -> Spill Vote -> 90-Day Meeting

Strike 1: 25%+ against onceStrike 2: 25%+ against againSpill vote: majority triggers s250VSpill meeting: within 90 days

Malus vs Clawback

Malus

  • Applies before reward vests
  • Forfeits an unpaid amount
  • Reduces a future payout

Clawback

  • Applies after reward is paid
  • Reclaims an already-paid amount
  • Recovers a past payout

Unpaid risk vs paid recovery

Two-Strikes Escalation

  1. First AGM, 25%+ against→Record a first strike(Board must explain next year)
  2. Second AGM, 25%+ again→Put a spill resolution(s250V)
  3. Majority backs the spill→Call a spill meeting(s250W)
  4. Executive reward not yet paid→Apply malus(Forfeit before vesting)
  5. Reward already paid out→Apply clawback(Reclaim the paid amount)

Board & Committees

Board Role
Set strategy, oversee management
Management Role
Run daily operations
Chair-CEO Split
Chair independent, not CEO
Audit Committee
Rec 4.1: three-plus, independent-chaired
Independent Director
No material relationship
Board Diversity
Reduces groupthink risk
Malus
Forfeit unvested reward
Clawback
Recover already-paid reward

NDB Scheme vs SOCI Act

NDB Scheme

  • Covers Privacy Act breaches
  • Regulator is the OAIC
  • Assess within 30 days

SOCI Act

  • Covers critical infrastructure assets
  • Regulator is the ACSC
  • Report in 12 or 72 hours

Data privacy vs infrastructure risk

Cyber & Privacy Response

  1. Significant impact on CI asset→Report to ASD ACSC in 12h(SOCI Act deadline)
  2. Relevant impact on CI asset→Report to ASD ACSC in 72h(SOCI Act deadline)
  3. Suspect an eligible breach→Assess it within 30 days(Privacy Act s26WH)
  4. Serious harm is likely→Notify OAIC and individuals(NDB scheme duty)
  5. Remedial action stops the harm→No notification is required(Safe harbour, s26WF)

Remuneration & Risk Oversight

Section 300A
Requires a remuneration report
Section 308(3C)
Auditor opines on report
Two-Strikes
25%+ against, twice [s250U]s250R
Spill Resolution
Majority vote triggers re-elections250V
Spill Meeting
Held within 90 dayss250W
Three Lines of Defence
Operations, risk, audit layers
COSO ERM
Enterprise risk management framework
CPS 511
APRA's remuneration standard

Remuneration Vote vs Spill Vote

Remuneration Vote

  • Non-binding, advisory only
  • Held at every AGM
  • No automatic consequence

Spill Resolution

  • Binding escalation trigger
  • Needs two consecutive strikes
  • Forces director re-election

Advisory vote vs escalation trigger

Whistleblowing & Cyber Duties

Part 9.4AAA
Corporate whistleblower protection regime
Eligible Discloser
Officer, employee, or contractor
Large Proprietary
2 of 3: revenue, assets, staff
APPs
Thirteen privacy principles
NDB Scheme
Notify serious-harm data breach
30-Day Rule
Assess a suspected breach
SOCI Act
Eleven critical infrastructure sectors
Incident Reporting
12h significant, 72h relevant impact

CSR Materiality Lenses

GRI = Impact | ISSB = Financial | Both = Double

GRI: society's impact lensISSB: investor's financial lensCSRD: double materiality, both lenses

GRI vs ISSB Standards

GRI

  • Impact materiality, inside-out lens
  • Serves multiple stakeholder groups
  • Set by the GSSB

ISSB / IFRS

  • Financial materiality, outside-in lens
  • Serves capital providers mainly
  • Set by the IFRS Foundation

Society lens vs investor lens

CSR & Sustainability Reporting

Triple Bottom Line
Profit, people, and planet
Carroll's Pyramid
Economic up to philanthropic
Legitimacy Theory
Match society's values, norms
Stakeholder Theory
Accountable beyond just shareholders
GRI
Impact materiality, inside-out lens
Integrated Reporting
Six capitals create value
ISSB
Financial materiality, outside-in lens
Double Materiality
EU CSRD uses both lenses
AASB S1
Voluntary general disclosure standard
AASB S2
Mandatory climate disclosure standard

AASB S1 vs AASB S2

AASB S1

  • General sustainability disclosures
  • Voluntary to apply now
  • Broader ESG topic coverage

AASB S2

  • Climate-related disclosures only
  • Mandatory, phased by size
  • Groups 1, 2, and 3

Voluntary standard vs mandatory standard

Common Traps

Legal vs Ethical Minimum

Law is the floor ≠ Ethics can exceed the law

Pass Score vs Raw Percent

540 scaled score is fixed ≠ Raw percentage is never published

APESB vs CPA Australia

APESB writes the Code ≠ CPA Australia enforces it on members

Malus vs Clawback Timing

Malus stops an unpaid reward ≠ Clawback reclaims an already-paid reward

First Strike vs Second Strike

First strike just requires disclosure ≠ Second strike can trigger a spill

GRI vs ISSB Audience

GRI serves broad stakeholder groups ≠ ISSB serves investors and lenders

AASB S1 vs S2 Status

S1 general disclosure stays voluntary ≠ S2 climate disclosure is mandatory

NDB vs SOCI Deadlines

NDB gives 30 days to assess ≠ SOCI gives 12 or 72 hours

Last Minute

  1. 1.Governance modules: 25% each, largest
  2. 2.Exam: 195 minutes working, 225 total
  3. 3.Pass: scaled score 540 of 900
  4. 4.APES 110 has five threat categories
  5. 5.Threats: eliminate, apply safeguards, or decline
  6. 6.Independence needs mind and appearance both
  7. 7.Two strikes: 25%+ against, twice running
  8. 8.Spill resolution: re-election within 90 days
  9. 9.Malus forfeits pay before it vests
  10. 10.Clawback recovers pay already paid out
  11. 11.AASB S2 climate disclosure: mandatory, phased
  12. 12.AASB S1 general disclosure stays voluntary
  13. 13.Whistleblowers include current and former staff
  14. 14.Data breach: assess within 30 days
  15. 15.ASX Code sets 8 core principles
Same family resources

Explore More CPA Australia Program

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.