5.4 Professional Confidentiality, Legal Disclosure & NOCLAR Rules

Key Takeaways

  • Subsection 114 of the ICAB Code (the restructured IESBA Code ICAB publishes) makes confidentiality indefinite: information acquired through a professional relationship stays protected after the engagement or employment ends, and covers prospective clients.
  • Disclosure is permitted or required in exactly three cases: the client authorises it, the law compels it, or a professional duty or right applies (ICAB QAB review, disciplinary inquiry, legal defence).
  • Most breaches are accidental — discussing one client at another client's premises, misdirected email, unencrypted devices, and papers left in printers or waste bins — so need-to-know, encryption and clear-desk rules are the tested safeguards.
  • Bangladesh statute overrides confidentiality: an auditor who suspects proceeds of crime must file a Suspicious Transaction Report with the BFIU, and MLPA 2012 s.6 prohibits tipping off the client.
  • Under NOCLAR (IESBA Code s.360 for public practice, s.260 for business), if management and TCWG fail to rectify serious non-compliance the auditor may disclose to an external authority, and good-faith disclosure is not a breach of confidentiality.
Last updated: August 2026

Professional Confidentiality, Legal Disclosure & NOCLAR Rules

1. The Scope and Mechanics of Professional Confidentiality

Confidentiality is both an ethical principle under Subsection 114 of the ICAB/IESBA Code and an implied contractual duty between a professional accountant and a client or employer. The rationale behind confidentiality is to foster complete openness and trust: clients must feel secure that sensitive financial records, trade secrets, tax planning strategies, and operational data disclosed to their auditors will not be leaked or misused.

The Operational Scope of Confidentiality

Under Subsection 114 of the Code, the duty of confidentiality requires a professional accountant to:

  1. Refrain from disclosing confidential information acquired as a result of professional and business relationships outside the firm or employing organization without proper and specific authority, unless there is a legal or professional right or duty to disclose;
  2. Refrain from using confidential information acquired as a result of professional and business relationships for personal advantage or for the advantage of third parties (e.g., trading in securities based on unreleased earnings data, which constitutes illegal insider trading under Bangladesh Securities and Exchange Commission regulations);
  3. Maintain confidentiality in social environments, remaining alert to the risk of inadvertent disclosure to family members or business associates;
  4. Maintain confidentiality within the firm, ensuring that colleagues not assigned to the specific engagement do not access restricted client files;
  5. Uphold confidentiality indefinitely, extending to prospective clients and persisting even after the professional relationship between the accountant and the client or employer has ended.

2. Permissible Disclosures: When Confidentiality Can Be Overridden

Confidentiality is a fundamental duty, but it is not absolute. The ICAB Code of Ethics categorizes the circumstances where a professional accountant is permitted or required to disclose confidential client information into three distinct categories:

                             [ Disclosure of Confidential Information ]
                                                 │
       ┌─────────────────────────────────────────┼────────────────────────────────────────┐
       ▼                                         ▼                                        ▼
[ 1. Client Authorized ]              [ 2. Mandatory by Law ]                 [ 3. Professional Duty/Right ]
  • Written consent from client         • Court Orders / Subpoenas              • ICAB QAB Practice Review
  • Specific scope defined              • Money Laundering Act (BFIU)           • ICAB Disciplinary Inquiry
                                        • Financial Reporting Act (FRC)         • Legal defense in litigation
                                        • ACC / Tax Statutory Summons           • Compliance with ISAs

Category 1: Disclosure Authorized by the Client

Information may be disclosed if the client or employer explicitly authorizes the accountant to do so in writing. Example: A client instructs their statutory auditor to provide audited financial schedules directly to a commercial bank to secure a syndicate loan facility.

Category 2: Obligatory / Mandatory Disclosure (Required by Law)

In these situations, Bangladesh statutory legislation explicitly overrides confidentiality obligations. The accountant must disclose the information, regardless of client consent. Key statutory reporting mandates include:

  • Money Laundering Prevention Act, 2012 (MLPA): Under Bangladesh money laundering laws, if an auditor suspects that funds or transactions involve proceeds of crime, corruption, or money laundering, the auditor is statutorily mandated to file a Suspicious Transaction Report (STR) or Suspicious Activity Report (SAR) with the Bangladesh Financial Intelligence Unit (BFIU) at Bangladesh Bank. Crucial Rule — Anti-Tipping Off: Section 6 of the MLPA strictly prohibits "tipping off" the client. The auditor must NOT inform client management that a report has been filed with BFIU.
  • Financial Reporting Act, 2015 (FRA): The FRA established the Financial Reporting Council (FRC) as the oversight body for the financial reporting, external auditing, valuation and actuarial work of Public Interest Entities (PIEs), and for ICAB and ICMAB. Auditors of PIEs must be enlisted with the FRC, and the FRC's monitoring, audit practice review and enforcement divisions may require information from them. (Section 40 of the FRA is the provision under which the FRC issues financial reporting and auditing standards; the reporting and information-gathering powers sit across the Act rather than in that single section, so cite the Act rather than a specific section unless your sitting materials say otherwise.)
  • Court Summons and Orders: Producing documents or giving evidence under a lawful court order, judge's warrant, or official summons issued by the Anti-Corruption Commission (ACC) or Tax Tribunals under National Board of Revenue (NBR) proceedings.

Category 3: Voluntary / Discretionary Disclosure (Permitted by Law / Professional Duty)

An accountant is permitted (and professionally expected) to disclose confidential information under the following circumstances:

  • To comply with the quality review requirements of ICAB or the Quality Assurance Board (QAB);
  • To respond to an inquiry or investigation by the ICAB Disciplinary Committee;
  • To protect the professional interests of the accountant in legal proceedings (e.g., defending against a lawsuit for professional negligence brought by a client);
  • To comply with technical standards and ethical requirements (e.g., replying to a professional-clearance enquiry from a prospective successor auditor, which the professional-appointment rules in Section 320 of the ICAB/IESBA Code require the outgoing auditor to answer).

2A. Accidental Disclosure: Sources of Risk and How to Prevent It

Learning outcomes 4(h) and 4(i) of the syllabus ask candidates to recognise the importance of confidentiality and identify the sources of risks of accidental disclosure of information, and to identify steps to prevent the accidental disclosure of information. Most real breaches of confidentiality are not deliberate leaks. They are careless ones, and ICAB's own published sample paper tests exactly this point.

Where accidental disclosure comes from

Source of riskHow the breach happens
Discussing client affairs in publicConversations in lifts, restaurants, on public transport, in a client's reception area, or on a mobile phone where others can hear. Discussing Client A's affairs while working at Client B's premises is a classic.
Working in shared or client premisesFiles, laptops and notebooks left open on a client's desk; screens visible to client staff; papers left in a meeting room after the meeting.
Physical documentsWorking papers taken home or carried in transit; documents left in printers, photocopiers or waste bins rather than confidential shredding.
Electronic transmissionEmails sent to the wrong recipient through address auto-complete; unencrypted attachments; using personal email or consumer file-sharing accounts.
DevicesUnencrypted laptops, phones or USB drives lost or stolen; devices left unlocked and unattended; automatic screen locks disabled.
Social contactAnswering "how's work?" with a recognisable story; social media posts naming a client or revealing a site visit; recruitment interviews where a candidate volunteers a former client's information.
Within the firmDiscussing an engagement with colleagues who have no need to know; conflicting engagements without an information barrier.
Family and householdWorking on client data at home where family members can see the screen or the papers.

Steps to prevent accidental disclosure

  1. Never discuss client affairs outside a private setting, and never at another client's premises.
  2. Apply need-to-know within the firm, including information barriers where the firm acts for competing or conflicting parties.
  3. Secure documents physically: lock assurance files away, use a clear-desk rule, collect printing immediately, shred confidential waste.
  4. Secure devices: full-disk encryption, strong authentication, automatic screen locking, remote-wipe capability, and no client data on personal devices or consumer cloud accounts.
  5. Control email: verify recipients before sending, disable or double-check address auto-complete, encrypt or password-protect sensitive attachments and send the password separately.
  6. Use screen privacy filters when working at client sites or in public.
  7. Train all staff, including temporary and support staff, and make confidentiality obligations contractual.
  8. Extend the discipline beyond the engagement. The duty of confidentiality continues after the engagement or employment ends, so a former client's information must be protected indefinitely.
  9. Report suspected breaches promptly to the firm's ethics partner so containment and, where required, regulatory notification can happen.

Exam framing. A question will typically offer four practices and ask which one would not be recommended. The wrong practice is almost always the one that moves information into a setting the firm does not control — discussing a client's affairs while sitting at another client's office, or emailing working papers to a personal address to finish them at home.

3. The NOCLAR Framework (Non-Compliance with Laws and Regulations)

The NOCLAR framework (IESBA Code Section 360 in Part 3, for professional accountants in public practice, and Section 260 in Part 2, for professional accountants in business) sets out a landmark international standard adopted by ICAB. NOCLAR provides an explicit ethical roadmap for auditors when they encounter non-compliance with laws and regulations during an engagement.

Definition of NOCLAR

NOCLAR is defined as any act of omission or commission, intentional or unintentional, committed by a client, or by Those Charged With Governance (TCWG), management, or other individuals working for or under the direction of a client, which is contrary to prevailing laws or regulations.

Scope of Laws Covered Under NOCLAR

NOCLAR applies to laws and regulations that have a direct effect on the determination of material amounts and disclosures in the financial statements, or whose compliance is fundamental to the entity's operations, avoiding material penalties, or continuing its business. Matters covered include:

  • Money laundering, terrorist financing, and proceeds of crime;
  • Fraud, corruption, and bribery;
  • Securities markets and capital regulations (BSEC directives);
  • Banking and financial regulations (Bangladesh Bank rules);
  • Tax and duty evasion (NBR legislation);
  • Environmental protection and public health laws.

NOCLAR does not cover personal misconduct unrelated to the client's business activities or matters clearly inconsequential.


4. Step-by-Step Auditor Response Protocol for NOCLAR

When an auditor discovers actual or suspected NOCLAR during an audit, they must follow a structured 5-stage protocol:

[ Stage 1: Discovery & Initial Assessment ] ──> Obtain understanding of act & legal implications
                      │
                      ▼
[ Stage 2: Discussion with Management & TCWG ] ──> Request rectification, disclosure & remediation
                      │
          (Did Management Rectify?)
          ├── YES ──> Document in audit files; proceed with audit
          └── NO
               │
               ▼
[ Stage 3: Evaluate Management Response ] ──> Assess integrity of TCWG & public interest impact
               │
               ▼
[ Stage 4: Determine External Disclosure ] ──> Disclose to external authorities (FRC/ACC/BFIU)
               │                              (Good-faith disclosure is NOT a breach of confidentiality)
               ▼
[ Stage 5: Audit Report & Resignation ] ──> Modify audit opinion (ISA 705) / Resign from engagement

Stage 1: Obtaining an Understanding

The auditor must obtain an understanding of the nature of the act and the circumstances in which it has occurred or may occur, evaluating the potential financial and regulatory consequences.

Stage 2: Addressing the Matter with Management and TCWG

The auditor must raise the matter promptly with the appropriate level of management and, where appropriate, Those Charged With Governance (TCWG). The auditor must advise management and TCWG to:

  • Take appropriate steps to rectify, remediate, or mitigate the consequences of the non-compliance;
  • Deter the commission of the non-compliance if it has not yet occurred; and
  • Disclose the matter to an appropriate authority where required by law or regulation.

Stage 3: Evaluating Management's Response

The auditor must evaluate whether management and TCWG have responded appropriately. If management fails to take adequate action, the auditor must evaluate the integrity of management and TCWG and determine whether further action is needed in the public interest.

Stage 4: Determining Whether to Disclose to an External Authority

If management or TCWG fail to rectify the matter or report it to regulators, the auditor must determine whether disclosing the NOCLAR to an external regulatory or enforcement authority (e.g., FRC, ACC, Bangladesh Bank, BSEC) is appropriate in the public interest.

Fundamental Rule: Disclosing NOCLAR to an external authority in good faith does NOT constitute a breach of the duty of confidentiality under the ICAB Code of Ethics.

Stage 5: Impact on Audit Opinion and Engagement Resignation

The auditor must evaluate the impact of the non-compliance on the audit opinion under ISA 705 (Modifications to the Opinion in the Independent Auditor's Report). If management's integrity is fundamentally compromised or if safeguards cannot mitigate the threat, the auditor should consider withdrawing/resign from the engagement.


5. Summary Table: Confidentiality Exceptions & Statutory Reporting

Exception ScenarioPrimary Governing Standard / ActReporting TypeTarget Authority / EntityTipping-off Restrictions
Money Laundering / Terrorist FinancingMoney Laundering Prevention Act 2012Mandatory Statutory ReportingBangladesh Financial Intelligence Unit (BFIU)STRICT PROHIBITION against tipping off client.
FRC monitoring, practice review or enquiry into a PIE auditFinancial Reporting Act 2015Mandatory response to a statutory information requestFinancial Reporting Council (FRC), BangladeshStatutory override of confidentiality; cite the Act, not s.40 (that section is the FRC's standard-setting power).
Lawful Court Warrant / ACC SummonsCode of Civil Procedure / ACC ActMandatory Judicial ComplianceCourt of Law / Anti-Corruption CommissionGoverned by judicial summons terms.
ICAB Quality InspectionICAB Bye-Laws 2004 / QAB RulesProfessional DutyQuality Assurance Board (QAB) ReviewersRestricted to authorized ICAB reviewers.
NOCLAR Unrectified by ClientIESBA Code Sec 360 / ICAB NOCLARDiscretionary Public InterestRelevant Industry Regulator (BSEC, BB, FRC)Good faith disclosure protected from breach claims.
Loading diagram...
NOCLAR Decision Tree & Reporting Flowchart
Test Your Knowledge

An auditor conducting a statutory audit in Chittagong discovers clear evidence of illicit money laundering transactions originating from proceeds of trade mis-invoicing. Under the Money Laundering Prevention Act 2012 (MLPA) in Bangladesh, what is the auditor's statutory obligation, and what restriction applies?

A
B
C
D
Test Your Knowledge

Under Subsection 114 of the ICAB Code of Ethics, in which of the following situations is an auditor PERMITTED or REQUIRED to disclose confidential client information without violating professional ethics?

A
B
C
D
Test Your Knowledge

During the audit of a listed manufacturing company, the audit team uncovers massive illegal dumping of toxic chemical waste in violation of environmental laws. Management and TCWG flatly refuse to rectify the breach or notify regulators. Under the NOCLAR framework, what is the auditor's ethical entitlement regarding external reporting?

A
B
C
D
Test Your Knowledge

Which of the following practices would NOT be recommended as a means of securing professional confidentiality?

A
B
C
D
Test Your Knowledge

An audit senior finishes an engagement and, three years later, is asked by a friend about that former client's financial difficulties. What does the duty of confidentiality require?

A
B
C
D