5.4 Professional Confidentiality, Legal Disclosure & NOCLAR Rules
Key Takeaways
- Subsection 114 of the ICAB Code (the restructured IESBA Code ICAB publishes) makes confidentiality indefinite: information acquired through a professional relationship stays protected after the engagement or employment ends, and covers prospective clients.
- Disclosure is permitted or required in exactly three cases: the client authorises it, the law compels it, or a professional duty or right applies (ICAB QAB review, disciplinary inquiry, legal defence).
- Most breaches are accidental — discussing one client at another client's premises, misdirected email, unencrypted devices, and papers left in printers or waste bins — so need-to-know, encryption and clear-desk rules are the tested safeguards.
- Bangladesh statute overrides confidentiality: an auditor who suspects proceeds of crime must file a Suspicious Transaction Report with the BFIU, and MLPA 2012 s.6 prohibits tipping off the client.
- Under NOCLAR (IESBA Code s.360 for public practice, s.260 for business), if management and TCWG fail to rectify serious non-compliance the auditor may disclose to an external authority, and good-faith disclosure is not a breach of confidentiality.
Professional Confidentiality, Legal Disclosure & NOCLAR Rules
1. The Scope and Mechanics of Professional Confidentiality
Confidentiality is both an ethical principle under Subsection 114 of the ICAB/IESBA Code and an implied contractual duty between a professional accountant and a client or employer. The rationale behind confidentiality is to foster complete openness and trust: clients must feel secure that sensitive financial records, trade secrets, tax planning strategies, and operational data disclosed to their auditors will not be leaked or misused.
The Operational Scope of Confidentiality
Under Subsection 114 of the Code, the duty of confidentiality requires a professional accountant to:
- Refrain from disclosing confidential information acquired as a result of professional and business relationships outside the firm or employing organization without proper and specific authority, unless there is a legal or professional right or duty to disclose;
- Refrain from using confidential information acquired as a result of professional and business relationships for personal advantage or for the advantage of third parties (e.g., trading in securities based on unreleased earnings data, which constitutes illegal insider trading under Bangladesh Securities and Exchange Commission regulations);
- Maintain confidentiality in social environments, remaining alert to the risk of inadvertent disclosure to family members or business associates;
- Maintain confidentiality within the firm, ensuring that colleagues not assigned to the specific engagement do not access restricted client files;
- Uphold confidentiality indefinitely, extending to prospective clients and persisting even after the professional relationship between the accountant and the client or employer has ended.
2. Permissible Disclosures: When Confidentiality Can Be Overridden
Confidentiality is a fundamental duty, but it is not absolute. The ICAB Code of Ethics categorizes the circumstances where a professional accountant is permitted or required to disclose confidential client information into three distinct categories:
[ Disclosure of Confidential Information ]
│
┌─────────────────────────────────────────┼────────────────────────────────────────┐
▼ ▼ ▼
[ 1. Client Authorized ] [ 2. Mandatory by Law ] [ 3. Professional Duty/Right ]
• Written consent from client • Court Orders / Subpoenas • ICAB QAB Practice Review
• Specific scope defined • Money Laundering Act (BFIU) • ICAB Disciplinary Inquiry
• Financial Reporting Act (FRC) • Legal defense in litigation
• ACC / Tax Statutory Summons • Compliance with ISAs
Category 1: Disclosure Authorized by the Client
Information may be disclosed if the client or employer explicitly authorizes the accountant to do so in writing. Example: A client instructs their statutory auditor to provide audited financial schedules directly to a commercial bank to secure a syndicate loan facility.
Category 2: Obligatory / Mandatory Disclosure (Required by Law)
In these situations, Bangladesh statutory legislation explicitly overrides confidentiality obligations. The accountant must disclose the information, regardless of client consent. Key statutory reporting mandates include:
- Money Laundering Prevention Act, 2012 (MLPA): Under Bangladesh money laundering laws, if an auditor suspects that funds or transactions involve proceeds of crime, corruption, or money laundering, the auditor is statutorily mandated to file a Suspicious Transaction Report (STR) or Suspicious Activity Report (SAR) with the Bangladesh Financial Intelligence Unit (BFIU) at Bangladesh Bank. Crucial Rule — Anti-Tipping Off: Section 6 of the MLPA strictly prohibits "tipping off" the client. The auditor must NOT inform client management that a report has been filed with BFIU.
- Financial Reporting Act, 2015 (FRA): The FRA established the Financial Reporting Council (FRC) as the oversight body for the financial reporting, external auditing, valuation and actuarial work of Public Interest Entities (PIEs), and for ICAB and ICMAB. Auditors of PIEs must be enlisted with the FRC, and the FRC's monitoring, audit practice review and enforcement divisions may require information from them. (Section 40 of the FRA is the provision under which the FRC issues financial reporting and auditing standards; the reporting and information-gathering powers sit across the Act rather than in that single section, so cite the Act rather than a specific section unless your sitting materials say otherwise.)
- Court Summons and Orders: Producing documents or giving evidence under a lawful court order, judge's warrant, or official summons issued by the Anti-Corruption Commission (ACC) or Tax Tribunals under National Board of Revenue (NBR) proceedings.
Category 3: Voluntary / Discretionary Disclosure (Permitted by Law / Professional Duty)
An accountant is permitted (and professionally expected) to disclose confidential information under the following circumstances:
- To comply with the quality review requirements of ICAB or the Quality Assurance Board (QAB);
- To respond to an inquiry or investigation by the ICAB Disciplinary Committee;
- To protect the professional interests of the accountant in legal proceedings (e.g., defending against a lawsuit for professional negligence brought by a client);
- To comply with technical standards and ethical requirements (e.g., replying to a professional-clearance enquiry from a prospective successor auditor, which the professional-appointment rules in Section 320 of the ICAB/IESBA Code require the outgoing auditor to answer).
2A. Accidental Disclosure: Sources of Risk and How to Prevent It
Learning outcomes 4(h) and 4(i) of the syllabus ask candidates to recognise the importance of confidentiality and identify the sources of risks of accidental disclosure of information, and to identify steps to prevent the accidental disclosure of information. Most real breaches of confidentiality are not deliberate leaks. They are careless ones, and ICAB's own published sample paper tests exactly this point.
Where accidental disclosure comes from
| Source of risk | How the breach happens |
|---|---|
| Discussing client affairs in public | Conversations in lifts, restaurants, on public transport, in a client's reception area, or on a mobile phone where others can hear. Discussing Client A's affairs while working at Client B's premises is a classic. |
| Working in shared or client premises | Files, laptops and notebooks left open on a client's desk; screens visible to client staff; papers left in a meeting room after the meeting. |
| Physical documents | Working papers taken home or carried in transit; documents left in printers, photocopiers or waste bins rather than confidential shredding. |
| Electronic transmission | Emails sent to the wrong recipient through address auto-complete; unencrypted attachments; using personal email or consumer file-sharing accounts. |
| Devices | Unencrypted laptops, phones or USB drives lost or stolen; devices left unlocked and unattended; automatic screen locks disabled. |
| Social contact | Answering "how's work?" with a recognisable story; social media posts naming a client or revealing a site visit; recruitment interviews where a candidate volunteers a former client's information. |
| Within the firm | Discussing an engagement with colleagues who have no need to know; conflicting engagements without an information barrier. |
| Family and household | Working on client data at home where family members can see the screen or the papers. |
Steps to prevent accidental disclosure
- Never discuss client affairs outside a private setting, and never at another client's premises.
- Apply need-to-know within the firm, including information barriers where the firm acts for competing or conflicting parties.
- Secure documents physically: lock assurance files away, use a clear-desk rule, collect printing immediately, shred confidential waste.
- Secure devices: full-disk encryption, strong authentication, automatic screen locking, remote-wipe capability, and no client data on personal devices or consumer cloud accounts.
- Control email: verify recipients before sending, disable or double-check address auto-complete, encrypt or password-protect sensitive attachments and send the password separately.
- Use screen privacy filters when working at client sites or in public.
- Train all staff, including temporary and support staff, and make confidentiality obligations contractual.
- Extend the discipline beyond the engagement. The duty of confidentiality continues after the engagement or employment ends, so a former client's information must be protected indefinitely.
- Report suspected breaches promptly to the firm's ethics partner so containment and, where required, regulatory notification can happen.
Exam framing. A question will typically offer four practices and ask which one would not be recommended. The wrong practice is almost always the one that moves information into a setting the firm does not control — discussing a client's affairs while sitting at another client's office, or emailing working papers to a personal address to finish them at home.
3. The NOCLAR Framework (Non-Compliance with Laws and Regulations)
The NOCLAR framework (IESBA Code Section 360 in Part 3, for professional accountants in public practice, and Section 260 in Part 2, for professional accountants in business) sets out a landmark international standard adopted by ICAB. NOCLAR provides an explicit ethical roadmap for auditors when they encounter non-compliance with laws and regulations during an engagement.
Definition of NOCLAR
NOCLAR is defined as any act of omission or commission, intentional or unintentional, committed by a client, or by Those Charged With Governance (TCWG), management, or other individuals working for or under the direction of a client, which is contrary to prevailing laws or regulations.
Scope of Laws Covered Under NOCLAR
NOCLAR applies to laws and regulations that have a direct effect on the determination of material amounts and disclosures in the financial statements, or whose compliance is fundamental to the entity's operations, avoiding material penalties, or continuing its business. Matters covered include:
- Money laundering, terrorist financing, and proceeds of crime;
- Fraud, corruption, and bribery;
- Securities markets and capital regulations (BSEC directives);
- Banking and financial regulations (Bangladesh Bank rules);
- Tax and duty evasion (NBR legislation);
- Environmental protection and public health laws.
NOCLAR does not cover personal misconduct unrelated to the client's business activities or matters clearly inconsequential.
4. Step-by-Step Auditor Response Protocol for NOCLAR
When an auditor discovers actual or suspected NOCLAR during an audit, they must follow a structured 5-stage protocol:
[ Stage 1: Discovery & Initial Assessment ] ──> Obtain understanding of act & legal implications
│
▼
[ Stage 2: Discussion with Management & TCWG ] ──> Request rectification, disclosure & remediation
│
(Did Management Rectify?)
├── YES ──> Document in audit files; proceed with audit
└── NO
│
▼
[ Stage 3: Evaluate Management Response ] ──> Assess integrity of TCWG & public interest impact
│
▼
[ Stage 4: Determine External Disclosure ] ──> Disclose to external authorities (FRC/ACC/BFIU)
│ (Good-faith disclosure is NOT a breach of confidentiality)
▼
[ Stage 5: Audit Report & Resignation ] ──> Modify audit opinion (ISA 705) / Resign from engagement
Stage 1: Obtaining an Understanding
The auditor must obtain an understanding of the nature of the act and the circumstances in which it has occurred or may occur, evaluating the potential financial and regulatory consequences.
Stage 2: Addressing the Matter with Management and TCWG
The auditor must raise the matter promptly with the appropriate level of management and, where appropriate, Those Charged With Governance (TCWG). The auditor must advise management and TCWG to:
- Take appropriate steps to rectify, remediate, or mitigate the consequences of the non-compliance;
- Deter the commission of the non-compliance if it has not yet occurred; and
- Disclose the matter to an appropriate authority where required by law or regulation.
Stage 3: Evaluating Management's Response
The auditor must evaluate whether management and TCWG have responded appropriately. If management fails to take adequate action, the auditor must evaluate the integrity of management and TCWG and determine whether further action is needed in the public interest.
Stage 4: Determining Whether to Disclose to an External Authority
If management or TCWG fail to rectify the matter or report it to regulators, the auditor must determine whether disclosing the NOCLAR to an external regulatory or enforcement authority (e.g., FRC, ACC, Bangladesh Bank, BSEC) is appropriate in the public interest.
Fundamental Rule: Disclosing NOCLAR to an external authority in good faith does NOT constitute a breach of the duty of confidentiality under the ICAB Code of Ethics.
Stage 5: Impact on Audit Opinion and Engagement Resignation
The auditor must evaluate the impact of the non-compliance on the audit opinion under ISA 705 (Modifications to the Opinion in the Independent Auditor's Report). If management's integrity is fundamentally compromised or if safeguards cannot mitigate the threat, the auditor should consider withdrawing/resign from the engagement.
5. Summary Table: Confidentiality Exceptions & Statutory Reporting
| Exception Scenario | Primary Governing Standard / Act | Reporting Type | Target Authority / Entity | Tipping-off Restrictions |
|---|---|---|---|---|
| Money Laundering / Terrorist Financing | Money Laundering Prevention Act 2012 | Mandatory Statutory Reporting | Bangladesh Financial Intelligence Unit (BFIU) | STRICT PROHIBITION against tipping off client. |
| FRC monitoring, practice review or enquiry into a PIE audit | Financial Reporting Act 2015 | Mandatory response to a statutory information request | Financial Reporting Council (FRC), Bangladesh | Statutory override of confidentiality; cite the Act, not s.40 (that section is the FRC's standard-setting power). |
| Lawful Court Warrant / ACC Summons | Code of Civil Procedure / ACC Act | Mandatory Judicial Compliance | Court of Law / Anti-Corruption Commission | Governed by judicial summons terms. |
| ICAB Quality Inspection | ICAB Bye-Laws 2004 / QAB Rules | Professional Duty | Quality Assurance Board (QAB) Reviewers | Restricted to authorized ICAB reviewers. |
| NOCLAR Unrectified by Client | IESBA Code Sec 360 / ICAB NOCLAR | Discretionary Public Interest | Relevant Industry Regulator (BSEC, BB, FRC) | Good faith disclosure protected from breach claims. |
An auditor conducting a statutory audit in Chittagong discovers clear evidence of illicit money laundering transactions originating from proceeds of trade mis-invoicing. Under the Money Laundering Prevention Act 2012 (MLPA) in Bangladesh, what is the auditor's statutory obligation, and what restriction applies?
Under Subsection 114 of the ICAB Code of Ethics, in which of the following situations is an auditor PERMITTED or REQUIRED to disclose confidential client information without violating professional ethics?
During the audit of a listed manufacturing company, the audit team uncovers massive illegal dumping of toxic chemical waste in violation of environmental laws. Management and TCWG flatly refuse to rectify the breach or notify regulators. Under the NOCLAR framework, what is the auditor's ethical entitlement regarding external reporting?
Which of the following practices would NOT be recommended as a means of securing professional confidentiality?
An audit senior finishes an engagement and, three years later, is asked by a friend about that former client's financial difficulties. What does the duty of confidentiality require?