6.2 Consideration of Laws, Regulations & Non-Compliance (AU-C 250 & NOCLAR)

Key Takeaways

  • AU-C 250 divides laws and regulations into Category 1 (direct and material effect on financial statement amounts/disclosures) and Category 2 (indirect operating compliance).
  • For Category 1 laws (tax statutes, pension regulations), the auditor has the identical affirmative responsibility as for errors and fraud: obtaining sufficient appropriate audit evidence regarding compliance.
  • For Category 2 laws (environmental, OSHA, FDA, antitrust), the auditor's proactive responsibility is strictly limited to specified procedures: inquiring of management and inspecting correspondence with regulatory authorities.
  • Under Section 10A, after the auditor reports a material uncorrected illegal act to the board, the issuer must notify the SEC within one business day; lacking a copy, the auditor furnishes its report next business day.
  • The AICPA NOCLAR standard directs CPAs who encounter non-compliance affecting the public interest to evaluate appropriate response steps, escalating to governance and evaluating external disclosure or resignation when substantial public harm threatens.
Last updated: September 2026

6.2 Consideration of Laws, Regulations & Non-Compliance (AU-C 250 & NOCLAR)

Core Principle: An entity's management and Those Charged With Governance (TCWG) bear primary responsibility for ensuring that company operations comply with applicable laws and regulations. Under AU-C 250 (Consideration of Laws and Regulations in an Audit of Financial Statements), the auditor's responsibility is to obtain reasonable assurance that the financial statements are free from material misstatement caused by non-compliance. The auditor is not an insurer or guarantor of client legal compliance, nor is the auditor responsible for preventing non-compliance. GAAS establishes a critical operational bifurcation based on how a legal framework interacts with the financial statements.


1. The Two Categories of Laws and Regulations Under AU-C 250

Auditing standards divide all statutory, regulatory, and administrative legal frameworks into two distinct categories, establishing fundamentally different evidence-gathering thresholds for each:

                                  LAWS AND REGULATIONS (AU-C 250)
                                                 |
                   +-----------------------------+-----------------------------+
                   |                                                           |
        [ CATEGORY 1: DIRECT EFFECT ]                               [ CATEGORY 2: INDIRECT EFFECT ]
                   |                                                           |
       Direct & material impact on                                  Operating compliance laws
       amounts and disclosures                                      (environmental, safety, licensing)
                   |                                                           |
         AUDITOR RESPONSIBILITY:                                     AUDITOR RESPONSIBILITY:
       Same as for Errors & Fraud                                  LIMITED to Specified Procedures
       Obtain sufficient appropriate audit                         1. Inquire of management / TCWG
       evidence regarding compliance                               2. Inspect regulatory correspondence

Comprehensive Comparison: Category 1 vs. Category 2

DimensionCategory 1: Direct and Material EffectCategory 2: Indirect Effect / Operating Compliance
DefinitionLaws and regulations recognized as having a direct and material effect on the determination of material amounts and disclosures in financial statements.Laws and regulations that govern operating aspects of the business rather than financial reporting, but non-compliance may have a material indirect effect on financial statements.
Statutory Examples- Internal Revenue Code & state/local corporate tax statutes (income taxes, ASC 740)<br>- Pension and employee benefit laws (ERISA)<br>- Statutory financial reporting frameworks for life insurers or commercial banks<br>- Federal Acquisition Regulation (FAR) cost-allowability rules for defense contractors- Environmental Protection Agency (EPA / CERCLA) hazardous waste laws<br>- Occupational Safety and Health Administration (OSHA) worker safety rules<br>- Food and Drug Administration (FDA) clinical trial and manufacturing standards<br>- Antitrust and anti-monopoly statutes<br>- State professional and commercial operating licenses<br>- Equal Employment Opportunity (EEOC) and labor statutes
Potential Impact on Financial StatementsDirect misstatement of recorded tax provisions, deferred tax assets/liabilities, pension obligations, or cost-plus contract revenues.Fines, penalties, forced operational shutdowns, customer boycotts, material litigation loss contingencies (ASC 450), asset impairments, or going concern threats.
Auditor's Proactive ResponsibilityIdentical to errors and fraud. The auditor must design and execute audit procedures to obtain sufficient appropriate audit evidence regarding compliance with the relevant provisions of these laws.Strictly limited to specified procedures:<br>1. Inquire of management and TCWG whether the entity is in compliance.<br>2. Inspect correspondence, if any, with relevant licensing or regulatory authorities.
Substantive Testing RequirementAffirmative substantive testing is mandatory (e.g., recalculating tax provisions, testing pension actuarial schedules).No affirmative duty to design or perform audit procedures to detect non-compliance unless specific information comes to the auditor's attention.

Exam Trap: Memorize this distinction thoroughly! If the exam asks about an environmental spill or an OSHA safety violation, candidates often incorrectly select that the auditor must perform detailed compliance testing. The correct answer is that the auditor's proactive duty is strictly limited to inquiry and inspecting regulatory correspondence.


2. Auditor Responses to Identified or Suspected Non-Compliance

When the auditor becomes aware of information concerning an instance of non-compliance or suspected non-compliance—whether identified through audit procedures, whistleblower complaints, regulatory investigations, or management disclosures—the auditor must execute a structured investigative response:

+-------------------------------------------------------------------------------------------------------+
|                      INVESTIGATIVE PROTOCOL FOR SUSPECTED NON-COMPLIANCE                              |
|                                                                                                       |
|   1. UNDERSTAND THE ACT         2. EVALUATE FINANCIAL IMPACT    3. DISCUSS WITH MANAGEMENT & TCWG     |
|   Inquire into the legal        Assess fines, penalties,        Present facts to management at least  |
|   nature of the transaction     litigation accruals (ASC 450),  one level above, and escalate to      |
|   and surrounding facts         impairments, and going concern  Audit Committee if serious/material   |
|                                                                                                       |
|   4. LEGAL CONSULTATION         5. RE-EVALUATE AUDIT RISK       6. ASSESS REPORTING OBLIGATIONS       |
|   Consult client's legal counsel Assess integrity of management Determine impact on audit report     |
|   and auditor's independent     and reconsider reliance on      and evaluate Section 10A / NOCLAR     |
|   legal advisors                representations and controls    external reporting duties             |
+-------------------------------------------------------------------------------------------------------+

Step-by-Step Response Actions

  1. Obtain an In-Depth Understanding: Inquire into the nature of the act, the circumstances under which it occurred, and obtain sufficient other information to evaluate the possible effect on the financial statements.
  2. Evaluate Financial Statement Implications: Determine whether non-compliance requires accounting recognition or disclosure:
    • Does the entity face substantial statutory fines or civil penalties?
    • Is an accrual or disclosure required for a loss contingency under ASC 450?
    • Are operating assets impaired (e.g., a manufacturing line rendered illegal by emissions standards)?
    • Does potential revocation of an operating license threaten the entity's going concern viability?
  3. Discuss with Management & Governance: Discuss the matter with the appropriate level of management (at least one level above those involved) and, when appropriate, Those Charged With Governance (the Audit Committee). If senior management or executive officers are implicated, the auditor bypasses management and reports directly to the Audit Committee.
  4. Consult Legal Counsel: If management does not provide adequate information confirming compliance, the auditor should consult with the client's internal or external legal counsel. If the client's counsel fails to resolve the matter, or if the auditor questions management integrity, the auditor should consult the auditor's own legal counsel to evaluate legal obligations, potential liability, and necessary audit actions.
  5. Re-evaluate Risk Assessment & Representations: Consider the implications of non-compliance in relation to other aspects of the audit, particularly the auditor's risk assessment and the reliability of written management representations.

3. Impact on the Auditor's Report & Potential Withdrawal

Non-compliance can directly impair the audit report through two primary mechanisms:

1. Material Misstatement (GAAP Departure) -> Qualified or Adverse Opinion

If the non-compliance has a material effect on the financial statements and has not been properly accounted for or disclosed (e.g., management refuses to accrue a material, probable fine, or fails to disclose a devastating regulatory sanction):

  • Qualified Opinion: If the misstatement is material but not pervasive.
  • Adverse Opinion: If the misstatement is both material and pervasive to the financial statements as a whole.

2. Scope Limitation (Inability to Obtain Evidence) -> Qualified or Disclaimer

If the auditor is precluded by management or circumstances from obtaining sufficient appropriate audit evidence to evaluate whether non-compliance that is material to the financial statements has occurred or is likely to have occurred:

  • Qualified Opinion: If the lack of evidence is material but not pervasive.
  • Disclaimer of Opinion: If the lack of evidence is both material and pervasive.

3. Withdrawal from the Engagement

If the client refuses to accept the auditor's modified report, or if management and TCWG demonstrate a fundamental lack of integrity regarding illegal conduct, the auditor should consider withdrawing from the engagement and communicating the reasons in writing to Those Charged With Governance.


4. Communication with Governance & Third-Party Reporting Exceptions

Communication with Those Charged With Governance (TCWG)

Under AU-C 250, the auditor must communicate with TCWG all matters involving non-compliance that come to the auditor's attention during the audit, other than matters that are clearly inconsequential. If the auditor suspects that senior management or TCWG themselves are involved in non-compliance, the auditor must communicate with the next higher level of authority (such as an independent audit committee or board of overseers).

External Reporting & Client Confidentiality

The AICPA Code of Professional Conduct (ET 1.700.001) strictly protects client confidentiality. The auditor is ethically barred from disclosing non-compliance to external third parties (such as law enforcement or regulatory agencies), except under specific statutory, regulatory, or professional provisions:

+-------------------------------------------------------------------------------------------------------+
|                                 SECTION 10A STATUTORY REPORTING TIMELINE                              |
|                              (Securities Exchange Act of 1934 - Public Companies)                     |
|                                                                                                       |
|   DAY 1: Auditor determines uncorrected illegal act has a material financial statement effect and    |
|          senior management / board have failed to take timely, appropriate remedial action.           |
|          --> Auditor immediately issues formal report to the Board of Directors.                      |
|                                                                                                       |
|   DAY 2 (Within 1 Business Day):                                                                      |
|          --> The Board must notify the SEC of the auditor's report AND furnish a copy to auditor.     |
|                                                                                                       |
|   DAY 3 (Within 1 Business Day thereafter):                                                           |
|          --> IF auditor does NOT receive copy of Board notice within 1 business day:                  |
|              AUDITOR MUST DIRECTLY FURNISH A COPY OF REPORT TO THE SEC WITHIN 1 BUSINESS DAY          |
|              (or resign from the audit engagement and immediately furnish report to the SEC).        |
+-------------------------------------------------------------------------------------------------------+

Critical External Reporting Triggers

  1. Section 10A of the Securities Exchange Act of 1934: As illustrated above, for public companies, Section 10A creates an affirmative legal duty overriding client confidentiality if the board fails to report material uncorrected illegal acts to the SEC.
  2. Subpoena or Court Order: The auditor must comply with a legally enforceable court summons, subpoena, or grand jury order.
  3. Successor Auditor Communications: Under AU-C 210, when authorized by the client, the auditor discusses matters of legal non-compliance with a prospective successor auditor.
  4. Government Auditing Standards (Yellow Book): Under GAGAS or federal grant agreements, direct external reporting to federal inspector generals or funding agencies is required when management fails to report known fraud or illegal acts as prescribed by law.

5. AICPA NOCLAR Standard (ET 1.180 & 2.180)

The AICPA adopted the Non-Compliance with Laws and Regulations (NOCLAR) interpretation in the AICPA Code of Professional Conduct to align US ethical standards with international benchmarks established by the International Ethics Standards Board for Accountants (IESBA):

Scope and Purpose of NOCLAR

NOCLAR provides a structured decision-making framework for CPAs in public practice (ET 1.180) and CPAs in business (ET 2.180) who encounter known or suspected non-compliance involving laws and regulations that directly affect:

  • Public health and safety
  • Environmental protection
  • Prevention of bribery, corruption, and money laundering
  • Securities markets and investor protection
  • Banking and financial product offerings
  • Tax and pension liabilities

The NOCLAR Framework Protocol

  1. Obtain an Understanding: Understand the matter, applicable legal provisions, and potential consequences for stakeholders.
  2. Address the Matter with Management: Advise management and TCWG to take timely and appropriate action to rectify, remediate, or mitigate the consequences of non-compliance, disclose the matter to appropriate authorities where required, and deter commission of future acts.
  3. Assess Management's Response: Evaluate the timeliness, completeness, and appropriateness of management's remedial measures.
  4. Determine Further Action: If management fails to respond adequately, the CPA must evaluate whether further action is necessary in the public interest. Considerations include:
    • The nature and severity of the harm to investors, creditors, employees, or the public.
    • Whether withdrawing from the engagement is warranted.
    • Whether disclosing the matter to an appropriate external authority is permitted or required by law.

Key Principle: Under AICPA NOCLAR, disclosing non-compliance to an external regulatory authority against client wishes is permissible only when authorized by law or regulation (such as Section 10A or federal whistleblower protection provisions). Where disclosure is not legally mandated or authorized, client confidentiality remains binding, and the CPA's primary professional remedy is withdrawal from the professional engagement.

Test Your Knowledge

An auditor is evaluating the client's compliance with laws and regulations under AU-C 250. The client operates chemical manufacturing plants subject to strict environmental discharge regulations enforced by the Environmental Protection Agency (EPA). Which of the following statements correctly describes the auditor's proactive responsibility regarding these operating environmental regulations?

A
B
C
D
Test Your Knowledge

An auditor auditing an SEC-registered public company discovers evidence indicating that an illegal bribe was paid to foreign officials to secure a major international contract. The auditor immediately reports the matter to the board of directors. Under Section 10A of the Securities Exchange Act of 1934, what is the sequence of reporting obligations if the board fails to take timely and appropriate remedial action regarding this material illegal act?

A
B
C
D
Test Your Knowledge

Under the AICPA Code of Professional Conduct regarding Non-Compliance with Laws and Regulations (NOCLAR), what is the overarching objective and expectation for a CPA in public practice who encounters known or suspected non-compliance involving toxic waste dumping into a municipal water supply?

A
B
C
D
Test Your Knowledge

In an audit of a corporate entity, an auditor evaluates compliance with both state corporate income tax statutes and federal workplace safety (OSHA) regulations. Under AU-C 250, how do the auditor's evidence-gathering responsibilities differ between these two regulatory frameworks?

A
B
C
D