7.2 Compliance Auditing: Legality, Regularity & ISSAI 400/4000
Key Takeaways
ISSAI 400 and ISSAI 4000 govern public sector compliance auditing, evaluating whether activities, transactions, and information adhere in all material respects to established legal and administrative authorities.
EU audit reporting commonly treats legality and regularity together: legality concerns authority in law, while regularity concerns compliance with applicable rules and conditions; sound financial management is a separate performance concept.
The EU compliance audit criteria hierarchy comprises EU primary law (Treaties), the EU Financial Regulation (Regulation 2024/2509), sector-specific fund rules (CAP and CPR), public procurement Directives (Directive 2014/24/EU), and contractual agreements.
Compliance work may be structured as an attestation engagement or a direct reporting engagement; the classification depends on who measures or evaluates the subject matter against the criteria.
Non-compliance findings are classified as quantitative errors (measurable financial impacts entering the estimated error rate, such as ineligible costs or unlawful direct procurement awards) or qualitative breaches (systemic, procedural, or transparency non-compliance).
7.2 Compliance Auditing: Legality, Regularity & ISSAI 400/4000
Core Principle: In constitutional governance, public money cannot be spent simply because an executive official considers an objective desirable. Every euro disbursed from the public treasury must be authorized by democratically enacted law, allocated through formal budgetary appropriations, and executed in strict adherence to statutory rules. Public sector compliance auditing verifies that the executive branch respects the limits of its legal authority, providing assurance to legislatures and citizens that public administration operates under the rule of law.
1. The INTOSAI Compliance Auditing Framework: ISSAI 400 & ISSAI 4000
The International Organization of Supreme Audit Institutions (INTOSAI) codifies compliance auditing in the INTOSAI Framework of Professional Pronouncements (IFPP):
- ISSAI 400: Fundamental Principles of Compliance Auditing: Establishes the conceptual foundation, core objectives, and ethical requirements governing compliance audit engagements across all Supreme Audit Institutions (SAIs).
- ISSAI 4000: Compliance Audit Standard: Provides the detailed operational standard for planning, executing, evaluating evidence, and reporting on compliance audits.
Definition and Objective of Compliance Auditing
Under ISSAI 400, compliance auditing is an independent, objective, and reliable examination of whether a particular subject matter (activities, financial transactions, operational systems, or information) adheres in all material respects to the governing authorities identified as audit criteria.
While commercial audits focus primarily on the fair presentation of financial balance sheets, public sector audit mandates routinely compel SAIs—such as the European Court of Auditors (ECA) and national audit courts—to examine the legality and regularity of underlying transactions.
The Three Parties in Compliance Auditing
In compliance auditing, the engagement revolves around three distinct parties:
- The Auditor: The independent audit institution (e.g., the ECA or a national Supreme Audit Institution) responsible for collecting evidence and delivering an objective audit conclusion.
- The Responsible Party: The executive body, ministry, European Commission Directorate-General, or national managing authority responsible for executing the budget and adhering to governing authorities.
- The Intended Users: The legislative body (such as the European Parliament and Council), parliamentary budgetary control committees, and the public, who rely on the audit report to exercise oversight and grant budgetary discharge.
2. Legality and Regularity
EU audit reporting commonly treats legality and regularity together: transactions must comply with the applicable legal and regulatory framework. A useful analytical distinction is that legality concerns authority in law, while regularity concerns compliance with the relevant rules and conditions. The boundary is not absolute, and sound financial management is a separate performance concept rather than the definition of regularity.
Auditors identify the applicable criteria—Treaties, the current Financial Regulation, sector legislation, financing decisions, contracts and valid national rules—and evaluate both quantitative and qualitative non-compliance.
3. Hierarchy of Authorities and Criteria in EU Compliance Audits
Compliance audit criteria represent the benchmarks against which the auditor evaluates actual evidence. In the audit of the EU budget, criteria are organized into a strict legal hierarchy:
LEVEL 1: PRIMARY EU LAW (Treaties)
Articles 310-325 TFEU: Budgetary principles, sound financial management, fight against fraud
|
LEVEL 2: GENERAL FINANCIAL LEGISLATION
The EU Financial Regulation (Regulation 2024/2509): Budget execution, grants, procurement
|
LEVEL 3: SECTOR-SPECIFIC REGULATIONS
Common Agricultural Policy (CAP) Regulations, Common Provisions Regulation (CPR - ERDF, ESF+)
|
LEVEL 4: HARMONIZATION DIRECTIVES
Public Procurement Directives (Directive 2014/24/EU, Directive 2014/25/EU)
|
LEVEL 5: OPERATIONAL & CONTRACTUAL INSTRUMENTS
Grant Agreements, Contribution Agreements, National Managing Authority Guidelines
Quality Characteristics of Compliance Criteria (ISSAI 400)
Under ISSAI 400, criteria must exhibit five fundamental quality characteristics to serve as valid audit benchmarks:
- Relevance: Meaningful and logically connected to the specific expenditure or activity being examined.
- Completeness: Sufficient to encompass all critical factors needed to determine compliance (not omitting essential conditions).
- Reliability: Objective and stable, yielding consistent conclusions when applied by different auditors to identical facts.
- Neutrality / Objectivity: Free from bias, ambiguity, or subjective political distortion.
- Understandability: Clearly formulated, publicly accessible, and unambiguous to both the auditor and the auditee.
4. Direct Reporting vs. Attestation Engagements
ISSAI 400 and ISSAI 4000 classify compliance audits into two distinct operational models based on who evaluates compliance first:
Attestation Engagements
- Mechanism: The responsible party (such as a national Managing Authority or Paying Agency) measures its own performance against the criteria and presents a formal statement of compliance or management declaration.
- Auditor's Role: The auditor gathers evidence on whether management's statement is fairly presented in all material respects, issuing an audit conclusion that attests to management's declaration.
- EU Example: In the Common Agricultural Policy (CAP), the Director of each national Paying Agency submits an annual Management Declaration certifying that control systems functioned effectively and expenditure was legal and regular. The independent national Certification Body performs an attestation audit to deliver an opinion on the accuracy of the director's management declaration.
Direct Reporting Engagements
- Mechanism: The responsible party does not prepare a formal assertion or statement of compliance for the audit. Instead, the auditor directly evaluates the subject matter against the criteria.
- Auditor's Role: The auditor identifies the criteria, examines the underlying transactions and systems directly, formulates findings, and issues a compliance report containing conclusions and recommendations addressed directly to the legislature and public.
- EU Example: The classification of a particular ECA engagement as direct reporting or attestation depends on the subject matter and criteria. The DAS provides Treaty-based conclusions on accounts and underlying transactions; avoid reducing its institutional design to a single generic example.
5. Quantitative vs. Qualitative Non-Compliance Findings
When compliance auditors identify deviations between actual conditions and governing criteria, they formulate non-compliance findings. In public sector audit methodology, these findings fall into two major categories:
Quantitative Non-Compliance (Measurable Financial Errors)
Quantitative non-compliance occurs when a transaction breaches governing rules in a manner that results in an exact, quantifiable monetary misstatement charged to the public budget:
- Ineligible Expenditure: Costs declared that do not meet regulatory eligibility criteria. Examples include expenditure incurred outside the project eligibility window, costs unrelated to project objectives, or items specifically excluded by sector rules (such as recoverable VAT declared as an eligible grant cost).
- Missing Essential Documentation: Expenditure claims unsupported by essential primary evidence—such as missing supplier invoices, absent proof of payment, or missing delivery notes verifying that goods were physically received.
- Ineligible Beneficiaries: Grants awarded to entities that fail statutory qualification requirements (e.g., an enterprise that exceeds the employee and turnover ceilings for SME subsidies).
- Severe Public Procurement Breaches with Financial Impact: Awarding a major public contract through an unlawful direct negotiation procedure without competitive tendering, or applying unlawful discriminatory selection criteria that excluded eligible competitors.
Impact on Audit Reporting: In ECA audits, all quantifiable financial errors are evaluated against financial materiality (customarily set at 2% for the EU budget). Measurable errors are statistically extrapolated across the sampling strata to calculate the estimated level of error, determining whether the audit opinion on legality and regularity must be modified (qualified or adverse).
Qualitative Non-Compliance (Procedural & Governance Breaches)
Qualitative non-compliance occurs when an entity breaches a legal or procedural requirement, but the breach does not produce a direct, measurable monetary loss to the public budget:
- Breach of Transparency and Publication Deadlines: Failing to publish a required contract award notice in the Official Journal of the European Union (Tenders Electronic Daily - TED) within the statutory 30-day deadline, even though the underlying competitive tender was otherwise conducted properly.
- Procedural Recordkeeping Deficiencies: Incomplete minutes of the tender evaluation committee, or failure to record the formal justification for selecting specific evaluation milestones.
- Inadequate Management Verification Trails: Managing authorities failing to document administrative desk checks (Article 74 verifications under the Financial Regulation) in a manner that allows third-party reconstruction, even where underlying project deliverables are physically present.
Impact on Audit Reporting: While qualitative breaches are not incorporated into the mathematical calculation of the quantitative error rate, they are critical to the auditor's evaluation of the internal control environment. Pervasive qualitative non-compliance indicates systemic administrative breakdown, leading to targeted audit recommendations, governance warnings in Special Reports, and potential reservations in Annual Activity Reports.
In public sector auditing under ISSAI 400 and ISSAI 4000, what is the core conceptual distinction between 'legality' and 'regularity'?
Legality applies exclusively to private contractors, whereas regularity applies exclusively to European Commission Directors-General
Legality emphasizes authority in law, while regularity addresses compliance with the applicable rules and conditions; they are commonly reported together
Legality concerns mathematical accuracy in double-entry bookkeeping, whereas regularity evaluates whether projects satisfy performance indicators
Legality requires zero error rates, whereas regularity allows public bodies to disburse funds without supporting invoices
How does a direct reporting engagement differ from an attestation engagement in public sector compliance auditing under ISSAI 400?
An attestation engagement requires oral testimony in court, whereas a direct reporting engagement consists solely of email memos
An attestation engagement is restricted to performance audits, whereas a direct reporting engagement evaluates only criminal statutes
In a direct reporting engagement, the auditor directly evaluates the subject matter against criteria and reports the findings, whereas in an attestation engagement, the responsible party first measures the subject matter and presents a statement of compliance for the auditor to evaluate
In an attestation engagement, the auditor assumes executive management of the audited entity, whereas in a direct reporting engagement, external consultants conduct the testing
When the European Court of Auditors conducts a compliance audit on agricultural or cohesion spending, what forms the applicable criteria hierarchy?
Informal guidelines published by private commercial consultancies and press releases
Voluntary corporate social responsibility charters and local municipal ordinances
National customary traditions and informal agreements between project beneficiaries
EU Treaties, the EU Financial Regulation, sector-specific fund regulations, public procurement directives, and specific grant agreements
In an annual compliance audit of the EU budget, how does the European Court of Auditors distinguish between quantitative and qualitative non-compliance findings?
Quantitative non-compliance involves measurable financial errors (such as ineligible expenditure or direct contract awards without competition) that are included in the estimated error rate, whereas qualitative non-compliance covers procedural or governance breaches that do not directly quantify a monetary loss
Quantitative non-compliance applies only to customs duties, while qualitative non-compliance applies to European Parliament travel allowances
Quantitative non-compliance results in automatic imprisonment, whereas qualitative non-compliance requires the auditor to reimburse the European Commission
Quantitative non-compliance can only be identified by external private audit firms, whereas qualitative non-compliance is identified exclusively by national police agencies
Sections you finish are checked off in the contents.