Skip to main content

Basel Consolidated Guidelines

This page sets out the guidelines and sound practices issued by the Basel Committee on Banking Supervision (BCBS). The application page outlines the implementation expectations for guidelines and sound practices, and their scope of application.

The consolidated guidelines and sound practices comprise the 13 modules listed below. Each module is divided into chapters. Each chapter includes links to the original source publications from which the contents of the chapter are based, related standards, related guidelines or sound practices, and other publications that are relevant to a particular topic.

Please provide first name.
Looks good!
FRD20

External audit

This chapter describes banks’ external audit function, and the supervisor´s relationships with external auditors and the audit oversight body.
  • Published: 01 Jan 2026

Guidelines

This chapter describes the audit committee’s responsibilities in overseeing the external audit function, and the supervisor´s relationships with external auditors of banks and the audit oversight body.

The contents of this chapter are based on:

Related standards

Related guidelines

  • CGO10 Corporate Governance
  • CAD30 Accounting issues
  • IAC10 Internal audit and control

Foreword

20.1

A bank’s board and management are responsible for ensuring that financial statements are prepared in accordance with the applicable financial reporting framework. They must also ensure that annual financial statements have been audited and include the opinion of an independent external auditor. The audit of the financial statements does not relieve the board or senior management of their responsibilities.

20.2

An external auditor conducts the audit of a bank’s financial statements to obtain reasonable assurance about whether the financial statements are free from material misstatement, whether due to fraud or error. This enables the auditor to:

  1. express an opinion on whether the financial statements are prepared, in all material respects, in accordance with an applicable financial reporting framework; and
  2. report on the financial statements, and communicate as required by internationally accepted auditing standards, in accordance with the auditor’s findings.
20.3

External auditors of banks can play an important role in contributing to financial stability when they deliver quality bank audits which foster market confidence in banks’ financial statements. Quality bank audits are also a valuable input in the supervisory process, as the external auditor has a duty to report/alert directly to the supervisor on matters of material significance.

Key terms

20.4

The following terms are used throughout this chapter and have the meaning given below:

  1. Audit committee: see CGO10.
  2. Banks / banking organisations: a reference to banks or banking organisations, means all banks (including those within a banking group) and holding companies whose subsidiaries are predominantly banks.
  3. Banking supervisor: refers to each of the authorities involved in banking supervision.
  4. Board and senior management: see CGO10.
  5. Duty to report/alert: When required by the law regulatory framework or by formal agreement or protocol, the external auditor should promptly communicate matters arising from the audit that may be of material significance to the supervisor (referred to as “duty to report/alert”). In jurisdictions with such a requirement, the disclosure in good faith to the supervisors by an external auditor of matters of material significance does not constitute a breach of the auditor’s duty of confidentiality.
  6. External auditor: the audit firm and the individual audit engagement team members conducting the audit. Where relevant, specific references are made to the audit firm or the individual audit engagement team members in certain paragraphs.
  7. Financial statement audit: an audit of a bank’s financial statements by an external auditor in accordance with internationally accepted auditing standards.
  8. Internationally accepted auditing standards: in this guidance, all references to internationally accepted auditing standards will be to International Standards on Auditing (ISAs), although the references apply equally to other equivalent internationally accepted auditing standards.
  9. Material significance: requires interpretation in the context of the specific legislation relevant to the regulated entity. A matter or group of matters is normally of material significance to a regulator’s function when, due either to its nature or its potential financial impact, it is likely of itself to require investigation by the regulator. The external auditor should apply professional judgment in determining whether the identified breach is likely to be of significance to the supervisor.
  10. Statutory audit: an audit carried out to comply with the requirements of particular legislation or regulations. In some jurisdictions, this may entail only the financial statement audit. In other jurisdictions, this may also include extended reporting by external auditors on matters such as internal controls and regulatory returns.
  11. Those charged with governance: as defined by internationally accepted auditing standards, the person(s) or organisation(s) with responsibility for overseeing the strategic direction of the entity and obligations related to the accountability of the entity. Such person(s) or organisation(s) is (are) typically the board of directors. Where the board of directors of a bank establishes an audit committee to assist it in meeting its responsibilities by charging the audit committee with specific tasks and responsibilities, the audit committee can be viewed as taking on the role of those charged with governance in relation to those specific tasks and responsibilities.

Scope and application

20.5

Supervisors have a keen interest in the quality with which external auditors perform bank audits. This chapter aims to enhance the quality of external audits of banks and the effectiveness of prudential supervision by:

  1. Promoting an effective two-way communication between the audit committee and the external auditor to enable the audit committee to carry out its oversight responsibilities and to contribute to the effectiveness of the audit process. This also can form the basis for the supervisor’s assessment of the audit committee’s oversight of the bank’s external audit.
  2. Promoting the establishment of open communication channels between the supervisor and the bank’s external auditor.
  3. Supporting the building of effective relationships between prudential supervisors and audit oversight bodies which are responsible for monitoring the quality of statutory audits, thereby promoting cooperation in the discharge of their respective legal duties.
  4. Setting supervisory expectations and recommendations regarding what constitutes a quality audit.
20.6

This chapter outlines supervisory expectations for the external audit, to help banks' audit committees oversee banks' external auditors. These expectations and recommendations also facilitate supervisors’ engagement with external auditors and the relevant audit oversight bodies. The Committee does not have the authority to set professional standards for external auditors. The recommendations should therefore be read alongside the professional standards, which provide additional guidance for the proper application of the standards to audits of banks, including:

  1. International Auditing and Assurance Standards Board (IAASB), Handbook of International Quality Management, Auditing, Review, Other Assurance, and Related Services Pronouncements;
  2. International Auditing Practice Note (IAPN) 1000, Special Considerations in Auditing Financial Instruments;
  3. International Ethics Standards Board for Accountants (IESBA), Handbook of the Code of Ethics for Professional Accountants;
  4. International Standard on Auditing (ISA) 200, Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance with International Standards on Auditing;
  5. International Standard on Auditing 220 (Revised), Quality Management for an Audit of Financial Statements,
  6. International Standard on Auditing (ISA) 230, Audit Documentation;
  7. International Standard on Auditing (ISA) 240, The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements;
  8. International Standard on Auditing (ISA) 250, Consideration of Laws and Regulations in an Audit of Financial Statements;
  9. International Standard on Auditing (ISA) 260 (Revised), Communication with those Charged with Governance;
  10. International Standard on Auditing (ISA) 265, Communicating Deficiencies in Internal Control to Those Charged with Governance and Management;
  11. International Standard on Auditing (ISA) 315 (Revised 2019), Identifying and Assessing the Risks of Material Misstatement;
  12. International Standard on Auditing (ISA) 320, Materiality in Planning and Performing an Audit;
  13. International Standard on Auditing (ISA) 330, The Auditor’s Responses to Assessed Risks;
  14. International Standard on Auditing (ISA) 540 (Revised), Auditing Accounting Estimates, Including Fair Value Accounting Estimates, and Related Disclosures;
  15. International Standard on Auditing (ISA) 570 (Revised), Going Concern;
  16. International Standard on Auditing (ISA) 610 (Revised 2013), Using the Work of Internal Auditors
  17. International Standard on Auditing (ISA) 620, Using the Work of an Auditor’s Expert;
  18. International Standard on Auditing (ISA) 720 (Revised), The Auditor’s Responsibilities Relating to Other Information;
  19. International Standard on Quality Management (ISQM) 1, Quality Management for Firms that Perform Audits and Reviews of Financial Statements, or Other Assurance or Related Services Engagements; and
  20. International Standard on Quality Management (ISQM) 2, Engagement Quality Reviews.
20.7

This chapter acknowledges significant differences in national and institutional frameworks, including accounting, auditing and governance standards. Supervisors are encouraged to address legal and institutional obstacles to implementing the guidelines within their authority and, where necessary, advocate for reforms to enhance their ability to fully apply these guidelines.

Banks’ audit committees and relationships with external auditors

Appointment of the external auditor

20.8

Principle 1: The audit committee should have a robust process for approving, or recommending for approval, the appointment, reappointment, removal and remuneration of the external auditor.

20.9

The audit committee should have the primary responsibility for the appointment, reappointment, removal, and remuneration of the external auditor. In doing so, the audit committee should determine appropriate criteria for selecting the external auditor and regularly assess their knowledge, competence and independence (see Principle 2 below) and the effectiveness of the external audit (see Principle 3 below), having due regard to the supervisory expectations and recommendations in this chapter.

20.10

The audit committee should evaluate risks related to the auditor’s potential withdrawal from the engagement and prepare a response plan.

20.11

The bank’s annual report should explain the approach the audit committee has taken regarding the recommendation of the appointment or reappointment of the external auditor, and include information on the tenure of the incumbent auditor.

20.12

If the board of directors disagrees with the audit committee’s recommendation, the annual report, or any publications by the bank relating to the appointment/reappointment/dismissal of the external auditor, should explain the audit committee’s recommendation and the board’s reasons for taking a different position.

20.13

The audit committee should assess the external auditor’s quality, before its first appointment and at least annually thereafter. This includes reviewing the auditor’s quality management procedures and its compliance with all applicable quality management standards, as well as any significant matters of concern arising from these procedures. The audit committee should also consider, where available, the external audit firm’s annual transparency report and any inspection reports from the audit oversight body.

20.14

The audit committee should stay informed about:the audit firm’s structure and governance, and the current nature of the audit environment (including in jurisdictions abroad where the bank operates). It should also be aware of:

  1. significant concerns raised by the relevant audit oversight body regarding the audit firm, and the auditor’s actions in addressing these concerns, to understand how these issues/concerns may affect the quality of the audit of the bank; and
  2. any regulatory issues that could have an impact on the bank.

It should also consider lessons learned from recent audit failures and how the audit firms have dealt with them.

20.15

The audit committee should satisfy itself that the level of the audit fees is commensurate with the scope of work undertaken and not compromise audit quality. Fee reductions should not lead to higher materiality thresholds, reduced audit scope, or less attention to significant risks without appropriate reason.

20.16

The audit committee should agree on the engagement letter with the external auditor before approval. This letter should be updated for changes in legal requirements or auditing standards.

20.17

If the external auditor resigns or communicates an intention to resign, the audit committee should investigate and consider whether further action is needed.

Independence of the external auditor
20.18

Principle 2: The audit committee should monitor and assess the independence of the external auditor.

20.19

The audit committee should monitor and assess the external auditor’s independence at least annually, considering relevant national laws, regulations and professional requirements. This includes reviewing relationships between the bank and the audit firm (including the provision of non-audit services), any inadvertent violations, and any safeguards established by the external auditor to maintain independence. The audit committee should consider whether, as well as complying with the applicable jurisdictional independence standards, the audit firm also complies with the independence standards applicable to public interest entities in internationally accepted ethical standards (see FRD20.106).

20.20

The audit committee should balance risks between:

  1. long auditor tenure, which can lead to familiarity risk and self-interest threat to the external auditor’s objectivity and independence; and
  2. rapid changes of external auditors, which can reduce their depth of understanding of the bank.
20.21

The audit committee should have a policy in place that stipulates the criteria for tendering the external audit contract. The audit committee should periodically consider putting the audit firm contract out for tender, considering the audit firm’s tenure and potential risks to independence.

20.22

The audit committee should understand the audit firm’s policy on rotation of members of the audit engagement team and the audit firm’s compliance with any jurisdictional or other local regulatory independence requirements in this regard.

20.23

The audit committee should seek assurance that the audit team and firm and, when applicable, the network external auditors have no relationships with the bank which could compromise actual or perceived independence. It should also review at least on an annual basis the audit firm’s policies and processes for maintaining independence.

20.24 The audit committee should develop a policy on non-audit services, specifying the criteria for services the auditor may provide or is prohibited from providing, and when advance approval by the audit committee is required. The policy should be reviewed periodically. IAC10 states that, as a sound practice, banks should not outsource internal audit activities to their own external auditor. Any departure from this best practice should be limited to small banks and should remain within the bounds of the applicable ethical standards for the statutory or external auditor.

20.25

Non-audit services provided by the external auditor should not impair the external auditor’s objectivity and independence. The audit committee should monitor these services and ensure safeguards are in place to mitigate any threat to objectivity and independence.

20.26

Where the external auditor provides non-audit services to the bank, the bank’s annual report (or other relevant publications) should explain to shareholders the nature of these services, the fee incentives for the non-audit services received, and how auditor independence is safeguarded.

Effectiveness of the external audit
20.27

Principles 3: The audit committee should monitor and assess the effectiveness of the external audit.

20.28

At the start of each audit, the audit committee should review the audit approach, scope, materiality level(s), areas of focus, and how the auditor proposes to address areas of significant risks.

20.29

The audit committee should confirm that the audit team has adequate resources and expertise for its engagement. The audit committee should understand the nature and extent to which the external auditor intends to use audit work performed by network firm personnel and other audit firms.

20.30

The audit committee should ensure the audit complies with internationally accepted auditing standards, as well as any applicable laws and regulations.

20.31

The audit committee should:

  1. discuss with the external auditor significant findings of the latter’s work, including those matters that were subsequently resolved as well as those that have been left unresolved and their implications, in particular the external auditor’s explanation of the significant judgments the audit engagement team made and the conclusions reached;
  2. obtain an understanding of the rationale behind the final conclusions drawn by the audit engagement partner on significant accounting and auditing matters; and
  3. review the nature and levels of misstatements identified during the audit, obtaining explanations from management and, where necessary, the external auditor as to why certain errors might remain unadjusted.
20.32

The audit committee should also discuss with the external auditor the statements provided by management in the representation letter to the auditor and ensure they are complete and appropriate.

20.33

The audit committee should discuss with the auditor the audit-related reports, including any management letter (or equivalent), which the external auditor has provided to the bank. In particular, the audit committee should discuss with the external auditor any significant deficiencies in internal control over financial reporting.

20.34

Upon completion of the audit fieldwork, but before the external auditor issues the audit report, the audit committee should review whether the audit plan has been followed and understand any changes made during the audit, including those resulting from changes in the identified risks of material misstatement and the work undertaken by the external auditor to address those risks.

20.35

After the audit, the audit committee should assess its effectiveness, report on the effectiveness of the process to the board of directors and discuss its findings and any recommendations with the board.

20.36

The audit committee should seek feedback from the external auditor, where relevant, on the main findings of audit quality reviews of the bank’s audit and the audit firm’s quality control systems by audit oversight bodies.

Relationship between the audit committee and the external auditor
20.37

Principle 4: The audit committee should have effective communication with the external auditor to enable the audit committee to carry out its oversight responsibilities and to enhance the quality of the audit.

20.38

Regular, timely open communication between the audit committee and the external auditor is essential. Regular dialogue should be held throughout the reporting cycle of the bank.

20.39

While cooperation is important, the audit committee should challenge the external auditor when necessary to ensure robust discussions and stronger and deeper understanding on key issues.

20.40

The audit committee should consider inviting the external auditor to attend audit committee meetings, even when no specific audit topics are on the agenda, to discuss relevant matters. To enhance audit quality, the audit committee should consider, if necessary, assisting the external auditor to gain access to any other committee meetings that the external auditor determines to be relevant for the auditor’s work.

20.41

The audit committee should have the right and authority to meet with the external auditor without executive management, to discuss any issues that arose during the external audit and their resolution.

20.42

The audit committee should discuss with the external auditor any matters arising from the statutory audit that may have an impact on regulatory capital or disclosures.

20.43

The audit committee should discuss with the external auditor any significant issues identified in the course of the audit, including upcoming changes in standards and the consequences of material transactions for the financial reporting processes and performance of the bank.

20.44

The audit committee should communicate matters that are likely to be of significant relevance to the conduct of the statutory audit to the external auditor, including significant communications with the supervisor.

Reporting by the external auditor to the audit committee
20.45

Principle 5: The audit committee should require the external auditor to report to it on all relevant matters to enable the audit committee to carry out its oversight responsibilities.

20.46

In some jurisdictions, auditors must also report on internal controls over financial reporting; this section focusses on reporting to the audit committee in the context of the financial statement audits.

20.47

The external auditor should provide those charged with governance with timely observations on significant matters relevant to their oversight responsibility on the financial reporting process, in line with internationally accepted auditing standards.

20.48

The audit committee should request reporting on key issues (see ISA 260 for examples of key issues).

20.49

The external auditor should also determine whether significant matters need to be communicated to the bank’s governing body.

20.50

Written communications of significant findings between the auditor and those charged with governance is recommended to enhance audit quality and to support supervisory work, even if oral communication is also used.

The relationship between the supervisor and the external auditor

20.51

The key objective of these relationships is to improve the supervision of the banking sector and enhance the quality of external audits. An effective relationship allows both parties to fulfil their responsibilities without implying that one is responsible for the other’s statutory duties.

Effective relationship at the supervised bank level
20.52

The external auditor can provide the supervisor with valuable insight into a bank’s operations, including management’s application of accounting policies and judgments. Conversely, supervisors can share independent assessments that may help the external auditor to focus attention on key areas of concern. In certain jurisdictions, the supervisor may also request the external auditor to perform specific assignments that go beyond the statutory audit work.

20.53

Principle 6: The supervisor and the external auditor should have an effective relationship that includes appropriate communication channels for the exchange of information relevant to carrying out their respective statutory responsibilities.

20.54

Supervisors and external auditors should have an open and constructive relationship ensuring that information shared is treated appropriately and confidentially.

20.55

For effective communication, both parties should engage knowledgeable individuals, who are authorised toc exchange relevant information.

20.56

The supervisor may benefit from the external auditor’s work as they often address similar issues, though with different focuses. The external auditor may also gain useful insights from the supervisor. However, neither party should rely on the other’s work as a substitute for their own and the bank should remain the main source of information for their respective work.

20.57

The terms of this relationship can be determined in individual jurisdictions and should be clear to both parties – for example, through guidance issued by the banking supervisor.

Access to communications with the bank
20.58

The external auditor’s report on financial statements is used for prudential supervisory purposes. During audits, the external auditor communicates significant matters to management or governance bodies, and these communications may also be accessed by the supervisor. In some cases, the external auditor may review the supervisor’s communications to the bank.1

1

The external auditor should review the supervisor’s communications to the bank to help identify instances of non-compliance with laws and regulations that may have a material effect on the financial statements as required by ISA 250.

20.59

The supervisor and the external auditor should consider communicating in writing on matters of potential mutual interest, ensuring these communications are part of the bank’s records and accessible to both parties.

Direct communication at the supervised bank level
20.60

Communication between supervisors and external auditors should include direct written and/or oral communication channels or a combination of both, depending on circumstances.

20.61

Written communication channels may include extended audit reports submitted to the supervisor but not made public.2 In some jurisdictions, these reports may be part of the external auditor’s statutory audit work and may also address prudential supervisory requirements.

2

Ordinarily, such reports would be issued for the attention of the board of directors of the audited bank, but should be delivered to the supervisor as well (directly or through the bank).

20.62

Oral communication channels may involve formal or or ad hoc bilateral meetings between the supervisor and the auditor. Trilateral meetings including the audit committee chair (or an independent non-executive director) may also be held. Bilateral and trilateral meetings are examples of sound practice communication channels, particularly for systematically important banks (SIBs).

Communication of matters outside the scope of the external auditor’s duty to report/alert
20.63

These communication channels can provide supervisors with information outside the external auditor’s formal duty to report/alert (see Principle 7), such as emerging and thematic issues, sector-wide issues or bank-specific matters. Examples of such matters include:

  1. Transactions designed to achieve a particular accounting or regulatory outcome, such that the accounting treatment is technically acceptable, but obscures their substance.
  2. Valuations showing consistent optimism or pessimism, indicating potential management bias.
  3. Significant deficiencies in internal control processes and the external auditor’s observations on matters that are significant to the responsibilities of those charged with governance. This may include, where relevant, their observations on the effectiveness of the internal audit function, the risk management function and the compliance function (where not already required by statute).
  4. Actual or suspected breaches of prudential regulations identified during the audit.
  5. Inconsistencies between financial statements and prudential disclosures.
20.64

Where bilateral and trilateral meetings are held, particularly in the case of SIBs, the timing and content of these meetings could be aligned with the external audit’s planning and concluding phases and/or the supervisory assessment of the bank. These meetings should focus on significant risks and findings.

20.65

The form, frequency and content of the communication between the supervisor and the external auditor of the bank will vary based on jurisdictional circumstances, the bank’s characteristics, and the supervisory model.

Safe harbour available to external auditors
20.66

External auditors are bound by ethical standards to treat much of their audit-related information as confidential. Nevertheless, in jurisdictions where a legal provision protects external auditors from disciplinary proceedings, prosecution and liabilities when making disclosures in good faith to the supervisor (safe harbour), external auditors may share information with the supervisor in good faith without breaching their duty of confidentiality.

20.67

For matters outside the scope of the duty to report/alert discussed in Principle 7, but which may still be of interest to the supervisor, the external auditor communicates these matters either indirectly through the bank, or directly with the bank’s consent, in cases where safe harbour protections do not exist.3

3

In jurisdictions where one does not exist, supervisors should be encouraged to work towards achieving a safe harbour.

Gateways available to supervisors
20.68

The supervisor, subject to confidentiality rules, may share bank-specific information with the external auditor if it supports its supervisory work and improves audit quality. Before sharing information, supervisors should assess its sensitivity and relevance to their duties and the auditor’s work.

20.69

Principle 7: The supervisor should require the external auditor to report to it directly on matters arising from an audit that are likely to be of material significance to the functions of the supervisor.

20.70

Reporting should be conducted directly from the auditor to the supervisor, unless not permitted, in which case reporting should be conducted indirectly through the bank.

Communication of matters within the scope of the external auditor’s duty to report/alert
20.71

When required by the regulatory framework or by formal agreement, the external auditor should promptly communicate matters of material significance to the supervisor (referred to as “duty to report/alert”). In jurisdictions with such a requirement, the disclosure in good faith to the supervisors by an external auditor of matters of material significance does not constitute a breach of the auditor’s duty of confidentiality.4

4

See BCP40.62 (Principle 27, EC9).

20.72

The external auditor typically discusses significant matters with the bank’s management and/or those charged with governance. However, when required to report directly to the supervisor on such matters, the external auditor should not rely on the bank to notify the supervisor.

20.73

Examples of significant matters within the auditor’s duty to report/alert include:

  1. information that indicates the bank’s failure to fulfil one of the requirements for a banking licence or material breaches of laws and regulations or the bank’s articles of association, charter or by-laws;
  2. serious conflicts within the decision-making bodies or unexpected departures of key managers;
  3. material adverse changes in the bank’s risk profile or future risks; and
  4. circumstances requiring modifications to the auditor’s opinion on the financial statements.
20.74

The external auditor should notify the supervisor of their resignation (or intent to resign) or removal by the bank.

Effective relationships at the levels of the audit firm and the accounting profession as a whole
20.75

Both the supervisor and external audit firms obtain information which, when reviewed entirely, can help identify trends and developments indicative of emerging systemic risk. Audit firms may also identify emerging issues, such as inconsistent or inappropriate application of accounting standards. Addressing these issues early will allow external auditors and supervisors to take timely remedial action at the national level and at affected banks to ensure the fair presentation of their financial statements.

20.76

Principle 8: There should be open, timely and regular communication between the banking supervisor, the audit firms, and the accounting profession as a whole, on key risks and systemic issues as well as a regular exchange of views on appropriate accounting techniques and auditing issues.

20.77

The banking supervisor and external audit firms should regularly discuss existing and emerging key risks and systemic issues at the national level. Open communication in a constructive environment is important, and ad hoc meetings should be held when urgent matters arise, to enable timely action.

20.78

Periodic meetings between the supervisor, audit firms, and professional accountancy bodies should address existing and emerging key risks and systemic issues. Discussions may identify key risks, including:

  1. the appropriateness of accounting techniques for new financial instruments and innovation and other aspects of financial innovation; and
  2. issues such as market opacity and impairment evaluations for particular asset classes.

Such discussions can help identify systemic issues and promote consistent application of appropriate accounting policies. It may be beneficial for banking industry associations to be involved in discussions on these topics.

The relationship between the supervisor and the audit oversight body

20.79

The audit oversight body’s main role is to monitor the quality of audits in order to protect the interests of investors or further the public interest.

20.80

Principle 9: There should be regular and effective dialogue between the banking supervisor and the relevant audit oversight body.

20.81

Where an audit oversight body exists, the supervisory authority should maintain regular dialogue with it to address issues related to bank audits.

20.82

Dialogue can occur through formal (eg scheduled regular meetings) and informal channels (eg ad hoc discussions, telephone conversations). Communication should be open, constructive, and two-way.

20.83

Meetings should occur as frequently as necessary to discuss issues of mutual concern or interest arising from each authority’s duties, subject to relevant legal constraints.

20.84

Information exchanges may include topics such as the robustness of audits in areas critical to the supervisor, such as loan loss provisioning, internal controls or risk management. Discussions may also address audit deficiencies identified by the oversight body, its responses and any corrective actions taken by audit firms to improve audit quality.

20.85

Where an appropriate framework for information-sharing is in place, the supervisor may also share concerns about audit quality at specific banks, or general issues with audit firms, such as areas where there can be a significant risk of material misstatement.

20.86

While identifying audit deficiencies is not the supervisor’s primary focus, it should inform the audit oversight body of any matters requiring its attention.

20.87

Discussions should cover not only current issues but also thematic or emerging topics.

20.88

Based on these discussions, the supervisor may take action such as:

  1. raising issues identified by the audit oversight body with individual banks, their external auditors or the professional bodies, encouraging remediation where appropriate; and
  2. initiating thematic reviews to assess the impact of identified issues from a prudential perspective.
20.89

Information shared between the supervisor and the audit oversight body is likely to be subject to legal confidentiality requirements. The receiving party should handle such information accordingly, and consider:

  1. consulting the providing party before sharing the information with third parties and
  2. notifying the other party if required to disclose the information under enforceable legal demands.

Supervisory expectations and recommendations for the external auditor of a bank

20.90

While the primary focus in this section is on the financial statement audit, the external auditor may identify matters during the audit that are relevant to the supervisor and which should be communicated to them.

20.91

In some jurisdictions, as part of the statutory audit, the external auditor may also undertake additional work, such as providing assurance on internal controls or other aspects of a bank’s operations. The supervisory expectations set out in this part of the document provide a relevant reference for such additional work.

Knowledge and competence

20.92

Expectation 1: The external auditor of a bank should have banking industry knowledge and competence sufficient to respond appropriately to the risks of material misstatement in the bank’s financial statements and to properly meet any additional regulatory requirements that may be part of the statutory audit.

20.93

The external auditor of a bank should have specialised knowledge and competence in auditing banks, appropriate to the size, complexity and diversity of banking activities, and the legal and regulatory framework in which banks operate. The auditor should use experts as appropriate.

20.94

Knowledge and competence are critical for exercising professional judgment and carrying out key audit tasks, such as identifying and assessing risks of material misstatement and designing and implementing appropriate responses.

Knowledge
20.95

For banking audits, the audit engagement team should have:

  1. proficient knowledge and practical experience in the banking sector, including its risks, operations and activities and bank audits. This knowledge may come from training, participation in bank audits or work in the banking sector;
  2. proficient knowledge of applicable accounting, assurance and ethical standards, industry practice and relevant guidance;
  3. proficient knowledge of relevant regulatory requirements in areas such as capital and liquidity, and a general understanding of the legal and regulatory framework applicable to banks; and
  4. proficient knowledge and understanding of IT relevant to bank audits.
20.96

Given the complexity of financial reporting requirements, especially for accounting estimates, the external auditor should consider whether to involve experts with specialised skills or knowledge in areas such as loan loss provisions, fair value measurements, and areas with differing interpretation, or newly developing practices.

Competence
20.97

Audit firms should have a documented policy and procedure that sets minimum competency criteria for the bank audit engagement team, considering the roles and experience of different team members.

20.98

Supervisors may have the ability to influence the competency requirements for external auditors. Where specific requirements for bank auditors do not exist, the supervisor may encourage professional and regulatory bodies to introduce training and experience requirements to ensure audit teams for bank audits are sufficiently competent.

Use of experts
20.99

In some cases, expertise in a field beyond accounting or auditing may be needed to support the audit engagement team. This may include complex valuations (eg financial instruments, commercial property), regulatory matters or evaluation of complex IT environments, particularly in areas with significant risks of material misstatement.

20.100

Internationally accepted auditing standards outline the procedures auditors should follow to determine whether to use the work of an expert and ensure the auditor’s expert’s work is adequate for the audit.

20.101

For complex valuation models used in accounting estimates, the external auditor should also consider the following when deciding whether to use an auditor’s expert:5

  1. whether the bank or the industry is introducing new products or structures; and
  2. whether recent events in the bank or the industry have highlighted previously unidentified risks.
5

These considerations are additional to those set out in ISA 620.

Objectivity and independence

20.102

Expectation 2: The external auditor of a bank should be objective and independent in both fact and appearance with respect to the bank.

Objectivity
20.103

Objectivity is a fundamental ethical principle and a key element of audit quality. It requires that the external auditor’s judgment is not compromised because of bias, conflict of interest or the undue influence of others. As objectivity is a state of mind that in most cases cannot be directly observed by users of financial statements, it is important for the external auditor to be independent in both fact and appearance.

Independence
20.104

Ethical standards, both jurisdictional and international provide frameworks to help external auditors achieve and maintain independence.

20.105

Independence means freedom from situations and influences, facts and circumstances where a reasonably informed third party would conclude that an external auditor’s objectivity is impaired. Independence applies not only to the bank being audited but also to its related entities.

20.106

The external auditor of a bank must comply with jurisdictional ethical standards. Whether or not the jurisdictional ethical standards align with internationally accepted ethical standards (eg IESBA), the external auditor of a bank should also comply with the independence standards for public interest entities6 under internationally accepted ethical standards.

6

Public interest entities are defined by IESBA and includes “an entity one of whose main functions is to take deposits from the public”.

20.107

When assessing potential threats to independence, the external auditor should evaluate not only the specific rules, but also the substance of the threat to independence, and how a reasonably informed third party would perceive the situation. Non-assurance services provided by the audit firm or its network firms to the audited bank may create threats to independence and objectivity, which should be carefully evaluated.

20.108

The external auditor should be particularly cautious of self-review threats, when advising management on accounting matters. For example, in cases where complex transactions are structured to achieve specific accounting or regulatory outcome, auditors must ensure they do not take on management’s role or responsibility while providing advice.

Professional scepticism

20.109

Expectation 3: The external auditor should exercise professional scepticism when planning and performing the audit of a bank, having due regard to the specific challenges in auditing a bank.

20.110

Professional scepticism should manifest itself not only through the auditor obtaining corroborating evidence for management’s assertions, but also challenging management’s assertions, considering whether there are alternative accounting treatments that are preferable to those selected by management, and documenting the auditing approach, the evidence obtained, the rationale applied and the conclusions reached.7 Throughout the audit, the auditor adopts a questioning approach when considering information and in forming conclusions.

7

Professional scepticism is defined by the IAASB as “an attitude that includes a questioning mind, being alert to conditions which may indicate possible misstatement due to error or fraud, and a critical assessment of evidence”.

20.111

Professional scepticism is critical in bank audits due to the significance of accounting estimates and the potential for limited objective evidence supporting those estimates. Professional scepticism is particularly important in areas involving:

  1. significant management estimates and judgments, especially with high measurement uncertainty;
  2. non-recurring or unusual transactions; or
  3. areas susceptible to fraud and errors due to weak internal controls.
20.112

Key areas where professional scepticism is essential include impairment calculations, fair value measurements and going concern assessments, including assessments of solvency and liquidity. It is also important for complex transactions that lack substance, or to achieve particular accounting or regulatory outcomes. In such cases, the external auditor should challenge management’s inputs and assumptions, forming independent views and questioning evidence provided by management.

20.113

Where a bank consistently uses valuations that show a pattern of optimism or pessimism within a range of acceptable valuations, the external auditor should consider the risk of management bias. This includes reviewing other areas that might be affected by management bias, such as accounting estimates and classification of financial instruments, that are used for regulatory capital measures. The auditor informs those charged with governance, where appropriate, of any indicators of possible management bias.

20.114

The extent of professional scepticism exercised should be evident in the audit documentation, which should clearly describe the conclusions reached and how they were achieved. Internationally accepted auditing standards set minimum requirements for audit documentation.

Quality control

20.115

Expectation 4: Audit firms undertaking bank audits should comply with the applicable standards on quality control.

20.116

Audit firms should comply with jurisdictional quality management standards. Regardless of jurisdictional standards, audit firms should also comply with the quality management requirements applicable to audits of listed entities under internationally accepted quality management standards.

20.117

The audit of a bank should be subject to an engagement quality review (EQR). The EQR reviewer should be involved from the early stages of the audit, not only at the end. The EQR reviewer should have the necessary competence and capabilities, including sufficient time, and appropriate authority, to perform the role and should review how the engagement team has demonstrated professional scepticism. Such considerations should be documented in the audit working papers. The EQR reviewer should also assess how the audit engagement team has addressed accounting and regulatory information.

20.118

EQR is part of a firm-level quality management system that emphasises quality, consultation and compliance with auditing, ethical, legal and regulatory standards.

20.119

The involvement of the EQR reviewer throughout the audit, and the outcome of the EQR, should be evident in the audit working papers. Robust documentation of the discussions between the EQR reviewer and the audit team on all matters of significant judgment should be included in the working papers. In jurisdictions where the supervisor has access to the external auditor’s working papers, the extent and results of the EQR would also be at the supervisor’s disposal.

Supervisory expectations and recommendations for the audit of a bank’s financial statements

Identifying and assessing significant risks of material misstatement

20.120

Expectation 5: The external auditor of a bank should identify and assess the risks of material misstatement in the bank’s financial statements, considering the complexities of the bank’s activities and the effectiveness of its internal control environment.

Identifying potential risks
20.121

In auditing a bank, the external auditor identifies and assesses risks of material misstatements at both the financial statement and assertion levels. The external auditor also gains an understanding of internal controls relevant to the audit, including the bank’s control environment.

20.122

To address assessed risks of material misstatement, the external auditor follows an audit strategy combining substantive procedures and control testing. Given the high volume of transactions in banks, the external auditor of a bank is expected to test relevant controls over significant financial reporting processes to determine their reliability.

Materiality
20.123

The external auditor needs to apply the concept of materiality appropriately in planning and performing the audit.

20.124

The external auditor exercises professional judgment to determine what is material to the financial statements, focusing on misstatements that could reasonably be expected to influence economic decisions of users taken on the basis of the financial statements.

20.125

Certain financial statement items, such as those used in regulatory ratios (eg leverage, liquidity and capital adequacy ratios) are critical to users. The auditor should consider these ratios when setting materiality thresholds for the audit.

20.126

Even misstatements below materiality thresholds should be carefully evaluated, as they may indicate broader control deficiencies that could lead to material misstatements.

Internal control and its components
20.127

According to internationally accepted auditing standards, the components of internal controls relevant to financial statement audits are:

  1. the control environment;
  2. the entity’s risk assessment processes;
  3. the entity’s process to monitor the system of internal control;
  4. the information system and communication; and,
  5. control activities.
20.128

A robust internal control environment is critical to the strength of a bank’s governance system and its ability to manage risk. The external auditor should assess, amongst other considerations:

  1. management’s commitment to a robust control environment (“tone at the top”);
  2. whether the control environment applies uniformly across operations, subsidiaries and branches of the banking group;
  3. the bank’s approach to outsourcing and how internal control over these activities is maintained;
  4. the organisation of key control functions, such as internal audit, risk management, compliance and other monitoring functions; and
  5. any material gaps in the bank’s control systems and the level of risk tolerance defined by those charged with governance.
20.129

Compensation arrangements can indicate a bank’s culture and risk attitude. The external auditor should pay attention to risks of material misstatement in the financial statements due to fraud, especially where compensation incentivises excessive risk-taking or other inappropriate behaviour.

Control activities
20.130

Understanding control activities relevant to the audit is critical for assessing risks and designing further audit procedures in response to assessed risks. The external auditor should take account of factors such as:

  1. the competence of financial reporting and of other control personnel;
  2. the nature of hedging strategies employed by the bank which, if complex, improperly structured or inadequately monitored, can have accounting and solvency implications;
  3. the use of complex financial instruments involving estimates of fair value based on significant unobservable inputs;
  4. the provision of custodial services and procedures in place to avoid co-mingling of assets;
  5. the volume of transactions by type of activity and the presence of significant non-routine transactions;
  6. the use and monitoring of internal accounts;
  7. IT system complexity and risks of fraud or error;
  8. the number, scope and geographical dispersion of subsidiaries and the necessity for complex consolidation procedures;
  9. related party transactions; and
  10. off-balance sheet financing arrangements, such as special purpose entities (SPEs) and other complex structures.
Internal audit
20.131

When the external auditor uses the work of internal auditors as evidence for the financial statement audit, internationally accepted auditing standards require that they assess its relevance and adequacy. The external auditor should engage with, the internal auditors. This may provide valuable input into the external auditor’s understanding of the entity and its environment and aid in identifying and assessing risks of material misstatement.

20.132

The external auditor should provide written feedback on their interactions with the internal audit function, including, where relevant, its observations on the adequacy of the work of the internal audit function, to those charged with governance. This information is also valuable to the supervisor.

Responding to significant risks of material misstatement

20.133

Expectation 6: The external auditor of a bank should respond appropriately to the significant risks of material misstatement in the bank’s financial statements.

20.134

After identifying significant risks of material misstatement, whether due to fraud or error, at the financial statement level and the assertion level, the auditor designs and implements appropriate responses, including testing controls in the current period that the auditor plans to rely on and performing substantive procedures specific to that risk.

20.135

In addition to the areas set out in FRD20.137 to FRD20.150, certain financial statement items, such as deferred tax assets, investments in unconsolidated entities, pension fund assets and the classification of financial instruments, may be subject to management bias. External auditors should evaluate these items for potential management bias and its impact on regulatory ratios.

20.136

Significant risks in banks change over time. Below is a list of audit areas commonly associated with significant risks of material misstatements, but is not exhaustive.

Loan loss provisioning
20.137

Loan loss provisioning is a key area involving complex judgements about credit risk. The external auditors should consider the following factors in relation to loan loss provisioning and the related allowance for loan losses. This list is not intended to be comprehensive.

  1. The estimation techniques used to compute provisions and how the techniques vary within and amongst banks (where possible).
  2. Whether an appropriate degree of caution has been exercised by management in judging anticipated cash flows and making other assumptions.
  3. All known and relevant impairment indicators for loan exposures which include previously unexpected adverse developments in the market or economic environment, adverse movements in interest rates, restructurings, inadequate underwriting policies adopted by the bank, overdue payments, failure of the borrower to meet budgeted revenues or net income, covenant breaches and forbearance.
  4. Whether the bank has sought perspectives and data from different functions within the bank, including risk management, credit and internal audit, as well as reliable sources external to the bank, including peer data and regulatory perspectives, to consider all relevant and available information in assessing impairment.
  5. Any large differences between provisions for accounting and regulatory purposes to ensure they do not indicate material misstatement of the loan loss provision reported in the financial statements. As the level of accounting provisions may affect the level or composition of regulatory capital, due to the treatment of the tax effect of provisions and the allocation of any excess provision to capital tiers, external auditors should be alert to any management bias in this area.
  6. Disclosures should enable users to assess the loan loss provisioning methodology applied by the bank, including how it relates to credit risk for that bank, and how it compares with methodologies applied across the banking sector.
Financial instruments, including fair value measurements
20.138

Financial instruments measured at fair value may include financial instruments that are subject to an impairment assessment which may be a key area of judgment. Auditors should consider changes in the bank’s portfolio of financial instruments and evaluate the accounting implications.

20.139

Accounting standards for financial instruments contain requirements for recognition; initial and subsequent measurement (including impairment); reclassification from fair value to amortised cost; derecognition; presentation; and disclosures. Auditing financial instruments often requires complex procedures to obtain sufficient appropriate audit evidence to obtain reasonable assurance that the financial statements are not materially misstated. The accounting classification of an individual financial instrument may be particularly important for achieving a favourable regulatory outcome.

20.140

Auditors should adopt a sceptical approach to management’s assumptions for valuing financial instruments with significant unobservable inputs, following guidance such as IAPN 1000, Special considerations in auditing financial instruments.

Liabilities arising from non-compliance with laws and regulations, and contractual breaches
20.141

Non-compliance with laws, regulations or contracts can lead to litigation, penalties or reputational damage. Such events may require recognition of provisions, contingent liabilities and/or qualitative disclosures in the bank’s financial statements. Further, any adverse impact on the bank’s reputation resulting from this non-compliance could have consequences for the bank’s going concern assessment. Auditors should remain alert to such risks.

Disclosures
20.142

Users of financial statements need relevant and extensive qualitative and quantitative disclosures, due to the complexity of transactions and estimates represented in banks’ financial statements. Increased transparency through fairly presented public disclosures enhances market confidence. It is therefore important that the bank provide disclosures that present the bank’s financial condition, identify and describe the risks to which the bank is exposed and how they are managed, and are meaningful and responsive to changes in market conditions and perceived risks.

20.143

The external auditor should assess whether the bank’s disclosures fairly present the bank’s financial condition and risks, particularly with regard to:

  1. the bank’s overall objectives and strategies;
  2. the bank’s control framework for managing its key business risks;
  3. the uncertainties associated with its key business risks; and
  4. all other related information included in the financial statements.
20.144

In some jurisdictions, certain regulatory ratios (eg capital ratios) may be published with banks’ financial statements and are material to a range of users in assessing bank performance. In its audit work, the external auditor should be alert to any indications that the regulatory ratios published with or included in the financial statements are not consistent with the auditor’s understanding of the bank’s risk profile, activities and strategy.

Going concern assessment
20.145

The external auditor is responsible for obtaining sufficient appropriate audit evidence and conclude about the appropriateness of management’s use of the going concern assumption in the preparation of the financial statements and whether there is material uncertainty about the entity’s ability to continue as a going concern. The external auditor should remain alert throughout the audit for evidence of events or conditions that may cast significant doubt on a bank’s ability to continue as a going concern.

20.146

Going concern assessments for banks is different from that likely to be performed for a non-bank entity because of features such as maturity mismatches, credit risk, the potential for regulatory intervention, and market sensitivity. Going concern assessments of banks are unique for the following reasons:

  1. Current emerging risks and concerns specific to the bank or the banking industry may have an adverse impact on projections such that historical trends may not reflect the likely results over the next year. For example, during periods of market turmoil, normal sources of funding may no longer be available, as deposits payable on demand may run off more quickly than historical experience would suggest and such deposits may be difficult to replace.
  2. As banks are highly leveraged, a small change in asset valuation may substantially affect the adequacy of a bank’s regulatory capital. Financial instruments held at fair value may be subject to substantial changes in value in the short term and significant volatility over the longer term. In addition, a significant increase in credit losses due to deteriorating economic conditions may result in the need for substantial additional provisions by the bank. These may contribute to a significant decrease in regulatory capital and may result in a downgrade by rating agencies, making funding more expensive and possibly harder to obtain.
  3. Banks generally derive a significant amount of their funding from short-term deposits and other short-term liabilities. A loss of confidence by depositors and other creditors in a bank’s solvency can quickly result in a liquidity crisis.
20.147

Banks are required to meet liquidity requirements and capital ratios set by the supervisor. The external auditor should evaluate the liquidity and solvency of the bank for the period over which the going concern assumption has been assessed:

  1. Liquidity: Factors to assess include the reasonableness and reliability of the cash forecast for at least 12 months after the date of the financial statements, liquidity risk disclosures, regulatory or contractual restrictions on cash, loan covenants, and pension funding.
  2. Solvency: Given the potential adverse impact of capital adequacy concerns on the confidence in a bank and, as a consequence, on the bank operating as a going concern,8 the external auditor should consider the robustness of the bank’s system for managing capital in response to credit, market and other risks to which the bank is exposed. In addition, the external auditor should consider the capital position in relation to the current and any known future capital requirements, definitions of capital components, and challenges in raising capital. This is particularly critical where capital levels are strained, access to capital resources is restricted or where, for example, the bank’s annual report or internal capital projections include ambitious projections of improvements in capital levels.
8

Non-compliance with capital requirements is one of the examples noted in ISA 570, under other events or conditions that may cast significant doubt about the going concern assumption.

20.148

In assessing management’s assertion that a bank is a going concern, the external auditor should consider at least the following factors:

  1. effectiveness of the bank’s own systems and controls for managing liquidity, capital and market risk;
  2. prudential information reported to supervisors covering the bank’s solvency and capital;
  3. external indicators of liquidity or funding concerns; and
  4. availability of short-term liquidity support.
20.149

If material uncertainties related to events or conditions that may cast significant doubt exist about the bank’s ability to continue as a going concern, the external auditor should promptly notify supervisors.

Securitisations – SPEs
20.150

Securitisations, including special purpose entities (SPEs), require special consideration by the external auditor and are of interest to the supervisor for the following reasons:

  1. Accounting concern: principles-based accounting frameworks often require significant management judgments, which can result in different treatments for complex transactions. For example, SPEs may be structured to remain off the sponsoring bank’s balance sheet. Auditors must evaluate management’s judgments to ensure the accounting treatment is appropriate and that disclosures are sufficient.
  2. Regulatory concern: the complexity of securitisation transactions and financial intermediation can lead to misstatements of the risk transferred or retained by the sponsoring bank. This includes reputational risks which might incentivise the bank to support its securitisations, and conflicts of interest in case of defaults on the securitised assets. Despite these risks, the originator may still achieve off-balance sheet accounting treatment and avoid holding regulatory capital against such exposures unless specifically required by the supervisor or the relevant regulatory rules.

Application of the guidelines and sound practices

  1. The Basel Framework is the full set of standards of the BCBS. The membership of the BCBS has agreed to fully implement these standards and apply them to the internationally active banks in their jurisdiction.1 For other banks, BCBS members may adopt a proportional approach to implementing specific rules and principles under the given standard.
  2. Guidelines elaborate the standards in areas where they are considered desirable for the prudential regulation and supervision of banks, in particular internationally active banks. They generally supplement BCBS standards by providing additional guidance for the purpose of their implementation.
  3. Sound practices generally describe actual observed practices, with the goal of promoting common understanding and improving supervisory or banking practices. BCBS members are encouraged to compare these practices with those applied by themselves and their supervised institutions to identify potential areas for improvement.
  4. The BCBS also publishes various other documents, including implementation reports and newsletters. These documents do not constitute standards, guidelines or sound practices.
  5. The Committee's standards (ie those set out in the Basel Framework) are subject to monitoring and assessment of their adoption by jurisdictions through the Regulatory Consistency Assessment Programme (RCAP). The Basel Core Principles are used in assessing the effectiveness of countries' regulatory and supervisory regimes, generally under the Financial Sector Assessment Program (FSAP). Guidelines, sound practices and other publications are not subject to RCAPs or FSAPs.
  6. The Committee periodically reviews its guidelines and sound practices as standards, supervisory practices and the financial system evolve. The consolidated guidelines and sound practices are intended to be a living document, which will be updated when the Committee publishes new materials.
  7. Unless otherwise indicated, the guidelines have been developed with a view towards application to: (i) large, internationally active banks; and (ii) supervisory and other relevant financial authorities in Basel Committee member jurisdictions. However, smaller banks and authorities in all jurisdictions may benefit from considering the guidelines and applying them on a proportionate basis, depending on the size, complexity and risk profile of the bank or banking sector for which the authority is responsible.

1 The Core Principles for effective banking supervision (Basel Core Principles) are also a standard and form part of the Basel Framework but are applicable to all jurisdictions and all banks.

This module describes expectations to combat money laundering and terrorist financing.

This module describes expectations and practices relating to capital adequacy.

This module describes expectations for corporate governance.

This module describes expectations for credit risk and counterparty credit risk management.

This module describes expectations for external audit and sets out references related to public disclosure.

This module describes expectations for banks’ internal audit and compliance functions.

This module describes expectations for liquidity risk management.

This module sets out references related to market risk and interest rate risk.

This module describes expectations for the management of operational risk and operational resilience.

This module describes expectations for the management of problem assets and expected credit losses.

This module describes the application of proportionality in prudential regulation and supervision.

This module describes expectations for risk management.

This module describes the nature and application of prudential supervision.

You might also be interested in