Corporate Reporting Ethics: Can the Firm Take the Extra Work?
This topic is covered as ETH.4 in our Corporate Reporting Model Answer Notes, which are built entirely from ICAEW Question Bank model answers: https://learn.paradigmshift.training/course/cr-man-2026
A client asks the audit firm to do something else as well. Usually the answer is yes, with safeguards. Occasionally it is no, whatever safeguards you propose. Working out which situation you are in, and saying why, is most of the requirement.
The four steps and the test
Before providing any non-audit service to an audit client, work through four steps.
Identify and assess the significance of the threats. Assess the safeguards available, and include declining the work as one of the options rather than assuming the engagement must somehow be made to work. Apply the third party test. Then communicate the position to those charged with governance and document the rationale for the conclusion reached.
That final step is worth a mark on its own and is regularly left out. The documented rationale is what protects the firm if the decision is questioned later, and it is what the audit committee needs in order to discharge its own responsibilities.
The third party test is the one that decides matters. Would an objective, reasonable and informed third party conclude that objectivity is not impaired? Note the framing. The question is not whether the firm believes it can remain objective. Firms almost always believe that. The question is how the arrangement would look to a well-informed outsider, which is a deliberately harder standard to meet. If you cannot answer yes, safeguards are not enough and the firm declines.
There is one absolute limit. It is never permissible for the firm to undertake a management role. No safeguard cures this, and there is no version of the arrangement that works. If you spot a management role in the scenario, say so plainly and stop looking for a way round it. Candidates who propose separate teams and independent review for what is plainly a management role have demonstrated that they do not understand why the prohibition exists.
Public interest entities narrow the field considerably further. The list of permitted services is restrictive, and the logic is straightforward: if the client is a PIE and the service is not on the permitted list, the firm declines. Two examples that have appeared in the papers are a value-for-money report on cyber security, and designing and implementing financial IT systems. Neither is on the list, so neither can be done, and no discussion of safeguards is required beyond saying so.
Where the service is permitted
Where the work can be taken on, the standard safeguards are separate teams with different reporting lines, and review of both the work itself and the audit engagement by a partner not involved in the audit.
Alongside those sit a set of client-side conditions that matter just as much. The client must accept responsibility for decisions, monitor its internal control, evaluate the results of the work and operate the resulting system. Those conditions are what keep the firm out of the management role, so they are not administrative box-ticking. If the scenario suggests the client is not capable of doing these things, or has no intention of doing them, the management threat has arrived by the back door.
For accounting services provided to a non-PIE, four conditions must all hold. No management role. Not initiating transactions. Requiring little or no professional judgement. Routine or mechanical in nature. All four, not a majority, and the third is usually the one that fails. Preparing a straightforward payroll journal is mechanical. Determining an impairment or a provision is not, whatever the client calls it.
Do not stop at the ethics, either. There are practical questions worth marks in most scenarios. Does the firm actually have the competence to do this work to a proper standard? Are suitable staff available given the audit timetable? What is the reputational risk of sending an individual who is not right for the engagement? And what does the additional fee do to dependency, which takes you straight back to the ten and fifteen per cent thresholds?
Finally, terms should be agreed in an engagement letter with the board, not with the one director who happened to ask. A private arrangement with a single director is a governance problem before it is anything else.
The short version
Four steps, then the third party test. A management role is never permissible, and saying so decisively is better than hedging. A public interest entity plus a service that is not on the permitted list equals decline. Separate teams with independent review are the standard safeguard where the work can properly be taken on, supported by the client accepting responsibility for the decisions.
Structure your answer in that order and it will read like a model answer, because that is the order the model answers use.