Corporate Reporting Ethics: Governance, and Who the Code Applies To

This topic is covered as ETH.12 in our Corporate Reporting Model Answer Notes, which are built entirely from ICAEW Question Bank model answers: https://learn.paradigmshift.training/course/cr-man-2026

Governance is not strictly an ethics topic. It is examined alongside ethics so consistently, and the two feed each other so directly, that it is worth revising as part of the same block. A company with weak governance is a company where ethical problems go unchallenged, and the scenarios are built on that connection.

The failures that keep appearing

The papers reuse a familiar set of weaknesses, and you will usually find two or three of them in any scenario.

The chair and chief executive roles combined in one person, so that nobody holds the executive to account. No non-executive directors at all, or non-executives who are not independent because of a past employment relationship, a consultancy arrangement or a family connection. Board meetings cancelled, poorly attended, or decisions taken without being properly minuted. A single dominant individual who controls the board, often the founder, whose judgement nobody is willing to question.

Then a second group. Key vacancies left unfilled, most commonly no finance director, which puts financial reporting decisions in the hands of people not qualified to take them. A principal risk delegated below board level, so that the people accountable for it have no authority to address it. A minority shareholder or a fellow director sidelined from decisions they should be part of. And remuneration set without a transparent, objective process, typically by the person who benefits from it.

Listing these is worth a little. Explaining why each one matters, in the context of the company in front of you, is worth considerably more. A dominant chief executive matters because it removes the challenge that would otherwise catch an aggressive accounting judgement. Say that, rather than simply noting that the roles are combined.

Which code applies

This is where answers most often go wrong, and it is a point of pure knowledge that costs marks unnecessarily.

The UK Corporate Governance Code applies to premium listed companies. AIM companies are not required to comply with it, and examiners have specifically recorded candidates wrongly asserting that it applied directly. Getting this wrong undermines everything that follows, because you have measured the company against a standard it was never subject to.

AIM companies are not exempt from governance requirements, though, and the balanced answer says both halves. Since September 2018 they have been required to comply with, or explain non-compliance with, a recognised corporate governance code. That need not be the UK Corporate Governance Code, and several alternatives are used in practice.

Where a company does comply with a code, non-compliance with any of its provisions must be disclosed and explained in the compliance statement. That explanation is examinable in its own right. In the Spring & Hare scenario a directors' share scheme with a vesting period of under five years was a departure from the Code requiring explanation, and the auditor should flag it to the audit committee. Comply or explain does not mean comply or ignore, and a departure that goes unexplained is itself a breach.

Applying the Code within subsidiaries, including overseas ones, is best practice rather than a requirement. Say so if the scenario invites it, because it is the kind of qualification that distinguishes a candidate who knows the scope of the rules from one who is applying them everywhere by default.

Why the auditor cares

This is the link back to ethics and to the audit, and it is the part candidates most often skip. Every governance weakness is also an audit risk.

Weak governance means an increased risk of management override of controls, since the checks that would ordinarily prevent it are absent. It means reduced reliability of management representations, because those representations come from the people whose conduct is in question. And it means less transparency to the board, which in turn means less transparency to the auditor.

The response is to raise concerns with those charged with governance under ISA 260, and to reconsider your risk assessment and the extent and nature of your planned testing. A governance answer that stops at describing the weaknesses has done half the work and taken half the marks.

So, four things to hold onto. Premium listed only for the Code itself. AIM needs a recognised code, and has done since September 2018. Comply or explain, with the explanation itself capable of being examined. And treat every governance weakness as an audit risk with consequences for your planned procedures.

Get the scope point right and you protect the marks that a confident but incorrect assertion about AIM companies would otherwise throw away.

Previous
Previous

Corporate Reporting Ethics: Report It, JUST Don't Mention It

Next
Next

Corporate Reporting Ethics: Don't Lose the Action Marks