Corporate Reporting Ethics: Naming the Right Threat to the Auditor

This topic is covered as ETH.2 in our Corporate Reporting Model Answer Notes, which are built entirely from ICAEW Question Bank model answers: https://learn.paradigmshift.training/course/cr-man-2026

You are not being asked to invent ethical theory in the exam. You are being asked to recognise a fact pattern you have seen before, name the threat correctly, and explain why it arises on these facts. The scenarios repeat from sitting to sitting with the names changed. Once you can spot them on sight, this becomes one of the more reliable sources of marks in the paper, because the recognition takes seconds and the explanation writes itself.

The patterns that keep coming back

Self-interest shows up in four main guises. Fee dependency, where the client is large enough relative to the firm that losing it would hurt. A low audit tender made in the expectation of profitable consultancy work to follow. Reluctance to jeopardise a large or prestigious client relationship, which is the firm's own position rather than an individual's. And a straightforward financial interest held in the client by someone connected to the engagement.

Not every financial interest is fatal, though, and saying so earns marks. In one scenario a junior team member held units in a tracker fund that included the client's listed parent company. That was assessed as not significant, for three reasons worth learning: the holding was indirect, held through a fund rather than directly; her role on the engagement was junior; and the investment was in the parent rather than in the client itself. The skill being tested is judgement, not reflex. A candidate who treats every mention of a shareholding as a disqualifying interest is not demonstrating the thing the marker is looking for.

Self-review is the rule that you cannot audit your own work. It appears as preparing accounting entries, valuations or hedge documentation and then auditing them. As designing or implementing financial IT systems and then placing reliance on those systems. As giving tax advice and then auditing the resulting balances and provisions. And as providing assurance over controls that the audit will later rely upon. The common thread is that the firm would be checking its own judgement, and no amount of care makes that check independent.

Management threat is where the firm takes a decision that belongs to the client. Acting in place of a finance director where none is appointed. Making the client's accounting policy choices rather than advising on them. Providing loan staff, which is prohibited even for private companies, a point candidates often assume applies only to listed clients. This is the threat most frequently missed altogether, and it matters because it is the one that cannot be cured by safeguards.

Familiarity covers long association with the client, social relationships between the two teams, a former engagement team member joining the client, and the acceptance of hospitality. In the Vacance scenario, the partner's hotel stays were paid for by the client, which raises a Bribery Act question alongside the independence one. Hospitality is usually two issues rather than one, and answers that spot both stand out.

Intimidation covers threats about fees, reappointment or the award of other work, pressure to accept a materiality level or a reporting timetable that would compromise the audit, and the dominant director who complains about junior staff asking awkward questions. Note that intimidation rarely arrives as an explicit threat in these scenarios. It is usually implied, and the fact that nobody said anything actionable out loud does not stop it being a threat.

Advocacy covers promoting the client's position to the point that objectivity is compromised. In KK the firm audited the acquirer and was then asked to review another firm's due diligence on the same transaction, which would put it in the position of defending a deal it must later audit the accounting for.

How to write it up

Recognise the pattern first, then name the threat, then explain why it arises on these facts rather than in general terms. That third step is where the marks concentrate. A list of threat names with no link to the scenario is a very common script and a low-scoring one, because it demonstrates that you have learnt the Code without being able to apply it.

Where an interest is not significant, say so and say why, using the same reasoning the model answers use: how direct is it, how senior is the person, and how close is the connection to the audited entity. Where a threat is significant, do not stop at naming it. Follow it into the safeguards, and be willing to conclude that safeguards are not enough. Management threats in particular cannot be safeguarded away, so an answer that proposes separate teams for one has misdiagnosed the problem.

One final piece of technique. Where two threats arise from the same fact, say both. Hospitality raises familiarity and bribery. A former team member joining the client raises familiarity and a question about the work they did while negotiating the job. Scenarios are constructed so that the richer answer is available to anyone who keeps reading past the first thing they recognise.

Previous
Previous

Corporate Reporting Ethics: The Two Fee Numbers You Have to Know

Next
Next

Corporate Reporting Ethics: Getting the Framework Right