01 Sep
01Sep

On December 10, 2025, the UK Financial Reporting Council (FRC) announced an investigation into Ernst & Young LLP (EY UK) and two individual members in relation to the unauthorised issuance of auditor’s reports to audited entities. EY informed the regulator that it had identified and notified the relevant audited entities, remediated the relevant audit files and concluded that no adjustments to the related financial statements or audit opinions were required. The FRC also stressed that opening an investigation does not itself constitute a finding of misconduct.


The case raises an unusual but important question: How can an audit report be issued without proper authorisation, yet the financial statements do not need to be restated and the audit opinion does not need to change?


The answer lies in separating three matters that are often treated as if they were the same: the financial statements, the audit opinion and the process by which the auditor’s report is authorised and issued.


The financial statements are prepared by management and those charged with governance. Whether they require restatement depends principally on whether they contain material errors or omissions. The audit opinion is the auditor’s conclusion, based on sufficient appropriate audit evidence, about whether those financial statements are prepared in accordance with the applicable financial reporting framework. The issuance of the auditor’s report, however, is also subject to legal, professional and firm-level authorisation requirements.


An error in the third process does not automatically prove that the first two were wrong.


For example, imagine that an audit team has completed all necessary procedures, management has corrected identified material misstatements, the engagement partner has reached an appropriate unmodified opinion and sufficient evidence exists to support that conclusion. If the final report is nevertheless released through a process that did not obtain a required approval, the release-control failure may be serious, but it does not automatically create a new accounting error in the client’s financial statements.


The same distinction applies to the opinion. If the underlying audit evidence already supported an unmodified opinion, correcting a defect in the report-authorisation process may not require changing that opinion. This appears to be the distinction reflected in EY’s statement to the FRC: the firm concluded that remediation of the affected audit files was necessary, but that the related financial statements and audit opinions did not require adjustment.


Importantly, the FRC’s December 2025 announcement did not publicly disclose the detailed mechanics of how the reports became unauthorised, the identities of the affected audited entities, or precisely which internal approval was missing. It would therefore be inappropriate to assume that a particular partner, manager or technology system “pressed the wrong button.” The regulatory investigation concerns the unauthorised issuance itself; its detailed cause and responsibility remain matters for the investigation.
Nevertheless, the case provides a useful opportunity to understand who is responsible for an auditor’s report.


Under UK company law, an auditor’s report must state the auditor’s name and be signed and dated. Where the statutory auditor is an audit firm, the report must be signed by the senior statutory auditor in his or her own name for and on behalf of the audit firm. The senior statutory auditor must also be eligible for appointment as auditor of the company.


ISA (UK) 700 similarly requires the auditor’s report to be signed. For listed entities, the engagement partner’s name must generally appear in the auditor’s report.


The date is equally important. ISA (UK) 700 requires the auditor’s report to be dated no earlier than the date on which sufficient appropriate audit evidence has been obtained to support the opinion, all financial statements and disclosures have been prepared, and those with recognised authority have accepted responsibility for them. Under the UK requirements, the report date is the date on which the auditor signs the report.


This means that the signature and report date are not merely administrative details added at the end of an audit. They represent an important boundary in the audit process. By signing the report, the auditor is effectively confirming that the audit has reached the point at which an opinion can properly be expressed.


In practice, large audit firms normally build additional internal controls around this point. Depending on the engagement, these may include completion of outstanding review notes, technical consultations, independence confirmations, review of subsequent events, final evaluation of uncorrected misstatements, management representations, approval of the financial statements, completion of required quality reviews and formal engagement-partner approval.

The exact workflow differs by firm and engagement, but the principle is the same: a report should not become externally available simply because someone has access to the PDF.
This distinction becomes even more important in a digital environment. Twenty years ago, “signing an audit report” might literally have meant applying a signature to a printed document. Today, a report may move through electronic audit systems, digital signatures, document portals, company annual-report production systems and regulatory filing platforms.


The operational act of uploading or transmitting the file can therefore be separated from the professional decision to authorise its issuance. An administrative employee or technology process may physically transmit an authorised document, but that does not mean that person has the professional authority to decide that the auditor’s report is ready to be issued.


This is why strong report release controls matter. A well-designed audit workflow should make it difficult for a final signed report to leave the firm before all mandatory conditions have been satisfied. Ideally, the system should distinguish clearly between “draft,” “approved for signature,” “signed” and “authorised for release.”

 Access rights should prevent unauthorised individuals from changing the report or issuing it prematurely, and there should be an audit trail showing who approved each critical stage and when.
The issue is not limited to the engagement partner. It is also a matter of the firm’s system of quality management. ISQM (UK) 1 requires audit firms to design and operate systems of quality management covering areas including governance and leadership, ethical requirements, resources, engagement performance, information and communication, and monitoring and remediation. The FRC supervises firms’ implementation of these quality-management requirements.


Where an engagement quality review is required, there is an additional safeguard. ISQM (UK) 2 requires the quality reviewer to evaluate significant judgments and conclusions, and the firm’s policies must prevent the engagement partner from dating the report until the engagement quality review has been completed.
This illustrates why “Who pressed Release?” may actually be the wrong first question. A better question is: What combination of professional approval, system controls and firm-level safeguards should have made an unauthorised release impossible?


If a report can be issued without the required approval, auditors should investigate more than the individual event. Was access to the reporting system too broad? Could someone bypass the normal workflow? Was approval recorded outside the audit system? Could a signed report be downloaded before final clearance? Were responsibilities between the engagement team and administrative support unclear? Did the system distinguish between signing and external release? Could the same failure have affected other engagements?


These are classic root-cause questions. The EY case is also useful because it demonstrates that restatement is not the automatic remedy for every audit-process failure. Restatement addresses errors in previously issued financial statements. If the financial statements themselves were not materially misstated, changing those numbers merely because the auditor had a report-authorisation problem would not solve the actual problem.


Likewise, changing an audit opinion would only be appropriate if the auditor’s conclusion about the financial statements should have been different. If subsequent review confirms that sufficient appropriate evidence supported the original opinion, the appropriate remediation may instead concern the audit file, the report-issuance process, affected clients and the firm’s controls.


That does not make an unauthorised report trivial. The auditor’s report is the formal communication of the audit firm’s professional conclusion to shareholders and other users. Firms therefore need strong controls over who can approve, sign, date and issue it. A failure at that final stage can undermine confidence in the audit process even where the underlying financial statements happen to remain correct.


Audit Committees should understand this distinction as well. When informed of a report-issuance issue, they should not ask only, “Does the company need to restate?” They should also understand whether the audit opinion remains supported, which approval requirement failed, whether the report needs to be reissued or otherwise remediated, whether regulatory notification is required and what controls the audit firm is implementing to prevent recurrence.


For audit firms, the practical lesson is particularly relevant as audit delivery becomes increasingly digital. The final-report process should have controls at least as robust as controls over significant audit judgments. A firm that protects complex valuation models but allows a final audit report to be released without effective authorisation has protected the analysis but not the final product.


In summary, an unauthorised auditor’s report and an incorrect audit opinion are not necessarily the same thing. A financial statement restatement addresses incorrect financial reporting. A modified or changed opinion addresses an incorrect audit conclusion. An unauthorised issuance may instead represent a failure in the governance, approval or release process surrounding the auditor’s report.


The December 10, 2025 EY UK investigation therefore provides a useful reminder that the final step in an audit is not merely “Save as PDF and Send.” The auditor’s report must be supported by sufficient evidence, properly signed and dated, and issued only after the required professional and firm-level approvals have been completed.


The simplest rule for an audit firm is: many people may help prepare and transmit the Audit Report, but the authority to conclude that it is ready to be issued must never be ambiguous.


ธันวาคม 2025 — ใครมีอำนาจกดปุ่ม Release Audit Report จริง ๆ? บทเรียนจากกรณี EY UK


เมื่อวันที่ 10 ธันวาคม 2025 Financial Reporting Council หรือ FRC ของสหราชอาณาจักรประกาศเปิดการสอบสวน Ernst & Young LLP หรือ EY UK และบุคคลสองราย เกี่ยวกับการ ออก Auditor’s Reports ให้แก่กิจการที่รับการตรวจสอบโดยไม่ได้รับอนุญาตอย่างถูกต้อง EY แจ้ง FRC ว่าได้ระบุกิจการที่ได้รับผลกระทบ แจ้งกิจการเหล่านั้น แก้ไขแฟ้มงานสอบบัญชีที่เกี่ยวข้อง และสรุปว่าไม่จำเป็นต้องปรับปรุงงบการเงินหรือเปลี่ยนความเห็นของผู้สอบบัญชี ทั้งนี้ FRC ย้ำว่าการเปิดสอบสวนยังไม่ได้หมายความว่ามีข้อสรุปว่าบุคคลหรือสำนักงานดังกล่าวกระทำผิด


กรณีนี้ทำให้เกิดคำถามที่น่าสนใจมากว่า รายงานของผู้สอบบัญชีออกไปโดยไม่ได้รับอนุญาต แต่เหตุใดงบการเงินจึงไม่ต้อง Restate และ Audit Opinion จึงไม่ต้องเปลี่ยน?


คำตอบอยู่ที่การแยกสามเรื่องออกจากกัน ได้แก่ ความถูกต้องของงบการเงิน ความถูกต้องของความเห็นผู้สอบบัญชี และความถูกต้องของกระบวนการอนุมัติและออกรายงานผู้สอบบัญชี


งบการเงินเป็นความรับผิดชอบของฝ่ายบริหารและผู้มีหน้าที่กำกับดูแล การจะต้องปรับย้อนหลังหรือไม่จึงขึ้นอยู่กับว่างบที่ออกไปมีข้อผิดพลาดหรือการเปิดเผยข้อมูลที่ขาดหายอย่างมีสาระสำคัญหรือไม่


ความเห็นของผู้สอบบัญชีเป็นข้อสรุปที่เกิดจากหลักฐานการสอบบัญชีว่า งบการเงินจัดทำตามกรอบการรายงานทางการเงินที่เกี่ยวข้องหรือไม่ หากหลักฐานที่มีอยู่เพียงพอและเหมาะสม และข้อสรุปเดิมถูกต้อง ความเห็นนั้นก็อาจยังถูกต้องอยู่
แต่การ “ออก” รายงานเป็นอีกกระบวนการหนึ่ง ซึ่งต้องเป็นไปตามกฎหมาย มาตรฐานวิชาชีพ และขั้นตอนควบคุมของสำนักงานสอบบัญชี
ดังนั้น ความผิดพลาดในเรื่องที่สามไม่ได้พิสูจน์โดยอัตโนมัติว่าสองเรื่องแรกผิดด้วย


ตัวอย่างเช่น สมมติทีมสอบบัญชีทำวิธีตรวจที่จำเป็นครบถ้วน ฝ่ายบริหารแก้ข้อผิดพลาดที่มีสาระสำคัญแล้ว ผู้สอบบัญชีที่รับผิดชอบงานได้ข้อสรุปว่าควรแสดงความเห็นแบบไม่มีเงื่อนไข และมีหลักฐานเพียงพอรองรับข้อสรุปนั้น แต่รายงานฉบับสุดท้ายกลับถูกส่งออกไปโดยขาดขั้นตอนอนุมัติบางอย่าง ความบกพร่องของกระบวนการออกเอกสารอาจเป็นเรื่องสำคัญ แต่ไม่ได้สร้างข้อผิดพลาดใหม่ขึ้นในงบการเงินของลูกค้าโดยอัตโนมัติ


หลักเดียวกันใช้กับความเห็นผู้สอบบัญชี หากหลักฐานเดิมรองรับความเห็นนั้นอยู่แล้ว การแก้ปัญหาเรื่องขั้นตอนการอนุมัติรายงานไม่จำเป็นต้องเปลี่ยนความเห็นเสมอไป ซึ่งสอดคล้องกับข้อมูลที่ EY แจ้งต่อ FRC ว่า แม้ต้องแก้ไขแฟ้มงานที่เกี่ยวข้อง แต่บริษัทสรุปว่าไม่จำเป็นต้องปรับงบการเงินหรือความเห็นสอบบัญชี


อย่างไรก็ตาม ต้องระมัดระวังไม่คาดเดาข้อเท็จจริงเกินกว่าที่ FRC เปิดเผย ประกาศเดือนธันวาคม 2025 ไม่ได้บอกรายละเอียดว่าเหตุใดรายงานจึงถูกออกโดยไม่ได้รับอนุญาต ไม่เปิดเผยรายชื่อกิจการที่เกี่ยวข้อง และไม่ได้ระบุว่าขั้นตอนอนุมัติใดเป็นขั้นตอนที่ขาดหายไป จึงยังไม่ควรสรุปว่า Partner, Manager หรือระบบใดเป็นผู้ “กดผิดปุ่ม” จนกว่าการสอบสวนจะมีข้อสรุปเพิ่มเติม
แต่กรณีนี้ช่วยให้เข้าใจหลักการสำคัญว่า ใครเป็นผู้มีอำนาจต่อรายงานของผู้สอบบัญชี


ภายใต้กฎหมายบริษัทของสหราชอาณาจักร รายงานของผู้สอบบัญชีต้องระบุชื่อผู้สอบบัญชี ลงนาม และลงวันที่ หากผู้สอบบัญชีที่ได้รับแต่งตั้งเป็นสำนักงานสอบบัญชี ผู้สอบบัญชีตามกฎหมายที่รับผิดชอบงานต้องลงนามด้วยชื่อตนเอง ในนามของสำนักงานสอบบัญชี และบุคคลนั้นต้องมีคุณสมบัติที่สามารถเป็นผู้สอบบัญชีของบริษัทดังกล่าวได้


ISA (UK) 700 ก็กำหนดให้รายงานผู้สอบบัญชีต้องมีลายมือชื่อ และสำหรับกิจการจดทะเบียนโดยทั่วไปต้องเปิดเผยชื่อ Engagement Partner ในรายงานด้วย


วันที่ในรายงานก็ไม่ใช่เพียงวันที่พิมพ์ไว้บนกระดาษ มาตรฐานกำหนดว่ารายงานไม่ควรลงวันที่ก่อนวันที่ผู้สอบบัญชีได้รับหลักฐานการสอบบัญชีที่เพียงพอและเหมาะสมเพื่อรองรับความเห็น งบการเงินและการเปิดเผยข้อมูลทั้งหมดต้องจัดทำเสร็จ และผู้มีอำนาจต้องยอมรับความรับผิดชอบต่องบการเงินแล้ว ภายใต้ข้อกำหนดของสหราชอาณาจักร วันที่รายงานคือวันที่ผู้สอบบัญชีลงนามในรายงานนั้น


ดังนั้น การลงนามและลงวันที่ไม่ใช่งานธุรการในขั้นตอนสุดท้าย แต่เป็นจุดสำคัญที่แสดงว่า งานสอบบัญชีได้เดินมาถึงระดับที่ผู้สอบบัญชีพร้อมแสดงความเห็นอย่างเป็นทางการแล้ว


ในทางปฏิบัติ สำนักงานสอบบัญชีขนาดใหญ่มักมีด่านควบคุมเพิ่มเติมก่อนออกรายงาน เช่น ต้องปิดประเด็นสอบบัญชีสำคัญ ทบทวนรายการที่ยังไม่ได้แก้ไข พิจารณาเหตุการณ์ภายหลังวันสิ้นงวด ได้รับหนังสือรับรองจากฝ่ายบริหาร ตรวจสอบความเป็นอิสระ ปิดข้อหารือทางเทคนิค และได้รับการอนุมัติตามระดับที่สำนักงานกำหนดก่อนออกรายงาน
รายละเอียดของแต่ละสำนักงานแตกต่างกัน แต่หลักการสำคัญเหมือนกันคือ รายงานผู้สอบบัญชีไม่ควรออกสู่ภายนอกได้เพียงเพราะมีใครคนหนึ่งสามารถเปิดไฟล์ PDF ได้


เรื่องนี้ยิ่งมีความสำคัญในยุคดิจิทัล ในอดีตการลงนามรายงานอาจหมายถึง Partner เซ็นกระดาษด้วยตนเอง แต่ปัจจุบันรายงานอาจผ่านระบบงานสอบบัญชี ลายมือชื่ออิเล็กทรอนิกส์ ระบบจัดเก็บเอกสารของลูกค้า ระบบจัดทำรายงานประจำปี และระบบนำส่งข้อมูลของหน่วยงานกำกับดูแลหลายขั้นตอน
จึงต้องแยกระหว่าง “ผู้ที่ส่งไฟล์ออกไปทางเทคนิค” กับ “ผู้ที่มีอำนาจทางวิชาชีพในการอนุมัติว่ารายงานพร้อมออกแล้ว”


เจ้าหน้าที่ธุรการหรือระบบอัตโนมัติอาจเป็นผู้ส่งเอกสารที่ได้รับอนุมัติแล้วได้ แต่ไม่ได้หมายความว่าบุคคลหรือระบบนั้นมีอำนาจตัดสินใจเองว่า งานสอบบัญชีเสร็จและพร้อมออกรายงาน


นี่คือเหตุผลที่สำนักงานควรมีระบบควบคุมการออก Auditor’s Report ที่ชัดเจน เช่น แยกสถานะเอกสารระหว่างร่าง รออนุมัติ อนุมัติให้ลงนาม ลงนามแล้ว และอนุมัติให้ออกภายนอก กำหนดสิทธิผู้ใช้งานไม่ให้บุคคลที่ไม่มีอำนาจสามารถเปลี่ยนหรือส่งรายงานก่อนเวลา และมีหลักฐานย้อนหลังได้ว่าใครอนุมัติแต่ละขั้นตอน เมื่อใด


ปัญหานี้จึงไม่ได้เป็นเพียงความรับผิดชอบของ Engagement Partner แต่เกี่ยวข้องกับระบบบริหารคุณภาพของสำนักงานด้วย ISQM (UK) 1 กำหนดให้สำนักงานมีระบบบริหารคุณภาพครอบคลุมเรื่องการกำกับดูแลและภาวะผู้นำ จริยธรรม ทรัพยากร การปฏิบัติงาน การสื่อสาร ตลอดจนการติดตามและแก้ไขข้อบกพร่อง ซึ่ง FRC มีการติดตามการดำเนินงานของสำนักงานในเรื่องเหล่านี้
สำหรับงานที่ต้องมีผู้สอบทานคุณภาพงานเป็นพิเศษ ยังมีด่านเพิ่มอีกชั้นหนึ่ง ภายใต้ ISQM (UK) 2 สำนักงานต้องมีนโยบายไม่ให้ผู้สอบบัญชีที่รับผิดชอบงานลงวันที่ในรายงานก่อนที่การสอบทานคุณภาพงานจะเสร็จสมบูรณ์และประเด็นที่ผู้สอบทานตั้งข้อสังเกตได้รับการจัดการแล้ว


ดังนั้น คำถามว่า “ใครเป็นคนกด Release?” อาจยังไม่ใช่คำถามที่ดีที่สุด
คำถามที่สำคัญกว่าคือ “ระบบควบคุมอะไรควรมีอยู่เพื่อทำให้รายงานที่ยังไม่ได้รับอนุญาตไม่สามารถถูก Release ได้ตั้งแต่แรก?”
หากรายงานสามารถออกไปได้โดยไม่มีการอนุมัติครบ สำนักงานควรตรวจหาสาเหตุที่แท้จริง เช่น สิทธิการเข้าถึงระบบกว้างเกินไปหรือไม่ สามารถข้ามลำดับการอนุมัติได้หรือไม่ การอนุมัติเกิดนอกระบบจนไม่มีหลักฐานหรือไม่ รายงานที่ลงนามแล้วสามารถถูกดาวน์โหลดก่อนการอนุมัติขั้นสุดท้ายหรือไม่ หน้าที่ระหว่างทีมสอบบัญชีกับฝ่ายสนับสนุนไม่ชัดเจนหรือไม่ และความบกพร่องเดียวกันอาจเกิดกับลูกค้ารายอื่นหรือไม่


นี่คือเหตุผลที่ปัญหาลักษณะนี้ควรถูกทำ Root Cause Analysis ไม่ใช่เพียงแก้ไฟล์แล้วจบ


กรณี EY ยังช่วยอธิบายว่า ไม่ใช่ทุกความผิดพลาดในกระบวนการสอบบัญชีจะต้องแก้ด้วยการ Restate งบ
การ Restate มีไว้แก้ไขงบการเงินที่เคยออกไปแล้วและพบว่ามีข้อผิดพลาดอย่างมีสาระสำคัญ หากตัวเลขและการเปิดเผยข้อมูลเดิมถูกต้องอยู่ การเปลี่ยนตัวเลขในงบเพราะสำนักงานสอบบัญชีมีปัญหาในขั้นตอนการออก Auditor’s Report ก็ไม่ได้แก้ต้นเหตุของปัญหา


เช่นเดียวกัน การเปลี่ยน Audit Opinion ควรเกิดเมื่อข้อสรุปของผู้สอบบัญชีที่มีต่องบควรแตกต่างจากเดิม หากเมื่อทบทวนแล้วพบว่าหลักฐานที่มีอยู่ยังเพียงพอและรองรับความเห็นเดิม การแก้ไขอาจต้องไปอยู่ที่แฟ้มงาน ขั้นตอนอนุมัติ ระบบการออกเอกสาร การแจ้งลูกค้าที่ได้รับผลกระทบ และระบบควบคุมของสำนักงานแทน


แต่ไม่ได้หมายความว่าการออก Auditor’s Report โดยไม่ได้รับอนุญาตเป็นเรื่องเล็ก รายงานผู้สอบบัญชีเป็นการสื่อสารอย่างเป็นทางการจากสำนักงานต่อผู้ถือหุ้นและผู้ใช้งบว่า ผู้สอบบัญชีได้ข้อสรุปอย่างไรจากงานที่ทำ การควบคุมว่าใครสามารถอนุมัติ ลงนาม ลงวันที่ และออกเอกสารดังกล่าวจึงเป็นส่วนสำคัญของ Audit Quality


คณะกรรมการตรวจสอบเองก็ควรเข้าใจความแตกต่างนี้ หากได้รับแจ้งเหตุการณ์ลักษณะดังกล่าว ไม่ควรถามเพียงว่า “ต้อง Restate งบหรือไม่?” แต่ควรถามต่อว่า ความเห็นเดิมยังมีหลักฐานรองรับครบหรือไม่ ขั้นตอนอนุมัติใดที่ล้มเหลว ต้องออก Auditor’s Report ใหม่หรือแก้ไขอย่างไร ต้องแจ้งหน่วยงานใดหรือไม่ และสำนักงานแก้ระบบควบคุมอย่างไรเพื่อป้องกันไม่ให้เกิดซ้ำ


สำหรับสำนักงานสอบบัญชี บทเรียนยิ่งมีความสำคัญเมื่อกระบวนการทำงานเปลี่ยนเป็นระบบดิจิทัลมากขึ้น การควบคุมขั้นตอนสุดท้ายในการออก Auditor’s Report ควรมีความเข้มแข็งไม่แพ้การควบคุมดุลยพินิจสำคัญระหว่างงาน เพราะหากสำนักงานตรวจแบบจำลองมูลค่ายุติธรรมอย่างละเอียดทุกขั้นตอน แต่กลับสามารถปล่อยรายงานฉบับสุดท้ายออกไปโดยไม่มีการอนุมัติที่เหมาะสม ก็เท่ากับควบคุมกระบวนการตรวจได้ดี แต่ไม่ได้ควบคุม “ผลผลิตสุดท้าย” ของงาน


โดยสรุป Auditor’s Report ที่ออกโดยไม่ได้รับอนุญาต ไม่ได้หมายความว่า Audit Opinion ผิดโดยอัตโนมัติ และไม่ได้หมายความว่างบการเงินต้อง Restate เสมอไป การ Restate ใช้แก้ความผิดพลาดของงบการเงิน การเปลี่ยนความเห็นใช้เมื่อข้อสรุปของผู้สอบบัญชีควรเปลี่ยน ส่วนการออก Auditor’s Report โดยไม่ได้รับอนุญาตอาจเป็นความบกพร่องของกระบวนการอนุมัติ การกำกับดูแล หรือระบบควบคุมการออกรายงานของสำนักงาน


กรณี EY UK ที่ FRC ประกาศสอบสวนเมื่อวันที่ 10 ธันวาคม 2025 จึงเป็นเครื่องเตือนใจว่า ขั้นตอนสุดท้ายของ Audit ไม่ใช่เพียง “Save PDF แล้ว Send” รายงานต้องมีหลักฐานเพียงพอรองรับ ลงนามและลงวันที่อย่างถูกต้อง และที่สำคัญต้องได้รับการอนุมัติตามกระบวนการที่กำหนดก่อนออกไปถึงผู้ใช้งบ
หลักคิดที่สำคัญที่สุดสำหรับ Audit Firm คือ หลายคนอาจมีส่วนช่วยจัดทำและส่ง Auditor’s Report ได้ แต่ต้องไม่มีความคลุมเครือว่าใครเป็นผู้มีอำนาจตัดสินใจว่า “รายงานฉบับนี้พร้อมออกแล้ว”

External References

  • Financial Reporting Council — 10 December 2025, investigation into two members and Ernst & Young LLP concerning the unauthorised issuance of auditor’s reports.
  • UK Companies Act 2006 — Sections 503–504, signature of the auditor’s report and senior statutory auditor requirements.
  • Financial Reporting Council — ISA (UK) 700, requirements concerning the engagement partner, signature and auditor’s report.
  • Financial Reporting Council — ISA (UK) 700, requirements concerning the date of the auditor’s report and sufficient appropriate audit evidence.
  • Financial Reporting Council — Systems of Quality Management Monitoring under ISQM (UK) 1 and ISQM (UK) 2.
Comments
* The email will not be published on the website.