22 Aug
22Aug

If an accounting employee, Finance Director or CFO intentionally deletes a company’s accounting and financial records following a dispute and the information cannot be recovered, the matter should be treated as a major corporate crisis rather than merely an IT problem. The incident may affect compliance with accounting laws, preparation of financial statements, tax filings, relationships with banks, creditors and customers, and the external audit. If the entity is listed, or is a subsidiary of a foreign listed group, the consequences can extend further to the stock exchange, securities regulator, shareholders, the foreign parent company and the group auditor.


The most important principle is that misconduct by an employee does not automatically release the company from its own legal obligations. The company remains responsible for maintaining accounting records, preparing financial statements, filing tax returns and providing information required by regulators. At the same time, the person who deliberately destroyed the records may have separate personal liability. The company should therefore deal with both issues simultaneously: investigate and preserve evidence of the misconduct while restoring its ability to prepare reliable financial information.


The immediate priority should be preservation of evidence. The company should suspend the relevant person’s access to accounting systems, email, cloud applications, online banking and other critical systems, while preserving computers, servers, audit logs and electronic evidence. Systems should not be unnecessarily reinstalled or overwritten before forensic evidence has been secured. An independent digital-forensics specialist should determine what information was deleted, when the deletion occurred, which user accounts were involved, whether information was modified before being deleted and whether copies remain in backups, emails, cloud storage, mobile devices or third-party systems.


Where intentional destruction is reasonably suspected, the board should involve legal counsel and consider filing a police report. If a CFO or another senior executive is involved, the matter should normally be escalated directly to the board and audit committee rather than being managed solely within the finance department. Board minutes, investigation reports, access logs and evidence of management’s response should be maintained carefully because they may later be required by DBD, the Revenue Department, regulators, banks, counterparties and auditors.


Under Thailand’s Accounting Act B.E. 2543, accounting records and supporting documents must be maintained, generally for at least five years. Where accounting records or supporting documents are lost or damaged, the person responsible for preparing the accounts must notify the accounting authority within 15 days from the date the loss or damage becomes known or should have become known. Failure to comply with the notification and record-retention provisions can result in a civil fine of up to THB 5,000.


The Accounting Act also specifically addresses deliberate destruction. A person who damages, destroys, conceals, causes the loss of or renders useless accounting records or supporting documents may face imprisonment for up to one year, a fine of up to THB 20,000, or both. Where the offender is the person responsible for preparing the accounting records, the maximum may increase to imprisonment for up to two years, a fine of up to THB 40,000, or both. The Act also provides for possible responsibility of directors, managers or persons responsible for the operations of a juristic person where the entity’s offence results from their direction, action or relevant failure to act.


Intentional deletion of electronic accounting information may also raise issues under Thailand’s Computer Crime Act. Whether an employee or executive who ordinarily had system access committed an offence depends on the scope of authority, whether the deletion was unauthorised and the surrounding facts. The company should therefore have legal counsel assess the criminal, employment and civil consequences rather than relying solely on the fact that the person had a valid system password.


The company itself must nevertheless continue to comply with DBD financial-reporting requirements. A Thai limited company is generally required to prepare financial statements, have them audited and submit them following approval by the shareholders within the statutory deadline. The Accounting Act allows the Director-General to consider an extension or postponement where genuine necessity prevents compliance with the normal deadline, but such relief is discretionary rather than automatic.


If financial statements are eventually filed late, penalties may apply to both the company and responsible directors. The financial effect of these fines may be modest compared with the size of many businesses, but late filing can create a much broader compliance, governance and reputational problem. DBD’s current published comparison schedules provide different fine levels according to the length and nature of the delay. (e-Filing)


The practical accounting solution is normally to reconstruct the records. Complete loss of the ERP database does not necessarily mean that financial statements can no longer be prepared because most business transactions leave evidence in several places. The previous year’s audited closing trial balance can normally become the starting point, after which current-year transactions are reconstructed from surviving internal data and independent external evidence.


Cash can often be rebuilt from bank statements and direct confirmations. Revenue and receivables can be reconstructed from invoices, shipping documents, tax information, bank receipts and customer confirmations. Purchases and payables can be rebuilt from supplier invoices, supplier statements, purchase orders, receiving documents and confirmations. Payroll may be supported by bank files, withholding-tax returns and social-security records. Borrowings can be confirmed directly with lenders, while fixed assets can be reconstructed from prior-year registers, purchase documents and physical inspection.


Information should also be sought outside the finance department. Procurement systems, warehouse applications, sales systems, electronic tax invoices, payment gateways, email archives, shared drives, cloud applications, logistics providers and other service providers may contain evidence that no longer exists in the accounting system. A transaction whose journal entry has disappeared may still leave independent traces with the bank, customer, supplier, tax authority and logistics provider.


The objective should be to reconstruct the general ledger, subsidiary ledgers and trial balance with a traceable evidential basis for each material balance. Unsupported numbers should not simply be inserted to make the financial statements balance. Where estimation becomes unavoidable, management should document the methodology, assumptions, supporting information and uncertainty so that the estimate can subsequently be audited.


The Revenue Department consequences can be much more serious than ordinary late-filing fines. The company remains responsible for corporate income tax, VAT, withholding tax and other tax obligations notwithstanding the destruction of the records. The fact that an employee intentionally deleted the information does not itself suspend tax filing deadlines.


A particularly significant risk is section 71(1) of the Revenue Code. In circumstances where a company fails to maintain required accounts, maintains incomplete accounts or fails to provide accounting records and evidence requested in a tax examination, the assessing officer may assess corporate income tax at 5% of gross receipts before expenses or gross sales before expenses, whichever is greater. This can be substantially more onerous than normal corporate income tax based on net taxable profit because expenses do not reduce that base. (Royal Decree)


Published Thai court decisions also demonstrate that the inability to produce accounting records can create serious tax consequences even where the taxpayer asserts that documents were unavailable through another person. A police report against the employee may therefore help explain the circumstances, but it does not replace evidence supporting the company’s income, expenses and tax positions. Reconstruction of tax documentation should take place in parallel with reconstruction of the financial accounts. (Royal Decree)


VAT and withholding tax create additional risks. If sales, output VAT, purchases or input-tax invoices cannot be substantiated, additional tax, penalties and surcharges may arise. The company must also reconstruct the identity of payees, payments made and tax previously withheld. Filing unsupported tax figures merely to meet a deadline can create a second problem by turning a record-destruction incident into an inaccurate-return problem.


Banks and lenders may also be significantly affected. Many loan agreements require audited financial statements, management accounts, covenant calculations or other financial information within specified periods. Failure to provide reliable information can breach an information undertaking and, depending on the contract, may also contribute to a covenant breach or event of default. The precise result must be determined from the facility agreement rather than assumed.


Management should therefore communicate proactively with lenders, explain the incident, provide reliable interim information where available and present a credible reconstruction timetable. Where necessary, the company should request extensions or waivers before contractual deadlines expire. Banks may increase monitoring, request additional reporting, suspend uncommitted facilities or reconsider further drawdowns until confidence in the company’s financial information has been restored.


If the CFO or employee involved also had access to electronic banking, the company should immediately review authorised users, signatories, transaction limits, beneficiary amendments and approval workflows. Destruction of the accounting records may be part of a broader fraud rather than an isolated retaliatory act.


Trade creditors can be affected because the company may no longer know which invoices remain outstanding, which invoices have already been paid and when obligations fall due. This creates risks of duplicate payment, late payment, supplier disputes and interruptions to supply. Major suppliers should be asked for statements and invoice copies, which should be reconciled against bank transactions, purchase orders, receiving evidence and contracts.


Communication with suppliers should remain controlled and factual. It is generally unnecessary to announce broadly that all company records have been destroyed. Management can explain that the company is conducting an urgent reconciliation following an internal systems incident and request confirmation of outstanding balances. Genuine obligations should continue to be paid through an emergency verification process rather than suspending all supplier payments indefinitely.


The accounts-receivable side creates the opposite problem. The company may no longer know which customer invoices remain outstanding or which receipts and credit notes have already been processed. Receivables should be reconstructed using invoices, shipping evidence, bank receipts, tax data and sales-system information. Once management has reconstructed a balance as far as possible, customers can be asked to confirm it or identify differences. Asking customers simply to state how much they believe they owe the company should generally be avoided because it weakens the company’s control over the reconciliation process.


If customer balances cannot be established quickly, the incident can become a liquidity problem because customers may delay payment until balances are agreed. The investigation should also examine whether the deletion was intended to hide diverted collections, unauthorised credit notes, write-offs or other manipulation of customer accounts.


If the affected company is listed on the Stock Exchange of Thailand, the consequences become considerably more serious because reliable financial information is public-market information rather than merely internal accounting information. Under current SET rules, material information affecting financial condition or business operations must be disclosed to investors appropriately, and where the board or audit committee identifies an event or indicator that may materially affect the internal control system, the listed company is required to disclose that information immediately. The current rules effective from July 2026 specifically strengthen disclosure concerning significant internal-control events. (SET Market)


A deliberate destruction of significant accounting data by a CFO or senior finance employee could therefore become a disclosure issue if the board or audit committee concludes that the incident materially affects internal control, the reliability of financial information or business operations. The disclosure should explain the nature of the event, known impact, actions being taken and progress in remediation without concealing negative information or presenting uncertain conclusions as facts. SET rules require material disclosures to be complete, accurate, clear and sufficient for investors to make decisions. (SET Market)


If the incident leads to the removal, resignation or replacement of the CFO or chief accountant, the change itself may also need to be reported. Current SET rules require changes in the person having the highest responsibility for finance and accounting and the person supervising accounting to be disclosed within three working days. (SET Market)


The most immediate capital-market consequence may arise if the company cannot submit its periodic financial statements. For Thai listed companies, quarterly reviewed financial statements are generally due within 45 days of quarter-end, while audited annual financial statements are generally due within two months of year-end, subject to the alternative timetable where fourth-quarter reviewed statements are submitted. (SEC Thailand)


SET rules provide that failure to submit required financial statements by the deadline can result in an SP suspension sign being posted immediately and remaining until the financial statements are properly submitted. A delay exceeding six months from the due date can cause the company to enter the possible-delisting process. These are not theoretical consequences; SET continues to apply SP signs to companies that fail to submit financial statements by required deadlines. (SET Market)


For shareholders, the effect can therefore extend well beyond accounting inconvenience. Trading suspension removes or severely restricts liquidity in their investment. Investors may also be unable to evaluate the company’s profitability, financial position, cash flows and risks with confidence. Uncertainty can increase the perceived risk premium and damage market confidence even before the eventual financial statements are released.


The inability to finalise reliable accounts may also complicate decisions concerning dividends, annual shareholder meetings, capital raising and other corporate actions because the board may lack reliable information on distributable profits and financial capacity. Even where legal deadlines can technically be managed, investors may question why the internal-control environment allowed a single employee or CFO to destroy records that were critical to the company’s reporting obligations.


The incident also has direct implications for the Thai SEC. Listed companies and securities issuers have obligations under section 56 of the Securities and Exchange Act to prepare and submit financial statements and other reports so investors receive information necessary for investment decisions. The financial statements of listed companies must be prepared in accordance with applicable standards and audited or reviewed by an SEC-approved auditor. (SEC Thailand)


SET’s current regulatory summary notes that the SEC may impose fines where periodic reports are submitted late, incomplete or contrary to applicable requirements, including a fine of up to THB 100,000 and a continuing fine of up to THB 3,000 per day while the failure continues. The exact enforcement outcome depends on the applicable legal provision and facts. (SET Market)


The SEC can also take a supervisory interest in the reliability of the financial statements themselves. Recent SEC cases demonstrate that where questions arise over accounting records or sufficient supporting evidence, the SEC may require a listed company to cooperate with its auditor, correct affected financial statements and submit amended audited or reviewed financial information and related section 56 reports. (SEC Thailand)


Consequently, a listed company should not manage the incident as a private dispute between the employer and former CFO. The board, audit committee, company secretary, legal counsel, investor-relations function and external auditor should promptly assess whether disclosure is required, what information can responsibly be disclosed and how progress will be updated. The company should also establish controls over insider access to the information while disclosure decisions are being made, because a severe accounting incident may itself be price-sensitive information.


The external auditor should be informed immediately whether the company is listed or private. Management should provide a chronology of the incident, affected systems and periods, persons involved, forensic findings, police reports where appropriate, regulatory notifications, information that remains available and the reconstruction plan. The appropriate message is not, “Our records are gone; can the auditor still sign?” It should be, “Accounting records were deliberately destroyed. This is the evidence of what occurred, this is the information that remains, and this is management’s documented plan to reconstruct the accounts using independent and verifiable evidence.”


Management remains responsible for the accounting records and financial statements. The auditor should not become the person who reconstructs the books and subsequently audits the same work. Reconstruction should normally be performed by management, a replacement accounting team or an independent accounting or forensic adviser, leaving the external auditor able to evaluate the resulting information independently.


Loss of the original accounting database does not automatically require a modified audit opinion. If sufficient appropriate evidence can be obtained through alternative procedures, the auditor may still be able to reach an unmodified opinion. Banks can confirm cash and loans, customers can confirm receivables, suppliers can confirm liabilities and revenue can be supported through external invoices, shipping evidence, tax information and cash collections.


If sufficient appropriate evidence cannot be obtained, however, the incident becomes a scope limitation. Under ISA 705, material but non-pervasive uncertainty arising from unavailable evidence may result in a qualified opinion, while a material and pervasive inability to obtain evidence could result in a disclaimer of opinion. (IAASB)
For a Thai listed company, a disclaimer can have consequences beyond the wording of the auditor’s report because regulators and the exchange place particular importance on the reliability and auditability of listed-company financial information. The company should therefore give the auditor full access to forensic findings and the reconstruction process rather than attempting to manage the audit issue only at the end of the reporting timetable.


The issue becomes even broader where the Thai company is not itself listed but is a subsidiary of a parent company listed on a foreign stock exchange. In that situation, the destruction of the Thai subsidiary’s records can become a group reporting problem because the foreign parent may be unable to obtain reliable financial information for consolidation, management reporting, tax reporting or regulatory filings.


The significance depends on the size and nature of the Thai subsidiary. If it is small and immaterial to the group, the group may be able to manage the issue with targeted alternative procedures. If the Thai subsidiary represents a significant proportion of group revenue, EBITDA, assets, cash flows or particular risks, failure to produce a reliable reporting package may jeopardise the foreign parent’s ability to complete its consolidated financial statements on time.


The foreign parent should therefore be informed immediately rather than waiting for the local accounting reconstruction to finish. Group CFO, group controller, group legal counsel, audit committee and group auditor may all need to become involved. The parent may establish its own incident-response or forensic team and may require the Thai subsidiary to report progress more frequently than would normally be required under the local reporting timetable.
Whether the foreign listed parent must publicly disclose the incident depends on the securities laws and stock-exchange rules of its home jurisdiction and on the materiality of the Thai subsidiary and the event. There is no single global disclosure rule.

 Nevertheless, an incident that threatens the parent’s ability to issue consolidated financial statements on time, creates a material loss, exposes a major internal-control failure or involves suspected senior-management fraud could become material information at the parent-company level and require consideration under the parent’s own market-disclosure framework.


The incident may also require the foreign parent to reassess its group-wide internal controls. If one subsidiary could permanently lose all accounting records because a local CFO had excessive administrator rights and backups could also be destroyed, the weakness may not be viewed merely as a local IT problem. The parent should consider whether similar access structures exist at other subsidiaries and whether group policies over backups, privileged access, segregation of duties and financial reporting controls require remediation.


The consequences for the parent company’s auditor are particularly important. ISA 600 (Revised) governs audits of group financial statements, including circumstances where component auditors perform work on subsidiaries. It strengthens the responsibilities of the group auditor relating to planning, risk assessment, professional scepticism, two-way communication with component auditors and documentation. The revised standard has applied to group audits for periods beginning on or after 15 December 2023. (IAASB)


If a Thai component auditor is involved, that auditor should communicate the incident, the destruction of records, fraud concerns, internal-control implications and limitations on available evidence promptly to the group auditor. The group auditor should not discover the issue only when the Thai audit report is issued. Early communication allows the group team to reconsider component materiality, risk assessment, the scope of component work and whether additional group-level procedures or specialists are required.


The group auditor may request substantially more work at the Thai subsidiary than originally planned. This might include expanded bank, customer and supplier confirmations, direct testing of reconstructed transactions, forensic procedures, testing of group reporting adjustments and additional work on consolidation information. Where reliable local records cannot be obtained, the group auditor may also seek evidence directly from sources controlled by the parent or other group entities.


Importantly, an unmodified audit report on the foreign parent cannot be achieved simply by excluding the problematic subsidiary from the audit if its financial information is material to the group. The group auditor remains responsible for obtaining sufficient appropriate audit evidence on which to base the group audit opinion. If the inability to obtain evidence over the Thai subsidiary creates material but non-pervasive possible effects on the consolidated financial statements, the group opinion may need to be qualified. If the possible effects are material and pervasive, the group auditor may ultimately need to disclaim an opinion in accordance with ISA 705. (IAASB)


A local accounting crisis can therefore become a capital-market crisis at group level. If the Thai subsidiary cannot close its books, the parent may be unable to complete consolidation. If consolidation cannot be completed, the group auditor may not be able to finish its audit. If the audit is not completed, the foreign listed parent may be unable to file its annual results on time. Depending on the parent’s jurisdiction, that can create regulatory, stock-exchange, lender and shareholder consequences at a scale far greater than those of the Thai subsidiary itself.


The board should therefore manage the incident as a coordinated corporate response rather than leaving the accounting department to solve it alone. Legal counsel, digital-forensics specialists, accounting personnel, tax advisers, the audit committee, investor relations where relevant, management and the external auditor should all be involved, with responsibilities kept appropriately separate. In a multinational group, the foreign parent and group auditor should be added to that communication structure immediately.


The company should maintain a comprehensive incident file containing board and audit-committee minutes, forensic reports, police reports, DBD notifications, communications with the Revenue Department, SET and SEC disclosures where applicable, correspondence with lenders, supplier and customer confirmations, communications with the foreign parent and group auditor, reconstruction methodology and evidence of corrective controls introduced after the incident.


Finally, the underlying control failure must be corrected. No single employee, including a CFO, should normally be able to permanently destroy all critical financial data without independent backups, access monitoring or recovery mechanisms. Backups should be segregated from normal administrator privileges, deletion of critical data should create logs and alerts, privileged access should be reviewed independently and financial information should remain recoverable even if a senior-user account is compromised.


In summary, intentional destruction of accounting records can simultaneously affect DBD, the Revenue Department, banks, creditors, customers, auditors and, for a listed company, the SET, SEC and shareholders. If the company is a subsidiary of a foreign listed group, the incident can also affect the parent’s consolidated financial statements, public disclosures, reporting deadlines, internal controls and the group audit.


The individual who deliberately destroyed the information may face separate legal consequences, but the company remains responsible for fulfilling its own statutory and reporting obligations. The statement that “the CFO deleted the records” explains how the crisis arose; it does not solve the obligations that follow from it.
The strongest position for the company is therefore evidence of responsible action: preserve the forensic trail, notify the appropriate authorities promptly, investigate possible fraud, reconstruct accounting and tax records from independent sources, communicate transparently with banks, counterparties, shareholders and auditors, involve the parent and group auditor immediately where relevant, and strengthen controls so that no individual can ever again permanently destroy the financial history of the company.



หากพนักงานบัญชีหรือ CFO จงใจลบข้อมูลบัญชีทั้งหมด บริษัทควรทำอย่างไร?


หากพนักงานบัญชี ผู้บริหารฝ่ายการเงิน หรือ CFO มีความขัดแย้งกับบริษัทและจงใจลบข้อมูลทางบัญชีและการเงินทั้งหมดจนไม่สามารถกู้คืนได้ เหตุการณ์ดังกล่าวควรถูกมองว่าเป็นวิกฤตของบริษัท ไม่ใช่เพียงปัญหาระบบสารสนเทศ เพราะอาจกระทบพร้อมกันทั้งกฎหมายบัญชี การจัดทำงบการเงิน ภาษี ธนาคาร เจ้าหนี้ ลูกหนี้ ผู้สอบบัญชี และหากเป็นบริษัทจดทะเบียน ผลกระทบอาจขยายไปถึงตลาดหลักทรัพย์ ก.ล.ต. และผู้ถือหุ้นด้วย หากบริษัทเป็นบริษัทย่อยของบริษัทจดทะเบียนในต่างประเทศ ปัญหายังอาจส่งต่อไปยังบริษัทแม่ งบการเงินรวม และผู้สอบบัญชีของกลุ่มบริษัท


หลักสำคัญที่สุดคือ การที่พนักงานเป็นผู้ลบข้อมูลไม่ได้ทำให้บริษัทพ้นจากหน้าที่ของตนเอง บริษัทในฐานะผู้มีหน้าที่จัดทำบัญชียังคงต้องเก็บรักษาบัญชี จัดทำงบการเงิน ยื่นภาษี และนำส่งข้อมูลตามที่กฎหมายกำหนด ขณะเดียวกัน ผู้ที่จงใจทำลายข้อมูลอาจมีความรับผิดเป็นการส่วนตัว ดังนั้น บริษัทต้องดำเนินการสองด้านพร้อมกัน คือสอบสวนและรักษาหลักฐานเกี่ยวกับผู้กระทำ และสร้างความสามารถในการจัดทำข้อมูลทางการเงินกลับคืนโดยเร็วที่สุด


สิ่งแรกที่ควรทำคือระงับสิทธิการเข้าถึงระบบของบุคคลที่เกี่ยวข้อง เก็บรักษาคอมพิวเตอร์ เครื่องแม่ข่าย อีเมล ระบบเก็บข้อมูลออนไลน์ ประวัติการเข้าใช้งาน และหลักฐานดิจิทัลอื่นทั้งหมด ไม่ควรรีบติดตั้งระบบใหม่หรือเขียนข้อมูลทับก่อนเก็บหลักฐาน ควรให้ผู้เชี่ยวชาญตรวจสอบว่าข้อมูลใดถูกลบ ลบเมื่อใด ใช้บัญชีผู้ใช้งานใด มีการแก้ไขข้อมูลก่อนลบหรือไม่ และยังมีสำเนาเหลืออยู่ในระบบสำรอง อีเมล โทรศัพท์ หรือระบบของบุคคลภายนอกหรือไม่


หากมีเหตุอันควรเชื่อว่าเป็นการจงใจทำลายข้อมูล ควรให้ที่ปรึกษากฎหมายเข้ามาดูแลและพิจารณาแจ้งความ หากผู้ที่เกี่ยวข้องเป็น CFO หรือผู้บริหารระดับสูง ควรรายงานต่อคณะกรรมการบริษัทและคณะกรรมการตรวจสอบโดยตรง ไม่ควรปล่อยให้ฝ่ายการเงินจัดการกันเอง รายงานการประชุม ผลการตรวจสอบ ประวัติการใช้งาน และหลักฐานการตอบสนองของฝ่ายบริหารควรถูกเก็บไว้อย่างเป็นระบบ เพราะอาจต้องใช้ชี้แจงต่อกรมพัฒนาธุรกิจการค้า กรมสรรพากร หน่วยงานตลาดทุน ธนาคาร คู่ค้า และผู้สอบบัญชี


พระราชบัญญัติการบัญชี พ.ศ. 2543 กำหนดให้เก็บรักษาบัญชีและเอกสารประกอบการลงบัญชีโดยทั่วไปไม่น้อยกว่าห้าปี และหากบัญชีหรือเอกสารสูญหายหรือเสียหาย ต้องแจ้งต่อเจ้าหน้าที่ภายใน 15 วันนับแต่วันที่ทราบหรือควรทราบถึงเหตุ หากไม่ปฏิบัติตามหน้าที่ดังกล่าวอาจมีค่าปรับทางพินัยไม่เกิน 5,000 บาท


กฎหมายยังมีบทลงโทษต่อผู้ที่จงใจทำลายข้อมูลโดยตรง ผู้ใดทำให้บัญชีหรือเอกสารประกอบการลงบัญชีเสียหาย ทำลาย ซ่อนเร้น ทำให้สูญหาย หรือทำให้ไร้ประโยชน์ อาจต้องระวางโทษจำคุกไม่เกินหนึ่งปี หรือปรับไม่เกิน 20,000 บาท หรือทั้งจำทั้งปรับ และหากผู้กระทำเป็นผู้มีหน้าที่จัดทำบัญชี โทษสูงสุดอาจเพิ่มเป็นจำคุกไม่เกินสองปี หรือปรับไม่เกิน 40,000 บาท หรือทั้งจำทั้งปรับ นอกจากนี้ หากความผิดของนิติบุคคลเกิดจากการสั่งการ การกระทำ หรือการละเว้นของกรรมการ ผู้จัดการ หรือผู้รับผิดชอบในการดำเนินงาน บุคคลดังกล่าวอาจมีความรับผิดด้วยตามเงื่อนไขของกฎหมาย


การจงใจลบข้อมูลอิเล็กทรอนิกส์ของบริษัทอาจมีประเด็นภายใต้กฎหมายว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ด้วย แต่หากผู้กระทำเป็นพนักงานหรือผู้บริหารที่เดิมมีสิทธิเข้าใช้ระบบอยู่แล้ว ต้องพิจารณาว่าการลบนั้นเกินขอบเขตอำนาจหรือเป็นการกระทำโดยมิชอบหรือไม่ จึงควรให้ทนายความวิเคราะห์ข้อเท็จจริงเฉพาะกรณี


บริษัทเองยังคงต้องปฏิบัติตามหน้าที่ในการจัดทำและนำส่งงบการเงิน การที่ข้อมูลถูกลบไม่ได้ทำให้หน้าที่ดังกล่าวสิ้นสุด หากมีเหตุจำเป็นจริงที่พิสูจน์ได้ กฎหมายเปิดโอกาสให้อธิบดีพิจารณาขยายหรือเลื่อนกำหนดการนำส่งงบการเงินได้ตามความจำเป็น แต่ไม่ได้หมายความว่าจะได้รับอนุมัติโดยอัตโนมัติ บริษัทจึงควรหารือกรมพัฒนาธุรกิจการค้าก่อนถึงกำหนด ไม่ควรรอให้ผิดนัดเสียก่อน
หากสุดท้ายยื่นงบล่าช้า บริษัทและกรรมการผู้รับผิดชอบอาจมีค่าปรับตามระยะเวลาที่ล่าช้า อัตราค่าปรับอาจไม่สูงมากเมื่อเทียบกับขนาดของกิจการ แต่ผลกระทบด้านการปฏิบัติตามกฎหมาย ความน่าเชื่อถือ และความสัมพันธ์กับธนาคารอาจรุนแรงกว่าจำนวนค่าปรับเอง (e-Filing)


ทางออกสำคัญคือการสร้างข้อมูลบัญชีกลับคืน การที่ฐานข้อมูลบัญชีถูกลบทั้งหมดไม่ได้หมายความว่างบการเงินไม่สามารถจัดทำได้เสมอไป เพราะธุรกรรมทางธุรกิจส่วนใหญ่ทิ้งหลักฐานไว้หลายแห่ง บริษัทสามารถเริ่มจากงบทดลองปิดบัญชีที่ผ่านการตรวจสอบของปีก่อน แล้วสร้างรายการของปีปัจจุบันกลับขึ้นใหม่จากข้อมูลที่ยังเหลืออยู่และหลักฐานของบุคคลภายนอก


ยอดเงินสดสามารถสร้างจากรายการเดินบัญชีและหนังสือยืนยันยอดธนาคาร รายได้และลูกหนี้สามารถสร้างจากใบแจ้งหนี้ เอกสารส่งสินค้า ข้อมูลภาษี การรับเงิน และหนังสือยืนยันจากลูกค้า เจ้าหนี้สามารถสร้างจากสำเนาใบแจ้งหนี้ รายงานยอดจากผู้ขาย ใบสั่งซื้อ และเอกสารรับสินค้า เงินเดือนสามารถตรวจจากรายการโอนเงิน แบบภาษี และข้อมูลประกันสังคม เงินกู้สามารถยืนยันจากธนาคาร และสินทรัพย์ถาวรสามารถอ้างอิงทะเบียนสินทรัพย์ปีก่อน ใบซื้อ และการตรวจนับจริง
ควรค้นข้อมูลนอกฝ่ายบัญชีด้วย เช่น ระบบจัดซื้อ ระบบคลังสินค้า ระบบขาย ระบบใบกำกับภาษีอิเล็กทรอนิกส์ ระบบรับชำระเงิน อีเมล พื้นที่เก็บเอกสารร่วม และระบบของผู้ให้บริการภายนอก รายการบัญชีอาจถูกลบไปแล้ว แต่หลักฐานของธุรกรรมเดียวกันอาจยังอยู่กับธนาคาร ลูกค้า ผู้ขาย บริษัทขนส่ง หรือกรมสรรพากร


เป้าหมายคือสร้างบัญชีแยกประเภท บัญชีย่อย และงบทดลองกลับขึ้นมาโดยสามารถตรวจสอบเส้นทางของหลักฐานได้ ไม่ควรประมาณตัวเลขขึ้นมาเพียงเพื่อให้งบการเงินสมดุล เพราะจะทำให้ปัญหาจากการสูญหายของข้อมูลกลายเป็นปัญหาใหม่เรื่องความถูกต้องของงบการเงิน หากจำเป็นต้องใช้ประมาณการจริง ต้องมีวิธีคำนวณ สมมติฐาน และหลักฐานรองรับอย่างชัดเจน


ผลกระทบต่อกรมสรรพากรอาจรุนแรงกว่าค่าปรับจากการยื่นงบล่าช้า เพราะบริษัทก็ยังคงต้องยื่นภาษีเงินได้นิติบุคคล ภาษีมูลค่าเพิ่ม ภาษีหัก ณ ที่จ่าย และแบบภาษีอื่นตามปกติ การไม่มีข้อมูลบัญชีไม่ได้ทำให้กำหนดเวลาภาษีหยุดเดิน
ความเสี่ยงสำคัญคือมาตรา 71(1) แห่งประมวลรัษฎากร หากบริษัทไม่ทำบัญชี ทำบัญชีไม่ครบ หรือไม่สามารถนำบัญชี เอกสาร หรือหลักฐานมาให้เจ้าพนักงานตรวจสอบตามเงื่อนไขที่กฎหมายกำหนด เจ้าพนักงานประเมินอาจประเมินภาษีเงินได้นิติบุคคลในอัตรา 5% ของยอดรายรับก่อนหักรายจ่ายหรือยอดขายก่อนหักรายจ่าย แล้วแต่ว่าจำนวนใดมากกว่า ซึ่งอาจรุนแรงกว่าการเสียภาษีจากกำไรสุทธิตามปกติอย่างมาก (Royal Decree)


แนวคำพิพากษาที่กรมสรรพากรเผยแพร่สะท้อนว่า การไม่สามารถนำบัญชีและหลักฐานมาแสดงอาจทำให้บริษัทเผชิญการประเมินดังกล่าวได้ แม้จะอ้างว่าเอกสารอยู่กับหรือสูญหายจากบุคคลอื่นก็ตาม ดังนั้น ใบแจ้งความต่อ CFO หรือพนักงานมีประโยชน์ในการพิสูจน์เหตุการณ์ แต่ไม่สามารถใช้แทนหลักฐานทางบัญชีและภาษีได้ บริษัทต้องพยายามสร้างข้อมูลภาษีกลับคืนควบคู่กับบัญชี (Royal Decree)


ภาษีมูลค่าเพิ่มและภาษีหัก ณ ที่จ่ายก็ต้องฟื้นข้อมูลเช่นเดียวกัน หากพิสูจน์ยอดขาย ภาษีขาย ภาษีซื้อ หรือใบกำกับภาษีไม่ได้ อาจเกิดภาษี เบี้ยปรับและเงินเพิ่มเพิ่มเติม ขณะที่ภาษีหัก ณ ที่จ่ายต้องสามารถระบุได้ว่าบริษัทจ่ายเงินให้ใคร จำนวนเท่าใด และหักภาษีไว้เท่าใด บริษัทไม่ควรยื่นแบบโดยใช้ตัวเลขที่ไม่มีหลักฐานเพียงเพื่อให้ทันกำหนด เพราะอาจทำให้เกิดปัญหาการยื่นแบบไม่ถูกต้องเพิ่มขึ้นอีกเรื่องหนึ่ง


ผลกระทบต่อธนาคารอาจมีนัยสำคัญเช่นกัน สัญญากู้หลายฉบับกำหนดให้บริษัทต้องส่งงบการเงินที่ผ่านการตรวจสอบ งบบริหาร อัตราส่วนทางการเงิน หรือหนังสือรับรองการปฏิบัติตามเงื่อนไขภายในกำหนด หากบริษัทไม่สามารถส่งข้อมูลที่น่าเชื่อถือได้ อาจถือเป็นการไม่ปฏิบัติตามข้อกำหนดด้านข้อมูล และในบางสัญญาอาจเชื่อมโยงไปถึงการผิดเงื่อนไขเงินกู้ได้ ทั้งนี้ ต้องอ่านจากสัญญาจริง ไม่ควรสรุปว่าธนาคารสามารถเรียกหนี้ทั้งหมดคืนได้โดยอัตโนมัติ
บริษัทควรแจ้งธนาคารก่อนถึงกำหนดส่งข้อมูล อธิบายเหตุการณ์ แสดงแผนการสร้างบัญชีกลับ และขอขยายเวลาหรือผ่อนผันหากจำเป็น ธนาคารอาจเพิ่มการติดตาม ขอข้อมูลเพิ่มเติม ทบทวนวงเงินที่ยังไม่ได้เบิก หรือชะลอการให้วงเงินใหม่จนกว่าจะมั่นใจในข้อมูลของบริษัท


หาก CFO หรือบุคคลที่เกี่ยวข้องมีสิทธิทำธุรกรรมธนาคาร บริษัทควรตรวจสอบผู้มีอำนาจลงนาม ผู้ใช้งานธนาคารอิเล็กทรอนิกส์ วงเงินโอน การเปลี่ยนบัญชีผู้รับเงิน และขั้นตอนอนุมัติทันที เพราะการลบข้อมูลอาจเป็นเพียงส่วนหนึ่งของการทุจริตที่ใหญ่กว่านั้น


ด้านเจ้าหนี้ บริษัทอาจไม่ทราบว่ามีหนี้ค้างกับผู้ขายรายใด จำนวนเท่าใด หรือใบแจ้งหนี้ใดชำระแล้ว ปัญหาที่ตามมาอาจเป็นการจ่ายเงินซ้ำ การจ่ายล่าช้า ข้อพิพาท หรือการถูกผู้ขายหยุดส่งสินค้า บริษัทควรขอรายงานยอดและสำเนาใบแจ้งหนี้จากผู้ขายรายสำคัญ แล้วกระทบยอดกับรายการธนาคาร ใบสั่งซื้อ เอกสารรับสินค้า และสัญญา


ด้านลูกหนี้ บริษัทอาจไม่ทราบว่าลูกค้าแต่ละรายยังเป็นหนี้เท่าใด ใบแจ้งหนี้ใดได้รับชำระแล้ว หรือมีใบลดหนี้ใดเกิดขึ้น บริษัทควรสร้างยอดกลับจากใบแจ้งหนี้ เอกสารส่งสินค้า รายการรับเงิน ข้อมูลภาษี และระบบขายก่อน แล้วจึงส่งยอดที่สร้างขึ้นใหม่ให้ลูกค้าช่วยยืนยัน ไม่ควรถามลูกค้าเพียงว่า “บริษัทไม่มีข้อมูลแล้ว คุณเป็นหนี้เท่าไร” เพราะอาจทำให้เกิดข้อพิพาทและทำให้บริษัทเสียเปรียบ
หากบริษัทเป็นบริษัทจดทะเบียนในตลาดหลักทรัพย์แห่งประเทศไทย ผลกระทบจะรุนแรงขึ้นอย่างมาก เพราะข้อมูลบัญชีไม่ได้มีความสำคัญเฉพาะต่อฝ่ายบริหารและผู้สอบบัญชี แต่เป็นข้อมูลที่ผู้ลงทุนใช้ตัดสินใจซื้อขายหลักทรัพย์ ตามเกณฑ์ของตลาดหลักทรัพย์ในปัจจุบัน ข้อมูลที่มีผลอย่างมีสาระสำคัญต่อฐานะการเงินและการดำเนินธุรกิจต้องได้รับการเปิดเผยอย่างเหมาะสม และหากคณะกรรมการบริษัทหรือคณะกรรมการตรวจสอบเห็นว่ามีเหตุการณ์หรือข้อบ่งชี้ที่อาจกระทบระบบควบคุมภายในอย่างมีนัยสำคัญ บริษัทต้องเปิดเผยข้อมูลโดยทันที โดยเกณฑ์ที่มีผลตั้งแต่เดือนกรกฎาคม 2569 ได้เพิ่มความเข้มงวดในเรื่องนี้โดยเฉพาะ (SET Market)


ดังนั้น หาก CFO สามารถลบข้อมูลบัญชีที่มีสาระสำคัญจนบริษัทไม่สามารถจัดทำงบได้ เหตุการณ์ดังกล่าวอาจเป็นข้อบ่งชี้ของปัญหาระบบควบคุมภายในที่บริษัทและคณะกรรมการตรวจสอบต้องประเมินอย่างจริงจัง หากเข้าเกณฑ์ต้องเปิดเผย ก็ควรอธิบายลักษณะเหตุการณ์ ผลกระทบที่ทราบแล้ว แผนแก้ไข และความคืบหน้าอย่างตรงไปตรงมา ไม่ควรปกปิดข้อเท็จจริงด้านลบหรือกล่าวในลักษณะที่ทำให้ผู้ลงทุนเข้าใจว่าปัญหาได้รับการแก้ไขแล้วทั้งที่ยังมีความไม่แน่นอน เพราะตลาดหลักทรัพย์กำหนดให้ข้อมูลที่เปิดเผยต้องครบถ้วน ถูกต้อง ชัดเจน และเพียงพอต่อการตัดสินใจลงทุน (SET Market)


หากเหตุการณ์ทำให้ CFO หรือผู้ควบคุมดูแลการทำบัญชีลาออก ถูกให้ออก หรือมีการเปลี่ยนตัว บริษัทจดทะเบียนยังต้องพิจารณาหน้าที่เปิดเผยการเปลี่ยนแปลงบุคคลดังกล่าว โดยเกณฑ์ตลาดหลักทรัพย์กำหนดให้การเปลี่ยนผู้รับผิดชอบสูงสุดสายงานบัญชีและการเงินและผู้ควบคุมดูแลการทำบัญชีเปิดเผยภายในสามวันทำการ (SET Market)


ปัญหาที่รุนแรงที่สุดอาจเกิดขึ้นหากบริษัทไม่สามารถส่งงบการเงินได้ตามกำหนด บริษัทจดทะเบียนโดยทั่วไปต้องส่งงบไตรมาสที่ผ่านการสอบทานภายใน 45 วันหลังสิ้นไตรมาส และงบประจำปีที่ผ่านการตรวจสอบภายในสองเดือนนับแต่วันสิ้นรอบบัญชี โดยมีทางเลือกบางกรณีที่ส่งงบไตรมาส 4 ก่อนและส่งงบประจำปีภายในสามเดือน (SEC Thailand)


หากไม่สามารถส่งงบได้ ตลาดหลักทรัพย์สามารถขึ้นเครื่องหมาย SP เพื่อพักการซื้อขายได้ทันทีตั้งแต่พ้นกำหนด และหากล่าช้าเกินหกเดือนอาจเข้าสู่เกณฑ์ที่หุ้นเข้าข่ายอาจถูกเพิกถอน ตลาดหลักทรัพย์ยังคงใช้มาตรการดังกล่าวกับบริษัทที่ส่งงบล่าช้าในปัจจุบัน (SET Market)


ผลต่อผู้ถือหุ้นจึงไม่ได้จำกัดอยู่ที่การรออ่านงบช้าลง หากหุ้นถูกพักการซื้อขาย ผู้ถือหุ้นอาจไม่สามารถขายหุ้นได้ตามปกติ สภาพคล่องของการลงทุนหายไป และตลาดไม่สามารถประเมินผลประกอบการ ฐานะการเงิน กระแสเงินสด และความเสี่ยงของบริษัทได้อย่างน่าเชื่อถือ ความไม่แน่นอนดังกล่าวอาจกระทบความเชื่อมั่นและมูลค่าที่นักลงทุนยินดีให้กับบริษัท แม้ท้ายที่สุดบริษัทจะสามารถสร้างบัญชีกลับมาได้ก็ตาม


การไม่มีข้อมูลที่น่าเชื่อถือยังอาจทำให้คณะกรรมการตัดสินใจเรื่องเงินปันผล การประชุมผู้ถือหุ้น การเพิ่มทุน หรือธุรกรรมสำคัญได้ยากขึ้น เพราะไม่สามารถมั่นใจในกำไร ฐานะการเงิน หรือความสามารถในการจ่ายเงินของกิจการได้ ผู้ถือหุ้นยังอาจตั้งคำถามต่อความรับผิดชอบของคณะกรรมการและคณะกรรมการตรวจสอบว่าเหตุใดบุคคลเพียงคนเดียวจึงสามารถทำลายข้อมูลสำคัญของบริษัทได้โดยไม่มีระบบสำรองหรือการป้องกันที่เพียงพอ


ในด้าน ก.ล.ต. บริษัทจดทะเบียนมีหน้าที่จัดทำและนำส่งงบการเงินและรายงานตามมาตรา 56 แห่งพระราชบัญญัติหลักทรัพย์และตลาดหลักทรัพย์ เพื่อให้ผู้ลงทุนมีข้อมูลสำหรับการตัดสินใจ งบการเงินต้องจัดทำตามมาตรฐานที่เกี่ยวข้องและได้รับการตรวจสอบหรือสอบทานโดยผู้สอบบัญชีที่ได้รับความเห็นชอบจาก ก.ล.ต. (SEC Thailand)


ข้อมูลของตลาดหลักทรัพย์ระบุว่า กรณีนำส่งรายงานตามรอบบัญชีล่าช้า จัดทำไม่ครบถ้วน หรือไม่เป็นไปตามหลักเกณฑ์ ก.ล.ต. อาจพิจารณาเปรียบเทียบปรับบริษัท โดยอาจมีโทษปรับไม่เกิน 100,000 บาท และปรับอีกไม่เกินวันละ 3,000 บาทตลอดเวลาที่ยังไม่แก้ไขให้ถูกต้อง ทั้งนี้ การใช้บทลงโทษจริงขึ้นอยู่กับข้อเท็จจริงและกฎหมายที่ใช้กับกรณีนั้น (SET Market)


หากปัญหาข้อมูลทำให้งบการเงินมีข้อสงสัยด้านความถูกต้อง ก.ล.ต. ยังสามารถเข้ามากำกับดูแลเรื่องคุณภาพของงบการเงินได้ ตัวอย่างในช่วงปี 2569 แสดงให้เห็นว่า ก.ล.ต. สามารถให้บริษัทจดทะเบียนให้ความร่วมมือกับผู้สอบบัญชี แก้ไขงบการเงิน และนำส่งงบที่แก้ไขซึ่งผ่านการตรวจสอบหรือสอบทาน พร้อมรายงานตามมาตรา 56 และเปิดเผยต่อสาธารณชนผ่านระบบของตลาดหลักทรัพย์ได้ (SEC Thailand)


ดังนั้น หากเป็นบริษัทจดทะเบียน เหตุการณ์นี้ไม่ควรถูกบริหารในฐานะข้อพิพาทส่วนตัวระหว่างบริษัทกับ CFO ฝ่ายกฎหมาย เลขานุการบริษัท คณะกรรมการตรวจสอบ ฝ่ายนักลงทุนสัมพันธ์ ผู้สอบบัญชี และคณะกรรมการบริษัทควรประเมินร่วมกันทันทีว่าต้องเปิดเผยข้อมูลหรือไม่ ควรเปิดเผยเมื่อใด และจะสื่อสารความคืบหน้าอย่างไร รวมทั้งควรควบคุมบุคคลที่เข้าถึงข้อมูลสำคัญในช่วงก่อนการเปิดเผยต่อสาธารณะอย่างเหมาะสม


บริษัทควรแจ้งผู้สอบบัญชีทันที ไม่ควรรอจนสร้างบัญชีเสร็จ ผู้สอบบัญชีควรได้รับลำดับเหตุการณ์ รายละเอียดระบบและช่วงเวลาที่ได้รับผลกระทบ บุคคลที่เกี่ยวข้อง ผลการตรวจสอบทางดิจิทัล ใบแจ้งความ การแจ้งหน่วยงานรัฐ ข้อมูลที่ยังเหลือ และแผนสร้างบัญชีกลับคืน


ข้อความที่เหมาะสมไม่ใช่ “ข้อมูลหายหมดแล้ว ผู้สอบบัญชีจะเซ็นให้ได้หรือไม่?” แต่ควรเป็น “เกิดการจงใจทำลายข้อมูลบัญชี นี่คือหลักฐานของเหตุการณ์ นี่คือข้อมูลที่ยังเหลืออยู่ และนี่คือแผนของฝ่ายบริหารในการสร้างบัญชีกลับจากแหล่งข้อมูลที่เป็นอิสระและตรวจสอบได้”


หน้าที่จัดทำบัญชีและงบการเงินยังเป็นของฝ่ายบริหาร ไม่ควรให้ผู้สอบบัญชีเป็นผู้สร้างบัญชีทั้งหมดแล้วกลับมาตรวจสิ่งที่ตนเองจัดทำ ควรใช้ทีมบัญชีชุดใหม่ ผู้ให้บริการบัญชี หรือผู้เชี่ยวชาญอิสระทำการสร้างข้อมูล แล้วให้ผู้สอบบัญชีตรวจสอบผลอย่างเป็นอิสระ


การสูญหายของฐานข้อมูลเดิมไม่ได้หมายความว่าผู้สอบบัญชีต้องแก้ไขความเห็นทันที หากสามารถหาหลักฐานอื่นที่เหมาะสมอย่างเพียงพอได้ ผู้สอบบัญชีอาจยังสามารถแสดงความเห็นแบบไม่มีเงื่อนไขได้ แต่หากท้ายที่สุดไม่สามารถรวบรวมหลักฐานได้เพียงพอ จะเกิดข้อจำกัดของขอบเขตการสอบบัญชี หากผลกระทบที่อาจเกิดขึ้นมีสาระสำคัญแต่ไม่แผ่กระจาย อาจเป็นความเห็นแบบมีเงื่อนไข แต่หากมีทั้งสาระสำคัญและแผ่กระจาย อาจรุนแรงถึงการไม่แสดงความเห็นตาม ISA 705 (IAASB)


หากบริษัทไทยแห่งนี้เป็นบริษัทย่อยของบริษัทแม่ที่จดทะเบียนในตลาดหลักทรัพย์ต่างประเทศ ผลกระทบจะไม่ได้หยุดอยู่ที่ประเทศไทย เพราะข้อมูลของบริษัทย่อยต้องถูกนำไปใช้ในการจัดทำงบการเงินรวมของบริษัทแม่ หากบริษัทย่อยไม่สามารถจัดทำข้อมูลทางการเงินที่น่าเชื่อถือได้ บริษัทแม่อาจไม่สามารถปิดบัญชีรวม จัดทำงบรวม หรือส่งรายงานต่อตลาดทุนของประเทศตนได้ทันเวลา


ระดับผลกระทบขึ้นอยู่กับความสำคัญของบริษัทย่อย หากเป็นบริษัทย่อยขนาดเล็กที่ไม่มีสาระสำคัญต่อกลุ่ม ผลกระทบอาจบริหารได้ด้วยวิธีตรวจสอบเพิ่มเติม แต่หากบริษัทไทยมีสัดส่วนสำคัญต่อรายได้ กำไร สินทรัพย์ กระแสเงินสด หรือความเสี่ยงของกลุ่ม การไม่สามารถจัดทำข้อมูลได้อาจกระทบโดยตรงต่อกำหนดการปิดงบรวมของบริษัทแม่


บริษัทไทยจึงควรแจ้งบริษัทแม่ทันที ไม่ควรรอจนสร้างบัญชีเสร็จ CFO ของกลุ่ม ผู้ควบคุมบัญชีกลุ่ม ฝ่ายกฎหมาย คณะกรรมการตรวจสอบ และผู้สอบบัญชีของกลุ่มอาจต้องเข้ามามีส่วนร่วม บริษัทแม่อาจส่งทีมตรวจสอบหรือผู้เชี่ยวชาญของตนเข้ามา และอาจกำหนดให้บริษัทย่อยรายงานความคืบหน้าถี่กว่าปกติ


บริษัทแม่จดทะเบียนในต่างประเทศจะต้องเปิดเผยเหตุการณ์ต่อผู้ลงทุนหรือไม่ ขึ้นอยู่กับกฎหมายหลักทรัพย์และกฎของตลาดหลักทรัพย์ในประเทศที่บริษัทแม่จดทะเบียน รวมถึงระดับความมีสาระสำคัญของบริษัทย่อย ไม่มีหลักเดียวที่ใช้เหมือนกันทั่วโลก แต่หากเหตุการณ์ทำให้บริษัทแม่เสี่ยงส่งงบรวมไม่ทัน ก่อให้เกิดความเสียหายที่มีสาระสำคัญ เปิดเผยจุดอ่อนสำคัญของระบบควบคุม หรือเกี่ยวข้องกับการทุจริตของผู้บริหารระดับสูง บริษัทแม่ย่อมต้องประเมินอย่างจริงจังว่าเหตุการณ์นั้นเป็นข้อมูลที่ต้องเปิดเผยต่อตลาดของตนหรือไม่


บริษัทแม่ควรประเมินระบบควบคุมของทั้งกลุ่มใหม่ด้วย หากบริษัทย่อยหนึ่งสามารถสูญเสียข้อมูลทั้งหมดเพราะ CFO ท้องถิ่นมีสิทธิระดับสูงและสามารถทำลายระบบสำรองได้ ปัญหาอาจไม่ได้เป็นเพียงจุดอ่อนของประเทศไทย บริษัทแม่ควรตรวจสอบว่าบริษัทย่อยประเทศอื่นมีโครงสร้างสิทธิ ระบบสำรอง การแบ่งแยกหน้าที่ และการติดตามผู้ใช้งานลักษณะเดียวกันหรือไม่


ผลต่อผู้สอบบัญชีของบริษัทแม่ก็มีความสำคัญมาก ISA 600 (Revised) กำหนดหลักสำหรับการตรวจสอบงบการเงินของกลุ่ม รวมถึงกรณีที่มีผู้สอบบัญชีของบริษัทย่อยเข้ามาร่วมงาน และเพิ่มความเข้มข้นในเรื่องการวางแผน การประเมินความเสี่ยง การใช้วิจารณญาณ การสื่อสารสองทางระหว่างผู้สอบบัญชีกลุ่มกับผู้สอบบัญชีของบริษัทย่อย และการจัดทำเอกสาร (IAASB)


หากมีผู้สอบบัญชีของบริษัทไทย ผู้สอบบัญชีรายนั้นควรแจ้งเรื่องข้อมูลถูกทำลาย ความเสี่ยงการทุจริต ข้อบกพร่องของระบบควบคุม และข้อจำกัดด้านหลักฐานต่อผู้สอบบัญชีกลุ่มโดยเร็ว ไม่ควรรอจนถึงวันที่ออก Audit Report ของบริษัทไทย เพราะผู้สอบบัญชีกลุ่มต้องใช้ข้อมูลนี้ในการทบทวนการประเมินความเสี่ยง ขอบเขตงาน และวิธีตรวจสอบของกลุ่ม


ผู้สอบบัญชีกลุ่มอาจกำหนดให้เพิ่มงานที่บริษัทไทยอย่างมาก เช่น เพิ่มการยืนยันยอดกับธนาคาร ลูกค้าและผู้ขาย ตรวจรายการที่สร้างกลับมาใหม่จำนวนมากขึ้น ใช้ผู้เชี่ยวชาญด้านการทุจริต ตรวจรายการปรับปรุงที่ส่งเข้าสู่งบรวม หรือหาหลักฐานจากระบบที่บริษัทแม่ควบคุมเอง


หากข้อมูลของบริษัทไทยมีสาระสำคัญ ผู้สอบบัญชีกลุ่มไม่สามารถแก้ปัญหาเพียงโดยไม่นำบริษัทย่อยนั้นมาตรวจ ผู้สอบบัญชีกลุ่มยังต้องมีหลักฐานที่เหมาะสมอย่างเพียงพอเพื่อรองรับความเห็นต่องบการเงินรวม หากข้อมูลของบริษัทย่อยไม่สามารถตรวจสอบได้และผลที่อาจเกิดกับงบรวมมีสาระสำคัญแต่ไม่แผ่กระจาย ความเห็นของผู้สอบบัญชีกลุ่มอาจต้องมีเงื่อนไข แต่หากผลกระทบมีทั้งสาระสำคัญและแผ่กระจาย อาจรุนแรงถึงการไม่แสดงความเห็นต่องบการเงินรวม (IAASB)


ดังนั้น ปัญหาที่เริ่มจาก “CFO ของบริษัทย่อยในประเทศไทยลบข้อมูล” สามารถพัฒนาเป็นปัญหาของตลาดทุนระดับกลุ่มได้ หากบริษัทไทยปิดบัญชีไม่ได้ บริษัทแม่อาจรวมงบไม่ได้ หากงบรวมไม่เสร็จ ผู้สอบบัญชีกลุ่มอาจตรวจไม่เสร็จ และหากการตรวจไม่เสร็จ บริษัทแม่จดทะเบียนในต่างประเทศก็อาจส่งผลประกอบการไม่ทันกำหนด ซึ่งอาจสร้างผลกระทบต่อหน่วยงานกำกับ ตลาดหลักทรัพย์ ธนาคาร และผู้ถือหุ้นของบริษัทแม่ด้วย


คณะกรรมการจึงควรบริหารเหตุการณ์นี้ในฐานะวิกฤตขององค์กร ไม่ควรปล่อยให้ฝ่ายบัญชีแก้ไขเพียงฝ่ายเดียว ควรมีฝ่ายบริหาร ที่ปรึกษากฎหมาย ผู้เชี่ยวชาญด้านการตรวจสอบข้อมูลดิจิทัล ทีมบัญชี ที่ปรึกษาภาษี คณะกรรมการตรวจสอบ และผู้สอบบัญชีเข้าร่วมตามบทบาท หากเป็นกลุ่มข้ามชาติ ต้องเพิ่มบริษัทแม่และผู้สอบบัญชีกลุ่มเข้ามาในกระบวนการสื่อสารตั้งแต่ต้น


บริษัทควรจัดทำแฟ้มเหตุการณ์โดยเฉพาะ เก็บรายงานการประชุมคณะกรรมการและคณะกรรมการตรวจสอบ รายงานการตรวจสอบระบบ ใบแจ้งความ หนังสือแจ้งกรมพัฒนาธุรกิจการค้า การติดต่อกรมสรรพากร การเปิดเผยต่อตลาดหลักทรัพย์และ ก.ล.ต. หากเกี่ยวข้อง การสื่อสารกับธนาคาร หนังสือยืนยันจากเจ้าหนี้และลูกหนี้ การสื่อสารกับบริษัทแม่และผู้สอบบัญชีกลุ่ม วิธีสร้างบัญชีกลับคืน และหลักฐานการแก้ไขระบบควบคุม


สุดท้าย บริษัทต้องแก้ไขจุดอ่อนที่ทำให้เหตุการณ์เกิดขึ้น ไม่ควรมีบุคคลเพียงคนเดียว แม้จะเป็น CFO สามารถทำลายข้อมูลทางการเงินทั้งหมดอย่างถาวรโดยไม่มีระบบสำรอง กลไกกู้คืน การบันทึกประวัติ หรือการตรวจสอบโดยบุคคลอื่น ระบบสำรองควรแยกออกจากสิทธิผู้ดูแลระบบทั่วไป การลบข้อมูลสำคัญควรมีประวัติและการแจ้งเตือน และข้อมูลต้องสามารถกู้คืนได้แม้บัญชีผู้ใช้งานระดับสูงถูกนำไปใช้โดยมิชอบ


โดยสรุป การจงใจลบข้อมูลบัญชีอาจกระทบพร้อมกันทั้งกรมพัฒนาธุรกิจการค้า กรมสรรพากร ธนาคาร เจ้าหนี้ ลูกหนี้ และผู้สอบบัญชี หากเป็นบริษัทจดทะเบียน ผลกระทบจะขยายไปยังตลาดหลักทรัพย์ ก.ล.ต. และผู้ถือหุ้น และหากเป็นบริษัทย่อยของบริษัทจดทะเบียนในต่างประเทศ ปัญหาอาจกระทบงบรวม การเปิดเผยข้อมูลของบริษัทแม่ ระบบควบคุมของกลุ่ม และความเห็นของผู้สอบบัญชีกลุ่มด้วย


ผู้ที่จงใจทำลายข้อมูลอาจมีความรับผิดตามกฎหมายเป็นการส่วนตัว แต่บริษัทก็ยังคงต้องปฏิบัติหน้าที่ของตนเอง ดังนั้น คำว่า “CFO เป็นคนลบข้อมูล” เป็นเพียงคำอธิบายว่าเหตุการณ์เกิดขึ้นอย่างไร ไม่ใช่คำตอบต่อกรมพัฒนาธุรกิจการค้า กรมสรรพากร ตลาดหลักทรัพย์ ก.ล.ต. ธนาคาร ผู้ถือหุ้น บริษัทแม่ หรือผู้สอบบัญชี


สิ่งที่ปกป้องบริษัทได้ดีที่สุดคือหลักฐานว่าได้ดำเนินการอย่างรับผิดชอบ ได้แก่ รักษาหลักฐาน แจ้งเหตุโดยเร็ว สอบสวนการทุจริตอย่างเป็นอิสระ สร้างบัญชีและข้อมูลภาษีกลับจากแหล่งที่ตรวจสอบได้ สื่อสารอย่างโปร่งใสกับหน่วยงานกำกับ ธนาคาร คู่ค้า ผู้ถือหุ้น และผู้สอบบัญชี แจ้งบริษัทแม่และผู้สอบบัญชีกลุ่มทันทีเมื่อเกี่ยวข้อง และปรับปรุงระบบควบคุมเพื่อให้ไม่มีบุคคลใดสามารถทำลายประวัติทางการเงินทั้งหมดของบริษัทได้อีกโดยไม่มีทางกู้คืน

External References

  • Department of Business Development — Accounting Act B.E. 2543, including requirements for preparation, retention and notification of lost accounting records, and related penalties.
  • Department of Business Development — Published fine schedule relating to delayed submission of financial statements. (e-Filing)
  • Revenue Department — Section 71(1) and published Supreme Court decisions concerning inability to provide adequate accounting records. (Royal Decree)
  • Stock Exchange of Thailand — Material-event disclosure requirements, including events or indicators affecting internal control systems. (SET Market)
  • Stock Exchange of Thailand — Periodic financial-reporting requirements and consequences of failure to submit financial statements, including SP and possible delisting. (SET Market)
  • Securities and Exchange Commission, Thailand — Financial statements and reports under section 56 and listed-company reporting requirements. (SEC Thailand)
  • Securities and Exchange Commission, Thailand — Recent supervisory cases requiring cooperation with auditors and corrected financial statements. (SEC Thailand)
  • IAASB — ISA 600 (Revised), Special Considerations—Audits of Group Financial Statements. (IAASB)
  • IAASB — ISA 705 (Revised), Modifications to the Opinion in the Independent Auditor’s Report. (IAASB)


Comments
* The email will not be published on the website.