Why this case deserves attention beyond its historical audit period

On 3 September 2026, the Accounting and Financial Reporting Council (AFRC) announced disciplinary action against HLB Hodgson Impey Cheng Limited and two practising directors for multiple deficiencies in the audit of Sound Global Ltd.’s 2014 consolidated financial statements. The source audit period was historical, but the regulatory message is immediate: an incoming auditor who knows of fraud indicators or significant predecessor-auditor concerns must design and perform a heightened, well-documented audit response. Routine procedures and unsupported management representations will not suffice.[1] [2]

The AFRC publicly reprimanded the audit firm, the engagement director and the engagement quality-control reviewer. It imposed pecuniary penalties of HK$490,000, HK$350,000 and HK$70,000 respectively, totalling HK$910,000.[1] The decision identifies deficiencies involving fraud-risk response, external confirmations, opening bank balances, balances due from or to customers for contract work, trade receivables, construction revenue estimates and documentation of alternative procedures. These issues are relevant to a broad range of Hong Kong audit files—not only environmental-construction or formerly listed entities.

Hong Kong CPA firms should treat the decision as an immediate engagement, methodology and competence review trigger. Firms must prove that prior deficiencies were remediated and tested—not merely logged.

The engagement context: an incoming auditor facing known red flags

AFRC states that the case followed a complaint by a local financial regulator in 2016. The complaint was based on allegations in a February 2015 short-seller report that the company had inflated revenue and bank balances. The predecessor auditor resigned after identifying a potential cash shortfall of about RMB2 billion between the company’s books and bank balances, together with related fraud risks. HLB was appointed in July 2015 and was aware of the short-seller report and the potential audit issues when it accepted the engagement.[1]

An incoming auditor is not required to assume every allegation is correct. However, information from public sources, a predecessor auditor, regulators, whistleblowers or the client’s own records can change the assessed risk. It should trigger a documented assessment of credibility, relevance, potential financial-statement assertions, possible management bias or override, implications for engagement acceptance and the procedures required to obtain sufficient appropriate evidence. If the client cannot provide reliable records or access to independent evidence, the engagement team should escalate the matter promptly rather than allow the issue to become a year-end documentation problem.

1. Maintain auditor control over external confirmations

AFRC explains that external confirmations can support the existence of opening bank balances only when the auditor maintains control over the confirmation process and can establish the reliability of the confirmations. Direct receipt from the confirming party is one way of achieving that control.[1] In the case, there was no evidence in the working papers of who returned 126 of 129 bank confirmations, or how their authenticity had been verified. Those 126 confirmations represented more than 99% of the group’s opening bank balances.[1] [2]

The practical control is not simply to send a confirmation form. Engagement teams should document the request population and selection rationale, the verified address or electronic channel, dispatch and return arrangements, receipt provenance, follow-up, exceptions, authenticity checks and how information received was reconciled to the client’s records. Where the confirmation process is electronic or assisted by a service provider, the file should show why the channel and respondent are reliable. The same discipline applies to customer, supplier and contract-work balances. An answer that appears favourable but has an unexplained origin is not automatically reliable audit evidence.

2. Design alternative procedures that can actually address the assertion

AFRC found that additional procedures said to have been performed did not verify the existence of the opening bank balances. The examples described—viewing information on bank staff computer screens during visits and calling general branch telephone lines—were inherently impracticable for the asserted purpose. The audit working papers also did not record sufficient details of the work, including specific dates, times or locations of bank visits.[1]

Alternative procedures are not a label for any work performed after a confirmation difficulty. Before relying on them, the team should state the assertion that remains unaddressed, why the original procedure did not produce sufficient evidence, the source of the alternative evidence, why that source is relevant and reliable, how the work responds to the identified risk and what result was obtained. Documentation should identify the performer, reviewer, date, population or item tested, method, source records, exceptions and conclusion. For a high-risk opening balance, a vague note that a bank was visited or called will rarely allow a reviewer to evaluate whether the evidence was capable of supporting existence, rights, completeness or valuation, as applicable.

3. Treat opening balances and receivables as linked evidence risks

AFRC identified similar weaknesses in work over opening balances of amounts due from or to customers for contract work and trade receivables. The working papers did not evidence who had returned the confirmations or how authenticity had been verified, and the additional procedures were insufficiently documented.[1] This illustrates an important quality-control point: different balance-sheet captions may share the same underlying evidence risk. A weak confirmation workflow can affect cash, receivables, contract-work balances and other third-party evidence across a file.

A focused file review should therefore assess the confirmation process as a system. It should test whether selections are risk-responsive, controls over dispatch and receipt are preserved, non-responses are followed up appropriately, alternative procedures are assertion-specific and material exceptions are escalated. It should also consider whether engagement teams are over-relying on client-prepared schedules, unsupported explanations or documents that lack a verified independent source. Where deficiencies are found in one material balance, the reviewer should decide whether the root cause affects other audit areas rather than closing the issue as a single isolated exception.

4. Make revenue estimates and construction progress auditable

For revenue from turnkey projects and services, AFRC found that the auditor had not obtained an understanding of, or evaluated the reasonableness of, management’s construction-revenue estimates. The working papers did not refer to construction contracts or progress reports, and contained no summary of the key terms of each contract.[1] The lesson for any judgmental revenue model is straightforward: the file must connect the accounting conclusion to the relevant contract terms, factual progress evidence, management assumptions, contradictory evidence, audit challenge and final conclusion.

For projects, long-term contracts, milestones or service arrangements, teams should identify the contractual performance obligations and payment terms; understand the client’s measurement of progress; inspect appropriate supporting evidence; reconcile calculations to accounting records; test significant inputs; evaluate changes from prior periods; and document the basis for the audit response. The necessary procedures will vary with the reporting framework, engagement facts and risk assessment. What should not vary is the need to explain why the evidence supports management’s estimate and why the audit team’s conclusion remains appropriate when there are red flags or heightened fraud risks.

5. Give engagement quality review a focused evidence agenda

The disciplinary outcome applied not only to the audit firm and engagement director, but also to the engagement quality-control reviewer.[1] This is a reminder that a quality review should focus on the engagement’s significant judgments, risk responses and conclusions. A reviewer does not improve audit quality by checking that every template is present. The reviewer should be able to identify whether a known fraud indicator has been translated into a robust strategy, whether the evidence for a material balance is traceable and reliable, and whether alternative procedures resolve rather than merely describe an evidence gap.

The AFRC assessed this case under the prior disciplinary regime because the 2014 audit pre-dated 1 October 2019. It nevertheless noted that substantially more severe sanctions could be expected for similar misconduct in PIE audit engagements arising on or after that date under the current regime.[1] This should increase the urgency of robust pre-issuance review and timely remediation, particularly for PIE, listed-entity, regulated-entity and other public-interest engagements.

A 30-day review plan for firm leadership

Within 30 days, the managing partner or quality-management lead should identify incoming, high-fraud-risk and high-judgment engagements; select a risk-based sample of completed or near-completion files; and test external-confirmation control, alternative procedures, opening-balance evidence, receivable evidence, revenue estimates and documentation of professional scepticism. The review should include prior audit findings and the status of remedial actions. Results should be analysed for recurring methodology, training, supervision, consultation, workload or culture causes—not just file-level corrections.

EQC Compliance Advisory can provide an Audit Evidence, Fraud-Risk and Incoming-Engagement File Review Workshop, including a targeted diagnostic of confirmation controls, alternative-procedure documentation, red-flag response, construction or contract-revenue evidence and pre-issuance review questions. The output can be a prioritised remediation plan, partner briefing and practical working-paper guidance. Where a practice needs a more consistent digital documentation workflow, AP4.1 can generate audit programmes and engagement-level working papers without compromising client confidential data and without requiring an upfront investment in IT infrastructure. Technology should support, not replace, the professional scepticism and evidence evaluation expected by AFRC.[1]

This article provides general information only. It is not legal, tax, audit or regulatory advice and should be considered in light of a firm’s own circumstances.

PHP Code Snippets Powered By : XYZScripts.com
Scroll to Top