(Corporate Governance & Professional Conduct)

Price is not the control; the fee-to-risk decision is

A low audit fee is not automatically evidence of a deficient audit, and a high fee is not evidence of quality. The control question is more precise: can the firm demonstrate that the approved fee, scope, risk assessment, team structure, time budget, review effort and specialist input can support a quality audit? If the answer cannot be reconstructed from the acceptance or continuance file, the engagement has a commercial decision with no quality-management evidence behind it.

A July 2026 Hong Kong Government reply gives this question practical urgency. It states that the Accounting and Financial Reporting Council (AFRC) may further examine an engagement where the fee is clearly disproportionate to the scope, risk and complexity of the work, including whether sufficient manpower, time and professional resources were deployed and whether audit-quality or professional-conduct issues arise.[1] It does not introduce a statutory minimum fee or a prohibition on fee reductions. The response instead reinforces a familiar but often poorly evidenced principle: an audit firm must make a risk-based resource decision and be able to explain it.

This is not only an audit-firm issue. A listed issuer’s audit committee, board, finance team and procurement process can either enable or undermine a sound appointment decision. The same Government reply links audit quality to existing governance arrangements around independent non-executive directors (INEDs), director continuing professional development and board-performance evaluation.[1] The practical objective is therefore a shared evidence trail: the audit firm can show why it accepted and resourced the engagement; those charged with governance can show why they appointed, challenged and oversaw the auditor.

The EQC fee-to-quality control chain

EQC recommends treating the engagement fee as a quality-control input through five linked gates: scope and risk, resource model, commercial pressure, execution evidence and governance challenge. The chain matters because a weakness at any gate can make later explanations unconvincing. A realistic budget cannot cure an acceptance decision made without understanding the engagement. Extra hours cannot cure a team that lacks competence in a specialist area. An audit committee cannot exercise meaningful challenge if it receives only a fee comparison with no scope, risk or resourcing analysis.

The chain is not a mandatory template imposed by a regulator. It is an EQC operating framework for applying existing professional responsibilities in a way that is testable. Each gate should produce a retained artefact: a scoped risk memo, a team-and-hours model, a commercial-pressure assessment, an execution-versus-budget review and a communication record for the engagement partner, quality leader or audit committee. Together, those artefacts turn “we had enough resources” from an assertion into evidence.

1. Scope and risk: establish the work before negotiating the price

The engagement team should define the work before treating the fee as final. The acceptance or continuance record should identify the reporting framework, entity and group structure, component locations, industry risks, significant classes of transactions, material estimates, related parties, going-concern conditions, fraud risks, systems environment, specialists, timetable and reporting obligations. Where the client asks for a fee quote before all information is available, the proposal should state the assumptions, exclusions and conditions rather than disguise uncertainty inside a fixed amount.

A prior-year fee is not a sufficient baseline. Changes in acquisitions, disposals, new financing, regulation, data systems, management turnover, accounting judgments, audit findings, component auditors, deadlines or expected deliverables may require a different scope. A concise “change since prior year” schedule is one of the strongest files a practice can retain. It forces the partner to explain why a lower, flat or higher fee remains compatible with the new risk profile.

The Government reply notes that AFRC has collected market information and says listed-company audit fees were broadly stable from 2018 to 2022, with 2022 mean and median engagement fees of HK$5.4 million and HK$2.1 million respectively.[1] These figures are market context, not a benchmark for any particular firm or client. They should never be used to justify a price by comparison alone. A small, simple client may need fewer resources; a similarly sized client with complex estimates, weak controls or compressed reporting may need materially more. The defensible comparison is the engagement’s own risk-to-work model.

2. Resource model: make the budget capable of being challenged

A quality budget should show the planned hours, grade mix and key responsibilities for planning, fieldwork, supervision, review, engagement-quality review where applicable, consultations, component coordination, specialist work, completion and reporting. It should also identify non-chargeable but necessary quality work such as coaching, re-performance, technical consultation and remediation of incomplete evidence. The objective is not to promise that every planned hour will be used. It is to demonstrate that the initial plan was feasible for the identified risk.

Use a fee-to-risk reconciliation. Begin with the key risks and translate each one into planned procedures, the appropriate level of staff, expected hours, reviewer attention and evidence output. For a complex revenue stream, the file might link the risk to contract analysis, information-technology involvement, sample design, evidence evaluation, partner review and a conclusion memo. For a material impairment, it might link the risk to valuation expertise, sensitivity testing, management challenge, disclosures and consultation. If an important risk has no related time, skill or review allocation, the budget is signalling a control gap.

Set internal escalation triggers, but label them correctly as firm controls rather than official thresholds. A significant fee reduction, a tender routed through an intermediary, a highly compressed timetable, a recurring time overrun, a new high-risk accounting issue, a specialist-resource constraint or a client request to remove procedures can each require documented partner and quality-leader review. The 20 per cent fee-cut statistic reported by the Government—where the share of listed-company auditor changes involving such cuts fell from 62 per cent in 2020 to 53 per cent in 2024—is useful for market monitoring only.[1] It is not a safe harbour or a universal trigger. A firm should define triggers that suit its own portfolio and risk appetite.

3. Commercial pressure: document the threat, safeguards and decision

Commercial pressure is often most visible when it is least documented. It can arise from a competitive tender, a client comparison to a cheaper firm, a short filing deadline, an intermediary’s proposed scope, pressure to accept a fee after work has expanded, or an expectation that the auditor will take management representations at face value to preserve the relationship. The response should not be a vague note that “independence was considered.” It should identify the pressure, the threat it creates, the safeguards, the approver and the action if the conditions cannot be met.

The Government reply is particularly clear about intermediaries: where audit services are referred through accounting-services intermediaries, the auditor remains responsible for professional ethics, audit quality and professional judgment.[1] An intermediary does not own the signing auditor’s responsibilities. The file should therefore record who introduced the client, what service terms were proposed, whether the intermediary influences scope or staffing, how communications are controlled, whether referral arrangements create conflicts, and who has authority to approve changes in fee or scope.

A practical safeguard can be simple. The engagement partner may require a revised scope and budget, a second-partner challenge, technical consultation, additional specialist time, a documented communication to those charged with governance, or a decision not to accept work on the proposed terms. The important point is that the safeguard must change the risk position. A boilerplate declaration does not compensate for an engagement that is still under-resourced after the declaration is signed.

4. Execution evidence: compare the plan with how the audit was actually performed

The fee-to-quality decision must be revisited during the audit. A planned budget is not a permanent conclusion. Engagement managers should periodically compare actual and forecast hours, unresolved risks, staffing changes, consultation needs, review points, delayed client information and scope changes with the approved plan. Where facts change, the record should show what changed, why it matters, who decided, whether the client was informed and how the audit plan or resources were adjusted.

A useful completed-file test traces one significant risk from acceptance to completion. The reviewer should be able to locate the initial risk assessment, planned procedures, budget allocation, work performed, exception or consultation, review notes, final conclusion and any variance from planned hours or staffing. If the final file has good substantive procedures but no explanation for why the engagement exceeded its planned effort, the firm has lost information needed for next year’s acceptance and budget decisions. If it remained within budget only because planned work was removed, the reviewer needs evidence that the revised approach remained sufficient and appropriate.

This is also where a quality-management system becomes operational. Aggregate the variances: which industries, client types, partners, intermediaries, reporting deadlines or risk areas repeatedly produce under-budgeted work? Are fee reductions associated with late evidence, unplanned senior time, incomplete review, high consultation demand or rework? The answers are management information. They should influence next-year pricing, staffing, acceptance criteria, training and monitoring—not merely be recorded in a time system.

5. Governance challenge: give the audit committee information it can use

For listed issuers, an auditor appointment recommendation should enable a substantive discussion rather than a lowest-price comparison. A board or audit committee can request a clear explanation of the proposed scope, material changes from the prior year, significant risks, planned seniority and specialist involvement, expected timetable, audit-quality indicators, independence matters, reasons for the proposed fee and any conditions that could cause a scope or fee change. It need not receive the audit firm’s proprietary working papers. It does need enough information to evaluate whether the appointment decision is responsible.

The Government reply confirms that the July 2025 HKEX Corporate Governance Code and related Listing Rule amendments introduced director continuing-professional-development requirements and enhanced board-performance-evaluation disclosures.[1] It also describes existing nomination and remuneration committee structures: each committee has INED majority membership and is chaired by the board chairman or an INED in the case of nomination, and by an INED in the case of remuneration. These are current governance features, not a new INED remuneration floor. A firm should avoid claiming that Hong Kong imposes a mandatory minimum audit fee or a minimum INED payment; the Government explicitly supports the existing market-based approach.

The practical governance connection is workload evidence. The committee responsible for recommending or overseeing the auditor should be able to show that members had time, information and competence to challenge the proposed appointment, related independence matters and significant changes during the audit. For the issuer, that evidence may sit in committee papers, attendance records, minutes, CPD records, board-evaluation material and follow-up actions. For the audit firm, it sits in communications with those charged with governance, independence records and documented responses to scope or resource constraints.

A 90-day implementation plan

In the first 30 days, design a concise acceptance-and-budget pack. Require a risk-to-work matrix, prior-year change schedule, hours and grade mix, specialist and reviewer plan, fee assumptions, commercial-pressure assessment, intermediary check and approval record. Identify all current listed-issuer and high-risk engagements with material fee reductions, recurring overruns, late reporting, unusual referral arrangements or changes in scope. These are priority files for partner and quality-leader review, not automatic indicators of misconduct.

In days 31–60, test operating effectiveness on a sample. Reperform the fee-to-risk reconciliation for selected engagements. Trace one significant risk through planning, time allocation, evidence, review and conclusion. Compare actual hours and staffing to the approved plan, inspect whether scope changes were approved, and test whether commercial-pressure matters were escalated. For listed-issuer work, inspect communications with those charged with governance and evaluate whether appointment and oversight papers enable a meaningful decision rather than a price-only selection.

In days 61–90, convert findings into governance. Trend the causes of fee and resource variances, identify root causes, revise pricing or acceptance guidance, allocate training and set effectiveness tests for the next monitoring cycle. EQC Compliance Advisory can assist through an Audit-Fee Adequacy, Engagement Resourcing and Board/Audit-Committee Oversight Effectiveness Review. The review assesses fee-to-risk evidence, team capacity, commercial-pressure safeguards, execution variances and governance communications, then produces a prioritised remediation plan. The aim is not to set a fee. It is to make the firm’s quality and professional-judgment decisions demonstrably sustainable.

This article provides general information only. It is not legal, tax, audit or regulatory advice and should be considered in light of a firm’s own circumstances.

Scroll to Top