Why the 2025–26 reports require partner attention now

The Accounting and Financial Reporting Council (AFRC) has released its 2025–26 Annual Inspection Report and inaugural Annual Enforcement Report. Together, the reports make a clear point: audit quality is being assessed as the product of the firm’s system of quality management, engagement execution, governance, documentation discipline, independence and regulatory compliance—not merely the appearance of one completed audit file.[1] [2] [3]

The reporting period ended on 31 March 2026. During it, AFRC inspected 39 audit firms and a selection of 90 completed audit engagements. The population included 58 listed-entity audits completed by 25 public interest entity (PIE) auditors. It also carried out additional AML/CTF compliance inspections at 27 firms against the HKICPA’s Guidelines on Anti-Money Laundering and Counter-Terrorist Financing for Professional Accountants, which form part of the Code of Ethics for Professional Accountants.[1] [2]

The immediate message for Hong Kong practice owners is not to wait for an inspection notice. The AFRC identifies uneven progress across the profession and continuing difficulty in complex, judgement-intensive areas, including revenue recognition, asset impairment, going concern and fraud-risk identification. These are areas in which the file must show the auditor’s reasoning, challenge and evidence—not simply a standard conclusion.[1]

The inspection agenda: five areas that should be tested together

The AFRC identifies five continuing areas of significant attention. They are connected. A firm that has a weak staffing plan will struggle to maintain professional scepticism. A firm that accepts an uneconomic fee may compress work and review time. A firm that introduces technology without governance may compromise data integrity or create an output that the engagement team cannot explain. The appropriate response is therefore an integrated management review, not five separate compliance checklists.[1] [2]

1. Resource management and reviewer capacity

AFRC expects firms to ensure that engagement teams have the necessary skills and relevant industry experience. It also expects rigorous management of partner workloads so that engagement partners and engagement quality reviewers can fulfil their responsibilities effectively.[1] Before accepting or continuing an engagement, the practice should document its capacity assessment: the engagement partner’s portfolio, manager and senior availability, industry experience, specialist requirements, reporting deadline, complexity, consultation needs and reviewer availability.

This review should not be confined to the planning file. The firm should periodically compare planned hours and review stages with actual progress, late adjustments, consultations and unresolved matters. Where the resource model is no longer realistic, the engagement should be escalated. This is especially important when a small practice has a limited pool of partners or reviewers and several high-risk assignments converge at the same reporting date.

2. Audit fee pressure and a quality-first culture

The AFRC states that audit fees must be commensurate with the resources needed to execute a high-quality audit, and that commercial pressures must never compromise auditor objectivity.[1] In its public message, the AFRC’s Chief Executive Officer described audit fees as an investment in trust rather than a cost to be minimised.[1] The practical implication is that partners should be able to explain how the engagement budget, staffing plan and review time support the assessed risk and audit strategy.

A fee-acceptance record should therefore explain significant discounts, scope changes, time pressure and the firm’s response. It should also identify who has authority to approve an engagement where the proposed fee or timetable is inconsistent with the work required. This protects both the engagement team and the firm’s quality-management process from a commercially driven reduction in necessary procedures or review.

3. Professional scepticism and defensible judgements

AFRC expects firm leadership—including the chairman and managing partner—to champion a quality-first culture that empowers auditors to exercise strong professional scepticism and challenge management’s key assumptions.[1] The relevant question is not whether the working paper contains a conclusion, but whether another experienced auditor can understand the facts considered, the risks identified, the evidence obtained, contrary information, management’s assumptions, consultations, challenge applied and basis for the conclusion.

For revenue, impairment, going concern and fraud risk, practices should reperform a focused sample review. The review should ask whether the audit response is linked to the assessed risk, whether contradictory evidence has been resolved rather than ignored, and whether the final conclusion is consistent with the evidence. Templates can support consistency, but they must be tailored to the client and must not replace the engagement team’s professional judgement.

4. Group audit oversight, IT governance and AI-enabled tools

The AFRC calls for rigorous direction, supervision and review of component auditors in cross-border audits, particularly because of the growing number of overseas issuers in Hong Kong’s capital markets.[1] Firms should be able to demonstrate what instructions were issued, how component-auditor competence and independence were considered, what work was reviewed, how significant risks and findings were communicated, and how the group engagement partner concluded on the sufficiency of involvement.

The regulator also expects auditors to identify and address complex IT and cybersecurity risks in IT-intensive environments. In the context of rapid AI adoption, it calls for robust IT governance, protection of data integrity and rigorous professional judgement in the deployment of technological audit tools.[1] Firms should approve intended tool use, assess client-data confidentiality, restrict access, retain evidence of material inputs and outputs, and make sure the engagement team can explain and review the result. Automated work is not a substitute for supervision, consultation or audit evidence.

5. Enforcement themes: documentation, independence and AML/CTF

The inaugural Annual Enforcement Report reinforces the inspection message with sanctions and recurring misconduct themes. During the reporting year, AFRC completed 81 investigation and enquiry cases and 22 disciplinary cases. Sanctions included public reprimands, pecuniary penalties exceeding HK$11.7 million in total and, where appropriate, suspension of registration and cancellation of practising certificates. Seventeen disciplinary cases published in the year concerned misconduct involving PIE auditors or listed-entity engagements and accounted for around HK$10 million of the total pecuniary penalties.[1] [3]

The enforcement themes are specific: deficient systems of quality management and control; significant audit deficiencies and inappropriate audit opinions; systemic late file archiving and backdating of working papers; non-compliance with registration requirements; breach of auditor independence requirements; and non-compliance with the AML/CTF Guidelines for Professional Accountants.[1] [3] These themes are not administrative side issues. They go directly to whether audit records can be relied upon, whether an auditor is eligible and objective, and whether a firm can demonstrate the operation of its controls.

For practices that also provide TCSP services, AML/CTF should be connected to the wider governance framework. Client acceptance, beneficial-owner information, risk assessment, ongoing monitoring, escalation, record retention and staff training should operate coherently across relevant service lines. A current policy manual is insufficient if the practice cannot demonstrate testing, exception handling and remediation.

SQM monitoring and completed-file monitoring are complementary

Firms should distinguish between the annual monitoring required under HKSQM 1 and a completed-file monitoring review. An SQM monitoring review considers whether the system of quality management is designed, implemented and operating effectively at the practice level. It asks whether leadership, risk assessment, acceptance and continuance, resources, information and communication, monitoring and remediation operate as a system. A completed-file monitoring review tests whether an individual completed engagement evidences appropriate execution, supervision, review, documentation and conclusions.

The distinction matters because a firm can have a sensible manual but still produce weak engagement files, or it can identify isolated file deficiencies without addressing the firm-wide cause. AFRC’s focus on leadership, governance, monitoring and remediation, alongside its focus on completed engagement deficiencies, makes both perspectives important.[1] [2] A monitoring programme should connect the findings: recurring file issues should inform root-cause analysis and firm-wide remedial action, while firm-wide risks should shape the selection and depth of completed-file reviews.

A practical 30-day response for practice owners

Within the next 30 days, the managing partner or quality-management lead should commission a documented gap assessment against the AFRC’s five inspection focus areas and enforcement themes. The assessment should review partner and reviewer workloads; fees and scope changes for higher-risk engagements; a sample of completed files in revenue, impairment, going concern and fraud-risk areas; archive timing; independence and registration checks; group-audit oversight; technology and data-governance controls; and the operation of AML/CTF procedures. Each finding should be assigned an owner, due date, evidence requirement and follow-up test.

EQC Compliance Advisory can support this response through an External Annual SQM Monitoring Review of firm-wide quality-management design and operation, together with Completed File Monitoring Reviews that test engagement-level execution. This combination helps a practice distinguish a one-file correction from a sustainable remedial action. Where a digital workflow is appropriate, AP4.1 can generate audit programmes and engagement-level working papers without compromising client confidential data and without requiring an upfront investment in IT infrastructure. The appropriate scope should always reflect the firm’s engagements, resources, risk profile and existing controls.

This article provides general information only. It is not legal, tax, audit or regulatory advice and should be considered in light of a firm’s own circumstances.

PHP Code Snippets Powered By : XYZScripts.com
Scroll to Top