ISA 250 (Revised) – Consideration of Laws and Regulations in an Audit of Financial Statements deals with the auditor’s responsibility to consider laws and regulations in an ‘audit‘ of financial statements.
Last Updated – August, 2026

ISA 250
Consideration of Laws and Regulations in an Audit of Financial Statements; what auditors must do, and where their duty ends.
What Is ISA 250?
ISA 250, Consideration of Laws and Regulations in an Audit of Financial Statements, is issued by the International Auditing and Assurance Standards Board (IAASB) under the International Federation of Accountants (IFAC). It sets out the auditor's responsibility to consider laws and regulations when auditing a set of financial statements.
ISA 250 requires the auditor to obtain evidence of compliance with laws that directly determine amounts in the financial statements, and to perform specified procedures to help identify non-compliance with other laws that could still have a material effect.
Objectives of ISA 250
Under ISA 250, the auditor works toward three linked objectives:
- Obtain sufficient appropriate audit evidence regarding compliance with laws and regulations generally recognised to have a direct effect on the determination of material amounts and disclosures in the financial statements, such as tax and pension law.
- Perform specified audit procedures to help identify instances of non-compliance with other laws and regulations that may have a material effect on the financial statements.
- Respond appropriately to non-compliance, or suspected non-compliance, identified during the audit.
Scope of ISA 250
ISA 250 is split into two parts, and it matters which one applies to a given engagement.
| Part | Applies to | Focus |
|---|---|---|
| Part A | All audits of financial statements | General requirements for considering laws and regulations, wherever the entity operates or whatever sector it is in. |
| Part B | Audits of financial statements of entities that are regulated financial institutions (e.g. banks, insurers) | Additional responsibilities that arise when law or regulation requires the auditor to report identified or suspected non-compliance to a supervisory or regulatory authority. |
Key Definitions
- Non-compliance
- Acts of omission or commission, intentional or unintentional, committed by the entity, or by those charged with governance, by management, or by employees or others working under the entity's direction, which are contrary to the prevailing laws or regulations.
- Direct-effect laws
- Laws and regulations generally recognised to have a direct effect on determining material amounts and disclosures in the financial statements, such as tax law and financial reporting frameworks themselves.
- Other laws and regulations
- Laws that do not have a direct effect on the determination of the amounts and disclosures in the financial statements, but compliance with which may be fundamental to the operating aspects of the business, its ability to continue trading, or to avoiding material penalties.
Direct Effect vs Indirect Effect Laws
This distinction is very crucial, because it determines how far the auditor is required to go.
Laws with a direct effect on the financial statements
Some laws feed straight into the numbers, corporate tax legislation determines the tax charge and provision, for example. For these, the auditor's responsibility looks much like the responsibility for any other material balance: obtain sufficient appropriate audit evidence of compliance, using the normal risk-assessment and substantive procedures set out in other ISAs.
Laws with only an indirect effect
Other laws; environmental permits, health and safety regulation, data protection rules, sector licensing do not appear as a line item anywhere, yet breaching them can trigger fines, loss of licence, reputational damage, or a going-concern problem. For this category, ISA 250 does not ask the auditor to test compliance directly. It asks for a lighter, more targeted set of procedures aimed at remaining alert to signs of trouble, not at conducting a compliance audit.
The auditor is not, and is not required to be, a legal expert. ISA 250 explicitly limits the auditor's role for indirect-effect laws to awareness and enquiry, not investigation or legal judgment.
Auditor's & Management's Responsibilities Under ISA 250
ISA 250 is explicit that responsibility for compliance with laws and regulations rests with management, with oversight from those charged with governance. The auditor's role is narrower and comes with built-in limitations.
- Management is responsible for ensuring the entity's operations are conducted in accordance with laws and regulations, including compliance with those that determine reported amounts.
- The auditor is responsible for obtaining reasonable assurance that the financial statements, taken as a whole, are free from material misstatement, whether caused by fraud or error, not for preventing or detecting all non-compliance.
- An audit carries an inherent risk that some material misstatements will not be detected, even when the audit is properly planned and performed. That risk is higher for non-compliance than for other kinds of misstatement, because non-compliance can involve concealment, collusion, forgery, deliberate non-recording of transactions, or management override of controls.
Audit Procedures Required by ISA 250
To meet its objectives, the audit team is required to carry out a defined set of procedures throughout the engagement.
Understand the framework
Obtain a general understanding of the legal and regulatory framework applicable to the entity and the industry, and how the entity complies with it.
Inspect correspondence
Inspect correspondence, if any, with licensing or regulatory authorities for indications of non-compliance.
Enquire of management
Ask management, and those charged with governance, whether the entity is in compliance and how it identifies and responds to legal matters.
Stay alert
Remain alert throughout the audit to instances of non-compliance or suspected non-compliance identified through other procedures, such as reading minutes or testing transactions.
Professional scepticism is maintained throughout: the auditor recognises that the audit may bring to light instances of non-compliance regardless of how well the planned procedures are designed.
When Non-Compliance Is Identified or Suspected
Once something surfaces, ISA 250 sets out a clear sequence rather than leaving the response to instinct.
- Understand the matter. Obtain an understanding of the nature of the act and the circumstances in which it occurred, and gather further information to evaluate the possible effect on the financial statements.
- Discuss with management. Where appropriate, discuss the matter with management and, where relevant, those charged with governance.
- Consider legal advice. If management or those charged with governance do not provide sufficient information to support that the entity is in compliance, and the matter is judged significant, consider the need to obtain legal advice.
- Evaluate the effect on the audit. If the auditor is unable to obtain sufficient appropriate audit evidence about suspected non-compliance, evaluate the effect of that limitation on the audit opinion.
- Consider the wider implications. Evaluate the implications of the non-compliance in relation to other aspects of the audit, including the risk assessment and the reliability of management representations.
Reporting Requirements Under ISA 250
ISA 250 requires the auditor to communicate matters of non-compliance to those charged with governance, unless the matter is clearly inconsequential. Where governance itself may be implicated, the standard requires the auditor to escalate. For example, to an audit committee, a supervisory board, or, in some structures, to the owners.
Part B adds a further layer for regulated entities: where law, regulation, or relevant ethical requirements clearly require it, the auditor reports identified or suspected non-compliance to an appropriate authority outside the entity, such as a financial regulator, even where this overrides the usual duty of confidentiality.
Finally, the auditor considers the implications for the engagement itself including, in serious cases and where permitted by applicable law, whether continuing the engagement remains appropriate, and documents the identified or suspected non-compliance, the results of discussions with management and those charged with governance, and how the matter was resolved.
ISA 250 vs ISA 240
The two standards are often confused because both deal with wrongdoing, but they answer different questions.
| ISA 250 | ISA 240 | |
|---|---|---|
| Subject | Compliance with laws and regulations generally | Fraud specifically |
| Intent | Covers both intentional and unintentional acts | Concerned with intentional acts to obtain unjust advantage |
| Depth of testing | Awareness and enquiry for indirect-effect laws; full evidence for direct-effect laws | Dedicated risk assessment, brainstorming, and response requirements for fraud risk |
| Overlap | Fraud is treated as one form of non-compliance | Non-compliance uncovered may itself point to fraud, triggering ISA 240 |
In practice the two standards work side by side: a finding under ISA 250 can trigger procedures under ISA 240, and vice versa, particularly where non-compliance involves deception, bribery, or corruption.
Frequently Asked Questions
Does ISA 250 make the auditor responsible for detecting all non-compliance?
No. The auditor's objective is reasonable assurance that the financial statements are free from material misstatement. ISA 250 explicitly recognises the inherent limitations of an audit, meaning some non-compliance, especially where it involves concealment or collusion, may go undetected even in a properly performed audit.
What is the difference between direct-effect and indirect-effect laws under ISA 250?
Direct-effect laws determine amounts and disclosures directly reported in the financial statements, such as tax law. Indirect-effect laws govern how the business operates; licensing, environmental, or safety rules and only affect the financial statements if a breach leads to fines, penalties, or a threat to the entity's ability to continue operating.
When must an auditor report non-compliance outside the entity?
Only when required to do so by law, regulation, or relevant ethical requirements. Part B of ISA 250 addresses this specifically for audits of regulated financial institutions, where reporting suspected non-compliance to a supervisor may be a legal obligation that overrides ordinary confidentiality.
Is ISA 250 the same as SA 250?
Many national auditing bodies adopt the IAASB's International Standards on Auditing into local standards with minimal wording changes; SA 250 in some jurisdictions is the domestically adopted equivalent of ISA 250, and the two are applied in substantially the same way.
How does ISA 250 relate to fraud under ISA 240?
Fraud is treated as a form of non-compliance with laws and regulations. Where an auditor's work under ISA 250 uncovers indicators consistent with fraud, the requirements of ISA 240 are applied alongside it.
The standard's real achievement is restraint: it gives the auditor a defined, workable duty regarding law and regulation, without quietly expanding the audit into a legal compliance review it was never designed to be.
About the author - Jhanzayb, ACA
Jhanzayb is a Qualified Chartered Accountant (ACA) writing on audit and assurance for Entrepreneurial Hub. Read his full credentials and areas of expertise on the author page.
About this page: This article summarises the requirements of ISA 250, Consideration of Laws and Regulations in an Audit of Financial Statements, for general educational purposes. It is not a substitute for the authoritative text issued by the IAASB, nor for professional advice on a specific engagement.
Standards are periodically amended. Always confirm the current effective version against the IAASB Handbook before relying on it for an active audit.

(Qualified) Chartered Accountant – ICAP
Master of Commerce – HEC, Pakistan
Bachelor of Accounting (Honours) – AeU, Malaysia