Next due
7 OCTTDS / TCS deposit · Deducted in Sep 2026tomorrow 11 OCTGSTR-1 · Outward supplies · Sep 2026in 5 days 15 OCTPF & ESI · Contributions · Sep 2026in 9 days 20 OCTGSTR-3B · Summary return · Sep 2026in 14 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 24 days 31 OCTITR filing · Audit cases · AY 2026-27in 25 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 54 days 15 DECAdvance Tax · 3rd (75%) instalment · FY 2026-27in 70 days
All due dates

SA 250, Consideration of Laws and Regulations in an Audit of Financial Statements: the two categories of laws, procedures to identify non-compliance, what to do when non-compliance is suspected, and reporting it

Management, with oversight of those charged with governance, is responsible for compliance with laws. The auditor must obtain sufficient appropriate evidence on laws with a direct...

Published
Updated
Reading time
8 min
Views
3
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 3, 2026
Last updated
Oct 5, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

SA 250 explains how far an auditor must go in checking that a company obeys the law. It splits laws into two groups, sets different duties for each, and tells the auditor what to do, and whom to tell, when non-compliance is found or suspected.

SA 250, as effective for audits of financial statements for periods beginning on or after 1 April 2009, applies to every audit of financial statements. ICAI may revise standards, so check icai.org for the current text. For where this fits among the standards see our full list of SAs.

Scope and responsibilities (paragraphs 1-8)

SA 250 applies to the audit of financial statements. It does not apply to separate engagements in which the auditor is engaged specifically to test and report on compliance with certain laws (paragraph 1). The effect of laws on statements varies a lot: some determine reported amounts and disclosures directly, others set the conditions for doing business and have no direct effect, and non-compliance may lead to fines, litigation or other consequences that matter to the statements (paragraph 2).

Paragraph 3 places the responsibility for compliance on management, with oversight from those charged with governance. The application material (A2) lists examples of what a well-run entity does: monitor legal requirements, operate internal controls, adopt and train staff on a code of conduct, discipline breaches, use legal advisers, and keep a register of significant laws and a record of complaints; larger entities may add internal audit, an audit committee and a compliance function.

The auditor is not responsible for preventing non-compliance and cannot be expected to detect all of it (paragraph 4). Inherent limits are greater here for three reasons given in paragraph 5: many laws affect operations and are not captured by the financial reporting system; non-compliance may be concealed through collusion, forgery, unrecorded transactions or override of controls; and whether an act is non-compliance is ultimately for a court to decide. The further removed non-compliance is from the transactions in the statements, the less likely the auditor is to notice it.

The two categories of laws

CategoryExamples in the standardAuditor's dutyParagraph
Laws with a direct effect on material amounts and disclosuresTax and labour lawsObtain sufficient appropriate audit evidence of compliance6(a), 13
Other laws, fundamental to operations, continuing the business or avoiding material penaltiesTerms of an operating licence, regulatory solvency requirements, environmental regulationsPerform specified procedures to help identify non-compliance6(b), 14

For the second group the auditor must (paragraph 14): inquire of management, and where appropriate those charged with governance, whether the entity complies; and inspect correspondence, if any, with licensing or regulatory authorities. A9-A10 give the application detail.

What the auditor does in every audit (paragraphs 12-17)

  1. Understand the legal framework. As part of understanding the entity under SA 315, obtain a general understanding of the legal and regulatory framework applicable to the entity and its industry, and how the entity complies with it (paragraph 12). See SA 315 part 1.
  2. Test direct-effect laws (paragraph 13).
  3. Do the specified procedures for other laws (paragraph 14).
  4. Stay alert. Other audit procedures, such as reading minutes or inspecting contracts, may reveal non-compliance (paragraph 15).
  5. Ask for a written representation that all known instances of non-compliance, or suspected non-compliance, whose effects should be considered in preparing the statements have been disclosed (paragraph 16).

Paragraph 17 adds that, absent identified or suspected non-compliance, the auditor need not perform other procedures on compliance with laws.

When non-compliance is identified or suspected (paragraphs 18-21)

  • The auditor obtains an understanding of the nature of the act and the circumstances, and further information to evaluate the possible effect on the statements (paragraph 18).
  • If non-compliance is suspected, the auditor discusses it with management and, where appropriate, those charged with governance. If they do not provide sufficient information to support compliance and the effect may be material, the auditor considers the need for legal advice (paragraph 19).
  • If sufficient information cannot be obtained, the auditor evaluates the effect of that lack of evidence on the opinion (paragraph 20).
  • The auditor evaluates the implications for the rest of the audit, including the risk assessment and the reliability of written representations (paragraph 21).

Reporting (paragraphs 22-28)

To whom or whereWhenParagraph
Those charged with governanceMatters of non-compliance that come to the auditor's attention, other than those clearly inconsequential, unless all of them are in management22
Those charged with governanceAs soon as practicable where non-compliance is believed to be intentional and material23
Next higher authorityIf management or governance are suspected of involvement, such as an audit committee or supervisory board; if none exists or the auditor fears it will not be acted on, consider legal advice24
The auditor's reportQualified or adverse opinion if non-compliance has a material effect on the statements and is not adequately reflected25
The auditor's reportQualified opinion or disclaimer if management or governance prevent the auditor from obtaining enough evidence26
The auditor's reportEvaluate the effect on the opinion if limits come from circumstances rather than management27
Outside the entityDetermine whether there is a responsibility to report to regulators or other outside parties28

Our SA 705 article explains the opinion choices. For communications with governance see SA 260. The auditor's powers and duties under the Companies Act are in our section 143 explainer; fraud, which overlaps with non-compliance, is covered in SA 240 part 1.

Documentation (paragraph 29)

The auditor documents identified or suspected non-compliance and the results of discussion with management, those charged with governance and, where applicable, outside parties. The SA 230 principles apply; see SA 230.

What the audited company should expect

The finance and legal team will be asked for a list of laws that apply to the business and how compliance is tracked, correspondence with regulators and licensing authorities, board and committee minutes, and a signed representation on known non-compliance. A good compliance calendar and a register of notices help the audit finish quicker; our compliance advisory team helps companies set these up.

Illustrative example

Rao Chemicals Pvt Ltd, an invented company, holds a pollution-control licence. The auditor asks the plant director whether all licence conditions have been met and inspects letters from the state pollution board, which include a notice about discharge levels. Because a fine and a possible shutdown could affect the statements, the auditor obtains details, discusses them with management, asks for the lawyer's view on the likely penalty and tells the audit committee. The company records a provision for the penalty and discloses the notice; the auditor concludes no modification is needed. Had the company refused to share the lawyer's letter, the auditor would have considered a scope limitation.

Need help with legal compliance records?

If you want a register of applicable laws, a compliance calendar and the documents an auditor will ask for, TaxClue's compliance advisory team can help you build them. Management teams preparing for audits can also use our compliance advisory service to review notices and licences before the auditor does.

Key takeaways

  • Laws with a direct effect on the statements, such as tax and labour laws, need audit evidence of compliance.
  • For other laws, the auditor inquires and inspects correspondence with regulators, unless non-compliance is suspected.
  • Suspected non-compliance is discussed with management and communicated to those charged with governance.
  • Material uncorrected non-compliance leads to a qualified or adverse opinion; blocked evidence leads to a qualified opinion or disclaimer.
  • Whether an act is non-compliance is ultimately a legal determination.

Read next

Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About SA 250

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Does the auditor check compliance with every law?

No. The auditor cannot be expected to detect all non-compliance. Evidence is needed for laws with a direct effect on the statements; for other laws the auditor does specified procedures (paragraphs 4, 13 and 14).

What is non-compliance under SA 250?

Acts of omission or commission by the entity, intentional or unintentional, contrary to prevailing laws. Personal misconduct unrelated to the business is excluded (paragraph 11).

Do not copy last year's filing without checking whether last year's law still applies.

— TaxClue Compliance Desk

SA 250: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,327 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

No. The auditor cannot be expected to detect all non-compliance. Evidence is needed for laws with a direct effect on the statements; for other laws the auditor does specified procedures (paragraphs 4, 13 and 14).

Acts of omission or commission by the entity, intentional or unintentional, contrary to prevailing laws. Personal misconduct unrelated to the business is excluded (paragraph 11).

Those charged with governance, other than clearly inconsequential matters; if management is suspected of involvement, the next higher authority such as an audit committee (paragraphs 22 and 24).

When it has a material effect on the statements and is not adequately reflected, or when the auditor is prevented from obtaining enough evidence (paragraphs 25-26).

The auditor must determine whether such a responsibility exists (paragraph 28). For companies, see our section 143 explainer and the fraud reporting posts.

No. It applies to the audit of financial statements, not to engagements to test and report on compliance with specific laws (paragraph 1).