SA 250 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
SA 250 explains how far an auditor must go in checking that a company obeys the law. It splits laws into two groups, sets different duties for each, and tells the auditor what to do, and whom to tell, when non-compliance is found or suspected.
SA 250, as effective for audits of financial statements for periods beginning on or after 1 April 2009, applies to every audit of financial statements. ICAI may revise standards, so check icai.org for the current text. For where this fits among the standards see our full list of SAs.
Management, with oversight of those charged with governance, is responsible for compliance with laws. The auditor must obtain sufficient appropriate evidence on laws with a direct effect on the financial statements, such as tax and labour laws, and for other laws perform limited, specified procedures: inquiry of management and inspection of correspondence with regulators. If non-compliance is suspected, the auditor investigates, communicates with governance and considers the effect on the opinion. The auditor is not responsible for preventing non-compliance and cannot be expected to detect it all.
Scope and responsibilities (paragraphs 1-8)
SA 250 applies to the audit of financial statements. It does not apply to separate engagements in which the auditor is engaged specifically to test and report on compliance with certain laws (paragraph 1). The effect of laws on statements varies a lot: some determine reported amounts and disclosures directly, others set the conditions for doing business and have no direct effect, and non-compliance may lead to fines, litigation or other consequences that matter to the statements (paragraph 2).
Paragraph 3 places the responsibility for compliance on management, with oversight from those charged with governance. The application material (A2) lists examples of what a well-run entity does: monitor legal requirements, operate internal controls, adopt and train staff on a code of conduct, discipline breaches, use legal advisers, and keep a register of significant laws and a record of complaints; larger entities may add internal audit, an audit committee and a compliance function.
The auditor is not responsible for preventing non-compliance and cannot be expected to detect all of it (paragraph 4). Inherent limits are greater here for three reasons given in paragraph 5: many laws affect operations and are not captured by the financial reporting system; non-compliance may be concealed through collusion, forgery, unrecorded transactions or override of controls; and whether an act is non-compliance is ultimately for a court to decide. The further removed non-compliance is from the transactions in the statements, the less likely the auditor is to notice it.
The two categories of laws
| Category | Examples in the standard | Auditor's duty | Paragraph |
|---|---|---|---|
| Laws with a direct effect on material amounts and disclosures | Tax and labour laws | Obtain sufficient appropriate audit evidence of compliance | 6(a), 13 |
| Other laws, fundamental to operations, continuing the business or avoiding material penalties | Terms of an operating licence, regulatory solvency requirements, environmental regulations | Perform specified procedures to help identify non-compliance | 6(b), 14 |
For the second group the auditor must (paragraph 14): inquire of management, and where appropriate those charged with governance, whether the entity complies; and inspect correspondence, if any, with licensing or regulatory authorities. A9-A10 give the application detail.
What the auditor does in every audit (paragraphs 12-17)
- Understand the legal framework. As part of understanding the entity under SA 315, obtain a general understanding of the legal and regulatory framework applicable to the entity and its industry, and how the entity complies with it (paragraph 12). See SA 315 part 1.
- Test direct-effect laws (paragraph 13).
- Do the specified procedures for other laws (paragraph 14).
- Stay alert. Other audit procedures, such as reading minutes or inspecting contracts, may reveal non-compliance (paragraph 15).
- Ask for a written representation that all known instances of non-compliance, or suspected non-compliance, whose effects should be considered in preparing the statements have been disclosed (paragraph 16).
Paragraph 17 adds that, absent identified or suspected non-compliance, the auditor need not perform other procedures on compliance with laws.
When non-compliance is identified or suspected (paragraphs 18-21)
- The auditor obtains an understanding of the nature of the act and the circumstances, and further information to evaluate the possible effect on the statements (paragraph 18).
- If non-compliance is suspected, the auditor discusses it with management and, where appropriate, those charged with governance. If they do not provide sufficient information to support compliance and the effect may be material, the auditor considers the need for legal advice (paragraph 19).
- If sufficient information cannot be obtained, the auditor evaluates the effect of that lack of evidence on the opinion (paragraph 20).
- The auditor evaluates the implications for the rest of the audit, including the risk assessment and the reliability of written representations (paragraph 21).
Reporting (paragraphs 22-28)
| To whom or where | When | Paragraph |
|---|---|---|
| Those charged with governance | Matters of non-compliance that come to the auditor's attention, other than those clearly inconsequential, unless all of them are in management | 22 |
| Those charged with governance | As soon as practicable where non-compliance is believed to be intentional and material | 23 |
| Next higher authority | If management or governance are suspected of involvement, such as an audit committee or supervisory board; if none exists or the auditor fears it will not be acted on, consider legal advice | 24 |
| The auditor's report | Qualified or adverse opinion if non-compliance has a material effect on the statements and is not adequately reflected | 25 |
| The auditor's report | Qualified opinion or disclaimer if management or governance prevent the auditor from obtaining enough evidence | 26 |
| The auditor's report | Evaluate the effect on the opinion if limits come from circumstances rather than management | 27 |
| Outside the entity | Determine whether there is a responsibility to report to regulators or other outside parties | 28 |
Our SA 705 article explains the opinion choices. For communications with governance see SA 260. The auditor's powers and duties under the Companies Act are in our section 143 explainer; fraud, which overlaps with non-compliance, is covered in SA 240 part 1.
Documentation (paragraph 29)
The auditor documents identified or suspected non-compliance and the results of discussion with management, those charged with governance and, where applicable, outside parties. The SA 230 principles apply; see SA 230.
What the audited company should expect
The finance and legal team will be asked for a list of laws that apply to the business and how compliance is tracked, correspondence with regulators and licensing authorities, board and committee minutes, and a signed representation on known non-compliance. A good compliance calendar and a register of notices help the audit finish quicker; our compliance advisory team helps companies set these up.
Illustrative example
Rao Chemicals Pvt Ltd, an invented company, holds a pollution-control licence. The auditor asks the plant director whether all licence conditions have been met and inspects letters from the state pollution board, which include a notice about discharge levels. Because a fine and a possible shutdown could affect the statements, the auditor obtains details, discusses them with management, asks for the lawyer's view on the likely penalty and tells the audit committee. The company records a provision for the penalty and discloses the notice; the auditor concludes no modification is needed. Had the company refused to share the lawyer's letter, the auditor would have considered a scope limitation.
Need help with legal compliance records?
If you want a register of applicable laws, a compliance calendar and the documents an auditor will ask for, TaxClue's compliance advisory team can help you build them. Management teams preparing for audits can also use our compliance advisory service to review notices and licences before the auditor does.
Key takeaways
- Laws with a direct effect on the statements, such as tax and labour laws, need audit evidence of compliance.
- For other laws, the auditor inquires and inspects correspondence with regulators, unless non-compliance is suspected.
- Suspected non-compliance is discussed with management and communicated to those charged with governance.
- Material uncorrected non-compliance leads to a qualified or adverse opinion; blocked evidence leads to a qualified opinion or disclaimer.
- Whether an act is non-compliance is ultimately a legal determination.
Read next
- SA 260: communication with those charged with governance
- SA 240, part 1: fraud risk assessment
- SA 580: written representations
- Section 143: auditor powers and duties
Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.
