FRC Audit Enforcement Reforms: New Pressure Points for Audited Entities

On 1 July 2026, the Financial Reporting Council (FRC) introduced several reforms to its Audit Enforcement Procedure (AEP), the framework for enforcement of auditor non-compliance. The reforms introduce three new pathways and raise the threshold for commencing enforcement. These changes form part of a wider shift in the FRC's regulatory philosophy, placing greater emphasis on early engagement and faster resolution where appropriate. Where concerns arise (whether through a whistleblower report, management becoming aware of potential misconduct, or the commencement of an internal investigation), the reforms are significant because they increase the likelihood that auditors will seek to engage with the FRC at an earlier stage. This has important implications for companies considering whether, when and how to self-report issues to regulators. In practical terms, the key risks are twofold: first, auditors now face both greater regulatory pressure and stronger incentives to consider disclosure to the FRC where fraud, misconduct or going-concern issues arise, which companies with active investigations must factor into their investigation strategy; and second, companies should expect auditors to seek much fuller disclosures and ongoing updates on live internal or regulatory investigations, requiring careful handling with expert advice to protect privileged work product. We discuss below the key changes to the AEP and the practical considerations that companies should have front of mind.

Additional pathways to resolution

The most significant feature of the reforms is the introduction of three new pathways to resolve auditor non-compliance: Published Constructive Engagement, Accelerated Procedure, Early Admissions Process. Together with the existing Constructive Engagement and formal investigation routes, the reforms provide the FRC with a broader range of enforcement tools, allowing it to respond more proportionately to the seriousness of the conduct while encouraging earlier engagement and resolution.

Under the previous regime, the gap between confidential supervisory action and formal enforcement action often resulted in lengthy and resource-intensive investigations. The revised AEP seeks to bridge that gap.[1]

Published Constructive Engagement

Like Constructive Engagement, Published Constructive Engagement applies where suspected breaches are low-level or inadvertent, involving no actual or limited potential financial harm, and the firm has demonstrated a willingness to remediate.[2] The key distinction is that Published Constructive Engagement results in a published outcome for deterrence, transparency or education.[3]

Accelerated Procedure

The Accelerated Procedure provides an alternative to formal investigation where the available information is sufficient for the FRC to determine whether a breach has occurred but where a full investigation might be disproportionate. It is intended to enable appropriate cases to be resolved more quickly and efficiently.

Early Admissions Process

Respondent firms referred for formal investigation may, with the FRC's agreement, prepare a Factual Account of the relevant events. The FRC can then decide whether to pursue settlement, continue investigating, or close the matter without the need for a full investigation in every instance.[4]

A higher threshold for commencing enforcement action

The revised AEP also raises the threshold for commencing enforcement action. Previously, the FRC could act where information simply raised a question of breach.[5] It must now have reasonable grounds to suspect a breach before pursuing action under the AEP and be satisfied that doing so is in the public interest.[6]

The knock-on effect for audited companies

The AEP reforms also sit alongside recent changes to the International Standards on Auditing (ISA) – specifically to ISA 240 (fraud) and 570 (going concern). ISA 240 requires an auditor who suspects fraud to report it to those charged with governance and, where management is implicated, consider reporting outside the entity. ISA 570 requires auditors to evaluate going-concern uncertainty and related disclosures, qualifying their opinion where management’s response is inadequate.

Together, these developments increase both the regulatory expectation and the practical incentive for auditors to identify, investigate and escalate concerns at an earlier stage – including, where appropriate, considering disclosure to the FRC itself where fraud, misconduct or going-concern issues arise. This is a risk that companies with active investigations need to factor into their investigation strategy from the outset. Audited entities are therefore under increased pressure to ensure that governance and escalation processes are robust, so that they do not find themselves in a position where an auditor is applying pressure that cannot be answered with timely information, or where an auditor concludes that external reporting or engagement with the FRC is appropriate. That alignment means auditors have both regulatory and practical incentives to escalate concerns earlier, rather than allowing management additional time to investigate internally.

Historically, companies retained control over how any concerns identified and any resulting internal investigations are handled – including timeframes, personnel and who was privy to findings – updating the auditor when appropriate. However, as auditors face growing pressure to coordinate with the FRC, they may be less willing to wait for a client's investigation to conclude before forming a view. Auditors may also increasingly seek greater visibility into, or in some cases direct involvement in, handling relevant concerns or indeed in internal investigations rather than relying on periodic updates from management, at the company's cost. Companies will need to think carefully about how information is shared with auditors. While auditors may seek greater visibility how relevant issues are being handled or investigated, companies will need to balance that against preserving legal privilege, protecting litigation and regulatory strategy and avoiding unnecessary waiver.

Key takeaways for companies

The revised AEP increases the pressure companies face when fraud, misconduct or going-concern issues arise. In light of the reforms, companies should consider:

  • Robust governance and escalation processes: Auditors are likely to seek greater assurance that fraud, misconduct or going-concern issues have been properly investigated and addressed before signing off on a company’s accounts. Where that assurance cannot be given, sign-off may be delayed. Governance and investigation processes must be sufficiently robust to address concerns promptly and to support constructive engagement with an auditor that is itself under pressure to demonstrate rigour to the FRC.

  • Increased auditor involvement: Auditors’ risk and quality functions may increasingly seek direct involvement in, or visibility over, a client’s live internal investigation or fact-finding exercise rather than waiting for management updates. This may create practical challenges for the conduct of investigations – preserving legal privilege becomes harder, and costs are likely to rise given companies must typically pay for the auditor’s own risk team to be involved. Companies should approach these requests carefully and with the benefit of expert advice to ensure that privileged work product remains adequately protected.

  • Rethinking when to communicate with the auditor: Companies should consider at an early stage how and when ongoing concerns or allegations are communicated to their auditor. The reforms mean that decisions about the timing of those communications may have broader regulatory implications than before.

  • Protecting the self-disclosure advantage: Companies have generally had greater control over the timing of any self-disclosure to a regulator. Companies should now be alive to the possibility that their auditor discloses first and move decisively so as not to lose control over the disclosure process. Although the consequences will depend on the regulator concerned, companies should consider whether delay in engaging with their auditor could ultimately prejudice the credit available for voluntary self-reporting or early cooperation.

  • Planning regulatory strategy from the outset: Where fraud, misconduct or going-concern issues arise, companies should consider at an early stage how communications with auditors, regulators and legal advisers fit together. Decisions that were previously taken sequentially may now need to be considered in parallel.

Taken together, the reforms do not alter companies' legal obligations directly, but rather materially change the environment in which those obligations are managed. Companies can no longer assume they control the pace or sequence of engagement with regulators. Early coordination between legal advisers, management and auditors will increasingly determine whether investigations remain orderly, privileged and strategically managed.

[1] AEP Case Assessment and Allocation Policy (July 2026) at [21].

[2] AEP Case Assessment and Allocation Policy (July 2026) at [29].

[3] AEP Case Assessment and Allocation Policy (July 2026) at [30].

[4] AEP (July 2026) at [21]-[28].

[5] AEP Guidance for the Case Examiner (June 2023) at [10A].

[6] AEP (July 2026) at [8].

By Mark Beardsworth, Sharon Takhar and Nikara Rangesh of Signature Litigation