Importance of confidentiality in Accounting work
Importance of confidentiality in Accounting work
Confidentiality is a fundamental principle of the IESBA codes of ethics. In addition to this ,accountants and auditors are bound by the data protection act .
Accountants are required to keep client information confidential. This is an important aspect of the trust between client and accountant, as to do their job, accountants require access to information about their business that client would not want made public externally to the business, and in some cases, such as where it relates to pay or future intentions of the doeectors, internationally to the business either.
In practice this means that an accountant should not discuss client matters with anyone outside the firm of accountants, and in cases where there is a conflict of interest with another audit client, with anyone outside of the team assigned to that client.
It is appropriate to discuss client matters , where necessary , with other members of staff from the firm for example, an audit team member may have to liaise with a member of the tax department over client affairs , but in general it is better to keep diacussions about client affairs to when they are professionally necessary, not merely as gossip.
The greatest risk of breach of confidentiality is likely to be accidental disclosure rather than deliberate disclosure. It is unlikely that an accountant or firm would make a deliberate disclosure of client information (under the exceptions to the duty of confidentiality noted below) without having taken legal advice and have made very suret that it is appropriate to do so. A greater risk of breach of confidentiality is by accidental disclosure( talking about client afdirs in the wrong place or leaving client information exposed accidentally ).
What is personal data breach?
A breach of security leading to the accidental or unlawful desteuction, loss, alteration, unauthorized disclosure of , or access to , personal data transmitted , stored or otherwise processed .
The ICO suggestes there will be a personal data breach whenever any personal data is lost, destroyed, corrupted or disclosed , if someone accessses the data or passes it on without proper authorisation , or if the data is made unavailable and this unavailability has a significant negative effect on individuals , for example , when it has been encrypted by ransomware, or accidentally lost or destroyed.
Personal data breaches can be very wide ranging and may include the following :
Unauthorized access to file storage( whether electronic or hard copy )
Leaving documents containing personal data on a photocopier / printer or public area
Emailing personal data to the wrong recipient
Accidently deleting or shredding a document or file containing personal data
Loss of availability of personal data
Laptops /phones /tablets containing oe having access to personal data being lost or stolen
Cars containing client files being broken into and the files being stolen or there is evidence that they have been read unlawfully.
Passing a client's contact details onto a third party without a lawful basis to do so
A staff member downloading a list of client contact details prior to leaving the firm
A staff member incorrectly updating contact details for the wrong person
Safeguards to confidentiality
There is probably a greater risk of accidental disclosure of information that is confidential within the businesses than external to the business. Such risk arises where client staff members are exposed to confidential information by overhearing audit staff conversations or by seeing documents that would normally be kept away from them.
However , there is also a risk of information passing outside the business if assurance providers work on a different client's file at another client's premises , or by losing or leaving files unprotected (for example , in a car which might be stolen) or through lack of electronic controls( for example by computer hacking)
The following security procedures are probably wise to prevent accidental disclosure of information :
Do not discuss client matters with colleagues in a public place
Do not discuss client matters with any party outside of the accountancy firm.
Do not leave audit files unattended
Do not leave client's files in cars or in unsecured private residence .
Do not remove working papers from the office unless strictly necessary
Do not work on electronic working papers on systems that do not have the requisite protection.
Disclosure of confidential information
Information acquired in the course of professional work should only be disclosed where:
Consent has been obtained from the client, employer or other proper sources
There is a public duty to disclose
There is a legal or professional right or duty to disclose.
The code of ethics identifies three circumstances where the professional accountant is or may be required to disclose confidential information .
Where disclose is permitted by law and is authorized by the client or the employer , for example where the auditor has uncovered a fraud and the client is in agreement that the matter should be referred to the policy.
Where disclosure is required by the law.
Where there is a professional duty or right to disclose, when not prohibited by law. An accountant may defend themselves in a negligence claim , for example . The code of ethics states that a professional accountant may disclose confidential information to third parties if the disclosure can be justified in the public interest and is not contrary to laws and regulations.
Difficult judgements are required by auditors as to whether the public interest overrides the duty of confidentiality. Usually , the assurance providers should take legal advice on the matter.
A professional accountant acquiring or receiving confidential information in the course of their professional work should neither use, nor appear to use, that information for their personal advantages or for the advantage of third party.
Examples of particular circumstances are:
On a change in employment , professional accountants are entitled to use experience gained in their previous position , but not confidential information acquired there.
A professional accountant should not deal in the shares of a company in which the member has had a professional association at such a time or in such manner as might make it seem that information obtained in a professional capacity was being turned to personal advantage.
Where a professional accountant has confidential information from client 1 that has affects an assurance report on client 2, they cannot provide an opinion on client 2 that they already know, from whatever source, to be untrue. If they are to continue as auditor to client 2 the conflict must be resolved. In order to do so, normal audit procedures / enquiries should be followed to enable that same information to be obtained from another source. Under no circumstances, however, should there be any disclosure of confidential information outside the firm.
Money laundering
Money laundering is defined in the Money laundering Prevention Act 2012(Bangladesh ). It is the process by which the proceeds of crime are converted into assets which appear to have a legitimate origin , so that they can be retained permanently or recycled into further criminal enterprises.
Accountants are subject to laws concerning money laundering , which makes it a criminal offence not to disclose a suspicion of money laundering ( the process by which criminals attempt to conceal the proceeds of crime). In addition , it is an offence to let as a suspected money launderer know that an invetigation may be taking place against them.
Therefore, accountants must report suspicions of money laundering to the appropriate authority , and this disclosure will not constitute a breach of confidentiality. In addition ,they should not advise the client that they have done so.
Firms must have both a money laundering reporting officer and a money laundering compliance principal , although it is possible for both roles to be held by the same person .
The MLCP must either be on the board or be a member of the firm's senior management . The nominated officer is responsible for the firm's compliance with the money laundering regulation.
The MLRO, sometimes referred to as the nominated officer' is responsible for receiving internal reports of ( suspected/ identified ) money laundering , and is responsible for making disclosure to the Anti corruption commission .
Trainees and staff carrying out assurance work must make a report to that nominated officer if a suspicion of money laundering arises.
Each firm must have these officers, so an audit team member will never be required to make a report to the authorities personally . It will always be appropriate for them to make the report of the suspicion to the nominated officer, and having made a report to the nominated officer is a defence against the criminal offence of failing to report a suspicious of money laundering. Examples of money laundering in this context could include :
Keeping customer overpayments
Offences under the comoanies act that are criminal ( such as making a loan to a director -so that the director is in possession of the proceeds of the company's crime).
Offences that involve a saved cost ( such as failure to meet environmental regulations about disposal and dumping waste instead )
The following issues therefore may give rise to suspicious of money laundering
Credits on the receivables ledger
Unusual related party transactions
Lack of expected costs in income statement
The existence of a complicated group structure with no obvious businesses reason for the complexity
High number of cash transactions without genuine business reason.
Conflicts of interest
Situations are frequently perceived by clients as conflicts of interest where in reality they involve no more than concerns over keeping information confidential. Hence the issues of confidentiality covered in sections 1 and 2 conflits of interest are releted.
The code states that firm should have in place procedures to enable them to identify whether any conflict of interest exist and to take all reasonable steps to determine whether any conflicts are likely to arise in relation to new assignments involving both new and existing clients. The code cites the following examples of conflicts of interest.
When a professional accountant competes directly with a client,or has a joint venture or similar arrangement with a major competitor of a client, then this is a thrrast to the accountant's objectivity.
When a professional accountant pwrforms services for clients whose whose interest are in conflict or who are in dispute with each other.
If there is no conflict of interest , firms may accept the assignment . If there is a conflict of interest, the significance of any threat to compliance with the fundamental principles should be evaluated . If any threats are other than clearly insignificant ,the safeguards must be applied to estimate the threat or to reduce it to an acceptable level.
There is nothing improper in a firm having two clients whose interests are in conflict provided that the activities of the firm are managed so as to avoid the work of the firm on behalf of one client adversely affecting that on behalf of another.
Where a firm believes that a conflict can be managed , sufficient disclosure should be made to the clients or potential clients concerned, together with details of any proposed safeguards to preserve confidentiality and manage conflict . If consent is refused by the client then the firm must not continue to act for one of the parties .
Where a conflict cannot be managed even with safeguards ,then the firm should not act,
A self interest threat to the objectivity of a professional accountant or their firm will arise where there is or is likely to be a conflict of interest between them and the client or where confidential information received from the client could be used by them for the firm's or for a third party's benefit .
The test to apply is weather a reasonable and informed observer would perceive that the objectivity of the member or their firm is likely to be impaired. The member or their firm should be able to satisfy themselves and the client that any conflict can be managed with available safeguards.
Safeguards might include:
Disclosure of the circumstances of the conflict
Obtaining the informed consent of the client to act
The use of confidentiality agreements of signed by employees
Establishing information barrires
Regular review of the application of safeguards by a senior individual not involved with the relevant client engagement .
Ceasing to act
Information barriers , traditionally knows as Chinese walls include :
Ensuring that there is no overlap between different teams
Physical separation of teams
Careful procedures for where information has to be disseminate beyond a barrier and for maintaining proper records where this occurs
Some commentators argue that the team Chinese walls is culturally insensitive and disrespectful of the ability of the great eall of china to keep china's enemies at bay. However , the term is in common use and is likely to remain so for some time in the future .

Comments
Post a Comment